/* */

03 October 2008

2009 IAFIE essay contest

We have long had mixed opinions regarding the International Association of Intelligence Education. While we are exceptionally glad an organization of this nature exists, and feel that it plays a valuable role in networking and ongoing conversation in the field, we have been quite discouraged regarding attempts to interpose the association as an arbiter of professional standards. The professional standards of the intelligence community cannot be governed by academics and outsiders – particularly when the organization itself has show that it has a long way to go towards understanding the full scope of the community’s tradecraft and many of its sub-disciplines.

However, we continue to believe that IAFIE can play a valuable role in spreading best practices identified by currently serving professionals throughout academia. We also see it as one of the organizations which could be fundamental in advancing the literature of intelligence, if it ever lives up to its true potential. There is much work to be done here, but expansion of the association out of Erie to a wider range of venues and institutions is an excellent start.

To this end, we are pleased to see the announcement of an essay competition for its 2009 conference. The full text is reproduced below:

The International Association for Intelligence Education (IAFIE) is pleased to announce its Essay Competition for 2009. This competition promotes IAFIE’s goal of providing a forum for the communication and exchange of ideas and information for those interested in and concerned with intelligence education.
Competition is open to everyone having an interest in furthering intelligence education. (IAFIE officers and staff are not eligible to compete.)

Awards
First place finishers in each category will receive a $1,000 cash award and be invited to speak at the Annual IAFIE Conference, May 27-28, 2009 at the University of Maryland. IAFIE will pay for travel, accommodations and conference registration costs.
Second place finishers in each category will each receive $500 in cash. First and second place finishers will have the opportunity to publish their essays on the IAFIE website.
First and second place finishers will also receive a one year free membership in IAFIE.

Categories
Professional – An individual who is working or who has worked as an intelligence analyst, or an individual who is or has been involved in teaching intelligence studies or providing intelligence training (teacher, trainer, consultant, private citizen).
Graduate Student – A full-time or part-time graduate student currently enrolled with a college or university.
Undergraduate Student - A full-time or part-time undergraduate student currently enrolled with a college or university.

Essay Questions
Please answer one of the following questions in your essay. Essays may be written from the perspective of national security, law enforcement, academia, business or private citizen.

1. What impact have major events of this decade had on the role of the intelligence professional in national security, law enforcement or competitive intelligence? (Select major events based upon your choice of field.)

2. Intelligence-led policing is in practice in several countries on several continents. Using real-world examples, what, in your opinion, are the strengths and weaknesses of intelligence-led policing?

3. What do you think are the most important challenges facing the intelligence community over the next 10 years?

4. What advantages do strategic analysis and futures thinking hold for the future of the intelligence professional and how can they be incorporated into the intelligence professional’s skill sets?

Submission Guidelines
Submissions must include a cover sheet with the author’s name, contact information, category (Professional, Graduate Student or Undergraduate Student), essay title and, for graduate or undergraduate students, the name of the college or university they are attending. Those submitting in the Professional category must submit a biography of 50 words or less. Do not include your name on the essay.
Essays must be no longer than 2,500 words, excluding endnotes and bibliography, double spaced, Times New Roman, 12 point font.
Essays must be submitted in English using Word or PDF format.
Essays must be original and not previously published. Submission constitutes permission to publish.

Deadline for Submission: January 9, 2009, midnight, EST. Email your submission to: submissions[at]iafie[dot]org

Notification: Award winners will be notified no later than April 2, 2009

Evaluation Criteria: A panel of intelligence professionals will judge all entries and select the winners for each category. Essays will be evaluated on their relevance to the question, creativity, strength of argument, and writing quality.


To those that will participate, bonne chance. We hope to see a robust response, and (hopefully) an edited collection can be circulated that will include both the winners and substantive runner-up entries.

Labels: , , , ,

02 October 2008

Technical OSINT innovation contest: the 2008 Malware Challenge

While the worlds of most OSINT analysts do not typically overlap with those working in the more rarified fields of digital network intelligence, forensic analysis, and network warfare, there are a highly specialized subset that may be interested in testing their skills as part of a challenge of their own. While clearly not as high profile as the recent DNI OSINT contest, the 2008 Malware Challenge promises interesting responses of its own.

The winners of the malware challenge will be announced at the 2008 Ohio Information Security Summit on 31 October 2008. We had not previously seen this conference, but it appears to be a small regional conference that is unusually well attended by the usual round of ex-spooks and ex-cops that have moved into the cyber security industry as of late.

