The Dark Side of Scale: Insecurity of Direct-to-Cell Satellite Mega-Constellations

Wei Liu, Yuanjie Li, Hewu Li, Yimei Chen, Yufeng Wang, Jingyi Lan

IEEE Symposium on Security and Privacy 2024 · Day 1 · Continental Ballroom 5

Overview

In this compelling talk from IEEE S&P, Wei Liu and his co-authors unveil a critical security vulnerability within the rapidly expanding landscape of direct-to-cell satellite mega-constellations. Titled "The Dark Side of Scale: Insecurity of Direct-to-Cell Satellite Mega-Constellations," the presentation challenges the prevailing assumption that the sheer scale and high mobility of these next-generation satellite networks inherently enhance their security. Instead, the researchers demonstrate how these very attributes can be weaponized by attackers, transforming into a "double-edged sword" that undermines the system's resilience.

Watch on YouTube

Visual summary for The Dark Side of Scale: Insecurity of Direct-to-Cell Satellite Mega-Constellations by Wei Liu, Yuanjie Li, Hewu Li, Yimei Chen, Yufeng Wang, Jingyi Lan
Visual summary for The Dark Side of Scale: Insecurity of Direct-to-Cell Satellite Mega-Constellations by Wei Liu, Yuanjie Li, Hewu Li, Yimei Chen, Yufeng Wang, Jingyi Lan

Key moments

  1. 0:00 Introduction: Mega-constellations and their security challenges
  2. 2:00 Initial assessment: Why mega-constellations seem secure
  3. 4:00 The core finding: Scale and mobility as a double-edged sword
  4. 4:35 Attack Amplification: Exploiting ground station bottlenecks
  5. 5:25 Attack Obfuscation: Mimicking satellite radio channels
  6. 8:00 Proposed control plane attack with three steps
  7. 9:00 Validation with real satellites and emulated devices

The Dark Side of Scale: Insecurity of Direct-to-Cell Satellite Mega-Constellations

Speakers: Wei Liu; Yuanjie Li; Hewu Li; Yimei Chen; Yufeng Wang; Jingyi Lan

Conference: IEEE S&P

YouTube: https://www.youtube.com/watch?v=xa7jF1gPIz0

Overview

In this compelling talk from IEEE S&P, Wei Liu and his co-authors unveil a critical security vulnerability within the rapidly expanding landscape of direct-to-cell satellite mega-constellations. Titled "The Dark Side of Scale: Insecurity of Direct-to-Cell Satellite Mega-Constellations," the presentation challenges the prevailing assumption that the sheer scale and high mobility of these next-generation satellite networks inherently enhance their security. Instead, the researchers demonstrate how these very attributes can be weaponized by attackers, transforming into a "double-edged sword" that undermines the system's resilience.

The talk addresses a highly pertinent and evolving area of telecommunications. As companies like Starlink and OneWeb deploy thousands of Low Earth Orbit (LEO) satellites to provide global direct-to-cell services, and with features like iPhone's emergency SOS via satellite already available and Android integration on the horizon, satellite connectivity is poised to become a ubiquitous feature of everyday mobile communications. Understanding the security implications of this massive technological shift is paramount, not only for the integrity of these networks but also for the critical services they are designed to support.

The research presented by Liu et al. provides a sobering assessment of these emerging networks. It introduces SetOver, a novel control plane cross-layer attack that exploits the unique characteristics of LEO mega-constellations to achieve widespread service disruption with unprecedented efficiency. By exposing the vulnerabilities inherent in the design and operational logic of these systems, the talk serves as a crucial call to action for operators, device manufacturers, and the broader security community to re-evaluate and fortify the foundational security of what is rapidly becoming the next frontier for mobile networks.

