SYSTEMS AND METHODS FOR INTELLIGENT PHISHING THREAT DETECTION AND PHISHING THREAT REMEDIATION IN A CYBER SECURITY THREAT DETECTION AND MITIGATION PLATFORM
A system and method for accelerating a cybersecurity event detection and remediation includes extracting corpora of feature data from a suspicious electronic communication, wherein the corpora of feature data comprise at least one corpus of text data extracted from a body of the suspicious electronic communication; computing at least one text embedding value for the suspicious electronic communication; evaluating the text embedding values of the corpus of text data against an n-dimensional mapping of adverse electronic communication vectors, the n-dimensional mapping comprising a plurality of historical electronic communication vectors derived for a plurality of historical electronic communications; identifying whether the suspicious electronic communication comprises one of an adverse electronic communication based on the evaluation of the text embedding value, and accelerating a cybersecurity event detection by routing data associated with the suspicious electronic communication to one of a plurality of distinct threat mitigation routes.
1 . A method comprising:
computing, by a text embedding model, at least one text embedding value for a suspicious electronic communication based on a corpus of text data extracted from the suspicious electronic communication;
evaluating the at least one text embedding value computed for the suspicious electronic communication against an n-dimensional mapping of embedding vectors of a plurality of distinct historical electronic communications;
identifying a distinct embedding vector of the n-dimensional mapping associated with a historical electronic communication based on the evaluation of the at least one text embedding value against the n-dimensional mapping; and
routing data associated with the suspicious electronic communication to one of a plurality of distinct cybersecurity threat mitigation routes based on an evaluation of a message body of the suspicious electronic communication against a message body of the historical electronic communication associated with the distinct embedding vector.
2 . A computer program product that, when executed by one or more processors, performs operations comprising:
computing, by a text embedding model, at least one text embedding value for a suspicious electronic communication based on a corpus of text data extracted from the suspicious electronic communication;
evaluating the at least one text embedding value computed for the suspicious electronic communication against an n-dimensional mapping of embedding vectors of a plurality of distinct historical electronic communications;
identifying a distinct embedding vector of the n-dimensional mapping associated with a historical electronic communication based on the evaluation of the at least one text embedding value against the n-dimensional mapping; and
routing data associated with the suspicious electronic communication to one of a plurality of distinct cybersecurity threat mitigation routes based on an evaluation of a message body of the suspicious electronic communication against a message body of the historical electronic communication associated with the distinct embedding vector.