As the number of cyberattacksgrow with what appears to be an ever-increasing cyber threat level and risks, important new questions are coming to light. 

As cyberattacks increase in both number and threat level, cyber professionals are asking head-scratching questions about cyber warfare, such as what constitutes treason. Recently, the question of treason in the context of cyber warfare came up and that has many scratching their heads. The Cambridge dictionary defines treason as "showing no loyalty to your country, especially by helping its enemies or trying to defeat its government."

One set of questions focused on the discovery and sale of zero-day vulnerabilities came up after the recent issue that arose when the FBI was attempting to access the Apple smartphone of the San Bernardino terrorists. The questions came up in the context of zero-day software vulnerabilities discovery and sale. Could treason charges be brought against an individual who that discovered a zero-day vulnerability in a common operating systems (OS) that is widely used by the military and within the nation’s critical infrastructure? What if it was packaged it as a penetration-testing tool and those discovering the zero-day began to sell that sold on the open market and/or black market? Could that be considered treason? By the way, when last checked such a vulnerability would go for between $60,000 to $250,000 on the black market and that far exceeds what they would get by contacting the OS vendor.

Clearly, software vulnerabilities have to be considered dual-use technology. Simply put, dual-use technologies can be and are commonly used in both (dual) military and commercial applications. According to the Department of Commerce, "dual-use technologies require export licenses when they involve/impact national security, foreign policy, short-supply, nuclear non-proliferation, missile technology, chemical and biological weapons, regional stability, crime control, or terrorist concerns." Given that definition, it is easy to see how some believe the sale of penetration-testing tools, especially those that include previously unknown vulnerabilities fall under this restriction. This gray area needs to get cleared up quickly as zero-day vulnerabilities are in high demand for legal (penetration-testing tools and evidence discovery) and illegal (cyber weapons) use. Or is it already too late?

Share:
More In Net Defense Blogs