Spreadsheet Spatial Metadata for Ransomware Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing complexity and volume of data pose challenges in rapid data management, storage, and security, particularly in detecting unauthorized access and ransomware threats, which are exacerbated by stringent data protection regulations like GDPR that require swift notification of data breaches.
Innovation Solution
A data management system that includes a storage device for virtual machine snapshots, a text content verifier, and processors to identify and generate spreadsheet spatial metadata, which is then used to verify audit events and enhance the speed and accuracy of text content verification through a tiered array of verifiers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional text verification methods are used to scan all files for security threats, then comprehensive security coverage is achieved, but computation time increases significantly and detection speed decreases
Solution Approach 1:
The patent segments the verification process into two distinct phases: a fast filter phase that uses spatial metadata (row/column dimensions, formatted text patterns) to quickly identify suspicious spreadsheet structures, and a slow verifier phase that performs comprehensive text analysis only on files that pass the filter. This segmentation resolves the contradiction by achieving comprehensive security coverage through the filter while minimizing computation time by limiting full verification to only suspicious files.
Solution Approach 2:
The patent performs preliminary extraction of spatial metadata (row counts, column counts, formatted text patterns) from spreadsheets before the main verification process. This preliminary action creates a lightweight index that enables rapid filtering without requiring full text verification, thus reducing computation time while maintaining detection accuracy for ransomware and unauthorized access patterns.
2Reliability
If comprehensive text verification is performed on all files to ensure security, then detection accuracy improves, but processing speed decreases
Solution Approach 1:
The patent applies different verification qualities to different files based on their spatial characteristics. Files with suspicious spatial patterns (e.g., excessive rows, unusual column configurations, specific formatted text patterns) receive full verification, while files with normal spatial characteristics receive minimal or no verification. This local quality approach maintains high detection accuracy for threats while dramatically improving overall processing speed.
Solution Approach 2:
The patent performs partial verification on most files by checking only spatial metadata characteristics rather than complete text content. Full verification is performed excessively only on files that exhibit suspicious spatial patterns. This partial/excessive action strategy achieves sufficient detection accuracy for security purposes while maintaining high processing speed across the entire file set.
3Productivity
If spatial metadata extraction and tiered verification arrays are implemented, then detection speed improves, but system complexity increases
Solution Approach 1:
The patent segments the verification system into a tiered array of verifiers with different complexity levels. The first tier uses simple spatial metadata filtering, while subsequent tiers perform progressively more complex analysis only on files that pass previous tiers. This segmentation resolves the complexity issue by organizing verification tasks into manageable stages, improving detection speed through the tiered structure while keeping each individual verifier relatively simple.
Solution Approach 2:
The patent performs preliminary spatial metadata extraction and analysis before engaging the full verification array. This preliminary action simplifies the overall system complexity by pre-processing files and identifying suspicious characteristics early, allowing the tiered verification array to focus only on relevant files rather than processing all files through every verification layer.
Data Source
AI summary
Some examples relate generally to computer architecture software data classification and information security and, in some more particular aspects, to verifying information or events in a file system using spatial data.


