Smart Groups for Dynamic Phishing Training

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security awareness training systems using static groups face inefficiencies and inaccuracies in managing user groups based on dynamic criteria, leading to workflow complexities and potential user misclassification.

Innovation Solution

The implementation of smart groups, which are dynamically created based on specified criteria, automatically identifies and manages user memberships at the time of use, eliminating the need for manual updates and reducing workflow complexities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If static groups are used for user management in security awareness training systems, then manual control over group membership is maintained, but workflow inefficiencies and user misclassification occur due to inability to automatically update groups based on changing criteria

Engineering Contradiction:
Improvemanual control over group membershipVSAvoidworkflow efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent transforms static user groups into dynamic groups that automatically update their membership based on changing criteria. The system continuously monitors user attributes and automatically adds or removes users from groups without manual intervention, resolving the contradiction between manual control and workflow efficiency by eliminating the need for repetitive manual updates while maintaining accurate group compositions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The dynamic group system performs self-updates by automatically evaluating users against group criteria and adjusting membership accordingly. The system serves itself by autonomously managing group compositions without requiring administrator intervention for each change, thereby improving productivity while maintaining operational control through predefined criteria.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If static groups are manually updated to reflect current user status, then accurate user classification can be achieved, but significant time and administrative effort are required

Engineering Contradiction:
Improveuser classification accuracyVSAvoidtime for manual updates
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system pre-establishes clear criteria for group membership that automatically reflect current user status. By defining these criteria in advance and implementing automatic evaluation mechanisms, the system ensures user classification accuracy is maintained continuously without requiring periodic manual updates, thereby eliminating the time loss associated with manual maintenance while preserving precision.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The dynamic group system implements continuous feedback loops where user attributes are monitored and automatically compared against group criteria. This real-time feedback mechanism ensures that user classification remains accurate by automatically detecting and responding to changes in user status, eliminating the need for manual verification while maintaining high precision in classification.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If multiple static groups are created to handle different user scenarios, then comprehensive coverage of user cases is achieved, but system complexity increases significantly

Engineering Contradiction:
Improvecoverage of user casesVSAvoidnumber of groups and management rules
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal dynamic group framework where a single group management mechanism handles all user scenarios through configurable criteria. Instead of creating multiple specialized static groups, the system uses one adaptable system that can evaluate users against different criteria sets, thereby maintaining comprehensive coverage of user cases while significantly reducing system complexity by eliminating the need for numerous separate groups and their associated management rules.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If workflows are designed to manually move users between static groups, then user progression through training stages can be tracked, but workflow inaccuracies and user misclassification occur

Engineering Contradiction:
Improveuser progression trackingVSAvoidworkflow accuracy
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent replaces the mechanical manual workflow of moving users between groups with an automated information-based system. The dynamic group system automatically evaluates user attributes against progression criteria and seamlessly transitions users between groups without manual intervention, thereby maintaining reliable user progression tracking while eliminating workflow inaccuracies and misclassification that occur with manual operations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentEP4044055B1Using smart groups for computer-based security awareness training systems
Publication Date: 2025.04.02 KNOWBE4 INC
  • EP4044055B1 patent drawingFigure 1A
  • EP4044055B1 patent drawingFigure 1B
  • EP4044055B1 patent drawingFigure 1C

AI summary

A system comprising: one or more servers (200) configured to: receive a selection of criteria for creating a group, the criteria for identifying one or more users from a plurality of users; establish the group comprising the criteria, the group configured to identify members of the group based on one or more users matching the criteria; receive an indication to use the group, the indication being a request to begin a simulated phishing campaign; determine, responsive to the indication, which one or more users of the plurality of users match the criteria of the group; execute the simulated phishing campaign using the group; and remove a user from the group responsive to the user interacting with a simulated phishing email that was sent as part of the simulated phishing campaign.