Cyber Attribution Confidence Analysis Using Multi-Stage Indicator Comparison
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cyber threat attribution for Advanced Persistent Threats (APTs) is challenging due to constantly changing indicators such as hash values, IP addresses, and domains, making it difficult to determine attribution confidence levels and identify information gaps.
Innovation Solution
A system and method for analyzing campaign intrusion set data to extract key indicators, compare them with activity group data, and determine attribution confidence levels using a multi-stage comparison process, while identifying gaps for higher confidence attribution and assisting in threat hunting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional cyber threat attribution methods are used, then attribution can be made quickly, but the confidence level is low due to constantly changing indicators
Solution Approach 1:
The system performs preliminary actions by collecting and analyzing multiple types of data (intrusion set data, activity group data, indicator data) before making attribution determinations. The multi-stage comparison process systematically evaluates evidence in advance, building a confidence level before final attribution is made, thereby improving measurement precision without excessive time loss.
Solution Approach 2:
The attribution process is segmented into multiple stages: collecting intrusion set data, collecting activity group data, extracting indicators, comparing indicators, and determining confidence levels. This segmentation allows systematic evaluation of different evidence types independently, improving overall attribution confidence while managing time through structured progression.
2Measurement precision
If multiple indicators are analyzed to improve attribution accuracy, then confidence level increases, but the complexity of the analysis process increases
Solution Approach 1:
The complex analysis process is segmented into distinct stages: data collection, indicator extraction, comparison, and confidence determination. Each stage handles specific tasks independently, making the overall complex process more manageable and systematic while maintaining high attribution confidence through comprehensive multi-indicator analysis.
Solution Approach 2:
The system uses an intermediary multi-stage comparison process that bridges the gap between raw indicator data and final attribution confidence levels. This intermediary process systematically evaluates multiple indicators (hash values, IP addresses, domains, TTPs) against activity group profiles, reducing analysis complexity while improving measurement precision.
3Measurement precision
If comprehensive data collection is performed to fill information gaps, then attribution confidence improves, but the time and resources required increase
Solution Approach 1:
The system extracts only the key indicators and capabilities relevant to attribution from large volumes of intrusion set data and activity group data. By taking out and focusing on critical elements (TTPs, indicators, capabilities) rather than processing all available data, the system improves attribution confidence while managing data processing volume efficiently.
Solution Approach 2:
The system performs preliminary data collection and organization, structuring intrusion set data and activity group data before comparison. This preliminary action prepares the data in advance, allowing efficient processing during the comparison stage and reducing the effective data volume that requires intensive analysis, thereby improving confidence levels without excessive resource consumption.
Data Source
AI summary
A system and method is provided for determining the confidence level in attributing a cyber campaign to an activity group. The system and method allows for determining information gaps that need to be filled in order to perform attribution with higher degree of confidence. The system and method is able to extract quantitative data from the campaign intrusion set data and perform a multi-stage analysis and comparison with quantitative data extracted from threat intelligence feeds/platforms and/or vendor intelligence reports. This allows for identifying an activity groups that may be attributed for the campaign with the associated level of confidence.


