Large language model (LLM) powered detection reasoning solution
Various techniques for LLM powered detection reasoning solutions are disclosed. In some embodiments, a system, a process, and/or a computer program product for an LLM powered detection reasoning solution includes monitoring network traffic at a security platform, wherein the security platform generates a sample based on the monitored network traffic; sending the sample to a security service to generate a Large Language Model (LLM) powered detection and reason, wherein the LLM is prompted to automatically generate a malware or benign verdict and a reason for explaining the verdict; and reporting the LLM powered detection and reason.
1 . A system, comprising:
a processor configured to:
monitor network traffic at a security platform, wherein the security platform generates a sample based on the monitored network traffic;
send the sample to a security service to generate a Large Language Model (LLM) powered detection and reason, wherein the LLM powered detection and reason is prompted to automatically generate a malware or benign verdict and a reason for explaining the malware or benign verdict, wherein the generating of the LLM comprises to:
generate, based on samples associated with malicious HyperText Transfer Protocol (HTTP) request headers with command injection, a plurality of prompts for training the LLM for malware detection reasoning; and
train the LLM based on the plurality of prompts; and
report the LLM powered detection and reason; and
a memory coupled to the processor and configured to provide the processor with instructions.
2 . The system of claim 1 , wherein LLM powered detection and reason is associated with an inline security service.
3 . The system of claim 1 , wherein LLM powered detection and reason is associated with an offline security reporting service.
4 . The system of claim 1 , wherein the security platform includes an endpoint agent, a Domain Name System (DNS) proxy, a network gateway firewall (NGFW), and/or an internal gateway hosted on a remote network associated with a cloud security service.
5 . The system of claim 1 , further comprising to:
generate a malware verdict for the sample based on the LLM powered detection and reason.
6 . The system of claim 1 , further comprising to:
generate a benign verdict for the sample based on the LLM powered detection and reason.
7 . The system of claim 1 , further comprising to:
generate a malware verdict for the sample based on the LLM powered detection and reason; and
generate a human understandable explanation for the malware verdict based on the LLM powered detection and reason.
8 . The system of claim 1 , further comprising to:
generate a benign verdict for the sample based on the LLM powered detection and reason; and
generate a human understandable explanation for the benign verdict based on the LLM powered detection and reason.
9 . A method, comprising:
monitoring network traffic at a security platform, wherein the security platform generates a sample based on the monitored network traffic;
sending the sample to a security service to generate a Large Language Model (LLM) powered detection and reason, wherein the LLM powered detection and reason is prompted to automatically generate a malware or benign verdict and a reason for explaining the malware or benign verdict, wherein the generating of the LLM comprises:
generating, based on samples associated with malicious HyperText Transfer Protocol (HTTP) request headers with command injection, a plurality of prompts for training the LLM for malware detection reasoning; and
training the LLM based on the plurality of prompts; and
reporting the LLM powered detection and reason.
10 . The method of claim 9 , wherein LLM powered detection and reason is associated with an inline security service.
11 . The method of claim 9 , wherein LLM powered detection and reason is associated with an offline security reporting service.
12 . The method of claim 9 , wherein the security platform includes an endpoint agent, a Domain Name System (DNS) proxy, a network gateway firewall (NGFW), and/or an internal gateway hosted on a remote network associated with a cloud security service.
13 . The method of claim 9 , further comprising:
generating a malware verdict for the sample based on the LLM powered detection and reason.
14 . The method of claim 9 , further comprising:
generating a benign verdict for the sample based on the LLM powered detection and reason.
15 . The method of claim 9 , further comprising:
generating a malware verdict for the sample based on the LLM powered detection and reason; and
generating a human understandable explanation for the malware verdict based on the LLM powered detection and reason.
16 . The method of claim 9 , further comprising:
generating a benign verdict for the sample based on the LLM powered detection and reason; and
generating a human understandable explanation for the benign verdict based on the LLM powered detection and reason.
17 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:
monitoring network traffic at a security platform, wherein the security platform generates a sample based on the monitored network traffic;
sending the sample to a security service to generate a Large Language Model (LLM) powered detection and reason, wherein the LLM powered detection and reason is prompted to automatically generate a malware or benign verdict and a reason for explaining the malware or benign verdict, wherein the generating of the LLM comprises:
generating, based on samples associated with malicious HyperText Transfer Protocol (HTTP) request headers with command injection, a plurality of prompts for training the LLM for malware detection reasoning; and
training the LLM based on the plurality of prompts; and
reporting the LLM powered detection and reason.
18 . A system, comprising:
a processor configured to:
send a set of malware samples for training data input to a Large Language Model (LLM), wherein the set of malware samples are associated with malicious HyperText Transfer Protocol (HTTP) request headers with command injection;
generate, based on the set of malware samples, a plurality of prompts to train the LLM for malware detection reasoning;
train the LLM using the plurality of prompts; and
deploy the LLM for the malware detection reasoning as an inline security service and/or an offline reporting security service; and
a memory coupled to the processor and configured to provide the processor with instructions.