La guerre par le biais de la communication
Contenu de la nouvRICR
Computer network
attack and
jus in belloby
Michael N. Schmitt
thereof, of a “revolution in military affairs”, it is undeniable
that twenty-first century warfare will differ dramatically
from that which characterized the twentieth century.
The tragic terrorist attacks of 11 September 2001 and their
aftermath are dominating the headlines at the beginning of the new
century. Perhaps equally remarkable will be the maturing of “information
warfare” as a tool of combat.
on the waging of war, necessitate a revised concept of battle space and
expand the available methods and means of warfare. Of particular note
will be the impact of information warfare on the principles of international
humanitarian law — and vice versa.
In brief, information warfare is a subset of information
operations, i.e. “actions taken to affect adversary information and
information systems while defending one’s own information and
information systems”.
measures intended to discover, alter, destroy, disrupt or
transfer data stored in a computer, manipulated by a computer or
transmitted through a computer.They can occur in peacetime, during
Professor of International Law, and Director, Executive Program in International and Security Affairs at George C. Marshall European Center for Security Studies, Garmisch-Partenkirchen, Germany.
and Security Affairs at George C. Marshall European Center for Security Studies,
Garmisch-Partenkirchen, Germany.
crises, or at the strategic, operational or tactical levels of armed conflict.
affected or protected — information.
Information warfare is narrower. It consists of “information
operations conducted during time of crisis or conflict to achieve
or promote specific objectives over a specific adversary or adversaries”.
Information operations are distinguished by that which is4
by the context in which it occurs — crisis or conflict. Routine
Thus information warfare is differentiated from other operations1 The United States National Military
Strategy cites information superiority as a
key element of its strategy for this century.
“Information superiority is the capability to
collect, process, and disseminate an uninterrupted
flow of precise and reliable information,
while exploiting and denying an adversary’s
ability to do the same.” Joint Chiefs of
Staff, National Military Strategy (1997),
3 At the strategic level, information operations
can be employed to “achieve national
objectives by influencing or affecting all elements
(political, military, economic, or informational)
of an adversary’s or potential adversary’s
national power while protecting similar
friendly elements”. At the operational level,
the focus of information operations is “on
affecting adversary lines of communication
(LOCs), logistics, command and control (C2),
and related capabilities and activities while
protecting similar friendly capabilities and
activities”. Finally, at the tactical level the
objective is to affect adversary “information
and information systems relating to C2, intelligence,
and other information-based processes
directly relating to the conduct of military operations...”.
JP 3-13,
4 JP 1-02,
Wired warfare: Computer network attack and jus in bellopeacetime espionage is, for example, an information operation that
does not constitute information warfare unless conducted during a
crisis or hostilities.
Computer network attacks (CNA), which may amount to
information warfare or merely information operations, are “operations
to disrupt, deny, degrade, or destroy information resident in computers
and computer networks, or the computers and networks themselves”.
5The essence of CNA is that, regardless of the context in which it
occurs, a data stream is relied on to execute the attack.
6 Thus, the meansused set CNA apart from other forms of information operations.
These means vary widely.They include,
computer system so as to acquire control over it, transmitting viruses
to destroy or alter data, using logic bombs that sit idle in a system until
triggered on the occasion of a particular occurrence or at a set time,
inserting worms that reproduce themselves upon entry into a system
and thereby overloading the network, and employing sniffers to monitor
and/or seize data.
This article addresses the use of CNA during
inter alia, gaining access to ainternationalarmed conflict and is limited to consideration of
jus in bello, that body5
Juin IRRC June 2002 Vol. 84 No 846 367of law concerned with what is permissible, or not, during hostilities,
irrespective of the legality of the initial resort to force by the belligerents.
of “State-on-State” armed conflict. Moreover, the article is an effort to
setting forth
warfare evolves,
existing humanitarian law to computer network attack, and identify
any prescriptive lacunae that may exist therein.
Discussion therefore centres on the use of CNA in the contextlex lata, rather than an exercise in considering lex ferenda.Whilelex ferenda is an especially worthy project as the nature of8 the goal here is simply to analyse the applicability ofApplicability of humanitarian law to
computer network attacks
The threshold question is whether computer network
attack is even subject to humanitarian law.To begin with, there is no
provision in any humanitarian law instrument that directly addresses
CNA, or, for that matter, information warfare or information operations;
this might suggest that CNA is as yet unregulated during armed
conflict. Additionally, it could be argued that the development and
employment of CNA postdates existing treaty law and thus, having not
been within the contemplation of the parties to those instruments, is
exempt from the coverage thereof.A third possible argument for inapplicability
is that humanitarian law is designed for methods and means
that are kinetic in nature; since there is little that is “physical” in CNA,
attacks by computers fall outside the scope of humanitarian law.
