The exponential increase in the number of satellites in orbit over the last decade, driven by miniaturization and by the use of commercial-off-the-shelf (COTS) components to lower production costs, has exposed these systems to an increasing number of cyber threats. This study introduces a novel unsupervised approach for the analysis of satellite telemetry, evaluated in the domains of intrusion detection and anomaly detection. The model is based on a Bi-LSTM (Bidirectional Long Short-Term Memory) Autoencoder that allows us to capture long-range temporal dependencies within telemetry sequences. In satellite telemetry, the same physical dynamics may affect multiple sensors simultaneously; for this reason, we employ the Mahalanobis distance on the model's reconstruction error, which allows us to detect correlated deviations between sensors more accurately. Given the absence in the literature of specific datasets for intrusion detection in the satellite domain, our approach was based on a review of the literature on cyber-physical systems and on identifying the most relevant attacks to inject synthetically into a real satellite dataset. Since intrusions and anomalies share common characteristics and effects on the satellite telemetry, the proposed approach was also evaluated in the domain of anomaly detection using the ESA-ADB framework, one of the most established benchmarks in the field. The results on anomaly detection show that our solution matched or outperformed existing algorithms on metrics that prioritize pure detection capability and alert responsiveness. When evaluated on the detection of synthetic attacks, our model shows superior performance in accurately detecting even the most evasive intrusions compared to existing anomaly detection methods. Overall, this work proposes a satellite detection architecture able to operate in an effective and efficient way in anomaly and intrusion detection on satellite telemetry, offering a concrete contribution to the security of satellite systems.
L'aumento esponenziale del numero di satelliti in orbita nell'ultimo decennio, favorito dalla miniaturizzazione e dall'utilizzo di componenti commerciali off-the-shelf (COTS) per abbassare i costi di produzione, ha esposto questi sistemi a un numero crescente di minacce informatiche. Questo studio introduce un nuovo approccio non supervisionato per l'analisi della telemetria satellitare, valutato nei domini del rilevamento di intrusioni e anomalie. Il modello si basa su un Autoencoder Bi-LSTM (Bidirectional Long Short-Term Memory) che permette di catturare le dipendenze temporali più distanti nelle sequenze di telemetria. Nella telemetria satellitare, le stesse dinamiche fisiche possono influenzare più sensori contemporaneamente; per questo motivo viene utilizzata la distanza di Mahalanobis sull'errore di ricostruzione del modello che permette di rilevare più accuratamente le deviazioni correlate tra i sensori. Data l'assenza nella letteratura di dataset specifici per il rilevamento di intrusioni in ambito satellitare, il nostro approccio si è basato sullo studio della letteratura sui sistemi cyberfisici e sulla definizione degli attacchi più rilevanti da iniettare in forma sintetica in un dataset satellitare reale. Poiché intrusioni e anomalie condividono caratteristiche ed effetti sulla telemetria satellitare, l'approccio proposto è stato valutato anche nel dominio del rilevamento di anomalie utilizzando il framework ESA-ADB, uno dei benchmark più consolidati nel settore. I risultati sul rilevamento di anomalie mostrano la nostra soluzione come la migliore o paragonabile ai migliori algoritmi nelle metriche che privilegiano la capacità di rilevamento e la tempestività degli alert. Valutato sul rilevamento degli attacchi sintetici, il nostro modello dimostra capacità superiori nel rilevare accuratamente anche le intrusioni più evasive rispetto ai metodi esistenti di rilevamento di anomalie. Nel complesso, questo lavoro propone un'architettura di detection satellitare capace di operare in modo efficace ed efficiente nel rilevamento di anomalie e intrusioni sulla telemetria satellitare, offrendo un contributo concreto alla sicurezza dei sistemi spaziali.
An unsupervised intrusion detection system for satellite telemetry: BISAT
Melfa, Roberto;MAFFESI, MATTEO
2025/2026
Abstract
The exponential increase in the number of satellites in orbit over the last decade, driven by miniaturization and by the use of commercial-off-the-shelf (COTS) components to lower production costs, has exposed these systems to an increasing number of cyber threats. This study introduces a novel unsupervised approach for the analysis of satellite telemetry, evaluated in the domains of intrusion detection and anomaly detection. The model is based on a Bi-LSTM (Bidirectional Long Short-Term Memory) Autoencoder that allows us to capture long-range temporal dependencies within telemetry sequences. In satellite telemetry, the same physical dynamics may affect multiple sensors simultaneously; for this reason, we employ the Mahalanobis distance on the model's reconstruction error, which allows us to detect correlated deviations between sensors more accurately. Given the absence in the literature of specific datasets for intrusion detection in the satellite domain, our approach was based on a review of the literature on cyber-physical systems and on identifying the most relevant attacks to inject synthetically into a real satellite dataset. Since intrusions and anomalies share common characteristics and effects on the satellite telemetry, the proposed approach was also evaluated in the domain of anomaly detection using the ESA-ADB framework, one of the most established benchmarks in the field. The results on anomaly detection show that our solution matched or outperformed existing algorithms on metrics that prioritize pure detection capability and alert responsiveness. When evaluated on the detection of synthetic attacks, our model shows superior performance in accurately detecting even the most evasive intrusions compared to existing anomaly detection methods. Overall, this work proposes a satellite detection architecture able to operate in an effective and efficient way in anomaly and intrusion detection on satellite telemetry, offering a concrete contribution to the security of satellite systems.| File | Dimensione | Formato | |
|---|---|---|---|
|
2026_07_Maffesi_Melfa_Executive_Summary.pdf
accessibile in internet solo dagli utenti autorizzati
Dimensione
445.67 kB
Formato
Adobe PDF
|
445.67 kB | Adobe PDF | Visualizza/Apri |
|
2026_07_Maffesi_Melfa_Tesi.pdf
accessibile in internet solo dagli utenti autorizzati
Dimensione
2.3 MB
Formato
Adobe PDF
|
2.3 MB | Adobe PDF | Visualizza/Apri |
I documenti in POLITesi sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.
https://hdl.handle.net/10589/259697