Then in LinkedIn: Write article → click into the body → paste (Ctrl+V). Headings, links and images come with it. The title usually pastes as the first line — cut it into LinkedIn's title field. back to the article

Comparing the Main Approaches to War, Security, and Technological Power

Conflict datasets, treaty law, and deterrence theory each explain a piece of how war and technology interact — and none of them explains the whole thing alone.

A conflict-event coding workstation with dual monitors mid-scroll through a geocoded incident log, a paper gazetteer open beside it

A conflict-event coding station: one incident record half-tagged, the cursor still on the location field. — Image prompt and art direction by Brecht Corbeel; image generated to that direction.

Abstract

Security studies uses at least three distinct methods to understand how technology changes war: quantitative conflict-event datasets such as UCDP, ACLED, and the Correlates of War project, which count and geocode violent events; legal and doctrinal analysis of treaty text and military doctrine, which reads formal commitments and rules of engagement; and case-study deterrence theory, which reconstructs the reasoning of decision-makers in a small number of historical crises. This article compares the three approaches on predictive power, granularity, and normative framing, using the same recurring problems — logistics, surveillance, cyber conflict, autonomous weapons, and nuclear proliferation — as test cases. It separates documented fact from vendor and government claims, from analytical inference, from scenario construction, and from forecasting, and it declines to name a single best method: each approach answers a different question, and each is blind to what the others see.

War has always outrun the theories built to explain it, and the technologies that reshape it — geolocation, encrypted communication, autonomous sensors, cheap satellite imagery — arrive faster than any single research tradition can absorb them. Security studies has responded not with one method but with several, and the three that dominate the field today answer genuinely different questions. Quantitative conflict-event analysis, built on datasets like the Uppsala Conflict Data Program (UCDP), the Armed Conflict Location & Event Data Project (ACLED), and the Correlates of War project, counts and geocodes violent incidents to find patterns across thousands of cases. Legal and doctrinal analysis reads treaty text, military doctrine, and rules of engagement to establish what states have formally committed to and how they interpret those commitments in new domains like cyberspace. Case-study deterrence theory, descended from Thomas Schelling’s Cold War writing, reconstructs the reasoning of decision-makers in a small number of historical crises to explain why threats succeed or fail.

None of the three is a diminished version of the others. Each was built to answer a question the other two cannot. This article compares them directly — on predictive power, granularity, and normative framing — using five recurring problems in the field as test cases: military logistics, surveillance, cyber conflict, autonomous weapons, and nuclear proliferation. It keeps documented fact, vendor or government claims, analytical inference, scenario construction, and forecasting in separate lanes throughout, because the biggest source of overreach in this literature is treating one method’s output as though it settled a question only another method can answer.

Three traditions, three units of analysis

The quantitative tradition treats the event as its unit of analysis. UCDP’s Georeferenced Event Dataset defines an event as an incident where an organized actor used armed force against another organized actor or against civilians, resulting in at least one direct death at a specific location and date [1]. That definition is deliberately narrow and mechanical: it does not ask why the violence happened, only whether it happened, where, when, and how many died. Sundberg and Melander describe the dataset’s original purpose as making sub-national, day-level disaggregation possible so that researchers could study the diffusion of violence within conflicts, not just between countries [2]. ACLED extends the same event-logging logic to a wider category of “conflict and protest” activity, including non-lethal incidents, and describes itself as an independent nonprofit monitor rather than a government or intergovernmental body [4]. The Correlates of War project, older than both, works one level up: its unit is the militarized dispute or the war itself, coded since 1816 with fields like battle deaths, participants, and outcome, built explicitly around the principles of replication and transparent coding rules [5].

