<?xml version="1.0"?>
<?xml-stylesheet type="text/xsl" href="billres.xsl"?>
<!DOCTYPE bill PUBLIC "-//US Congress//DTDs/bill.dtd//EN" "bill.dtd">
<bill bill-stage="Introduced-in-House" bill-type="olc" dms-id="HDB2BC4998D6A4B8996EB6A2BD843AB99" key="H" public-private="public"><metadata xmlns:dc="http://purl.org/dc/elements/1.1/">
<dublinCore>
<dc:title>116 HR 3270 IH: Active Cyber Defense Certainty Act</dc:title>
<dc:publisher>U.S. House of Representatives</dc:publisher>
<dc:date>2019-06-13</dc:date>
<dc:format>text/xml</dc:format>
<dc:language>EN</dc:language>
<dc:rights>Pursuant to Title 17 Section 105 of the United States Code, this file is not subject to copyright protection and is in the public domain.</dc:rights>
</dublinCore>
</metadata>
<form>
<distribution-code display="yes">I</distribution-code><congress display="yes">116th CONGRESS</congress><session display="yes">1st Session</session><legis-num display="yes">H. R. 3270</legis-num><current-chamber>IN THE HOUSE OF REPRESENTATIVES</current-chamber><action display="yes"><action-date date="20190613">June 13, 2019</action-date><action-desc><sponsor name-id="G000560">Mr. Graves of Georgia</sponsor> (for himself, <cosponsor name-id="G000583">Mr. Gottheimer</cosponsor>, <cosponsor name-id="S001189">Mr. Austin Scott of Georgia</cosponsor>, <cosponsor name-id="C001063">Mr. Cuellar</cosponsor>, <cosponsor name-id="C001103">Mr. Carter of Georgia</cosponsor>, <cosponsor name-id="F000465">Mr. Ferguson</cosponsor>, <cosponsor name-id="R000611">Mr. Riggleman</cosponsor>, <cosponsor name-id="L000583">Mr. Loudermilk</cosponsor>, <cosponsor name-id="S001192">Mr. Stewart</cosponsor>, <cosponsor name-id="P000601">Mr. Palazzo</cosponsor>, <cosponsor name-id="H001072">Mr. Hill of Arkansas</cosponsor>, <cosponsor name-id="B001305">Mr. Budd</cosponsor>, <cosponsor name-id="F000449">Mr. Fortenberry</cosponsor>, <cosponsor name-id="M001202">Mrs. Murphy</cosponsor>, <cosponsor name-id="R000610">Mr. Reschenthaler</cosponsor>, and <cosponsor name-id="R000602">Miss Rice of New York</cosponsor>) introduced the following bill; which was referred to the <committee-name committee-id="HJU00">Committee on the Judiciary</committee-name></action-desc></action><legis-type>A BILL</legis-type><official-title display="yes">To amend title 18, United States Code, to provide a defense to prosecution for fraud and related
			 activity in connection with computers for persons defending against
			 unauthorized intrusions into their computers, and for other purposes.</official-title></form>
	<legis-body id="H1D793F7A1BDD42D8901C4FBA87C55955" style="OLC">
 <section id="HA473B9D21749474083924EB7242D5449" section-type="section-one"><enum>1.</enum><header>Short title</header><text display-inline="no-display-inline">This Act may be cited as the <quote><short-title>Active Cyber Defense Certainty Act</short-title></quote>.</text> </section><section id="HDD8A8ACC832E49F8B5D8FC1889A0EFBD"><enum>2.</enum><header>Congressional findings</header><text display-inline="no-display-inline">Congress finds the following:</text>
 <paragraph id="H27CCC912416845D8B7B2F9E75A622858"><enum>(1)</enum><text>Cyber fraud and related cyber-enabled crimes pose a severe threat to the national security and economic vitality of the United States.</text>
 </paragraph><paragraph id="H6FA815EC0A1B461A8939CBA59EB93042"><enum>(2)</enum><text>As a result of the unique nature of cybercrime, it is very difficult for law enforcement to respond to and prosecute cybercrime in a timely manner, leading to the existing low level of deterrence and a rapidly growing threat. In 2017, the Department of Justice prosecuted only 165 cases of computer fraud. Congress determines that this status quo is unacceptable and that if left unchecked, the trend in cybercrime will only continue to deteriorate.</text>
 </paragraph><paragraph id="H87D3AEB010FA42A391A4188AC40DF330"><enum>(3)</enum><text>Cybercriminals have developed new tactics for monetizing the proceeds of their criminal acts, making it likely that the criminal activity will be further incentivized in the absence of reforms to current law allowing for new cyber tools and deterrence methods for defenders.</text>