The challenge scenario is reproduced below:

"A system administrator within your organization has come to you because a user's PC was infected with malware. Unfortunately, anti-virus is unable to remove the malware. However, the administrator was able to recover the suspected malware executable. Your job is to analyze the malware.
Participants should download the malware sample and analyze it. The end result should be a document containing details on the analysis performed. The analysis document can be written in any form, but the questions and statements below should be answered within it. Participants should note what questions are being answered.
The questions...
* Describe your malware lab.
* What information can you gather about the malware without executing it?
* Is the malware packed? If so, how did you determine what it was?
* Describe the malware's behavior. What files does it drop? What registry keys does it create and/or modify? What network connections does it create? How does it auto-start, etc?
* What type of command and control server does the malware use? Describe the server and interface this malware uses as well as the domains and URLs accessed by the malware.
* What commands are present within the malware and what do they do? If possible, take control of the malware and run some of these commands, documenting how you did it.
* How would you classify this malware? Why?
* What do you think the purpose of this malware is?

Bonus questions: (These questions are not required to be answered but could be used to break a tie for prizes.)
* Is it possible to find the malware's source code? If so, how did you do it?
* How would you write a custom detection and removal tool to determine if the malware is present on the system and remove it?

Analysis documents should be submitted in PDF format to 2008challenge@malwarechallenge.info by 12:00 Midnight EST (5:00 AM GMT) on October 26, 2008."

Additional information, including other contest rules and FAQ, can be found at the challenge website.

Interestingly, we note that Steve Jackson Games is among the sponsors providing prizes for the winners. SJG was most famously the victim of a botched Secret Service raid in 1990, which seized files and texts that were part of one its published gaming lines. For those that are not familiar with this disastrous episode from the earliest days of the cyber intelligence account, it was best recounted in Bruce Sterling’s still timeless book, The Hacker Crackdown. (In our opinion, this is also a text which should be mandatory reading for those involved in SIGINT, MEDEX, or eCrime analysis. And while the USSS has indeed come a long way since then, we do from time to time encounter other shops still grappling to come to terms with the new threat environment with often equally absurd results.)


h/t Spy Logic

Labels: , , , ,

23 September 2008

A new IC CAE and a new intelligence ethics conference

While the inimitable Dr. Jan Goldman will no doubt still retain his pre-eminence in the sub-discipline of intelligence ethics, we are pleased to see the discussion expanding outward throughout the academy. We note an upcoming conference at the newest of the IC CAE programs, University of Texas Pan American. The focus on border issues – no doubt a result of the proximity of the institution to the mission - we hope shall help to avoid some of the usual distractions of the endlessly rehashed arguments over interrogation methods that has significantly derailed much of the intellectual energies afforded the topic as of late.

If nothing else, we see with some amusement that this program takes the award for innovation in naming, being the first non-DOD program we are aware of to incorporate a superscript character in their acronym. (We look forward to future algorithmic naming permutations as time passes). More significantly however, the school’s program offers language instruction in Arabic, Chinese, and Portuguese – language families not always easily found in other institutions. We should have liked to see a greater emphasis on analytic tradecraft and intelligence professionalization in their program – a complaint we have regarding many of the IC CAE structures - but nonetheless we wish them well in their endeavors.

We repost below the call for papers issued by the conference organizers, for those that might be interested in the venue and feel unable to wait for the annual association’s event in February. (And while the timing of the events is nicely spaced, we do hope that the identical paper deadlines will not result in cannibalization of a limited scholarly output, but rather a greater flourishing of the area of inquiry. We hope next year that any similar efforts are better coordinated, as the intelligence studies discipline is frankly too small to long endure competing stovepipes.)


"Call for papers: “Ethics in Intelligence, Security, and Immigration: The Moral and Social Significance of Gathering and Managing Information and Borders in the Global Community”

The University of Texas-Pan American in Edinburg, Texas will be hosting a conference on “Ethics in Intelligence and Immigration” November 20-22, 2008. We invite submission of papers on any subject related to ethical issues in the fields of intelligence gathering, global security and immigration. Abstracts should be no more than 500 words. Send electronic submissions to: pace [at] utpa.edu

Topics include, but are not limited to:

  • Ethical issues in global intelligence
  • Ethical issues in competitive intelligence
  • Ethical issues in immigration
  • Ethical issues related to the collection, storage, and retrieval of intelligence
  • Ethical issues in privacy and global and national security
  • Codes of ethics in private and public intelligence
  • Open vs. closed borders
  • Ethical implications of a border wall

---Submission deadline: 1 October 2008---

Conference dates: 20-22 November 2008

There is a strong possibility that some or all conference papers will be published in a volume of conference proceedings.Sponsored by the Integrated Global Knowledge and Understanding Collaboration (IGkNU), the Pan American Collaboration for Ethics in the Professions (PACE), and the Office of International Programs at UTPA"


We look forward to the published volume, as well as the future scholarship of the IC CAE.

