Hydra measures botnet needs for disrupting leo satellite networks

HYDRA: Quantifying Botnet Resource Thresholds for Efficient Link-Flooding Attacks on LEO Satellite Networks

Cryptography and Security

Summary

Low Earth orbit satellite networks like Starlink are important for fast internet but can be attacked by overwhelming their links with fake traffic. The authors created HYDRA, a tool that models how many fake devices (bots) and how much traffic an attacker needs to disrupt communication between specific areas. HYDRA shows that fewer bots and less traffic are needed than previous estimates, and it tests ways to defend the network by changing routing and limiting traffic. This helps understand and improve the security of these satellite systems against targeted attacks.

What this means in practice

  • For network security teams: Estimate minimal attacker resources needed to compromise satellite network links and evaluate defenses for better protection.
  • For satellite network operators: Test and choose mitigation strategies to maintain connectivity despite evolving satellite network topologies facing targeted attacks.

Authors

Roee Idan, Rami Puzis, Asaf Shabtai, Yuval Elovici

Abstract

Low Earth orbit (LEO) satellite constellations, such as Starlink and Kuiper, are rapidly emerging as a critical backbone for low-latency global connectivity. As these systems expand, they become more attractive attack targets, necessitating increased resilience and security. Threat actors seek to exploit constellation-specific properties such as predictable motion, time-varying topologies, and reliance on inter-satellite and ground-satellite links. Recent work has shown that link-flooding attacks (LFAs) can exploit these properties to congest strategic network bottlenecks. Yet, prior work does not quantify the resilience of LEO networks to targeted disruption. We present HYDRA, a modeling and optimization framework that formulates LFA variants as botnet minimization problems. HYDRA quantifies network resilience to LFAs by measuring the smallest active subset of bots and the corresponding traffic allocation required to disrupt communication between targeted geographic areas. Under matched stealth constraints, HYDRA achieves the same targeted disruption as ICARUS while using 34% fewer bots and 23% less aggregate attack traffic. HYDRA achieves over 97% success in sustaining continuous attacks as the network topology evolves. Finally, HYDRA evaluates five mitigation strategies, showing how routing diversification, ingress policing, distance-based traffic constraints, source throttling, and botnet attrition reduce attack success and improve network resilience to targeted disruption.