/* */

11 March 2008

OSINT and faint indicators in the new cyber environment

For all of the sound and fury regarding the potential OPSEC implications of military and intelligence blogging, we must continually remind those mired in the old ways of thinking that there are far more pressing problems which inflict damage on the enterprise - be that enterprise government or commercial. While indiscretion will always remain a cardinal sin, the worst indiscretions are rarely committed by those that put pen to paper with proper foresight and consideration of the potential higher order effects of the discussion. The prohibition argument also rarely takes into consideration the kind of deliberate self-censorship that is routinely practiced by those with an active stake in the reputation market of the blogsphere – one that increasingly crosses into normal professional life in much the same manner as do one’s writings in an academic journal. The higher order benefits, on the other hand, of a robust and evolving literature, can be clearly shown to outweigh the actual problems identified in the kinds of studies which call for widespread prohibition of online writings on topics of relevance to the field. Worse yet, if such a prohibition would come to pass, the community will essentially have yielded the floor entirely to those who write without true understanding, and who increasingly lead the discussion further astray from the real issues and opportunities that today’s intelligence professionals face – as well as those critics which seek to deny entirely the legitimacy of the profession itself.

We have recently had occasion to note counter-examples which prove by comparison the vast gulf between the discretion of those current and former professionals engaged in active current debate in furtherance of the literature, and the kind of negligence and errors of the “official” discussion that if the shoe were on the other foot would provoke widespread (and justified) outrage. The first of these comes from the commercial world, at the Corporate Intelligence blog, where a case study examining the inferences which can be drawn from job vacancy postings is presented. We can recall quite a few similar issues emerging in the national security space, particularly with certain less than discrete contractors that tend to advertise in the major regional papers for rather explicit position descriptions, revealing rather more detail than one would like to see in public. These are rarely cited in prohibition discussions, however, but in the aggregate have likely done far more damage to the community than all of the public deliberative literature over the past sixty years.

We also recommend highly the analysis over at In From the Cold of a recent and much publicized incident involving the F-22 Raptor program, in which a pilot was less than discrete in online discussions. While we certainly feel that the individual responsible for disclosures deserves a long counseling session on appropriate standards for representing oneself in public, we take well the number of points in which supposedly “protected” information was previously disclosed through official public affairs channels. We also find observations of the interest displayed by certain parties more valuable than the information provided back to them, especially when the alternative pathways for those parties to obtain the same answers could have been used through entirely passive means, of which the community might never have been aware.

Of course, OSINT does have its dark side in that the adversary is always capable of using it against friendly interests. However, it requires a level of effort, understanding, and skill to parse through the overwhelming volume of noise to find those faint indicators – a task not unfamiliar to those that have ever worked with publicly available source information. In our view, it is better our adversaries waste that time – not knowing the wheat from the chaff – than they should spend efforts pursuing real collection against more sensitive activities that might yield a return on that investment that is more damaging to friendly interests in the long run.

The modern information environment is increasingly complex, and now that the genie of those technologies is out of the bottle, there is no chance of returning to a simpler era. It thus becomes all the more critical that the discussion regarding the effects of new media and online public discussions focus more narrowly on those areas which are truly essential elements of friendly information that must be protected with exceptional caution, rather than a blanket of prohibition that will harm our own side’s sensemaking and adaptation more than it will impair the enemy’s collection efforts.

Labels: , , , ,

06 February 2008

123 Meme, with variation

Thanks to Mountainrunner, we have been tagged with one of these random interweb memes that seem to us to be a deliberate attempt to spark a convulsive degree of self-consciousness within the restless stirring of electrons that is the Parallel Universe. (And given the gentleman’s interest in all things UxV, one cannot discount his role as agent provocateur in welcoming the new robot overlords – after all, he is the individual that inserted reference to Cylons into a serious DOD briefing.)

For those that may have been thus far spared exposure to this particular viral idea

  1. Pick up the nearest book (of at least 123 pages)
  2. Open the book to page 123
  3. Find the fifth sentence
  4. Post the next three sentences
  5. Tag five people

Given that our group format by its very structure creates a different response to this question for each participant, we found ourselves internally cross-tagged. After some discussion, we also decided to introduce an additional element of randomness in the passages selected – within a moderate degree of ambiguity near to the canonical 123 meme segment – just to stir the echoes a bit more (and no doubt as further evidence of our contrarian nature). After all, intelligence professionals should not become accustomed to too high an artificial measure of certainty in anything.

Thus we offer a few of the more notable passages from the various and sundry texts offered by our contributors:

Ransom, Harry Rowe. Central Intelligence and National Security. Harvard University Press. 1958.

“’New concepts’ earlier mentioned in State’s intelligence organization are partly the result of the influx of Foreign Service officers into intelligence – ‘Wristonization’ – and partly the result of a redefinition of intelligence requirements of the Department. Effort is being made to assure that the intelligence produced is attuned to the real needs of State’s policy makers and operators. Through various administrative devices closer daily operational contact exists between officials responsible for making and implanting policy and those supplying intelligence.”

