Simulated Phishing Message Recipient Attribution via User Identifier

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current approaches to assessing cybersecurity risks through simulated phishing campaigns lack accuracy in determining whether a simulated malicious message has reached the intended recipient or has been forwarded to another user, leading to incorrect identification of users who fell for the phishing attempt.

Innovation Solution

An electronic device modifies a simulated malicious message by appending a user identifier to the service address of an actuatable element, allowing the system to track whether the intended recipient or an alternate recipient acted upon the message, ensuring accurate attribution of actions and targeted training.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If simulated phishing messages are sent to assess user cybersecurity risk, then cybersecurity risk assessment capability is improved, but accuracy in determining whether the intended recipient or alternate recipient acted upon the message deteriorates

Engineering Contradiction:
Improvecybersecurity risk assessment capabilityVSAvoidaccuracy in determining recipient action
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The system performs preliminary actions by modifying the simulated phishing message before it is sent to the recipient. Specifically, the service address in the message is modified to include a unique identifier for the intended recipient. This preliminary modification ensures that when the message is forwarded to an alternate recipient, the system can still track and attribute actions accurately based on the embedded identifier, thus resolving the contradiction between maintaining assessment capability and improving measurement precision.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If message forwarding is allowed in simulated phishing campaigns, then ease of operation is improved, but reliability of action attribution deteriorates

Engineering Contradiction:
Improvemessage forwarding capabilityVSAvoidaction attribution accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system implements a feedback mechanism by modifying the service address to include a unique recipient identifier. When a message is forwarded, the modified service address travels with the message, providing feedback information that allows the system to determine whether the action was taken by the intended recipient or an alternate recipient. This feedback loop maintains reliable action attribution while allowing message forwarding to occur, thus resolving the contradiction between ease of operation and reliability.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240396858A1Determining Authenticity of Reported User Action in Cybersecurity Risk Assessment
Publication Date: 2024.11.28 GOLDMAN SACHS BANK USA
  • US20240396858A1 patent drawing
  • US20240396858A1 patent drawing
  • US20240396858A1 patent drawing

AI summary

An electronic device will identify an electronic message received by a messaging client that is associated with a first recipient, and it will analyze the electronic message to determine whether the electronic message is a simulated malicious message. Upon determining that electronic message is a simulated malicious message, the device will identify an actuatable element in the electronic message. The actuatable element will include a service address. The device will modify the electronic message by appending a user identifier of the first recipient to the service address of the actuatable element. Then, when the actuatable element is actuated, the system may determine whether the first recipient actuated the actuatable element or an alternate recipient did so based on whether the user identifier of the first recipient is still appended (or is the only user identifier appended) to the actuatable element.