Attribution to State and Non State Actors Engaging Cyber War Activities and Breaches of Cyber Security in Cyber Space
With the advancement of information and network technologies and the rising interconnectedness of the world, the threats connected to online communication have become increasingly pressing. Due to the global nature of such communication unrestricted by physical boundaries, network technologies challenge the prevailing international legal structure based on such notions as jurisdiction and sovereignty, where each sovereign jurisdiction legalizes communication that takes place in its territory. Online communication, that side steps geographical and jurisdictional restraints, is a grave concern for the national and international legal orders in their current form.
I. Introduction
Wars are fought within the context of their age with the weapons concluded by the prevalent technology of the age.3 Because of that concepts like electronic warfare, information warfare, network warfare, cyber war and cyber terrorism have been presented to explain the emerging area of conflict. There are several preconditions and elusive moments that decision-makers need to remember when it comes to the issue of the right identification of cyber attacks and the present article may shed some light on them.
The word cyber war deals the actions of a nation-state to pierce other nation's computers or networks for harm or disruption. It is believed that the world’s largest militaries are building cyber war fare programs, with several nation-states including the U.S., China, Russia, Israel, and Iran already considered to have joined the ranks of the cyber war-capable.4
Security is not only about being free from danger, as it is commonly conceived, but is associated with the presence of an adversary. The established goals of security in an information environment result from the notion of threat. Conventionally, there are three goals: Confidentiality, Integrity, Availability, sometimes called the “CIA triad.”5
There are countless preconditions and vague moments that decision-makers need to consider when it comes to the question of the correct attribution of cyber attacks and the present article may shed some light on them. A significant new study shows that “the attribution debate is evolving surprisingly slowly” with an excessive focus on technical forensics.6 Attribution requires a great deal of professional knowledge, strategic skills and operational leadership, and this requires a lot of time, commitment and investment to create.
II. Use of attribution in industry and practical world
Attribution of Cyber Security Breach is defined as a process to identify the location of an attacker on geographical area. The attribution even though deals with the original attackers but also deals with the identification of intermediary nodes that acts as bridge for original cybercriminals to conduct cybercrime. In sequence to combat high tech miscreants who would aim to violate our security, many argue that a universal strategy needs to be established. This strategy must involve the use of cyber attribution but at the same time, others are concerned that their right to privacy and other civil liberties will be compromised because of the government’s use of cyber attribution. If a participant participates in dangerous behavior, the applicable statute and the consequences of such behavior would depend on whether the participant is a physical person or, in fact, a government behind the citizen. Law enforcement eventually must decide the actual source of an attack. When they work with law enforcement, firms can help them develop and evaluate evidence.7
III. Issues faced by states and on state actors
A feasible cyber security framework shall target at the development of the adequate cyber security culture. It will also require national and international joint initiatives to create norms, methodologies, protocols and processes that align the policies of regulation, industry, education and technology to resolve cyber threats. In view of the inclusive and holistic existence of the desirable policy structure, the private sector would inevitably play an equally important role in the execution of the policy as the public sector does. In doing so, the policy on cyber protection and cybercrime is driven by the sufficient perception of the cyber-vulnerability challenge on the part of the policy makers. In this light, possibly the most important of all the issues relating to the establishment of a sustainable cyber security policy system is the topic formulated by Shane as “the current state of public ignorance and indifference to this problem, "which involves executive and legislative authority of different jurisdictions. Although Shane’s analysis concerned the United States, there is, however, no reason to believe that the situation is significantly different in the rest of the world.
While there are several regulatory proposals targeting data security in different countries, it is doubtful that the executive and legislative authority of the majority of governments will have a proper awareness of cyber security as a real policy issue. We can say that the governments see the matters of cyber security as insignificant. Instead, there are no viable and systematic strategies in place that will aim to raise the societal understanding of cyber threats and the capacity to handle those threats.8 To this end, some say that the most critical issue of cyber protection is to ensure that the private sector meets the standards of vital infrastructure safety in an appropriate fashion and to propose that law enforcement agencies take the initiative to establish a regulatory model. Others believe that the most important cyber security problem to be solved in the near term is ensuring a better flow of information between the private and public sectors and that the intellectual community has the essential expertise to lead the way.9
In some cases, the actions of non -state actors may be related to the state and may give rise to the international legal liability of the state. Every acts or omissions of organs of a state are habitually and necessarily attributable to state. The actions of non-state actors may also sometime be attributed to state.10 The legal issues neighboring cyber warfare are massive, especially when it comes to the frameworks that presently govern state-to-state warfare. It is still relevant to acknowledge the present in decisions in existing legislation and international conventions and to witness how this uncertainty affects the employment of non-state actors in state-sponsored cyber conflict. As a result, nation-states have little to no ability to help legal aid binding concept of cyber war that will curtail their freedom of action or officially claim responsibility for cyber-attacks carried out.
