International Cooperation in Combating Cyberthreats and U.S. Law
This article originally appeared in the January/February 2014 edition of the Maryland Bar Journal and is republished by permission of the Maryland State Bar Association.
Download a PDF of the original article.
In a recent report, McAfee, the computer security company, estimated that the cost of global malicious cyber activity ranged from $300 billion to $1 trillion. Center for Strategic and Int’l Studies, The Econ. Impact of Cybercrime and Cyber Espionage 5 (2013). In computing this broad estimate, the authors examined a number of categories of such activity, e.g., theft of intellectual property and confidential business information; possible stock manipulation; opportunity costs for service and employment disruptions; the additional cost of securing networks, insurance, and recovery from cyber attacks; and reputational damage. Id at 3. But the McAfee report addresses only the cost of cyber attacks on the private sector.
To gauge the impact of cyber attacks on public sector institutions, one need only start with Estonia, where, in April 2007, the first series of sustained Distributed Denial-of-Service cyberattacks, lasting 22 days, were launched. The attacks, which were unprecedented in scope and persistence, flooded computer, servers, routers and websites supporting government ministries, political parties, banks, internet service providers (“ISPs”) and telecommunications companies, and blocked legitimate users. Because of Estonia’s high dependence on information technology (“IT”) but inadequate IT infrastructure, the attacks effectively “crippled” the country. See CHARLES DOYLE, CONG. RESEARCH SERV., RS20830, CYBERCRIME: A SKETCH OF 18 U.S.C. 1030 AND RELATED FEDERAL CRIMINAL LAWS 7-8 (2008). NATO and the United States scurried to send computer security experts to Estonia to help the country recover from the attacks; to analyze the methods used; and to attempt to ascertain the source(s) of the attacks. Id. at 7.
Given the volume, duration and timing of the attacks, Estonian officials initially blamed Russia. The investigators concluded, however, that the incidents were not concerted attacks, but the product of the collective anger of numerous, albeit unaffiliated, hackers. Specifically, data showed that the sources of the attacks were dispersed over many countries, rather than concentrated in a few locations; that the computer code that caused the attacks was posted and shared in numerous Russian-language chat rooms; that there was no apparent attempt to cause extensive damage, except to internet resources; and that were no extortion demands. Id. at 8. Still, the realization that cyberattacks could threaten the national security of an entire country was a “true wake-up call for NATO,” including its leading member, the United States. VINCENT JOUBERT, FIVE YEARS AFTER ESTONIA’S CYBER ATTACKS: LESSONS LEARNED FOR NATO ?, 1, NATO DEF. COLL., RES. PAPER NO. 76 (2012), available at http://www.ndc.nato.int/ news/current_news.php?icode=394,
In the aftermath of the attacks on Estonia, two distinctly different types of international actors learned apparently very different lessons. The United States and its allies learned that cooperation by like-minded countries and their private sectors was critical for combating cyberthreats. See, e.g., Jack Goldsmith, Cybersecurity Treaties: A Skeptical View in FUTURE CHALLENGES IN NAT’L SECURITY AND LAW 6 (Peter Berkowitz, ed., 2011) (stating that the U.S. Government’s “recent foray into international negotiation on [combating cyberattacks] appears to reflect a judgment that it cannot adequately protect its critical infrastructure and other digital assets without international cooperation”); THE WHITE HOUSE, INT’L STRATEGY FOR CYBERSPACE: PROSPERITY, SECURITY, AND OPENNESS IN A NETWORKED WORLD 3 (2011) (“The world must collectively recognize the challenges posed by malevolent actors’ entry into cyberspace, and update and strengthen our national and international policies accordingly.”).
