
Closing the space-cyber workforce gap.
Nick Cohen: So it's based on Oregon Trail, but it's in space, and you've got all these space mission considerations. So you have a mission you have to conduct. You've got only so much power available. You're going to be facing threats like space weather, so solar storms coming at your spacecraft, micrometeoroid asteroids. You've got cyber actors trying to attack your spacecraft. You've got space dysentery that you have to worry about. It's meant to be a relatively light introduction to space cyber, and you learn some interesting things along the way.
Maria Varmazis: Welcome. I'm Maria Varmazis, and you're listening to "T-Minus, Space-Cyber Briefing." In this show, we examine the evolution of cybersecurity in the global and orbital infrastructure that powers, protects, and connects our lives. [ Music ] Hi, everybody. Thank you for joining me today. Today's show is a look back at much of the space cyber activities that went on at DEF CON 34. And if you weren't at this year's Hacker Summer Camp, don't worry, you are not alone. We are going to fill you in today on what was shared and how you can kick the tires yourself. Joining me today as my space cyber sherpa for DEF CON 34 is Nick Cohen, principal engineer at the Aerospace Corporation. And I say it every episode, but especially for today's show, there are lots and lots of links in the show notes, as we're going to be talking about a lot of great space cyber resources that you will want to check out for yourself, frameworks, CTFs, simulations, and oh yeah, the learning game that can give you space dysentery. It's educational, I promise. Let's dive in.
Nick Cohen: So, I work at the Aerospace Corporation in the space cyber group. So I've been doing that; I've been at Aerospace for coming up on 20 years now. So I've been doing it a while. Actually got my job there at a poker game. I met-- I was at--
Maria Varmazis: Wait, wait what?
Nick Cohen: I wish I could say, you know, I won a big hand, and there was a job on the line, but it wasn't quite that exciting. But a friend of mine was hosting a poker game, and I just sold a company that I had started before Aerospace, and I was looking for something new to do. And one of my friend's friends was a hiring manager at Aerospace, and he was looking to expand the department. So we got to talking over the table during some slow hands, and it just sounded like a really exciting opportunity. And so I went over to Aerospace and started off in systems engineering. I was looking at how spacecraft fail, doing a lot of studies on that, which was actually a great introduction to space for me. Just finding out how spacecraft fail taught me a lot about how they're supposed to operate. And then a few years after that, in 2014, I moved over to aerospace cyber. It was just an area that I was really interested in and wanted to get back to working more hands-on with computers, and cyber was really growing at the time. So it was just a really good opportunity to move over there. So I've been doing that since 2014 and been having a lot of fun with it. I work on a lot of different things, a lot of defensive cyber opportunities for spacecraft and ground systems. So it's just given me a chance to work on a lot of different exciting projects and programs.
Maria Varmazis: That's so cool. Nick, thank you so much for joining me, and thank you for speaking with me today. I could probably pick your brain about a million things, but I'm going to focus today on DEF CON 34, which just happened recently. You were just there. And I know there was a lot of good stuff going on at this year's DEF CON. So why don't we start with, I guess, the high level. You were telling me earlier, you've been a few times to DEF CON, and every year is always different. I wasn't there. It's been a little while since I've gone. I want to say it's been about a decade. So it's been a while. I guess let's start with your impressions of this year's DEF CON. And I suppose we'll try to focus on the aerospace side of things, because the entire Defcon is probably a whole other show. But how did it go for, you know, the space hacking side of things for DEF CON this year?
