Satellite Networks Under Siege: Cybersecurity Challenges of Targeted DDoS

Roee Idan (PhD student · Mangoran University)

DEF CON 33 · Day 1 · Main Stage

Overview

In an increasingly interconnected world, Low Earth Orbit (LEO) satellite networks like Starlink, OneWeb, and Kuiper are becoming indispensable. They bridge connectivity gaps in remote areas, provide critical backup for national infrastructure, and offer resilient communication during disasters and conflicts. However, this growing reliance also exposes them to significant cyber threats. Roee Idan, a PhD student at Mangoran University and part of the CBG Cyber Bengalon research lab, presented a groundbreaking framework at DEF CON designed to plan and optimize targeted Distributed Denial of Service (DDoS) attacks on these vital satellite networks.

Watch on YouTube

Visual summary for Satellite Networks Under Siege: Cybersecurity Challenges of Targeted DDoS by Roee Idan
Visual summary for Satellite Networks Under Siege: Cybersecurity Challenges of Targeted DDoS by Roee Idan

Key moments

  1. 0:00 Introduction to satellite network DDoS challenges
  2. 2:20 Real-world satellite network attack incidents
  3. 4:30 Understanding unique characteristics of LEO satellite networks
  4. 6:00 Concept of Link Flooding Attacks (LFA)
  5. 7:10 Why satellite networks are vulnerable to LFAs

Satellite Networks Under Siege: Cybersecurity Challenges of Targeted DDoS

Speakers: Roee Idan, PhD student, Mangoran University

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=xMfXqtcni_I

Overview

In an increasingly interconnected world, Low Earth Orbit (LEO) satellite networks like Starlink, OneWeb, and Kuiper are becoming indispensable. They bridge connectivity gaps in remote areas, provide critical backup for national infrastructure, and offer resilient communication during disasters and conflicts. However, this growing reliance also exposes them to significant cyber threats. Roee Idan, a PhD student at Mangoran University and part of the CBG Cyber Bengalon research lab, presented a groundbreaking framework at DEF CON designed to plan and optimize targeted Distributed Denial of Service (DDoS) attacks on these vital satellite networks.

Idan's talk, "Satellite Networks Under Siege: Cybersecurity Challenges of Targeted DDoS," delved into the unique vulnerabilities of LEO constellations. Unlike traditional DDoS attacks that rely on brute-force volumetric traffic, this research explores sophisticated, planned traffic injection aimed at congesting critical links within the satellite network itself. The core objective was to quantify the minimum botnet size required, identify optimal geographical locations for attack initiation, and understand how such an attack could scale and persist, causing widespread disruption with surprisingly modest resources.

This research is particularly timely and crucial given the escalating frequency of attacks against satellite infrastructure. By shedding light on the methodology and efficacy of these sophisticated link flooding attacks, the work provides an invaluable foundation for developing more robust detection and mitigation strategies. Understanding the attacker's capabilities, as demonstrated by Idan's framework, is the first step toward safeguarding the burgeoning global satellite ecosystem.

Background

▶ Watch: Introduction to satellite network DDoS challenges (0:00)

The landscape of global communication is rapidly evolving, with LEO satellite constellations playing an increasingly central role. These satellites orbit Earth at altitudes up to 2,000 kilometers, distinguishing them from geostationary satellites. They communicate with ground stations via Ground-Satellite Links (GSLs) and, crucially, with each other through Inter-Satellite Links (ISLs), typically employing laser-based optical or radio frequency communication. A defining characteristic of LEO satellites is their rapid movement; they complete an orbit every 90 minutes. This high velocity, combined with the sheer number of satellites in a constellation (often thousands), results in a constantly changing, highly dynamic network topology where links form, break, and paths are rerouted continuously.

Traditionally, Denial of Service (DoS) and DDoS attacks are classified into volumetric, protocol-based, or application-layer attacks, each exploiting different layers of the network stack. However, a more insidious variant is the Link Flooding Attack (LFA). Unlike attacks that target endpoints like servers, LFAs concentrate on overwhelming specific infrastructure links, causing congestion and disrupting communication for all users reliant on those paths. This makes them particularly challenging to detect, as many conventional defenses are endpoint-focused. LFAs are not new; research dating back over a decade, such as the Corelt study, demonstrated their feasibility by showing how traffic could be routed to congest specific links. Later, Crossfire expanded on this, illustrating how even "nominal" traffic, optimally planned, could achieve link congestion, appearing innocuous to standard network monitoring while causing significant disruption and delay in targeted areas.

