Cyber Attribution Data Centre (CADC): The Future of Identifying Cyber Threat Actors
By Canadian Institute for Cybersecurity (CIC)
Key Concepts
- Cyber Attribution: The process of identifying the individuals, groups, or nations responsible for cyberattacks.
- CIC (Canadian Institute for Cybersecurity): A multi-disciplinary institute focused on cybersecurity research, innovation, education, and entrepreneurship.
- CAT Attribution Framework: A six-component framework developed by CIC for cyber attribution.
- Honeypots/Honeynets: Decoy systems or networks designed to attract and trap attackers, collecting data on their methods.
- Dark Web Monitoring: Gathering intelligence and artifacts from the dark web for attribution purposes.
- Sandbox Community: A collaborative network of sandboxes used to analyze malware and its behavior.
- Data Lake: A centralized repository for storing raw data from various sources.
- AI-based Attribution: Utilizing artificial intelligence algorithms for the process of cyber attribution.
- Concept Drift: The phenomenon where the characteristics of data change over time, impacting the effectiveness of models.
- Misattribution: The incorrect assignment of responsibility for a cyberattack.
- Interpretability (AI): The ability to explain the reasoning behind an AI model's output.
CIC: Driving Excellence in Cyber Attribution
The presentation introduces the Canadian Institute for Cybersecurity (CIC), a multi-disciplinary institute with over 25 years of experience in innovative R&D and entrepreneurship in cybersecurity. CIC's vision is to drive excellence and leadership in cybersecurity research, innovation, and education in Canada. Their primary focus areas are training, awareness for various sectors, and professional development. CIC has successfully established partnerships with over 20 industry and academic partners and has launched startups, notably Q1 Labs, which was sold to IBM. They have also established consortia, including the National Cybersecurity Consortium.
Federal Funding and CIC's Goals
CIC has secured $10 million in federal funding from Public Safety Canada via AOA to position Canada at the forefront of cyber threat attribution. Their three primary goals are to:
- Create: Set up highly secure infrastructure and a reliable data center.
- Generate: Ensure verifiable, reproducible, and reliable intelligence.
- Develop: Primarily AI-based tools and datasets for sharing, while strictly adhering to national security, ethics, and privacy principles.
The CIC Team
The presentation highlights the key personnel at CIC, including:
- Leadership: Professor Ali Gorbani, Dr. Dka Hugh Hicks, and the presenter.
- Operations Team: Pamela Kitchen, Muhammad Badawi, Morakino Ok, and Alireza Anbi.
- Research Team (Insights and Data Analytics): Dr. Dordi, Dr. Chuhan, Dr. Robani, Dr. Muhammad Yian, Dr. Eran.
- Specialized Researchers: Dr. Alcatib (Forensics and Malware), Dr. Ba, Dr. Wi Malasora, Ali Zohuran (Attribution), Arash Karisnovi (Honeynets), Samuel Lanssung (Data Analytics), Joseph Soa (Dark Web).
CIC's Five-Year Plan
CIC has a comprehensive five-year plan:
- Year 1:
- Establish organizational structure and infrastructure.
- Hire Highly Qualified Personnel (HQPs).
- Set up two data centers.
- Establish a baseline for the attribution platform.
- Year 2:
- Scale operations due to increasing data volume.
- Expand HQPs.
- Fully develop the CIC Attribution Framework.
- Implement training programs for academic, private, and federal stakeholders.
- Year 3:
- Achieve operational excellence with uninterrupted capacity.
- Focus on high availability and reliability.
- Expand attribution focus to various sectors beyond IT, including military and operational technology.
- Year 4:
- Focus on sustainability.
- Position CIC as a leader in cyber attribution.
- Generate revenue from private and government sectors.
- Contribute to national policy.
- Patent and commercialize research outputs.
- Beyond 2030 (Year 5):
- Achieve full sustainability with annual revenue generation.
- Develop a trained alumni network.
- Aim for global leadership in cyber attribution.
The CAT Attribution Framework
CIC is developing a six-component CAT Attribution Framework:
- Data Collection: Gathering existing and new data, including rerunning existing data and leveraging honeynets.
- Clustering: Grouping similar types of data.
- Analysis: Examining the clustered data.
