Cyber Attribution - Beyond the Breach: Challenges, Techniques, and Policy Implications
By Canadian Institute for Cybersecurity (CIC)
Key Concepts
- Attribution: The process of identifying the responsible party behind a cyber attack.
- Technical Attribution: Identifying the technical indicators and evidence left by an attacker.
- Legal Attribution: The formal identification of a party for legal or policy purposes.
- Geopolitical Insight: Understanding the political context and motivations behind cyber attacks.
- Threat Intelligence: Information about potential or current threats to an organization or nation.
- False Flags: Deceptive indicators planted to mislead attribution efforts.
- Proxy Infrastructure: Using intermediary systems to mask the origin of an attack.
- Global Attack Surfaces: The vast and interconnected nature of digital systems, making attacks harder to trace.
- Deterrence: The act of discouraging future malicious behavior through the threat of consequences.
- Norms of Responsible State Behavior in Cyberspace: Agreed-upon principles for how states should act in cyberspace.
- Public-Private Collaboration: The partnership between government and private sector entities in addressing cyber threats.
- Data Privacy: Regulations and principles governing the collection, use, and protection of personal information.
- AI-Powered Attacks: Cyber attacks that leverage artificial intelligence for enhanced sophistication and scale.
- Quantum Computing: A new paradigm of computing that could break current encryption methods.
- Open-Source Intelligence (OSINT): Information gathered from publicly available sources.
Cyber Attribution: Challenges, Frameworks, and the Future
This panel discussion, moderated by Colin Mcween of Public Safety Canada, delves into the complex and consequential issue of cyber attribution, exploring its technical, legal, policy, and geopolitical dimensions. The discussion highlights the challenges in identifying malicious actors in cyberspace and the evolving frameworks for attribution, with a particular focus on the roles of government and the private sector.
1. Understanding Cyber Attribution: Process and Perspectives
Attribution is defined as the process of identifying the responsible party behind a cyber attack, answering the "who" behind a breach, intrusion, or malware campaign. However, this process is far from straightforward due to deliberately obscured digital trails, false flags, proxy infrastructure, and global attack surfaces. Attribution often requires a multidisciplinary approach, integrating technical analysis, geopolitical insight, threat intelligence, and strategic judgment.
- Technical vs. Legal Attribution: Lawyers distinguish between technical and legal attribution, with legal and political attribution also being distinct. The process is interdisciplinary, involving cybersecurity experts, digital forensics teams, and policymakers. Legal attribution is triggered when specific legal norms are invoked.
- Probabilistic Outcomes in Business: From a business perspective, particularly in fraud detection, attribution often yields probabilistic outcomes based on data analysis. This makes it difficult to link attacks to specific sources, especially when full information is not available to clients.
- Industry-Specific Needs: In certain industries like adtech, attribution to a specific actor is crucial for operational efficiency and future prevention. The presence of certain products can eliminate large-scale attacks but smaller, user-level fraud remains a challenge.
- Diplomatic Perspective: From a diplomatic standpoint, attribution is about calling out a state for malicious behavior. This decision is based on technical, legal, and domestic assessments of implications.
- Reasons for Attribution:
- Domestic Awareness: Informing Canadians about malicious state actors targeting them or the government.
- International Messaging: Signaling unacceptable behaviors and drawing "red lines" to prevent them from shifting. Raising awareness among states with less advanced technology.
- Calling Out States: Imposing reputational damage and potentially accompanying actions like sanctions or criminal investigations to deter behavior.
- Confidence and Collective Effort: Attribution is fundamentally about assigning responsibility for disruptions in the online ecosystem. It builds public confidence that states and tech companies are aware and in control. It is a collective effort, with no single entity capable of achieving a full picture alone.
- Example: Twitter (X) Transparency Reports: In the past, Twitter's Transparency Center published data on user removals, attributing them to specific countries (e.g., Russia, Iran). Later, they provided more technical details and mentioned assistance from agencies like the FBI, underscoring the collective nature of attribution.
