Attack Surface Analysis On Satellites

Sheng-Hao Ma

S4x24 - ICS Security Conference · Day 3 · Main Stage

Overview

Sheng-Hao Ma's presentation, "Attack Surface Analysis On Satellites," at the S4 conference delves into the often-overlooked and increasingly critical security landscape of satellite communication networks. The talk challenges a long-held but now outdated belief that satellite systems are inherently secure due to the perceived complexity and high cost of intercepting their signals. As industries, private companies, and even consumer devices like the iPhone 14 increasingly integrate satellite connectivity for vital services—from remote factories and high-speed railways to emergency SOS features—the security posture of these systems has become a pressing concern.

Watch on YouTube

Visual summary for Attack Surface Analysis On Satellites by Sheng-Hao Ma
Visual summary for Attack Surface Analysis On Satellites by Sheng-Hao Ma

Key moments

  1. 0:00 Introduction: Why satellite networks are critical for private sectors
  2. 2:05 Debunking the 'secure' theory: Equipment now accessible to decode signals
  3. 3:17 Widespread insecure practices: Plain text data over satellite networks
  4. 4:25 Overview of satellite attack surface: Space, ground, and user terminals
  5. 5:50 Supply chain vulnerabilities due to cost reduction in manufacturing
  6. 6:54 Real-world Viasat attack during Russian invasion of Ukraine
  7. 8:09 Unique threat: Active noise cancellation attack on Starlink terminals

Attack Surface Analysis On Satellites

Speakers: Sheng-Hao Ma

Conference: S4

YouTube: https://www.youtube.com/watch?v=60afYHmt9Ys

Overview

Sheng-Hao Ma's presentation, "Attack Surface Analysis On Satellites," at the S4 conference delves into the often-overlooked and increasingly critical security landscape of satellite communication networks. The talk challenges a long-held but now outdated belief that satellite systems are inherently secure due to the perceived complexity and high cost of intercepting their signals. As industries, private companies, and even consumer devices like the iPhone 14 increasingly integrate satellite connectivity for vital services—from remote factories and high-speed railways to emergency SOS features—the security posture of these systems has become a pressing concern.

Ma highlights that despite the growing reliance on satellite networks for critical infrastructure and everyday operations, many implementations still operate with fundamental security flaws, primarily the widespread use of unencrypted plaintext communication. This vulnerability, coupled with supply chain weaknesses and novel attack vectors, exposes sensitive data and operational control to malicious actors, including sophisticated APT groups. The presentation serves as a stark warning, urging organizations to re-evaluate their satellite network security strategies and adopt proactive defense mechanisms against these evolving threats.

The talk systematically dissects the satellite attack surface, categorizing potential vulnerabilities across the space segment, ground stations, and user terminals. Through compelling examples of real-world attacks, including the Viasat hack during the Russian invasion of Ukraine and the Turla APT group's exploitation of satellite communications, Ma illustrates the tangible risks. He not only exposes the vulnerabilities but also introduces a unique denial-of-service technique, Active Noise Cancellation, showcasing the breadth of potential attacks that defenders must now contend with in the burgeoning satellite ecosystem.

Background

▶ Watch: Introduction: Why satellite networks are critical for private sectors (0:00)

For decades, a prevailing theory, even among government entities like the US and Canadian Departments of Defense, suggested that satellite networks were inherently secure. The rationale was twofold: the complexity of satellite signal waves in the air made decoding them seem insurmountable, and the equipment required for such interception was prohibitively expensive, placing it beyond the reach of all but nation-states. This perception fostered a false sense of security, leading to the widespread deployment of satellite solutions without adequate consideration for modern cyber threats.

However, the landscape has dramatically shifted. Over the past decade, the rapid advancements in technology and the commercialization of space have democratized access to satellite communication. The proliferation of satellite networks into everyday life, exemplified by features like the iPhone 14's SOS message over satellite network, has made signal decoding equipment more accessible and affordable than ever before. This accessibility directly undermines the "expensive equipment" premise that once bolstered the security theory.

Compounding this issue, research from Oxford University in 2021 highlighted a critical vulnerability: a significant portion of satellite network traffic still operates without encryption. The primary reason cited is the perceived slow speed of satellite networks, leading many users and industries to prioritize throughput over security by transmitting data in plaintext mode. This includes sensitive operations like receiving POP3 email, downloading files via FTP with username and password credentials, and even logging into remote Windows desktops using the RDP protocol, all without encryption. This means that if an attacker possesses the now-accessible equipment to decode on-air satellite signals, they can easily sniff and intercept critical data, including authentication credentials, from across vast geographical regions.

