North Carolina Journal of International Law and Commercial Regulation

Moving Towards International Norms in Cyberwarfare

In an October 12, 2012, meeting with Time magazine, Secretary of Defense Leon Panetta warned of the immediate threat sophisticated malware posed to the United States.[1] Secretary Panetta lamented that such malware, now being developed by numerous countries[2], has “the kind of capability that can basically take down a power grid, take down a water system, take down a transportation system, take down a financial system.”[3] The most recent illustration of the power of state-sponsored cyberattacks came on August 15, 2012, when Saudi Armco, the world’s largest oil company, was the victim of an attack, which researchers believe was launched by Iranian hackers in retaliation for recent attacks by the United States and Israel.[4] The attack erased the contents of three-fourths of the company’s hard drives, leaving in their place an image of a burning American flag.[5] Advancements in cyberwarfare present the opportunity to accomplish foreign policy and military goals without the human, economic, or political cost inherent in traditional warfare.[6] However, it is evident that the rise of state-sponsored cyberattacks implicates strategic, ethical, and legal issues of the highest order.[7]

Since reports surfaced that the United States and Israel launched Stuxnet, a super-virus that successfully attacked Iranian nuclear centrifuges, U.S. officials have been willing to discuss the classified cyberwarefare program with increasing frequency and candor.[8] Such disclosures, along with media investigations[9] and reports from private cybersecurity firms[10], have revealed the increasing regularity of attacks targeting states and private entities alike.[11] Increased openness concerning the use of cyberweapons could lead to unsustainable consequences: The development of a cyber arms race[12], justification for those who seek to retaliate against the United States for the acknowledged attacks[13], or a movement towards international norms tolerating unfettered use of cyberweapons.[14] However, a dialogue concerning these issues also presents an opportunity for the United States to lead in shaping the legal framework that will govern the future of cyberwarfare.[15]

While the United States currently has offensive capacities that far outpace potential rivals, it is in its’ best interest to champion an effort to build an international consensus in favor of regulation and cyber arms control.[16] Albeit, there is reason for the United States to be skeptical of curbing its use of such weapons, especially at a time when it has leveraged the legal vacuum in this area to its strategic advantage, yielding notable successes.[17] Due in part to a nonexistent legal framework governing the use and development of cyberweapons, the United States was able to use Stuxnet to successfully infiltrate Iranian nuclear facilities, delaying Iran’s march towards developing a nuclear weapon by as much as two years.[18] Stuxnet represented a high-water mark for the U.S. cyberwarfare program, accomplishing a major foreign policy goal at a time when sanctions were ineffective, diplomacy was failing, and traditional armed conflict was untenable.[19]

However, despite the allure of the opportunities created by the legal vacuum, the United States should take action to establish international standards regulating the use of cyberweapons because the threats and uncertainties of unregulated use will quickly outweigh the benefits.[20] Given the ever-increasing threat of attack against the United States and its citizens, there are several factors suggesting that the United States should work towards an international agreement.[21] First, no country is more reliant on its computer networks than the United States.[22] While sophisticated networks ensure speed and efficiency in all areas of life, the reliance on such networks also makes the United States particularly vulnerable to a high-impact cyberattack.[23] Another factor to consider is the relative ease of creating and copying such weapons[24], making it increasingly likely that terrorist groups, or other malevolent actors, will acquire such a weapon in the near future.[25] Compared to traditional weapons, malware is a budget alternative that causes significant damage.[26]

Given the vulnerability of the United States to cyberattack and the increasing availability of sophisticated viruses to states and non-state actors, it is in the interest of the United States to forego, to a reasonable extent, its short-term offensive advantage in favor of embracing the stability and safety that would come through establishing international norms governing cyberwarfare. Whether it be through broad international agreement or through a piecemeal approach of bi-lateral agreements with key nations, such as China and Russia, the sooner mechanisms are in place for regulating the use of cyberweapons, the more secure U.S. interests will be.

Categories: Cyberwarfare

