Mail phishing drill method and system based on intelligent knowledge graph

By generating differentiated fishing tasks through intelligent knowledge graphs, the problems of high manual participation, severe solidification and low reuse rate of existing fishing platforms are solved, automated and flexible fishing drills are realized, and the success rate and adaptability of fishing activities are improved.

CN117914564BActive Publication Date: 2025-10-17JIANGSU BOZHI SOFTWARE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311856271.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-28
Publication Date
2025-10-17
Estimated Expiration
2043-12-28

AI Technical Summary

Technical Problem

Existing phishing platforms have high levels of human involvement, severe rigidity, and low reuse rates, which makes phishing activities easy to detect and unable to adapt to diverse phishing targets.

Method used

Using an intelligent knowledge graph-based method, differentiated phishing tasks are generated through standardized labels and multi-label matching, including phishing targets, email templates, and site templates. Email sending plans are generated by combining personal information and random numbers to achieve automated and differentiated phishing drills.

Benefits of technology

It reduces manual participation, improves the differentiation and success rate of fishing activities, avoids solidification and repetitiveness, and enhances the flexibility and effectiveness of fishing tasks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117914564B_ABST
    Figure CN117914564B_ABST
Patent Text Reader

Abstract

The application discloses a phishing email drill method and system based on an intelligent knowledge graph, which can automatically generate a complete phishing activity plan according to a phishing activity theme, realize differentiated and accurate phishing emails, and display various data of a phishing activity process and results based on personal information of a phishing target, random numbers generated by a system and in combination with the intelligent knowledge graph. The application reduces the complexity of phishing email drills, solves the problems of homogenization of phishing emails, low reusability of entity resources and high difficulty of personnel operation, realizes intelligent knowledge graph multi-label matching of phishing emails, and improves the phishing awareness of the general public.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application relates to a mail phishing drill method and system, and belongs to the network security field, in particular to a mail phishing drill method and system based on an intelligent knowledge graph. BACKGROUND

[0002] With the rapid development of computer network technology, the large-scale popularity of cellular mobile networks and high-frequency short-wave communication, network communication security has become the focus of attention of countries around the world. In recent years, telecommunication fraud, mail phishing, website phishing attacks and other events have occurred frequently, seriously endangering the property safety and information security of citizens in various countries.

[0003] Currently, there are public phishing platforms such as Gophish and PhEmail. This type of platform has some solidified problems and a very high degree of manual participation. For example, the basic process of the current phishing email platform is: first, people analyze the phishing task, find relevant information, select a topic, and then build an email phishing platform after the topic is selected. Taking Gophish as an example, after the construction is completed, you need to create an email template, which can be imported in the form of importing email source code text. In order to ensure the authenticity of the imported email template, you need to obtain the email source code text from the email sent on the real website. After the email template is created, you need to create a phishing site. The phishing site must be strongly associated with the phishing email (for example, a phishing email for resetting QQ password must be a QQ password reset email as a template, and after clicking the URL link, it must jump to the interface for resetting QQ password). Open the real website, save it in the form of web page source code, modify the website source code, and modify the FORM form part in the website source code while ensuring that the page is more than 95% similar to the original website. The submission method of the FORM form must be POST. Gophish ish submits data by interacting with a resident webhook, so there are strict requirements for the FORM format of the submitted data. The action attribute value in the FROM form cannot be empty, the input tag must be included in the FORM form, and the name attribute value of the input tag must be a meaningful string such as password, username, or password. At the same time, to ensure that the submitted data is not garbled or unrecognizable, all forms must be encrypted or the encrypted part of the submitted information must be removed. Then copy the website source code into the phishing site add edit box, select the capture submitted data and capture password, and finally enter the data into the incorrectly jumped web page address into the Redirect to box. Finally, save the web page source code as a phishing site template. After the phishing site is created, you need to specify a phishing target. To add phishing targets, you can import data stored in plain text comma-delimited format into the phishing target, or add individual phishing targets one by one according to the format on the web page. Finally, the users added in the same batch will be formed into a target group (in the phishing target information, the target email address is the unique primary key and cannot be empty, while other information can be empty).After the phishing target is added, a mailbox that can send emails needs to be set up. The mailbox and phishing emails are strongly associated (for example, the email for resetting the QQ password must be sent from the QQ mailbox, and there is no case where a QQ password reset email is sent from a 163 mailbox). Setting up a mailbox requires configuring an SMTP server address, setting an account password, and testing email sending (note that public network email sending is generally subject to quantity restrictions, and once a certain number is exceeded, email sending will not be possible. Therefore, when using a public network mailbox, attention should be paid to this issue, and some service providers can use a membership to solve this problem). After the test is passed, a phishing task needs to be created. First, configure the user name, select the email template, phishing site template, email sending mailbox, and phishing target group. Set up a URL that can listen to requests, set the task start time, and set the email sending end time. Complete the phishing email configuration. After the configuration is complete, wait for the specified time to be triggered, and then generate a site page according to the preset phishing site template, generate an email according to the preset email template, and use the preset mailbox to complete the email sending to the preset phishing target within the specified time.

