All techniques
EXF-0002.03
ST0008Exfiltration
sub-technique

Traffic Analysis Attacks

Parent: EXF-0002

Description

In a terrestrial environment, threat actors use traffic analysis attacks to analyze traffic flow to gather topological information. This traffic flow can divulge information about critical nodes, such as the aggregator node in a sensor network. In the space environment, specifically with relays and constellations, traffic analysis can be used to understand the energy capacity of spacecraft node and the fact that the transceiver component of a spacecraft node consumes the most power. The spacecraft nodes in a constellation network limit the use of the transceiver to transmit or receive information either at a regulated time interval or only when an event has been detected. This generally results in an architecture comprising some aggregator spacecraft nodes within a constellation network. These spacecraft aggregator nodes are the sensor nodes whose primary purpose is to relay transmissions from nodes toward the ground station in an efficient manner, instead of monitoring events like a normal node. The added functionality of acting as a hub for information gathering and preprocessing before relaying makes aggregator nodes an attractive target to side channel attacks. A possible side channel attack could be as simple as monitoring the occurrences and duration of computing activities at an aggregator node. If a node is frequently in active states (instead of idle states), there is high probability that the node is an aggregator node and also there is a high probability that the communication with the node is valid. Such leakage of information is highly undesirable because the leaked information could be strategically used by threat actors in the accumulation phase of an attack.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(e)
    addresses
    moderate
    inferred

    mitigates DOWNGRADE: (2)(e) confidentiality is domain-adjacent but does not interdict traffic-flow/timing analysis, since topology and activity timing leak from transceiver duty-cycle even under encryption; the operative controls are traffic-flow padding and constant-rate transmission, not data confidentiality.

  • eu-space-actArt. 85(1)
    addresses
    moderate
    direct

    Traffic-analysis defenses (constant-rate transmission, padding) are within the cryptographic concept 85(1) scopes — not just confidentiality of payload but also of patterns.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    inferred

    Art. 21(2)(h) encryption protects content but does not interdict traffic-flow analysis, which infers aggregator nodes and activity from metadata patterns; the operative control is traffic padding and emission management. Addresses (domain relevance).

  • nis2-implAnnex 6.7.1
    addresses
    moderate
    derived

    Network-security obligations cover protection of traffic flows including measures that resist traffic analysis (cover traffic, padding, link-load smoothing) where appropriate to the risk profile.

ENISA controls

  • Communications security is relevant to the communications-protection domain, but content confidentiality/integrity does not actively defeat the traffic-flow analysis EXF-0002.03 performs.

  • Traffic flow security is the canonical defense against traffic-analysis attacks: padding/obfuscating volumes and concealing routing information defeats topology inference.

Cross-reference controls

SPARTA countermeasures

Cite as SafeMode Space, EXF-0002.03 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.