All techniques
EXF-0002.05
ST0008Exfiltration
sub-technique

Thermal Imaging attacks

Parent: EXF-0002

Description

Threat actors can leverage thermal imaging attacks (e.g., infrared images) to measure heat that is emitted as a means to exfiltrate information from spacecraft processors. Thermal attacks rely on temperature profiling using sensors to extract critical information from the chip(s). The availability of highly sensitive thermal sensors, infrared cameras, and techniques to calculate power consumption from temperature distribution [7] has enhanced the effectiveness of these attacks. As a result, side-channel attacks can be performed by using temperature data without measuring power pins of the chip.

Mappings

EU regulation articles

  • craAnnex I, Part I, (2)(e)
    addresses
    moderate
    inferred

    (2)(e) confidentiality is in the data-protection domain but does not interdict thermal-emanation extraction; the operative control is physical thermal masking/shielding (TEMPEST), so record as addresses.

  • craAnnex I, Part I, (2)(k)
    addresses
    moderate
    inferred

    mitigates DOWNGRADE: (2)(k) exploitation-mitigation is domain-adjacent but does not interdict a thermal side-channel that extracts secrets through physical heat emission; the operative controls are physical (thermal masking, balanced thermal layout, TEMPEST/EMSEC shielding), not generic incident-impact mechanisms.

  • craAnnex I, Part II, (3)
    addresses
    moderate
    direct

    Thermal-imaging attacks (primary mapping: Annex I, Part I, (2)(k)) cascade to (3) — thermal-balancing countermeasures require periodic validation through thermal-imaging-based security testing.

  • eu-space-actArt. 85(1)
    addresses
    moderate
    inferred

    Art. 85(1)'s cryptographic concept is crypto-domain-relevant to thermal side-channels, but does not interdict the thermal emanation; thermal-balancing physical design is the actual mitigation.

  • nis2Art. 21(2)(h)
    addresses
    moderate
    inferred

    Art. 21(2)(h) crypto policy does not interdict thermal-imaging extraction; the operative mitigation is thermal and emission design, not use-of-cryptography policy. Addresses (domain relevance).

  • nis2-implAnnex 13.2.1
    addresses
    high
    derived

    Thermal-imaging exfiltration observes IR signatures of processors and harnesses; the protection-against-physical-and-environmental-threats obligation covers thermal-signature management (insulation, radiator placement, deliberate dummy heaters) that resists thermal analysis.

ENISA controls

  • Security of power systems with power-randomisation hardware indirectly limits chip-level temperature signatures correlated with power consumption.

  • A tamper-resistant body encasing sensor nodes is a physical-protection control relevant to the physical side-channel domain, but the excerpt describes tamper-resistant material rather than thermal masking or shielding, so it does not actively counter thermal-imaging exfiltration.

Cross-reference controls

  • nist-80053-rev5PE-19Information Leakage
    relates to
    moderate

    Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • Referenced in: sparta-data

    Mapped by SPARTA, not curated by SafeMode Space.

  • space-shieldT2029.001Optical (visual) reconnaissance
    addresses
    moderate

    T2029.001 'Optical (visual) reconnaissance' covers optical-sensor proximity intelligence — addresses the IR/thermal-camera subset of EXF-0002.05 when conducted from on-orbit proximity assets.

  • space-shieldT2035Side-channel exfiltration
    addresses
    moderate

    T2035 covers side-channel exfiltration — addresses EXF-0002.05 Thermal Imaging Attacks (using temperature profiling to extract information). SPACE-SHIELD has no thermal-imaging-specific sub-technique.

SPARTA countermeasures

Cite as SafeMode Space, EXF-0002.05 (SPARTA v3.2).

Built 2026-07-25 from 216 techniques, 334 regulation articles, 125 ENISA controls, 2,610 framework controls, and 90 countermeasures.