Cyber ​​strategies and international responsibility of states in the West Asian security order

Volume 9, Issue 2 - Serial Number 33
Summer 2025
Pages 263-283

Document Type : Original Independent Original Article

Authors

1 PhD in Public Administration, Public Administration, Faculty of Management and Accounting, Allameh Tabatabaei University, Tehran, Iran

2 PhD student in Industrial Engineering, Quality and Productivity Management, Malek Ashtar University of Technology, Tehran,

Abstract
The rapid growth of technology and the increasing dependence on digital infrastructure have turned the concept of state responsibility in cyberspace into one of the most pressing challenges of the contemporary international order. The absence of a unified definition of “cyber aggression” and clear attribution standards has enabled states to operate in the gray zone between peace and conflict, conducting costly operations without direct accountability. This study, using an explanatory–analytical approach and a qualitative comparative method, analyzes international documents, security reports, and state behaviors to propose a three-layered framework: “norms and international law,” “multilayered deterrence and defense,” and “credible attribution with transparent narrative-building.” Findings reveal that weak legal mechanisms and a lack of intelligence cooperation undermine the legitimacy of state responses and increase the risk of civilian harm. Conversely, the combination of technical cooperation, active norm-building, and enhanced transparency can create sustainable deterrence. The study concludes that strengthening technical collaboration, improving attribution transparency, and enhancing the role of international institutions are essential for accountability and civilian protection.

Keywords

Subjects
رضایی، علی(۱۴۰۲). تحلیل تطبیقی دکترین بازدارندگی سایبری در ایران و رژیم صهیونیستی، امنیت ملی، ۳۴(1)، ۲۵۵۴.
شهبازی، سید محمد؛ آقاجانی رونقی، امیر(۱۴۰۰). مسئولیت دولت‌ها در قبال عملیات سایبری فراملی: از حقوق عرفی تا رویه بین‌المللی، مطالعات حقوقی بین‌المللی، ۵۱(2)، ۴۵۷۳.
صفری، احمد؛ احمدی، نسرین(۱۴۰۱). سیاست دفاع سایبری جمهوری اسلامی ایران: چالش‌ها و چشم‌اندازها»، مطالعات راهبردی، ۲۹(3)، ۱۱۲۱۳۵.
قره‌باغی، مهدی؛ کشاورز، سارا(۱۳۹۹). حملات سایبری و مسئولیت بین‌المللی دولت‌ها: مطالعه موردی ایران، سیاست جهانی، ۲۶(4)، ۸۸۱۱۰.
موسوی، رضا(۱۳۹۶). حقوق بین‌الملل و چالش‌های جنگ سایبری، تهران: انتشارات دانشگاه علامه طباطبایی.
Bronk, C., & Tikk, E. (2013). The Cyber Attack on Saudi Aramco. Survival, 55(2), 8196.
CISA / ICS-CERT. (2016). IR-ALERT-H-16-056-01: Cyber-Attack Against Ukrainian Critical Infrastructure. U.S. Department of Homeland Security.
Delerue, F. (2020). Cyber Operations and International Law. Cambridge University Press.
ENISA. (2023). ENISA Threat Landscape 2023. European Union Agency for Cybersecurity.
ESET Research. (2022). INDUSTROYER2: New Sandworm Malware Targeting Ukraine’s Energy Sector. ESET White Paper.
Greenberg, A. (2020). Sandworm: A New Era of Cyberwar and the Hunt for the Kremlin’s Most Dangerous Hackers. New York: Doubleday.
Hathaway, O. A., Crootof, R., Levitz, P., Nix, H., Nowlan, A., Perdue, W., & Spiegel, J. (2012). The Law of Cyber-Attack. California Law Review, 100(4), 817885.
Healey, J. (Ed.). (2013). A Fierce Domain: Conflict in Cyberspace, 19862012. Washington, DC: Atlantic Council.
Klimburg, A. (2017). The Darkening Web: The War for Cyberspace. New York: Penguin Press.
Lindsay, J. R., Smeets, M., & Vu, A. (2021). Routledge Handbook of Cybersecurity. London: Routledge.
Maurer, T. (2018). Cyber Mercenaries: The State, Hackers, and Power. Cambridge: Cambridge University Press.
Nye, J. S. (2017). Deterrence and Dissuasion in Cyberspace. International Security, 41(3), 4471.
Rid, T., & Buchanan, B. (2015). Attributing Cyber Attacks. Journal of Strategic Studies, 38(12), 437.
Roscini, M. (2020). Cyber Operations and the Use of Force in International Law. Oxford: Oxford University Press.
Schmitt, M. N. (Ed.). (2017). Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations. Cambridge: Cambridge University Press.
Shackelford, S. J. (2014). Managing Cyber Attacks in International Law, Business, and Relations: In Search of a Common Language. Cambridge: Cambridge University Press.
The White House. (2023). National Cybersecurity Strategy. Washington, DC.
Tsagourias, N., & Buchan, R. (Eds.). (2021). Research Handbook on International Law and Cyberspace (2nd ed.). Cheltenham: Edward Elgar.
UN GGE. (2021). Report of the Group of Governmental Experts on Advancing Responsible State Behaviour in Cyberspace in the Context of International Security (A/76/135). United Nations.
UN OEWG. (2021). Final Report of the Open-ended Working Group on Developments in the Field of ICTs in the Context of International Security (A/75/816). United Nations.
UNIDIR. (2024). Norms, Rules, and Principles for Responsible State Behaviour in Cyberspace. Geneva: United Nations Institute for Disarmament Research.
Zetter, K. (2014). Countdown to Zero Day: Stuxnet and the Launch of the World’s First Digital Weapon. New York: Crown.