ForenSiX: Automated Network Forensics and Diagnostics for Beyond-5G and 6G Networks Using Large Language Models

Xuanbo Huang, Kaiping Xue, Lutong Chen, Jiangping Han, Jian Li, David S. L. Wei · IEEE Network · 2025

Network forensics and diagnostics play a critical role in enabling operators to locate the root causes of attacks or service disruptions by analyzing logs and evidence of various devices. For example, when a subscriber reports a “disconnection” error, the network operator must investigate the subscriber’s service functionality and determine the underlying cause. However, these tasks are becoming more difficult in the future beyond-5G (B5G) and 6G environments. The expanding number of network functions, services, interfaces, and contexts results in more complex data flows and longer network management chains, making traditional manual diagnosis infeasible to trace and locate root causes from large-scale semantic network logs. To address these challenges, we propose ForenSiX, an automated framework designed for B5G and 6G networks. ForenSiX utilizes static analysis of relevant standards, module source code, and config files to construct a comprehensive data-dependency graph, enabling causal relationship analysis across multiple network functions. Next, it integrates a dynamic log-tracking subsystem that harnesses both regular expressions and commercial off-the-shelf large language models (LLMs). A multithreaded component further enhances processing efficiency, and a fault-tolerance unit ensures accuracy and robustness. We evaluate ForenSiX in Open5GS and UERANSIM, demonstrating its effectiveness, reliability, and adaptability in realistic scenarios.

Read the paper · More papers on PaperTik