Deception and Decoys

Deception and decoy techniques can reduce the accuracy or confidence of adversary assessments concerning spacecraft location, capability, operational status, mission type, or constellation robustness. Ground segment honeypots, such as HoneySat, extend deception into the cyber domain by simulating realistic satellite ground infrastructure and mission control systems to attract, deceive, and collect intelligence on adversaries attempting network-based compromise of satellite operations. Their effectiveness depends on whether the deception remains credible when evaluated across the observable signatures and intelligence sources available to the adversary. Strategic deception encompasses information operations approaches such as controlled public messaging and launch announcements that limit disclosure or actively introduce uncertainty about satellite capabilities, as well as operational practices that conceal spacecraft functions through careful management of observable behaviors and emissions. On-orbit capability deception, enabled by swappable payload modules and on-orbit servicing vehicles that periodically transfer payloads between satellites, creates persistent uncertainty in the adversary's intelligence picture about which capabilities are resident on which platform at any given time, directly complicating targeting calculus. Tactical decoys provide active point defense by creating false targets that confuse the sensors of anti-satellite (ASAT) weapons and space domain awareness (SDA) surveillance systems; physical decoys, such as deployable inflatable devices that replicate a satellite's size and radar cross-section, and electromagnetic decoys that mimic a spacecraft's radio frequency (RF) signature, can each divert adversary attention and degrade the reliability of tracking and targeting solutions. Multiple decoys stored onboard for sequential deployment extend the utility of the capability across engagement scenarios. Cyber-layer deception through satellite honeypots represents an emerging defensive capability that complements physical and electromagnetic deception techniques. Systems like HoneySat simulate complete satellite missions, including ground segment software, mission control interfaces, orbital pass timing, and realistic telemetry generation, to create high-fidelity decoys accessible over network protocols commonly used in satellite operations. By mimicking the communication patterns, telecommand structures, and subsystem behaviors of operational small satellites, these honeypots can successfully deceive adversaries conducting reconnaissance or attempting unauthorized access via Internet-exposed ground infrastructure. The intelligence collected from honeypot interactions provides visibility into adversary TTPs targeting space systems, enabling defenders to characterize threat actor capabilities, refine attribution assessments, and develop countermeasures based on observed attack patterns. Integration of honeypots into satellite mission architectures, whether as standalone decoy systems or as protective layers around operational ground segments, adds depth to cyber defense postures while imposing costs on adversaries who must expend resources distinguishing genuine targets from sophisticated simulations.

Sources

ID: CM0082
Tier: III
Onboard SV CM 
Created: 2023/04/22
Last Modified: 2026/08/06

Pre-Operations Government

Acquisition strategies for missions facing credible adversary targeting should evaluate strategic deception and tactical decoy capabilities. Requirements should define the deception objectives, decoy types and quantities, deployment conditions, and integration with the spacecraft’s threat-warning, maneuver, and defensive-response systems. Where swappable payloads are used for strategic capability deception, requirements should define the modular interfaces, servicing compatibility, and information controls needed to protect the actual payload configuration of each spacecraft. Decoy design parameters, deception strategies, deployment procedures, and host-signature data should be protected according to their assigned sensitivity and limited to personnel with an operational need to know. Evaluation criteria should assess the proposed decoy designs, storage and deployment mechanisms, threat-relevant RF and radar signature fidelity, and integration with other defensive capabilities. Verification should use representative threat-sensor surrogates to demonstrate that the decoys produce the intended observable signatures under the defined engagement conditions. Requirements for deployable physical decoys must also address deployment authorization, tracking and identification, collision risk, orbital lifetime, passivation, and end-of-life disposition. Decoy deployment must not create unacceptable risk to the host spacecraft, other space objects, or subsequent mission operations.

Pre-Operations Developer/Supplier

Spacecraft incorporating physical or electromagnetic decoy systems must design the decoy storage, ejection, and deployment mechanisms from the earliest structural and mechanical design phases, as late-stage integration of deployable decoy systems into a mature spacecraft design is likely to conflict with structural layouts, center-of-mass requirements, and available volume that cannot be easily accommodated without significant redesign. Physical decoy design must characterize the host spacecraft’s threat-relevant radar signatures and identify the frequencies, viewing geometries, attitudes, and temporal behaviors the decoy is intended to reproduce. The decoy need not replicate the host across every condition, but its observable differences must not allow reliable discrimination within the defined engagement scenario. Host-signature data and effectiveness assessments must be protected according to their assigned sensitivity. Electromagnetic decoys must reproduce the threat-relevant RF characteristics needed to create a credible false target under the defined adversary collection model. Design and testing must evaluate whether the decoy can be distinguished using signal characteristics, direction finding, motion, timing, or correlation with other observations. The required level and duration of deception must be defined as a testable performance objective rather than assumed from similarity to the host transmission. For missions incorporating on-orbit payload swapping as a strategic deception capability, the payload interface design must support rapid and reliable servicing operations while maintaining the integrity of the capability deception, with configuration management systems tracking actual payload locations under strict access controls that prevent adversary intelligence exploitation. Decoy deployment must be integrated with the threat-warning and defensive-response architecture. Autonomous deployment should be used only when required by the engagement timeline and when preauthorized conditions, release constraints, deployment inhibits, and spacecraft safety checks are technically enforced. Otherwise, deployment should require the mission-approved authorization process.