Nick Cohen: Yeah, it went really well. So we were spending all of our time at the Aerospace Village, you know, tried to get a little bit out and explore other things, just because there's so much going on at DEF CON that's really fun and interesting and, you know, fun to explore. But we were hanging out mostly at the Aerospace Village, which is a relatively new thing, I think, in the past few years at DEF CON. So, you know, we started kind of getting involved with the Aerospace Village as part of Hack-A-Sat, the space security challenge that started and ran for four years. So we were involved in helping with that. And then we wanted to stay involved. So Hack-A-Sat, as a big production, kind of had its finale and hasn't been happening in the past couple of years. But we want to keep a space element involved. And so we've been continuing to show up at the Aerospace Village and bring challenges, bring fun things for people to try hands-on every year since then. So that's what we were doing this year. We brought some challenges as part of a Capture the Flag called STARPWN. We had some hands-on things people could do. We had some 3D-printed antennas that they could control. We had a real industrial control system controller that people could try and hack into. And when they did, they were actually able to connect to the antenna site and make things happen. So that was kind of cool. It wasn't just kind of a virtual challenge. You actually see something tangible when you get success, and you actually can see the antenna move.
Maria Varmazis: Oh, that's the best.
Nick Cohen: Yeah, people really enjoyed that. I think those were busy the entire time.
Maria Varmazis: Tell me a bit about STARPWN, how that went this year. Because I was watching online on the various social media channels to see how people were reacting to it. And it sounded like people really enjoyed it. It was a really good challenge. So tell me about what your impressions were.
Nick Cohen: Yeah, so I didn't get a chance to actually try it myself. I was just kind of keeping an eye on it and seeing how people were working on it. But yeah, I think people had a really fun time with it. It's kind of a chance to give people exposure to space systems, you know, how they might be vulnerable to cyberattacks and how we could protect them better. And just get people interested in thinking about it with Capture the Flag challenges. You know, Capture the Flags are really popular at DEF CON. And so it's kind of an easy way for people to sit down. And even if they have very little experience, you know, just try some simple challenges first. And it goes all the way up. So if you've got really good hacking skills, a lot of knowledge of how space systems and industrial control systems operate, there's going to be something challenging all the way up. But it's kind of a fun thing to actually try out. So it was really popular. I think a lot of people were trying it out. It was a good collaboration. So we were working with Aerospace Village, with several other companies that were helping put it together. So we were just one contributor as part of a big team, which was really cool, too.
Maria Varmazis: That's awesome. And obviously, we can't talk too much about, like, specifics of who competed because that's a huge no-no. But I'm curious about sometimes for CTFs, people want to be a part of them if it's in a certain area, like in this case, in space. But they go, "I don't know specifically the rules of the road for this domain, but I want to learn." Were there people who were, you know, just kind of going, this really interests me. I don't know necessarily how to get started here, but I'd like to participate, like a fly-on-the-wall situation? Or what was your impression of the people who were competing?
Nick Cohen: Yeah, that's always been the case. Every year we come, we get kind of a range of people with different knowledge, different expertise. Sometimes they know a lot about space, but not a whole lot about cyber. Sometimes they know a ton about cyber, and they're interested in learning more about space. And sometimes it's all kind of a new thing to them, and they're just walking around the con and trying to try something new. So the nice thing is, you know, when you put together some challenges, you want to make it interesting for all kinds of people, different backgrounds, different expertise, to be able to sit down and have fun. So, you know, that's happened every year. You get all kinds of different people trying it out. We encourage people sometimes to just try some of the easier challenges and see how they do with that. We also encourage people to maybe find a team. So meet someone new if you haven't, you know, done something like this before. Try and group up, and then you can learn from each other too. It's always pretty awesome when you get a team of people, and each of them is contributing something unique.
Maria Varmazis: That's awesome. Yeah, I love seeing that magic happen. As someone who just often-- just stand back and witness, it's the best. It's one of the highlights for DEF CON for me when I've been.
Nick Cohen: It's definitely getting us kind of out of our natural element. You know, we're--
Maria Varmazis: We have to talk to people.
Nick Cohen: We have to talk to people. Strangers, what?
Maria Varmazis: Yeah, I know.
Nick Cohen: But it's a good exercise. And, you know, it's more comfortable when you know that everybody else is-- hey, you have a common interest. Everybody else is shy and introverted, you know, tend to be like you are. It just makes it a little bit easier, in my experience, to meet people.
