Configure Predictive Intelligence for User Reported Phishing
Configure and prepare the model to identify user reported phishing emails.
Vorbereitungen
Role required: ml_admin
Prozedur
- Navigate to All > Predictive Intelligence for Phishing > Configuration.
-
In Step 1 of the configuration, select one of the following options from the
Close code source list:
- Default close code: Select this option to specify the default security incident close codes that must be used by the training model to identify malicious emails and legitimate ones. Click the lock icon and select one or more False positive codes or Confirmed phishing codes.
- Custom close code: Select the Custom close code option if you want to define close codes from custom fields that may be used as part of your existing incident response procedures. To define a close code, select a field from the security incident table and specify one or more filter conditions.
-
In Step 2, import historical data that can be used to train the model.
Select the Data Source for importing the historical data. This can be:
- User reported phishing email table: You can see the number of records that can be imported as historical data. Select this option and click Import.
- Custom data source: You can attach a single formatted CSV file that contains historical data records. Select the file and click Import.
Hinweis:The CSV file that you import must contain the following headers:- Label
- Header
- Body text
Click Cancel Import to stop importing the data. The import process is canceled and all records that have been imported so far are deleted.
-
After you have imported the historical data, click the link to refresh the
page.
You can then either import more training data or continue with the next step.
-
In Step 3, verify if the number of records available for training meet the
minimum threshold requirements.
Hinweis:The default values for maximum and minimum number of training records are displayed. These thresholds can be modified in the Platform Machine Learning Properties page. Contact Customer Support for assistance.
-
If the training data is sufficient, click Train
model.
You can update the inputs for training in the screen below.
-
Prediction inputs that you can modify include:
- What are you interested in predicting?
- What input data is helpful to predict the output field?
- What historical data do you want to use to train the solution and how frequently do you want to retrain it?
The default values for these inputs are displayed. You can modify them and click either of the following:- Update: Updates the training model definition.
- Update & Retrain: Updates the training model definition and retrains the model (Triggers the Train Model function).
-
Finally, when you have completed training the model, click the
Activate Prediction check box.
Predictions are now provided on every user reported phishing record using that model. If you would like to stop providing predictions on the user reported phishing records, clear the Activate Prediction check box and click Deactivate.