Who is the actual user of the cloud service?¶
The actual user is the person who performed the relevant activity through the cloud service. They may be the named account holder, an authorised colleague, a person using shared credentials or someone who gained access without permission.
Start with the provider event¶
Identify the precise activity: account creation, login, upload, download, sharing change, deletion or administrative action. Record the provider’s timestamp, account or user identifier and any available session, device or network information.
Suppose the provider records an upload by Dave's account. A matching file and active session on Dave's laptop, a contemporaneous message about the upload and evidence that Dave controlled the device can build a strong bridge from the provider event to Dave.
The provider event is the anchor. Independent records make the bridge to the person stronger and explain why the conclusion is justified.
This establishes what the service recorded and creates the anchor for attribution. The human conclusion comes from the quality and independence of the connections built around it.
Build the bridge to a person¶
Useful corroboration can include:
- a seized device holding an authenticated session;
- local copies or application records matching the cloud event;
- multi-factor prompts received on a controlled device;
- communications discussing the action or content;
- location and access evidence consistent with the event;
- distinctive files, names or working patterns;
- evidence of who benefited from or directed the activity.
Several independent connections are usually more persuasive than one subscriber or login address.
Understand shared and delegated access¶
Workplace accounts may be used through individual profiles, shared mailboxes, service accounts or administrator impersonation features. Personal accounts may be shared within a household or left signed in on several devices.
Check roles and permissions. An administrator capable of accessing an account did not necessarily perform the event, and a named user may not be the only person able to use their session.
Test compromise properly¶
Account compromise is an alternative explanation to examine, not a magic phrase that ends attribution. Look for unfamiliar logins, recovery changes, security alerts, malware, unusual locations and the user’s response when warned.
Equally, the absence of an alert does not prove personal use. Explain what the provider records can and cannot distinguish.
State the conclusion at the right level¶
Separate “account X performed the upload” from “person Y performed the upload”. Then set out the evidence connecting the account event to the person and any remaining uncertainty.
The point to remember
Provider logs attribute activity to an account or session. Personal attribution requires corroboration through devices, access, communications, context and benefit.