I. Introduction
Low Earth orbit (LEO) satellite networks, such as SpaceX’s Starlink [1] and Amazon’s Project Kuiper [2], are transforming global communications. These constellations consist of thousands of satellites operating at altitudes of up to 2,000 km, forming a new connectivity backbone in space. They offer low-latency, highspeed Internet access worldwide, extend connectivity to underserved regions, enable direct satellite-to-cell connectivity [3], [4], [5], and support applications such as broadband services, financial data transfer, and emergency communications [6], [7]. Modern LEO satellite networks are connected by a mesh of inter-satellite links (ISLs) and ground-satellite links (GSLs) [8]. While many constellations still route traffic through ground stations (GSs) and terrestrial networks [9], there is growing interest in using ISLs for direct in-network routing. ISL based routing can create a more self contained space network, reducing dependence on ground infrastructure and enabling more direct end-toend paths. Prior studies show that such architectures can halve end-to-end latency compared to terrestrial routing due to faster signal propagation, shorter routes, and fewer hops [6]. As a result, end-to-end communication that relies on ISLs for in-network routing is expected to become more common, increasing the performance and flexibility of LEO connectivity [10], [11]. Despite their large scale, LEO constellations are topologically sparse and capacity constrained. Each satellite typically maintains only a small number of active ISLs and GSLs, and these links have finite capacity [8]. LEO satellite motion is also highly predictable; publicly available two-line element (TLE) data enables forecasting satellite positions with deviations of only a few kilometers [12], [13]. As a result, the network topology evolves in a structured and largely foreseeable manner over time. These characteristics distinguish LEO constellations from terrestrial networks and shape both how traffic is routed and how performance bottlenecks emerge across geographic regions. The rapid growth of LEO satellite networks has drawn the attention of threat actors, as the number of satellites and the range of offered services increase the exposed surface for cyberattacks. Researchers in academia and industry have also begun systematically exploring broader cybersecurity risks in LEO constellations. Prior studies document threats ranging from physical-layer attacks, such as jamming, spoofing, and energy draining [14], [15], to terminal-level exploits, such as bypassing secure boot protections to access and inspect internals of the Starlink user terminal [16]. These threats are no longer just theoretical. In May 2022, the pro-Russian group Killnet claimed responsibility for DDoS attacks on Starlink [17]. These events, along with others discussed in Section II, highlight adversaries’ growing interest in targeting satellite Internet services. As satellite Internet services expand, these threats motivate a need to better
arXiv:2609.15693v1 [cs.CR] 14 Sep 2026
HYDRA: Quantifying Botnet Resource Thresholds for Efficient Link-Flooding Attacks on LEO Satellite Networks
Roee Idan Rami Puzis Asaf Shabtai Yuval Elovici Stein Faculty of Computer and Information Science, Ben-Gurion University of the Negev, Beer-Sheva, Israel Abstract— Low Earth orbit (LEO) satellite constellations, such as Starlink and Kuiper, are rapidly emerging as a critical backbone for lowlatency global connectivity. As these systems expand, they become more attractive attack targets, necessitating increased resilience and security. Threat actors seek to exploit constellation-specific properties such as predictable motion, time-varying topologies, and reliance on inter-satellite and ground-satellite links. Recent work has shown that link-flooding attacks (LFAs) can exploit these properties to congest strategic network bottlenecks. Yet, prior work does not quantify the resilience of LEO networks to targeted disruption. We present HYDRA, a modeling and optimization framework that formulates LFA variants as botnet minimization problems. HYDRA quantifies network resilience to LFAs by measuring the smallest active subset of bots and the corresponding traffic allocation required to disrupt communication between targeted geographic areas. Under matched stealth constraints, HYDRA achieves the same targeted disruption as ICARUS while using 34% fewer bots and 23% less aggregate attack traffic. HYDRA achieves over 97% success in sustaining continuous attacks as the network topology evolves. Finally, HYDRA evaluates five mitigation strategies, showing how routing diversification, ingress policing, distance-based traffic constraints, source throttling, and botnet attrition reduce attack success and improve network resilience to targeted disruption. Index Terms— Botnets, denial-of-service attacks, inter-satellite links, link-flooding attacks, low Earth orbit satellite networks, network resilience, satellite constellations, space network security.
(Corresponding author: R. Idan, [email protected]). Roee Idan, Rami Puzis, Asaf Shabtai, and Yuval Elovici are with the Stein Faculty of Computer and Information Science, Ben-Gurion University of the Negev, Beer-Sheva, Israel (e-mail: [email protected]; [email protected]; [email protected]; [email protected]).
1
understand the feasibility and resource requirements of disruptive network-layer attacks. Among the cyber threats LEO constellations are facing, distributed denial-of-service (DDoS) attacks, and in particular link-flooding attacks (LFAs), are especially well suited to exploiting the unique characteristics of these networks. DDoS attacks use a distributed set of compromised hosts, called a botnet, that are remotely controlled by an adversary to inject traffic and overwhelm limited network resources, while LFAs steer this traffic to congest a small set of strategically chosen links [18]. In LEO networks, an adversary can exploit the global reach of satellite access together with publicly available orbital information to plan targeted congestion at specific times and locations. This can increase the impact of each active bot by focusing traffic on time-varying bottlenecks, lowering the botnet resources required for targeted disruption. In this work, we focus on zone attacks, where the adversary uses multiple LFAs to disrupt connectivity between two targeted geographic areas rather than aiming for a network-wide outage or a single endpoint. Prior work has shown that LFAs against LEO constellations are possible, including snapshot-based demonstrations, attacks that remain effective without assuming exact routing knowledge, attacks that account for shortterm topology changes, and attack structures that aim for broader disruption beyond a single precisely targeted path [8], [19], [20]. Collectively, these studies show the potential of targeted congestion attacks in LEO networks. However, prior work does not address how feasible such attacks are under a constrained population of compromised satellite users. This question is especially important in LEO networks, where the pool of plausibly usable bots is far smaller than in terrestrial settings: IoT deployments include tens of billions of connected devices [21], whereas the largest LEO constellation, Starlink, currently serves more than 10 million active users [22]. Since only a subset of satellite users could plausibly be compromised, and each compromised terminal can contribute only uplink capacity on the order of tens of Mbps [23], the required botnet size becomes a key measure of attack practicality. Furthermore, existing work does not quantify attacker efficiency for zone attacks, including how to minimize the number of active bots needed to disrupt connectivity between selected areas, how this requirement changes as the topology evolves over time, and how it scales when the attacker pursues broader or multiple disruption objectives. It also remains unclear how versatile a single botnet configuration can be across different disruption goals. Aggregate attack flow alone does not characterize LFA feasibility, because generating and steering a given traffic volume through the targeted bottlenecks depends on the number, uplink capacity, and geographic location of bots. The minimum botnet required to disrupt connectivity between targeted zones captures the resources an adversary must actually obtain and coordinate, and therefore provides a direct measure of the network’s resilience to LFAs: a network
that requires a larger botnet to achieve disruption is more resilient. This leaves a broader security question open: how resilient are LEO networks to LFAs? To address these questions, we introduce HYDRA, a modeling and optimization framework for LFAs in dynamic LEO networks. Rather than focusing only on attack execution in a single snapshot, HYDRA models adversarial planning, including bot selection, traffic allocation, and persistence under time-varying topologies. Given a pool of bots mapped to geographic locations, HYDRA computes the smallest active bot subset and corresponding traffic plan needed to induce targeted congestion under constellation capacity constraints. Under idealized, fully optimized conditions, HYDRA estimates the minimum botnet resources required to achieve targeted disruption, establishing a baseline for assessing network resilience to LFAs. HYDRA evaluates this threshold across multiple LFA objectives, from single-snapshot attacks to persistent attacks over time, and examines whether a single botnet can support flexible targeting and simultaneous disruption across multiple targets. Finally, HYDRA evaluates five mitigation strategies, showing how they reduce attack success and increase the minimum botnet resources required for targeted disruption. Using HYDRA, we find that the resilience of LEO networks to LFAs is substantially lower than prior attack models imply. In single-snapshot zone-attack instances, HYDRA reduces the active botnet size by 34% relative to an ICARUS stealth-distribution baseline under matched detectability constraints, while also reducing aggregate attack flow by 23%. HYDRA maintains over 97% success in continuous attacks under the modeled routing and traffic assumptions, and the required resources scale efficiently when extending disruption to multiple targets. We further use HYDRA to evaluate five mitigation strategies, showing how changes to routing, ingress capacity, source rate limits, traffic constraints, and bot availability reduce global attack success and increase the minimum botnet resources required for targeted disruption. The main contributions of this paper are:
• We model the dynamic topology of LEO satellite networks and define disruption objectives for LFAbased zone attacks. • We develop a discrete optimization framework that quantifies resilience to LFAs through the minimum botnet resources and corresponding traffic allocation required to induce targeted congestion under constellation capacity constraints. • We evaluate persistent disruption, showing that a single optimized botnet can sustain attacks across time-varying topologies. • We study flexible botnet utilization, showing how a single botnet can be reused to target different disruption objectives without reconfiguration. • We quantify simultaneous multi-target disruption, showing that a coordinated botnet can attack multiple 2
zone pairs at once more efficiently than planning each target independently. • We use HYDRA to evaluate five mitigation strategies, quantifying how changes to routing, ingress capacity, source rate limits, traffic constraints, and bot availability affect global attack success and the minimum botnet resources required for targeted disruption.
models like SGP4 [13] to predict satellite positions with deviations of just 1–2 km. While useful for legitimate applications, TLEs can be exploited by adversaries to predict satellite locations and reconstruct network topologies [8], facilitating cyberattack planning.