Maria Varmazis: I totally agree. I totally agree. And we were all there for the similar reason. And going in there with a learner's attitude of, I don't know a lot about this, but I want to learn, and I want to figure it out. People I've found at DEF CON are very receptive to that. I guess that's a pro tip for newbies who are going next year. Just people really are receptive to that, contrary to what you might have heard. So it's a great place to learn. It's such a great place to learn.
Nick Cohen: Yeah, everyone is there to learn. And everyone is there to talk about stuff that they're passionate about, really interested in.
Maria Varmazis: Yeah, we're there to nerd out.
Nick Cohen: Yeah, exactly. I've always felt like no one-- I've never gotten like anything but a super positive response when I just ask someone, like, why is that antenna sticking out of your backpack? Or, you know, tell me about, you know, this thing you have going on at your table.
Maria Varmazis: Yeah, yeah. Not an uncommon sight at DEF CON either. Definitely not. Yeah, I'm kind of missing it right now. I'm like, "Oh man, I should go next year."
Nick Cohen: You should.
Maria Varmazis: So we've talked a bit about STARPWN, and I know that there were a lot of other things that you all were working on and had at the Aerospace Village this year. And one of them was not just Space Trail, but there was also SpaceCOP. So lots of space going on. So tell me about those.
Nick Cohen: Yeah, so SpaceCOP is-- this is a kind of a software prototype, software project that Aerospace has been working on for several years now. But we were actually able to release it open source this year. And so Brandon Bailey, who I think you interviewed back in April on this podcast.
Maria Varmazis: Yeah, I've interviewed him a few times. Back when SPARTA was, like, brand new even. That was years ago. So yes, yeah, I spoke to him a few times. Yeah.
Nick Cohen: Yeah, Brandon is awesome. So he gave a talk and was actually able to talk a little bit about how do you defend spacecraft themselves? So, you know, we always talk about how do you defend ground, kind of terrestrial IT systems. So you're protecting Active Directory, Linux, making software more secure. But, you know, how do you protect a spacecraft, which is a very specialized computer system? So SpaceCOP is a way to do that with a prototype we've developed to actually run intrusion detection on board the spacecraft. And so we were able to open source it and release it to the community this year. And so Brandon gave a talk and made the official announcement and talked a little bit about why we did that, you know, what kind of considerations went into it. And so we're excited about that. So it's based on several years of research. Again, you know, Randy, who worked on Space Trail as well, she and several other folks on her team contributed quite a bit to the SpaceCOP Community Edition. We had sponsorship from the Department of Homeland Security, Science and Technology to actually make that happen, which was really cool. So it's, you know, I'm really excited. It's just like it's a way to, you know, we do so many things kind of behind closed doors. This is a way to actually, you know, put some of our work out into the community, let people see it, share it, contribute to it, hopefully, and make it a much wider audience that's able to use it.
Maria Varmazis: Yeah, I will for sure make sure that we have links to that, for the GitHub link to SpaceCOP, because I'm sure a lot of people listening right now are going, "I want to download that immediately." And in terms of, you know, expertise needed or hardware needed even, like what-- is this for people who are just starting? Like what's the expectation of expertise needed and gear for that kind of thing?
Nick Cohen: Yeah, we try to make it kind of as easy to get up and running quickly and easily as possible. It takes a little bit of experience, maybe with Linux. So it's-- but it's based on an open-source satellite simulator from NASA, which, you know, again, like that's awesome that they provide that out to the community, but it's called NOS Cubed. So that's available on NASA's website. We based it on NOS Cubed. So it's kind of an application that runs alongside NOS Cubed, and it's very tightly integrated into NOS Cubed. So it comes-- when you set it up as a kit, the NOS Cubed setup comes with a satellite simulator, a ground simulator, and a kind of dynamics physics simulator to make the spacecraft think that it's actually orbiting the Earth in space.
Maria Varmazis: That's awesome.
