CrossHound: Multi-Source Provenance Correlation for Advanced Persistent Threat Detection and Investigation
Abstract
Advanced Persistent Threat (APT) attacks pose severe cybersecurity challenges due to their stealthy, prolonged, and highly targeted nature. Despite advancements in defensive technologies, detecting APTs remains difficult because their attack traces are often scattered across multiple data sources, leading to fragmented visibility when relying solely on host or network logs. Existing Provenance-based Intrusion Detection Systems (PIDS) predominantly focus on single-source analysis, resulting in high false positives and incomplete attack reconstructions. While commercial solutions like Extended Detection and Response (XDR) platforms attempt multi-source correlation, their proprietary nature and lack of systematic attack path reconstruction limit academic scrutiny and operational adaptability. This paper presents CrossHound, the first open-source, provenance-based system that establishes a unified framework to perform fine-grained APT detection by systematically correlating host and network logs. Unlike prior approaches, CrossHound employs a decoupled anomaly detection strategy, independently analyzing host and network provenance graphs while preserving their semantic relationships. It introduces a cross-source correlation technique that bridges host and network anomalies using IP five-tuples and temporal proximity, enabling precise linkage of malicious events. Additionally, CrossHound formulates attack path reconstruction as a Steiner Tree Problem (STP), efficiently connecting multi-source anomalies while minimizing false positives. We evaluate CrossHound on two large-scale datasets (OpTC and LANL) and demonstrate competitive performance against state-of-the-art (SOTA) baselines (FLASH, MAGIC, ARGUS), achieving 3-18% higher F1-scores and 29% fewer false positives. Notably, CrossHound reconstructs 97% of attack steps in DARPA OpTC, nearly doubling the coverage of network-related stages compared to host-only methods. Our open-source implementation provides the first transparent framework for multi-source APT analysis, enabling reproducibility and community adoption.