STARM · SW-06 · SOFTWARE
Insecure Bootloader
STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.
Overwriting startup code with malicious version.
Severity in the dataset8/10
Not the paper’s H/M/L.
- Target
- Startup Logic
- Layer in the inventory
- Bootloader / Firmware
- Mitigation
- Hardware-anchored Secure Boot.
- How the inventory says to fix it
- Rule-based: UEFI Secure Boot with hardware root of trust (TPM/HSM).
- Quick fix
- Re-flash firmware
- ML approaches named
- Binary classification models, CNNs for firmware fingerprinting, Siamese Networks for firmware similarity detection, One-Class SVM
- Methodology
- Boot sequence deviations, unexpected firmware hashes, anomalous startup timing, unsigned or modified components
- Handler role
- Embedded Developer
- Stage
- Manufacturing
- Standard named
- NIST SP 800-193
- Status in the inventory
- Avoided
STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.
Related in the matrix
STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.
Connection recorded in the inventory
Glitching