Phishing Metrics Tool for Dynamic Security Awareness Training

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional information security training methods are inadequate in addressing evolving social engineering threats, particularly phishing attacks, as they fail to provide consistent user awareness and are not targeted towards susceptible users.

Innovation Solution

The STAR*Phish system employs a service-oriented design for continuous phishing awareness training, using a Phishing Metrics Tool (PMT) and Phishing Training Tool (PTT) to provide tailored, live exercises that exploit 'teachable moments' and track metrics, offering customizable training for specific user groups and adapting to evolving threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional static presentations or test events are used for information security training, then training can be implemented periodically, but user awareness of evolving threats is insufficient

Engineering Contradiction:
Improveuser awareness of security threatsVSAvoidtraining adaptability to evolving threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The training system transitions from static periodic presentations to dynamic simulated phishing attacks that adapt to user interactions in real-time. The simulation evolves based on user decisions, providing customized training scenarios that reflect current threat landscapes rather than predetermined static content.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary actions by proactively identifying susceptible users through behavioral analysis and pre-targeting them with customized phishing simulations before actual attacks occur. This allows organizations to address security vulnerabilities before they are exploited by real attackers.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If traditional annual data security training is provided, then all users receive training, but training is not targeted to susceptible users and consistency in awareness is not achieved

Engineering Contradiction:
Improveconsistency of user awarenessVSAvoidtraining targeting complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system continuously monitors user behavior, clicks, and interactions with security-related content to identify susceptible users. This feedback loop enables dynamic targeting of training efforts to specific individuals who demonstrate vulnerability to phishing attacks, rather than applying uniform training to all users.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system changes training parameters such as simulation frequency, complexity, and content based on individual user susceptibility levels. Susceptible users receive more frequent and targeted simulations, while less susceptible users receive reduced training intensity, optimizing resource allocation and training effectiveness.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If live phishing exercises are conducted, then realistic training is provided, but users who fall victim need immediate training intervention

Engineering Contradiction:
Improvetraining realismVSAvoidtime to provide training after failure
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The system has pre-prepared training modules and intervention protocols ready to be immediately deployed when a user fails a phishing simulation. This preliminary preparation ensures that training intervention occurs without delay, capitalizing on the teachable moment while the user's susceptibility is fresh.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The training process continues uninterrupted by seamlessly transitioning users from the phishing simulation directly into targeted training modules without breaking the learning flow. This continuous action ensures immediate reinforcement of correct behaviors while the security lesson is still relevant to the user.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS9270696B2Systems and method for identifying and mitigating information security risks
Publication Date: 2016.02.23 BOOZ ALLEN HAMILTON INC
  • US9270696B2 patent drawing
  • US9270696B2 patent drawing
  • US9270696B2 patent drawing

AI summary

Methods and systems for Sustained Testing and Awareness Refresh against Phishing threats (STAR*Phishâ„¢) are disclosed. In an embodiment, a method assigns schemes and unique identifiers to target e-mail addresses associated with a user accounts. The method delivers e-mail messages to the targeted e-mail addresses, the e-mail messages comprising an HTTP request and a unique identifier associated with each of the user accounts. The method then receives, at a Phishing Metric Tool (PMT), a response including the unique identifier. The PMT logs training requirements for the user accounts, tracks response metrics for the training requirements, and redirects the respective HTTP requests to a phishing training tool (PTT). The PTT sends a notification of the user account identities and the unique identifiers to the PMT and returns a status for the training requirements for the user accounts. Upon completion of the training, the PMT sends completion notifications for the user accounts.