Satellite networks, however, present unique vulnerabilities that amplify the threat of LFAs. Firstly, the movement and location of LEO satellites are highly predictable. Publicly available data, such as Two-Line Elements (TLEs), allows attackers to predict satellite positions with high accuracy (degradation of only 1-2 kilometers over several days of simulation). This predictability extends to understanding which satellites will be connected and how paths will be routed, especially given that ISL and GSL capacities and layouts are typically known. Secondly, satellite links have relatively limited capacity, ranging from a few tens to a few hundred gigabits per second, making them susceptible to congestion with less traffic compared to terrestrial fiber. Thirdly, satellite routing often prioritizes low-latency routes, which, while beneficial for performance, also makes the paths more predictable and therefore easier for an attacker to target. Finally, the global nature of satellite networks means a botnet can inject traffic from virtually any internet-connected location, offering a vast attack surface. Combining these factors creates an ideal environment for a stealthy, global LFA campaign.

Current satellite traffic often aims to reach ground stations quickly to relay data through terrestrial networks. However, this paradigm is shifting. Research indicates that direct communication solely through ISLs can reduce latency by more than two times compared to terrestrial networks, making it highly attractive for long-haul communications, areas with limited ground station coverage, and scenarios where latency and data sovereignty are paramount. This shift further elevates the importance and vulnerability of ISLs as primary targets.

Previous research has indeed explored aspects of LFA in satellite networks. Ecorus demonstrated the feasibility of injecting traffic to congest key satellite links, even with diverse routing protocols. Warts expanded on this by studying short-time attacks and leveraging orbital patterns to identify targets for widespread disruption. Further analysis has also focused on predicting network bottlenecks. However, critical questions remained unanswered: What is the actual botnet size required? How much traffic is needed? How can these attacks be sustained over long periods (hours, days)? And what happens when multiple geographical zones are targeted simultaneously? These open questions formed the impetus for Idan's research.

Key Findings

▶ Watch: Real-world satellite network attack incidents (2:20)

The research presented by Roee Idan unveiled several critical findings regarding the feasibility and impact of targeted DDoS attacks on LEO satellite networks:

  • Modest Botnet Requirements: Contrary to the expectation of massive botnets, the study demonstrated that targeted link flooding attacks can be executed with surprisingly small botnet sizes, often requiring only a few thousand bots to cause significant, widespread disruption. For a single snapshot attack on a Starlink-like constellation, approximately 1,000 bots were found to be sufficient, proving 50% more efficient than previous methods.
  • Persistent and Continuous Attacks: Attacks can be sustained over extended periods without a substantial increase in botnet size. Maintaining a continuous attack over a 90-minute orbital interval required only a 10-15% increase in botnet size compared to a single snapshot, equating to roughly 1,000 to 1,500 bots. The attack remained remarkably stable over 90 hours with only a 1-2% degradation in effectiveness, indicating its long-term viability.
  • Flexible and Global Impact: A "flexible" botnet, optimized to attack multiple zone pairs, showed remarkable versatility. With around 6,000 bots, it could persistently attack over 85% of thousands of globally generated, untargeted zone pairs, demonstrating a wide-reaching disruptive capability. The impact scaled logarithmically with optimization.
  • Identified Geographical Hotspots: The research generated heatmaps indicating critical geographical locations for attack injection. Hotspots around regions like New York and the China/India area were identified as prime locations for bots to exert maximum impact across multiple communication paths, providing valuable insights for both attackers and defenders.
  • Simultaneous Multi-Zone Attacks: The most aggressive attack scenario, targeting multiple zone pairs simultaneously, was also found to be feasible. A logarithmic growth in botnet size was observed, with approximately 10,000 bots capable of congesting around 30 different zone pairs concurrently, highlighting the potential for widespread, coordinated disruption.

These findings collectively underscore the significant and underappreciated threat that targeted link flooding poses to LEO satellite infrastructure, emphasizing that sophisticated attacks do not necessitate overwhelming resources but rather intelligent planning and exploitation of network dynamics.

Technical Deep Dive

▶ Watch: Understanding unique characteristics of LEO satellite networks (4:30)

The core of Idan's research is the Hydra framework, a sophisticated system designed to plan and optimize targeted DDoS attacks on LEO satellite networks. This framework moves beyond brute-force methods, focusing instead on strategic congestion of critical links.

The problem is fundamentally modeled as an optimization problem. The objective is to minimize the size of the botnet required while ensuring that all targeted communication zones remain congested. This is achieved by modeling the satellite network as a graph over time. The time continuum is broken down into discrete snapshots, each representing the network's state at a specific moment. In this dynamic graph, nodes represent either users on the ground or the satellites themselves. Links represent the GSLs (Ground-Satellite Links) and ISLs (Inter-Satellite Links). Due to the constant movement of LEO satellites, the network topology is continuously changing, meaning each snapshot presents a different graph with varying connectivity and routing paths.

