ANTEATER: A Filter-then-Scrutinize Architecture for End-to-End Attack Investigation
Yiming Ren, Haoqiang Wang, Linghao Li, Haoyang Chen, Chengxiang Si, Zhou Zhou, Qingyun Liu
摘要
Audit logs serve as a fundamental data source for system security. However, extracting high-value threat information from massive log data poses significant data management challenges: traditional unsupervised models produce high false positive rates due to their inherent assumption of equating statistical anomalies with malicious activities; Emerging Large Language Model (LLM) based solutions, despite their powerful semantic understanding capabilities, are constrained by high computational costs and context window lengths, making it difficult to detect attacks within massive logs. Furthermore, the outputs of existing methods differ significantly from the practical attack reports required by security analysts. To overcome these limitations, this paper proposes ANTEATER, an innovative end-to-end attack investigation framework based on raw logs that features a cascading ''filter-then-scrutinize'' architecture. The ''Filter'' stage is a lightweight, flow-based anomaly detection model that efficiently filters massive logs and reduces the data scale for investigation. Subsequently, the ''Scrutinize'' stage is an attack investigation model with a three-agent LLM collaboration. It operates on a provenance graph constructed from the filtered anomalous logs. The agents collaboratively and autonomously explore and reconstruct the attack subgraph, then generate a structured natural-language report. ANTEATER not only effectively mitigates the LLM bottleneck from cost and context window, enabling it to tackle long-term, stealthy attacks, but also bridges the critical gap between raw data detection and the generation of readable attack reports.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- OCR-APT: Reconstructing APT Stories from Audit Logs using Subgraph Anomaly Detection and LLMsAhmed Aly, Essam Mansour, Amr M. YoussefCCS 2025 · 被引用 2 次
- Semantic Curriculum for Anomaly Detection: A Unified Language-Driven Meta-Optimization FrameworkKai Tan, Yangliu Du, Dongyang Zhan, Haining Yu 等INFOCOM 2026
- CoorLog: Efficient-Generalizable Log Anomaly Detection via Adaptive Coordinator in Software EvolutionPei Xiao, Chiming Duan, Minghua He, Tong Jia 等ASE 2025 · 被引用 3 次
- WATSON: Abstracting Behaviors from Audit Logs via Aggregation of Contextual SemanticsJun Zeng, Zheng Leong Chua, Yinfang Chen, Kaihang Ji 等NDSS 2021
- CoLA: Model Collaboration for Log-based Anomaly DetectionXuhang Zhu, Xiu Tang, Sai Wu, Jichen Li 等VLDB 2025 · 被引用 2 次