Wired warfare: Computer network attack and jus in belloIn other words, humanitarian law applies to armed conflict, and computer
network attack is not “armed”.
The first two possibilities are easily dispensed with. The
fact that existing conventions are silent on CNA is of little significance.
First, the Martens Clause, a well-accepted principle of humanitarian
law, provides that whenever a situation is not covered by an
international agreement, “civilians and combatants remain under the
protection and authority of the principles of international law derived
from established custom, from the principles of humanity, and from the
dictates of public conscience.”
armed conflict are subject to application of humanitarian law principles;
there is no lawless void. The acceptance of “international custom”
as a source of law in Article 38 of the Statute of the International
Court of Justice also demonstrates the fallacy of any contention of
inapplicability based on the absence of specific
Juin IRRC June 2002 Vol. 84 No 846 369Wired warfare: Computer network attack and jus in belloArguments focusing on the fact that CNA postdates present
prescriptive instruments are similarly fallacious. Precisely this line
of reasoning was presented to the International Court of Justice in
Legality of the Threat or Use of Nuclear Weapons
the Court summarily rejected the assertion that because humanitarian
“principles and rules had evolved prior to the invention of nuclear
weapons”, humanitarian law was inapplicable to them. As the Court
noted, “[i]n the view of the vast majority of States as well as writers
there can be no doubt as to the applicability of humanitarian law to
nuclear weapons”.
computer weapons, at least on the basis of when they were developed
vis-à-vis the entry into force of relevant humanitarian law norms, the
same conclusion applies to CNA. Furthermore, a review of new
weapons and weapon systems for compliance with humanitarian law is
a legal, and often a policy, requirement.
so if pre-existing law were inapplicable,
and means of warfare.
This analysis leaves only the third argument for inapplicability
of humanitarian law to computer network attack — that it is not
. In its advisory opinion,12 There being no reason to distinguish nuclear from13 Obviously, this would not beab initio, to nascent methodsarmed
fact, armed conflict is the condition that activates
common to the four 1949 Geneva Conventions provides that they
apply, aside from specific provisions that pertain in peacetime, “to all
cases of declared war or of any other
conflict, at least not in the absence of conventional hostilities. Injus in bello.Article 2armed conflict which may arise12
between two or more of the High Contracting Parties, even if the state of war is not recognized by one of them".
of war is not recognized by one of them”.
Protocol I, which, like the Conventions pertains to international
armed conflict, adopts the same “armed conflict” standard, one that has
become an accepted customary law threshold for humanitarian law.
14 The 1977 Additional15The fact that the 1977 Additional Protocol II also embraces the term
“armed conflict”,
conflict, demonstrates that armed conflict is a condition determined
by its nature rather than its participants,
formerly the case with “war”, by the belligerents’ declaration thereof.
16 albeit in the context of non-international armed17 by its location18 or, as was19It seems relatively clear, then, that humanitarian law is
activated through the commencement of armed conflict. But what is
armed conflict? Commentaries published by the International
Committee of the Red Cross on the 1949 Geneva Conventions and
the 1977 Additional Protocols take a very expansive approach towards
Juin IRRC June 2002 Vol. 84 No 846 371Wired warfare: Computer network attack and jus in bellothe meaning of the term.The former define armed conflict as “[a]ny
difference arising between two States and leading to the
armed forces
of war. It makes no difference how long the conflict lasts, or how
much slaughter takes place.”
Additional Protocol I specifies that “humanitarian law… covers any
dispute between two States involving the
Neither the duration of the conflict, nor its intensity, play a role…”.
intervention of… even if one of the Parties denies the existence of a state20 Similarly, the Commentary onuse of their armed forces.21That on Additional Protocol II describes armed conflict as “the existence
of open
greater or lesser degree”.
commitment of armed forces.
But a dispute or difference resulting in the engagement of
armed forces cannot be the sole criterion. Military forces are used on
a regular basis against adversaries without necessarily producing a state
of armed conflict — consider aerial reconnaissance/surveillance operations
as just one example. Furthermore, it is now generally accepted
that isolated incidents such as border clashes or small-scale raids do not
reach the level of armed conflict as that term is employed in humanitarian
of publicists, illustrates that Additional Protocol I’s dismissal of intensity
and duration has proven slightly overstated.
