THE ATTRIBUTION PROCESS

POL370F

PROF.BENJAMINBARTLETT

MIAMI UNIVERSITY

THREE LEVELS

  1. Tactical(technical)
  2. Operational
  3. Strategic

TACTICAL LEVEL

OPERATIONAL LEVEL

STRATEGIC LEVEL

THE ATTRIBUTION PROCESS

QUESTIONS AT THE TACTICAL LEVEL(ABOUT A SINGLE OPERATION)

EXAMPLE: BREAK-IN AT LOCAL CREDIT UNION

  1. Hackers mainly stole credentials from employees.
  2. Usedaphishingemailcontainingmalware.
  3. Somecomments written in Korean.
  4. Hackers always connected at the same time, during “workinghours” in North Korea.

Probably North Korean hackers.

QUESTIONS AT THE OPERATIONAL LEVEL(ABOUT MULTIPLE, RELATED OPERATIONS)

EXAMPLE(CONTINUED)

  1. Have seen similar break-ins at other local banks, always aiming foremployee credentials.
  2. M.O. is similar to a well-known North Korean APT.
  3. ThisAPThasstolencredentialsfromlocal banks in other countries,used those credentials to steal money from central banks.

Probably same APT trying to steal from U.S. central bank.

QUESTIONS AT THE STRATEGIC LEVEL(HOW DO THE OPERATIONS FIT INTO THE BIGGERPICTURE?)

EXAMPLE (CONTINUED)

  1. From other intelligence sources, know that North Korea has beentrying to find ways to fund its ongoing missile developmentprogram.

Probably that is what they are doing with the stolen money.

  1. Now,thehardpart:doyouleteveryone know North Korea isbehind these operations? How much do you reveal about how youknow? And how do you respond?

CONCLUSION