目录

QEMU-AVR32 OPS-SAT Emulator

This emulator was used for security research on ESA’s OPS-SAT during our work for the Space Odyssey academic research paper, published on the 44th IEEE Symposium on Security and Privacy (IEEE S&P / Oakland). The paper describes the details of our findings. The emulator emulates the satellite’s bus system consisting of a GomSpace NanoMind A3200 board and is based on the work of Florian Göhler’s AVR32 implementation for QEMU: https://github.com/flogosec/qemu-avr32.

Disclaimer

This project does not contain satellite firmware, it is just an emulator that can be used to analyze specific satellite firmware. Unfortunately, we can not provide you with firmware.

Build Instructions

The easiest way to build and execute the emulator is using the provided Docker file. The emulator exposes a TCP port that can be used to send telecommands (TC) to the emulator and receive back telemetry (TM). There are also ports opened for the UART interface to retrieve logging output on the satellite.

docker build . -t opssat-test
docker run -p 10001:10001 opssat-test

For this to work, you need some satellite firmware first. Building this without firmware will result in an error. You need to provide the following path and the files:

  • FIRMWARE_IMAGE_PATH: A valid AVR32 binary firmware image compiled with GomSpace’s NanoMind A3200
  • FLASH0/1_IMAGE: There are two flash chips for redundancy that store an uffs filesystem. You need to provide a path to valid images.

FAQ - Frequently Asked Questions

Can you provide the OPS-Sat firmware?

No, the OPS-Sat team at ESA was so kind to provide us with the image for our research, under the condition that we don’t share it.

Can this emulator be used for other satellites?

It depends. If they are also using GomSpace’s NanoMind A3200 board then it could work (but is untested). Also, the code contains multiple segments that are specific for OPS-SAT (for example, workarounds to fix missing hardware emulations), so you might have to adapt the code to your needs.

Is this still actively developed?

At the time of writing, development is continued by Florian Göhler in his repository (we recommend you check it out!): https://github.com/flogosec/qemu-avr32. This repository serves as a snapshot of the emulator we have used for our paper.

Citing the Paper

If you would like to cite our work, please use the following BibTex entry:

@inproceedings{willbold2023space,
  title={Space Odyssey: An Experimental Software Security Analysis of Satellites},
  author={Willbold, Johannes and Schloegel, Moritz and V{\"o}gele, Manuel and Gerhardt, Maximilian and Holz, Thorsten and Abbasi, Ali},
  booktitle={IEEE Symposium on Security and Privacy (S
@inproceedings{willbold2023space,
  title={Space Odyssey: An Experimental Software Security Analysis of Satellites},
  author={Willbold, Johannes and Schloegel, Moritz and V{\"o}gele, Manuel and Gerhardt, Maximilian and Holz, Thorsten and Abbasi, Ali},
  booktitle={IEEE Symposium on Security and Privacy (S\&P)},
  year={2023}
}
P)},
  year={2023}
}
关于

OPS-SAT 星载软件 QEMU 仿真器,无硬件全系统仿真运行卫星软件,支撑地面测试与安全研究。镜像收录自 https://github.com/CISPA-SysSec/SpaceOdyssey-QEMU-AVR32,License:GPL-2.0(QEMU 组合许可)

458.9 MB
邀请码
    Gitlink(确实开源)
  • 加入我们
  • 官网邮箱:gitlink@ccf.org.cn
  • QQ群
  • QQ群
  • 公众号
  • 公众号

版权所有:中国计算机学会技术支持:开源发展技术委员会
京ICP备13000930号-9 京公网安备 11010802047560号