 </paragraph><paragraph id="HC680A5C3D6FA4E589920D93F45FA894E"><enum>(4)</enum><text>When a citizen or United States business is victimized as the result of such crime, the first recourse should be to report the crime to law enforcement and seek to improve defensive measures.</text>
 </paragraph><paragraph id="H202BFCA4E57540828BA6C6D5480B5373"><enum>(5)</enum><text>Congress also acknowledges that many cyberattacks could be prevented through improved cyber defensive practices, including enhanced training, strong passwords, and routine updating and patching to computer systems.</text>
 </paragraph><paragraph id="H1FEE4FE39BD749CEA50B151998F496CF"><enum>(6)</enum><text>Congress determines that the use of active cyber defense techniques, when properly applied, can also assist in improving defenses and deterring cybercrimes.</text>
 </paragraph><paragraph id="HAEDB9D38A8AA431E8B9D4FD2A1F18449"><enum>(7)</enum><text>Congress also acknowledges that many private entities are increasingly concerned with stemming the growth of dark web based cyber-enabled crimes. The Department of Justice should attempt to clarify the proper protocol for entities who are engaged in active cyber defense in the dark web so that these defenders can return private property such as intellectual property and financial records gathered inadvertently.</text>
 </paragraph><paragraph id="HC3020A6A347A4D96A46FAF01C2BF9DB3"><enum>(8)</enum><text>Congress also recognizes that while Federal agencies will need to prioritize cyber incidents of national significance, there is the potential to assist the private sector by being more responsive to reports of crime through different reporting mechanisms. Many reported cybercrimes are not responded to in a timely manner creating significant uncertainty for many businesses and individuals.</text>
 </paragraph><paragraph id="HA1428D27CED248309D97A9BDBE9D943E"><enum>(9)</enum><text>Computer defenders should also exercise extreme caution to avoid violating the law of any other nation where an attacker’s computer may reside.</text>
 </paragraph><paragraph id="H43557FA2071B45C8B9ABBE6F571CE819"><enum>(10)</enum><text>Congress holds that active cyber defense techniques should only be used by qualified defenders with a high degree of confidence in attribution, and that extreme caution should be taken to avoid impacting intermediary computers or resulting in an escalatory cycle of cyber activity.</text>
 </paragraph><paragraph id="H3BA7E945501741359D1CF79569399460"><enum>(11)</enum><text>It is the purpose of this Act to provide legal certainty by clarifying the type of tools and techniques that defenders can use that exceed the boundaries of their own computer network.</text>
 </paragraph></section><section id="HA5A21D5666A947F98ACFA6CE8D478A0B"><enum>3.</enum><header>Exception for the use of attributional technology</header><text display-inline="no-display-inline">Section 1030 of title 18, United States Code, is amended by adding at the end the following:</text> <quoted-block id="HAB55A1DCA02A40E2AFB900E2145424F9" style="OLC"> <subsection id="HBA76916CCA8F43DFBD1320F11F971DD0"><enum>(k)</enum><header>Exception for the use of attributional technology</header> <paragraph id="H668A84379DEF41EDB4A47AEBE1E3D132"><enum>(1)</enum><text>This section shall not apply with respect to the use of attributional technology in regard to a defender who uses a program, code, or command for attributional purposes that beacons or returns locational or attributional data in response to a cyber intrusion in order to identify the source of an intrusion; if—</text>
 <subparagraph id="HEAC4A202D4DF459685273FBA193118A2"><enum>(A)</enum><text>the program, code, or command originated on the computer of the defender but is copied or removed by an unauthorized user; and</text>
 </subparagraph><subparagraph id="HDC49DD59646A470BAE1B46F50D955EDF"><enum>(B)</enum><text>the program, code, or command does not result in the destruction of data or result in an impairment of the essential operating functionality of the attacker’s computer system, or intentionally create a backdoor enabling intrusive access into the attacker’s computer system.</text>
