Enterprise employee anti-phishing mail awareness training system and method
By building a multi-module collaborative enterprise employee anti-phishing email awareness training system, the problems of insufficient differentiation and interactive detection in existing training programs have been solved. It realizes the generation of personalized simulated phishing emails and real-time feedback, thereby improving employees' anti-phishing capabilities and the enterprise's network security protection capabilities.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- XIAN THERMAL POWER RES INST CO LTD
- Filing Date
- 2026-01-22
- Publication Date
- 2026-04-24
AI Technical Summary
Existing corporate employee anti-phishing email awareness training lacks differentiated design, the training content is out of touch with the actual phishing attack scenarios employees face, and the interactive detection and feedback mechanisms are insufficient, resulting in poor training effectiveness and wasted resources.
A multi-module collaborative training system is constructed, including modules for configuration management, phishing email generation and sending, interaction detection, real-time feedback, data statistics and analysis, and targeted strategy generation. By obtaining employee department distribution and permission information, personalized simulated phishing emails are generated, interactive behavior is monitored in real time and provided with instant feedback, and behavior logs are analyzed in depth to formulate targeted training strategies.
This significantly improves the relevance and effectiveness of training, helps employees build job-related anti-phishing awareness, uncovers data value, accurately identifies high-risk groups and weak links, optimizes the allocation of training resources, and continuously enhances the company's awareness of anti-phishing emails.
Smart Images

Figure CN121923904A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and in particular to a training system and method for training enterprise employees on anti-phishing email awareness. Background Technology
[0002] Currently, in the field of corporate employee anti-phishing email awareness training, existing technologies mostly adopt a uniform training model, lacking differentiated consideration for different employee groups within an enterprise. Most solutions rely solely on general anti-phishing knowledge courses or fixed-template simulated emails for training, failing to consider employees' departmental attributes, job permissions, and email interaction characteristics in daily office scenarios. This results in training content being disconnected from the actual phishing attack scenarios employees face. Employees rarely encounter phishing email types relevant to their work during training, failing to develop targeted prevention awareness. Consequently, their ability to identify real phishing emails after training is limited, and the training effect falls short of meeting the actual needs of enterprise network security protection.
[0003] Meanwhile, existing training technologies have significant shortcomings in interactive detection and feedback mechanisms, and the degree of data value mining is low. On the one hand, while some solutions can simulate sending phishing emails, they cannot accurately monitor the complete interactive behavior of employees, or lack timely educational guidance after employees trigger simulated malicious attachments. Employees cannot promptly understand the risks of their actions and find it difficult to quickly correct misunderstandings. On the other hand, existing technologies only perform basic statistical summaries on the data generated during training, failing to deeply analyze employees' high-risk behavioral patterns, departmental security weaknesses, and characteristics of high-risk periods. This prevents companies from developing targeted follow-up training strategies based on data, and repeated training still fails to address core security vulnerabilities, ultimately resulting in a waste of training resources and low efficiency in building the company's overall anti-phishing email security defense. Therefore, how to improve the efficiency of anti-phishing email awareness training for corporate employees has become an urgent problem to be solved. Summary of the Invention
[0004] This invention provides a training system and method for enterprise employees to prevent phishing emails, in order to solve the problems mentioned in the background art.
[0005] To achieve the above objectives, this invention provides an enterprise employee anti-phishing email awareness training system, characterized in that the system includes a configuration management module, a phishing email generation and sending module, an interaction detection module, an instant feedback module, a data statistics and analysis module, and a targeted strategy generation module, wherein: The configuration management module is used to configure phishing email parameters and target groups; The phishing email generation and sending module is used to generate personalized simulated phishing emails based on phishing email parameters and send them to the target group. The interaction detection module is used to monitor employees' interaction behavior with personalized simulated phishing emails. When it is detected that an employee triggers a simulated malicious attachment, the module reports the employee's behavior log through an encrypted communication channel. The instant feedback module is used to trigger an instant feedback mechanism based on behavior logs, pop up an educational pop-up on the employee's terminal, and send anti-phishing knowledge content to the employee's corporate email. The data statistics and analysis module is used to statistically analyze behavior logs and generate statistical data and training reports; The targeted strategy generation module is used to identify high-risk groups and weak links based on statistical data and training reports, and to develop targeted training strategies.
[0006] In one implementation, when configuring phishing email parameters and target groups, the configuration management module is specifically used for: Obtain employee department distribution information and permission information from the enterprise's organizational structure data package; Based on departmental distribution and access information, the initial target groups vulnerable to phishing attacks are identified. Based on the pre-set phishing email template library, filter the email subject parameters and content parameters that are relevant to the initial target group to obtain the initial phishing email parameters for employees; The initial target group and preliminary phishing email parameters were analyzed and verified to obtain the phishing email parameters and target group.
[0007] In one implementation, the phishing email generation and sending module, when generating personalized simulated phishing emails based on phishing email parameters and sending them to the target group, is specifically used for: Based on the content template in the phishing email parameters and combined with the role characteristics of the target group, a personalized email body is generated. By disguising phishing email parameters and personalized email body as executable files, a simulated attachment of phishing email parameters is obtained. The simulated attachments are obfuscated to obtain personalized phishing emails with simulated attachments; The behavior logic of personalized simulated phishing emails is restricted. When a personalized simulated phishing email is triggered, it is only reported through an encrypted channel and no actual malicious operation is performed. Personalized emails are combined with personalized phishing emails and packaged together, then sent to the corporate email accounts of the target group through an isolated external mail server.
[0008] In one implementation, the phishing email generation and sending module, when performing the executable file disguise of the phishing email parameters and the personalized email body to obtain a simulated attachment of the phishing email parameters, is specifically used for: Based on the characteristics of the bait content in the phishing email parameters, set the file names according to the naming habits of real office documents in the enterprise's organizational structure; The content of the personalized email body is converted into a text data block, and the text data block is embedded into a preset position in the body of the phishing email program; Based on the file structure of filenames and text data blocks, generate simulated executable files with a document visualization appearance; By combining icon resources with simulated executable files, simulated attachments for phishing email parameters can be generated.
[0009] In one implementation, when the interaction detection module monitors employee interactions with personalized simulated phishing emails and reports the employee's behavior logs via an encrypted communication channel when it detects that the employee has triggered a simulated malicious attachment, it is specifically used for: Monitor employee terminal interactions with personalized phishing emails, and detect email open events and attachment trigger events; When an attachment trigger event is detected to be targeting a simulated malicious attachment, the simulated malicious attachment is launched after verifying the security of the execution environment. Based on the built-in recording function of the simulated malicious attachment, the employee's identification, operation timestamp, and terminal environment information are fused and detected to obtain the employee's interaction data; Interaction data is encapsulated into structured behavior logs and uploaded in real time via an encrypted communication channel.
[0010] In one implementation, when the interaction detection module verifies the security of the execution environment and launches the simulated malicious attachment after recognizing an attachment triggering event targeting a simulated malicious attachment, it is specifically used for: Perform an environment detection operation to confirm that the employee terminal is within the enterprise's dedicated network environment and generate an environment verification result; Verify the process list on the employee terminal to confirm that there are no debugging tools or dynamic analysis programs. Check the system security status identifier to confirm that the endpoint protection software is in normal operating condition; The results of environmental verification, process verification, and security status checks are combined to generate a comprehensive security assessment conclusion. When the comprehensive security assessment results meet the preset security conditions, the function of recording simulated malicious attachments will be activated.
[0011] In one implementation, when the instant feedback module executes the instant feedback mechanism triggered based on behavior logs, pops up an educational pop-up on the employee's terminal, and sends anti-phishing knowledge content to the employee's corporate email, it is specifically used for: Parse the employee identifier and operation type in the behavior log to generate feedback type information; Based on the pre-set anti-phishing knowledge base, the feedback type information is matched and mapped to obtain the employee's educational content. The system locates the corresponding employee's terminal device based on the employee's identification, and then displays an educational pop-up window on the employee's terminal device, showing the educational content. Customized anti-phishing knowledge materials from the anti-phishing knowledge base will be simultaneously sent to the corporate email addresses corresponding to the employee's identification.
[0012] In one implementation, the statistics and analysis module, when executing statistical analysis behavior logs and generating statistical data and training reports, is specifically used for: Parse the employee department information, operation timestamps, and operation types in the behavior logs to generate statistical data from the behavior logs; Based on statistical data, the trigger rate of personalized simulated phishing emails is calculated by department, and departmental security level indicators are generated from behavioral logs. Time series analysis of operation timestamps reveals high-risk periods in the behavior logs; Integrate departmental safety level indicators, characteristics of high-risk periods, and key training content to generate a training report that includes improvement suggestions.
