Ekonomik ve endüstriyel siber espiyonaj'a karşı Uluslararası Hukuk yolları
2016
0 views
0 downloads
Advisor: Prof. Dr. Akif Emre Öktem
Abstract (EN)
This study joins a vibrant discussion in the social sciences about one of the challenging issues of cyber security in particular, cyberespionage, as well as appropriate legal responses that might be adopted by victim States. The aim of this study is to investigate and identify economic and industrial cyberespionage and to offer and analyze effective domestic and international legal responses. First of all, we have witnessed a digital revolution which affects the existing traditional social, economic, political and legal systems around the world globally. This revolution has transformed our interaction with societies and environments. As it is the rule for all new developments, they can offer society an opportunity to ease struggles, but new beginnings are not always clear and certainly not simple. Individuals seek to embrace vast opportunities offered by information technologies as long as they perceive them safe. However, such revolutions have to be addressed by legal mechanisms in order to balance privacy and the need for security. In this sense, scholars and law makers seek for effective legal mechanisms to regulate the new realm called cyberspace. There are basically two mainstream views: 1) this space is free from the control of real space sovereigns, but also traditional legal structures are insufficient to regulate this area, 2) this space is no different than space, air and sea; it has physical dimensions and components, therefore existing legal structures are adequate to offer protection. We will adopt and discuss hybrid views which indicate that existing legal structures are sufficient, but we also need new approaches at some point. This thesis is composed of two main chapters namely, 1) Cyberspace, espionage and cyberespionage, 2) Tackling economic and industrial cyberespionage. In the first chapter, challenges inherent to defining and regulating cyberspace and espionage activities are presented. This shows that international legal scholars have different opinions about deciding whether intelligence activities are permitted or restricted by international law when they are conducted in times of peace or war. The thesis then discusses the legality of wartime and peacetime espionage activities. Regarding peacetime espionage activities, we will analyze customary international principles which allow or restrict such activities. Although international law is oblivious to espionage activities during peaceful times, there are several incidents and attempts to regulate this area especially in peacetime. For example, U-2 reconnaissance flights paved the way for the signing of the Treaty on Open Skies as conclusion of confidence and security building measures. Therefore, we envisaged the same procedure can occur with regards to cyberespionage. However, due to the proliferation of cyberespionage operations, states and corporations strongly look for international regulations or mechanisms to protect their strategic interests. This thesis further identifies cyberespionage and the changing features of espionage, such as its purpose and targets, methods and means, and actors and incidents. Basically, this is to show that modern day espionage activities can not be compared to those people are used to seeing in James Bond or other Hollywood movies. Although espionage seems to have been accepted as a tool adopted by parties of war in times of conflict, actually, espionage and its techniques, mechanisms and tools are dual-use in nature. This nature has been understood, observed and experienced within the past decade as a result of the proliferation of technology, which paves the way for cyber weapons, attacks, crimes and espionage. We will explain the changing features of espionage in the face of evolving technology. For instance, one of the significant tools frequently adopted by cyberespionage is called APT, Advanced Persistent Threat, which is a sophisticated technique used by hackers to extract large amounts of data from targeted industries over a long period of time. This type of attack is well-tailored for intended sectors or computer networks and has advanced capabilities to extract data and compromise the targeted entity. Such an adversary can spend years to exfiltrate documents from the targeted entity without being spotted. In a detailed central section, the thesis provides an evaluation of cyberespionage under international legal theory. Here, the thesis supports rational choice and game theory rather than classical approaches. We consider the application of rational choice and game theory for explaining the logic behind cyberespionage and cyber attacks. In other words, the actors in cyberspace act and decide rationally in the case of choosing their targets therefore, their choices eventually create a norm or offer a way for creating a norm. Thus, we conclude that confidence and security building measures can be proposed regarding activities or inactivity of the actors adopting cyberespionage techniques. The second chapter is devoted to the domestic and international legal tools appropriate to adopt in cases of cyberespionage incidents. We accepted and built our analysis upon the fact that cyberespionage activities are a kind of cyber attack, which violates intellectual property rights, trade secrets and confidentiality, integrity and sometimes availability of the targeted networks. Many states do not have specific regulations dedicated to tackle cyberespionage so, traditional legal approaches offer to apply regulations covering intellectual property crimes for such activities. Therefore, regulations related to the protection of trade secrets and cybercrimes are domestic legal tools if any private network is targeted by cyberespionage. There are also specific regulations to penalize economic and industrial espionage. Those