 </subparagraph></paragraph><paragraph id="H3A2EDA62176A440390B3C4119493D44C"><enum>(2)</enum><header>Definition</header><text>The term <quote>attributional data</quote> means any digital information such as log files, text strings, time stamps, malware samples, identifiers such as user names and Internet Protocol addresses and metadata or other digital artifacts gathered through forensic analysis.</text></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block>
		</section><section id="HB269DF06A06B478EBE0408982208E1EF"><enum>4.</enum><header>Exclusion from prosecution for certain computer crimes for those taking active cyber defense
 measures</header><text display-inline="no-display-inline">Section 1030 of title 18, United States Code, is amended by adding at the end the following:</text> <quoted-block id="HAABBD48A16EC49CAA1FAC4C7588E1368" style="OLC"> <subsection id="H15FAC7CB87964C1D8F6D46561F5BCC78"><enum>(l)</enum><header>Active cyber defense measures not a violation</header> <paragraph id="HE6F92120AB6942C3BDFC1A45D981852A"><enum>(1)</enum><header>Generally</header><text>It is a defense to a criminal prosecution under this section that the conduct constituting the offense was an active cyber defense measure.</text>
 </paragraph><paragraph id="HEE4462546A254970A9AA55A8C5C0D28D"><enum>(2)</enum><header>Inapplicability to civil action</header><text>The defense against prosecution created by this section does not prevent a United States person or entity who is targeted by an active defense measure from seeking a civil remedy, including compensatory damages or injunctive relief pursuant to subsection (g).</text>
 </paragraph><paragraph id="HD696AD86BCAC49A8BC3E66CC710ED80C"><enum>(3)</enum><header>Definitions</header><text>In this subsection—</text> <subparagraph id="H825CDE9CBAD04B7094AD302318C718D6"><enum>(A)</enum><text>the term <quote>defender</quote> means a person or an entity that is a victim of a persistent unauthorized intrusion of the individual entity’s computer;</text>
 </subparagraph><subparagraph id="HF233C492FADD4BFFAFDA9D922D0943AF"><enum>(B)</enum><text>the term <quote>active cyber defense measure</quote>—</text> <clause id="H8CD4B29C6BA843289E75A57E1698E57F"><enum>(i)</enum><text>means any measure—</text>
 <subclause id="H131FD75BF1D849BA9B1E3CDD472D5323"><enum>(I)</enum><text>undertaken by, or at the direction of, a defender; and</text> </subclause><subclause id="H8CD5F71B4A2B4681904C7B4873F93559"><enum>(II)</enum><text>consisting of accessing without authorization the computer of the attacker to the defender’s own network to gather information in order to—</text>
 <item id="HBF4BC3551F364DD7B7466F31DFFA3F28"><enum>(aa)</enum><text>establish attribution of criminal activity to share with law enforcement and other United States Government agencies responsible for cybersecurity;</text>
 </item><item id="H62DD721DB23A4094B579176D72FDB1C6"><enum>(bb)</enum><text>disrupt continued unauthorized activity against the defender’s own network; or</text> </item><item id="HB49C7019CAA64F4E8821BB1E529EBD0D"><enum>(cc)</enum><text>monitor the behavior of an attacker to assist in developing future intrusion prevention or cyber defense techniques; but</text>
 </item></subclause></clause><clause id="HE9E8D4A2F58A49B2AF32EFAE7C43459F"><enum>(ii)</enum><text>does not include conduct that—</text> <subclause id="H4B0F8A1E373D40F3A183BC57814089D4"><enum>(I)</enum><text>intentionally destroys or renders inoperable information that does not belong to the victim that is stored on another person or entity’s computer;</text>
 </subclause><subclause id="H71C82230CC2E45958768ED4C7F4CB8C2"><enum>(II)</enum><text>recklessly causes physical injury or financial loss as described under subsection (c)(4);</text> </subclause><subclause id="H2812223AFB404D0AA2AD2AAD418B23B0"><enum>(III)</enum><text>creates a threat to the public health or safety;</text>
 </subclause><subclause id="H8E85E5E5A20C43589DA4F5EA29130D3A"><enum>(IV)</enum><text>intentionally exceeds the level of activity required to perform reconnaissance on an intermediary computer to allow for attribution of the origin of the persistent cyber intrusion;</text>
