Adaptive Simulated Phishing for Cross-Channel Security Training

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The increasing number of electronic communications, particularly unsecure and malicious ones, poses a significant challenge in confirming their veracity in time to prevent unauthorized actions that jeopardize user information and device security, as existing technologies lack proactive and predictive cross-channel security measures.

Innovation Solution

A system and method for dynamically constructing and targeting adaptive simulated malicious electronic communications across various channels and media to train users in identifying unsecure communications, while escalating authentication requirements in real-time based on user actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional static security measures are used, then implementation is simple, but they cannot proactively identify malicious communications in real-time across multiple channels

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements dynamic simulated phishing campaigns that adapt in real-time based on user interactions and risk assessments. The simulation parameters, targeting criteria, and authentication requirements dynamically adjust according to detected user behavior patterns and risk levels, transforming static security into a responsive, adaptive system that evolves with threats

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary risk assessments and constructs simulated malicious communications before actual threats materialize. By proactively deploying simulated phishing scenarios across multiple channels and evaluating user responses in advance, the system prepares defensive measures and adjusts authentication requirements before real attacks occur

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If simulated malicious communications are sent across multiple channels, then user training effectiveness improves, but the quantity of communications and system operations increases

Engineering Contradiction:
Improveuser identification accuracyVSAvoidsystem operation efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The system applies differentiated simulation strategies to different communication channels and user groups. Each channel (email, SMS, social media) receives customized simulated communications tailored to its characteristics, and users receive targeted simulations based on their risk profiles and interaction patterns, optimizing training effectiveness while reducing redundant operations

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system continuously monitors user responses to simulated communications and uses this feedback to refine future simulations. By analyzing interaction data, success rates, and behavioral patterns, the system adjusts simulation parameters and targeting criteria to improve measurement precision while optimizing system efficiency through learned patterns

Inventive Principle:
Principle #23Feedback

3Reliability

If authentication requirements are escalated in real-time, then security response to detected threats improves, but processing time and computational resources increase

Engineering Contradiction:
Improvesecurity response effectivenessVSAvoidauthentication processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-establishes authentication escalation protocols and risk thresholds before threats occur. Authentication requirements are predetermined based on simulated communication outcomes, allowing the system to quickly enforce appropriate security measures without real-time computational delays when actual threats are detected

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts authentication parameters based on risk levels detected through simulated communications. By changing authentication requirements (such as adding verification steps or tightening credentials) based on simulated user responses and risk assessments, the system achieves adaptive security without requiring complex real-time processing during actual authentication events

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10771485B2Systems and methods for cross-channel electronic communication security with dynamic targeting
Publication Date: 2020.09.08 BANK OF AMERICA CORP
  • US10771485B2 patent drawing
  • US10771485B2 patent drawing
  • US10771485B2 patent drawing

AI summary

Embodiments of the invention are directed to a system, method, or computer program product for cross-channel electronic communication security. In this regard, the invention provides dynamic construction and targeting of adaptive simulated malicious electronic communications for unsecure communication identification by a user. The invention configures adaptive simulated malicious electronic communications for interacting with users via user interfaces of the multiple electronic communication media and user devices. Another aspect of the invention is directed to configuring, dynamically and in real time, a simulated malicious electronic communication for one electronic communication medium, based on and in response to, user actions on another simulated malicious electronic communication on another electronic communication medium. Another aspect of the invention is directed to escalating, in real-time, a level of authentication required for the user to execute the user activity based on user actions performed on the simulated malicious electronic communications.