The Dark Side of Scale: Insecurity of Direct-to-Cell Satellite Mega-Constellations

Wei Liu, Yuanjie Li, Hewu Li, Yimei Chen, Yufeng Wang, Jingyi Lan

IEEE Symposium on Security and Privacy 2024 · Day 1 · Continental Ballroom 5

Overview

This talk, presented at IEEE S&P, delves into the often-overlooked security vulnerabilities inherent in the burgeoning direct-to-cell (D2C) satellite mega-constellations. Led by Wei Liu and co-authored by a team of researchers, the presentation challenges the prevailing assumption that the sheer scale and high mobility of these constellations inherently enhance their security. Instead, the research demonstrates how these very characteristics can be weaponized, turning a perceived strength into a critical weakness.

Watch on YouTube

Visual summary for The Dark Side of Scale: Insecurity of Direct-to-Cell Satellite Mega-Constellations by Wei Liu, Yuanjie Li, Hewu Li, Yimei Chen, Yufeng Wang, Jingyi Lan
Visual summary for The Dark Side of Scale: Insecurity of Direct-to-Cell Satellite Mega-Constellations by Wei Liu, Yuanjie Li, Hewu Li, Yimei Chen, Yufeng Wang, Jingyi Lan

Key moments

  1. 0:00 Introduction to direct-to-cell satellite mega-constellations.
  2. 1:00 Why mega-constellations initially appear more secure.
  3. 4:00 Extreme scale and mobility are a "double-edged sword."
  4. 4:30 How attackers exploit ground station bottlenecks for amplification.
  5. 5:30 Obfuscation: mimicking satellite radio channels and geometry.
  6. 8:00 Three-step control plane attack against direct-to-cell networks.
  7. 9:00 Validating attack with operators and assessing scalability.

The Dark Side of Scale: Insecurity of Direct-to-Cell Satellite Mega-Constellations

Speakers: Wei Liu; Yuanjie Li; Hewu Li; Yimei Chen; Yufeng Wang; Jingyi Lan

Conference: IEEE S&P

YouTube: https://www.youtube.com/watch?v=jGtLyeAxJ88

Overview

This talk, presented at IEEE S&P, delves into the often-overlooked security vulnerabilities inherent in the burgeoning direct-to-cell (D2C) satellite mega-constellations. Led by Wei Liu and co-authored by a team of researchers, the presentation challenges the prevailing assumption that the sheer scale and high mobility of these constellations inherently enhance their security. Instead, the research demonstrates how these very characteristics can be weaponized, turning a perceived strength into a critical weakness.

The article explores the "SetOver" attack, a novel control plane cross-layer vulnerability that exploits the architectural design and operational protocols of D2C networks to achieve widespread service disruption. As companies like Starlink and OneWeb rapidly deploy thousands of Low Earth Orbit (LEO) satellites to provide global mobile connectivity, and as features like emergency SOS via satellite become standard on devices like the iPhone, understanding and mitigating these vulnerabilities is paramount. This research provides a crucial, analytical perspective on securing the next frontier of mobile communication.

Background

▶ Watch: Introduction to direct-to-cell satellite mega-constellations. (0:00)

The concept of direct-to-cell satellite communication is not entirely new, having existed for decades primarily through Geostationary Orbit (GSO) satellites. These traditional systems, while offering broad coverage, were typically characterized by power-hungry, slow, and noisy transmissions, often requiring dedicated, expensive satellite phones with high-gain antennas. Consequently, their accessibility and affordability remained limited for most consumers.

The advent of LEO satellites has dramatically shifted this paradigm. Positioned much closer to Earth, LEO constellations offer significantly faster network speeds, lower energy costs, and the potential for compatibility with more affordable hardware, including regular smartphones. To compensate for their smaller individual coverage footprints, companies like Starlink and OneWeb are deploying hundreds to thousands of LEO satellites, forming mega-constellations designed to provide ubiquitous global coverage and greatly increased network capacity.

Initially, the extreme scale and mobility of these mega-constellations were widely perceived as significant security advantages. Proponents, including figures like Elon Musk, have suggested that such systems are inherently resilient, capable of resisting hacking and jamming attacks. The rationale often cited is that if one satellite is attacked, users can simply switch to another. Furthermore, the rapid orbital velocity of LEO satellites (approximately 7 km/s) makes them fast-moving targets, increasing the cost and complexity for attackers who would need to track and switch targets every few seconds. These characteristics were thought to make large-scale attacks prohibitively expensive and easily detectable due to distinct radio propagation paths and Doppler shifts. However, this research critically re-evaluates these assumptions, revealing that the very attributes celebrated for their security benefits can, in fact, be cleverly exploited by sophisticated attackers.

