Time-varying Bottleneck Links in LEO Satellite Networks: Identification, Exploits, and Countermeasures
Yangtao Deng (Chinua University)
Network and Distributed System Security (NDSS) Symposium 2025 · Day 1 · Wireless, Cellular & Satellite Security · Wireless, Cellular & Satellite Security
Overview
This talk, presented by Yangtao Deng from Chinua University on behalf of his colleagues, delves into the critical and under-explored area of security vulnerabilities within Low Earth Orbit (LEO) satellite networks. Specifically, the research identifies and analyzes time-varying bottleneck links—ground-satellite links (GSLs) that disproportionately carry traffic and are subject to dynamic changes. The presentation introduces Skyfall, a novel risk analyzer designed to assess the impact of link flooding attacks (LFAs) orchestrated by compromised user terminals (UTs) targeting these identified bottlenecks.
Key moments
- 0:00 Introduction to LEO networks and AFA challenges
- 2:09 Three key metrics for identifying bottleneck links
- 4:00 Case study: identifying dynamic, time-varying bottleneck links
- 5:05 Introducing Skyfall, the AFA risk analyzer
- 6:00 Skyfall's two-stage methodology: data and risk analysis
- 7:00 Simulation setup for evaluating Skyfall and bottleneck impacts
- 8:00 Bottleneck validation: small congestion, large traffic impact
- 9:00 Skyfall's superior impact by targeting bottleneck links
Time-varying Bottleneck Links in LEO Satellite Networks: Identification, Exploits, and Countermeasures
Speakers: Yangtao Deng (Chinua University)
Conference: NDSS Symposium
YouTube: https://www.youtube.com/watch?v=sdHrFkCnebk
Overview
This talk, presented by Yangtao Deng from Chinua University on behalf of his colleagues, delves into the critical and under-explored area of security vulnerabilities within Low Earth Orbit (LEO) satellite networks. Specifically, the research identifies and analyzes time-varying bottleneck links—ground-satellite links (GSLs) that disproportionately carry traffic and are subject to dynamic changes. The presentation introduces Skyfall, a novel risk analyzer designed to assess the impact of link flooding attacks (LFAs) orchestrated by compromised user terminals (UTs) targeting these identified bottlenecks.
The work is significant because LEO satellite constellations, such as Starlink and Kuiper, are rapidly expanding to provide global internet services, making their security paramount. While previous research has explored LFAs, it has often overlooked the dynamic, time-varying nature of modern LEO topologies and lacked robust methods to quantify the risk to specific GSLs. This research fills that gap by providing a systematic approach to identify these crucial, transient bottlenecks and demonstrate how their exploitation can lead to substantial service disruption, offering vital insights for network defenders.
Background
▶ Watch: Introduction to LEO networks and AFA challenges (0:00)
The proliferation of LEO satellite networks marks a new era in global connectivity, promising high-speed and high-throughput internet access even in remote regions. Companies like Starlink, with over 700 satellites and more than 100 ground stations, are at the forefront of this development. These networks are characterized by their high-speed ground-satellite links (GSLs) and inter-satellite links (ISLs), which together form a complex, distributed infrastructure.
However, LEO networks possess unique characteristics that introduce novel security challenges. Firstly, there is a significant spatial disparity in ground station (GS) and user terminal (UT) connectivity, with these facilities dispersed unevenly across the globe. Secondly, and perhaps more critically from a security perspective, LEO networks exhibit remarkable temporal dynamism. The connection between a satellite and a ground station, a GSL, typically lasts only a few minutes due to the satellites' rapid movement and the necessity for frequent handovers. This constant change makes traditional, static network analysis inadequate for identifying persistent vulnerabilities.
Security threats continue to evolve in this landscape. Real-world Denial-of-Service (DoS) attacks on satellites and fault injections on user terminals have already been observed. Prior academic research has investigated link flooding attacks (LFAs) targeting both ISLs and GSLs. However, these studies often relied on simplified or outdated LEO network structures. Crucially, there has been a notable absence of an LFA analyzer that effectively adapts to the latest, highly dynamic LEO topologies. Furthermore, previous methods have not adequately quantified the risk posed by LFAs specifically towards negotiated GSLs, which are the direct conduits for user traffic to and from the satellite constellation. This gap highlights the need for a sophisticated risk assessment tool that accounts for the unique temporal and spatial dynamics of modern LEO networks.
