IP Library Granted Patent US 11,973,801
Granted Patent B2
US 11,973,801 · App. 17/952,426 · Granted Apr 30, 2024

Dynamically initiating and managing automated spear phishing in enterprise computing environments

Inventor: Nathan James Grealish (Allison Park, PA)
Assignee: Proofpoint, Inc.
H04L63/1483G06N20/00H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,973,801
App. No.
17/952,426
Granted
Apr 30, 2024
Kind
B2
Abstract

Aspects of the disclosure relate to dynamic and automated spear phishing management. A computing platform may identify users to receive a simulated spear phishing message. In some instances, the computing platform may receive a very attacked persons (VAP) list and may identify the users to receive the simulated spear phishing message based on the VAP list. Based on historical message data associated with a first user, the computing platform may identify message features associated with the first user. Using a predetermined template and for a first user account linked to the first user, the computing platform may generate a first spear phishing message based on the message features. The computing platform may then send, to the first user account, the first spear phishing message.

Claims (57)

1. A computing platform, comprising:

at least one processor;

a communication interface communicatively coupled to the at least one processor; and

memory storing computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

generate, using a predetermined template and for a first user account linked to a first user, a first spear phishing message based on message features of messages associated with the first user, wherein the first spear phishing message comprises a general introductory message;

send, to the first user account, the first spear phishing message;

receive, from the first user account, a reply message to the first spear phishing message; and

send, to the first user account, a second spear phishing message, wherein the second spear phishing message comprises a specific ask of the first user, wherein content of the first spear phishing message has a first level of specificity determined by the computing platform based on the message features of the messages associated with the first user, and wherein the content of the second spear phishing message has a second level of specificity greater than the first level of specificity and determined by the computing platform based on the message features of the messages associated with the first user.

2. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

identify a plurality of users to receive one or more simulated spear phishing messages, wherein the first user is included in the plurality of users; and

identify, based on historical message data associated with the first user of the plurality of users identified to receive the one or more simulated spear phishing messages, the message features of messages associated with the first user.

3. The computing platform of claim 2 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

prior to identifying the plurality of users to receive the one or more simulated spear phishing messages, receive a very attacked persons (VAP) list, wherein identifying the plurality of users to receive the one or more simulated spear phishing messages comprises identifying the plurality of users to receive the one or more simulated spear phishing messages based on the VAP list.

4. The computing platform of claim 3 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

update, at a predetermined interval, the VAP list.

5. The computing platform of claim 2 , wherein identifying the plurality of users to receive the one or more simulated spear phishing messages comprises identifying the plurality of users to receive the one or more simulated spear phishing messages based on each user of the plurality of users having security posture characteristics that meet predetermined security posture criteria.

6. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

determine a spear phishing score for the first user account linked to the first user; and

generate, based on a determination that the spear phishing score for the first user account linked to the first user exceeds a predetermined threshold, the first spear phishing message.

7. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

receive first user interaction information indicating an initial interaction with the first spear phishing message; and

in response to receiving the first user interaction information, send, to the first user account, a message indicating first spear phishing training to be completed by the first user.

8. The computing platform of claim 7 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

receive second user interaction information indicating a second interaction with the first spear phishing message; and

in response to receiving the second user interaction information, send, to the first user account, a message indicating second spear phishing training to be completed by the first user.

9. The computing platform of claim 1 , wherein the message features of the messages associated with the first user include one or more of: a quantity of messages received from external accounts, a quantity of messages received from internal accounts, information about the external accounts, information about the internal accounts, an average number of attachments, information about the attachments, the attachments themselves, an average number of links, information about the links, the links themselves, or an average number of replies sent on a message string.

10. The computing platform of claim 1 , wherein generating the first spear phishing message comprises:

automatically selecting the predetermined template;

directing an administrator computing system to cause display of the predetermined template;

receiving user input indicating text to be included in the first spear phishing message; and

creating the first spear phishing message based on the user input and the predetermined template.

11. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

analyze, using one or more natural language processing (NLP) algorithms, the reply message; and

generate, based on the NLP analysis of the reply message, the second spear phishing message.

12. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

identify, by accessing an internal database configured to store personal details about the first user, personal details corresponding to the first user, wherein generating the first spear phishing message comprises generating, based in part on the personal details corresponding to the first user, the first spear phishing message.

13. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to select, based on the message features of the messages associated with the first user, the predetermined template prior to generating the first spear phishing message based on the message features.

14. The computing platform of claim 1 , wherein the memory stores additional computer-readable instructions that, when executed by the at least one processor, cause the computing platform to:

select, based on historical message data associated with an enterprise organization with which the first user is affiliated, the predetermined template, wherein generating the first spear phishing message comprises inputting information specific to the first user, based on the message features, into the predetermined template.

15. A method, comprising:

at a computing platform comprising at least one processor, a communication interface, and memory:

generating, using a predetermined template and for a first user account linked to a first user, a first spear phishing message based on message features of messages associated with the first user, wherein the first spear phishing message comprises a general introductory message;

sending, to the first user account, the first spear phishing message;

receiving, from the first user account, a reply message to the first spear phishing message; and

sending, to the first user account, a second spear phishing message, wherein the second spear phishing message comprises a specific ask of the first user, wherein content of the first spear phishing message has a first level of specificity determined by the computing platform based on the message features of the messages associated with the first user, and wherein the content of the second spear phishing message has a second level of specificity greater than the first level of specificity and determined by the computing platform based on the message features of the messages associated with the first user.

16. The method of claim 15 , further comprising:

identifying a plurality of users to receive one or more simulated spear phishing messages, wherein the first user is included in the plurality of users; and

identifying, based on historical message data associated with the first user of the plurality of users identified to receive the one or more simulated spear phishing messages, the message features of messages associated with the first user.

17. The method of claim 16 , further comprising:

prior to identifying the plurality of users to receive the one or more simulated spear phishing messages, receiving a very attacked persons (VAP) list, wherein identifying the plurality of users to receive the one or more simulated spear phishing messages comprises identifying the plurality of users to receive the one or more simulated spear phishing messages based on the VAP list.

18. The method of claim 17 , comprising:

updating, by the at least one processor, at a predetermined interval, the VAP list.

19. One or more non-transitory computer-readable media storing instructions that, when executed by a computing platform comprising at least one processor, a communication interface, and memory, cause the computing platform to:

generate, using a predetermined template and for a first user account linked to a first user, a first spear phishing message based on message features of messages associated with the first user, wherein the first spear phishing message comprises a general introductory message;

send, to the first user account, the first spear phishing message;

receive, from the first user account, a reply message to the first spear phishing message; and

send, to the first user account, a second spear phishing message, wherein the second spear phishing message comprises a specific ask of the first user, wherein content of the first spear phishing message has a first level of specificity determined by the computing platform based on the message features of the messages associated with the first user, and wherein the content of the second spear phishing message has a second level of specificity greater than the first level of specificity and determined by the computing platform based on the message features of the messages associated with the first user.

Assignments (3)
INTELLECTUAL PROPERTY AGREEMENT SUPPLEMENT Recorded Dec 9, 2025
From: PROOFPOINT, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 073910/0027 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Dec 8, 2025
From: PROOFPOINT, INC.
To: U.S. BANK TRUST COMPANY, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 073889/0677 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 27, 2022
From: GREALISH, NATHAN JAMES
To: PROOFPOINT
Reel/Frame 061224/0099 →
Continuity (3)
Continuation 16718389 · Dec 18, 2019
Provisional Application 62896065 · Sep 5, 2019
Related Publication 20230016110A1 · Jan 19, 2023
Cited By (1)
US 12,225,047