Follow the Operator ยท 18 โ The Split Problem: One Cluster, Two Hands
Follow the Operator โ Case 18. This register takes a cloud of unrelated-looking attacks and follows one forensic thread back to the single hand behind them, closing each case on the signal that clinched it: SHARED KEY ยท SHARED MALWARE ยท SHARED FINGERPRINT ยท SHARED INFRASTRUCTURE ยท SHARED BEHAVIOR ยท NAMED IDENTITY.
The merge corrected under-clustering โ two operators seen as one, unified by a heavy edge. This case corrects the opposite and more dangerous error: over-clustering, one cluster that is really two operators, falsely joined into a single hand by a light bridging edge. Where the merge added a heavy edge to unify what should have been together, the split removes a light edge to separate what should never have been joined. And the split is the graver of the two corrections, because the error it fixes is the graver error: a false merge over-attributes, crediting one operator with another's actions, and over-attribution is the mistake the whole register has been most afraid of โ the super-node, the shared-tool trap, the innocent swept into a cluster. The split is the register cleaning up its own worst failure mode, and it does so with a bias the merge did not have: an aggressive presumption that a cluster held together by light edges is probably two operators, not one.
The false unifier is almost always a shared commodity artifact โ the same light edges the register warned about throughout, now seen doing their damage in the graph. Two genuinely distinct operators both use the same common scanning tool, and a shared-fingerprint edge appears between them. Both load the same public wordlist, and a shared-behavior edge appears. Both rent from the same legitimate cloud, and a shared-infrastructure edge appears. Any one of these light edges, if trusted, bridges the two operators into one cluster, and an analyst reading the graph by connections rather than by weights concludes he has found one large operator when he has found two smaller ones joined by a market they both shop in. The false super-node is built from exactly the edges the register always rated LOW, and the split is the operation that recognizes those edges as the false bridges they are and cuts them.
The tell that a cluster should be split is its internal structure, and this is the case's central technical insight. A genuine single operator is a region uniformly dense in heavy edges โ his key, his behavior, his infrastructure tie all his nodes together thickly. A false super-node is not uniformly dense; it has structure: two internally-dense sub-regions, each a real operator cohered by his own bespoke keys and behaviors, connected to each other only by a thin seam of light edges โ the shared tool, the shared wordlist. The two dense cores are the two real operators; the thin light seam between them is the false bridge; and cutting the seam splits the false cluster into its true two hands. The split reads the graph not as a flat set of connections but as a landscape of dense cores and thin seams, and it cuts at the seams, because a seam of light edges between two heavy cores is the signature of two operators wrongly joined. Linkage signal: the SHARED FINGERPRINT caveat โ the shared tool that falsely unified, made structural.
1. Cores and Seams
Begin with the structural picture, because the split depends entirely on reading it correctly. Imagine the graph region that has been attributed as one operator. If it is genuinely one operator, its internal structure is homogeneous: pick any two nodes in it, and they are connected by heavy edges (the operator's reused key, his consistent behavior), directly or through short heavy paths, because one operator's fleet is thickly interconnected by his own reused invariants. There is no internal seam, no place where the region is only weakly held together, because the operator's invariants pervade the whole of it. A genuine operator-region is a dense, uniform knot.
A false super-node looks different, and the difference is visible to anyone who examines the internal edges rather than just the outer boundary. It is not one uniform knot but two, joined by a thread. Sub-region A is dense in heavy edges โ operator A's key, operator A's behavior, tying operator A's nodes thickly together. Sub-region B is likewise dense in operator B's heavy edges. But between A and B, there is no heavy edge at all; there is only a thin bundle of light edges โ the shared tool both operators use, the public wordlist both loaded โ connecting the two dense cores across a narrow seam. Remove that seam and the region falls into two pieces, each of which is a genuine dense operator-core. The false super-node is two operators wearing, between them, one commodity artifact, and the artifact is the only thing holding the two cores together.
