{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T10:35:22Z","timestamp":1783074922985,"version":"3.54.6"},"reference-count":86,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2020,3,20]],"date-time":"2020-03-20T00:00:00Z","timestamp":1584662400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2020,3,20]],"date-time":"2020-03-20T00:00:00Z","timestamp":1584662400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecur"],"published-print":{"date-parts":[[2020,12]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>The attribution of cyber attacks is often neglected. The consensus still is that little can be done to prosecute the perpetrators \u2013 and unfortunately, this might be right in many cases. What is however only of limited interest for the private industry is in the center of interest for nation states. Investigating if an attack was carried out in the name of a nation state is a crucial task for secret services. Many methods, tools and processes exist for network- and computer forensics that allow the collection of traces and evidences. They are the basis to associate adversarial actions to threat actors. However, a serious problem which has not got the appropriate attention from research yet, are false flag campaigns, cyber attacks which apply covert tactics to deceive or misguide attribution attempts \u2013 either to hide traces or to blame others. In this paper we provide an overview of prominent attack techniques along the cyber kill chain. We investigate traces left by attack techniques and which questions in course of the attribution process are answered by investigating these traces. Eventually, we assess how easily traces can be spoofed and rate their relevancy with respect to identifying false flag campaigns.<\/jats:p>","DOI":"10.1186\/s42400-020-00048-4","type":"journal-article","created":{"date-parts":[[2020,3,20]],"date-time":"2020-03-20T00:04:44Z","timestamp":1584662684000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":40,"title":["Under false flag: using technical artifacts for cyber attack attribution"],"prefix":"10.1186","volume":"3","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1922-7892","authenticated-orcid":false,"given":"Florian","family":"Skopik","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Timea","family":"Pahi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2020,3,20]]},"reference":[{"key":"48_CR1","unstructured":"2016 Public-Private Analytic Exchange Program Team (2016) Cyber Attribution Using Unclassified Data. https:\/\/www.dni.gov\/files\/PE\/Documents\/Cyber-Attribution.pdf. Accessed 25 Feb 2020."},{"key":"48_CR2","doi-asserted-by":"crossref","unstructured":"Afroz, S, Brennan M, Greenstadt R (2012) Detecting hoaxes, frauds, and deception in writing style online In: 2012 IEEE Symposium on Security and Privacy, 461\u2013475.. IEEE.","DOI":"10.1109\/SP.2012.34"},{"issue":"3","key":"48_CR3","first-page":"71","volume":"8","author":"A Algarni","year":"2014","unstructured":"Algarni, A, Malaiya Y (2014) Software vulnerability markets: Discoverers and buyers. Int J Comput Inf Sci Eng 8(3):71\u201381.","journal-title":"Int J Comput Inf Sci Eng"},{"key":"48_CR4","volume-title":"Revealed: Operation Shady RAT, vol. 3","author":"D Alperovitch","year":"2011","unstructured":"Alperovitch, D, et al. (2011) Revealed: Operation Shady RAT, vol. 3. McAfee, Santa Clara."},{"key":"48_CR5","unstructured":"Bartholomew, B, Guerrero-Saade JA (2016) Wave your false flags! deception tactics muddying attribution in targeted attacks In: Virus Bulletin Conference, 1\u20139."},{"key":"48_CR6","doi-asserted-by":"crossref","unstructured":"Bartlett, G, Heidemann J, Papadopoulos C (2007) Understanding passive and active service discovery In: Proceedings of the 7th ACM SIGCOMM Conference on Internet Measurement, 57\u201370.. ACM.","DOI":"10.1145\/1298306.1298314"},{"key":"48_CR7","unstructured":"Beatty, M (2019) The current and future threat of steganography in malware command and control. PhD thesis. Utica College."