Reference card.

Downloads ▾
← Back to course
TLP:GREEN Limited Disclosure · SCORP² community members only
Exported by: verifying identity… Exported at:
Distribution notice. This document is for active SCORP² community members only. Unauthorized distribution will result in revocation of community membership.

Analytic Layer

Taxonomic Element Nomenclature (TEN)

The Analytic Layer is the fifth layer of the METEORSTORM data model, built on the four structural layers that enumerate the platform itself. The layer contributes three mechanisms. Its taxonomy classifies analytic knowledge into six elements, each carrying its published definition verbatim. Its ontology anchors every enumerated analytic element through a fixed target field to the exact platform elements it concerns, so a finding recorded against an asset is reachable from the service, the segment, and the environment above it. Its normalization is the innovation: intelligence and peer-framework content, whatever its origin, is normalized into the same six elements and attaches to the same decomposition in one shared vocabulary, so the catalogue keeps pace with the ecosystem without re-architecting the data model. This card is the taxonomic dictionary for the analytic layer; the organizational enumeration is the companion analytic ETEN reference.

Why the analytic layer was developed

The analytic layer was developed for front-line space collective defense. The intent of the layer: entries move operator to operator as machine-to-machine exchange across a trusted network, and a peer acts on an entry without renegotiating its provenance. Every entry declares its SOURCE at the gate before enumeration.

The four structural layers classify what the platform is. The analytic layer classifies what the analyst knows about it, in a form every participating organization reads identically. Its six elements answer the six questions an analyst asks in the order a situation unfolds: has a platform been compromised, is an attack confirmed, is an attack path active, is a threat confirmed, is a detection signature available, and can the threat be engineered out of the platform. A platform means the organization’s own or a trusted community member’s.

The six-element structure is also the layer's intake surface. Peer frameworks evolve on their own timelines; their content normalizes into these six elements without changing the data model. The ingestion structure is fixed, the contents refresh continuously, and evolution in the peer ecosystem becomes a taxonomy update, not a re-architecting.

METEORSTORM Data Model Fields

Layer
The layer the element belongs to; every element on this card is AN, Analytic (L5).
Tag
The published tag for the element within its layer, for example THR.
Label
The published name that corresponds to the tag, for example Threat.
Definition
The published definition for the element, quoted verbatim.
Target
The target field fixed by the element: TOE, TDM, or TRE. It names the platform elements the enumerated element concerns.
Source
Declared at the gate before enumeration: observable, a signal or data captured from a system, or synthetic, authored data for resilience engineering and exercises.

Every element below carries its published fields. To record one real analytic element on your platform, switch to the colon ETEN nomenclature in the companion analytic ETEN reference.

Verbatim rule. Every definition below is the published METEORSTORM taxonomy text, quoted exactly. On this platform an element definition is never abbreviated, paraphrased, or reworded. When you need to describe how an element applies to your actual system, that is the job of the ETEN, not an edit to the definition.
METEORSTORM Analytic Layer L5 · AN · Analytic  ·  the FINDINGS “Analytic constructs for threat, detection, and resilience.” Six analytic elements · no parent; each carries a target field. AN-IOC Indicator of Compromise AN-IOA Indicator of Attack AN-ATT Attack Path AN-THR Threat AN-DET Detection Signature AN-RES Resilience Measure TOE Target of Exploitation TDM Target of Detection Method TRE Target of Resilience Enhancement PLATFORM ELEMENTS PCE · SEG · SVC · AST A target may name any platform element, the environment included; it never names another enrichment element.

The Gate

The analytic layer was developed for front-line space collective defense. The intent of the layer: entries move operator to operator as machine-to-machine exchange across a trusted network, and a peer acts on an entry without renegotiating its provenance. That intent holds only if every entry declares its SOURCE before enumeration:

L5Analytic (AN)

Predicate: “Analytic constructs for threat, detection, and resilience.” The ENRICHMENT layer. Every AN element is an enrichment element; it anchors to the platform element it concerns through its target field.

METEORSTORM Data Model Fields

TOE
Target of Exploitation. Carried by Attack Path, Indicator of Compromise, Indicator of Attack, and Threat; names the platform elements the adversary activity is directed at.
TDM
Target of Detection Method. Carried by Detection Signature; names the platform elements the signature observes.
TRE
Target of Resilience Enhancement. Carried by Resilience Measure; names the platform elements the measure protects.

The target field is fixed by the element; it is never chosen freely. It references platform elements in any layer, PCE, SEG, SVC, or AST, so a threat can anchor to the environment itself; it never references another enrichment element.

Question 01 · Has an organizational or trusted community member platform been compromised?

Indicator of Compromise

The highest priority analytic element: backward-looking evidence of a confirmed platform breach, traceable to an actual incident or live operator telemetry, and acted on by a peer operator without further analysis.

Layer
AN Analytic (L5)
Tag
IOC
Label
Indicator of Compromise
Definition
Confirmed indication that a converged space system has been compromised.
Target
TOE Target of Exploitation

Question 02 · Is there a confirmed attack against an organizational or trusted community member platform?

Indicator of Attack

Present-tense evidence that adversary activity is in progress against the platform. The compromise may or may not have completed; the response window is open. Past and present stay separate elements so each question gets its own decision path.