Earley, Pete. Comrade J. GP Putnam’s Sons. 2007.

“Having tasted the reforms sparked by perestroika and glasnost, Soviet legislators were not willing to turn back the clock. This left the KGB chairman and his cronies with only one option. If they wanted to stop the Union Treaty, they had to remove Gorbachev with military force before the August treaty was signed.”

Sageman, Marc. Leaderless Jihad. University of Pennsylvania Press. 2008.

“Unlike traditional terrorist organizations that have physical sites and more territorial ambitions, there is no incentive for a leaderless virtual social movement to moderate or evolve beyond terrorism. Because there is no formal organization, with assets, sunk costs, physical commitments, or other stabilizing elements, participants who become more moderate in their views simply leave the forum and move on, or are banished from the forum by the webmaster. But their legacy lives on; their previous commitments and activities (writings, videos, and terrorist operations) are still archived in the forums and could continue to inspire new generations of dreamers to capture the glory that had inspired the old stalwarts in the first place.”

Anderson, Terence; Schum, David, and Twining, William. Analysis of Evidence, 2nd edition. Cambridge University Press. 2005.

“The logic is simple; the complexity lies in the materials to be analyzed and in identifying the relationships between the propositions in an extensive argument based on a mass of conflicting evidence. The logic is binary: every relevant proposition either tends to support or tends to negate a single hypothesis or conclusion (the ultimate probandum). The technique is dialectical: the aim of the chart-maker should be to construct the most cogent possible argument for and against the ultimate conclusion and to relate the opposing arguments within a single coherent structure.


But we do also wish to tag a few others, for we are far more interested in thoughts which originate outside of our little skunkworks. Thus:

Labels: , ,

15 January 2008

Intelligence history in the Black Valley

We are quite fortunate to number among our readers a gentleman of expertise and innovation, who passed along an excellent video in which he can be seen here lecturing at Google's occasional talks series. The topic of conversation was what we would consider the early history of intelligence privatization – the development of the early partnerships to pursue new scientific and technical intelligence operations against Germany and the Soviet Union. For those generally unfamiliar with the importance of the Wizard’s War, the lecture also serves as an excellent introduction to basic electronic warfare concepts and the SIGINT / ELINT challenges required to effectively support EW during WWII and the Cold War era.

The lecture in particular resonates as it tracks the eventual higher order effects of the early Cold War surge in a way that is rarely done in intelligence history surveys. One can almost for a moment imagine a different lecturer, sitting in a room somewhere in a start-up turned world changing firm of not so distant futurity, exploring the impact of innovations in the early years of the Long War from a similar perspective and style. In our mind’s eye, we perhaps think that such a future lecture might focus on the IED Defeat fight, or perhaps the manhunting problem – but of course it has not been given to us to seen the future, only merely to glimpse the outlines of its potential.

For now, we are pleased to see this kind of history surfacing, and being spread in places where creative and imaginative young minds cluster, especially by such a gifted speaker and guide. Let us hope that it may inspire the next generation of intelligence developments and successes, even as it enlightens us to the pasts we share.

Labels: , , , , ,

31 December 2007

Of PSDs and future assassinations

It is no surprise that highly visible political targets under significant threat would seek the very best protection money could buy. Thus the news that Benazir Bhutto sought to obtain the services of a Blackwater protective security detail prior to her assassination is not entirely without precedent.

However, we are reminded of Mountainrunner’s admonition that private military companies play into US foreign policy overseas – and in particular, US public diplomacy – in a manner that few analysts or decision-makers take into account. Blackwater is among the most visibly associated with US engagements in the Long War – even though it plays a protective rather than offensive role. In the minds of many in the Gap, Blackwater is just another instrument of the United States itself.

In this case, there is little doubt that a more professional PSD would have likely never permitted the risk of moving the principle standing in an open sun-roof, given recent attack history and threat intelligence. The likelihood therefore that Bhutto would have survived the attack – whatever one believes about the mechanism which may have actually inflicted the lethal wound (bullet, blast, or blunt trauma impact) – seems to mark the incident down into the “missed opportunities” column, the fodder for counterfactual analysis and alternative history for a long time to come.

It has long been a maxim that any political target can be taken by a sufficiently motivated suicidal attacker. While modern protective intelligence and operational TTPs have thankfully greatly reduced the margin of success for an attack, the PIRA’s warning to Lady Thatcher after the failed 1984 IED attack still haunts every practitioner: “Today we were unlucky, but remember we only have to be lucky once. You will have to be lucky always.”

Given this backdrop, one can only imagine the consequences of a successful attack should a Blackwater PSD have been engaged to protect Ms. Bhutto. The conspiracy minded would have a field day – and such suggestions have a way of turning to riots in the global Street. Belmont Club has a few of the headlines that we might have seen run in the past few days in such an alternative history.

