ATTRIBUTION OF MALICIOUS CYBER INCIDENTS: FROM SOUP TO NUTS.

Attribution of malicious cyber activities is a deep issue about which confusion and disquiet can be found in abundance. Attribution has many aspects— technical, political, legal, policy, and so on. A number of well-researched and executed papers cover one or more of these aspects, but integration of...

Descripción completa

Detalles Bibliográficos
Publicado en:Journal of International Affairs Vol. 70; no. 1; pp. 75 - 138
Autor principal: Lin, Herbert
Formato: Artículo
Publicado: Journal of International Affairs Winter2016
Materias:
Acceso en línea:Ver este registro en EBSCOhost
Descripción
Sumario:Attribution of malicious cyber activities is a deep issue about which confusion and disquiet can be found in abundance. Attribution has many aspects— technical, political, legal, policy, and so on. A number of well-researched and executed papers cover one or more of these aspects, but integration of these aspects is usually left as an exercise for the analyst. This paper distinguishes between attribution of malicious cyber activity to a machine, to a specific perpetrator (often a human being pressing the keys) initiating that activity, and to an adversary that is deemed ultimately responsible for that activity. Which type of attribution is relevant depends on the goals of the relevant decisionmaker. Further, attribution is a multi-dimensional issue that draws on all sources of information available, including technical forensics, human intelligence, signals intelligence, history, and geopolitics, among others. From the perspective of the victim, some degree of factual uncertainty attaches to any of these types of attribution, although the last type—attribution to an ultimately responsible party—also implicates to a very large degree legal, policy, and political questions. But from the perspective of the adversary, the ability to conceal its identity from the victim with high confidence is also uncertain. It is the very existence of such risk that underpins the possibility of deterring hostile actions in cyberspace.