a forger’s skill becomes their signature.
epistylometry, from the greek “epistos” for “knowledge” and “stylos” for “style”, is the knowledge signature of a person. what someone does demonstrates what they know, possibly what they don’t know, and possibly what they are trying to obscure they know. the term borrows from the commonplace word “stylometry”, which is used to describe someone’s writing style based on various metrics.
you know in “breaking bad”, where it should have been obvious to agent schrader that heisenberg was walter white, due to the advanced chemistry knowledge needed to make blue meth? that chemistry is walter white’s epistylometric signature.
this terminology pulls together a few other similar-but-disparately-named terms and concepts from various places (see the need for a nomenclator), including:
this framework for epistylometry was written with high-stakes scenarios in mind, where it would be necassary, such as corporate espionage, national intelligence agencies, and cybercrime. a more applicable but medium-stakes scenario is criminal investigations. an example of staff at a restaurant is used because it is a low-stakes environment.
here we use:
we also use:
epistylometric uniqueness is the measurement of how disparate your domains of expertise are.
the simple formula for EU is the mean pairwise distance of all your knowledge domains.
where is your set of knowledge domains and is the distance between two domains.
someone who uses only {python, javascript, react} in an operation demonstrates minimal EU - those domains are all adjacent. someone who uses {mechanical engineering, louisiana folklore, fashion design} in an operation demonstrates much higher EU because those domains are maximally distant.
now if someone has a bunch of “domains” that are closely related (for example, 20 different programming languages) and then one or two really disparate ones (louisiana culture, clothing design), the mean pairwise distance formula would have a really low result, (lets arbitrarily say 0.1); whereas if you regard all the programming languages together as one domain - which it might as well be - than your EU would skyrocket (say, 0.9).
to deal with this problem best, we use the spatio-parametric Rao’s quadratic entropy (Rocchini, Marcantonio, Re, Bacaro, Enrico, et. al., 2021) formula to adjust for domain proximity
when comparing two or more people’s EU, the highest one should always be measured as 1, and the other ones lower.
several good strategies for “red teaming” emerge.
imagine agent iso studying agent allo’s knowledge signature so carefully they can carry out an operation that looks exactly like allo did it. the higher your epistylometric uniqueness, the harder you are to impersonate fully.
when choosing a target for framing someone with epistylometric camouflage, two things must be considered
the more similar someone’s epistylometric profile, the easier it will be to mimic them.
epistylometric camouflage, if executed well, is most effective on very unique epistylometric profiles (“there is only one person in the world with this combination, so the culprit has to be them”), but it is harder to replicate on them. highly unique profiles are both the most valuable to impersonate and the hardest to fake.
a good heuristic would not be choosing someone who’s EU is too similar to your own, because than it makes you a suspect if epistylometric camouflage is not considered.
if there is someone who’s knowledge base is fairly similar to your own, but not too similar, and who has a very high epistylometric uniqueness (i.e. they know a lot of the things you know, but they also know a couple topics that are way out there), than they would be an ideal camouflage target.
to demonstrate actual expertise, an impostor would have able to counterfeit for low alpha parameter and show enough specific expertise within subdomains or closely related domains. to demonstrate someone else’s signature clearly, an impostor would have to be able to counterfeit very disparate domains, or low alpha parameter.
a passive strategy an attacker can take is to obscure what they know, particularly certain techniques. with attacker alpha and skill tau, if no one knows alpha knows tau, than alpha can use tau without being feared of being easily detected. (see)
when carrying out a non-crucial attack and not using epistylomtric camouflage, a good strategy an attacker can take is to handicap themselves, and take care to use only commonly known skillsets (no obscure computer programming languages from russia or odd lisp dialects) - using pep-8 styled python, linux styled c. this may limit their capabilities, but also limits the possibility of them being detected.
if an attacker has a some specific skills that compliments the rest of their skillset really well but is somewhat obscure and can be used to identify them, a strategy they could take is broadcasting to many people how to do that skill. then it becomes much harder for detectives to use those particular skills to narrow down their search.
for example, if a restaurant manager tells a few trainees where the key to get into the backdoor is while the owner is present in the conversation, and the next day the manager sneaks into the store and wipes the cash register, then the trainees are also suspect. this reasonable doubt attribution cannot be overcome.
compliments epistylometric dilution. can also be used in blue teaming.
an attacker or a detective can create and thinly distribute honeypot techniques, which could be faulty techniques that don’t work, or techniques that are easily identifiable, or something else. if an attacker is framing another attacker (maybe to eliminate competition), than they would have to make sure that both the other attacker and a detective know it. when the other attacker uses the honeypot technique, than they are trapped. for a detective, this is a classic setup. is more effective the less it is spread around. (if it’s an intentionally faulty technique, and it is discovered it is faulty, than a bridge channel could broadcast to everyone that is faulty and then no one would use it.)
for example, if a restaurant employee iso wants to get rid of another employee allo, they can show them a video of a hairpin lockpicking technique that only work on some locks and breaks the hairpin inside in other locks, that iso knows doesn’t work on the cash register. it is important that iso makes allo demonstrate that he knows the technique to at least one other person. now if allo attempts to open the cash register and the hairpin breaks, than allo has been epistylometrically honeypotted.
if known agent ’s skillset contains skills , and detective knows that unknown attacker ’s skillset contains , than can suspect .
schelling points are natural convergence points where most competent people would arrive at the same solution to a problem, first introduced by the American economist Thomas Schelling in his 1960 book The Strategy of Conflict. A criminologist can use schelling points to narrow down who the culprit is based on what levels of competency the culprit displays.
epistylometry is about how knowledge itself creates identity. we are what we know and the unique combination of what we know. it’s not paranoia