Key Findings

▶ Watch: Extreme scale and mobility are a "double-edged sword." (4:00)

The central revelation of this research is that the extreme scale and mobility of LEO mega-constellations, far from being an unmitigated security boon, present a double-edged sword. The talk introduces a novel attack methodology named "SetOver", which leverages these characteristics not to enhance security, but to amplify the impact of attacks and obfuscate their presence, thereby evading detection.

The Key Findings can be summarized through two primary attack strategies enabled by SetOver:

  1. Attack Amplification: By exploiting architectural bottlenecks, specifically the centralized ground station processing and standardized congestion control mechanisms, SetOver can achieve widespread service disruption across an entire mega-constellation with minimal attacker resources. Unlike traditional jamming, which requires numerous attack nodes to cover a wide area, SetOver achieves broad blocking by manipulating the network's internal signaling.
  2. Attack Obfuscation: SetOver leverages the predictable orbital mechanics of LEO satellites to disguise itself as a legitimate, fast-changing satellite. This is achieved by meticulously mimicking the radio channel geometry and signaling, making it exceedingly difficult for victim devices to distinguish between a legitimate satellite and an attacker. This high degree of stealth allows the attack to persist undetected by individual user equipment.

In essence, the researchers demonstrate that the very attributes designed for global coverage and resilience can be turned against the system, enabling low-cost, large-scale, and highly stealthy attacks that were previously thought impractical against such dynamic and distributed networks.

Technical Deep Dive

▶ Watch: How attackers exploit ground station bottlenecks for amplification. (4:30)

The SetOver attack is a sophisticated control plane cross-layer attack that targets the fundamental operational mechanisms of direct-to-cell LEO satellite mega-constellations. It achieves its potency through a combination of attack amplification and attack obfuscation techniques.

Attack Amplification

The core of SetOver's amplification strategy lies in exploiting a critical architectural vulnerability: the single-point bottleneck at the ground stations. Despite the vast number of satellites, all user signals must eventually be redirected to ground stations for further processing. This centralized processing creates a potential point of congestion.

When this bottleneck becomes overloaded, the core network initiates congestion control mechanisms, rejecting excessive registration requests from user devices. Crucially, upon receiving a congestion signal, user devices are designed to stop sending further registration requests, even if other legitimate satellites are available within range. The assumption is that the congestion resides in the core network, making attempts to connect to alternative satellites futile.

SetOver exploits this behavior. Instead of physically jamming dozens of satellites one by one, a single attacker (or a small number of attackers) can spoof the congestion control signaling. By indicating network-wide congestion, the attacker effectively traps victims within its vicinity, preventing them from connecting to any legitimate satellite in the mega-constellation. This achieves a widespread denial of service with significantly fewer resources than traditional jamming. The talk highlights that SetOver requires only 1% of the attack nodes compared to jamming to block service in the same area, demonstrating its extreme cost-efficiency for large-scale disruptions.

Attack Obfuscation

To evade detection, SetOver employs sophisticated attack obfuscation techniques, designed to make the attacker indistinguishable from a legitimate, fast-moving LEO satellite. The most challenging aspect is mimicking the dynamic radio channel characteristics of satellites.

A naive approach of directly mimicking the radio channel as a function of time and carrier frequency would fail due to the extreme and unpredictable fluctuations caused by satellite mobility. SetOver overcomes this by leveraging the predictable orbital motion of satellites. It emulates the satellite channel in the delay domain, which describes the radio channel in terms of geometry and Doppler shift between the user equipment and the moving satellite. These parameters are more predictable than other wireless qualities due to the regular orbital mechanics.

A key insight is that due to the distant transmission of legitimate satellites, victims within the attacker's relatively small coverage area experience similar delays and Doppler shifts. This facilitates high-fidelity radio channel and geometry spoofing. The attacker can use publicly available ephemeris data (satellite orbital prediction data) to generate spoofed serving satellite delays and Doppler shifts, thereby replicating the actual radio channel and geometry that a legitimate satellite would present. Furthermore, the presence of more satellites in the sky tends to stabilize the serving satellite's radio channel, simplifying the obfuscation process.