The legal-doctrinal tradition treats the instrument as its unit of analysis — a treaty article, a doctrine manual, a rule of engagement. The Treaty on the Non-Proliferation of Nuclear Weapons is a compact document: non-nuclear-weapon states agree not to acquire nuclear weapons, nuclear-weapon states agree not to transfer them, and all parties agree to a safeguards system administered by the International Atomic Energy Agency and to pursue eventual disarmament [8]. Reading that treaty tells you what states have promised, and by extension what a violation would look like, but it tells you nothing about how often states actually comply, because compliance is not observed in the text. The Tallinn Manual project extends the same instrument-reading method into a domain with no dedicated treaty at all: a multi-year effort by international law experts produced 154 “black letter” rules describing how existing international law — the law that already governs armed conflict, sovereignty, and state responsibility — applies to cyber operations, on the premise that cyberspace is not a legal vacuum even though no state has ever ratified a cyber-specific treaty [7]. This is doctrinal reasoning by analogy rather than empirical measurement: it tells you what a coherent legal position implies, not what states will actually do under pressure.

The deterrence-theory tradition treats the crisis as its unit of analysis, typically one at a time, reconstructed in depth. Schelling’s foundational argument in Arms and Influence is that military power is used for its persuasive effect on an opponent’s decisions as much as for its direct destructive effect — that the “diplomacy of violence” runs on threats, credible commitments, and the deliberate manipulation of shared risk, not simply on force applied [6]. That single insight generated a research program built on close historical reconstruction: the Cuban Missile Crisis, the Berlin blockade, and later cyber and space incidents, each examined for what decision-makers believed, threatened, and risked. RAND’s cross-domain deterrence work extends the same case-based logic to newer domains, arguing that cyber, space, and autonomous systems complicate deterrence because they share the attribution and escalation-control problems long identified in nuclear case studies, without behaving identically to nuclear weapons [9]. A companion RAND report on escalation vocabulary makes explicit what the tradition has always done implicitly: it builds a typology of escalation dynamics from close reading of historical crises rather than from a dataset of many cases [10].

A treaty text printed on a light table with margin tabs, one clause underlined and a fresh annotation tab half-attached

Figure 1. A treaty clause under annotation: the tab that will mark it is still only half fixed to the page. — Image prompt and art direction by Brecht Corbeel; image generated to that direction.

Predictive power: what each method can and cannot forecast

Quantitative conflict-event data is strongest exactly where deterrence case studies are weakest: base rates across many cases. UCDP’s annual “Organized violence” series reports that global battle-related and one-sided-violence fatalities dropped from roughly 310,000 in 2022 to roughly 154,000 in 2023, a decline the authors attribute in large part to the winding down of the Tigray conflict in Ethiopia, which alone had accounted for roughly 60 percent of recent battle deaths [3]. That is a fact about the recorded world, not a prediction, but it is the kind of pattern only an event dataset spanning decades and many countries can surface: a single conflict’s trajectory dominating a global trend line. No case study of one crisis and no reading of one treaty could produce that number, because it depends on aggregating thousands of geocoded incidents across dozens of active conflicts in a single year.

What conflict-event data cannot do is explain why a specific actor chose escalation over restraint in a specific crisis, because the event record only shows what happened, not the counterfactual reasoning that produced it. That is the deterrence tradition’s strength: Schelling’s account of compellence and the manipulation of risk gives an analyst a vocabulary for asking why a threat was or was not credible in one encounter, something no row in an event dataset encodes [6]. But that same depth is the tradition’s limit — a handful of intensively studied Cold War crises cannot establish a base rate for how often coercive threats succeed, because the cases are neither randomly sampled nor numerous enough to support that kind of inference, and the RAND cross-domain deterrence literature is explicit that new domains like cyber and space break several of the assumptions the original nuclear case studies relied on, such as clear attribution and easily observed capability [9].

Doctrinal and treaty analysis predicts neither aggregate rates nor individual decisions; it predicts legal exposure — what a violation would be classified as and what obligations attach to it. The NPT’s safeguards system creates a monitoring mechanism, not a probability estimate of violation [8], and the Tallinn Manual’s 154 rules describe what a lawful or unlawful cyber operation looks like under existing law, not how likely a given state is to conduct one [7]. This is analysis, not forecasting in the disconfirmable sense: it says what the rules imply, and testing it means examining whether state practice cites, argues from, or violates those rules, not counting future incidents against a predicted rate.

