IP Library › Granted Patent US 12,513,176
Granted Patent B2
US 12,513,176 · App. 18/513,244 · Granted Dec 30, 2025

Large language model based intelligent malicious packet detection

Inventors: Madhav Aggarwal (San Jose, CA); Vishnu Vasanth Radja (San Jose, CA); Vernon Richard Groves (San Jose, CA)
Assignee: A10 NETWORKS INC
H04L63/1425G06F16/35G06F16/9535G06F40/20G06F40/284G06F40/58G06N3/0455
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,513,176
App. No.
18/513,244
Granted
Dec 30, 2025
Kind
B2
Abstract

A method and system for detecting malicious network packets via an intelligent large language model are described. In addition, a method for fine-tuning a pretrained large language model to detect malicious network packets is described. The training process generates a plurality of embeddings from input network packet data, generates clusters for those embeddings, performs an entropy analysis, and calculates a loss value. Contrastive learning is used to further fine-tune the large language model based embedder.

Claims (31)

1 . A method of training a large language model based packet detection software tool, the method comprising:

processing a training data set of network packets with a large language model (LLM) based embedder to generate a plurality of embeddings;

generating a plurality of clusters from the plurality of embeddings;

performing an entropy analysis of the generated plurality of clusters from the plurality of embeddings;

computing a loss value from a result of the performed entropy analysis; and

updating the LLM based embedder based on the computed loss value, wherein when a malicious packet is detected, an attack detector begins to take actions to mitigate the attack, to launch a counter attack, to publish the identity of the originator of the malicious packet, or to take no action.

2 . The method of claim 1 , wherein the LLM utilizes a Generative Pre-trained Transformer (GPT) neural network.

3 . The method of claim 1 , wherein each of the generated plurality of embeddings is a numerical array.

4 . The method of claim 3 , further comprising reducing at least some of the generated plurality of embeddings to two-dimensional coordinates.

5 . The method of claim 4 , further comprising generating a two-dimensional graphical representation of the at least some of the generated plurality of embeddings.

6 . The method of claim 1 , wherein the performing the entropy analysis further comprises determining an anchor point embedding, a first candidate point embedding, and a second candidate point embedding.

7 . The method of claim 6 , further comprising: using a contrastive learning process to label each of the first candidate point embedding and the second candidate point embedding with one of a positive label and a negative label.

8 . The method of claim 1 , wherein the training data set of network packets comprises at least one of the following parameters for each network packet: destination address, source address, destination port, source port, TCP sequence number, TCP ACK number, packet length, and frame length.

9 . The method of claim 1 , wherein the training data set of network packets comprises historical data from past malicious network packets.

10 . A method of malicious packet detection via an intelligent large language model, the method comprising:

processing network packets at a trained large language model (LLM) based embedder to generate a plurality of embeddings;

generating a plurality of clusters from the plurality of embeddings; and

generating a Berkeley Packet Filter (BPF) from the plurality of clusters.

11 . The method of claim 10 , wherein the trained LLM based embedder utilizes a Generative Pre-trained Transformer (GPT) neural network.

12 . The method of claim 10 , wherein the trained LLM based embedder is trained with a contrastive learning process.

13 . The method of claim 10 , wherein the processing the network packets comprises processing at least one of the following parameters for each network packet: destination address, source address, destination port, source port, TCP sequence number, TCP ACK number, packet length, and frame length.

14 . The method of claim 10 , wherein the trained LLM based embedder is trained with historical data from past malicious network packets.

15 . A system for malicious packet detection via a large language model, the system comprising:

at least one processor configured to:

process network packets at a trained large language model (LLM) based embedder to generate a plurality of embeddings;

generate a plurality of clusters from the plurality of embeddings; and

generate a Berkeley Packet Filter (BPF) from the plurality of clusters.

16 . The system of claim 15 , wherein the trained LLM based embedder utilizes a Generative Pre-trained Transformer (GPT) neural network.

17 . The system of claim 15 , wherein the trained LLM based embedder is trained with a contrastive learning process.

18 . The system of claim 15 , wherein the wherein the processing the network packets comprises processing at least one of the following parameters for each network packet: destination address, source address, destination port, source port, TCP sequence number, TCP ACK number, packet length, and frame length.

19 . The system of claim 15 , wherein the trained LLM based embedder is trained with historical data from past malicious network packets.

Continuity (2)
Continuation 18384379 · Oct 26, 2023
Related Publication 20250141899A1 · May 1, 2025
References Cited (10)
US 12340191B1 · Serban · 2025 [cited by examiner]
US 20230386450A1 · Eby · 2023 [cited by examiner]
US 20240354830A1 · Raghavan · 2024 [cited by examiner]
US 20240412011A1 · Hoang · 2024 [cited by examiner]
US 20240419903A1 · Wu · 2024 [cited by examiner]
US 20250014571A1 · Wu · 2025 [cited by examiner]
US 20250036800A1 · Joshi · 2025 [cited by examiner]
US 20250131262A1 · Bang · 2025 [cited by examiner]
US 20250148031A1 · Rakhmanov · 2025 [cited by examiner]
US 20250156460A1 · Gibson · 2025 [cited by examiner]