Public attribution in the US government: implications for diplomacy and norms in cyberspace

被引:0
|
作者
Lee, Heajune [1 ]
机构
[1] Carnegie Endowment Int Peace, Technol & Int Affairs Program, Washington, DC 20036 USA
关键词
Cybersecurity; cyber operations; cyber attribution; state responsibility; cyber norms; international norms; CYBERATTACK; LAW;
D O I
10.1080/25741292.2023.2199964
中图分类号
C93 [管理学]; D035 [国家行政管理]; D523 [行政管理]; D63 [国家行政管理];
学科分类号
12 ; 1201 ; 1202 ; 120202 ; 1204 ; 120401 ;
摘要
In recent years, states have publicly assigned responsibility for cyber incidents to state adversaries with increasing frequency. While emerging scholarship provides insight into the strategic rationale for public cyber attribution, the literature lacks a rigorous understanding of when and under what circumstances states publicly attribute cyber incidents in practice. This paper seeks to address this gap by providing an empirical study of public cyber attribution by the US government from 2010-2020. Based on an original dataset, I find that US government actors publicly attribute cyber incidents through four distinct "channels"-criminal, technical, official policy, and unofficial policy. The purpose, timing, and state subject of attribution appear to vary consistently by channel, while organizational interests and channel-specific factors shape the context in which public attribution takes place. The lack of a unified approach creates challenges for US diplomacy-as adversaries may misperceive attributions as reflecting a whole-of-government agenda-and informs the normative environment of cyber operations in ways potentially unanticipated by individual agencies.
引用
收藏
页码:198 / 216
页数:19
相关论文
共 50 条