This structural signature is what makes the split principled rather than arbitrary, and it is the answer to "how do you know where to cut." You do not cut arbitrarily; you cut at the seam, which the graph itself reveals as the place where the region is held together only by light edges. Community-detection algorithms, run on the weighted graph, find exactly this: they identify the two dense communities (the real operators) and the sparse boundary between them (the false bridge), and the split is made at that boundary. The heavy edges within each core are kept โ they are the real operators' real invariants โ and the light edges across the seam are cut, because they are the false unifier. So the split is not the analyst deciding to break a cluster on a hunch; it is the analyst reading the cluster's internal structure, finding it is two dense cores joined by a light seam, and cutting the seam the structure itself identifies. The graph shows where it is falsely joined, and the split cuts there.
2. The Shared Tool as the Prime Suspect
Now the most common false bridge, because naming it lets the analyst know where to look: the shared tool, the SHARED FINGERPRINT caveat made structural. The fingerprint case warned that a shared tool ties a tool's whole userbase, not one hand โ that a common HASSH attributes a market, not an operator. In the graph, that warning becomes a specific structural danger: a shared-tool edge between two operators is a light edge that will, if trusted, bridge them into one cluster. And because tools are so widely shared โ thousands of operators use the same common scanners, the same public libraries โ shared-tool edges are the single most prolific source of false bridges, connecting operators who have nothing in common but a download. The shared tool is the prime suspect whenever a cluster looks too large or too heterogeneous, because it is the edge most likely to have falsely joined two hands.
The honeypot's own largest clusters are the proof, and they are instructive precisely because they are so large. Its biggest HASSH clusters โ libssh 0.11.x at 1,313 IPs across 84 countries, OpenSSH_7.4 at 757 across 78 โ are enormous, and if read naively as operators, they would be absurd mega-operators spanning most of the world. They are, of course, nothing of the kind: they are the userbases of common SSH libraries, populations of a tool, not operators, and the 1,313 IPs sharing the libssh fingerprint are 1,313 unrelated attackers who happen to run the same library. These are the over-clustered super-nodes a shared tool creates, at their most extreme, and they are the standing illustration of why a shared-tool edge must never merge and why any cluster built on shared-tool edges must be split. The honeypot does not report these HASSH clusters as operators; it reports them as tool clusters, correctly, and the split is the general operation of doing to smaller false super-nodes what the sensor already does to these obvious ones.
This is why the split's prime move is to interrogate the bridging edges of any large or heterogeneous cluster: are they heavy or light? A cluster genuinely held together by heavy edges (one operator's key pervading it) is real and stays whole. A cluster held together, at its seams, by light edges (a shared tool, a shared wordlist, a shared cloud) is a false super-node and must be split at those seams. The analyst does not need to prove the cluster is two operators from scratch; he needs only to notice that its cohesion depends on light edges, which is the signature of over-clustering, and split accordingly. The shared tool is the prime suspect because it is the most common light bridge, and the register's whole treatment of the fingerprint as a low-confidence signal was, all along, preparation for this moment: recognizing the shared tool as a false unifier in the graph and refusing to let it hold two operators in one cluster.
3. Why Splitting Is the Safer Bias
Now the asymmetry that gives the split its aggressive default, because it is the ethical core of the case and the register's whole method: over-clustering is a worse error than under-clustering, so when in doubt, split. The merge case established that under-clustering (two hands seen as two) is a mild error โ it misses a connection, leaving a real operator split across two clusters, which is incomplete but not false. Over-clustering (two hands seen as one) is a severe error โ it invents a connection, crediting one operator with another's actions, and that is not merely incomplete but actively wrong, and wrong in the direction that harms. A false super-node over-attributes: it makes one operator appear responsible for everything the two of them did, inflating his apparent scale, misdirecting defense toward a phantom mega-operator, and โ most seriously, if the attribution ever reaches naming โ risking that one operator (or an innocent swept into the cluster) is blamed for the other's crimes.
This asymmetry is why the register's defaults differ between the two corrections. For the merge, the default was against merging โ the burden was on the merge to prove a heavy bridge, and absent proof the clusters stayed separate, erring toward the milder under-clustering. For the split, the default is toward splitting โ the burden is on keeping a light-bridged cluster whole, and absent a heavy edge spanning the whole cluster, the register splits it, erring away from the severe over-clustering. The two defaults both point in the same ethical direction: toward the milder error, toward under-attribution rather than over-attribution, toward "we may have missed a connection" rather than "we may have invented one." The register would rather show two operators that are really one (a missed merge, recoverable) than one operator that is really two (a false merge, harmful), so it merges reluctantly and splits readily, and both reluctances serve the same principle.