},{"key":"48_CR8","doi-asserted-by":"crossref","unstructured":"Bilge, L, Dumitra\u015f T (2012) Before we knew it: an empirical study of zero-day attacks in the real world In: Proceedings of the 2012 ACM Conference on Computer and Communications Security, 833\u2013844.. ACM.","DOI":"10.1145\/2382196.2382284"},{"key":"48_CR9","unstructured":"Bilge, L, Kirda E, Kruegel C, Balduzzi M (2011) Exposure: Finding malicious domains using passive dns analysis In: Ndss, 1\u201317."},{"key":"48_CR10","doi-asserted-by":"crossref","unstructured":"Bowen, BM, Hershkop S, Keromytis AD, Stolfo SJ (2009) Baiting inside attackers using decoy documents In: International Conference on Security and Privacy in Communication Systems, 51\u201370.. Springer.","DOI":"10.1007\/978-3-642-05284-2_4"},{"key":"48_CR11","doi-asserted-by":"crossref","unstructured":"Brangetto, P, Veenendaal MA (2016) Influence cyber operations: The use of cyberattacks in support of influence operations In: 2016 8th International Conference on Cyber Conflict (CyCon), 113\u2013126.. IEEE.","DOI":"10.1109\/CYCON.2016.7529430"},{"key":"48_CR12","first-page":"379","volume":"97","author":"SW Brenner","year":"2006","unstructured":"Brenner, SW (2006) At light speed: Attribution and response to cybercrime\/terrorism\/warfare. J Crim L Criminol 97:379.","journal-title":"J Crim L Criminol"},{"key":"48_CR13","doi-asserted-by":"crossref","unstructured":"Brown, S, Gommers J, Serrano O (2015) From cyber security information sharing to threat management In: Proceedings of the 2nd ACM Workshop on Information Sharing and Collaborative Security, 43\u201349.. ACM.","DOI":"10.1145\/2808128.2808133"},{"key":"48_CR14","unstructured":"Bullock, C (2018) Don\u2019t Forget Victimology as a Cybersecurity Strategy. Secureworks Inc.https:\/\/www.secureworks.com\/blog\/dont-forget-victimology-as-a-cybersecurity-strategy. Accessed 25 Feb 2020."},{"key":"48_CR15","volume-title":"The diamond model of intrusion analysis. Technical report","author":"S Caltagirone","year":"2013","unstructured":"Caltagirone, S, Pendergast A, Betz C (2013) The diamond model of intrusion analysis. Technical report. Center For Cyber Intelligence Analysis and Threat Research, Hanover Md."},{"key":"48_CR16","unstructured":"Cherepanov, A (2018) GreyEnergy-A successor to BlackEnergy. https:\/\/www.welivesecurity.com\/wp-content\/uploads\/2018\/10\/ESET_GreyEnergy.pdf. Accessed 25 Feb 2020."},{"key":"48_CR17","doi-asserted-by":"publisher","DOI":"10.1201\/9781420086942","volume-title":"Profiling Hackers: the Science of Criminal Profiling as Applied to the World of Hacking","author":"R Chiesa","year":"2008","unstructured":"Chiesa, R, Ducci S, Ciappi S (2008) Profiling Hackers: the Science of Criminal Profiling as Applied to the World of Hacking. Auerbach Publications, Boca Raton."},{"key":"48_CR18","unstructured":"Cohen, D, Bar\u2019el D (2017) The use of cyberwarfare in influence operations In: October, Tel Aviv: Yuval Ne\u2019eman Workshop for Science, Technology and Security, 1\u201358."},{"key":"48_CR19","unstructured":"Corera, G (2016) How france\u2019s tv5 was almost destroyed by \u2019russian hackers\u2019. BBC News."},{"key":"48_CR20","doi-asserted-by":"crossref","unstructured":"Cova, M, Kruegel C, Vigna G (2010) Detection and analysis of drive-by-download attacks and malicious javascript code In: Proceedings of the 19th International Conference on World Wide Web, 281\u2013290.. ACM.","DOI":"10.1145\/1772690.1772720"},{"key":"48_CR21","unstructured":"Council on Foreign Relations (2018) Compromise of TV5 Monde. https:\/\/www.cfr.org\/interactive\/cyber-operations\/compromise-tv5-monde. Accessed 25 Feb 2020."