Background

▶ Watch: Introduction: Mega-constellations and their security challenges (0:00)

The concept of direct-to-cell satellite communication is not entirely new, having existed for decades primarily through Geostationary Orbit (GSO) satellites. These high-altitude satellites offer excellent coverage but come with significant drawbacks: their distant transmission necessitates power-hungry, dedicated satellite phones, resulting in slow, noisy, and expensive services largely inaccessible to the average consumer. The advent of Low Earth Orbit (LEO) satellites dramatically changed this paradigm. Positioned much closer to Earth, LEO satellites offer faster network speeds, lower energy costs, and can be accessed with more affordable hardware, including regular smartphones.

However, LEO satellites have smaller coverage footprints, necessitating the deployment of hundreds to thousands of satellites to achieve global coverage and sufficient network capacity. This has led to the rise of mega-constellations by operators such as Starlink and OneWeb. Initially, the scale and mobility of these mega-constellations were perceived as inherent security advantages. Proponents argued that if one satellite were attacked (e.g., physically or via jamming), users could simply switch to another. The sheer number of satellites would make deploying enough attack nodes prohibitively expensive. Furthermore, LEO satellites are fast-moving targets, traveling at approximately 7 kilometers per second, requiring attackers to constantly track and switch targets within 10-second windows, further increasing attack costs. Even in protocol attacks, the high mobility was thought to make attacks easily detectable, as the distinct radio propagation paths and Doppler shifts between legitimate satellites and stationary attackers would allow victim devices to identify and blacklist malicious nodes.

This talk, however, fundamentally challenges these assumptions. It posits that the very attributes of extreme scale and mobility, far from being unassailable defenses, can be leveraged by sophisticated attackers to create highly effective and difficult-to-detect attacks. The research identifies that existing attacks, when combined with the unique characteristics of mega-constellations, can be amplified and obfuscated, turning the perceived strengths into critical weaknesses. This re-evaluation of the security landscape is crucial as direct-to-cell satellite services transition from niche applications to mainstream mobile connectivity.

Key Findings

▶ Watch: The core finding: Scale and mobility as a double-edged sword (4:00)

The central finding of this research is that the extreme scale and mobility of LEO mega-constellations, while superficially appearing to enhance security, are in fact a "double-edged sword." The authors demonstrate that these characteristics can be exploited to facilitate two critical attack dimensions: attack amplification and attack obfuscation. These dimensions are combined in a novel control plane cross-layer attack termed SetOver, which can effectively block direct-to-cell LEO satellite mega-constellations.

Attack Amplification is achieved by exploiting a fundamental architectural bottleneck: all user signals must be redirected to ground stations for processing. This creates a single point of congestion. The core network's standard congestion control mechanisms, designed to reject excessive registration requests during periods of high load, are weaponized. An attacker can mimic network congestion, causing victim devices to cease registration attempts even when other legitimate satellites are available, thereby trapping them in a denial-of-service state. This allows a single attacker, or a small number of attackers, to disrupt service across a wide area, achieving a disproportionately large impact compared to the resources expended.

Attack Obfuscation is the ability for an attacker to disguise itself as a legitimate, fast-changing satellite, thereby evading detection. This is achieved by meticulously mimicking the dynamic radio channels and geometry of LEO satellites. By leveraging the predictability of satellite orbital motions and the fact that victims within an attacker's relatively small coverage experience similar delays and Doppler shifts, the attacker can generate highly realistic fake radio channel characteristics. This capability makes it extremely difficult for victim devices to distinguish between legitimate satellites and malicious entities, rendering traditional detection methods ineffective.

The SetOver attack, which integrates these two principles, was rigorously validated. The researchers worked with a satellite operator and device vendor, using both real satellites and commercial off-the-shelf (COTS) devices. Further validation was conducted using an emulated community of the shared 3GPP Non-Terrestrial Network (NTN) protocol stacks, capable of emulating various satellite devices, including COTS, Reduced Capability NTN (RNT), and Internet of Things NTN (IoT NTN) devices. Emulations were performed across different cities and countries to assess scalability. A key finding from these validations is the remarkable efficiency of SetOver: it requires only 1% of the attack nodes needed for traditional jamming to block service in the same area, making it a low-cost, high-impact threat for large-scale attacks.

