Vulnerability Assessment of Starlink User Terminals: Firmware and gRPC Communication Analysis

Citations

WEB OF SCIENCE

0
Citations

SCOPUS

0

초록

Modern society relies on communication networks; however, geographic constraints and infrastructure disparities perpetuate the global digital divide. Low Earth orbit (LEO) satellite communication has emerged as a promising solution. Companies such as SpaceX's Starlink, OneWeb, and Amazon Kuiper are deploying LEO constellations, with Starlink leading the market in commercial deployment and satellite count. Nevertheless, networking equipment remains a primary target for attackers because it handles large volumes of traffic and often incorporates lightweight security features. This study presents a vulnerability assessment of Starlink user terminals (Dishy and Router). Static analysis was performed by extracting and examining firmware, and dynamic analysis was conducted by recovering and analyzing the internal Google remote procedure call (gRPC) protocol structure. The analysis revealed security concerns arising from packet replay and policy asymmetries between the web-based user interface (UI) and the backend gRPC application programming interface (API). Specifically, advanced configuration features that are unlisted or restricted in the official UI could be successfully executed when invoked through the API server. This discrepancy indicates an unclear separation of privileges, potentially expanding the attack surface and enabling session hijacking. To mitigate these risks, fine-grained permission control across the web-based UI and gRPC endpoints is recommended. In addition, securing gRPC communications against tampering through data-integrity verification mechanisms, such as digital signatures with random numbers, is proposed. These findings are reported to SpaceX, and mitigation measures are suggested to enhance the security of LEO satellite communication systems.

키워드

Satellite constellationsSecuritySatellitesLow earth orbit satellitesSoftwareServersSatellite communicationsProtocolsInternetWireless communicationEmbedded systems securityfirmware securityIoT securitysatellite communication securitysatellite internetStarlinkuser terminalsvulnerability analysisTHREATS
제목
Vulnerability Assessment of Starlink User Terminals: Firmware and gRPC Communication Analysis
저자
Kim, SeoyulHan, Seunghun
DOI
10.1109/ACCESS.2026.3669344
발행일
2026-03
유형
Article
저널명
IEEE Access
14
페이지
36911 ~ 36923