},{"key":"48_CR22","unstructured":"ESET (2016) En Route with Sednit. http:\/\/www.welivesecurity.com\/wp-content\/uploads\/2016\/10\/eset-sednit-full.pdf. Accessed 25 Feb 2020."},{"issue":"6","key":"48_CR23","first-page":"29","volume":"5","author":"N Falliere","year":"2011","unstructured":"Falliere, N, Murchu LO, Chien E (2011) W32. stuxnet dossier. White Pap Symantec Corp Secur Response 5(6):29.","journal-title":"White Pap Symantec Corp Secur Response"},{"key":"48_CR24","volume-title":"9th USENIX Workshop on Offensive Technologies (WOOT 15)","author":"I Foster","year":"2015","unstructured":"Foster, I, Prudhomme A, Koscher K, Savage S (2015) Fast and vulnerable: a story of telematic failures In: 9th USENIX Workshop on Offensive Technologies (WOOT 15).. USENIX Association, Washington, D.C."},{"key":"48_CR25","unstructured":"Galperin, E, Marquis-Boire M (2012) Pro-syrian government hackers target activists with fake anti-hacking tool. Electron Front Found. https:\/\/www.eff.org\/deeplinks\/2012\/08\/syrian-malware-post. Accessed 25 Feb 2020."},{"key":"48_CR26","volume-title":"Cyber deterrence: Tougher in theory than in practice? Technical report","author":"W Goodman","year":"2010","unstructured":"Goodman, W (2010) Cyber deterrence: Tougher in theory than in practice? Technical report. Washington DC Committee on Armed Services, Senate (United States)."},{"key":"48_CR27","unstructured":"Gross, MJ (2011) A declaration of cyber-war. Vanity Fair. https:\/\/www2.cs.duke.edu\/courses\/common\/compsci092\/papers\/cyberwar\/stuxnet.pdf. Accessed 25 Feb 2020."},{"issue":"1","key":"48_CR28","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1016\/j.diin.2005.01.010","volume":"2","author":"D Haagman","year":"2005","unstructured":"Haagman, D, Ghavalas B (2005) Trojan defence: A forensic view. Digit Investig 2(1):23\u201330.","journal-title":"Digit Investig"},{"key":"48_CR29","volume-title":"Social Engineering: The Art of Human Hacking","author":"C Hadnagy","year":"2010","unstructured":"Hadnagy, C (2010) Social Engineering: The Art of Human Hacking. Wiley, New York City."},{"issue":"4","key":"48_CR30","doi-asserted-by":"publisher","first-page":"386","DOI":"10.1080\/15564886.2011.607402","volume":"6","author":"D Halder","year":"2011","unstructured":"Halder, D, Jaishankar K (2011) Cyber gender harassment and secondary victimization: A comparative analysis of the united states, the uk, and india. Vict Offenders 6(4):386\u2013398.","journal-title":"Vict Offenders"},{"issue":"4","key":"48_CR31","first-page":"12","volume":"20","author":"SL Harrington","year":"2014","unstructured":"Harrington, SL (2014) Cyber security active defense: Playing with fire or sound risk management. Richmond J Law Technol 20(4):12.","journal-title":"Richmond J Law Technol"},{"key":"48_CR32","doi-asserted-by":"publisher","first-page":"44","DOI":"10.1016\/j.diin.2006.06.005","volume":"3","author":"R Harris","year":"2006","unstructured":"Harris, R (2006) Arriving at an anti-forensics consensus: Examining how to define and control the anti-forensics problem. Digit Investig 3:44\u201349.","journal-title":"Digit Investig"},{"key":"48_CR33","doi-asserted-by":"crossref","unstructured":"Hulnick, AS (2010) The dilemma of open sources intelligence: Is osint really intelligence? In: The Oxford Handbook of National Security Intelligence.. Oxford University Press.","DOI":"10.1093\/oxfordhb\/9780195375886.003.0014"},{"key":"48_CR34","unstructured":"Hunker, J, Hutchinson B, Margulies J (2008) Role and challenges for sufficient cyber-attack attribution. Inst Inf Infrastruct Prot: 5\u201310."