As cyberattacks against critical infrastructure become increasingly frequent, third-party countermeasures in cyberspace have emerged as a major subject of debate in international legal scholarship. Third-party countermeasures refer to measures taken b...
As cyberattacks against critical infrastructure become increasingly frequent, third-party countermeasures in cyberspace have emerged as a major subject of debate in international legal scholarship. Third-party countermeasures refer to measures taken by states other than the injured state against the responsible state. In the context of cyberspace, they could provide an international legal basis for cyber-capable third states to employ cyber means such as hack-back to terminate cyberattacks on behalf of injured states lacking technical capacity. However, the 2001 ILC Draft Articles on Responsibility of States for Internationally Wrongful Acts did not clearly establish whether third-party countermeasures are permissible.
The essential requirement for third-party countermeasures is the breach of obligations erga omnes. Since the ICJ first articulated the concept of obligations erga omnes in the Barcelona Traction case (1970), it has confirmed that the prohibition of aggression and genocide constitute such obligations. Analysis of state practice reveals that states have employed third-party countermeasures-including asset freezes and trade restrictions-to halt violations or secure reparation when obligations such as the prohibition of aggression or genocide have been breached. This demonstrates that third-party countermeasures in response to breaches of obligations erga omnes are permissible as customary international law.
Cyberspace possesses distinctive characteristics, including interconnectivity among states, technological disparities, and difficulties in legal attribution. Hack-back, as a form of active cyber defense measure aimed at neutralizing the source of cyberattacks, can be considered a type of countermeasure. However, existing international legal cooperation mechanisms are inadequate for responding such cyberattacks. The doctrine of proxy countermeasures, which would permit countermeasures even for breaches of bilateral obligations rather than obligations erga omnes, lacks sufficient legal foundation due to inconsistency with the existing international legal framework and insufficient state practice.
Examination of obligations erga omnes that could be breached through cyberattacks reveals that the prohibitions of use of force and threat of force, as well as the prohibition of genocide, are unlikely to be violated by peacetime cyberattacks. For a cyberattack to constitute a use of force, it must possess scale and effects comparable to physical use of force, yet most cyberattacks fall short of this threshold. The due diligence obligation, which requires territorial states to prevent harm to other states, applies in cyberspace but cannot yet be considered an obligation erga omnes with respect to cyberattacks.
The UN, through its GGE reports, has articulated non-binding cyber norms for critical infrastructure protection, including prohibition of attacks against critical infrastructure, protection of domestic critical infrastructure, due diligence obligations to protect other states’ critical infrastructure, and cooperation obligations in case of harm. While these non-binding norms cannot yet be regarded as binding international law, the EU, ASEAN, OAS and other organizations recognize critical infrastructure protection as a common interest.
Accordingly, this dissertation explores a treaty framework for international cyber cooperation and response to protect critical infrastructure. The proposed treaty stipulates that territorial states bear due diligence obligations to prevent critical infrastructure attacks originating from their territory and must accept intervention by assisting states. This recognizes the difficulty of attribution under the law of state responsibility in cyberspace, permitting assisting states to conduct hack-back operations within the territorial state's territory upon request from the injured state. Furthermore, assisting states would have the right to take enforcement measures at the request of injured states. The term “enforcement measures” is adopted to avoid the contentious nature of third-party countermeasures in cyberspace and emphasize that these are cooperative measures for treaty implementation. Key requirements include the injured state's request, substantial harm to critical infrastructure, and breach of the territorial state's due diligence obligations. The harm assessment criteria propose a multi-layered standard comprehensively considering the degree of critical infrastructure function disruption, affected population size, duration of harm, and restoration costs. Additionally, the treaty proposes arranging of conciliation commission and arbitral tribunal to perform roles including harm assessment, determination of due diligence compliance, and dispute resolution.
This treaty framework enhances legal predictability by converting third-party countermeasures-which can only be exercised upon meeting the strict criterion of breach of obligations erga omnes-into enforcement measures based on clear treaty-based rights and obligations. It establishes critical infrastructure protection as an obligation erga omnes partes among state parties, presents realistic solutions considering the difficulty of cyberattack attribution, provides cooperation mechanisms to address injured states’ technical capacity deficiencies, and mitigates the risks of self-help through institutionalized dispute resolution mechanisms.