[0004] Taking the above phishing process as an example, the entire process is quite complex:

[0005] First of all, the manual participation is extremely high. In the entire email phishing activity process, personnel need to select the process, modify the original phishing email according to a certain method, form an email template, debug the web source code according to the standard method and generate a phishing site template, select and collect some targets, import them into the system according to a specific format or method, log in to the mailbox service, set the task time, and finally execute the email sending task. The entire process involves personnel, and the requirements for personnel are high, requiring multiple application technologies.

[0006] Secondly, the problem of solidification. For email tasks, the content of the phishing email received by each phishing target is consistent, the URL link clicked is the same, and the time is also continuous (because the platform is continuously sending emails). Such phishing actions are very solidified and can be easily identified.

[0007] Finally, the problem of low reuse rate. Since all templates and targets in the phishing activity process are from the current production, they cannot be reused. In the absence of a pre-subject, the existing content cannot be effectively organized, and the degree of association is entirely determined by the implementer of the phishing activity on an ad hoc basis, lacking some rules. When performing the next phishing activity, only templates can be temporarily produced for phishing activities. SUMMARY

[0008] According to one aspect of the present application, a method for phishing email drill based on intelligent knowledge graph is provided. The method can generate a complete phishing activity plan according to the theme of phishing activity, and realize differentiated and accurate phishing email, and display the process of phishing activity and the data of results on demand, based on personal information, random numbers generated by the system and in combination with intelligent knowledge graph.

[0009] The method for phishing email drill based on intelligent knowledge graph comprises:

[0010] (1) creating a phishing task, and selecting a standardized label, wherein the standardized label is a label standardized by intelligent knowledge graph;

[0011] (2) obtaining a phishing target of the phishing task according to the standardized label of the phishing task and in combination with intelligent knowledge graph in a multi-label matching manner;

[0012] (3) matching a plurality of phishing email templates according to the standardized label of the phishing task and the standardized label of the phishing target and in combination with intelligent knowledge graph;

[0013] (4) performing multi-label matching on an existing phishing site template according to the standardized label of the phishing task, the standardized label of the single phishing target and the standardized label of the single phishing email template and in combination with intelligent knowledge graph, generating a phishing site template for a single phishing template, and generating a plurality of different phishing site templates for a plurality of phishing templates;

[0014] (5) generating a phishing email sending plan for an individual according to part of personal information of the single phishing template and a generated random number and in combination with intelligent knowledge graph; and combining a plurality of phishing email sending plans with other entities to form the phishing task;

[0015] (6) waiting for a phishing task starting condition to be met, and starting the task.

[0016] Optionally, the step (1) further comprises creating a name of the phishing task, remark information of the phishing and a task starting time.

[0017] Optionally, the phishing target information is obtained through a user questionnaire, and the obtained content comprises at least one of the following: personal name, age, ID card, email, telephone, work and rest, education, bone piece, medical record, finance, family information and friend relationship.

[0018] In the step (3), the working mechanism of matching the plurality of phishing email templates is that, based on the current phishing theme and the standardized label, the phishing target and the phishing email template have the same associated attribute, and the closeness of the association can improve the probability of the phishing target clicking the phishing email.

[0019] Optionally, the multi-label matching refers to matching of multiple labels, performing maximum label matching, in one-to-one matching, taking the one with more label matching hits as the best matching item, and only taking one matching result; in one-to-many matching, taking a specified number of matching results according to system configuration.

[0020] Optionally, in step (5), the generating of the phishing email sending plan for the individual includes: generating a random number, and generating a list of email sending times based on the individual's work and rest time and intelligent knowledge graph of the phishing target, wherein the content includes at least one of: phishing task start time, number of emails sent, phishing task stop time, and phishing email sending time for a single phishing target.

[0021] Optionally, the step (6) includes: the phishing task listens to external requests according to task requirements; each phishing target generates a unique ID for statistics of the phishing target's operation on the phishing email; each phishing email generates a unique ID for statistics of the phishing email's opening status by the phishing target; and each phishing site generates a unique ID for statistics of the operation of each opened phishing site or collection of information submitted by each phishing site.

[0022] The unique ID is the unique ID of each entity, and during the phishing task, the unique ID of the entity is used to identify the current state of the entity, and some operations on the current entity will trigger a request to the phishing task server, which contains the current entity ID and other entity IDs connected thereto. When the request enters the phishing task server, the phishing task server will calculate the operation of the phishing target on each entity according to the stored data.

