Reflections on the Opportunity of an International Attribution and Accountability Mechanism for Cyber Operations

image_pdfimage_print

1. Introduction

The Secretary-General of the United Nations recently recommended ‘[e]stablish[ing] an independent multilateral accountability mechanism for malicious use of cyberspace by States to reduce incentives for such conduct’.[1] This is the latest illustration of the repeated questioning and advocacy for the establishment of an international mechanism on cyber operations and international security to address the issues of attribution, responsibility of wrongdoing States and more broadly accountability of different actors, in particular with respect to norms of responsible behaviour.[2] Various proposals have been put forward over the years,[3] but the basic idea remains the same: the creation of an international mechanism – either multilateral, multi-stakeholder, or exclusively involving non-state actors – aimed at conducting investigations into specific cyber incidents – focusing only on alleged state-sponsored cases or taking a broader approach – and identifying the involved actors. Some proposals suggest that the mechanism, once it has identified the wrongdoing actors, should be able to refer the cases to the United Nations Security Council (UNSC) or the International Court of Justice (ICJ), or should be able to impose consequences directly on the wrongdoing actors.
I had the honour to be invited together with Nicholas Tsagourias by Questions of International Law to participate in this Zoom-in dialogue on the question of an international mechanism on the attribution of cyber operations. In this dialogue, he focused on the arguments against such a mechanism, while I took the opposite view. This is an interesting exercise for me, as I am generally skeptical on the naïve and general idea that we should create a ‘cyber international court’; however, I am generally optimistic on the possibility to advance further the implementation of international law in cyberspace, including through specific multilateral and multi-stakeholder processes. For this reason, I have focused my reflections on the possible forms of such a mechanism and what it could achieve.
There are different factors that can explain the interest in an international mechanism on cyber operations and international security. Unlike other forms of state-sponsored unlawful or unfriendly acts such as the violation of another State’s airspace by a military aircraft, cyber operations take place every day and in every corner of the world, including between allies and close partners. In cyberspace, activities that violate the rights of other States are very common, they take different forms and have a wide range of consequences. Moreover, cyber operations conducted by one State against another can have significant consequences for the economy of the targeted State and other States. I argue that the speed of development of cyber capabilities, the diversity of forms and effects of cyber operations, and their commonality and perception of risk are the factors that foster the specific objective of advancing attribution and accountability in cyberspace. Together with a clearer understanding of the interpretation of the rules of international law in cyberspace,[4] the development of an international attribution mechanism is sometimes considered necessary to achieve such an objective.
However, despite this specific objective, identifying the perpetrating or sponsoring State and the actors acting on its behalf is sometimes difficult; this observation could explain the particular interest in capacity-building and information sharing for the purpose of attribution. In addition, it is usually difficult for the victim to hold the wrongdoing State accountable, to obtain the cessation of cyber operations and the reparation of their consequence. This last observation could be the reason for the particular interest in collective and coordinated action, such as coordinated campaigns of public attribution of cyber operations and the introduction of dedicated sanction mechanisms.
This article aims to assess the merits of a potential international attribution and accountability mechanism and to offer some reflections on the possible forms and functions of such a mechanism. After this Introduction, section 2 analyses existing mechanisms and cooperations relevant to the attribution of cyber operations. Section 3 analyses the various proposals that have been made for the creation of such a mechanism. Sections 4 and 5 reflect on the possible objectives and main features of a possible international mechanism for attribution and accountability.

