Hacking Back: Optimal Use of Self-Defense in Cyberspace

69 Pages Posted: 19 Mar 2009 Last revised: 2 Mar 2012

Ruperto P. Majuca

University of Illinois at Urbana-Champaign - Department of Economics

Jay P. Kesan

University of Illinois College of Law

Date Written: March 18, 2009

Abstract

Should the law permit hackback? How should the law on self-defense in cyberspace be designed? In this paper, we use game-theoretic analysis to develop criteria that determine whether police enforcement, litigation, or hackback is best, and under what circumstances. Our model suggests that the law should permit hackback only if: (1) other alternatives, such as police enforcement and resort to courts, would be ineffective; (2) there is a serious prospect of hitting the hacker instead of innocent third parties; and (3) the damages that can be potentially mitigated to the defender's systems outweigh the potential damages to third parties. The law should require that counterstrikers use only force that is necessary to avoid damage to their own systems. Also, proper liability rules will induce counterstrikers to internalize the damages of third parties in their decision-making. Finally, better intrusion detection systems (IDS) and traceback technology improve the deterrent effect and efficacy of hackback.

Suggested Citation

Majuca, Ruperto P. and Kesan, Jay P., Hacking Back: Optimal Use of Self-Defense in Cyberspace (March 18, 2009). Chicago-Kent Law Review, Vol. 84, No. 3, 2010; Illinois Public Law Research Paper No. 08-20. Available at SSRN: https://ssrn.com/abstract=1363932 or http://dx.doi.org/10.2139/ssrn.1363932

Ruperto P. Majuca

University of Illinois at Urbana-Champaign - Department of Economics ( email )

1301 W. Gregory Drive
Urbana, IL 61801
United States

Jay P. Kesan (Contact Author)

University of Illinois College of Law ( email )

504 E. Pennsylvania Avenue
Champaign, IL 61820
United States
217-333-7887 (Phone)
217-244-1478 (Fax)

HOME PAGE: http://www.jaykesan.com

Paper statistics

Downloads
486
Rank
46,784
Abstract Views
1,976