In space, no one can hear cyber security professionals scream

"Space is an invaluable domain, but it is also increasingly crowded and particularly susceptible to a range of cyber vulnerabilities and threats." That's not an overblown sci-fi movie strapline, but rather the chilling words of Gina Galasso, managing director of The Aerospace Corporation UK, a member of the international collaborative organisation, Space ISAC (the Space Information Sharing and Analysis Center.) And she's not wrong on either count. In the UK alone, Galasso told The Register, the space sector contributes £5.7bn to the national economy each year and underpins a further £5.5bn in exports. When it comes to threats, Galasso says some types are quickly detected – including orbital, kinetic and electronic attacks – but there are other less easily detected forms of cyber intrusion that "result in data manipulation or corruption, communications jamming or supply chain interruption". Mi NASA, su NASA? Now add to the sense of foreboding with a report published by the NASA Office of Inspector General in May 2021 [PDF here] investigating how ready the organisation is from a cybersecurity perspective. This audit found that during the last four years, NASA had experienced more than 6,000 cyber incidents, and 1,785 in 2020 alone. With some 3,000 websites and 42,000 publicly accessible datasets, perhaps that's not surprising. "I know NASA suffers a large amount of nearly daily cyber attacks by sophisticated and unsophisticated actors," says Ian Thornton-Trump, CISO at threat intelligence outfit Cyjax. "But the team at NASA is constantly vigilant as they have a keen understanding of just how dangerous a place it is to lose control of something moving tens of thousands of miles per hour or even faster." The space attack surface, one giant leap for threat actors Also filed under "not surprising" is the fact that the space attack surface is both huge and attractive. After all, space is a crucial part of international critical infrastructure. "Persistent, over-the-horizon vision and continual, assured, high data-rate connectivity is fundamental in winning modern wars," Professor Kevin Curran, a senior IEEE (Institute of Electrical and Electronics Engineers) member and professor of cyber security at Ulster University, tells us. The importance of space to the largest nation states cannot be overstated, according to Prof Curran. "Essential systems such as communications, air transport, maritime trade, financial services, weather monitoring and defence all rely heavily on space infrastructure, including satellites, ground stations and data links at the national, regional, and international level," he adds. Attacks on any of these core space- or ground-based components could disrupt an entire nation. Paul Kostek is an advisory systems engineer to Base2 Solutions, and a former president of the IEEE Aerospace and Electronics Systems Society and member of the American Institute of Aeronautics and Astronautics. He tells us his concern is not only that as the number of satellite constellations increases, so does the interest from adversaries, but also the sheer number of possible threat actor entry points. These range "from the ground stations transferring the data to the telemetry stream, which is not currently encrypted," he points out, as well as the reliance on IoT devices which provide even more access opportunities. Then there's the small matter that "most ground stations may not be controlled by the owners or providers of the constellation and as a result may not provide adequate security", Kostek adds. The threat risk will "only increase as the need for connectivity grows and we see more reliance on space-based infrastructure such as high-speed internet access", Phil Mar, CTO of government systems at satellite communications specialists Viasat, insists. Logic clearly dictates the security needs of the many outweigh the needs of the few It's all too easy to think of the attack surface being limited to national space missions and the organisations that support them, including the military. However, the truth is that the private spaceflight industry, including companies such as Space X and Blue Origin, has served to highlight the true size of the problem. The space industry has a huge target on its back because it's so innovative and has such a rapid R&D rate, says Lisa Forte, a partner at Red Goat Cyber Security. When it comes to data theft there's a hefty financial reward for any successful attacker. "The space industry has one huge problem," Forte told The Register. "It may well be have the biggest supply chain in the world." We already know that supply chain attacks are a favourite of ransomware groups: "With the recent rise in commercial ransomware attacks, the issue of cyber security must be a top priority for anyone operating