Cyber Attack Attribution: Who Pays When the Commander Is Wrong?

Cyber Attack Attribution
Image by imkara visual on unsplash.com

Estimated reading time: 23 minutes


Cyber attack attribution is routinely called the hardest problem in the domain. The description is fair. What gets inferred from it is not.

The attribution enterprise was built to identify organisations and States. Its technical arm resolves machines, infrastructure and intrusion sets. Its legal arm resolves responsibility under the law of State responsibility. Both are answering a question about which State to blame.

The law of targeting asks something narrower. Article 51(3) AP I withdraws protection from a civilian for such time as he takes a direct part in hostilities. The object of that judgement is a person. A commander does not engage an organisation. He engages someone, and he must be able to say who.

That mismatch is the subject of this post. In my view, the standard move in the debate runs two different legal questions together. “We cannot attribute, therefore the participant cannot lawfully be reached” treats an evidentiary difficulty as though it answered a question about what the commander must do. The difficulty being described is retrospective and adjudicative. The targeting rule is neither. It asks what the commander did to verify, and whether his assessment was reasonable on the information he then had.

I should say at the outset that this conclusion cuts toward permissibility, and that it lands differently on the two people who must live with it. For a commander it means a cyber participant may be lawfully reachable without having been identified to certainty. For his legal adviser it removes a safe refusal and replaces it with a different judgement he has to make and own. Section V asks what protects the person on the other end of that judgement.

One threshold needs fixing before the analysis begins. Direct participation carries its own threshold of harm, and it sits below the threshold for an attack. The Tallinn Experts accept that operations falling short of a cyber attack can still satisfy it (Rule 97, commentary para 5). So the contested question I examined in whether data is a military objective, when a cyber operation becomes an attack, does not govern who counts as a participant. It governs the response, and I return to it in Section V.

This post follows my treatment of disengagement when the capability runs on, which asked what a cyber participant must do to stop participating, and found that one who discloses in order to disengage individuates himself in the act. It also rests on the presumption of civilian status in case of doubt, where I set out how the doubt rules operate under uncertainty. Neither is re-argued here. Both are extended.

I. Two decisions, one set of facts

The problem shows itself most clearly when one set of facts produces two different legal questions. Take an armed conflict in which a cyber operation disables the fire-control network of State A’s air defences. State A’s investigators trace the operation to M, a civilian contractor working from State B’s territory. The evidence is good without being conclusive. There is reused infrastructure, a pattern of working hours consistent with M’s time zone, and one operational error by the intruder.

Two officials in State A now face different questions. A legal adviser must decide whether State A may take a countermeasure against State B. A commander must decide whether M may be engaged as a person taking a direct part in hostilities. Both questions turn on who did this. They do not ask for the same thing.

Part of what makes the attribution debate feel intractable is that a single word covers three different operations. Technical attribution identifies a machine or a network. Identity attribution identifies a person. Legal attribution assigns conduct to a State for the purposes of responsibility. The United Kingdom’s statement separates the legal sense, which it describes as “identifying those who are responsible for an internationally wrongful act”, from a non-legal sense covering the identification of actors, including non-State ones (at para 13). Davis draws a comparable three-way split between technical, political and legal attribution (at pp. 7–8).

None of the three delivers what the commander needs. Technical work stops at the machine. Goel and Nussbaum, surveying the state of the art, find that technical data may indicate where an attack came from while remaining “not able to identify the individuals responsible” (at p. 1089). Davis makes the same point in legal register: the terminal reveals little about the person at the keyboard (at p. 7). Legal attribution stops at the State, and does so by design, because its purpose is to fix responsibility on an entity rather than on a human being. Even the commentary of the International Law Commission frames the exercise as identifying actors and their association with a State (Chapter II, commentary para 9).

So the commander’s question is left standing. He is not asking which machine, and he is not asking which State. He wants to know whether the person in front of him is the one who did this, and how sure he must be before acting. Section II shows why the second half of that question has a different structure from anything the attribution debate has been arguing about.