Any PMC which might take on such a high visibility, high threat contract in the future must be prepared for this kind of aftermath from the start. The State Department should also be planning for such contingencies, both to counter the inevitable immediate reactions as well as the potential long term impact to an American image which is inextricably tied to PMC actions abroad.

More significantly for the purposes of our profession, those engaged in providing protective intelligence support to such engagements must be exceedingly mindful of the possibility that all intelligence activities and products will no doubt come under the microscope of public examination in the days and weeks following an attack. We can think of little better fodder for the kind of damaging political grandstanding that has been favoured in the Beltway as of late, or for the kind of lawfare that has sapped critical capabilities on so many accounts. Even if such protective intelligence is provided under the auspices of official USG liaison, should contractors have been involved in the analysis and production process, we could well see the same sort of scrum develop. (This creates one of the better arguments for defining publishing and release authority as an inherently governmental responsibility, we should think – as it is done in most shops. However, there will likely always be a number of unresolved questions regarding uncoordinated products and unpublished or internal papers sufficient to keep such arguments alive for some time. The buck may stop at a government officer’s desk, but we are sure the damnable lawyers will have their day with the underlying process in any event.)

This has significant implications even in the domestic homeland security environment. Those of the numerous fusion centers and watch desks around the community that have protective intelligence for state and local officials as a secondary (and often implied) responsibility will no doubt face very similar challenges, to perhaps even a greater degree of political vitriol – including the same dynamics that arise with any degree of privatized support.

Let us be clear, though – such issues need not arise from any impropriety on the part of the private contractor capability, be they intelligence officers or PSD operators. This is an emergent property of the current political and media atmosphere that has not yet reconciled to the business of privatized intelligence or PMCs – largely because of the continued illusion that the state can (or should) somehow magically still provide the range of capabilities demanded in the Long War. In a perfect world, it might be so – but as we fight on an ever more specialized basis across increasingly far flung locations, the impossibility of the drain on high demand / low density assets that attempts to service such illusions would create should be ever more obvious, even to the outsider. That the market organizes to meet the unfilled demand should not be such a surprise – and should be rationally discussed rather than sensationalized. Unfortunately, the Beltway and media does not often function on the logic of reality, but rather according the rules of transient political advantage.

Strategic communications, public affairs, and public diplomacy professionals that will have to deal with the consequences of such an incident in the future had best start preparing contingency planning for this sort of political football. It is only a matter of time – and of adversary kinetic and IO action.

Labels: , , , , , , ,

11 December 2007

Understanding the village

The following piece from Marginal Revolution catches our attention as yet another example of the growing utility of interdisciplinary approaches to those aspects of the intelligence that have not been traditionally served by the national and technical collection apparatus.

The tool is strikingly simple – a piece of software designed to ease data collection and processing burdens for studying epidemics in developing nations. The package will run on common mobile phone platforms, typically ubiquitous in such environments – or otherwise exceptionally cheap to obtain and circulate. Strategic communication branding, anyone?

The potential applications however go far beyond epidemiology – or even other aspects of medical intelligence. We can immediately see a use for such a tool in a number of information operations, civil affairs, and cultural intelligence settings – not to mention any of the political intelligence activities that require survey information. Less obvious mechanisms for overt human derived reporting also suggest themselves, given a degree of preparation and planning.

There are distinct limitations to what might be accomplished using this approach, but with those limitations in mind it is quite possible to develop new and innovative collection programs leveraging this capability against the kinds of questions it may suitably answer. This is precisely the kind of experimentation – and extensible designs – that ought to be coming out of the intelligence studies academia, in support of forward deployed intelligence professionals.

Labels: , , , , ,

22 November 2007

Case studies with enduring legacy

There is much to be thankful this holiday season, and it is natural at such a time to reflect back on the conflicts past, and those lost in the course of these conflicts. It is also a time to reflect upon history within the intelligence community, as our first – and for nearly 60 years, our most severe – intelligence failure at Pearl Harbor falls within these months.

Recently, new allegations have surfaced regarding what some consider to be another greater intelligence failure – the Allied ignorance of the machinations of death that were the Holocaust. This has long been an area of immense historical controversy, and present a number of opportunity to examine intelligence / policy relationships, the effects of cognitive bias, the questions of imagination (in thinking about the unthinkable), and (due to the importance of ULTRA decrypts in the overall reporting stream) decision-making in the SIGINT environment.

In short, the new claims put forth in the Hebrew language book Pazner: The Man Who Knew, are centered around supposed HUMINT reporting containing explicit discussion of the construction of camps intended for extermination operations in German occupied Eastern European areas. The reporting, alleged to originate in July 1942 from an unidentified German officer source with what was claimed to be good access, was passed through a Swiss intermediary to a Jewish Agency official. This reporting was subsequently provided to Allied intelligence, and may have even made its way to the highest echelons of the British government.

