SI-7(17) - Software, Firmware, and Information Integrity | Runtime Application Self-protection

Implement [Assignment: organization-defined controls] for application self-protection at runtime.


ID: SI-7(17)
Enhancement of : SI-7

Space Segment Guidance

Add runtime application self-protection for the command interpreter. Embed control-flow guard and stack canary libraries that trap unexpected jumps or buffer overflows, terminate the offending task, and raise a discrete telemetry flag. Pair this with a low-overhead heuristic that watches for atypical opcode sequences characteristic of shell code. Although full endpoint detection is unrealistic within tight processor margins, these micro-shields give the vehicle a final layer of defense during the long round-trip delay while ground crews analyze an anomaly.