IP Library Granted Patent US 10,917,434
Granted Patent B1
US 10,917,434 · App. 17/070,370 · Granted Feb 9, 2021

Systems and methods for AIDA based second chance

Inventors: Alin Irimie (Clearwater, FL); Stu Sjouwerman (Bellair, FL); Greg Kras (Dunedin, FL); Eric Sites (Clearwater, FL)
Assignee: KnowBe4, Inc.
H04L63/1483G06F21/552G06F21/554G06F21/577G06N3/082H04L67/22
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,917,434
App. No.
17/070,370
Granted
Feb 9, 2021
Kind
B1
Abstract

Methods and systems are described in which a system provides a user interface to confirm whether to review or take an action associated with an untrusted email. A driver on a device monitors the startup of any processes. Responsive to monitoring, the driver detects an application process that was created that indicates than an application was launched, and notifies a user console about the creation of the application process. The user console determines if the application process is of significance, if so, it injects a monitor library into the process. Once injected into the process, the monitor library detects if the application process receives an action of a user to access a domain that is not identified as trusted. The monitor library notifies the user console of the user's URL-access request.

Claims (33)

1. A method comprising:

receiving, by one or more processors, information identifying that one or more users provided input via a user interface to revert back to a point in an application of one or more applications at which the one or more users requested one or more actions that were intercepted based at least on a domain associated with the one or more applications not being identified as trusted;

using, by the one or more processors, at least the information to train an artificial intelligence model configured to select a model from a plurality of models;

selecting, by the one or more processors using the artificial intelligence model, the model from a plurality of models configured to provide information on how to create a simulated phishing communication; and

using, by the one or more processors, information provided by the selected model to create the simulated phishing communication to communicate to a device of a user.

2. The method of claim 1 , further comprising receiving, by the one or more processors, information identifying that one or more users provided input via the user interface to take the one or one more actions that were based at least on the domain associated with the one or more applications not being identified as trusted.

3. The method of claim 1 , wherein the one or more actions comprises an action to access the domain via the one or more applications.

4. The method of claim 1 , wherein the information comprises one or more of the following: a type of action, a type of exploit, an identifier of an application of the one or more applications and an identifier of the domain.

5. The method of claim 1 , wherein the one or more actions are intercepted prior to accessing the domain.

6. The method of claim 1 , further comprising training, by the one or more processors, the artificial intelligence model using at least the information and one or more attributes of the one or more users.

7. The method of claim 5 , further comprising providing, by the one or more processors, one or more attributes of the user as input to the artificial intelligence model and responsive to the input, the artificial intelligence model providing as output identification of the selected model.

8. A method comprising:

receiving, by one or more processors, information identifying that one or more users provided input via a user interface to revert back to a point in an application of one or more applications at which the one or more users requested one or more actions that were intercepted based at least on a domain associated with the one or more applications not being identified as trusted;

using, by the one or more processors, at least the information to train an artificial intelligence model configured to select a template from a plurality of templates;

selecting, by the one or more processors using the artificial intelligence model, the template from a plurality of templates configured to information to create a simulated phishing communication; and

using, by the one or more processors, information provided by the selected template to create the simulated phishing communication to communicate to a device of a user.

9. The method of claim 8 , further comprising receiving, by the one or more processors, information identifying that one or more users provided input via the user interface to take the one or one more actions that were based at least on the domain associated with the one or more application not being identified as trusted.

10. The method of claim 8 , wherein the one or more actions comprises an action to access the domain via the one or more applications.

11. The method of claim 8 , wherein the information comprises one or more of the following: a type of action, a type of exploit, an identifier of an application of the one or more applications and an identifier of the domain.

12. The method of claim 8 , wherein the one or more actions are intercepted prior to accessing the domain.

13. The method of claim 8 , further comprising training, by the one or more processors, the artificial intelligence model using at least the information and one or more attributes of the one or more users.

14. The method of claim 13 , further comprising providing, by the one or more processors, one or more attributes of the user as input to the artificial intelligence model and responsive to the input, the artificial intelligence model providing as output identification of the selected template.

15. A system comprising:

one or more processors, coupled to memory and configured to:

receive information identifying that one or more users provided input via a user interface to revert back to a point in an application of one or more applications at which the one or more users requested one or more actions that were intercepted based at least on a domain associated with the one or more applications not being identified as trusted;

use at least the information to train an artificial intelligence model configured to select a model from a plurality of models or a template from a plurality of templates;

select, using the artificial intelligence model, one of the model from the plurality of models or the template from the plurality of templates; and

use information provided by one of the selected model or the selected template to create the simulated phishing communication to communicate to a device of a user.

16. The system of claim 15 , wherein the information identifies that one or more users provided input via the user interface to take the one or one more actions that were based at least on the domain associated with the one or more applications not being identified as trusted.

17. The system of claim 15 , wherein the plurality of templates are configured to specify content to use to create the simulated phishing communication.

18. The system of claim 15 , wherein the plurality of models are configured to specify how to create the simulated phishing communication.

19. The system of claim 15 , wherein the one or more processors are further configured to train the artificial intelligence model using at least the information and one or more attributes of the one or more users.

20. The system of claim 19 , wherein the one or more processors are further configured to provide, one or more attributes of the user as input to the artificial intelligence model and responsive to the input, the artificial intelligence model is configured to provide as output identification of one of the selected model or the selected template.

Assignments (6)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL/FRAME NO.: 056885/0889 Recorded Feb 2, 2023
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: KNOWBE4, INC.
Reel/Frame 062625/0841 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Mar 12, 2021
From: KNOWBE4, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 056885/0889 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 14, 2020
From: IRIMIE, ALIN; SJOUWERMAN, STU; KRAS, GREG; SITES, ERIC
To: KNOWBE4, INC.
Reel/Frame 054053/0133 →