REVIEW 3 cited by
HOLMES: Real-time APT Detection through Correlation of Suspicious Information Flows
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
In this paper, we present HOLMES, a system that implements a new approach to the detection of Advanced and Persistent Threats (APTs). HOLMES is inspired by several case studies of real-world APTs that highlight some common goals of APT actors. In a nutshell, HOLMES aims to produce a detection signal that indicates the presence of a coordinated set of activities that are part of an APT campaign. One of the main challenges addressed by our approach involves developing a suite of techniques that make the detection signal robust and reliable. At a high-level, the techniques we develop effectively leverage the correlation between suspicious information flows that arise during an attacker campaign. In addition to its detection capability, HOLMES is also able to generate a high-level graph that summarizes the attacker's actions in real-time. This graph can be used by an analyst for an effective cyber response. An evaluation of our approach against some real-world APTs indicates that HOLMES can detect APT campaigns with high precision and low false alarm rate. The compact high-level graphs produced by HOLMES effectively summarizes an ongoing attack campaign and can assist real-time cyber-response operations.
Forward citations
Cited by 3 Pith papers
-
Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures
A structured review of 33 APT campaigns shows command-and-control traffic overwhelmingly uses HTTP(S) and DNS, with over half of campaigns splitting traffic across multiple servers to evade volume-based detection.
-
Detecting APT Malware Command and Control over HTTP(S) Using Contextual Summaries
EarlyCrow detects APT malware command-and-control over HTTP(S) by classifying contextual summaries of network flows, achieving a macro F1 of about 93% on unseen APT families.
-
SCADE: Scalable Framework for Anomaly Detection in High-Performance System
SCADE uses BM25 and log-entropy rarity scoring plus Isolation Forest context to detect command-line attacks, claiming over 98% SNR with no labeled data.
Discussion (0). Continue with ORCID to comment.