About | HeinOnline Law Journal Library | HeinOnline Law Journal Library | HeinOnline



1 [1] (April 17, 2015)

handle is hein.crs/crsmthaafdc0001 and id is 1 raw text is: CRS Insights
Attribution in Cyberspace: Challenges for U.S. Law Enforcement
Kristin Finklea, Specialist in Domestic Security (kfink11ea(c Dcgov, 7-6259)
April 17, 2015 (fN 10259)
i? Attribution, some may argue, is a challenge as old as crime and punishmen. In the cyber realm
too, criminal attribution is a key delineating factor between cybercrime and other threats. When investigating a
given incident, law enforcement is challenged with tracing the action to its source and determining whether the
actor is a criminal or whether the actor may be a terrorist or state actor posing a potentially greater national
security threat.
Blurry lines between various types of malicious activity in cyberspace may make it difficult for investigators to
attribute an incident to a specific individual or organization. Without knowing the criminal intent or motivation,
some activities of cybercriminals and other malicious actors may appear on the surface to be similar, causing
confusion as to whether a particular action should be associated with a criminal or other actor. Further, LtJh
s  d  an nonymity of cyber attacks makes distinguishing among the action of terrorists, criminals and nation
states difficult a task which often occrs only after h  if  llMoreover, officials have noted cooperation
an b rrin    fin         n       f   r, including nation states, organizations, and individuals, which can
complicate or stymie attribution.
Attribution in the Sony Pictures Entertainment Breach
The attribution issue is highlighted in the November 2014 revelation of a breach at Sony Pictures Entertainment
(SPE) by actors claiming responsibility and calling themselves the Guardians of Peace. The Federal Bureau of
Investigation (FBI), in its investigation of the breach, noestha it consisted of the deployment of destructive
malware and the theft of proprietary information as well as employees' personally identifiable information and
confidential communications. The attacks also rendered thousands of SPE's computers inoperable, forced SPE to
take its entire computer network offline, and significantly disrupted the company's business operations. Hackers
further hr       a September 11, 2001-type of attack on movie theaters that showed The Interview, a spoof
about journalists tasked with killing North Korea's Supreme Leader, Kim Jong-un. There has been debate about
the true source of the breach. As of December 2014, the FBI-leading an interagency effort-had attributed the
hack to the North Korean government. In its attribution, the FBI cited malware linked to other malware that the
FBI knows North Korean actors previously developed, significant overlap between the infrastructure used in this
attack and other malicious cyberactivity the U.S. government has previously linked directly to North Korea, and
tools similar to those used in a 2013 North Korean cyberattack against South Korean banks and media outlets.
Nonetheless, experts critical of this attribution note that the evidence linking North Korea to the SPE breach is nt
definijive. Further fueling concerns that the hack may be mis-attributed, U.S. officials have no r el  specifics
surrounding how the attribution was reached.
As a response to North Korea's numerous Drovocations Darticularly the [2014] cyber-attack targetina Sony
Pictures Entet ainment and the threats aainst mo  tars and moxiegoers, President Obama signed an
Executive Order on January 2, 2015, authorizing additional sanctions against certain individuals and entities
associated with the North Korean government.
Attribution in the Anthem Inc. Breach
In February 2015, it was revealed that one of the nation's largest health insurance companies, Anthem Inc., had
suffered a data breach involving the personal information-including Social Security numbers-of potentially 80
milliDn-in ividuals. However, Anthem    n  -li    that banking, credit card, or certain medical information
was compromised. Law enforcement has not publicly attributed this attack. Notably, security experts involved in
the ongoing forensics investigation into the breach say the servers and attack tools used in the attack on Anthem