II. Why the two regimes treat honest error differently

The law of State responsibility and the law of targeting both speak of reasonableness. They put the word in different structural positions, and that placement decides who pays when a careful decision-maker turns out to be wrong.

Start with the legal adviser. A countermeasure is conduct that would otherwise breach an obligation owed to State B, and the justification is available only against a State that is actually responsible. Article 49 of the Articles on Responsibility of States for Internationally Wrongful Acts (ARSIWA) presupposes an objective standard, and the commentary is explicit that a State resorting to countermeasures on its own assessment “acts at its peril” (Article 49, commentary para 3). The Tallinn Experts take the same view by majority: where the attribution conclusion proves flawed, wrongfulness is not precluded (Chapter 4, Section 1, para 12). State B’s responsibility is a fact the excuse requires, not a belief the excuse accepts.

The United States describes the decision side of this accurately and stops there. Its 2021 position states that a State “acts as its own judge of the facts”, that absolute certainty is not required, and that international law asks the State to act reasonably in the circumstances (2021 UN compendium of national positions, A/76/136, at p. 141). All of that is right about how the determination is made. None of it bears on whether the determination holds. Judging for oneself is not judging finally, and the Tallinn commentary notes that such determinations may face post factum review in a judicial or other forum (Chapter 4, Section 1, para 9).

The strictness is not uniform even within the law of State responsibility. A plea of necessity is treated differently, and the ILC is explicit that it does not depend on the prior conduct of the injured State (Article 25, commentary para 2). Uncertainty about the future does not disqualify a State from invoking it, provided the peril is clearly established on the evidence reasonably available at the time (Article 25, commentary para 16). Germany applies this to cyber, accepting that necessity may be invoked where the origin of a cyber measure has not yet been clearly established, while urging States to keep working at attribution (at p. 15). Norway says the same from its own necessity section: it is not a requirement that the preceding operation be attributable to a particular State (at p. 73). The trade is a hard one, since necessity demands an essential interest, a grave and imminent peril, and a measure that is the only way available. Countermeasures are the strict case on attribution, not the pattern.

Now the commander. Articles 57(2)(a)(i) and 50(1) AP I are primary rules. They do not excuse a breach; they define what compliance consists of, and what they require is a feasible verification and a reasonable assessment. The Trial Chamber in Galić put the test as whether, in the circumstances of the person contemplating the attack and on the information available to him, “it is not reasonable to believe… that the potential target is a combatant” (at para 50). The ICRC’s Interpretive Guidance is equally direct that the targeting standard is not the criminal one, and must instead reflect “the level of certainty that can reasonably be achieved in the circumstances” (at p. 76).

The two rules therefore differ in kind and not in strictness. In the first, reasonableness governs how the State reached its view while the justification stays hostage to the facts. In the second, reasonableness is the content of the obligation itself. A commander who verified feasibly and assessed reasonably has complied, and there is no breach for his State to answer for under Article 91 AP I. Same honest error, opposite bearer: the acting State pays in one case, and in the other the misidentified person, who has no remedy against a commander who complied.

Davis noticed a version of this asymmetry in 2022 and drew a different conclusion. Comparing countermeasures with self-defence, he observed that unlike a State that takes countermeasures against an internationally wrongful act, the responding State that is acting in self-defence need “merely be reasonable in its attribution determination, not also correct”. Davis called this contrast illogical. The law refuses error where the consequence is a non-forcible breach, committed by a countermeasure resting on a false attribution. It accepts error where the consequence may be death, caused by self-defence against a misattributed attack (at p. 13). His charge is normative, and it deserves an answer rather than a dismissal. I take no position here on whether self-defence tolerates reasonable misattribution, which is contested and belongs to another debate. The comparison this post draws is different and, I think, sharper. Countermeasures and self-defence each have an objective trigger, an internationally wrongful act in the one case and an armed attack in the other. Articles 57(2)(a)(i) and 50(1) AP I have no such trigger. They do not make lawfulness depend on the person having been a participant in hostilities. They make it depend on what verification was feasible and whether the assessment was reasonable on the information then available. That is not a lower threshold of proof. It is a rule of a different kind.

