Skip to content
Skip to main content
Cyber Incidents & Offender Methods Foundation Explainer

What does technical attribution actually mean?

Technical attribution links activity to a device, account, session, service, infrastructure item or technical method. It can establish how an event was carried out without necessarily identifying the person responsible.

That is not a weak conclusion. It is a precise description of the level the evidence reaches.

Technical identifiers describe different things

Evidence may show that an account performed an action, a device made a connection, a server delivered a file or a wallet received funds. Each finding needs its own limits:

  • an account may be shared, compromised or automated;
  • a device may be remotely controlled;
  • an IP address may be a proxy, gateway or shared connection;
  • infrastructure may be rented or transferred; and
  • a tool or malware family may be used by several groups.

Prefer wording such as “the activity was performed through the account” or “the connection originated from the device” where that is what the record establishes.

Check time and independence

Control can change. Current subscription or account ownership should not be projected backwards without historical session, provider or configuration records covering the relevant period.

Several identifiers do not automatically provide several independent sources. A device label, address and session time may all come from the same provider event. Stronger attribution comes from corroboration across systems - for example, provider activity aligned with a seized device and contemporaneous communications.

Personal attribution is the next evidential step, not a synonym for technical linkage.

Key takeaway

State exactly which system, account, session or infrastructure item the evidence links to the activity, and build any conclusion about a person from separate corroboration.

Reference: CIM-278Cyber Incidents & Offender Methods