Attacker-Focused Granular Blocking Before Account Disablement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity measures often fail to rapidly and accurately detect cyberattacks, leading to potential significant damage before intervention, as they wait for high confidence in attack detection, thereby risking data integrity, confidentiality, privacy, and system availability.

Innovation Solution

Implementing attacker-focused granular action disruption (AFGAD) functionality that observes a precursor action sequence, discerns a likely incrimination action, and blocks it before full account disablement, maintaining permissions for legitimate activities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing cybersecurity measures wait for high confidence in attack detection before intervention, then false positive disruptions are reduced, but damage from attacks increases due to delayed detection

Engineering Contradiction:
Improveaccuracy of attack detectionVSAvoidtime to detect attack
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary analysis of user account actions to identify precursor sequences that indicate potential attacks. By detecting these precursor patterns before full attack execution, the system can intervene earlier while maintaining reliability through pattern-based confidence assessment rather than waiting for complete attack confirmation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The attack detection process is segmented into multiple stages: observing precursor actions, identifying incrimination actions, and executing targeted blocks. This segmentation allows the system to intervene at intermediate stages with granular blocking of specific actions rather than waiting for complete attack confirmation, reducing detection time while maintaining accuracy through staged confidence building.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If user accounts are completely disabled upon suspicious activity, then attack damage is limited, but legitimate user activities are also disrupted

Engineering Contradiction:
Improvedamage from attackVSAvoidlegitimate system use
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

Instead of applying uniform account disablement, the system applies granular blocking that targets specific incrimination actions while leaving other account permissions intact. This localised approach blocks only the harmful actions identified through precursor analysis, allowing legitimate user activities to continue uninterrupted while still limiting attack damage.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system applies partial blocking by targeting only specific actions rather than completely disabling the account. This partial action is sufficient to prevent attack progression while maintaining ease of operation for legitimate activities. The blocking is calibrated to match the severity and specificity of the detected precursor patterns.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If broad account disabling is used to prevent attacks, then security coverage is comprehensive, but fine-grained control over specific malicious actions is lost

Engineering Contradiction:
Improvesecurity coverageVSAvoidgranularity of control
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security control mechanism is segmented into action-level granularity, where individual incrimination actions can be blocked independently. This segmentation provides both comprehensive security coverage by targeting specific malicious actions and fine-grained control by allowing selective blocking rather than blanket account disablement.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The blocking mechanism is dynamic and adaptive, adjusting the level of restriction based on the detected precursor patterns and confidence levels. The system can escalate from granular action blocking to broader account disabling as the attack progresses or confidence increases, providing both comprehensive coverage and fine-grained control as needed.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP4614366A1Attacker-focused granular action disruption
Publication Date: 2025.09.10 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP4614366A1 patent drawingFigure 1~3
  • EP4614366A1 patent drawingFigure 4~5
  • EP4614366A1 patent drawingFigure 6~7

AI summary

Some embodiments provide attacker-focused granular disruption functionality to detect and defend against cyberattacks. An embodiment observes that a user account or a user session has executed one or more precursor events but has not executed an incrimination action. The incrimination action is more likely, by at least a specified amount, to be performed by an attacker-driven account or session than by a non-attacker-driven account or session. Performance of the incrimination action is preemptively blocked, without disabling the account or session. The block is focused on the incrimination action, and in some scenarios the embodiment also blocks performance of similar actions. After an attempt by the account or session to perform the blocked incrimination action, larger blocks on activity are enforced, up to and including disablement, because the attempt indicates strongly that the account or session is driven by an attacker.