IP Library › Granted Patent US 12,301,615
Granted Patent B2
US 12,301,615 · App. 17/727,759 · Granted May 13, 2025

Organization-level ransomware incrimination

Inventors: Arie Agranonik (Herzliya, IL); Shay Kels (Givatayim, IL); Amir Rubin (Vancouver, CA); Charles Edouard Elie Bettan (Tel Aviv, IL); Yair Tsarfaty (Nahariya, IL); Itai Kollmann Dekel (Herzliya, IL)
Assignee: Microsoft Technology Licensing, LLC
H04L63/145G06N3/04H04L63/1416H04L63/1425H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,301,615
App. No.
17/727,759
Granted
May 13, 2025
Kind
B2
Abstract

Some embodiments help protect an organization against ransomware attacks by combining incrimination logics. An organizational-level incrimination logic helps detect alert spikes across many machines, which collectively indicate an attack. Graph-based incrimination logics help detect infestations of even a few machines, and local incrimination logics focus on protecting respective individual machines. Graph-based incrimination logics may compare monitored system graphs to known ransomware attack graphs. Graphs may have devices as nodes and device network connectivity, repeated files, repeated processes or actions, or other connections as edges. Statistical analyses and machine learning models may be employed as incrimination logics. Search logics may find additional incrimination candidates that would otherwise evade detection, based on files, processes, IP addresses, devices, accounts, or other computational entities previously incriminated. Incrimination engine results are forwarded to endpoint protection systems, intrusion protection systems, authentication controls, or other intervention mechanisms to enhance monitored system security.

Claims (61)

1. A computing system which is configured to help protect an organization against a ransomware attack by an organizational ransomware that targets multiple machines of the organization, the computing system comprising:

a digital memory;

an organization-level incrimination logic configured to detect a spike in cybersecurity alerts which occur collectively on at least a specified number of machines of the organization or on at least a specified percentage of machines of the organization, or both;

at least one sub-organization-level incrimination logic configured to detect a cybersecurity anomaly on at least one machine of the organization without regard to the organization-level incrimination logic specified number of machines of the organization and without regard to the organization-level incrimination logic specified percentage of machines of the organization;

an incrimination logics interface in operable digital communication with the incrimination logics;

a processor in operable communication with the digital memory, the processor configured to execute organizational protection against the organizational ransomware, the execution of organizational protection comprising execution of a two-level approach which combines consideration of alerts from a group of machines by using the organization-level incrimination logic with consideration of alerts from fewer machines or from only a single machine by using the at least one sub-organization-level incrimination logic, in order to detect organizational ransomware, the organizational ransomware being a particular kind of malware which is designed to spread among multiple machines without detection and then present a ransom demand, the organizational protection including: collecting at least one incrimination candidate, the incrimination candidate comprising a set of one or more attack indication computational entities, the collecting based on at least one cybersecurity alert specifying at least one computational entity of at least one machine of the organization, the at least one incrimination candidate including the at least one computational entity, submitting the at least one collected incrimination candidate to the incrimination logics interface and in response receiving an incrimination boost attempt result, determining that the incrimination boost attempt result indicates a boost in an incrimination confidence past a specified threshold, marking each computational entity specified in the at least one cybersecurity alert as an incriminated computational entity, the marking being in response to the boost attempt result indicating that the incrimination confidence passed the specified threshold, and notifying an intervention mechanism of the incriminated computational entity.

2. The computing system of claim 1 , wherein the at least one sub-organization-level incrimination logic comprises a graph-based incrimination logic, the graph-based incrimination logic comprising computing hardware configured by software to detect a cybersecurity anomaly based on a digital graph representation of the following: at least two machines of the organization, at least one connection between machines of the organization, and at least one machine attribute or at least one connection attribute or both.

3. The computing system of claim 2 , wherein the at least one sub-organization-level incrimination logic further comprises a local incrimination logic, the local incrimination logic comprising computing hardware configured by software to detect a cybersecurity anomaly based on a digital representation of data or computational activity or both on a particular machine of the organization.

4. The computing system of claim 1 , wherein the processor is further configured to search for an additional incrimination candidate based on at least one incriminated computational entity.

