ANTEATER: A Filter-then-Scrutinize Architecture for End-to-End Attack Investigation
Yiming Ren, Haoqiang Wang, Linghao Li, Haoyang Chen, Chengxiang Si, Zhou Zhou, Qingyun Liu
Abstract
Audit logs serve as a fundamental data source for system security. However, extracting high-value threat information from massive log data poses significant data management challenges: traditional unsupervised models produce high false positive rates due to their inherent assumption of equating statistical anomalies with malicious activities; Emerging Large Language Model (LLM) based solutions, despite their powerful semantic understanding capabilities, are constrained by high computational costs and context window lengths, making it difficult to detect attacks within massive logs. Furthermore, the outputs of existing methods differ significantly from the practical attack reports required by security analysts. To overcome these limitations, this paper proposes ANTEATER, an innovative end-to-end attack investigation framework based on raw logs that features a cascading ''filter-then-scrutinize'' architecture. The ''Filter'' stage is a lightweight, flow-based anomaly detection model that efficiently filters massive logs and reduces the data scale for investigation. Subsequently, the ''Scrutinize'' stage is an attack investigation model with a three-agent LLM collaboration. It operates on a provenance graph constructed from the filtered anomalous logs. The agents collaboratively and autonomously explore and reconstruct the attack subgraph, then generate a structured natural-language report. ANTEATER not only effectively mitigates the LLM bottleneck from cost and context window, enabling it to tackle long-term, stealthy attacks, but also bridges the critical gap between raw data detection and the generation of readable attack reports.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Related papers
- OCR-APT: Reconstructing APT Stories from Audit Logs using Subgraph Anomaly Detection and LLMsAhmed Aly, Essam Mansour, Amr M. YoussefCCS 2025 · 2 citations
- Semantic Curriculum for Anomaly Detection: A Unified Language-Driven Meta-Optimization FrameworkKai Tan, Yangliu Du, Dongyang Zhan, Haining Yu et al.INFOCOM 2026
- CoorLog: Efficient-Generalizable Log Anomaly Detection via Adaptive Coordinator in Software EvolutionPei Xiao, Chiming Duan, Minghua He, Tong Jia et al.ASE 2025 · 3 citations
- WATSON: Abstracting Behaviors from Audit Logs via Aggregation of Contextual SemanticsJun Zeng, Zheng Leong Chua, Yinfang Chen, Kaihang Ji et al.NDSS 2021
- CoLA: Model Collaboration for Log-based Anomaly DetectionXuhang Zhu, Xiu Tang, Sai Wu, Jichen Li et al.VLDB 2025 · 2 citations
