SYSTEMS AND METHODS FOR INTELLIGENT IDENTIFICATION AND AUTOMATED DISPOSAL OF NON-MALICIOUS ELECTRONIC COMMUNICATIONS
A system and method for accelerating a disposition of non-malicious electronic communications includes extracting one or more corpora of feature vectors from an electronic communication based on providing the electronic communication as input to a feature extractor; computing, by a machine learning-based electronic communication classification model, an electronic communication-type classification inference that includes a probability of the electronic communication being of the target non-malicious electronic communication type in response to the machine learning-based electronic communication classification model receiving the one or more corpora of feature vectors; attributing a classification label of the target non-malicious electronic communication type to the electronic communication based on the probability of the electronic communication-type classification inference satisfying a minimum electronic communication classification threshold; and automatically routing a security alert associated with the electronic communication to an alert disposal queue based on the electronic communication having the classification label of the target non-malicious electronic communication type.
1 . A computer-implemented method comprising:
generating a security alert based on receiving a request to assess a threat of an electronic message;
generating one or more corpora of feature vectors based on message data associated with the electronic message, wherein the one or more corpora of feature vectors includes:
(i) a first corpus of feature vectors comprising feature data indicative of whether the electronic message is of a target type, and
(ii) a second corpus of feature vectors comprising feature data indicative of whether the electronic message is a suspicious electronic message;
computing, using a machine learning model, an inference that includes a probability of the electronic message being of the target type in response to providing the one or more corpora of feature vectors to the machine learning model; and
executing an alert handling action for the security alert after computing the inference, wherein executing the alert handling action includes:
automatically closing the security alert when the probability of the electronic message being of the target type satisfies a predetermined minimum classification threshold, or
preventing the automatic closing of the security alert when one or more features of the second corpus of feature vectors satisfy predetermined suspicious criteria.
2 . The computer-implemented method according to claim 1 , wherein:
the target type corresponds to a class of electronic messages that are non-malicious.
3 . The computer-implemented method according to claim 1 , wherein:
the target type refers to a class of electronic messages that promotes one or more products, one or more services, or one or more events.
4 . The computer-implemented method according to claim 1 , wherein:
the security alert is routed to a security alert queue after the security alert is generated,
the security alert queue includes a plurality of security alerts, wherein each security alert of the plurality of security alerts is awaiting an alert triage,
the probability of the electronic message being of the target type satisfies the predetermined minimum classification threshold, and
automatically closing the security alert associated with the electronic message includes automatically removing the security alert associated with the electronic message from the security alert queue.
5 . The computer-implemented method according to claim 1 , further comprising:
obtaining a corpus of training data that includes a plurality of electronic message training data samples, wherein the corpus of training data includes:
(a) a first set of labeled electronic messages, wherein each electronic message of the first set of labeled electronic messages is labeled as being of the target type,
(b) a second set of labeled electronic messages, wherein each electronic message of the second set of labeled electronic messages is labeled as not being of the target type, and
(c) a third set of unlabeled electronic messages, wherein the corpus of training data includes more unlabeled electronic messages than labeled electronic messages; and
configuring the machine learning model based on a semi-supervised training of a machine learning classification model using the corpus of training data.
6 . The computer-implemented method according to claim 1 , further comprising:
displaying, via a user interface, a representation of the security alert that includes:
(a) a representation of the electronic message, and
(b) the probability of the electronic message being of the target type.
7 . The computer-implemented method according to claim 1 , wherein:
one feature of the second corpus of feature vectors indicates whether a return path of the electronic message matches a sender address of the electronic message, and
the machine learning model uses at least the one feature of the second corpus of feature vectors to assist with computing the probability of the electronic message being of the target type.
8 . The computer-implemented method according to claim 1 , wherein:
one feature of the second corpus of feature vectors indicates whether a sender domain of the electronic message was involved in a previous security incident, and
the machine learning model uses at least the one feature of the second corpus of feature vectors to assist with computing the probability of the electronic message being of the target type.
