Bot IP Detection in Simulated Phishing Campaigns
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Simulated phishing attacks often result in incorrect user statistics due to automated 'robo-clicks' from non-human security appliances, which can lead to inaccurate identification of user vulnerabilities and inappropriate training measures.
Innovation Solution
A system and method that automatically identifies IP addresses associated with bot activities rather than human interactions, allowing for the exclusion of such events from user statistics and providing a user interface for administrators to classify and manage suspect IP addresses.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If automated link following is implemented to improve security analysis efficiency, then security appliance performance is improved, but user statistics accuracy deteriorates due to robo-clicks being misattributed to human users
Solution Approach 1:
The patent introduces an intermediary mechanism (bot detection system) that sits between the automated link following process and the user statistics collection. This intermediary detects and identifies bot-generated clicks, separating them from human user interactions before statistics are compiled, thereby maintaining both automated analysis efficiency and statistical accuracy
Solution Approach 2:
The patent segments user interactions into distinct categories: human-generated clicks and bot-generated clicks. By dividing the overall click stream into these separate segments and tracking them independently, the system can maintain high productivity from automated following while ensuring only human interactions are counted in user statistics
2Measurement precision
If bot detection and filtering is implemented to improve user statistics accuracy, then measurement precision is improved, but system complexity increases due to additional detection mechanisms
Solution Approach 1:
The patent implements feedback mechanisms where bot detection results are fed back into the statistics collection process. The system continuously monitors click patterns, identifies bot behavior through analysis feedback, and adjusts filtering accordingly, improving accuracy without requiring overly complex predetermined filtering rules
Solution Approach 2:
The bot detection system operates autonomously, self-identifying bot-generated clicks through pattern recognition and automated analysis. This self-service capability reduces the need for manual configuration and complex external detection mechanisms, achieving accurate filtering with relatively simple system architecture
Data Source
AI summary
Methods, systems and apparatus are provided which allow a server of a security awareness system to associate IP addresses with events representing user interactions with simulated phishing campaigns. The server receives a plurality of events related to one or more simulated phishing campaigns for a plurality of accounts. The server determines if an IP address of the plurality of IP addresses is associated with one or more events for multiple accounts of the plurality of accounts. Based upon this determination, the server provides identification of the IP address as suspected as having the one or more events associated with it not originating from any user of the multiple accounts. The server receives an indication of whether the IP address is validated as having the one or more events originating from a bot instead of a user of one of the multiple accounts.


