STARM · SW-07 · SOFTWARE
Zombie Firmware
STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.
Dormant malicious code that activates later.
Severity in the dataset8/10
Not the paper’s H/M/L.
- Target
- Program Logic
- Layer in the inventory
- Firmware
- Mitigation
- Code signing and multi-stage verification.
- How the inventory says to fix it
- AI: Time-series analysis of process activity to detect 'awakening' dormant code patterns.
- Quick fix
- Firmware rollback
- ML approaches named
- Behavioral clustering (k-means, DBSCAN), Autoencoders, LSTM-based telemetry monitoring, Graph-based anomaly detection
- Methodology
- Firmware behaving differently from expected operational profile, unexpected outbound communication, persistence after update
- Handler role
- Security Auditor
- Stage
- Operation
- Standard named
- ISO/IEC 15408
- Status in the inventory
- Not evaluated
STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.
Related in the matrix
STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.
Connection recorded in the inventory
Supply Chain Backdoor