Instead, the reference to armed forces is more logically
understood as a form of prescriptive shorthand for activity of a particular
nature and intensity. At the time when the relevant instruments
were drafted,
Juin IRRC June 2002 Vol. 84 No 846 373Wired warfare: Computer network attack and jus in belloself-defence; nevertheless, as long as the actions were intended to
injure, kill, damage or destroy, humanitarian law governs them. It
should be noted that given the current weight of opinion, actions that
are sporadic or isolated in nature would not suffice. Additionally,
because the issue is the law applicable to international armed conflict,
the relevant actions must be attributable to a State.
26Returning to the topic at hand, and quite aside from
ad bellumissues, humanitarian law principles apply whenever computer network
attacks can be ascribed to a State are more than merely sporadic
and isolated incidents and are either intended to cause injury, death,
damage or destruction (and analogous effects), or such consequences
are foreseeable. This is so even though classic
employed. By this standard, a computer network attack on a large airport’s
air traffic control system by agents of another State would implicate
humanitarian law. So too would an attack intended to destroy oil
pipelines by surging oil through them after taking control of computers
governing flow,
of its computerized nerve centre, or using computers to trigger a
release of toxic chemicals from production and storage facilities. On the
other hand, humanitarian law would not pertain to disrupting a university
intranet, downloading financial records, shutting down Internet
access temporarily or conducting cyber espionage, because, even if part
of a regular campaign of similar acts, the foreseeable consequences
would not include injury, death, damage or destruction.
It should be apparent that, given advances in methods and
means of warfare, especially information warfare, it is not sufficient to
apply an actor-based threshold for application of humanitarian law;
instead, a consequence-based one is more appropriate.This is hardly a
jurisprudential epiphany. No one would deny, for instance, that biological
or chemical warfare (which does not involve delivery by a kinetic
is also supported by the fact that once armed conflict has commenced
(and except for prohibitions relevant to particular weapons),
the means by which injury, death, damage or destruction are produced
have no bearing on the legality of the causal act. Intentionally targeting
a civilian or other protected persons or objects is unlawful irrespective
of the method or means used. Starvation, suffocation, beating,
shooting, bombing, even cyber attack — all are subject to humanitarian
law owing to the fact that a particular consequence results.That
this is so counters any assertion that, standing alone, cyber attacks are
not subject to humanitarian law because they are not “armed” force.
On the contrary, they may or may not be, depending on their nature
and likely consequences.
Computer network attack targets
As has been discussed, computer network attacks are subject
to humanitarian law if they are part and parcel of either a classic
conflict or a “cyber war” in which injury, death, damage or destruction
are intended or foreseeable. This being so, it is necessary to consider
the targets against which computer network attacks may be directed.
A useful starting point is to frame the conduct that is subject
to the prescriptive norms governing targeting. Because most relevant
Additional Protocol I provisions articulate standards applicable to
Parties and non-Parties (as a restatement of binding customary law)
alike, that instrument serves as an apt point of departure.
the basic rule governing the protection of the civilian population, provides
that “Parties to the conflict… shall direct their operations only
Juin IRRC June 2002 Vol. 84 No 846 375Wired warfare: Computer network attack and jus in belloagainst military objectives”.
rule out
than purely military objectives. In fact, it does not. In subsequent articles,
proscriptions are routinely expressed in terms of “attacks”.Thus,
“the civilian population as such, as well as individual civilians, shall not
be the object of attack”;
limited strictly to military objectives”;
expressly defined in Article 49: “’Attacks’ means acts of violence
against the adversary, whether in offence or in defence.” As a general
matter then, the prohibition is not so much on targeting non-military
objectives as it is on
This interpretation is supported by the text of Article 51, which
sets forth the general principle that the “civilian population and individual
civilians shall enjoy general protection against
from military operations” and prohibits “acts or threats of
primary purpose of which is to spread terror among the civilian
29 At face value,Article 48 would seem toany military operation, including CNA, directed against other30 “civilian objects shall not be the object of31 “indiscriminate attacks are forbidden”;32 “attacks shall be33 and so forth. The term isattacking them, specifically through the use of violence.dangers arisingviolence the29 Additional Protocol I,
Wired warfare: Computer network attack and jus in belloterms of “severe losses among the civilian population”
be excessive in relation to the concrete and direct military advantage
anticipated”. Furthermore, during negotiations on Additional Protocol
I, the issue of whether laying landmines constituted an attack arose.
Most agreed that it did because “there is an attack whenever a person
is directly endangered by a mine laid”.
attack which foreseeably endangers protected persons or property
would amount to an attack.
Let us return now to Article 48. In the context of computer
network attack, and as a general rule (various other specific prohibitions
are discussed below), the article would ban those CNA operations
directed against non-military objectives that are intended to, or
would foreseeably, cause injury, death, damage or destruction. Unless
otherwise prohibited by specific provisions of humanitarian law,CNA
operations unlikely to result in the aforementioned consequences are
permissible against non-military objectives, such as the population.
