Prosecuting Computer Virus Authors: The Need for an Adequate and Immediate International Solution

Kelly Cesare
The Transnational Lawyer, 14, Spring, 2001, pp.135-170
ISSN 1045-8905

Copyright (c) 2001 University of the Pacific, McGeorge School of Law

J.D., University of the Pacific, McGeorge School of Law, to be conferred May, 2002; B.A., Communication, University of Southern California, 1999.

I would like to thank Andrew Nelson for his countless hours of patience and assistance; his guidance and sense of humor made the entire writing process enjoyable for me. I would also like to thank my parents and friends for their constant love, faith, encouragement and support, especially my roommate, Gina Nargie, for putting up with me and my inability to keep our apartment tidy during Fast Trak.


... However, a new villain - the virus author - has surfaced, bringing a new crime into the international forum: the spread of the computer virus. ... Free from the fear of prosecution, the virus author feels no need to stop wreaking global havoc. ... Part II focuses on the crime of the spread of a computer virus and the type of damage that a virus author is capable of inflicting across the world from a single isolated terminal. ... Finally, the section concludes with an overview of the role a virus author plays in instigating that crime. ... Computer crime legislation as a whole covers a wide variety of offenses. ... For the United States, the Melissa virus concluded with "the first successful prosecution of a virus author in over a decade and only the second successful prosecution in [American] history" under the nation's specialized computer crime statutes. ... Countries with Lesser Computer Crime Laws ... " Certain aspects of computer crime legislation are particularly incompatible with extradition. ... This roadblock kept the United States from extraditing the ILOVEYOU virus author from the Philippines. ... Some government efforts do not require help from the private sector to combat computer crime. ...

I. Introduction

Imagine the following scenario: a disgruntled employee1 decides to take it upon herself to seek revenge on her employer corporation. She secretly creates a strand of malicious computer code 2 that will damage any computer it infects. 3 From her home computer, the employee uses her dial-up modem 4 to access 5 the corporation's computer system and releases the code into it, destroying data on every company computer that becomes infected and completing her mission of revenge. However, the nightmare does not end here. Unbeknownst to anyone, including the culprit, co-workers that are working from infected terminals are perpetuating the malicious code with every e-mail 6 they send 7 through the Internet. 8 The code reaches countless computer terminals, irrespective of jurisdictional and sovereign boundaries. The code causes millions of dollars in damage throughout the world before it can be quashed. But the greater injustice resulting from this scenario has yet to be realized: the country in which the disgruntled employee resides has no law under which to prosecute her act, and her extradition to a country which does is unfeasible. She emerges unpunished by the law. What may sound like an imaginary plot for a dramatic movie is unfortunately an all too real scenario, reflective of how a computer virus 9 proliferates into a worldwide problem.

International borders have long been a stumbling block in the successful prosecution of crimes. There are a number of common scenarios that illustrate this point: an individual may commit a crime in one country, then flee to another, in an attempt to escape the law; she may commit an act in a country that does not consider the action criminal; 10 or she may act in one country, which produces effects in another. 11 Any of these three generalizations lead to prosecutorial problems for the countries involved. Questions of jurisdiction are inevitably invoked.

In response to jurisdictional problems, the world engineered a solution: extradition. 12 Extradition works because most nations prosecute the same types of crimes, although the severity of punishment varies from country to country. 13 Deterring crime is an underlying policy goal for the enactment of all laws. 14 Through extradition, an international criminal can run but cannot hide. The deterrent effect of criminal laws are thereby strengthened.

However, a new villain - the virus author 15 - has surfaced, bringing a new crime into the international forum: the spread of the computer virus. 16 However, she escapes prosecution 17 largely because many countries simply have no cyber 18 crime laws. Therefore, extradition is not a viable prosecutorial alternative. Free from the fear of prosecution, the virus author feels no need to stop wreaking global havoc.

This Comment addresses the hardships experienced by nations around the world in attempting to prosecute virus authors. Ultimately, this Comment argues that among the numerous proposals attempting to address the problem, the Council of Europe's draft Cyber-Crime Treaty 19 is the best solution offered thus far. Part II focuses on the crime of the spread of a computer virus and the type of damage that a virus author is capable of inflicting across the world from a single isolated terminal. This section goes on to discuss the current state of cyber crime laws, or lack thereof, in the United States and other nations, and their level of success in prosecuting virus authors. Part III discusses the difficulty in prosecuting cyber criminals, illustrating this with a few examples from recent history. Part IV evaluates some solutions proposed by various parties and gives a detailed description of the relevant sections of the Council of Europe's proposed solution: a draft Cyber-Crime Treaty. Finally, Part V concludes that, despite its minor flaws, the Council of Europe's draft Cyber-Crime Treaty is the most efficient and effective way to effect immediate change in light of the other proposed solutions.

