Skip to main navigation Skip to search Skip to main content

HOLMES: Real-time APT detection through correlation of suspicious information flows

  • Sadegh Momeni Milajerdi
  • , Rigel Gjomemo
  • , Birhanu Eshete
  • , R. Sekar
  • , V. N. Venkatakrishnan
  • University of Illinois at Chicago
  • University of Michigan, Dearborn

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

566 Scopus citations

Abstract

In this paper, we present HOLMES, a system that implements a new approach to the detection of Advanced and Persistent Threats (APTs). HOLMES is inspired by several case studies of real-world APTs that highlight some common goals of APT actors. In a nutshell, HOLMES aims to produce a detection signal that indicates the presence of a coordinated set of activities that are part of an APT campaign. One of the main challenges addressed by our approach involves developing a suite of techniques that make the detection signal robust and reliable. At a high-level, the techniques we develop effectively leverage the correlation between suspicious information flows that arise during an attacker campaign. In addition to its detection capability, HOLMES is also able to generate a high-level graph that summarizes the attacker's actions in real-time. This graph can be used by an analyst for an effective cyber response. An evaluation of our approach against some real-world APTs indicates that HOLMES can detect APT campaigns with high precision and low false alarm rate. The compact high-level graphs produced by HOLMES effectively summarizes an ongoing attack campaign and can assist real-time cyber-response operations.

Original languageEnglish
Title of host publicationProceedings - 2019 IEEE Symposium on Security and Privacy, SP 2019
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages1137-1152
Number of pages16
ISBN (Electronic)9781538666609
DOIs
StatePublished - May 2019
Event40th IEEE Symposium on Security and Privacy, SP 2019 - San Francisco, United States
Duration: May 19 2019May 23 2019

Publication series

NameProceedings - IEEE Symposium on Security and Privacy
Volume2019-May
ISSN (Print)1081-6011

Conference

Conference40th IEEE Symposium on Security and Privacy, SP 2019
Country/TerritoryUnited States
CitySan Francisco
Period05/19/1905/23/19

Keywords

  • Advanced-Persistent-Threat-(APT)
  • Alarm-Correlation
  • Cyber-attack
  • Intrusion-detection
  • Provenance-graph
  • Scenario-Reconstruction
  • Tactics-techniques-procedures-(TTP)

Fingerprint

Dive into the research topics of 'HOLMES: Real-time APT detection through correlation of suspicious information flows'. Together they form a unique fingerprint.

Cite this