How to alert for high traffic utilization?

Ransomware has a habit of copying large amounts of data out to the WAN. How can I monitor/alert on the WAN interface when there is high, sustained traffic utilization that might indicate large amounts of data are leaving the LAN going to the Internet?
Category: Firewall Management and Analytics
I too am interested in this.
Firewall cannot do this by itself. The closest it comes is to generate alerts when network probes are failing but by that point it's probably too late in terms of user experience.