390
Views
0
CrossRef citations to date
0
Altmetric
Research Articles

Hackers of critical infrastructure: expectations and limits of the principle of target distinction

ORCID Icon
Pages 274-293 | Received 11 Oct 2022, Accepted 29 Dec 2022, Published online: 10 Jan 2023
 

ABSTRACT

I explore reasons why existing defense has failed to prevent cyber attacks on critical infrastructure. I study one of the least studied notions of cyberspace behavior known as target distinction. Drawn from customary international law, the principle posits that states should tell their wartime targets between combatants and noncombatants and use force only toward military objects. States should not target critical infrastructure, like gas pipelines, because to do so harms civilian populations who use it.

I investigate four issues that keeps the principle from preventing attacks on critical infrastructure. The first is its inability to capture the networked nature of critical infrastructure beyond the simple dual-use (military and cyber) purposes. The second defect is the interpretive confusion that the principle generates over the rules of engagement. The third problem is the omission from its coverage of actors other than nation states. By design, the principle condones cyber attacks by nonstate actors on infrastructure, or by those whose linkage to state sponsors cannot be legally established. Finally, the principle is prone to fail when hackers lack proper understanding of what it does and does not allow.

Acknowledgments

I presented an early version of this article at the 2022 annual meeting of the International Studies Association in Nashville. I thank Michael Poznansky for constructive comments and Saint Louis University College of Arts and Sciences and the Department of Political Science for financial support on this research.

Disclosure statement

No potential conflict of interest was reported by the author(s).

Notes

1 I thank one of the reviewers for raising this important point.

2 I thank one of the reviewers for this comment.

3 Gallais and Filiol, “Critical Infrastructure,” pp. 80-87. The surveyed entities are Argentina, Asia-Pacific Telecommunity, Australia, Austria, Belgium, Brazil, Canada, Chile, Czech Republic, Denmark, Estonia, EU, Finland, France, Germany, Greece, Hungary, Iceland, India, Ireland, Italy, Japan, Kenya, Latvia, Lithuania, Luxembourg, Mauritius, Malaysia, Mexico, NATO, the Netherlands, New Zealand, Norway, Poland, Portugal, Romania, Russia, Singapore, Slovakia, Slovenia, Spain, Sweden, Switzerland, UK, and USA.

4 Schmitt, Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations, p. 420.

5 Article 24(2) of the draft Additional Protocol II.

6 Claudia Saladin, “Precautionary Principle in International Law,” International Journal of Occupational and Environmental Health, Vol. 6, No. 4 (2000).

7 Schmitt, Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations, p. 11.

8 Schmitt, Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations, p. 348.

9 Schmitt, Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations, p. 470.

10 Schmitt, Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations, p. 30.

Additional information

Funding

This work was supported by the College of Arts and Sciences, Saint Louis University.

Log in via your institution

Log in to Taylor & Francis Online

PDF download + Online access

  • 48 hours access to article PDF & online version
  • Article PDF can be downloaded
  • Article PDF can be printed
USD 53.00 Add to cart

Issue Purchase

  • 30 days online access to complete issue
  • Article PDFs can be downloaded
  • Article PDFs can be printed
USD 878.00 Add to cart

* Local tax will be added as applicable

Related Research

People also read lists articles that other readers of this article have read.

Recommended articles lists articles that we recommend and is powered by our AI driven recommendation engine.

Cited by lists all citing articles based on Crossref citations.
Articles with the Crossref icon will open in a new tab.