
Securing satellites already in space, with journalist Shaun Waterman.
Shaun Waterman: Space assets have traditionally been protected, at least from nation state attack by these very strong norms. But in cyberspace, there just aren't the same norms. Historically there's been no penalty for attacking in cyberspace and frankly that's -- that's a little worrying.
Maria Varmazis: Welcome. I'm Maria Varmazis and you're listening to "T-Minus Space Cyber Briefing." In this show, we examine the evolution of cybersecurity in the global and orbital infrastructure that powers, protects and connects our lives. [ Music ] Hi, everybody, thank you for joining me today. In our show today, we are featuring my recent interview with journalist Shaun Waterman. And he's been covering emerging technology and the space industry for decades. Space cybersecurity specifically has also been a part of his beat. You may have seen his byline in "Satellite Today" or in "Newsweek." Shaun recently wrote an article about how the newest space race is cyber in which he covers recent work in the industry to bring incident detection and response onto satellites themselves rather than focusing solely on the ground systems. And well, as you might imagine, that really piqued my interest. We have a link in the show notes for you so you can read that article. But even if you haven't read it yet, I know you'll get a lot out of our conversation about the current state of space cyber. Let's start off with Shaun telling us a little bit about himself.
Shaun Waterman: So, I am a reporter, a freelance journalist. I write about cyber security and other emerging technological threats, and I write about the space industry. And I used to write more about federal IT. My background is I -- I came to Washington with the BBC originally, for six months in 1999, but I liked it so much here that when they wanted me to go back to London, I quit. So, I -- and I, you know, never looked back. The rest, history, as they say.
Maria Varmazis: That's wonderful, Shaun. Well -- well, thank you so much for joining me today. I reached out because you wrote this fantastic article with the headline, "The Newest Space Race is Cyber." Would you mind walking me through a little bit about how you put this article together and what -- what your pitch was for creating this?
Shaun Waterman: Well, actually, in -- in some ways, this was a follow up to a story that I wrote last year after the CyberSat conference in Reston, in November. There was a presentation by the DHS Science and Technology Division and -- and the Aerospace Corporation, about a couple of things that they were doing. Open-source projects basically, designed for on-orbit cyber detection and response. Space companies, you know, think about cybersecurity or -- or operationalize it. Anyway, it tends to be on the ground, protect their ground assets. You know, they protect their assets in the cloud. They encrypt their links. Hopefully, they do.
Maria Varmazis: Hopefully.
Shaun Waterman: But they can't take that for granted. But no one really knows how to protect the satellite itself, you know, the software that's on there. So, and I have been writing about this for about five years. You know, I -- I first wrote about it in 2020 actually, which is the first Hack-A-Sat contest at DEF CON. So, there's a history there of you know, what Hack-A-Sat was doing and they were building up to it eventually in, I think it was 2024, there was actually a -- a CTF, you know, capture the flag contest between these teams of hackers on a satellite actually in orbit, called Moonlighter.
Maria Varmazis: Yes.
Shaun Waterman: It was an aerospace corporation and Air Force Research Lab project. So -- so, there's been -- on the offensive side, there's been quite a lot of work to demonstrate the -- the dangers of this hacking presents. But on the defensive side, by contrast, there -- there really didn't seem to have been much work done. I wrote a couple of articles, you know, one for "Via Satellite Magazine" and one for "Air and Space Forces Magazine" about these efforts last year. And so, this -- the story in "OT Today" for -- for Information Security Media Group was -- was really a -- a sort of continuation of that, an update of it, you know, what had happened since, because they were going to try and open source some of these projects, so that people could toy around with them and because you know, it's a very difficult thing when the Hack-A-Sat people were looking to try and find a satellite that people would let them hack in or you know, in the end they had to launch their own. Right? Because that -- everyone was like, "No, I don't think we're going to do that."
Maria Varmazis: A multi-million-dollar asset on orbit.
Shaun Waterman: Exactly.
Maria Varmazis: A bit of a hard sell, yes.
Shaun Waterman: So, part of the problem is you know, people need to have confidence, have a trust and familiarity with the tools. Right? That was what DHS Science and Technology Division, and the Aerospace Corporation were trying to do. And then there were also a couple of other different initiatives which I -- I touched on in the ISMG story. Deloitte is actually -- they have a small constellation now in orbit, three satellites altogether that have this on-orbit intrusion detection system, and they've been testing it out. They and their partners have been trying a series of increasingly complex attacks on -- on the satellite. None -- none of them succeeded so far. So, that's a good thing. The guy, Ryan, over at Deloitte did say to me, you know, the -- the one we're going to really learn from is the one that succeeds, right?
Maria Varmazis: Yes, yes, indeed. Yes.