 </subclause><subclause id="HE218B7B11264499A987CA3147A3916A6"><enum>(V)</enum><text>intentionally results in intrusive or remote access into an intermediary’s computer;</text> </subclause><subclause id="HBA993256B31948619479BBCBB363F52C"><enum>(VI)</enum><text>intentionally results in the persistent disruption to a person or entities internet connectivity resulting in damages defined under subsection (c)(4); or</text>
 </subclause><subclause id="H774AFF96AA46421D9585494FAE01DAED"><enum>(VII)</enum><text>impacts any computer described under subsection (a)(1) regarding access to national security information, subsection (a)(3) regarding government computers, or to subsection (c)(4)(A)(i)(V) regarding a computer system used by or for a Government entity for the furtherance of the administration of justice, national defense, or national security;</text>
 </subclause></clause></subparagraph><subparagraph id="HE17C7447E71C4362900D4520A53AC51F"><enum>(C)</enum><text>the term <quote>attacker</quote> means a person or an entity that is the source of the persistent unauthorized intrusion into the victim’s computer; and</text>
 </subparagraph><subparagraph id="H7F9047EE014A47C89256BE8A37CFEFC1"><enum>(D)</enum><text>the term <quote>intermediary computer</quote> means a person or entity’s computer that is not under the ownership or primary control of the attacker but has been used to launch or obscure the origin of the persistent cyber-attack.</text></subparagraph></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block>
 </section><section id="H33AB5C6550C6486CBC18015CC47CC458"><enum>5.</enum><header>Notification requirement for the use of active cyber defense measures</header><text display-inline="no-display-inline">Section 1030 of title 18, United States Code, is amended by adding the following:</text> <quoted-block id="HDAFFAA3E28CE46D6881D10C91F8586C9" style="OLC"> <subsection id="HDAC111D9BA6746F2889ADBF50F81D914"><enum>(m)</enum><header>Notification requirement for the use of active cyber defense measures</header> <paragraph id="H7DF5210FF5104B1DB653D9ACB4150384"><enum>(1)</enum><header>Generally</header><text display-inline="yes-display-inline">A defender who uses an active cyber defense measure under the preceding section must notify the FBI National Cyber Investigative Joint Task Force and receive a response from the FBI acknowledging receipt of the notification prior to using the measure.</text>
 </paragraph><paragraph id="HB5300196443848BAA3B772734A9288D0"><enum>(2)</enum><header>Required information</header><text display-inline="yes-display-inline">Notification must include the type of cyber breach that the person or entity was a victim of, the intended target of the active cyber defense measure, the steps the defender plans to take to preserve evidence of the attacker’s criminal cyber intrusion, as well as the steps they plan to prevent damage to intermediary computers not under the ownership of the attacker and other information requested by the FBI to assist with oversight.</text></paragraph></subsection><after-quoted-block>.</after-quoted-block></quoted-block>
		</section><section id="H889172DD1E7F44EA80411478E94EC649"><enum>6.</enum><header>Voluntary preemptive review of active cyber defense measures</header>
 <subsection id="H0DC98CA46A4D44758A09D074318F9CE1"><enum>(a)</enum><header>Pilot program</header><text>The Federal Bureau of Investigation (hereinafter in this section referred to as the <quote>FBI</quote>), in coordination with other Federal agencies, shall create a pilot program to last for 2 years after the date of enactment of this Act, to allow for a voluntary preemptive review of active defense measures.</text>
 </subsection><subsection id="H2FCC0F7E2C064DF992CD9E4D65E4E6D5"><enum>(b)</enum><header>Advance review</header><text>A defender who intends to prepare an active defense measure under section 4 may submit their notification to the FBI National Cyber Investigative Joint Task Force in advance of its use so that the FBI and other agencies can review the notification and provide its assessment on how the proposed active defense measure may be amended to better conform to Federal law, the terms of section 4, and improve the technical operation of the measure.</text>
