STARM · SW-08 · SOFTWARE
Credential Hardcoding
STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.
Using factory-default passwords in code.
Severity in the dataset7/10
Not the paper’s H/M/L.
- Target
- Access Control
- Layer in the inventory
- Application
- Mitigation
- Environment variables and secret management.
- How the inventory says to fix it
- Rule-based: Pre-commit hooks to scan code for secrets/passwords.
- Quick fix
- Change password
- ML approaches named
- Classification models (Random Forest, Logistic Regression), anomaly detection models, NLP-based static code analysis models, Transformer-based code models
- Methodology
- Static credential reuse patterns, abnormal authentication success rates, repeated identical auth signatures across subsystems
- Handler role
- DevOps Engineer
- Stage
- Development
- Standard named
- ISO/IEC 27002
- Status in the inventory
- Partially managed
STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.
Connection recorded in the inventory
Ground Station Breach