Shaun Waterman: They have their silent shield, which is their cyber product. You know, they're on orbit, intrusion detection and response. Well, on the first satellite was behind a one-way diode, right? So, that meant it could receive information from the satellite payload, but it couldn't actually, you know, transmit to it. It couldn't actually do anything. And that again is for the confidence issue. But with the second two satellites, they wanted to demonstrate on-orbit updatability, right, because they were not just trying to sell new satellites, they're trying to sell this tool to people who have satellites in orbit and -- and you can update them over the air. You know, if they're software defined, they're software capable of being updated, which, you know, all the satellites in these new LEO mega constellations are, then, you know, you could upload, silent shield to your satellite and -- and it will be protected, not just on the ground, but actually, you know, in orbit itself. And then -- and then the final initiative was an initiative, well, it's a Space Force contract, actually, with a couple of startups to build a tool that will look, not in the software, but in the behavior of the satellite itself. You know, what's it doing, what's it transmitting, is it maneuvering, what's its orbital status and where's it pointed, is it pointed in the right direction?
Maria Varmazis: Yes.
Shaun Waterman: All of this stuff. It's dangerous to rely on telemetry for detection, you know, because one of the things that a hacker might be able to do, and this is a -- a big part often of hacking operational technology systems, is you get the system to keep sending telemetry that says everything's fine. I mean, that was how Stuxnet worked, right? The weapon that was deployed against the Iranian nuclear program, these centrifuges that spin at enormous speeds to enrich uranium, started shaking themselves to pieces and the Iranians couldn't figure out why because everything, all the telemetry, all the sensors were reporting all normal.
Maria Varmazis: Right. Right.
Shaun Waterman: So, that's an important problem. And that -- and that Space Force have focused on. That's called the cyber resilience on orbit.
Maria Varmazis: Time for a quick break now. When we come back, Shaun Waterman details why behavior is the key indicator for security incidents with spacecraft. Here's a hint. How often do you see space-based CVEs? Yes. More on that after this. [ Music ] And we're back. Here's more of my conversation with journalist Shaun Waterman, jumping back in with indicators of behavior and what that means.
Shaun Waterman: So, indicators of behavior look at things other than the software to figure out if there's an intruder in the system. Part of the reasoning for that is that there isn't in space a -- a tradition like you have with earthbound IT systems of you know, people finding vulnerabilities and reporting them and this huge bank of CVEs which are reported and validated software flaws. This is how a lot of detection is done in -- in earthbound cyber, through looking for the indicators of compromise that show that a particular CVE is being exploited. Now, in -- in space, because you don't have this huge database of like previously discovered vulnerabilities, it might be much harder to detect a cyber-attack just through looking at the software itself. Especially because so much of the kit is, you know, it's -- it's sort of nonstandard.
Maria Varmazis: Yes, it's custom per -- per satellite in some cases. Right?
Shaun Waterman: Absolutely. And especially --
Maria Varmazis: Yes.
Shaun Waterman: -- with the big, the sort of legacy geo satellites in -- in geostationary orbit. These huge exquisite satellites, they have custom-built hardware like absolutely custom and it's run with firmware embedded software. Very difficult to analyze, very difficult to detect potential attacks. The indicators of behavior are a sort of collateral way really of -- of protecting an attack. You know, not looking directly at the software but looking at possible impact that it's having on the way the satellite is actually behaving. The drawback --
Maria Varmazis: Yes.
Shaun Waterman: -- Maria, is that indicators of compromise, if they're done in the right way are pretty deterministic. Right? If you see this, you know it's an attack, you know it's exploiting the following CVE, you know its blast radius might be X, Y or Z. With indicators of behavior, it's much more probabilistic, you know. Well, this looks like it might be X, Y or Z. That's the $64,000 question because, or challenge because you know, if you're trying to empower satellite owners and operators to defend their assets, but they really need a yes or no answer, they're not going to mess with a multimillion dollar orbital asset, you know, because it might be, you know, something might be up. So, yes. But that's, I mean it is -- it is --
Maria Varmazis: That's fascinating.
Shaun Waterman: -- it is very interesting because it just, you know, it's -- it's --
Maria Varmazis: That is.
Shaun Waterman: -- cyber is not one thing and certainly not in space. You know, it's -- it's -- there's multitude of sort of different approaches that you have to take, this multi-layer defense to protect these assets.
