This Blog has Moved!

This blog is moving to


Thank you for visiting! Content will remain here for archival purposes.
Showing posts with label NASA. Show all posts
Showing posts with label NASA. Show all posts

Hacking a Space Probe For Science! The @ISEE3Reboot Project

This is the fourth article in my series on Space Security.

Today NASA announced that it signed an agreement which will legally allow the ISEE-3 Reboot Project to contact, and literally "hack" the ISEE-3/ICE probe in order to redirect it into a new orbit for future scientific studies.

ISEE-3 was originally launched in 1978 to study space weather.

In 1982, it was redirected to a new orbit, and was used to study several comets, including Halley's Comet.

The probe was supposed to be powered down in the late 1990's, but in 2008 it was discovered that the probe was still functional, and would most likely still work on its return orbit to Earth, 31 years after it departed from its original orbit.

However, there was a problem; NASA no longer has the equipment needed to communicate with the probe. In fact, the hardware no longer exists.

As a result, a small group of engineers put together a crowdfunding campaign to redirect the probe into a stable orbit under the ISEE-3 Reboot Project, and resume its original mission of studying space weather.

So far, one of the biggest challenges faced by the project is that the team must take the entire set of commands understood by the probe (which were originally generated by hardware), and recreate them using software defined radio.

In order to take over this probe, the team is relying on documentation provided by former engineers of the ISEE-3 project, and hopefully documentation which can be acquired through the Space Act Agreement which NASA signed today.

For those interested, here is a publicly released document with the technical details of the ISEE-3 probe, including communications frequencies.  However, unless you have an antenna the size of the Arecibo Observatory, don't expect to be able to take over this probe yourself.  In other words, don't try this at home kids.

ISSE-3/ICE Telecommunications Summary


Also, the team has put together a YouTube video for your viewing pleasure.


NASA Open Source - Cyber Security Applications in Space and on the Ground

This is the third article in my series on Space Security.


NASA has recently released its 2014 Software Catalog, featuring a comprehensive list of software titles available for US Government Only, as well as Public use.

Here is an overview of some of the more interesting titles available.  Note that some titles may need to be acquired by contacting NASA directly.

There are multiple publicly available applications in the list which could be tremendously helpful to public and private organizations helping to secure their networks. It is clear to me that NASA is leading the way in the public sector helping to provide resources which can help secure not only other agencies, but private industry as well.

I'd like to give a HUGE shout-out to NASA for releasing all of these great applications!

Space Security Starts on the Ground

This is the first of a series of articles on Space Security.  In the article series, we will look at the current strengths and weaknesses of NASA's cyber security efforts.


The above video was taken on April 17, 2013 at Wallops Flight Facility during the Antares NASA Social launch event.  In it, Deputy Administrator Lori Garver discusses the importance of Cyber Security and NASA.

NASA was criticized in 2009 by the Government Accountability Office (GAO) for having security vulnerabilities in key networks, despite important progress in securing their computer systems.

Space Security Article Series - Stay Tuned!

I am back from my trip to Wallops Flight Facility and feverishly working on organizing all my notes and recordings to begin my series of Space Security articles.

In the meantime, I'd like to encourage you to check out the pictures and videos I've uploaded from this AMAZING event!

Facebook: https://www.facebook.com/CaffSec

YouTube: http://www.youtube.com/user/CaffeineSecurity


I will be writing a thank you letter to all of the organizations and people who took the time to meet with me, but in the meantime I'd like to give a big shout out to the following organizations:

NASA Wallops
NASA Social
Orbital Sciences Corporation
ATK

Thank you all for helping make the Antares NASA Social event fantastic!

Want to Give Me Feedback During the Antares Launch Event? Call Me!

Because I'm going to be almost completely disconnected for about a week I've added to my blog the ability for you to leave a voicemail to give me feedback for during the Antares launch event.  I will check voicemail nightly and if possible include any feedback in the next day's events.

Thanks!

