IP Library Granted Patent US 9,781,160
Granted Patent B1
US 9,781,160 · App. 15/610,513 · Granted Oct 3, 2017

Systems and methods for discovering suspect bot IP addresses and using validated bot IP address to ignore actions in a simulated phishing environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,781,160
App. No.
15/610,513
Granted
Oct 3, 2017
Kind
B1
Abstract

Methods, systems and apparatus are provided which allow a server of a security awareness system to associate IP addresses with events representing user interactions with simulated phishing campaigns. The server receives a plurality of events related to one or more simulated phishing campaigns for a plurality of accounts. The server determines if an IP address of the plurality of IP addresses is associated with one or more events for multiple accounts of the plurality of accounts. Based upon this determination, the server provides identification of the IP address as suspected as having the one or more events associated with it not originating from any user of the multiple accounts. The server receives an indication of whether the IP address is validated as having the one or more events originating from a bot instead of a user of one of the multiple accounts.

Claims (27)

1. A method for validating internet protocol addresses as having events originating from a user associated with an account, the method comprising

(a) receiving, by a server, a plurality of events comprising clicks of users on one or more links of one or more campaigns for a plurality of accounts and a plurality of internet protocol (IP) addresses of devices of the users clicking on the one or more links;

(b) determining, by the server, that an IP address of the plurality of IP addresses is associated with one or more events for multiple accounts of the plurality of accounts;

(c) providing, by the server based on at least the determination, identification of the IP address as suspected as having the one or more events not originating from any user of the multiple accounts; and

(d) receiving, by the server, an indication of whether the IP address is validated as having the one or more events originating from a bot instead of any user of one of the multiple accounts.

2. The method of claim 1 , wherein (a) further comprises receiving, by the server, the plurality of events comprising automatic clicks on one or more links of one or more campaigns from at least one of a network device or a software, and IP addresses of the at least one of the network device or the software.

3. The method of claim 1 , wherein (b) further comprises performing, by the server, one or more queries on a database comprising the plurality of events to determine which accounts of the plurality of accounts have events associated with the same IP address.

4. The method of claim 1 , wherein (b) further comprises determining, by the server, that a first account of the plurality of accounts has at least a first event associated with a first IP address and that a second account of the plurality of accounts has at least a second event associated with the first IP address.

5. The method of claim 1 , wherein (b) further comprises determining, by the server, a number of occurrences of the IP address across multiple accounts and a number of unique accounts of the plurality of accounts for which the IP address is associated.

6. The method of claim 1 , wherein (c) further comprises providing, by the server, a user interface to display identification of the IP addresses suspected as having the one or more events originating from a user of one of the multiple accounts.

7. The method of claim 1 , wherein (c) further comprises providing, by the server, a number of occurrences of the IP address across multiple accounts and a number of unique accounts of the plurality of accounts for which the IP address is associated.

8. The method of claim 1 , wherein (d) further comprises receiving, by the server, via a user interface the indication that the IP address is from a bot instead of a user of one of the multiple accounts.

9. The method of claim 1 , further comprising receiving, by the server, specification of a rule identifying whether the IP address is validated as a bot or a user and automatically determining, by the server, whether the rule overlaps with any other rules.

10. A system for validating internet protocol addresses as having events originating from a user associated with an account, the system comprising

a server comprising one or more processors, coupled to non-transitory memory, and configured to:

receive a plurality of events comprising clicks of users on one or more links of one or more campaigns for a plurality of accounts and a plurality of internet protocol (IP) addresses of devices of the users clicking on the one or more links;

determine that an IP address of the plurality of IP addresses is associated with one or more events for multiple accounts of the plurality of accounts;

provide identification, based on at least the determination, of the IP addresses suspected as having the one or more events not originating from any user of the multiple accounts; and

receive an indication of whether the IP address is validated as having the one or more events originating from a bot instead of any user of one of the multiple accounts.

11. The system of claim 10 , wherein the plurality of events comprises automatic clicks on one or more links of one or more campaigns from at least one of a network device or a software, and IP addresses of the at least one of the network device or the software.

12. The system of claim 10 , wherein the server is further configured to perform one or more queries on a database comprising the plurality of events to determine which accounts of the plurality of accounts have events associated with the same IP address.

13. The system of claim 10 , wherein the server is further configured to determine that a first account of the plurality of accounts has at least a first event associated with a first IP address and that a second account of the plurality of accounts has at least a second event associated with the first IP address.

14. The system of claim 10 , wherein the server is further configured to determine a number of occurrences of the IP address across multiple accounts and a number of unique accounts of the plurality of accounts for which the IP address is associated.

15. The system of claim 10 , wherein the server is further configured to provide a user interface to display identification of the IP addresses suspected as having the one or more events originating from a user of one of the multiple accounts.

16. The system of claim 10 , wherein the server is further configured to provide a number of occurrences of the IP address across multiple accounts and a number of unique accounts of the plurality of user accounts for which the IP address is associated.

17. The system of claim 10 , wherein the server is further configured to receive via a user interface the indication that the IP address is from the user of one of the multiple accounts.

18. The system of claim 10 , wherein the server is further configured to establish a rule identifying whether the IP address is validated as a bot or a user and automatically determine whether the rule overlaps with any other rules.

Assignments (7)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL/FRAME NO.: 056885/0889 Recorded Feb 2, 2023
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: KNOWBE4, INC.
Reel/Frame 062625/0841 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Mar 12, 2021
From: KNOWBE4, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 056885/0889 →
CORRECTIVE ASSIGNMENT TO CORRECT THE NAME OF THE SECOND CONVEYING PARTY PREVIOUSLY RECORDED ON REEL 042558 FRAME 0953. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Aug 17, 2017
From: KRAS, GREG; IRIMIE, ALIN
To: KNOWBE4, INC.
Reel/Frame 043582/0826 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 1, 2017
From: KRAS, GREG; IRIMIE, ALAN
To: KNOWBE4, INC.
Reel/Frame 042558/0953 →