Skip to content
León AerospaceLeón Aerospace
LA-SOCSecurity operations centre

Satellite Security Operations Center

Monitoring, protection and intelligent operation of the entire LeonAeroSpace space infrastructure from a single control centre.

LA-SOC · Scope

What is a satellite SOC?

The nerve centre overseeing the full infrastructure: from the satellite in orbit to the link reaching the customer.

SL-01

Satellites

LEO platforms across the constellation, with their payloads and critical subsystems.

SL-02

Ground Stations

Earth stations that open and close the contact windows with each satellite.

SL-03

Teleports

Entry points into the terrestrial network, including the Benavides de Órbigo teleport.

SL-04

Mission Control

Operations centre that issues telecommands and verifies the health of the fleet.

SL-05

IP networks

Transport, routing and segmentation of traffic between the teleport and customers.

SL-06

Cloud infrastructure

Management, analytics and customer portal services deployed on private cloud.

SL-07

RF links

Ka- and Ku-band uplinks and downlinks, monitored continuously against interference.

SL-08

Laser links

Optical inter-satellite links that route traffic without returning to the ground.

SL-09

5G NTN infrastructure

5G core and non-terrestrial network functions that serve the end user.

SL-10

OT infrastructure

Industrial systems for antennas, power supply and climate control across the sites.

SL-11

Data centres

Technical rooms hosting processing, storage and backup for the whole platform.

LA-SOC · Capabilities

Ten capabilities running continuously.

Each capability covers a different surface of the service, and all of them share one console and one incident flow.

24×7 monitoring

Continuous surveillance of the constellation and the ground segment, every day of the year.

Threat detection

Security event correlation to identify hostile activity against the infrastructure.

Anomaly detection

Comparison of each subsystem behaviour against its expected nominal pattern.

Artificial Intelligence

Models that rank alerts and filter out false positives before they reach an analyst.

Incident management

Full cycle of logging, triage, containment and documented closure for every incident.

Space telemetry

TT&C telemetry analysis to detect in-orbit degradation at an early stage.

RF security

Spectrum monitoring to locate interference, jamming and unauthorised emissions.

Orbital management

Ephemeris tracking and conjunction risk assessment to preserve fleet integrity.

End-to-end encryption

Cryptographic protection of the link and of telecommands between satellite and control centre.

Automated response

Playbooks that carry out containment in seconds without waiting for manual action.

LA-SOC · Protected chain

From satellite to customer, a single perimeter.

The whole service chain is instrumented: every node emits telemetry and every link is watched end to end.

SatellitesLA-Cover, LA-Xylon and LA-Onyx generate telemetry and carry the user traffic.
Ground StationsThey receive the downlink and return telecommands during every orbital pass.
Mission ControlConsolidates fleet status and decides on in-orbit manoeuvres and configurations.
Satellite SOCOversees the whole chain, detects the incident and triggers the matching response.
CustomersThey receive satellite 5G service protected end to end, without noticing the incident.
LA-SOC · Real time

Live monitoring.

Reference indicators for the constellation and the ground segment, updated continuously from the control centre.

Active satellites
0
Constellation health
0.00%
Current coverage
0.00%
Average latency
0ms
5G traffic
0.00Gbps
Open incidents
0
Security level
0%
Average temperature
0°C
Ground Stations online
0
Bandwidth usage
0%
LA-SOC · Threats

What the SOC detects.

Threats specific to the space domain alongside conventional IT ones, ranked by operational criticality.

Critical05High04Medium01
Critical

GPS Spoofing

Forged GNSS signals that induce position and timing errors across the platform.

Critical

RF Jamming

Deliberate emissions that saturate the link and degrade the capacity of the beam.

Critical

Ground Station intrusion

Unauthorised access to the systems that drive the tracking antennas.

High

Malware

Malicious code introduced into ground segment or teleport servers.

High

Unauthorised access

Misuse of credentials to reach restricted operations consoles.

High

DDoS attacks

Saturation of network services and the customer portal through massive traffic.

Critical

Telemetry tampering

Alteration of housekeeping data to mask the real behaviour of the satellite.

Critical

Malicious commands

Illegitimate telecommands seeking to change in-orbit configuration or attitude.

Medium

RF interference

Third-party emissions, intentional or not, overlapping the assigned frequencies.

High

Cloud infrastructure attacks

Exploitation of the services and containers that support platform management.

LA-SOC · Response

Incident response flow.

Eight steps between the first signal and the lesson learned. Automated stages run without waiting for an operator.

  1. 01

    Detection

    Space and ground segment sensors register the first anomalous indicator.

  2. 02

    Correlation

    The SIEM cross-references events from different layers into a single case.

  3. 03

    Triage

    The analyst assigns severity, scope and priority based on the impact on service.

  4. 04

    Automation

    The SOAR runs the matching playbook and gathers evidence with no manual input.

  5. 05

    Containment

    The affected element is isolated to stop the incident from spreading further.

  6. 06

    Recovery

    Nominal service is restored and the integrity of every subsystem is verified.

  7. 07

    Reporting

    The timeline, root cause and actions taken during the incident are documented.

  8. 08

    Lessons learned

    Findings are fed back into detection rules and into the existing playbooks.

LA-SOC · Intelligence

AI applied to operations.

Models consume telemetry, logs and RF traffic to anticipate failure before it degrades the service.

Inputs

Constellation telemetry
System and network logs
RF traffic and spectrum occupancy
Security events
Threat intelligence feeds
Orbital behaviour
Analysis engine

Outputs

Prioritised alerts
Failure and degradation forecasts
Recommendations for the analyst
Response automations
LA-SOC · Case study

A real incident, step by step.

RF interference, an intrusion attempt and rising latency. This is how it is correlated, contained and kept in service.

Detection03
  1. 01

    RF interference

    A third-party emission overlaps the service band over north-west Spain.

  2. 02

    Intrusion attempt

    An attacker tries credentials against the console of a Ground Station.

  3. 03

    Rising latency

    Average link latency doubles and starts affecting user 5G traffic.

Response04
  1. 04

    Event correlation

    The SOC links the interference, the failed access and the degradation as one case.

  2. 05

    Incident identified

    A coordinated attack on the ground segment and the RF link is confirmed.

  3. 06

    Automated response

    The playbook blocks the source of the access and isolates the compromised station.

  4. 07

    Backup link

    Traffic switches to a clean frequency and to another available ground station.

Service protected02
  1. 08

    Service protected

    Latency returns to nominal values and no customer session is lost.

  2. 09

    5G network online

    The satellite 5G network stays in service while the incident is documented.

Connect what has been out of coverage until now.

Space infrastructure and 5G connectivity, engineered in Spain. Let’s talk about your case: home, business, public administration or defence.