Furthermore, cyber attacks can be carried out cheaply and can, at least potentially, inflict significant harm or at least cause severe disturbances to ICT-based networks. Also, if a nation-state can furtively initiate, fund, or control such attacks, trusting on non-state actors to carry out the attacks in their stead, they can decrease the now low risk of political implications, and theoretically achieve their objectives without the burden of adhering to the Law of Armed Conflict. This provides the attacker a substantial asymmetrical advantage, particularly for smaller nations that cannot prevail on a kinetic battlefield.
Due to which, employment of non-state actors in cyberspace operations is likely to be quiet attractive option for nation-states or an equivalent body, particularly when pursuing limited strategic goals.11
Attribution of cyber-attack is very difficult due to anonymity feature of cybercrime. Cyber attackers have more professional hands and employ nearly modern methods every day to conceal the origins of cybercrime. Cyber criminals often alter the identity of the sender or forge the identity of the sender to connect with users as an authentic source or service provider called "Spoofing."12 Cyber criminals generally use “Reflector host” which are capable to convey forged massages to a large number of computers which are sufferers of cyber-attacks, frequently employed to hide the location of cybercriminal.13Another way to overcome the problem at individual level is the adopting monitoring system which will deliver surveillance. This approach would be contradictory to the U.S. First Amendment. The Constitution grants a person the freedom to talk anonymously.
Another problem of jurisdictional fragmentation follows from the fact that it does not and cannot agree with the global nature of cyberspace. Jurisdiction, implicitly related to the notion of State Sovereignty, imposes the sole duty of a sovereign State over its territories and/or its residents, and thereby prohibits the extra-judicial intervention of other Nations. The sovereign equality of states is safeguarded by rules of customary public international law. No state, can demand sovereignty over cyberspace and therefore introduce its effective regulation. As it is one thing to enact laws that regulate conduct whereas it is fairly another to assert jurisdiction over conduct that may originate anywhere in the world. Cyberspace is a separate phenomenon, outside which traditional rules are based on geographical location. Jurisdictional fragmentations sometimes become an obstacle when specific online conduct entails criminal responsibility.
According to Tallinn Manual, a state bears international accountability for a cyber-operation owing to it and that constitutes a breach of a global obligation. A State wounded by associate internationally wrongful act might resort to proportionate counter measures, as well as cyber counter live, against the accountable state. A cyber operation that creates a menace or use of force against the territorial integrity or political independence of any state, or in the other manner varying with the needs of the world organization, is unlawful.
There are rules for protection against armed attack conjointly. A State that's the target of a cyber-operation that rises to the extent of associate armed attack might exercise its inherent right of self-defense, whether a cyber-operation constitutes associate armed attack depends on its scale and effects, the correct of defense should be necessary and proportionate.14
Cyberspace lets participants conceal or disguise their identities during a method that's uphill within the universe. One individual with the access to the net is capable of such associate attack thanks to the probabilities of the network and knowledge technologies. These options appear to be, ‘incompatible’ with the important world territorial fragmentation. 15Hence, the attribution of cyber attacks clearly poses an excellent downside for call manufacturers. As, the net ensures that the namelessness of its users be unbroken intact. Whereas this could appear cheap and in concordance with the democratic virtues and laws, however, an issue arises that are we tend to planning to pay shortly or later for giving potential cyber terrorists and criminals the comfort shelter is known as namelessness. A world policy on cyber-attacks is required that may capture accurately the origin and culprit to be caterpillar-tracked down accurately. Smart phones and wearable’s build shoppers simply traceable and therefore, the advanced technology they use is assembling digital breadcrumbs on the far side what most would wish or recognize. The expansion of the net of Things and quality of business management systems can cause additional vulnerabilities in hardware systems. With few penalties if they're caught, nations still conduct online operations to steal data and gain advantage over their rivals, inflicting real economic impact.16
IV. Specific solution for above issues
Citizens World Health Organization wish to own net access in their property should attend the native police, register by providing personal info, and acquire a license. Most of the webs users in China gain access through the web cafés and these places square measure duty-bound to stay record or video tape all guests. Chinese police store and maintain a large info with all the knowledge concerning users’ identifications, IP addresses, email addresses, website subscriptions, net service suppliers, etc. net users have the sensation that each one of their online activity is being monitored.17
There square measure 2 basic technical ways for vital systems' protection — (i) defensive the system from the web risks whereas, the system stays online, and (ii) air gaping the system and also the general networks, that's a disconnection of such vital systems from the web entirely by the authorities. Such proposals have recently been popular some politicians in lightweight of the developments with the North American National Security Agency leaks. 18