[0023] Optionally, the phishing task start condition includes: task start time, start mode, and the task start is according to the task start trigger time point, selects the first trigger mechanism, and the subsequent trigger mechanisms are automatically disabled.

[0024] Optionally, the step (6) further includes: monitoring the phishing task execution process to obtain state data.

[0025] Optionally, the step (6) uses a webhook data transmission mechanism when listening.

[0026] Optionally, the state data includes at least one of: server running state (such as CPU, memory, disk), application running state (such as number of emails sent, number of sites created, number of emails to be sent, number of sites to be created), task state (such as number of emails opened, number of sites opened, number of data captured, overall success rate of the task).

[0027] According to another aspect of the present application, a phishing email drill system based on intelligent knowledge graph is provided, characterized in that the system comprises a task resource subsystem, a standardized label management subsystem, an intelligent knowledge graph subsystem, and a task generation subsystem; the standardized label management subsystem matches the entity resources provided by the task resource subsystem in combination with the intelligent knowledge graph subsystem, and the task generation subsystem is used to generate phishing email tasks by combining phishing email sending plans according to the matching results, wherein the phishing email sending plan refers to a set of email sending plans for a single phishing target, the email sending plans for multiple phishing targets are different, the email sending plan uses relative time, and the plan is generated by combining phishing target information, phishing target labels, phishing email labels, and the intelligent knowledge graph in the intelligent knowledge graph subsystem.

[0028] Optionally, the task resource subsystem is used to manage at least one of the following entity resources: email templates, mailbox services, phishing targets, and site templates.

[0029] Optionally, the management content of the task resource subsystem includes at least one of the following: adding, deleting, modifying, and setting standardized labels for entities.

[0030] Optionally, the management of the phishing target includes at least one of the following: target questionnaires, phishing target management, and target label management.

[0031] Optionally, the target questionnaire is mainly used to obtain information from unspecified crowds, and the obtained information includes at least one of the following: commonly used passwords, family information, commonly used apps, personal email, phone, office email, education-related information, graduation school, and financial information.

[0032] Optionally, the phishing target management refers to the maintenance of the original information collected for a single phishing target.

[0033] Optionally, the standardized label includes not only the labels standardized by the intelligent knowledge graph, but also the summary of the personnel built-in and personal custom labels.

[0034] Optionally, the target label management is used to manage personal custom labels and standardized labels, and includes a summarization function of personal custom labels. The summarization is not simply narrowing the scope, but expanding or summarizing the labels based on standardization, so that the description of the labels to the individual is more clear.

[0035] Optionally, the management of the mailbox service is the management of the service state obtained by the standard SMTP authentication service. The mailbox service is limited by the resource quota of the currently authenticated service provider for the account, and the SMTP authentication key provided by each service provider is obtained in different ways, and the service request frequency is also limited.

[0036] The SMTP authentication method refers to obtaining the permission to use the application based on the standard authentication protocol, but each public service mailbox uses different special keys for authentication, and the authentication key acquisition methods are different and complex.

[0037] The resource quota refers to the fact that the mailbox service of the public network generally has some limitations. For example, QQ mailbox allows each user to send only 200 emails per day.

[0038] The service request frequency refers to the request limit of the public network mailbox service. For example, some public networks limit the number of emails sent per unit time to 100.

[0039] Optionally, the intelligent knowledge graph subsystem is configured to match at least one of the following entity resources based on the intelligent knowledge graph: a mail template, a mailbox service, a phishing target, a site template, and a phishing email sending task. The mail template and the site template need to conform to the label topic, and the mailbox service needs to fit the real use scenario of the label.

[0040] Optionally, the standardized label management subsystem is configured to manage the standardized labels of entity resources and participate in a multi-label matching mechanism.

[0041] Optionally, the multi-label matching mechanism refers to the matching of multiple labels, which implements maximum label matching. In the case of one-to-one matching, the label matching hits more is the best matching item, and only one matching result is taken. In the case of one-to-many matching, the specified number of matching results is taken according to the system configuration.

[0042] Optionally, the task generation subsystem is configured to combine and manage phishing tasks. The combination refers to selecting a phishing target, a phishing email template, a phishing site template, and a mail service to form a phishing task based on the standardized labels and the intelligent knowledge graph. The management refers to adjusting the generated phishing task.

[0043] Optionally, the adjustment includes modifying the email sending plan of a single phishing target, removing a phishing target, and changing the start time of a phishing task.

[0044] Optionally, the system further includes a task display subsystem configured to display the phishing task process.

[0045] Optionally, the phishing task process display comprises at least one of the following: system running status, email sending task execution, phishing target triggering.

[0046] Optionally, the system further comprises a database for storing system data, the system data comprising at least one of the following: phishing user information, standardized label information, phishing email template metadata, phishing site template metadata, email service metadata, phishing task information, phishing email sending plan.