9 . The computer-implemented method according to claim 1 , wherein:
one feature of the first corpus of feature vectors indicates whether a sender of the electronic message corresponds to a corporate marketing account of an organization, and
the machine learning model uses at least the one feature of the first corpus of feature vectors to assist with computing the probability of the electronic message being of the target type.
10 . The computer-implemented method according to claim 1 , wherein:
one feature of the first corpus of feature vectors indicates a combined number of terms and phrases included in a body of the electronic message that is indicative of the target type, and
the machine learning model uses at least the one feature of the first corpus of feature vectors to assist with computing the probability of the electronic message being of the target type.
11 . The computer-implemented method according to claim 1 , wherein:
one feature of the first corpus of feature vectors indicates a chromatic intensity of the electronic message, and
the machine learning model uses at least the one feature of the first corpus of feature vectors to assist with computing the probability of the electronic message being of the target type.
12 . The computer-implemented method according to claim 1 , wherein:
one feature of the second corpus of feature vectors indicates a domain age of a sender domain used in the electronic message, and
the machine learning model uses at least the one feature of the second corpus of feature vectors to assist with computing the probability of the electronic message being of the target type.
13 . The computer-implemented method according to claim 1 , wherein:
one feature of the first corpus of feature vectors indicates whether one or more digital images are embedded in the electronic message, and
the machine learning model uses at least the one feature of the first corpus of feature vectors to assist with computing the probability of the electronic message being of the target type.
14 . The computer-implemented method according to claim 1 , wherein:
one feature of the first corpus of feature vectors indicates whether the electronic message includes an unsubscribe feature, and
the machine learning model uses at least the one feature of the first corpus of feature vectors to assist with computing the probability of the electronic message being of the target type.
15 . The computer-implemented method according to claim 1 , further comprising:
automatically attributing a classification label of the target type to the electronic message when the probability satisfies the predetermined minimum classification threshold.
16 . The computer-implemented method according to claim 1 , wherein:
the one or more features of the second corpus of feature vectors satisfies the predetermined suspicious criteria, and
preventing the automatic closing of the security alert includes routing the security alert to a review queue for assessment.
17 . A method comprising:
generating an alert based on receiving a request to assess a threat of an electronic message;
generating one or more sets of feature vectors based on message data associated with the electronic message, wherein the one or more sets of feature vectors includes:
(i) a first feature vector comprising feature data indicative of whether the electronic message is of a target type, and
(ii) a second feature vector comprising feature data indicative of whether the electronic message is a suspicious electronic message;
computing, using a machine learning model, an inference that includes a probability of the electronic message being of the target type in response to providing the one or more sets of feature vectors to the machine learning model; and
executing an alert handling action for the alert after computing the inference, wherein executing the alert handling action includes:
automatically closing the alert when the probability of the electronic message being of the target type satisfies a predetermined minimum classification threshold, or
preventing the automatic closing of the alert when one or more features of the second feature vector satisfy predetermined suspicious criteria.
18 . The method according to claim 17 , wherein:
the target type corresponds to a class of electronic messages that are non-malicious.
19 . The method according to claim 17 , wherein:
the target type refers to a class of electronic messages that promotes one or more products, one or more services, or one or more events.
20 . A method comprising:
identifying an alert associated with an electronic message;
generating one or more feature vectors based on message data associated with the electronic message, wherein the one or more feature vectors includes:
(i) a first set of features indicative of whether the electronic message is of a target type, and
(ii) a second set of features indicative of whether the electronic message is a suspicious electronic message;
computing, using a machine learning model, an inference that includes a probability of the electronic message being of the target type in response to providing the one or more feature vectors to the machine learning model; and
executing an alert handling action for the alert after computing the inference, wherein executing the alert handling action includes:
automatically closing the alert when the probability of the electronic message being of the target type satisfies a predetermined minimum classification threshold, or
preventing the automatic closing of the alert when one or more features of the second set of features satisfy predetermined suspicious criteria.