Bot IP Detection in Simulated Phishing Campaigns

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Simulated phishing attacks often result in incorrect user statistics due to automated 'robo-clicks' from non-human security appliances, which can lead to inaccurate identification of user vulnerabilities and inappropriate training measures.

Innovation Solution

A system and method that automatically identifies IP addresses associated with bot activities rather than human interactions, allowing for the exclusion of such events from user statistics and providing a user interface for administrators to classify and manage suspect IP addresses.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated link following is implemented to improve security analysis efficiency, then security appliance performance is improved, but user statistics accuracy deteriorates due to robo-clicks being misattributed to human users

Engineering Contradiction:
Improvesecurity analysis efficiencyVSAvoiduser statistics accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent introduces an intermediary mechanism (bot detection system) that sits between the automated link following process and the user statistics collection. This intermediary detects and identifies bot-generated clicks, separating them from human user interactions before statistics are compiled, thereby maintaining both automated analysis efficiency and statistical accuracy

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments user interactions into distinct categories: human-generated clicks and bot-generated clicks. By dividing the overall click stream into these separate segments and tracking them independently, the system can maintain high productivity from automated following while ensuring only human interactions are counted in user statistics

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If bot detection and filtering is implemented to improve user statistics accuracy, then measurement precision is improved, but system complexity increases due to additional detection mechanisms

Engineering Contradiction:
Improveuser statistics accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where bot detection results are fed back into the statistics collection process. The system continuously monitors click patterns, identifies bot behavior through analysis feedback, and adjusts filtering accordingly, improving accuracy without requiring overly complex predetermined filtering rules

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The bot detection system operates autonomously, self-identifying bot-generated clicks through pattern recognition and automated analysis. This self-service capability reduces the need for manual configuration and complex external detection mechanisms, achieving accurate filtering with relatively simple system architecture

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9781160B1Systems and methods for discovering suspect bot IP addresses and using validated bot IP address to ignore actions in a simulated phishing environment
Publication Date: 2017.10.03 KNOWBE4 INC
  • US9781160B1 patent drawing
  • US9781160B1 patent drawing
  • US9781160B1 patent drawing

AI summary

Methods, systems and apparatus are provided which allow a server of a security awareness system to associate IP addresses with events representing user interactions with simulated phishing campaigns. The server receives a plurality of events related to one or more simulated phishing campaigns for a plurality of accounts. The server determines if an IP address of the plurality of IP addresses is associated with one or more events for multiple accounts of the plurality of accounts. Based upon this determination, the server provides identification of the IP address as suspected as having the one or more events associated with it not originating from any user of the multiple accounts. The server receives an indication of whether the IP address is validated as having the one or more events originating from a bot instead of a user of one of the multiple accounts.