2Relevant existing mechanisms and institutions

Cyber operations do not take place in a vacuum, and the existing rules of international law are applicable to them.[5] Indeed, there is nothing pre-
venting the existing rules from applying to these activities.[6] Moreover, there is no specificity attached to cyber operations that would prevent the UNSC, the ICJ, or other international mechanisms from dealing with such threats to international peace and security. There is also no reason for the cyber-related damage to be excluded from the Register of Damage Caused by the Aggression of the Russian Federation against Ukraine established by the Council of Europe.[7] There are, however, other reasons that may explain why international institutions may not be able to deal with certain situations, such as the use of veto power by permanent members of the UNSC, which we will not discuss in this article. With the goal of advancing the attribution and accountability for cyber operations in mind, it is important to identify the specific mechanisms and practices in place.
Regarding the technical dimension of attribution, cyber incident investigations are generally conducted at the victim organization level, in particular by Computer Security Incident Response Teams (CSIRTs), and by national cybersecurity and law enforcement agencies. However, it is important to note that there is important cooperation between law enforcement agencies, either bilaterally or through Interpol or Europol. In addition, the Forum of Incident Response and Security Teams (FIRST) has been facilitating cooperation between these actors since 1990. At the European level, the European Union Agency for Cybersecurity (ENISA) coordinates cooperation among the information security authorities of the EU Member States. Institutions such as Interpol, Europol, ENISA or FIRST do not publicly attribute cyber operations to States, but they contribute to the exchange of information between different actors involved in the attribution of cyber operations.
The legal and political dimension of attribution generally falls within the competence of States. Some States, in particular the Five Eyes,[8] regularly publicly attribute cyber operations to other States and actors, including through coordinated and joint attribution campaigns.[9] The practice of public attribution by the United States, for example, takes generally one or more of four forms: ‘(1) criminal indictments; (2) economic sanctions; (3) technical alerts; and (4) official statements or press releases’.[10] Despite some abstract references to ‘international law’ and the ‘international rules-based order’, international law is generally absent from this practice,[11] and no explicit reference to the rules violated is made in the declarations of the attributing States.[12] Moreover, in case of coordinated attribution campaigns, a great diversity in the content of the declarations can be observed. This last observation emphasizes the need for greater cooperation, which is one of the key elements of the proposals developed in this article. Interestingly, it can also be observed that non-state actors – for example, non-governmental organizations (NGOs) such as Citizen Lab[13] and private companies such as Mandiant[14] and Microsoft[15] – also publicly attribute cyber operations to States and other actors.[16] States have also developed specific sanction regimes in relation to cyber operations. The European Union and its member States, for instance, have developed a collective diplomatic response to malicious cyber activities and sanction mechanism called the EU Cyber Diplomatic Toolbox.[17]
There are two other examples that are relevant to this article. Firstly, the Tallinn Mechanism for the coordination of civilian cyber assistance to Ukraine launched by ten States[18] in December 2023.[19] The Tallinn Mechanism focuses on crisis management in relation to the cyber operations targeting Ukraine and may thus be related, to some extent, to the investigation and attribution of cyber operations even if it is not its objective. Secondly, the CyberPeace Institute, an NGO created in 2019 and funded by the William & Flora Hewlett Foundation, Mastercard, Microsoft, and the Ford Foundation.[20] The CyberPeace Institute primarily analyses cyber operations, from the technical perspective and in assessing whether international law or norms of responsible behaviour have been violated. It also supports other NGOs and actors. One of their initiatives is a database that collects information on cyber operations related to the war in Ukraine, and provides an assessment of their attribution and whether they have violated international law and norms of responsible behaviour.

