DEF CON 33 - Satellite Networks Under Siege: Cybersecurity Challenges of Targeted DDoS - Roee Idan

DEF CON 33 - Satellite Networks Under Siege: Cybersecurity Challenges of Targeted DDoS - Roee Idan

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 24:11

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Revised Summary (Optimized Based on Feedback):

[BLUF] A targeted link flooding attack on satellite networks can be executed with as few as 1,000–1,500 bots, leveraging the predictable orbital paths of satellites, limited link bandwidth, and dynamic routing to disrupt global communications—without requiring massive botnets 12:30.

Key Takeaways:

  • Satellite networks are inherently vulnerable due to predictable satellite orbits, publicly available TLE (Two-Line Element) data, and limited link capacities (typically tens to hundreds of gigabits per second), combined with dynamic routing that makes them susceptible to targeted congestion attacks 5:09–5:30.

  • A small, focused botnet (~1,000 bots) can disrupt communication between geographic zones by congesting key inter-satellite or ground-to-satellite links in a single snapshot, demonstrating that high-impact disruption is achievable with minimal resources 15:00–15:16.

  • The attack can be persistent and scalable over time: a 10–15% increase in botnet size (still under 1,500 bots) is sufficient to maintain congestion over a 90-minute orbital period (one Earth orbit), showing that continuous disruption is feasible without exponential resource growth 16:00–16:34.

  • A flexible, globally deployable botnet can achieve persistent attacks on 85% of all zone pairs using only 6,000 bots, with attack hotspots concentrated in New York and regions around China/India—indicating predictable attack patterns and high-risk zones 19:31–20:18.

  • Simultaneous multi-zone attacks require approximately 10,000 bots to congest multiple paths, revealing critical network links that attackers prefer

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

Great. So, I'll start. Hello. Nice to meet everybody. My name is Roy. It's actually my first time being here and presenting in Defcon. So, I'm quite excited. Thank you. Thank you. So, we have a bit of a technical difficulty a bit. So, I'll present I'll start by presenting the introduction a bit without the screen and hopefully it will be fixed by the time we'll get to some of the graphs and the results that I want to show. So, so my name is Roy. I'm a PhD student in Mangoran University and I'm part of the CBG Cyber Bengalon research lab. My today I'll be showing you a framework that we designed to plan and optimize DDS targeted attacks on satellite networks. The idea of these attacks is not to use brute force but to try and see how can we utilize smart and sophisticated and planned traffic…