IP Library Granted Patent US 9,824,609
Granted Patent B2
US 9,824,609 · App. 15/389,506 · Granted Nov 21, 2017

Mock attack cybersecurity training system and methods

Inventors: Norman Sadeh-Koniecpol (Pittsburgh, PA); Kurt Wescoe (Pittsburgh, PA); Jason Brubaker (Mechanicsburg, PA); Jason Hong (Pittsburgh, PA)
Assignee: WOMBAT SECURITY TECHNOLOGIES, INC.
G09B19/0053G06F21/55G06F21/552G06F21/554G06F21/56G06F21/562G06F21/563G06F21/564G06F21/565G06F21/566G06F21/567G09B5/00G09B5/02H04L63/145H04L63/1425H04L63/1433H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,824,609
App. No.
15/389,506
Granted
Nov 21, 2017
Kind
B2
Abstract

A system assesses the susceptibility of an electronic device user to a cybersecurity threat by identifying information relating to the user of an electronic device, selecting a mock attack, and causing the mock attack to be deployed to the user so that the user receives the mock attack in the user's regular context of use of the electronic device. When a sensor detects a user action that the user has interacted with the electronic device in response to the mock attack, the system will record the sensed user action and use the sensed user action to determine the susceptibility of the user to a cybersecurity threat. In some embodiments, the lack of user action in response to a mock attack also may be used to determine the user's susceptibility to a cybersecurity threat.

Claims (85)

1. A computer-implemented method of assessing susceptibility of an electronic device user to a cybersecurity threat, the method comprising:

by one or more processors:

accessing identifying information relating to a user of an electronic device;

selecting a mock attack;

causing the mock attack to be deployed to the user so that the user receives the mock attack in the user's regular context of use of the electronic device;

receiving, from a sensor, a sensed user action in response to the mock attack, wherein the sensed user action comprises a user interaction with the electronic device;

recording the sensed user action;

using the sensed user action to determine a susceptibility of the user to a cybersecurity threat; and

generating one or more records that include the identifying information relating to the user, the susceptibility of the user to the cybersecurity threat, and the sensed user action in response to the mock attack.

2. The method of claim 1 , further comprising:

accessing a set of historical data for the user; and

when determining the susceptibility of the user to the cybersecurity threat, also using the historical data in the determining.

3. The method of claim 1 , wherein:

using the sensed user action to determine the susceptibility of the user to the cybersecurity threat comprises determining whether the user repeated a particular action at least a threshold number of times.

4. The method of claim 1 , wherein causing the mock attack to be deployed to the user in the user's regular context of use of the electronic device comprises luring the user to use the electronic device with at least one of the following:

a mock malicious memory device;

a mock malicious short-range tag;

a mock malicious barcode;

a piece of mock malware; or

a mock rogue, compromised or malfunctioning device or service.

5. The method of claim 1 , wherein:

the mock attack comprises a network service or device that broadcasts an availability message; and

the sensed user action comprises a request to connect the electronic device to the network service or device.

6. The method of claim 1 , wherein:

the mock attack comprises an attack that is configured to lure users to install fake malware; and

the sensed user action comprises a request to install fake malware on the electronic device.

7. The method of claim 1 , further comprising:

determining that the susceptibility of the user to the cybersecurity threat satisfies a rule to implement a training intervention;

selecting a training intervention that corresponds to one or more actions of the user; and

causing the electronic device to present the selected training intervention to the user.

8. The method of claim 7 , wherein:

using the sensed user action to determine the susceptibility of the user to the cybersecurity threat comprises using the sensed user action to identify a threat scenario for which the user is at risk; and

selecting the training intervention comprises:

identifying a collection of available training interventions that are relevant to the threat scenario, and

selecting from the collection, based on the identified threat scenario, the selected training intervention.

9. A computer-implemented method of assessing susceptibility of an electronic device user to a cybersecurity threat, the method comprising:

by one or more processors:

accessing identifying information relating to a user of an electronic device;

selecting a mock attack;

causing the mock attack to be deployed to the user so that the user receives the mock attack in the user's regular context of use of the electronic device;

by a sensor, sensing whether there is a user action that comprises a user interaction with the electronic device in response to the mock attack;

detecting, by the sensor, a lack of the user action in response to the mock attack, wherein the user action comprises a user interaction with the electronic device;

using the lack of the user action to determine a susceptibility of the user to a cybersecurity threat; and

generating one or more records that include the identifying information relating to the user and the susceptibility of the user to the cybersecurity threat.

