Phishing Simulation Injection Bypassing Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for simulating phishing attacks are inefficient, as they often get identified by threat detection software, require time-consuming whitelisting, and are not delivered directly to user mailboxes, and lack real-time response to suspicious messages.

Innovation Solution

A system that receives reports of suspicious messages, identifies similar messages, quarantines them, and generates simulated phishing messages, which can be directly injected into user mailboxes during active usage, using a network server device with a phishing simulation module and management console for efficient analysis and response.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If simulated phishing emails are sent through standard email systems, then the simulation can be delivered to users, but the emails are identified by threat detection software and do not reach the intended user

Engineering Contradiction:
Improvedelivery reliabilityVSAvoidthreat detection blocking
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary component that injects simulated phishing emails directly into user mailboxes, bypassing the standard email delivery path that triggers threat detection. This intermediary injection mechanism allows the simulation emails to reach users without being blocked by security software.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates copies of real phishing emails (with malicious content removed or neutralized) and injects these copies directly into user mailboxes. This copying approach allows the simulation to closely resemble actual threats while avoiding detection, as the copied structure and format are familiar to users but the harmful elements are eliminated.

Inventive Principle:
Principle #26Copying

2Reliability

If enterprises whitelist domains or information in simulation messages, then the simulation messages can bypass threat detection, but the process is extremely time consuming and impractical

Engineering Contradiction:
Improvesimulation deliveryVSAvoidwhitelisting preparation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs self-service by automatically injecting simulation emails directly into mailboxes without requiring manual whitelisting configuration. The injection mechanism inherently bypasses threat detection without needing pre-approval or domain whitelisting, eliminating the time-consuming setup process.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary neutralization of malicious content in copied phishing emails before injection, and uses direct injection as a pre-established delivery path that automatically bypasses threat detection. This preliminary preparation eliminates the need for time-consuming whitelisting operations.

Inventive Principle:
Principle #10Preliminary action

3Extent of automation

If phishing simulations are sent according to a scheduled timeline, then the system can automate delivery, but users are less likely to engage when not actively working with email

Engineering Contradiction:
Improvesimulation schedulingVSAvoiduser engagement rate
Core Design Contradiction:
Extent of automationVSProductivity

Solution Approach 1:

The system transitions from static scheduled delivery to dynamic on-demand injection. The injection timing is dynamically adjusted based on real-time detection of user activity in their email accounts, ensuring simulations are delivered when users are most likely to engage rather than following a fixed schedule.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system uses feedback from mailbox activity monitoring to determine optimal injection timing. By continuously monitoring when users are actively working with their email, the system adjusts delivery timing dynamically, creating a feedback loop that maximizes engagement rates.

Inventive Principle:
Principle #23Feedback

4Measurement precision

If users report suspicious messages, then the system can identify threats, but there is a delay in engaging other users with neutralized versions of the threat

Engineering Contradiction:
Improvethreat detection accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system maintains continuous monitoring and ready-state injection capability, allowing immediate response to reported threats. When a suspicious message is reported, the system continuously searches for similar emails and can instantly inject neutralized versions into affected mailboxes without interruption or delay.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs preliminary analysis and preparation of neutralized simulation versions in advance. When threats are reported, the neutralized versions are already prepared and can be immediately injected, eliminating response delays.

Inventive Principle:
Principle #10Preliminary action

5Reliability

If the system searches for and removes suspicious messages from all user accounts, then threat propagation is prevented, but the process may restore benign messages incorrectly

Engineering Contradiction:
Improvethreat remediation effectivenessVSAvoidfalse positive restoration
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system applies different quality levels of analysis and neutralization to different messages. Rather than uniformly treating all suspicious messages the same way, it performs localized analysis on each message's characteristics, allowing for more precise differentiation between malicious and benign content while maintaining effective threat removal.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11997115B1Message platform for automated threat simulation, reporting, detection, and remediation
Publication Date: 2024.05.28 COFENSE INC
  • US11997115B1 patent drawing
  • US11997115B1 patent drawing
  • US11997115B1 patent drawing

AI summary

Methods, network devices, and machine-readable media for an integrated environment and platform for automated processing of reports of suspicious messages, and further including automated threat simulation, reporting, detection, and remediation, including rapid quarantine and restore functions.