2012International Conference on Cyber ConflictRequires access

A methodology for cyber operations targeting and control of collateral damage in the context of lawful armed conflict

Robert Fanelli, Gregory Conti

Open publisher page 17 citations

Abstract

Throughout history, the law of warfare has evolved to protect non-combatants and limit collateral damage. The same legal and ethical constraints apply to the conduct of cyber warfare, where it is similarly desirable to limit the effects of offensive actions to specific locations and groups. However, conventional wisdom suggests that this is extremely difficult, if not impossible to accomplish in the cyber domain. In this paper, we argue to the contrary. It is possible to constrain the effects of cyber actions to specifically desired, legitimate targets while significantly limiting collateral damage and injury to non-combatants. To this end we present a generalized methodology for analysis of the targeting and effects of cyber operations with respect to principles of lawful conduct in armed conflict. This methodology includes a framework of effects categories, target attributes and control measures to direct and constrain cyber operations. It also includes a process for evaluating these effects and controls against the principles for lawful conduct in armed conflict. We illustrate the methodology in action by applying it to W32. Stuxnet, software widely considered to be a cyber weapon. Our results indicate that it is entirely possible to analyze complex cyber war problems, identify legally authorized courses of action, and focus effects on desired targets while greatly minimizing collateral damage.

About this research paper

What this paper is about

Throughout history, the law of warfare has evolved to protect non-combatants and limit collateral damage. The same legal and ethical constraints apply to the conduct of cyber warfare, where it is similarly desirable to limit the effects of offensive actions to specific locations and groups. However, conventional wisdom suggests that this is extremely difficult, if not impossible to accomplish in the cyber domain. In this paper, we argue to the contrary. It is possible to constrain the effects of cyber actions to specifically desired, legitimate targets while significantly limiting collateral damage and injury to non-combatants. To this end we present a generalized methodology for analysis of the targeting and effects of cyber operations with respect to principles of lawful conduct in armed conflict. This methodology includes a framework of effects categories, target attributes and control measures to direct and constrain cyber operations. It also includes a process for evaluating these effects and controls against the principles for lawful conduct in armed conflict. We illustrate the methodology in action by applying it to W32. Stuxnet, software widely considered to be a cyber weapon. Our results indicate that it is entirely possible to analyze complex cyber war problems, identify legally authorized courses of action, and focus effects on desired targets while greatly minimizing collateral damage.

Why it matters

OpenAlex reports 17 citations for this work. Citation counts describe recorded attention and do not establish research quality.

Key contribution

A contribution statement is not available in the OpenAlex record.

Method / approach

Method details are not available in the OpenAlex metadata.

Main findings

Findings are not separately available in the OpenAlex metadata.

Limitations

Limitations are not available in the OpenAlex metadata.

Applications

Application details are not available in the OpenAlex metadata.

Available abstract

Throughout history, the law of warfare has evolved to protect non-combatants and limit collateral damage. The same legal and ethical constraints apply to the conduct of cyber warfare, where it is similarly desirable to limit the effects of offensive actions to specific locations and groups. However, conventional wisdom suggests that this is extremely difficult, if not impossible to accomplish in the cyber domain. In this paper, we argue to the contrary. It is possible to constrain the effects of cyber actions to specifically desired, legitimate targets while significantly limiting collateral damage and injury to non-combatants. To this end we present a generalized methodology for analysis of the targeting and effects of cyber operations with respect to principles of lawful conduct in armed conflict. This methodology includes a framework of effects categories, target attributes and control measures to direct and constrain cyber operations. It also includes a process for evaluating these effects and controls against the principles for lawful conduct in armed conflict. We illustrate the methodology in action by applying it to W32. Stuxnet, software widely considered to be a cyber weapon. Our results indicate that it is entirely possible to analyze complex cyber war problems, identify legally authorized courses of action, and focus effects on desired targets while greatly minimizing collateral damage.

Key concepts: Collateral damage, Offensive, Computer security, Collateral, Context (archaeology), Cyberwarfare, Action (physics), Limiting

Related papers

Back to paper searchBrowse research topicsOriginal source
A methodology for cyber operations targeting and control of collateral damage in the context of lawful armed conflict — Research Paper | ScholarLens