Technical Deep Dive

▶ Watch: Attack Amplification: Exploiting ground station bottlenecks (4:35)

The SetOver attack leverages a sophisticated combination of attack amplification and attack obfuscation to achieve widespread service denial in direct-to-cell LEO satellite mega-constellations. The technical underpinnings are rooted in exploiting both network control plane protocols and physical layer radio channel characteristics.

Attack Amplification Mechanism:

The core of attack amplification lies in the single-point bottleneck at the ground station. LEO satellites, despite their number, must redirect all user signals to a relatively limited number of ground stations for core network processing. This creates a potential point of congestion. To prevent overload, the core network implements congestion control mechanisms, rejecting excessive registration requests by signaling network congestion.

SetOver exploits this by:

  1. Inducing Perceived Congestion: An attacker, instead of jamming all satellites, focuses on manipulating the perception of network congestion. By deploying even a few attack nodes to selectively block or interfere with registration attempts, or by simply sending malicious signals mimicking congestion, the attacker can trigger the core network's congestion control.
  2. Device-Side Reaction: Upon receiving a congestion signal, the victim device's protocol stack is designed to stop sending further registration requests, assuming the entire core network is congested. Crucially, the device will not attempt to switch to another available satellite because it incorrectly attributes the issue to a core network problem, not a local satellite access issue. This effectively traps the victim within the attacker's sphere of influence, blocking access to all legitimate LEO service areas. This method is far more efficient than brute-force jamming, which would require significant resources to block multiple fast-moving satellites.

Attack Obfuscation Mechanism:

The goal of attack obfuscation is to make the attacker indistinguishable from a legitimate, fast-moving LEO satellite, thereby evading detection. This is the most challenging aspect due to the extreme mobility of satellites.

  1. Mimicking Radio Channels in the Delay Domain: A naive approach to mimic a radio channel (how a signal propagates) as a function of time and frequency would fail due to rapid fluctuations. Instead, SetOver operates in the delay domain, which describes the radio channel in terms of geometry and Doppler shift between the user equipment (UE) and the moving satellite. This domain is more predictable due to regular satellite orbital motions.
  2. Exploiting Distant Transmission Properties: A key insight is that due to the distant transmission of LEO satellites, victims within an attacker's relatively small coverage area experience similar delays and Doppler shifts as if they were interacting with a real satellite. This facilitates high-fidelity radio channel and geometry mimicry.
  3. Leveraging Ephemeris Data: Attackers can use publicly available ephemeris (EFW) data, which describes satellite orbital paths, to generate authentic-looking serving satellite delays and Doppler shifts. This allows them to accurately recreate the radio channel and geometry of a legitimate satellite. The presence of more satellites also stabilizes the serving satellite's radio channel, further simplifying obfuscation.
  4. System Information Block (SIB) Manipulation: LEO satellites broadcast System Information Blocks (SIBs) to UEs, containing vital information such as operator identity, cell identity, service area identity, and frequencies. SetOver attackers drop legitimate SIBs and inject their own modified SIBs, tricking victims into connecting to the malicious entity.

SetOver Attack Execution (Three Steps):

  1. Cell Selection Manipulation: The attacker, positioned significantly closer (10 to 100 times) to victims than actual satellites, manipulates the cell selection process. This subtly hijacks victims attempting to access satellite services, directing them towards the attacker's rogue signal.
  2. Registration Hijacking and Implicit Blocking: By exploiting the centralized ground station's standardized congestion controls, the hijacked victims' registration requests are intentionally rejected or manipulated. This implicitly blocks access to all legitimate LEO service areas, not just the one the attacker is mimicking.
  3. Continuous Obfuscation: The SetOver attacker continuously repeats the radio channel geometry and signaling recreation process, maintaining its disguise as a fast-changing, legitimate serving satellite. This persistent obfuscation prevents victims from easily detecting the attack.

