STARM · SW-02 · SOFTWARE

Ransomware-in-Orbit

Back to the STARM matrix

STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.

Encrypting flight data for ransom.

Severity in the dataset8/10

Not the paper’s H/M/L.

Target
Data
Layer in the inventory
OS / Database
Mitigation
Off-site offline backups and file integrity monitoring.
How the inventory says to fix it
AI/ML: Detect rapid encryption/entropy changes in filesystem. Rule-based: Disallow unauthorized mass encryption processes.
Quick fix
Restore from backup
ML approaches named
LSTM / GRU sequence models, Autoencoders (anomaly detection), Isolation Forest, One-Class SVM, Temporal CNNs
Methodology
Detetcting sudden file encryption patterns, abnormal storage I/O, unexpected CPU spikes, unusual process execution sequences, telemetry deviations from the baseline
Handler role
CISO
Stage
Operation
Standard named
NIST SP 800-53
Status in the inventory
Avoided

STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.

Connection recorded in the inventory

Wiper Malware