3 Navigating the different proposals

The idea of an international mechanism on cyber operations and international security is not new and is a recurring theme in the literature and in policy debates. In this section, I present the main proposals and highlight their main merits and shortcomings.
In 2014, the publication resulting from a NATO Advanced Research Workshop on Confidence-Building Measures in Cyberspace convened by the Atlantic Council and Swedish National Defense College proposed, among other confidence-building measures, the idea of creating a ‘[t]he Multilateral Cyber Attribution and Adjudication Council (MCAAC)’.[21] This proposal combines the two dimensions mentioned in the introduction, namely the attribution of cyber operations, on the one hand, and the questions of responsibility and accountability, on the other hand. The authors further the idea that the MCAAC could determine the ‘damage to be paid to the plaintiff by the defendant as compensation’.[22] The MCAAC would have no enforcement dimension and would refer the cases, alongside its recommendations and evidence, to the UNSC, the ICJ, or regional security bodies. On that point, the authors noted that ‘[t]hus, the MCAAC could become a specialized advisory agency for cyber violations of international law that formalizes and institutionalizes cyber attribution and adjudication’.[23]
A few years later, alongside to the idea of a Digital Geneva Convention,[24] Microsoft also proposed the creation of an ‘attribution organization’.[25] Microsoft’s proposal focused on both on attribution and the assessment of compliance with the rules of international law and non-binding norms of responsible behaviour in cyberspace.[26] In addition, Microsoft sponsored a research project conducted by the RAND Corporation to ‘assess the potential merits and challenges of an organization for performing cyber attribution, and to explore construction of such an organization’.[27] The result was a proposal for a ‘Global Cyber Attribution Consortium’ that would have a formal selection process for cases to be investigated, collect and assess evidence, develop specific standards and methodologies, and attribute and communicate with the relevant parties and through the publication of reports. Similar to the MCAAC, the Global Cyber Attribution Consortium could refer the case to the ICJ or the UNSC for further action.[28] Both the Microsoft and RAND proposals recommend that the mechanism be established as a non-governmental organization, with very limited participation by States, and composed of independent technical, policy, and legal experts. However, both mechanisms would generally focus on severe cyber operations sponsored by States.
In 2018, Serge Droz and Daniel Stauffacher wrote a report for the ICT4Peace Foundation, in which they argue in favour of a ‘Global Cyber Attribution Network’.[29] Although this proposal is based on similar considerations, it differs from the previous ones in that it does not aim to create a new institution, but to develop a network of actors involved in attribution – State representatives, private companies, civil society and academia – for the purpose of peer-review of attributions.[30] It should be emphasized, however, that while the report also mentions international law and policy matters, the proposed network focuses primarily on the technical dimension of attribution.
More recently, in an article published in International Law Studies in 2020, Michael N Schmitt and Yuval Shany commented on the earlier proposals and set out their own perspective.[31] In general, their proposal aims to support States with more limited capacities, in particular by providing them with independent access to better intelligence and investigation capacities, as well as to further accountability, especially in conjunction with existing sanction regimes.[32]
To summarize, most of the proposals have some common features. The main objective of the proposed mechanisms is generally the investigation of state-sponsored cyber operations, notably to collect and assess evidence. In other words, they focus primarily on the technical dimension of attribution. The ability of such a mechanism to conduct investigations and collect evidence is central in most proposals. As regards to the legal form and functioning of the mechanism, most proposals favour a mechanism that would be independent from States, for instance taking the form of a non-governmental organization with limited or no involvement of States. These proposals have not been implemented, apart from the creation of the CyberPeace Institute which is partly based on the Microsoft and RAND proposals.

