Rethinking Satellite Cybersecurity: A System-Level Taxonomy and Longitudinal Analysis
This work provides a critical framework for cybersecurity professionals and satellite operators to understand and mitigate evolving threats to satellite systems, particularly in low Earth orbit.
This paper addresses the increasing cyber and electronic-warfare threats to satellite systems by developing a comprehensive, satellite-specific taxonomy of adversarial tactics, techniques, and procedures. It analyzes over 200 publicly reported satellite incidents from 1962 to 2026, identifying shifts towards ground-segment compromise, GNSS interference, and deception-oriented attacks.
Satellite systems are increasingly targeted by cyber and electronic-warfare adversaries as their roles in communication, navigation, Earth observation, and defense expand. Existing surveys do not comprehensively characterize adversarial behavior across the full attack lifecycle and often omit emerging attack surfaces such as adversarial machine learning (AML). This paper presents a satellite-specific taxonomy of tactics, techniques, and procedures (TTPs), developed primarily for low Earth orbit systems and informed by evidence from LEO, MEO, and GEO missions. We analyze the space, ground, communication, and user segments to identify architectural exposures and operational attack surfaces, and compile a dataset of more than 200 publicly reported satellite incidents from 1962 to 2026, including over 80 incidents not covered in prior work. Longitudinal analysis reveals shifts toward ground-segment compromise, GNSS interference, communication disruption, proximity-based counterspace activity, and deception-oriented attacks. Building on these findings, we propose a MITRE ATT&CK-inspired satellite attack lifecycle taxonomy that integrates subsystem exploitation, radio-frequency interference, on-orbit operations, AML, and deception techniques. We demonstrate its practical utility through case studies of the 2022 Viasat KA-SAT cyberattack and a simulation-based ICARUS constellation-scale denial-of-service scenario. The framework combines longitudinal evidence, real-world incidents, and emerging attack modalities to support threat modeling, defensive planning, and the design of detection and mitigation strategies.