4 hours 12 minutes
Hello and welcome to the new module about attribution.
The first lesson will be an introduction to this module as introduction. We need to understand what is attribution,
The Different Types of Retribution and Approaches to attribution
and you will see important requirements that are needed for attribution.
When discussing the latest targeted attacks, the question invariably arises. Who was behind it?
It's a simple question,
but it became difficult and complex to answer
attribution off. Cyber attacks has never bean an exact science
at the same time, attribution is done based on similarity off digital fingerprints such as coat similarity, share tools and sharing infrastructure, however, attribution, used in such methods is becoming increasingly difficult, especially with a trend off Attackers using fire less threats
you'll use tools, for example. Yes, exactly.
There is also the classic problem off Attackers inserting false flags, including purposeful misdirection, obfuscation and fake calls. Design it to mask their identities.
Despite these challenges, attribution remains an important part off attack on the license. So by tying activity to specific groups, we start to see patterns off behavior that follows us to better understand the Attackers motivation
their target profile and sets the are pursuing,
but there are limits to how far we can go with retribution. For instance, even if we concise specific incidents Toe Unknown Attack Group
identifying who or what organization is directing or funding that activity is not in the scope or focus off what we are doing.
This level off attribution requires the substantial resources on access to information that is generally available on Lee to law enforcement or government intelligence agencies.
Attribution to cyber attacks means different things to different audiences. In some cases, analysts only care about group in multiple intrusions together toe, identify an adversary group
or their campaigns toe others attribution means determining the person, organization or nation state responsible off the successful intrusion or attack.
Rob Emily, the CEO and founder off Cyber security company. Drag US defines two types off attribution.
The 1st 1 is true attribution, which means that we are a tribute and an intrusion tow an individual threat actor or a group of actors who are executing the intrusion. It can also be attribution to nation state, which means that the actors are operating for interests off the government.
The second type is campaign attribution,
which means that we are linking a set of intrusions using them. In key indicators, the second attribution is much more useful than true distribution for network defense. It helps defenders identify group and investigate activity faster. Probably the fines. Also
four roads to true attribution.
The first approach is adversary admission. Here the adversary admits that they did, and Children.
The second drawer under approach is through leaks.
Here, the adversary releases the information or someone else releases this information about that. The third road is through direct access, and here it's records and direction with adversary and or their systems to collect information. In other words,
spying on the anniversary.
The first approach is through campaign attribution and here we are talking about intrusion and a license that we've explained in the previous light.
Why does distribution matters
now? Let's see that attribution.
Now let's see if attribution matters
the security blob. Our security has a great post about the value off attribution. Here are five reasons why attribution Matters based on five levels off strategy thought starting from the bottom
are the tools level attribution matters because identifying adversary my tell defenders what software they can expect to encounter during an intrusion or a campy.
It is helpful to know if the adversary uses simple tools that traditional defenses can counter or if they can write custom code and exploits to evade most any programmatic countermeasures. The benefits off attribution are similar. A Tactics Level
Tactics describes how adversary acts within an engagement or a battle.
The level off operations or campaigns describes activity over long periods of time from days to months and perhaps years over wider theater off operations. So from a department or network segment to an entire organizations environment
defenders who can perform attributions will better row their opponents long term patterns off behavior.
Basically, does the adversary prefer to conduct operations around holidays or certain hours of the day or days of the week?
Attribution House defenders answer these and related questions
at the level Off Strategy attribution matters to an organization's management and leadership as well as policy makers.
These individuals must decide if they should adjust how they conduct business based on who is attacking and damaging,
while cannot think strategically without recognizing and understanding their adversaries. Finally, the level off policy or program goals in the diagram. It's the super um goal off the government officials on top organizational management, such as sea use on their corporate boards.
can apply many government tools to problems such as law enforcement legislation,
diplomacy, sanctions and for once so force. Policymakers may truth to fund programs to reduce vulnerabilities, which is, in some sense, an attribution free approach. However, addressing the threat in a comprehensive manner, the man's knowing the threat. Attribution is the key toe.
Any policy decision
where one expects other parties to act or react to one's own moves When it comes to requirements for attribution, it is essential for any analysts to defeat their biases and logical errors. We will have two lessons dedicated to focus on these two concepts, but
you need to keep in mind
that biases are especially dangerous when performing any analyzes, because analyzes leaves so heavily on the human thought processes that it can lead us to inappropriate conclusions.
This is all for this video in this ness, and we introduce it attribution. We've seen the different types off attribution. We've seen that there is one type called a true attribution and their roads to true attributions.
We also discovered why attribution matters
and we define it. Some requirements for attribution
The next video will be focused on cognitive biases
and before moving to the next lesson, I will leave you with this short comics off little Bobby.
Advanced Cyber Threat Intelligence
Advanced Cyber Threat Intelligence will benefit security practitioners interested in preventing cyber threats. Learn how to leverage your existing data sources to extract useful information and find complementary information from external sources.