IP Library Granted Patent US 11,075,943
Granted Patent B2
US 11,075,943 · App. 17/107,294 · Granted Jul 27, 2021

Systems and methods for an artificial intelligence driven agent

Inventors: Alin Irimie (Clearwater, FL); Stu Sjouwerman (Bellair, FL); Greg Kras (Dunedin, FL); Eric Sites (Clearwater, FL)
Assignee: KnowBe4, Inc.
H04L63/1433G06F16/951G06F30/20G06N5/02G06N20/00H04L51/12H04L63/1466H04L63/1483H04W12/122H04L51/30H04W12/128
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,075,943
App. No.
17/107,294
Granted
Jul 27, 2021
Kind
B2
Abstract

A system and method is described that sends multiple simulated phishing emails, text messages, and/or phone calls (e.g., via VoIP) varying the quantity, frequency, type, sophistication, and combination using machine learning algorithms or other forms of artificial intelligence. In some implementations, some or all messages (email, text messages, VoIP calls) in a campaign after the first simulated phishing email, text message, or call may be used to direct the user to open the first simulated phishing email or text message, or to open the latest simulated phishing email or text message. In some implementations, simulated phishing emails, text messages, or phone calls of a campaign may be intended to lure the user to perform a different requested action, such as selecting a hyperlink in an email or text message, or returning a voice call.

Claims (36)

1. A method comprising:

training, by one or more processors, an artificial intelligence model with results from a plurality of simulated phishing campaigns comprising a plurality of sequences of simulated phishing communications of different types of communications, wherein the artificial intelligence model is configured to take as input one or more attributes of a user and provide as output information identifying a sequence of different types of communications to cause the user to take a predetermined action responsive to one of the simulated phishing communications of the sequence;

determining, by the one or more processors by providing one or more attributes of the user as input to the artificial intelligence model, the sequence of different types of communications to use for a simulated phishing campaign for the user that has a predetermined likelihood of causing the user to take the predetermined action responsive to one of the simulated phishing communications of the sequence; and

communicating, by the one or more processors, a second simulated phishing communication of a second type of communication of the sequence to a device of the user at a predetermined time identified by the artificial intelligence model, the second simulated phishing communication communicated subsequent to and different from a first simulated phishing communication of a first type of communication of the sequence communicated to the device of the user.

2. The method of claim 1 , wherein the first type of communication comprises at least one of email, text, short message service (SMS) message, a phone call or an Internet based communication and the second type of communication comprises one of email, text, SMS message, a phone call or an Internet based communication different from the first type of communication.

3. The method of claim 1 , wherein the artificial intelligence model is configured to output information identifying timing between simulated phishing communications in the sequence of different types of communications.

4. The method of claim 1 , further comprising determining, by the one or more processors from output of the artificial intelligence model, timing between simulated phishing communications in the sequence of different types of communications.

5. The method of claim 1 , further comprising determining, by the one or more processors responsive to the artificial intelligence model, that a particular type of communication has the predetermined likelihood of causing the user to take the predetermined action.

6. The method of claim 1 , further comprising determining, by the one or more processors responsive to the artificial intelligence model, that the first type of communication followed by the second type of communication has the predetermined likelihood of causing the user to take the predetermined action.

7. The method of claim 6 , further comprising determining, by the one or more processors responsive to the artificial intelligence model, that the first type of communication followed by the second type of communication at a predetermined time has the predetermined likelihood of causing the user to take the predetermined action.

8. The method of claim 1 , further comprising determining, by the one or more processors responsive to the artificial intelligence model, one of a frequency or quantity of communications for the sequence of types of communications to use for the user.

9. The method of claim 1 , further comprising identifying, by the one or more processors, the sequence of types of communications from the output of the artificial intelligence model.