Key Findings
▶ Watch: Case study: identifying dynamic, time-varying bottleneck links (4:00)
The research makes several critical findings regarding the nature and exploitability of LEO satellite networks:
- Existence of Time-Varying Bottleneck Links: The most fundamental finding is the confirmation that "bottleneck links" indeed exist within LEO satellite networks. These are specific GSLs that transmit a disproportionately large amount of traffic, often originating from multiple regions. Crucially, these bottlenecks are not static; their identity and significance vary over time due to the dynamic nature of LEO constellations, satellite movement, and frequent handovers.
- Identifiable Characteristics of Bottlenecks: The study identifies three key characteristics that can be used to pinpoint these critical GSLs:
- Uneven Ground Station Service Time: Ground stations in mid-to-high latitude regions tend to have longer accumulated service times throughout the day. This prolonged connectivity makes them more susceptible to sustained flooding attacks.
- Ground Station Occurrence: A higher "occurrence" metric for a ground station indicates that it transfers data traffic from a greater number of regions. Such ground stations are more likely to serve as central hubs and thus represent more attractive targets for attackers. This occurrence also fluctuates temporally.
- GSL Throughput (GSLut): The actual throughput of individual GSLs exhibits significant temporal fluctuation, often changing within tens of seconds. Links operating near their capacity are inherently more vulnerable to congestion.
- Disproportionate Impact of Targeted Attacks: The research demonstrates that targeting a small percentage of these identified bottleneck links can lead to a significantly larger disruption of legal traffic. Simulations showed that by congesting merely 8% of the global GSLs identified as bottlenecks, over 41% of the legal traffic originating from 19% of the network blocks could be severely impacted. This translates to an attack "payoff" as high as twice that of randomly targeting GSLs.
- Effectiveness of Strategic UT Placement: The study reveals that the placement of compromised user terminals plays a critical role in the success and impact of a link flooding attack. When compromised UTs are strategically positioned near identified bottleneck links, they can achieve a much higher rate of legal traffic congestion compared to scenarios where UTs are distributed proportionally to overall traffic patterns. Specifically, Skyfall's approach (UTs near bottlenecks) achieved 37% legal traffic congestion by targeting 8% of GSLs, whereas a proportional distribution (Acaris) only achieved 11% congestion for the same number of targeted GSLs.
These findings collectively underscore the vulnerability of LEO networks to sophisticated, targeted attacks that leverage their dynamic topology. They highlight the need for a proactive and adaptive security posture rather than relying on static defense mechanisms.
Technical Deep Dive
▶ Watch: Skyfall's two-stage methodology: data and risk analysis (6:00)
The core of this research lies in its methodology for identifying time-varying bottleneck links and the design of Skyfall, an LFA risk analyzer. The approach is structured to account for the unique dynamism of LEO networks.
Bottleneck Link Identification Methodology
The identification process for bottleneck links is iterative and time-slot dependent, reflecting the temporal variability of LEO constellations. The method proceeds as follows:
- Time Slot Partitioning: The entire operational period (e.g., a day) is divided into discrete time slots. The presentation uses an example interval of 120 seconds to illustrate the dynamic changes.
- Ground Station Prioritization (Per Time Slot): For each individual time slot, ground stations (GSs) are prioritized based on two key metrics:
- Ground Station Service Time: This refers to the total accumulated time that a particular GS is connectable to satellites throughout the day. GSs with longer service times are considered more vital as they sustain connectivity for extended durations.
- Ground Station Occurrence: This metric quantifies how many distinct regions a GS serves or how many different traffic flows pass through it. A higher occurrence indicates a more central role in routing traffic.
- The top-ranked GSs in both these metrics are identified as potentially vital for that specific time slot.