},{"issue":"1","key":"48_CR35","first-page":"80","volume":"1","author":"EM Hutchins","year":"2011","unstructured":"Hutchins, EM, Cloppert MJ, Amin RM (2011) Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains. Lead Issues Inf Warf Secur Res 1(1):80.","journal-title":"Lead Issues Inf Warf Secur Res"},{"key":"48_CR36","unstructured":"InfosecPartners (2016) Autopsy of Cyber Attack on TV5Monde. https:\/\/www.infosecpartners.com\/newsroom\/2016\/10\/10\/autopsy-cyber-attack-tv5monde\/. Accessed 25 Feb 2020."},{"issue":"1","key":"48_CR37","first-page":"43","volume":"18","author":"S Irshad","year":"2018","unstructured":"Irshad, S, Soomro TR (2018) Identity theft and social media. Int J Comput Sci Netw Secur 18(1):43\u201355.","journal-title":"Int J Comput Sci Netw Secur"},{"key":"48_CR38","doi-asserted-by":"publisher","DOI":"10.1201\/b10718","volume-title":"Cyber Criminology: Exploring Internet Crimes and Criminal Behavior","author":"K Jaishankar","year":"2011","unstructured":"Jaishankar, K (2011) Cyber Criminology: Exploring Internet Crimes and Criminal Behavior. CRC Press, Boca Raton."},{"issue":"4","key":"48_CR39","doi-asserted-by":"publisher","first-page":"657","DOI":"10.1080\/09546553.2013.847827","volume":"27","author":"L Jarvis","year":"2015","unstructured":"Jarvis, L, Macdonald S (2015) What is cyberterrorism? findings from a survey of researchers. Terrorism Polit Violence 27(4):657\u2013678.","journal-title":"Terrorism Polit Violence"},{"issue":"6","key":"48_CR40","first-page":"1317","volume":"27","author":"H Kang","year":"2017","unstructured":"Kang, H, Kim H, Lee H, Lee S-j (2017) Study on collecting server information through banner grabbing. J Korea Inst Inf Secur Cryptol 27(6):1317\u20131330.","journal-title":"J Korea Inst Inf Secur Cryptol"},{"key":"48_CR41","doi-asserted-by":"crossref","unstructured":"Kaushik, AK, Pilli ES, Joshi R (2010) Network forensic system for port scanning attack In: 2010 IEEE 2nd International Advance Computing Conference (IACC), 310\u2013315.. IEEE.","DOI":"10.1109\/IADCC.2010.5422935"},{"issue":"5","key":"48_CR42","doi-asserted-by":"publisher","first-page":"422","DOI":"10.1080\/1057610X.2014.893480","volume":"37","author":"EM Kearns","year":"2014","unstructured":"Kearns, EM, Conlon B, Young JK (2014) Lying about terrorism. Stud Confl Terrorism 37(5):422\u2013439.","journal-title":"Stud Confl Terrorism"},{"issue":"4","key":"48_CR43","doi-asserted-by":"publisher","first-page":"27","DOI":"10.1109\/MC.2002.1012428","volume":"35","author":"RA Kemmerer","year":"2002","unstructured":"Kemmerer, RA, Vigna G (2002) Intrusion detection: a brief history and overview. Computer 35(4):27\u201330.","journal-title":"Computer"},{"key":"48_CR44","doi-asserted-by":"crossref","unstructured":"Kijewski, P, Jaroszewski P, Urbanowicz JA, Armin J (2016) The never-ending game of cyberattack attribution In: Combatting Cybercrime and Cyberterrorism, 175\u2013192.. Springer, International.","DOI":"10.1007\/978-3-319-38930-1_10"},{"key":"48_CR45","first-page":"113","volume":"22","author":"K Krombholz","year":"2015","unstructured":"Krombholz, K, Hobel H, Huber M, Weippl E (2015) Advanced social engineering attacks. J Inf Secur Appl 22:113\u2013122.","journal-title":"J Inf Secur Appl"},{"key":"48_CR46","volume-title":"Managing Cyber Threats: Issues, Approaches, and Challenges, vol. 5","author":"V Kumar","year":"2006","unstructured":"Kumar, V, Srivastava J, Lazarevic A (2006) Managing Cyber Threats: Issues, Approaches, and Challenges, vol. 5. Springer, New York."},{"key":"48_CR47","doi-asserted-by":"publisher","first-page":"26","DOI":"10.1016\/j.cose.2017.08.005","volume":"72","author":"A Lemay","year":"2018","unstructured":"Lemay, A, Calvet J, Menet F, Fernandez JM (2018) Survey of publicly available reports on advanced persistent threat actors. Comput Secur 72:26\u201359.","journal-title":"Comput Secur"},{"key":"48_CR48","unstructured":"Li, F (2014) Apt attribution and dns profiling. Black Hat."