Simulated Phishing Email Annotation for Adaptive Cybersecurity Training

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large enterprise organizations face challenges in effectively training users to recognize and avoid cybersecurity threats in electronic communications, particularly due to varying skill sets and backgrounds, which complicates balancing training with computing resource consumption.

Innovation Solution

A computing platform generates simulated attack messages that users annotate, allowing for customized training modules to be created based on user performance, with scoring mechanisms that adapt to user selections and frequency of correct annotations, updating machine learning models for improved training effectiveness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If customized training modules are generated for each user based on their performance, then training effectiveness is improved, but computing resource consumption increases

Engineering Contradiction:
Improvetraining effectivenessVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system dynamically changes training parameters (content, difficulty, format) based on user performance metrics. Machine learning models analyze user interactions with simulated phishing emails and adjust training module parameters accordingly, providing customization without requiring full recomputation of training content for each user.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system performs preliminary analysis of user behavior during simulated phishing exercises before generating customized training modules. By pre-processing user interaction data and identifying key performance indicators during the simulation phase, the system reduces the computational burden of later customization steps.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If simulated attack messages are used for training, then user awareness is improved, but network security risks increase

Engineering Contradiction:
Improveuser awarenessVSAvoidnetwork security risks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system uses copies or simulations of real phishing attacks rather than actual malicious content. These simulated attack messages replicate the structure, language, and tactics of real phishing emails without containing functional malicious code, allowing users to be trained on realistic threats without exposing the network to actual security risks.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system introduces an intermediary layer between users and real phishing threats. The simulated attack messages act as intermediaries that convey the same training value as real attacks while eliminating the harmful effects. This intermediary approach allows safe exposure to attack patterns without actual compromise risk.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If comprehensive annotation tools are provided for user interaction, then training accuracy is improved, but interface complexity increases

Engineering Contradiction:
Improvetraining accuracyVSAvoidinterface complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The annotation interface is segmented into distinct functional zones and interaction types. Users are presented with specific annotation tasks (e.g., marking suspicious elements, categorizing threats) rather than a single complex annotation system. This segmentation reduces perceived complexity while maintaining comprehensive data collection for accurate training assessment.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12198575B2Prompting users to annotate simulated phishing emails in cybersecurity training
Publication Date: 2025.01.14 GOLDMAN SACHS BANK USA
  • US12198575B2 patent drawing
  • US12198575B2 patent drawing
  • US12198575B2 patent drawing

AI summary

Aspects of the disclosure relate to dynamically generating simulated attack messages configured for annotation by users as part of cybersecurity training. A computing platform may generate a simulated attack message including a plurality of elements and send the simulated attack message to an enterprise user device. Subsequently, the computing platform may receive, from the enterprise user device, user selections annotating selected elements of the plurality of elements of the simulated attack message. The computing platform may thereafter identify one or more training areas for the user based on the user selections received from the enterprise user device, generate a customized training module specific to the identified one or more training areas, and send the customized training module to the enterprise user device. Sending the customized training module to the enterprise user device may cause the enterprise user device to display the customized training module.