2. Policy and Legal Considerations in Attribution Decisions
Attributing malicious cyber activity carries significant consequences, necessitating careful consideration of policy and legal factors. Deterrence is a key objective, but its effectiveness is debated.
- Applicability of International Law: Canada has affirmed that international law applies to cyberspace, contributing to the development of global norms. Over a hundred states now acknowledge this applicability, though it remains contested by some major powers.
- Deterrence and Rule of Law: Attribution serves as a deterrence mechanism and signals a commitment to upholding the international rule of law in cyberspace.
- Geopolitical Alliances: Attribution efforts can involve collaborative endeavors and alliances among countries, extending beyond bilateral relations.
- Business Case for Disclosure: In the B2B context, the decision to disclose the source of an attack is multi-dimensional and depends on business cases. While sensitive, exposing bad actors can lead to legal consequences and escalation of issues. The presence of analytical products inherently reduces risk, but disclosure is a business decision.
- Effectiveness of Deterrence: While attribution may deter states considering malicious cyber activities by raising reputational concerns, it is unlikely to deter determined malicious actors. However, it plays a crucial role in drawing lines and defining responsible behavior in cyberspace.
- Reputational Damage: Adversaries, such as China, have actively sought measures to prevent attribution, indicating its negative impact and reputational damage.
- Evolving Tactics: Malicious actors adapt their tactics to avoid detection after being identified, highlighting the dynamic nature of cyber operations.
- Balancing Evidence and Secrecy: A significant challenge in attribution is balancing the need to expose sufficient evidence for consequences with the necessity of keeping proprietary business logic and research methods secret to prevent adversaries from becoming more sophisticated.
- Case Study: DFR Lab and Meta's Inauthentic Coordinated Behavior Report: A report by DFR Lab on Islamophobic content targeting Canadian Muslims led to Meta identifying a PR company, Stoic, as the source of a campaign originating from Israel. OpenAI also confirmed Stoic's involvement, noting the use of its own technologies. This case illustrates the collective effort in attribution and how actors may change tactics (e.g., avoid using specific AI tools like ChatGPT) after being publicly identified.
3. Private Sector Collaboration in Attribution
The private sector plays a vital role in attribution, leveraging its data and analytical capabilities. Effective collaboration with governments is crucial, balancing national security, foreign policy, and commercial interests.
- Government of Canada Framework: Global Affairs Canada leads the attribution framework, but it involves input from various domestic partners, including Public Safety and the Communications Security Establishment (CSE). The process relies on technical assessments from intelligence partners, followed by legal, foreign policy, and domestic assessments. The final decision rests with the Minister of Foreign Affairs.
- Role of Private Sector Data: Private companies possess extensive data that can be valuable for attribution. However, governments cannot formally attribute based solely on commercial sector findings; these must be validated by the technical community.
- Demystifying Attribution: The private sector can play a role in demystifying attribution by sharing findings, though this must be done carefully to avoid revealing sensitive tactics.
- Challenges in Public-Private Collaboration:
- Proxy Actors: States often act through private proxies, complicating attribution.
- Data and Analytics: The private sector provides data, analytics, and insights to support decisions, often built on "security by design" and "privacy by design" principles.
- Classified Intelligence: Much of the basis for government attribution is classified, limiting public disclosure.
- Risk of Targeting: Private entities may become targets if they publicly attribute activities.
- Fact-Checking Organizations and Research Labs: Entities like DFR Lab, Bellingcat, and Canada's Citizen Lab are instrumental in identifying cyber operations and malware through OSINT and qualitative research, demonstrating the importance of non-governmental actors.
- Cyber Peace Institute: Private funding supports large-scale attribution efforts, and coalitions involving states and private actors assist in cyber defense.
4. The Future of Cyber Attribution: Evolving Threats and Gaps