regulations exist only under the American legal system, so we will also analyze these regulations as well. With regards to domestic regulations, we comparatively analyzed the Turkish and American legal systems in terms of protection of trade secrets and computer crimes. In terms of international legal responses, we have compared legal responses given and discussed previous sections on wartime and peacetime cyberespionage activities. However, peacetime cyberespionage activities and the appropriate legal responses are the focal points of the study, as they are frequently applied. We argued that cyberespionage activities should be accepted as a form of use of force considering their extremely adverse effects. Moreover, cyber operations need not amount to use of force within the meaning of article 2/4 of the UN Charter to be internationally wrongful, such operations can violate certain obligations and principles of customary international law either. In this sense, cyberespionage activities violate the binding customary principles of international law, which prohibits interference with the sovereignty and domestic affairs of other states. A state bears international legal responsibility for a cyber operation attributable to it and which constitutes a breach of an international obligation. The basic legal argument to invoke state responsibility with regard to economic cyberespionage is state sovereignty, which also covers the very concept of economic sovereignty. Whether the operation targets public or private infrastructures, states have sovereignty over both of them. We will argue that cyberespionage operations provide sufficient legal grounds to invoke state responsibility and adopt appropriate measures compatible with internationally wrongful acts, which are considered retorsion and countermeasures covering diplomatic and economic sanctions. Therefore, the first mechanism is declaring responsibility of states for illegitimate acts and taking appropriate measures. Furthermore, we have identified that cyberespionage activities are also conducted before or during bilateral or multilateral treaty negotiations. In this sense, the thesis argues that the Vienna Convention on the Law of Treaties can provide protection against and play a significant deterrent role for such activities, as they violate the good faith principle and limit the parties' ability to negotiate freely and fairly. Therefore, such violations can trigger invalidity of the treaty by fraud, which is adopted by the Vienna Convention on the Law of Treaties. To illustrate, we have investigated the Timor-Leste vs. Australia case. With regard to the case, violation of both treaty law obligations and established international law norms and principles (inviolability of diplomatic premises, good faith in negotiations, state sovereignty and non-intervention) provide concrete legal basis to assert illegality of cyberespionage. However, establishing the legal and factual link between espionage and fraudulent conduct is complex and problematic due to the lack of any precedent. Lastly, as economic and industrial cyberespionage activities target intellectual properties, we have discussed legal measures adopted by the Trade-Related Aspects of Intellectual Property Rights (TRIPS) Agreement. Within the limits of World Trade Organization (WTO) agreements, the interpretation of the preamble of the TRIPS Agreement include economic cyberespionage operations within the agreement. As in the commentary of the Article 39 of the TRIPS, "a manner contrary to honest commercial practices" has been explained as a "breach of contract, breach of confidence and inducement to breach, and includes the acquisition of undisclosed information by third parties who knew, or were grossly negligent in failing to know, that such practices were involved in the acquisition." Pursuant to the wording of the article, it should be acknowledge that cyberespionage operations are kind of manner contrary to honest commercial practices. However, obligations created by the WTO are only effective and binding within the territories of the parties. Therefore, we have concluded that the WTO dispute resolution mechanism is politically "the most appropriate and effective forum", but legally, parties of the WTO and TRIPS should first agree on international norms and principles explicitly restricting economic cyberespionage operations under WTO agreements. To this end, in case of extraterritorial responses, states may adopt certain measures in accordance with international laws. For instance, declaring such activities as internationally wrongful acts and deploy countermeasures; seek for treaty law responses accordingly such as terminating bilateral treaties due to fraudulence; or apply international forums such as the WTO. In order to respond to cyberespionage activities legally, we should consult legal documents for definitions, criminalization, and punishments for individuals and legal entities. This thesis offers, States and corporations targeted by economic and industrial cyberespionage, several effective legal measures on confronting such activities, and thus make a small contribution to improve the legal literature on this subject.
Author
Dr. Oğuz Kaan Pehlivan
How to Cite
Oğuz Kaan Pehlivan (Master Thesis). Ekonomik ve endüstriyel siber espiyonaj'a karşı Uluslararası Hukuk yolları, 2016, Galatasaray University.
License
Tüm Hakları Saklıdır
This work is shared under the specified license terms.
More theses from Galatasaray University
- International state responsibility arising from new space activities(2025)
- The liability of shareholders and organs for public debts in capital companies(2022)
- Karşı kültürel bir kimlik olarak taraftarlık: istanbul futbol tribünlerinde kimliksel yapılanış biçimleri çalışması(2014)
- Yeni roman: claude simon ve william faulkner(2014)
- Directors and officers liability insurance(2015)
- Langlands fonktörsellik ilkesi(2021)