If true, it is an interesting addition to the historical case study of the Holocaust warning problem. One raw report does not warning make – particularly third-hand HUMINT from unevaluated sub-sources. However, a HUMINT source would have been encumbered by only a fraction of the difficulties of dissemination that the information provided by the ULTRA channel would have imposed. It is possible that such reporting could indeed have been the best “public case” material that could be used to support strategic communications and information operations pressure against the Nazi regime. Indeed, the source is alleged to have even proposed such a use of the information himself, recommending daily BBC broadcasts warning against the commission of war crimes. A later very similar reporting stream, which surfaced through the Riegner telegram, did become the basis of the US acknowledgement of the genocide in November 1942. Public diplomacy at the time had impact on the Nazi pogrom - and given modern experience in Bosnia, Darfur, and elsewhere - it is indeed questionable how effective even widespread public knowledge would have been in halting evil intent.

The handling of this information joins the already extant list of intelligence controversies from other collection disciplines – from the ULTRA COMINT to strategic air IMINT. The ultimate questions that are invoked, however, are ones of policy and operations – not merely intelligence. And these all continue to be well worth study – particularly in the face of the continued threat of genocide throughout the world.

Labels: , , , , ,

16 November 2007

Living intelligence history through hobbyist cryptanalysis



Following up with the latest in the recent stream of news regarding the ever so eccentric world of code breaking, we are both impressed and amused with the effort at Bletchly Park to recreate the machines that automated much of the attacks against German cryptosystems – and arguably shortened WWII by an incalculable duration. The reconstructed Colossus will test its mettle once again versus the Lorenz cipher, code named FISH.

The original FISH break came about in no small part due to operator error - which involved retransmission of the same lengthy message twice, using only slightly modified cipher settings. Let us hope that similar fortune favours the boffins of Station X once again.

Given that the recreated test also involves a comparison against a modern virtual emulation of the Colossus system, we cannot help but wonder what the results might be if a modern botnet-based cryptanalytic attack was to be added to the race? To be fair, we suppose a virtual analogue of the Y Service intercept system would also have to be crafted – perhaps paired with a software defined radio link or a TCP/IP intercept capability of some flavour. Of course, we would rather prefer the pretty young female clerks that used to operate the radio sets...


h/t Futurismic


UPDATE:

The rebuilt Colossus worked as expected, and achieved a successful break of the encrypted transmissions in a little over three hours. A modern computer analogue did nonetheless manage a successful break faster. Joachim Scheuth, a German cryptologic hobbyist, is to collect the first round of drinks at Bletchley.

However, the exercise did demonstrate the sheer difficulty of SIGINT – particularly in the interception of the weak radio signals of the day using contemporaneous equipment. Something to ponder in this age of far more sensitive systems, and far more elevated expecations.

Labels: , , , ,

06 November 2007

Home-brewed, open source cryptanalysis

Among the odder developments created by the inevitable trends in Moore’s Law of increasing computing power (at ever cheaper price points) has been the feasibility of private cryptanalysis capabilities functioning at effectiveness which only a few years ago would likely have been possible solely with the resources of the nation state.

These bootstrapped rigs as a rule tend to emphasize the lowest possible cost configurations – a natural consideration given that most are assembled on a shoestring budget by university researchers or other computer sciences academic types. They have been assembled for diverse purposes of privacy advocacy, systems research, and some simply for the sheer technical interest of the thing.

We particularly like the COPACOBANA system, a FGPA based parallel computing design optimized to attack symmetric ciphers, created entirely using commercial off the shelf components. The system can typically identify DES keys within less than a week of effort, at a cost of about $10,000 per machine. The now obsolete Data Encryption Standard cipher was a widely used algorithm between its approval in 1977 and its withdrawal in 2002, and remains in use in some legacy systems in the commercial environment to this day. A stronger derivative algorithm, 3DES, also remains more commonly in use in some applications, with end of life projected to 2030. DES did have a good long run, having survived the public disclosure of the previously secret technique of differential cryptanalysis to which it might have been vulnerable, had NSA and IBM not supposedly collaborated on a stronger implementation during its development phases. An earlier custom built FGPA rig - DeepCrack – was built to attack the cipher successfully, but at a cost of nearly a quarter million dollars.

These cryptanalysis systems may be jury rigged, but they are undeniably effective – and cheap. And more powerful implementations are no doubt easily within the budgets of smaller nation-states, if not wealthy non-state actors.

However, it is the development of the alternative track of home-brewed cryptanalysis that gives us pause. One competitor in the attack against the DES cryptosystem was a distributed computing network that relied on the contributions of unused capacity from volunteers’ personal boxen. The DESCHALL project achieved its successful break using 78,000 contributors over the course of three months. The project demonstrated the architecture – more advanced attacks are mostly a matter of optimization and scale.

It is from this that we begin to ponder our greater concerns. The development of very large scale botnets, made up of aggregated collections of individual systems compromised by malware, offer far greater potential computing capacity – both an individual basis per processor as well as in overall numbers of contributing systems. The widely discussed STORM botnet remains perhaps the largest of such malicious aggregates that has publicly identified. While exact numbers remain subject to debate, STORM is believed to consist of up to 50 million individual systems. And while recent indicators are that the botnet is being sub-divided into smaller segments for illicit commercial sale, this kind of capacity in the hands of non-state actors is truly revolutionary. Its potential applications to home-brewed cryptanalysis are clear.

