首页> 外文会议>IEEE Symposium on Security and Privacy >HOLMES: Real-Time APT Detection through Correlation of Suspicious Information Flows
【24h】

HOLMES: Real-Time APT Detection through Correlation of Suspicious Information Flows

机译:HOLMES:通过可疑信息流的关联进行实时APT检测

获取原文

摘要

In this paper, we present HOLMES, a system that implements a new approach to the detection of Advanced and Persistent Threats (APTs). HOLMES is inspired by several case studies of real-world APTs that highlight some common goals of APT actors. In a nutshell, HOLMES aims to produce a detection signal that indicates the presence of a coordinated set of activities that are part of an APT campaign. One of the main challenges addressed by our approach involves developing a suite of techniques that make the detection signal robust and reliable. At a high-level, the techniques we develop effectively leverage the correlation between suspicious information flows that arise during an attacker campaign. In addition to its detection capability, HOLMES is also able to generate a high-level graph that summarizes the attacker's actions in real-time. This graph can be used by an analyst for an effective cyber response. An evaluation of our approach against some real-world APTs indicates that HOLMES can detect APT campaigns with high precision and low false alarm rate. The compact high-level graphs produced by HOLMES effectively summarizes an ongoing attack campaign and can assist real-time cyber-response operations.
机译:在本文中,我们介绍了HOLMES,该系统采用了一种用于检测高级威胁和持久性威胁(APT)的新方法。 HOLMES受到现实世界APT案例研究的启发,这些案例研究突显了APT参与者的一些共同目标。简而言之,HOLMES的目标是产生一个检测信号,该信号表明存在着一系列协调的活动,这些活动是APT活动的一部分。我们的方法解决的主要挑战之一是开发一套使检测信号稳定可靠的技术。在较高级别,我们开发的技术有效地利用了攻击者战役期间产生的可疑信息流之间的相关性。除了其检测功能外,HOLMES还能够生成高级图表,实时总结攻击者的行为。分析师可以使用此图进行有效的网络响应。对我们针对某些实际APT的方法进行的评估表明,HOLMES可以检测出高精度和低误报率的APT活动。 HOLMES生成的紧凑的高级图表有效地总结了正在进行的攻击活动,并且可以辅助实时网络响应操作。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号