Prevent Downlink: Inhibit Ground System Functionality

Threat actors may utilize ground-system presence to inhibit the ground system software's ability to process (or display) telemetry, effectively leaving ground controllers unaware of vehicle activity during this time. Telemetry is the only method in which ground controllers can monitor the health and stability of the spacecraft while in orbit. By disabling this downlink, threat actors may be able to stop mitigations from taking place.

ID: DE-0002.01
Sub-technique of:  DE-0002
Notional Risk (H | M | L):  21 | 17 | 12
Related Aerospace Threat IDs:  SV-MA-7 | SV-AV-1
Related MITRE ATT&CK TTPs:  T1562.006
Created: 2022/10/19
Last Modified: 2022/12/08


ID Name Description NIST Rev5 D3FEND ISO 27001
CM0005 Ground-based Countermeasures This countermeasure is focused on the protection of terrestrial assets like ground networks and development environments/contractor networks, etc. Traditional detection technologies and capabilities would be applicable here. Utilizing resources from NIST CSF to properly secure these environments using identify, protect, detect, recover, and respond is likely warranted. Additionally, NISTIR 8401 may provide resources as well since it was developed to focus on ground-based security for space systems ( Furthermore, the MITRE ATT&CK framework provides IT focused TTPs and their mitigations Several recommended NIST 800-53 Rev5 controls are provided for reference when designing ground systems/networks. CM0070 Alternate Communications Paths Establish alternate communications paths to reduce the risk of all communications paths being affected by the same incident. AC-17 CP-2 CP-8(3) PL-8 PL-8(1) SC-47 D3-NM D3-NTPM A.5.14 A.6.7 A.8.1 7.5.1 7.5.2 7.5.3 A.5.2 A.5.29 A.8.1 A.5.8