Interestingly enough, the STORM botnet also appears to itself utilize encryption in order to secure its own control communications, and to permit more effective illicit commercialization. (Although surprisingly not a GOST standard cipher). The use of STORM, or the application of similar very large scale capabilities, to the flip side of the cryptographic equation is surely not far off.

If nothing else, it is good reason to accelerate those academic intelligence studies that might have an interest in cryptanalysis.

Labels: , , , ,

09 October 2007

Electronic attack and advanced denial and deception in new contexts

The technical boffins over at O’Reilly Radar have highlighted an interesting potential scenario, first put forth by Aviation Week, to explain the apparent failure of the Syrian air defense network during last month’s air strikes by Israel.

This is not the first time that public reporting has emerged discussing the potential applications of sophisticated EW techniques in suppressing adversary air defense networks. One can recall similar speculative stories coming out in the initial days of major combat operations of OIF in 2003.

What makes this interesting is the boffins’ discussion of engineering new public networks to defeat these kinds of attacks in the context of other, civil applications. One can easily understand the desire to do so in order to protect the integrity of wide-scale surveillance networks such as London’s ring of steel. There are less obvious applications in assuring the reliability of monitoring systems which do not rely on even such unambiguous elements as video feeds – perhaps large scale environmental monitoring programs? Given the research dollars flowing towards theories of climate change, one can easily see the potential motivations for manipulation of sensors and associated data streams at the source, in order to avoid the appearance of bias in later analysis.

These approaches will rapidly scale beyond their original military context as widely implemented sensors systems come into more common civil use. One can easily picture such efforts directed against GPS based highway toll and use monitoring systems, for example, or against other RFID or cellular population density measurements. (Persistent virtual worlds have already proven the potential benefits to retail and other establishments from manipulating such “popularity” measurements based on presence related data. The real world would be no different.)

The Wizard’s War is always with us. It just grows more interesting over time.

Labels: , ,

01 October 2007

Marketing of the deed

StrategyPage has an interesting take on the prospects for the Russian defense industry in the wake of the apparently unopposed transit of the Israeli air force strike package to its target in Syria. Needless to say, the failure of the Syrian air defense network – centered around “advanced” Russian systems – does not inspire other buyers in quite the same manner that Rosoboronexport would undoubtedly prefer for its “premium” brands.

The point regarding the impact of perceived effectiveness in real world engagements on the value of selected weapons systems and doctrines is well founded. In part, this has been a driving force behind the bazaar of violence described by John Robb’s Global Guerrillas theory. Adoption of shared tactics, weapons choices, and targeting patterns among distributed independent threat actors is accelerated given unique, recognizable, and replicable branding.

In the same vein, the expansion of privatized military responses is also accelerated by the marketing of the deed. In comparison the corrupt and ineffective third country national forces which typically make up the bulk of peacekeeping deployments, PMCs are provable more effective and – despite all of the IO activity aimed at discrediting their activities – far more respectable in most cases. It is entirely unsurprising that recruiters seeking to attract talented young Iraqis for military service – even in specialized units – face brand competition as many Iraqi prospects desire very much to seek out service as PSDs, a position which they perceive to bring with it more respect.

This raises similar questions when discussing the privatization of intelligence. How much of the recent successes of contractor shops in attracting and retaining the best talent in a scarcity dominated market comes from the intangibles of being perceived as more effective in a heavily resource constrained and bureaucratic environment? It is clearly not just the money in many cases, as recent blue badging initiatives are demonstrating – but there has been little examination of the other market forces in play. A shop which offers its staff better integration into the intellectual life of the community, more accesses to events and networks, and better opportunities to develop intellectual capital, is going to demonstrate through its deeds the value of its effectiveness and philosophies. The body shops and salt mines will signal a far different picture to prospects. But are human resources groups (both within contractor shops and government agencies) paying attention to these perceptions, and working with other elements within their organizations to shape them in a favourable fashion? This is a community that is at most two people deep, and these intangibles can dictate the success or failure of a shop in very short order in these times of rapid mobility and high demand.

Labels: , , , ,

25 September 2007

Real strategic communications and the wages of ignoring diplomacy

We have long noted our continuing interest in the world of soft power, and in the intersection between it and the harder aspects of military and intelligence instruments. It seems the topic gains much momentum in recent days, to our great pleasure. Zenpundit brings up a series of interesting points regarding the challenges of the contemporary information operations environment, and how these differ from the world of Kent, Langer, and his younger brother – a pioneer in the field of leadership analysis. The incomparable Mountainrunner has been leading an examination into the continued misinterpretation of Smith-Mundt, along with excoriation of the ineffective machinery for public diplomacy at State – a discussion also joined by Swedish Meatballs and Political Warfare.