II. The Crime of the Computer Virus

Because the spread of a computer virus is still a relatively new crime, understanding the mechanics of a malicious code is a precursor to demonstrating how the computer virus can be used as an instrument of crime. Upon concluding that some type of conduct relating to computer use may be criminal in nature, the next step is to identify how modern criminal law systems might be better equipped to deal with the problem. Examples of recent virus outbreaks help illustrate why the spread of computer viruses constitutes criminal conduct, which necessitates strong prosecutorial strategies.

A. The New Crime: The Computer Virus

This section begins by outlining the basics of a computer virus. 20 It then discusses how a computer virus is used to facilitate a crime. 21 Finally, the section concludes with an overview of the role a virus author plays in instigating that crime. 22

1. What is a Computer Virus?

A virus is one species of a malicious computer code 23 "written with the sole intent to cause damage to a machine or to invade the machine to steal information." 24 "A virus is a program that infects a computer by inserting a copy of itself into the computer and harms the computer in some manner, generally without the computer user's awareness." 25 Viruses can be harmful or benign. 26 The typical mode of distributing a virus is via e-mail or an infected disk, 27 but a virus cannot infect a computer until the program is executed. 28 Usually the unknowing recipient is duped into opening an attached file in an e-mail or a file contained on a disk, thinking it is harmless and/or it came from a friendly source. 29 Hiding a "macro" 30 routine in a common Microsoft Office product file, such as Word or Excel where the macro tells the computer to perform harmful actions, is another way a virus can be executed. 31 Only files that are "executable" (.exe) 32 are capable of transmitting a virus, whereas, data files, such as image (.jpg and .gif), music (.wav and .mp3) or text (.txt) files are not capable of transmitting a virus because they do not contain macro functionality, 33 or they cannot command the computer to perform any functions. 34 Once a virus is activated, the damage or interference it causes is not always immediate or apparent. 35 An author can design a virus to trigger in countless ways, 36 and individuals are constantly inventing new triggering mechanisms. There are several places a virus can hide within a host computer, 37 and once the virus infiltrates a computer, it can replicate and spread itself without further assistance from the user. 38 Once triggered, the damage that a virus causes is referred to as the "payload." 39 When the virus infects the hard drive, 40 its payload launches. The damaging interference that results can range from "annoyingly humorous ... to total devastation" of the hard drive. 41

2. The Role of the Computer Virus in Criminal Law

Computer crime legislation as a whole covers a wide variety of offenses. 42 Since computer crime legislation is still relatively new, 43 it is necessary to understand precisely how the proliferation of a virus constitutes computer crime. As computer viruses began to evolve into serious security and financial threats, lawmakers began criminalizing their distribution. In the United States, merely writing a piece of malicious code is not a crime without the necessary intent to access an unauthorized computer. 44 To constitute a punishable offense, the virus must be knowingly transmitted to another computer, via e-mail, infected disk, or otherwise.

When computer crimes were first recognized, they were simply encompassed by traditional crimes, the only difference being that the crime was being committed with the aid of a computer. 45 As technology advanced, however, it became apparent that new computer crimes, such as the intentional spread of viruses, were unique to computers and thus needed particularized legislation. 46 There is an ongoing debate in today's world as to whether such legislation is in fact necessary because a great number of crimes committed with the use of a computer can be prosecuted under traditional statutes already in existence.

Legal scholars and law enforcement experts differ in opinion as to where cyber crimes fit within modern criminal law. 47 Some experts believe that computer crimes, including the mischievous use of viruses, are simply traditional crimes committed with advanced technology, and current criminal laws suffice to punish computer crimes. 48 Other experts believe that cyber crimes are a new category of crime requiring a comprehensive, separate legal framework to address the unique nature of the emerging technologies and the unique set of challenges that traditional crimes do not address. 49

In the United States, there are many statutes from which a federal prosecutor can choose when prosecuting a computer criminal. 50 Sometimes, a prosecutor uses a traditional statute to prosecute a computer-related offense. For example, the federal Copyright Infringement Act, 17 U.S.C. 506 can be used to prosecute a copyright violation, despite the fact that a person used a computer to facilitate the crime. Other times, a prosecutor may utilize a new computer crime statute, tailor-made for crimes that cannot be committed absent the aid of a computer. An example of such a statute is the National Information Infrastructure Protection Act. 51 The prosecutor's choice depends on the circumstances surrounding the crime and which statute is most likely to lead to a successful prosecution. 52 However, one country with a statute tailor-made to combat cyber crime is not always the answer. 53

