The Tallinn Manual on the International Law Applicable to Cyber Warfare draws on Michael N. Schmitt's factor analysis to judge whether a cyber operation is a mere "use of force" (UN Charter Art. 2(4)) or crosses into an "armed attack" that can trigger self-defense (Art. 51) โ no state has ever formally invoked Art. 51 over a cyber operation, so this remains an analytical framework, not settled case law.
7 factors, each scored 0-10, plotted on the radar:
Severity โ physical/economic harm, casualties
Immediacy โ speed from cause to effect
Directness โ causal chain length to the harm
Invasiveness โ depth of intrusion into the target system
Measurability โ how quantifiable the damage is
Military char. โ resemblance to a traditional military act
State resp. โ attribution confidence to a state actor
Composite = ฮฃ(wk ยท fk) / ฮฃwk, weights favor Severity (x3) and
Military character (x2) per Tallinn Manual commentary.
score < 5.0 -> below use-of-force threshold (gray zone)
5.0 <= score < 7.0 -> use of force, Art. 2(4)
score >= 7.0 -> armed attack, Art. 51 self-defense may apply
Immediacy, measurability and directness are derived from the sliders you control (severity, invasiveness, military character) using the correlations Schmitt's commentary describes between them โ e.g. highly invasive intrusions tend to have more measurable, more direct effects.
The strip plot runs a small Monte Carlo model: each of the alliance's 32 members is given a personal perceived threshold drawn from a Normal(7.0, 1.0) distribution (member states genuinely disagree on where the line sits), and "agrees" only if the composite score exceeds their draw. Article 5 requires consensus of all 32 โ the strip shows how far from unanimous a given incident would fall. Drag the radar chart to rotate it; the history strip underneath scrolls the composite score over time.