Cybersecurity for Military Satellite Systems: Threats, Domains, and Engineering Countermeasures

Authors

  • William Easttom Vanderbilt University

DOI:

https://doi.org/10.34190/eccws.25.1.4662

Keywords:

Satellite cybersecurity, SATCOM, TT&C, Zero trust, Mission assurance, Space systems security

Abstract

Military operations increasingly depend on satellite-enabled services for beyond-line-of-sight command-and-control, intelligence, surveillance and reconnaissance (ISR), missile warning, and precision navigation and timing. As space becomes more contested, adversaries can achieve operationally significant effects by cyber-compromising the end-to-end satellite enterprise rather than physically destroying spacecraft. A prominent example is the 24 February 2022 KA-SAT incident, where an intrusion into terrestrial management infrastructure and downstream user terminals disrupted connectivity for tens of thousands of users across Ukraine and Europe (CyberPeace Institute, 2022; Viasat, 2022). This paper develops an engineering-oriented threat model for military satellite systems across the ground, link, space, and user segments, then translates that model into implementable security controls and mission assurance design patterns. Using a quantitative, model-based risk assessment (Monte Carlo simulation) and control-to-attack-surface mapping, the paper prioritizes high-leverage mitigations such as privileged access management for mission operations, authenticated command and telemetry protection using standards-based space data-link cryptography, and zero trust architectures adapted to intermittent, high-latency RF environments (CISA, 2024a; CCSDS, 2020). Finally, the paper synthesizes resilience engineering principles—redundancy, graceful degradation, rapid reconstitution, and cyber-informed autonomy—into a pragmatic roadmap that aligns security investments with operational tempo. The central finding is that satellite cybersecurity must be treated as mission assurance: an integrated set of architectural, procedural, and cryptographic controls that preserve capability under sustained cyber pressure and enable recovery within tactically relevant timelines.

Downloads

Published

2026-06-15