B. Distributed Denial-of-Service and Link-Flooding Attacks in Terrestrial Networks
DDoS attacks are a major threat in computer networking, aiming to make resources unavailable to legitimate users [30]. Attackers often rely on botnets to flood specific servers or infrastructure with large volumes of traffic [31]. A notable example is the Mirai botnet [31], which infected hundreds of thousands of IoT devices and used them to launch massive DDoS attacks. In addition to traditional high-volume flooding attacks, more sophisticated strategies use low-rate flows to exploit network topology and congest targeted links. In the Coremelt attack [18], bots exchange traffic in a way that causes it to converge on core ISP links without directly targeting end systems. The Crossfire attack [32] refines this approach by sending traffic to public decoy servers, carefully selected so that the traffic paths traverse critical links. While these flows appear benign, when coordinated within a botnet they can cause sustained congestion. Both attacks demonstrate how knowledge of routing and topology can enable stealthy, persistent disruption without relying on high traffic volumes.
II. Background A. LEO Satellite Network Architecture
LEO satellite constellations consist of thousands of satellites orbiting Earth at altitudes of up to 2,000 km [3], [1], [24], enabling low latency and fast data transmission. However, due to this closeness each satellite has a limited coverage area. Each LEO satellite completes an orbit in approximately 90 minutes [25], [6], leading to constant motion and frequent changes in position relative to the Earth’s surface. Due to this rapid movement and narrow coverage area, consistent regional coverage requires many satellites, with handovers every few minutes [26], [6]. Precise orbital configurations and sufficient satellite density are necessary to ensure uninterrupted global coverage [4]. LEO constellations are often arranged in structured patterns, such as the Walker-Delta configuration [25], [6], across multiple orbital planes to optimize coverage and connectivity. With sufficient satellite density, this design supports continuous coverage by keeping at least one satellite within communication range of any point on Earth, enabling reliable global connectivity [6]. Each satellite is equipped with GSLs that connect to user terminals (UTs) and ground stations (GSes), which in turn connect to the terrestrial internet, and typically supports four ISLs; together, the GSLs and ISLs form a dynamic mesh [27], [28]. These links transmit data using either radio frequency or optical lasers, with optical ISLs offering higher bandwidth and lower latency [29]. However, their capacity remains limited: ISLs typically support tens of Gbps, while GSLs operate at just a few Gbps [27]. As satellites orbit and the Earth rotates, the constellation topology continually changes [25]. ISL connections are reconfigured dynamically, and GSL connections shift with satellite movement to serve different users. These changes introduce routing variability, resulting in a highly dynamic and complex network structure [28]. Routing in such networks typically relies on topology aware algorithms that adapt to the dynamic connectivity to select low-latency paths [7]. There is extensive public data on satellite constellations, including orbital elements, launch information, constellation configurations, and community tracking data published by governments, researchers, and hobbyists. TLE sets, which are freely available and updated every few days [12], provide orbital parameters used with
C. Cybersecurity Challenges in Space and Satellite Networks
The growing reliance on space-based infrastructure introduces unique cybersecurity challenges. Space systems operate in harsh environments and face limitations such as constrained computational resources, long development cycles, and difficult to deploy software updates [33], [34]. Attacks targeting space systems include jamming, spoofing, malware injection, data interception, and DoS attacks [34], [33]. Among these threats, Willbold et al. [33] performed an experimental security analysis of real satellite firmware and discovered multiple critical vulnerabilities, showing that software and firmware weaknesses can be exploited to compromise satellite systems and achieve persistent control. In February 2022, a cyberattack on Viasat’s KASAT network disrupted broadband across Ukraine and Europe, affecting thousands of users and critical infrastructure [35]. Viasat traced the attack to a misconfigured VPN appliance, which illustrates how ground-side vulnerabilities can compromise satellite operations [36]. In May 2022, the pro-Russian group Killnet claimed responsibility for DDoS attacks targeting SpaceX’s Starlink satellite internet services [17]. This incident highlights the increased targeting of satellite networks, particularly in conflict zones. 3
Beyond disruption, satellite links can also be abused as part of an adversary’s operational infrastructure. The Turla APT group used satellite connectivity to support cyber-espionage activity against government and military organizations [37], [38]. By routing traffic through satellite connections and hijacking IP address space, Turla increased its anonymity and made detection more difficult [37], [38]. Together, these incidents reflect adversaries’ growing interest in the space sector and highlight that satellite connectivity can be disrupted or abused through both ground-side compromise and network-layer attacks.
inter-zone connection over extended periods across a dynamic satellite topology. • Multi-target efficiency: Prior work focused on disrupting single links or single zones. The studies did not explore whether an adversary could efficiently use a single botnet to simultaneously disrupt communication between multiple, distinct pairs of geographic zones. • Mitigation impact on attack thresholds: Existing studies offer limited evaluation of how mitigations affect the botnet resources required for disruption in dynamic LEO topologies. HYDRA addresses these underexplored aspects by explicitly modeling the strategic planning phase of an attack. It quantifies resilience to LFAs through the minimum botnet resources required for targeted disruption, evaluates this threshold across persistent, flexible, and simultaneous attack objectives, and assesses how mitigations affect both attack feasibility and the threshold.
III. Related Work: LFAs on LEO Satellite Networks
While the principles of LFAs were developed for terrestrial networks, recent research has begun to adapt them for the unique, dynamic environment of LEO constellations. ICARUS [8] was the pioneering attack. It provided the first dedicated framework for simulating LFAs against LEO networks and successfully demonstrated that an adversary could congest specific ISLs and GSLs by exploiting the network’s predictable topology and routing. This work was foundational in establishing the general feasibility of the threat. Subsequent research built upon this foundation and explored more dynamic attack strategies. The DoSat study [19] showed that attacks could be timed to coincide with vulnerable link handover periods, a moment of weakness in the network, to maximize their disruptive impact. The StarMaze study [20] introduced a novel attack variant that creates persistent traffic loops within the constellation’s regular, ring-like topologies, focusing on network-wide disruption by targeting entire satellite rings and causing more widespread damage. While the state-of-the-art works demonstrate the feasibility of LFAs and their importance and impact on LEO networks, the studies share common limitations that motivate our research. As can be seen in Table I, which summarizes prior work, researchers have primarily focused on execution of the attack, assuming the existence of the necessary attack infrastructure while overlooking the following aspects:
IV. The HYDRA Attack
In this section, we define the HYDRA attack model and its optimization-based mathematical formulation for zone attacks in LEO satellite networks. We present the threat model, formal attack definitions, optimizationbased planning methods, and execution phase constraints. A. High-Level Attack Overview
The HYDRA attack unfolds in two phases: • Weaponization Phase: The attacker determines the optimal layout and composition of the botnet. The goal is to minimize the number of bots while ensuring that sufficient traffic can be generated to disrupt communication between the targeted areas. • Execution Phase: Once the botnet is assembled, the attacker executes the attack by directing carefully constructed traffic flows to congest critical links without violating background capacity constraints.
This targeted congestion effectively disrupts the communication paths between the designated areas, as illustrated in Figure 1.
• Botnet optimization: Prior work assumes access to a large, well-distributed botnet and does not address how to minimize the number of bots required for an attack under per-bot upload constraints. This overlooks a key limitation in LEO networks: the number of user terminals that could serve as bots is limited, and each bot can inject only a limited amount of attack traffic. • Long-term persistence and adaptation strategy: While some studies examined short-term dynamics, most prior work did not formalize or optimize the problem of sustaining a targeted attack against an
B. Threat Model 1. Adversary’s Capabilities We assume an adversary with detailed knowledge of the constellation topology and satellite orbits, based on publicly available sources such as NORAD [12], [13]. This enables accurate prediction of satellite positions over time, which is valuable for attack planning. The adversary can analyze observable traffic from compromised endpoints to infer the routing policy and obtain coarse estimates of link capacities and background loads. They also control a globally distributed botnet and can 4
TABLE I Comparison of HYDRA to state-of-the-art LFA approaches for LEO networks. Aspects Considered Targeting ISLs Snapshot-Based Network Modeling Adaptation to Dynamic Network Topologies Continuous Attacks Long-Lasting Attack Strategy Active Botnet Minimization Flexible Botnet Utilization Simultaneous Attacks on Multiple Zone Pairs Defense / Mitigation Evaluation
HYDRA ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓ ✓
ISL
GSL
GSL
GSL
𝑧𝑠
DoSat [19] ✓ ✓ ✓ ✓
StarMaze [20] ✓ ✓ ✓ ✓ ✓
✓
2. Traffic Matrix (TM) In our simulation traffic flows between pairs of GPOs: a source gs ∈ N GP O and a destination gd ∈ N GP O . The amount of traffic sent by gs to gd at every time point t is captured by the traffic matrix TMt,gs ,gd .
ISL
GSL
ICARUS [8] ✓ ✓
GSL
3. Routing Function (F) We define a routing function Ft (gs , gd ) which maps a source-destination pair (gs , gd ) to a sequence of links (a path) in Gt . We assume that shortest-path routing is used to maintain reliable communication [7]. For simplicity, and to keep the formulation focused on botnet minimization rather than routing dynamics, we abstract routing as a single route per (gs , gd ) pair at each snapshot (i.e., no path dispersion). This separation keeps HYDRA focused on quantifying attack resource requirements for a given routing policy, while alternative routing policies are evaluated separately as mitigation mechanisms in Section VI.
𝑧𝑑
Fig. 1. Illustration of the HYDRA attack during a specific snapshot. Attack traffic is injected into the LEO satellite constellation via ground points of origin (GPOs) and flows through GSLs and ISLs toward its destination. The goal is to congest selected links (highlighted in red), disrupting communication between a source zone (zs ) and a destination zone (zd ) based on the topology at that snapshot.
synchronize its activity to converge traffic on targeted links simultaneously [31], [39].