A Potential Look at the Security Technology Behind #Antares and #Cygnus Remote Control

The main purpose of the Antares rocket is to launch the Cygnus spacecraft - a remotely controlled cargo craft designed to deliver cargo to/from the International Space Station.

Some searching of patents by Orbital Sciences Corporation will reveal a patent from 2009 describing "A secondary payload interface for payload communications using a primary payload communications channel is provided."  This is essentially a space version of a radio repeater or WiFi range extender - and also provides for a redundant communications network to ensure that remote controlled spacecraft and satellites can remain in constant contact with ground control.

The patent discusses the potential for using communications satellites to relay commands remotely:

Although typically built with that single purpose in mind, these satellites may provide platforms for secondary payloads. For example, communications satellites can provide power, thermal control, and attitude control system (ACS) functions, as well as other services, to secondary payloads, such as, for example, earth-observing or weather-monitoring payloads. An auxiliary high rate communications system can be provided on the communications satellite to accommodate the secondary payload.

And good news! The patent is designed with security (encryption) in mind!
In some embodiments, the secondary payload interface may be designed such that control and telemetry interactions with the operators of the primary payload and/or the host satellite (which may be the same or different) are limited. For example, control interactions may be limited to power connections. As another example, telemetry interactions may be limited to discrete telemetry points that provide insight into the basic health of the secondary payload interface. As a result, the secondary payload may still be securely controlled by its operator without involvement by the operations center of the primary payload and/or the host satellite. This approach provides segregation of signals between an encrypted state and a non-encrypted state (e.g., a "red/black" interface) as required by some encryption systems. 

A second possibly related patent by Orbital describes "Emergency Communications Channel Systems and Methods for Satellite Command".  This patent can be accessed here.

This patent creates a backup system for satellite communications - ensuring availability of control if something goes wrong with traditional satellite communications.
To address [...] shortcomings within [remote satellite control], an Emergency Communications Channels (ECC) satellite command system according to one aspect of invention enables commanding of a satellite by remotely modulating telemetry data parameters indicative of the operation of one or more of the satellite's payloads by modulating signals sent directly to the payload from a ground station.  

The two above patents definitely show that Orbital understands the importance of implementing security and redundancy in space systems - and is actively implementing important security concepts in their spacecraft and launch systems.

I look forward to discussing this topic further with them when I visit NASA's Wallops Flight Facility in a few days.

Could you Hack the Mars Rover?

More related reading for my upcoming trip to the Antares rocket launch - this article outlines the difficulties of remotely gaining control of a NASA spacecraft such as the Mars Rover.

http://www.extremetech.com/extreme/134334-could-you-hack-into-mars-rover-curiosity

How Rockets and Spacecraft Are Controlled Remotely

One of the topics I'm hoping to discuss with NASA and Orbital on my upcoming visit to the Antares rocket launch is how rockets and spacecraft are controlled remotely - and how this communication is secured from tampering by outside parties.

I'm not a rocket scientist - and since this really is rocket science - I figured I should start reading up on the topic.

I found on Archive.org a book from 1964 titled "Radio Control of Rockets".  The book was written by two Russian scientists and contributed to by NASA.  It discusses the theory behind remote control of a rocket.

If you're interested in learning more visit the Archive.org page and start reading the book!

If you could ask a question about Space Security what would it be?

I've been given an excellent opportunity to attend the NASA/Orbital Antares rocket test launch at Wallops Flight Facility in Wallops Island Virginia under NASA's social media credentials program.

I hope to learn and share fascinating information such as how remote flight telemetry and control of spacecraft is secured from tampering and interception.  However - since my blog wouldn't be the same without reader interaction - I'd like to take the time to find out what information security related questions my readers would like to have answered.

Please go to Facebook and answer the poll!  Feel free to add your own question if you don't see one listed you're interested in.  Please try to keep questions information security/computer security related.

I will gather questions until a few days before launch - then select the best ones from the poll.