Read The Times Australia

Daily Bulletin

Why international law is failing to keep pace with technology in preventing cyber attacks

  • Written by: Lorraine Finlay, Lecturer in Law, Murdoch University
Why international law is failing to keep pace with technology in preventing cyber attacks

The prime minister’s announcement yesterday that a “sophisticated state actor” had hacked the computer networks of Australia’s major political parties again highlights the serious threat posed by cyber attacks.

This follows a breach of the Parliament House network earlier this year. Previous examples in Australia include the 2015 malware attack on the Bureau of Meteorology and breaches of the computer systems at the Australian National University in 2018.

Indeed, cyber measures targeting Australian government infrastructure have been described as the “new normal”.

Read more: A state actor has targeted Australian political parties – but that shouldn't surprise us

Australia is not alone in facing this threat, and it is a significant one. The US Secretary of Homeland Security highlighted the seriousness of this challenge when she recently suggested that:

… cyber-attacks in terms of their breadth and scope of possible consequences now exceed the risk of physical attacks.

Technological advances continue to outpace legal developments. While intelligence officials have suggested the most recent attack came from a “nation state”, the reality is that the existing international law framework fails to provide timely or effective legal remedies.

The problem of attribution

One of the most significant hurdles is the problem of attribution. For a nation state to be held responsible under international law for a particular act, that act must be attributable to that state. There are a variety of ways this can occur. For example, the conduct of state organs (such as government departments and officials) will usually be attributable to the state.

But here’s a key problem: in the case of cyber attacks, states don’t generally operate through formal state bodies. Instead, they tend to use non-state actors who are less visible, more removed and offer plausible deniability. This creates problems of both factual and legal attribution.

Read more: Is counter-attack justified against a state-sponsored cyber attack? It's a legal grey area

The factual problem is that it is often extremely difficult to accurately identify the origin of a cyber attack. The lack of boundaries and anonymity that are characteristic of cyberspace make it hard for states to identify exactly who is responsible for a specific cyber attack.

Perpetrators are becoming increasingly effective at masking their true identities and locations. They may even deliberately make it look as though innocent third parties are responsible for an attack.

The legal problem of attribution arises from the fact that international law does not generally hold states responsible for the actions of non-state actors.

Responsibility will only be attributed if the state either acknowledges and adopts the conduct of the non-state actor as its own, or the state directs or controls the non-state actor.

The former is unlikely given the lengths that states go to mask their involvement in cyber attacks in the first place. The latter is also unlikely, given the high threshold set by international law to establish the required direction or control.

The International Court of Justice has held that a state must be shown to have had “effective control” over each specific act for which attribution is sought. Simply providing financial aid or equipment to support a cyber attack, or even providing a safe haven base for individual hackers, would likely not be enough to meet the “effective control” test.

Given these problems, it is highly unlikely that a state will ever be held publicly accountable under the existing legal framework.

It is one thing for intelligence officials to privately suggest China may be to blame for the most recent breach. But that is a long way from meeting the high threshold required to establish state responsibility under international law.

How can a state respond to a cyber attack?

Even if legal attribution could be established, that does not entirely resolve the legal complexities. International law has few mechanisms that allow a state to respond effectively to a cyber attack once it has occurred.

A state is allowed to use force in self-defence – but only in response to an armed attack. An armed attack in this context refers to only the most grave use of force. It is highly unlikely that acts of cyber espionage focused primarily on gathering intelligence or data could ever be characterised as an armed attack under this definition.

Similarly, while countermeasures (a broad category of temporary, reversible measures designed to induce a state to cease its wrongful conduct) are allowed under international law in certain circumstances, the conditions imposed on these mean they are of limited use in the context of cyber attacks. For example, in all but the most urgent circumstances, an injured state must notify the responsible state of the decision to take countermeasures and offer to negotiate with them before any countermeasures are actually taken. Such procedural requirements are simply impractical when responding to cyber attacks, given their potential speed and reach.

Cyber attacks by foreign states pose a real and growing threat to Australia. Unfortunately, the existing international law framework provides little effective protection or recourse. This makes it even more important for Australia to ensure we are doing everything possible to protect ourselves and our democratic institutions from cyber attacks.