4 The possible objectives of an international attribution and accountability mechanism

In the previous two sections, I have presented the various proposals for an international attribution and accountability mechanism as well as the existing relevant mechanisms and institutions. For me, however, the central question is what the objectives of such a mechanism could or should be. For an article that argues in favour of an international mechanism, the reader may find this section surprisingly critical. However, the aim is indeed to take a critical stance in order to exclude issues for which an international mechanism would not be appropriate and to identify those for which it would be relevant. Nicholas Tsagourias raises a number of criticisms against a possible international attribution mechanism, which are commented in this section.[33] I share most of his criticisms, but we generally disagree on the way forward. In this section, we will break down the different dimensions of attribution, looking at the technical, legal, and political dimensions in turn.
Identifying the perpetrators of a cyber operation involves investigating and collecting evidence.[34] I agree with Nicholas Tsagourias that the way cyberspace works makes it unlikely that States would accept an international investigation. It would imply that the victim State, and possibly also the accused State, would allow external investigators access to their computer networks and thus gain knowledge about their functioning and security. Based on this observation, the question arises as to whether it makes sense to create an international mechanism or whether it would be better to strengthen existing cooperations. I think the second option makes more sense. The first response to cyber incidents and crisis management are usually handled at the level of the victim organization and coordinated at the domestic level. As already mentioned, there are some forms of international cooperation and coordination in place, in particular through FIRST. Most proposals for an international mechanism focus on the issue of the cyber incident investigation and evidence collection. These proposals notably draw from the verification mechanisms in place within international organizations such as the International Atomic Energy Agency (IAEA) and the Organisation for the Prohibition of Chemical Weapons (OPCW), as well as existing examples of fact-finding missions. In general, verification mechanisms and investigations result from the existence of a specific treaty, an agreement between the parties on a specific dispute, or at the request of the UNSC on a specific situation. In addition, these investigations rely usually on reports and investigations by States and other actors and assess the evidence and information provided, which may differ from the objective contemplated with an international attribution mechanism. Building on these observations, I believe that an international mechanism conducting investigation is not an appropriate option. Conversely, I believe that cooperation between first responders, including private cybersecurity companies, law enforcement agencies, and other actors involved in the technical dimension of attribution as well as the review of evidence could be significantly improved by the creation of an international mechanism.[35]
The standard of evidence has become an important issue in the context of cyber operations,[36] as some States have developed a practice of public attribution. In this context, the United Nations Group of Governmental Experts (UNGGE) noted in its report that ‘the accusations of organizing and implementing wrongful acts brought against States should be substantiated’.[37] The standard of evidence to be used depends on the institution in question, in particular the dispute settlement mechanisms involved. However, I believe that an international mechanism operating at a pre-dispute phase could also provide some guidance on the definition of evidence, particularly in terms of setting certain standards on the collection and presentation of evidence. I assert that this can be an important contribution of an international mechanism.
The international legal dimension of attribution aims to determine whether a cyber operation can be attributed to a State. The Articles on Responsibility of States for Internationally Wrongful Acts adopted by the International Law Commission (ILC) in 2001 codify the norms of customary international law on State responsibility, including on the question of attribution of conduct.[38] I have analysed these rules and their application to cyber operations in detail elsewhere[39] and have concluded that the different types of situations arising from the conduct or sponsorship of cyber operations by a State are covered by the different norms of international law. I assert that the difficulty to attribute does not result from a non-liquet,[40] meaning that international law would not be able to provide a definitive legal characterization and answer to a specific situation, but from factors that are not related to the content of the norms. It is other factors, such as the availability of evidence, that generally make attribution more difficult.
One of the contentious issues is the threshold of control required to attribute the behaviour of a non-state actor to a State, either as a de facto organ or a non-state actor controlled and directed by the State. On this issue, the ICJ, the International Criminal Tribunal for the former Yugoslavia (ICTY) and the ILC have adopted different positions, which I will not detail here.[41] I observed that cyberspace provides at the same time an easy way for States to incentivize non-state actors, either individuals or groups, to act against another State, and to provide them with the necessary tools to act. This might be particularly true for a large-scale campaign of distributed denial-of-service (DDoS) attacks, such as the one against Estonia in 2007.[42] In such a situation, the level of control necessary for the State to incentivize the non-state actors is low and thus might be below the different thresholds identified by the ICJ, the ICTY, and the ILC. However, lowering the threshold of control may lead to over-attribution or misattribution to States, and thus be counterproductive. Building on these observations, I have argued that this may be one of the issues on which the rules of international law may evolve in the future due to the shift to cyberspace.[43] However, this challenge could not really be addressed by the creation of an international mechanism for cyber attribution per se, mainly because it is a general issue of international law that concerns the rules of international law themselves, and not only their interpretation and application in relation to cyber operations.
The political dimension of attribution is a sovereign prerogative of States, on this point I agree with Nicholas Tsagourias. I believe that the political dimension of attribution is unlikely to be transferred to an international mechanism, and my proposal focuses on assisting States in developing their practice. As previously emphasized, international law is generally absent from the current practice of public attribution. In other words, States accuse other States of conducting cyber operations, but in their statements they do not specify the legal basis of the attribution, the rules that have been violated, or the legal basis of an eventual response. Similar observations can be made on State practice outside of cyberspace. In cyberspace, however, this observation is to be put in perspective with the practice of interpretative statements on the application of international law, the call for the substantiation of attribution, and for the development of accountability. In this context, an international mechanism could support the political dimension of attribution by providing the necessary support for States to coordinate their practice, to exchange good practice and information, for instance through the development of standards of evidence collection.
Accountability is an important issue for international law in general, and even more so in relation to cyber operations. The accountability crisis is a broader issue that is not limited to cyber activities.[44] Existing mechanisms and institutions, such as the UNSC and the ICJ, are often criticized for their failure in ensuring compliance with international law and the management of crises. The creation of a specific mechanism dealing with cyber operations might thus have a limited interest, as the issue is not coming from the shift to cyberspace, but rather from the current state of international law.
In the case of cyber operations in particular, it can generally be observed that the responsible State often escapes consequences. Some States have developed a practice of collective and coordinated attribution campaigns, with the objective to increase the pressure on the wrongdoing State.[45] The same rationale, together with other considerations, explains the current push by some States for collective countermeasures in cyberspace.[46] By acting collectively, States expect to impose more consequences on the wrongdoing State and thus to limit its ability to evade accountability. This is also the reason for the development of coordinated sanction regimes. I assert that the same logic could justify the creation of an international mechanism, not to conduct political attribution but to support States in developing cooperation and synergies in this respect. Another advantage would be to assist in the contestation of public attributions. Not in being itself the forum for such a contestation, which can be done unilaterally by the concerned State or within existing fora, but by providing specific guidance on the various elements of attribution.

