| CPC G06F 21/577 (2013.01) [G06F 16/338 (2019.01); G06F 16/355 (2019.01); G06F 16/36 (2019.01)] | 20 Claims |

|
1. A method, comprising:
monitoring, by a cyberthreat detection system, a target of interest in network communications to and from a digital medium, wherein the cyberthreat detection system comprises a rules database, wherein the monitoring comprises processing unstructured content in the network communications, and wherein the processing comprises:
determining, from the unstructured content, content items containing combinations of static keywords, dynamic keywords, or regular expressions that represent the target of interest;
clustering, based on the combinations of the static keywords, the dynamic keywords, or the regular expressions, the content items into clusters;
determining, from the clusters and utilizing vetted cybersecurity phrases, a cluster containing high precision phrases relating to the target of interest; and
updating the rules database utilizing the high precision phrases; and
classifying, utilizing classifier rules stored in the rules database, the unstructured content in the network communications to thereby identify which content items in the unstructured content that refer to the target of interest constitute cyberthreats.
|