Authors: Lorraine Finlay, Lecturer in Law, Murdoch University

Read more http://theconversation.com/why-international-law-is-failing-to-keep-pace-with-technology-in-preventing-cyber-attacks-111998

Business News

How to Tell if a Childcare Centre Is a Good Fit for Your Child

Choosing childcare can feel like you’re making a huge decision with limited information. Tours are short, centres are often on their best behaviour, and your child might act differently in a new space...

Daily Bulletin - avatar Daily Bulletin

Car Import Timeline: What Usually Happens at Each Stage

Importing a car into Australia can feel confusing because multiple agencies and checkpoints are involved, and the timeline is shaped as much by paperwork quality as it is by shipping speed. The most u...

Daily Bulletin - avatar Daily Bulletin

Portable Toilet Hygiene Standards Explained: Clean vs Sanitised vs Disinfected

In portable toilet servicing, the words clean, sanitised, and disinfected often get used as if they mean the same thing. They don’t. And that difference matters because a unit can look tidy and still ...

Daily Bulletin - avatar Daily Bulletin

Options Available When a Company Faces Financial Distress

Financial distress can develop gradually or arrive suddenly, and when it does, the decisions made in the early stages often determine what options remain available later. Directors who act promptly ...

Daily Bulletin - avatar Daily Bulletin

What Healthcare Teams Look for When Choosing Specialist Surgical Supplies

In clinical environments, small details rarely stay small. A delayed instrument, a poorly matched device or inconsistent supply quality can affect theatre flow, staff confidence and patient outcomes. ...

Daily Bulletin - avatar Daily Bulletin

Reducing Sales Friction Through Centralized Content Delivery

Sales friction appears whenever buyers or sales teams face unnecessary obstacles in the buying journey. It can happen when information is hard to find, when messaging feels inconsistent, when product ...

Daily Bulletin - avatar Daily Bulletin

Why Choosing the Right Bollard Supplier Matters for Australian Businesses and Public Spaces

From busy CBD streetscapes to sprawling warehouse loading docks, bollards have become one of the most essential safety and security fixtures across Australia. Whether protecting pedestrians from veh...

Daily Bulletin - avatar Daily Bulletin

Why Modular Content Is Transforming Modern Marketing Teams

Modern marketing teams are expected to produce more content than ever before. They need to support websites, landing pages, email campaigns, social channels, product pages, sales enablement material...

Daily Bulletin - avatar Daily Bulletin

Everything You Need to Know About Getting Support from Optus

Whether you've been an Optus customer for years or you've just switched over, at some point you'll probably need to contact their support team. Maybe your bill looks different from what you expected. ...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

What to Ask a Wedding Photographer Before You Book

Booking a wedding photographer can feel deceptively simple: you like the photos, you like the vibe...

Why Stress Relief For Dogs Is Essential For Emotional Balance And Long-Term Wellbeing

Managing emotional health is just as important as physical care when it comes to pets, which is why ...

Australia’s Best Walking Trails and the Shoes You Need to Tackle Them

Australia is not short on spectacular walks. You can follow ocean cliffs in Victoria, cross ancien...

Why Pre-Purchase Building Inspections Are Essential Before Buying a Home in Australia

source Have you ever walked through an open home and started picturing your furniture, family d...

5 Signs Your Car Needs Immediate Attention Before It Breaks Down

Car problems rarely appear without warning. In most cases, your vehicle gives clear signals before...

Ensuring Safety and Efficiency with Professional Electrical Solutions

For businesses in Newcastle, a safe and fully functioning workplace remains a key part of day-to-d...

Choosing The Right Bin Hire Solution For Hassle-Free Waste Management

When it comes to managing waste efficiently, finding the right solution can save both time and eff...

Why Cleanliness Is Critical In Childcare Environments

Children explore the world with curiosity, often touching surfaces, sharing toys, and interacting ...

What to Look for in a Reliable Australian Engineering Partner

Choosing an engineering partner is rarely just about technical capability. Most businesses can fin...