9270696

Systems and Method for Identifying and Mitigating Information Security Risks

PublishedFebruary 23, 2016
Assigneenot available in USPTO data we have
Technical Abstract

Patent Claims
20 claims

Legal claims defining the scope of protection, as filed with the USPTO.

1

1. A computer-implemented method for identifying and mitigating information security risks, the method comprising: assigning unique identifiers to a plurality of target e-mail addresses, wherein each e-mail address is associated with an individual user account, respectively; delivering an e-mail message to one or more of the plurality of target e-mail addresses, wherein the e-mail message comprises a hypertext transfer protocol (HTTP) request and a unique identifier associated with a user account; receiving, at a Phishing Metric Tool (PMT), a response including the unique identifier; logging, by the PMT, a training requirement for the user account; tracking, by the PMT, response metrics for the training requirement; redirecting the HTTP request to a phishing training tool (PTT); sending, by the PTT, a notification of a verified identity of the user account and the unique identifier to the PMT; returning a status report for the training requirement, the status report including an indication of whether the user account has failed at least a portion of the training requirement; and redirecting, by the PMT, the user account to undergo an additional training requirement related to the portion of the training requirement which was failed, upon receipt of the status report, when the status report indicates that the user account has failed at least the portion of the training requirement so that the user account is subjected to the additional training requirement, wherein the PMT and the PTT are respectively implemented by at least one processor of a computer processing device.

2

2. The method of claim 1 , wherein each target e-mail address is associated with a user account in an organization, and a training exercise is associated with the training requirement for the user account respectively associated with the target e-mail address.

3

3. The method of claim 2 , further comprising: updating, by the PMT, the status of the training requirement, wherein the status is based at least in part on the tracked response metrics.

4

4. The method of claim 3 , wherein the status indicates at least one of: a response to the e-mail message has not been received; the training exercise is underway; the training exercise has been completed unsuccessfully; the training exercise has been completed successfully; a certificate for a successfully completed training exercise has been generated; and a notification for a completed training exercise has been sent.

5

5. The method of claim 4 , wherein the notification is an e-mail message sent to the target e-mail address.

6

6. The method of claim 4 , further comprising: sending a reminder notification to the target e-mail address in response to determining that the user account has not completed information security training within a pre-determined period of time.

7

7. The method of claim 4 , wherein the notification is an e-mail message sent to an administrator e-mail address associated with a system administrator of the organization.

8

8. The method of claim 7 , further comprising: sending a reminder notification to the administrator e-mail address in response to determining that the user account has not completed information security training within a pre-determined period of time.

9

9. The method of claim 2 , further comprising: receiving, at the PTT, credentials for the user account; validating, by the PTT, the credentials for the user account; and verifying a login to the user account based upon the validated credentials; and sending a start exercise message for the training exercise based upon verifying the login.

10

10. A non-transitory computer readable storage medium having program instructions stored thereon for identifying and mitigating information security risks, the instructions being executable by a processor of a computing device, the instructions comprising: instructions for receiving, at a phishing metrics tool (PMT), a phishing hypertext transfer protocol (HTTP) request; instructions for sending a redirect message from the PMT to a browser session; instructions for receiving, at a phishing training tool (PTT), a request for an application, wherein the request is based at least in part on the received phishing HTTP request; instructions for sending, from the PTT to the browser session, the requested application; instructions for sending, from the PTT, a start message for a first training requirement; instructions for sending, from the PTT, a training exercise associated with the first training requirement; instructions for returning a status report for the first training requirement, the status report including an indication of whether at least a portion of the first training requirement has been failed; and instructions for redirecting, by the PMT, the browser session to undergo an additional training requirement related to portion of the first training requirement which was failed, upon receipt of the status report, when the status report indicates that the at least the portion of the first training requirement has been failed so that a user using the browsing session is subjected to the additional training requirement.

11

11. The non-transitory computer readable storage medium of claim 10 , wherein the instructions further comprise: instructions for determining whether the training exercise has been completed; and instructions for generating a completion message in response to determining that the training exercise has been completed.

12

12. The non-transitory computer readable storage medium of claim 11 , wherein the instructions further comprise: instructions for sending the completion message from the PTT to the PMT in response to determining that the training exercise has been completed.

13

13. The non-transitory computer readable storage medium of claim 10 , wherein the training exercise is an ADOBE™ Flex application.

14

14. The non-transitory computer readable storage medium of claim 10 , wherein the training exercise is an ADOBE™ Flash application.

15

15. The non-transitory computer readable storage medium of claim 10 , wherein the training exercise is an HTML5 application.

16

16. A system capable of identifying and mitigating information security risks, the system comprising: a phishing metric tool (PMT) configured to: receive a phishing hypertext transfer protocol (HTTP) request from a browser session; and send a redirect message to the browser session, the redirect message redirecting the browser session to a phishing training tool (PTT); an e-mail server configured to: send an e-mail message to a target user account, wherein the e-mail message is based on the phishing HTTP request, and wherein the e-mail message includes a unique identifier; and receive a response from the target user account, wherein the response includes the unique identifier; wherein the PTT is configured to: receive an application request based on the response; send the requested application to the browser session; send a start message for a training requirement for the target user account; send a training exercise associated with the training requirement; send a notification to the PMT of an identity of the target user account and the unique identifier; and update a status of the training exercise, the status of the training exercise including an indication of whether the user account has failed at least a portion of the training requirement, wherein the PMT is configured to redirect the user account to undergo an additional training requirement related to portion of the training requirement which was failed, upon receipt of the status, when the status indicates that the user account has failed at least the portion of the training requirement so that the user account is subjected to the additional training requirement, and wherein the PMT and the PTT are respectively implemented by at least one processor of a computer processing device.

17

17. The system of claim 16 , wherein the PTT is in a trusted domain associated with an organization and wherein the target user account is associated with the organization.

18

18. The system of claim 17 , wherein the PMT is in an untrusted domain external to the organization comprising at least one web server and one or more distributed phishing agents.

19

19. The system of claim 16 , wherein the PMT is further configured to send a reminder notification in response to determining that the training exercise has not been completed within a designated time period.

20

20. The system of claim 16 , wherein the PTT is further configured to send a completion notification in response to determining that the training exercise has been completed.

Patent Metadata

Filing Date

Unknown

Publication Date

February 23, 2016

Inventors

Art FRITZSON
Semion BEZRUKOV
Sean PALKA

Want to explore more patents?

Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.

Citation & reuse

Analysis on this page is generated by Patentable — an AI-powered patent intelligence platform. AI-generated summaries, explanations, and analysis may be reused with attribution and a visible link back to the canonical URL below. Patent abstracts and claims are USPTO public domain.

Cite as: Patentable. “SYSTEMS AND METHOD FOR IDENTIFYING AND MITIGATING INFORMATION SECURITY RISKS” (9270696). https://patentable.app/patents/9270696

© 2026 Patentable. All rights reserved.

Patentable is a research and drafting-assistant tool, not a law firm, and does not provide legal advice. Documents we generate are drafts for review by a licensed patent attorney.