10. A system comprising:

one or more processors, coupled to memory;

an artificial intelligence model stored in memory and configured to take as input one or more attributes of a user and provide as output information identifying a sequence of different types of communications to cause the user to take a predetermined action responsive to one of the simulated phishing communications of the sequence;

wherein the one or more processors are configured to:

train the artificial intelligence model with results from a plurality of simulated phishing campaigns comprising a plurality of sequences of simulated phishing communications of different types of communications;

provide one or more attributes of the user as input to the artificial intelligence model to determine the sequence of different types of communications to use for a simulated phishing campaign for the user that has a predetermined likelihood of causing the user to take the predetermined action responsive to one of the simulated phishing communications of the sequence; and

communicate a second simulated phishing communication of a second type of communication of the sequence to a device of the user at a predetermined time identified by the artificial intelligence model, the second simulated phishing communication communicated subsequent to and different from a first simulated phishing communication of a first type of communication of the sequence communicated to the device of the user.

11. The system of claim 10 , wherein the first type of communication comprises at least one of email, text, short message service (SMS) message, a phone call or an Internet based communication and the second type of communication comprises one of email, text, SMS message, a phone call or an Internet based communication different from the first type of communication.

12. The system of claim 10 , wherein the artificial intelligence model is further configured to output information identifying timing between simulated phishing communications in the sequence of different types of communications.

13. The system of claim 10 , wherein the one or more processors are further configured to determine from output of the artificial intelligence model, timing between simulated phishing communications in the sequence of different types of communications.

14. The system of claim 10 , wherein the one or more processors are further configured to determine, responsive to the artificial intelligence model, that a particular type of communication has the predetermined likelihood of causing the user to take the predetermined action.

15. The system of claim 10 , wherein the one or more processors are further configured to determine, responsive to the artificial intelligence model, that the first type of communication followed by the second type of communication has the predetermined likelihood of causing the user to take the predetermined action.

16. The system of claim 15 , wherein the one or more processors are further configured to determine, responsive to the artificial intelligence model, that the first type of communication followed by the second type of communication at a predetermined time has the predetermined likelihood of causing the user to take the predetermined action.

17. The system of claim 10 , wherein the one or more processors are further configured to determine, responsive to the artificial intelligence model, one of a frequency or quantity of communications for the sequence of types of communications to use for the user.

18. The system of claim 10 , wherein the one or more processors are further configured to identify the sequence of types of communications from the output of the artificial intelligence model.

19. A system comprising:

one or more processors, coupled to memory;

an artificial intelligence model stored in memory and configured to take as input one or more attributes of a user and provide as output information identifying a sequence of different types of communications to cause the user to take a predetermined action responsive to one of the simulated phishing communications of the sequence;

wherein the one or more processors are configured to:

train the artificial intelligence model with results from a plurality of simulated phishing campaigns comprising a plurality of sequences of simulated phishing communications of different types of communications;

provide one or more attributes of the user as input to the artificial intelligence model to determine the sequence of different types of communications to use for a simulated phishing campaign for the user that has a predetermined likelihood of causing the user to take the predetermined action responsive to one of the simulated phishing communications of the sequence; and

communicate a second simulated phishing communication of a second type of communication of the sequence to a device of the user subsequent to and different from a first simulated phishing communication of a first type of communication of the sequence communicated to the device of the user; and

wherein the one or more processors are configured to determine, responsive to the artificial intelligence model, that the first type of communication followed by the second type of communication has the predetermined likelihood of causing the user to take the predetermined action.

20. The system of claim 19 , wherein the one or more processors are further configured to determine, responsive to the artificial intelligence model, that the first type of communication followed by the second type of communication at a predetermined time has the predetermined likelihood of causing the user to take the predetermined action.

Assignments (6)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL/FRAME NO.: 056885/0889 Recorded Feb 2, 2023
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: KNOWBE4, INC.
Reel/Frame 062625/0841 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Mar 12, 2021
From: KNOWBE4, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 056885/0889 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2020
From: IRIMIE, ALIN; SJOUWERMAN, STU; KRAS, GREG; SITES, ERIC
To: KNOWBE4, INC.
Reel/Frame 054508/0028 →
Cited By (1)
US 12,321,583