ORBITAL EXPLOIT · SATELLITE SECURITY LAB

Operations Reference Manual

Protocol, interface, and system specification for the simulated ISS platform
FOR TRAINING / AUTHORIZED RESEARCH USE

01 System Overview

This document describes the communication protocol, message formats, and system properties of the simulated satellite in this lab. It is a specification, not a walkthrough: it tells you how the system is built, not how to defeat it.

The simulated vehicle (callsign ZARYA, NORAD catalog number 25544) communicates using the CCSDS Space Packet Protocol (CCSDS 133.0-B-2), the same packet format used by real NASA, ESA, and NOAA missions. A telemetry downlink continuously broadcasts vehicle health and position; a telecommand uplink accepts control packets. Everything in this manual reflects the exact byte layout implemented by the simulator.

02 Network Interfaces

InterfaceProtocolPortDirectionPurpose
Telemetry downlinkUDP7000Satellite → GroundContinuous broadcast of housekeeping, position, and attitude telemetry
Telecommand uplinkUDP7001Ground → SatelliteAccepts CCSDS telecommand packets
Mission Control serviceTCP (HTTP / WebSocket)8080BidirectionalDashboard UI, live-state query, WebSocket telemetry stream, command-injection interface

03 CCSDS Packet Structure

Every packet on the wire, telemetry or telecommand, has the same three-part structure:

[ Primary Header 6 bytes ][ Secondary Header 8 bytes ][ Payload ][ CRC-16 2 bytes ]

Primary Header (6 bytes)

15 14 13 12 11 10 9 8 7 6 5 4 3 2 1 0 ┌───────────┬───┬───┬───────────────────────────────────────────┐ │ Version │Typ│SHF│ APID (11 bits) │ Word 0 └───────────┴───┴───┴───────────────────────────────────────────┘ ┌───────┬───────────────────────────────────────────────────────┐ │SeqFlg │ Sequence Count (14 bits) │ Word 1 └───────┴───────────────────────────────────────────────────────┘ ┌───────────────────────────────────────────────────────────────┐ │ Packet Data Length (16 bits) │ Word 2 └───────────────────────────────────────────────────────────────┘ Typ: 0 = TM (downlink) 1 = TC (uplink) Packet Data Length = number of bytes AFTER this header, minus 1

Secondary Header

An 8-byte millisecond timestamp, present on every packet type in this system.

Trailer

Every packet ends with a 2-byte CRC-16 (CCITT-FALSE variant: polynomial 0x1021, initial value 0xFFFF) computed over everything preceding it.

Note: the CRC verifies the packet was not corrupted in transit. It does not verify who sent it: there is no field anywhere in this header that identifies or authenticates the sender.

04 APID Assignments

The Application Process ID (APID) field in the primary header identifies what kind of packet it is.

APIDDirectionContents
0x001TMHousekeeping: mode, battery, temperature, bus voltage/current, solar status, power rails
0x002TMPosition: latitude, longitude, altitude, velocity vector
0x003TMAttitude: roll, pitch, yaw
0x064TCTelecommand: function code + arguments

05 Telecommand Reference

A telecommand's payload is a single function-code byte followed immediately by its arguments, wrapped in the packet structure above (APID 0x064).

CodeNameArguments
0x01SWITCH_POWERrail (1 byte, 0–2), state (1 byte: 0 = OFF, 1 = ON)
0x02SET_MODEmode (1 byte: 0 = NOMINAL, 1 = SAFE, 2 = EMERGENCY)
0x03RESETnone
0x04MEMORY_DUMPaddress (4 bytes, big-endian), length (2 bytes)
0x05DISABLE_SAFE_MODEnone

06 Operating Modes

ValueNameMeaning
0NOMINALNormal operation, all systems active
1SAFENon-essential systems disabled to conserve power and protect the vehicle
2EMERGENCYOnly the most essential systems remain active

07 Telemetry Fields (Housekeeping)

FieldUnitDescription
modeenumCurrent operating mode, see Section 6
battery_soc%Battery state of charge
battery_voltageVBattery terminal voltage
temperature°COnboard electronics temperature
bus_voltageVMain power bus voltage
bus_currentAMain power bus current draw
in_sunlightboolWhether the vehicle is currently in direct sunlight
solar_powerWInstantaneous solar panel output
power_rails3 × boolLive/dead state of each of the three independent power circuits

08 Mission Control Interface

The mission control service (port 8080) exposes the live dashboard plus a small HTTP/WebSocket interface layered on top of the raw UDP protocol above:

InterfaceMethodPurpose
/wsWebSocketStreams the current satellite state once per second
/api/stateGETReturns the current satellite state as JSON
/api/attack/injectPOSTBuilds and sends a telecommand packet on your behalf: accepts a satellite name, a function code (Section 5), and hex-encoded arguments, so you do not have to hand-assemble the raw packet bytes yourself

Both this HTTP interface and raw UDP packets sent directly to port 7001 reach the same telecommand listener: they are two ways to speak the same protocol, not two different systems.

· Scope of This Manual

This manual describes protocol structure and system design only. It intentionally does not include attack procedures, step-by-step instructions, example payloads for a specific outcome, or expected results. What you do with the information above is left to you to work out.