39 which “would40 By analogy, a computer network41As a result of this distinction, the need to carefully assess whether or
not an information warfare operation is or is not an “attack” is greatly
heightened. In the past, analysis of this matter approximated to a
ipsa loquitor
traditional military operations, thereby demanding a more challenging
consequence-based consideration.
While CNA does dramatically expand the possibilities for
“targeting” (but not attacking) non-military objectives, it is unfair to
characterize this as a weakening of the prescriptive architecture.
Instead, it simply represents an expansion of permissible methods and
means resulting from advances in technology; existing norms remain
intact. Recall, for example, that psychological operations directed
against the civilian population that cause no physical harm are entirely
permissible, so long as they are not intended to terrorize.
resapproach. However, CNA is much more ambiguous than42 This is so39
Nevertheless, although the objective regime is a constant, the advent of
CNA reveals a normative lacuna that, unless filled, will inevitably result
in an expansion of war’s impact on the civilian population.
Assuming that a CNA operation is an “attack,” what can
be targeted? Analytically, potential targets can be classified into three
broad categories: 1) combatants and military objectives; 2) civilians and
civilian objects; and 3) dual-use objects. Moreover, particular types of
potential targets enjoy specific protection. It is useful to address each
grouping separately.
Combatants and military objectives
Combatants and military objectives are by nature valid targets
and may be directly attacked as long as the method and means
used, as discussed in the next section, are consistent with humanitarian
law restrictions.Those who plan or decide on attacks have an affirmative
duty to “do everything feasible” to verify that intended targets are
legitimate, i.e. that they do not enjoy immunity from attack under
humanitarian law.
43A combatant is a member of the armed forces other than
medical personnel and chaplains; armed forces include “all organized
43 Additional Protocol I,
Juin IRRC June 2002 Vol. 84 No 846 379Wired warfare: Computer network attack and jus in belloarmed forces, groups and units which are under a command responsible
to [a Party to the conflict] for the conduct of its subordinates…
[They must] be subject to an internal disciplinary system which,
applicable in armed conflict”.
against combatants, for instance by causing a military air traffic control
system to transmit false navigational information in order to cause a
military troop transport to crash, is clearly permissible.
Military objectives are defined in Article 52 of Additional
Protocol I as “those objects which by their nature, location, purpose or
use make an effective contribution to military action and whose total
or partial destruction, capture or neutralization, in the circumstances
ruling at the time, offers a definite advantage”.
and facilities, other than medical and religious items, are clearly military
objectives, and thereby subject to direct computer network attack.
However, determining which objects are military objectives beyond
these obvious exemplars is often difficult.
the required nexus between the object to be attacked and military
The crux of the dilemma is interpretation of the terms
“effective” and “definite”. Some, such as the International Committee
of the Red Cross (ICRC), define them very narrowly. According to
the ICRC Commentary on the Protocol, effective contribution
includes objects “directly used by the armed forces” (e.g.weapons and
equipment), locations of “special importance for military operations”
(e.g. bridges), and objects intended for use or being used for military
excludes attacks that offer only a “potential or indeterminate” advantage.
inter, shall enforce compliance with the rules of international law44 Directing computer network attacks45 Military equipment46 The problem lies in ascertaining47 As to “definite military advantage”. the Commentary48
Juin IRRC June 2002 Vol. 84 No 846 381Wired warfare: Computer network attack and jus in bellonegative publicity, as well as the litigation in the European Court of
Human Rights.
50Civilians and civilian objects
Civilians are those persons who are not considered combatants,
whereas a civilian object is one that is not a military objective.52
nearly absolute. Specifically,Additional Protocol I stipulates:
Article 51(2) “The civilian population as such, as well as individual
civilians shall not be the object of attack. Acts or threats of
violence the primary purpose of which is to spread terror
among the civilian population are prohibited.”
Article 52 “Civilian objects shall not be the object of attack or of
The prohibition on attacking civilians and civilian objects is53Doubts as to the character of an object or individual are to
be resolved in favour of a finding of civilian status.
of computer network attack, the threshold question is whether or not
the attack is intended to, or foreseeably will, cause injury, death, damage
or destruction; if so, the prohibitions set forth earlier, which undeniably
restate existing customary law, apply.
