Organization-Level Ransomware Incrimination via Alert Spike Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organization-level ransomware attacks, which target multiple machines of an organization in a coordinated manner, pose significant detection and mitigation challenges due to their complexity and scale.

Innovation Solution

The implementation of an organization-level incrimination logic combined with sub-organization-level incrimination logics, which detect spikes in cybersecurity alerts across a substantial number of machines and anomalies on individual machines, respectively, to enhance the detection and mitigation of organization-level ransomware attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple security mechanisms are layered across the organization to detect ransomware, then the detection capability improves, but the system complexity increases

Engineering Contradiction:
Improveransomware detection capabilityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security system is segmented into multiple independent incrimination logics (organization-level, sub-organization-level, machine-level) that each operate autonomously on different data granularities. This segmentation allows the system to maintain high detection capability while managing complexity through modular, independent components rather than a monolithic complex system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension of analysis by examining cybersecurity alerts across multiple organizational levels simultaneously (organization-wide, sub-organization, and individual machine). This multi-dimensional approach enhances detection capability by capturing patterns that span different scopes, while the structured hierarchical framework helps manage the complexity of analyzing multiple dimensions.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Measurement precision

If organization-level incrimination logic analyzes alerts across many machines to detect coordinated attacks, then the detection accuracy for organization-level ransomware improves, but the computational resources required increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The analysis workload is segmented across three hierarchical levels: organization-level logic analyzes aggregated alerts across many machines, sub-organization-level logic analyzes intermediate groups, and machine-level logic analyzes individual machine alerts. This segmentation distributes computational resources efficiently, allowing high detection accuracy through comprehensive multi-level analysis while avoiding the excessive resource consumption of a single monolithic analysis system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies partial analysis at each level rather than exhaustive analysis of all data at all levels. The organization-level logic performs partial analysis on aggregated data, sub-organization-level logic performs partial analysis on intermediate data, and machine-level logic performs partial analysis on individual machine data. This partial action approach achieves sufficient detection accuracy while significantly reducing overall computational resource consumption compared to exhaustive analysis.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If the system monitors a substantial percentage of organization's machines for alert spikes, then the ability to detect organization-level ransomware improves, but the time required for detection increases

Engineering Contradiction:
Improvedetection reliabilityVSAvoiddetection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The monitoring scope is segmented into multiple organizational levels with different thresholds. Organization-level logic monitors alerts across a substantial percentage of machines for coordinated attacks, sub-organization-level logic monitors intermediate groups, and machine-level logic monitors individual machines. This segmentation enables the system to detect organization-level ransomware reliably through multi-level monitoring while reducing detection time by identifying attacks at appropriate granularities rather than requiring complete organization-wide analysis.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies partial monitoring at each level rather than requiring complete monitoring of all machines at all levels. By implementing partial monitoring with appropriate thresholds at organization, sub-organization, and machine levels, the system achieves reliable detection of organization-level ransomware while significantly reducing the time required compared to exhaustive monitoring of every machine.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12301615B2Organization-level ransomware incrimination
Publication Date: 2025.05.13 MICROSOFT TECHNOLOGY LICENSING LLC
  • US12301615B2 patent drawing
  • US12301615B2 patent drawing
  • US12301615B2 patent drawing

AI summary

Some embodiments help protect an organization against ransomware attacks by combining incrimination logics. An organizational-level incrimination logic helps detect alert spikes across many machines, which collectively indicate an attack. Graph-based incrimination logics help detect infestations of even a few machines, and local incrimination logics focus on protecting respective individual machines. Graph-based incrimination logics may compare monitored system graphs to known ransomware attack graphs. Graphs may have devices as nodes and device network connectivity, repeated files, repeated processes or actions, or other connections as edges. Statistical analyses and machine learning models may be employed as incrimination logics. Search logics may find additional incrimination candidates that would otherwise evade detection, based on files, processes, IP addresses, devices, accounts, or other computational entities previously incriminated. Incrimination engine results are forwarded to endpoint protection systems, intrusion protection systems, authentication controls, or other intervention mechanisms to enhance monitored system security.