IP Library Granted Patent US 12,174,966
Granted Patent B2
US 12,174,966 · App. 17/539,922 · Granted Dec 24, 2024

Systems and methods for mitigating false positives in a simulated phishing campaign

Inventor: Greg Kras (Dunedin, FL)
Assignee: KnowBe4, Inc.
G06F21/577G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,174,966
App. No.
17/539,922
Granted
Dec 24, 2024
Kind
B2
Abstract

Systems and methods are described for mitigating false positives in a simulated phishing campaign. A simulated phishing message reported to second security awareness system by a user as suspicious is received by first security awareness system. The reported message includes a link that has been followed. Link data of followed link of the reported message is held in click cache having predetermined delay. Post the predetermined delay, whether the link was followed by second security awareness system instead of being clicked by user responsive to identifying that link data in click cache corresponds to link data in link cache or internet protocol (IP) address of an entity that follows a link corresponds to IP address stored in IP cache known to be associated with second security awareness system. Responsive to determination, second security awareness system's following of link of the reported message is excluded as interaction of the user.

Claims (37)

1. A method comprising:

receiving, by a first security awareness system, a simulated phishing message of a user reported to a second security awareness system as suspicious, the simulated phishing message comprising a link that has been followed;

holding, by the first security awareness system, link data of the link of the simulated phishing message in a click cache having a predetermined delay;

determining, by the first security awareness system upon expiration of the predetermined delay, that the link data in the click cache corresponds to link data in a link cache;

identifying, by the first security awareness system responsive to determining the link data in the click cache corresponds to the link data in the link cache, that the link was followed by the second security awareness system instead of being clicked by the user; and

excluding, by the first security awareness system, the second security awareness system's following of the link of the simulated phishing message as an interaction of the user.

2. The method of claim 1 , further comprising disassociating, by the first security awareness system, from a user record of the user of the first security awareness system a click of the user for the link that was recorded for the second security awareness system's following of the link of the simulated phishing message.

3. The method of claim 1 , further comprising receiving, by the first security awareness system, the simulated phishing message forwarded by the second security awareness system.

4. The method of claim 1 , further comprising receiving, by the first security awareness system, the simulated phishing message of the second security awareness system by one of monitoring or scanning a mailbox within the second security awareness system for simulated phishing messages.

5. The method of claim 1 , further comprising storing, by the first security awareness system, click data for the simulated phishing message to the click cache.

6. The method of claim 1 , further comprising updating, by the first security awareness system, link data for the simulated phishing message to the link cache, wherein the link cache stores links that have a probability of being followed by the second security awareness system.

7. The method of claim 1 , further comprising resetting age of the link in the link cache.

8. The method of claim 1 , further comprising adding, by the first security awareness system, to an internet protocol (IP) cache, data comprising an IP address, wherein the IP cache stores IP addresses known to be associated with the second security awareness system.

9. The method of claim 8 , further comprising resetting age of IP data of an entity that follows the link in the IP cache.

10. A method comprising:

receiving, by a first security awareness system, a simulated phishing message of a user reported to a second security awareness system as suspicious, the simulated phishing message comprising a link that has been followed;

holding, by the first security awareness system, link data of the link of the simulated phishing message in a click cache having a predetermined delay;

determining, by the first security awareness system upon expiration of the predetermined delay, that the link data in the click cache is not in a link cache;

determining, by the first security awareness system, that the internet protocol (IP) address of a click of the link corresponds to an IP address stored in an IP cache of IP addresses known to be associated with the second security awareness system;

identifying, by the first security awareness system, that the link was followed by the second security awareness system instead of being clicked by the user; and

excluding, by the first security awareness system, the second security awareness system's following of the link of the simulated phishing message as an interaction of the user.

11. The method of claim 10 , further comprising disassociating, by the first security awareness system, from a user record of the user of the first security awareness system a click of the user for the link that was recorded for the second security awareness system's following of the link of the simulated phishing message.

12. The method of claim 10 , further comprising receiving, by the first security awareness system, the simulated phishing message forwarded by the second security awareness system.

13. The method of claim 10 , further comprising receiving, by the first security awareness system, the simulated phishing message of the second security awareness system by one of monitoring or scanning a mailbox within the second security awareness system for simulated phishing messages.

14. The method of claim 10 , further comprising resetting age of IP data of an entity that follows the link in the IP cache.

15. The method of claim 10 , further comprising resetting age of the link in the link cache.

16. A system comprising:

a memory;

a first security awareness system executable on one or more processors, coupled to the memory and configured to:

receive a simulated phishing message of a user reported to a second security awareness system as suspicious, the simulated phishing message comprising a link that has been followed;

hold, link data of the link of the simulated phishing message in a click cache having a predetermined delay;

determine, upon expiration of the predetermined delay, that the link was followed by the second security awareness system instead of being clicked by the user responsive to identifying that the link data in the click cache corresponds to link data in a link cache or an internet protocol (IP) address of a click of the link corresponds to an IP address stored in an IP cache of IP addresses known to be associated with the second security awareness system; and

exclude, responsive to the determination, the second security awareness system's following of the link of the simulated phishing message as an interaction of the user.

17. The system of claim 16 , wherein the first security awareness system is further configured to dissociate from a user record of the user of the first security awareness system a click of the user for the link that was recorded for the second security awareness system's following of the link of the simulated phishing message.

18. The system of claim 16 , wherein the first security awareness system is further configured to receive the simulated phishing message forwarded by the second security awareness system.

19. The system of claim 16 , wherein the first security awareness system is further configured to receive the simulated phishing message of the second security awareness system by one of monitoring or scanning a mailbox within the second security awareness system for simulated phishing messages.

20. The system of claim 16 , wherein the first security awareness system is further configured to refresh an entry of IP data and link address of the link in the IP cache and the link cache.

Assignments (4)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2021
From: KRAS, GREG
To: KNOWBE4, INC.
Reel/Frame 058260/0923 →
Continuity (2)
Provisional Application 63120528 · Dec 2, 2020
Related Publication 20220171860A1 · Jun 2, 2022