Unfortunately, the norms, albeit clear at first sight, are subject
to interpretative difficulties. The differing standards for distinguishing
civilian objects from military objectives have already been
highlighted. Similar disparities exist with regard to when a civilian
may be attacked. Additional Protocol I allows for this possibility only
54 Again, in the case50
Czech Republic, Denmark, France, Germany,
Greece, Hungary, Iceland, Italy, Luxembourg,
the Netherlands, Norway, Poland, Portugal,
Spain, Turkey and the United Kingdom
App. No. 52207/99 (2001). In its decision of
12 December 2001, the Court found the application
Juin IRRC June 2002 Vol. 84 No 846 383in the case of a civilian taking a “direct part in hostilities”, a standard
described in the Commentary as “acts of war which by their nature or
purpose are likely to cause actual harm to the personnel or equipment
of the enemy armed forces”.
Some would limit civilian immunity even more severely by, for
instance, characterizing mission-essential civilians working at a base
during hostilities, though not engaged directly in acts of war, as legitimate
55 This is the illegal combatant problem.56In the context of information operations, the civilian issue
is an important one. Some countries have elected to contract out
information warfare functions, whether those functions involve the
maintenance of assets or the conduct of operations. Moreover, computer
network attack is a function that may be tasked to government
agencies other than the military. In the event of civilian contractors or
non-military personnel being in a support role that is essential to the
conduct of operations, for instance maintaining CNA equipment, by
the latter interpretation they would be directly targetable. Further,
because they are valid targets, any injury caused them would not be
calculated when assessing whether an attack is proportional (see discussion
above). On the other hand, narrowly applying the “direct part
in hostilities” standard would preserve the protection they enjoy as
civilians, though if captured they would be entitled to prisoner-of-war
status as persons “accompanying the armed forces”.
57Should civilians engage in a computer network attack
themselves, the problem becomes more complex. If the CNA results,
or foreseeably could result, in injury, death, damage or destruction,
then the “perpetrators” would be illegal combatants. This status
attaches because they have taken a direct part in hostilities without
complying with the criteria for characterization as a combatant. As
illegal combatants, they may be directly attacked, any injury suffered
by them would be irrelevant in a proportionality calculation, and in
Wired warfare: Computer network attack and jus in bellothe event of their capture they would not be entitled to prisoner-ofwar
Conversely, if the civilians involved were conducting computer
network operations that did not reach the level of “attacks”, they
would not be illegal combatants because they would have committed
no “acts of war that by their nature or purpose are likely to cause
actual harm to the personnel or equipment of the enemy armed
forces”. Their civilian status and its corresponding protections would
remain intact. Nevertheless, as with support personnel, if attached to a
military unit and accompanying that unit these civilians would be
classed as prisoners of war.
being used to conduct the operations might well be valid military
objectives and, as a result, be subject to attack; but the operators themselves
could not be directly attacked.
As should be apparent, the use of civilians, whether contractors
or government employees, is fraught with legal pitfalls. Clearly,
a prudent approach would be to employ military personnel for information
warfare purposes.
58 Of course, the facility and equipmentDual-use objects
A dual-use object is one that serves both civilian and military
purposes. Examples of common dual-use objects (or objectives)
include airports, rail lines, electrical systems, communications systems,
factories that produce items for both the military and the civilian population
and satellites such as INTELSAT, EUROSAT and ARABSAT,
etc. If an object is being used for military purposes, it is a military
objective vulnerable to attack, including computer network attack.This
is true even if the military purposes are secondary to the civilian ones.
Several caveats are in order. First, whether or not an object
is a military objective may turn on whether the narrow or broad definition
of the term, a matter discussed above, is used. Second, whether
an object is dual-use, and therefore a military objective,will depend on
the nature of the specific conflict.An airfield may be utilized for logistics
purposes in one conflict, but serve no military function in another.
, Art. 56(2).Ibid., Art. 54(2). See also Rome Statute,op. cit.
(note 53), Art. 8(2)(b)(xxv).Third, an object that has the potential for military usage, but is currently
used solely for civilian purposes, is a military objective if the likelihood
of military use is reasonable and not remote in the context of
the particular conflict under way. Finally, dual-use objects must be carefully
measured against the requirements of discrimination and proportionality,
discussed above, because by definition an attack thereon risks
collateral damage and incidental injury to civilians or civilian objects.
Specifically protected objects
In addition to the general rules regarding the protection of
the civilian population, certain objects enjoy specific protection. A
controversial category of specially protected objects is dams, dykes and
nuclear electrical generating stations. Because of their reliance on
computers and computer networks, such facilities are especially vulnerable
to CNA. Article 56 of Additional Protocol I, a provision
opposed by the United States, forbids an attack on these facilities if the
attack might “cause the release of dangerous forces [e.g. water or
radioactivity] and consequent severe losses among the civilian population”.
