How should attribution from logs be worded?¶
Attribution from logs should be worded according to the strength of the link between the technical identity and the person.
The account, device, session and network evidence should not be collapsed into one unsupported statement.
Avoid the dangerous assumption¶
The dangerous assumption is that a username, device name or IP address automatically identifies the person responsible.
It does not.
Start by describing the technical fact. The system recorded activity against a particular account, from a device or address, within a particular session.
Then explain the evidence linking that technical identity to the person. That may include possession of the device, known account use, communications, physical-access records, subscriber data, authentication method or behaviour before and after the event.
Where the evidence is strong, it may support wording such as “the records are consistent with use by X” or “the available evidence supports attribution to X”.
Where alternative explanations remain, state them. Shared accounts, remote access, compromised sessions, automation and administrator action may weaken the link.
Avoid absolute phrases such as “X made the login” or “X deleted the file” unless the wider evidence genuinely supports them.
Different propositions may require different levels of confidence. The evidence may strongly link the account to the person while remaining weaker on who controlled a particular session at a particular time.
Record which parts are direct system observations and which are inferences. If attribution depends on specialist interpretation, identify that basis.
Operational takeaway¶
Word attribution in stages from technical identity to personal inference, using language that matches the corroboration and remaining alternatives rather than treating account, device or address fields as a person.