5. The computing system of claim 1 , further characterized in at least one of the following ways:

the organization-level incrimination logic comprises computing hardware configured by a machine learning software model trained using alert spike data derived from multiple ransomware organizational-level attacks;

the organization-level incrimination logic comprises computing hardware configured by a machine learning software model trained by supervised learning using alert spike data derived from at least one ransomware organizational-level attack;

the sub-organization-level incrimination logic comprises a graph-based incrimination logic, which comprises computing hardware configured by a graph convolutional neural network machine learning software model trained using a graph having nodes which represent machines of the organization, edges which represent connections between machines of the organization, and at least one machine attribute or at least one connection attribute or both; or

the sub-organization-level incrimination logic comprises a graph-based incrimination logic, which comprises computing hardware configured by a graph machine learning software model trained by supervised learning using graphs having nodes which represent machines of the organization, and edges which represent connections between machines of the organization.

6. A method for protecting an organization against a ransomware attack by an organizational ransomware, the organizational ransomware being a particular kind of malware which is designed to spread among multiple machines without detection and then present a ransom demand, the method executed by a computing system, the method comprising:

collecting at least one incrimination candidate based on at least one cybersecurity alert specifying at least one computational entity, the incrimination candidate comprising a set of one or more attack indication computational entities;

submitting at least one collected incrimination candidate to an organization-level incrimination logic via an organization-level incrimination logic interface and in response receiving an organization-level incrimination boost attempt result, the organization-level incrimination logic configured to detect a spike in cybersecurity alerts which occur collectively on at least a specified number of machines of the organization or on at least a specified percentage of machines of the organization, or both;

submitting at least one collected incrimination candidate to at least one sub-organization-level incrimination logic via at least one sub-organization-level incrimination interface and in response receiving at least one sub-organization-level incrimination boost attempt result, the sub-organization-level incrimination logic configured to detect a cybersecurity anomaly on at least one machine of the organization without regard to the organization-level incrimination logic specified number of machines of the organization and without regard to the organization-level incrimination logic specified percentage of machines of the organization;

determining the incrimination boost attempt results collectively indicate a boost in an incrimination confidence past the specified threshold, and marking each computational entity specified in the at least one cybersecurity alert as an incriminated computational entity which is compromised by the organizational ransomware, the marking being in response to the boost attempt results collectively indicating that the incrimination confidence passed the specified threshold; and

notifying an intervention mechanism of the at least one incriminated computational entity;

wherein the method comprises execution of a two-level approach which combines consideration of alerts from a group of machines by using the organization-level incrimination logic with consideration of alerts from fewer machines or from only a single machine by using the at least one sub-organization-level incrimination logic, in order to detect organizational ransomware.

7. The method of claim 6 , further comprising:

receiving the at least one collected incrimination candidate from the organization-level incrimination logic interface;

executing an organization-level incrimination logic which includes performing a statistical analysis of alerts from a substantial amount of machines of the organization, the substantial amount including at least fifteen percent of the machines of the organization or at least ten machines of the organization, or both;

determining the organization-level incrimination boost attempt result based on at least whether the executing identifies an anomaly; and

sending the organization-level incrimination boost attempt result to the organization-level incrimination logic interface.

8. The method of claim 6 , further comprising:

receiving the at least one collected incrimination candidate from the organization-level incrimination logic interface;

executing an organization-level incrimination logic which includes a machine learning model trained using alert data derived from multiple ransomware organizational-level attacks;

determining the organization-level incrimination boost attempt result based on at least an output of the machine learning model; and

sending the organization-level incrimination boost attempt result to the organization-level incrimination logic interface.

9. The method of claim 6 , further comprising:

receiving the at least one collected incrimination candidate from the sub-organization-level incrimination logic interface;

executing a sub-organization-level incrimination logic which includes a machine learning model trained using graph data derived from multiple ransomware organizational-level attacks, the graph data including a graph having nodes which represent machines of the organization, and edges which represent connections between machines of the organization;

determining the sub-organization-level incrimination boost attempt result based on at least an output of the machine learning model; and

sending the sub-organization-level incrimination boost attempt result to the sub-organization-level incrimination logic interface.

10. The method of claim 6 , further comprising searching for an additional incrimination candidate based on at least one incriminated computational entity, and wherein the at least one incriminated computational entity includes or identifies at least one of the following: a computational process in a kernel or an application program, a file, an IP address, a device, or a user account.

11. The method of claim 6 , further comprising executing a sub-organization-level incrimination logic which includes performing at least one of the following graph classification algorithms:

a graph neural network algorithm;

a graph statistical anomaly detection algorithm; or

a bag of words algorithm based on graph node features.