},{"key":"48_CR49","doi-asserted-by":"crossref","unstructured":"Li, C, Jiang W, Zou X (2009) Botnet: Survey and case study In: 2009 Fourth International Conference on Innovative Computing, Information and Control (ICICIC), 1184\u20131187.. IEEE.","DOI":"10.1109\/ICICIC.2009.127"},{"key":"48_CR50","doi-asserted-by":"crossref","unstructured":"Liao, K, Zhao Z, Doup\u00e9 A, Ahn G-J (2016) Behind closed doors: measurement and analysis of cryptolocker ransoms in bitcoin In: 2016 APWG Symposium on Electronic Crime Research (eCrime), 1\u201313.. IEEE.","DOI":"10.1109\/ECRIME.2016.7487938"},{"key":"48_CR51","volume-title":"Malware Analyst\u2019s Cookbook and DVD: Tools and Techniques for Fighting Malicious Code","author":"M Ligh","year":"2010","unstructured":"Ligh, M, Adair S, Hartstein B, Richard M (2010) Malware Analyst\u2019s Cookbook and DVD: Tools and Techniques for Fighting Malicious Code. Wiley Publishing, New York City."},{"key":"48_CR52","unstructured":"Long, LA (2012) Profiling hackers. SANS Institute Reading Room: pp 1\u201322. https:\/\/www.sans.org\/reading-room\/whitepapers\/hackers\/profiling-hackers-33864. Accessed 25 Feb 2020."},{"issue":"5","key":"48_CR53","doi-asserted-by":"publisher","first-page":"225","DOI":"10.1109\/MCOM.2014.6815916","volume":"52","author":"J Lubacz","year":"2014","unstructured":"Lubacz, J, Mazurczyk W, Szczypiorski K (2014) Principles and overview of network steganography. IEEE Commun Mag 52(5):225\u2013229.","journal-title":"IEEE Commun Mag"},{"key":"48_CR54","volume-title":"Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning","author":"GF Lyon","year":"2009","unstructured":"Lyon, GF (2009) Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning. Insecure, Sunnyvale."},{"key":"48_CR55","first-page":"2016","volume":"28","author":"N MacFarquhar","year":"2016","unstructured":"MacFarquhar, N (2016) A powerful russian weapon: The spread of false stories. N Y Times 28:2016.","journal-title":"N Y Times"},{"key":"48_CR56","unstructured":"Maurice, E (2015) Cyber attack on French TV finds EU unprepared. https:\/\/euobserver.com\/news\/128285. Accessed 25 Feb 2020."},{"key":"48_CR57","unstructured":"Miller, C (2007) The legitimate vulnerability market: Inside the secretive world of 0-day exploit sales In: In Sixth Workshop on the Economics of Information Security."},{"key":"48_CR58","unstructured":"MITRE (2019) ATT&CK Matrix for Enterprise. https:\/\/attack.mitre.org\/. Accessed 25 Feb 2020."},{"key":"48_CR59","unstructured":"Morgan, R, Kelly D (2019) A novel perspective on cyber attribution In: International Conference on Cyber Warfare and Security, 609.. Academic Conferences International Limited."},{"key":"48_CR60","doi-asserted-by":"crossref","unstructured":"Nunes, E, Diab A, Gunn A, Marin E, Mishra V, Paliath V, Robertson J, Shakarian J, Thart A, Shakarian P (2016) Darknet and deepnet mining for proactive cybersecurity threat intelligence In: 2016 IEEE Conference on Intelligence and Security Informatics (ISI), 7\u201312.. IEEE.","DOI":"10.1109\/ISI.2016.7745435"},{"key":"48_CR61","unstructured":"Obervser Schindler, JR (2016) False Flags:The Kremlin\u2019s Hidden Cyber Hand. https:\/\/observer.com\/2016\/06\/false-flags-the-kremlins-hidden-cyber-hand\/. Accessed 25 Feb 2020."},{"key":"48_CR62","unstructured":"Paganini, P (2015) FireEye Claims Russian APT28 Hacked France\u2019s TV5Monde Channel. Secur Aff. https:\/\/securityaffairs.co\/wordpress\/37710\/hacking\/apt28-hacked-tv5monde.html. Accessed 25 Feb 2020."},{"key":"48_CR63","unstructured":"Pahi, T, Skopik F (2019) Cyber attribution 2.0: Capture the false flag In: ECCWS 2019 18th European Conference on Cyber Warfare and Security, 338.. Academic Conferences and publishing limited."