Can Software Licenses Contribute to Cyberarms Control?

Steve Dierker, Volker Röth · 2018

We discuss the potential role that software licenses can play in cyberarms control, the attribution of cyber attacks and the adherence to international humanitarian law and treaties that stipulate that the effects of war on the civilian population shall be minimized. We consider the increasing reliance of civilian and military institutions on FOSS and conduct a thought experiment: what would happen if a fraction of FOSS migrated to a license with non-military use clauses? If this caused civilian and military systems to diverge in design, and exploits and malware reflect their targets, then erroneous targeting of civilian institutions could be ruled out. This idea led us to perform an initial analysis of software dependencies and their relationship to the propagation of copyleft licenses. We analyzed packet manager data for seven different programming languages, based on data from Libraries.io. Among other things we found that a small number of packages accounts for the majority of the dependencies. The number of dependent packages varies from language to language and ranges from 79% in the case of Cargo to merely 3.9% in the case of Pypi. We also review existing non-military licenses and identify areas that need further research in order to understand the potential and the applicability of non-military licensing regimes.

Read the paper · More papers on PaperTik