- GSL Prioritization and Bottleneck Identification: Once vital GSs are identified for a time slot, their connected ground-satellite links (GSLs) are further prioritized based on their link throughput (GSLut).
- The methodology specifically identifies GSLs whose current throughput utilization exceeds half of their total capacity. These links are operating under significant load and are thus more susceptible to congestion.
- These identified GSLs, connected to vital GSs and operating under high load, are provisionally categorized as bottleneck candidates for that time slot.
- Defining Time-Varying Bottleneck Links: The final set of "bottleneck links" is defined as the union of all such identified links across multiple consecutive time slots over a defined period. This union captures the entire set of links that, at some point, act as bottlenecks, acknowledging their transient nature.
A case study presented visually demonstrated this dynamism. Comparing two time slots, T1 and T2, separated by 120 seconds, the research showed distinct sets of vital GSs and bottleneck GSLs. For instance, at T1, 44 links were identified as bottlenecks, while at T2, 42 links were identified. Crucially, only 34 of these links remained connected and identified as bottlenecks across the 120-second interval, confirming the highly dynamic and time-varying nature of these critical network components. This dynamic behavior necessitates an adaptive approach to both identification and defense.
Skyfall: An AFA Risk Analyzer
Skyfall is designed as a two-stage risk analyzer to assess the impact of link flooding attacks on these identified bottleneck links.
Stage 1: Data Gathering
The initial stage focuses on collecting essential information about the target LEO network:
- Topology and Routing Information: Skyfall leverages publicly available data to acquire details about the network's topology (satellite positions, ground station locations, inter-satellite links, ground-satellite links) and its routing protocols. This foundational data allows Skyfall to model the network's structure and how traffic flows within it.
- Throughput Estimation: To understand the baseline legal traffic on GSLs, Skyfall employs a practical estimation method. It simulates the use of compromised user terminals (UTs) to transmit UDP packets towards a target GSL. This transmission continues until the link becomes congested, allowing Skyfall to estimate the current legal traffic throughput of that specific GSL. This provides a real-time (or near-real-time in simulation) understanding of link utilization, which is crucial for identifying links operating near capacity.
Stage 2: Analysis
With the necessary data gathered, Skyfall proceeds to analyze potential attack scenarios:
- Bottleneck Link Identification: Using the methodology described above, Skyfall first identifies the set of time-varying bottleneck links within the current network state.
- Malicious Traffic Generation and Route Inference: Skyfall then simulates the generation of malicious traffic from a set of compromised user terminals. It infers the likely routes this malicious traffic would take through the LEO network. For example, traffic from a UT connected to a satellite typically flows to the nearest ground station via a downlink GSL.
- Impact Assessment: Based on the simulated malicious traffic and its inferred routes, Skyfall determines which GSLs would experience congestion and quantifies the overall influence of this congestion on legal traffic. The worst-case scenarios are specifically analyzed, such as when compromised UTs are strategically positioned in close proximity to the identified bottleneck links, maximizing the attack's severity.
- Factor Analysis: Skyfall also analyzes various factors that could affect the risk analysis results, including the total number of compromised UTs available to the attacker and their geographical positions. This allows for a comprehensive understanding of how different attack parameters influence the outcome.
Evaluation and Simulation
To validate Skyfall's effectiveness, the researchers conducted extensive simulations:
- Network Models: The evaluation considered two prominent LEO constellations: Starlink and Kuiper. This allowed for testing against different network architectures and operational parameters.
- Network Topologies: The experiments utilized two kinds of network topologies: the gray topology, which has been widely studied in previous works, and a circular topology, likely representing a different routing or satellite arrangement.
- User Traffic Generation: To ensure realism, user traffic was modeled and generated based on real-world Starlink traffic distributions obtained from Cloudflare data spanning over 50 countries. This provided a robust and representative dataset for evaluating attack impacts.
- Metrics: The primary evaluation metrics included the accuracy of bottleneck link identification and the quantifiable risky impacts on legal traffic and GSLs under simulated attack conditions.
The technical depth of Skyfall's design, from its dynamic bottleneck identification to its data-driven simulation and impact assessment, provides a powerful tool for understanding and mitigating LFA risks in the complex and evolving LEO satellite network landscape.