4. Residual Capacity Each link l ∈ LISL ∪ LGSL has a maximum capacity clmax . Link usage is the total traffic exchanged between GPOs through the link. The residual capacity is the remaining bandwidth on link l at time t after accounting for all traffic traversing the link. We consider a link congested if its residual capacity drops below a fraction (1 − α) of its maximum capacity, i.e., (1 − α) · clmax . The parameter α ∈ (0, 1) sets the residual-capacity margin used to classify links as congested, providing a common congestion criterion across snapshots, zone pairs, and attack configurations. When a link is congested, it may result in increased latency, packet loss, or dropped connections between communicating nodes [18].
2. Attacker’s Objective The adversary’s objective is to identify the smallest subset of the botnet and corresponding data flows needed to disrupt communication between targeted geographic zones, while maintaining a persistent attack over time. C. Preliminaries: The Satellite Network 1. Dynamic Network Topology We model the LEO network as a time-varying graph (Gt ) captured at periodic time snapshots t ∈ T . The network comprises thousands of satellites (N S ) and ground point origins (GPOs), denoted as N GP O . GPOs represent discrete locations on Earth based on a geodesic grid [40]. We assume that N S and N GP O remain fixed over the time scales we study, and thus we do not model changes in them. However, satellite positions change continuously, and link connectivity changes with them. Satellites communicate with each other via ISLs (LISL ⊆ NS × NS) t GSL and with the ground via GSLs (Lt ⊆ N S × N GP O ). The LEO network at time t is represented as Gt = (N S ∪ N GP O , LGSL ∪ LISL ). In the remainder of the t t paper, we may omit the time index t when the context makes it clear, to simplify notation.
D. The HYDRA Attack Model
In this section, we formulate the constraints and functions that define the attack and describe how the network and attacker’s actions are modeled, how the injected traffic is represented, and how we ensure the network capacity constraints. 1. Attack Traffic Matrix (ATM) The attack traffic matrix ATM captures the additional traffic sent by the botnet as part of the attack. Each entry 5
ATMt,gs ,gd denotes the amount of attack traffic sent from source GPO gs to destination GPO gd at snapshot t.
5. Non-Target Congestion Constraint (U) To limit congestion to the links selected for the attack, all non-selected links need to remain uncongested. This condition evaluates whether all non-selected links remain uncongested at time t and can be written as
2. Attack Target Consider a geographic zone such as a country, state, or region. We define a zone as a subset of GPOs z ⊆ N GP O . The adversary’s goal is to disrupt communication between one or more pairs of zones, A = {(z1 , z2 ), . . . : zi ⊆ N GP O }. We define a function P(t, zp) that returns the set of all paths between a pair of zones zp = (z1 , z2 ) ∈ A at time t as P(t, zp) = {Ft (gs , gd ) : gs ∈ z1 , gd ∈ z2 } .
zp sel U(t, zp, ATMzp t ) = ∀ l ∈ Lt \ Lt (zp, ATMt ), Et (l, ATMzp t ) > τl .
An attack satisfies the non-target congestion constraint if U(t, zp, ATMzp t ) is true for all zp ∈ A and all t ∈ T . To encode U(t, zp, ATMzp t ) in the optimization problems, we use the same binary variables that indicate whether a link is selected as congested, and enforce that every non-selected link remains above the congestion threshold. The goal of this constraint is to help the attacker avoid congestion on links other than the selected target links under the modeled traffic conditions, so that attack traffic can reach the intended congestion points without disrupting itself earlier in the path.
(1)
Since Ft (gs , gd ) returns a single route for each GPO pair (gs , gd ) at snapshot t, P(t, zp) contains one path per pair and thus scales as |P(t, zp)| = |z1 ||z2 |, rather than with the number of arbitrary simple paths in the topology. The attacker’s objective is to congest at least one link in every route in P(t, zp). For a specific zone pair zp = (z1 , z2 ) ∈ A, we denote ATMzp as the attack traffic matrix targeting that pair. More generally, ATMA is the set of all such matrices for zone pairs in A.
6. Total Outgoing Attack Traffic Let β be the maximum upload capacity of a single host. We use a uniform per-bot rate limit β to keep the formulation focused on botnet minimization; this can be interpreted as a conservative bound (e.g., a lowerpercentile upload rate) across the bot population. We define S(gs , t, ATM) as the minimal number of bots the attacker must operate at gs at time t as P gd ATMt,gs ,gd S(gs , t, ATM) = . (7) β
3. Post-Attack Available Capacity (E) This function represents the remaining available capacity of a link l at time t after accounting for both nominal and attacker-injected traffic. Formally, it is defined as X Et (l, ATM) = clmax − (TM + ATM)t,gs ,gd . gs ,gd : l∈Ft (gs ,gd )
(2) We define the residual-capacity congestion threshold of link l as τl = (1 − α)clmax . (3)
Let I(ATMA T ) denote the set of all source GPOs gs that appear as a row index in any attack traffic matrix ATMzp for some zp ∈ A and t ∈ T . We define t SM (T, A, ATM) as a vector indexed by gs ∈ I(ATMA T ), where each entry represents the maximum number of bots the attacker must operate at gs across all relevant snapshots and zone pairs
A link is considered congested when its post-attack residual capacity is at most τl while remaining physically feasible, i.e., 0 ≤ Et (l, ATM) ≤ τl .
(6)
(4)
SM (T, A, ATM)
4. Congestion Condition (C) To disrupt communication, the adversary must ensure that each path p ∈ P(t, zp) is congested. A path is considered congested when it contains at least one link whose aggregate traffic reaches or surpasses the congestion threshold. This condition evaluates whether all paths between a zone pair zp are congested at time t and can be written as C(t, zp, ATMt ) = ∀ p ∈ P(t, zp), ∃ l ∈ p s.t. (5) 0 ≤ Et (l, ATMzp t ) ≤ τl . An attack is considered successful if C(t, zp, ATMt ) is true for all zp ∈ A and all t ∈ T . To encode C(t, zp, ATMt ) in the optimization problems, we use binary variables indicating whether a link is selected as congested at a snapshot, and enforce that for every path the sum of these binaries over its links is at least one. Let zp Lsel t (zp, ATMt ) ⊆ Lt denote the set of links selected as congested for zone pair zp at time t.
= max S(gs , t, ATMzp t ) t∈T zp∈A
.
(8)
gs ∈I(ATMA T)
E. Weaponization Phase Optimization
During the weaponization phase, the attacker seeks to minimize the number of active bots required to disrupt communication between the targeted zones. Botnet size is expressed as the L1 norm of ATM∗ = arg min ∥SM (T, A, ATM)∥1 .
(9)
ATMA T
For a given disruption objective and set of modeled constraints, the optimum of Eq. (9) identifies the minimum active botnet required to induce targeted congestion and its corresponding traffic allocation. We use this minimum botnet and corresponding traffic allocation as 6
an operational measure of resilience to LFAs: the more bots a network requires an adversary to deploy to achieve disruption, the greater its resilience. We aim to fulfill this objective in several attack scenarios (described below), which we formulate as botnet minimization problems (BMPs). All BMP instances are formulated as mixedinteger linear programs (MILPs) and solved using the Gurobi Optimizer [41].
snapshots. This is done by determining, for each GPO, the maximum number of bots that need to be sent across all t ∈ T , summing these peak values across all GPOs, and minimizing the total number of bots required to maintain the attack throughout the time window. The associated continuous botnet minimization problem (C-BMP) is defined as follows
1. Snapshot Attack Method The snapshot attack method aims to disrupt communication between a single targeted zone pair zp = (z1 , z2 ) at a specific snapshot time t, while minimizing the botnet size. The associated single snapshot botnet minimization problem (SS-BMP) is defined as follows
All inputs of SS-BMP. T : Set of snapshot times capturing the dynamic topology of the network. SM (T, zp, ATM): Vector representing the maximum number of bots needed per GPO across all t ∈ T .
P ROBLEM D EFINITION 2 (C-BMP) Given:
Find {ATMzp t }t∈T : A set of attack traffic matrices for zone pair zp across all snapshots.
P ROBLEM D EFINITION 1 (SS-BMP) Given: P(t, zp): Set of paths connecting zones z1 and z2 at time t. Lt : Set of ISLs and GSLs in the network Gt at time t. SM (t, zp, ATM): Vector of required bots per GPO for the snapshot (t, zp). C(t, zp, ATMzp t ): Congestion indicator for all paths in P(t, zp). zp Lsel t (zp, ATMt ): Set of links selected as congested for zone pair zp at timet. U(t, zp, ATMzp t ): Non-selected link congestion constraint.
ATM∗ =
(10a)
∀t ∈ T,
C(t, zp, ATMzp t ), zp U(t, zp, ATMt ).
(10b) (10c)
U(t, zp, ATMzp t ).
(11a) (11b) (11c)
Solving the optimization problem across all t ∈ T minimizes the total size of the botnet while maintaining congestion throughout the entire attack window. This approach adapts to changes in satellite positions, connectivity, and nominal data transfers, ensuring sustained disruption with minimal resources. 3. Flexible Botnet Configuration for Targeted Attacks This method aims to identify the smallest botnet that can individually attack any pair of zones within a defined set. This approach ensures that any zone pair in the set can be targeted without adjusting the botnet. The optimization here focuses on solving the problem globally to find a minimal set that can be reused for attacking each zone pair individually, for each pair zp ∈ A, where A is the set of all attacked zone pairs. The associated flexible botnet minimization problem (F-BMP) is defined as follows
ATMzp t
s.t.
∥SM (T, zp, ATM)∥1
∀t ∈ T, C(t, zp, ATMzp t ),
s.t.
Find ATMzp t : Attack traffic for zone pair zp at time t. ATM∗ = arg min ∥SM (t, zp, ATM)∥1
arg min {ATMzp t }t∈T
Constraint eq. (10b) guarantees that each path between the targeted zones is disrupted via at least one congested link. Constraint eq. (10c) ensures that links not selected for congestion remain uncongested. Together, these conditions ensure that the attack achieves its goal without obstructing its own execution. The SS-BMP serves as a baseline for more advanced attacks, laying the groundwork for strategies like sustained attacks over time or simultaneous multi-zone disruption.