Maria Varmazis: Now, we were talking a lot about, you know, when we're thinking of the more custom, the exquisite. I love that word that you use, the exquisite satellites and GO. You know, the huge military, especially assets. But I'm thinking for the proliferation of more commercial constellations in LEO, do we see the paradigm changing dramatically or maybe not at all when we're thinking about that, or maybe is it too early to even be thinking about we've got these constellations in LEO that are more commercialized. Will they have their own custom Linux distro that they're running on or is it going to be sort of a similar situation? Well, that's a really interesting question. So -- so, the big LEO mega constellations are all vertically integrated, right? So, you know, it's a Starlink dish, it's a Starlink satellite, it's Starlink hardware, it's Starlink software all the way up and down the chain. At least with SpaceX, you know, they have used or -- or tried to make much more use of commodity hardware, you know, regular chips and yes, running -- running Linux. I actually don't know what the operating system for -- for Starlink is. I mean the firmware for the -- for the dish has been taken down a couple of times I think by -- by researchers at Black Hat and DEF CON. Obviously, the satellites themselves, that's a very different kettle of fish. And -- and I don't know -- I'm not aware that anyone's you know, done any sort of work trying to tinker with that. But, yes, I think the -- the -- the big LEO constellations, we are seeing a lot more commodity. You know, just because the scale, you can't, you know, you're not going to build your own -- your own chips. You know, if you're putting 20,000 satellites into orbit, that is not going to -- Truly, yes.
Shaun Waterman: -- work out.
Maria Varmazis: Yes, and -- and SpaceX's vertically integrated approach, they're SpaceX, they're the big you know, exception to a lot of things. And they've -- they've been able to do that walled garden approach. But certainly, at least if -- if we listen to what the space industry's saying about the way things are going to be going, they certainly won't be the only dominant player doing what they're doing if we give it enough time. And at some point, I wonder, they've been sort of able to keep things walled off and -- and relatively protected, but there are going to be a lot more constellations out there that probably won't be as vertically integrated as Starlink's is. I -- I can't help but wonder what's going to happen.
Shaun Waterman: Well, I mean it's going to be very interesting. Amazon, LEO, you know, which is probably going to be the first -- well, there's -- actually there's one other operative LEO constellation out there. But I think it's one where Amazon LEO is coming online, I -- I believe this year, is scheduled to come online and you know, and to have a global coverage next year. So, and -- and they are apparently it seems taking a less walled garden approach. Although you know, I mean it's all within the Amazon ecosystem. But I think the objective from Amazon is that those AWS customers find it much easier to integrate the LEO connectivity.
Maria Varmazis: Yes. Yes.
Shaun Waterman: You're -- you're right though. It is. And you know, there's going to be, I mean there's also all of the Earth observation constellations and you know, there's just, there's so much activity up there in orbit now. And a lot more of it I think is going to be using commoditized hardware and software. Kratos is creating -- has created an open-source management platform for satellites. So, and -- and the virtualization as well. I mean this is back on the ground replacing hardware switches and modems with -- with software. You know, again that arguably does open up the attack surface. So, the convergence of cyber and space I think is unfortunately is -- is going to create a lot of risks for space. Space assets have traditionally been protected at least from nation state attack by these very strong norms that all the superpowers have demonstrated kinetic antisatellite capabilities. None of them have ever used them. Part of the reason is that it's clearly a red line. You know, if you're doing nuclear command and control through your satellites and the adversary starts to mess with them, that is a very bright thick red line that's been crossed, and people generally don't want to do that. But -- but in cyberspace, there's just aren't the same norms. Historically, there's been no penalty for attacking in cyberspace and frankly that's -- that's a little worrying.
Maria Varmazis: Oh, it's a lot to think about, Shaun. Thank you again so much for speaking with me. I greatly appreciate it.
Shaun Waterman: Oh, it was lovely. I enjoyed it, Maria. And I'll come back anytime.
Maria Varmazis: And that is "T-Minus Space Cyber Briefing" brought to you by N2K CyberWire. If you like what you heard today, you will also enjoy our newsletter "Signals and Space." You'll get research and notes pulled together by our producer Ethan Cook and me, along with this week's top space cyber news stories. Subscribe by visiting thecyberwire.com/newsletters. We'd love to know what you think of our podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing cyber security landscape. If you like our show, please share a rating and review in your podcast app. You can also fill out the survey in the Show Notes or just send us an email. Space@N2K.com is how you can get in touch. We are proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector. From the Fortune 500 to many of the world's preeminent intelligence and law enforcement agencies, N2K helps cybersecurity professionals grow, learn and stay informed. As the nexus for discovery and connection, we bring you the people, the technology and the ideas shaping the future of secure innovation. Learn how at n2k.com. Thank you for listening to "T-Minus." I am your host, Maria Varmazis. The show is produced by Ethan Cook and Liz Stokes. We are mixed by Elliott Peltzman and Tre Hester with original music by Elliott Peltzman. Our executive producer is Jennifer Eiben with content strategy by Mayan Plaut. Peter Kilpe is our publisher. Thanks again for joining us. See you next week.