[0047] The application can produce beneficial effects, including:

[0048] 1) The application uses a user survey form to obtain phishing target information, and the user can customize labels, and the phishing target information is classified, sorted and stored through intelligent knowledge graph and standardized labels.

[0049] 2) The application uses standardized labels to describe the properties of an object in clear, accurate, explicit and standardized language.

[0050] 3) The label standardization of the phishing site template, phishing email template, email service, and phishing target provided by the application is not a replacement or deletion of the label, but a standardized description of the entity based on understanding of the entity, and multiple labels are used to improve the explanation.

[0051] 4) The application generates a phishing email sending plan based on intelligent knowledge graph combined with individual work and rest time and system random numbers, to avoid phishing email centralized interception caused by specific email sending cycles or intensive email sending methods. Among them, the individual work and rest time is used to generate a sub-phishing task for each phishing target, and then the randomly generated sub-phishing tasks are combined with the phishing email sending plan to generate a different and accurate email phishing task; the random number can ensure that the entire sending plan is random but conforms to the phishing target activity scene; the intelligent knowledge graph standardized label can conveniently and quickly and accurately describe the individual.

[0052] 5) The multi-label matching method provided by the application is based on the standardized labels induced by the intelligent knowledge graph, and the multi-label weight value is controlled to match the target properties more closely. Specifically, based on the existing entity labels, the best match is performed, multiple entities are combined with the phishing email sending plan to form a unique phishing task, and the multi-label matching stores a sending record, so that the phishing email sent does not match the phishing site and email service, or the same content is sent to the same user.

[0053] 6) The various entities provided in the present application will form a single record when performing multi-label combination, and since the record of a single phishing activity provided to the phishing target is completely random. That is, the entity has only a single record, and the current record can be used on other phishing targets that do not match this record, and since the record is not unique, it can be repeatedly matched and used multiple times.

[0054] 7) The phishing task provided in the present application is not only sending one email during the execution of the phishing task, and thanks to the randomness of the email sending task, the same subject phishing email with different content is sent multiple times in a single phishing drill, enhancing the effectiveness and success of the phishing task.

[0055] 8) The phishing task provided in the present application does not have an end time, so it also needs to be manually closed. When the task is started and not manually closed, the phishing email will continue to send phishing emails according to the phishing email sending plan, and generate phishing sites. When the entity combined by the multi-label matching algorithm cannot be reused, the email sending task stops. BRIEF DESCRIPTION OF DRAWINGS

[0056] Figure 1 A flowchart of a phishing drill method based on an intelligent knowledge graph in an embodiment of the present application;

[0057] Figure 2 A frame diagram of a phishing system based on an intelligent knowledge graph in an embodiment of the present application. DETAILED DESCRIPTION

[0058] The present application will be described in detail below with reference to the embodiments, but the present application is not limited to these embodiments.

[0059] The present application provides a phishing drill method based on an intelligent knowledge graph, which comprises:

[0060] (1) Obtain the phishing target information through the form of user questionnaire filling.

[0061] (2) Induce standardized personal labels based on the intelligent knowledge graph.

[0062] (3) Produce phishing email templates, phishing site templates, and email services based on the intelligent knowledge graph and standardized labels.

[0063] (4) Produce a phishing email sending plan based on the intelligent knowledge graph and the personal work and rest time and the random number generated by the system.

[0064] (5) Generate a difference-precise phishing task based on the intelligent knowledge graph and the standardized labels.

[0065] In an embodiment, the phishing target information obtained in step (1) includes, but is not limited to, personal name, age, ID card, email, phone, work and rest, education, bone fragments, medical record, financial management, family information, and friend relationship.

[0066] In an embodiment, the labels include system labels and custom labels. The system labels are preset by the system, and the custom labels are customized by the user filling in the survey file.

[0067] Preferably, step (2) includes classifying the custom labels according to the standardized labels. The classification is not simply narrowing the range, but expanding or summarizing the labels based on standardization, so that the labels describe the individual more clearly.

[0068] In an embodiment, step (3) includes making some templates or services according to the detailed and accurate labels. The email templates and website templates made are consistent with the label topics, and the email services need to be consistent with the real use scenarios of the labels.

[0069] In an embodiment, step (4) includes that after the phishing target is specified, the system calculates and generates a list of email sending times based on the knowledge graph and the personal work and rest time and the random number generated by the system. The list includes the following information: what time to send how many emails, what time to stop sending emails, and what time to send to whom. The entire sending plan is random but consistent with the phishing target activity scenario.

[0070] In an embodiment, step (5) includes that after the phishing target is specified, the phishing task creation automatically generates a phishing task based on the intelligent knowledge graph standardized label, and generates a phishing email sending plan for each phishing target.