Nick Cohen: So yeah, it's really cool.
Maria Varmazis: That is super cool.
Nick Cohen: Yeah, you can visualize it orbiting the Earth. You can, you know, you can mess with it. In some ways it looks a little bit like Kerbal Space Program, maybe a little bit less polished from a game perspective. Oh, a lot of people's ears just perked up. Oh man, that's all you needed to say. You should have led with that, Nick. That's fantastic, honestly. Yeah. It's a little bit less polished than that maybe, but it's just very cool that it's actually got like some real physics behind it. It's running software that is actually running on real spacecraft. NASA launches their-- so it's based on core flight services, CFS software, which NASA actually launches onto a lot of their missions. So you can list maybe a dozen or two missions that actually run CFS. So it's very realistic.
Maria Varmazis: That's fantastic, yeah.
Nick Cohen: So this is a chance to actually try, you know, some cyber things against spacecraft. So, you know, try hacking it and then you run SpaceCOP integrated into it. And then you can see how to actually defend against those.
Maria Varmazis: That's awesome. This is going to really get a lot of people some fantastic hands-on experience in an area where we need a lot more people to be able to learn this stuff. So that's going to be huge in a good way.
Nick Cohen: Yeah, thank you. That's our hope.
Maria Varmazis: We're going to hop to a quick break now. When we come back, my chat with Nick Cohen of the Aerospace Corporation continues. And yeah, we are finally going to talk about that game that we keep hinting about. And we're back to my interview with Nick Cohen of the Aerospace Corporation. And now we will turn our attention to the game, Space Trail.
Nick Cohen: Space Trail was designed as a space cyber challenge for people that, you know, may come into it with no experience. It's based on Oregon Trail. So, you know, like hopefully a lot of people, you know, have some experience playing Oregon Trail, kind of dating myself. But, you know, going back to like an Apple IIe, you know, I played it all the way back then.
Maria Varmazis: That was the computer I had too. So yeah.
Nick Cohen: Awesome.
Maria Varmazis: Exactly the same one I had, yeah.
Nick Cohen: Who needs a modern, you know, 5090 GPU when you just have your Apple IIe? Yeah, so it's based on Oregon Trail, but it's in space. And you've got all these space mission considerations. You've got-- so you have a mission you have to conduct. You've got only so much power available. You're going to be facing threats like space weather. So solar storms coming at your spacecraft, micrometeoroid asteroids. You've got cyber actors trying to attack your spacecraft continuously. You've got space dysentery that you have to worry about. So it's just kind of like, it's meant to be a fun, relatively-- I won't-- I'll say-- oh, it's hard to say easy, because the game is actually really challenging, but in some fun ways. But it's meant to be a relatively light introduction to space cyber. And you learn some interesting things along the way too. So it's not just completely written as a game. You know, all of the things in there are, maybe except for space dysentery, are based on real things that could happen to a space mission.
Maria Varmazis: Yeah, and I poked around with it and found myself playing it a lot longer than I thought I would. I thought I would just kind of check it out and be like, all right. I was engrossed in it entirely. And again, I don't know if I was the target audience, but I really appreciated that, especially when, you know, you're role-playing certain, you know, cyber scenarios that could occur to a satellite on orbit. It tied it to the SPARTA framework. And it was like, this is sort of the recommend-- these are the optional, you know, recommended paths that you could take here. And these are the possible scenarios that could play out. And that was a great learning tool for me, sort of familiarizing myself with the framework. So it was genuinely very fun and also really got me thinking about a lot of stuff. And I thought it was a fantastic tool and actually genuinely fun game. So yeah, I really enjoyed it. So again, we'll link that for people as well. But I sent it to people who know nothing about cyber or space, and they enjoyed it too. So--
Nick Cohen: Very good.
Maria Varmazis: I don't know if that was the goal, but people actually were going, "Whoa, this is a lot harder than I thought it would be." And I went, "Yeah, I think that's kind of the idea."
