THREAT DETECTION PLATFORMS FOR DETECTING, CHARACTERIZING, AND REMEDIATING EMAIL-BASED THREATS IN REAL TIME
Conventional email filtering services are not suitable for recognizing sophisticated malicious emails, and therefore may allow sophisticated malicious emails to reach inboxes by mistake. Introduced here are threat detection platforms designed to take an integrative approach to detecting security threats. For example, after receiving input indicative of an approval from an individual to access past email received by employees of an enterprise, a threat detection platform can download past emails to build a machine learning (ML) model that understands the norms of communication with internal contacts (e.g., other employees) and/or external contacts (e.g., vendors). By applying the ML model to incoming email, the threat detection platform can identify security threats in real time in a targeted manner.
1 . A system, comprising:
a processor configured to:
receive an email addressed to an employee of an enterprise;
apply a first model to the email to produce a first output indicative of whether the email is representative of a non-malicious email, wherein the first model is trained using past emails addressed to the employee that have been verified as non-malicious emails;
determine, based on the first output, that the email may be a malicious email;
apply a second model to the email to produce a second output indicative of whether the email is representative of a given type of malicious email; and
perform an action with respect to the email based on the second output; and
a memory coupled to the processor and configured to provide the processor with instructions.