SearcharxivSearch

arXiv subjects

Peilong Liu

Publications and source records attributed to Peilong Liu.

3 recordsLinked to original sources

A Consolidated Game Framework for Cooperative Defense Against Cross-Domain Cyber Attacks in Satellite-Enabled Internet of Things

As the adoption of satellite-enabled Internet of Things (IoT) continues to rise, its intricate multidomain architecture becomes increasingly susceptible to cross-domain cyber threats. Attackers can exploit compromised IoT devices, inject malicious packets into data streams aggregated at the IoT gateway for satellite backhaul, and potentially endanger the satellite network during transmission by exploiting the hardware, software, and protocol vulnerabilities. Compared to single-domain defenses, cooperative defense at the IoT devices, IoT access network, and satellite transmission network provides fine-granularity defense against cross-domain intelligent attacks. However, quantifying cross-domain impacts and tilting incentive misalignment among different participants remain significant challenges, making systematic cooperative defense development a complex task. To address this, we develop a tripartite security game framework to characterize the impacts of attacks and defense methods across both the terrestrial and satellite domains. Leveraging this game model, we devise flow pricing to optimally motivate the IoT network operator (IoT-NO) to prevent malicious packet infiltration into the satellite domain. Subsequently, we propose efficient learning algorithms enabling both the IoT-NO to ascertain their ideal flow sampling strategies and the satellite service provider (SAT-SP) to determine optimal flow pricing. The simulation results corroborate the effectiveness of the consolidated game in counteracting cross-domain cyber attacks and facilitating cooperative defense between the IoT-NO and the SAT-SP with nonaligned incentives.

cs.GT

Toward Secure Operation and Management (O&M) of Satellite Constellations: Efficiency, Resilience, and Reliability in a Network Perspective

Satellite constellations equipped with Inter-Satellite Links and onboard packet switching enable real-time Operation and Management across globally distributed satellites, but also broaden the attack surface and introduce unprecedented cybersecurity threats. Existing efforts mainly focus on cryptography for single-satellite point-to-point links, without considering constellation-level security. To address this gap, this article extends security research in two directions: from individual satellites to constellation-wide architectures, and from isolated cryptography to system-level security incorporating efficiency, resilience, and reliability. These extensions raise three key questions: how to design efficient security mechanisms for dynamic constellation topologies with adaptive onboard routing; how a constellation O&M system can recover resiliently under worst-case failures of onboard security functions; and how to improve the reliability of onboard security functions under stringent resource constraints. To address these challenges, we first construct a constellation-wide hybrid security framework that protects semantically sensitive content fields using End-to-End encryption, while safeguarding routing-related fields through Moving Target Defense. Next, we introduce a ciphered-mode and safe-mode management mechanism with an M-delayed fallback that balances recovery timeliness and exploitability. Finally, we propose security-aware routers that manage plaintext/ciphered modes and coordinate access to a shared pool of onboard cipher modules, enabling redundancy sharing across multiple endpoints and extending secure operation duration in ciphered mode. These solutions comply with existing standards defined by organizations including DVB and the CCSDS, while translating conceptual security principles into practical system-level mechanisms.

cs.CE

STARDIS: Strategic Scheduling and Deceptive Signaling for Satellite Intrusion Detection System Deployment

Satellite communication networks operate under stringent computational constraints and are susceptible to sophisticated cyberattacks. This paper introduces a novel defense framework that decouples security optimization into ground-based analysis and onboard real-time execution. In the long-term loop, the ground segment processes historical data to estimate key statistical parameters of the task environment. Additionally, we incorporate the time-varying characteristics of satellite wireless links to account for the dynamic communication context. In the short-term loop, the satellite employs a receding horizon optimization that models dynamic task arrivals and maximizes a utility function considering detection rates and resource costs. To counter intelligent adversaries interception, we introduce a deception mechanism using Bayesian persuasion theory. By strategically manipulating the short-term action sequences in the telemetry downlink, we mislead an external attacker's beliefs. We mathematically model the attacker's optimal response under channel uncertainty and demonstrate that our framework significantly reduces attacker utility. The approach's effectiveness is formally proven using Lyapunov theory.

cs.GT