The reason such a rule is defensible is forbearance. A State contemplating a countermeasure can wait, investigate further, or decline to act, and Norway requires it to be confident in its attribution before resorting to one (at p. 73). A commander cannot set his own tempo. A rule keyed to the correctness of his identification would stop guiding his conduct rather than tightening it, because it would make compliance turn on something he cannot secure. Davis may still be right that the outcome is unattractive. What it is not is a drafting error.

The reverse of the targeting rule is also graded rather than binary, and the post should not flatten it. A commander who fails the feasibility standard has breached Article 57, which founds his State’s obligation to make reparation. Criminal liability requires more. Galić frames the offence around whether a reasonable person could not have believed the target was a combatant, with that burden resting on the prosecution (at para 55). Breach and crime are different findings.

The two bodies of law can also meet on one set of facts. Norway gives the case: where infrastructure in a third country is used in a wrongful cyber operation, the injured State may under certain conditions act to disrupt it, even though this violates that third State’s sovereignty (at p. 73). Transpose it to our facts and suppose M sits not in State B but in State C, a non-party to the conflict. Whether M may be attacked remains a question of targeting law. Whether State A may operate on State C’s territory at all is a question of State responsibility, with its own justifications and its own consequences for error. A commander can be entirely compliant on the first while his State is exposed on the second.

In operational terms, the finding lands differently on the two people who must act on it. For the commander it means an identification short of certainty does not, by itself, put the participant beyond reach. For the legal adviser it means the question cannot be closed by pointing at the attribution literature, because that literature is arguing about a standard that governs a different decision from his. What he owes instead is an account of what verification was feasible and what was done. Section V takes up what that account has to contain.

III. What that does to the “attribution is hard” inference

Rid and Buchanan say plainly what the attribution enterprise is for, and it is not the person. They state that “The ultimate goal of attribution is identifying an organisation or government, not individuals” (at p. 13). Individuals appear in their model as a route rather than a destination. They draw the contrast with kinetic conflict directly: raiding aircraft can be identified as Israeli from type, geography and flight path, all without identifying the pilots. Cyber may run the other way. Absent markings and geography, individual operators become the link, so reaching the organisation may require descending to persona level first (at p. 13).

The legal literature aims at the same target and is careful to say so. Davis surveys the standards of proof that should govern attribution and keys them to retorsion, countermeasures and self-defence, which are the three responses available outside armed conflict (at pp. 10–15). Targeting a person under IHL never enters the frame. Macák and Pircher approach the individual from the prosecution side and reach the same limit: even where technical methods trace an operation to a machine, identifying the human responsible and meeting the standard of proof for criminal liability remains a formidable challenge (at p. 16). That is a true statement about prosecution. It is not a statement about targeting.

State practice sits in the same register throughout. Of the seven national positions this post relies on, every one addresses attribution to a State, and none addresses the identification of a person for the purposes of an attack. Finland separates the two operations expressly, distinguishing “identification as a technical operation from attribution as a legal operation” and holding that technical difficulty has no consequence for the legal rules of attribution (at p. 5). Norway treats the difficulty of establishing direction or effective control as a question of evidence rather than a gap in the law (at p. 71). Brazil pushes from the other direction, insisting that technical difficulty must not lower the bar for attribution determinations (at p. 21). The United States separates proof for judicial proceedings from a State’s own determination for response purposes (at p. 141). Each is answering a question about which State is responsible.

