Serving Module for Phishing Campaign Clustering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security awareness systems are inadequate in training users to detect sophisticated and personalized phishing attacks, as they fail to create a simulated environment that mimics real-world phishing scenarios effectively, leading to inconsistent training outcomes across different users.

Innovation Solution

An AI-driven security awareness system that uses machine learning algorithms to adaptively design and execute simulated phishing campaigns by classifying users into clusters based on their attributes and behavior, tailoring the campaign's design, frequency, and content to mimic real-world phishing attacks, including emails, SMS, and VoIP messages.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single simulated phishing attack template is used for all users, then the system complexity is reduced and ease of operation is improved, but the adaptability to different user behaviors and the effectiveness of training are worsened

Engineering Contradiction:
Improveease of operating the systemVSAvoidadaptability to different user behaviors
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The system segments users into different clusters based on their behavior patterns, attributes, and responses to phishing attempts. By dividing the user base into distinct groups (e.g., tech-savvy users, less tech-savvy users, department-specific clusters), the system can apply different simulated phishing templates to each segment, thereby improving adaptability while maintaining operational simplicity through automated classification.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically adjusts the simulated phishing templates based on real-time user behavior and historical data. Machine learning algorithms continuously learn from user interactions and automatically modify which templates are deployed to which users, enabling the system to adapt to changing user patterns without manual reconfiguration, thus balancing adaptability with ease of operation.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If multiple customized simulated phishing templates are created for different user segments, then the adaptability and training effectiveness are improved, but the device complexity and time required for campaign setup increase

Engineering Contradiction:
Improveadaptability to different user behaviorsVSAvoidcomplexity of the system
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system employs machine learning algorithms that automatically perform user classification, template selection, and campaign configuration without requiring manual intervention. The system serves itself by autonomously analyzing user data, identifying patterns, and deploying appropriate simulated phishing templates, thereby reducing the perceived complexity for operators while maintaining high adaptability.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system changes parameters such as user clustering criteria, template selection rules, and campaign timing based on learned patterns from historical data. By dynamically adjusting these parameters through machine learning, the system achieves high adaptability without requiring complex manual configuration, as the parameters are automatically optimized based on observed user behaviors.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If simulated phishing campaigns are sent frequently to all users, then the productivity of security training is improved, but the loss of user engagement and potential annoyance increase

Engineering Contradiction:
Improveproductivity of security trainingVSAvoiduser engagement and tolerance
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The system applies different messaging frequencies and campaign intensities to different user clusters based on their specific needs and risk profiles. For example, users who consistently fail phishing tests may receive more frequent targeted campaigns, while users who demonstrate good security awareness receive less frequent reinforcement, thereby optimizing training productivity while preserving user engagement by avoiding excessive messaging for low-risk users.

Inventive Principle:
Principle #3Local quality

4Measurement precision

If the system collects and analyzes extensive user behavior data, then the measurement precision and model accuracy are improved, but the loss of time for data processing and computational resources increase

Engineering Contradiction:
Improveprecision of user classificationVSAvoidtime for data processing
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-processing and storing user behavior data as it is generated, organizing it into structured formats suitable for machine learning analysis. By preparing the data in advance and maintaining it in ready-to-analyze states, the system reduces the computational burden during actual classification tasks, thereby improving measurement precision without proportionally increasing processing time when campaigns need to be deployed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10348762B2Systems and methods for serving module
Publication Date: 2019.07.09 KNOWBE4 INC
  • US10348762B2 patent drawing
  • US10348762B2 patent drawing
  • US10348762B2 patent drawing

AI summary

Systems and methods are described for selecting a model for a simulated phishing campaign for a user based on classifying a user into a cluster of a plurality of clusters. A campaign controller may initiate a simulated phishing campaign for a user. In some examples, while initiating the simulated phishing campaign the campaign controller identifies a plurality of attributes of the user and/or a plurality of attributes of a company of the user, and sends the plurality of attributes to a serving module of the campaign controller. The serving module receives historical information on activity associated with the user during previous simulated phishing campaigns. The serving module uses the historical information as input into one or more clustering models and using the model, classifies the user into a cluster which contains users that are responsive to one or more specific models.