[0013] In one implementation, the targeted strategy generation module, when performing the task of identifying high-risk groups and weaknesses and formulating targeted training strategies based on statistical data and training reports, is specifically used for: Analyze the frequency and type distribution of employee interaction behaviors in statistical data to identify high-risk behavioral patterns that deviate from the normal safety baseline; Based on high-risk behavior patterns and the departmental attributes of the target group, high-risk groups with common risk characteristics are clustered. Identify the key triggers for high-risk groups in specific phishing email topics and content, and determine the knowledge gaps of high-risk groups. Based on the knowledge gaps, matching training materials are extracted from the anti-phishing knowledge base and combined into targeted training courses for high-risk groups. Based on the targeted training courses and the work characteristics and risk levels of high-risk groups, differentiated training intensity and assessment standards are set to generate targeted training strategies for enterprises.
[0014] To address the aforementioned problems, this invention also provides a method for training enterprise employees on anti-phishing email awareness, the method comprising: S1. Configure phishing email parameters and target groups; S2. Generate a personalized simulated phishing email based on the phishing email parameters and send it to the target group; S3. Monitor employee interaction with personalized simulated phishing emails. When an employee triggers a simulated malicious attachment, report the employee's behavior log through an encrypted communication channel. S4. Trigger an instant feedback mechanism based on behavior logs, pop up an educational pop-up on the employee's terminal, and send anti-phishing knowledge content to the employee's corporate email. S5. Statistical analysis of behavior logs to generate statistical data and training reports; S6. Based on statistical data and training reports, identify high-risk groups and weak links, and develop targeted training strategies.
[0015] Compared with the prior art, the present invention has the following beneficial effects: 1. This invention significantly improves the relevance and effectiveness of anti-phishing email awareness training for enterprise employees by constructing a multi-module collaborative training system. The system utilizes a configuration management module to accurately obtain employee department distribution and permission information, combines this with a preset template library to filter matching email parameters, and then uses a phishing email generation and sending module to integrate target group role characteristics to generate personalized simulated phishing emails. This ensures that the training scenario highly matches the employees' actual work scenarios, helping employees establish an anti-phishing awareness system relevant to their own positions. Simultaneously, the interaction detection module can monitor employees' interaction behavior with simulated emails in real time. Upon detecting risky operations, it reports the behavior log through an encrypted channel. The instant feedback module then triggers pop-up prompts and knowledge pushes, allowing employees to immediately identify the risk points and obtain corresponding anti-phishing knowledge after the operation, effectively strengthening employees' memory and recognition capabilities of phishing email characteristics and improving the knowledge absorption efficiency of a single training session.
[0016] 2. This invention also fully leverages the value of training data. Through a data statistics and analysis module, it deeply processes behavioral logs to generate key information such as departmental security level indicators and high-risk periods, along with training reports containing improvement suggestions, providing data support for subsequent training. The targeted strategy generation module, based on statistical data and reports, accurately identifies high-risk groups and areas of knowledge weakness. It extracts matching training materials from an anti-phishing knowledge base and develops differentiated training intensities and assessment standards, ensuring that training resources are precisely targeted to core needs and avoiding waste. This data-driven, targeted training model not only provides intensive training to high-risk groups to address their cognitive gaps but also makes the company's overall training plan more aligned with actual security needs, ultimately continuously improving employees' overall awareness of anti-phishing emails and building a more robust cybersecurity barrier for the company. Attached Figure Description
[0017] Figure 1 A system architecture diagram of an anti-phishing email awareness training system for enterprise employees is provided in an embodiment of the present invention; Figure 2This is a flowchart illustrating a method for training enterprise employees on anti-phishing email awareness, as provided in an embodiment of the present invention.
[0018] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation
[0019] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments belong to some, but not all, embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0020] The terminology used in the embodiments of this invention is for the purpose of describing particular embodiments only and is not intended to limit the invention. The singular forms “said” and “the” as used in the embodiments of this invention and the appended claims are also intended to include the plural forms, and “multiple” generally includes at least two unless the context clearly indicates otherwise.
[0021] Depending on the context, the word "if" or "if" as used here can be interpreted as "when," "when," "in response to determination," or "in response to detection." Similarly, depending on the context, the phrase "if determination" or "if detection (of the stated condition or event)" can be interpreted as "when determination," "in response to determination," "when detection (of the stated condition or event)," or "in response to detection (of the stated condition or event)."
[0022] Furthermore, the timing of the steps in the following method embodiments is merely an example and not a strict limitation.
[0023] In practice, the server-side equipment deployed in an enterprise employee anti-phishing email awareness training system may consist of one or more devices. This system can be implemented as a business instance, a virtual machine, or hardware devices. For example, it can be implemented as a business instance deployed on one or more devices in a cloud node. Simply put, it can be understood as software deployed on a cloud node to provide anti-phishing email awareness training to various users. Alternatively, it can be implemented as a virtual machine deployed on one or more devices in a cloud node, with application software installed to manage various users. Or, it can be implemented as a server composed of numerous identical or different types of hardware devices, with one or more devices configured to provide anti-phishing email awareness training to various users.
[0024] In terms of implementation, the enterprise employee anti-phishing email awareness training system and the user terminal are mutually compatible. That is, if the enterprise employee anti-phishing email awareness training system is implemented as an application installed on a cloud service platform, then the user terminal is a client that establishes a communication connection with the application; or if the enterprise employee anti-phishing email awareness training system is implemented as a website, then the user terminal is implemented as a webpage; or if the enterprise employee anti-phishing email awareness training system is implemented as a cloud service platform, then the user terminal is implemented as a mini-program in an instant messaging application.
[0025] like Figure 1 The diagram shown is a system architecture diagram of an enterprise employee anti-phishing email awareness training system provided by an embodiment of the present invention.
[0026] The enterprise employee anti-phishing email awareness training system 100 described in this invention can be set up in a cloud server. In terms of implementation, it can be used as one or more service devices, or as an application installed in the cloud (e.g., a mobile service operator's server, server cluster, etc.), or it can be developed as a website. Depending on the functions implemented, the enterprise employee anti-phishing email awareness training system 100 may include a configuration management module 101, a phishing email generation and sending module 102, an interaction detection module 103, an instant feedback module 104, a data statistics and analysis module 105, and a targeted strategy generation module 106. The modules described in this invention can also be called units, referring to a series of computer program segments that can be executed by the processor of an electronic device and perform a fixed function, stored in the memory of the electronic device.
[0027] In this embodiment of the invention, in an enterprise employee anti-phishing email awareness training system, each of the above-mentioned modules can be implemented independently and can call other modules. Here, "calling" can be understood as one module connecting to multiple modules of another type and providing corresponding services to those connected modules. The enterprise employee anti-phishing email awareness training system provided by this embodiment of the invention allows for adjustment of the system's applicability by adding modules and directly calling them without modifying the program code, achieving cluster-based horizontal expansion to quickly and flexibly expand the system. In practical applications, the above modules can be set up on the same device or different devices, or they can be set up on virtual devices, such as service instances on a cloud server.
[0028] The following describes, with reference to specific embodiments, the various components and specific workflows of an enterprise employee anti-phishing email awareness training system: Configuration management module 101 is used to configure phishing email parameters and target groups; In this embodiment of the invention, when configuring phishing email parameters and target groups, the configuration management module is specifically used for: Obtain employee department distribution information and permission information from the enterprise's organizational structure data package; Based on departmental distribution and access information, the initial target groups vulnerable to phishing attacks are identified. Based on the pre-set phishing email template library, filter the email subject parameters and content parameters that are relevant to the initial target group to obtain the initial phishing email parameters for employees; The initial target group and preliminary phishing email parameters were analyzed and verified to obtain the phishing email parameters and target group.
[0029] Specifically, the configuration management module retrieves the organizational structure data package from the enterprise's designated data source. It sends a data extraction request through a dedicated data interface that interfaces with this data source, explicitly specifying the fields to be retrieved: employee department distribution information and permission information. Upon receiving the request, the data source extracts the corresponding employee data from the database or file based on the requested fields and returns it to the configuration management module in a structured format. After receiving the returned data, the configuration management module performs an integrity check, confirming that the department distribution information and permission information fields for each employee are complete. Once the check passes, the module stores this data in a dedicated data table within its internal system, thus completing the retrieval of employee department distribution information and permission information from the enterprise's organizational structure data package.