Nick Cohen: Yeah, the more it catches on, the better. Yeah, and so Randy told me that the most difficult level still hasn't had anyone beat it yet. So there's a record out there to be set.
Maria Varmazis: Oh, dang. Well, we're going to throw that gauntlet down. I want to hear somebody beating that. And please let us know when you do, and don't send doctored screenshots because we'll be able to tell.
Nick Cohen: That's right.
Maria Varmazis: Yeah, we'll absolutely be able to tell. Anyway, so that is awesome. And I know I mentioned SPARTA just now, and I remember that I got an email right as DEF CON was happening that SPARTA version 4.0 just dropped. Can you tell me a bit about that?
Nick Cohen: Yeah, so Sparta 4.0 has several new tactics, techniques, and procedures. Brandon, Brad, Randy, who are kind of the primary developers on it, they're constantly adding new content. We actually receive a lot now. It's caught on. SPARTA has caught on enough that people are using it, which is just awesome.
Maria Varmazis: That's great.
Nick Cohen: And they're contributing back too. So they get a lot of input from people using it about, "Hey, did you think of this?" Or, "Hey, we thought of this new thing." Or, you know, sometimes like we can't provide details, but, you know, maybe you should add this to SPARTA. So that's just awesome. Like, you know, it's catching on and getting some momentum. And so it's becoming a really good resource that a lot of people can use. So yeah, SPARTA 4.0 has several new tactics, techniques, procedures. Brandon went through and rewrote a lot of the countermeasures. So adding new content on countermeasures, that just gives a lot more detail about how you actually protect against all of the TTPs listed in Sparta. And we've got Space Trail integrated as part of Sparta. Now you can actually reach it from the website. Some new resources, new documents, and kind of implementation guides. So yeah, there's just a whole bunch of new features to check out at SPARTA 4.0.
Maria Varmazis: I wanted to make sure I asked you a little bit about why the Aerospace Corporation was at DEF CON and has been at DEF CON to begin with. Because I think that's a very notable thing that you all are there.
Nick Cohen: Yeah, yeah. So we want to learn and we want to sort of get-- you know, put information out there, you know, contribute to the community. So that all started with our involvements going back to Hack-A-Sat. We were working with the Air Force Research Lab and the core team that was putting together Hack-A-Sat, contributing quite a bit. Not always visible, but, you know, we were kind of part of the team putting that together. And we learned just from the-- just huge amount of interest from Hack-A-Sat, you know, what a big community there is out there that's interested in space cyber. So our participation goes back quite a bit before that. You know, we would always attend to learn and watch talks and participate in CTFs ourselves, you know, kind of participate in DEF CON. Ever since Hack-A-Sat, we've been bringing space cyber challenges, putting a lot of work into that to make something interesting for people to try out and learn from. SpaceCOP, now we're releasing, you know, open source. Brandon has announced several versions of SPARTA at DEF CON now, and it's been a really good opportunity for him and others to-- Brandon's talked, Randy has talked at DEF CON, several others from Aerospace have given talks at DEF CON. So it's a really good audience and place for us to get a lot, share a lot of our knowledge as we're learning and learn from people too. So we're really hoping that as we become more of a member of the community, people participate as well. So, you know, Brandon's gotten a lot of information back where people are adding to SPARTA, kind of leveraging, expanding, you know, what we could do by ourselves at Aerospace. That's really cool. We're hoping with SpaceCOP that people are contributing back to the open source repo on GitHub. We're learning new things from that, new detections, new things that we didn't think of. Games like Space Trail, you know, hoping that people use it, learn from it, want to come up with new things that they can use it for. So that's kind of the hope is just get conversations going, learn, learn. You know, hopefully you find people who are interested in space cyber, get new people interested in it, and become a part of the community.