},{"issue":"1","key":"48_CR64","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1080\/01402390.2012.742014","volume":"36","author":"D Peterson","year":"2013","unstructured":"Peterson, D (2013) Offensive cyber weapons: construction, development, and employment. J Strat Stud 36(1):120\u2013124.","journal-title":"J Strat Stud"},{"key":"48_CR65","volume-title":"Cyber deterrence: An old concept in a new domain. Technical report","author":"MJ Philbin","year":"2013","unstructured":"Philbin, MJ (2013) Cyber deterrence: An old concept in a new domain. Technical report. Army War College, Carlisle Barracks PA."},{"key":"48_CR66","volume-title":"Mitigating risks arising from false-flag and no-flag cyber attacks","author":"M Pihelgas","year":"2015","unstructured":"Pihelgas, M (2015) Mitigating risks arising from false-flag and no-flag cyber attacks. CCD COE, NATO, Tallinn."},{"issue":"1-2","key":"48_CR67","doi-asserted-by":"publisher","first-page":"4","DOI":"10.1080\/01402390.2014.977382","volume":"38","author":"T Rid","year":"2015","unstructured":"Rid, T, Buchanan B (2015) Attributing cyber attacks. J Strateg Stud 38(1-2):4\u201337.","journal-title":"J Strateg Stud"},{"key":"48_CR68","doi-asserted-by":"crossref","unstructured":"Santanna, JJ, van Rijswijk-Deij R, Hofstede R, Sperotto A, Wierbosch M, Granville LZ, Pras A (2015) Booters\u2014an analysis of ddos-as-a-service attacks In: 2015 IFIP\/IEEE International Symposium on Integrated Network Management (IM), 243\u2013251.. IEEE.","DOI":"10.1109\/INM.2015.7140298"},{"key":"48_CR69","unstructured":"Schwarzt, MJ (2017) French Officials details \"Fancy Bear\" hack on TV5Monde. https:\/\/www.bankinfosecurity.com\/french-officials-detail-fancy-bear-hack-tv5monde-a-9983. Accessed 25 Feb 2020."},{"key":"48_CR70","doi-asserted-by":"publisher","first-page":"154","DOI":"10.1016\/j.cose.2016.04.003","volume":"60","author":"F Skopik","year":"2016","unstructured":"Skopik, F, Settanni G, Fiedler R (2016) A problem shared is a problem halved: A survey on the dimensions of collective cyber defense through security information sharing. Comput Secur 60:154\u2013176.","journal-title":"Comput Secur"},{"key":"48_CR71","doi-asserted-by":"crossref","unstructured":"Stone-Gross, B, Cova M, Cavallaro L, Gilbert B, Szydlowski M, Kemmerer R, Kruegel C, Vigna G (2009) Your botnet is my botnet: analysis of a botnet takeover In: Proceedings of the 16th ACM Conference on Computer and Communications Security, 635\u2013647.. ACM.","DOI":"10.1145\/1653662.1653738"},{"key":"48_CR72","unstructured":"Strom, BE, Battaglia JA, Kemmerer MS, Kupersanin W, Miller DP, Wampler C, Whitley SM, Wolf RD (2017) Finding cyber threats with att&ckTM-based analytics. Technical report. MITRE Technical Report MTR170202. The MITRE Corporation."},{"issue":"8","key":"48_CR73","doi-asserted-by":"publisher","first-page":"16","DOI":"10.1016\/S1353-4858(11)70086-1","volume":"2011","author":"C Tankard","year":"2011","unstructured":"Tankard, C (2011) Advanced persistent threats and how to monitor and deter them. Netw Secur 2011(8):16\u201319.","journal-title":"Netw Secur"},{"key":"48_CR74","first-page":"376","volume":"20","author":"D Tran","year":"2018","unstructured":"Tran, D (2018) The law of attribution: Rules for attribution the source of a cyber-attack. Yale JL Tech 20:376.","journal-title":"Yale JL Tech"},{"key":"48_CR75","unstructured":"TrendMicro (2015) TV5 Monde, Russia and the CyberCaliphate. https:\/\/blog.trendmicro.com\/tv5-monde-russia-and-the-cybercaliphate\/. Accessed 25 Feb 2020."},{"key":"48_CR76","unstructured":"TrendMicro (2016) Operation Pawn Storm: Fast Facts and the Latest Developments. https:\/\/blog.trendmicro.com\/tv5-monde-russia-and-the-cybercaliphate\/. Accessed 25 Feb 2020."