Abstract
The proliferation of state-sponsored cyberattacks against critical civilian infrastructure has dramatically exposed the limitations of traditional international legal frameworks governing the use of force. This article critically examines the "attribution problem"—the technical and legal difficulty of definitively linking a cyber operation to a specific sovereign state—as the primary obstacle to enforcing accountability under the UN Charter and customary international law. Relying on the principles codified in the Tallinn Manual 2.0, the authors analyze the evidentiary thresholds required to attribute the actions of proxy hacker groups, advanced persistent threats (APTs), and patriotic hacktivists to state sponsors. The paper dissects the legal doctrines of "effective control" and "overall control" as interpreted by the International Court of Justice (ICJ) and the International Criminal Tribunal for the former Yugoslavia (ICTY), arguing that these standards are dangerously rigid when applied to the asymmetric and deniable nature of cyberspace. Furthermore, the authors explore the emerging doctrine of "due diligence," which posits that states have an affirmative obligation to prevent their digital territory from being used to launch cyberattacks against other nations. We argue that while due diligence offers a promising supplementary framework for state responsibility, it suffers from a lack of widespread *opinio juris* and state practice. The article concludes by proposing a modernized, multi-tiered attribution mechanism that incorporates independent technical intelligence, geopolitical context, and shared evidentiary standards to facilitate proportional legal countermeasures, thereby deterring the weaponization of the digital domain without escalating to kinetic warfare.
Keywords: Cyber Warfare, State Responsibility, Attribution Problem, Tallinn Manual, Use of Force, International Law