Demo / Proof of Concept
▶ Watch: Simulation setup for evaluating Skyfall and bottleneck impacts (7:00)
While the presentation did not include a live demonstration in the traditional sense, the researchers provided compelling simulation-based proof-of-concept results that validate their methodology and the effectiveness of the Skyfall analyzer. These simulations serve as the practical demonstration of the identified vulnerabilities and the potential impact of link flooding attacks.
Bottleneck Link Validation Results
The first set of results focused on validating that the identified bottleneck links indeed yield a disproportionately high impact when congested.
- Comparison: Skyfall's approach (targeting identified bottlenecks) was compared against a baseline scenario where the same number of GSLs were congested randomly.
- Key Finding: By strategically congesting merely 8% of the global GSLs identified by Skyfall as bottlenecks, over 41% of the legal traffic originating from 19% of the network blocks experienced congestion.
- Payoff Ratio: When the ratio of congested traffic to congested GSLs was calculated, Skyfall's targeted approach yielded a "payoff" that was twice as high as random targeting.
- Conclusion: These results unequivocally demonstrate that the bottleneck links identified by Skyfall are critical points of failure. They are not only more substantial adverse impact points but also significantly more effective choices for potential attackers seeking to maximize disruption with minimal resources.
Impact Evaluation with Compromised User Terminals
The second set of results evaluated the impact of link flooding attacks when leveraging compromised user terminals (UTs), comparing Skyfall's strategic placement with a more generalized distribution.
- Comparison Scenarios:
- Skyfall Scheme: Compromised UTs were strategically placed near the identified bottleneck links.
- Acaris Scheme: Compromised UTs were distributed proportionally to the overall traffic distribution of Starlink, representing a less targeted, more generalized attack.
- Key Finding: Under the Skyfall scheme, by targeting only 8% of the GSLs, the legal traffic was successfully congested by an average of 37%. In stark contrast, the Acaris scheme, with the same number of targeted GSLs, only achieved 11% legal traffic congestion.
- Throughput Reduction: The throughput change of legal traffic clearly showed a more significant reduction under the Skyfall scheme. This indicates that even a small number of strategically congested GSLs can lead to a substantial and long-term reduction in throughput for legitimate users.
- Conclusion: This evaluation highlights the critical importance of attacker strategy, specifically the placement of compromised resources. By positioning UTs near the dynamic bottleneck links, attackers can achieve a far greater impact with the same or even fewer resources, making the Skyfall identification methodology a crucial component for both attack simulation and defensive planning.
These simulation results provide a strong proof of concept, illustrating the real-world implications of the identified vulnerabilities and the efficacy of Skyfall as an analytical tool. They serve as a clear demonstration of how a sophisticated attacker could exploit the time-varying nature of LEO networks to cause widespread disruption.
Defensive Implications
▶ Watch: Skyfall's superior impact by targeting bottleneck links (9:00)
The research by Yangtao Deng and his colleagues highlights significant vulnerabilities in LEO satellite networks, necessitating robust defensive strategies. The dynamic and time-varying nature of bottleneck links means that static, traditional security measures may be insufficient. The talk explored two potential countermeasures, acknowledging their inherent complexities.
- Customized Traffic Rerouting:
- Mechanism: This approach proposes that a ground controller continuously monitors real-time GSL traffic. If a GSL experiences excessive traffic or congestion, the controller would signal the connected satellite to redirect the extra traffic. This redirection would involve rerouting the overflow traffic from the congested GSL to the closest available satellite for relay, effectively load-balancing the network dynamically.
- Challenges: The primary obstacle lies in the significant computational expenses required for real-time recalculation of LEO network topologies. Given the rapid movement of satellites and frequent handovers, the network topology is constantly changing. By the time a complex rerouting calculation is completed and applied, the optimal path or even the network's state may have already changed, rendering the recalculation obsolete or suboptimal. This "race condition" between calculation and network dynamism makes real-time, global rerouting extremely difficult to implement efficiently and effectively.