On the other hand, U.S. adversaries, whether foreign governments or non-State actors, realized that focused, persistent cyber attacks that were designed to make attribution difficult, if not impossible, could be a low-cost, but highly disruptive tool or weapon. In other words, cyber attacks since Estonia are proliferating, if for no other reason than their means are becoming “less expensive and easier to acquire and use.” William Banks, The Role of Counterterrorism Law in Shaping ad Bellum Norms for Cyber Warfare, 89 INT’L L. STUD. 157, 159 (2013) (citations omitted). Indeed, when targeted at powerful countries like the United States, cyber intrusions offer a “model application of asymmetric warfare, where adversaries much weaker in conventional terms exploit vulnerabilities in the stronger foe. The asymmetric attackers are further advantaged by the fact that they may mask their identity and location, at least temporarily, and avoid immediate attribution and response to the attacks.” Id. at 159.
Since “most cybersecurity incidents are transnational in nature,” KRISTIN M. FINKLEA, CONG. RESEARCH SERV., R41927, THE INTERPLAY OF BORDERS, TURF, CYBERSPACE AND JURISDICTION 6 (2012), the purpose of this article, then, is to explore how existing international law applies to cyberthreats; how U.S. law applies to cross-border cyberthreats; and how the United States could better promote international cooperation to combat cyberthreats.
How Existing Customary International Law Applies to Cyberthreats
To begin with, international law is comprised principally of two sources of rules: (1) “customary international law,” which is defined as the corpus of doctrines resulting from the “general and consistent practice of states followed by them from a sense of legal obligation,” RESTATEMENT (THIRD) OF THE FOREIGN RELATIONS LAW OF THE UNITED STATES § 102 (1987); and (2) international agreements, such as treaties or conventions. Id.
Given that the technology that has given rise to cyberspace is only a few decades old and is rapidly evolving, January 2014 Maryland Bar Journal 39 it is no wonder that an “international group of experts,” who were invited to compile a comprehensive report on the applicability of international law to cyber warfare by the NATO Cooperative Cyber Defense Center of Excellence in Tallinn, acknowledged that it is “sometimes difficult to definitively conclude that any cyberspecific customary international law norm exists.” TALLINN MANUAL ON THE INTERNATIONAL LAW APPLICABLE TO CYBER WARFARE 5 (Michael N. Schmitt ed., 2013). Still, the Tallinn experts unanimously agreed that “general principles of international law applied to cyberspace.” Id. at 13.
Indeed, achieving a consensus understanding of the international law of cyber threats is complicated by some of the unique attributes of cyberspace. For example, timely “attribution of an attack and even threat identification can be very difficult. As a result, setting the critical normative starting point in the UN Charter and laws of armed conflict—the line between offense and defense—is elusive, particularly taking into account the possibilities afforded by cyber ‘active defenses.’” Banks, supra, 89 INT’L L. STUD at 161.
In the view of the United States, however, the development of norms for state conduct in cyberspace “does not require a reinvention of customary international law, nor does it render existing international norms obsolete.” THE WHITE HOUSE, INT’L STRATEGY FOR CYBERSPACE: PROSPERITY, SECURITY, AND OPENNESS IN A NETWORKED WORLD 9 (2011), available at http://www.whitehouse. gov/sites/default/files/rss_ viewer/international_strategy_for_ cyberspace.pdf. In other words, the U.S. posits that longstanding international norms guiding state behavior— in times of peace and conflict—”also apply in cyberspace.” Id. Nonetheless, the U.S. recognizes that “unique attributes of networked technology require additional work to clarify how these norms apply and what additional understandings might be necessary to supplement them. We will continue to work internationally to forge consensus regarding how norms of behavior apply to cyberspace ….” Id.
Still, international law does little to thwart cyber-intrusions and, as many observers believe, that is not likely to change. See, e.g., Michael J. Glennon, State-level Cybersecurity: The Missing Link in the Battle Against Global Botnets, POLICY REVIEW NO. 171 (Feb. 12, 2012). For one thing, the United States 40 Maryland Bar Journal January 2014 and its allies have long argued that the current rules of international law limit only “armed” attack — violence involving “kinetic” effects, not cutoffs of foreign aid, trade boycotts, travel bans, or other acts that might have the same effects as an armed attack. That interpretation is now widely accepted and, as Glennon argues, “[f]ew will be persuaded if the United States and its newly vulnerable allies now reverse course and contend that it’s really an attack’s effects that count, not the means.” Id.
