Active Cyber Defense Certainty Act
A BILL
To amend title 18, United States Code, to provide a defense to prosecution for fraud and related activity in connection with computers for persons defending against unauthorized intrusions into their computers, and for other purposes.
2. Congressional findings
3. Exception for the use of attributional technology
“(k) Exception for the use of attributional technology
“(1) This section shall not apply with respect to the use of attributional technology in regard to a defender who uses a program, code, or command for attributional purposes that beacons or returns locational or attributional data in response to a cyber intrusion in order to identify the source of an intrusion; if—
“(A) the program, code, or command originated on the computer of the defender but is copied or removed by an unauthorized user; and
“(B) the program, code, or command does not result in the destruction of data or result in an impairment of the essential operating functionality of the attacker’s computer system, or intentionally create a backdoor enabling intrusive access into the attacker’s computer system.
“(2) Definition—The term “attributional data” means any digital information such as log files, text strings, time stamps, malware samples, identifiers such as user names and Internet Protocol addresses and metadata or other digital artifacts gathered through forensic analysis.”
4. Exclusion from prosecution for certain computer crimes for those taking active cyber defense measures
“(l) Active cyber defense measures not a violation
“(1) Generally—It is a defense to a criminal prosecution under this section that the conduct constituting the offense was an active cyber defense measure.
“(2) Inapplicability to civil action—The defense against prosecution created by this section does not prevent a United States person or entity who is targeted by an active defense measure from seeking a civil remedy, including compensatory damages or injunctive relief pursuant to subsection (g).
“(3) Definitions—In this subsection—
“(A) the term “defender” means a person or an entity that is a victim of a persistent unauthorized intrusion of the individual entity’s computer;
“(B) the term “active cyber defense measure”—
“(i) means any measure—
“(I) undertaken by, or at the direction of, a defender; and
“(II) consisting of accessing without authorization the computer of the attacker to the defender’s own network to gather information in order to—
“(aa) establish attribution of criminal activity to share with law enforcement and other United States Government agencies responsible for cybersecurity;
“(bb) disrupt continued unauthorized activity against the defender’s own network; or
“(cc) monitor the behavior of an attacker to assist in developing future intrusion prevention or cyber defense techniques; but
“(ii) does not include conduct that—
“(I) intentionally destroys or renders inoperable information that does not belong to the victim that is stored on another person or entity’s computer;
“(II) recklessly causes physical injury or financial loss as described under subsection (c)(4);
“(III) creates a threat to the public health or safety;
“(IV) intentionally exceeds the level of activity required to perform reconnaissance on an intermediary computer to allow for attribution of the origin of the persistent cyber intrusion;
“(V) intentionally results in intrusive or remote access into an intermediary’s computer;
“(VI) intentionally results in the persistent disruption to a person or entities internet connectivity resulting in damages defined under subsection (c)(4); or
“(VII) impacts any computer described under subsection (a)(1) regarding access to national security information, subsection (a)(3) regarding government computers, or to subsection (c)(4)(A)(i)(V) regarding a computer system used by or for a Government entity for the furtherance of the administration of justice, national defense, or national security;
“(C) the term “attacker” means a person or an entity that is the source of the persistent unauthorized intrusion into the victim’s computer; and
“(D) the term “intermediary computer” means a person or entity’s computer that is not under the ownership or primary control of the attacker but has been used to launch or obscure the origin of the persistent cyber-attack.”
5. Notification requirement for the use of active cyber defense measures
“(m) Notification requirement for the use of active cyber defense measures
“(1) Generally—A defender who uses an active cyber defense measure under the preceding section must notify the FBI National Cyber Investigative Joint Task Force and receive a response from the FBI acknowledging receipt of the notification prior to using the measure.
“(2) Required information—Notification must include the type of cyber breach that the person or entity was a victim of, the intended target of the active cyber defense measure, the steps the defender plans to take to preserve evidence of the attacker’s criminal cyber intrusion, as well as the steps they plan to prevent damage to intermediary computers not under the ownership of the attacker and other information requested by the FBI to assist with oversight.”