The talk categorizes the comprehensive satellite attack surface into three distinct components: the space segment (the satellites themselves), the ground station (operated by network providers), and the user terminal (the victim's equipment). Understanding these interconnected parts is crucial for identifying and mitigating the diverse range of threats facing modern satellite communication.

Key Findings

▶ Watch: Widespread insecure practices: Plain text data over satellite networks (3:17)

Sheng-Hao Ma's presentation unveils several critical findings that collectively paint a concerning picture of the current state of satellite network security:

  1. Debunking the "Secure by Complexity" Myth: The long-held belief that satellite communications are secure due to the complexity of signal decoding and the high cost of interception equipment is fundamentally outdated. Technological advancements and commercialization have made the necessary equipment far more accessible to a broader range of actors, including malicious ones.
  1. Widespread Unencrypted Plaintext Communication: A significant and alarming finding is the prevalence of unencrypted plaintext traffic over satellite networks. Due to perceived speed limitations, many industrial and private sector users are transmitting sensitive data—including POP3 emails, FTP credentials, and RDP logins—without any form of encryption, making it trivial for interceptors to capture and utilize this information.
  1. Supply Chain Vulnerabilities Enabling APT Attacks: The rapid expansion of satellite network adoption has led manufacturers to prioritize cost reduction in production. This often involves sourcing cheaper components, potentially from regions with less stringent security oversight. These cost-saving measures introduce software vulnerabilities through the supply chain, which nation-state APT groups can exploit to gain control over critical infrastructure, as demonstrated by the Viasat attack.
  1. Novel Denial-of-Service via Active Noise Cancellation (ANC): The talk introduces a unique and sophisticated attack vector: Active Noise Cancellation. Similar to the technology in noise-canceling headphones, an attacker can detect a victim's satellite uplink signal ("noise") and transmit an inverted counter-signal. This effectively jams the victim's transmission, preventing the satellite in space from receiving their requests and leading to a denial-of-service.
  1. Broadcasting Nature and Cross-National Interception: Satellite signals are broadcast over vast geographical areas. Research, including that cited from Kaspersky, demonstrates that signals from one continent (e.g., Africa or Germany) can be successfully sniffed from another (e.g., the UK). This global reach means that a local vulnerability can have far-reaching international implications, allowing attackers to target entities across national borders.
  1. Readily Available Tools for Interception: The presentation underscores that sophisticated attacks do not necessarily require state-of-the-art, custom-built equipment. APT groups like Turla have successfully utilized common television dishes and modulators to capture and decode on-air satellite signals into usable network packets, proving that the barrier to entry for signal interception is surprisingly low.

Technical Deep Dive

▶ Watch: Overview of satellite attack surface: Space, ground, and user terminals (4:25)

The technical deep dive into satellite attack surfaces reveals a multi-faceted threat landscape, encompassing supply chain compromises, novel signal interference techniques, and the pervasive risk of plaintext data interception.

Ground Side Attacks: Supply Chain and Configuration Vulnerabilities

The rapid growth in demand for satellite network solutions has pressured manufacturers to increase production volumes and reduce costs. This often leads to the incorporation of cheaper components, potentially sourced from regions like China or Russia, where code quality and security standards may be less rigorous. Such practices introduce supply chain vulnerabilities, embedding latent software flaws within satellite modems and ground station equipment before they even reach the end-user.

A prominent real-world example of this vulnerability is the Viasat hack that occurred at the onset of the Russian invasion of Ukraine in February 2022. Russian hackers exploited misconfigured VPN credentials, specifically leveraging default usernames and passwords such as root and root1234, to gain unauthorized access to Viasat's management servers. Once inside, the attackers issued management instructions to satellite modems used by Ukrainian citizens and military personnel, commanding the devices to wipe their software and firmware. This devastating attack rendered thousands of Viasat modems inoperable, effectively cutting off critical satellite communication for Ukrainian users during a crucial period of conflict. This incident serves as a stark reminder that even seemingly basic configuration flaws, exacerbated by supply chain compromises, can have nation-state level impact.

