SAGE: Self-Reflective End-to-End Framework for Automated APT Investigation in 5G Networks
Xinyu Liu, Yu Sun, Gaojian Xiong, Jianhua Liu, Jian Cui, Jianwei Liu
Abstract
5G mobile networks are becoming new targets for Advanced Persistent Threat (APT) attacks. While existing provenance-based intrusion detection systems (PIDS) show promise for APT detection, they are inadequate for complex 5G networks due to the absence of explainable investigation results. They generate alert graphs with numerous false positive nodes, imposing substantial cognitive burdens on security analysts. This paper presents SAGE, the first end-to-end framework for automated APT investigation in 5G networks. SAGE presents a two-stage approach. For improved detection precision, SAGE constructs global heterogeneous provenance graphs integrating system and 5G application logs with semantic embeddings for efficient node-level anomaly detection. For automated investigation, SAGE introduces a novel self-reflective and self-reasoning LLM framework with domain-specific Retrieval Augmented Generation (RAG). Through carefully designed APT investigation workflows, it reduces detection false positives and automatically generates comprehensive natural language reports explaining attack tactics, techniques and procedures (TTPs) and impacts, bridging the critical gap between alerts and human-friendly intelligence. Extensive experiments on the constructed 5G APT dataset demonstrate that SAGE’s investigation framework improves node-level detection precision by an average of 12% and generates high-quality investigation reports, achieving superior TTP-level detection performance with over 80% precision, significantly outperforming state-of-the-art methods.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- OCR-APT: Reconstructing APT Stories from Audit Logs using Subgraph Anomaly Detection and LLMsAhmed Aly, Essam Mansour, Amr M. YoussefCCS 2025 · 2 citations
- Sentient: Detecting APTs via Capturing Indirect Dependencies and Behavioral LogicWenhao Yan, Ning An, Wei Qiao, Weiheng Wu et al.AAAI 2026 · 1 citation
- PROGRAPHER: An Anomaly Detection System based on Provenance Graph EmbeddingFan Yang, Jiacen Xu, Chunlin Xiong, Zhou Li et al.USENIX Security 2023
- STGAN: Detecting Host Threats via Fusion of Spatial-Temporal Features in Host Provenance GraphsAnyuan Sang, Xuezheng Fan, Li Yang, Yuchen Wang et al.WWW 2025 · 6 citations
- Unicorn: Runtime Provenance-Based Detector for Advanced Persistent ThreatsXueyuan Han, Thomas F. J.-M. Pasquier, Adam Bates, James Mickens et al.NDSS 2020