5 A possible international attribution and accountability mechanism for state-sponsored cyber operations

The aim of this section is to describe the main features of a possible international attribution and accountability mechanism for state-sponsored cyber operations. Nicholas Tsagourias is of the view that an international mechanism, should it be established, will focus on technical attribution. I do not share this view and have explained already why I believe that the technical dimension of attribution could be further coordinated without being transferred to an international mechanism. The proposal I am developing focuses on the issue of evidence and accountability. However, it is important to point out that my proposal is not a dispute settlement mechanism and would most likely operate in the pre-dispute phase.
Building on the observations made in the previous sections, I believe that an international mechanism could be developed to assist States in the investigation and attribution of cyber operations. This mechanism would be relevant in the pre-dispute phase, when the victim State conducts the investigation, collects and assesses the evidence, and evaluates the possible next steps. With regard to existing organizations, I believe that the proposed mechanism could, to a limited extent, play a similar role to the Permanent Court of Arbitration outside its adjudication functions. Indeed, the objective is not to create a dispute settlement mechanism. The main function of the mechanism would be to assist States in developing their approach to and practice of attribution and accountability, by providing them with possible standards for the collection and presentation of evidence that States could voluntarily follow, as well as lists of experts.
Such an international mechanism could be created as an international organization that is also open to other actors, for instance first responders such as CSIRTs, non-governmental organizations, and private cybersecurity companies. There are already international organizations with members that are non-state actors, for instance the World Tourism Organization and the International Telecommunication Union. However, the question will be what role they should play in the governance of the organization and the decision-making processes. This is an important difference from previous proposals, which advocated for a non-governmental organization with a limited role for States. Since the aim is to focus on the behaviour of States and to uphold international law, it is crucial to have States on board if we want them to accept the mechanism and to follow its recommendations.
A key objective of the mechanism would be to establish standards of evidence and promote compliance with international law and norms of responsible behaviour. The mechanism could assess existing evidentiary standards for attribution of cyber operations used in different contexts and propose rules and standards specifically tailored for the international context. The proposed standards would not be legally binding, and it would be up to the States to follow and acknowledge them in their practice. Furthermore, these standards could serve as a basis for fact-finding missions, as well as dispute settlement mechanisms at a later stage. On this point, Nicholas Tsagourias believes that my proposal would be relevant when an actual dispute occurs, whereas I believe that it would be relevant at a pre-dispute stage to help States characterize the situation and decide whether a dispute might exist and what the next steps might be. States and other actors could also be invited to report regularly on how they apply these standards in their practice. This reporting and its assessment could become an important dimension of the work of such a mechanism, with the aim of contributing to the further development and improvement of the standards.
A second important dimension of such a mechanism would be to contribute to capacity-building pursuing two directions. Firstly, in maintaining different lists of technical, legal and policy experts at the disposal of States and other actors. As highlighted in most proposals, States have different capacities, and States with lesser capacities may have more difficulties to attribute. However, rather than proposing a centralized mechanism that may have difficulty responding to very different situations, I suggest a mechanism that helps to connect the relevant experts with the States requesting assistance. In addition, more advanced States could financially support other States to cover the costs of engaging these experts. Secondly, this mechanism could organize training and other exercises aimed at developing the capacity of States and other actors, particularly on the basis of the expert lists and reporting activities. There are already various States and international organizations conducting such activities, and the question would be how synergies could be developed.
One might ask why States and other actors should be interested in such a mechanism. As noted previously, the UNGGE called for the substantiation of attribution[47] while the question of accountability is at the centre of the current debate on State behaviours in cyberspace. Such a mechanism would provide a voluntary basis to advance these questions, in particular in supporting the development of State practice on attribution, including on contestation in case of misattribution. In this context, such a mechanism could also contribute to the development of the framework of responsible State behaviour in cyberspace which is at the heart of the work of the United Nations Open-Ended Working Group and the future Programme of Action.