These States do not speak with one voice, which is itself instructive. Finland makes confidence a condition of responding, requiring adequate proof of the source and convincing evidence of a particular State’s responsibility (at p. 6). The American position holds that absolute certainty is not required and that reasonableness suffices, adding that there is no legal obligation to reveal the evidence, though public attributions should where feasible include enough to allow corroboration (at p. 141). The practical distance between them is narrower than it first appears. The structural distance is not, because one states a condition of lawfulness and the other a recommendation about transparency. Both disagreements are conducted wholly within the law of State responsibility, and neither tells a commander anything about his own question.

France is the one State that touches the targeting question, and what it offers is not a legal standard. Its position records that “the targeting of such individuals remains marginal” given the difficulties of identifying the perpetrators of a cyberattack (at p. 15). That sentence repays careful reading. It reports how often something happens. It does not say that such targeting is unlawful, and it does not say what a commander must establish before undertaking it. An observation about frequency cannot discharge a legal question, and France does not claim that it does.

In my view the dominant treatment of cyber attribution is therefore arguing the wrong standard for the targeting question. The claim is not that the field is confused about its own subject, because it answers its own questions well. The claim is narrower. Its central negative finding, that we cannot attribute a cyberattack with confidence, is a finding about evidentiary standards for State responsibility and for criminal liability. That finding is then carried across into a sentence about whether a person may be engaged. The crossing is not argued anywhere. It is assumed.

Davis shows how naturally the assumption forms. He treats reasonableness as too vague to govern. In its place he proposes a preponderance standard for countermeasures, which asks whether the identification of the perpetrator is more probably correct than not, and a clear and convincing evidence standard for self-defence (at pp. 13–15). Within his subject that is a serious reform proposal. Carried into Article 57(2)(a)(i), the same instinct would replace a duty to do everything feasible with a threshold of proof, which would substitute a different rule rather than tighten this one. Section IV shows that the doctrinal machinery for identity uncertainty is thinner than either debate assumes.

IV. The doubt taxonomy and the case it straddles

The Tallinn Manual sorts doubt into two boxes, and identity fits neither of them cleanly. Rule 95 handles doubt about a person’s status. Rule 97 handles doubt about whether conduct amounts to direct participation. The Experts keep the two apart deliberately, explaining that where direct participation is in issue the individual is a civilian by definition, so “the matters about which doubt can exist relate to that individual’s activities, not his or her status” (Rule 95, commentary para 5).

That reasoning carries a premise which is easy to miss. It works only once you know who you are looking at. The Experts assume an identified person and ask what he did. Our commander is one step earlier. He is asking whether the person in front of him is the one who did anything at all.

Both boxes are available to him, and they lead to opposite defaults. Framed as status doubt, Article 50(1) AP I directs that the person be considered a civilian. Framed as activity doubt, the Experts divide, and the camp that rejects the analogy with Rule 95 holds that the attacker must review all relevant information and act reasonably in the circumstances, with “No presumption attaches” (Rule 97, commentary para 13).

I have already taken a side on the second of those, and it is worth saying so plainly rather than arriving at it twice. In my treatment of direct participation I parted company with the ICRC on conduct doubt and followed Schmitt: a civilian already shown to be acting, who has placed himself close enough to hostilities to raise the question, should carry the consequence of the doubt rather than the commander. I do not reargue that here.

In my view it does not extend to identity, and the reason is the premise. Schmitt’s argument earns its result from something the person has done. He came close to the fighting, and proximity he chose is what justifies loading the doubt onto him rather than onto the commander. In the identity case nothing of the kind has been established. The only thing connecting this person to the hostilities is the inference now under test. To route identity doubt into the activity box would be to charge him for a proximity that has not been shown, using the very uncertainty that was supposed to be resolved.

Article 50(1) AP I says nothing about identity, and I am not suggesting it does. What it addresses is doubt as to whether a person is a civilian. But for a civilian, protection is lost only through conduct, so the claim that this person is not protected depends entirely on the claim that this person is the one who acted. Where the second is unresolved, the first is unresolved with it. A commander who cannot say whether M is the deployer is a commander who cannot say that M’s protection has been displaced, and that is doubt about status arriving by a route the Manual did not chart. He is to be considered a civilian.