Layer
AN Analytic (L5)
Tag
IOA
Label
Indicator of Attack
Definition
Confirmed indication that a converged space system has been attacked.
Target
TOE Target of Exploitation

Question 03 · Is there an active attack path against an organizational or trusted community member platform?

Attack Path

A documented sequence of adversary actions that could traverse the platform from entry to impact. An exposure, not an observation: recorded in enough detail for another analyst to evaluate it against their own platform.

Layer
AN Analytic (L5)
Tag
ATT
Label
Attack Path
Definition
Confirmed attack path for a converged space system.
Target
TOE Target of Exploitation

Question 04 · Is there a confirmed threat against an organizational or trusted community member platform?

Threat

A known adversary capability or campaign directed at the platform, built on attributed activity: threat-intelligence reporting, government attribution, or a peer-shared adversary profile. Where the Attack Path records what the platform exposes, the Threat records who is likely to exercise it.

Layer
AN Analytic (L5)
Tag
THR
Label
Threat
Definition
Confirmed and active threat against a converged space system.
Target
TOE Target of Exploitation

Question 05 · Is there a confirmed detection signature available for a confirmed threat?

Detection Signature

The written commitment to see a specific behavior, expressed in the open RootA format so a signature written by one operator deploys in another operator's stack; the native vendor query rides along as enrichment. A threat or attack path with no matching signature is a detection gap, and the gap is itself an enumerable analytic product.

Layer
AN Analytic (L5)
Tag
DET
Label
Detection Signature
Definition
Validated and operational pattern, signal, or logic that triggers on contextualized threat behavior for a converged space system.
Target
TDM Target of Detection Method

Question 06 · Is there a means to engineer the threat out of the platform?

Resilience Measure

The forward-looking element: a protective capability serving one of the four resiliency goals of NIST SP 800-160 Volume 2, Anticipate, Withstand, Recover, Adapt. Applied in place at the cadence the technology supports, or captured as input to the next generation of platform design when the vehicle is on orbit.

Layer
AN Analytic (L5)
Tag
RES
Label
Resilience Measure
Definition
Validated and operational protective capability ensuring converged space system resistance or recovery from confirmed threats.
Target
TRE Target of Resilience Enhancement
The target field is mandatory. An analytic element is enumerated only when its target field, the TOE, TDM, or TRE, names a real enumerated platform element on your platform; an element with no populated target is not a valid ETEN and is not entered in the catalogue. The target may name a platform element in any structural layer, the environment included; it never names another enrichment element. That is the value of the analytic layer: every threat, indicator, attack path, detection signature, and resilience measure anchors to the exact platform element it concerns, so any department reads it and acts on it without re-translation.
Enumeration. This card carries the taxonomy of the analytic layer; the target field is its ontology. Enumerating against it produces the analytic ETEN record: each element named with an ordinal and a description, its target populated. The companion analytic ETEN reference applies these six elements to the Kestrel Orbital Day-1 CONOPS with worked examples from Modules 02 through 05.

The Analytics Catalog

The catalog is what the layer produces: the organized, running collection of analytic elements that results from enumerating the organization's own intelligence and normalizing peer-framework content into the six elements, expressed in this nomenclature and anchored to the structural decomposition of the platform being defended. The catalog is not a separate product; it is what an organization ends up with after applying the method consistently. METEORSTORM does not replace the source frameworks below; it provides a way for organizations to normalize the fluid and broad range of reference frameworks into one reliable lens, so every framework contributes to the same catalog without forcing its vocabulary on the others.

Different source types feed different elements, and the element tags in the SOURCE column are recommendations, not restrictions: they name the elements each source most naturally supplies. Threat-intelligence feeds carrying observations from real incidents feed the two indicators; an indicator entry is never drawn from an architectural framework, because an indicator cannot be theoretical. Adversary-behavior catalogues feed Attack Path and Threat. Control and defensive-technique frameworks feed Detection Signature and Resilience Measure.

FrameworkPublisherSOURCE
Trusted threat-intelligence feeds (Space ISAC Exchange, vendor and government reporting, own telemetry)VariousIOC · IOA · ATT · THR · DET · RES
MITRE ATT&CKThe MITRE CorporationATT · THR · RES
MITRE FiGHTThe MITRE Corporation with the U.S. DoD 5G Cross-Functional TeamATT · THR · RES
MITRE ATLASThe MITRE CorporationATT · THR · RES
MITRE CAPECThe MITRE CorporationATT
Aerospace SPARTAThe Aerospace CorporationATT · THR · DET · RES
ESA SPACE-SHIELDEuropean Space AgencyATT · THR · RES
MITRE EMB3DThe MITRE CorporationATT · THR · RES
MITRE D3FENDThe MITRE Corporation, funded by the NSADET · RES
CSA AI Controls MatrixCloud Security AllianceRES
CSA Cloud Controls MatrixCloud Security AllianceRES
CSA Shared Security Responsibility ModelCloud Security AllianceRES
NIST SP 800-160 Volumes 1 and 2National Institute of Standards and TechnologyRES
NIST SP 800-53National Institute of Standards and TechnologyRES