A small server and archival storage room with labelled data drives, one drive half-slotted into an open bay

Figure 2. A dataset archive room: the newest yearly release still half-inserted into its bay. — Image prompt and art direction by Brecht Corbeel; image generated to that direction.

Granularity and normative framing: the trade nobody escapes

Granularity trades directly against interpretive depth in this literature, and every method sits at a different point on that trade-off. UCDP’s event-level coding is granular down to the day and, where possible, the village, because the dataset was purpose-built for studying how violence spreads geographically and over time within a conflict rather than only between conflicts [2]. ACLED pushes granularity further by logging non-lethal protest and disorder events alongside lethal ones, at the cost of a broader and less strictly comparable category boundary than UCDP’s death-threshold definition [4]. The Correlates of War project sits at a coarser grain by design — its unit is the dispute or war, not the day-level incident — which is precisely what lets it maintain a consistent coding scheme back to 1816, a span no event-level dataset attempts [5]. None of these grain sizes is more correct than another; each was chosen for the question the dataset was built to answer, and using a coarse-grained dataset to make a fine-grained claim, or vice versa, misapplies it.

Normative framing separates the traditions even more sharply than granularity does. Conflict-event datasets aim for descriptive neutrality: an event either meets the coding threshold or it does not, and UCDP’s codebook is explicit that its category boundaries are mechanical rules applied uniformly rather than judgments about legitimacy [1]. Treaty and doctrinal analysis is inescapably normative — the Tallinn Manual’s black-letter rules are framed as what the law requires, and the NPT’s text is a set of obligations parties have accepted, not a description of what states do on average [7] [8]. Deterrence theory sits in between: Schelling’s framework describes strategic behavior positively, as a theory of how threats function, but it is frequently deployed prescriptively, as guidance for how a state should signal resolve, and the RAND escalation-vocabulary report is explicit that its typology is meant to inform policy choices about escalation management, not merely to describe historical outcomes [10]. A reader moving between these three literatures without noticing the shift in register will mistake a legal obligation for an empirical regularity, or a policy recommendation for a measured base rate.

A light table reviewing a printed satellite image strip through a loupe, the loupe still tilted mid-slide across the print

Figure 3. A satellite-image review bay: the loupe is still sliding across the strip, one frame not yet reached. — Image prompt and art direction by Brecht Corbeel; image generated to that direction.

Five problems, three lenses

Logistics. Event datasets can show where and when engagements cluster along supply corridors, but they do not code supply-chain data directly, so logistics conclusions drawn from UCDP or ACLED are inferences from the geography of violence, not direct measurements of logistics [1] [4]. Doctrine documents state a force’s intended logistics posture explicitly; deterrence case studies examine how vulnerable logistics did or did not affect a specific historical decision to escalate or stand down.

Surveillance. Treaty law says relatively little in this domain — there is no dedicated surveillance treaty comparable to the NPT — so the doctrinal method here works mostly through domestic law and export-control regimes rather than a single instrument. Event data captures surveillance’s downstream effects (where strikes or arrests followed identified targets) far more often than it captures the technology itself.

Cyber conflict. This is the clearest case of a domain the doctrinal method reached first: the Tallinn Manual process began specifically because a state-on-state cyber campaign against Estonia occurred before any treaty addressed it, and international law experts extended existing law by analogy rather than waiting for a new instrument [7]. Event datasets struggle here because many cyber incidents produce no direct death and therefore fall outside UCDP’s coding threshold entirely, while ACLED and COW were not built with cyber incidents as a primary category [1] [5]. Deterrence theory has arguably done the most active work in this domain, because RAND’s cross-domain deterrence research treats cyber precisely as a case where attribution difficulty and unclear thresholds break assumptions inherited from nuclear-era case studies [9].