 </subsection><subsection id="H4DD17D9D0F0641FABFEBDDE7B0A69E3A"><enum>(c)</enum><header>Prioritization of requests</header><text>The FBI may decide how to prioritize the issuance of such guidance to defenders based on the availability of resources.</text>
			</subsection></section><section id="H594E8ADF368F4D51B4FD37EFADF8DCD2"><enum>7.</enum><header>Annual report on the Federal Government’s progress in deterring cyber fraud and cyber-enabled
 crimes</header><text display-inline="no-display-inline">The Department of Justice, after consultation with the Department of Homeland Security and other relevant Federal agencies, shall deliver an annual report to Congress not later than March 31 of each year, detailing the results of law enforcement activities pertaining to cybercriminal deterrence for the previous calendar year. The report shall include—</text>
 <paragraph id="H98B190851FCE415494D59750A3AB22E1"><enum>(1)</enum><text>the number of computer fraud cases reported by United States citizens and United States businesses to FBI Field Offices, the Secret Service Electronic Crimes Task Force, the Internet Crimes Complaint Center (IC3) website, and other Federal law enforcement agencies;</text>
 </paragraph><paragraph id="H3C5D16924772484FB1DFA50C60E44B17"><enum>(2)</enum><text>the number of investigations opened as a result of public reporting of computer fraud crimes, and the number of investigations open independently of any specific crimes being reported;</text>
 </paragraph><paragraph id="HB71B3EB32F06439197190182BC9DDE0B"><enum>(3)</enum><text>the number of cyber fraud cases prosecuted under section 1030 of title 18, United States Code, and other related statutes involving cybercrime, including the resolution of the cases;</text>
 </paragraph><paragraph id="H8866097B61DC4EC2B391C48B5959B4E6"><enum>(4)</enum><text>the number of computer fraud crimes determined to have originated from United States suspects and the number determined to have originated from foreign suspects, and details of the country of origin of the suspected foreign suspects;</text>
 </paragraph><paragraph id="H4015CE8EAFCD4A46B4A43AA95EAD7426"><enum>(5)</enum><text>the number of dark web cybercriminal marketplaces and cybercriminal networks disabled by law enforcement activities;</text>
 </paragraph><paragraph id="H8A634B5F52C44D5EBA848F03B34C2465"><enum>(6)</enum><text>an estimate of the total financial damages suffered by United States citizens and businesses resulting from ransomware and other fraudulent cyberattacks;</text>
 </paragraph><paragraph id="H6B4A78030ADC40A4AC173C49AA0F4E81"><enum>(7)</enum><text>the number of law enforcement personnel assigned to investigate and prosecute cybercrimes; and</text> </paragraph><paragraph id="H7F05373776B84EDFB188A64ADAD41869"><enum>(8)</enum><text display-inline="yes-display-inline">the number of active cyber defense notifications filed as required by this Act and a comprehensive evaluation of the notification process and voluntary preemptive review pilot program.</text>
			</paragraph></section><section id="H6B4A9827FD6A47BBBDFB1146F800ED66"><enum>8.</enum><header>Requirement for the Department of Justice to update the manual on the prosecution of cybercrimes</header>
 <subsection id="H4FB6FA963DDC403E9AB135ED61093B6A"><enum>(a)</enum><text>The Department of Justice shall update the <quote>Prosecuting Computer Crimes Manual</quote> to reflect the changes made by this legislation.</text> </subsection><subsection id="H1121730E663E40BFAE78E295F481EC9B"><enum>(b)</enum><text>The Department of Justice is encouraged to seek additional opportunities to clarify the manual and other guidance to the public to reflect evolving defensive techniques and cyber technology that can be used in manner that does not violate section 1030 of title 18, United States Code, or other Federal law and international treaties.</text>
 </subsection></section><section id="HD4DBA932580645C38AD780703D22A004"><enum>9.</enum><header>Sunset</header><text display-inline="no-display-inline">The exclusion from prosecution created by this Act shall expire 2 years after the date of enactment of this Act.</text>
		</section></legis-body></bill>