The field of cyber attribution is expected to become increasingly complex due to advancements in technology like AI and quantum computing, posing challenges for both defenders and threat actors.
- Capacity Building and Norm Setting: Future efforts will focus on national and global capacity building in both norm setting and technical capabilities.
- Quantum Computing Impact: Preparation for a post-quantum world is essential, as encrypted data currently held by threat actors could become accessible. New coalitions may form to secure necessary infrastructure.
- AI-Powered Attacks: AI will likely increase the volume and sophistication of malicious activity, making it harder to distinguish malicious behavior from normal activity. This will require more resources and novel techniques for attribution.
- Data Privacy as a Barrier: Evolving data privacy laws, while important, can complicate attribution efforts by restricting access to crucial personal identifying information (PII) like IP addresses and location data. Fraudsters, however, do not face these constraints.
- Balancing Privacy and Security: A key challenge is finding a balance between protecting personal information and enabling effective cyber attribution. The classification of data elements may need to be reviewed as technology evolves and fraudsters exploit new methods, including using individuals' devices.
- Increased Complexity: Attribution will become more complex due to AI, the increased use of proxies, and adversaries' ability to operate in less clear-cut spaces.
- Clarity on Responsible Behavior: Greater clarity is needed on what constitutes responsible state behavior in cyberspace, particularly in discussions at international forums. Identifying irresponsible or malicious behavior is becoming increasingly difficult.
- Expertise Development: Building expertise in various types of cyber operations, beyond hacking and denial-of-service attacks, including disinformation campaigns, is crucial for effective defense.
- Fluid and Evolving Landscape: The nature of cyber operations is fluid and dynamic, requiring continuous adaptation and staying "on top of the game" to counter new technologies and tactics.
5. Audience Questions and Panel Responses
- Government Support for Private Sector Attribution: While the panel acknowledged the complexity of cyber insurance declining claims due to state or activist involvement, they noted that direct government support for private sector attribution efforts is limited. The focus for Global Affairs Canada is on diplomatic implications. Engagement with CSE and potential legislative reforms were suggested as areas for improvement.
- Data Privacy Barriers: The discussion highlighted how data privacy regulations, particularly concerning PII like IP addresses, can impede attribution efforts. While carve-outs exist for criminal investigations, the B2B context and global product development necessitate adherence to strict regulations like GDPR. The evolving nature of data compromise and the rise of AI-generated deception may require a re-evaluation of data classification and attribution methodologies.
- Evolving Legislation: The rapid pace of technological advancement, especially with AI, outstrips legislative development. There is a need for faster adaptation of legislation to govern emerging technologies and their use in cyber operations.
- Misinformation Literacy Funding: In Canada, the Department of Heritage has funded private sector organizations to enhance misinformation literacy, though this is distinct from direct attribution support.
Conclusion
The panel underscored that cyber attribution is a critical, complex, and evolving challenge. It requires a multidisciplinary approach, integrating technical expertise, legal frameworks, policy considerations, and geopolitical understanding. While governments lead formal attribution efforts, effective collaboration with the private sector, academia, and fact-checking organizations is essential. The future landscape, shaped by AI and quantum computing, will demand continuous adaptation, capacity building, and a concerted effort to define and uphold norms of responsible behavior in cyberspace, all while navigating the intricate balance between security and privacy.
Chat with this Video
AI-PoweredLoad the transcript when you're ready to chat so the initial page stays lighter.
Related Videos

Why Does This Guy Appear In Kids Videos?
sphynx

TIC en las Organizaciones - Electiva Complementaria II Unisimon
Julieth Güell S

How to Tame Your Advice Monster | Michael Bungay Stanier | TED
TED

Margaret Heffernan: Why it's time to forget the pecking order at work
TED

The importance of psychological safety: Amy Edmondson
The King's Fund

What Is Psychological Safety?
Harvard Business Review

13-Conflict Management: Listening in Conflict
Deliberate Development