STARM · HW-10 · HARDWARE
Malicious Peripheral Devices
STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.
Rogue devices attached to the internal bus.
Severity in the dataset7/10
Not the paper’s H/M/L.
- Target
- Bus Traffic
- Layer in the inventory
- Network Interface / Bus
- Mitigation
- Device authentication on the internal bus.
- How the inventory says to fix it
- Rule-based: Whitelisting device IDs (VID/PID) and authentication via PKI.
- Quick fix
- Isolate device
- ML approaches named
- Autoencoders, Long Short-Term Memory (LSTM) networks, and Recurrent Neural Networks (RNNs) , Random Forest and Support Vector Machines (SVM)
- Methodology
- Analyze telemetry and network behavior for anomalies, achieving high detection rates for both known and unknown threats
- Handler role
- Hardware Architect
- Stage
- Integration
- Standard named
- ISO/IEC 19790
- Status in the inventory
- Partially managed
STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.
Connection recorded in the inventory
Lateral Movement