- ECMP (Equal-Cost Multi-Path) for Traffic Partitioning:
- Mechanism: ECMP is a routing strategy that allows for distributing traffic across multiple paths of equal cost. In the context of LEO networks, this would involve partitioning traffic equally over multiple Inter-Satellite Link (ISL) paths. The goal is to avoid concentrating traffic on a single path, thereby reducing the likelihood of creating a single point of failure or an easily congestible bottleneck.
- Challenges: While conceptually sound, implementing ECMP in a highly dynamic LEO environment presents difficulties. It is challenging to select and maintain appropriate multiple paths for each runtime data stream, especially when satellite links are constantly being established and torn down. The "cost" of paths in a LEO network is not static and can fluctuate based on latency, link quality, and current load, making true "equal-cost" path selection a complex optimization problem that needs to adapt in real-time. The feasibility of this countermeasure in a practical, large-scale LEO deployment still requires considerable contemplation and research.
During the Q&A session, Yangtao Deng revealed that the research team had engaged with LEO operators, including national operators. He noted that existing mitigations primarily involve basic security measures such as firewalls that implement blacklisting or whitelisting of traffic from certain ports and IP addresses. While these are fundamental security practices, they are largely static and reactive. They are unlikely to be effective against sophisticated, dynamic link flooding attacks that leverage the time-varying nature of LEO bottlenecks, as identified by Skyfall.
The implications are clear: current defensive postures, though necessary, are insufficient to address the advanced threats identified. Future LEO network security must move towards more adaptive, real-time, and computationally intensive solutions that can dynamically respond to the rapidly changing network topology and traffic patterns. This research serves as a critical call to action for LEO operators to invest in and develop more sophisticated, proactive countermeasures.
Key Takeaways
- LEO satellite networks possess dynamic, time-varying bottleneck links that are critical for global internet services and susceptible to targeted attacks.
- These bottlenecks can be systematically identified by analyzing ground station service time, ground station occurrence, and GSL throughput (GSLut), which fluctuate significantly over short time intervals.
- The Skyfall analyzer effectively quantifies the risk of link flooding attacks (LFAs) by identifying these dynamic bottlenecks and simulating the impact of compromised user terminals.
- Targeting a small fraction of these identified bottleneck GSLs (e.g., 8%) can lead to a disproportionately large impact, congesting over 41% of legal traffic, making such attacks highly efficient.
- The strategic placement of compromised user terminals near identified bottlenecks is crucial for maximizing attack impact, yielding significantly higher congestion rates (e.g., 37% vs. 11% for random placement).
- Current operator mitigations, primarily static firewalls, are likely insufficient against these dynamic, sophisticated LFA threats, highlighting the need for advanced, adaptive defensive mechanisms like real-time traffic rerouting or dynamic ECMP, despite their inherent computational challenges.
About the Speaker(s)
The talk was presented by Yangtao Deng from Chinua University. He delivered the presentation on behalf of the paper's authors, who are all affiliated with Chinua University. Yangtao Deng explicitly mentioned that he is not an expert in this particular research area and was presenting the work using notes. This indicates that he was likely a representative or a junior researcher supporting the primary authors, effectively communicating complex technical details to the conference audience.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Legitimate systems-security research on a genuinely underexplored attack surface — LEO bottleneck exploitation via time-varying topology analysis is a real problem and Skyfall is a credible contribution. The numbers are concrete, the threat model is grounded in real infrastructure, and the gap they're filling (dynamic LFA risk quantification vs. static prior work) is well-defined. What keeps this at three stars is that the work is solid but not surprising: it's essentially a careful measurement-plus-simulation paper that confirms intuitions about spatial/temporal unevenness in LEO routing, rather than delivering an unexpected capability or a result that forces defenders to rethink their…
Heather Calloway (CISO) — PASS
Technically credible academic work on LEO satellite network vulnerability to link flooding attacks, but squarely outside the governance and operational security lane. The research is narrow, simulation-based, and addresses a threat surface that no enterprise CISO controls or defends.
→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025
All talks from Network and Distributed System Security (NDSS) Symposium 2025