6 Conclusions

The international attribution and accountability mechanism proposed in this article differs from previous proposals in that it does not seek to investigate or attribute cyber operations, but rather to support States that engage in such a practice. It is also important to note that it is not a dispute settlement mechanism. The objective is for States to benefit from appropriate assistance, in the form of expertise, evidentiary standards, best practices, and capacity-building.

* Assistant Professor of International Law, IE University (francois.delerue@ie.edu). I am thankful to Professor Nicholas Tsagourias for engaging with me in this discussion, as well as to Professor Emanuele Cimiotta and the anonymous reviewer for their valuable suggestions and comments.
[1] United Nations, ‘Our Common Agenda Policy Brief 9: A New Agenda for Peace’ (July 2023) 27 ˂https://www.un.org/sites/un2.un.org/files/our-common-agenda-policy-brief-new-agenda-for-peace-en.pdf˃.
[2] On norms of responsible behaviour in cyberspace, see M Lehto, ‘The Rise of Cyber Norms’ in R Buchan, N Tsagourias (eds), Research Handbook on International Law and Cyberspace (Elgar 2021) 32-45; B Hogeveen, ‘The UN Cyber Norms: How Do They Guide the Responsible Development and Use of Offensive Cyber Capabilities?’ (2022) 7 The Cyber Defense Review 123, 123-142.
[3] The main proposals are presented in Section 3. See, also, the analysis in B Kuerbis, F Badiei, K Grindal, M Mueller, ‘Understanding Transnational Cyber Attribution: Moving from “Whodunit” to Who Did It’ in MD Cavelty, A Wenger (eds), Cyber Security Politics: Socio-Technological Transformations and Political Fragmentation (Routledge 2022) 230-232.
[4] To date (July 2024), thirty-two States and the African Union have publicly issued detailed statements on their approach to the rules and principles of international law applicable to cyberspace. See, generally, the updated list of national positions on the website of the ‘International Cyber Law in Practice: Interactive Toolkit’ project ˂https://cyberlaw.ccdcoe.org/wiki/List_of_articles#National_positions˃.
[5] On the application of international law to cyber operations, see generally, HH Dinniss, Cyber Warfare and the Laws of War (CUP 2012); G Kerschischnig, Cyberthreats and International Law (Eleven International Publishing 2012); M Roscini, Cyber Operations and the Use of Force in International Law (OUP 2014); Y Radziwill, Cyber-Attacks and the Exploitable Imperfection of International Law (Brill/Martinus Nijhoff Publishers 2015); MN Schmitt, L Vihul (eds), The Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations (2nd edn, CUP 2017); H Lahmann, Unilateral Remedies to Cyber Operations: Self-Defence, Countermeasures, Necessity, and the Question of Attribution (CUP 2020); D Akande, A Coco, TS Diaz, ‘Drawing the Cyber Baseline: The Applicability of Existing International Law to the Governance of Information and Communication Technologies’ (2022) 99 Intl Law Studies 4, 4-36; F Delerue, A Géry, A-T Norodom (eds), Digital Challenges for International Law (ILA 2023). Members of the ILA steering committee as of 2023: E Benvenisti, N Bhuta, D Hollis, Z Huang, N Ifeanyi-Ajufo, E Ivanov, J Kulesza, C Strydom, J Tridgell, R Young.
[6] F Delerue, Cyber Operations and International Law (CUP 2020) 1-50.
[7] Council of Europe, ‘Resolution CM/Res (2023)3 establishing the Enlarged Partial Agreement on the Register of Damage Caused by the Aggression of the Russian Federation against Ukraine’ (12 May 2023) adopted by the Committee of Ministers at the 1466th meeting of the Ministers’ Deputies.
[8] Australia, Canada, New Zealand, United Kingdom, and the United States.
