White Paper

Using Near-Real-Time Threat Intelligence to Detect Email-based Threats

Using Near-Real-Time Threat Intelligence to Detect Email-based Threats

Pages 8 Pages

This Cisco white paper explores how near-real-time threat intelligence strengthens email security. It focuses on detecting false negatives—malicious emails that bypass defenses—and using them as learning opportunities. Cisco Secure Email Threat Defense (ETD) converts such emails into embedding vectors stored in a context database. These vectors fuel a similarity detector that identifies and blocks new threats by comparing incoming emails to known threats. The system improves over time, learning from false negatives, customer reports, and analyst input to refine detection using machine learning and large language models.

Join for free to read