Attribution
Definition
The process of identifying the threat actor responsible for a cyberattack. Attribution is a confidence-weighted analytical conclusion, not a binary fact. It ranges from technical attribution (identifying the machine or infrastructure used) to legal attribution (establishing criminal or state responsibility in a court or diplomatic context).
- Definition
- Identifying the threat actor responsible for a cyberattack
- Nature
- Confidence-weighted analytical conclusion, not a binary fact
- Technical level
- Identifying the machine or infrastructure used
- Legal level
- Establishing criminal or state responsibility
Common questions
Why is attribution described as confidence-weighted rather than certain?+
Evidence such as IP addresses, malware code reuse, and infrastructure overlap can be spoofed, shared, or planted by a different actor to mislead investigators, so analysts express conclusions with a stated confidence level rather than treating any single indicator as proof.
Why does technical attribution not automatically support legal attribution?+
Identifying the infrastructure or tooling used in an attack shows how it was carried out but does not by itself meet the evidentiary or diplomatic standard needed to hold a specific individual, organisation, or state legally or politically responsible, which typically requires corroborating intelligence beyond the technical trail.
Related terms
- Confidence Level
- An explicit label attached to an attribution assessment indicating how strongly the available evidence supports the conclusion. Standard tiers are low, medium,...
- False Flag
- A deliberate deception in which an attacker plants indicators designed to make the intrusion appear to originate from a different actor. Common...
- Technical vs Legal Attribution
- Technical attribution identifies the infrastructure and tooling used in an attack and may link it to a known cluster or actor profile....
- Threat Actor Cluster
- A named collection of observed activity linked by shared infrastructure, malware, and TTPs, without necessarily having confirmed the real-world identity of the...
- TTPs (Tactics, Techniques, and Procedures)
- The behavioural fingerprint of a threat actor: the broad goals and approaches they pursue (tactics), the specific methods they use to achieve...