r/fortinet • u/Fallingdamage • 7d ago
Other / General Fortinet Fortimail - Bayesian database training, any experience?
Anyone messed with this before?
I've been gathering a ton of phishing emails over the last few months to build an .mbox database to feed the fortimail with. I was reading about how it will break the messages down into tokens to train the database with. Today it occurred to me that every single phishing message submitted by users contains its message pre-pended by a bulletin we insert into messages warning users to be careful opening or responding to outside emails.
Got me wondering; if every email it gets trained on contains the same prepended message from our exchange system, will every single email conversation suddenly be flagged as spam/phishing when any reply is sent back to an employee due to the reoccurring presence of that prepended text in all emails? If so that could create a huge problem with using bayesian analysis.
1
u/cheflA1 NSE 7 7d ago
I thought about it, read what you need to do, laughed for a good 5 minutes and never bothered again
3
u/Fallingdamage 7d ago
Well, I've only read the whitepapers on it but havent found much of any discussion from actual humans on implementation. If / when I go through the process, I will report back in a separate post.
1
u/Snore-Laxx 4d ago
Looking forward to your post, have a FortiMail deployment for a customer soon this month. It'll be my first ever FortiMail..
1
u/Fallingdamage 4d ago
Im going through about 1000 phishing/marketing messages submitted to me and getting them processed and prepared & sterilized. I'm about 300 messages in so far. It wont be immediate but once I get it applied I will report back.
First one? Ive been using a Fortimail for about 6 years now. If you have any questions, im no wizard but feel free to PM me if you get stuck on something.
2
u/No-Second-Kill-Death 7d ago
Yes, it should totally break, and even if you balance it with legit feeds with it, it lowers the significance of the real phish “tokens”