IP Library Granted Patent US 9,262,629
Granted Patent B2
US 9,262,629 · App. 14/160,443 · Granted Feb 16, 2016

Methods and systems for preventing malicious use of phishing simulation records

Inventors: Rohyt Belani (New York, NY); Aaron Higbee (Leesburg, VA); Scott Greaux (Glenmont, NY)
Assignee: PhishMe, Inc.
G06F21/55H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,262,629
App. No.
14/160,443
Granted
Feb 16, 2016
Kind
B2
Abstract

Described herein are methods, network devices and machine-readable media for preventing the malicious use of phishing simulation records. Phishing simulation records often times can reveal which individuals are most susceptible to phishing attacks. In the event that an attacker gains access to these records, the attacker can exploit such information to send phishing attacks to those individuals who are the most susceptible. To address such vulnerabilities, a phishing simulation record of an individual is only associated with an e-mail alias of the individual. Further, such e-mail alias may be deactivated after phishing simulations have been completed. Therefore, even if an attacker were able to identify individuals most susceptible to phishing attacks, the attacker will be unable to send any phishing attacks to those individuals since their e-mail aliases will have been deactivated.

Claims (36)

1. A computer-implemented method performed by a data processing apparatus, the method comprising:

for an individual, associating a phishing simulation record of the individual with an e-mail alias of the individual and associating the e-mail alias of the individual with a primary e-mail address of the individual;

sending via a computer network one or more simulated phishing messages to the individual via the e-mail alias associated with the individual;

generating a phishing simulation record based on a response by the individual to the one or more simulated phishing messages,

wherein, for the individual, the phishing simulation record of the individual is associated with the primary e-mail address of the individual only through the e-mail alias of the individual;

wherein, after sending the one or more messages, disassociating by a computer processor the primary e-mail address of the individual from the e-mail alias of the individual such that phishing susceptibility attribution is precluded for the individual.

2. The method of claim 1 , wherein the phishing simulation record comprises a measure of the corresponding individual's susceptibility to phishing attacks.

3. The method of claim 1 , further comprising determining which of the phishing simulation records has a measure of phishing susceptibility that exceeds a threshold.

4. The method of claim 1 , wherein the phishing simulation record comprises a total number of phishing simulations that the corresponding individual has fallen victim to.

5. The method of claim 4 , wherein if the total number of phishing simulations that the corresponding individual has fallen victim to exceeds a threshold, then sending via the computer network one or more simulated phishing messages to the individual.

6. The method of claim 1 , wherein the association between the e-mail aliases and the primary e-mail addresses is stored using encryption.

7. The method of claim 1 , wherein the association between the phishing simulation records and the e-mail aliases is stored in a first data store and the association between the e-mail aliases and the primary e-mail addresses is stored in a second data store, the first data store being separate from the second data store so that even if an attacker gains access to the first data store, the attacker does not automatically gain access to the second data store.

8. The method of claim 1 , further comprising:

upon detecting that one or more messages have been sent to an individual's e-mail alias, forwarding the one or more messages to the primary e-mail address of the individual.

9. The method of claim 1 , wherein the one or more messages comprise one or more of phishing simulations and training materials constructed to increase an individual's awareness of phishing attacks.

10. A network device, comprising:

a processor;

a storage device connected to the processor; and

a set of instructions on the storage device that, when executed by the processor, cause the processor to:

for an individual, associate a phishing simulation record of the individual with an e-mail alias of the individual and associate the e-mail alias of the individual with a primary e-mail address of the individual;

sending one or more simulated phishing messages to the individual via the e-mail alias associated with the individual;

generating a phishing simulation record based on a response by the individual to the one or more simulated phishing messages,

wherein, for the individual, the phishing simulation record of the individual is associated with the primary e-mail address of the individual only through the e-mail alias of the individual;

wherein, after sending the one or more messages, disassociating by a computer processor the primary e-mail address of the individual from the e-mail alias of the individual such that phishing susceptibility attribution is precluded for the individual.

11. A non-transitory machine-readable storage medium comprising software instructions that, when executed by a processor, cause the processor to:

for an individual, associate a phishing simulation record of the individual with an e-mail alias of the individual and associate the e-mail alias of the individual with a primary e-mail address of the individual;

sending one or more simulated phishing messages to the individual via the e-mail alias associated with the individual;

generating a phishing simulation record based on a response by the individual to the one or more simulated phishing messages,

wherein, for the individual, the phishing simulation record of the individual is associated with the primary e-mail address of the individual only through the e-mail alias of the individual;

wherein, after sending the one or more messages, disassociating by a computer processor the primary e-mail address of the individual from the e-mail alias of the individual such that phishing susceptibility attribution is precluded for the individual.

12. The method of claim 10 , the instructions further comprising instructions for determining which of the phishing simulation records has a measure of phishing susceptibility that exceeds a threshold.

13. The method of claim 10 , wherein the phishing simulation record comprises a total number of phishing simulations that the corresponding individual has fallen victim to.

14. The method of claim 10 , wherein if the total number of phishing simulations that the corresponding individual has fallen victim to exceeds a threshold, then sending via the computer network one or more simulated phishing messages to the individual.

15. The non-transitory machine-readable storage medium of claim 11 , the instructions further comprising instructions for determining which of the phishing simulation records has a measure of phishing susceptibility that exceeds a threshold.

16. The non-transitory machine-readable storage medium of claim 11 , wherein the phishing simulation record comprises a total number of phishing simulations that the corresponding individual has fallen victim to.

17. The non-transitory machine-readable storage medium of claim 11 , wherein if the total number of phishing simulations that the corresponding individual has fallen victim to exceeds a threshold, then sending via the computer network one or more simulated phishing messages to the individual.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE BLUE TORCH FINANCE LLC PREVIOUSLY RECORDED ON REEL 059800 FRAME 0834. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded May 5, 2023
From: COFENSE INC.
To: BLUE TORCH FINANCE LLC
Reel/Frame 064381/0245 →
RELEASE OF SECURITY INTEREST Recorded May 6, 2022
From: ORIX GROWTH CAPITAL, LLC
To: COFENSE INC.; COFENSE BIDCO CORPORATION
Reel/Frame 059864/0955 →
SECURITY INTEREST Recorded May 3, 2022
From: COFENSE INC.
To: BLUE TORCH CAPITAL LP
Reel/Frame 059800/0834 →
SECURITY INTEREST Recorded Oct 4, 2021
From: COFENSE BIDCO CORPORATION; COFENSE INC.
To: ORIX GROWTH CAPITAL, LLC, AS ADMINSTRATIVE AGENT
Reel/Frame 057692/0722 →
RELEASE OF SECURITY INTEREST Recorded Oct 3, 2019
From: SILICON VALLEY BANK
To: COFENSE, INC.
Reel/Frame 050616/0262 →
SECURITY INTEREST Recorded Sep 24, 2019
From: COFENSE INC.
To: ORIX GROWTH CAPITAL, LLC
Reel/Frame 050478/0889 →
MERGER AND CHANGE OF NAME Recorded Jan 15, 2019
From: PHISHME INC; POSEIDON MERGER SUB 2 INC; COFENSE INC
To: COFENSE INC
Reel/Frame 048016/0424 →
SECURITY INTEREST Recorded Nov 4, 2016
From: PHISHME INC.
To: SILICON VALLEY BANK
Reel/Frame 040222/0684 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 23, 2014
From: BELANI, ROHYT; HIGBEE, AARON; GREAUX, SCOTT
To: PHISHME, INC.
Reel/Frame 032032/0980 →
Continuity (1)
Related Publication 20150205953A1 · Jul 23, 2015