Ilmu Komputer & AI editorial
An Empirical Security Analysis of Open-Source Software Used in Onboard Satellite Systems
The core problem
Innovation
The analysis produced 2,827 findings, revealing that security issues are widespread but unevenly distributed. Key quantitative results include:
- **Severity distribution:** Medium-severity findings account for 49% of the dataset. When combined with high and critical findings, 72% of all findings are classified as medium severity or higher. This indicates that the majority of issues are not trivial and may require attention.
- **Weakness families:** The CWE-based taxonomy assigns all findings to eight weakness families. The dominant families are **Memory Safety** and **Code Quality**, followed by **Input Validation** and **Injection**. This distribution suggests that fundamental programming errors and resource management issues are prevalent.
- **Code origin:** Most findings occur in project-developed code, accounting for 81.4% of the dataset. External dependency code remains a relevant source of findings, though to a lesser extent.
The results highlight that while OSS brings benefits, it also introduces a significant number of security weaknesses. The concentration in project-developed code suggests that development practices within the satellite OSS community may need improvemen
Why it matters
The findings offer an empirical characterization of recurring security patterns across the open-source onboard satellite software ecosystem. While the study does not establish mission-specific exploitability, it quantifies prevalence and helps prioritize areas for security attention. The dominance of Memory Safety and Code Quality weaknesses is particularly notable: in embedded and resource-constrained environments like onboard satellite systems, memory safety issues can lead to unpredictable behavior, and code quality problems may exacerbate maintenance and patching challenges. The fact that 81.4% of findings are in project-developed code suggests that the satellite OSS community may benefit from stronger secure coding practices, code review processes, and automated testing. External dependencies still contribute findings, highlighting the need for continuous dependency monitoring.
The severity distribution—with 72% of findings at medium severity or higher—indicates that many issues warrant remediation. However, the authors caution that these findings do not necessarily imply exploitability in a mission context; rather, they represent potential weaknesses that could be exploited under certain conditions. The study's pipeline approach, combining SBOM, SCA, SAST, IaC analysis, and secret scanning, proves effective for large-scale empirical analysis. Future work could extend this to dynamic analysis or mission-specific threat modeling.
From a taxonomy perspective, the eight weakness families align with established cybersecurity categories, but the specific distribution in onboard satellite systems may differ from terrestrial software. This underscores the need for domain-specific security guidelines. The results also have implications for supply chain security: while project-developed code is the primary source of findings, external dependencies introduce additional risk that must be managed through vetting and monitoring.
In summary, this study provides a foundational empirical baseline for security in onboard satellite OSS. It highlights that security findings are widespread but unevenly distributed, with memory safety and code quality as the most prevalent weakness families. The findings can inform prioritization for developers, maintainers, and mission planners aiming to harden satellite software against cyber threats.
Who should read this
Opening member content…