STARM · SW-07 · SOFTWARE

Zombie Firmware

Back to the STARM matrix

STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.

Dormant malicious code that activates later.

Severity in the dataset8/10

Not the paper’s H/M/L.

Target
Program Logic
Layer in the inventory
Firmware
Mitigation
Code signing and multi-stage verification.
How the inventory says to fix it
AI: Time-series analysis of process activity to detect 'awakening' dormant code patterns.
Quick fix
Firmware rollback
ML approaches named
Behavioral clustering (k-means, DBSCAN), Autoencoders, LSTM-based telemetry monitoring, Graph-based anomaly detection
Methodology
Firmware behaving differently from expected operational profile, unexpected outbound communication, persistence after update
Handler role
Security Auditor
Stage
Operation
Standard named
ISO/IEC 15408
Status in the inventory
Not evaluated

STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.

Related in the matrix

STARMCatalog entries from the DIPS Threat Inventory. The paper cites that dataset and does not use this name.

Connection recorded in the inventory

Supply Chain Backdoor