Satellite user terminals are a promising target for adversaries seeking to target satellite communication networks. Despite this, many protections commonly found in terrestrial routers are not present in some user terminals. As a case study we audit the attack surface presented by the Starlink router's admin interface, using fuzzing to uncover a denial of service attack on the Starlink user terminal. We explore the attack's impact, particularly in the cases of drive-by attackers, and attackers that are able to maintain a continuous presence on the network. Finally, we discuss wider implications, looking at lessons learned in terrestrial router security, and how to properly implement them in this new context.
翻译:卫星用户终端是攻击者针对卫星通信网络的一个极具吸引力的目标。然而,尽管地面路由器普遍具备多种安全防护措施,部分用户终端却未能实现这些保护。本研究以星链路由器管理界面为案例,通过模糊测试手段挖掘该界面存在的攻击面,发现一种可导致星链用户终端拒绝服务的攻击方式。我们分析了该攻击的影响,特别是针对路过式攻击者以及能够维持网络持续连接的攻击者两种场景。最后,我们探讨了更广泛的影响,借鉴地面路由器安全领域经验,并研究如何在新环境中恰当应用这些经验教训。