3. Illustrative Examples of Recent Virus Outbreaks

As technology advances, individuals consistently find ways to exploit it for deviant purposes. 54 The vast majority of intrusive hacking is done for research purposes, such as investigating breaches in security. 55 There are those, however, that use their software and computer talents in a mischievous manner, launching computer viruses for purposes that are criminal in nature. 56 Some reports attribute major financial and security threats to the ever-increasing volume of new viruses released on the Internet each year. 57 These virus releases can originate from any location equipped with a telephone line, and the effects can vary widely. The act of releasing a computer virus contains the basic elements of what makes certain conduct criminal, namely community condemnation and moral delinquency. 58

a. Melissa

The Melissa virus first surfaced in March 1999, rapidly infecting computers across the world and causing eighty billion dollars in damages. 59 Melissa was the fastest-spreading virus the United States had ever seen, hitting over one hundred thousand U.S. computers in just a few days. 60 The virus spread via e-mail, invading users' address books and sending up to fifty e-mail messages to addresses stored on the infected computer. 61 The virus enticed the user into opening an attachment with the message subject header "Important Message from (the name of someone on the list)." 62 Melissa spread rapidly, and within forty-eight hours major companies such as Microsoft and Intel were forced to shut down their servers. 63

b. Chernobyl

April 26, 1999 marked the thirteenth anniversary of Russia's Chernobyl nuclear power plant meltdown, and the day Chen Ing-hau chose to trigger a release of his virus of the same name causing "a meltdown of a different kind." 64 The virus "Chernobyl" or "CIH" 65 was a particularly frightening virus because its infection actually damages a computer, rendering it physically inoperable. 66 Infecting computers running Windows 95 and 98, Chernobyl "deleted data on a computer's hard drive and attempted to overwrite and destroy a PC's flash BIOS, which [are] needed to boot the computer." 67

Although Chernobyl "paralyzed" sixty million computers across the globe, 68 it scarcely affected the United States. 69 Since the recent Melissa virus disaster, 70 U.S. companies improved their virus protection strategies that successfully shielded them from the Chernobyl virus. 71 However, as the rest of the world was uninformed about the Melissa virus and therefore unaware of the need to improve its technology, Chernobyl hit the rest of the world hard, with Asia suffering the most serious damages. 72


On May 4, 2000, the Internet experienced a monumental disaster when the ILOVEYOU virus surfaced, infecting millions of computer files around the world. 73 The virus, which quickly earned the nickname the "Love Bug" due to the "I Love You" phrase displayed in the subject-matter heading of each contaminated e-mail, 74 activates when the e-mail attachment is downloaded, thereby destroying image and sound files stored in the computer. 75 After infecting the terminal, it spreads by automatically sending the e-mail to everyone in the infected computer's address book and thus causing widespread infection. 76 The "Love Bug" reportedly attacked only Microsoft Windows operating systems, the dominant operating systems among personal computers and where most e-mails are downloaded. 77 Conservative estimates show the loss directly attributed to the ILOVEYOU virus at around ten billion dollars. 78

B. Current Laws and Levels of Success

"All nations continue to struggle with defining computer crime and developing computer crime legislation that is applicable to both domestic and international audiences." 79 Unfortunately, countries are not advancing at equal speeds, and virus authors are taking advantage of those countries making slower progress. 80 Understanding the vast gap in the legislative advances of some nations when compared to others leads to the conclusion that more must be done on an international level in order to effectuate successful cyber crime prosecutions.

1. United States Law

There are at least forty different statutes in the United States under which computer criminals can be charged. 81 The United States realized that some offenses such as viruses are unique to computers and require prosecution under specialized statutes tailored to computer related activities. 82 Therefore, the United States has treated cyber crime as a distinct federal offense since 1984. 83 Throughout the 1980s 84 and 1990s, 85 Congress amended cyber crime statutes to reflect the growth in the number and breadth of diversity of cyber crimes. 86 In 1996, Congress passed the National Information Infrastructure Protection Act (NIIPA) 18 U.S.C. 1030 which contains the most recent changes and modifications to the Counterfeit Access Device and Computer Fraud and Abuse Law. 87 The statute, which previously only covered crimes involving computers in more than one state, now covers any computer with Internet access, even if all the computers involved in the crime are located within one state. 88

For virus authors, the relevant portion of NIIPA is section 1030(a)(5), which criminalizes knowingly causing the transmission of a program, code, or command with the intent to cause damage. 89 Sections 1030(a)(5)(B) and (C) criminalize the intentional accessing of a computer in excess of one's authority, 90 and causing damage as a result of that conduct, regardless of intent. Therefore, "unauthorized users, such as hackers who cause the transmission of malevolent software, including viruses, are responsible even if the transmission was not intentional, but only reckless or negligent." 91 The newest version of the legislation removes some of the possible defenses a virus author could raise under earlier versions regarding jurisdiction, intent, and the amount of damages she was required to inflict. 92

For the United States, the Melissa virus concluded with "the first successful prosecution of a virus author in over a decade and only the second successful prosecution in [American] history" 93 under the nation's specialized computer crime statutes. As a result of an extensive search, the virus author, David Smith, was apprehended within a few days of Melissa's appearance. 94 He pled guilty to state 95 and federal charges of causing computer damage, 96 which included an admission that he was responsible for the eighty million dollars in damages to over a million affected computers. 97 Smith is still awaiting sentencing for the crime, 98 despite being found guilty in late 1999. 99 He could receive several years in prison and a fine of hundreds of thousands of dollars. 100

2. Countries with Lesser Computer Crime Laws

While the United States and other technology-dependent countries are drafting sophisticated computer legislation, the majority of countries are not. Outbreaks of damaging and fast-spreading viruses, such as Chernobyl and ILOVEYOU, are illustrative of two countries that have inadequate criminal protection against the spread of computer viruses.