P ROBLEM D EFINITION 3 (F-BMP) Given: All inputs of C-BMP. A: Set of zone pairs that the botnet needs to be able to attack individually. SM (T, A, ATM): Vector representing the number of bots required per GPO for each zone pair in A across snapshots.
2. Continuous Attack We extend the attack over time by optimizing the botnet strategy across multiple snapshots. Each snapshot captures the network state at a specific time, with the attack aiming to maintain congestion across relevant paths throughout all snapshots in T . For each snapshot t ∈ T , the parameters P(t, . . .), Lt , EtTM , and C(t, . . .) vary based on satellite positions, connectivity, and nominal data transfers through the network. The overall objective is to minimize the size of the botnet needed to sustain the attack across all
Find {ATMzp t }zp∈A, t∈T : A set of attack traffic matrices for each zone pair zp across all snapshots. ATM∗ =
arg min {ATMzp t }zp∈A, t∈T
s.t.
∥SM (T, A, ATM)∥1 (12a)
∀zp ∈ A, ∀t ∈ T, C(t, zp, ATMzp t ), (12b) ∀zp ∈ A, ∀t ∈ T, U(t, zp, ATMzp t ). (12c)
7
Minimizing ∥SM (T, A, ATM)∥1 yields the smallest botnet capable of executing each attack independently. Constraint (12b) ensures that every zone pair zp ∈ A can be successfully targeted. Solving the optimization problem across all zone pairs enables the creation of a single botnet configuration that supports all attacks in A, improving resource efficiency and allowing flexible targeting without reconfiguration.
ISLs, or limit the amount of attack traffic that traverses any GSL. For a link l, let Dt (l) = {(gs , gd ) : l ∈ Ft (gs , gd )}
(15)
denote the set of source-destination GPO pairs whose route at time t traverses l. The total attack traffic traversing each GSL can then be bounded by an absolute threshold u(l), X ATMt,gs ,gd ≤ u(l). ∀t ∈ T, ∀l ∈ LGSL , t
4. Maximized Simultaneous Attack Method This method targets multiple zone pairs simultaneously using a unified set of constraints that span all relevant paths. As previously done, the set of targeted zone pairs is denoted as A. For each snapshot t ∈ T , we define the unified path set PA (t) as the union of all communication pathsSbetween zone pairs in A during that snapshot PA (t) = zp∈A P(t, zp). This unified set enables the construction of a single attack traffic matrix ATMt for each snapshot, which must simultaneously congest all relevant paths across all zone pairs in A. The associated simultaneous botnet minimization problem (SIMU-BMP) is defined as follows:
(gs ,gd )∈Dt (l)
(16) Alternatively, the bound can be defined relative to the nominal residual capacity on the GSL. We define the preattack residual capacity of link l at time t as X ϕt (l) = clmax − TMt,gs ,gd . (17) (gs ,gd )∈Dt (l)
The total attack traffic traversing each GSL can then be limited to a fraction γ(l) of this residual capacity, X ATMt,gs ,gd ≤ γ(l)ϕt (l). (18) ∀t ∈ T, ∀l ∈ LGSL , t (gs ,gd )∈Dt (l)
P ROBLEM D EFINITION 4 (SIMU-BMP) Given:
Additionally, a limit m(g) can be placed on the number of bots used per GPO
All inputsSof SS-BMP. PA (t) = zp∈A P(t, zp): Set of all communication paths across the zone pairs in A at snapshot t.
∀g ∈ N GP O , Bg ≤ m(g).
The term Bg captures the required bot availability at each GPO, while m(g) can be used to impose deploymentspecific limits, such as population-based or operatorspecific caps on the number of bots available at that location.
Find {ATMt }t∈T : A set of attacker-injected traffic matrices, one per snapshot. ATM∗ = arg min ∥SM (T, A, ATM)∥1
(13a)
∀t ∈ T, C(t, A, ATMt ),
(13b) (13c)
(19)
{ATMt }t∈T
s.t.
∀t ∈ T, U(t, A, ATMt ).
V. Evaluation
To evaluate these attack strategies, we simulated 10 constellation formations, including Starlink [1], [24], OneWeb [42], and Project Kuiper [2]. Each setup was based on key parameters: the number of orbital planes, number of satellites per plane, altitude, inclination, and link capacity. We evaluated the first Starlink shell (72 planes × 22 satellites, 550 km altitude, 53◦ inclination). Each simulation modeled a 90-hour period with routing updates every 30 seconds, capturing a dynamic topology. We used an extended ICARUS simulator [8] on a system with 256 AMD EPYC 7763 CPU cores and 1TB RAM. The targeted pairs were selected via GDP-weighted sampling of global city pairs to reflect economically important regions. The GDP data came from public sources [43], [44]. Ten thousand random pairs were examined to assess robustness and scalability. Link capacities are fixed per link type for ISLs and GSLs. At each snapshot t, the background traffic is generated by sampling source–destination GPO pairs using GDP-weighted GPO weights and assigning each sampled pair to a shortest-path route in Gt . In our evaluation, we use 250,000 source–destination pairs per snapshot, randomly sampled according to the GDP-weighted GPO
This optimization approach minimizes the botnet size while maximizing the attack effectiveness by identifying shared ISLs and data flows that can congest multiple paths concurrently. F. Execution Phase and Stealth Constraints
In the execution phase, the optimization is constrained by a pre-existing botnet B , ensuring that the total attack traffic sent from any GPO does not exceed the aggregate bandwidth of the bots available at that location. This constraint is enforced via X ∀t ∈ T, ∀g ∈ N GP O , β · Bg ≥ ATMt,g,gd , (14) gd
where β is the maximum sending capacity of a single bot, and Bg denotes the number of bots assigned to GPO g . The summation on the right-hand side represents the total attack traffic sent from g at time t. To further reduce detectability, the attacker can impose additional execution constraints inspired by [8]. These constraints can restrict the selected congestion targets to 8
TABLE II Key parameters used in the evaluation. Parameter
Value
Snapshot interval Evaluation window Number of GPOs
30 seconds 90 hours 1,800
Background pair sampling Sampled background demands per snapshot Routing model
GDP-weighted 250,000 sampled (gs , gd ) pairs
ISL capacity clmax GSL capacity clmax
20,000 Mbps 4,000 Mbps
Congestion threshold Per-bot upload cap
α = 0.9 β = 25 Mbps
the median botnet size reduced by 35.6%, and the 25th and 75th percentile botnet sizes reduced by 31.4% and 32.6%, respectively. HYDRA also reduces the aggregate attack flow by 23.0% on average and 20.3% at the median, indicating that the optimized allocation reduces both the number of active bots and the amount of attack traffic required to reach the modeled congestion condition. These results show that HYDRA can achieve the same modeled attack objective as ICARUS while maintaining the same stealth threshold and requiring fewer resources. While ICARUS completes its computation in seconds, HYDRA took around half a minute on average. This runtime difference does not materially affect attack planning because HYDRA is used during the weaponization phase.
Shortest-path routing
TABLE III Comparison between ICARUS and HYDRA under matched topology, traffic, routing, capacity, congestion-threshold, per-bot upload, and maxUp constraints. Metric Mean botnet size Median botnet size 25th percentile 75th percentile Mean attack flow (Mbps) Median attack flow (Mbps)
ICARUS 1,096.56 1,012 640 1,542.5 23,467.59 20,349
HYDRA 725.18 652 439 1,039 18,062.78 16,226
B. Continuous Attack Evaluation
In this evaluation, we assessed the continuous attack strategy described in Section 2, executed over a 90-minute period with snapshots taken every 30 seconds. This resulted in 180 snapshots, making joint optimization across all snapshots computationally challenging. To examine the effect of the number of snapshots used for optimization, we selected evenly spaced subsets of snapshots from the 90-minute interval. This process produced different botnets based on the selected snapshots. We evaluated the effectiveness of each botnet by analyzing its ability to congest targeted paths. This assessment was conducted for each 30-second snapshot. Accuracy was measured as the percentage of successful attacks over the time window, representing the proportion of snapshots where the botnet achieved the intended congestion. The computation time required to solve the optimization problem varied depending on the network conditions and targeted zones. It ranged from a few seconds for simpler cases to a few hours for complex scenarios with larger numbers of snapshots, with an average computation time of 480 seconds. Figure 2 illustrates how the number of snapshots used in the optimization affects the success rate of continuous attacks over a 90-minute period. The botnet is obtained by solving the optimization problem with varying numbers of snapshots. Using only 2–5 snapshots produces lower success rates. As the snapshot count increases, performance surpasses 90% with 30–60 snapshots, and approaches 99% with 90 snapshots. Although the use of fewer snapshots significantly reduces the computation time, continuous congestion is not sustained over the entire 90-minute period, indicating that higher snapshot counts enhance overall attack effectiveness. To evaluate the attack strategy’s robustness over an extended period, we used the botnet computed for one 90minute interval with varying numbers of snapshots. The scenario was analyzed over 90 hours with 30-second intervals, using the execution phase to assess attack accuracy over time. The trend observed in Figure 2 continued. Over the 90-hour evaluation period, the average success rate varied by only around 2%, demonstrating the strategy’s
Change −33.9% −35.6% −31.4% −32.6% −23.0% −20.3%
distribution. In our experiments, α = 0.9, corresponding to 90% utilization and 10% headroom. Table II summarizes the concrete values used in our experiments. The GPOs were represented as discussed in Section 1, using a triangulated grid that created 1,800 points. The per-host upload limit was assumed to be 25 Mbps [23]. A. Botnet Resource-Threshold Comparison
To compare the botnet resource thresholds estimated by HYDRA and ICARUS, we evaluated single-snapshot attack instances under matched experimental conditions, including the same network snapshot topology, background traffic state, routing model, link capacities, congestion threshold α, per-bot upload cap β , and GPO grid. DoSat and StarMaze study complementary LEO LFA mechanisms, but we compare them qualitatively in Table I because we did not identify public implementations that could be faithfully integrated into our evaluation setting. Because ICARUS emphasizes stealth by distributing attack traffic across uplinks, quantified by the maxUp metric [8], we constrain HYDRA using the same detectability metric. As defined in ICARUS [8], maxUp measures the maximum attack-induced traffic increase observed at any single source uplink. Specifically, for each evaluated instance, HYDRA is constrained so that its maximum source uplink traffic does not exceed the ICARUS maxUp value. As shown in Table III, HYDRA reduces the required botnet size by 33.9% on average relative to ICARUS. This reduction is also consistent across the distribution, with 9
100
8000
95
7000 6000
Botnet Size
Accuracy (%)
90
5000 4000
85
3000
80
2000 1000
75
0
70
5 Data point
65 60 0
0
20
40
60
Number of Snapshots
10
15
20
Number of Zone Pairs Average point
25
30
35
Square-root trend
Fig. 3. Botnet size versus the number of targeted zone pairs. Gray points show individual runs, blue points show the means, and the red line shows the fitted square-root trend.
