IP Library Granted Patent US 9,674,221
Granted Patent B1
US 9,674,221 · App. 15/418,709 · Granted Jun 6, 2017

Collaborative phishing attack detection

Inventors: Aaron Higbee (Leesburg, VA); Rohyt Belani (New York, NY); Scott Greaux (Glenmont, NY)
Assignee: PhishMe, Inc.
H04L63/1483H04L63/1416H04L63/1425H04L63/1433H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,674,221
App. No.
15/418,709
Granted
Jun 6, 2017
Kind
B1
Abstract

Described herein are methods, network devices and machine-readable storage media for detecting whether a message is a phishing attack based on the collective responses from one or more individuals who have received that message. The individuals may flag the message as a possible phishing attack, and/or may provide a numerical ranking indicating the likelihood that the message is a possible phishing attack. As responses from different individuals may have a different degree of reliability, each response from an individual may be weighted with a corresponding trustworthiness level of that individual, in an overall determination as to whether a message is a phishing attack. A trustworthiness level of an individual may indicate a degree to which the response of that individual can be trusted and/or relied upon, and may be determined by how well that individual recognized simulated phishing attacks.

Claims (45)

1. A method for identifying and processing email messages received at a remote computing device in connection with a simulated phishing email campaign, comprising:

generating, by a network device, a simulated phishing email, wherein the simulated phishing email is a non-malicious email that resembles a real phishing attack by attempting to lure an individual into performing a target action on the remote computing device, wherein the simulated phishing email comprises at least one embedded hyperlink, and wherein if the individual performs the target action, performance of the target action does not compromise the remote computing device or personal information of the individual;

causing the simulated phishing email to be transmitted over a communications network to the remote computing device, the simulated phishing email comprising an identifying header, wherein the identifying header designates the simulated phishing email as a non-malicious simulated phishing email sent by the network device;

providing a plug-in for an email client at the remote computing device, the plug-in configurable for executing computer instructions for receiving a graphical user interface action performed by the individual indicating that an email, the email being either the simulated phishing email or another email, delivered in an email account associated with the individual has been identified by the individual as a possible phishing attack;

determining whether the identified email is a known simulated phishing attack by comparing one or more headers of the identified email to information identifying at least one known simulated phishing attack;

when the identified email is determined to be a known simulated phishing attack based on the comparison of the one or more headers of the identified email to information identifying at least one known simulated phishing attack, providing a graphically displayed feedback to the individual confirming that the identified email was a simulated phishing attack; and

when the identified email is determined not to be a known simulated phishing attack based on the comparison of the one or more headers of the identified email to the information identifying at least one known simulated phishing attack, sending the identified email for analysis or detection of whether or not the identified email is a phishing attack;

providing a graphical user interface element that, when selected, causes a notification to be sent to the network device, the notification triggered by the user interface action by the individual that the email delivered in the email account associated with the individual has been identified by the individual as a possible phishing attack;

receiving the notification over the communications network by the network device from the remote computing device;

if the identified email is determined to be a known simulated phishing attack based on the comparison of the one or more headers of the identified email to information identifying at least one known simulated phishing attack, electronically recording data indicating that the email has been identified as a simulated phishing attack;

if the identified email is determined not to be a known simulated phishing attack based on the comparison of the one or more headers of the identified email to information identifying at least one known simulated phishing attack, electronically recording data indicating that the email has been identified as a potential phishing attack;

causing the provisioning of an electronic training to the individual if the individual clicks on the embedded hyperlink in the simulated phishing email; and

if the email has been identified as a potential phishing attack, computing a likelihood that the identified email is a real phishing attack or is not a real phishing attack based on one or more attributes associated with the identified email.

2. The method of claim 1 , wherein sending the identified email for analysis or detection further comprises sending the identified email to a computer security technician for analysis to determine if the identified email is a real phishing attack or not.

3. The method of claim 1 , wherein sending the identified email for analysis or detection further comprises sending the identified email to computer configured to detect phishing attacks to determine if the identified email is a real phishing attack or not.

4. The method of claim 1 , wherein if the identified email is determined not to be a known simulated phishing attack, and analysis or detection of the identified email results in a determination that the identified email is a real phishing attack, providing feedback to the individual that identified the identified email as a possible phishing attack confirming that the identified email was a real phishing attack.

5. The method of claim 1 , wherein a single graphical user interface action performed by the individual is sufficient to trigger the notification to be sent from the computing device of the individual.

6. The method of claim 1 , wherein the plugin is further configurable to provide a graphical user interface element comprising a button that, when selected, automatically sends the notification to the network device by one click or touch of the button.

7. The method of claim 1 , further comprising searching through a log of simulated phishing attacks to determine whether the identified email is a simulated phishing attack.

8. The method of claim 1 , wherein sending the identified email for analysis or detection further comprises sending the identified email in its entirety.

9. The method of claim 1 , further comprising computing a likelihood that the identified email is a real phishing attack based on a history of the individual in identifying previous simulated phishing attacks as suspicious.

10. The method of claim 1 , further comprising computing a likelihood that the identified email is a real phishing attack based a quantitative trustworthiness level assigned to the individual.