Moreover, it is questionable whether new international legal rules on cyberattacks are possible because compliance could not be verified, since verification requires the ability to identify transgressors. Id. As Glennon adds, it is unlikely that customary norms applicable to cyberspace will emerge from ad hoc state practice, as they did long ago concerning diplomatic immunity and freedom of the seas because nations’ cyber-behavior is “veiled in secrecy, which makes it extremely difficult, if not impossible, to find any dots to connect.” Id. Indeed, since malicious cyber activity and its sponsor are usually concealed, “verification of compliance is impossible, so too is deterrence and effective legal regulation.” Id. In short, no verifiable international agreement “can regulate the covert writing or storage of computer code useful for launching a clandestine cyber attack. Michael J. Glennon, The Dark Future of International Cybersecurity Regulation, 6 J. NAT’L SEC. L. & POL’Y 563, 564 (2013).
How Existing International Agreements Apply to Cyberthreats
To date, the only relevant treaty is the Council of Europe Convention on Cybercrime, otherwise known as the Budapest Convention, which is intended to, inter alia, harmonize the Parties’ domestic laws against cybercrime and improve international cooperation on investigations and enforcement. Council of Europe, Convention on Cybercrime, Nov. 23, 2001, ETS No. 185, TIAS 13174. Although it has entered into force for almost all members of the Council of Europe, it has been ratified by only five countries outside of Europe – Australia, the Dominican Republic, Japan, Mauritius, and the United States – and has never been signed by Russia, China or any of the other countries from which most cross-border cyber attacks have been launched. In other words, the Budapest Convention is limited in both scope and breadth of support beyond the NATO countries. Whether a broader, more widely accepted treaty could more effectively constrain international cyberattacks is doubtful, however, and none is on the horizon.
How U.S. Law Applies to Cyberthreats from Abroad
Given the relative recency of the Internet, it was not until 1991 that the United States entered into its first international agreement that was expressly intended to coordinate cybersecurity measures. See Memorandum of Understanding on Cooperative Research, Development and Demonstration of Internetworking Technologies to Improve Communications Systems Network Interoperability, Oct. 22, 1991, TIAS 13174 (consisting of nine NATO members). That was the only cyber treaty until 2000, when the United States entered into the Memorandum of Understanding for Interoperable Networks for Secure Communications, Oct. 31, 2000, TIAS (consisting of eight NATO members). Finally, the United States ratified the Budapest Convention in 2005. But, as indicated above, the Budapest Convention is aimed at resisting and detecting criminal activities in cyberspace, and neither it nor any other treaty provisions directly deal with cyber warfare. See TALLINN MANUAL 5.
In light of the fact that no treaty provisions deal directly with cyber warfare and that cyber-specific customary international law is only in an incipient state, the first issue that arises in connection with “international cooperation” under U.S. law is the legal nature of the “cooperation,” i.e., whether the legal framework will be a “treaty,” a military “alliance,” or another international commercial “agreement,” and whether such agreement requires ratification by two-thirds of the Senate under the Treaty Clause, U.S. CONST. art. II, § 2, cl. 2, or may be approved by a majority vote in each house of Congress, as a “congressional-executive agreement.”
Indeed, that question – i.e., what form of agreement? – raises “complex issues” of constitutional interpretation, Made in the USA Found. v. United States, 242 F.3d 1300, 1302 (11th Cir. 2001), that the Supreme Court has never resolved. Id. at 1305 (stating that the Supreme Court has “never seen fit to address the question of what exactly constitutes and distinguishes ‘treaties,’ as that term is used in Art. II, § 2, from ‘alliances,’ ‘confederations,’ ‘compacts,’ or ‘agreements,’ as those terms are employed in Art. I, § 10”).
Still, it is well-settled that the President has the authority to enter into an international agreement that is binding on the United States. See, e.g., Ludecke v. Watkins, 335 U.S. 160, 173 (1948) (the President is the January 2014 Maryland Bar Journal 41 nation’s “guiding organ in the conduct of our foreign affairs,” in whom the Constitution vests “vast powers in relation to the outside world”).