Interestingly, CNA offers a fairly reliable means of neutralizing such
facilities without risking the release of dangerous forces, a difficult task
when using kinetic weapons.
Conducting attacks that starve the civilian population or
otherwise deny it “indispensable objects”,
This prohibition applies even if they are military objectives.60 even if enemy armed386
Wired warfare: Computer network attack and jus in belloforces are the intended “victims”, is prohibited.
include such items as foodstuffs, crops, livestock or drinking water.
Under this restriction, computer network attacks against, for instance,
a food storage and distribution system or a water treatment plant serving
the civilian population would not be permissible even if military
forces also rely on them.
Additional Protocol I furthermore prohibits military
operations likely to cause widespread, long-term and severe damage to
the environment,
provision as a restatement of customary law. Computer network
attacks might conceivably cause such devastation. An attack on a
nuclear reactor could result in a meltdown of its core and consequent
release of radioactivity. Similarly, CNA could be used to release chemicals
from a storage or production facility or rupture a major oil
pipeline. Many other possibilities for causing environmental damage
through CNA exist. It is important to note that the prohibition applies
regardless of whether or not the attack is targeted against a valid military
objective and even if it complies with the principle of proportionality.
Once the requisite quantum of damage is expected to occur,
the operation is prohibited.
Finally, it must be noted that there are a number of other
objects, persons and activities that enjoy special protected status and
are susceptible to computer network attack, but do not present unique
CNA opportunities or challenges.These should be handled during the
targeting cycle in the same manner as they would be in the planning
Juin IRRC June 2002 Vol. 84 No 846 38763 For example, military and civilian medical
units and supplies are exempt from attack
unless being used for military purposes.
Additional Protocol I,
There are specific criteria for the extension of
protection to civilian facilities.
See also Rome Statute,
Art. 8(2)(b)(ix) and (xxv). Medical transport
enjoys similar protection. Additional Protocol
varies, depending on the category of
transportation and its location. Other objects
enjoying protection include cultural objects,
places of worship and civil defence shelters,
facilities and material.
62(3). In addition, humanitarian relief activities
must not be interfered with.
Special provisions as to when such operations
are entitled to the protection apply. Rome
these prohibitions, for example, a computer
network attack to alter blood type information
in a hospital’s data bank, deny power to a
bomb shelter or oemisroute humanitarian
relief supplies would all be unlawful. Of
course, misuse of protected items or locations
for military purposes renders them valid military
objectives that may be attacked.
64 Reprisals are otherwise unlawful actions
taken during armed conflict in response to an
adversary’s own unlawful conduct. They must
be designed solely to cause the adversary to
act lawfully, be preceded by a warning (if feasible),
be proportionate to the adversary’s violation,
and cease as soon as the other side
complies with the legal limitations on its
conduct. The right to conduct reprisals has
been severely restricted in treaty law, much of
which expresses customary law. There are specific
prohibitions on reprisals conducted
against civilians; prisoners of war; the
wounded, sick and shipwrecked; medical and
religious personnel and their equipment;
protected buildings, equipment and vessels;
civilian objects; cultural objects; objects indispensable
for the survival of the civilian population;
works containing dangerous forces; and
the environment. GC I,
Art. 46; GC II,
op. cit. (note 10), Art. 12.Ibid., Art. 12(2).op. cit. (note 53),op. cit., Arts 21-31. The extent of the protectionIbid., Arts 53 andIbid., Art. 70.op. cit. (note 53), Art. 8(2)(b)(iii). Byop. cit. (note 14),op. cit. (note 14), Art. 47; GC III,op. cit.
(note 14), Art. 13; GC IV, op. cit.(note 14), Art. 33; Additional Protocol I,
op. cit.(note 10), Arts 20, 51-56. In fairness, it should
be acknowledged that certain countries argue
that the Additional Protocol I restrictions on
reprisals fail to reflect customary law. The
United States, while accepting that most reprisals
against civilians would be inappropriate
(and illegitimate), asserts that the absolute
prohibition thereon “removes a significant
deterrent that presently protects civilians and
other war victims on all sides of the conflict”.
US position on reprisals against civilians, see
Handbook, The United Kingdom issued a reservation
on precisely the same point when it
became party to the Protocol. Reprinted on the
International Committee of the Red Cross
Treaty Database website,
have adopted this position, reprisatory computer
network attacks are issues of policy, not law.
op. cit. (note 28), p. 470. For the officialop. cit. (note 49), paras 6.2.3 and<http://www.icrc.>. For these and other countries thatof kinetic attacks.
objects or individuals in reprisal, including reprisals by computer
network attack.