When Chernobyl first surfaced in 1999, military authorities briefly questioned its author, Chen Ing-hau, yet he evaded punishment because Taiwanese companies failed to file complaints. 101 However, when the virus surfaced again in April of 2000, a Taiwanese resident filed criminal charges after the virus infected his computer, 102 and Ing-hau was thereafter arrested by Taiwanese authorities. 103 Since Taiwan does not have a cyber crime law, the Bureau of Criminal Investigation charged him with offenses of destruction and damage. 104 If convicted, Ing-hau faces a maximum sentence of three years. 105

While Ing-hau's arrest is a positive step toward dealing with computer crime, it falls short of the success that legislation specifically designed to combat computer crime can accomplish. 106 Taiwan depended on someone stepping forward to file formal charges, 107 fortunately giving the country a second opportunity to prosecute the virus author. If a law existed that defined Ing-hau's act of intentionally releasing a computer virus onto the Internet as criminal, the government could have prosecuted him over a year earlier, instead of being forced to wait for a civil complaint to surface.

When the ILOVEYOU virus surfaced in May 2000, the Philippines found itself in a situation similar to Taiwan's: an apprehended culprit but no adequate criminal statute under which to charge him. The National Bureau of Investigation (NBI) charged Onel de Guzman, the suspected author of the "Love Bug," 108 with theft, malicious intent, and violation of the Philippines Access Devices Regulation Act, 109 which carries penalties of six to twenty years imprisonment. 110 The Department of Justice Panel reviewed the case and was left with no alternative but to clear De Guzman of all charges because a prima facie case could not be established. 111 One of the member-prosecutors of the three-man panel commented that the charges of theft and malicious intent were bound to fail because "the NBI failed to provide evidences of the suspect's intent to gain or inflict injury." 112 Philippine authorities released de Guzman, and dismissed his formal charges due to a lack of evidence and a lack of a specific law criminalizing computer hacking. 113

The Philippines' embarrassment following the release of this cyber criminal motivated the government to quickly write and pass the Electronic Commerce Act of 2000, 114 legislation that could have facilitated de Guzman's prosecution if it had been in place at the time he committed his act. 115 Although the new piece of legislation came too late to adequately handle the ILOVEYOU disaster, the Philippines is now equipped to deal with such a problem should it arise again.

Although the Philippines is now prepared to combat cyber crime, other virus havens 116 continue to exist around the world. Passing the Electronic Commerce Act of 2000, ensured that the Philippines would no longer be one of these havens, but this is not sufficient to deal with the global threat cyber crimes present. A coordinated international solution is required.

III. The Problem: Enforcement and Extradition

Today, countries worldwide are learning the hard way that their domestic laws are inadequate when attempting to prosecute virus authors located on foreign soil. 117 "Cyberspace has no geographic or political boundaries." 118 The ease with which viruses spread allows virus authors to perpetrate their criminal conduct in one country and simply watch their handiwork spread across national boundaries. Recent Internet virus outbreaks 119 and the difficulties many countries faced attempting to bring the responsible authors to justice demonstrate the ineffectiveness of the current international system. It is evident that only laws which transcend physical boundaries can remedy this ongoing problem.

A. Enforcement Problems

Although countries like the United States drafted specially-tailored laws to aid in the prosecution of computer crimes, very few indictments have actually resulted. 120 One reason for this prosecutorial lag may be that until 1996, prosecution under the Computer Fraud and Abuse Act depended on the type of computer that the virus affected. 121 Another reason may be that those who own statutorily protected computers often do not report security problems for fear that it would spotlight the vulnerability of their computers and cause them to lose business. 122 In addition, there is the difficulty inherent in tracking down a culprit. 123 This may be attributable to both the ease with which one can maintain anonymity on the Internet 124 and the lack of specially trained or experienced agents skilled to investigate complex computer crimes. 125 Together these factors prevent countries from bringing perpetrators of computer-related crimes to justice.

Inability to quickly apprehend a perpetrator may also result in enforcement problems. When a search is underway for a cyber criminal, countries depend on the assistance of the international community. More often than not, countries are unable to respond quickly to each other, causing setbacks to a fast-paced investigation. 126 When a country is forced to request international assistance to handle a developing situation the complex nature of the legal process or a lack of amicable relations between countries sometimes causes a loss of momentum. These types of impediments can result in suspending an entire investigation for weeks, sometimes months. 127 Most countries agree that eliminating the time-consuming red tape that often interferes with an investigation is necessary to ensure a more rapid response to cyber events. 128

Although chronologically, Melissa was one of the first major viruses to appear on the Internet, Melissa is an outstanding illustration of effective cooperation between law enforcement and the Internet community. David Smith was identified through the collaborative efforts of private companies, individual Internet users in Sweden and the United States, 129 America Online, and federal and state law enforcement. 130

Before concluding that Smith's successful prosecution is a result of seamless international cooperation, the underlying circumstances require a closer look. The success and ease with which Smith was apprehended may be due to his choice of authoring Melissa in the United States and remaining in the country until apprehended. The United States, a country with a specialized cyber crime law firmly in place, 131 was well-equipped statutorily to handle the situation once Smith was caught. If Smith had authored Melissa in a country without a cyber crime law or fled to one after releasing the virus, it is less likely he would have been prosecuted. 132 Lack of extradition treaties also aid virus authors in escaping the not-so-long arm of the law.

