IP Library Granted Patent US 8,910,287
Granted Patent B1
US 8,910,287 · App. 14/223,820 · Granted Dec 9, 2014

Methods and systems for preventing malicious use of phishing simulation records

Inventors: Rohyt Belani (New York, NY); Aaron Higbee (Leesburg, VA); Scott Greaux (Glenmont, NY)
Assignee: PhishMe, Inc.
H04L63/1483G06F21/60
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,910,287
App. No.
14/223,820
Granted
Dec 9, 2014
Kind
B1
Abstract

Described herein are methods, network devices and machine-readable media for preventing the malicious use of phishing simulation records. Phishing simulation records often times can reveal which individuals are most susceptible to phishing attacks. In the event that an attacker gains access to these records, the attacker can exploit such information to send phishing attacks to those individuals who are the most susceptible. To address such vulnerabilities, a phishing simulation record of an individual is only associated with an e-mail alias of the individual. Further, such e-mail alias may be deactivated after phishing simulations have been completed. Therefore, even if an attacker were able to identify individuals most susceptible to phishing attacks, the attacker will be unable to send any phishing attacks to those individuals since their e-mail aliases will have been deactivated.

Claims (34)

1. A method, comprising:

for each individual, associating a phishing simulation record of the individual with an e-mail alias of the individual;

determining which of the phishing simulation records satisfies a criterion;

selecting at least one of the phishing simulation records which satisfies the criterion; and

for each of the selected phishing simulation records, sending one or more messages to the individual associated with the selected phishing simulation record via that individual's e-mail alias,

wherein after sending the one or more messages, at least one of the e-mail aliases becomes invalid, preventing one or more of the individuals whose e-mail aliases have become invalid from receiving any further messages from their respective e-mail aliases while their respective e-mail aliases are invalid.

2. The method of claim 1 , wherein each of the phishing simulation records comprises a measure of the corresponding individual's susceptibility to phishing attacks.

3. The method of claim 2 , wherein the criterion is satisfied if the measure of the corresponding individual's susceptibility to phishing attacks exceeds a threshold.

4. The method of claim 1 , wherein each of the phishing simulation records comprises a total number of phishing simulations that the corresponding individual has fallen victim to.

5. The method of claim 4 , wherein the criterion is satisfied if the total number of phishing simulations that the corresponding individual has fallen victim to exceeds a threshold.

6. The method of claim 1 , further comprising:

for each of the individuals, associating the e-mail alias of the individual with a primary e-mail address of the individual.

7. The method of claim 6 , wherein the association between the e-mail aliases and the primary e-mail addresses is stored using encryption.

8. The method of claim 6 , wherein the association between the phishing simulation records and the e-mail aliases is stored in a first data store and the association between the e-mail aliases and the primary e-mail addresses is stored in a second data store, the first data store being separate from the second data store so that even if an attacker gains access to the first data store, the attacker does not automatically gain access to the second data store.

9. The method of claim 6 , further comprising:

upon detecting that one or more messages have been sent to an individual's e-mail alias, forwarding the one or more messages to the primary e-mail address of the individual.

10. The method of claim 6 , wherein the at least one of the e-mail aliases becomes invalid upon terminating any forwarding of messages from the at least one of the e-mail aliases to their corresponding primary e-mail addresses.

11. The method of claim 1 , wherein the one or more messages comprise one or more of phishing simulations and training materials constructed to increase an individual's awareness of phishing attacks.

12. The method of claim 6 , wherein, for each of the individuals, the phishing simulation record of the individual is associated with the primary e-mail address of the individual only through the e-mail alias of the individual.

13. A network device, comprising:

a processor;

a storage device connected to the processor; and

a set of instructions on the storage device that, when executed by the processor, cause the processor to:

for each individual, associate a phishing simulation record of the individual with an e-mail alias of the individual;

determine which of the phishing simulation records satisfies a criterion;

select at least one of the phishing simulation records which satisfies the criterion; and

for each of the selected phishing simulation records, send one or more messages to the individual associated with the selected phishing simulation record via that individual's e-mail alias,

wherein after sending the one or more messages, at least one of the e-mail aliases becomes invalid, preventing one or more of the individuals whose e-mail aliases have become invalid from receiving any further messages from their respective e-mail aliases while their respective e-mail aliases are invalid.

14. A non-transitory machine-readable storage medium comprising software instructions that, when executed by a processor, cause the processor to:

for each individual, associate a phishing simulation record of the individual with an e-mail alias of the individual;

determine which of the phishing simulation records satisfies a criterion;

select at least one of the phishing simulation records which satisfies the criterion; and

for each of the selected phishing simulation records, send one or more messages to the individual associated with the selected phishing simulation record via that individual's e-mail alias,

wherein after sending the one or more messages, at least one of the e-mail aliases becomes invalid, preventing one or more of the individuals whose e-mail aliases have become invalid from receiving any further messages from their respective e-mail aliases while their respective e-mail aliases are invalid.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE BLUE TORCH FINANCE LLC PREVIOUSLY RECORDED ON REEL 059800 FRAME 0834. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded May 5, 2023
From: COFENSE INC.
To: BLUE TORCH FINANCE LLC
Reel/Frame 064381/0245 →
RELEASE OF SECURITY INTEREST Recorded May 6, 2022
From: ORIX GROWTH CAPITAL, LLC
To: COFENSE INC.; COFENSE BIDCO CORPORATION
Reel/Frame 059864/0955 →
SECURITY INTEREST Recorded May 3, 2022
From: COFENSE INC.
To: BLUE TORCH CAPITAL LP
Reel/Frame 059800/0834 →
SECURITY INTEREST Recorded Oct 4, 2021
From: COFENSE BIDCO CORPORATION; COFENSE INC.
To: ORIX GROWTH CAPITAL, LLC, AS ADMINSTRATIVE AGENT
Reel/Frame 057692/0722 →
RELEASE OF SECURITY INTEREST Recorded Oct 3, 2019
From: SILICON VALLEY BANK
To: COFENSE, INC.
Reel/Frame 050616/0262 →
SECURITY INTEREST Recorded Sep 24, 2019
From: COFENSE INC.
To: ORIX GROWTH CAPITAL, LLC
Reel/Frame 050478/0889 →
MERGER AND CHANGE OF NAME Recorded Jan 15, 2019
From: PHISHME INC; POSEIDON MERGER SUB 2 INC; COFENSE INC
To: COFENSE INC
Reel/Frame 048016/0424 →
SECURITY INTEREST Recorded Mar 24, 2015
From: PHISHME INC.
To: SILICON VALLEY BANK
Reel/Frame 035246/0017 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2014
From: BELANI, ROHYT; HIGBEE, AARON; GREAUX, SCOTT
To: PHISHME, INC.
Reel/Frame 034083/0195 →
Continuity (1)
Continuation 14160443 · Jan 21, 2014