63 In addition, there are limitations on striking certain64388
The core prescriptions on striking legitimate targets are
based on the principle of discrimination.
most clearly expresses humanitarian law’s balancing of State-centric
interests in resorting to force against the more broadly based human
interest in shielding non-participants from the effects of what is, at
best, an unfortunate necessity.
The discrimination requirement is twofold. Applied to
weapons, it prohibits the use of those that are incapable of distinguishing
between combatants and military objectives on the one hand and
civilians, civilian objects and other protected entities on the other.
Applied to tactics and the use of weapons, it requires that an effort be
made to distinguish between these two categories, civilian and military,
when conducting military operations. Additional Protocol I articulates
this difference in Article 51(4):
“Indiscriminate attacks are: (a) those which are not directed at a
specific military objective; (b) those which employ a method or
means of combat which cannot be directed at a specific military
objective; or (c) those which employ a method or means of
combat the effects of which cannot be limited as required by this
Protocol; and consequently, in each such case, are of a nature to
strike military objectives and civilians or civilian objects without
Subparagraph (a) refers to indiscriminate use, whereas (b)
and (c) describe indiscriminate weapons or tactics.The indiscriminate
use aspect of discrimination consists of three related components —
distinction, proportionality, and minimizing collateral damage and
incidental injury.
65 It is this principle which6665 For a comprehensive review of the principle,
see Esbjörn Rosenblad,
Humanitarian Law of Armed Conflict: Some
Aspects of the Principle of Distinction and
Related Problems
Geneva, 1979.
66 This typology is adopted from
Christopher Greenwood, “The Law of Weaponry
at the Start of the New Millennium”, in
Michael N. Schmitt and Leslie C. Green (eds),
International, Henry Dunant Institute,The Law of Armed Conflict: Into the Next
1998, p. 185; also published in
College International Law Studies
1998. By contrast, the US Air Force employs
the categories of military necessity, humanity
and chivalry, with proportionality folded into
necessity, whereas the US Navy uses
, Naval War College, Newport, RI,US Naval War, Vol. 71,RICR
Department of the Air Force,
Law: The Conduct of Armed Conflict and
Air Operations
at 1-5 – 1-6 with Handbook,
para. 5-1.
67 Additional Protocols: A Commentary,
Wired warfare: Computer network attack and jus in belloDistinction
The principle of distinction, unquestionably part of customary
humanitarian law, is set forth in Additional Protocol I, Article
48: “[T]he Parties to the conflict shall at all times distinguish
between the civilian population and combatants and between civilian
objects and military objectives and accordingly shall direct their operations
only against military objectives”. Whereas the prohibition of
direct attacks on civilians rendered a specific category of potential targets
off-limits, the distinction requirement extends protection to cases
in which an attack may not be directed against civilian or civilian
objectives specifically, but in which there is a high likelihood of striking
them nonetheless. An example would be firing a weapon blindly,
although that weapon is capable of being aimed.
This is a particularly relevant prohibition in the context of
computer network attack. For example, it would embrace situations
where it is possible to discreetly target a military objective through a
particular means of CNA, but instead a broad attack likely to affect
civilian systems is launched. Such an attack would be analogous to the
Iraqi SCUD missile attacks against Saudi and Israeli population centres
during the 1990-91 Gulf War.
weapon. Indeed, it is easily capable of being aimed with sufficient
accuracy against, for instance, military formations in the desert.
However, the use of SCUDS against population centres was indiscriminate
even if the Iraqi intent was to strike military objectives situated
therein; the likelihood of striking protected persons and objects so
outweighed that of hitting legitimate targets that the use was inadmissible.
Given the interconnection of computer systems today, computer
network attacks could readily be launched in an analogous fashion.
68 The SCUD is not an inherently indiscriminateProportionality
that of distinction. Distinction limits direct attacks on protected persons
or objects and those in which there is culpable disregard for
in which harm to protected persons or objects is the foreseeable
consequence of an attack, but not its intended purpose.The principle
is most often violated (sometimes in an unintended but culpably negligent
fashion) as a result of: 1) lack of sufficient knowledge or understanding
of what is being attacked; 2) an inability to surgically craft the
amount of “force” being applied against a target; and 3) the inability to
ensure the weapon strikes the intended target with complete accuracy.
network attack.
As set forth in Additional Protocol I, an attack is indiscriminate
as violating the principle of proportionality when it “may be
expected to cause incidental loss of civilian life, injury to civilians,
damage to civilian objects, or a combination thereof, which would be
excessive in relation to the concrete and direct military advantage
close[;] … advantages which are hardly perceptible and those
which would only appear in the long term should be disregarded”.
