SAGE: Self-Reflective End-to-End Framework for Automated APT Investigation in 5G Networks
Xinyu Liu, Yu Sun, Gaojian Xiong, Jianhua Liu, Jian Cui, Jianwei Liu
摘要
5G mobile networks are becoming new targets for Advanced Persistent Threat (APT) attacks. While existing provenance-based intrusion detection systems (PIDS) show promise for APT detection, they are inadequate for complex 5G networks due to the absence of explainable investigation results. They generate alert graphs with numerous false positive nodes, imposing substantial cognitive burdens on security analysts. This paper presents SAGE, the first end-to-end framework for automated APT investigation in 5G networks. SAGE presents a two-stage approach. For improved detection precision, SAGE constructs global heterogeneous provenance graphs integrating system and 5G application logs with semantic embeddings for efficient node-level anomaly detection. For automated investigation, SAGE introduces a novel self-reflective and self-reasoning LLM framework with domain-specific Retrieval Augmented Generation (RAG). Through carefully designed APT investigation workflows, it reduces detection false positives and automatically generates comprehensive natural language reports explaining attack tactics, techniques and procedures (TTPs) and impacts, bridging the critical gap between alerts and human-friendly intelligence. Extensive experiments on the constructed 5G APT dataset demonstrate that SAGE’s investigation framework improves node-level detection precision by an average of 12% and generates high-quality investigation reports, achieving superior TTP-level detection performance with over 80% precision, significantly outperforming state-of-the-art methods.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- OCR-APT: Reconstructing APT Stories from Audit Logs using Subgraph Anomaly Detection and LLMsAhmed Aly, Essam Mansour, Amr M. YoussefCCS 2025 · 被引用 2 次
- Sentient: Detecting APTs via Capturing Indirect Dependencies and Behavioral LogicWenhao Yan, Ning An, Wei Qiao, Weiheng Wu 等AAAI 2026 · 被引用 1 次
- PROGRAPHER: An Anomaly Detection System based on Provenance Graph EmbeddingFan Yang, Jiacen Xu, Chunlin Xiong, Zhou Li 等USENIX Security 2023
- STGAN: Detecting Host Threats via Fusion of Spatial-Temporal Features in Host Provenance GraphsAnyuan Sang, Xuezheng Fan, Li Yang, Yuchen Wang 等WWW 2025 · 被引用 6 次
- Unicorn: Runtime Provenance-Based Detector for Advanced Persistent ThreatsXueyuan Han, Thomas F. J.-M. Pasquier, Adam Bates, James Mickens 等NDSS 2020