In these discussions, several important concepts continually resurface in various forms. The first is that of the information threshold – the sensemaking barrier below which modern attention deficit and information overload so degrades signals in the IO environment as to render them meaningless. Related is the idea that certain actions will always speak louder than words, especially in given unanticipated higher order effects.

It is against this backdrop which we measure the shameful performance of Columbia University in giving a podium to our adversary’s propaganda. Ridiculous though the Persian pretenders statements may be to Western ears, one cannot help but reflect how many times a Farsi narrated video of the events’ dubious “highlights” will be shown to legions of adoring Basiji and the true believers among the Pasadaran.

We feel that one who previously violated the sanctity of international diplomacy should not be allowed to rest secure in its protections when it is convenient for them to seek to do so. In an alternative history, yesterday’s events could have provided a platform for a real strategic communications message of lasting historical import – as opposed to the disgraceful, but ultimately brief, irrelevance that transpired.

A nation that understood the value of actions in its public diplomacy, and the strategic worth of unpredictability, would have seen the Iranian hostage taker seized by the Mobbe – a body of men that would have been comprised of those NYPD, NYFD, and ordinary citizens who remember well the costs of inaction. It would have seen the very cranes once used to remove the remains of the fallen towers now choking the life from a man whose orders are also responsible for the deaths of Americans, in the same manner in which his own regime carries out its hangings in the public square. The image of his kicking feet would have graced the front page of every fishwrapper and news weekly across the globe this morning.

In this alternative history, America’s cowboy image is used as a weapon against our enemies – not as a strategic weakness which must be overcome through perception management and re-branding efforts. It is an alternative history which would have evoked an earlier time, when the affairs of nations were conducted by serious men for real stakes – rather than in the senescent pretence of “dialogue” with one who comes to the table in bad faith, with the blood of our people on his hands from an undeclared war stretching across the decades.

Troubled times call for difficult actions. We fear that only more dark days lie ahead because the nation is unwilling to undertake the kind of messages carried by that brief counterfactual thought experiment.

Labels: , , ,

20 September 2007

The genteel competition among allies

It is a maxim that one never has true alliances in intelligence, only mutual interests. The longstanding UKUSA intelligence liaison, as well its Four Eyes partnerships with the other countries of the democratic Anglosphere, if often held to be a counterexample to that dictum. And given the levels of cooperation in the Long War – especially involving special operations and other operational activities – one can see the merit to the argument.

Yet at the same time a genteel competition between the cousins still takes place, with small victories substituting for times when grand policy changes are inappropriate or impossible. This is most often expressed in the subtle manner of counting coup – forcing a liaison officer to inadvertently exceed his brief, or worming one’s national way into another country’s unilateral operation. Its usually nothing more than a fun game, resulting in bureaucratic embarrassment and individual red faces at worst – and good practice for the day when one must liaise with a “partner” in the multinational environment whose interest are not nearly so benign. If take too far, it sometimes can result in ruined operations and burned programs – but usually there are plenty of older and wiser heads around to ensure the game doesn’t stray too far outside of bounds.

Thus we note with amusement the purported cryptologic success of the Australian Defense Forces during the 1980’s, during their attempts to enhance capabilities against opponents using other than Warsaw Pact standard equipment. One can surmise that this included Identification Friend Foe (IFF) systems as well as other electronic warfare (EW) programs - such as jamming pods and their related processing databases.

For as much as those in Oz may express frustration at the American’s purported unwillingness to share their toys in this case, one should remember that one of the great publicly debated “intelligence failures” of Desert Storm - only a few short years later - was the supposed lack of non-Warsaw Pact EW intelligence. Given the large numbers of Western systems in use by the Ba’athist Iraqi forces – much of French origin – the Cold War postured US forces were alleged to be poorly prepared to address this wider spectrum of threats. Similarly, many of the regional threats (or competitors) faced by Australia during the 1980’s (and today) may well have utilized systems that the 1980’s US EW establishment was simply not postured to address.

All in all, a fascinating bit of history and a good lesson in the difficulties of liaison relationships over the course of the Cold War. One can reasonably surmise that while the issues at hand may change in the new environment, many of the same dynamics will persist. For those interested in further exploring the history of the Wizard War during that time period, we recommend highly the Journal of Electronic Defense, which often includes not only case study articles but an excellent series of first person oral accounts from those that worked those accounts back in the day.

Labels: , , ,

13 September 2007

The strange higher order effects of post Soviet organized crime

We have recently had occasion to note the increasingly strange ripples throughout areas of interest to the intelligence community, particularly those interests in the transnational issues space, created by developments in post Soviet organized crime. Whether one believes in the model of the Kombinat, or merely in the inevitable cycles of anarchical decay and authoritarian response that may be giving rise to, in the words of the Economist, a “neo-KGB” state - it is clear that the problem set is far from a dead issue, no matter how long ignored in many circles more focused on the immediately pressing problems of the Long War.