All three pitfalls could be encountered in the context of computer70 A concrete and direct advantage is “substantial and relatively71Moreover, the advantage calculated is that resulting from the overall
operation, not the individual attack itself.
72Basically, the principle of proportionality calls for striking
a balance — a task that is especially difficult to accomplish because differing
entities (suffering and damage v. military advantage) are being
weighed against each other without a common system of valuation.
73Complicating matters is the fact that the answers to these and similar
questions, assuming that there are any “right” answers, are contextual
because the military advantage resulting from an attack always depends
on the state of hostilities at the time.
putting principle into practice, the Commentary on Additional
Protocol I notes that “[p]utting these provisions into practice… will
require complete good faith on the part of the belligerents, as well as
the desire to conform with the general principle of respect for the
civilian population”.
74 Acknowledging the difficulty of75Further complicating matters is the issue of knock-on
effects, i.e. those effects not directly and immediately caused by the
attack, but nevertheless the product thereof — it is the problem of the
effects caused by the effects of an attack. The most cited example is
that of the attack on the Iraqi electrical grid during the 1990-91 Gulf
War. Although it successfully disrupted Iraqi command and control,
the attack also denied electricity to the civilian population (a “firsttier”
effect), thereby affecting hospitals, refrigeration, emergency
response, etc. Similarly, when NATO struck at Yugoslavia’s electrical
supply network during Operation “Allied Force”, one consequence
was to shut down drinking water pumping stations.
gave rise, as a knock-on effect, to “second-tier” suffering of the population.
Obviously, precisely the same effects could have resulted had the
attacks been conducted through CNA. Indeed, the problem of knock-
76 Such attacks392
/europe/newsid_351000/351780.stm>.on effects looms much larger in computer network attacks than in
kinetic attacks owing to the interconnectivity of computers, particularly
between military and civilian systems.
Knock-on effects have a bearing on proportionality analysis
because they must be considered when balancing collateral damage
and incidental injury against military advantage. Unfortunately, when
caused by computer network attack such damage and injury, whether
direct or indirect, are difficult to assess without knowing how the
computer systems involved function and to which other systems they
are linked. Despite this obstacle, planners and decision-makers have an
affirmative duty to attempt to avoid collateral damage and incidental
injury whenever feasible, a duty that necessarily implies an effort to
ascertain the damage or injury likely to result from an attack.
the complexity of computer network attack, the high probability of an
impact on civilian systems and the relatively low understanding of its
nature and effects on the part of those charged with ordering the
attacks, computer experts will have to be available to assess potential
collateral and incidental effects throughout the mission-planning
conducted for nuclear weapons, would prove invaluable in identifying
possible knock-on effects; to conduct them prior to the outbreak of
hostilities — free from the fog, friction and pace of war — would be
well advised.
77 Given78 Additionally, modelling and simulation, like those alreadyMinimizing collateral damage and incidental injury
The determination of proportionality establishes
whether a military objective may be attacked at all. However, even if
the selected target is legitimate and the planned attack thereon
would be proportional, the attacker has an obligation to select that
method or means of warfare likely to cause the least collateral damage
and incidental injury, all other things being equal (such as risk to
the forces conducting the attack, likelihood of success, weapons
Juin IRRC June 2002 Vol. 84 No 846 393inventory, etc.).
military objectives that can be attacked to achieve a desired result, the
attack which carries the lowest risk of collateral damage and incidental
injury must be chosen.
79 Furthermore, whenever a choice is possible between80The availability of computer network attack actually
increases the options for minimizing collateral damage and incidental
injury.Whereas in the past physical destruction may have been necessary
to neutralize a target’s contribution to the enemy’s efforts, now it
may be possible to simply “turn it off ”. For instance, rather than
bombing an airfield, air traffic control can be interrupted.The same is
true of power production and distribution systems, communications,
industrial plants, and so forth.Those who plan and execute such operations
must still be concerned about collateral damage, incidental
injury and knock-on effects (consider the Iraqi electric grid example
above), but the risks associated with conducting classic kinetic warfare
are mitigated significantly through CNA. Also, depending on the
desired result, it may be possible to simply interrupt operation of the
target facility.This tactic would be particularly attractive in the case of
dual-use objectives. Consider an electrical grid. It might only be militarily
necessary to shut the system down for a short period, for example
immediately preceding and during an assault.The system could be
brought back on track as soon as the pressing need for its suspension is
over, thereby limiting the negative effects on the civilian population.
Similarly, because targets are not physically damaged and thus do not
need to be repaired or rebuilt, the civilian population’s return to normalcy
at the end of the conflict would be facilitated.