STARM · NW-04 · NETWORK

Replay Attack

Back to the STARM matrix

STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.

Recording and re-sending valid commands.

Severity in the dataset8/10

Not the paper’s H/M/L.

Target
Instructions
Layer in the inventory
Datalink Layer
Mitigation
Time-stamping and nonces in packets.
How the inventory says to fix it
Rule-based: Nonce/Time-stamping validation. If timestamp is old, reject packet.
Quick fix
Flush buffers
ML approaches named
Sequence models (LSTM/Transformer), Hidden Markov Models, Time-series anomaly detection, Isolation Forest
Methodology
Duplicate command sequences, repeated timing patterns, mismatched timestamps, abnormal authentication timing
Handler role
Network Admin
Stage
Operation
Standard named
CCSDS 352.0-B-2
Status in the inventory
Fixed

STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.

Related in the matrix

STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.

Connection recorded in the inventory

Command Injection