80
Fig. 2. Impact of the number of snapshots used for optimization on the attack success rate when performing continuous attacks over a 90-minute period.
robustness and consistent high performance despite the extended duration and evolving network conditions. C. Flexible Botnet Configuration Attack Evaluation Fig. 4. Distribution of the botnet computed to attack 33 zone pairs, which achieved a 65% success rate across 3,500 randomly sampled zone pairs.
We evaluate the flexible botnet configuration approach, which is aimed at minimizing the size of the botnet while maintaining the ability to attack any selected zone pair, as described in Section 3. Instead of solving each optimization problem independently, this approach identifies a global botnet, optimizing the allocation of resources across multiple attacks. In this evaluation, we analyze the performance of the resulting attacks as a function of the number of targeted zone pairs. For this analysis, we examined attacks targeting between 1 and 35 zone pairs. The average botnet size required to attack each set of targeted zone pairs is presented in Figure 3. As the number of zone pairs increases, the size of the required botnet also increases. However, the rate of growth decreases as the number of pairs increases. This trend √ can be captured by a square root curve y = 978 x − 12, depicted in red, with R2 = 0.99 in Figure 3. The slowing growth rate in required botnet size demonstrates the efficiency of the flexible configuration. This efficiency enables the targeting of more pairs with relatively few additional resources, which enhances the botnet’s effectiveness in large-scale scenarios. An example of the layout of the distribution of the computed botnet is illustrated in Figure 4, which depicts the computed layout for attacking 33 zone pairs. To assess the generalizability of the flexible configuration for global attacks, we randomly sampled 3,500 additional zone pairs based on GDP data and evaluated how effectively the different botnets could target them. The global attack accuracy, measured as the percentage of sampled pairs successfully attacked, is presented in Figure 5. The blue line represents the average global at-
tack accuracy of HYDRA-optimized botnets weaponized in the flexible configuration phase described earlier in this subsection. For comparison, we evaluated randomly generated botnets of the same size, which are represented by the red line. For each HYDRA-optimized botnet size, we evaluated 10 different randomly generated botnets of the same size. The results of these botnets were averaged to evaluate their effectiveness in attacking the sampled zone pairs. HYDRA-optimized botnets outperformed the randomly generated ones, especially for smaller botnet sizes, where they achieved about 20% higher global attack accuracy. Even larger botnets maintained an advantage, attacking 5–10% more zone pairs globally. These results demonstrate the efficiency and scalability possible when strategically selecting botnet locations. D. Targeted Simultaneous Attacks
In this section, we evaluate the simultaneous attack strategy described in Section 4, focusing on targeting multiple zone pairs concurrently. We conducted the evaluation on groups of zone pairs, with each group containing 1–35 pairs; multiple evaluations were performed for each group size. To assess this approach, we examined the botnet size as a function of the number of simultaneously attacked zone pairs. Figure 6 shows a strong square root trend in the relationship between botnet size and the number of simulta10
Global Attack Accuracy (%)
80
TABLE IV Attack sensitivity to α and β . Each cell reports feasibility percentage / mean botnet size relative to β = 25 for the same α.
60
α 0.85 0.90 0.95
40
1000
2000
3000
4000
Botnet Size
5000
6000
HYDRA-Optimized Botnets
7000
Random Botnets
Fig. 5. Global attack accuracy as a function of botnet size for HYDRA-optimized botnets and randomly generated botnets of the same size.
neously attacked zone √ pairs. This trend can be captured by the curve y = 2,385 x−2,335, with R2 = 0.992, which is shown in red in Figure 6. This trend is largely influenced by zone pairs whose paths have ISLs in common or by attack paths that intersect multiple ISLs, which may become congested due to overlapping attacks. Closer zone pairs are more likely to experience these effects, thereby reducing the required botnet size. These results demonstrate efficient resource utilization, with square root growth in botnet size observed as the number of simultaneously attacked pairs increases. For example, simultaneously attacking 15 pairs required an average botnet size of 6,994 bots. 17500
To assess whether HYDRA’s feasibility trends are specific to the main Starlink-like shell, we evaluated single-snapshot attack instances across ten LEO constellation configurations. For each configuration, we report the constellation parameters, the feasibility percentage, and the mean botnet size over feasible instances. As shown in Table V, HYDRA remains feasible across a broad range of LEO constellation configurations, with feasibility ranging from 85.8% to 99.6%. The required botnet size also remains within the same order of magnitude across configurations, with mean botnet sizes ranging from 679 to 1,047 bots. These results indicate that the observed attack feasibility is not limited to a single topology, although constellation structure affects both the percentage of feasible attack instances and the required botnet size.
12500
Botnet Size
β = 50 89.71% / 50.1% 88.83% / 50.1% 87.76% / 50.1%
F. Cross-Constellation Sensitivity
15000 10000 7500 5000 2500 0
β = 25 89.68% / 100.0% 88.83% / 100.0% 87.73% / 100.0%
setting, we used the same topology, background traffic, routing model, and sampled zone pairs. We report the percentage of feasible attacks and the mean required botnet size normalized to the corresponding β = 25 setting for the same value of α. Table IV shows two main trends. First, increasing α slightly reduces feasibility, from about 89.7% at α = 0.85 to about 87.7% at α = 0.95. This is expected because larger α values require links to be driven closer to saturation before they satisfy the congestion condition. Second, changing β has little effect on feasibility but changes the required botnet size almost proportionally. Reducing the per-bot upload limit from 25 Mbps to 10 Mbps increases the mean required botnet size by about 2.5×, while increasing it to 50 Mbps reduces the required botnet size by about half. This indicates that β primarily scales the number of bots needed to generate a feasible traffic allocation, whereas α affects whether the targeted congestion condition can be reached under the modeled topology and capacity constraints. These results show that a network’s resilience to LFAs depends on the upload capacity available to individual compromised terminals, since lower per-terminal upload capacities require larger botnets to achieve the same disruption.
20
0 0
β = 10 89.73% / 249.7% 88.86% / 249.7% 87.74% / 249.6%
0
5 Data point
Fig. 6.
10
15
20
25
30
Number of Zone Pairs Average point
35
Square-root trend
Botnet size versus number of zone pairs simultaneously attacked.
