Machine-Learning Spear Phishing Simulations for Tailored Training

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large enterprise organizations face challenges in training users to recognize spear phishing attacks due to their personalized nature, which complicates user training and resource optimization, especially in balancing security and computing resources.

Innovation Solution

A computing platform uses machine learning to generate simulated spear phishing messages and customize training modules based on user interactions and temporal data, employing branching templates to assess susceptibility and generate tailored training content.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional cybersecurity training is provided to all users, then user awareness of spear phishing attacks is improved, but computing resources and network bandwidth are excessively consumed

Engineering Contradiction:
Improveuser awareness of spear phishing attacksVSAvoidcomputing resources and network bandwidth
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system transitions from uniform training for all users to personalized training content tailored to each user's specific susceptibility level, interaction patterns, and risk profile. This allows computing resources to be focused on users who need training most, rather than uniformly distributing resources to all users.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts training parameters including content type, delivery method, frequency, and intensity based on user behavior analysis and susceptibility scoring. This enables optimization of resource consumption by adapting training delivery to match user needs rather than using a fixed approach for all users.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If personalized spear phishing training is provided to each user, then training effectiveness is improved, but device complexity and processing requirements increase

Engineering Contradiction:
Improvetraining effectivenessVSAvoidprocessing requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments users into different risk groups and susceptibility categories based on their interaction patterns with simulated phishing messages. This segmentation allows the system to apply different processing levels and training intensities to different user groups, reducing overall computational complexity while maintaining personalization where needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system uses machine learning models trained on aggregated user data to generate personalized training content. Once patterns are learned from群体 data, individual personalized training modules can be efficiently generated by applying these learned patterns to specific users, reducing the processing required for each individual user while maintaining personalization effectiveness.

Inventive Principle:
Principle #26Copying

3Measurement precision

If simulated spear phishing messages are sent to assess user susceptibility, then personalized training can be generated, but network bandwidth and user time are consumed

Engineering Contradiction:
Improveuser susceptibility assessmentVSAvoiduser time and network bandwidth
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system sends a limited number of simulated phishing messages rather than continuous monitoring, using just enough assessments to reliably determine user susceptibility categories. This partial action approach achieves sufficient measurement precision without excessive consumption of user time and network resources.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs susceptibility assessment through simulated phishing messages before delivering personalized training content. This preliminary action allows the system to pre-categorize users and prepare appropriate training modules in advance, reducing the total time users spend on training by avoiding unnecessary generic training for low-risk users.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12423421B2Generating simulated spear phishing messages and customized cybersecurity training modules using machine learning
Publication Date: 2025.09.23 GOLDMAN SACHS BANK USA
  • US12423421B2 patent drawing
  • US12423421B2 patent drawing
  • US12423421B2 patent drawing

AI summary

Aspects of the disclosure relate to spear phishing simulation using machine learning. A computing platform may send, to an enterprise user device, a spear phishing message. The computing platform may receive initial user interaction information indicating how a user of the enterprise user device interacted with the spear phishing message. Based on the initial user interaction information and using a series of branching message templates, the computing platform may generate additional spear phishing messages. The computing platform may receive additional user interaction information indicating how the user interacted with the additional spear phishing messages. Based on the initial user interaction information and the additional user interaction information, the computing platform may compute spear phishing scores. Based on a comparison of the spear phishing scores to spear phishing thresholds, the computing platform may generate training modules for the user, and may send the training modules to the enterprise user device.