A handbook named after the Estonian capital Tallinn, due to be published later this week, applies international law to the world of electronic warfare in an effort to show how hospitals, civilians, and neutral nations can be protected in an information age fight.
"Everyone was seeing the Internet as the 'Wild, Wild, West,'" US Naval War College Professor Michael Schmidt, the manual's editor, said in an interview before its official release. "What they had forgotten is that international law applies to cyber weapons like it applies to any other weapons."
The Tallinn Manual — named for the Estonian capital where it was compiled — was created at the behest of the NATO Co operative Cyber Defence Centre of Excellence, a NATO think tank. It takes existing rules on battlefield behaviour, such as the 1868 St. Petersburg Declaration or the 1949 Geneva Convention, to the Internet, occasionally in creative or unexpected ways. Marco Roscini, who teaches international law at London's University of Westminster, described the manual as a first-of-its-kind attempt to show that the laws of war — some of which date back to the 19th century — were flexible enough to accommodate the new realities of online conflict.
The 282-page handbook has no official standing, but Roscini predicted that it would be an important reference as military lawyers across the world increasingly grapple with what to do about electronic attacks. "I'm sure it will be quite influential," he said.
The manual's central premise is that war doesn't stop being war just because it happens online. Hacking a dam's controls to release its reservoir into a river valley can have the same effect as breaching it with explosives, its authors argue. Legally speaking, a cyber attack which sparks a fire at a military base is indistinguishable from an attack that uses an incendiary shell.
The experts behind the manual — two dozen officers, academics, and researchers drawn mainly from NATO member states — didn't always agree on how traditional rules applied in the context of a cyber war.
Self-defence was a thorny issue. International law generally allows nations to strike first if they spot enemy soldiers about to pour across the border, but how could that be applied to a world in which attacks can happen at the click of a mouse?
Other aspects of international law seemed obsolete — or at least in need of an upgrade — in the electronic context.
The law also forbids attacks on "civilian objects," but the authors were divided as to whether the word "object" could be interpreted to mean "data." Did that leave a legal loophole for a military attack that erased valuable civilian data, such as a nation's voter registration records?
Tallinn Manual Lays Down Rules for Online Attacks