IP Library Granted Patent US 11,494,719
Granted Patent B2
US 11,494,719 · App. 16/867,953 · Granted Nov 8, 2022

Systems and methods for using artificial intelligence driven agent to automate assessment of organizational vulnerabilities

Inventors: Alin Irimie (Clearwater, FL); Stu Sjouwerman (Bellair, FL); Greg Kras (Dunedin, FL); Eric Sites (Clearwater, FL)
Assignee: KnowBe4, Inc.
G06Q10/0635H04L63/1433H04L63/1483H04L63/1491
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,494,719
App. No.
16/867,953
Granted
Nov 8, 2022
Kind
B2
Abstract

The present disclosure describes systems and method for performing a vulnerabilities assessment of an organization. A campaign controller executes one or more simulated phishing campaigns directed to a plurality of users of an organization, using a plurality of models determined by the campaign controller based at least on identification of the organization. The campaign controller stores to a database the results of execution of the one or more simulated phishing campaigns and based on the results, the campaign controller determines one or more vulnerabilities to phishing for the organization. In one embodiment, the campaign controller determines a percentage of the plurality of users of the organization that are phish-prone. In some embodiments, the users of the organization that are phish-prone interacted with a link of a simulated phishing communication.

Claims (29)

1. A method comprising:

receiving, by one or more processors, an identification of an entity;

selecting, by the one or more processors, based on at least identification of the entity, one or more models from a plurality of models to use for the entity to configure one or more simulated phishing campaigns directed to users associated with the entity, the plurality of models comprising one of an artificial intelligence or machine learning model trained with results from one or more previous simulated phishing campaigns and configured to specify to the one or more processors how to configure one or more new simulated phishing campaigns;

executing, by the one or more processors using the selected one or more models, the one or more simulated phishing campaigns configured using the one or more selected models; and

determining, by the one or more processors, one or more vulnerabilities of the entity based at least on results of execution of the one or more simulated phishing campaigns.

2. The method of claim 1 , further comprising receiving, by the one or more processors, via a user interface the identification of the entity and one or more attributes of the entity.

3. The method of claim 1 , further comprising identifying, by the one or more processors, one or more attributes of the entity.

4. The method of claim 1 , further comprising selecting, by the one or more processors, the one or more models from the plurality of models using one or more attributes of the entity.

5. The method of claim 1 , further comprising identifying, by the one or more processors, one or more attributes of users associated with the entity.

6. The method of claim 1 , further comprising selecting, by the one or more processors, the one or more models from the plurality of models using one or more attributes of the users.

7. The method of claim 1 , where the one or more models comprises a template selected from a plurality of templates for the simulated phishing campaign.

8. The method of claim 1 , further comprising determining as the one or more vulnerabilities a percentage of users that are phish-prone.

9. The method of claim 8 , wherein the percentage of users that are phish-prone comprises a number of the users that interacted with a simulated phishing communication.

10. The method of claim 1 , wherein the one or more vulnerabilities causing one or more of the users of to interact with a simulated phishing communication includes one or more of the following: a type of the simulated phishing communication, a type of exploit used by the simulated phishing communication, content of the simulated phishing communication and timing of or between simulated phishing communications.

11. A system comprising:

one or more processors, coupled to memory and configured to:

receive an identification of an entity;

selecting, based on at least identification of the entity, one or more models from a plurality of models to use for the entity to configure one or more simulated phishing campaigns directed to users associated with the entity, wherein the plurality of models comprises one of an artificial intelligence or machine learning model trained with results from one or more previous simulated phishing campaigns and configured to specify to the one or more processors how to configure one or more new simulated phishing campaigns;

execute, using the selected one or more models, one or more simulated phishing campaigns configured using the one or more selected models; and

determine one or more vulnerabilities of the entity based at least on results of execution of the one or more simulated phishing campaigns.

12. The system of claim 11 , wherein the one or more processors are further configured to receive via a user interface the identification of the entity and one or more attributes of the entity.

13. The system of claim 11 , wherein the one or more processors are further configured to identify one or more attributes of the entity.

14. The system of claim 11 , wherein the one or more processors are further configured to select the one or more models from the plurality of models using one or more attributes of the entity.

15. The system of claim 11 , wherein the one or more processors are further configured to identify one or more attributes of users associated with the entity.

16. The system of claim 11 , wherein the one or more processors are further configured to select the one or more models from the plurality of models using one or more attributes of the users.

17. The system of claim 11 , where the one or more models comprise a template selected from a plurality of templates for the simulated phishing campaign.

18. The system of claim 11 , wherein the one or more processors are further configured to determine as the one or more vulnerabilities a percentage of users that are phish-prone.

19. The system of claim 18 , wherein the percentage of users that are phish-prone comprises a number of the users that interacted with a simulated phishing communication.

20. The system of claim 11 , wherein the one or more vulnerabilities causing one or more of the users of to interact with a simulated phishing communication includes one or more of the following: a type of the simulated phishing communication, a type of exploit used by the simulated phishing communication, content of the simulated phishing communication and timing of or between simulated phishing communications.

Assignments (6)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL/FRAME NO.: 056885/0889 Recorded Feb 2, 2023
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: KNOWBE4, INC.
Reel/Frame 062625/0841 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Mar 12, 2021
From: KNOWBE4, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 056885/0889 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2020
From: IRIMIE, ALIN; SJOUWERMAN, STU; KRAS, GREG; SITES, ERIC
To: KNOWBE4, INC.
Reel/Frame 052590/0490 →
Continuity (2)
Continuation 15829714 · Dec 1, 2017
Related Publication 20200265358A1 · Aug 20, 2020