Beyond radio channel spoofing, SetOver also manipulates System Information Blocks (SIBs). Legitimate satellites continuously broadcast SIBs, which contain critical information such as operator identity, cell identity, service area identity, and scheduling information. SetOver intercepts or fabricates these SIBs, replacing the legitimate data with its own spoofed information, and broadcasts them to victims within its coverage. This ensures that the hijacked devices perceive the attacker as a valid, albeit congested, part of the legitimate satellite network.

The Three Steps of SetOver

The researchers outline SetOver as a three-step control plane cross-layer attack:

  1. Cell Selection Manipulation: The SetOver attacker, positioned significantly closer to victims (10 to 100 times closer than actual satellites), manipulates the cell selection process. This subtly hijacks victim devices as they attempt their initial access to the satellite network.
  2. Congestion Control Exploitation: By exploiting the centralized ground station's standardized signaling and congestion control mechanisms, the attacker implicitly blocks all legitimate service from the LEO mega-constellation. Hijacked victims, believing the core network is congested, cease further registration attempts.
  3. Radio Channel/Geometry/Signaling Replication: The attacker continuously repeats its radio channel geometry and signaling replication techniques, effectively disguising itself as a legitimate, fast-changing serving satellite. This makes it exceptionally difficult for victim devices to detect the attack.

Validation and Scalability

The researchers rigorously validated SetOver. They collaborated with satellite operators and device vendors, testing the attack against real satellites and community devices. They further validated SetOver using 3GPP Non-Terrestrial Network (NTN) protocol stacks, which allowed them to emulate various types of satellite devices, including Commercial Off-The-Shelf (Cots) Radio Network Terminators (RNTs) and Internet of Things (IoT) NTN devices.

Emulations were conducted in diverse cities and countries to assess the scalability of SetOver. The findings indicated that if adopted by ground-based LTE or 5G operators with massive base stations, SetOver could enable ubiquitous blocking across vast geographical areas. This underscores the potential for a single, coordinated attacker to disrupt D2C services on a global scale.

Demo / Proof of Concept

▶ Watch: Three-step control plane attack against direct-to-cell networks. (8:00)

While the talk did not feature a live, on-stage demonstration or a traditional "proof of concept" in the sense of a real-time hack, the researchers extensively validated their SetOver attack and proposed defenses through rigorous emulation and collaboration with industry partners. They confirmed the attack's feasibility and impact by working with satellite operators and device vendors, testing the SetOver methodology against real satellites and community devices. Furthermore, the team conducted comprehensive emulations using 3GPP Non-Terrestrial Network protocol stacks, which accurately simulated various satellite devices, including Cots RNT and IoT NTN devices, in different cities and countries to assess the attack's scalability and effectiveness under diverse conditions. This thorough validation process served as the practical demonstration of SetOver's capabilities.

Defensive Implications

▶ Watch: Validating attack with operators and assessing scalability. (9:00)

Addressing the SetOver attack requires both short-term and long-term defensive strategies, each presenting its own set of challenges and trade-offs.

Short-Term Defense

For immediate mitigation, the researchers propose a straightforward short-term defense: disabling congestion control during the initial registration phase. In this modified scenario, if a victim device receives a congestion signal, it would detach from the perceived attacker and then attempt to switch to another available satellite. This approach is particularly effective during the initial access stage when there are fewer active users, reducing the likelihood of legitimate congestion. The researchers have partnered with satellite operators to implement and adopt this short-term solution. However, this defense has a significant limitation: it can suffer from legitimate congestion issues as the number of users grows, potentially impacting network performance.

Long-Term Defense Challenges

Developing robust long-term defenses against SetOver is considerably more complex, primarily due to the attacker's sophisticated obfuscation techniques. The ability of SetOver to mimic fast-changing real satellites in terms of radio channel geometry and signaling makes it inherently difficult for individual user equipment to detect the attack.

