Reverse Vishing Security Awareness System for Phishing Training

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security awareness systems are inadequate in training users to detect sophisticated and personalized phishing attacks, as they fail to create a simulated environment that mimics real-world attacks effectively, particularly with the rise of vishing and reverse vishing techniques.

Innovation Solution

A security awareness system that utilizes simulated phishing campaigns, including reverse vishing, by sending and receiving voice calls to users, using unique telephone numbers and reference identifiers, to identify and remediate user failures, providing personalized training and locking device functions until training is completed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional simulated phishing attacks are used, then users can be tested for phishing susceptibility, but the training effectiveness is reduced because not all users respond to the same phishing stimulus and sophisticated personalized attacks are not adequately simulated

Engineering Contradiction:
Improvetraining effectivenessVSAvoidpersonalization capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent inverts the traditional phishing approach by using reverse vishing - instead of sending phishing messages to users, the system calls users with simulated phishing scenarios. This inversion allows for more effective personalization because voice calls can dynamically adapt to user responses and deliver customized training content based on individual susceptibility patterns, thereby improving both training effectiveness and adaptability simultaneously

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If sophisticated personalized phishing attacks are simulated, then training realism is improved, but system complexity increases

Engineering Contradiction:
Improveattack simulation realismVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses voice call technology to create simplified copies of sophisticated phishing attacks. Instead of building complex multi-channel attack simulations, the system uses phone calls - a familiar and simple medium - to replicate the essential elements of personalized phishing attacks through scripted scenarios and dynamic user interaction, achieving high realism without proportional increases in system complexity

Inventive Principle:
Principle #26Copying

3Measurement precision

If reverse vishing techniques are implemented, then user identification and training delivery are improved, but ease of operation decreases due to device locking requirements

Engineering Contradiction:
Improveuser identification accuracyVSAvoiddevice accessibility
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent applies preliminary anti-action by locking device functions before phishing susceptibility testing. This pre-emptive measure prevents users from bypassing the training or accessing external resources during the simulation, ensuring accurate identification of susceptible users. The locking is automatically reversed after training completion, temporarily restricting access to protect training integrity while restoring full functionality once education is delivered

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11457041B2System and methods for reverse vishing and point of failure remedial training
Publication Date: 2022.09.27 KNOWBE4 INC
  • US11457041B2 patent drawing
  • US11457041B2 patent drawing
  • US11457041B2 patent drawing

AI summary

Embodiments of the disclosure describe a simulated phishing campaign manager that communicates a simulated phishing communication that includes at least the telephone number and reference identifier, to a device of a user. The content of the simulated phishing communication may prompt the user to call the telephone number identified in the simulated phishing communication. The security awareness system may select a telephone number and a reference identifier to use for the simulated phishing communication, the combination of which may be later used to identify a specific user if they respond to the message. Each of a plurality of users may have a unique combination of telephone number and reference identifier. The telephone number may be selected based on the geographic location of the user, or the telephone number may be selected to correspond to content in a simulated phishing communication.