12. The method of claim 6 , further comprising executing a sub-organization-level incrimination logic which includes performing at least one of the following local incrimination logic sequences:

collecting an incriminated file from the at least one cybersecurity alert for a particular machine, and searching other machines of the organization for a copy of the incriminated file;

checking a precision of the at least one cybersecurity alert for a particular machine, and searching the particular machine for a remoting connection; or

discerning an aggregated process tree alerts score of the at least one cybersecurity alert for a particular machine, and searching the particular machine for a remoting connection.

13. The method of claim 6 , wherein the method comprises boosting the incrimination confidence based on at least the following incrimination confidence boost condition: a graph-based sub-organization-level incrimination logic determines that a graph representing the incrimination candidate is similar to graphs of ransomware incidents.

14. The method of claim 6 , wherein the method comprises boosting the incrimination confidence based on at least the following incrimination confidence boost condition: a local sub-organization-level incrimination logic determines that a particular machine of the organization is under ransomware attack, and a computational entity of the incrimination candidate is also found on at least a specified number of other machines of the organization within a specified time period.

15. The method of claim 6 , wherein the method comprises boosting the incrimination confidence based on at least the following incrimination confidence boost condition: at least a specified number of different sub-organization-level incrimination logics and at least a specified number of different machines of the organization are identified in cybersecurity alerts within a specified time period.

16. A computer-readable storage device configured with data and instructions which upon execution by a processor cause a computing system to perform a method for protecting an organization against a ransomware attack by an organizational ransomware, the organizational ransomware being a particular kind of malware which is designed to spread among multiple machines without detection and then present a ransom demand, the method comprising:

submitting at least one incrimination candidate to an organization-level incrimination logic via an organization-level incrimination logic interface and in response receiving an organization-level incrimination boost attempt result, the organization-level incrimination logic configured to detect a spike in cybersecurity alerts which occur collectively on at least a specified number of machines of the organization or on at least a specified percentage of machines of the organization, or both, the incrimination candidate comprising a set of one or more attack indication computational entities;

submitting at least one incrimination candidate to at least one sub-organization-level incrimination logic via at least one sub-organization-level incrimination interface and in response receiving at least one sub-organization-level incrimination boost attempt result, the sub-organization-level incrimination logic configured to detect a cybersecurity anomaly on at least one machine of the organization without regard to the organization-level incrimination logic specified number of machines of the organization and without regard to the organization-level incrimination logic specified percentage of machines of the organization;

ascertaining that the incrimination boost attempt results collectively indicate a boost in an incrimination confidence past a specified threshold; and

in response to the ascertaining, notifying an intervention mechanism that a computational entity of the incrimination candidate is an incriminated computational entity which is compromised by the organizational ransomware;

wherein the method comprises execution of a two-level approach which combines consideration of alerts from a group of machines by using the organization-level incrimination logic with consideration of alerts from fewer machines or from only a single machine by using the at least one sub-organization-level incrimination logic, in order to detect organizational ransomware.

17. The computer-readable storage device of claim 16 , wherein the method further comprises performing at least one of the following graph classification algorithms:

a graph neural network algorithm; or

a graph statistical anomaly detection algorithm.

18. The computer-readable storage device of claim 16 , wherein the method comprises performing a local incrimination logic sequence which includes:

collecting an incriminated file from the at least one cybersecurity alert for a particular machine, and searching other machines of the organization for a copy of the incriminated file.

19. The computer-readable storage device of claim 16 , wherein the method comprises performing a local incrimination logic sequence which includes: checking a precision of the at least one cybersecurity alert for a particular machine, and searching the particular machine for a remoting connection.