And this principle is the register's deepest commitment made structural, connecting the split back to the whole series' ethical spine. Every caution the register raised โ the shared-tool trap, the bulletproof-landlord conflation, the stolen-identity warning, the false-flag defense โ was a caution against over-attribution, against crediting a hand with what it did not do or naming a party that is innocent. The split is that caution operationalized in the graph: the operation that actively hunts down over-clustering and undoes it, cutting the false bridges that would credit one operator with another's actions. That the register splits aggressively โ suspecting every light-bridged cluster, cutting at every light seam โ is not analytical timidity; it is the register's refusal to over-attribute, applied to its own clusters, hunting its own worst error before that error can harm. The split is where the register polices itself against the mistake it fears most, and its aggressive default is the measure of how much it fears it.
4. SHARED FINGERPRINT โ The Caveat Made Structural
The linkage signal is the SHARED FINGERPRINT caveat, because the shared tool is the archetypal false bridge, and the split is the operation that finally cashes out the warning the fingerprint case issued. When the fingerprint case rated the shared tool at MEDIUM-HIGH-and-falling, warning that a shared tool ties a market not a hand, that warning was a promissory note: it said "do not trust this edge to attribute an operator," but it did not yet show what happens when you do. The split shows it: you build a false super-node, joining unrelated operators by the tool they share, and the honeypot's 1,313-IP libssh cluster is what that looks like at scale. The split is the fingerprint caveat's consequence and its remedy โ the demonstration of the damage a trusted shared-tool edge does, and the operation that undoes it by cutting the shared-tool seam.
And the split completes the merge's symmetry, giving the register its full account of graph correction. The two cases are exact mirrors: the merge adds a heavy edge to correct under-clustering; the split cuts a light edge to correct over-clustering. Together they establish that the graph is corrected in both directions by the same principle โ edge weight โ applied to the two ways a cluster can be wrong. A cluster too small (missing a real unity) is corrected by adding the heavy edge that reveals the unity; a cluster too large (containing a false unity) is corrected by cutting the light edge that faked it. Heavy edges unify truly and light edges unify falsely, and the whole of graph correction is adding true unifications and removing false ones, both governed by the shareability gradient that decides which edges are heavy and which are light. The merge and the split are the graph's two hands, and between them they keep the graph honest as it grows.
That the register performs both corrections, and biases each toward the milder error, is the final expression of its calibration. It does not treat its clusters as fixed truths; it treats them as a living structure to be continuously corrected as evidence accumulates โ merged when a heavy edge reveals a hidden unity, split when a light seam reveals a false one. And it biases the corrections asymmetrically, reluctant to merge and ready to split, because the two errors are not equally harmful and honesty requires erring toward the less harmful one. The SHARED FINGERPRINT caveat, which seemed a mere confidence footnote when the fingerprint case raised it, is revealed here as a structural principle: the shared tool is a false unifier, its edge must not bridge, and the split is the operation that enforces the caveat against the graph's tendency to over-cluster. The register spent a case teaching the reader to distrust the shared tool; the split is where that distrust does its work, cutting the tool's false bridges so that two operators wearing one tool are seen, correctly, as two.
5. Splitting Well (and Trusting the Split)
The register owes the analyst a split discipline, and it is the merge discipline inverted. First, suspect any cluster whose cohesion depends on light edges โ a cluster held together by shared tools, public wordlists, or shared legitimate clouds is a split candidate by default, because light edges bridge markets not hands. Second, examine the internal structure: look for dense sub-regions of heavy edges connected only by thin seams of light ones, because that structure is the signature of two operators falsely joined. Third, cut at the seam: split the cluster into its dense cores, keeping the heavy intra-core edges and discarding the light bridging ones. Fourth, keep whole only what a heavy edge genuinely spans: a cluster stays one operator only if a heavy edge (a bespoke key, a bespoke C2) pervades the whole of it, not just its sub-regions. The split is aggressive by design โ the default is to split the light-bridged cluster unless a heavy edge proves it whole โ because the error it prevents (over-clustering) is the one that harms.
