发明名称 SYSTEMS AND METHOD FOR IDENTIFYING AND MITIGATING INFORMATION SECURITY RISKS
摘要 Methods and systems for Sustained Testing and Awareness Refresh against Phishing threats (STAR*Phish™) are disclosed. In an embodiment, a method assigns schemes and unique identifiers to target e-mail addresses associated with a user accounts. The method delivers e-mail messages to the targeted e-mail addresses, the e-mail messages comprising an HTTP request and a unique identifier associated with each of the user accounts. The method then receives, at a Phishing Metric Tool (PMT), a response including the unique identifier. The PMT logs training requirements for the user accounts, tracks response metrics for the training requirements, and redirects the respective HTTP requests to a phishing training tool (PTT). The PTT sends a notification of the user account identities and the unique identifiers to the PMT and returns a status for the training requirements for the user accounts. Upon completion of the training, the PMT sends completion notifications for the user accounts.
申请公布号 US2014337995(A1) 申请公布日期 2014.11.13
申请号 US201414444673 申请日期 2014.07.28
申请人 BOOZ, ALLEN & HAMILTON 发明人 FRITZSON Art;BEZRUKOV Semion;PALKA Sean
分类号 H04L29/06;H04L12/58 主分类号 H04L29/06
代理机构 代理人
主权项 1. A computer-implemented method for identifying and mitigating information security risks, the method comprising: assigning unique identifiers to a plurality of target e-mail addresses, wherein each e-mail address is associated with an individual user account, respectively; delivering an e-mail message to one or more of the plurality of target e-mail addresses, wherein the e-mail message comprises a hypertext transfer protocol (HTTP) request and a unique identifier associated with a user account; receiving, at a Phishing Metric Tool (PMT), a response including the unique identifier; logging, by the PMT, a training requirement for the user account; tracking, by the PMT, response metrics for the training requirement; redirecting the HTTP request to a phishing training tool (PTT); sending, by the PTT, a notification of a verified identity of the user account and the unique identifier to the PMT; returning a status report for the training requirement, the status report including an indication of whether the user account has failed at least a portion of the training requirement; and redirecting, by the PMT, the user account to undergo an additional training requirement related to the portion of the training requirement which was failed, upon receipt of the status report, when the status report indicates that the user account has failed at least the portion of the training requirement so that the user account is subjected to the additional training requirement, wherein the PMT and the PTT are respectively implemented by at least one processor of a computer processing device.
地址 McLean VA US