E. Sensitivity to Congestion and Bot Upload Parameters
VI. Mitigation Strategies
The main evaluation uses α = 0.9 and β = 25 Mbps. To assess whether the results depend on these specific values, we perform a sensitivity analysis over α ∈ {0.85, 0.90, 0.95} and β ∈ {10, 25, 50} Mbps. For each
In this section, we use HYDRA to evaluate how different mitigation mechanisms affect the resilience of LEO networks to LFAs. Our goal is not to determine whether a single attack instance can be prevented, but 11
TABLE V Constellation sensitivity of the HYDRA minimum-user attack across representative LEO constellation scenarios. Scenario Starlink baseline Densified Starlink OneWeb polar scenario Expanded OneWeb scenario Sun-synchronous scenario Kuiper 630-km shell Starlink 70◦ scenario Kuiper 610-km shell Low-inclination Walker scenario High-altitude Walker scenario
Planes
Sats/plane
72 72 18 20 34 34 36 36 60 70
22 30 40 50 32 34 22 36 24 25
Incl. (deg.) 53.0 53.0 86.4 86.4 97.4 51.9 70.0 42.0 30.0 55.0
Alt. (km) 550 550 1200 1200 600 630 570 610 550 1200
Feasibility
Mean bots
85.8% 92.3% 95.6% 99.6% 99.6% 97.2% 94.9% 96.6% 93.3% 89.3%
679 786 894 813 935 776 884 1,047 1,045 814
work conditions, while probabilistic routing [45] introduces randomized path selection. Following [45], for each source-destination pair the routing procedure randomly selects among four path-selection strategies with fixed probabilities: KSP with probability 0.703, KDG with probability 0.070, KDS with probability 0.143, and KLO with probability 0.084. We then re-evaluate HYDRA using the routes produced by this randomized routing policy. KBM follows the bottleneck-minimization routing approach of [46]. Each link is assigned a bottleneck score, and route computation uses this score as the Dijkstra edge weight rather than physical distance. Candidate paths are accepted only if their physical length remains within a bounded stretch of the source-destination distance. After a candidate path is selected, its ISL edges are disabled before searching for additional alternatives, encouraging path diversity and reducing repeated use of bottleneck links. In our evaluation, we use a stretch bound of 1.53 and generate up to k = 5 candidate paths. We further evaluate segment-routing multipath inspired by LGSR [47]. LGSR partitions the constellation into regions, abstracts them into a skeleton graph, and uses segment routing to guide traffic across landmark-based skeleton paths. Within each skeleton segment, probabilistic multipath forwarding spreads traffic over multiple local forwarding choices to improve load balancing and avoid hotspot congestion. In our evaluation, we adapt this idea by generating k = 3 segment-routed candidate paths per source-destination pair under a stretch bound of 1.70. As shown in Figure 7, all three routing defenses reduce HYDRA’s global attack success relative to shortestpath routing. The reduction is most pronounced at small and medium botnet sizes. KBM provides the strongest reduction, probabilistic routing produces a noticeable reduction, and segment-routing multipath provides a smaller but measurable reduction. As the botnet size increases, the attacker partially recovers because a larger botnet provides more source-destination options for reaching targeted congestion links. The multipath result shows that path diversity alone is not sufficient to fully neutralize HYDRA, since multiple candidate routes in the targeted area may still share exploitable bottlenecks or provide alternative bottlenecks that the attacker can target. Overall, these
to measure how each mechanism changes the adversary’s overall ability to execute attacks at a global scale. We define global attack success as the percentage of the 3,500 GDP-weighted randomly sampled zone pairs that a given attack configuration successfully attacks, using the same set of pairs from the flexible-botnet analysis. This allows us to evaluate whether a mitigation reduces global attack success, increases the resources required for disruption, or limits the attacker’s ability to reuse an optimized botnet across targets. We evaluate five mitigation strategies that target different dependencies of the attack: routing diversification, link-triggered source throttling, ingress capacity policing, distance-based traffic constraints, and botnet attrition. We then re-evaluate attack feasibility under the modified constraints and compare the resulting global attack success to the unmitigated baseline. Potential QoS implications and operational trade-offs are discussed qualitatively at the end of this section. A. Route Diversification
LFAs depend on routing behavior because the selected routes determine whether attack traffic reaches the links the adversary seeks to congest. This makes routing a natural mitigation point: by diversifying route selection or avoiding heavily used links, the defender can reduce the attacker’s ability to concentrate traffic on the same bottlenecks. To evaluate this routing dependency, we implement three routing-based defenses from prior work: probabilistic routing [45], Bottleneck-Minimize Routing (KBM) [46], and segment-routing multipath inspired by landmark-based skeleton routing for broadband LEO constellations [47]. Probabilistic routing reduces path predictability, KBM avoids bottleneck-heavy routes, and segment-routing multipath increases route diversity. Together, these mechanisms target the path consistency that LFAs exploit, making it harder for an adversary to direct limited botnet resources through the links selected for congestion. Recent work on LEO routing has explored route selection as a defense mechanism against congestion and DDoS-style disruption. For example, GRL-RR [48] and STARCURE [49] adapt routing decisions to net12
100
80
80
Global Attack Accuracy (%)
Global Attack Accuracy (%)
100
60 40 20 0
5000
10000
15000
Botnet Size
Shortest-Path Routing Probabilistic Routing
20000
25000
40 20
30000
00
KBM Routing Segment-Routing Multipath
5000
10000
15000
Botnet Size
Baseline Step 5 Mbps/round, floor 10 Mbps
Fig. 7. Effect of route diversification on global attack success. Probabilistic routing reduces path predictability, KBM avoids bottleneck-heavy routes, and segment-routing multipath increases route diversity. KBM and probabilistic routing provide the strongest reductions relative to deterministic shortest-path routing, while segment-routing multipath provides a smaller reduction.
20000
25000
30000
Hard cap 15 Mbps Hard cap 20 Mbps
Fig. 8. Effect of link-triggered source throttling on global attack success. Throttling reduces the bandwidth available to traffic sources associated with congested links, either through a hard cap or a fixed-step reduction.
results show that routing diversity and bottleneck-aware path selection can raise the botnet resources required for successful disruption, especially when the adversary operates with a limited bot population.
We then re-evaluate HYDRA under these updated sourceside bandwidth limits. Figure 8 shows that link-triggered source throttling reduces HYDRA’s attack success relative to the baseline. The effect is most visible at small and medium botnet sizes, where reducing the bandwidth of congestioncontributing sources leaves the attacker with fewer effective allocation options. This effect is strongest under repeated throttling, because sources that continue to contribute to congestion have their effective sending limits reduced over multiple rounds. At larger botnet sizes, the attacker has more sources available, so the relative benefit of throttling becomes smaller.
B. Throttling Based on Congestion Source Attribution
Next, we evaluate a mitigation strategy based on linktriggered source throttling. This approach is inspired by prior DDoS defenses [50], [51] that treat overload as a congestion-control problem and apply rate limits to traffic aggregates that contribute to congestion. When a link becomes congested, the defender applies rate limits to users or traffic aggregates that send traffic through the congested link. This mitigation does not require identifying which users are malicious, because throttling is applied to all traffic sources associated with the congested link. Let Ut,l denote the set of users or traffic aggregates whose traffic traverses link l at snapshot t. For each user (r) u ∈ Ut,l , let κu be the effective sending limit after throttling round r. The total traffic sent by user u is constrained by Rt,u ≤ κ(r) u ,
60
C. Ingress Capacity Policing
Another strategy we evaluate is ingress capacity policing, a mitigation that limits the traffic admitted into the constellation at network entry points. This idea follows traffic conditioning and ingress policing, where traffic is regulated close to where it enters the network [52], [53]. In LEO satellite networks, uplink GSLs provide natural enforcement points because user traffic enters the constellation only through these links. The geographic origin of uplink traffic can also be estimated from physical-layer measurements, as prior work shows that satellite constellations can localize ground devices using received signal strength and Doppler measurements [54]. By enforcing admission budgets at the uplink GSLs or at geographic source areas, the defender can constrain excess traffic before it propagates through the network and contributes to downstream congestion. This is especially relevant when adversarial traffic is concentrated in specific geographic regions, since ingress policing limits the excess traffic admitted from those regions. These admission budgets should reflect the expected nominal demand of
(20)
where Rt,u denotes the aggregate traffic generated by user u at snapshot t. After each throttling round, users associated with congested links receive a lower sending limit. We evaluate two simple policies. The first applies a hard cap κ(r+1) = min κ(r) (21) u u , κcap . The second reduces the limit gradually by a fixed step while preserving a minimum floor κ(r+1) = max κmin , κ(r) (22) u u −∆ . 13
100
of a specific source area. Overall, these results show that ingress policing can hinder LFA-style attacks in satellite constellations and increase the resources required for successful disruption.
Global Attack Accuracy (%)
80 60
D. Distance-Based Traffic Constraints 40
Distance-based traffic constraints limit the amount of traffic that can be sent between geographically distant source-destination pairs. The mitigation applies stricter sending limits as the distance between the source and destination increases, while leaving shorter flows less affected. For LFAs, this reduces the attacker’s ability to use distant destinations to steer traffic from distributed bot locations through targeted congestion links. Let d(gs , gd ) denote the geographic distance between GPOs gs and gd . We model distance-based mitigation as a per-user sending limit that depends on the distance to the destination GPO. For each user located at gs and sending traffic toward gd , the admissible sending rate is capped by σt,gs ,gd β , where σt,gs ,gd ∈ [0, 1] and β is the nominal per-user sending limit. When σt,gs ,gd = 1, the user’s sending limit is unchanged and σt,gs ,gd = 0 blocks that source-destination direction. We evaluate several forms of σt,gs ,gd . The first is a hard distance limit ( 1, d(gs , gd ) ≤ dmax , σt,gs ,gd = (25) 0, d(gs , gd ) > dmax .
20 00
5000
10000
Baseline GSL ingress cap 15% GSL ingress cap 30%
15000
Botnet Size
20000
25000
30000
Source-area upload cap 25% Source-area upload cap 50%
Fig. 9. Effect of ingress capacity policing on global attack success. GSL ingress caps limit uplink admission capacity directly, while source-area upload caps limit admitted traffic relative to expected nominal demand from each source area.
each region, so that regular service is preserved while unusually large traffic injections are limited. We evaluate this mitigation using fixed caps on uplink GSL admission capacity and demand-based caps on the upload traffic admitted from each source area. To model fixed ingress caps at the GSL level, let ρ ∈ (0, 1] denote the ingress-cap ratio. Under ingress capacity policing, the total traffic admitted through each GSL is limited to a fraction ρ of that link’s capacity X (TMt,gs ,gd + ATMt,gs ,gd ) ≤ ρcmax , l
This policy blocks source-destination flows whose geographic distance exceeds dmax . We also evaluate a gradual distance-decay policy, where the allowed sending rate decreases as the source-destination distance increases beyond a reference distance d0
gs ,gd : l∈Ft (gs ,gd )
∀l ∈ LGSL . t
(23)
σgexp ,g = s d 1,
For the demand-based source-area policy, each GPO serves as a source area. Let λ̄g denote the expected nominal upload demand from source area g ∈ N GP O , estimated from the background traffic profile, and let η denote the allowed excess-demand ratio. The resulting constraint limits the total traffic admitted from each source area relative to its expected nominal demand as X (TMt,g,gd + ATMt,g,gd ) ≤ (1 + η)λ̄g , ∀g ∈ N GP O .
d(gs , gd ) ≤ d0 , − ln(2)
max σmin , e
d(gs ,gd )−d0 d1/2
,
d(gs , gd ) > d0 .
