articleMay 1, 2019GOLD OA

HOLMES: Real-Time APT Detection through Correlation of Suspicious Information Flows

University of Illinois Chicago · Stony Brook University

Indexed incrossref

Abstract

In this paper, we present HOLMES, a system that implements a new approach to the detection of Advanced and Persistent Threats (APTs). HOLMES is inspired by several case studies of real-world APTs that highlight some common goals of APT actors. In a nutshell, HOLMES aims to produce a detection signal that indicates the presence of a coordinated set of activities that are part of an APT campaign. One of the main challenges addressed by our approach involves developing a suite of techniques that make the detection signal robust and reliable. At a high-level, the techniques we develop effectively leverage the correlation between suspicious information flows that arise during an attacker campaign. In addition to…

Citation impact

465
total citations
FWCI
26.38
Percentile
100%
References
63
Citations per year

Authors

5

Topics & keywords

Keywords
  • Computer science
  • Leverage (statistics)
  • Suite
  • Constant false alarm rate
  • False alarm
  • Real-time computing
  • Graph
  • ALARM
UN Sustainable Development Goals
  • Peace, Justice and strong institutions
No related works found for this paper.

Funding