Conference item
Watch this space: securing satellite communication through resilient transmitter fingerprinting
- Abstract:
- Due to an increase in the availability of cheap off-the-shelf radio hardware, signal spoofing and replay attacks on satellite ground systems have become more accessible than ever. This is particularly a problem for legacy systems, many of which do not offer cryptographic security and cannot be patched to support novel security measures. Therefore, in this paper we explore radio transmitter fingerprinting in the context of satellite systems. We introduce the SatIQ system, proposing novel techniques for authenticating transmissions using characteristics of the transmitter hardware expressed as impairments on the downlinked radio signal. We look in particular at high sample rate fingerprinting, making device fingerprints difficult to forge without similarly high sample rate transmitting hardware, thus raising the required budget for spoofing and replay attacks. We also examine the difficulty of this approach with high levels of atmospheric noise and multipath scattering, and analyze potential solutions to this problem. We focus on the Iridium satellite constellation, for which we collected 1 705 202 messages at a sample rate of 25 MS/s. We use this data to train a fingerprinting model consisting of an autoencoder combined with a Siamese neural network, enabling the model to learn an efficient encoding of the message headers that preserves identifying information. We demonstrate the fingerprinting system’s robustness under attack by replaying messages using a Software-Defined Radio, achieving an Equal Error Rate of 0.120, and ROC AUC of 0.946. Finally, we analyze its stability over time by introducing a time gap between training and testing data, and its extensibility by introducing new transmitters which have not been seen before. We conclude that our techniques are useful for building fingerprinting systems that are stable over time, can be used immediately with new transmitters without retraining, and provide robustness against spoofing and replay attacks by raising the required budget for attacks.
- Publication status:
- Published
- Peer review status:
- Peer reviewed
Actions
Access Document
- Files:
-
-
(Preview, Accepted manuscript, pdf, 1.6MB, Terms of use)
-
- Publisher copy:
- 10.1145/3576915.3623135
Authors
- Publisher:
- Association for Computing Machinery
- Host title:
- Proceedings of the ACM Conference on Computer and Communications Security (CCS 2023)
- Journal:
- Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security More from this journal
- Pages:
- 608–621
- Publication date:
- 2023-11-21
- Acceptance date:
- 2023-09-02
- Event title:
- ACM Conference on Computer and Communications Security (CCS 2023)
- Event location:
- Copenhagen, Denmark
- Event website:
- https://www.sigsac.org/ccs/CCS2023/
- Event start date:
- 2023-11-26
- Event end date:
- 2023-11-30
- DOI:
- ISBN:
- 9798400700507
- Language:
-
English
- Keywords:
- Pubs id:
-
1521655
- Local pid:
-
pubs:1521655
- Deposit date:
-
2023-09-06
- ARK identifier:
Terms of use
- Copyright holder:
- Smailes et al
- Copyright date:
- 2023
- Rights statement:
- © 2023 Copyright held by the owner/author(s). Publication rights licensed to ACM
- Notes:
- This paper will be presented at the ACM Conference on Computer and Communications Security (CCS 2023), 26th-30th November 2023, Copenhagen, Denmark. This is the accepted manuscript version of the article. The final version will be available online from Association for Computing Machinery: https://doi.org/10.1145/3576915.3623135
If you are the owner of this record, you can report an update to it here: Report update to this record