Illegal: The SolarWinds Hack under International Law.
In late 2020, news surfaced about one of the most extensive attacks on an information technology (IT) supply chain to date. Hackers exploited a vulnerability in the update system of Orion, a network-monitoring and management software developed by the company SolarWinds. Malicious code embedded in Or...
| Publicado en: | European Journal of International Law Vol. 33; no. 4; pp. 1275 - 1287 |
|---|---|
| Autores principales: | , , |
| Formato: | Artículo |
| Publicado: |
Oxford University Press / USA
Nov2022
|
| Materias: | |
| Acceso en línea: | Ver este registro en EBSCOhost |
| fields | @attributes: recordID: 1 pdfLink: plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=162875084&site=ehost-live header: @attributes: shortDbName: hlh uiTerm: 162875084 longDbName: Humanities International Complete uiTag: AN controlInfo: bkinfo: jinfo: jid: 09385428 BHU jtl: European Journal of International Law issn: 09385428 maglogo: N pubinfo: dt: Nov2022 vid: 33 iid: 4 pid: 622 pub: Oxford University Press / USA artinfo: ui: 162875084 10.1093/ejil/chac063 ppf: 1275 ppct: 12 formats: tig: atl: Illegal: The SolarWinds Hack under International Law. aug: au: Coco, Antonio Dias, Talita van Benthem, Tsvetelina affil: Visiting Fellow, Oxford Institute for Ethics, Law and Armed Conflict, Blavatnik School of Government, University of Oxford (Oxford ELAC), United Kingdom Lecturer, School of Law, University of Essex, , Colchester Research Fellow, Oxford ELAC, United Kingdom Shaw Foundation Junior Research Fellow in Law, Jesus College, University of Oxford Lecturer in Public International Law, Department of Continuing Education, University of Oxford Research Associate, Oxford ELAC, United Kingdom DPhil Candidate, Faculty of Law, University of Oxford su: Computer hacking SolarWinds Corp. Information technology Malware Human rights violations sug: subj: Computer hacking SolarWinds Corp. Information technology Malware Human rights violations ab: In late 2020, news surfaced about one of the most extensive attacks on an information technology (IT) supply chain to date. Hackers exploited a vulnerability in the update system of Orion, a network-monitoring and management software developed by the company SolarWinds. Malicious code embedded in Orion updates created a backdoor into the systems used by numerous private and public entities. This backdoor was then used to insert additional malware into affected systems – in particular, spyware to exfiltrate confidential or sensitive data. Considering both the importance of preserving the integrity of IT supply chains and the diverse risks of harm that attacks such as the SolarWinds hack give rise to, this article examines this cyber operation according to the relevant rules of international law – notably those on sovereignty, non-intervention, general due diligence duties and international human rights law. It concludes that the operation may have been illegal on multiple fronts. pubtype: Academic Journal doctype: Article src: R language: English refInfo: copyright: @attributes: flag: Y dt: @attributes: year: 2022 holdings: @attributes: islocal: N |
|---|