Systems and user interfaces for dynamic and interactive investigation of bad actor behavior based on automatic clustering of related data in various data structures
US-9367872-B1 · Jun 14, 2016 · US
US9942249B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9942249-B2 |
| Application number | US-201514805719-A |
| Country | US |
| Kind code | B2 |
| Filing date | Jul 22, 2015 |
| Priority date | Jul 22, 2015 |
| Publication date | Apr 10, 2018 |
| Grant date | Apr 10, 2018 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
According to one embodiment, an apparatus is configured to communicate a first plurality of phishing emails to a first plurality of users, each phishing email of the first plurality of phishing emails is of a first type or a second type. The apparatus is configured to determine a first response rate of the first plurality of users to phishing emails of the first type and to determine a second response rate of the first plurality of users to phishing emails of the second type. The apparatus is configured to determine a second plurality of phishing emails comprising phishing emails of the first type and the second type, wherein an aggregate response rate of a second plurality of users to the second plurality of phishing emails is predicted to be closer to a target response rate than one or more of the first response rate and the second response rate.
Opening claim text (preview).
What is claimed is: 1. An apparatus comprising: a memory; and a processor communicatively coupled to the memory, the processor configured to: communicate a first plurality of phishing emails to a first plurality of users, each phishing email of the first plurality of phishing emails is of a first type or a second type; determine a first response rate of the first plurality of users to phishing emails of the first type; determine a second response rate of the first plurality of users to phishing emails of the second type; determine, based on the first and second response rates of the first plurality of users, a second plurality of phishing emails comprising phishing emails of the first type and the second type, wherein an aggregate response rate of a second plurality of users to the second plurality of phishing emails is predicted to be closer to a target response rate than one or more of the first response rate and the second response rate; communicate the second plurality of phishing emails to the second plurality of users, wherein the second plurality of phishing emails comprises a different number of phishing emails of the first type than the first plurality of phishing emails and a different number of phishing emails of the second type than the second plurality of phishing emails; determine the different number of phishing emails of the first type based on the first response rate; determine that a user of the first plurality of users previously received a phishing email of the first type, wherein, in response to the determination that the user previously received the phishing email of the first type, communicating the first plurality of phishing emails comprises communicating a phishing email of the second type to the user; and assign a score to the user of the first plurality of users based on whether the user responded to a phishing email of the first plurality of phishing emails, the score indicating how likely the user is to respond to another phishing email. 2. The apparatus of claim 1 , wherein the processor is further configured to communicate a subsequent phishing email to the first plurality of users who responded to a phishing email of the first plurality of phishing emails. 3. The apparatus of claim 1 , wherein the processor is further configured to track the users of the first plurality of users who responded to a phishing email of the first plurality of phishing emails. 4. The apparatus of claim 1 , wherein the first plurality of users comprises fewer users than the second plurality of users. 5. A method comprising: communicating a first plurality of phishing emails to a first plurality of users, each phishing email of the first plurality of phishing emails is of a first type or a second type; determining, by a processor, a first response rate of the first plurality of users to phishing emails of the first type; determining, by the processor, a second response rate of the first plurality of users to phishing emails of the second type; determining, by the processor, based on the first and second response rates of the first plurality of users, a second plurality of phishing emails comprising phishing emails of the first type and the second type, wherein an aggregate response rate of a second plurality of users to the second plurality of phishing emails is predicted to be closer to a target response rate than one or more of the first response rate and the second response rate; communicating the second plurality of phishing emails to the second plurality of users, wherein the second plurality of phishing emails comprises a different number of phishing emails of the first type than the first plurality of phishing emails and a different number of phishing emails of the second type than the second plurality of phishing emails; determining the different number of phishing emails of the first type based on the first response rate; determining that a user of the first plurality of users previously received a phishing email of the first type, wherein, in response to the determination that the user previously received the phishing email of the first type, communicating the first plurality of phishing emails comprises communicating a phishing email of the second type to the user; and assigning a score to the user of the first plurality of users based on whether the user responded to a phishing email of the first plurality of phishing emails, the score indicating how likely the user is to respond to another phishing email. 6. The method of claim 5 , further comprising communicating a subsequent phishing email to the first plurality of users who responded to a phishing email of the first plurality of phishing emails. 7. The method of claim 5 , further comprising tracking the users of the first plurality of users who responded to a phishing email of the first plurality of phishing emails. 8. The method of claim 5 , wherein the first plurality of users comprises fewer users than the second plurality of users. 9. A system comprising: a plurality of users; and a phishing management device configured to: communicate a first plurality of phishing emails to a first plurality of users, each phishing email of the first plurality of phishing emails is of a first type or a second type; determine a first response rate of the first plurality of users to phishing emails of the first type; determine a second response rate of the first plurality of users to phishing emails of the second type; determine, based on the first and second response rates of the first plurality of users, a second plurality of phishing emails comprising phishing emails of the first type and the second type, wherein an aggregate response rate of a second plurality of users to the second plurality of phishing emails is predicted to be closer to a target response rate than one or more of the first response rate and the second response rate; communicate the second plurality of phishing emails to the second plurality of users, wherein the second plurality of phishing emails comprises a different number of phishing emails of the first type than the first plurality of phishing emails and a different number of phishing emails of the second type than the second plurality of phishing emails; determine the different number of phishing emails of the first type based on the first response rate; determine that a user of the first plurality of users previously received a phishing email of the first type, wherein, in response to the determination that the user previously received the phishing email of the first type, communicating the first plurality of phishing emails comprises communicating a phishing email of the second type to the user; and assign a score to the user of the first plurality of users based on whether the user responded to a phishing email of the first plurality of phishing emails, the score indicating how likely the user is to respond to another phishing email. 10. The system of claim 9 , wherein the phishing management device is further configured to communicate a subsequent phishing email to the first plurality of users who responded to a phishing email of the first plurality of phishing emails. 11. The system of claim 9 , wherein the phishing management device is further configured to track the users of the first plurality of users who responded to a phishing email of the first plurality of phishing emails. 12. The system of claim 9 , wherein the first plurality of users comprises fewer users than the second plurality of users.
by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title
Electricity · mapped topic
service impersonation, e.g. phishing, pharming or web spoofing (detection of rogue wireless access points H04W12/12) · CPC title
User-to-user messaging in packet-switching networks, transmitted according to store-and-forward or real-time protocols, e.g. e-mail · CPC title
Electricity · mapped topic
Related publications grouped by family.
Answers are generated from the same data shown on this page.