B. Extradition

Extradition 133 and laws governing computer crimes share a common characteristic: both are "hopelessly outdated and therefore, lagging behind the forces they are trying to regulate." 134 Certain aspects of computer crime legislation are particularly incompatible with extradition. 135 Some countries liberally interpret treaties to allow for extradition while others such as the United States require more formal arrangements. 136

While the United States has entered into numerous treaties with countries all over the globe, 137 U.S. extradition arrangements share many basics traits. The traits relevant to the extradition of cyber criminals are reciprocity, 138 a treaty, 139 and double criminality. 140

Reciprocity is more a function of one nation's goodwill toward another, rather than a technical treaty provision. 141 Reciprocity rests on the notion that if one nation honors another country's request for extradition, the requesting nation will do likewise when the situation is reversed. 142 Reciprocity is most often a critical factor when no treaty exists between the two countries. 143 However, countries such as the United States that require an actual treaty to be in place for any extradition, will always refuse extradition to a country with whom it has no treaty, regardless of goodwill considerations. 144

"Double criminality requires that the offense charged be considered criminal in both the requesting and requested jurisdictions." 145 Originally, the double criminality provision 146 in a treaty stood for securing fundamental rights for the individual. 147 Now it functions as a loophole that allows computer criminals to escape prosecution. 148 Although most nations agree that spreading computer viruses should be illegal, extradition is difficult because of disagreement over the severity of punishment and precisely what is regulated. 149

Historically, extradition treaties listed extraditable offenses, ensuring that only those particular crimes required a country to hand over a criminal. 150 A major drawback of this approach is its inability to respond to substantive changes in the law. Many countries realized this and amended existing extradition treaties to utilize the "eliminative method," where actions are extraditable if under both countries' laws the action carries a specified minimum level of punishment, 151 usually one year. 152

However, even the eliminative approach contains obstacles, particularly with regard to computer crimes. When such novel crimes are at issue, it becomes impossible to measure the length of a sentence under one country's law against another country's because the latter may not consider the act criminal. 153 This roadblock kept the United States from extraditing the ILOVEYOU virus author from the Philippines. 154 Although the majority of countries today criminalize computer crimes, 155 the lack of legal uniformity causes serious extradition problems. 156

Regardless of the reason for the low number of computer crime prosecutions, it is evident that the current difficulty countries around the world experience in prosecuting virus authors needs correcting. It is no longer sufficient for countries to act independently of one another, through legislation, investigation, or otherwise, because the spread of a computer virus is not a crime likely to be contained within one country. An international solution must be proposed and implemented in order to make successful virus author prosecution a reality.

IV. Proposed Solutions

Most experts agree that it would be ideal if international cooperation existed to facilitate the apprehension of virus authors. 157 Because the outbreak of a computer virus is frequently a cross-border incident, only an international or a uniform approach to the problem can expedite the task of bringing offenders to justice. While no consensus exists as to what is the best method, some proposed solutions have surfaced. These solutions include adopting amendments to domestic legislation to better facilitate extradition, implementing a global cyber crime police unit, and building stronger centralized government. Others, however, advocate government deregulation. The Council of Europe's multilateral draft Cyber-Crime Treaty comprises a final proposed solution to increase the apprehension and prosecution of virus authors.

A. Facilitation of Extradition

One way to facilitate extradition is to change a nation's laws to provide for extradition in the absence of a specific treaty being in place. At the domestic level, language could be added to existing extradition laws to afford more guarantees in the extradition of computer criminals. 158 If the United States inserted such language into existing legislation, it might read: "The offenses defined herein shall be considered extraditable offenses so long as the Requesting State possesses equivalent legislation and the Requesting State agrees to reciprocate when presented with any similar requests made by the government of the United States." 159 Such a clause allows extradition even in the absence of an extradition treaty or with an enumerative treaty that does not specifically address computer crimes. 160 It would also allow extradition for crimes, such as the spread of computer viruses, when most countries recognize the act as criminal but differ in opinion as to appropriate levels of punishment. There is evidence that this concept might work in countries that have already added similar legislative provisions. 161 If the United States, which currently lacks such language in its extradition laws, followed suit, extradition for computer crimes would immediately be possible with a number of countries. 162 A U.S. citizen, however, could not be extradited to a nation that did not have equivalent legislation. 163

