Original scientific paper
https://doi.org/10.63191/mcpr.17.1.2
Legal and Ethical Responsibility in Unwitting DDoS/DRDoS Participation
Krunoslav Antoliš
Abstract
The digital space is becoming increasingly complex, and cyberattacks such as DDoS and DRDoS pose a serious threat to critical infrastructure, corporations, and individuals (Zengupta et al., 2021). A key issue in this context is the question of responsibility when a computer owner is unaware that their device has been compromised and used in an attack. This paper analyzes the legal, technical, and ethical aspects of responsibility in the digital space through three research questions: (1) how legal frameworks treat the responsibility of owners in cases of ignorance, (2) which technical measures can prevent involuntary participation in attacks, and (3) whether there is an ethical obligation for society to educate users.
The methodological approach includes a qualitative analysis of literature, legal documents (EU NIS2 Directive, U.S. CFAA), case studies (Mirai botnet), and expert works on cybersecurity. The results show that most legal systems do not penalize users who were unaware of an infection unless they exhibited gross negligence (Schjolberg, 2017). However, the technical unpreparedness of users necessitates a redistribution of responsibility to software manufacturers, ISPs, and government agencies. The ethical analysis emphasizes the collective nature of cybersecurity and the need for systematic education (Livingstone et al., 2021).
Keywords
Hrčak ID:
349525
URI
Publication date:
17.8.2026.
Visits: 0 *