[0071] Preferably, the phishing task refers to generating a sub-phishing task for each phishing target. Each sub-task is generated by the work and rest time of a single phishing target combined with a system random number. The email sent to a single target is also based on the multi-label matching mode (the labels are matched according to the maximum matching number, for example, in the email template label and the personal label, 3 overlapping labels are greater than 2 overlapping labels, and the matching is successful to establish an association relationship; in the one-to-one matching case, the label matching hit number is more, and only one matching result is taken; in the one-to-many matching case, the specified number of matching results is taken according to the system configuration), and the phishing task is randomly generated. Each sub-phishing task and the phishing email sending plan combine to generate a different and precise email phishing task.

[0072] Embodiment 1

[0073] As Figure 1 shown, a phishing drill method and system based on intelligent knowledge graph, wherein the method comprises the following steps.

[0074] Step one, create a phishing task, the user inputs the name of the phishing task, the note information of the phishing, selects the standardized label, etc.

[0075] Among them, the standardized label can select one or more.

[0076] The user can also set the task start time, end time, and start time trigger priority lower than manual trigger.

[0077] Step two, according to the standardized label of the phishing task combined with the intelligent knowledge graph, the system acquires the phishing target of the phishing task according to the multi-label matching mode. If you want to specify a specific purpose as the phishing target of the current task, you can mark the same label for the specified phishing target, and the label only belongs to the internal label of the phishing target, that is, you can perform specific grouping on the specified target.

[0078] Step three, according to the selected standardized label of the task, the standardized label of the phishing target, and the intelligent knowledge graph, the phishing email template is matched, and multiple phishing email templates are matched. The mapping relationship between the task and the email template is that each phishing target corresponds to multiple phishing email templates.

[0079] Step four, through the standardized label of the phishing task, the standardized label of the single phishing target, and the standardized label of the single phishing email template combined with the intelligent knowledge graph, the existing phishing site template is matched with multiple labels. For a single target, the multi-label matching intelligently generates a phishing site template. For multiple targets, the matching results of the phishing email template and the phishing site template are randomly generated. There are multiple matching results for a single phishing target, that is, a single phishing task for multiple phishing targets, a single phishing target for multiple phishing email templates, and a single phishing email template for a single phishing site. The template matching result corresponding to multiple phishing targets is random.

[0080] Step four, for part of the personal information of a single phishing target and the random number generated by the system combined with the intelligent knowledge graph, a mail sending plan for an individual is generated, which is mainly used to meet the habit of using mail of the phishing target and prevent some mail checking situations. Further, the single mail sending plan can be combined to obtain a mail sending plan for the entire phishing target, and the mail sending time is performed according to the relative time, rather than the fixed time; finally, the phishing target, the phishing email template, the phishing site template, and the phishing email sending plan form a phishing task.

[0081] Step five, wait for the phishing task to start condition, task start. Phishing task according to the task demand, open webhook, listen to the request from outside; Each phishing target generates a unique ID, which is used to count the operation of the phishing target to the phishing email; Each email generates a unique ID for counting the status of the email opened by the phishing target; Each phishing site will generate a unique ID, which is used to count the operation of each opened phishing site or collect the information submitted by each phishing site. The task execution process state will be displayed in real time in the task display interface, and the phishing activity will be ended after the task is manually ended.

[0082] In an embodiment, the phishing task refers to an entity of a phishing activity. The task is mainly associated by standardized tags, thereby realizing automatic phishing task creation. After creation, the details of the phishing task can be edited, such as removing a phishing email from a single user, and removing a phishing target in a single phishing task.

[0083] In an embodiment, the phishing email template and the phishing website template theme remain consistent, that is, the subject of the phishing email template and the phishing website template have consistent deception. For example, the content in a phishing email template is a shopping website price reduction notice, and then the phishing site must be a price reduction notice. If the content of the phishing site is not a price reduction notice, it will result in no correlation between the front and back, resulting in the failure of the entire phishing task.

[0084] In an embodiment, the phishing task standardized tag refers to the target can label the attribute value of itself when collecting personal information from a non-specific target group. The label can be self-defined, or selected by the system administrator or internally customized by the system. The user-defined label, after summarizing, combines with the intelligent knowledge graph to form a clear, accurate, explicit, and standardized language to describe the attributes of a thing.

[0085] In an embodiment, the multi-label matching mode refers to the best matching based on existing entity labels, that is, using a matching scheduler to realize a configuration mechanism based on multiple labels. For example, entity A1 has 5 labels, entity A2 has 5 labels, entity A3 has 4 labels, B1 has 5 labels, entity B2 has 5 labels, and entity B3 has 4 labels. When 3 labels in A1 match successfully with B1, 2 labels match successfully with B2, and 3 labels match successfully with B3. Then two records are formed, that is, A1 and B1, and A1 and B3.