Amending legislation facilitates the prosecution of virus authors, but it does not solve the problem; some computer crimes may still fall outside extradition's reaches. For example, stronger extradition legislation is not helpful where the requesting country views the act in question as criminal, but the requested country does not. 164 Inconsistencies in the criminalization of particular conduct is especially likely with crimes such as adult pornography and dangerous speech. 165 It is unlikely that a country would go to the extreme of amending the legislation simply to achieve the narrow result of facilitating extradition in the area of computer viruses. 166 In addition, simply amending extradition laws may realistically fail due to the depth of the digital divide that exists in today's world. "In a world where 1.2 billion people live on less than $ 1 a day," 167 the problems associated with computers and malicious codes are trivial and irrelevant to many countries. 168

An alternative way to facilitate extradition is to amend the treaties themselves, both the substantive and procedural sections, to include computer crimes. As previously discussed, most of the older U.S. treaties list specific offenses that are extraditable, rather than use the newer eliminative method. 169 Practical application of this solution would force lawmakers to consider amending each of the vast number of extradition treaties the United States already has in place. 170

Changing existing treaties or legislation to facilitate extradition is theoretically noteworthy. However, the diversity among national laws on computer crimes forewarn that this solution is of little real merit as it would leave open too many gaps. In sum, "stronger treaties and a uniformity of computer crime laws must evolve before extradition will ever become a truly effective mechanism for permitting apprehension and prosecution of international computer criminals." 171

B. Varying Levels of Cooperation Between Law Enforcement and the Private Sector

Both law enforcement and the private sector have an interest in combating computer crimes. Separately, the ability of law enforcement and the private sector to combat cyber crime is limited. 172 Some believe, however, that a cooperative effort between the two is the most effective way of preventing and apprehending perpetrators of cyber crime. 173 Many organizations and global leaders have voiced the need for the implementation of such a solution. 174

Former U.S. Attorney General Janet Reno is not alone in believing that "increased cooperation between law enforcement and industry" 175 is the surest way to effectively handle identifying, locating, and punishing cyber criminals. Reno acknowledged the government's shortcomings in technical ability, pointing out that federal agents are quite aware that the increasing complexity of cyber crimes is exceeding the ability of law enforcement agencies to prosecute them. 176 Without assistance from the private sector, government investigators are at a disadvantage. 177

Interpol, "the world's pre-eminent organization supporting the prevention and detection of international crime," 178 made the idea of cooperation between the public and private sector a reality. Interpol worked directly with AtomicTangerine, a consulting "powerhouse," to create an innovative alliance between the private and public sector. 179 Interpol and AtomicTangerine "initiated a special relationship designed to deliver advanced intelligence collected by the law enforcement organization to corporations worldwide." 180 Basically, law enforcement gives to the private sector the technological advancements aimed at protecting computer systems from outside attacks. The private sector reciprocates by sharing helpful information it gathers, such as user profiles, to government agencies. 181

While voluntary cooperation between the public and private sectors is a practical solution in theory, it may not be plausible on an international scale. For example, many U.S. corporations do not like the idea of cooperating with law enforcement in criminal investigations, fearing that turning over information may breach privacy agreements they have with their customers. 182 These concerns will continue even if the government tightened its regulations and mandated cooperation during computer crime investigations. 183

C. Stronger Governments

Some government efforts do not require help from the private sector to combat computer crime. In fact, several do not believe that public and private sector cooperation is the solution at all. 184 The public sector strongly believes it must recruit individuals that possess the necessary computer skills, whether they are would-be hackers 185 or corporate computer professionals, 186 to use their talents to combat cyber criminals' technological superiority. One example of this "independent" approach is the new specialist squad based at the multi-agency National High-Tech Crime Unit in London which targets computer criminals who use the Internet to commit crimes across international borders. 187 The specialist unit, to be set up in April 2001, consists of staff drawn from Customs, National Crime Squad, and the National Criminal Intelligence Service. 188 The United Kingdom invested twenty-five million pounds toward implementing the Unit, a squad totaling over eighty "cyber cops" based in regional police forces around England and Wales. 189 The countries that attended the Group of Eight nations (G8) meeting in Berlin in October 2000 discussed cyber crime and reached an agreement to fund "a team dedicated to Internet crime to provide an instant response... ." 190 To compliment this "strategic fight against crime," the British government committed thirty-seven million pounds to fund a National Management Information System (NMIS) for police forces in England and Wales. 191

NMIS will provide the police with a comprehensive information management and analysis tool, "joining-up' data held on the various information technology systems from every force and area of police work. The system will present this data in a consistent format so the whole range of police business can be easily and reliably compared and analyzed across the country. 192

The funding will also be used to help finance an international hotline to exchange information regarding and facilitating investigations of cyber crimes. 193

Again, combating cyber crime by acquiring technological specialists to improve the quality of computer investigations is noteworthy in theory, but not practical. 194 Individuals with specialized abilities are in demand and unlikely to accept positions with government organizations when private corporations are willing to pay them relatively higher salaries. 195 Unless government agencies can increase the salaries of such specialists, they will continue to surrender talent to the private sector.