In essence, SetOver combines a deceptive physical layer presence with a clever exploitation of network layer congestion control, making it a potent and stealthy threat to the integrity and availability of direct-to-cell satellite mega-constellations.

Demo / Proof of Concept

▶ Watch: Proposed control plane attack with three steps (8:00)

While the talk did not feature a live, real-time demonstration in the traditional sense, the researchers provided extensive validation and emulation results that serve as robust proof-of-concept for the SetOver attack. These validations were critical in assessing the attack's feasibility, scalability, and efficiency in realistic scenarios.

The team engaged in collaborative efforts with both a satellite operator and a device vendor to validate SetOver using real satellites and commercial off-the-shelf (COTS) devices. This real-world testing is crucial for ensuring that the theoretical vulnerabilities translate into practical exploits against existing infrastructure and user equipment.

Further validation was conducted through a sophisticated emulation environment. This involved an "am resolved community" of shared 3GPP Non-Terrestrial Network (NTN) protocol stacks. This emulation platform was capable of simulating various types of satellite devices, including COTS, Reduced Capability NTN (RNT), and Internet of Things NTN (IoT NTN) devices. The ability to emulate a diverse range of devices and protocol stacks highlights the broad applicability of the SetOver attack across the NTN ecosystem.

To assess the attack's scalability and potential for widespread disruption, the researchers conducted extensive emulations across different cities and countries. This allowed them to evaluate how SetOver would perform if adopted by terrestrial LTE or 5G operators with massive base stations, potentially enabling ubiquitous blocking capabilities.

A significant quantitative finding from these validations underscores the efficiency of SetOver: compared to traditional jamming techniques, SetOver requires only 1% of the attack nodes to block service in the same geographical area. This drastically reduced cost makes large-scale attacks far more economically viable for malicious actors, marking a substantial increase in the threat posed to satellite mega-constellations. The comprehensive validation process, combining real-world interaction with large-scale emulation, firmly establishes SetOver as a credible and highly efficient attack vector.

Defensive Implications

▶ Watch: Validation with real satellites and emulated devices (9:00)

The SetOver attack presents significant challenges for defenders due to its efficiency and obfuscation capabilities. The researchers proposed both short-term and long-term defenses, acknowledging the complexities involved in counteracting such a sophisticated attack.

Short-Term Defense:

For immediate mitigation, the team proposes to disable congestion control during the initial registration phase. The rationale is that in the early stages of connection, with fewer active users, the risk of legitimate congestion is lower. If an attacker signals congestion, the victim device, without congestion control enabled, would not simply stop trying to connect. Instead, it would detect the issue, detach from the attacking entity, and attempt to switch to another available satellite. This short-term fix was developed in partnership with a satellite operator for adoption. However, the limitation is clear: it will suffer from legitimate congestion issues when the user base grows, making it a temporary solution rather than a fundamental one.

Long-Term Defense Challenges:

The core challenge for long-term defense lies in the attacker's ability to intelligently disguise itself as fast-changing real satellites through radio channel geometry and signaling recreation. This makes it exceedingly difficult for a single user equipment (UE) to detect the difference between an attacker and a legitimate satellite at the physical layer.

One proposed long-term solution, often discussed in security contexts, is digitally signing all bootstrapping messages to authenticated satellites before registration. This would enable UEs to detect fake satellites by verifying their digital signatures. However, the researchers highlight several critical limitations:

  1. Cots Device Compatibility: This solution is not readily available or capable for COTS devices, which form the majority of user equipment. Implementing new hardware or firmware for signature verification across a vast array of existing devices is impractical.
  2. Key Management for Initial Registration: For a UE to verify a satellite's digital signature, it needs the satellite's public key or certificate. It is not feasible for a device to pre-store all base station and satellite certificates for verification, especially during initial registration in a global network.
  3. Prohibitive Overhead: Digital signatures introduce significant overhead. The signature size can even exceed the maximum signal size for IoT devices, making this approach unviable for resource-constrained endpoints.
  4. Impact on Critical Functions: Previous works have acknowledged that digital signatures can hinder critical 4G/5G functions, such as international roaming and emergency calls, which are key applications for direct-to-cell satellite services.

