Pith. sign in

REVIEW 3 cited by

HOLMES: Real-time APT Detection through Correlation of Suspicious Information Flows

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1810.01594 v2 pith:5XMYIIXB submitted 2018-10-03 cs.CR

classification cs.CR
keywords holmesdetectionapproachaptscampaignhigh-levelreal-timeattacker
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

In this paper, we present HOLMES, a system that implements a new approach to the detection of Advanced and Persistent Threats (APTs). HOLMES is inspired by several case studies of real-world APTs that highlight some common goals of APT actors. In a nutshell, HOLMES aims to produce a detection signal that indicates the presence of a coordinated set of activities that are part of an APT campaign. One of the main challenges addressed by our approach involves developing a suite of techniques that make the detection signal robust and reliable. At a high-level, the techniques we develop effectively leverage the correlation between suspicious information flows that arise during an attacker campaign. In addition to its detection capability, HOLMES is also able to generate a high-level graph that summarizes the attacker's actions in real-time. This graph can be used by an analyst for an effective cyber response. An evaluation of our approach against some real-world APTs indicates that HOLMES can detect APT campaigns with high precision and low false alarm rate. The compact high-level graphs produced by HOLMES effectively summarizes an ongoing attack campaign and can assist real-time cyber-response operations.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 3 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Investigation of Advanced Persistent Threats Network-based Tactics, Techniques and Procedures

    cs.CR 2025-02 conditional novelty 5.0 of 10

    A structured review of 33 APT campaigns shows command-and-control traffic overwhelmingly uses HTTP(S) and DNS, with over half of campaigns splitting traffic across multiple servers to evade volume-based detection.

  2. Detecting APT Malware Command and Control over HTTP(S) Using Contextual Summaries

    cs.CR 2025-02 conditional novelty 5.0 of 10

    EarlyCrow detects APT malware command-and-control over HTTP(S) by classifying contextual summaries of network flows, achieving a macro F1 of about 93% on unseen APT families.

  3. SCADE: Scalable Framework for Anomaly Detection in High-Performance System

    cs.CR 2024-12 reject novelty 3.0 of 10

    SCADE uses BM25 and log-entropy rarity scoring plus Isolation Forest context to detect command-line attacks, claiming over 98% SNR with no labeled data.

Pith tools