STARM · SW-05 · SOFTWARE

Insecure API Endpoints

Back to the STARM matrix

STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.

Exploiting interfaces used for satellite apps.

Severity in the dataset7/10

Not the paper’s H/M/L.

Target
Instructions
Layer in the inventory
Frontend / Backend
Mitigation
OAuth 2.0 and API rate limiting.
How the inventory says to fix it
Rule-based: Rate limiting and OAuth. AI: User Behavior Analytics (UBA) to find API scraping/abuse.
Quick fix
Revoke API key
ML approaches named
Gradient Boosting (XGBoost/LightGBM), Random Forest, Isolation Forest, Deep Neural Network classifiers, NLP-based sequence models for request analysis
Methodology
Unusual API call frequency, abnormal parameter distributions, unauthorized request patterns, protocol misuse
Handler role
DevOps Engineer
Stage
Operation
Standard named
OWASP Top 10
Status in the inventory
Mittigated

STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.

Connection recorded in the inventory

Credential Theft