NASA's cFS Flight Software Architecture Treats Onboard Components as Trusted Peers — One Compromised Module Is Hard to Distinguish From Normal
An architectural analysis of NASA's Core Flight Software examines how authority, identity, communication, observability, and persistence are distributed across onboard components, validated with five experiments on NASA's flight-representative NOS3 simulator using a malicious component that abuses only legitimate architectural privileges. A single compromised component can exploit broadly shared authority in ways difficult to separate from legitimate behavior, and comparison against other modular flight software frameworks finds the same trust assumptions recurring. The pattern generalizes past spacecraft: it is the same failure mode as a plugin architecture where every module inherits the host's permissions.
↳ Follow the thread