Physical Layer Defense via Multi-Device Time Difference of Arrival (TDOA):

Given the difficulties with single-UE detection and the limitations of digital signatures, the researchers propose a more robust physical layer defense: utilizing multi-device time difference of arrival (TDOA). This approach leverages the power of user location diversity, where distributed devices cooperatively counteract SetOver.

  1. Cooperative Detection: Instead of a single device trying to detect the attacker, multiple devices in proximity can collaborate.
  2. TDOA Principle: The core idea is to measure the time difference of arrival of signals from both a real satellite and a suspected attacker at different victim devices.
  3. Geometric Discrepancy: The crucial insight is that the altitude of a real satellite (H) is vastly greater than the range of an attacker's node (R). Consequently, the TDOA measured from an attacker will be significantly larger than the TDOA measured from a real satellite between two geographically distinct victim devices. This distinct difference allows UEs to utilize TDOA measurements to reliably distinguish between real and fake satellites, enhancing cell selection and enabling escape from malicious entities.

This multi-device TDOA approach offers a promising long-term defense by exploiting fundamental physical layer differences that attackers cannot easily mimic, providing a more resilient mechanism against the sophisticated obfuscation tactics of SetOver.

Key Takeaways

  • Double-Edged Sword: The extreme scale and mobility of LEO mega-constellations, often perceived as security advantages, can be exploited to create effective and low-cost attacks.
  • SetOver Attack: A novel control plane cross-layer attack that combines attack amplification (exploiting ground station congestion control) and attack obfuscation (mimicking satellite radio channels and geometry).
  • Efficiency and Stealth: SetOver is highly efficient, requiring only 1% of attack nodes compared to traditional jamming to block service, and uses ephemeris (EFW) data and System Information Block (SIB) manipulation to remain stealthy.
  • Validation: The attack was validated with real satellites, COTS devices, and emulated 3GPP Non-Terrestrial Network (NTN) protocol stacks, confirming its practical feasibility.
  • Short-Term Defense: Disabling congestion control during initial registration can offer temporary relief but is not a scalable long-term solution.
  • Long-Term Defense: Traditional digital signatures are largely impractical for NTN due to overhead, key management, and COTS device limitations. A more promising approach is multi-device time difference of arrival (TDOA), which leverages physical layer geometric differences to detect fake satellites.

About the Speaker(s)

This research was presented by Wei Liu, with contributions from co-authors Yuanjie Li, Hewu Li, Yimei Chen, Yufeng Wang, and Jingyi Lan. Wei Liu, as the primary speaker, elucidated the intricate details of the SetOver attack and its profound implications for the security of direct-to-cell satellite mega-constellations. Their collective work highlights a critical area of research at the intersection of satellite communication, mobile networks, and cybersecurity, underscoring the need for proactive security measures as these technologies become increasingly integrated into global infrastructure.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This research obliterates the myth of inherent security in LEO mega-constellations. It introduces SetOver, a novel attack that weaponizes scale and mobility, achieving widespread service disruption with alarming efficiency by exploiting ground station bottlenecks and sophisticated physical layer mimicry. A critical, urgent wake-up call for the entire direct-to-cell satellite industry.

Heather Calloway (CISO) — STRONG ACCEPT

This research compellingly demonstrates how the perceived security advantages of LEO mega-constellations can be weaponized, unveiling a significant systemic vulnerability. The SetOver attack, validated with real-world infrastructure, poses a low-cost, high-impact threat to global direct-to-cell services, demanding immediate and strategic re-evaluation of network security by operators and regulators. While short-term mitigations exist, the long-term defense requires a fundamental shift in detection paradigms.

→ Top-rated talks at IEEE Symposium on Security and Privacy 2024

All talks from IEEE Symposium on Security and Privacy 2024