D. Government Deregulation

The solution primarily advanced by the private sector is for government to refrain from regulating computer crimes that cause security breaches, including computer viruses. Only a minority of IT leaders think extensive government involvement is the correct course of action. 196 Corporate leaders are interested in letting "technology flourish," and prefer that government "apply no more than a light touch" to Internet security issues. 197

Those promoting less government regulation focus on the amount of time allocated by legislators to deal with cyber problems such as computer viruses. Many elected officials believe that "the machinery of government should only be deployed to solve problems that the private sector cannot solve on its own," 198 and some private sectors agree. 199 One scholar even suggested that allowing government to obviate what private corporations could accomplish through their own security research is almost harmful: forcing legislators to address issues that the private sector can completely take care of itself, diverts the legislators attention from other pressing matters. 200 Another concern surrounding the criminalization of computer acts is that legislators often misunderstand technology and thus struggle when developing solutions. 201 Lawmaking is already a long term process that desperately tries to keep pace with evolving technology. 202 In short, the slow process of legislation and the quick growth and change of computer crime do not compliment one another.

Opponents of government regulation also argue that individuals should be left to settle their differences via tort actions. Providing remedies in tort for computer virus infections may effectively deter further virus outbreaks. 203 Since the "wide-spread, non-uniform" damage caused by virus infections is similar to the personal injuries suffered in other mass torts, it may be best handled by class action suits. 204 Civil suits would target software companies and Internet service providers (ISPs), giving them incentive to upgrade security and better screen the background of their customers. "Because individuals are often judgment proof, software distributors and on-line service providers present more lucrative targets and must adapt their business strategies to offset this increased risk of liability." 205 Distributors and ISPs who would bear the majority of the liability can protect themselves by acquiring 206 liability insurance, making a contractual disclaimer, and developing secure computer strategies.

In theory, holding ISPs and software distributors financially liable in civil tort for the millions of dollars in damages caused by viruses is logical, because they are in the best positions to shoulder the financial burden. In addition the ISP through which the perpetrator spreads the virus onto the Internet can eliminate him as a customer immediately and notify all other ISPs of his identity in order to avoid a recurrence. However, assuring that those harmed are reimbursed for their damages focuses more on the aftermath following a virus release and only contributes marginally to deterring the perpetrator if he is judgment-proof. As earlier noted, deterrence is a basic necessity. 207 Without the threat of prison, little remains to deter judgment-proof criminals. Furthermore, only providing victims a remedy in civil tort 208 does nothing to bring the culprit to justice in the criminal forum.

Regardless of whether a victim can recover monetary damages from a virus attack, the problem of prosecuting the virus author is still not addressed. Allowing for a civil remedy in tort is an important feature in computer law because it provides companies with an incentive to report the attacks. 209 However, authorities are still at a disadvantage if there are no criminal laws under which to prosecute cyber criminals. The difficulty of prosecution across international borders pervades without the implementation of a uniform solution applicable to all countries around the world.

E. The Council of Europe's Draft Cyber-Crime Treaty

An effort that solves the uniformity problem for any proposed solution to virus crime is currently underway. "Forty-one countries stretching from Iceland to the former Soviet republic of Georgia could be close to approving a treaty that would fight cyber crime." 210 In response to the growing number of computer viruses, a special committee of the Council of Europe, 211 consulting with the U.S. Department of Justice, 212 proposed a convention "to harmonize cyber-crime laws and facilitate international investigations." 213 The "Draft Convention on Cyber-Crime" (Draft Treaty) includes, among other things, provisions dealing with illegal access and interception of computerized information of any kind, including data and system interference. 214 Some provisions contained in the draft treaty limit the production, distribution, and possession of the software used by hackers to exploit computer vulnerabilities. 215 The Treaty, still in its drafting phase, "will be the first ever international treaty to address criminal behavior directed against computer systems, networks or data and other types of similar misuse," 216 and may be signed as early as mid-2001. 217

1. The Relevant Provisions of the Treaty

The current draft of the Treaty, released on December 22, 2000, "attempts to level the playing field throughout Europe by standardizing computer crime statutes and requiring signatories to cooperate with one another." 218 For example, the Draft Treaty requires participating nations to make unathorized access 219 and interference of computer systems or communications 220 a criminal offense. Others criminalize the production, sale, distribution, or other distribution of devices or computer programs whose primary use is to access, intercept, or interfere with computer systems or communications. 221 The Draft Treaty also requires signatory nations to hold corporations liable for crimes committed by an employee holding a "leading position," 222 and requires ISPs to collect data on their subscribers and make available such data to authorities. 223 Signatories are also required to cooperate with other jurisdictions to secure evidence 224 and extradite persons charged with a computer crime. 225

2. Supporters of the Treaty

Various global groups, including the G8 and the Council of Europe, believe that treaties are the only way to align countries against cyber criminals. 226 These entities recognize that treaties create effective law enforcement and are pressing for treaties that address data and computer crimes. 227 Draft Treaty's call for the regulation of "cyberweapons," such as hacking tools that have generally escaped regulation, has been praised. 228 "Cyberweapons control would establish a standard for behavior on the Internet and provide a means for prosecuting offenders. Their enforcement could curtail attacks and limit the damage by those brazen enough to violate the law." 229

