System and methods for automated detection, reasoning and recommendations for resilient cyber systems
US-2018103052-A1 · Apr 12, 2018 · US
US10855716B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-10855716-B2 |
| Application number | US-201916672715-A |
| Country | US |
| Kind code | B2 |
| Filing date | Nov 4, 2019 |
| Priority date | Feb 26, 2016 |
| Publication date | Dec 1, 2020 |
| Grant date | Dec 1, 2020 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A method for establishing a campaign for a simulated phishing attack includes receiving, via a campaign manager, specification of a plurality of parameters for a campaign including at least an identifier of a campaign and identification of users to which to send the campaign, establishing, via the campaign manager, a type of exploit for the campaign and one or more types of data to collect via the type of exploit, storing, by the campaign manager, the campaign comprising the plurality of parameters, and identifying, by a simulation server, the campaign stored in the database to create a simulated phishing email, to be sent to email accounts of the users, using the plurality of parameters of the campaign, wherein the simulated phishing email is to be created to have a link to a landing page comprising the type of exploit and configured to collect the one or more types of data.
Opening claim text (preview).
What is claimed is: 1. A system comprising: one or more processors, coupled to memory, and configured to receive identification of a type of exploit to use for a simulated phishing communication and one or more types of data to collect for the type of exploit; wherein the one or more processors are configured to create the simulated phishing communication with a link that is configured to cause execution of an application configured to simulate the type of exploit and collect the one or more types of data; wherein the one or more processors are configured to communicate the simulated communication email to email accounts of one or more users; and wherein responsive to interaction with the link, the application is executed and the one or more types of data collected by the application for the type of exploit are communicated to a server to identify a result of the type of exploit caused by the simulated phishing communication. 2. The system of claim 1 , wherein the application comprises a downloader to obtain one or more files to be executed to simulate the type of exploit. 3. The system of claim 1 , wherein the application comprises one of a Java application or a Flash Script. 4. The system of claim 2 , wherein the downloader is configured to obtain the one or more files over a network from a server. 5. The system of claim 2 , wherein the downloader is configured to receive a uniform resource location (URL) from which to download the one or more files. 6. The system of claim 2 , wherein the one or more files provides for one of installation or execution of the type of exploit. 7. The system of claim 1 , wherein the link is configured to traverse to a web page configured to cause execution of the application. 8. The system of claim 1 , wherein the application is configured to one of collect the one or more types of data or communicate the collected one or more types of data according to a timeframe corresponding to the type of exploit. 9. The system of claim 1 , wherein the one or more processors are configured to receive the identification of the type of exploit via a selection from a plurality of types of exploits provided by an interface. 10. The system of claim 1 , wherein the one or more processors are configured to receive the identification of one or more types of data via a selection from a plurality of types of data provided by an interface. 11. A system comprising: a database configured to store a plurality of campaigns configured for one or more simulated phishing attacks, wherein each of the plurality of campaigns identifies a type of exploit and a selection of one or more types of data to collect via configuration of the type of exploit; and a simulation server executable on one or more processors and configured to identify from the database a first campaign from the plurality of campaigns and create a first simulated phishing email with a first link to a first landing page comprising a first type of exploit and the first type of exploit configured to collect the selection of a first one or more types of data. 12. The system of claim 11 , wherein the simulation server is further configured to communicate the first simulated phishing email to one or more email accounts of one or more users. 13. The system of claim 11 , wherein the simulation server is further configured to identify from the database a second campaign from the plurality of campaigns. 14. The system of claim 13 , wherein the simulation server is further configured to create a second simulated phishing email with a second link to a second landing page comprising a second type of exploit and the second type of exploit configured to collect a selection of a second one or more types of data. 15. The system of claim 14 , wherein the simulation server is further configured to communicate the second simulated phishing email to one or more email accounts of one or more users. 16. The system of claim 12 , wherein the selection of the type of exploit from a plurality of types of exploits is received via an interface. 17. The system of claim 12 , wherein the selection of one or more types of data from a plurality of types of data for the type of exploit is received via an interface. 18. The system of claim 12 , wherein the one or more the types of data comprises one or more of the following types of data: user information, network information, system information and Light Directory Access Protocol (LDAP) information. 19. The system of claim 12 , wherein the simulation server is further configured to receive, responsive to traversal via the first link to the first landing page, data corresponding to the one or more types of data. 20. The system of claim 12 , wherein one of the landing page or the type of exploit is configured to collect the one or more types of data.
Vulnerability analysis · CPC title
service impersonation, e.g. phishing, pharming or web spoofing (detection of rogue wireless access points H04W12/12) · CPC title
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.