in the sector," Mar suggests. Indeed, you may recall a story last year that revealed aerospace industry players including Boeing, Lockheed Martin and SpaceX had been caught up in just such a supply chain ransomware incident. "In purely monetary terms, NASA's current annual budget is close to $23bn," Thom Langford, a global security advocate at SentinalOne points out. "So from the perspective of a ransomware demand, there is plenty of money to be had." And with thousands of subcontractors in the supply chain, the attack surface is certainly expansive. This drag sail could prevent spacecraft from turning into long-term orbiting junk. We spoke to its inventors ahead of launch More cracks found in Russian annex of the International Space Station The Register recreates Apollo 15 through the medium of plastic bricks, 50 years on Bonkers rocket launch sees craft slip sideways, barely climb and tear up terrain "Space is hard, resulting in extremely complex operations, multinational cooperation, and rigorously tested environments that are classed as critical infrastructure, and protected by their relevant nation-states," Langford continues. This level of strong collaboration between superpowers, which results in the sharing of benefits, could be one reason that the space sector has largely escaped direct targeting by ransomware players. When it comes to space: "The attackers who may normally be tacitly endorsed by nation-states may not enjoy this support and may therefore take aim at other softer targets as a result," Langford suggests. Unfortunately, he adds, "this level of community may not last". How many assholes have we got on this ship, anyhow? Spaceballs could have provided so many sub-heads, but the "how many assholes have we got on this ship?" one seems most appropriate when examining the defensive measures being taken to protect the space sector from a policy perspective. The principles set out in the Trump presidency – Memorandum on Space Policy – Directive 5 – Cybersecurity, for example – are all well and good on paper, but how do you go about putting them into practice? The Register spoke to HypaSec CEO, Chris Kubecka, who served in the US Air Force before transferring to Space Command, where she handled command and control systems, securing military and intelligence assets from nation-state attacks, and cyber security. "There are less than a handful of policy wonks who know anything about cyber security on the technical level," Kubecka says. "Instead, there are lots of lawyers and political science folks who work in cyber policy and approach the issues from a purely theoretical perspective, using the newest buzzwords to get their unimplementable policy through." Kubecka compares this to health policy, where people who have never seen the inside workings of a medical facility wouldn't be expected to write implementable policy during a pandemic. "Until major governments bring the technical cyber security community into policy, more useless 'cyber' policy will continue to be written," she adds. One reasons for this, Kubecka suggests, could be that policy and national defence leadership in the US lament Russia for being ahead of the game because they include hackers. "Yet the same USA leadership trust non-technical people whilst locking out the ethical hacker community," she says. "It’s mind-boggling." Space, the final unregulated frontier The trouble, according to Martin Rudd, co-founder at SECQAI, is that to date there are limited regulations and policies concerning this area. "When it comes to cyber conflict, the Outer Space Treaty (1967) only covers the issue that kinetic weapons (including weapons of mass destruction) must not be placed in orbit," Rudd says. Despite an increasing number of space-based assets – both commercial and government-owned – there is no reference or amendments to cover cyber security and the data stored on, or transiting, the satellites in orbit. "This is extremely interesting as by their very nature these space-based assets are facilitators of cyber warfare," he warns. "To avoid conflict or cyber warfare, it will become increasingly important to develop international standards and agreements to govern all space technology." Space is a fundamentally contested environment. As Pete 'Rocky' Rochelle, previously chief of staff for capability acquisition in the Royal Air Force and part of the Five Eyes working group on space capabilities, and now COO at quantum encryption provider Arqit points out: "In both doctrine and operations, the US has declared offensive space capabilities," he says, adding: "China has also demonstrated capabilities to shoot down rival satellites and there are frequent proximity testers happening with Russian satellites." All of which means that the risk of cyber or kinetic attack can massively heighten tensions. This, Rochelle says, has