A hint at what a potential answer would possibly seem like came in a very recent speech by Daniel Equus caballus, chief government of JPMorgan’s company and investment bank. “Each country includes a totally different commonplace however we've a worldwide drawback. After you attend purpose wherever you have got to own totally different standards in each place, you place yourself in a very vulnerable position,” Equus caballus same in a very speech. Countries could also be able to defend information in their jurisdictions. However, if corporations in a very specific country wish to try to do business with the globe, they need to require what they are given although it comes from corporations in another jurisdiction that had less tight security standards. 19
Also, one in all the challenges state face in the cyber setting is the scope, and manner of international law’s relevancy to cyber operations, whether in offense or defense, has remained unsettled since their advent. After all, at the time the present international legal norms emerged, cyber technology wasn't on the horizon. Consequently, there's a risk that cyber follow could quickly outstrip in agreement understanding auto It's governing legal regime. 20
As our world transitions additional product and services online, and that we successively depend upon them, protective this technological infrastructure has become an elementary building block for info systems globally. It should underpin every technology, each device, each application, and anyplace information is keep.21 Attribution is very important for rhetorical proof supporting Associate in Nursing arrest, for a government to a see if there was a casus belli and for a possible target to find out details of Associate in Nursing future attack or Associate in Nursing attack ongoing and return. 22
The community of states is clearly involved concerning this normative ambiguity. In 2011, the us set forth its position on the matter within International strategy for cyber area: ‘The development of norms for states conduct in cyber space doesn't need reinvention of customary law, nor will it render existing international norms obsolete. Tallinn Manual was launched within the hope of transferal some extent of clarity to the complicated legal problems encompassing cyber operations, with specific attention paid to those involving the jes ad bellum and also the jus in bello. The result's in, “Tallinn Manual.”23
On International level, cyber security thinks about with the applying of law to the realities of network and PC technologies, together with the likelihood of their use in fashionable warfare. The attribution of the conduct identifying the bad person between state or non-state actors and identification of the bad person jurisdiction square measure vital challenges. With of these challenges in hand, the effective legal regulation of the web presumes creation of the viable policy which will adequately address the substance of the matter and its technical complexness on various levels, together with legislative interventions within the variety of lawmaking and harmonization; international cooperation; collaboration with the non-public sector; skilled instructional and capability building regarding technical support and help, particularly within the developing countries.24There square measure two main challenges that the worldwide connection, and its individual options gift for the legal systems tailored to control the ‘real world’ behavior.
V. Conclusion
Although Net conflicts square measure predominately a non-state activity, they're drawing the eye of this World Health Organization would like to leverage them to push their functions. In most cases, as we've seen, cyber actions involve varied non-state actors. However, the overlapping gray-zone between these actor classes and bona fide state-backed cyber warriors square measure a supply of concern since no legal definition of cyber warfare, or agreement on what constitutes Associate in Nursing, “act or war” in Net, presently exists. The covert or obvious employment of non-state actors in Net operations, as volunteers in state-to-state conflicts, cyber-mercenaries or organized cyber-criminals raise several new queries, and is a stimulating trend that deserves additional study. Though there haven't nevertheless been any concrete instances wherever cyber actions, or cyber attack, have resulted in physical injury or extended destruction of property, the serious cyber-dependency of contemporary western country make additional damaging cyber attack plausible or perhaps probable in future eventualities. Within the different corner, the worldwide defense business is probably going choosing up the scent of serious military defrayment returning their approach. This makes for a stimulating, if maybe somewhat uncomfortable development within the returning years, wherever one may most likely solely hope for a balanced and wise approach from all concerned actors.
*****
Footnotes
- Author is a student at University of Petroleum and Energy Studies, India.
- Author is a student at University of Petroleum and Energy Studies, India.
- MEHAN, Cyber war, Cyber terror, Cybercrime: A Guide to the Role of Standards in an Environment of Change and Danger 21. 2008. ↩
- Artur Appazov, Legal aspects of Cybersecurity,2014. ↩
- P.W. SINGER and ALLAN FRIEDMAN, Cyber security and cyber war. ↩
- Rid T Buchanan B. Attributing cyber-attacks. J Strat Stud 2015; 38: 4 – 37. ↩
- http://blog.trendmicro.com/what-are-the-benefits-of-attribution. ↩
- Artur Appazov, Legal aspects of Cybersecurity,2014. ↩
- Artur Appazov, Legal aspects of Cybersecurity,2014. ↩
- Tallinn Manual. ↩
- Johan Sigholm, Captain, Ph.D. student, Swedish National Defence College ↩
- Rajesh Kumar Goutam, The problem of Attribution in cyber security, december7 ↩
- David A. Wheeler, Gregory N. Larsen and Task Leader, “Techniques for Cyber Attack Attribution”, Institute for Defense Analysis, October 2003. ↩
- International Group of Experts at invitation of the NATO Cooperative Cyber Defence Centre of Excellence. (Tallinn Manual on the international law applicable to cyber warfare). ↩
- Artur Appazov, Legal aspects of Cybersecurity,2014. ↩
- Artur Appazov, Legal aspects of Cybersecurity,2014. ↩
- Rotenberg, M. (2010). ↩
- Artur Appazov, Legal aspects of Cybersecurity,2014. ↩
- https://www.infosecurity-magazine.com/opinions/problem-cybersecurity-regulations. ↩
- Tallinn Manual. ↩
- https://www.acs.org.au/content/dam/acs/acs-publications/ACS_Cybersecurity_Guide.pdf. ↩
- http://blog.trendmicro.com/what-are-the-benefits-of-attribution/ ↩
- Tallinn Manual on the international law applicable to cyber warfare. ↩
- Artur Appazov, Legal aspects of Cybersecurity,2014. ↩
