US2021385242A1PendingUtilityA1

Methods and sytems for implementing a phishing assessment

Assignee: CISCO TECH INCPriority: Oct 29, 2015Filed: Aug 23, 2021Published: Dec 9, 2021
Est. expiryOct 29, 2035(~9.2 yrs left)· nominal 20-yr term from priority
Inventors:Jon Oberheide
H04L 63/1433H04L 63/10H04L 63/1483H04L 63/1491H04L 63/105
72
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A system, method, and computer program product for implementing a phishing assessment of a target computer network that includes a phishing assessment platform for generating parameters for the phishing assessment; generating the phishing assessment parameters includes identifying a target domain name for the phishing assessment; identifying a pseudo domain name based on the target domain name; generating a pseudo web page using one or more features and attributes of an entity; and implementing the phishing assessment using the pseudo domain name and pseudoweb page.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for testing security of a computer system, the method comprising:
 generating a plurality of phishing domain names based on a legitimate domain name associated with a target entity;   rating each phishing domain name of the plurality of phishing domain names based on a visual similarity of the phishing domain name to the legitimate domain name; and   implementing a test phishing campaign based on the rating.   
     
     
         2 . The method of  claim 1 , wherein the generating of the plurality of phishing domain names comprises transforming the legitimate domain name based on at least two homoglyphic transformation techniques. 
     
     
         3 . The method of  claim 1 , wherein the rating of each phishing domain name of the plurality of phishing domain names is based, at least in part, on a visual similarity between the legitimate domain name and the phishing domain name. 
     
     
         4 . The method of  claim 3 , wherein the rating of each phishing domain name of the plurality of phishing domain names is further based, at least in part, on a phonic of the phishing domain name. 
     
     
         5 . The method of  claim 1 , further comprising:
 building a plurality of phishing communications that each references a different phishing domain name of the plurality of phishing domain names; and   transmitting the plurality of phishing communications to the target entity.   
     
     
         6 . The method of  claim 5 , further comprising:
 receiving one or more responses to each of the plurality of phishing communications; and   collecting information based on the one or more responses.   
     
     
         7 . The method of  claim 1 , further comprising determining a time to implement the test phishing campaign based on an indication of when network traffic or an email count is relatively high, wherein the implementing of the test phishing campaign is initiated at the time. 
     
     
         8 . The method of  claim 1 , wherein the implementing of the test phishing campaign comprises initiating two or more of email, instant messaging, a phone call, a text message, or a social network communication with the target entity. 
     
     
         9 . One or more phishing assessment servers, comprising:
 one or more processors; and   one or more memories storing instructions that when executed configure the one or more processors to perform operations comprising:
 generating a plurality of phishing domain names based on a legitimate domain name associated with a target entity; 
 rating each phishing domain name of the plurality of phishing domain names based on a visual similarity of the phishing domain name to the legitimate domain name; and 
 implementing a test phishing campaign based on the rating. 
   
     
     
         10 . The one or more phishing assessment servers of  claim 9 , wherein the generating of the plurality of phishing domain names comprises transforming the legitimate domain name based on at least two homoglyphic transformation techniques. 
     
     
         11 . The one or more phishing assessment servers of  claim 9 , wherein the rating of each phishing domain name of the plurality of phishing domain names is based, at least in part, on a visual similarity between the legitimate domain name and the phishing domain name. 
     
     
         12 . The one or more phishing assessment servers of  claim 11 , wherein the rating of each phishing domain name of the plurality of phishing domain names is further based, at least in part, on a phonic of the phishing domain name. 
     
     
         13 . The one or more phishing assessment servers of  claim 9 , the operations further comprising:
 building a plurality of phishing communications that each references a different phishing domain name of the plurality of phishing domain names; and   transmitting the plurality of phishing communications to the target entity.   
     
     
         14 . The one or more phishing assessment servers of  claim 13 , the operations further comprising:
 receiving one or more responses to each of the plurality of phishing communications; and   collecting information based on the one or more responses.   
     
     
         15 . The one or more phishing assessment servers of  claim 9 , the operations further comprising determining a time to implement the test phishing campaign based on an indication of when network traffic or an email count is relatively high, wherein the implementing of the test phishing campaign is initiated at the time. 
     
     
         16 . A computer readable storage medium comprising instructions that when executed configure one or more processors to perform operations comprising:
 generating a plurality of phishing domain names based on a legitimate domain name associated with a target entity;   rating each phishing domain name of the plurality of phishing domain names based on a visual similarity of the phishing domain name to the legitimate domain name; and   implementing a test phishing campaign based on the-rating.   
     
     
         17 . The computer readable storage medium of  claim 16 , wherein the rating of each phishing domain name of the plurality of phishing domain names is based, at least in part, on a visual similarity between the legitimate domain name and the phishing domain name. 
     
     
         18 . The computer readable storage medium of  claim 17 , wherein the rating of each phishing domain name of the plurality of phishing domain names is further based, at least in part, on a phonic of the phishing domain name. 
     
     
         19 . The computer readable storage medium of  claim 16 , the operations further comprising:
 building a plurality of phishing communications that each references a different phishing domain name of the plurality of phishing domain names; and   transmitting the plurality of phishing communications to the target entity.   
     
     
         20 . The computer readable storage medium of  claim 19 , the operations further comprising:
 receiving one or more responses to each of the plurality of phishing communications; and   collecting information based on the one or more responses.

Join the waitlist — get patent alerts

Track US2021385242A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.