STARM · NW-04 · NETWORK
Replay Attack
STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.
Recording and re-sending valid commands.
Severity in the dataset8/10
Not the paper’s H/M/L.
- Target
- Instructions
- Layer in the inventory
- Datalink Layer
- Mitigation
- Time-stamping and nonces in packets.
- How the inventory says to fix it
- Rule-based: Nonce/Time-stamping validation. If timestamp is old, reject packet.
- Quick fix
- Flush buffers
- ML approaches named
- Sequence models (LSTM/Transformer), Hidden Markov Models, Time-series anomaly detection, Isolation Forest
- Methodology
- Duplicate command sequences, repeated timing patterns, mismatched timestamps, abnormal authentication timing
- Handler role
- Network Admin
- Stage
- Operation
- Standard named
- CCSDS 352.0-B-2
- Status in the inventory
- Fixed
STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.
Related in the matrix
STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.
Connection recorded in the inventory
Command Injection