Pentagon officials weighed illegal force in 1999 network attacks

By Miriam Adler ·

National sovereignty was at risk as the Department of Defense debated whether proactive counter-intrusions during peacetime constituted an illegal escalation of force.

In November 1999, the Department of Defense was attempting to reconcile the physics of the internet with the centuries-old laws of war. The file's catalogue entry records an unclassified study from the Office of General Counsel titled An Assessment of International Legal Issues in Information Operations. It is a document from a moment when the digital frontier was shifting from a tool of communication to a theater of operation.

"Active Defense"

According to the archive's description, one chapter of the study focuses specifically on the "international legal regulation of force in peacetime." This is the central friction point of the document. In traditional military terms, the use of force is a binary state: a nation is either at peace or it is at war. The transition from one to the other is usually marked by a kinetic event—a border crossing, a missile launch, a formal declaration.

However, the 1999 assessment applies this analysis to "computer network attacks" and a concept termed "active defense."

In the context of information privacy, the public record defines the field as the relationship between the collection and dissemination of data, technology, and the legal and political issues surrounding them. When the Department of Defense enters this relationship, the "political issues" are not merely about individual privacy, but about national sovereignty. If a state actor penetrates a foreign network to disable a power grid or a communications hub during a time of nominal peace, does that constitute a "use of force" under international law?

"Active defense" suggests a posture that goes beyond passive firewalls and encryption. While the catalogue entry does not detail the specific tactics proposed, the term implies a proactive response—a way of meeting a network attack with a counter-intrusion designed to neutralize the threat. The legal question is whether such a response is a legitimate act of self-defense or an illegal escalation of force in peacetime.

Document imagery from nsarchive.gwu.edu From the files: nsarchive.gwu.edu

November 1, 1999

The date of the document is significant. This was an era of transition. The Clinton administration was navigating the fallout of the 1998 embassy bombings in Nairobi and Dar es Salaam, and the military was grappling with the reality that the most sensitive data of the state now lived on interconnected servers.

At the time, the concept of a "cyber weapon" was largely theoretical, yet the Office of General Counsel was already treating it as a legal reality. The study sought to determine where the line lay between espionage—which is generally tolerated as a standard function of statecraft—and an attack. Espionage is the quiet theft of data; an "attack" is the disruption or destruction of a system. The 1999 report suggests the DoD was acutely aware that the distinction between the two is often a matter of a few lines of code.

This legal anxiety is reflected in other records of the period. The National Security Archive holds references to a December 2000 report from the Office of the Manager of the National Communications System regarding the "Electronic Intrusion Threat to National Security and Emergency Preparedness (NS/EP) Internet Communications." The 1999 assessment provided the legal scaffolding for the technical threats identified a year later.

"Computer Network Attacks"

By applying the regulation of force to "computer network attacks," the DoD was essentially asking if the digital world required a new set of laws or if the old ones could be stretched to fit. The public record on data protection emphasizes the role of contextual information norms; the norm for a military is survival and dominance, while the norm for a civilian is privacy and security. When these two norms collide in a shared network, the result is a legal gray zone.

Related files across various archives show a continuing struggle to define these boundaries. The US National Archives holds "General Legal Files" and "Daily Summaries" that track the evolving nature of state litigation, while more recent records, such as the 2025 and 2026 District Court filings in Armando Fernandez-Larios v. Charles Parra and cases in the Northern District of Illinois, suggest that the tension between state data collection and individual privacy remains unresolved decades after the 1999 assessment.

There is a peculiar detail in the archival record: the existence of a "Second Edition" of the Assessment of International Legal Issues in Information Operations, also dated November 1, 1999. The presence of a revised edition on the very day of the original's release suggests a high degree of urgency—or perhaps a rapid correction of a legal position that the Department of Defense found untenable even as it was being printed.

Whether the "active defense" strategies contemplated in 1999 became standard operating procedure remains a matter of speculation, as the provided text stops at the catalogue entry. The record leaves open the question of whether the DoD ever found a satisfactory answer to the problem of peacetime force, or if they simply decided that the digital void was the only place where the laws of war didn't apply.

One month after the assessment was finalized, the Department of Defense continued to monitor the electronic intrusion threat, leading into the December 2000 warnings about the vulnerability of national security communications.