Autonomous weapons. No treaty comparable to the NPT yet governs autonomous weapons specifically, so doctrinal analysis here proceeds by asking whether existing law of armed conflict principles — distinction, proportionality — extend cleanly to a system without a human decision-maker in the loop, an open and contested legal question rather than a settled rule. Event datasets can eventually show whether autonomous systems change fatality patterns once such systems are common enough to appear at scale in the record, but as of the sources reviewed here, no dataset cited in this article reports autonomous-weapon involvement as a distinct coded field [1] [4]. Case-study deterrence theory has begun asking whether an autonomous system changes the credibility calculus of a threat, but that is analysis of a hypothesis, not yet a finding drawn from realized crises, since so few real autonomous-weapon crises exist to study.

Nuclear proliferation. The doctrinal method is strongest here: the NPT’s text and IAEA safeguards system are the primary artifact, and violations are assessed against a specific, ratified instrument [8]. Event datasets contribute almost nothing directly to proliferation analysis, because acquiring a weapon is not itself a coded violent event. Deterrence theory, by contrast, was built largely to explain nuclear behavior in the first place — Schelling’s original argument was framed around the nuclear age — so of the three domains, this is the one where case-study deterrence theory and treaty analysis were constructed to work together rather than separately [6] [8].

A tabletop terrain model of a coastline with small abstract marker blocks, one block hovering just above its grid square

Figure 4. A scenario terrain model mid-staffing: one marker still hovers above the grid, not yet set down. — Image prompt and art direction by Brecht Corbeel; image generated to that direction.

Analysis: why no method dominates

The pattern across all five problems is consistent. Quantitative conflict data is strong wherever a phenomenon can be reduced to countable, geocoded, dated incidents across enough cases to support a base rate, and it is weak wherever the phenomenon in question — legal obligation, or a single actor’s strategic reasoning — is not observable as an incident at all. Doctrinal analysis is strong wherever a formal instrument exists or can be extended by analogy, and weak wherever no comparable instrument exists yet, as with autonomous weapons, or where the interesting question is not what the rule says but whether anyone follows it. Deterrence case-study theory is strong wherever the question is “why did this one actor choose this one action,” and weak wherever the question requires a base rate across many actors and many decisions, because a handful of intensively studied crises cannot support that kind of generalization no matter how carefully they are read.

This is not a case where combining the three methods produces one super-method; it is a case where each method answers a question the others structurally cannot. A researcher who wants to know how likely it is that any given border dispute turns lethal in the next year should look to UCDP or COW base rates, not to a single deterrence case study [1] [5] [3]. A researcher who wants to know whether a specific cyber operation violated international law should read the Tallinn Manual’s rules and the underlying law of state responsibility, not an event count [7]. A researcher who wants to know why a specific leader backed down in a specific standoff should reconstruct that crisis the way Schelling and the RAND escalation literature do, not search for it in an aggregate dataset [6] [10]. Where experts in this field disagree, the disagreement is often not about facts within one method but about which method’s question is the right one to be asking of a given case — a disagreement about framing, not evidence.

Scenario and forecast, kept separate from the above

Everything above describes existing methods and existing findings. What follows is explicitly a scenario, not a prediction of what will happen, offered to show how the three lenses would jointly need to track a plausible near-term development: a state-level use of an autonomous weapon system causing an internationally reported fatality within the next five years (by 2031).

If that scenario occurred, the quantitative tradition would need a new coding field — something UCDP, ACLED, and COW do not currently carry — to distinguish autonomous-system fatalities from human-directed ones, since none of the codebooks reviewed here mention such a category today [1] [4] [5]. The doctrinal tradition would face a test of whether Tallinn-Manual-style extension by analogy is adequate for autonomous weapons the way it was judged adequate for cyber operations, or whether states would instead move toward a dedicated instrument resembling the NPT rather than relying on analogy [7] [8]. The deterrence tradition would gain its first real case rather than a hypothetical one, and RAND’s existing cross-domain framework predicts that attribution difficulty would be the central complication, the same complication already documented for cyber incidents [9].

