STARM · HW-10 · HARDWARE

Malicious Peripheral Devices

Back to the STARM matrix

STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.

Rogue devices attached to the internal bus.

Severity in the dataset7/10

Not the paper’s H/M/L.

Target
Bus Traffic
Layer in the inventory
Network Interface / Bus
Mitigation
Device authentication on the internal bus.
How the inventory says to fix it
Rule-based: Whitelisting device IDs (VID/PID) and authentication via PKI.
Quick fix
Isolate device
ML approaches named
Autoencoders, Long Short-Term Memory (LSTM) networks, and Recurrent Neural Networks (RNNs) , Random Forest and Support Vector Machines (SVM)
Methodology
Analyze telemetry and network behavior for anomalies, achieving high detection rates for both known and unknown threats
Handler role
Hardware Architect
Stage
Integration
Standard named
ISO/IEC 19790
Status in the inventory
Partially managed

STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.

Connection recorded in the inventory

Lateral Movement