LLM-based system for detecting anomalous commands in network traffic

DE202025102500U1Active Publication Date: 2025-07-17ALANG KARAN SINGH CUPERTINO
View PDF 0 Cites 3 Cited by

Patent Information

Application Number
DE202025102500
Authority / Receiving Office
DE · DE
Patent Type
Utility models
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-07-17
Estimated Expiration
2035-05-31

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

System (100) for detecting anomalous commands in network traffic using a Large Language Model (LLM), comprising: a. a traffic capture module configured to monitor and extract command-level data from incoming network traffic over one or more communication protocols; b. a preprocessing and tokenization module configured to normalize, filter and transform the extracted commands into a structured format suitable for analysis; c. a contextual embedding module comprising a pre-trained or fine-tuned LLM configured to generate semantic embeddings of the structured commands; d. an anomaly detection module configured to compare the generated embeddings with a baseline profile of legitimate command behavior and identify deviations using machine learning algorithms; e. a threat classification module configured to categorize the identified anomalies based on the type and severity of the threat; and f. a response and logging module configured to initiate automatic remedial actions and record the events for further analysis, g. the system operates in real time to detect, classify, and respond to anomalous commands in a networked environment.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] The present invention relates to the field of network security systems. More specifically, it relates to a system for detecting anomalous or malicious commands in network traffic using large language models (LLMs). The invention aims to improve real-time threat detection and cybersecurity in digital communication networks.

[0002] In modern digital infrastructures, networked systems are increasingly vulnerable to cyberattacks, such as unauthorized command injections, malware proliferation, and advanced persistent threats. Traditional security tools often rely on signature- or rule-based detection mechanisms, which struggle to keep pace with the dynamic and evolving nature of cyber threats. These systems fail to detect novel, obfuscated, or zero-day attacks that don't match predefined patterns, leaving critical networks vulnerable to attack.

[0003] One of the most pressing challenges in this area is identifying anomalous or malicious commands embedded in legitimate network traffic. Attackers often use sophisticated techniques to mimic normal behavior, making it difficult for conventional systems to distinguish between benign and malicious actions. As command-based attacks increasingly leverage subtle syntax and context manipulation, a more intelligent and adaptive solution is needed to understand the intent behind network commands.

[0004] The present invention addresses these limitations by introducing a system that leverages large language models (LLMs) to analyze and detect anomalous commands in network traffic. By leveraging the contextual and semantic understanding capabilities of LLMs, the system can identify suspicious patterns that deviate from expected network behavior—even if these commands appear syntactically correct. This intelligent approach significantly improves the accuracy and responsiveness of network security operations in identifying and mitigating advanced threats.

[0005] One goal of the present disclosure is to enable real-time detection of anomalous commands in network traffic.

[0006] Another goal of the present disclosure is to use LLMs to understand the semantic context of network commands.

[0007] Another goal of this disclosure is to detect zero-day and obfuscated attacks that bypass traditional systems.

[0008] Another objective of this disclosure is to support multi-protocol monitoring for comprehensive network coverage.

[0009] Another objective of the present disclosure is to use a modular architecture for scalability and easy integration.

[0010] Another objective of this disclosure is to reduce false alarms through context-dependent anomaly detection.

[0011] Another goal of this disclosure is to automatically classify and prioritize detected threats in order to respond more quickly.

[0012] Another objective of this disclosure is to maintain detailed records for forensic analysis and compliance audits.

[0013] Further objects and advantages of the present disclosure will become apparent from the following description, which is not intended to limit the scope of the present disclosure.

[0014] The present invention generally provides an advanced system for detecting anomalous commands in network traffic using large language models (LLMs). It addresses the limitations of traditional rule-based and signature-based detection methods. The system improves cybersecurity by identifying threats in real time based on semantic understanding.

[0015] One embodiment of the present invention is a traffic capture module used to monitor and extract command-level data from live network communications. This module operates across multiple protocols, such as SSH, Telnet, and HTTP. It ensures comprehensive capture of potential attack vectors penetrating the system.

[0016] Another embodiment of the invention is the preprocessing and tokenization module, which refines the acquired data by filtering out noise and converting it into structured command representations. This step ensures that the input is clean and suitable for language model processing. It also performs normalization and encoding to preserve the semantics of the commands.

[0017] Another embodiment of the invention is the contextual embedding module, which leverages LLMs to generate deep contextual embeddings of commands. These embeddings capture both the syntax and intent behind the commands. This enables the system to understand subtle linguistic variations used in obfuscated or novel attacks.

[0018] Another embodiment of the invention is an anomaly detection module that compares current command behavior with a model of legitimate command usage. Using unsupervised or semi-supervised learning, it identifies deviations that may indicate malicious intent. This enables the detection of zero-day threats and threats that are not based on signatures.

