Adaptive Phishing Simulation System Using AI-Driven Template Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security awareness systems struggle to effectively train users to detect sophisticated and personalized phishing attacks, as they lack the ability to create a simulated phishing environment that mimics real-world attacks.

Innovation Solution

A security awareness system configured to send multiple simulated phishing emails, text messages, and voice calls, using machine learning algorithms and artificial intelligence to adapt the campaign design based on user responses, and to record and analyze user actions for reporting and training purposes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security awareness system sends simulated phishing attacks to train users, then user security awareness is improved, but the system complexity increases due to the need to adapt to different user behaviors and attack scenarios

Engineering Contradiction:
Improveuser security awarenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments phishing attack templates into multiple components (header, body, footer, attachments, links) that can be independently selected and combined. This modular structure allows the system to handle complexity through organized composition rather than monolithic design, enabling adaptive phishing simulation while maintaining manageable system architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system creates universal phishing templates that can be applied across multiple users and scenarios. A single template structure serves multiple purposes by dynamically inserting user-specific information (names, job titles, departments) and attack-specific parameters, allowing one template to function as many specialized templates without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If the system creates individualized simulated phishing attacks for each user, then training effectiveness is improved, but the time required to generate and send attacks increases

Engineering Contradiction:
Improvetraining effectivenessVSAvoidattack generation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-defining phishing attack templates with all possible variations and configurations stored in a database. User profiles with relevant attributes (name, title, department, role) are also prepared in advance. When a phishing simulation is initiated, the system rapidly assembles individualized attacks by selecting and combining pre-prepared components, dramatically reducing generation time compared to creating attacks from scratch for each user.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses copying by creating user-specific phishing instances through template instantiation. Instead of manually crafting unique phishing attacks for each user, the system copies a master template structure and populates it with user-specific data from profiles and attack parameters, enabling rapid generation of individualized simulations through automated text substitution and component assembly.

Inventive Principle:
Principle #26Copying

3Reliability

If the system uses sophisticated phishing templates with multiple actions and conditions, then the realism of simulated attacks is improved, but the difficulty of creating and managing templates increases

Engineering Contradiction:
Improveattack realismVSAvoidtemplate creation ease
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The system segments sophisticated phishing templates into discrete, manageable components (headers, bodies, footers, attachments, hyperlinks) with clearly defined functions. Each component can be independently configured and validated. This segmentation allows security analysts to create complex realistic phishing simulations by assembling standardized building blocks rather than managing monolithic template structures, reducing creation and management difficulty.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary layer between template design and execution through a structured database schema and configuration interface. This intermediary translates complex phishing attack designs into standardized data structures, managing the complexity of sophisticated templates through automated data validation, relationship management, and parameter mapping, thereby easing template creation and management for security analysts.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Measurement precision

If the system tracks and analyzes all user responses to phishing attacks, then security vulnerability detection is improved, but the amount of data to be processed and stored increases

Engineering Contradiction:
Improvevulnerability detection precisionVSAvoiddata volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system extracts and isolates only the most critical response data from user interactions with phishing simulations. Rather than storing and processing all possible data points, the system identifies and extracts key metrics (click decisions, attachment openings, form submissions, response time) that directly indicate security vulnerabilities. This selective extraction reduces data volume while maintaining high precision in vulnerability detection by focusing on discriminative features.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12212596B2Systems and methods for an artificial intelligence driven smart template
Publication Date: 2025.01.28 KNOWBE4 INC
  • US12212596B2 patent drawing
  • US12212596B2 patent drawing
  • US12212596B2 patent drawing

AI summary

The present disclosure describes systems and methods for determining a subsequent action of a simulated phishing campaign. A campaign controller identifies a starting action for a simulated phishing campaign directed to a user of a plurality of users. The simulated phishing campaign includes a plurality of actions, one or more of the plurality of actions to be determined during execution of the simulated phishing campaign The campaign controller responsive to the starting action, communicates a simulated phishing communication to one or more devices of a user. The campaign controller determines a subsequent action of the plurality of actions of the simulated phishing campaign based at least on one of a response to the simulated phishing communication received by the campaign controller or a lack of response within a predetermined time period and initiating, responsive to the determination, the subsequent action of the simulated phishing campaign.