10. The method of claim 9 , further comprising:

accessing a set of historical data for the user; and

when determining the susceptibility of the user to the cybersecurity threat, also using the historical data in the determining.

11. The method of claim 9 , wherein causing the mock attack to be deployed to the user in the user's regular context of use of the electronic device comprises luring the user to use the electronic device with at least one of the following:

a mock malicious memory device;

a mock malicious short-range tag;

a mock malicious barcode;

a piece of mock malware; or

a mock rogue, compromised or malfunctioning device or service.

12. The method of claim 9 , wherein:

the mock attack comprises a network service or device that broadcasts an availability message; and

the user action comprises a request to connect the electronic device to the network service or device.

13. The method of claim 9 , wherein:

the mock attack comprises an attack that is configured to lure users to install fake malware; and

the user action comprises a request to install fake malware on the device.

14. The method of claim 9 , further comprising:

determining that the susceptibility of the user to the cybersecurity threat satisfies a rule to implement a training intervention;

selecting a training intervention that corresponds to one or more actions of the user; and

causing the electronic device to present the selected training intervention to the user.

15. A computer-implemented method of providing cybersecurity training to a user of an electronic device, the method comprising:

by one or more processors: selecting a mock attack; causing the mock attack to be deployed to the user so that the user receives the mock attack in a regular context of use of the user;

receiving, from a sensor, a sensed user action in response to the mock attack; and

implementing a policy manager that:

uses the sensed user action to determine a susceptibility of the user to a cybersecurity threat;

based on the susceptibility of the user to the cybersecurity threat, selects a training intervention that corresponds to the sensed action; and

causes the selected training intervention to be presented to the user.

16. The method of claim 15 , further comprising:

receiving historical data for the user of the electronic device;

when determining the susceptibility of the user to a cybersecurity threat, also using the historical data to do so.

17. The method of claim 15 , wherein causing the mock attack comprises luring the user to use the electronic device with at least one of the following:

a mock malicious memory device;

a mock malicious short-range tag;

a mock malicious barcode;

a piece of mock malware; or

a mock rogue, compromised or malfunctioning device or service.

18. The method of claim 15 , wherein:

the mock attack comprises a network service or device that broadcasts an availability message; and

the sensed user action comprises a request to connect the electronic device to the network service or device.

19. The method of claim 15 , wherein:

the mock attack comprises an attack that lures users to install fake malware; and

the sensed user action comprises a request to install fake malware on the device.

Assignments (8)
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 8, 2025
From: PROOFPOINT, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 073889/0677 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Mar 21, 2024
From: GOLDMAN SACHS BANK USA, AS AGENT
To: PROOFPOINT, INC.
Reel/Frame 066865/0648 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 31, 2021
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057389/0642 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 31, 2021
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057389/0615 →
RELEASE OF SECURITY INTEREST Recorded May 24, 2021
From: WESTERN ALLIANCE BANK (D/B/A BRIDGE BANK)
To: WOMBAT SECURITY TECHNOLOGIES, INC.
Reel/Frame 056327/0658 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 19, 2019
From: WOMBAT SECURITY TECHNOLOGIES, INC.
To: PROOFPOINT, INC.
Reel/Frame 048632/0031 →
SECURITY INTEREST Recorded Jan 17, 2018
From: WOMBAT SECURITY TECHNOLOGIES, INC.
To: BRIDGE BANK, NATIONAL ASSOCIATION
Reel/Frame 044640/0360 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2017
From: SADEH-KONIECPOL, NORMAN; WESCOE, KURT; BRUBAKER, JASON; HONG, JASON
To: WOMBAT SECURITY TECHNOLOGIES, INC.
Reel/Frame 041117/0366 →
Continuity (9)
Continuation In Part 13442587 · Apr 9, 2012
Continuation 14216002 · Mar 17, 2014
Continuation In Part 13442587 · Apr 9, 2012
Continuation In Part 13832070 · Mar 15, 2013
Continuation 13442587 · Apr 9, 2012
Provisional Application 61473384 · Apr 8, 2011
Provisional Application 61473366 · Apr 8, 2011
Provisional Application 61793011 · Mar 15, 2013
Related Publication 20170103674A1 · Apr 13, 2017