Adversarial Assessment of the F Prime Flight Software Framework: Findings and Recommendations
收藏DataCite Commons2024-06-17 更新2025-04-16 收录
下载链接:
http://dataverse.jpl.nasa.gov/citation?persistentId=doi:10.48577/jpl.VJVAMT
下载链接
链接失效反馈官方服务:
资源简介:
F Prime (F') is a multi-platform, open-source flight software (FSW) framework developed by the Jet Propulsion Laboratory (JPL). F' provides a highly capable, component-driven framework tailored towards, but not limited to, small-scale systems like CubeSats, SmallSats, and instruments. We conducted an adversarial assessment of F' aimed at evaluating its security vulnerabilities. This preliminary assessment of F' entailed a multi-stage simulation of a malicious actor's activities, including open-source reconnaissance, passive and active reconnaissance, and exploitation. In this paper, we present our methodology and discuss the preliminary findings of this assessment, which highlighted several areas where F' could be enhanced. These areas include the implementation of encryption for uplink and downlink communication, command authentication, the establishment of community standard cybersecurity practices, remediation of information leakage, and development of an opcode randomizer to provide secure defaults.We expect this preliminary work to inspire further detailed security assessments, and further the design and development of more secure and resilient flight software architectures.
提供机构:
Root
创建时间:
2024-06-17



