STARM · SW-09 · SOFTWARE

Unauthorized Command Execution

Back to the STARM matrix

STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.

Bypassing auth to send flight commands.

Severity in the dataset9/10

Not the paper’s H/M/L.

Target
Instructions
Layer in the inventory
Application Layer
Mitigation
Multi-signature command verification.
How the inventory says to fix it
Rule-based: Multi-sig (M-of-N) auth. AI: Detecting 'weird' command sequences relative to mission profile.
Quick fix
Lock account
ML approaches named
Sequence learning (LSTM/Transformer), Markov models, Reinforcement-learning-based policy deviation detection, Isolation Forest
Methodology
Commands outside mission profile, abnormal command timing, unexpected source patterns, deviation from operational sequences
Handler role
Mission Controller
Stage
Operation
Standard named
CCSDS 355.0-B-1
Status in the inventory
Status unknown

STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.

Connection recorded in the inventory

Command Injection