Phishing Campaign False Positive Mitigation via Click Cache Delay

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Simulated phishing campaigns often result in false positives due to interactions with third-party threat detection systems, leading to unreliable user metrics and inaccurate risk scores, as the systems cannot differentiate between user interactions and automated actions by the threat detection systems.

Innovation Solution

A first security awareness system receives simulated phishing messages, holds link data in a click cache with a predetermined delay, and determines if the link was followed by the user or the second security awareness system by checking correspondence with the link cache or IP cache, excluding automated interactions from user records.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a simulated phishing campaign is executed to test employee security awareness, then the security awareness of employees can be gauged and improved, but false positives occur when third-party threat detection systems automatically interact with the simulated phishing messages, leading to unreliable metrics

Engineering Contradiction:
Improveaccuracy of security awareness metricsVSAvoidreliability of user interaction data
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system performs preliminary actions by implementing a delay mechanism before recording link clicks, and by pre-establishing identification methods to distinguish automated bot interactions from genuine user clicks. This preliminary filtering prevents false positives from being recorded in the first place, ensuring metric accuracy.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification mechanism that acts as a mediator between the simulated phishing message delivery and the metric recording process. This intermediary layer analyzes click patterns and timing to determine whether a click originated from a genuine user or an automated threat detection system, thereby protecting the integrity of security awareness metrics.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If link click data is recorded immediately to provide real-time security metrics, then productivity and responsiveness are improved, but automated interactions by threat detection systems are mistakenly counted as user interactions, creating false positives

Engineering Contradiction:
Improvespeed of metric generationVSAvoidaccuracy of interaction attribution
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system implements a predetermined delay period before finalizing link click recordings. During this delay, the system has an opportunity to verify whether the click originated from a genuine user or an automated system. This preliminary verification maintains real-time responsiveness while preventing false positives from contaminating the metrics.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces dynamic elements to the metric recording process, including variable delay periods and adaptive verification mechanisms. The system can adjust the delay duration and verification intensity based on contextual factors such as the source of the click, the timing patterns, and the specific phishing campaign being executed, thereby maintaining productivity while improving measurement precision.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12174966B2Systems and methods for mitigating false positives in a simulated phishing campaign
Publication Date: 2024.12.24 KNOWBE4 INC
  • US12174966B2 patent drawing
  • US12174966B2 patent drawing
  • US12174966B2 patent drawing

AI summary

Systems and methods are described for mitigating false positives in a simulated phishing campaign. A simulated phishing message reported to second security awareness system by a user as suspicious is received by first security awareness system. The reported message includes a link that has been followed. Link data of followed link of the reported message is held in click cache having predetermined delay. Post the predetermined delay, whether the link was followed by second security awareness system instead of being clicked by user responsive to identifying that link data in click cache corresponds to link data in link cache or internet protocol (IP) address of an entity that follows a link corresponds to IP address stored in IP cache known to be associated with second security awareness system. Responsive to determination, second security awareness system's following of link of the reported message is excluded as interaction of the user.