The attacker's capabilities are assumed to be relatively straightforward yet powerful:

  1. Global Botnet: The attacker has access to a botnet that can inject traffic into the satellite network from various geographical locations worldwide. The research's goal is to quantify the size of this botnet.
  2. Traffic Coordination: The attacker can coordinate the timing and destination of traffic sent from the botnet.
  3. Publicly Available Data: The attacker leverages publicly available TLEs (Two-Line Elements) of satellites to accurately predict their orbital paths and, consequently, their connectivity at any given time.

A link is considered congested when the total traffic flowing through it exceeds its predefined capacity. A communication path between two geographical zones is deemed congested if at least one link along that path is congested. With these definitions, the optimization problem seeks to find the smallest botnet configuration (number of bots and their locations) that can ensure all desired paths between targeted zones are congested over a specified period.

The Hydra framework explores four distinct attack strategies:

  1. Single Snapshot Attack:

This foundational strategy aims to understand the minimal botnet size required for an instantaneous disruption at a specific moment in time. For a case study focusing on the first shell of the Starlink constellation, the analysis revealed that approximately 1,000 bots were sufficient to create targeted congestion and disrupt communication between zones. This finding was significant as it indicated a 50% improvement in efficiency compared to previous methods, establishing a baseline that targeted attacks require only a "few thousand bots" – a relatively small number for a global botnet.

  1. Continuous Attack:

Recognizing that real-world attacks need persistence, this strategy extends the optimization problem across multiple snapshots simultaneously. The goal is to identify a botnet that can continuously congest links as the network topology changes over time. By optimizing for a 90-minute interval (a single satellite orbit) broken into 30-second snapshots, the research found that sustaining the attack required only a modest increase of 10-15% in botnet size compared to the single snapshot scenario, bringing the total to approximately 1,000 to 1,500 bots. Furthermore, testing the attack over an extended period of 90 hours (without re-optimization) showed remarkable stability, with only a 1-2% drop in effectiveness, demonstrating the long-term viability of such an attack.

  1. Flexible Botnet:

This strategy investigates the creation of a versatile botnet capable of attacking virtually any zone pair globally. The optimization focused on identifying bots in geographical locations that would have the highest impact across a multitude of potential targets. The results indicated a logarithmic growth in the amount of traffic needed to achieve this flexibility. Impressively, a botnet of around 6,000 bots, optimized for 48 different zone pairs, was able to persistently attack over 85% of thousands of untrained and unoptimized zone pairs globally. This analysis also yielded heatmaps identifying geographical hotspots for botnet deployment, with areas around New York and the China/India region showing the highest probability of impact.

  1. Simultaneous Multi-Zone Attack:

Representing the most aggressive scenario, this strategy aims to congest as many communication paths between multiple zone pairs as possible concurrently. The approach involved identifying critical links that, when congested, would disrupt several communication zones. Similar to the flexible botnet, a logarithmic growth was observed in the required botnet size relative to the number of zone pairs attacked. For instance, approximately 10,000 bots were sufficient to congest around 30 different zone pairs simultaneously. This strategy highlighted the potential for an attacker to cause widespread, debilitating disruption across a significant portion of the satellite network's global connectivity with a relatively contained botnet.

In summary, the Hydra framework systematically demonstrates how an understanding of satellite dynamics, coupled with strategic traffic injection, allows for highly effective and persistent DDoS attacks with surprisingly limited resources, moving the threat from theoretical to a quantifiable and imminent reality.

Demo / Proof of Concept

▶ Watch: Concept of Link Flooding Attacks (LFA) (6:00)

Due to technical difficulties encountered at the beginning of the presentation, a live demonstration or visual display of graphs and results was not possible during the talk. However, the speaker explicitly stated that the research is based on extensive simulations and a designed framework. The findings presented, including botnet sizes, efficiency percentages, and attack persistence rates, are direct results of these computational models and analyses. The speaker offered to share the detailed notes and graphs with interested attendees after the presentation, indicating the existence of comprehensive simulated proof-of-concept data that underpins the research conclusions.

Defensive Implications

▶ Watch: Why satellite networks are vulnerable to LFAs (7:10)

The findings from the Hydra framework underscore the urgent need for advanced defensive strategies against sophisticated link flooding attacks on LEO satellite networks. Traditional DDoS mitigation, often focused on volumetric attacks at endpoints, is insufficient for these stealthy, targeted disruptions. Roee Idan's research explored preliminary mitigation methods, highlighting both their potential and inherent trade-offs.