Active Noise Cancellation (ANC) Attacks

Beyond traditional cyber exploits, the talk introduces a unique and sophisticated denial-of-service (DoS) attack vector: Active Noise Cancellation (ANC). This concept, familiar from consumer audio devices like AirPods Pro, is adapted to the radio frequency domain. When a user terminal, such as a Starlink terminal, transmits a network request (an "uplink noise" carrying data packets) from the ground to a satellite in space, an attacker in close proximity can detect this signal.

The attacker then precisely generates and transmits an inverted counter-signal designed to mathematically cancel out the victim's uplink signal. By broadcasting this counter-signal during the victim's transmission, the attacker effectively creates destructive interference in the airwave. The result is that the satellite in orbit receives a garbled or nullified signal, unable to discern the original data request. This prevents the victim's communication from reaching its intended destination, leading to a localized and effective denial-of-service attack without requiring direct access to the victim's hardware or network.

Plaintext Data Interception

Perhaps the most widespread and easily exploitable vulnerability discussed is the interception of unencrypted plaintext data. Due to the broadcasting nature of satellite signals and the historical misconception of their inherent security, many organizations continue to transmit sensitive information in the clear.

Attackers can leverage readily available equipment, specifically television dishes (satellite dishes commonly used for TV reception) combined with a television modulator, to capture and decode these on-air satellite signals. The modulator transforms the raw radio frequency data into usable network packets. With this setup, an attacker can passively sniff various types of unencrypted traffic:

  • POP3 email: Intercepting email content.
  • FTP protocol: Capturing usernames and passwords used to download files from FTP servers.
  • RDP protocol: Sniffing credentials for remote desktop logins to Windows machines.

The global reach of satellite signals makes this particularly dangerous. As highlighted by Kaspersky's research, a security researcher in the UK successfully sniffed satellite signals originating from Africa or Germany, demonstrating the cross-national capability of such interception. A concrete example of this exploitation comes from the Russian APT group Turla, which, between 2015 and 2020, actively utilized television dishes to capture on-air satellite signals. They successfully intercepted administrator credentials for a wind power facility in Germany, subsequently logging in as administrators and gaining control over the facility's operations. This incident underscores the severe implications of unencrypted satellite communications, allowing adversaries to achieve critical infrastructure control with relatively low-tech interception methods.

Demo / Proof of Concept

▶ Watch: Real-world Viasat attack during Russian invasion of Ukraine (6:54)

The presentation "Attack Surface Analysis On Satellites" by Sheng-Hao Ma primarily focuses on analyzing existing attack surfaces, documenting historical and ongoing threats, and drawing conclusions from various security research papers and real-world incidents. While the talk provides detailed technical explanations of attack vectors like Active Noise Cancellation and plaintext data interception, it does not describe a live demonstration or a novel proof-of-concept developed by the speaker. Instead, it synthesizes information from documented APT activities, academic research (e.g., Oxford University, Kaspersky), and specific incidents like the Viasat hack, to illustrate the practical implications of these vulnerabilities. The emphasis is on raising awareness about the current state of satellite network security rather than showcasing new exploit development.

Defensive Implications

▶ Watch: Unique threat: Active noise cancellation attack on Starlink terminals (8:09)

The detailed analysis of satellite attack surfaces by Sheng-Hao Ma provides critical insights for defenders looking to secure these increasingly vital networks. Immediate and proactive measures are essential to mitigate the identified risks:

