IP Library Granted Patent US 9,224,117
Granted Patent B2
US 9,224,117 · App. 13/934,850 · Granted Dec 29, 2015

Software service to facilitate organizational testing of employees to determine their potential susceptibility to phishing scams

Inventor: Mark T. Chapman (Muskego, WI)
Assignee: Phishline, LLC
G06Q10/0635G06Q10/107H04L63/1483H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,224,117
App. No.
13/934,850
Granted
Dec 29, 2015
Kind
B2
Abstract

A software system and service for facilitating organizational testing of employees in order to determine their potential susceptibility to phishing scams is disclosed to evaluate their susceptibility to e-mail and Internet cybercrimes such as phishing. The e-mail addresses of a client organization's employees are provided to the system, a phishing e-mail is created and customized, and a phishing e-mail campaign in which the phishing e-mail message is sent and the responses to the phishing e-mail is monitored, and the results of the e-mail campaign are provided for evaluation. The phishing e-mail may optionally contain attachments and various types of probes and “call home” mechanisms.

Claims (33)

1. A system for facilitating an information technology administrator of a client organization to assess the potential susceptibility of employees of the client organization to phishing scams, the system comprising:

an appliance comprising at least one processor device that is accessible by the information technology administrator of a client organization to set up a phishing e-mail campaign, the appliance comprising:

a first module configured to facilitate entry of the e-mail addresses of a group of individuals into one or more address books;

a second module configured to facilitate creation of a phishing e-mail that includes at least a link;

a third module configured to facilitate creation of a web page accessible by a recipient of the phishing e-mail by clicking on the link included in the phishing e-mail;

a fourth module configured to facilitate establishment of a campaign by selecting and correlating at least one address book and at least one phishing e mails e-mail to be sent;

a fifth module configured to execute the campaign by sending the phishing e-mail(s) to the group of individuals in the address book(s);

a sixth module configured to monitor responses to the phishing e-mail(s) by recipients of phishing e-mail(s) who respond by providing potentially confidential information, the sixth module further configured to instruct an employee's web browser to profile potentially confidential information provided by recipients of phishing e-mail(s) and to avoid collecting potentially confidential information provided by recipients of phishing e-mail(s); and

a seventh module configured to provide analysis of responses to the phishing e-mail(s) for review by the information technology administrator.

2. The system defined in claim 1 , wherein the phishing e-mail created by the e-mail manager module contains a call-home probe macro, which call-home probe macro may selectively be either signed or unsigned.

3. The system defined in claim 1 , wherein the sixth module is configured to monitor automatic responses to phishing e-mail including at least a received by e-mail recipient's server response, a read by e-mail recipient response, and an out-of-office response.

4. The system defined in claim 1 , wherein the potentially confidential information provided by recipients of phishing e-mails comprise at least one of the activities from the group consisting of clicking on a link included in a received phishing e-mail, submitting data in a web form in response to the phishing e-mail, uploading a file in response to the phishing e-mail, submitting a login form, submitting a non-blank password on a login form, submitting a value in a Captcha form field, or providing another response to a received phishing e-mail.

5. The system defined in claim 1 , wherein the seventh module is configured to provide at least one of:

an outbound analysis for each phishing e-mail scheduled for sending by the campaign manager module, the outbound analysis indicating whether the phishing e-mail is Queued, Sending, Sent, or Late;

an inbound analysis for each phishing e-mail sent, the inbound analysis indicating the e-mail address of the responding e-mail, a size of the responding e-mail, and its time stamp;

a number of web activities, that were each caused by the recipient of the phishing e-mail having one access to a web page resource by a browser or e-mail client responding to the phishing e-mail;

an indication of whether the recipient of the phishing e-mail opened a web page or submitted a web form in response to the phishing e-mail;

an indication of whether the recipient of the phishing e-mail requested an individual image, downloaded a file, or uploaded a form in response to the phishing e-mail;

an indication of whether the recipient of the phishing e-mail submitted a login form, a non-blank password on a login form, or a feedback form; and

an indication of whether the recipient of the phishing e-mail viewed a web page containing an action Captcha request or submitted a value in a Captcha form field.

6. The system defined in claim 1 , wherein the seventh module is configured to indicate at least one of:

whether a response has been received for the phishing e-mail indicating that it has been bounced, indicating that the phishing e-mail was undeliverable;

whether a response has been received for the phishing e-mail indicating that the recipient of the phishing e-mail is out-of-office; and

whether a response has been received to the phishing e-mail from the recipient of the phishing e-mail;

wherein the one or more address books include attributes regarding the individuals correlated with each of the e-mail addresses; and

wherein the fourth module is configured to sort e-mail addresses in the one or more address books based on attributes.

7. A system for facilitating an information technology administrator of a client organization to assess the potential susceptibility of employees of the client organization to phishing scams, the system comprising:

an appliance comprising at least one processor device that is accessible by the information technology administrator of a client organization to set up a phishing e-mail campaign, the appliance comprising:

an address book manager module configured to facilitate the input by the information technology administrator of the e-mail addresses of the group of individuals into one or more address books;

an e-mail manager module configured to facilitate the creation by the information technology administrator of at least one phishing e-mail;

a message generation module configured to execute a campaign by sending the phishing e-mails to the group(s) of individuals in the address book(s);

a monitoring module configured to monitor responses to the phishing e-mails by interacting with recipients of phishing e-mails who respond by providing potentially confidential information while avoiding collecting potentially confidential information provided by recipients of phishing e-mails; and

a report generating module configured to provide analysis of responses to the phishing e-mails, including analysis of a characteristic of the information provided by the recipients of phishing e-mails who respond, for review by the information technology administrator.

Assignments (10)
SECURITY INTEREST Recorded Mar 17, 2025
From: BARRACUDA NETWORKS, INC.
To: OAKTREE FUND ADMINISTRATION, LLC, AS COLLATERAL AGENT
Reel/Frame 070529/0123 →
SECURITY INTEREST Recorded Sep 3, 2022
From: BARRACUDA NETWORKS, INC.
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 061377/0208 →
SECURITY INTEREST Recorded Sep 3, 2022
From: BARRACUDA NETWORKS, INC.
To: KKR LOAN ADMINISTRATION SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 061377/0231 →
RELEASE OF SUPPLEMENTAL FIRST LIEN SECURITY INTEREST IN IP RECORDED AT R/F 054260/0605 Recorded Aug 16, 2022
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: BARRACUDA NETWORKS, INC.
Reel/Frame 061179/0896 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN IP RECORDED AT R/F 054260/0746 Recorded Aug 16, 2022
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: BARRACUDA NETWORKS, INC.
Reel/Frame 061521/0086 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Oct 30, 2020
From: BARRAUDA NETWORKS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 054260/0746 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT SUPPLEMENT Recorded Oct 30, 2020
From: BARRAUDA NETWORKS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 054260/0605 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 15, 2018
From: CHAPMAN TECHNOLOGY GROUP, INC.; PHISHLINE, LLC
To: BARRACUDA NETWORKS, INC.
Reel/Frame 044946/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 14, 2015
From: CHAPMAN TECHNOLOGY GROUP, INC.
To: PHISHLINE, LLC
Reel/Frame 035407/0993 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 3, 2013
From: CHAPMAN, MARK T.
To: CHAPMAN TECHNOLOGY GROUP, INC.
Reel/Frame 030736/0700 →
Continuity (2)
Continuation 13360420 · Jan 27, 2012
Related Publication 20130297375A1 · Nov 7, 2013