Phishing Training Tool for Adaptive User Susceptibility Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Phishing emails pose a significant risk to computing systems and networks as they can deceive a large number of recipients, making it difficult to prevent security threats, and existing methods are inefficient in training users to identify and respond to phishing attempts effectively.

Innovation Solution

A system that communicates different types of phishing emails to users, determines response rates, and adjusts the distribution of subsequent emails to achieve an aggregate response rate closer to a target, thereby reducing the effectiveness of phishing attempts by tailoring training to individual user susceptibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If phishing emails are sent to a large number of users, then the training coverage is improved, but the risk of actual phishing attacks increases

Engineering Contradiction:
Improvenumber of users trainedVSAvoidphishing attack risk
Core Design Contradiction:
Quantity of substanceVSObject-affected harmful factors

Solution Approach 1:

The system segments the user population into different groups based on their susceptibility to phishing emails. By dividing users into segments with different risk profiles, the system can apply targeted training strategies to each segment, reducing the need to send phishing emails to all users while still achieving comprehensive training coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically changes parameters such as email composition, sending timing, and target user selection based on observed response rates and susceptibility metrics. This allows the system to optimize training effectiveness while minimizing the spread of phishing emails by adjusting these parameters in real-time.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If phishing emails are composed to be more deceptive, then the training effectiveness is improved, but the ethical concerns and potential harm increase

Engineering Contradiction:
Improvetraining effectivenessVSAvoidethical harm
Core Design Contradiction:
Measurement precisionVSObject-generated harmful factors

Solution Approach 1:

The system uses feedback from user responses to phishing emails to continuously improve training effectiveness. By analyzing response rates and user behavior, the system can adjust future email compositions to be more effective without necessarily increasing deception, as the feedback loop allows for optimization based on actual user susceptibility patterns.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system applies partial deception by sending phishing emails only to users who are identified as susceptible based on preliminary assessments. This partial action approach ensures that training is applied where needed without exposing all users to potentially harmful deceptive content, thus reducing overall ethical harm while maintaining training effectiveness for the target population.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If the system sends more phishing emails to achieve target response rates, then the training coverage is improved, but the system complexity and resource consumption increase

Engineering Contradiction:
Improvetraining coverageVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-assessing user susceptibility to phishing emails before sending the actual training emails. This preliminary assessment allows the system to identify which users need training and send phishing emails only to them, reducing the overall number of emails needed to achieve target response rates and simplifying the system's operational complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system uses automated algorithms and machine learning models to self-adjust email composition and distribution strategies based on observed data. This self-service capability reduces the need for manual intervention and complex system management, allowing the system to maintain high training coverage while managing complexity through automation.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9942249B2Phishing training tool
Publication Date: 2018.04.10 BANK OF AMERICA CORP
  • US9942249B2 patent drawing
  • US9942249B2 patent drawing
  • US9942249B2 patent drawing

AI summary

According to one embodiment, an apparatus is configured to communicate a first plurality of phishing emails to a first plurality of users, each phishing email of the first plurality of phishing emails is of a first type or a second type. The apparatus is configured to determine a first response rate of the first plurality of users to phishing emails of the first type and to determine a second response rate of the first plurality of users to phishing emails of the second type. The apparatus is configured to determine a second plurality of phishing emails comprising phishing emails of the first type and the second type, wherein an aggregate response rate of a second plurality of users to the second plurality of phishing emails is predicted to be closer to a target response rate than one or more of the first response rate and the second response rate.