11. A system for identifying and processing email messages received at a remote computing device in connection with a simulated phishing email campaign, comprising:

a network device configured for:

generating a simulated phishing email wherein the simulated phishing email is a non-malicious email that resembles a real phishing attack by attempting to lure an individual into performing a target action on the remote computing device, wherein the simulated phishing email comprises at least one embedded hyperlink, and wherein if the individual performs the target action, performance of the target action does not compromise the remote computing device or personal information of the individual;

causing the simulated phishing email to be transmitted over a communications network to the remote computing device, the simulated phishing email comprising an identifying header, wherein the identifying header designates the simulated phishing email as a non-malicious simulated phishing email sent by the network device;

if the identified email is determined to be a known simulated phishing attack based on a comparison of the one or more headers of the identified email to information identifying at least one known simulated phishing attack, electronically recording data indicating that the email has been identified as a simulated phishing attack;

if the identified email is determined not to be a known simulated phishing attack based on the comparison of the one or more headers of the identified email to information identifying at least one known simulated phishing attack, electronically recording data indicating that the email has been identified as a potential phishing attack; and

causing the provisioning of an electronic training to the individual if the individual clicks on the embedded hyperlink in the simulated phishing email; and

if the email has been identified as a potential phishing attack, computing a likelihood that the identified email is a real phishing attack or is not a real phishing attack based on one or more attributes associated with the identified email;

the remote computing device configured for:

executing a plug-in for an email client at the remote computing device for receiving a graphical user interface action performed by the individual indicating that an email, the email being either the simulated phishing email or another email, delivered in an email account associated with the individual has been identified by the individual as a possible phishing attack;

determining whether the identified email is a known simulated phishing attack by comparing one or more headers of the identified email to information identifying at least one known simulated phishing attack;

when the identified email is determined to be a known simulated phishing attack based on the comparison of the headers of the identified email to information identifying at least one known simulated phishing attack, providing a graphically displayed feedback to the individual confirming that the identified email was a simulated phishing attack;

when the identified email is determined not to be a known simulated phishing attack based on the comparison of the one or more headers to the information identifying at least one known simulated phishing attack, sending the identified email for analysis or detection of whether or not the identified email is a phishing attack; and

wherein the remote computing device is further configurable to provide a graphical user interface element that, when selected, causes a notification to be sent to the network device, the notification triggered by the user interface action by the individual that the email delivered in the email account associated with the individual has been identified by the individual as a possible phishing attack.

12. The system of claim 11 , wherein sending the identified email for analysis or detection further comprises sending the identified email to a computer security technician for analysis to determine if the identified email is a real phishing attack or not.

13. The system of claim 11 , wherein sending the identified email for analysis or detection further comprises sending the identified email to computer configured to detect phishing attacks to determine if the identified email is a real phishing attack or not.

14. The system of claim 11 , wherein if the identified email is determined not to be a known simulated phishing attack, and analysis or detection of the identified email results in a determination that the identified email is a real phishing attack, providing feedback to the individual that identified the identified email as a possible phishing attack confirming that the identified email was a real phishing attack.

15. The system of claim 11 , wherein a single graphical user interface action performed by the individual is sufficient to trigger the notification to be sent from the computing device of the individual.

16. The system of claim 11 , wherein a plugin provided for email client at the remote computing device is further configurable to provide a graphical user interface element comprising a button that, when selected, automatically sends the notification to the network device by one click or touch of the button.

17. The system of claim 11 , further comprising searching through a log of simulated phishing attacks to determine whether the identified email is a simulated phishing attack.

18. The system of claim 11 , wherein sending the identified email for analysis or detection further comprises sending the identified email in its entirety.

19. The system of claim 11 , further comprising computing a likelihood that the identified email is a real phishing attack based on a history of the individual in identifying previous simulated phishing attacks as suspicious.

20. The system of claim 11 , further comprising computing a likelihood that the identified email is a real phishing attack based a quantitative trustworthiness level assigned to the individual.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE BLUE TORCH FINANCE LLC PREVIOUSLY RECORDED ON REEL 059800 FRAME 0834. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded May 5, 2023
From: COFENSE INC.
To: BLUE TORCH FINANCE LLC
Reel/Frame 064381/0245 →
RELEASE OF SECURITY INTEREST Recorded May 6, 2022
From: ORIX GROWTH CAPITAL, LLC
To: COFENSE INC.; COFENSE BIDCO CORPORATION
Reel/Frame 059864/0955 →
SECURITY INTEREST Recorded May 3, 2022
From: COFENSE INC.
To: BLUE TORCH CAPITAL LP
Reel/Frame 059800/0834 →
SECURITY INTEREST Recorded Oct 4, 2021
From: COFENSE BIDCO CORPORATION; COFENSE INC.
To: ORIX GROWTH CAPITAL, LLC, AS ADMINSTRATIVE AGENT
Reel/Frame 057692/0722 →
RELEASE OF SECURITY INTEREST Recorded Oct 3, 2019
From: SILICON VALLEY BANK
To: COFENSE, INC.
Reel/Frame 050616/0262 →
SECURITY INTEREST Recorded Sep 24, 2019
From: COFENSE INC.
To: ORIX GROWTH CAPITAL, LLC
Reel/Frame 050478/0889 →
MERGER AND CHANGE OF NAME Recorded Jan 15, 2019
From: PHISHME INC; POSEIDON MERGER SUB 2 INC; COFENSE INC
To: COFENSE INC
Reel/Frame 048014/0092 →
FIRST SUPPLEMENT TO INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Sep 14, 2017
From: PHISHME INC.
To: SILICON VALLEY BANK
Reel/Frame 043862/0961 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2017
From: GREAUX, SCOTT; BELANI, ROHYT; HIGBEE, AARON
To: PHISHME, INC.
Reel/Frame 042617/0280 →
Continuity (6)
Continuation 15138188 · Apr 25, 2016
Continuation 14620245 · Feb 12, 2015
Continuation 13958480 · Aug 2, 2013
Continuation In Part 13918702 · Jun 14, 2013
Continuation In Part 13785252 · Mar 5, 2013
Continuation 13763538 · Feb 8, 2013