Jadwal Sholat

Memuat jadwal sholat…

Ilmu Komputer & AI editorial

Open AccessOA2026

An Empirical Security Analysis of Open-Source Software Used in Onboard Satellite Systems

A pipeline-driven study of 126 public repositories reveals 2,827 security findings, with memory safety and code quality dominating the onboard satellite OSS ecosystem.
Roee Idan; Tomer Cohen Galor; Asaf Shabtai; Yuval Elovici· 2026· DOI 10.48550/arXiv.2609.15425

The core problem

The adoption of open-source software (OSS) in satellite flight systems is accelerating as missions increasingly rely on reusable frameworks, shared libraries, and community-maintained components. This shift accelerates development and reduces costs, but it also introduces software-security risks into systems where patching is costly and failures can directly affect mission operations. The authors—Roee Idan, Tomer Cohen Galor, Asaf Shabtai, and Yuval Elovici—present an empirical security study of OSS used in onboard satellite systems. Their work addresses a critical gap: while OSS security has been studied in terrestrial contexts, the onboard satellite ecosystem has unique constraints, including limited update opportunities and high consequences of failure. The study aims to characterize recurring security patterns across public repositories, quantify their prevalence, and help prioritize areas that warrant the greatest security attention. The central research question is: what are the empirical security characteristics of OSS used in onboard satellite systems, and how are findings distributed across severity levels, weakness types, and code origins?

Innovation

The analysis produced 2,827 findings, revealing that security issues are widespread but unevenly distributed. Key quantitative results include:

- **Severity distribution:** Medium-severity findings account for 49% of the dataset. When combined with high and critical findings, 72% of all findings are classified as medium severity or higher. This indicates that the majority of issues are not trivial and may require attention.
- **Weakness families:** The CWE-based taxonomy assigns all findings to eight weakness families. The dominant families are **Memory Safety** and **Code Quality**, followed by **Input Validation** and **Injection**. This distribution suggests that fundamental programming errors and resource management issues are prevalent.
- **Code origin:** Most findings occur in project-developed code, accounting for 81.4% of the dataset. External dependency code remains a relevant source of findings, though to a lesser extent.

The results highlight that while OSS brings benefits, it also introduces a significant number of security weaknesses. The concentration in project-developed code suggests that development practices within the satellite OSS community may need improvemen

The adoption of open-source software (OSS) in satellite flight systems is accelerating as missions increasingly rely on reusable frameworks, shared libraries, and community-maintained components. This shift accelerates development and reduces costs, but it also introduces software-security risks into systems where patching is costly and failures can directly affect mission operations. The authors—Roee Idan, Tomer Cohen Galor, Asaf Shabtai, and Yuval Elovici—present an empirical security study of OSS used in onboard satellite systems. Their work addresses a critical gap: while OSS security has been studied in terrestrial contexts, the onboard satellite ecosystem has unique constraints, including limited update opportunities and high consequences of failure. The study aims to characterize recurring security patterns across public repositories, quantify their prevalence, and help prioritize areas that warrant the greatest security attention. The central research question is: what are the empirical security characteristics of OSS used in onboard satellite systems, and how are findings distributed across severity levels, weakness types, and code origins?
The authors analyzed 126 public repositories using a multi-stage pipeline that combines several security analysis techniques. The pipeline integrates:

Why it matters

The findings offer an empirical characterization of recurring security patterns across the open-source onboard satellite software ecosystem. While the study does not establish mission-specific exploitability, it quantifies prevalence and helps prioritize areas for security attention. The dominance of Memory Safety and Code Quality weaknesses is particularly notable: in embedded and resource-constrained environments like onboard satellite systems, memory safety issues can lead to unpredictable behavior, and code quality problems may exacerbate maintenance and patching challenges. The fact that 81.4% of findings are in project-developed code suggests that the satellite OSS community may benefit from stronger secure coding practices, code review processes, and automated testing. External dependencies still contribute findings, highlighting the need for continuous dependency monitoring.

The severity distribution—with 72% of findings at medium severity or higher—indicates that many issues warrant remediation. However, the authors caution that these findings do not necessarily imply exploitability in a mission context; rather, they represent potential weaknesses that could be exploited under certain conditions. The study's pipeline approach, combining SBOM, SCA, SAST, IaC analysis, and secret scanning, proves effective for large-scale empirical analysis. Future work could extend this to dynamic analysis or mission-specific threat modeling.

From a taxonomy perspective, the eight weakness families align with established cybersecurity categories, but the specific distribution in onboard satellite systems may differ from terrestrial software. This underscores the need for domain-specific security guidelines. The results also have implications for supply chain security: while project-developed code is the primary source of findings, external dependencies introduce additional risk that must be managed through vetting and monitoring.

In summary, this study provides a foundational empirical baseline for security in onboard satellite OSS. It highlights that security findings are widespread but unevenly distributed, with memory safety and code quality as the most prevalent weakness families. The findings can inform prioritization for developers, maintainers, and mission planners aiming to harden satellite software against cyber threats.

Who should read this

CS practitioners and researchers

Opening member content…