Per-User Phishing Training Using Behavior-Based Email Simulation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional phishing security systems lack realism in training, employ a one-size-fits-all approach, and fail to adapt to evolving attack methods, necessitating a per-user basis training technique.

Innovation Solution

A user behavior training model is generated using machine learning to customize phishing attack simulations and training videos based on individual user interactions, enabling personalized phishing attack training.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If conventional phishing security systems use a one-size-fits-all training approach, then the training process is simple and efficient, but the training effectiveness is reduced because it ignores individual user needs and behaviors

Engineering Contradiction:
Improvetraining efficiencyVSAvoidtraining effectiveness
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system transitions from uniform training to personalized training by analyzing individual user behaviors, risk profiles, and interaction patterns. Each user receives customized phishing simulations and training content tailored to their specific characteristics, thereby improving training effectiveness while maintaining efficiency through automation.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system automatically analyzes user behaviors, generates personalized training plans, and adapts training content without requiring manual intervention. Users interact with the system at their own pace, and the system self-adjusts based on their responses, making the training process both efficient and effective.

Inventive Principle:
Principle #25Self-service

2Ease of manufacture

If conventional phishing security systems lack realism in training, then the training content is easy to produce and deliver, but the training fails to prepare users for real-world phishing attacks

Engineering Contradiction:
Improvetraining content productionVSAvoidtraining realism
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system creates realistic phishing simulations by copying actual attack patterns, tactics, and techniques used by threat actors. These simulated phishing emails replicate real-world scenarios including sophisticated email formatting, attachments, and social engineering elements, providing authentic training experiences that prepare users for actual attacks.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system prepares users in advance by exposing them to realistic phishing simulations before actual attacks occur. Through preliminary training with simulated attacks, users develop the skills and awareness needed to recognize and respond to real phishing attempts, reducing the impact of actual attacks when they occur.

Inventive Principle:
Principle #10Preliminary action

3Stability of the object's composition

If conventional phishing security systems do not adapt to evolving attack methods, then the training curriculum is stable and easy to maintain, but the training becomes outdated as attackers change tactics

Engineering Contradiction:
Improvetraining curriculum stabilityVSAvoidtraining adaptability to new attacks
Core Design Contradiction:
Stability of the object's compositionVSAdaptability or versatility

Solution Approach 1:

The training system dynamically adapts to evolving attack methods by continuously analyzing new phishing patterns and automatically updating training content. The system maintains stability through structured training frameworks while incorporating real-time updates based on emerging threat intelligence, ensuring the training remains current without requiring complete curriculum redesigns.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops that monitor user responses to phishing simulations and analyze emerging attack patterns. This feedback information is used to continuously improve and update the training curriculum, ensuring it adapts to new attack methods while maintaining overall structural stability through automated processes.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12580961B2Training trusted users of an enterprise network for phishing attacks on a per-user basis
Publication Date: 2026.03.17 FORTINET INC
  • US12580961B2 patent drawing
  • US12580961B2 patent drawing
  • US12580961B2 patent drawing

AI summary

A user behavior training model is generated, using machine learning, from tracking a plurality of trusted users for interactions with respect to a plurality of monitored phishing e-mails. When a unique phishing attack is detected from an incoming email, a new campaign is initiated. A unique phishing attack email that is modified by the user behavior model is generated for each user. In particular, a first test phishing e-mail for a first user is modified based on interactions tracked for the first user and a second test phishing e-mail for a second user is modified based on interactions tracked for the second user. Based on responses to the plurality of test phishing emails, a plurality of custom training videos is generated. A first training video is modified based on a response from the first user and a second training video is modified based on a response from the second user.