Cybersecurity of COSPAS-SARSAT and EPIRB: threat and attacker models, exploits, future research
Andrei Costin, Syed Khandker, Hannu Turtiainen, Timo H\"am\"al\"ainen

TL;DR
This paper examines the cybersecurity vulnerabilities of the COSPAS-SARSAT satellite rescue system, demonstrating practical attacks and proposing mitigations to enhance its security.
Contribution
It is the first to practically demonstrate attacks on COSPAS-SARSAT protocols and discusses key cybersecurity challenges and potential defenses.
Findings
Successful replay, spoofing, and fuzzing attacks on EPIRB protocols
Identification of critical cybersecurity weaknesses in COSPAS-SARSAT
Outline of future research challenges and mitigation strategies
Abstract
COSPAS-SARSAT is an International programme for "Search and Rescue" (SAR) missions based on the "Satellite Aided Tracking" system (SARSAT). It is designed to provide accurate, timely, and reliable distress alert and location data to help SAR authorities of participating countries to assist persons and vessels in distress. Two types of satellite constellations serve COSPAS-SARSAT, low earth orbit search and rescue (LEOSAR) and geostationary orbiting search and rescue (GEOSAR). Despite its nearly-global deployment and critical importance, unfortunately enough, we found that COSPAS-SARSAT protocols and standard 406 MHz transmissions lack essential means of cybersecurity. In this paper, we investigate the cybersecurity aspects of COSPAS-SARSAT space-/satellite-based systems. In particular, we practically and successfully implement and demonstrate the first (to our knowledge) attacks on…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSatellite Communication Systems · Space Satellite Systems and Control