[9] A Paulus, C Rupp, ‘Official Public Political Attribution of Cyber Operations: State of Play and Policy Options’ (12 October 2023) Stiftung Neue Verantwortung ˂https://www.interface-eu.org/publications/official-public-political-attribution-of-cyber-operations˃; FJ Egloff, M Smeets, ‘Publicly Attributing Cyber Attacks: A Framework’ (2023) 46 Journal of Strategic Studies 502, 502-533; Kuerbis and others (n 3) 221-230; M Finnemore, DB Hollis, ‘Beyond Naming and Shaming: Accusations and International Law in Cybersecurity’ (2020) 31 European J Intl L 969, 969-1003; T Rid, B Buchanan, ‘Attributing Cyber Attacks’ (2015) 38 Journal of Strategic Studies 4, 4-37; D Broeders, E Busser, P Pawlak, ‘Three Tales of Attribution in Cyberspace: Criminal Law, International Law and Policy Debates’ (April 2020) The Hague Program for Cyber Norms ˂https://www.thehaguecybernorms.nl/research-and-publication-posts/three-tales-of-attribution-in-cyberspace-criminal-law-international-law-and-policy-debates˃.
[10] KE Eichensehr, ‘The Law and Politics of Cyberattack Attribution’ (2020) 67 UCLA Law Review 520-598, 532.
[11] Finnemore and Hollis (n 9) 997-1000.
[12] F Delerue, ‘Is International Law Fading Away in State Practice on Cyber Operations?’ in F Cristiano, B van den Berg (eds), Hybridity, Conflict, and the Global Politics of Cybersecurity (Rowman & Littlefield 2023) 31-52.
[13] M Kenyon, ‘Citizen Lab Response to the UN Working Group on the Use of Mercenaries’ (18 February 2021) Citizen Lab, University of Toronto <https://citizenlab.ca/2021/02/citizen-lab-response-to-the-u-n-working-group-on-the-use-of-mercenaries/>.
[14] Mandiant, ‘APT1 Exposing One of China’s Cyber Espionage Units’ (30 December 2021) ˂https://www.mandiant.com/resources/reports/apt1-exposing-one-chinas-cyber-espionage-units˃
[15] Microsoft Threat Intelligence, ‘Microsoft Investigates Iranian Attacks against the Albanian Government’ (8 September 2022) Microsoft Security ˂https://www.microsoft.com/en-us/security/blog/2022/09/08/microsoft-investigates-iranian-attacks-against-the-albanian-government/˃.
[16] Eichensehr (n 10) 547-551.
[17] European Union, ‘Council Conclusions on a Framework for a Joint EU Diplomatic Response to Malicious Cyber Activities (“Cyber Diplomacy Toolbox”)’ doc 10474/17 (19 June 2017); European Union, ‘Council Conclusions on exploring the potential of the Joint Cyber Unit initiative – complementing the EU Coordinated Response to Large-Scale Cybersecurity Incidents and Crises’ doc 13048/21 (19 October 2021); European Union, ‘Council conclusions on the development of the European Union’s cyber posture’ doc 9364/22 (23 May 2022).
[18] Canada, Denmark, Estonia, France, Germany, the Netherlands, Poland, Sweden, the United Kingdom and the United States.
[19] Estonia, Ministry of Foreign Affairs, ‘Tallinn Mechanism, Mission Statement’ (30 May 2023) ˂https://vm.ee/sites/default/files/documents/2023-12/Mission%20Statement%20-%20Scope.pdf˃.
[20] CyberPeace Institute, ˂https://cyberpeaceinstitute.org/who-we-are/˃.
[21] J Healey, JC Mallery, KT Jordan, NV Youd, ‘Confidence-Building Measures in Cyberspace: A Multistakeholder Approach for Stability and Security’ Atlantic Council of the United States/Swedish National Defense College (November 2014) ˂https://www.files.ethz.ch/isn/185487/Confidence-Building_Measures_in_Cyberspace.pdf˃ 10-12.
[22] ibid 11.
[23] ibid.
[24] B Smith, ‘The Need for a Digital Geneva Convention’ (14 February 2017) Microsoft <https://blogs.microsoft.com/on-the-issues/2017/02/14/need-digital-geneva-convention/>.
[25] Microsoft, ‘An Attribution Organization to Strengthen Trust Online: Policy Paper’ (2017) <https://www.microsoft.com/en-us/cybersecurity/content-hub/an-attribution-organization-to-strengthen-trust-online>.
[26] S Charney and others, ‘From Articulation to Implementation: Enabling Progress on Cybersecurity Norms’ (2016) Microsoft 9-12 <https://www.microsoft.com/en-us/cybersecurity/content-hub/enabling-progress-on-cybersecurity-norms>.
