IP Library › Granted Patent US 12,627,689
Granted Patent B2
US 12,627,689 · App. 18/416,669 · Granted May 12, 2026

Large language model (LLM) powered detection reasoning solution

Inventors: Zhibin Zhang (Santa Clara, CA); Yu Fu (Sunnyvale, CA); Yuwen Dai (Santa Clara, CA); Qian Feng (Mountain View, CA); Zhemin Su (San Jose, CA); Mei Wang (Saratoga, CA)
Assignee: Palo Alto Networks, Inc.
H04L63/1425H04L41/16
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,627,689
App. No.
18/416,669
Granted
May 12, 2026
Kind
B2
Abstract

Various techniques for LLM powered detection reasoning solutions are disclosed. In some embodiments, a system, a process, and/or a computer program product for an LLM powered detection reasoning solution includes monitoring network traffic at a security platform, wherein the security platform generates a sample based on the monitored network traffic; sending the sample to a security service to generate a Large Language Model (LLM) powered detection and reason, wherein the LLM is prompted to automatically generate a malware or benign verdict and a reason for explaining the verdict; and reporting the LLM powered detection and reason.

Claims (53)

1 . A system, comprising:

a processor configured to:

monitor network traffic at a security platform, wherein the security platform generates a sample based on the monitored network traffic;

send the sample to a security service to generate a Large Language Model (LLM) powered detection and reason, wherein the LLM powered detection and reason is prompted to automatically generate a malware or benign verdict and a reason for explaining the malware or benign verdict, wherein the generating of the LLM comprises to:

generate, based on samples associated with malicious HyperText Transfer Protocol (HTTP) request headers with command injection, a plurality of prompts for training the LLM for malware detection reasoning; and

train the LLM based on the plurality of prompts; and

report the LLM powered detection and reason; and

a memory coupled to the processor and configured to provide the processor with instructions.

2 . The system of claim 1 , wherein LLM powered detection and reason is associated with an inline security service.

3 . The system of claim 1 , wherein LLM powered detection and reason is associated with an offline security reporting service.

4 . The system of claim 1 , wherein the security platform includes an endpoint agent, a Domain Name System (DNS) proxy, a network gateway firewall (NGFW), and/or an internal gateway hosted on a remote network associated with a cloud security service.

5 . The system of claim 1 , further comprising to:

generate a malware verdict for the sample based on the LLM powered detection and reason.

6 . The system of claim 1 , further comprising to:

generate a benign verdict for the sample based on the LLM powered detection and reason.

7 . The system of claim 1 , further comprising to:

generate a malware verdict for the sample based on the LLM powered detection and reason; and

generate a human understandable explanation for the malware verdict based on the LLM powered detection and reason.

8 . The system of claim 1 , further comprising to:

generate a benign verdict for the sample based on the LLM powered detection and reason; and

generate a human understandable explanation for the benign verdict based on the LLM powered detection and reason.

9 . A method, comprising:

monitoring network traffic at a security platform, wherein the security platform generates a sample based on the monitored network traffic;

sending the sample to a security service to generate a Large Language Model (LLM) powered detection and reason, wherein the LLM powered detection and reason is prompted to automatically generate a malware or benign verdict and a reason for explaining the malware or benign verdict, wherein the generating of the LLM comprises:

generating, based on samples associated with malicious HyperText Transfer Protocol (HTTP) request headers with command injection, a plurality of prompts for training the LLM for malware detection reasoning; and

training the LLM based on the plurality of prompts; and

reporting the LLM powered detection and reason.

10 . The method of claim 9 , wherein LLM powered detection and reason is associated with an inline security service.

11 . The method of claim 9 , wherein LLM powered detection and reason is associated with an offline security reporting service.

12 . The method of claim 9 , wherein the security platform includes an endpoint agent, a Domain Name System (DNS) proxy, a network gateway firewall (NGFW), and/or an internal gateway hosted on a remote network associated with a cloud security service.

13 . The method of claim 9 , further comprising:

generating a malware verdict for the sample based on the LLM powered detection and reason.

14 . The method of claim 9 , further comprising:

generating a benign verdict for the sample based on the LLM powered detection and reason.

15 . The method of claim 9 , further comprising:

generating a malware verdict for the sample based on the LLM powered detection and reason; and

generating a human understandable explanation for the malware verdict based on the LLM powered detection and reason.

16 . The method of claim 9 , further comprising:

generating a benign verdict for the sample based on the LLM powered detection and reason; and

generating a human understandable explanation for the benign verdict based on the LLM powered detection and reason.

17 . A computer program product embodied in a non-transitory computer readable medium and comprising computer instructions for:

monitoring network traffic at a security platform, wherein the security platform generates a sample based on the monitored network traffic;

sending the sample to a security service to generate a Large Language Model (LLM) powered detection and reason, wherein the LLM powered detection and reason is prompted to automatically generate a malware or benign verdict and a reason for explaining the malware or benign verdict, wherein the generating of the LLM comprises:

generating, based on samples associated with malicious HyperText Transfer Protocol (HTTP) request headers with command injection, a plurality of prompts for training the LLM for malware detection reasoning; and

training the LLM based on the plurality of prompts; and

reporting the LLM powered detection and reason.

18 . A system, comprising:

a processor configured to:

send a set of malware samples for training data input to a Large Language Model (LLM), wherein the set of malware samples are associated with malicious HyperText Transfer Protocol (HTTP) request headers with command injection;

generate, based on the set of malware samples, a plurality of prompts to train the LLM for malware detection reasoning;

train the LLM using the plurality of prompts; and

deploy the LLM for the malware detection reasoning as an inline security service and/or an offline reporting security service; and

a memory coupled to the processor and configured to provide the processor with instructions.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 20, 2024
From: ZHANG, ZHIBIN; FU, YU; DAI, YUWEN; FENG, QIAN; SU, ZHEMIN; WANG, MEI
To: PALO ALTO NETWORKS, INC.
Reel/Frame 066845/0500 →
Continuity (1)
Related Publication 20250240313A1 · Jul 24, 2025
References Cited (10)
US 20140068563A1 · Saltzman · 2014 [cited by examiner]
US 20200019889A1 · Keanini · 2020 [cited by examiner]
US 20230318926A1 · McNamara · 2023 [cited by examiner]
US 20240414211A1 · Boyer · 2024 [cited by examiner]
US 20250141899A1 · Aggarwal · 2025 [cited by examiner]
US 20250156546A1 · Tseng · 2025 [cited by examiner]
Author Unknown, Few-Shot Prompting, Prompt Engineering Guide, Jan. 8, 2024, pp. 1-4. [cited by applicant]
Brown et al., Language Models are Few-Shot Learners, Advances in Neural Information Processing Systems, vol. 33, Jul. 22, 2020, pp. 1877-1901, arXiv:2005.14165v4 [cs.CL]. [cited by applicant]
Kaplan et al., Scaling Laws for Neural Language Models, Jan. 23, 2020, pp. 1-30. [cited by applicant]
Touvron et al., LLaMA: Open and Efficient Foundation Language Models, Feb. 27, 2023. [cited by applicant]