STARM · SW-08 · SOFTWARE

Credential Hardcoding

Back to the STARM matrix

STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.

Using factory-default passwords in code.

Severity in the dataset7/10

Not the paper’s H/M/L.

Target
Access Control
Layer in the inventory
Application
Mitigation
Environment variables and secret management.
How the inventory says to fix it
Rule-based: Pre-commit hooks to scan code for secrets/passwords.
Quick fix
Change password
ML approaches named
Classification models (Random Forest, Logistic Regression), anomaly detection models, NLP-based static code analysis models, Transformer-based code models
Methodology
Static credential reuse patterns, abnormal authentication success rates, repeated identical auth signatures across subsystems
Handler role
DevOps Engineer
Stage
Development
Standard named
ISO/IEC 27002
Status in the inventory
Partially managed

STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.

Connection recorded in the inventory

Ground Station Breach