Simulated Phishing Communications via Employee Message Context

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current simulated phishing communications often lack relevance to employees, leading to ineffective training and increased vulnerability to actual phishing attacks due to insufficiently gathered information, resulting in potential security breaches.

Innovation Solution

A system and method that utilize a message store to generate simulated phishing communications by analyzing message characteristics such as keywords, links, dates, and message participants, applying AI and ML to determine contextual information, and creating communications that are highly relevant to individual employees, thereby enhancing the authenticity and effectiveness of the training.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Loss of information

If information is gathered from OSINT sources to create simulated phishing communications, then some level of personalization is achieved, but the information is insufficient to create highly relevant communications

Engineering Contradiction:
Improveinformation sufficiencyVSAvoidcommunication relevance
Core Design Contradiction:
Loss of informationVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by accessing and analyzing the employee's message store before generating the simulated phishing communication. This allows the system to gather rich contextual information from actual message exchanges, including communication patterns, contacts, and topics, which then informs the creation of highly relevant simulated phishing communications tailored to the employee's specific work context

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary mechanism (message store analysis) between the available information and the generated communication. By analyzing the employee's actual message store, the system extracts contextual information that serves as a bridge, enabling the creation of simulated phishing communications that are both personally relevant and contextually accurate without requiring direct access to sensitive personal data

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If simulated phishing communications are created with high relevance to individual employees, then training effectiveness improves, but the complexity of information gathering and analysis increases

Engineering Contradiction:
Improvetraining effectivenessVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system employs self-service mechanisms by automatically accessing the employee's message store, analyzing communication patterns, and generating contextual information without requiring manual intervention. The system autonomously performs information gathering, pattern recognition, and communication generation, reducing the need for human analysts while maintaining high relevance and effectiveness of the simulated phishing communications

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system replaces manual, mechanical processes of information gathering and analysis with automated computational processes. Instead of manually collecting and analyzing employee information, the system uses automated access to message stores, algorithmic analysis of communication patterns, and automated generation of simulated phishing communications, significantly reducing system complexity despite the sophisticated analysis performed

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If more information is gathered about employees to create relevant simulated phishing communications, then communication authenticity improves, but the need for human intervention and processing increases

Engineering Contradiction:
Improvecommunication authenticityVSAvoidautomation level
Core Design Contradiction:
Adaptability or versatilityVSExtent of automation

Solution Approach 1:

The system performs self-service by automatically accessing message stores, analyzing communication patterns, and generating contextual information without human intervention. The automated process handles information gathering, pattern recognition, and communication creation end-to-end, maintaining high authenticity while maximizing automation and minimizing manual processing

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms by analyzing actual message store data to understand employee communication patterns, then using this feedback to generate more authentic simulated phishing communications. The system continuously learns from the message store analysis and adjusts the generated communications to better match the employee's actual communication style and context, improving authenticity while remaining fully automated

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20210365866A1Systems and methods for use of employee message exchanges for a simulated phishing campaign
Publication Date: 2021.11.25 KNOWBE4 INC
  • US20210365866A1 patent drawing
  • US20210365866A1 patent drawing
  • US20210365866A1 patent drawing

AI summary

Systems and methods are described for facilitating use of employee message exchanges for a simulated phishing campaign. Initially, a message store of one or more users is accessed to retrieve one or more messages from the message store. Further, one or more message characteristics of the one or more messages are identified. The one or more message characteristics are processed to determine contextual information. Based on the contextual information, a simulated phishing communication is generated such that the generated simulated phishing communication is relevant to a user of the one or more users. The simulated phishing communication is then communicated to the user.