20. The computer-readable storage device of claim 16 , wherein the method comprises performing a local incrimination logic sequence which includes: discerning an aggregated process tree alerts score of the at least one cybersecurity alert for a particular machine, and searching the particular machine for a remoting connection.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2022
From: AGRANONIK, ARIE; KELS, SHAY; RUBIN, AMIR; BETTAN, CHARLES EDOUARD ELIE; TSARFATY, YAIR; KOLLMANN DEKEL, ITAI
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 059688/0092 →
Continuity (1)
Related Publication 20230344860A1 · Oct 26, 2023
References Cited (30)
US 11503075B1 · Sirianni · 2022 [cited by examiner]
US 11509682B1 · Paget · 2022 [cited by examiner]
US 20060236392A1 · Thomas · 2006 [cited by examiner]
US 20150180890A1 · Ronen et al. · 2015 [cited by applicant]
US 20150371044A1 · Horne · 2015 [cited by examiner]
US 20170078324A1 · Bordawekar · 2017 [cited by examiner]
US 20180004948A1 · Martin et al. · 2018 [cited by applicant]
US 20190173893A1 · Muddu · 2019 [cited by examiner]
US 20200042700A1 · Li et al. · 2020 [cited by applicant]
US 20200137083A1 · Chen · 2020 [cited by examiner]
US 20200213322A1 · Anand · 2020 [cited by examiner]
US 20200389496A1 · Xuan · 2020 [cited by applicant]
US 20210406365A1 · Neil et al. · 2021 [cited by applicant]
US 20210406368A1 · Agranonik et al. · 2021 [cited by applicant]
US 20220159034A1 · Volkov · 2022 [cited by examiner]
US 20230325292A1 · Ardel · 2023 [cited by examiner]
WO 2020040878A1 · 2020 [cited by applicant]
“International Search Report and Written Opinion Issued in PCT Application No. PCT/US2023/015718”, Mailed Date: Jun. 23, 2023, 15 Pages. [cited by applicant]
Danai Koutra, et al., “Algorithms for Graph Similarity and Subgraph Matching”, retrieved from << https://www.cs.cmu.edu/˜jingx/docs/DBreport.pdf >>, Dec. 4, 2011, 50 pages. [cited by applicant]
Kyle Johnson, “3 ransomware detection techniques to catch an attack”, retrieved from <<https://www.techtarget.com/searchsecurity/feature/3-ransomware-detection-techniques-to-catch-an-attack>>, no later than Apr. 8, 2022… [cited by applicant]
Francesco Casalegno, “Graph Convolutional Networks—Deep Learning on Graphs”, retrieved from <<https://towardsdatascience.com/graph-convolutional-networks-deep-99d7fee5706f>>, Jan. 22, 2021, 10 pages. [cited by applicant]
Ruofan Wang and Kelly Kang, “AI-driven adaptive protection against human-operated ransomware”, retrieved from <<https://www.microsoft.com/security/blog/2021/11/15/ai-driven-adaptive-protection-against-human-operated-ran… [cited by applicant]
Sylvie Liu, “What's new: Fusion Detection for Ransomware”, retrieved from <<https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/what-s-new-fusion-detection-for-ransomware/ba-p/2621373?msclkid=28b5b1f9af3d11ec… [cited by applicant]
Justin Carroll, et al., “Inside Microsoft 365 Defender: Attack modeling for finding and stopping lateral movement”, retrieved from <<https://www.microsoft.com/security/blog/2020/06/10/the-science-behind-microsoft-threat… [cited by applicant]
Eric Avena, “The science behind Microsoft Threat Protection: Attack modeling for finding and stopping evasive ransomware”, retrieved from <<https://argonsys.com/microsoft-cloud/library/the-science-behind-microsoft-threa… [cited by applicant]
Subash Poudyal, et al., “A Framework for Analyzing Ransomware using Machine Learning”, retrieved from <<https://www.researchgate.net/publication/334559366_A_Framework_for_Analyzing_Ransomware_using_Machine_Learning>>, J… [cited by applicant]
“The growing threat of ransomware”, retrieved from <<https://blogs.microsoft.com/on-the-issues/2021/07/20/the-growing-threat-of-ransomware/?msclkid=28b5ddc4af3d11ecad546757ccb5a953>>, Jul. 20, 2021, 14 pages. [cited by applicant]
“Human-operated ransomware attacks: A preventable disaster”, retrieved from <<https://www.microsoft.com/security/blog/2020/03/05/human-operated-ransomware-attacks-a-preventable-disaster/>>, Mar. 5, 2020, 29 pages. [cited by applicant]
“Human-operated ransomware”, retrieved from <<https://docs.microsoft.com/en-us/security/compass/human-operated-ransomware>>, Feb. 18, 2022, 7 pages. [cited by applicant]
Vangel, et al., “Feedback-loop Blocking”, Retrieved From: https://learn.microsoft.com/en-us/microsoft-365/security/defender-endpoint/feedback-loop-blocking?view=o365-worldwide, Jul. 19, 2023, 2 Pages. [cited by applicant]