Site navigation

Do State-Sponsored Cyber Attacks Warrant a Digital Geneva Convention?

Chloe Henderson

,

Conflicts between nations have taken on a new dimension as state-sponsored cyber-attacks open up cyberspace as a new and global battlefield.

Recent escalations in cyber warfare, such as the alleged Russian hacking of the Democratic National Convention, have resulted in an erosion of trust between businesses, governments, and their citizens.

Such is the opinion of Brad Smith, President and Chief Legal Officer to Microsoft, who is calling for the creation of a “Digital Geneva Convention” regulating the use of cyber warfare.

In a blog post penned last Tuesday, Smith urged the world’s governments to come together in the creation of an international regulatory body committed to protecting private citizens against state-sponsored cyber attacks.

The Geneva Convention as we know it today was introduced by war-weary nations in 1949 to protect civilians in times of war. The Microsoft head is now arguing for a digital equivalent, claiming that state-sponsored hacking attacks are being carried out against civilians in times of peace.

In the past year alone there has been a proliferation in “new and disconcerting” state-sponsored cyber attacks, and ordinary internet users are getting caught up in the crossfire.

“Cyberspace in fact is produced, operated, managed and secured by the private sector,” Smith wrote. “Governments obviously play all sorts of critical roles, but the reality is that the targets in this new battle – from submarine cables to datacenters, servers, laptops and smartphones – in fact are private property owned by civilians.”

According to Smith, the time has come for the world’s governments to unite in affirming a binding set of international cybersecurity laws. They would forbid nation-states from targeting technology companies, the private sector, or any critical infrastructure, and would also require them to assist the private sector in detecting, containing, responding to, and recovering from cyber crime.

It’s not only governments that need to address the issue. Smith also emphasised the need for the technology sector to act collectively as a “neutral Digital Switzerland,” protecting their customers from state-sponsored attacks.

“As the first responders to threats that in part target our own infrastructure, it’s important for global technology companies to adopt concrete commitments to help deter and respond to nation-state cyberattacks. As the Fourth Geneva Convention relies on the Red Cross to help protect civilians in wartime, protection against nation-state cyberattacks requires the active assistance of the tech sector.”

The commitments would include a pledge to never assist in offensive actions, even if asked to do so by national leaders. They would also urge companies to work together in supporting international defensive efforts.

In return, they would benefit from the regulation of a form of warfare that often views them as the targets.

Smith revealed that 74% of the world’s businesses expect to be hacked every year, with the economic loss as a result of cybercrime estimated to reach $3 trillion by 2020. Whilst many of these attacks are carried out by unaffiliated organisations and individuals, an increasing number of them have state-sponsored origins.

In 2014 Sony Pictures was targeted in a high profile cyber attack allegedly conducted by North Korea. The hack saw private employee information, emails between employees, and copies of then-unreleased Sony films leaked online. In the previous year, the Yahoo accounts of one billion users were compromised in an attack that the company has claimed was state-sponsored.

Subsequently, Smith believes that the creation of a global regulatory body limiting the use of cyber warfare is of as equal importance to the technology sector as it is to private citizens.

But in order to have any real impact, technology companies need to work together rather than attempt to tackle the problem on their own.

“Across the tech sector, companies are racing to provide stronger cybersecurity protection for customers, including from nation-states,” Smith wrote. “Each of our advances is making an important contribution. But we’re nowhere close to being able to declare victory. Governments are increasing their investments in offensive cyber capabilities. We therefore need to recognize a critical truth – this is not a problem that we can solve solely with each of us acting alone.”

Smith’s vision for a Digital Geneva Convention is spearheaded by the hope that world governments can be persuaded to build upon existing cybersecurity legislation.

In July 2015 governmental experts from 20 nations endorsed cybersecurity norms for nation-states “aimed at promoting an open, secure, stable, accessible and peaceful ICT environment.” In September of the same year, the United States and China pledged that neither country’s government would conduct or support cyber-attacks that enabled theft of intellectual property.

Whilst examples of progress are encouraging, several important obstacles stand in the way of globally endorsed cyber warfare regulation.

One of the most significant is the fact that cyber warfare is too valuable a tool for nation-states to forsake. As a cheaper, more low risk, and more difficult-to-trace alternative to traditional methods of diplomacy and intelligence gathering, the benefits vastly outweigh the drawbacks.

Past incidences of cyber warfare have also proved that it is an extremely effective method of conducting foreign and domestic policy.

The most notable and recent example was the alleged hacking of the Democratic National Convention by Russia towards the end of last year. In 2010 the United States also made headlines for after deploying a Stuxnet worm attack against Iran, successfully causing disruption to the nation’s nuclear programme. The UK government is also alleged to have hacked into undersea cables owned by Google and Yahoo as part of its mass surveillance programme. State-sponsored cyber hacking is a tried and tested method that has reaped rewards for governments in the past.

The establishment of Digital Geneva Convention is further hindered by the fact that correctly attributing cyber attacks is often a complicated process. It is extremely difficult to distinguish state sponsored attacks from those carried out by organisations, particularly when nation-states solicit freelance hackers to carry them out. If an attack cannot be attributed with 100% certainty, then a state cannot be held accountable by a global body. This could potentially undermine the purpose of common cybersecurity law – if a nation cannot be held accountable then it cannot be punished, meaning that there is little to fear from violating any convention.

World governments aren’t alone in hindering the process: the interests of the private sector could also make a “Digital Geneva Convention” hard to achieve.

Speaking to CBS News about Smith’s suggestions, CNET Senior Editor Dan Ackerman acknowledged that whilst the technology sector recognised the need for a new approach to cybersecurity, a Digital Geneva Convention required an unrealistic level of cooperation.

He said: “Everybody knows that something has to be done, but whatever this is – it’s very tough to get everybody on board with something like this… It’s a very expansive ask.”

But in opposition to his claims, Smith does provide substantial evidence to suggest that the technology sector is already moving towards greater collaboration. In his blog he references recent debates over immigration in the United States, citing it as at least once example of an issue that successfully united the technology sector.

“The recent debates about immigration have brought to the surface an important truth.” He wrote. “As an industry, the tech sector has literally brought the world together under its own roof… As an industry, we’ve brought people together in ways that can promote mutual understanding and respect. We need to harness this global understanding to protect people everywhere, earning their confidence as the world’s Digital Switzerland.”

Chloe Henderson

Staff Writer - DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data