[0019] Another embodiment of the invention is for the threat classification module to further analyze the detected anomalies to determine the type and severity of the threat. It can classify threats such as privilege escalation, remote code execution, and data exfiltration. This helps establish an appropriate priority list for response measures.

[0020] Another embodiment of the invention is the response and logging module, which enables automatic or manual defense strategies once a threat is confirmed.

[0021] It can terminate sessions, block IP addresses, or generate alerts for security teams. While maintaining detailed logs for audits and forensic review.

[0022] Another embodiment of the invention is the introduction of a modular, intelligent, and adaptable network security system. It combines deep language understanding with real-time detection to address evolving cyber threats. This system ensures a higher level of protection for critical digital infrastructures.

[0023] The present invention relates to an intelligent LLM-based system for detecting anomalous commands in network traffic. It integrates several functional modules that work together to ensure real-time threat detection and response. The system includes a traffic detection module for monitoring data, a preprocessing and tokenization module for cleaning and structuring inputs, and a contextual embedding module that uses a large language model to extract semantic features. Detected anomalies are identified by the anomaly detection module and classified by the threat classification module. Finally, the response and logging module performs mitigation measures and stores the events for review and analysis.

[0024] The invention is explained again below with reference to the figure. It shows: Fig. : an LLM-based system for detecting anomalous commands in network traffic.

[0025] Fig.illustrates an LLM-based system for detecting anomalous commands in network traffic. The invention discloses an intelligent LLM-based system for detecting anomalous commands in network traffic, comprising several integrated modules that collectively improve cybersecurity through semantic analysis and behavioral profiling. The Traffic Capture Module passively monitors live network traffic and extracts command-level data from protocols such as SSH, Telnet, or HTTP. This data is passed to the Preprocessing and Tokenization Module, which filters out irrelevant content, normalizes commands, and converts them into a structured format suitable for language model analysis.The processed data is then passed to the contextual embedding module, which uses a pre-trained or fine-tuned large language model (LLM) to generate contextual embeddings that capture the semantic meaning and syntactic structure of each command. These embeddings are evaluated in the anomaly detection module, which compares them to a baseline of legitimate command patterns, using unsupervised or semi-supervised learning algorithms to detect deviations. If an anomaly is detected, the threat classification module categorizes the threat type (e.g., privilege escalation, data exfiltration, command injection) based on learned threat signatures and behavioral profiles. Finally, the response and logging module triggers either automatic remediation actions, such asTerminating sessions or notifying administrators, and logs all events for forensic analysis. This modular system enables adaptive and context-aware detection of malicious network activity in real time, significantly improving security in dynamic digital environments.

Claims

[1] System (100) for detecting anomalous commands in network traffic using a Large Language Model (LLM), comprising: a. a traffic capture module configured to monitor and extract command-level data from incoming network traffic over one or more communication protocols; b. a preprocessing and tokenization module configured to normalize, filter and transform the extracted commands into a structured format suitable for analysis; c. a contextual embedding module comprising a pre-trained or fine-tuned LLM configured to generate semantic embeddings of the structured commands; d. an anomaly detection module configured to compare the generated embeddings with a baseline profile of legitimate command behavior and identify deviations using machine learning algorithms; e. a threat classification module configured to categorize the identified anomalies based on the type and severity of the threat; and f. a response and logging module configured to initiate automatic remedial actions and record the events for further analysis, g. the system operates in real time to detect, classify, and respond to anomalous commands in a networked environment. [2] The system (100) of claim 1, wherein the traffic detection module supports protocols selected from the group consisting of SSH, Telnet, HTTP, and FTP. [3] The system (100) of claim 1, wherein the preprocessing and tokenization module applies instruction normalization rules to remove noise and encode syntactic structures. [4] The system (100) of claim 1, wherein the large language model used in the contextual embedding module is fine-tuned using a dataset of network command sequences. [5] The system (100) of claim 1, wherein the anomaly detection module uses unsupervised learning techniques selected from the group consisting of clustering, autoencoders, and one-class SVM. [6] The system (100) of claim 1, wherein the threat classification module is configured to classify threats into categories such as privilege escalation, command injection, and data exfiltration. [7] The system (100) of claim 1, wherein the response and logging module is configured to generate alerts, terminate user sessions, or block IP addresses upon detection of high-level threats. [8] The system (100) of claim 1, wherein all modules are deployed in a distributed, cloud-based environment for scalable and real-time performance.

Citation Information

Cited By

  • Interaction monitoring method and system based on LLM security protection system

    CN120781348A

  • Network flow restoring and monitoring method

    CN120825342A

  • Medical sensing equipment production log analysis method and device based on big data

    CN121051078A