[0086] In an embodiment, the multi-tag matching of the phishing email template and the phishing site template has some restrictions. For a single phishing target, the relationship between the phishing email template and the phishing site template is one-to-one. Once a single phishing email template is matched to a phishing site template, a binding relationship is formed, and the phishing email template cannot be matched again. The record results of each phishing target are randomly formed. For multiple phishing targets, the relationship between the phishing email template and the phishing site template is fixed, and the content is random.

[0087] In an embodiment, the email sending plan refers to that each phishing target is generated with an email sending plan. All plans are relative to time. The relative coordinates of the plan time are the time of triggering task execution. All email sending plans are completed within a fixed time range. If the task is not completed within the relative time range, the plan is generated again, and the execution continues until the task is completed or other task stopping conditions are met.

[0088] In an embodiment, the mailbox service mainly performs multi-tag matching with the phishing email. The phishing email template corresponding to the email service is one-to-one.

[0089] In an embodiment, the phishing task starting conditions include but are not limited to the task starting time, manual start by personnel, or some other ways. According to the task starting trigger time point, the first trigger mechanism is taken, and the subsequent trigger mechanisms are automatically disabled.

[0090] In an embodiment, during the task execution process, each phishing target corresponds to multiple phishing emails, and for a single phishing target, each phishing email corresponds to a phishing site. All entities (including: phishing target, phishing site, phishing email) have a unique ID. When the entity is triggered, an external request is made with the ID, and the ID is automatically counted by the system.

[0091] In an embodiment, the task execution process state includes but is not limited to: server running state (such as CPU, memory, disk), application running state (such as the number of sent emails, the number of created sites, the number of pending emails, the number of pending sites), task progress state (such as the number of opened emails, the number of opened sites, the number of data captured, the overall success rate of the task).

[0092] As Figure 2As shown, in one embodiment, a mail phishing system based on intelligent knowledge graph includes a task display subsystem, a task generation subsystem, an intelligent knowledge graph subsystem, a database, a task resource subsystem, and a standardized label management subsystem. The task display subsystem is developed using Html5+CSS3 to adapt to various types of clients. The task resource subsystem, the standardized label management subsystem, the task generation subsystem, and the intelligent knowledge graph subsystem are developed using Golang to cope with a large number of program concurrency. The database uses a MySQL database and a read-write separated database cluster as a backend support.

[0093] The task display subsystem is mainly responsible for front-end page display, which includes: mail phishing task situation summary, mail phishing system resource usage, mail phishing task target display, system running state during mail phishing execution, task running status, and target triggering situation display.

[0094] The task generation subsystem is mainly responsible for the creation and management of phishing tasks, including creating phishing tasks, selecting standardized labels to automatically form a complete phishing task, matching the overall label of the user through the intelligent knowledge graph subsystem, generating a mail sending task for a single user for the matched entity, and combining the mail sending task as a whole. The mail task also has functions such as starting, stopping, and setting the start time.

[0095] In one embodiment, the task generation subsystem is used to combine and manage phishing tasks. The combination refers to selecting phishing targets, phishing email templates, phishing site templates, and mail services to form phishing tasks based on standardized labels and intelligent knowledge graphs. The management refers to adjusting the generated phishing tasks, including but not limited to modifying the mail sending plan of a single phishing target, removing a phishing target, and changing the start time of a phishing task.

[0096] The intelligent knowledge graph subsystem is mainly responsible for assisting in calculation, i.e., summarizing the custom labels of phishing targets to form clear, accurate, explicit, and standardized labels, and affecting multi-label matching in the phishing email task process.

[0097] In one embodiment, the intelligent knowledge graph subsystem is used to match entity resources based on intelligent knowledge graphs, including but not limited to: email templates, mailbox services, phishing targets, site templates, and phishing email sending tasks.

[0098] The database is mainly responsible for system data storage, including phishing user information, labeled label information, phishing email template metadata, phishing site template metadata, mail service metadata, phishing task information, and phishing email sending plans.

[0099] The task resource subsystem is mainly responsible for providing resources to the task generation subsystem, including a mail service management engine, a target management engine, a site management engine, and a mail management engine. Each engine is responsible for entity management to realize the addition, deletion, modification, and query of entity resources. The subsystem is also responsible for providing each entity resource and setting standardized tags for the task generation subsystem. The entity resources include, but are not limited to, a mail template, a mailbox service, a phishing target, and a site template.

[0100] In an embodiment, the management of the phishing target includes at least one of the following: a target questionnaire, phishing target management, and target tag management.

[0101] The target questionnaire is mainly used to obtain information from unspecified crowds, and the obtained information includes, but is not limited to, personal commonly used passwords, family information, commonly used apps, personal mailboxes, phones, office mailboxes, education-related information, graduation institutions, and financial information.