For the defender and the consumer of threat intelligence, the split carries a crucial consumer-side lesson: distrust the mega-operator. When threat intelligence reports a single vast operator spanning many countries and many campaigns, the consumer's first question should be "is this one hand or a tool cluster?" โ because the most common way attribution goes wrong at scale is the false super-node, a tool's userbase reported as an operator. A claimed operator of 1,313 IPs across 84 countries is far more likely a HASSH cluster than a hand, and the sophisticated consumer knows to ask whether the cluster is held together by heavy edges (real) or light ones (a false super-node). The split's lesson to the consumer is skepticism toward size: a big attribution is more likely wrong than a small one, because bigness is what over-clustering produces, and the biggest attributions are the ones most likely to be tool clusters mislabeled as operators.
The honest close is the trust the split earns for the register, and it is the counterpart to the merge's. A register that only merged โ that only ever made its attributions bigger โ would be an over-attribution machine, always growing its clusters and never questioning them. A register that splits, and splits aggressively, demonstrates the opposite: that it actively hunts its own over-clustering, cuts its own false bridges, and revises its clusters downward when their cohesion proves to be a shared tool rather than a shared hand. The willingness to split is the register's proof that its clusters are not inflated โ that when it reports one operator, it has checked that the cluster is not two, cut any light seam it found, and kept whole only what heavy edges genuinely span. And like the merge, the split revises the record honestly: a prior dossier that documented two operators as one is superseded, updated downward, the correction shown rather than hidden. The register updates in both directions with equal honesty, merging reluctantly and splitting readily, because the two errors are unequal and honesty requires treating them so. The vectors do not lie, but a shared tool creates a false bridge that looks like a connection, and the register cuts it โ reading the graph for the dense cores and the thin seams, and splitting the one hand that was always two. We do not judge. We record. We let people judge โ and we cut the false bridge before it credits one operator with another's crimes.
6. The counter-narrative, steelmanned
The strongest objection to this case is that the split, biased as aggressively as the register wants it, is a fragmentation machine โ by defaulting to split any cluster held together by light edges, it will shatter genuine operators who happen to use common tools into many false fragments, under-attributing as badly as the merge over-attributes, and there is no principled stopping point to the splitting.
The argument runs like this. Real operators, the objection notes, do use common tools โ an operator who scatters across cloud providers, uses stock scanners, and loads public wordlists is a real single hand whose edges are mostly light, and the aggressive split would tear him apart at every light seam, fragmenting one operator into a dozen tiny clusters because his cohesion happens to run through commodity artifacts. The bias toward splitting, the objection continues, has no natural limit: if any light-bridged region is a split candidate, and if operators legitimately share light edges, then the split will keep cutting until every cluster is reduced to its heaviest cores and everything connected only by light edges is severed โ which under-attributes the real operator whose activity is genuinely bridged by his own (light) tooling choices. The register, on this view, has replaced the over-attribution of the merge with a symmetrical over-fragmentation, and its "bias toward the milder error" just moves the error to the other side.
The register accepts that reckless splitting would fragment and argues that the split is gated by the same structural test that prevents it. Yes โ a split with no principle would shatter real operators, and under-fragmentation is a real error the register does not want to commit; the objection correctly identifies the failure mode of an unprincipled split. But the split is not "cut every light edge"; it is "cut the light SEAM between two dense heavy cores," and that structural condition is what limits it. The test is not the mere presence of light edges (real operators have those) but the specific structure of two internally-dense heavy-edge cores connected only by light edges โ and that structure exists only when there really are two operators, because a single operator does not have two separate dense heavy cores; he has one, pervaded by his own heavy invariants. An operator who uses common tools is still, internally, one dense core of his own reused key and behavior, so he presents no seam to cut โ his light tool-edges are within his single heavy core, not a bridge between two, and the split leaves him whole because there is no two-core structure to separate. The split fires only when the graph shows two heavy cores with a light bridge, which is the actual signature of two operators, and it does not fire on a single operator who merely uses light tooling, because he is one core. So the bias toward splitting is not unlimited; it is bounded by the requirement of two dense cores, which is present for two operators and absent for one. The objection's fragmented operator would only be split if he genuinely had two separate heavy-edge cores โ and if he did, he would be two operations worth distinguishing anyway. The register splits aggressively at true seams and not at all within true cores, and the two-core structural test is exactly the principled stopping point the objection says is missing.
