Systems and methods for performing a simulated phishing attack

US9800613B1 · US · B1

Patent metadata
FieldValue
Publication numberUS-9800613-B1
Application numberUS-201715636135-A
CountryUS
Kind codeB1
Filing dateJun 28, 2017
Priority dateJun 28, 2016
Publication dateOct 24, 2017
Grant dateOct 24, 2017

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

Systems and methods for performing a simulated phishing attack are provided. A simulated attack server can send a simulated attack email including a unique identifier to a target. The simulated attack server can receive a reply email including the unique identifier from the target. The simulated attack server can extract the unique identifier from the reply email. The simulated attack server can determine a match between the unique identifier and an identity of the target. The simulated attack server can record a target failure, responsive to determining the match between the unique identifier and the identity of the target.

First claim

Opening claim text (preview).

What is claimed is: 1. A method for identifying users that reply to a simulated phishing email, the method comprising: (a) establishing, by one or more servers comprising a processor coupled to memory, a unique identifier for each user of a plurality of users to receive a simulated phishing email via a simulated phishing campaign; (b) generating, by the one or more servers, for each user of the plurality of users a simulated phishing email to comprise the unique identifier of the respective user embedded in at least one of a subject line of the simulated phishing email, a body of the simulated phishing email or an attachment of the simulated phishing email; (c) communicating, by the one or more servers, the respective simulated phishing email to an email account corresponding to each user of the plurality of users, the respective simulated phishing email comprising an email address in a to field that corresponds to the one or more servers; (d) receiving, by the one or more servers, a reply email to the email address communicated responsive to the respective simulated phishing email from the email account of at least one user of the plurality of users, the reply email comprising the unique identifier; and (e) determining by the one or more servers, that the at least one user has replied to the simulated phishing email by comparing the unique identifier embedded in the reply email to the unique identifier established by the one or more servers for the at least one user. 2. The method of claim 1 , wherein (a) further comprises establishing, by the one or more servers, the unique identifier to identify a user corresponding to one or more email accounts. 3. The method of claim 1 , wherein (b) further comprises generating the simulated phishing email by embedding the unique identifier of the respective user to be invisible in the body of the simulated phishing email. 4. The method of claim 1 , wherein (b) further comprises generating the simulated phishing email by embedding the unique identifier of the respective user in a file name of the attachment. 5. The method of claim 1 , wherein (b) further comprises generating the simulated phishing email by embedding the unique identifier of the respective user in content of the attachment. 6. The method of claim 1 , wherein (d) further comprises receiving, by the one or more servers, the reply email sent to a domain of or hosted by the one or more servers. 7. The method of claim 1 , wherein (e) further comprises identifying, by the one or more servers, the unique identifier embedded in at least one of the subject line of the simulated phishing email, the body of the simulated phishing email or the attachment of the simulated phishing email. 8. A system for identifying users that reply to a simulated phishing email, the system comprising: one or more servers comprising a processor coupled to memory, and configured to establish a unique identifier for each user of a plurality of users to receive a simulated phishing email via a simulated phishing campaign; a campaign manager of the one or more servers configured to: generate for each user of the plurality of users a simulated phishing email to comprise the unique identifier of the respective user embedded in at least one of a subject line of the simulated phishing email, a body of the simulated phishing email or an attachment of the simulated phishing email; and communicate the respective simulated phishing email to an email account corresponding to each user of the plurality of users, the respective simulated phishing email comprising an email address in a to field that corresponds to the one or more servers; wherein the one or more servers are configured to receive a reply email to the email address communicated responsive to the respective simulated phishing email from the email account of at least one user of the plurality of users, the reply email comprising the unique identifier; and wherein the campaign manager is configured to determine that the at least one user has replied to the simulated phishing email by comparing the unique identifier embedded in the reply email to the unique identifier established by the one or more servers for the at least one user. 9. The system of claim 8 , wherein the one or more servers are further configured to establish the unique identifier to identify a user corresponding to one or more email accounts. 10. The system of claim 8 , wherein the campaign manager is further configured to generate the simulated phishing email by embedding the unique identifier of the respective user to be invisible in the body of the simulated phishing email. 11. The system of claim 8 , wherein the campaign manager is further configured to generate the simulated phishing email by embedding the unique identifier of the respective user in a file name of the attachment. 12. The system of claim 8 , wherein the campaign manager is further configured to generate the simulated phishing email by embedding the unique identifier of the respective user in content of the attachment. 13. The system of claim 8 , wherein the one or more servers are further configured to receive the reply email sent to a domain of or hosted by the one or more servers. 14. The system of claim 8 , wherein the campaign manager is further configured to identify the unique identifier embedded in at least one of the subject line of the simulated phishing email, the body of the simulated phishing email or the attachment of the simulated phishing email. 15. A method for identifying users that reply to a simulated phishing email, the method comprising: (a) establishing, by one or more servers comprising a processor coupled to memory, a unique identifier for each user of a plurality of users to receive a simulated phishing email via a simulated phishing campaign; (b) generating, by the one or more servers, for each user of the plurality of users a simulated phishing email to comprise the unique identifier of the respective user embedded in an email address of one of a plurality of address fields of the simulated phishing email; (c) communicating, by the one or more servers, the respective simulated phishing email to an email account corresponding to each user of the plurality of users, the respective simulated phishing email comprising an email address in a to field that corresponds to the one or more servers; (d) receiving, by the one or more servers, a reply email to the email address communicated responsive to the respective simulated phishing email from the email account of at least one user of the plurality of users, the reply email comprising the unique identifier in an address field of the plurality of address fields; and (e) determining by the one or more servers, that the at least one user has replied to the simulated phishing email by comparing the unique identifier embedded in the email address field of the reply email to the unique identifier established by the one or more servers for the at least one user. 16. The method of claim 15 , wherein (a) further comprises establishing, by the one or more servers, the unique identifier to identify one or more email accounts. 17. The method of claim 15 , wherein (b) further comprises generating the simulated phishing email by embedding the unique identifier of the respective user in a to field of the simulated phishing email. 18. The method of claim 15 , wherein (b) further comprises generating the simulated phishing email by embedding the unique identifier of the respective user in a cc field of the simulated phishing email

Assignees

Inventors

Classifications

  • service impersonation, e.g. phishing, pharming or web spoofing (detection of rogue wireless access points H04W12/12) · CPC title

  • Vulnerability analysis · CPC title

  • Commands or executable codes · CPC title

  • Electricity · mapped topic

  • Traffic logging, e.g. anomaly detection · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9800613B1 cover?
Systems and methods for performing a simulated phishing attack are provided. A simulated attack server can send a simulated attack email including a unique identifier to a target. The simulated attack server can receive a reply email including the unique identifier from the target. The simulated attack server can extract the unique identifier from the reply email. The simulated attack server ca…
Who is the assignee on this patent?
Knowbe4 Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1483. Mapped technology areas include Electricity.
When was this patent published?
Publication date Tue Oct 24 2017 00:00:00 GMT+0000 (Coordinated Universal Time) (B1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).