[0102] The phishing target management refers to the maintenance of original information collected for a single phishing target.

[0103] The target tag management is used for the management of personal custom tags and standardized tags, and includes a summarization function of the personal custom tags.

[0104] The management of the mailbox service is the management of the service state obtained through standard SMTP authentication services.

[0105] The standardized tag management subsystem is mainly responsible for providing tag management for phishing targets, phishing mail templates, phishing site templates, and mail services, and providing a custom tag standardization function for the phishing targets.

[0106] In an embodiment, the standardized tag management subsystem is used to manage standardized tags of entity resources and participate in a multi-tag matching mechanism.

[0107] The multi-tag matching mechanism refers to the matching of multiple tags, the implementation of maximum tag matching, the selection of the best matching item in one-to-one matching according to the number of tag matching hits, and the selection of only one matching result. In one-to-many matching, a specified number of matching results are selected according to system configuration.

[0108] The above is only a few embodiments of the present application, and does not limit the present application in any form. Although the above describes the preferred embodiments of the present application, it is not intended to limit the present application. Any skilled person in the art can make some changes or modifications to the above disclosed technical content without departing from the scope of the technical solution of the present application, and the equivalent embodiments are equivalent to the equivalent embodiments, which are within the scope of the technical solution.

Claims

1. An email phishing drill method based on intelligent knowledge graph, characterized in that: The method includes: (1) Create a fishing task and select a standardized tag. The standardized tag refers to a tag that has been standardized by the intelligent knowledge graph; (2) Based on the standardized labels of the fishing task and in combination with the intelligent knowledge graph, the fishing target of the fishing task is obtained in accordance with a multi-label matching method; (3) Matching multiple phishing email templates based on the standardized labels of the phishing tasks and the standardized labels of the phishing targets in combination with the intelligent knowledge graph; (4) Based on the standardized label of the phishing task, the standardized label of a single phishing target, and the standardized label of a single phishing email template, combined with the intelligent knowledge graph, multi-label matching is performed on the existing phishing site templates, and a single phishing site template is generated for a single phishing template, and multiple different phishing site templates are generated for multiple phishing templates; (5) Generate a phishing email sending plan for an individual based on the partial personal information of a single phishing template and the generated random number combined with the intelligent knowledge graph; combine multiple phishing email sending plans with other entities to form the phishing task; (6) Wait for the fishing mission start conditions to be met and the mission to start; The multi-label matching mechanism refers to: matching multiple labels, implementing maximum label matching. In the case of one-to-one matching, the label with the most hits is the best match, and only one matching result is used; in the case of one-to-many matching, a specified number of matching results are used according to the system configuration; The generation of a phishing email sending plan for an individual includes: generating a random number, and calculating and generating an email sending time list based on the personal work and rest time of the phishing target and the intelligent knowledge graph, wherein the content includes at least one of the following: the start time of the phishing task, the number of emails sent, the stop time of the phishing task, and the phishing email sending time for a single phishing target.

2. The email phishing drill method based on intelligent knowledge graph according to claim 1 is characterized in that: The step (1) also includes: creating the name of the fishing task, fishing notes, and task start time.

3. The email phishing drill method based on intelligent knowledge graph according to claim 1 is characterized in that: The phishing target information is obtained through a user questionnaire, and the obtained content includes at least one of the following: personal name, age, ID card, email address, phone number, work and rest schedule, education level, bone slices, medical records, financial management, family information, and friend relationships.

4. The email phishing drill method based on intelligent knowledge graph according to claim 1 is characterized in that: The step (6) includes: the phishing task monitors external requests according to task requirements; each phishing target generates a unique ID for counting the operations of the phishing target on the phishing email; each phishing email generates a unique ID for counting the status of the phishing email being opened by the phishing target; each phishing site generates a unique ID for counting each operation of opening the phishing site or collecting information submitted by each phishing site.

5. The email phishing drill method based on intelligent knowledge graph according to claim 1 is characterized in that: The fishing task initiation conditions include: task initiation time and initiation method. The task initiation is based on the task initiation trigger time point, the first trigger mechanism is selected, and the subsequent trigger mechanisms are automatically invalidated; The step (6) further includes: monitoring the execution process of the fishing task to obtain status data; The status data includes at least one of the following: server running status, application running status, and task progress status.