(26) For source-destination pairs with d(gs , gd ) ≤ d0 , no rate reduction is applied. For pairs with d(gs , gd ) > d0 , the allowed sending rate decreases with distance until it reaches the minimum value set by σmin . The parameter d1/2 controls how quickly this decrease occurs. We also consider a hop-aware traffic constraint, where route length is represented by the number of satellites traversed by a source-destination flow. In this mitigation, source-destination pairs that traverse more satellites receive a lower sending limit. Let h(gs , gd ) denote the representative number of satellites traversed by traffic from gs to gd , assuming the shortest available route. For each GPO pair, we define the hop-aware sending-rate factor as ( 1, h(gs , gd ) ≤ hfree , hop q σgs ,gd = hfree max σmin , h(gs ,gd ) , h(gs , gd ) > hfree , (27)
gd
(24) Figure 9 shows that ingress policing reduces HYDRA’s global attack success, but the effect differs across the two policies. Source-area upload caps produce the strongest reduction, especially as the botnet size increases. This occurs because larger botnets may place more bots in the same source areas, where their combined upload is constrained by the same demand-based cap, limiting the usable contribution of additional bots in those areas. GSL ingress caps also reduce attack success by limiting the total traffic admitted through each uplink link, but their effect is less pronounced because each cap applies to aggregate GSL traffic rather than to the upload budget 14
100
80
80
Global Attack Accuracy (%)
Global Attack Accuracy (%)
100
60 40 20 00
5000
10000
Baseline Hard limit (8,000 km) Exp decay
15000
Botnet Size
20000
25000
60 40 20 00
30000
Hop throughput (hfree = 2, q = 3) Hop throughput (hfree = 3, q = 3)
5000
10000
Baseline
15%
15000
Botnet Size
20000
25%
25000
30000
35%
45%
Fig. 11. Impact of botnet attrition on global attack success. Higher attrition rates reduce the attacker’s ability to re-optimize after used bots are removed from the available bot pool.
Fig. 10. Effect of distance-based and hop-aware traffic constraints on global attack success. Hard distance limits block long-distance source-destination flows, exponential decay gradually reduces admissible traffic with geographic distance, and hop-throughput policies reduce admissible traffic for routes that traverse more satellites.
force the attacker to re-optimize with a smaller and less favorable bot pool. Let B(r) denote the set of bots available to the attacker after attrition round r, and let U (r) ⊆ B(r) denote the bots used by the optimized attack allocation in that round. Let Aη denote an attrition process with attrition intensity η ∈ [0, 1]. After round r, the defender removes a subset of the bots used by the optimized attack allocation, R(r) = Aη U (r) , R(r) ⊆ U (r) . (28)
where hfree is the number of hops allowed before throughput reduction is applied, q controls the aggressiveness of the hop-based throughput reduction, and σmin is the minimum permitted sending-rate multiplier. Thus, routes that traverse more satellites receive a lower per-user sending limit. Figure 10 shows that distance-based and hop-aware traffic constraints reduce HYDRA’s global attack success relative to the baseline. The strongest reduction is obtained by the hop-throughput policy with hfree = 2 and q = 3, which sharply limits the contribution of longer satellite-hop routes and keeps attack success substantially below the baseline across botnet sizes. The hard 8,000 km limit also provides a strong reduction by removing long-distance source-destination flows entirely. Softer policies, such as exponential distance decay and the hop-throughput policy with hfree = 3, reduce attack success more gradually, but allow the attacker to recover more as botnet size increases. These results show that both geographically distant flows and longer satellitehop routes provide useful attack options for reaching bottleneck links. Constraining these flows reduces the feasible attack space and increases the resources required for successful disruption.
The attacker pool for the next round is then updated as B (r+1) = B (r) \ R(r) .
(29)
(r)
Equivalently, each removed bot b ∈ R has zero effective sending capacity in subsequent evaluations (r+1)
βb
= 0.
(30)
In our experiments, we instantiate Aη by uniformly sampling an η fraction of the bots used by the optimized attack allocation in each attrition round. We evaluate attrition rates of 15%, 25%, 35%, and 45%. Figure 11 shows that botnet attrition reduces HYDRA’s attack success relative to the baseline, with the strongest impact at small and medium botnet sizes. HYDRA minimizes the active bot resources required for each attack, so attrition is applied to the compact set of bots exposed during the optimized attack rather than to the entire candidate botnet. When the available bot pool is small, removing part of this active set leaves fewer alternatives for re-optimization, leading to a larger reduction in attack feasibility. For larger botnets, many candidate bots remain unused during each optimized attack, allowing the attacker to replace removed bots from reserve sources in subsequent iterations. These results suggest that attrition is most effective when the attacker has limited reserve capacity. Combining attrition with the mitigation strategies evaluated earlier
E. Botnet Attrition
We next evaluate botnet attrition as a reactive mitigation that removes attacker-controlled bots after attack activity is observed. This models remediation actions such as blocking, cleanup, quarantine, or loss of attacker control over participating bots. Since HYDRA repeatedly relies on effective bot locations, removing used bots can 15
is therefore a more promising direction for reducing the feasibility of HYDRA and similar LFA attacks.
routing and traffic assumptions, HYDRA maintains over 97% success in continuous attacks and scales efficiently to multiple targets, with square-root botnet growth as the number of targeted zone pairs increases. We also show the defensive potential of routing diversification, source throttling, ingress policing, distance-based traffic constraints, and botnet attrition in strengthening the network’s resilience to LFAs. These findings highlight structural vulnerabilities in LEO constellations and reinforce the need for defenses that account for routing behavior, traffic admission, source bandwidth limits, botnet reuse, and the constellation’s evolving topology. As LEO satellite networks continue to expand and support increasingly important communication services, understanding the resource requirements of LFAs and the trade-offs involved in mitigating them is essential for improving network resilience against such attacks.
F. Operational Deployment Trade-offs
Implementing mitigation mechanisms in real LEO networks introduces a trade-off between reducing attack feasibility and preserving quality of service (QoS). Stricter mitigation policies can make LFAs harder to execute, but they may also reduce QoS by increasing latency, limiting legitimate traffic bursts, or degrading service for users whose traffic matches the mitigation policy. Route diversification can reduce path predictability, but longer or less direct routes may increase latency. Link-triggered source throttling can relieve congested links, but it may also rate limit benign users whose traffic traverses those links. Ingress capacity policing can constrain excessive uplink traffic at network entry points, but strict admission budgets may reduce service quality during legitimate demand spikes. Distance-based traffic constraints can limit the attacker’s use of globally distributed bots, but distance-aware rate shaping may also degrade QoS for legitimate long-distance traffic, a core use case of satellite constellations. Botnet attrition can weaken the attacker’s available bot pool, but aggressive remediation may disrupt service for legitimate users if detection misidentifies benign activity as malicious. The goal of this mitigation analysis is to show the defensive potential of these directions and quantify how they strengthen the network’s resilience to LFAs. In practice, each mitigation would need to be tailored to the operator’s constellation design, routing architecture, customer base, service-level requirements, and acceptable QoS impact. A production deployment would therefore require operatorspecific tuning of enforcement thresholds, traffic policies, and service guarantees.
Ethical Considerations
This work analyzes LFAs in LEO satellite networks to quantify adversarial resource thresholds and evaluate defensive strategies. The study is conducted entirely in simulation and does not involve experiments on operational satellite systems, production networks, or real users. HYDRA is intended as a risk-assessment and resilienceevaluation framework for researchers and network operators, enabling them to assess how routing, capacity controls, throttling, traffic constraints, and botnet availability affect attack feasibility. Because the techniques studied in this paper are dual-use, we frame the analysis around defensive planning, capacity assessment, and mitigation evaluation rather than operational guidance for disrupting deployed satellite services. Acknowledgment
VII. Conclusion
The authors used OpenAI’s ChatGPT and Anthropic’s Claude to assist with grammar review, language review, and editorial refinement throughout the manuscript. The tools were used to improve clarity and presentation, not to generate experimental results, figures, or technical claims. The authors reviewed and edited all assisted text.