One proposed solution involves digitally signing all bootstrapping messages to authenticate satellites before registration. This would enable user equipment to detect fake satellites by verifying their digital signatures. However, this approach faces several practical hurdles:

  • Cots Device Incompatibility: Many existing Commercial Off-The-Shelf (Cots) devices are not readily equipped or capable of implementing such a solution.
  • Key Management Overhead: To verify digital signatures, victim devices would need to possess the public keys or certificates of all legitimate base stations and satellites. Pre-provisioning these for initial registration is not feasible, as acknowledged by prior research.
  • Prohibitive Overhead: The signature size itself can be substantial, potentially exceeding the maximum signal size permissible for IoT devices, leading to prohibitive communication overhead.
  • Hindrance to Critical Functions: Digital signatures could inadvertently hinder critical 5G functions such as international roaming and emergency calls, which are key applications for direct-to-cell satellite services.

Physical Layer Defense: Cooperative Detection

Given the difficulty for a single user equipment to detect the subtle differences between an attacker and a satellite at the physical layer, the researchers propose a novel defense leveraging user location diversity and cooperative counteraction. Instead of relying on individual devices, a distributed network of devices can cooperatively detect and counteract SetOver.

The proposed mechanism utilizes Multi-device Time Difference of Arrival (TDOA). Consider a scenario with two victim devices: one at the edge of the attacker's range and another closer to the attacker, with the attacker positioned at a known point relative to the satellite's trajectory. By comparing the time difference of arrival of signals from a real satellite at these two distinct locations with the TDOA from the attacker, a clear distinction can be made.

The key insight here is the significant difference in altitude. The altitude of a LEO satellite (H) is vastly greater than the typical range of an attacker (R). Consequently, the attacker's TDOA will be significantly larger and distinctly different from that of a real satellite. This allows victim devices, when collaborating, to utilize this disparity to distinguish between legitimate and spoofed signals, thereby enhancing cell selection and enabling escape from false satellites. This cooperative approach offers a promising long-term defense by leveraging the collective intelligence of the network.

Key Takeaways

  • The extreme scale and mobility of LEO mega-constellations, while often touted for security, can be a double-edged sword, creating new vulnerabilities.
  • The SetOver attack is a novel control plane cross-layer attack that exploits architectural bottlenecks and predictable satellite dynamics to disrupt direct-to-cell satellite services.
  • SetOver achieves attack amplification by spoofing congestion control signals from ground stations, allowing a single attacker to implicitly block an entire service area with significantly fewer resources (1% of attack nodes compared to jamming).
  • Attack obfuscation is achieved by mimicking satellite radio channel geometry and Doppler shift in the delay domain and spoofing System Information Blocks (SIBs), making the attacker indistinguishable from a real satellite.
  • Short-term defenses, such as disabling congestion control during initial registration, are feasible but have scalability limitations as user numbers grow.
  • Long-term defenses are challenging, with digital signing solutions facing issues with Cots devices, key management overhead, and potential hindrance to critical 5G functions.
  • Cooperative physical layer defenses, such as Multi-device Time Difference of Arrival (TDOA), show promise for detecting highly obfuscated SetOver attacks by leveraging user location diversity.

About the Speaker(s)

The talk, "The Dark Side of Scale: Insecurity of Direct-to-Cell Satellite Mega-Constellations," was presented by Wei Liu. The research itself was a collaborative effort, with Yuanjie Li, Hewu Li, Yimei Chen, Yufeng Wang, and Jingyi Lan listed as co-authors. As academics and researchers, their work contributes significantly to understanding and improving the security posture of emerging communication technologies, particularly in the rapidly evolving domain of satellite-based mobile networks. Their expertise lies in identifying complex vulnerabilities within large-scale, distributed systems and proposing innovative defensive mechanisms.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This research uncovers "SetOver," a novel control plane cross-layer attack that weaponizes the scale and mobility of D2C satellite mega-constellations to achieve widespread, stealthy service disruption. It critically re-evaluates prevailing security assumptions, demonstrating how a single attacker can implicitly block an entire service area with minimal resources.

Heather Calloway (CISO) — STRONG ACCEPT

This research credibly exposes a critical, under-appreciated governance risk in direct-to-cell satellite mega-constellations. The "SetOver" attack demonstrates how perceived strengths like scale and mobility can be weaponized for widespread, stealthy service disruption with minimal resources, demanding immediate re-evaluation of resilience and accountability for this emerging infrastructure. While immediate tactical solutions are complex, the strategic implications for operators and policymakers are profound.

→ Top-rated talks at IEEE Symposium on Security and Privacy 2024

All talks from IEEE Symposium on Security and Privacy 2024