[0030] The selection criteria for identifying vulnerable employees to phishing attacks are determined as follows: Departmental distribution is selected based on frequent external email processing and low participation in technical security training; Access control is based on basic system access levels. The configuration management module extracts each employee's department information from the stored employee data table and compares it with the above departmental selection criteria, retaining records of employees matching the criteria. Then, it extracts each employee's access control information and compares it with the above access control criteria, retaining records of employees matching the criteria. The employee records retained after the two selections are merged, and duplicate records are removed. The resulting employee list represents the initial target group vulnerable to phishing attacks.
[0031] The pre-defined phishing email template library stores multiple categorized templates. Each template includes sample email subject and content, and each template is labeled with the applicable department type and permission level. The configuration management module calculates the department types and permission levels within the identified initial target groups to form group characteristic information. The module extracts the labeling information for each template from the template library and matches it with the group characteristic information, retaining templates whose labeling information is completely consistent with the group characteristic information as candidate templates. From each candidate template, the specific email subject text and email content text are extracted, and the subject and content parameters extracted from all candidate templates are summarized into a temporary list. The parameters in the temporary list are deduplicated; if the subject or content parameters extracted from different candidate templates are exactly the same, only one is retained. The final set of subject and content parameters is the initial phishing email parameters for employees.
[0032] The configuration management module retrieves recent phishing drill data and security incident records from the enterprise, filtering out historical data of employee groups with the same department type and permission level as the initial target group. It then calculates the percentage of these historical groups clicking on phishing emails during phishing drills and the percentage of successful phishing attacks in actual security incidents. The module compares each subject and content parameter in the initial phishing email with the enterprise's secure email gateway's interception keyword database until all parameters pass the interception check. Simultaneously, it retrieves parameter data similar to the initial phishing email parameters used in historical phishing drills, calculates the phishing success rate for similar parameters, and identifies these parameters as verified phishing email parameters. The verified target group and verified phishing email parameters are then associated and stored to obtain the phishing email parameters and target group.
[0033] In summary, the configuration management module retrieves the organizational structure data package from the data source specified by the enterprise, sends an extraction request containing the required fields through a dedicated data interface that interfaces with the data source, and performs integrity verification on the data after receiving the structured data returned by the data source. After the verification is successful, the data is stored in a dedicated data table inside the module, and finally the department distribution information and permission information of employees in the enterprise organizational structure data package are obtained.
[0034] In summary, the configuration management module first determines the screening criteria for those vulnerable to phishing attacks, then extracts the department information and permission information of each employee from the stored employee data table, compares them with the corresponding screening criteria, and retains the records that meet the conditions. Subsequently, the two screening results are merged and duplicate records are removed, and finally the initial target group vulnerable to phishing attacks is selected.
[0035] In summary, the configuration management module first counts department types and permission levels from the identified initial target groups to form group characteristic information; then it matches candidate templates with matching annotation information and group characteristic information from the preset phishing email template library; finally, it extracts the email subject text and content text from the candidate templates, summarizes them into a temporary list and removes duplicates, and finally obtains the preliminary phishing email parameters for employees.
[0036] In summary, the configuration management module first retrieves phishing drill data and security incident records from the enterprise in the recent period to verify the initial target group. If the target group does not meet the criteria, it is re-screened. Then, the initial phishing email parameters are compared with the enterprise's secure email gateway's interception keyword database to verify its historical success rate. If the target group does not meet the criteria, the parameters are replaced. After both the target group and the parameters are verified, the two are associated and stored to finally obtain the phishing email parameters and the target group.
[0037] The phishing email generation and sending module 102 is used to generate personalized simulated phishing emails based on phishing email parameters and send them to the target group. In this embodiment of the invention, when the phishing email generation and sending module generates personalized simulated phishing emails based on phishing email parameters and sends them to the target group, it is specifically used for: Based on the content template in the phishing email parameters and combined with the role characteristics of the target group, a personalized email body is generated. By disguising phishing email parameters and personalized email body as executable files, a simulated attachment of phishing email parameters is obtained. The simulated attachments are obfuscated to obtain personalized phishing emails with simulated attachments; The behavior logic of personalized simulated phishing emails is restricted. When a personalized simulated phishing email is triggered, it is only reported through an encrypted channel and no actual malicious operation is performed. Personalized emails are combined with personalized phishing emails and packaged together, then sent to the corporate email accounts of the target group through an isolated external mail server.
[0038] The phishing email generation and sending module, when performing the execution of disguising the phishing email parameters and personalized email body as an executable file to obtain a simulated attachment of the phishing email parameters, is specifically used for: Based on the characteristics of the bait content in the phishing email parameters, set the file names according to the naming habits of real office documents in the enterprise's organizational structure; The content of the personalized email body is converted into a text data block, and the text data block is embedded into a preset position in the body of the phishing email program; Based on the file structure of filenames and text data blocks, generate simulated executable files with a document visualization appearance; By combining icon resources with simulated executable files, simulated attachments for phishing email parameters can be generated.
[0039] Specifically, the content template is extracted from the parameters of the phishing email, including fixed paragraphs and role-related placeholders to be filled. At the same time, employee role characteristics are extracted from the target group information database. The phishing email generation and sending module accurately matches the role characteristics with the template placeholders to form a personalized email body that fits the role characteristics of the target group.
[0040] The executable file type to be disguised is selected as a commonly used office document format for corporate employees. Key data such as subject keywords and core information are extracted from the parameters of the phishing email. This data is then embedded along with the personalized email body into a pre-built blank office document framework—the personalized email body serves as the core content of the file, and the key data is associated with the file attributes. Next, the file extension is modified using a format conversion tool to ensure consistency with the selected format. The corresponding office software icon from the icon resource library is then used to replace the default icon, making the file appearance consistent with a normal office document. This processed file is the simulated attachment.
[0041] The core code for processing simulated attachments works as follows: First, variable names with clear meanings are replaced with meaningless random characters; then, the order of code statements is adjusted without changing the execution logic; finally, redundant code with no actual function is inserted. This code does not affect the normal use of the attachments, only reducing readability. After processing, a personalized simulated phishing email is obtained.
[0042] The personalized phishing email code is pre-programmed with trigger conditions and incorporates behavior control logic: upon detecting a trigger condition, the code immediately invokes a built-in encryption component, employing a pre-defined symmetric encryption method and encrypting the trigger event information with a fixed internal key. After encryption, the code initiates a dedicated encrypted channel connecting to a pre-defined monitoring server, transmitting only the encrypted trigger information, and this channel is not connected to any external public network. Simultaneously, the code explicitly prohibits operations on a list, blocking operations within the list through code logic to ensure that information is reported only through the encrypted channel.
[0043] The personalized email body serves as the main message, formatted according to email style guidelines for normal reading. A personalized phishing email is added as an attachment to the list, with an attachment notification at the end of the body. The email is then packaged, and the header information, including sender, recipient, subject, and content type, is set according to the SMTP protocol. After packaging, it is sent via a dedicated, isolated external mail server. This server is used solely for transmitting phishing emails and does not process other business emails. Upon receiving the email, the isolated server forwards it sequentially to the target email addresses, avoiding interception of large-scale simultaneous transmissions, ultimately delivering it to the target corporate inbox.
[0044] Specifically, bait content features are extracted from the parameters of phishing emails. These features are core business identifiers that are strongly related to the daily work of the target group. At the same time, the historical office document naming records stored in the company's internal storage are retrieved, and the frequently occurring naming structures in the records are analyzed. The extracted bait content features are then precisely combined according to the analyzed naming structures. For example, if the bait content feature is "sales report", and the company's frequent naming structure is "sales department - document type - monthly", then filenames such as "sales department - sales report - monthly" are generated. This ensures that the generated filenames are completely consistent with the company's actual office document naming habits, resulting in filenames that conform to the company's organizational structure and actual office document naming habits.
[0045] All text content in the personalized email body is processed according to UTF-8 encoding format, converting each character into corresponding binary data. All binary data are concatenated to form a continuous and unbroken text data block. At the same time, the code file of the phishing email program body is opened. In the pre-defined text embedding area of the program body, a dedicated data writing tool is used to write the generated text data block byte by byte into the area, overwriting the original blank placeholder data in the area. During the writing process, the data integrity is verified in real time to ensure that the text data block is completely embedded without destroying the basic operating logic of the phishing email program body. This completes the operation of converting the content of the personalized email body into text data blocks and embedding the text data blocks into the preset position of the phishing email program body.
[0046] Referring to the standard file structure of real office documents used by enterprise employees on a daily basis, this structure includes three core parts: file header, data area, and file footer. The file name, which conforms to the enterprise's naming conventions, is written into the "file name field" of the file header. The phishing email program body, which has been embedded with text data blocks, is used as the core content of the data area and filled in. A CRC check field consistent with the format of real office documents is added to the file footer. Using a file structure assembly tool, the file header, data area, and file footer are sequentially assembled according to the format specifications of real office documents to form a complete file structure. This file is displayed in the operating system with the same appearance as a real office document, resulting in a simulated executable file with a document visual appearance.
