- House and Senate negotiators reach two-year budget deal
- Congress seeks ban on in-flight calls
- Michelle Malkin’s Twitchy site sold to owners of Townhall, HotAir: report
- GM’s Barra to be first woman to run top American carmaker
- China: Poisonous smog is a military asset, if you think about it
- Texas woman admits to sending ricin to Obama
- Ron Paul on son Rand: ‘I think he probably will’ run for president
- Cold War heats up again in the Arctic: Russian airfield reactivated after 20 years
- 6-year-old boy suspended for sexual harassment over kiss
- Voters deciding Mass. congressional contest
U.S.-Israeli cyberattack on Iran was ‘act of force,’ NATO study found
Strike devastated nuclear program
The 2009 cyberattack by the U.S. and Israel that crippled Iran’s nuclear program by sabotaging industrial equipment constituted “an act of force” and was likely illegal under international law, according to a manual commissioned by NATO’s cyber defense center in Estonia.
“Acts that kill or injure persons or destroy or damage objects are unambiguously uses of force,” according to “The Tallinn Manual on the International Law Applicable to Cyber Warfare.”
Under the charter, states may use force in self-defense — and that, some argue, includes “anticipatory self-defense” against an incipient or imminent attack.
The international group of researchers who wrote the manual were unanimous that Stuxnet — the self-replicating cyberweapon that destroyed Iranian centrifuges that were enriching uranium — was an act of force, said Mr. Schmitt, professor of international law at the U.S. Naval War College in Newport, R.I.
But they were divided on whether its effects were severe enough to constitute an “armed attack,” he said.
Under the U.N. charter, an armed attack by one state against another triggers international hostilities, entitling the attacked state to use force in self-defense, and marks the start of a conflict to which the laws of war, such as the Geneva Conventions, apply.
Neither Israel nor the United States has publicly acknowledged being behind Stuxnet, but anonymous U.S. national security officials have told news outlets that the two countries worked together to launch the attack, which set the Iranian nuclear program back as much as two years, according to some estimates.
A group of 20 researchers wrote the manual at the invitation of NATO's Cooperative Cyber Defense Center of Excellence in Tallinn, Estonia.
It is not a statement of official policy by NATO or any of its member governments, but it reflects a consensus view of a large group of legal scholars and practitioners, including several senior military lawyers from NATO countries who took part in producing the manual.
The authors, advised by a group of technical analysts in cybersecurity, took three years to write the 300-page manual, which was published earlier this month in London, Mr. Schmitt said.
“We wrote it as an aid to legal advisers to governments and militaries almost a textbook,” he said, noting that many of the authors are or have been legal advisers.
He said the manual also was intended to be a starting point for discussions about the law.
“States make law, not scholars,” he said. “We wanted to create a product that would be useful to states to help them decide what their position is” in regard to the manual’s interpretation of the law.
“We were not making recommendations, we did not define best practice we did not want to get into policy,” he said.
Instead, the authors had tried to write the definitive account of “how does existing law apply in cyberspace,” he said.
The threshold questions of what constitutes an act of force and what triggers international hostilities are far from merely hypothetical questions, Mr. Schmitt said.
In August 2008, Georgia and Russia went to war in the disputed border province of South Ossetia. The shooting war was accompanied by cyberattacks that knocked offline many Georgian news sites and much of the country’s government, including the foreign ministry.
Mr. Schmitt said that if a cyberattack occurs before the shooting starts, “It’s a crime.” If it occurs after the shooting begins, then the hackers behind the cyberattack effectively have joined the hostilities as combatants and can be targeted with lethal force, he said.
Some researchers in cybersecurity and international law believe that judgment, like many others in the manual, is contentious.
“That’s is why you don’t let lawyers go off on their own,” said James A. Lewis, a scholar at the Center for Strategic and International Studies.
Mr. Lewis said there has not yet been enough conflict in cyberspace to allow states to develop the norms and rules needed to interpret international law. The manual’s authors “are writing way ahead of practice,” he said.
Article 5 of the NATO treaty obliges member states to come to the aid of a fellow member state that has been attacked.
In 2007, Estonia was locked in a civil and political conflict with its ethnic Russian population and with Russia over the removal of a war memorial to the Russian soldiers killed fighting Nazism in World War II. The country was beset by massive cyberattacks that crippled computer networks belonging to the government, news organizations and banks.
The attacks were traced to hackers in Russia, and most Western observers believe they were encouraged or even orchestrated by the Kremlin.
“The facts of a cyberincident are generally not well known, difficult to ascertain in detail and unclear even years in retrospect,” he said.
A central issue for international law, such as who carried out an attack, for instance, is generally regarded as extremely difficult to ascertain — the so-called attribution problem.
Mr. Schmitt opined that, for “a [nation] state with highly advanced technical capabilities, attribution is not as hard as the public believes.”
As Mr. Lewis noted, “The standards of proof on the battlefield are lower than they are in court.”
© Copyright 2013 The Washington Times, LLC. Click here for reprint permission.
About the Author
Shaun Waterman is an award-winning reporter for The Washington Times, covering foreign affairs, defense and cybersecurity. He was a senior editor and correspondent for United Press International for nearly a decade, and has covered the Department of Homeland Security since 2003. His reporting on the Sept. 11 Commission and the tortuous process by which some of its recommendations finally became ...
- Democrats proceed with Mayorkas vote despite pending investigation
- Game players don't think peace has a chance in Syria
- NSA monitored 'World of Warcraft' players
- New Internet security challenge arises for cybercops
- Britain eyes new powers to thwart Islamic extremists
Latest Blog Entries
By Donald Lambro
Growth spikes are little more than trend-free anomalies
- Harry Reid's visa pressure cooker
- Obama takes 'selfie' at Mandela's funeral service
- Chinese man fed up with his girlfriend's shopping jumps to his death
- American bourbon now better than Scottish whiskey: U.K.-born expert
- Somber duty: U.S. presidents in hot demand at Mandela's memorial
- FITTON: A closer look at the Benghazi lie
- Obama shakes hands with Cuba's Raul Castro at Nelson Mandela's funeral
- 6-year-old boy suspended for sexual harassment over kiss
- CARSON: Why did the founders give us the Second Amendment?
- Israeli P.M. Benjamin Netanyahu backs out of Nelson Mandela funeral
Independent voices from the The Washington Times Communities
Global economy, the civilizing power of markets and public morals.
News and opinion from a Millennial Urbanite with Southern sensibilities,
White House pets gone wild!
Let it snow