  1. Mandate End-to-End Encryption: This is the most crucial defense. All satellite communications, regardless of perceived speed implications, must be secured with robust, modern end-to-end encryption. Protocols like TLS/SSL, IPsec VPNs, or secure application-layer encryption should be universally applied to prevent the interception of plaintext data, including emails, file transfers, and remote access credentials. Organizations should audit their satellite traffic to identify and eliminate any unencrypted channels.
  1. Strengthen Supply Chain Security: Organizations must demand greater transparency and security assurances from satellite hardware and software vendors. This includes conducting thorough security audits of components, scrutinizing the origins of hardware, and requiring independent validation of software quality. Prioritizing vendors with strong security track records and verifiable supply chain integrity is paramount to prevent the introduction of vulnerabilities at the manufacturing stage.
  1. Eliminate Default Credentials and Enforce Strong Authentication: The Viasat hack serves as a stark reminder of the dangers of weak authentication. All satellite modems, ground station equipment, and associated management interfaces (e.g., VPNs) must have strong, unique passwords enforced from deployment. Default credentials should be immediately changed, and multi-factor authentication (MFA) should be implemented wherever possible to prevent unauthorized access.
  1. Implement Robust Network Segmentation: Satellite-connected systems, especially those within critical infrastructure, should be isolated and segmented from internal operational technology (OT) and information technology (IT) networks. This limits the lateral movement of attackers if a satellite terminal is compromised, preventing a breach from escalating into a full-scale network intrusion.
  1. Develop Signal Monitoring and Interference Detection Capabilities: To counter advanced threats like Active Noise Cancellation, organizations should invest in capabilities to monitor their satellite uplink and downlink signals. Detecting unusual signal patterns, unexpected drops in signal-to-noise ratio, or specific interference signatures could indicate an active jamming or ANC attack, allowing for timely response and mitigation.
  1. Regular Vulnerability Management and Patching: Like any other network device, satellite modems, ground station software, and associated infrastructure require continuous vulnerability management. Regular patching and firmware updates are necessary to address newly discovered security flaws and protect against known exploits.
  1. Raise Awareness and Conduct Security Training: Educating users, IT staff, and decision-makers about the specific risks associated with satellite communications is vital. Training should cover the importance of encryption, secure configuration practices, and recognizing potential indicators of compromise.

By implementing these defensive strategies, organizations can significantly reduce their exposure to the sophisticated and evolving attack vectors targeting satellite networks, safeguarding critical operations and sensitive data.

Key Takeaways

  • The long-held belief that satellite networks are inherently secure due to complexity and cost is outdated; readily available equipment can now intercept and decode satellite signals.
  • A significant amount of satellite traffic, including sensitive data like usernames and passwords for POP3, FTP, and RDP, is still transmitted unencrypted in plaintext, making it highly vulnerable to interception.
  • Supply chain vulnerabilities, often stemming from cost-cutting measures and the use of cheaper components, introduce critical security flaws that can be exploited by advanced persistent threat (APT) groups, as demonstrated by the Viasat hack.
  • Novel denial-of-service (DoS) techniques, such as Active Noise Cancellation, can be deployed to jam satellite uplinks by generating inverted counter-signals, preventing legitimate communication from reaching satellites.
  • The broadcasting nature of satellite signals allows for cross-national interception using simple tools like television dishes and modulators, enabling attackers to sniff credentials and gain control over critical infrastructure from remote locations.
  • Organizations must prioritize robust end-to-end encryption for all satellite communications, implement stringent supply chain security, enforce strong authentication (e.g., eliminating default credentials), and develop capabilities for signal monitoring to defend against these pervasive threats.

About the Speaker(s)

Sheng-Hao Ma is a presenter at the S4 conference, where he delivered the talk "Attack Surface Analysis On Satellites." His presentation draws upon a comprehensive analysis of various security research, real-world incidents, and documented APT activities to highlight the critical and evolving security challenges within the satellite communication industry. While the transcript does not provide specific biographical details beyond his name, his work demonstrates a deep understanding of satellite network architectures, attack vectors, and the broader implications for industrial and private sector security.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This talk delivers a stark and crucial update on satellite network security, effectively dismantling the outdated 'secure by complexity' myth. Sheng-Hao Ma highlights the alarming prevalence of unencrypted plaintext communications, details critical supply chain vulnerabilities exploited by APTs, and introduces a genuinely novel denial-of-service technique using Active Noise Cancellation. The detailed analysis of real-world attacks and actionable defensive strategies makes this essential viewing for anyone involved in critical infrastructure or modern communications.

Heather Calloway (CISO) — STRONG ACCEPT

Sheng-Hao Ma's "Attack Surface Analysis On Satellites" delivers a timely and critical assessment of satellite network security, effectively dismantling the outdated notion of inherent security in these systems. The presentation expertly translates complex technical vulnerabilities—from widespread plaintext communication and supply chain weaknesses to novel denial-of-service techniques like Active Noise Cancellation—into clear business and governance risks. By providing concrete examples like the Viasat hack and actionable defensive strategies, Ma offers security leaders and decision-makers a vital roadmap to confront a rapidly evolving threat landscape that impacts critical infrastructure…

→ Top-rated talks at S4x24 - ICS Security Conference

All talks from S4x24 - ICS Security Conference