STARM · SW-05 · SOFTWARE
Insecure API Endpoints
STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.
Exploiting interfaces used for satellite apps.
Severity in the dataset7/10
Not the paper’s H/M/L.
- Target
- Instructions
- Layer in the inventory
- Frontend / Backend
- Mitigation
- OAuth 2.0 and API rate limiting.
- How the inventory says to fix it
- Rule-based: Rate limiting and OAuth. AI: User Behavior Analytics (UBA) to find API scraping/abuse.
- Quick fix
- Revoke API key
- ML approaches named
- Gradient Boosting (XGBoost/LightGBM), Random Forest, Isolation Forest, Deep Neural Network classifiers, NLP-based sequence models for request analysis
- Methodology
- Unusual API call frequency, abnormal parameter distributions, unauthorized request patterns, protocol misuse
- Handler role
- DevOps Engineer
- Stage
- Operation
- Standard named
- OWASP Top 10
- Status in the inventory
- Mittigated
STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.
Connection recorded in the inventory
Credential Theft