},{"issue":"2","key":"48_CR77","doi-asserted-by":"publisher","first-page":"229","DOI":"10.1093\/jcsl\/krs019","volume":"17","author":"N Tsagourias","year":"2012","unstructured":"Tsagourias, N (2012) Cyber attacks, self-defence and the problem of attribution. J Confl Secur Law 17(2):229\u2013244.","journal-title":"J Confl Secur Law"},{"key":"48_CR78","unstructured":"Tsagourias, N, Farrell MD (2018) Cyber attribution: technical and legal approaches and challenges. draft article. https:\/\/sites.tufts.edu\/cilg\/files\/2018\/09\/attributiondraftsm.pdf. Accessed 25 Feb 2020."},{"issue":"3","key":"48_CR79","first-page":"106","volume":"2","author":"P Tuli","year":"2013","unstructured":"Tuli, P, Sahu P (2013) System monitoring and security using keylogger. Int J Comput Sci Mob Comput 2(3):106\u2013111.","journal-title":"Int J Comput Sci Mob Comput"},{"key":"48_CR80","volume-title":"Criminal Profiling: An Introduction to Behavioral Evidence Analysis","author":"BE Turvey","year":"2011","unstructured":"Turvey, BE (2011) Criminal Profiling: An Introduction to Behavioral Evidence Analysis. Academic press, USA."},{"key":"48_CR81","unstructured":"Vogt, P, Nentwich F, Jovanovic N, Kirda E, Kruegel C, Vigna G (2007) Cross site scripting prevention with dynamic data tainting and static analysis In: NDSS, vol. 2007, 12."},{"key":"48_CR82","doi-asserted-by":"crossref","unstructured":"Wagner, C, Dulaunoy A, Wagener G, Iklody A (2016) Misp: The design and implementation of a collaborative threat intelligence sharing platform In: Proceedings of the 2016 ACM on Workshop on Information Sharing and Collaborative Security, 49\u201356.. ACM.","DOI":"10.1145\/2994539.2994542"},{"key":"48_CR83","doi-asserted-by":"publisher","DOI":"10.21236\/ADA468859","volume-title":"Techniques for cyber attack attribution. Technical report","author":"DA Wheeler","year":"2003","unstructured":"Wheeler, DA, Larsen GN (2003) Techniques for cyber attack attribution. Technical report. Institute for Defense Analyses, Alexandria VA."},{"key":"48_CR84","volume-title":"Handbook of Terrorism and Counter Terrorism Post 9\/11","author":"JR Woodier","year":"2019","unstructured":"Woodier, JR, Zingerle A (2019) The internet and cybersecurity: taking the virtual fight to cybercrime and cyberwarfare In: Handbook of Terrorism and Counter Terrorism Post 9\/11.. Edward Elgar Publishing, Cheltenham."},{"key":"48_CR85","doi-asserted-by":"crossref","unstructured":"Yadav, T, Rao AM (2015) Technical aspects of cyber kill chain In: International Symposium on Security in Computing and Communication, 438\u2013452.. Springer.","DOI":"10.1007\/978-3-319-22915-7_40"},{"key":"48_CR86","volume-title":"Ten strategies of a world-class cybersecurity operations center","author":"C Zimmermann","year":"2014","unstructured":"Zimmermann, C (2014) Ten strategies of a world-class cybersecurity operations center. MITRE corporate communications and public affairs, Bedford. Appendices."}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-020-00048-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1186\/s42400-020-00048-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-020-00048-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,3,20]],"date-time":"2021-03-20T00:13:02Z","timestamp":1616199182000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-020-00048-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,3,20]]},"references-count":86,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2020,12]]}},"alternative-id":["48"],"URL":"https:\/\/doi.org\/10.1186\/s42400-020-00048-4","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,3,20]]},"assertion":[{"value":"8 October 2019","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"20 February 2020","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"20 March 2020","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"None","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"8"}}