[0047] The module retrieves an internal icon resource library for office software, which contains icon files identical to those used in common enterprise office software. Based on the document type simulated by the generated executable file, the corresponding icon file is selected from the library. The executable file's property configuration interface is opened, and the "Icon Resource Index" field is located. An icon embedding tool is used to write the pixel data and color channel information from the selected icon file pixel by pixel into the "Icon Resource Index" field, replacing the original default icon data. After writing, the property configuration interface is closed. The operating system's file preview function is used to check if the icons display correctly. Simultaneously, it is verified that the file maintains its visual appearance and can be opened and previewed normally, ensuring that the merged file conforms to visual perception without affecting basic functionality. Finally, a simulated attachment containing phishing email parameters is generated.
[0048] In general, the phishing email generation and sending module first extracts the content template from the phishing email parameters, then obtains the role characteristics of each employee from the target group information database, and then accurately matches and replaces the role characteristics with the template placeholders. The text content formed after all placeholders have been replaced is the personalized email body.
[0049] The phishing email generation and sending module first generates a filename that conforms to the naming habits of real office documents by combining the characteristics of the bait content in the phishing email parameters with the high-frequency naming structure analyzed from the company's historical office document naming records. Then, it converts the personalized email body into a text data block and embeds it into the preset position of the phishing email program body. Next, it assembles the filename and text data block according to the standard structure of real office documents. Finally, it merges the corresponding office software icon to obtain a simulated attachment of the phishing email parameters.
[0050] The phishing email generation and sending module processes the core code in the simulated attachments, replacing variable names with meaningful combinations of random characters, adjusting the order of code statements without changing the execution logic, and inserting redundant code segments without any actual function. Through these operations, the code readability is reduced, and a personalized simulated phishing email with simulated attachments is finally obtained.
[0051] The phishing email generation and sending module presets trigger conditions and embeds behavior control logic in the personalized phishing email code: when the trigger conditions are met, it calls the built-in encryption component to encrypt the trigger event information and reports it to the monitoring server through a dedicated encrypted channel; at the same time, it explicitly sets a list of malicious operations that are prohibited from being executed, and blocks the operations in the list through code logic to ensure that no actual malicious operations are executed.
[0052] The phishing email generation and sending module formats the personalized email body as a normal email, adds the personalized simulated phishing email as an attachment and supplements the attachment prompt text, and then completes the combination and encapsulation by setting the email header information according to the SMTP protocol. Then, it sends the encapsulated email to an isolated external mail server through a dedicated channel that is physically isolated from the enterprise's internal network. The server then sends the emails sequentially according to the target group's email address list, and finally delivers them to the target group's enterprise email address.
[0053] The phishing email generation and sending module first extracts bait content features related to the daily work of the target group from the phishing email parameters, then retrieves the company's internal historical office document naming records, analyzes the frequently occurring naming structures, and then combines the bait content features according to the naming structure to generate filenames that conform to the company's actual office document naming habits in its organizational structure.
[0054] The phishing email generation and sending module converts all the text in the personalized email body into continuous binary text data blocks according to a specified encoding format. Then, it opens the phishing email program body, finds the pre-marked text embedding area, and uses a special tool to write the text data blocks byte by byte into the area. At the same time, it verifies the data integrity in real time to ensure that it does not damage the main program's operating logic. This completes the operation of converting the personalized email body content into text data blocks and embedding them into the preset position of the phishing email program body.
[0055] The phishing email generation and sending module references the standard structure of commonly used real office documents in enterprises. It fills the corresponding fields in the file header with the previously generated file name that conforms to real naming habits, fills the data area with the phishing email program body with embedded text data blocks as the core content, adds a verification field consistent with the real document to the end of the file, and then uses a tool to concatenate the file header, data area and file footer in sequence according to the real document format specifications to form a file that appears as a normal document in the operating system, resulting in a simulated executable file with a document visual appearance.
[0056] The phishing email generation and sending module selects an office software icon from its internal icon resource library that matches the document type simulated by the executable file. Then, it opens the property configuration interface of the simulated executable file and uses an icon embedding tool to write the pixel data and color information of the selected icon into the icon resource index field of the file, replacing the default icon. After that, it verifies that the file icon displays normally and can still maintain the document's visual appearance and preview function, and finally generates a simulated attachment with phishing email parameters.
[0057] The interaction detection module 103 is used to monitor employees' interaction behavior with personalized simulated phishing emails. When it is detected that an employee triggers a simulated malicious attachment, the module reports the employee's behavior log through an encrypted communication channel. In this embodiment of the invention, when the interaction detection module monitors employee interactions with personalized simulated phishing emails and reports the employee's behavior log through an encrypted communication channel upon detecting that the employee has triggered a simulated malicious attachment, it is specifically used for: Monitor employee terminal interactions with personalized phishing emails, and detect email open events and attachment trigger events; When an attachment trigger event is detected to be targeting a simulated malicious attachment, the simulated malicious attachment is launched after verifying the security of the execution environment. Based on the built-in recording function of the simulated malicious attachment, the employee's identification, operation timestamp, and terminal environment information are fused and detected to obtain the employee's interaction data; Interaction data is encapsulated into structured behavior logs and uploaded in real time via an encrypted communication channel.
[0058] Specifically, the interaction detection module deploys a lightweight monitoring process on the employee's terminal. This process continuously captures file operation behavior and email client operation behavior on the terminal. When it detects that the email client is launched and loads a personalized simulated phishing email, the process determines to generate an email open event by identifying the email identification information in the email client window title and the path of the loaded file. When it detects that the employee performs actions such as right-clicking an email attachment and selecting the "open" option, double-clicking the attachment icon, or clicking the attachment open button in the email preview window, the process captures these mouse operation commands and checks whether the attachment file path and file name corresponding to the operation match the simulated malicious attachment information in the personalized simulated phishing email. If they match, it determines to generate an attachment trigger event, thus completing the monitoring of the employee's terminal's interactive operations with the personalized simulated phishing email, as well as the detection of email open events and attachment trigger events.
[0059] The interactive detection module pre-stores characteristic information of simulated malicious attachments, including the filename, file size, and specific identifier fields in the file header. When an attachment trigger event is detected, the module immediately extracts the filename, file size, and file header identifier fields of the attachment corresponding to the trigger event and compares them one by one with the pre-stored characteristic information of simulated malicious attachments. If all characteristic information is completely consistent, the module identifies that the attachment trigger event is for a simulated malicious attachment. Subsequently, the module initiates the execution environment security verification process. It checks whether the employee terminal is running the enterprise-specified security protection software and whether the real-time monitoring function of the security protection software is enabled. At the same time, it scans all processes currently running on the terminal to check whether there are any unknown processes reading or modifying critical directories of the system. If the security protection software is running normally and there are no abnormal operations by unknown processes, the execution environment is determined to be secure. Then, the module calls the terminal's file execution interface through the monitoring process, loads and runs the simulated malicious attachment according to the normal attachment opening process, and completes the operation of starting the simulated malicious attachment after verifying the security of the execution environment when the attachment trigger event is identified as being for a simulated malicious attachment.
[0060] The built-in logging function of the simulated malicious attachment is automatically activated upon startup. This function first accesses the system account management directory of the employee terminal to extract the currently logged-in employee system account name; then it calls the terminal system's time service interface to obtain the current terminal system time; next, it reads the terminal's system configuration file to collect the terminal's operating system version number, CPU model, and memory capacity, while simultaneously accessing the terminal's network adapter configuration information to obtain the network adapter's MAC address, integrating this information into terminal environment information; the logging function concatenates and integrates the employee's identifier, operation timestamp, and terminal environment information according to a fixed format of "employee identifier - operation timestamp - operating system version number - CPU model - memory capacity - MAC address", checking the completeness of each information field during the integration process to ensure that no information is missing, and the resulting complete information set is the employee's interaction data.
[0061] The interaction detection module first determines the fixed format of the structured behavior log. This format includes four fields: log number, data source identifier, employee interaction data, and log generation time. The module fills the employee's interaction data into the format according to the field correspondence, with each field separated by "|", forming a complete structured text, which is the structured behavior log. The module then activates the built-in encrypted communication component. This component uses a preset symmetric encryption method and a fixed key pre-agreed between the module and the backend monitoring server to encrypt the structured behavior log character by character, generating encrypted data blocks. Simultaneously, the module establishes a dedicated encrypted communication channel based on the TLS protocol with the monitoring server. This channel only allows data transmission between the interaction detection module and the monitoring server. The module sends the encrypted data blocks to the monitoring server in real time through this channel, completing the operation of encapsulating the interaction data into a structured behavior log and uploading it in real time through the encrypted communication channel.
