ATTRIBUTION OF MALICIOUS CYBER INCIDENTS: FROM SOUP TO NUTS.
Attribution of malicious cyber activities is a deep issue about which confusion and disquiet can be found in abundance. Attribution has many aspects— technical, political, legal, policy, and so on. A number of well-researched and executed papers cover one or more of these aspects, but integration of...
| Published in: | Journal of International Affairs Vol. 70; no. 1; pp. 75 - 138 |
|---|---|
| Main Author: | |
| Format: | Article |
| Published: |
Journal of International Affairs
Winter2016
|
| Subjects: | |
| Online Access: | View this record in EBSCOhost |
| fields | @attributes: recordID: 1 pdfLink: plink: https://search.ebscohost.com/login.aspx?direct=true&db=ssf&AN=120438201&site=ehost-live header: @attributes: shortDbName: ssf uiTerm: 120438201 longDbName: Social Sciences Full Text (H.W. Wilson) uiTag: AN controlInfo: bkinfo: jinfo: jid: 0022197X JIA jtl: Journal of International Affairs issn: 0022197X maglogo: N pubinfo: dt: Winter2016 vid: 70 iid: 1 pid: 127 pub: Journal of International Affairs artinfo: ui: 120438201 ppf: 75 ppct: 63 formats: fmt: @attributes: type: P size: 26.9MB tig: atl: ATTRIBUTION OF MALICIOUS CYBER INCIDENTS: FROM SOUP TO NUTS. aug: au: Lin, Herbert affil: Senior research scholar for cyber policy and security at the Center for International Security and Cooperation, Stanford University Research fellow at the Hoover Institution, Stanford University su: Geopolitics Malware Internet security Research management Human intelligence (Intelligence service) Computer software sug: subj: Geopolitics Computer, computer peripheral and pre-packaged software merchant wholesalers Computer and Computer Peripheral Equipment and Software Merchant Wholesalers Computer and software stores Software publishers (except video game publishers) Wired Telecommunications Carriers Internet Publishing and Broadcasting and Web Search Portals Malware Internet security Research management Human intelligence (Intelligence service) Computer software ab: Attribution of malicious cyber activities is a deep issue about which confusion and disquiet can be found in abundance. Attribution has many aspects— technical, political, legal, policy, and so on. A number of well-researched and executed papers cover one or more of these aspects, but integration of these aspects is usually left as an exercise for the analyst. This paper distinguishes between attribution of malicious cyber activity to a machine, to a specific perpetrator (often a human being pressing the keys) initiating that activity, and to an adversary that is deemed ultimately responsible for that activity. Which type of attribution is relevant depends on the goals of the relevant decisionmaker. Further, attribution is a multi-dimensional issue that draws on all sources of information available, including technical forensics, human intelligence, signals intelligence, history, and geopolitics, among others. From the perspective of the victim, some degree of factual uncertainty attaches to any of these types of attribution, although the last type—attribution to an ultimately responsible party—also implicates to a very large degree legal, policy, and political questions. But from the perspective of the adversary, the ability to conceal its identity from the victim with high confidence is also uncertain. It is the very existence of such risk that underpins the possibility of deterring hostile actions in cyberspace. pubtype: Academic Journal doctype: Article src: R language: English refInfo: copyright: @attributes: flag: N holdings: @attributes: islocal: N |
|---|