Skip to the main content

Original scientific paper

https://doi.org/10.63191/mcpr.17.1.2

Legal and Ethical Responsibility in Unwitting DDoS/DRDoS Participation

Krunoslav Antoliš


Full text: english pdf 103 Kb

page 25-36

downloads: 0

cite


Abstract

The digital space is becoming increasingly complex, and cyberattacks such as DDoS and DRDoS pose a serious threat to critical infrastructure, corporations, and individuals (Zengupta et al., 2021). A key issue in this context is the question of responsibility when a computer owner is unaware that their device has been compromised and used in an attack. This paper analyzes the legal, technical, and ethical aspects of responsibility in the digital space through three research questions: (1) how legal frameworks treat the responsibility of owners in cases of ignorance, (2) which technical measures can prevent involuntary participation in attacks, and (3) whether there is an ethical obligation for society to educate users.
The methodological approach includes a qualitative analysis of literature, legal documents (EU NIS2 Directive, U.S. CFAA), case studies (Mirai botnet), and expert works on cybersecurity. The results show that most legal systems do not penalize users who were unaware of an infection unless they exhibited gross negligence (Schjolberg, 2017). However, the technical unpreparedness of users necessitates a redistribution of responsibility to software manufacturers, ISPs, and government agencies. The ethical analysis emphasizes the collective nature of cybersecurity and the need for systematic education (Livingstone et al., 2021).

Keywords

Cybersecurity Responsibility, DDoS/DRDoS Attacks, Botnet Involvement, Legal and Ethical Frameworks, Shared Responsibility Model

Hrčak ID:

349525

URI

https://hrcak.srce.hr/349525

Publication date:

17.8.2026.

Visits: 0 *