One of the largest growth businesses in Russian organized crime occurs in the Parallel World – or whatever cyberspace is becoming in its evolving ubiquity. Cyber attack against financial institutions and consumers is fast creating entirely new classes of network warfare tools and TTP, and forcing defenders to rapidly develop the sophistication of their own responses. The driving energies of these defensive efforts are not merely privatized, but almost entirely the result of the efforts of critical infrastructure owners who have been essentially abandoned by governments which lack the priority focus, the resources and the key people to even begin to discuss the problem set, let alone begin to address action. The developments in this space thus tend to occur along entirely unique and frequently unanticipated lines, with innovation flourishing from far stranger soil than the results of the typical government RFP.

Thus we note with interest a new European toolset designed to expedite analysis of compromised machines for forensic examination. The tool itself seems more an evolutionary advance on previous packages, but it is good to see movement in the space. The recent Estonian flap has definitely driven new interest within Europe on many previously poorly understood aspects of what are in that context intensely regional problems, and it is good to see our allies begin to move towards unique contributions to the shared defense in areas where they might be able to bring new competencies (vice legacy systems and logistics demands). We also immediately would note the potential utility of the item for DOMEX efforts, long languishing in need of further attention (as frequently discussed at Haft of the Spear.)

We hope to see further developments of this nature in the unanticipated higher order effects of otherwise nearly intractable problem sets. The potential benefits to the IC from finding, and exploiting, these reservoirs of expertise and pathways of alternative development could be quite incalculable.

Labels: , ,

18 June 2007

Combat stress and society’s (manufactured) reaction

Combat stress is a real thing. There are robust programs in place in DOD and elsewhere to help handle the effects of that stress on the human being, for war is a distinctly unnatural state of affairs and prolonged participation in it can do things to the health of one’s mind. Unconventional units, particularly those engaged in the delicate business of intelligence in support of counterinsurgency and counterterrorism, suffer combat stress more than most. So we, like many in our profession, are greatly cognizant of the hazard – and to a great extent, much of the community’s culture evolved to help place such stress in a larger context, and share it among those whom one trusts – especially those parts of the culture which have been so roundly criticized by those seeking political correctness and sterility.

The most important lesson we ever learned was that combat stress is driven primarily by one’s own reaction to society’s reaction regarding the stress events. The lesson came from the law enforcement realm, where the exposure to serious trauma and emotional tension was far more routine, and far more frequent, over the course of careers often spanning decades. These lessons have been validated time and again in the wars we have seen. It is not merely that one saw terrible things, or carried out difficult deeds during a period of time in a bad place. It is the cultural, political, and interpersonal context of what those things mean back in the World that can settle the restless nightmares or spur the haunting demons that lurk in a man’s mind.

There are outlets for this kind of stress, and means by which it may be handled. There are avenues available that those who need help may turn to. There is no shame in it.

Every man reacts differently to the stress. Physiological symptoms, psychological conditions, and triggering factors all vary. But there is no more sure means to convince a man that he is suffering than a relentless media campaign that tells him he should be. The propaganda in this case creates a reality. And this is a direct and grievous wound to those who should be offered instead support, care, and a greater context into which they might place the burdens of their days and thus see them lightened.

It is for these reasons that we view the recent Washington Post (and other media outlets’) attempts to stir up the ghosts of conflicts past to destroy support for the Long War as contemptible beyond measure. The media manufactured Vietnam-era PTSD coverage has proven over the careful examination of history to be driven by frauds and liars, who sought to cover their inadequacies in the stolen glories of others, and in failing sought to discredit entirely the idea of heroism, and bravery, and valour. (One of the best works documenting these false claims, and the media profiteering on the backs of such lies, was written by B.G. Burkett.) It is with this firmly in mind that we note the troubling similarities with current media accounts.

We view this most damnable of frauds as arising from an impulse that the Bard identified long ago in one of his more stirring military scenes:

And gentlemen in England now-a-bed
Shall think themselves accurs'd they were not here,
And hold their manhoods cheap whiles any speaks
That fought with us upon Saint Crispin's day.

Labels: , ,

20 May 2007

War in the Parallel World

When is a war a war? When has a war gone “mainstream”, coming out of the shadows of deniable engagements and hidden casualties? What does sustained information warfare truly look like – not in the sterile academic settings of the university lecture, or the exercise conference table – but in the real world of humans and their systems?

If there was ever an answer to the question of threshold, it appears the ongoing cyber conflict involving Russia and Estonia has crossed it. See now Instapundit and Belmont Club, based on the Washington Post.

We have commented on this new conflict before, but a European state on state crisis in the 21st century is more than worth a second glance - if indeed it is truly state on state, for which we have not yet seen definitive attribution.

Wretchard in particular applies an apt name: the Wizard War. This captures, in succinct form, the alienation the typical man on the street might feel in the event of such a war. To be sure, Everyman knows all about the interwebs, and the tubes, and the magic motion picture music box thing that exists to feed their iPods and cameraphones. But the technical understanding of higher level cyber environment dependencies exists at about the same level of comforting abstraction (the legions of Slashdot and the rest of the technical blogsphere aside.) So when more than one banks computers go down, and the panic begins to set in, Everyman will be facing a shattering of illusions for which he is mentally unprepared. The loss of confidence will have a far greater effect than any mere temporary disruption, however mass.

