US 11,870,807 B2
System and method for phishing email training
Brian E. Hemingway, Sykesville, MD (US); Hayley Newman, Lorong (SG); Todd Arnts, New York, NY (US); Kimm Eagle, New York, NY (US); Kai Yu, New York, NY (US); Roger Rex Allen, III, New York, NY (US); and Julian Boddy, New York, NY (US)
Assigned to JPMORGAN CHASE BANK, N.A., New York, NY (US)
Filed by JPMORGAN CHASE BANK, N.A., New York, NY (US)
Filed on Nov. 6, 2020, as Appl. No. 17/091,565.
Claims priority of provisional application 62/937,719, filed on Nov. 19, 2019.
Prior Publication US 2021/0152596 A1, May 20, 2021
Int. Cl. H04L 29/06 (2006.01); H04L 9/40 (2022.01); H04L 51/08 (2022.01); G06N 20/00 (2019.01); H04L 51/212 (2022.01); H04L 67/50 (2022.01)
CPC H04L 63/1483 (2013.01) [G06N 20/00 (2019.01); H04L 51/08 (2013.01); H04L 51/212 (2022.05); H04L 67/535 (2022.05)] 19 Claims
OG exemplary drawing
 
1. A method for generating test phishing emails with a target difficulty level, comprising:
receiving, by a phishing email training computer program, a target difficulty level, a target population comprising a plurality of members, and a plurality of parameters for a test phishing email, the target population based on a response to a prior phishing email, and the plurality of parameters based on a weakness identified from the response to a prior phishing email, wherein the weakness comprises identifying a certain kind of test phishing email for the target population;
selecting, by the phishing email training computer program, a plurality of test email components from a library of test email components based on the parameters and the target difficulty level;
generating, by the phishing email training computer program, the test phishing using the selected test email components, wherein the test phishing email comprises at least one of a hyperlink and an attachment;
disseminating, by the phishing email training computer program, the test phishing email to the target population;
monitoring, by the phishing email training computer program, a response to the test phishing email from the target population;
identifying, by the phishing email training computer program, one or more automated action to take with one of members of the target population based on the response of the member, wherein the automated action comprises preventing external emails from being delivered to the member; and
executing, by the phishing email training computer program, the automated action.