STARM · SW-02 · SOFTWARE
Ransomware-in-Orbit
STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.
Encrypting flight data for ransom.
Severity in the dataset8/10
Not the paper’s H/M/L.
- Target
- Data
- Layer in the inventory
- OS / Database
- Mitigation
- Off-site offline backups and file integrity monitoring.
- How the inventory says to fix it
- AI/ML: Detect rapid encryption/entropy changes in filesystem. Rule-based: Disallow unauthorized mass encryption processes.
- Quick fix
- Restore from backup
- ML approaches named
- LSTM / GRU sequence models, Autoencoders (anomaly detection), Isolation Forest, One-Class SVM, Temporal CNNs
- Methodology
- Detetcting sudden file encryption patterns, abnormal storage I/O, unexpected CPU spikes, unusual process execution sequences, telemetry deviations from the baseline
- Handler role
- CISO
- Stage
- Operation
- Standard named
- NIST SP 800-53
- Status in the inventory
- Avoided
STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.
Connection recorded in the inventory
Wiper Malware