What is personal attribution?¶
Personal attribution is a supported conclusion that a particular person performed, directed, controlled, assisted or knowingly participated in activity. It requires evidence connecting the person to the relevant technical events and role.
Ownership of an account, device or subscription is a possible link, not a complete attribution.
Build from control and context¶
Depending on the case, personal attribution may draw on:
- control of the relevant device, account or session;
- physical or remote presence at the time;
- communications and instructions;
- possession or use of credentials;
- payments and infrastructure management;
- knowledge of incident-specific facts;
- witness evidence, admissions or seized material; and
- conduct before and after the event.
These sources should be tested together. A device owner may not control a remote session, an account may be shared, and the person paying for infrastructure may not operate it.
Describe the person's actual role¶
Complex activity may involve one person configuring infrastructure, another operating it and another receiving the benefit. Direct execution, direction, assistance, knowledge and benefit are distinct propositions. Report the role the evidence supports rather than forcing every participant into the same description.
Where control is contested, test credible alternatives such as another user, shared access, compromise, automation or coercion. An attribution is more defensible when it explains why those alternatives are less consistent with the evidence, or acknowledges when they remain unresolved.
Key takeaway
Attribute conduct to a person only when technical events and independent evidence of control, knowledge or participation converge, and state the specific role supported.