Organization-Level Ransomware Incrimination via Alert Spike Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organization-level ransomware attacks, which target multiple machines of an organization in a coordinated manner, pose significant detection and mitigation challenges due to their complexity and scale.
Innovation Solution
The implementation of an organization-level incrimination logic combined with sub-organization-level incrimination logics, which detect spikes in cybersecurity alerts across a substantial number of machines and anomalies on individual machines, respectively, to enhance the detection and mitigation of organization-level ransomware attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple security mechanisms are layered across the organization to detect ransomware, then the detection capability improves, but the system complexity increases
Solution Approach 1:
The security system is segmented into multiple independent incrimination logics (organization-level, sub-organization-level, machine-level) that each operate autonomously on different data granularities. This segmentation allows the system to maintain high detection capability while managing complexity through modular, independent components rather than a monolithic complex system.
Solution Approach 2:
The patent introduces a new dimension of analysis by examining cybersecurity alerts across multiple organizational levels simultaneously (organization-wide, sub-organization, and individual machine). This multi-dimensional approach enhances detection capability by capturing patterns that span different scopes, while the structured hierarchical framework helps manage the complexity of analyzing multiple dimensions.
2Measurement precision
If organization-level incrimination logic analyzes alerts across many machines to detect coordinated attacks, then the detection accuracy for organization-level ransomware improves, but the computational resources required increase
Solution Approach 1:
The analysis workload is segmented across three hierarchical levels: organization-level logic analyzes aggregated alerts across many machines, sub-organization-level logic analyzes intermediate groups, and machine-level logic analyzes individual machine alerts. This segmentation distributes computational resources efficiently, allowing high detection accuracy through comprehensive multi-level analysis while avoiding the excessive resource consumption of a single monolithic analysis system.
Solution Approach 2:
The system applies partial analysis at each level rather than exhaustive analysis of all data at all levels. The organization-level logic performs partial analysis on aggregated data, sub-organization-level logic performs partial analysis on intermediate data, and machine-level logic performs partial analysis on individual machine data. This partial action approach achieves sufficient detection accuracy while significantly reducing overall computational resource consumption compared to exhaustive analysis.
3Reliability
If the system monitors a substantial percentage of organization's machines for alert spikes, then the ability to detect organization-level ransomware improves, but the time required for detection increases
Solution Approach 1:
The monitoring scope is segmented into multiple organizational levels with different thresholds. Organization-level logic monitors alerts across a substantial percentage of machines for coordinated attacks, sub-organization-level logic monitors intermediate groups, and machine-level logic monitors individual machines. This segmentation enables the system to detect organization-level ransomware reliably through multi-level monitoring while reducing detection time by identifying attacks at appropriate granularities rather than requiring complete organization-wide analysis.
Solution Approach 2:
The system applies partial monitoring at each level rather than requiring complete monitoring of all machines at all levels. By implementing partial monitoring with appropriate thresholds at organization, sub-organization, and machine levels, the system achieves reliable detection of organization-level ransomware while significantly reducing the time required compared to exhaustive monitoring of every machine.
Data Source
AI summary
Some embodiments help protect an organization against ransomware attacks by combining incrimination logics. An organizational-level incrimination logic helps detect alert spikes across many machines, which collectively indicate an attack. Graph-based incrimination logics help detect infestations of even a few machines, and local incrimination logics focus on protecting respective individual machines. Graph-based incrimination logics may compare monitored system graphs to known ransomware attack graphs. Graphs may have devices as nodes and device network connectivity, repeated files, repeated processes or actions, or other connections as edges. Statistical analyses and machine learning models may be employed as incrimination logics. Search logics may find additional incrimination candidates that would otherwise evade detection, based on files, processes, IP addresses, devices, accounts, or other computational entities previously incriminated. Incrimination engine results are forwarded to endpoint protection systems, intrusion protection systems, authentication controls, or other intervention mechanisms to enhance monitored system security.