Maria Varmazis: That's awesome. And, Nick, you all have contributed clearly a lot to help the community grow and increase its expertise. And that's really what it's all about because I know a lot of people who listen to this show are people who are very familiar with cybersecurity in general, people who are practitioners and are interested in space cyber, but are trying to figure out, even if it's just a hobby, but many people are trying to make like a job switch and they're trying to figure out how to get those missing pieces of the expertise in. And it's just wonderful to know that we have places to point people to now, aside from like go back in time and join the military, which was the advice given to a lot of people. You know, it's like there actually are resources now where you can upskill. And the fact that, you know, SpaceCOP exists is awesome. The fact that SPARTA exists is awesome. So that's just, that's fabulous. And I'm curious, Nick, given your expertise, is there, in addition to everything that we've mentioned, I'm sure you got a lot of people asking you at DEF CON and in general, how do I learn more about this? What do you tell people?
Nick Cohen: Yeah. So the SPARTA website is a great place to begin. It's kind of a, first of it's kind of like how, you know, how do you describe what, how spacecraft can be hacked and what to do about it, how to defend them. So SPARTA is kind of a great place to learn that type of stuff. There's-- if you go to the resources tab at SPARTA, there's a whole bunch of talks that go all the way from like, you know, 101 type stuff all the way up to kind of state-of-the-art thinking in that area. And then you can dive in and just go into all kinds of depth about all the different tactics and techniques and countermeasures. Now there's Space Trail. That's, you know, linked on SPARTA. That's a good way to start. Capture the flags, you know, like that's a big thing at DEF CON. That was always my go-to. I learned so much about cyber in general from participating in Capture the Flags. You just learn new techniques. And so things like STARPWN, you know, the space Capture the Flag at DEF CON, that's a really good chance to learn. There are other CTFs, you know, just learning cyber concepts in general. There's still a bunch of resources from Hack-A-Sat out there. So the whole goal of Hack-A-Sat initially was to get people interested in learning more about space cyber. There's actually quite a few resources. So Cromulence, the company that put together a lot of the challenges for the Air Force Research Lab, they're on GitHub. You can actually go back, and you can solve a lot of the original Hack-A-Sat qualifier challenges. Those are really interesting. They range all the way from, you know, pure orbital mechanics and calculating orbits from quaternions and things like that to just very, very, like almost pure cyber. So there's a huge range of things to learn there. So yeah, I think, you know, SPARTA, Space Trail, Capture the Flags, going back to Hack-A-Sat resources. Those are all some really excellent resources, I think, to learn from.
Maria Varmazis: Well, thank you, Nick. This has been such a pleasure. Thank you so much for filling me in on what I missed at DEF CON 34. I have terrible FOMO now, but I also-- the pointers are fantastic. So I know a lot of people listening who also missed DEF CON this year are going to be upscaling like crazy in preparation for next year. So thank you so much for taking the time to speak with me. I really appreciate it.
Nick Cohen: It was my pleasure. Thanks, Maria. I really appreciate the opportunity to come on the podcast.
Maria Varmazis: And that's "T-Minus, Space-Cyber Briefing," brought to you by N2K CyberWire. If you like what you heard today, you will also enjoy our newsletter, Signals in Space. You'll get research and notes pulled together by our producer, Ethan Cook, and me, along with this week's top space cyber news stories. Subscribe by visiting thecyberwire.com/newsletters. We'd love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing cybersecurity landscape. If you like the show, please share a rating and review in your podcast app. You can also fill out the survey in the show notes or send an email to space@N2K.com. We're proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world's preeminent intelligence and law enforcement agencies. N2K helps cybersecurity professionals grow, learn, and stay informed. As the nexus for discovery and connection, we bring you the people, the technology, and the ideas shaping the future of secure innovation. Learn how at N2K.com. Thank you for listening to "T-Minus." I am your host, Maria Varmazis. This show is produced by Ethan Cook and Liz Stokes. We're mixed by Elliott Peltzman and Tré Hester, with original music by Elliott Peltzman. Our executive producer is Jennifer Eiben, with content strategy by Ma'ayan Plaut. Peter Kilpe is our publisher. See you next week.
