infrastructure falling down by the second?  For such a legal regime to be functional, the doctrine of state responsibility for cyber attacks would have to be restructured and sufficiently defined.


State Responsibility for Cyber Attacks

The speed and anonymity of cyber attacks makes “distinguishing among the actions of terrorists, criminals, and nation states difficult.”170  Simultaneously, the instances of state-sponsored terrorist acts have increased since the end of the Cold War.171  Proving state responsibility for such acts though is exceedingly difficult.  As seen in the Estonian cyber attack, a sponsoring state may not cooperate in the investigation, apprehension, and extradition of those who acted on its behalf in committing criminal or terrorist acts.  A nation-state might even be able to “conceal its involvement in self-interested cyber attacks by encouraging ‘civilian’ cybercriminals and cyberterrorists to conduct their operations from within its borders since the fog of ‘civilian’ cyberattacks would obscure the purpose and origins of the state-sponsored attacks.”172  Consequently should the cyber attack on Estonia be characterized as: a cybercrime, with Russian Nashi hackers orchestrating a coup; cyberterrorism by a group pursuing idiosyncratic ideological goals; or cyberwarfare, a virtual sortie by Russian

