IP Library Granted Patent US 11,847,935
Granted Patent B2
US 11,847,935 · App. 17/104,767 · Granted Dec 19, 2023

Prompting users to annotate simulated phishing emails in cybersecurity training

Inventors: Jason R. Brubaker (East Berlin, PA); Benjamin C. Blanchard (Pittsburgh, PA)
Assignee: Proofpoint, Inc.
G09B5/02G06Q10/06393G06Q10/107H04L51/42H04L63/1483
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,847,935
App. No.
17/104,767
Granted
Dec 19, 2023
Kind
B2
Abstract

Aspects of the disclosure relate to dynamically generating simulated attack messages configured for annotation by users as part of cybersecurity training. A computing platform may generate a simulated attack message including a plurality of elements and send the simulated attack message to an enterprise user device. Subsequently, the computing platform may receive, from the enterprise user device, user selections annotating selected elements of the plurality of elements of the simulated attack message. The computing platform may thereafter identify one or more training areas for the user based on the user selections received from the enterprise user device, generate a customized training module specific to the identified one or more training areas, and send the customized training module to the enterprise user device. Sending the customized training module to the enterprise user device may cause the enterprise user device to display the customized training module.

Claims (55)

1. A computing platform, comprising:

at least one processor;

a communication interface; and

memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

generate an electronic communication including a simulated attack message;

send, to an enterprise user device, the simulated attack message, wherein sending the simulated attack message causes the enterprise user device to interactively display a simulated attack interface comprising a plurality of interactive elements;

receive, from the enterprise user device, user selections annotating selected elements of the plurality of interactive elements of the simulated attack message, wherein receiving the user selections annotating selected elements of the plurality of interactive elements of the simulated attack message includes receiving markers proximate the selected elements dynamically modifying the simulated attack interface;

identify one or more training areas for a user based on the user selections received from the enterprise user device;

generate a customized training module specific to the identified one or more training areas, wherein generating the customized training module includes training a machine learning engine based on the user selections to dynamically adapt a training module template to the identified one or more training areas for the user; and

send, to the enterprise user device, the customized training module, wherein sending the customized training module to the enterprise user device causes the enterprise user device to display a training interface that allows the user to interactively complete the customized training module.

2. The computing platform of claim 1 , wherein identifying one or more training areas for the user includes calculating a user performance score based on the user selections.

3. The computing platform of claim 2 , wherein the user performance score includes a first score component based on portions of the simulated attack message correctly selected and a second score components based on portions of the simulated attack message correctly not selected.

4. The computing platform of claim 1 ,

wherein the user selections annotating selected elements of the plurality of r elements of the simulated attack message are received responsive to displaying the simulated attack message in an email client application, and

wherein an initial user selection includes an interaction with the simulated attack message indicating that the simulated attack message has been marked as potentially suspicious or indicating that a user at the enterprise user device fell for the simulated attacked message.

5. The computing platform of claim 1 , wherein the user selections annotating selected elements of the plurality of interactive elements of the simulated attack message are received responsive to displaying a prompt at the enterprise user device to identify one or more potentially malicious elements of the simulated attack message.

6. The computing platform of claim 1 , wherein the user selections annotating selected elements of the plurality of interactive elements of the simulated attack message are received responsive to providing, at the enterprise user device, one or more annotation tools to allow user selections of elements of the simulated attack message.

7. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

receive, from the enterprise user device, additional user selections categorizing the selected elements from a list of types of malicious elements.

8. The computing platform of claim 1 , wherein the user selections annotating selected elements of the plurality of interactive elements of the simulated attack message are received responsive to displaying the simulated attack message in a cybersecurity training application.

9. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

aggregate user selections received from a plurality of enterprise user devices; and

transmit the aggregated user selections to an administrator computing device.

10. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

compute a frequency with which elements are correctly selected by users.

11. The computing platform of claim 10 ,

wherein generating the simulated attack message includes assigning a baseline score weighting to each element of the plurality of interactive elements, and

wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

assign an adjusted score weighting for each element of the plurality of interactive elements based on the computed frequency with which elements are correctly selected by users.