Using that authority, the U.S. Department of Homeland Security’s National Cyber Security Division (NCSD) is an active member of a collaborative effort among Australia, Canada, New Zealand and the U.K.; NCSD’s U.S. Computer Emergency Readiness Team (US-CERT) participates in the Organization of American States’ Inter-American Committee Against Terrorism cybersecurity workshop; and is active in the Meridian Conference, which provides a forum for countries to share information relating to cybersecurity initiatives, critical infrastructure protections issues, and lessons learned to improve global cybersecurity infrastructure. DEP’T OF HOMELAND SECURITY, OFFICE OF INSPECTOR GEN. NO. OIG-12-112, DHS CAN STRENGTHEN ITS INTERNATIONAL CYBERSECURITY PROGRAMS 6 (Aug. 2012) (redacted version).
Canada has long been the closest ally of the United States. Indeed, Canada is part of the U.S. industrial base, and in February 2011 the United States and Canada signed the Beyond the Border declaration, which focuses on information sharing and joint threat assessments to develop a common and early understanding of the threat environment; infrastructure investment to accommodate continued growth in legal commercial and passenger traffic; integrated cross-border law enforcement operations; and integrated steps to strengthen shared cyber-infrastructure.
Similarly, Federal law enforcement has already taken steps to network with other federal, state, local, and international partners. This model has been used for decades to combat more traditional crime, and it has more recently been used to combat cybercrime. See, e.g., KRISTIN M. FINKLEA, CONG. RESEARCH SERV., R41927, THE INTERPLAY OF BORDERS, TURF, CYBERSPACE AND JURISDICTION: ISSUES CONFRONTING U.S. LAW ENFORCEMENT 26 (2012). For instance, the FBI began embedding agents with international law enforcement partners in Romania in 2006 in order to target cyber criminals, and the FBI collaboration has since been expanded to countries including Estonia, Ukraine, and the Netherlands. Id. These partnerships have proved beneficial in investigating and prosecuting transnational criminals. Id. See also, e.g., DoD, Defense Industrial Base (“DIB”) Voluntary Cyber Security and Information Assurance (CS/IA) Activities, 78 Fed. Reg. 62430 (Oct. 22, 2013) (to be codified at 32 C.F.R. Pt. 236).
U.S. Strategies for Improving International Cooperation Against Cyberthreat
In the INTERNATIONAL STRATEGY, supra, the United States stated that it is committed to fostering an “open, interoperable, secure and reliable cyberspace,” which depends on “nations recognizing and safeguarding that which should endure, while confronting those who would destabilize or undermine our increasingly networked world.” Int’l Strategy at 3. An effective strategy, the U.S. states, “will require action on many fronts, with shared responsibility at every level of society, from the end-user up through collaboration among nationstates.” Id. at 8.
To achieve the objective of reduced vulnerability, the U.S. continues: will require robust technical standards and solutions, effective incident management, trustworthy hardware and software, and secure supply chains. Risk reduction on a global scale will require effective law enforcement; internationally agreed norms of state behavior; measures that build confidence and enhance transparency; active, informed diplomacy; and appropriate deterrence. Finally, incident response will require increased collaboration and technical information sharing with the private sector and international community. This work cannot be fully addressed by any single nation or sector alone; it is a responsibility and duty that every nation, and its people, all share. Id. at 9.
Conclusion
Given that most cyberattacks are international, the need for effective international cooperation in combating cyberthreats is growing every day. In light of the Tallinn Manual’s conclusion that customary international law applies to cyber warfare, the precedent of the Budapest Convention, and the U.S. strategy of being committed to working closely with like-minded nations and their private sectors to strive for an open, secure networked world, there is hope that international cooperation can mitigate, if not eliminate, cyberthreats.
Mr. Hoffman is a Principal in the Cybersecurity, Government Contracts and International Practice Groups at Offit Kurman, P.A., and is a member of the CyberMaryland Advisory Board. He may be reached at ihoffman@offitkurman.com.