[27] JS Davis and others, ‘Stateless Attribution: Toward International Accountability in Cyberspace’ (2017) RAND 6 <https://www.rand.org/pubs/research_reports/RR2081.html>.
[28] ibid 35-41.
[29] S Droz, D Stauffacher, ‘Trust and Attribution in Cyberspace: A Proposal for an Independent Network of Organisations Engaging in Attribution Peer-Review’ (2018) ICT4Peace Foundation ˂https://ict4peace.org/wp-content/uploads/2019/07/ICT4Peace-2019-Trust-and-Attribution-in-Cyberspace.pdf˃.
[30] ibid 8; this proposal builds on a proposal made by Ron Deibert at the RightsCon conference for a global network of researchers from universities on attribution of state-sponsored cyber operations, see H Solomon, ‘RightsCon Report: Universities Should Form Cyber Attribution Network’ (18 May 2018) IT World Canada News <https://www.itworldcanada.com/article/rightscon-report-universities-should-form-cyber-attribution-network/405399>. See, also, on the possible role of academia FJ Egloff, ‘Contested Public Attributions of Cyber Incidents and the Role of Academia’ (2020) 41 Contemporary Security Policy 55, 55-81.
[31] MN Schmitt, Y Shany, ‘An International Attribution Mechanism for Hostile Cyber Operations?’ (2020) 96 Intl Law Studies 196, 196-222.
[32] ibid 219-221.
[33] See N Tsagourias, ‘Cyber Attribution Agencies: A Sceptical View’ in this Zoom in, infra 23-38.
[34] N Tsagourias, M Farrell, ‘Cyber Attribution: Technical and Legal Approaches and Challenges’ (2020) 31 European J Intl L 941, 945, 955-959.
[35] For a similar view, see Droz and Stauffacher (n 29).
[36] M Roscini, ‘Digital Evidence as a Means of Proof before the International Court of Justice’ (2016) 21 Journal of Conflict & Security Law 541, 541-554.
[37] UNGA, ‘Report of the Group of Governmental Experts on Developments in the Field of Information and Telecommunications in the Context of International Security’ UN Doc A/70/174 (22 July 2015) 28(f).
[38] International Law Commission, ‘Report of the International Law Commission on the Work of Its Fifty-third Session’ (23 April-1 June and 2 July-10 August 2001) UN Doc A/56/10 (2001) II/2 YB ILC.
[39] Delerue (n 6) 111-191. See also Tsagourias and Farrell (n 34) 951-955; K Mačák, ‘Decoding Article 8 of the International Law Commission’s Articles on State Responsibility: Attribution of Cyber Operations by Non-State Actors’ (2016) 21 Journal of Conflict & Security Law 405, 405-428.
[40] A non liquet would not result from the lack of evidence or the impossibility to identify the perpetrator but from the impossibility to apply or find an answer in the rules and principles of international law on the attribution of behaviours to States. On non liquet, see generally D Bodansky, ‘Non Liquet’ in R Wolfrum (ed), Max Planck Encyclopaedia of Public International Law (OUP 2008).
[41] See, generally, O De Frouville, ‘Attribution of Conduct to the State: Private Individuals’ in J Crawford, A Pellet, S Olleson (eds), The Law of International Responsibility (OUP 2010) 257-280; P Palchetti, L’organo di fatto dello Stato nell’illecito internazionale (Giuffrè 2007); A Cassese, ‘The Nicaragua and Tadić Tests Revisited in Light of the ICJ Judgment on Genocide in Bosnia’ (2007) 18 European J Intl L 649-668. See also Delerue (n 6) 118-122, 130-144.
[42] Delerue (n 6) 146-149.
[43] ibid 185-186. See also the discussion in Tsagourias and Farrell (n 34) 961-965.
[44] See, generally, S Besson (ed), Theories of International Responsibility Law (CUP 2022) 7-8.
[45] Finnemore and Hollis (n 9) 1001.
[46] See, generally, M Jackson, FI Paddeu, ‘The Countermeasures of Others: When Can States Collaborate in the Taking of Countermeasures?’ (2024) 118 American J Intl L 231, 259-267; T Dias, ‘Countermeasures in International Law and Their Role in Cyberspace’ (23 May 2024) Chatham House 33-55 ˂https://www.chathamhouse.org/2024/05/countermeasures-international-law-and-their-role-cyberspace˃.
[47] UN Doc A/70/174 (n 37) 28(f).

You may also like...