It is in the layers of these abstractions that 5th generation warfare (5GW) lurks and hides. Trying to unpack the complexity of the issues involved in facing a concerted series of attacks against what is our collective hallucination of cyberspace (in Gibson’s terms) begins to take on the character of a Jesuit debating society. We have taken part in our share of these debates throughout our careers, and have yet to find an acceptable set of answers to any of them – but regrettably, keep running into ever more numerous sets of lawyers that all claim they do, even though none of them agree with each other, as the years go by.

In the original Wizard War of World War II (so named by Churchill), these debates were equally as divorced from the prosaic realities of the day. However, it was the boffins of Bletchley Park, and the luminaries of the MI establishment such as R.V. Jones that set the stage for decisive victory – subtly in the European theatre and more brilliantly in the Pacific, illuminated by the impossible brightness of Paul Tibbett’s mission.

But then it was the heyday of the state military-industrial intelligence complexes. It was the time of control, and of massive resources spent towards national ends in a unity of purpose and a shroud of absolute secrecy. That it brought about victory is the lesson of history. But the question before us now stands: can victory be accomplished without reverting to those kinds of organizational and political structures? For today’s environment is far removed from sixty years ago, and some genies can never be put back in their bottles.

There is a good reason that the threshold of cyber war has not yet been fully crossed by state actors (as opposed to their non-state counterparts, whose effects to date have been more akin to terrorism, crime, and disorder than anything approximating a war). Once the triggers have been pulled, there are certain losses which have major systemic effects which ripple beyond borders and far outside of military or even strategic national target sets.

We continue to watch with interest.

Labels: , , ,

18 May 2007

Contrasting official lightness with private gravity

We are continually fascinated by the manner in which the private sector so far exceeds government capabilities in understanding the Parallel World. While it is one thing to know that the rapid development of IT and related innovations has been driven by the private sector for at least a generation, it is another thing entirely to realize what that means for organizations still struggling to come to terms with the implications of even the most basic of developments (such as email or even lightweight web publishing.)

To be sure, there are highly technical and very savvy individuals scattered throughout the intelligence community, dedicated to the study and analysis of such issues. But this is increasingly one area in which the open source realm may be dramatically outstripping what occurs in the vault.

By way of example, we reference recent coverage of the ongoing cyber conflict between Russia and Estonia. Again, we make no assertions regarding the incidents, their attribution, or implications beyond what others have already stated in public sources (whether accurately or not, time will tell.) But we are very interested in the increasing levels of technical sophistication and interest being applied to the analysis of current network disruption events.

While Global Guerrillas has a theory type think piece (worth examining in the overall context of John Robb’s contribution to the body of emerging 5GW theory), various Internet security shops are increasingly publishing open versions of analysis at a more technical, and tactical level. As an example of the latter we reference Arbor Network’s corporate blog posts on the subject.

We have seen enough of the failing cyber security report cards, and the constant shuffle of senior executives through the relevant government posts, to venture that the sort of quality of thought behind the focused attention paid to this incident (and others like it) would be simply alien to many otherwise nominally assigned to the responsibility of covering these key accounts. (For more background on the ongoing trials and tribulations of the federal cyber security sector, we can recommend no better and more consistent commentator than can be found at Haft of the Spear.)

Of all the areas in which public/private partnerships for enhanced analysis and intelligence production could be of value, we can see few potential accounts more clearly in need of such unique contributions. It does not take a major Beltway contractor, nor any sort of specialized access program, to accomplish significant aggregation, interpretation, and insight into these sorts of problems – and policymakers are likely to be better served by a more broadly based attempt to integrate more substantive experts into the community’s coverage of these accounts.

To be sure, this will require a culture shift, and a serious re-think of structures and processes by which intelligence is created in support of decision-maker needs to understand this new realm. But it is indeed something entirely new in form, shape, and outcomes. It simply makes no sense to continue to try to force fit industrial age organizations and Taylor inspired processes into a future where they have no place.

Labels: , , ,

03 January 2007

Magical realism and information operations

The beliefs, and processes of belief formation, of target audiences in information operations has always been underappreciated by operations planners and intelligence officers alike.

The Economist has an excellent piece examining one of the more pervasive beliefs in the Islamic world, and the impact of that belief on the narratives surrounding the Long War.

This is not the first time that elements of the fantastic have been noted in the propaganda of the jihad. In fact, many of the near legendary aspects of the Afghan conflict against the Soviets drew heavily upon this tradition, and was built upon by militant Islamists in other theatres.

Outside of those primary targets, similar narratives have been encountered even in what one would consider otherwise secular and “reality-based” environments from European political discussions to Asian business settings, proving time and time again that cognitive factors cut across cultures, education systems, and professions. Memetic influences rely upon common initial human conditions.

So the intelligence professional would be well advised to look to the smokeless fire…

Labels: ,