[0062] Specifically, the interactive detection module calls the network configuration query interface of the employee terminal to extract the default gateway IP address and DNS server IP address of the current terminal. At the same time, it retrieves the preset default gateway IP address and DNS server IP address of the enterprise-specific network from the enterprise-specific network configuration library stored within the module. The network parameters actually extracted by the terminal are compared one by one with the preset enterprise-specific network parameters. If the default gateway IP address and DNS server IP address of the terminal are completely consistent with the preset parameters, it is determined that the employee terminal is in the enterprise-specific network environment, and an environment verification result of "environment verification passed" is generated. If any network parameter does not match the preset parameter, it is determined that the employee terminal is not in the enterprise-specific network environment, and an environment verification result of "environment verification failed" is generated.
[0063] The interactive detection module obtains the complete process names of all currently running processes on the employee terminal by calling the system process query interface. It then retrieves preset debugging tool process names and dynamic analysis program process names from the internally stored risk process database. The module precisely matches the actual running process names on the terminal with those in the risk process database. If no process with a name matching the database is found, it is determined that no debugging tool or dynamic analysis program exists, and a "process verification passed" result is generated. Conversely, if any process name matches a process name in the database, it is determined that a debugging tool or dynamic analysis program exists, and a "process verification failed" result is generated.
[0064] The interactive detection module first locates the preset security status identifier path of the enterprise-specified endpoint protection software in the system registry. By calling the system registry read interface, it accesses the "RunningStatus" identifier under that path and reads its value. The enterprise protection software defaults to "1" to represent normal operation and "0" to represent not running or abnormal. If the read "RunningStatus" identifier value is "1", it is determined that the endpoint protection software is in a normal operating state, and a security status check result of "security status check passed" is generated; if the value is "0", it is determined that the endpoint protection software is not running normally, and a security status check result of "security status check failed" is generated.
[0065] The interactive detection module centrally aggregates the generated environment verification results, process verification results, and security status check results into the internal evaluation module. The evaluation module judges according to preset rules: only when the environment verification result is "Environment Verification Passed", the process verification result is "Process Verification Passed", and the security status check result is "Security Status Check Passed", it is determined that the comprehensive security requirements are met, and a comprehensive security assessment conclusion of "Comprehensive Security Assessment Conclusion Qualified" is generated; if any of the three results is "Failed", it is determined that the comprehensive security requirements are not met, and a comprehensive security assessment conclusion of "Comprehensive Security Assessment Conclusion Unqualified" is generated.
[0066] The interactive detection module reads the preset security condition – “Comprehensive security assessment conclusion is qualified” – and compares the generated comprehensive security assessment conclusion with this preset security condition. If the comprehensive security assessment conclusion is “Comprehensive security assessment conclusion is qualified”, it is determined that the preset security condition is met. The module then sends a specific startup command to the built-in function interface of the simulated malicious attachment to activate the program module in the simulated malicious attachment used to record employee interaction information, putting the recording module into running state and completing the operation of starting the recording function of the simulated malicious attachment. If the comprehensive security assessment conclusion is “Comprehensive security assessment conclusion is unqualified”, it is determined that the preset security condition is not met, no startup command is sent, and the recording function of the simulated malicious attachment remains inactive.
[0067] In summary, the interaction detection module deploys a lightweight monitoring process on the employee's terminal. This process tracks file operations and email client operation status in real time. When it detects that the email client is loading a personalized simulated phishing email, it determines to generate an email open event by verifying the email identifier and file path. When it detects that an employee is opening an email attachment and the attachment path and file name match the simulated malicious attachment information, it determines to generate an attachment trigger event. This completes the monitoring of employee terminal interaction operations and the detection of the two events.
[0068] The interactive detection module first extracts the attachment features corresponding to the attachment triggering event and compares them one by one with the pre-stored simulated malicious attachment features. After confirming that it is targeting the simulated malicious attachment, it starts the execution environment security verification—checking whether the terminal is on the enterprise's dedicated network, whether there are no debugging tools or dynamic analysis programs in the process list, and whether the terminal protection software is running normally. After the verification is passed, the terminal file execution interface is called to start the simulated malicious attachment.
[0069] Once the simulated malicious attachment is launched, its built-in logging function will be automatically activated. This function extracts the system account name corresponding to the enterprise employee's identifier from the terminal system account management directory, obtains the current time from the terminal time service interface, and collects the operating system version, CPU model, memory capacity, and MAC address from the system configuration file and network adapter information. Then, it integrates these three types of information in a fixed format to form the employee's interaction data.
[0070] The interaction detection module fills the employee's interaction data into the corresponding fields according to the preset format and concatenates them with delimiters to form a structured behavior log. Then, it starts the built-in encrypted communication component, encrypts the log with the preset symmetric encryption method, and then sends the encrypted behavior log to the backend monitoring server in real time through a dedicated encrypted communication channel based on the TLS protocol, thus completing the encapsulation and uploading of the log.
[0071] The interactive detection module calls the network configuration query interface of the employee terminal to extract the terminal's current default gateway IP address and DNS server IP address, and then compares them one by one with the preset parameters of the enterprise-specific network stored in the module. If the two are completely consistent, it is determined that the terminal is in the enterprise-specific network environment. If there is a discrepancy, it is determined that the terminal is not in the environment. Finally, an environment verification result containing "environment verification passed" or "environment verification failed" is generated.
[0072] The interactive detection module obtains the full names of all currently running processes on the employee terminal by calling the system process query interface. Then, it performs a precise match with the pre-set risk process library within the module. If no matching process is found, it is determined that the relevant tools and programs do not exist. If a matching process is found, it is determined that the process exists. The module then generates a process verification result containing "process verification passed" or "process verification failed".
[0073] The interactive detection module locates the preset security status identifier path of the enterprise-specified endpoint protection software in the system registry. It accesses the "RunningStatus" identifier under this path through the system registry reading interface. If the read value is the preset "normal operation" flag of the protection software, it is determined that the protection software is operating normally. If it is the "not running or abnormal" flag, it is determined that it is not operating normally. This generates a security status check result containing "security status check passed" or "security status check failed".
[0074] The interactive detection module summarizes the environment verification results, process verification results, and security status check results into the internal evaluation module. The evaluation module judges according to preset rules to obtain a comprehensive security evaluation conclusion.
[0075] The preset security condition for the interaction detection module is "comprehensive security assessment conclusion is qualified". The generated comprehensive security assessment conclusion is compared with this condition. If the conclusion is qualified, a start command is sent to the built-in function interface of the simulated malicious attachment to activate its program module for recording employee interaction information. If the conclusion is unqualified, no command is sent, and the recording function of the simulated malicious attachment remains inactive. This completes the relevant operations for starting the recording function of the simulated malicious attachment.
[0076] The instant feedback module 104 is used to trigger the instant feedback mechanism based on behavior logs, pop up an educational pop-up on the employee's terminal, and send anti-phishing knowledge content to the employee's corporate email. In this embodiment of the invention, when the instant feedback module executes the instant feedback mechanism triggered based on behavior logs, pops up an educational pop-up on the employee's terminal, and sends anti-phishing knowledge content to the employee's corporate email, it is specifically used for: Parse the employee identifier and operation type in the behavior log to generate feedback type information; Based on the pre-set anti-phishing knowledge base, the feedback type information is matched and mapped to obtain the employee's educational content. The system locates the corresponding employee's terminal device based on the employee's identification, and then displays an educational pop-up window on the employee's terminal device, showing the educational content. Customized anti-phishing knowledge materials from the anti-phishing knowledge base will be simultaneously sent to the corporate email addresses corresponding to the employee's identification.
[0077] Specifically, the instant feedback module first reads fixed fields from the structured behavior log, extracts the employee system account name corresponding to the "Employee Identifier" field, and then extracts the operation type recorded in the "Employee Interaction Data" field. The module internally pre-defines the correspondence between operation types and feedback types. For example, "double-click to open a simulated malicious attachment" corresponds to "attachment-triggered feedback," and "clicking a link within an attachment triggers a simulated malicious operation" corresponds to "link-triggered feedback." The extracted operation type is compared with this rule to determine the corresponding feedback type. Finally, the employee identifier and feedback type are integrated into text information containing "Employee Account Name - Feedback Type," which is the feedback type information.