led to a recognition of the need to unify, cohere and coordinate efforts that were previously cut across various governmental units. "In the UK too," he tells The Register, "space integration has featured as an important element of the government's recent Integrated Review. Within an allied context, the Five Eyes coalition serves a similar purpose." The space domain awareness coalition based at Vandenberg Space Force Base monitors all space activity, whether accidental or deliberate, in order to pre-warn commercial vendors about space conjunctions (significant debris impact, for instance). "Such crucial information is shared among western allies through federated satellites which need cyber protection," Rochelle says. A quantum leap into space security To understand the cyber threat to the critical infrastructure in the sky – essentially, the digital platform that the space industry has created – we need to imagine what it would be like were it to be disrupted. "If these satellites stopped working, our modern lives would be set back decades in a matter of seconds," Rochelle says. "The global transport of people and goods across supply chains would be seriously affected, an increasingly decentralised energy supply would become impossible to synchronise without time signals from satellites and entire power grids would become unstable." Yet, according to Galasso: "Space systems are often overlooked in wider discussions of cyber threats to critical infrastructure." This requires a quantum leap towards taking space security seriously. "All space systems, hardware, firmware and software components, should feature cyber hardened designs with risk-based, defence-in-depth cyber protections to detect and deter threats and vulnerabilities," Galasso insists. Currently, the UK has designated space as one of 13 critical national infrastructure sectors, and it is a joint, cross-government responsibility for the defence, civil space and commercial sectors. "The EU and US are considering similar designations to enable better internal coordination for securing space systems," Galasso continues. "This is an international priority that requires a degree of collaboration and coordination, which has traditionally happened in a top-down approach through organisations like the United Nations." However, a bottom-up process – utilising national space legislation like the Space Industry Act 2018 and using guidance from bodies like the UK’s National Cyber Security Centre – is required to allow each state to develop a regime that best suits their respective national interests and may achieve global consistency in developing norms more quickly, Galasso insists. Indeed, in order to combat threats, whether from cyber criminals or state-sponsored attacks, as well as to protect infrastructure and sovereign integrity in space, we will need to see the same nationalistic cyber security endeavours that have been rolled out on Earth also implemented in orbit and beyond, Rudd says. These include "space versions of the UK government's creation of the 'High Risk Vendor' category and subsequently numerous decisions concerning Huawei, for example," he suggests. "It's likely that the same inter-country/continent trade agreements and relationships will be established in space as a defensive strategy against cyber attacks." But, as Galasso says: "Resilience for space comes not just from high-quality sovereign capabilities and cross-government responsibilities, but also from strong relationships with allies and international partners that emphasise the value of partnership and information sharing. The space enterprise needs a fully integrated approach across policy and technology to enhance resilience." ® Similar topics Corrections Send us news Other stories you might like Banned: The 1,170 words you can't use with GitHub Copilot Hash cracking reveals verboten slurs, terms like 'liberals, 'Palestine,' and 'socialist' ... and Quake's famous Fast InvSqrt Thomas Claburn in San Francisco Thu 2 Sep 2021 // 22:01 UTC GitHub's Copilot comes with a coded list of 1,170 slurs to prevent the AI programming assistant from responding to input, or generating output, with offensive terms, while also keeping users safe from words like "Israel," "Palestine," "communist," "liberal," and "socialist," according to new research. Copilot was released as a limited technical preview in July in the hope it can serve as a more sophisticated version of source-code autocomplete, drawing on an OpenAI neural network called Codex to turn text prompts into functioning code and make suggestions based on existing code. To date, the results have been interesting but not quite compelling – the code produced has been simplistic and insecure, though the project is still being improved. Continue reading FTC bans 'brazen' stalkerware maker SpyFone, orders data deletion, alerts