The Draft Treaty eliminates many of the problems found with the other proposed solutions previously discussed. 230 For instance, the need to change domestic legislation 231 or amend existing treaties 232 in order to facilitate extradition becomes irrelevant because the Draft Treaty contains provisions that ameliorate the dilemma. 233 The problem of facilitating cooperation between the public and private sectors during criminal investigations is also solved by provisions in the treaty making such cooperation mandatory for all signatories. 234 The same provision also eliminates the complications involved in strengthening government agencies by increasing the number of highly skilled technical investigators 235 because all involved work cooperatively. 236 In sum, the Draft Treaty surpasses the other proposed solutions by resolving the prosecutorial problem in one effort as opposed to a combination of many.

3. Opposition

Outright support is not the only response that the Council of Europe's Draft Treaty received. Some have protested the Draft Treaty, arguing that this recent attempt to remedy the inability of countries to effectively prosecute virus authors leaves open too many gaps. 237 The opposition asserts that provisions may be over-broad, thereby inadvertently over-regulating security software currently available on the commercial market. 238 Private companies are anxious because the Draft Treaty contains what they consider burdensome mandates on ISPs to save and possibly relinquish information regarding their customers. 239 Tension also surrounds the controversial assistance of the United States in the Treaty's drafting. 240

"European Union nations ... are about to make nearly any form of hacking - even security research - illegal by treaty." 241 Members of the private sector voiced strong opposition to the Treaty. 242 Currently, hacking for security research purposes is legal in the United States. 243 Professional network administrators fear the Draft Treaty may chill security research. 244 It is necessary to discover possible security breaches and alert others of potential dangers. 245 For the most part, the computer software used to accomplish this type of research has the potential to be used for illegal hacking. 246 Some are concerned that the language in the current version of the Draft Treaty may lead some countries to construe simple possession of such software as intent of malicious activity. 247

Additionally, opponents are outraged that the Draft Treaty requires "internet service providers and network administrators to help police by maintaining detailed logs of all network activity," 248 a measure that at least one U.S. statesman bluntly denounced. 249 Some U.S. Senators repeatedly refuse to support any domestic legislation that requires private sectors to cooperate with the government, 250 an intentional goal of the Draft Treaty. One senator "cautioned security managers that the federal government does not have adequate resources to prosecute security attacks," and urged Congress not to pass legislation that forces companies to cooperate with investigations. 251

Civil rights activists share the private sector's concerns regarding the Draft Treaty 252 and additionally accuse the United States of improperly using its global influence. 253 The Global Internet Liberty Campaign (GILC), 254 a civil rights coalition of twenty-eight international cyber-rights organizations, opposes the European Union's Draft Treaty on Cyber-Crime. 255 Specifically, the GILC takes issue with the involvement of members of the U.S. Department of Justice and Federal Bureau of Investigation in the Treaty's drafting. 256 "[GILC] members believe that U.S. law enforcement is attempting to gain international support for modifications to its own country's laws - support that it has not been able to gain domestically." 257 The GILC fears that, once a significant amount of European countries signed the Treaty and argue that the United States must "reconcile its laws with - what then will have become - the international norm," U.S. Treaty supporters could bring the agreement back to Congress. 258 The GILC campaign interprets U.S. tactics as an "endrun" approach to gain the support overseas for an expansion of authority because it cannot acquire the support domestically. 259

V. Conclusion

A successful cyber crime treaty must address three major areas in order to effectively bring about much needed prosecutions: recognition and enforcement of criminal judgments issued by a particular country's court, efficient and expedient cooperation between nations in the retention of evidence and witnesses, and consistent extradition of criminals. 260 In light of the vast number of computer crimes occurring today, virus regulation and prosecution comprise the most efficient subject matter for a treaty because they involve an area of computer crime that all countries agree must be criminalized. 261

In approaching any long term goal, the drafters of the Treaty must address how much attention a country is willing to devote to computers and Internet problems "in a world where 1.2 billion people live on less than $ 1 a day." 262 This issue inevitably goes hand in hand with the need to measure the depth of the globe's digital divide and devise strategies for closing high tech gaps in order to ensure that the Internet is built as an "Internet for all as opposed ... to an Internet for a few." 263

The Council of Europe's Draft Cyber-Crime Treaty provides the best framework for a successful international solution, a solution with the potential to bring results. As currently drafted, 264 the Draft Treaty's biggest potential problem is that the language may inadvertently result in criminalizing techniques and software commonly used to aid many computer systems in resisting attack. 265 This may result in a chilling effect on research and the use of many types of security tools. 266

The Draft Treaty is scheduled to be signed into effect in June 2001, but there still remains a number of interpretation problems within its language. By proceeding with caution and taking care to address all valid concerns, the Council of Europe can avoid hasty lawmaking that could do more harm than good. If given the time it needs to adequately develop, this Draft Treaty has the potential to offer the international solution necessary to successfully prosecute computer virus authors.