[0078] The pre-built anti-phishing knowledge base stores educational content templates categorized by feedback type. Each template is labeled with its corresponding feedback type and contains anti-phishing knowledge related to the operation type. A placeholder for "[Employee Name]" is also provided. The instant feedback module retrieves the real name of the corresponding employee from the company's employee information database based on the employee identifier in the feedback type information. It then extracts an educational content template from the knowledge base that matches the feedback type label in the feedback type information. The retrieved employee's real name is filled into the "[Employee Name]" placeholder in the template. The resulting text, containing the employee's unique identifier and targeted knowledge content, constitutes the employee's educational content.
[0079] The instant feedback module accesses the enterprise device management database, which stores records linking employee identifiers to terminal device information. The module precisely matches the employee identifier in the feedback type information with the employee's system account name in the database to find the corresponding terminal IP address and unique device number, thus identifying the employee's terminal device requiring the pop-up. The module establishes a TCP connection with this terminal device via the enterprise's internal LAN and sends a pop-up command containing the educational content and pop-up display parameters. Upon receiving the command, the terminal device invokes the system desktop pop-up program, displays the pop-up according to the command parameters, and loads the educational content, completing the operation of displaying the educational pop-up and content on the employee's terminal device.
[0080] The anti-phishing knowledge base also stores customized anti-phishing knowledge materials corresponding to different feedback types, with each material clearly labeled with its corresponding feedback type. The instant feedback module extracts the corresponding customized anti-phishing knowledge materials from the knowledge base based on the feedback type information, and then retrieves the corresponding employee's corporate email address from the company's employee information database based on the employee's identifier. The module calls the built-in email sending component, sets the email subject to "Anti-phishing Security Tips - [Employee Name]", and the email body to "Hello! Based on your recent email activity, we have attached anti-phishing knowledge materials for your review and study." The extracted customized anti-phishing knowledge materials are added as an email attachment, and then the email is sent to the retrieved employee's corporate email address via the company's internal email transmission channel, completing the operation of simultaneously sending the customized anti-phishing knowledge materials to the employee's corporate email address.
[0081] In general, the instant feedback module first reads fixed fields from the behavior log, extracts the employee system account name corresponding to the "employee identifier" and the operation type recorded in the "employee interaction data", and then integrates the employee identifier with the matched feedback type according to the preset "operation type - feedback type" correspondence rules in the module to generate feedback type information containing "employee account name - feedback type".
[0082] The pre-set anti-phishing knowledge base stores educational content templates categorized by feedback type. The instant feedback module first extracts the matching template from the knowledge base based on the feedback type information, and then retrieves the corresponding employee's real name from the enterprise employee information database through the employee identifier, fills it into the "[Employee Name]" placeholder in the template, and the resulting text containing the employee's exclusive identifier and targeted knowledge is the employee's educational content.
[0083] The instant feedback module accesses the enterprise device management database that stores the association records of "employee ID - terminal device information". It precisely matches the employee ID in the feedback type information with the employee system account name in the database to find the IP address and device number of the corresponding terminal and determine the target employee terminal device. Then, it establishes a connection with the terminal through the enterprise LAN and sends a pop-up command containing educational content and pop-up display rules. After receiving the command, the terminal calls the system pop-up program, pops up the educational pop-up according to the rules, and loads and displays the educational content.
[0084] The anti-phishing knowledge base also contains customized anti-phishing knowledge materials corresponding to the feedback type. The instant feedback module extracts matching materials based on the feedback type information, and then retrieves the corresponding corporate email address from the employee information database through the employee identifier. Subsequently, it calls the email sending component, sets the email subject and body, adds the knowledge materials as attachments, and sends the email to the employee's corporate email address through the internal corporate email channel, completing the synchronous sending of customized knowledge materials.
[0085] Data statistics and analysis module 105 is used to statistically analyze behavior logs and generate statistical data and training reports; In this embodiment of the invention, when the statistics and analysis module executes statistical analysis behavior logs and generates statistical data and training reports, it is specifically used for: Parse the employee department information, operation timestamps, and operation types in the behavior logs to generate statistical data from the behavior logs; Based on statistical data, the trigger rate of personalized simulated phishing emails is calculated by department, and departmental security level indicators are generated from behavioral logs. Time series analysis of operation timestamps reveals high-risk periods in the behavior logs; Integrate departmental safety level indicators, characteristics of high-risk periods, and key training content to generate a training report that includes improvement suggestions.
[0086] Specifically, the statistics and analysis module first reads the structured fields of the behavior log, extracting the employee identifier, operation timestamp, and operation type fields. Then, it accesses the enterprise organizational structure database, matching the employee identifier with the associated records of "employee identifier - department name" in the database to obtain the department information of the corresponding employee. Subsequently, the time information in the operation timestamp field is converted into a standard format containing year, month, day, and specific time period. The content in the operation type field is categorized and labeled according to "triggered by double-clicking attachment," "triggered by clicking link," and "triggered by filling in form." Finally, the employee department information, the categorized operation types, and the standard format operation timestamps are integrated into tabular data in the format of "department name - operation type - operation time - employee identifier." This tabular data is the statistical data of the behavior log.
[0087] The statistics and analysis module filters employee records marked as "triggered personalized simulated phishing emails" from the statistical data of the behavior logs, and counts the number of employees in each department that triggered the phishing emails. At the same time, it accesses the enterprise organizational structure database to obtain the current total number of employees in each department. For each department, it divides the number of employees who triggered the phishing emails in that department by the total number of employees in that department to obtain the trigger rate of personalized simulated phishing emails in that department. According to the preset trigger rate classification standard, it matches the trigger rate of each department with a corresponding risk level, forming an indicator list containing "department name-trigger rate-risk level". This list is the department security level indicator of the behavior logs.
[0088] The statistics and analysis module groups all operation timestamps in the behavior log statistics by "daily time period", counts the personalized simulated phishing email trigger records in each time period, and obtains the trigger count for each time period. The trigger counts of each time period are compared, and the 1-2 time periods with the most trigger counts are selected. For example, if the trigger count of the "afternoon before leaving get off work" time period is much higher than that of other time periods, then the time period is determined to be a high-risk time period. The finally determined time period is the high-risk time period of the behavior log.
[0089] The statistics and analysis module first retrieves key training content corresponding to the department's security level indicators from the anti-phishing knowledge base; then, it determines training time recommendations based on the characteristics of high-risk periods; subsequently, it integrates the department's security level indicators, characteristics of high-risk periods, and key training content, and proposes improvements for weak departments, such as "conducting one special training session per week" and "regularly sending anti-phishing case studies," and for high-risk periods, it proposes improvements such as "pop-up security reminders during those periods"; finally, it formats the report into a document format, following the structure of "department security status - high-risk period analysis - training focus - improvement suggestions," which is the training report containing improvement suggestions.
[0090] In summary, the statistics and analysis module first reads the structured fields of the behavior log, extracts the employee identifier, operation timestamp, and operation type, and then associates the employee identifier with the enterprise organizational structure database to obtain the corresponding employee's department information. Next, it converts the operation timestamp into a standard format containing year, month, day, and specific time period, classifies and labels the operation types according to preset categories, and finally integrates the employee department information, the classified operation types, and the standard format operation timestamps into tabular data in a fixed format. This tabular data is the statistical data of the behavior log.
[0091] The statistics and analysis module filters employee records that triggered personalized simulated phishing emails from the statistical data of the behavior logs, and counts the number of triggered employees in each department. At the same time, it obtains the total number of employees in each department from the enterprise organizational structure database, and divides the number of triggered employees in each department by the total number of employees in the department to obtain the trigger rate. Then, it matches the trigger rate of each department with a risk level according to the preset trigger rate classification standard, forming an indicator list containing "department name-trigger rate-risk level". This list is the department security level indicator of the behavior logs.
[0092] The statistics and analysis module groups all operation timestamps in the behavior log statistics into daily time periods such as "early morning work session, mid-morning work session, after lunch break, mid-afternoon work session, and before leaving get off work in the afternoon". It counts the personalized simulated phishing email trigger records within each time period to obtain the trigger count for each time period. By comparing the trigger counts for each time period, the time period with the most trigger counts is selected, and this time period is the high-risk time period of the behavior log.
[0093] The statistics and analysis module retrieves key training content corresponding to the department's safety level indicators from the anti-phishing knowledge base; it determines training time suggestions based on the characteristics of high-risk periods; it then integrates the department's safety level indicators, the characteristics of high-risk periods, and the key training content to supplement improvement suggestions for weak departments and high-risk periods, and formats the results into a document with a fixed structure. This document is the training report containing improvement suggestions.
