Simulated Phishing Attack User Identification via Unique Identifier Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for simulating phishing attacks lack the ability to accurately identify users who respond to such attacks, especially when they use different email accounts, making it difficult to assess and address vulnerabilities in security systems and user behavior.

Innovation Solution

Incorporating unique identifiers in simulated phishing emails that are embedded in various fields such as the subject line, body, or attachments, allowing the system to track and match these identifiers in reply emails, regardless of the email account used, to determine the responding user's identity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If simulated phishing attacks are performed without unique identifiers, then the attack can be simpler and faster, but the system cannot accurately identify users who respond to the attack

Engineering Contradiction:
Improveuser identification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system pre-generates and embeds unique identifiers in the phishing emails before sending them to users. These identifiers are placed in various fields such as subject line, body, or attachments of the emails. When users respond, the system extracts and matches these pre-placed identifiers to accurately identify the responding user, thereby solving the identification accuracy problem without requiring complex real-time analysis mechanisms

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The unique identifier acts as an intermediary element that bridges the phishing email and the user response. By embedding this intermediary identifier in the email and extracting it from the response, the system creates a reliable link between the sent email and the responding user, enabling accurate user identification without direct complex tracking mechanisms

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the system tracks users across different email accounts, then user identification becomes more accurate, but the system complexity increases

Engineering Contradiction:
Improveuser tracking reliabilityVSAvoidtracking system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The unique identifier serves multiple functions: it identifies the user, tracks their response to the phishing attack, and works across different email accounts. By making the identifier universal rather than account-specific, the system achieves reliable user tracking across multiple accounts without requiring separate tracking mechanisms for each account, thereby reducing overall system complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If unique identifiers are embedded in multiple email fields, then user identification accuracy improves, but the email content becomes more complex

Engineering Contradiction:
Improveuser identification accuracyVSAvoidemail generation complexity
Core Design Contradiction:
Measurement precisionVSEase of manufacture

Solution Approach 1:

The system segments the unique identifier placement into different optional locations within the email (subject line, body, attachments) rather than requiring all fields to be modified. This segmentation allows the system to achieve accurate user identification by placing the identifier in at least one field while keeping the email generation process simple and manageable, avoiding the complexity of modifying every possible email field

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12081574B2Systems and methods for performing a simulated phishing attack
Publication Date: 2024.09.03 KNOWBE4 INC
  • US12081574B2 patent drawing
  • US12081574B2 patent drawing
  • US12081574B2 patent drawing

AI summary

Systems and methods for performing a simulated phishing attack are provided. A simulated attack server can send a simulated attack email including a unique identifier to a target. The simulated attack server can receive a reply email including the unique identifier from the target. The simulated attack server can extract the unique identifier from the reply email. The simulated attack server can determine a match between the unique identifier and an identity of the target. The simulated attack server can record a target failure, responsive to determining the match between the unique identifier and the identity of the target.