12. The computing platform of claim 11 , wherein identifying one or more training areas for the user includes calculating a user performance score based on the user selections and the adjusted score weighting for each element.

13. The computing platform of claim 10 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

update a machine learning model used in generating the simulated attack message based on the computed frequency with which elements are correctly selected by users.

14. A method, comprising:

at a computing platform comprising at least one processor, a communication interface, and memory:

generating, by the at least one processor, an electronic message including a simulated attack message;

sending, by the at least one processor, via the communication interface, the simulated attack message to an enterprise user device, wherein sending the simulated attack message causes the enterprise user device to interactively display a simulated attack interface comprising a plurality of interactive elements;

receiving, by the at least one processor, from the enterprise user device, user selections annotating selected elements of the plurality of interactive elements of the simulated attack message, wherein receiving the user selections annotating selected elements of the plurality of interactive elements of the simulated attack message includes receiving markers proximate the selected elements dynamically modifying the simulated attack interface;

identifying, by the at least one processor, one or more training areas for a user based on the user selections received from the enterprise user device;

generating, by the at least one processor, a customized training module specific to the identified one or more training areas, wherein generating the customized training module includes training a machine learning engine based on the user selections to dynamically adapt a training module template to the identified one or more training areas for the user; and

sending, by the at least one processor, the customized training module to the enterprise user device, wherein sending the customized training module to the enterprise user device causes the enterprise user device to display a training interface that allows the user to interactively complete the customized training module.

15. The method of claim 14 , further comprising:

computing, by the at least one processor, a frequency with which elements are correctly selected by users.

16. The method of claim 15 , wherein generating the simulated attack message includes assigning a baseline score weighting to each element of the plurality of interactive elements, and the method further comprising:

assigning, by the at least one processor, an adjusted score weighting for each element of the plurality of interactive elements based on the computed frequency with which elements are correctly selected by users.

17. The method of claim 16 , wherein identifying one or more training areas for the user includes calculating a user performance score based on the user selections and the adjusted score weighting for each element.

18. The method of claim 15 , further comprising:

updating, by the at least one processor, a machine learning model used in generating the simulated attack message based on the computed frequency with which elements are correctly selected by users.

19. The method of claim 14 , wherein the user selections annotating selected elements of the plurality of interactive elements of the simulated attack message are received responsive to displaying the simulated attack message in a cybersecurity training application.

20. One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, a communication interface, and memory, cause the computing platform to:

generate an electronic message including a simulated attack message;

send, to an enterprise user device, the simulated attack message, wherein sending the simulated attack message causes the enterprise user device to interactively display a simulated attack interface comprising a plurality of interactive elements;

receive, from the enterprise user device, user selections annotating selected elements of the plurality of interactive elements of the simulated attack message, wherein receiving the user selections annotating selected elements of the plurality of interactive elements of the simulated attack message includes receiving markers proximate the selected elements dynamically modifying the simulated attack interface;

identify one or more training areas for the user based on the user selections received from the enterprise user device;

generate a customized training module specific to the identified one or more training areas, wherein generating the customized training module includes training a machine learning engine based on the user selections to dynamically adapt a training module template to the identified one or more training areas for the user; and

send, to the enterprise user device, the customized training module, wherein sending the customized training module to the enterprise user device causes the enterprise user device to display a training interface that allows the user to interactively complete the customized training module.

Assignments (5)
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 8, 2025
From: PROOFPOINT, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 073889/0677 →
RELEASE OF SECOND LIEN SECURITY INTEREST IN INTELLECTUAL PROPERTY Recorded Mar 21, 2024
From: GOLDMAN SACHS BANK USA, AS AGENT
To: PROOFPOINT, INC.
Reel/Frame 066865/0648 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 31, 2021
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057389/0615 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 31, 2021
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057389/0642 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 25, 2020
From: BRUBAKER, JASON R.; BLANCHARD, BENJAMIN C.
To: PROOFPOINT, INC.
Reel/Frame 054471/0166 →