to victims Insecure systems were compromised by miscreant, too, watchdog said Tim Richardson Thu 2 Sep 2021 // 21:05 UTC America's trade watchdog today banned stalkerware developer SpyFone and its CEO from the surveillance industry, effectively putting an end to its business. The outfit makes an Android app that can be secretly installed on someone's smartphone; once in place, the software relays back information about the handheld and its user to SpyFone's systems so that whoever installed the program can remotely monitor their victim in real time, block other apps from being installed, send spoofed messages as the victim, and so on. In effect, the FTC said, Support King LLC, which traded as SpyFone, and its CEO Scott Zuckerman, "secretly harvested and shared data on people’s physical movements, phone use, and online activities" and allowed "stalkers and domestic abusers to stealthily track the potential targets of their violence." Continue reading Autodesk was one of the 18,000 firms breached in SolarWinds attack, firm admits Door was opened but nobody stepped inside, luckily Gareth Corfield Thu 2 Sep 2021 // 17:33 UTC Autodesk, makers of computer-aided design (CAD) software for manufacturing, has told the US stock market it was targeted as part of the the supply chain attack on SolarWinds' Orion software. In a filing with the American Stock Exchange Commission, Autodesk said it had identified a compromised server in the wake of public reporting of the SolarWinds breach. According to the US and UK governments, the attack saw spies from Russia's SVR agency (the equivalent of Britain's MI6) compromise systems used to compile new builds of network monitoring software Orion. Continue reading This too shall PaaS: VMware's new Tanzu Application Platform explained Plus: We find out why VMware gave up on running Tanzu Application Service on Kubernetes Tim Anderson Thu 2 Sep 2021 // 16:29 UTC Interview VMware has previewed Tanzu Application Platform, a bundle of Kubernetes packages which it claims will simplify application delivery – but its plans to run the existing Tanzu Application Service on Kubernetes have been abandoned. The first thing to understand about Tanzu Application Platform (TAP) is that it has little in common with Tanzu Application Service (TAS). They are quite different things, making the similarity in name unfortunate. TAS is based on Cloud Foundry technology, an open-source application platform whose tangled origins go back to VMware in 2009. It was then spun out to Pivotal Software, which handed the core software to the Cloud Foundry Foundation and was then re-acquired by VMware to become part of Tanzu. TAS, and Cloud Foundry, uses BOSH to package and deploy applications. Continue reading Remember the Oracle-botherers at Rimini Street? They are expanding third party support into open source database world About time: 51 per cent of databases run on open source now Paul Kunert Thu 2 Sep 2021 // 15:35 UTC Rimini Street is spreading its tentacles beyond proprietary databases and will provide third party support services to platforms with a distinctly open source flavour, including MySQL, MariaDB, PostgreSQL and MongoDB. Historically, the relatively small enterprise software provider has independently delivered services for Oracle, SAP, IBM DB2 and Microsoft SQL Server products via its near-400 full-time DB engineers to more than 1,400 clients worldwide. It is also an official provider of software services for CRM monster Salesforce. Many Reg readers may know the company from its protracted courtroom battle with Oracle over a copyright dispute. Big Red won a permanent injunction against Rimini in 2018 that prevents it from distributing Oracle software, and accessing source code for testing or dev work, amongst other things. Continue reading Facebook: Let us tell you WhatsApp – we don't want to pay that €225m GDPR fine Zuckerborg plans to appeal Irish data protection slap Tim Richardson Thu 2 Sep 2021 // 14:27 UTC WhatsApp has been slapped with a fine of €225m [PDF] following a long and drawn out investigation into whether it had provided the necessary data protection information to users under the EU General Data Protection Regulation (GDPR). The fine - along with a slap on the wrist - has been imposed by the Data Protection Commission (DPC), the national independent authority in Ireland responsible for personal data protection in the EU. It's reported to be the heftiest fine ever issued by the DPC and the second-largest handed out under EU data protection laws. Continue reading The unit of measure for fatbergs is not hippopotami, even if the operator of an Australian sewer says so Thou shalt not infringe upon the Register Standards Soviet Gareth Corfield Thu 2 Sep 2021 // 12:27 UTC An Australian drainage company has made a valiant effort to define a new standard for