HOW CAN EVIDENTIARY STANDARDS BE REGULATED AT THE INTERNATIONAL LEVEL FOR VERIFIABLE AND TRANSPARENT ATTRIBUTIONS OF CYBERATTACKES TO STATES?

Taís Fernanda Blauth and Dr Oskar J. Gstrein

Introduction
Individuals, private organisations, and the public sector are increasingly reliant on digital technologies and infrastructures to function. This scenario of reliability on technology and growing digital data sets is explored by hackers, who can cause extensive harms. A cyberattack might affect, for instance, the data of one individual, but it can also affect the security and critical infrastructure of a state. For this reason, there is a general interest in holding the perpetrator(s) accountable and suppressing future attacks. In this context, the attribution of a cyberattack is critical, considering its purpose of assigning responsibility for conducting a cyberattack. The process of attribution has technical, legal, and political aspects. Technical attribution involves forensic investigation to identify the origin of an attack; legal attribution refers to the legal determination of responsibility; and political attribution involves attributing cyberattacks to states or to entities linked to a state. This essay will focus on political attributions, which have emerged as a possible course of action for foreign policy when responding to attacks such as “Wannacry” and “NotPetya”.

Political cyberattack attributions, which are increasingly common, are critical (1) to maintain strategic stability through deterrence and escalation control and (2) as a way for states to assign responsibility and denounce violations of norms in cyberspace. However, such attributions might suffer from a lack of credibility if they are not accompanied by sufficient evidence. Consequently, such declarations often cannot produce the desired effect of “naming and shaming”.

One way of making political cyberattack attributions more credible and trustworthy is by establishing evidentiary standards that states should follow when making public declarations. More substantiated attributions could lead to a better understanding of cyberattacks and increase trust. However, substantiating attributions would require states to disclose their sources and methods, which can be undesirable for reasons of confidentiality and secrecy.

The process of attribution, including the procedural and substantive elements, has been widely debated. Scholars, private organisations, and civil society have provided a number of suggestions regarding the creation of institutional mechanisms for public attribution of cyberattacks. It has also been argued that the focus of this discussion should shift towards the development of evidentiary standard guidelines. This essay explores how evidentiary standards can be regulated at the international level in order
to establish verifiable and transparent attributions of cyberattacks to states. It will first analyse current practices for providing evidence, which contributes to understanding the current practice as well as the main issues at stake. Subsequently, the main advantages and difficulties in regulating the presentation of evidence will be analysed and discussed. This overview helps to understand what could hinder regulation, as well as why standards for evidence are important. Finally, I will explore the possibility of regulating this procedure based on customary international law, arguing that such regulation could lead to more verifiable and transparent attributions. To this end, I will reflect on the two constitutive elements of customary international law, namely (1) consistent, general state practice and (2) a sense of legal obligation (opinio juris) and how they relate to the
current practice. Read full version below.