[0094] The targeted strategy generation module 106 is used to identify high-risk groups and weak links and develop targeted training strategies based on statistical data and training reports.
[0095] In this embodiment of the invention, when the targeted strategy generation module identifies high-risk groups and weak points and formulates targeted training strategies based on statistical data and training reports, it is specifically used for: Analyze the frequency and type distribution of employee interaction behaviors in statistical data to identify high-risk behavioral patterns that deviate from the normal safety baseline; Based on high-risk behavior patterns and the departmental attributes of the target group, high-risk groups with common risk characteristics are clustered. Identify the key triggers for high-risk groups in specific phishing email topics and content, and determine the knowledge gaps of high-risk groups. Based on the knowledge gaps, matching training materials are extracted from the anti-phishing knowledge base and combined into targeted training courses for high-risk groups. Based on the targeted training courses and the work characteristics and risk levels of high-risk groups, differentiated training intensity and assessment standards are set to generate targeted training strategies for enterprises.
[0096] Specifically, the targeted strategy generation module extracts the number of times each employee's personalized simulated phishing emails are triggered from the statistical data of the behavior logs. At the same time, it categorizes each employee's operation type according to "double-clicking attachment trigger," "clicking link trigger," and "filling out form trigger." Then, it retrieves the company's preset normal security baseline—which is the average frequency of employee interaction behavior and the average proportion of each operation type in the company's historical anti-phishing drills. It compares each employee's interaction behavior frequency with the average frequency in the baseline. If the number of employee triggers is higher than the average frequency, it is marked as "high-frequency interaction." Then, combined with the distribution of operation types, if employees with "high-frequency interaction" mainly exhibit "double-clicking attachment trigger" or "clicking link trigger," the combination of "high-frequency interaction + specific operation type" is defined as a pattern that deviates from the normal security baseline. This pattern is a high-risk behavior pattern.
[0097] The targeted strategy generation module first filters out all employees who meet the high-risk behavior pattern. It then retrieves the department attributes of these employees from the enterprise organizational structure database and groups the eligible employees by department name. For each department group, it counts the number of employees in that department who meet the high-risk behavior pattern. If the proportion of such employees in a department is higher than that in other departments, and the high-risk behavior pattern types of the employees in that department are consistent, then the eligible employees in that department are grouped into the same group. This process is repeated to classify employees in different departments who meet the high-risk behavior pattern and whose pattern types are consistent. The final set of employees is the high-risk group with common risk characteristics.
[0098] The targeted strategy generation module filters out the email subject and content keywords corresponding to the personalized simulated phishing emails triggered by high-risk groups from the statistical data of behavior logs. It performs frequency statistics on these subjects and keywords to identify the 1-2 email subjects and corresponding content keywords that high-risk groups trigger most frequently. If high-risk groups concentrate on triggering emails with a certain type of subject or keyword, it is determined that the recognition ability for that type of subject and keyword is insufficient. The area of insufficient recognition ability is the knowledge weakness of high-risk groups.
[0099] The targeted strategy generation module retrieves training materials matching the knowledge gaps from the anti-phishing knowledge base. For example, if the knowledge gap is "insufficient identification of attachments in financial emails," it retrieves relevant materials from the knowledge base such as "characteristics of disguised attachments in financial scenarios" and "verification methods for phishing email attachments in reimbursement-related emails." If the knowledge gap is "triggering of links in meeting-related emails," it retrieves relevant materials such as "techniques for identifying phishing links in meeting notifications" and "quick steps to verify link security." The retrieved training materials are arranged in a logical order of "theoretical explanation - case analysis - practical demonstration" to ensure that the content revolves around the knowledge gaps, forming a complete course content system. This system is the targeted training course for high-risk groups.
[0100] The targeted strategy generation module first analyzes the work characteristics of high-risk groups. For example, if the high-risk group consists of finance department employees whose work characteristics include "handling a large number of attachments daily and concentrated work hours," then the training intensity is set to "short class hours + high frequency." If the high-risk group consists of administrative department employees whose work characteristics include "handling diverse types of emails and flexible time," then the training intensity is set to "long class hours + low frequency." Next, based on the risk level of the high-risk group, assessment standards are set. For groups with high risk levels, the assessment includes "simulated email recognition test + practical verification," while for groups with low risk levels, the assessment only requires "simulated email recognition test." Finally, the targeted training courses, the set training intensity, and the assessment standards are integrated and documented according to the structure of "high-risk group name - training course content - training intensity - assessment standards." This document constitutes the company's targeted training strategy.
[0101] In summary, the targeted strategy generation module extracts the number of times each employee triggers a personalized simulated phishing email from statistical data, categorizes employee behavior by operation type, and then compares this data with the company's preset normal security baseline. If the number of employee triggers is higher than the average frequency and is concentrated in a specific operation type, this combination of "high-frequency interaction + specific operation type" is defined as a high-risk behavior pattern that deviates from the baseline.
[0102] The targeted strategy generation module first filters out employees who meet the high-risk behavior patterns, obtains the department attributes of these employees through the enterprise organizational structure database, then groups the employees who meet the criteria by department, counts the percentage of employees who meet the pattern in each group, and groups the employees of departments with a high percentage and consistent behavior patterns into the same group, ultimately forming a high-risk group with common risk characteristics.
[0103] The targeted strategy generation module will filter out the email topics and content keywords that high-risk groups trigger emails from statistical data, perform frequency statistics on these topics and keywords, and find the email topics and corresponding keywords that are triggered most frequently. If high-risk groups concentrate on triggering emails with these topics or keywords, it will determine that this area is a weak knowledge link with insufficient identification capabilities.
[0104] The targeted strategy generation module retrieves matching training materials from the anti-phishing knowledge base based on knowledge gaps, and then arranges these materials in a logical order of "theoretical explanation - case analysis - practical demonstration" to form a complete course content system centered around the weak points, which is a targeted training course for high-risk groups.
[0105] The targeted strategy generation module first analyzes the work characteristics of high-risk groups and sets the training intensity accordingly; then, it sets corresponding assessment standards based on the risk level of high-risk groups; finally, it integrates targeted training courses, training intensity, and assessment standards to form a structured document, namely the company's targeted training strategy.
[0106] To help those skilled in the art understand the technical solution of this invention, the following example illustrates the implementation process of this invention: (Using anti-phishing training for new employees of a company as an example) System Configuration: In the configuration management module, the administrator sets the following: the sender is disguised as "HR Department hr_notice@external-hr.com", the email subject is "[New Employee Onboarding Supplement] Please check the attachment", and the body description is "Hello, to complete the onboarding process, please download the attachment, fill it out, and reply. The deadline is 18:00 today"; the target group is new employees who have joined within the last 30 days; the sending time is randomly selected every Wednesday at 10:00; the simulated attachment file name is "Onboarding Registration Form_202405.docx.exe", and advanced code mutation is enabled.
[0107] Email sending: After the set time, the system sends an email from an external IP pool (such as 210.xx.xx.xx, a non-enterprise intranet IP range). The attachment is a .exe file disguised as a Word icon. This file simulates antivirus evasion by inserting random comment code and dynamic string encryption, which can bypass the basic static antivirus scan of enterprise terminals.
[0108] Employee interaction behavior monitoring: After receiving the email, new employee Zhang failed to notice that the sender's domain was not the company's official domain (the company's official domain is @company.com) and double-clicked to open the attachment. Upon opening the attachment, the system detected it as an intranet terminal (IP segment 192.168.xx.xx) and immediately sent a log to the system backend (Employee ID: zhangxx, Time: 2024-05-22 10:15:30), then automatically logged out.
[0109] Instant Feedback: Ten seconds later, an educational pop-up appeared on Zhang's computer, displaying the message, "You just opened a simulated corporate anti-phishing training email!" It pointed out suspicious details: "The sender's domain, external-hr.com, is not the company's official domain; the attachment's extension is actually .exe (an executable program), but it's disguised as a Word icon." The message also provided the correct procedures: "1. Do not open suspicious attachments; 2. Contact the Human Resources Department via WeChat to verify; 3. Click the email report button to mark the phishing email." Simultaneously, Zhang received a similar educational email in his corporate email account.
[0110] Data statistics: At the end of the month, the system generated a report showing that the misclick rate of new employees this month was 15%, among which the "human resources" themed emails had the highest success rate of deception (22%). Based on this, the administrator arranged special training for new employees on "identifying fake HR emails".