The Tallinn Manual does not address this case anywhere. Its commentary to Rule 95 comes nearest, identifying cyber as the domain where doubt matters most and giving reasons that include the pervasiveness of civilian computer use, the conjoined character of networks, and the invisibility of individuals while they act (Rule 95, commentary para 4). Those reasons are offered to explain why doubt about status arises more often in cyber. They are not offered to raise a question about who is acting. Paragraph 5 then divides the field into status and activity and presents the division as complete. The prior question never arrives.

Macák and Pircher come at the same ground from the other side and stop in the same place. They name the root difficulty as attributing cyber operations to specific individuals, and trace two consequences from it. Targeting the person conducting a cyber attack will often be impractical in real time, a point they take from France. And cyberspace creates distinctive obstacles to determining an individual’s status or activity (at p. 12). Both consequences are stated in categories the law already recognises. The root is not. Their first consequence is a question about what is feasible, and Section V takes it up.

V. What protects the person who did not choose the risk

Article 50(1) AP I does not tell a commander who the person is. It tells him where he stands while he does not know, which is a narrower thing and a defensive one. What does the work of getting him out of that position is Article 57(2)(a)(i) AP I, and its demand is not evidentiary. He must do everything feasible to verify.

The two rules operate in series rather than together, and I have set out in my post on the presumption of civilian status why the order matters. The doubt rules engage on doubt that survives a reasonably executed verification, not on doubt the commander could have dispelled and did not. Where doubt persists because the inquiry was thin, the persisting doubt is evidence that the precautions duty has failed rather than a trigger for the protective rule. So the question a commander should be asking is not how confident he is. It is what more he could have done to verify that the objectives to be attacked are, in the words of Article 57(2)(a)(i) AP I, “neither civilians nor civilian objects” and not subject to special protection.

Feasibility has no fixed content, and the temptation to give it one should be resisted. What is feasible depends on the circumstances, and cyber cases occupy the entire range. At one end, the Tallinn Experts describe States facing situations in which they must respond within an extremely short time frame and without recourse to the full range of information available outside the cyber context (Chapter 4, Section 1, para 9). At the other, they note that a State facing merely disruptive operations may be positioned to accumulate more evidence than one suffering devastating operations and needing to act immediately to stop them (Chapter 4, Section 1, para 11). Direct participation stretches across the same range. A logic bomb emplaced now and triggered months later is not the case of an operation running against a military network this afternoon.

That variability cuts against generalisation in both directions. I have seen it suggested that cyber targeting is typically less time-constrained than a kinetic decision, and therefore that more verification is always feasible. I do not think the claim can be supported. There is no body of reported practice from which decision timelines could be drawn, which is unsurprising given that France records such targeting as marginal. The honest position is that feasibility is indexed to circumstances, and that a commander who wants to know what he owes must look at his own case rather than at a rule of thumb.

In operational terms, some things can be said about what the inquiry has to contain. The characteristic failure in identity attribution is not absence of evidence but evidence consistent with more than one person. Where the indicators available would fit an innocent explanation as readily as the working one, an inquiry that has not addressed that has not verified anything. Stolen credentials, shared infrastructure and a machine conscripted without its owner’s knowledge all produce indicators pointing at someone who did nothing. The Manual’s own example is instructive: a person whose computer has been made part of a botnet without his knowledge “is not, without more, a direct participant in hostilities”, though the computer itself may qualify as a military objective (Rule 97, commentary para 4). The machine and the person come apart, and technical attribution that reaches the first has not reached the second.

Where a reasonably executed inquiry leaves doubt standing, the commander may not attack him. That is Article 50(1) doing its work, and Section IV explained why identity doubt engages it. But the rule operates on residual doubt, not on the ordinary condition of incomplete information. A commander who has tested the alternatives, weighed indicators that conflict, and reached a reasonable conclusion about who acted has satisfied what the law asks of him. He has not reached certainty, and he was never asked to.

