Simulated Phishing Delivery Verification System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity measures, such as email security systems, often intercept and modify simulated phishing communications, leading to inaccurate assessments of employee cybersecurity awareness and increased administrative workload due to ineffective whitelisting and post-delivery scanning, which can result in skewed perceptions of user risk and reliability issues in delivering simulated phishing campaigns.

Innovation Solution

A method and system for verifying whether simulated phishing communications can pass through email security systems to user accounts without being blocked or modified, involving a delivery verification campaign that identifies suitable email accounts, selects types of simulated phishing communications, configures the campaign, communicates them to test accounts, and determines their reception status, allowing reliable delivery and adaptation of phishing campaign configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Object-affected harmful factors

If email security systems intercept and scan simulated phishing communications, then security detection capability is improved, but delivery reliability deteriorates because the communications are blocked or modified

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoiddelivery reliability
Core Design Contradiction:
Object-affected harmful factorsVSReliability

Solution Approach 1:

The system performs preliminary actions by sending test emails before the actual simulated phishing campaign to identify which email types are blocked by the security system. This advance testing allows the system to adapt and select only those communication types that will successfully deliver, ensuring both security detection capability and delivery reliability are maintained.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system changes parameters by adapting the simulated phishing campaign configuration based on test results. When certain email types are blocked, the system modifies the campaign to use different email types or formats that successfully pass through the security system, thereby maintaining delivery reliability while preserving security detection capability.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If administrators manually update whitelisting configurations to ensure delivery, then delivery reliability is improved, but administrative workload increases

Engineering Contradiction:
Improvedelivery reliabilityVSAvoidadministrative workload
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs self-service by automatically conducting test emails and adapting the simulated phishing campaign configuration without requiring manual administrator intervention. The system independently identifies blocked email types and adjusts the campaign accordingly, eliminating the need for constant whitelisting updates while maintaining delivery reliability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary testing automatically before deployment to identify delivery issues. This advance automated testing prevents the need for manual whitelisting updates by proactively adapting the campaign configuration to bypass security blocks, thereby reducing administrative workload while ensuring reliable delivery.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If simulated phishing communications are sent through SMTP, then ease of operation is improved, but measurement precision deteriorates because delivery status cannot be reliably determined

Engineering Contradiction:
Improveease of operationVSAvoiddelivery status accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system implements feedback by monitoring whether test emails and simulated phishing communications actually reach user inboxes. This feedback mechanism allows the system to determine delivery status accurately by comparing expected delivery with actual reception, thereby maintaining ease of SMTP operation while improving measurement precision of delivery status.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11729206B2Systems and methods for effective delivery of simulated phishing campaigns
Publication Date: 2023.08.15 KNOWBE4 INC
  • US11729206B2 patent drawing
  • US11729206B2 patent drawing
  • US11729206B2 patent drawing

AI summary

Systems and methods are described for verifying whether simulated phishing communications are allowed to pass by a security system of an email system to email account of users. One or more email accounts of the email system with the security system may be identified to use for a delivery verification campaign. Further, one or more types of simulated phishing communications may be selected from a plurality of types of simulated phishing communications. The delivery verification campaign may be configured to include the selection of the one or more types of simulated phishing communications from the plurality of types of simulated phishing communications. The selected one or more types of simulated phishing communications of the delivery verification campaign may be communicated to the one or more email accounts. Further, whether or not each of the one or more types of simulated phishing communications was allowed by the security system to be received unchanged at the one or more email accounts.