IP Library Granted Patent US 11,206,288
Granted Patent B2
US 11,206,288 · App. 17/145,650 · Granted Dec 21, 2021

Systems and methods for AIDA based grouping

Inventors: Alin Irimie (Clearwater, FL); Stu Sjouwerman (Bellair, FL); Greg Kras (Dunedin, FL); Eric Sites (Clearwater, FL)
Assignee: KnowBe4, Inc.
H04L63/1483G06F21/552G06F21/577G06N3/082G06N3/084H04L63/1433H04L63/1491H04L67/22G06N3/0445G06N3/0472
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,206,288
App. No.
17/145,650
Granted
Dec 21, 2021
Kind
B2
Abstract

The present disclosure describes systems and methods for dynamically creating groups of users based on attributes for simulated phishing campaign. A campaign controller determines one or more attributes of a plurality of users during execution of a simulated phishing campaign and creates one or more groups of users during based on the identified attributes. The campaign controller selects a template to be used to execute a portion of the simulated phishing campaign for a first group of users and then communicates one or more simulated phishing communications to the first group of users according to the template. The template may identify a list of a plurality of types of simulated phishing communications (email, text or SMS message, phone call or Internet based communication) and at least a portion of the content for the simulated phishing communication.

Claims (29)

1. A method comprising:

identifying, by one or more processors, a plurality of groups of users;

using, by a device for executing a simulated phishing campaign, a model configured to identify a template for one or more simulated phishing communications to one or more users for each group of users of the plurality of groups of users, the model trained to identify the template having at least a likelihood to cause a group of users to take a predetermined action and configured to identify the template of at least one group of the plurality of groups different from the template of another group of the plurality of groups; and

communicating, by the device for the simulated phishing campaign, one or more simulated phishing communications to a first group of users of the plurality of groups of users according to a first template identified by the model and to a second group of users of the plurality of groups of users according to a second template identified by the model.

2. The method of claim 1 , further comprising establishing the plurality of groups of users responsive to one or more results of one or more simulated phishing communications to a plurality of users.

3. The method of claim 2 , further comprising establishing the plurality of groups during execution of the simulated phishing campaign.

4. The method of claim 1 , further comprising establishing, by the one or more processors, a first group of users and a second group of users from the plurality of groups of users.

5. The method of claim 4 , further comprising establishing, by the one or more processors, the first group of users and the second group of users based at least on results from one or more simulated phishing communications.

6. The method of claim 4 , further comprising establishing, by the one or more processors, the first group of users and the second group of users based at least on one or more attributes of the plurality of users.

7. The method of claim 1 , further comprising receiving, by the one or more processors, identification from the model of the template for each group of users responsive to providing the model one or more attributes of users in each group.

8. A system comprising:

one or more processors, coupled to memory, and configured to:

identify a plurality of groups of users;

use, for executing a simulated phishing campaign, a model configured to identify a template for one or more simulated phishing communications to one or more users for each group of users of the plurality of groups of users, the model trained to identify the template having at least a likelihood to cause a group of users to take a predetermined action, wherein the model is configured to identify the template of at least one group of the plurality of groups different from the template of another group of the plurality of groups; and

communicate one or more simulated phishing communications to a first group of users of the plurality of groups of users according to a first template identified by the model and to a second group of users of the plurality of groups of users according to a second template identified by the model.

9. The system of claim 8 , wherein the one or more processors are further configured to establish the plurality of groups of users responsive to one or more results of one or more simulated phishing communications to a plurality of users.

10. The system of claim 8 , wherein the one or more processors are further configured establishing the plurality of groups during execution of the simulated phishing campaign.

11. The system of claim 8 , wherein the one or more processors are further configured to establish a first group of users and a second group of users from the plurality of groups of users.

12. The system of claim 11 , wherein the one or more processors are further configured to establish the first group of users and the second group of users based at least on results from one or more simulated phishing communications.

13. The system of claim 11 , wherein the one or more processors are further configured to establish the first group of users and the second group of users based at least on one or more attributes of a plurality of users.

14. The system of claim 11 , wherein the one or more processors are further configured to communicate one or more simulated phishing communications to the first group of users according to a first template identified by the model and to the second group of users according to a second template identified by the model.

15. The system of claim 8 , wherein the one or more processors are further configured to receive identification from the model of the template for each group of users responsive to providing the model one or more attributes of users in each group.

16. A system comprising:

one or more processors, coupled to memory and configured with a model trained via machine learning using results from a plurality of simulated phishing communications;

wherein the model, responsive to being trained, is configured to receive as input one or more attributes of one or more users and provide as output identification of a template to use for generating a simulated phishing communication for the one or more users; and

wherein the one or more processors are configured to generate a first simulated phishing communication for a first group of users based at least on a first template identified by the model responsive to receiving one or more attributes of one or more users of the first group of users and generate a second simulated phishing communication for a second group of users based at least on a second template identified by the model responsive to receiving one or more attributes of one or more users of the second group of users.

17. The system of claim 16 , wherein the one or more processors are further configured to communicate the first simulated phishing communication to the one or more users of the first group of users.

18. The system of claim 16 , wherein the one or more processors are further configured to communicate the second simulated phishing communication to the one or more users of the second group of users.

19. The system of claim 16 , wherein the one or more attributes comprises one or more of the following: a geographic region, a demographic, or an organizational level within a company.

Assignments (6)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL/FRAME NO.: 056885/0889 Recorded Feb 2, 2023
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: KNOWBE4, INC.
Reel/Frame 062625/0841 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Mar 12, 2021
From: KNOWBE4, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 056885/0889 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 11, 2021
From: IRIMIE, ALIN; SJOUWERMAN, STU; KRAS, GREG; SITES, ERIC
To: KNOWBE4, INC.
Reel/Frame 054875/0721 →
Continuity (3)
Continuation 16875002 · May 15, 2020
Continuation 15829728 · Dec 1, 2017
Related Publication 20210136109A1 · May 6, 2021