7. Linkage Signal โ SHARED FINGERPRINT
Case 18 was the mirror of the merge: the split corrects over-clustering. One operator cluster documented as a single hand is revealed to be two operators falsely joined by a light bridging edge โ a shared common tool, a public wordlist, a shared legitimate cloud โ that tied a market and not a hand. The tell is the internal structure: an over-clustered region is not one uniform dense knot but two dense cores of heavy edges connected only by a thin seam of light ones, and the split cuts the seam and keeps the cores, resolving the false super-node into its true two hands. The graph itself shows where it is falsely joined, and the split cuts there.
The linkage signal โ the false unifier โ is the SHARED FINGERPRINT caveat made structural: the shared tool is the most common false bridge, because a tool ties its whole userbase, and the honeypot's largest clusters (libssh 0.11.x at 1,313 IPs across 84 countries, OpenSSH_7.4 at 757) are exactly these tool populations โ over-clustered super-nodes a shared tool creates, reported correctly as tool clusters and not operators. The split is the fingerprint caveat's consequence and remedy: the demonstration of the damage a trusted shared-tool edge does, and the operation that undoes it by cutting the shared-tool seam. It completes the merge's symmetry โ the merge adds a heavy edge to unify truly, the split cuts a light edge to separate falsely, both governed by the shareability gradient that decides which edges are heavy and which light.
The split's aggressive default is the register's ethical core made operational: over-clustering (two hands seen as one) over-attributes, crediting one operator with another's actions, and is a worse error than under-clustering (two hands seen as two), which only misses a connection โ so the register merges reluctantly and splits readily, erring always toward the milder mistake. The split is where the register hunts its own worst failure, cutting the false bridges that would credit a hand with what it did not do, before that error can harm. It is bounded by the two-dense-cores structural test, so it separates real seams without fragmenting real operators. And it revises the record downward as honestly as the merge revises upward. The vectors do not lie, but a shared tool creates a false bridge that looks like a connection, and the register cuts it. We do not judge. We record. We let people judge โ and we cut the false bridge before it credits one operator with another's crimes.
Follow the Operator โ Case 18. Linkage signal: SHARED FINGERPRINT caveat (the shared tool that falsely unified, made structural). Confidence: the case is about revising attribution DOWNWARD, honestly, and biasing toward the split. The split corrects over-clustering: one cluster documented as a single operator is revealed to be two, falsely joined by a light bridging edge (shared common tool, public wordlist, shared legitimate cloud). The tell is the internal structure โ two internally-dense heavy-edge cores (the real operators) connected only by a thin seam of light edges (the false bridge) โ and the split cuts the light seam and keeps the heavy cores. The classic false bridge is the shared tool; the honeypot's largest clusters (libssh 1,313 IPs/84 countries; OpenSSH_7.4 757/78) are tool populations, not operators โ the over-clustered super-nodes the split resolves. Over-clustering is the register's WORSE error (a false merge over-attributes, crediting one hand with another's actions), so the register biases aggressively toward splitting: default to split any light-bridged cluster unless a heavy edge genuinely spans the whole of it. The split is bounded by the two-dense-cores structural test (it separates true seams without fragmenting a single operator who merely uses light tooling, since one operator is one core). It completes the merge/split symmetry (both governed by edge weight) and revises the record downward as honestly as the merge revises upward. The steelmanned objection (the split is a fragmentation machine) is answered by the two-core structural gate. No individual named. Classification: TLP:WHITE. Include everything โ the vectors do not lie, but a shared tool makes a false bridge; we cut it before it credits one operator with another's crimes.