- Attribution: Identifying groups responsible for attacks, providing defense insights, and understanding adversary motivations.
- Reporting: Providing reports while ensuring ethical practices and privacy.
Data Collection Strategies
CIC employs several strategies for data collection:
- Honeypots/Honeynets: Creating highly interactive honeynets that mimic actual infrastructure. This includes creating fake user profiles on platforms like LinkedIn to attract adversaries. Initial efforts are focused on creating a honeynet for a hospital. The goal is to allow stakeholders to route attacks to CIC for analysis.
- Dark Web: Monitoring the dark web to gather human intelligence and other artifacts to supplement attribution data.
- Sandbox Community: Utilizing a community of sandboxes with varying advantages and disadvantages to analyze malware outputs. CIC has acquired two sandboxes and plans to acquire more.
Data Pipeline and Analysis
The collected data flows through a data pipeline:
- Data Collection: From various stakeholders and existing threat intelligence sources.
- Honeynet Infrastructure: Interconnected honeynets across different sectors ("honey city") to track attack flows.
- Dark Web Monitoring: "Dark web spa" and "dark space monitor."
- Data Lake: Storing all collected information.
- Sandbox Analysis: Malware information is processed through the sandbox community and stored in the data lake.
- Analysis and Enrichment: Data is clustered and analyzed, with feedback loops for enrichment.
- Attribution: AI-based attribution algorithms are applied.
- Reporting: Insights are provided to various stakeholders, including the general public and protected partners.
Interesting Facts and Trends
- Honeynet Efficacy: A single deployed honeynet component ("lightning rod") received approximately 2,000 attack requests within two days, demonstrating the active threat landscape.
- AP Known Groups and Cyber Kill Chain: Analysis of AP (Advanced Persistent Threat) known groups mapped to the cyber kill chain shows a decline in recorded techniques from over 50 in 2017 to less than 10 by 2025. This could indicate groups becoming more sophisticated, reduced reporting, or less effective attribution. Identifying recognized AP groups is becoming increasingly challenging, with many now aligned as intrusion sets.
- Cyber Kill Chain Stages: The reconnaissance and action-on-objectives stages consistently show high activity, highlighting the ongoing challenge of data collection.
- Threat Actor Motivation and Victims: CIC observes structures related to threat actor motivation and victims. A notable factor is culture, where religious beliefs or cultural practices can influence attack timings, potentially leading to misattribution if not considered.
Challenges in Cyber Attribution
CIC has identified four key challenges:
- Data Scarcity: Lack of metadata and the difficulty for institutions to record and back up large volumes of data.
- Concept Drift: Adversaries constantly change tactics. For example, the "Elsas dump" technique is phasing out due to Windows 11 patches, leading to a shift towards attacks against domain controllers.
- Misattribution: Attackers intentionally cover their tracks or frame other actors (nation-states or organizations) to hide their own activities.
- Interpretability: For AI-based attribution, it's crucial to understand the reasoning behind the AI's conclusions, rather than accepting them as a "black box."
Call to Action
The presentation concludes with an invitation to join CIC in enhancing Canada's security posture through innovation and sustainability, with a clear roadmap to global leadership in cyber attribution. Opportunities include partnerships, membership, or bringing talent to the institute.
Chat with this Video
AI-PoweredLoad the transcript when you're ready to chat so the initial page stays lighter.
Related Videos

CrowdStrike raises fiscal year guidance
BNN Bloomberg

Tigera CEO on Calico AI and the Push for Simpler, Unified Kubernetes Security
The New Stack

Could SentinelOne Deliver on Its 'Purple AI' Promise?
The Motley Fool

Emerging Cybersecurity Threats by Igor Opushnyev & Kostiantyn Nikolaiev
Canadian Institute for Cybersecurity (CIC)

SentinelOne Could Expand Its AI Security TAM
The Motley Fool

Why AI ignorance is the biggest threat to your software
GitHub

Ask a Cybersecurity Expert - Neil Daswani, Co-Academic Director, Advanced Cybersecurity Program
Unknown Author