One approach investigated was adaptive routing. In this scenario, network paths are dynamically changed in response to real-time network conditions, including congestion levels. The simulations showed that adaptive routing could indeed decrease the success rate of an attack. By constantly rerouting traffic away from congested links, the network attempts to bypass the attacker's choke points. However, the research also revealed that a persistent attacker, using even a slightly larger botnet, could still execute the attack by anticipating and congesting these fallback options. This defense mechanism also comes with a cost: it can introduce longer latency and a higher number of hops between satellites, potentially degrading the user experience or critical application performance. This suggests that while adaptive routing can increase the attacker's effort and cost, it may not be a complete solution on its own.

Another mitigation strategy explored was link targeted link throttling. This method involves actively limiting the amount of user traffic that can utilize congested links. The study evaluated different levels of bandwidth limiting. In an extreme scenario where user traffic on congested links was throttled down to just 1 megabit per second, the defense was remarkably effective, mitigating over 80% of the attacks. While highly effective, such an aggressive throttling policy is generally not feasible for operational networks, as it severely impacts legitimate user communication. However, this finding is crucial: it demonstrates that targeted link capacity management, even if not implemented at such extreme levels, can significantly disrupt LFA effectiveness.

The implications for defenders are clear:

  • Enhanced Detection: There is a critical need for advanced detection mechanisms that can identify sophisticated, low-volume, targeted traffic patterns indicative of LFAs, rather than solely relying on volumetric thresholds. This might involve deep packet inspection, behavioral analytics, and real-time topology awareness.
  • Proactive Bottleneck Identification: Leveraging the predictability of satellite orbits, defenders should proactively identify potential critical links and bottlenecks that are most susceptible to congestion, similar to how attackers identify hotspots.
  • Hybrid Mitigation Strategies: A combination of defenses will likely be necessary. This could involve intelligently combining adaptive routing with dynamic, policy-based link throttling that can be selectively applied to suspected malicious traffic or temporarily to specific links during an attack, minimizing impact on legitimate users.
  • Increased Resilience through Redundancy: Designing satellite networks with greater link redundancy and diverse routing options can make it harder for attackers to congest all possible paths simultaneously.
  • Threat Intelligence Sharing: Real-time sharing of threat intelligence regarding identified attack patterns and compromised botnet locations can aid in pre-emptive defense and rapid response.

Ultimately, the research emphasizes that satellite networks, as critical infrastructure, require a paradigm shift in cybersecurity thinking. Defenses must evolve beyond terrestrial models to account for the unique dynamics, predictability, and limited capacities inherent in LEO constellations. The cost of such attacks is low for the attacker, making the need for robust, intelligent defenses paramount.

Key Takeaways

  • LEO satellite networks are highly vulnerable to targeted Distributed Denial of Service (DDoS) attacks, specifically Link Flooding Attacks (LFAs), due to their dynamic topology, limited link capacities, and predictable orbital patterns.
  • The Hydra framework demonstrates that these attacks can be executed with surprisingly small botnet sizes (e.g., ~1,000 bots for single snapshot, ~1,000-1,500 for continuous, ~6,000 for flexible global impact), making them accessible to a broader range of malicious actors.
  • Attacks can be persistent and continuous over long durations with minimal additional resources, and a single flexible botnet can effectively disrupt communication across a vast number of global zone pairs.
  • The research identified geographical hotspots (e.g., New York, China/India regions) where botnet injection points can achieve maximum disruptive impact across multiple communication paths, providing critical intelligence for defensive planning.
  • Preliminary defensive strategies like adaptive routing and link targeted link throttling show promise in mitigating these attacks, but often come with trade-offs (e.g., increased latency) or require careful implementation to avoid impacting legitimate traffic.
  • As global reliance on satellite networks grows, there is an urgent need for advanced, intelligent detection and hybrid mitigation strategies that move beyond traditional volumetric DDoS defenses to counter sophisticated, low-resource link flooding campaigns.

About the Speaker(s)

Roee Idan is a PhD student at Mangoran University, where he is actively involved with the CBG Cyber Bengalon research lab. This presentation at DEF CON marked his inaugural appearance and presentation at the prestigious security conference, reflecting his emerging expertise in the field of satellite network cybersecurity. His research focuses on understanding and optimizing targeted denial-of-service attacks against critical infrastructure like LEO satellite constellations.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Legitimate academic research on a genuinely important target — LEO constellation link flooding is underexplored and the timing is right given Starlink's role in active conflicts. The Hydra framework is a real contribution: quantifying botnet minimums, modeling topology across time snapshots, and generating geographic hotspot heatmaps is solid work. But it reads like a polished dissertation chapter, not a DEF CON talk, and the demo died on stage.

Heather Calloway (CISO) — WEAK

Technically interesting attack modeling on LEO satellite infrastructure, but the research stops where the real work begins. The defensive section is thin, the demo failed, and a PhD student presenting an attack optimization framework at DEF CON without a clear path to operator or policy action leaves security leaders with a problem statement, not a decision.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33