Traffic Volume Spike on Out-of-Band Link

Monitors traffic volume or bandwidth usage on the out-of-band communication link to detect spikes that exceed normal operational thresholds, which may indicate malicious activity.

STIX Pattern

[network-traffic:src_ref.value = 'out_of_band_channel' AND network-traffic:traffic_volume > 'baseline_threshold']

SPARTA TTPs

ID Name Description
EXF-0004 Out-of-Band Communications Link Some missions field secondary links, separate frequencies and hardware, for limited, purpose-built functions (e.g., rekeying, emergency commanding, beacons, custodial crosslinks). Adversaries co-opt these channels as covert data paths: embedding content in maintenance messages, beacon fields, or low-rate housekeeping; initiating vendor/service modes that carry file fragments; or switching to contingency profiles that bypass normal routing and monitoring. Because these paths are distinct from the main TT&C and may be sparsely supervised, they provide discreet avenues to move data off the spacecraft or to external relays without altering the primary link’s traffic patterns.