Threats · CIA+A · defenses

Securing the space mission.

A satellite is a computer in a hostile place, reachable only over radio. This is an interactive, hands-on guide to its cyber risks and what protects them — the attack surface, jamming and spoofing, the CIA+A model, and the controls that keep a mission trustworthy. Hover every i for detail.

interactive throughout

Where the risk lives

The four segments of a space system

A space mission is not just the satellite. It is four connected segments — and an attacker only needs the weakest one. Click each part of the system to see what can go wrong there. In practice, most successful attacks never touch the satellite: they hit the ground.

The security model

CIA + A — what we are protecting

Every security control exists to defend one of these properties. The classic triad — Confidentiality, Integrity, Availability — is extended in space (and PNT) with Authenticity, because the worst attacks are not about stealing data but about making a system trust a lie. Tap each pillar.

Denial

Jamming — drowning the signal

Jamming is brute force: flood the receiver with enough radio noise on the right frequency that it can no longer hear the real signal. It does not break encryption or steal data — it simply denies the link. It is the most common form of attack on space systems because it is cheap and needs no access. It primarily attacks Availability.

What matters is the jam-to-signal ratio at the receiver, not raw power. A receiver tolerates noise up to a margin; beyond it, the bit errors overwhelm error-correction and the link drops. Defenders raise that margin with spread spectrum, directional antennas and power — attackers raise jammer power or get closer. Move the slider (a teaching model, not real attack parameters).

0 dB
12 dB

Link status

Kinds of jamming

Uplink jamming blinds the satellite's command receiver; downlink jamming denies users on the ground; GNSS jamming wipes out positioning and timing over a wide area — often the most disruptive of all, since timing underpins power grids, finance and telecoms.

Deception

Spoofing — feeding a believable lie

Spoofing is the dangerous cousin of jamming. Instead of denying the signal, it transmits a fake one that looks authentic — so the victim keeps working, but on false data. A spoofed GNSS receiver reports a confident, wrong position. A spoofed command could make a satellite act on an order that never came from its operator. Spoofing attacks Integrity and Authenticity, and it is far harder to detect than jamming.

GNSS spoofing — the "walk-off" i

0 km

The receiver (green) is slowly "walked off" its true position (white) by a signal it still believes. No alarm fires — that is the danger.

Why it works — and how we stop it

Civil GNSS signals (like GPS L1 C/A) carry no signature, so a receiver cannot tell a genuine satellite from a clever fake. The fixes are authentication and cross-checks: Galileo OSNMA signs the navigation message, encrypted military codes resist it by design, and receivers can sanity-check against inertial sensors, multiple constellations and known clock behaviour.

Jamming vs spoofing. Jamming is loud and obvious — you notice the outage. Spoofing is quiet and you may never know: the system reports success while doing the wrong thing. That is why integrity and authenticity, not just availability, sit at the centre of space cyber.

The full taxonomy

Threats beyond the radio

Jamming and spoofing are the famous ones, but most real compromises are ordinary cyberattacks against the ground and supply chain. Each card shows what the threat is, which CIA+A property it breaks, which segment it hits, and the control that stops it.

What we need

Defenses & frameworks

Security in space is engineered in, not bolted on. These are the core controls and the real frameworks that codify them — from the data-link layer up to national policy. Click any for detail.

It already happened

Real incidents

Space cyber is not theoretical. These documented public cases show the patterns — and that the ground segment is usually the way in.

Test yourself

Challenges

Two quick games. Read each scenario and choose — you will get instant feedback and a running score.

0 / 0
0 / 0

Left: is it jamming (denial) or spoofing (deception)? Right: which CIA+A property does the attack break?

Quick reference

Glossary & frameworks

🛡
Educational & defensive. This page explains how threats work so that systems can be defended. It deliberately contains no operational instructions, parameters or code for conducting attacks. The interactive models are simplified teaching tools, not real attack tooling. For real systems, follow frameworks such as SPD-5, NIST and IEC 62443, and qualified security engineering.