6. An email phishing drill system based on intelligent knowledge graph, characterized in that: The system includes: a task resource subsystem, a standardized tag management subsystem, an intelligent knowledge graph subsystem, and a task generation subsystem; the standardized tag management subsystem matches the entity resources provided by the task resource subsystem in combination with the intelligent knowledge graph subsystem; Step 1: The task generation subsystem is used to generate a phishing email task by combining phishing email sending plans based on the matching results, wherein the phishing email sending plan refers to a collection of email sending plans for a single phishing target, and the email sending plans for multiple phishing targets are different. The email sending plans use relative time, and the plans are generated by combining phishing target information, phishing target labels, and phishing email labels with the intelligent knowledge graph in the intelligent knowledge graph subsystem; Step 2: Based on the standardized labels of the fishing task and the intelligent knowledge graph, the system obtains the fishing target of the fishing task according to the multi-label matching method; Step 3: Based on the standardized labels selected for the task creation and the standardized labels for the phishing targets, combined with the intelligent knowledge graph, the phishing email templates are matched to generate multiple phishing email templates. The mapping relationship between tasks and email templates is that each phishing target corresponds to multiple sets of phishing email templates. Step 4: Use standardized labels for phishing tasks, individual phishing targets, and individual phishing email templates in combination with the intelligent knowledge graph to perform multi-label matching on existing phishing site templates. The multi-label matching mechanism refers to: matching multiple labels, implementing maximum label matching. In the case of one-to-one matching, the label with the most hits is the best match, and only one matching result is used; in the case of one-to-many matching, a specified number of matching results are used according to the system configuration; The generation of a phishing email sending plan for an individual includes: generating a random number, and calculating and generating an email sending time list based on the personal work and rest time of the phishing target and the intelligent knowledge graph, wherein the content includes at least one of the following: the start time of the phishing task, the number of emails sent, the stop time of the phishing task, and the phishing email sending time for a single phishing target.

7. The email phishing drill system based on intelligent knowledge graph according to claim 6 is characterized in that: The task resource subsystem is used to manage at least one of the following entity resources: email templates, mailbox services, phishing targets, and site templates.

8. The email phishing drill system based on intelligent knowledge graph according to claim 6 is characterized in that: The management content of the task resource subsystem includes at least one of: adding, deleting, modifying entities, and setting standardized labels.

9. The email phishing drill system based on intelligent knowledge graph according to claim 6 is characterized in that: The management of the fishing target includes at least one of the following: target questionnaire, fishing target management, and target tag management.

10. The email phishing drill system based on intelligent knowledge graph according to claim 9 is characterized in that: The target questionnaire is mainly used to obtain information from the general public, and the information obtained includes at least one of the following: personal commonly used passwords, family information, commonly used apps, personal email, phone number, work email, academic qualifications, graduation school, and financial information.

11. The email phishing drill system based on intelligent knowledge graph according to claim 9 is characterized in that: The phishing target management refers to the maintenance of the original information collected for a single phishing target.

12. The email phishing drill system based on intelligent knowledge graph according to claim 9 is characterized in that: The target tag management is used to manage personal customized tags and standardized tags, including the function of summarizing personal customized tags.

13. The email phishing drill system based on intelligent knowledge graph according to claim 7 is characterized in that: The management of the mailbox service is service status management obtained by standard SMTP authentication service.

14. The email phishing drill system based on intelligent knowledge graph according to claim 6 is characterized in that: The intelligent knowledge graph subsystem is used to match at least one of the following entity resources based on the intelligent knowledge graph: email template, mailbox service, phishing target, site template, and phishing email sending task.

15. The email phishing drill system based on intelligent knowledge graph according to claim 6 is characterized in that: The standardized tag management subsystem is used to manage standardized tags of entity resources and participate in the multi-tag matching mechanism.

16. The email phishing drill system based on intelligent knowledge graph according to claim 6, characterized in that: The task generation subsystem is used to combine and manage phishing tasks. The combination refers to the selection of phishing targets, phishing email templates, phishing site templates, and email services by combining standardized tags with intelligent knowledge graphs to form phishing tasks. The management refers to the adjustment of already generated phishing tasks.

17. The email phishing drill system based on intelligent knowledge graph according to claim 16, characterized in that: The adjustments include: modifying the email sending plan of a single phishing target, removing the phishing target, and changing the start time of the phishing task.

18. The email phishing drill system based on intelligent knowledge graph according to claim 6, characterized in that: The system also includes a task display subsystem for displaying the fishing task process.

19. The email phishing drill system based on intelligent knowledge graph according to claim 6, characterized in that: The phishing task process display includes at least one of the following: system operation status, email sending task execution status, and phishing target triggering status.

20. The email phishing drill system based on intelligent knowledge graph according to claim 19, characterized in that: The system also includes a database for storing system data, and the system data includes at least one of the following: phishing user information, standardized label information, phishing email template metadata, phishing site template metadata, email service metadata, phishing task information, and phishing email sending plan.

Citation Information

Patent Citations

  • Fishing user simulation collection method, device and system and computer readable storage medium

    CN111770086A

  • Fishing simulation test method and system and electronic equipment

    CN113806740A