This forecast rests on three assumptions: that autonomous weapon systems continue to proliferate among state militaries at roughly their current pace, that no dedicated international instrument is adopted in the interim, and that existing conflict-monitoring organizations do not add an autonomy field to their coding schemes before such an incident occurs. Observable indicators that would support the scenario developing include continued national deployments of autonomous strike or loitering-munition systems in active conflicts, and continued silence in international negotiating fora on a dedicated treaty. The scenario would be disconfirmed if a dedicated autonomous-weapons treaty is adopted before 2031, or if existing conflict-event datasets add an autonomy-attribution field and report zero qualifying incidents through that date — either outcome would show the analytical gap identified here closing before the crisis case that would otherwise force it open.

An archive room of case-study folders in open drawers, one folder pulled halfway out labelled only with a plain year tab

Figure 5. A case-study archive: one crisis folder pulled halfway from its drawer, still not fully opened. — Image prompt and art direction by Brecht Corbeel; image generated to that direction.

What this comparison does not resolve

None of this implies that the three traditions could or should be merged into a single super-dataset. A merged record that tried to carry Schelling-style reasoning about credibility and resolve as a coded field in a UCDP-style dataset would either flatten that reasoning into unusable categories or abandon the replicability that makes event data useful in the first place. Similarly, a treaty database that tried to encode base rates of compliance the way UCDP encodes fatalities would need an entirely different kind of evidence — enforcement actions, verified violations — that legal text alone does not provide. The three methods persist side by side because security studies has three genuinely different questions to answer, not because the field has failed to unify them.

The disciplined way to use this literature is to name, for any specific claim, which of the three questions is being asked and which method actually answers it. A claim about how often militarized disputes escalate to war belongs to the quantitative tradition and should cite a dataset like COW [5]. A claim about what a state is legally permitted to do in cyberspace belongs to the doctrinal tradition and should cite an instrument or an authoritative interpretation like the Tallinn Manual [7]. A claim about why one crisis resolved the way it did belongs to case-study deterrence theory and should cite the specific historical reconstruction it rests on, in the tradition Schelling founded [6]. Confusing the three is the most common and most avoidable error in public commentary on war and technology, and separating them is the discipline this article has tried to model rather than merely assert.

Sources

  1. Uppsala Conflict Data Program. UCDP Georeferenced Event Dataset Codebook, Version 24.1. Uppsala University (2024).
  2. Ralph Sundberg, Erik Melander. Introducing the UCDP Georeferenced Event Dataset. Journal of Peace Research (2013). DOI: 10.1177/0022343313484347.
  3. Shawn Davies, Garoun Engström, Therése Pettersson, Magnus Öberg. Organized violence 1989–2023, and the prevalence of organized crime groups. Journal of Peace Research (2024). DOI: 10.1177/00223433241262912.
  4. Armed Conflict Location & Event Data Project. About ACLED. ACLED (2026).
  5. Correlates of War Project. Data Sets — The Correlates of War Project. Correlates of War Project (2026).
  6. Thomas C. Schelling. Arms and Influence. Yale University Press (1966).
  7. Michael N. Schmitt (ed.). Tallinn Manual 2.0 on the International Law Applicable to Cyber Operations. Cambridge University Press (2017).
  8. International Atomic Energy Agency. Treaty on the Non-Proliferation of Nuclear Weapons (NPT). IAEA (1968).
  9. Michael J. Mazarr. New Challenges in Cross-Domain Deterrence. RAND Corporation (2018).
  10. Andrew Radin, Alyssa Demus, Alexandra T. Evans. A Vocabulary of Escalation. RAND Corporation (2023).

Originally published at https://absolutedigitalpublishers.com/articles/comparing-the-main-approaches-to-war-security-and-technological-power.