Static File Phishing Training via Client-Side Execution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing phishing training systems rely on third-party resources, limiting customization and authenticity, and require complex server-side technologies to track user interactions, making them costly and difficult to deploy across various environments.

Innovation Solution

Deploying static files with executable code on customer-controlled servers, accessible via a URL, which transmit interaction data back to the phishing training application provider, eliminating the need for server-side business logic and allowing for more authentic training campaigns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If entity-controlled resources are used to host training pages, then customization and authenticity are improved, but device complexity and deployment difficulty increase

Engineering Contradiction:
ImprovecustomizationVSAvoiddeployment complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the business logic and tracking functionality from the server-side environment and relocates it to client-side web browsers through static files with embedded executable code. This allows the training campaign to be hosted on simple entity-controlled resources without requiring complex server-side capabilities, resolving the contradiction between customization and deployment complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The static files contain self-contained executable code that automatically tracks user interactions and reports data back to the phishing training application. This self-service mechanism eliminates the need for complex server-side business logic, allowing entity-controlled resources to provide customization while maintaining simple deployment.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If server-side code execution is implemented for tracking, then measurement precision is improved, but device complexity and maintenance burden increase

Engineering Contradiction:
Improveinteraction tracking accuracyVSAvoidserver environment complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

Instead of implementing tracking logic on the server-side, the patent inverts the approach by embedding executable code in client-side static files. The user's web browser executes the tracking code locally, providing precise measurement of interactions while eliminating the need for complex server-side code execution environments.

Inventive Principle:
Principle #13The other way round (Inversion)

3Ease of operation

If third-party resources are used, then ease of deployment is improved, but adaptability and authenticity deteriorate

Engineering Contradiction:
Improvedeployment easeVSAvoidcampaign customization
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal solution where static files with embedded executable code can be deployed on any simple web server or hosting environment. This multi-functional approach allows entity-controlled resources to provide both the simplicity of third-party deployment and the customization of self-hosting, resolving the contradiction between ease of deployment and adaptability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11870806B1Phishing attack training systems and methods
Publication Date: 2024.01.09 RAPID7 INC
  • US11870806B1 patent drawing
  • US11870806B1 patent drawing
  • US11870806B1 patent drawing

AI summary

Systems and methods for user training. The systems and methods involve deploying at least one static file on a computing resource controlled by an operator, transmitting a URL to a target user, receiving a request for the URL from the target user, transmitting the at least one static file to the target user for execution in a web browser of the user, and receiving data regarding the execution of the at least one static file.