[0111] Reference Figure 2 The diagram shown is a flowchart illustrating a method for training enterprise employees on anti-phishing email awareness, according to an embodiment of the present invention. In this embodiment, the method includes: S1. Configure phishing email parameters and target groups; S2. Generate a personalized simulated phishing email based on the phishing email parameters and send it to the target group; S3. Monitor employee interaction with personalized simulated phishing emails. When an employee triggers a simulated malicious attachment, report the employee's behavior log through an encrypted communication channel. S4. Trigger an instant feedback mechanism based on behavior logs, pop up an educational pop-up on the employee's terminal, and send anti-phishing knowledge content to the employee's corporate email. S5. Statistical analysis of behavior logs to generate statistical data and training reports; S6. Based on statistical data and training reports, identify high-risk groups and weak links, and develop targeted training strategies.
[0112] It will be apparent to those skilled in the art that the present invention is not limited to the details of the exemplary embodiments described above, and that the present invention can be implemented in other specific forms without departing from the spirit or essential characteristics of the present invention.
[0113] The embodiments of this application can acquire and process relevant data based on artificial intelligence technology. Artificial intelligence is the theory, method, technology, and application system that uses digital computers or machines controlled by digital computers to simulate, extend, and expand human intelligence, perceive the environment, acquire knowledge, and use that knowledge to obtain optimal results.
[0114] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention.
Claims
1. A training system for enterprise employees on anti-phishing email awareness, characterized in that, The system includes a configuration management module, a phishing email generation and sending module, an interaction detection module, an instant feedback module, a data statistics and analysis module, and a targeted strategy generation module, wherein: The configuration management module is used to configure phishing email parameters and target groups; The phishing email generation and sending module is used to generate personalized simulated phishing emails based on the phishing email parameters and send them to the target group; The interaction detection module is used to monitor employees' interaction behavior with the personalized simulated phishing emails. When it is detected that an employee triggers a simulated malicious attachment, the module reports the employee's behavior log through an encrypted communication channel. The instant feedback module is used to trigger an instant feedback mechanism based on the behavior log, pop up an educational pop-up on the employee's terminal, and send anti-phishing knowledge content to the employee's corporate email. The data statistics and analysis module is used to statistically analyze the behavior logs and generate statistical data and training reports; and The targeted strategy generation module is used to identify high-risk groups and weak links and formulate targeted training strategies based on the statistical data and training reports.
2. The enterprise employee anti-phishing email awareness training system as described in claim 1, characterized in that, When configuring phishing email parameters and target groups, the configuration management module is specifically used for: Obtain employee department distribution information and permission information from the enterprise's organizational structure data package; Based on the departmental distribution information and permission information, an initial target group vulnerable to phishing attacks is identified; Based on the preset phishing email template library, the email subject parameters and content parameters related to the initial target group are filtered to obtain the initial phishing email parameters for employees. The initial target group and preliminary phishing email parameters were analyzed and verified to obtain the phishing email parameters and target group.
3. The enterprise employee anti-phishing email awareness training system as described in claim 1, characterized in that, The phishing email generation and sending module, when executing the process of generating personalized simulated phishing emails based on phishing email parameters and sending them to the target group, is specifically used for: Based on the content template in the phishing email parameters and combined with the role characteristics of the target group, a personalized email body is generated. By disguising phishing email parameters and personalized email body as executable files, a simulated attachment of phishing email parameters is obtained. The simulated attachments are obfuscated to obtain personalized phishing emails with simulated attachments; The behavior logic of personalized simulated phishing emails is restricted. When a personalized simulated phishing email is triggered, it is only reported through an encrypted channel and no actual malicious operation is performed. Personalized emails are combined with personalized phishing emails and packaged together, then sent to the corporate email accounts of the target group through an isolated external mail server.
4. The enterprise employee anti-phishing email awareness training system as described in claim 3, characterized in that, The phishing email generation and sending module, when performing the execution of disguising the phishing email parameters and personalized email body as an executable file to obtain a simulated attachment of the phishing email parameters, is specifically used for: Based on the characteristics of the bait content in the phishing email parameters, set the file names according to the naming habits of real office documents in the enterprise's organizational structure; The content of the personalized email body is converted into a text data block, and the text data block is embedded into a preset position in the body of the phishing email program; Based on the file structure of filenames and text data blocks, generate simulated executable files with a document visualization appearance; By combining icon resources with simulated executable files, simulated attachments for phishing email parameters can be generated.
5. The enterprise employee anti-phishing email awareness training system as described in claim 1, characterized in that, The interaction detection module, when monitoring employee interactions with personalized simulated phishing emails, and when it detects that an employee has triggered a simulated malicious attachment, reports the employee's behavior log through an encrypted communication channel. Specifically, it is used for: Monitor employee terminal interactions with personalized phishing emails, and detect email open events and attachment trigger events; When an attachment trigger event is detected to be targeting a simulated malicious attachment, the simulated malicious attachment is launched after verifying the security of the execution environment. Based on the built-in recording function of the simulated malicious attachment, the employee's identification, operation timestamp, and terminal environment information are fused and detected to obtain the employee's interaction data; Interaction data is encapsulated into structured behavior logs and uploaded in real time via an encrypted communication channel.
6. The enterprise employee anti-phishing email awareness training system as described in claim 5, characterized in that, When the interactive detection module detects an attachment triggering event targeting a simulated malicious attachment and verifies the security of the execution environment before launching the simulated malicious attachment, it is specifically used for: Perform an environment detection operation to confirm that the employee terminal is within the enterprise's dedicated network environment and generate an environment verification result; Verify the process list on the employee terminal to confirm that there are no debugging tools or dynamic analysis programs. Check the system security status identifier to confirm that the endpoint protection software is in normal operating condition; The results of environmental verification, process verification, and security status checks are combined to generate a comprehensive security assessment conclusion. When the comprehensive security assessment results meet the preset security conditions, the function of recording simulated malicious attachments will be activated.
7. The enterprise employee anti-phishing email awareness training system as described in claim 1, characterized in that, When the instant feedback module executes the instant feedback mechanism triggered based on behavior logs, pops up an educational pop-up on the employee's terminal, and sends anti-phishing knowledge content to the employee's corporate email, it is specifically used for: Parse the employee identifier and operation type in the behavior log to generate feedback type information; Based on the pre-set anti-phishing knowledge base, the feedback type information is matched and mapped to obtain the employee's educational content. The system locates the corresponding employee's terminal device based on the employee's identification, and then displays an educational pop-up window on the employee's terminal device, showing the educational content. Customized anti-phishing knowledge materials from the anti-phishing knowledge base will be simultaneously sent to the corporate email addresses corresponding to the employee's identification.
8. The enterprise employee anti-phishing email awareness training system as described in claim 1, characterized in that, When executing statistical analysis behavior logs and generating statistical data and training reports, the statistics and analysis module is specifically used for: Parse the employee department information, operation timestamps, and operation types in the behavior logs to generate statistical data from the behavior logs; Based on statistical data, the trigger rate of personalized simulated phishing emails is calculated by department, and departmental security level indicators are generated from behavioral logs. Time series analysis of operation timestamps reveals high-risk periods in the behavior logs; Integrate departmental safety level indicators, characteristics of high-risk periods, and key training content to generate a training report that includes improvement suggestions.
9. The enterprise employee anti-phishing email awareness training system as described in claim 1, characterized in that, The targeted strategy generation module, when performing the task of identifying high-risk groups and weak points based on statistical data and training reports, and formulating targeted training strategies, is specifically used for: Analyze the frequency and type distribution of employee interaction behaviors in statistical data to identify high-risk behavioral patterns that deviate from the normal safety baseline; Based on high-risk behavior patterns and the departmental attributes of the target group, high-risk groups with common risk characteristics are clustered. Identify the key triggers for high-risk groups in specific phishing email topics and content, and determine the knowledge gaps of high-risk groups. Based on the knowledge gaps, matching training materials are extracted from the anti-phishing knowledge base and combined into targeted training courses for high-risk groups. Based on the targeted training courses and the work characteristics and risk levels of high-risk groups, differentiated training intensity and assessment standards are set to generate targeted training strategies for enterprises.
10. A method for training enterprise employees on anti-phishing email awareness, characterized in that, The method includes: S1. Configure phishing email parameters and target groups; S2. Generate a personalized simulated phishing email based on the phishing email parameters and send it to the target group; S3. Monitor employee interaction with personalized simulated phishing emails. When an employee triggers a simulated malicious attachment, report the employee's behavior log through an encrypted communication channel. S4. Trigger an instant feedback mechanism based on behavior logs, pop up an educational pop-up on the employee's terminal, and send anti-phishing knowledge content to the employee's corporate email. S5. Statistical analysis of behavior logs to generate statistical data and training reports; S6. Based on statistical data and training reports, identify high-risk groups and weak links, and develop targeted training strategies.