Nothing in this reading lowers a standard. It declines to import one. The attribution literature argues about thresholds of proof because thresholds of proof are what its own questions require. However, a percentage attached to Article 57(2)(a)(i) would not make the duty stricter. It would replace an obligation that scales with circumstances by a figure that does not, and a commander facing a fast-moving operation with thin collection would find the figure either unreachable or, worse, reachable and wrong. This is not an argument that quantified inputs have no place. Confidence levels, how long further collection would take, and error rates are exactly the kind of material a commander should be weighing. It is an argument about what the criterion of compliance is. What the rule asks is whether everything feasible was done in the circumstances, and no fixed number can answer that question for him.

The rules below the attack threshold also continue to run, and two States say so directly. Finland’s position records constant care extending to essential civilian infrastructure, civilian services and civilian data (at p. 7). Denmark states that where a cyber operation does not amount to an attack, the rules addressing conduct falling below that threshold nevertheless apply, and names the obligation of constant care among them (at p. 455). Article 57(1) AP I does not wait on the classification question I examined in my post on data as a military objective, and the practitioner consequence is that a commander uncertain whether his response crosses the attack threshold is not thereby released from precaution.

Conclusion

The difficulty of cyber attack attribution is real, and this post has not disputed it. What it disputes is the inference. A finding about what can be proved to a tribunal, or established against a State, does not decide what a commander may do. The two rules are built differently, and the difference shows most clearly in who carries the cost of an honest mistake. A State that takes a countermeasure on a careful but mistaken attribution is in breach, because the responsibility it relied on was a fact its justification required. A commander who verifies feasibly and assesses reasonably has complied, even if he was wrong, because reasonableness is what his rule asks for rather than a route to an excuse.

That allocation is not an oversight. States can wait, investigate, and decline to act. Commanders cannot set their own tempo, and a rule keyed to the correctness of an identification would stop guiding conduct rather than tightening it. The price is borne by someone who chose nothing, which is why the feasibility duty in Article 57(2)(a)(i) AP I is the operative protection rather than a formality, and why doubt that survives a real inquiry still stops the attack.

One channel of identification comes from the participant himself. In my treatment of disengagement I concluded that a deployer who cannot recall his capability must warn the adverse party and disclose what neutralises it, and that in doing so he names himself. That conclusion stands, and it is worth noticing as a route to identity that runs opposite to the forensic one. But it reaches only those who take it. The ordinary deployer stays silent, and about him it says nothing at all.

In my view one extension must be refused, and it is worth separating carefully from what the disengagement rule does say. That rule governs a person already identified as a deployer, and it holds that where disclosure is his only route out, silence does not end his participation. He stays exposed. What cannot be done is to run the rule backwards and use silence as a reason to think that someone is the deployer in the first place. Silence is the ordinary condition of every person on a network. It distinguishes nobody. A rule about what an identified participant must do to stop is not a rule about who is participating, and reading it as one would invert Article 50(1) AP I by treating the ordinary condition of civilian life as a mark against a person.

What is left is a narrower and more usable proposition. The commander’s question was never how certain he is. It is what verification his circumstances permitted, whether he tested the explanations that would exonerate the person in front of him, and whether the conclusion he reached was one a reasonable commander could reach on what he had. Attribution may be the hardest problem in the domain. It is not the question his rule asks him to answer.

About the author

With more than 25 years of experience, Andreas Leupold is a lawyer trusted by German, European, US and UK clients.

He specializes in intellectual property (IP) and IT law and the law of armed conflict (LOAC). Andreas advises clients in the industrial and defense sectors on how to address the unique legal challenges posed by artificial intelligence and emerging technologies.

A recognized thought leader, he has edited and co-authored several handbooks on IT law and the legal dimensions of 3D printing/Additive Manufacturing, which he also examined in a landmark study for NATO/NSPA.

Connect with Andreas on LinkedIn