HOLMES: Real-Time APT Detection through Correlation of Suspicious Information Flows

HOLMES: Real-Time APT Detection through Correlation of Suspicious Information Flows
复制标题

DOI:
10.1109/sp.2019.00026
复制
发表时间:
2018-10
期刊:
2019 IEEE Symposium on Security and Privacy (SP)
影响因子:
--
通讯作者:
Sadegh M. Milajerdi;Rigel Gjomemo;Birhanu Eshete;R. Sekar;V. Venkatakrishnan
Sadegh M. Milajerdi;Rigel Gjomemo;Birhanu Eshete;R. Sekar;V. Venkatakrishnan
中科院分区:
其他
文献类型:
--
作者:
Sadegh M. Milajerdi;Rigel Gjomemo;Birhanu Eshete;R. Sekar;V. Venkatakrishnan

文献摘要

被引文献

相似文献

在本文中,我们提出了HOLMES,一个系统,实现了一种新的方法来检测高级和持久性威胁(APT)。HOLMES的灵感来自于现实世界APT的几个案例研究,这些案例强调了APT参与者的一些共同目标。简而言之,HOLMES的目标是产生一个检测信号,表明存在一组协调的活动,这些活动是APT活动的一部分。我们的方法解决的主要挑战之一是开发一套技术,使检测信号鲁棒性和可靠性。在高层次上,我们开发的技术有效地利用了攻击者活动期间出现的可疑信息流之间的相关性。除了检测能力,HOLMES还能够生成一个高级图,实时总结攻击者的行为。分析师可以使用此图进行有效的网络响应。我们的方法对一些现实世界的APT的评估表明,HOLMES可以检测APT运动具有高精度和低误报率。HOLMES制作的紧凑型高级图表有效地总结了正在进行的攻击活动,并可以帮助实时网络响应操作。
In this paper, we present HOLMES, a system that implements a new approach to the detection of Advanced and Persistent Threats (APTs). HOLMES is inspired by several case studies of real-world APTs that highlight some common goals of APT actors. In a nutshell, HOLMES aims to produce a detection signal that indicates the presence of a coordinated set of activities that are part of an APT campaign. One of the main challenges addressed by our approach involves developing a suite of techniques that make the detection signal robust and reliable. At a high-level, the techniques we develop effectively leverage the correlation between suspicious information flows that arise during an attacker campaign. In addition to its detection capability, HOLMES is also able to generate a high-level graph that summarizes the attacker’s actions in real-time. This graph can be used by an analyst for an effective cyber response. An evaluation of our approach against some real-world APTs indicates that HOLMES can detect APT campaigns with high precision and low false alarm rate. The compact high-level graphs produced by HOLMES effectively summarizes an ongoing attack campaign and can assist real-time cyber-response operations.