Innovations in artificial intelligence (AI) have changed the email security landscape in recent years. However, some older approaches are still very much in place and it can be difficult to determine what differentiates them. What is certain is that there is a significant distinction between new approaches using cyber AI and those based on signatures and blacklists that can determine whether the technology provides true protection or simply offers a notion of cybersecurity.
Signatures – an approach of the past
For the past several decades, cybersecurity technologies have sought to mitigate risks by preventing concurrent attacks from reoccurring. In the past, when the lifespan of a given malware or attack infrastructure was months or years, this approach worked. But today’s approach, which looks at past attacks to try to detect future attacks, is completely wrong. With the decreasing lifespan of attacks, where a domain could now be used in a single email and never be seen again, the historical-looking signature-based approach must be largely replaced by smarter systems.
Training machines about malicious emails
The first AI approach we consistently see involves leveraging an extremely large dataset with thousands or millions of emails. Once these emails arrive, the AI is trained to look for common patterns in malicious emails. The system then updates its models, ruleset, and blacklists based on that data.
This method certainly represents an improvement on traditional rules and signatures, but it doesn’t escape the fact that it is still reactive and incapable of stopping new attack infrastructure and new types of email attacks. It’s simply automating that flawed traditional approach, only instead of a human updating the rules and signatures, a machine does it.
Detecting Intent
Darktrace uses this approach, which works timelessly and is not susceptible to change over time, to analyze the grammar and tone of an email to identify intent: asking questions like “Does this look like an attempt at inducement? Is the sender trying to solicit confidential information? Is this extortion? By training a system on an extremely large data set collected over a period of time, you can begin to understand what, for example, inducement looks like. This allows you to easily detect future induction scenarios based on a common set of characteristics.
Training a system in this way works because, unlike the subject lines of phishing emails, the fundamental patterns in tone and language do not change over time. A solicitation attempt is always a solicitation attempt and will always have common characteristics. It provides an additional indication of the nature of the threat but is not in itself used to determine anomalous emails.
Identifying unknown unknowns
In addition to using the above approach to identify intent, Darktrace uses unsupervised machine learning, which starts with extracting and extrapolating thousands of pieces of data from each email. Some of this is taken directly from the email itself, while other data can only be determined by analyzing the type of intent above. Additional insights are also gained by looking at the emails in the broader context of all the data available in the organization’s email, network, and cloud environment.
Only after you have a significantly larger and more complete set of metrics, with a comprehensive description of that email, can you feed the data into a machine learning engine to begin to interrogate the data in a million ways to understand if it fits, given the broader context of the organization’s typical “pattern of life”.
The technology identifies patterns throughout an organization and acquires an ever-evolving sense of “self” as the organization grows and changes. It is this innate understanding of what is and is not “normal” that allows AI to detect the “unknown unknowns” rather than just “new variations of known evils”.
It is clear that older, signature and rule-based approaches are not sufficient to counter the threats that exist against email. Therefore, only a cyber AI approach, with different layers of security where the intent and tone of emails are analyzed, complex email information such as the server it was sent from, among other things, can combat the numerous threats. The great advantage of cyber AI is that it continuously learns from data and activity in real-time, allowing it to perform millions of calculations and thus ensure that the email is protected.

“I think detecting intent is more important than identifying unknown unknowns. Thoughts?”
I respectfully disagree. While detecting intent is crucial, identifying unknown unknowns is equally important. It helps us uncover blind spots and anticipate unforeseen challenges. Both aspects go hand in hand, complementing each other in a comprehensive approach.
“Who knew AI could be so good at sniffing out suspicious emails? 🤔 #Gamechanger”
“Signatures are so outdated, we need AI to save us from those sneaky email scams!”
Seriously? AI can’t save us from everything. Signatures are a basic security measure, and if you’re falling for email scams, maybe you need to work on your own vigilance. Don’t rely on technology to solve all your problems.
I don’t know about you guys, but I’m all for training machines about malicious emails! Let’s stay one step ahead of those sneaky spammers! 🤖📧
“Wow, who knew AI could be so powerful in protecting our inboxes? 🤖💪”
AI can indeed be powerful in protecting our inboxes, but let’s not forget that it’s not foolproof. Hackers are always finding ways to outsmart it. We still need to stay vigilant and not blindly rely on technology alone.
“Who needs signatures when we have machines that can detect intent? 🤖🔍 #AIprogress”
Signatures are not just about intent, they represent authenticity and accountability. Machines can’t replicate the personal touch and legal weight that handwritten signatures carry. Let’s not dismiss the value of traditional practices in the pursuit of AI progress. 🖋️🤝
“Who needs signatures? Let AI tackle those unknown unknowns and detect malicious intent! 🤖💥”
AI may be powerful, but it’s not infallible. Signatures provide accountability and human oversight, helping to prevent false positives and protect innocent individuals from being flagged as malicious. Let’s not underestimate the value of human judgment in the age of technology.