weights; in this specific case they're measuring sewer fatbergs in hippopotami. Australia's Broadcasting Corporation reported that Urban Utilities of Queensland was recently complaining about rubbish blocking its sewers. Fair enough; the utility firm reckoned it was costing them around AU$1m a year to clear the fatbergs. "We attend to about 4,000 blockages in the sewage network per year, costing us an additional maintenance cost of about $1 million per annum," the company's lead for Environmental Solutions Colin Hester told the ABC. "There's no nationally agreed standard between makers, retailers and utilities," he added, seemingly referring to products that really shouldn't be flushed down the bog but which retailers label as "flushable" anyway. Continue reading Nutanix mandates vaccinations for in-office workers, doesn't mandate going to offices Finishes FY 2021 with a bang and starts to re-open Simon Sharwood, APAC Editor Thu 2 Sep 2021 // 11:25 UTC Hyperconverged upstart Nutanix has made vaccinations mandatory for staff attending its offices, but hasn't made coming to the office mandatory. CEO Rajiv Ramaswami told The Register the policy was introduced as part of the company's phased return to working in offices, which commences this month in the USA. The policy will only be applied where it is legal to do so and won't be applied globally. In India, for example, Nutanix does not feel it is safe for staff to return to its offices. "We are not forcing people into the office," the CEO said, but added that he feels "hybrid work" – blending office attendance and working in other locations – is a permanent feature of life at Nutanix. Continue reading UK VoIP telco receives 'colossal ransom demand', reveals REvil cybercrooks suspected of 'organised' DDoS attacks on UK VoIP companies One firm hit with at least two attacks as outages continue Tim Richardson Thu 2 Sep 2021 // 10:32 UTC Two UK VoIP operators have had their services disrupted over the last couple of days by ongoing, aggressive DDoS attacks. South Coast-based Voip Unlimited has confirmed it has been slapped with a "colossal ransom demand" after being hit by a sustained and large-scale DDoS attack it believes originated from the Russian cybercriminal gang REvil. This morning, it confirmed that "services are operational ... however the attacks are still ongoing." Continue reading O-RAN Alliance: Nokia downplays decision to take breather as critics worry over fate of key industry groups Backs away from potential Entity List security issues related to Chinese alliance members Tim Richardson Thu 2 Sep 2021 // 09:35 UTC Ericsson has voiced its concern over "progress" within the O-RAN Alliance, days after Nokia called a technical timeout with the group amid "compliance-related" concerns. Nokia's withdrawal comes after some members of the open radio access network industry group were added to the US government's "Entity List," which fingers organisations the country claims pose a threat to America's security. News of the Finnish telecoms giant's decision to suspend work with the O-RAN Alliance – a group of telcos and vendors that work together to test and work on open standards and software around telecoms infrastructure kit – emerged last week following a report by Politico – which Nokia confirmed. Continue reading Imaginary numbers help AIs solve the very real problem of adversarial imagery Duke University boffins figure out a way to boost the security of recognition networks Gareth Halfacree Thu 2 Sep 2021 // 08:32 UTC Boffins from Duke University say they have figured out a way to help protect artificial intelligences from adversarial image-modification attacks: by throwing a few imaginary numbers their way. Computer vision systems which recognise objects are at the heart of a whole swathe of shiny new technologies, from automated shops to robotaxis. Increasingly broad deployment makes them increasingly of interest to ne'er-do-wells - and attacks like AMpLe Poltergeist show how they can be fooled with potentially deadly results. "We're already seeing machine learning algorithms being put to use in the real world that are making real decisions in areas like vehicle autonomy and facial recognition," said Eric Yeats, a doctoral student at Duke University, following the presentation of his team's work at the 38th International Conference on Machine Learning. "We need to think of ways to ensure that these algorithms are reliable to make sure they can't cause any problems or hurt anyone." Continue reading SITUATION PUBLISHING The Next Platform DevClass Blocks and Files Continuous Lifecycle London M-cubed The Register - Independent news and views for the tech community. Part of Situation Publishing SIGN UP TO OUR DAILY NEWSLETTER Subscribe Biting the hand that feeds IT © 1998–2021 Do not sell my personal information Cookies Privacy Ts&Cs