This paper introduced HYDRA, an optimization-based framework for modeling strategic LFAs in dynamic LEO satellite networks. HYDRA captures the attack planning problem under time-varying topology, limited bot availability, per-bot upload constraints, and geographic placement constraints. Rather than assuming widespread control over compromised devices, as in prior work, HYDRA identifies the smallest active bot set and traffic allocation needed to congest GSL and ISL links between targeted geographic zones across time-varying topologies. Our evaluation shows that HYDRA provides a resource-threshold view of LEO network resilience to LFAs by quantifying the minimum botnet resources required for targeted disruption. In single-snapshot zoneattack instances, HYDRA reduces the active botnet required to reach the same modeled congestion objective by 34% relative to an ICARUS stealth-distribution baseline under matched detectability constraints, while also reducing aggregate attack flow by 23%. Under the modeled
REFERENCES [1] SpaceX, “Sat-mod-20190830-00087,” https://fcc.report/IBFS/ SAT-MOD-20190830-00087/1877671, 2019. [2] A. Kuiper, “Sat-loa-20211104-00145,” https://fcc.report/IBFS/ SAT-LOA-20211104-00145, 2021. [3] Z. Qu, G. Zhang, H. Cao, and J. Xie, “Leo satellite constellation for internet of things,” IEEE access, vol. 5, pp. 18 391–18 401, 2017. [4] F. Vatalaro, G. E. Corazza, C. Caini, and C. Ferrarelli, “Analysis of leo, meo, and geo global mobile satellite systems in the presence of interference and fading,” IEEE Journal on selected areas in communications, vol. 13, no. 2, pp. 291–300, 1995. [5] Starlink, “Starlink direct-to-cell,” https://www.starlink.com/ business/direct-to-cell, 2024. 16
[27] “Mynaric,” https://mynaric.com/products/space/. [28] Y. Zhang, Q. Wu, Z. Lai, and H. Li, “Enabling low-latency-capable satellite-ground topology for emerging leo satellite networks,” in IEEE INFOCOM 2022-IEEE Conference On Computer Communications. IEEE, 2022, pp. 1329–1338. [29] A. U. Chaudhry and H. Yanikomeroglu, “On crossover distance for optical wireless satellite networks and optical fiber terrestrial networks,” in 2022 IEEE Future Networks World Forum (FNWF). IEEE, 2022, pp. 480–485. [30] C. Douligeris and A. Mitrokotsa, “Ddos attacks and defense mechanisms: classification and state-of-the-art,” Computer networks, vol. 44, no. 5, pp. 643–666, 2004. [31] M. Antonakakis, T. April, M. Bailey, M. Bernhard, E. Bursztein, J. Cochran, Z. Durumeric, J. A. Halderman, L. Invernizzi, M. Kallitsis et al., “Understanding the mirai botnet,” in 26th USENIX security symposium (USENIX Security 17), 2017, pp. 1093–1110. [32] M. S. Kang, S. B. Lee, and V. D. Gligor, “The crossfire attack,” in 2013 IEEE symposium on security and privacy. IEEE, 2013, pp. 127–141. [33] J. Willbold, M. Schloegel, M. Vögele, M. Gerhardt, T. Holz, and A. Abbasi, “Space odyssey: An experimental software security analysis of satellites,” in 2023 IEEE Symposium on Security and Privacy (SP). IEEE, 2023, pp. 1–19. [34] P. Yue, J. An, J. Zhang, J. Ye, G. Pan, S. Wang, P. Xiao, and L. Hanzo, “Low earth orbit satellite security and reliability: Issues, solutions, and the road ahead,” IEEE Communications Surveys & Tutorials, vol. 25, no. 3, pp. 1604–1652, 2023. [35] Cyberpeace Institute, “Viasat Cyberattack Case Analysis,” https:// cyberconflicts.cyberpeaceinstitute.org/law-and-policy/cases/viasat, 2024. [36] Viasat, “An update on the ka-sat network cyber attack,” https://news.viasat.com/blog/corporate/ ka-sat-network-cyber-attack-overview, 2022. [37] K. Lab, “The epic turla operation,” https://securelist.com/ the-epic-turla-operation/65545/, 2014. [38] S. S. Response, “Turla: Spying tool targets governments and diplomats,” https://www.security.com/threat-intelligence/ turla-espionage-diplomats, 2014. [39] R. Rasti, M. Murthy, N. Weaver, and V. Paxson, “Temporal lensing and its application in pulsing denial-of-service attacks,” in 2015 IEEE Symposium on Security and Privacy. IEEE, 2015, pp. 187– 198. [40] K. Sahr, D. White, and A. J. Kimerling, “Geodesic discrete global grid systems,” Cartography and Geographic Information Science, vol. 30, no. 2, pp. 121–134, 2003. [41] Gurobi Optimization, LLC, “Gurobi Optimizer Reference Manual,” 2024. [Online]. Available: https://www.gurobi.com [42] E. OneWeb, “Eutelsat oneweb,” https://www.eutelsat.com/, 2024. [43] W. D. Nordhaus and X. Chen, “Global gridded geographically based economic (g-econ) data set, version 4,” Palisades, NY, 2016. [Online]. Available: https://www.earthdata.nasa.gov/data/ catalog/sedac-ciesin-sedac-spatialecon-gecon4-4.0 [44] Kaggle, “Global cities by gdp,” https://www.kaggle.com/datasets/ khushikhushikhushi/global-cities-by-gdp, 2024. [45] R. Fratty, Y. Saar, R. Kumar, and S. Arnon, “Random routing algorithm for enhancing the cybersecurity of leo satellite networks,” Electronics, vol. 12, no. 3, p. 518, 2023. [46] F. Meng, X. Yan, Y. Zhang, J. Yang, A. Cao, R. Liu, and Y. Zhao, “Mitigating ddos attacks in leo satellite networks through bottleneck minimize routing,” Electronics, vol. 14, no. 12, p. 2376, 2025. [47] M. Hu, C. Wang, B. Cao, B. Zhou, Y. Dong, and K. Peng, “A lightweight and scalable design of segment routing in broadband leo constellations using landmark-based skeleton graphs,” arXiv preprint arXiv:2411.19679, 2024. [48] L. Bai, H. Ma, Y. Jiang, Z. Yin, H. Wan, and H. Wang, “Grl-rr: A graph reinforcement learning-based resilient routing framework for
[6] D. Bhattacherjee and A. Singla, “Network topology design at 27,000 km/hour,” in Proceedings of the 15th International Conference on Emerging Networking Experiments And Technologies, 2019, pp. 341–354. [7] M. Handley, “Delay is not an option: Low latency routing in space,” in Proceedings of the 17th ACM Workshop on Hot Topics in Networks, 2018, pp. 85–91. [8] G. Giuliari, T. Ciussani, A. Perrig, and A. Singla, “{ICARUS}: Attacking low earth orbit satellite networks,” in 2021 USENIX Annual Technical Conference (USENIX ATC 21), 2021, pp. 317– 331. [9] Y. Deng, Q. Wu, Z. Lai, C. Gu, H. Li, Y. Li, and J. Liu, “Timevarying bottleneck links in leo satellite networks: Identification, exploits, and countermeasures.” in NDSS, 2025. [10] E. Arevalo, “Spacex starlink satellites with lasers could soon enable internet in countries like afghanistan without a ground station,” https://www.tesmanian.com/blogs/tesmanian-blog/ starlink-laser-6months, 2021. [11] Y. Hauri, D. Bhattacherjee, M. Grossmann, and A. Singla, “” internet from space” without inter-satellite links,” in Proceedings of the 19th ACM Workshop on Hot Topics in Networks, 2020, pp. 205–211. [12] T. Kelso, “Celestrak: Current gp element sets,” https://celestrak. org/NORAD/elements/, 2025. [13] T. Kelso et al., “Validation of sgp4 and is-gps-200d against gps precision ephemerides,” 2007. [14] “Threats to united states space capabilities,” https://spp.fas.org/ eprint/article05.html. [15] Y. Zhang, Q. Wu, Z. Lai, Y. Deng, H. Li, Y. Li, and J. Liu, “Energy drain attack in satellite internet constellations,” in 2023 IEEE/ACM 31st International Symposium on Quality of Service (IWQoS). IEEE, 2023, pp. 1–10. [16] M. Burgess, “The hacking of starlink terminals has begun,” Aug. 2022. [Online]. Available: https://www.wired.com/story/ starlink-internet-dish-hack/ [17] B. Bracken, “Killnet gloats ddos attacks on starlink, whitehouse.gov,” https://www.darkreading.com/threat-intelligence/ killnet-gloats-ddos-attacks-starlink-whitehouse-gov, 2022. [18] A. Studer and A. Perrig, “The coremelt attack,” in European Symposium on Research in Computer Security. Springer, 2009, pp. 37–52. [19] T. Lu, X. Ding, J. Shang, P. Zhao, and H. Zhang, “Dosat: a ddos attack on the vulnerable time-varying topology of leo satellite networks,” in International Conference on Applied Cryptography and Network Security. Springer, 2024, pp. 265–282. [20] Y. Wang, H. Li, Z. Lai, and J. Li, “Starmaze: Ring-based attack in satellite internet constellations,” in 2024 IEEE/ACM 32nd International Symposium on Quality of Service (IWQoS). IEEE, 2024, pp. 1–10. [21] M. Fagan, J. Marron, P. Watrobski, M. Souppaya, and W. Barker, “Trusted internet of things (iot) device network-layer onboarding and lifecycle management: Enhancing internet protocol-based iot device and network security,” NIST SPECIAL PUBLICATION, vol. 1800, p. 36, 2023. [22] Starlink, “Starlink is connecting more than 10M active customers with high-speed internet across 160 countries, territories and many other markets,” Feb. 2026. [Online]. Available: https: //x.com/Starlink/status/2022446814591615013 [23] Starlink, “Starlink specifications,” https://starlink.com/legal/ documents/DOC-1470-99699-90, 2026. [24] SpaceX, “Sat-amd-20210818-00105,” https://fcc.report/IBFS/ SAT-AMD-20210818-00105/12943362.pdf, 2021. [25] D. Fischer, D. Basin, and T. Engel, “Topology dynamics and routing for predictable mobile networks,” in 2008 IEEE International Conference on Network Protocols. IEEE, 2008, pp. 207–217. [26] R. Deng, B. Di, H. Zhang, L. Kuang, and L. Song, “Ultra-dense leo satellite constellations: How many leo satellites do we need?” IEEE Transactions on wireless communications, vol. 20, no. 8, pp. 4843–4857, 2021. 17
Transactions on Parallel and Distributed Systems, vol. 18, no. 7, pp. 983–995, 2007.
software-defined leo mega-constellations,” Computer Networks, vol. 259, p. 111089, 2025. [49] Z. Lai, H. Li, Y. Wang, Q. Wu, Y. Deng, J. Liu, Y. Li, and J. Wu, “Achieving resilient and performance-guaranteed routing in spaceterrestrial integrated networks,” in IEEE INFOCOM 2023-IEEE Conference on Computer Communications. IEEE, 2023, pp. 1– 10. [50] J. Ioannidis, “Pushback: Router-based defense against ddos attacks,” Proceedings of NDSS, February, 2002, 2002. [51] C. W. Tan, D.-M. Chiu, J. C. Lui, and D. K. Yau, “A distributed throttling approach for handling high bandwidth aggregates,” IEEE
[52] S. Blake, D. Black, M. Carlson, E. Davies, Z. Wang, and W. Weiss, “An architecture for differentiated services,” Tech. Rep., 1998. [53] J. Heinanen and R. Guérin, “A two rate three color marker,” Tech. Rep., 1999. [54] I. S. M. Hashim, A. Al-Hourani, and B. Ristic, “Satellite localization of iot devices using signal strength and doppler measurements,” IEEE Wireless Communications Letters, vol. 11, no. 9, pp. 1910–1914, 2022.
18