Search arXivSearch

arXiv subjects

Roy Peled

Publications and source records attributed to Roy Peled.

2 recordsLinked to original sources

JANUS: Denial-of-Service Attack Against Beam Hopping in LEO Satellite Networks

Low Earth orbit (LEO) satellite networks are increasingly used to provide global connectivity. However, each satellite has limited resources that need to be allocated according to demand, which varies geographically and over time. Beam hopping addresses this challenge by dividing a satellite's service area into geographic cells. Rather than illuminating every cell simultaneously, it dynamically assigns available beams to a selected subset based on demand. This reliance on observed traffic demand as an input to beam-selection decisions creates a new attack surface whose security implications have received little attention. In this paper, we present JANUS, a novel targeted denial-of-service attack against beam-hopping systems in LEO networks. We show that a small botnet of compromised terminals can inject legitimate user traffic into carefully selected non-victim cells to manipulate the beam-hopping scheduler's view of demand. This manipulation alters beam-allocation decisions and redirects service away from the targeted victim area. We evaluate JANUS across different system configurations, schedulers, attack horizons, and attacker-knowledge settings to characterize the attack's effectiveness, required resources, and resulting service disruption over time. Against a rank-based KMAX scheduler, JANUS achieves complete service denial for up to approximately 95% of evaluated victims. Against DRL, JANUS can exclude the victim from approximately 92% of scheduling decisions. Finally, we evaluate mitigation strategies that reduce the attack effectiveness.

cs.CR

Rethinking Satellite Cybersecurity: A System-Level Taxonomy and Longitudinal Analysis

Satellite systems are increasingly targeted by cyber and electronic-warfare adversaries as their roles in communication, navigation, Earth observation, and defense expand. Existing surveys do not comprehensively characterize adversarial behavior across the full attack lifecycle and often omit emerging attack surfaces such as adversarial machine learning (AML). This paper presents a satellite-specific taxonomy of tactics, techniques, and procedures (TTPs), developed primarily for low Earth orbit systems and informed by evidence from LEO, MEO, and GEO missions. We analyze the space, ground, communication, and user segments to identify architectural exposures and operational attack surfaces, and compile a dataset of more than 200 publicly reported satellite incidents from 1962 to 2026, including over 80 incidents not covered in prior work. Longitudinal analysis reveals shifts toward ground-segment compromise, GNSS interference, communication disruption, proximity-based counterspace activity, and deception-oriented attacks. Building on these findings, we propose a MITRE ATT&CK-inspired satellite attack lifecycle taxonomy that integrates subsystem exploitation, radio-frequency interference, on-orbit operations, AML, and deception techniques. We demonstrate its practical utility through case studies of the 2022 Viasat KA-SAT cyberattack and a simulation-based ICARUS constellation-scale denial-of-service scenario. The framework combines longitudinal evidence, real-world incidents, and emerging attack modalities to support threat modeling, defensive planning, and the design of detection and mitigation strategies.

cs.CR