US2021385242A1PendingUtilityA1
Methods and sytems for implementing a phishing assessment
Est. expiryOct 29, 2035(~9.2 yrs left)· nominal 20-yr term from priority
Inventors:Jon Oberheide
H04L 63/1433H04L 63/10H04L 63/1483H04L 63/1491H04L 63/105
72
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A system, method, and computer program product for implementing a phishing assessment of a target computer network that includes a phishing assessment platform for generating parameters for the phishing assessment; generating the phishing assessment parameters includes identifying a target domain name for the phishing assessment; identifying a pseudo domain name based on the target domain name; generating a pseudo web page using one or more features and attributes of an entity; and implementing the phishing assessment using the pseudo domain name and pseudoweb page.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method for testing security of a computer system, the method comprising:
generating a plurality of phishing domain names based on a legitimate domain name associated with a target entity; rating each phishing domain name of the plurality of phishing domain names based on a visual similarity of the phishing domain name to the legitimate domain name; and implementing a test phishing campaign based on the rating.
2 . The method of claim 1 , wherein the generating of the plurality of phishing domain names comprises transforming the legitimate domain name based on at least two homoglyphic transformation techniques.
3 . The method of claim 1 , wherein the rating of each phishing domain name of the plurality of phishing domain names is based, at least in part, on a visual similarity between the legitimate domain name and the phishing domain name.
4 . The method of claim 3 , wherein the rating of each phishing domain name of the plurality of phishing domain names is further based, at least in part, on a phonic of the phishing domain name.
5 . The method of claim 1 , further comprising:
building a plurality of phishing communications that each references a different phishing domain name of the plurality of phishing domain names; and transmitting the plurality of phishing communications to the target entity.
6 . The method of claim 5 , further comprising:
receiving one or more responses to each of the plurality of phishing communications; and collecting information based on the one or more responses.
7 . The method of claim 1 , further comprising determining a time to implement the test phishing campaign based on an indication of when network traffic or an email count is relatively high, wherein the implementing of the test phishing campaign is initiated at the time.
8 . The method of claim 1 , wherein the implementing of the test phishing campaign comprises initiating two or more of email, instant messaging, a phone call, a text message, or a social network communication with the target entity.
9 . One or more phishing assessment servers, comprising:
one or more processors; and one or more memories storing instructions that when executed configure the one or more processors to perform operations comprising:
generating a plurality of phishing domain names based on a legitimate domain name associated with a target entity;
rating each phishing domain name of the plurality of phishing domain names based on a visual similarity of the phishing domain name to the legitimate domain name; and
implementing a test phishing campaign based on the rating.
10 . The one or more phishing assessment servers of claim 9 , wherein the generating of the plurality of phishing domain names comprises transforming the legitimate domain name based on at least two homoglyphic transformation techniques.
11 . The one or more phishing assessment servers of claim 9 , wherein the rating of each phishing domain name of the plurality of phishing domain names is based, at least in part, on a visual similarity between the legitimate domain name and the phishing domain name.
12 . The one or more phishing assessment servers of claim 11 , wherein the rating of each phishing domain name of the plurality of phishing domain names is further based, at least in part, on a phonic of the phishing domain name.
13 . The one or more phishing assessment servers of claim 9 , the operations further comprising:
building a plurality of phishing communications that each references a different phishing domain name of the plurality of phishing domain names; and transmitting the plurality of phishing communications to the target entity.
14 . The one or more phishing assessment servers of claim 13 , the operations further comprising:
receiving one or more responses to each of the plurality of phishing communications; and collecting information based on the one or more responses.
15 . The one or more phishing assessment servers of claim 9 , the operations further comprising determining a time to implement the test phishing campaign based on an indication of when network traffic or an email count is relatively high, wherein the implementing of the test phishing campaign is initiated at the time.
16 . A computer readable storage medium comprising instructions that when executed configure one or more processors to perform operations comprising:
generating a plurality of phishing domain names based on a legitimate domain name associated with a target entity; rating each phishing domain name of the plurality of phishing domain names based on a visual similarity of the phishing domain name to the legitimate domain name; and implementing a test phishing campaign based on the-rating.
17 . The computer readable storage medium of claim 16 , wherein the rating of each phishing domain name of the plurality of phishing domain names is based, at least in part, on a visual similarity between the legitimate domain name and the phishing domain name.
18 . The computer readable storage medium of claim 17 , wherein the rating of each phishing domain name of the plurality of phishing domain names is further based, at least in part, on a phonic of the phishing domain name.
19 . The computer readable storage medium of claim 16 , the operations further comprising:
building a plurality of phishing communications that each references a different phishing domain name of the plurality of phishing domain names; and transmitting the plurality of phishing communications to the target entity.
20 . The computer readable storage medium of claim 19 , the operations further comprising:
receiving one or more responses to each of the plurality of phishing communications; and collecting information based on the one or more responses.Join the waitlist — get patent alerts
Track US2021385242A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.