Labels: , , ,

18 September 2008

Contagions and their higher order effects



Anyone who attends conferences or tradeshows on a routine basis is painfully aware of the risks of common illness created by bringing thousands of strangers together in a small series of rooms for several days – especially when programs seemed entirely designed to keep participants on the move, and consuming either the typical rubber chicken plates – or worse yet – boxed meals.

Thus it was from the recent DNI OSINT conference. There seems to our (admittedly anecdotal sample) that most attendees last week have fallen ill within a short number of days. Of course, there has been significant overlap with enough other events within the relatively small conference circuit for intelligence professionals, creating a more ideal environment for incubating pathogens. After all, September has been the INSA’s Analytic Transformation, NDIA Disruptive Technology, DNI OSINT, and DNI Proteus conferences.

However, while this year’s sicknesses are merely the usual expected issue, our Red Cell attuned eyes do wonder what the potential impact of a targeted, small scale biological attack would be for such an event – particularly given the highly cross disciplinary, interagency nature of these kinds of conferences. Of course, this is exactly the value which brings participants together, but a longer incubation strain could inflict significant damage.

This potential for damage is nonetheless offset by the nature of who typically attends such conferences. After all, the working level grunts usually can’t break away for an event, nor get travel approvals through layers of management. Perhaps the net result might even be an increase in productivity, assuming that the chain of infective transmission doesn’t spread too widely within the vaults once participating managers are back at their home agencies…

While this has been an idle thought experiment, and we are rarely given to commenting on the reasons for our little band’s absence from blogging, suffice it to say our group’s interest in the abstract is driven by personal experiences (admittedly of an entirely more mundane nature) in this matter. At the very least, it was the conversational upside of inevitable biological realities. And we would not be surprised if next year on the conference circuit we see the comeback of the Asian style designer medical masks, as well as the increased presence of indoor biodetection sensors – if only for the experimentation, modeling & simulation folks to mull over in a very different kind of crowdsourcing exercise.

Labels: , , ,

28 August 2008

DNI Open Source Innovation Challenge 2008

We are unabashed believers in the unique contributions offered by open source intelligence as a discipline, and have been greatly pleased to see the increased prominence of such efforts within the Intelligence Community over the past decade. Today’s OSINT is a far cry more advanced from the early days of the 1990’s, when the first glimpses of the potential offered by the information revolution were visible in the newly opened media markets of the Soviet Union.

One of the most dramatic shifts since that time has been the development of OSINT as more than a mere data gathering function, increasingly focused on providing insight through rigorous analysis and imaginative exploration. Analytic outreach naturally goes hand in hand with open sources. And while the intelligence community is still grappling with the best manner to encourage and develop such efforts, this evolution is a fascinating space to observe and participate in.

Thus we are immensely interested to see the results of the DNI’s Open Source Innovation Challenge for 2008. This is a frankly unprecedented effort - and long overdue. Announced via email and on their public blog, the invitation speaks for itself:

Special Announcement

The Open Source Innovation Challenge

We are pleased to announce an exciting opportunity in conjunction with the DNI Open Source Conference 2008: "The Open Source Innovation Challenge." This is a unique occasion for representatives from academia; think tanks; industry; the media; federal, state, local, and tribal government; and other diverse sectors to use open source information to address real intelligence challenges. Subject matter experts from any field can apply innovative research techniques, thus giving new insight to the Intelligence Community.

Can you provide the most innovative and relevant answer to the Challenge questions?

The Office of the Director of National Intelligence (ODNI) has provided two Challenge questions (below) and instructions to all conference registrants. Those who choose to accept the Challenge can submit a answer for one of the two challenge questions posed. Entries will be reviewed by a panel of judges consisting of senior IC representatives. The three entries judged to be the best answers to Challenge questions will be announced during the opening plenary session of the DNI Open Source Conference on September 11th and the answers will be presented at the concluding conference plenary on September 12th. The Challenge is open to all conference registrants, including those who are not able to attend due to overwhelming registration demand.

Challenge Questions

1. Using the best open sources to inform your answer, is Al Qaeda a cohesive organization with strong and centralized control, intent and direction?

2. According to open sources, who will be the global leader in alternative fuels and why?

Challenge Guidelines

1. Challenge Participants and Entries: Entries can be submitted either by individuals or teams, with no limit to the number of individuals on a team. Teams can consist of individuals from any number of organizations, rather than representatives exclusively from a single university, company or organization; multidisciplinary teams are encouraged. Each person, however, can only enter the Challenge once—as an individual or part of a team, not both. At least one member of each team must be a registered conference attendee and entries from individuals must be submitted by a registered (not necessarily a confirmed) attendee. Entries should address one of the two Challenge questions proposed; entries attempting to address both questions will be disqualified.

The remainder of the full guidelines may be found here.

This seems to us an excellent opportunity for a number of academic and private sector shops to demonstrate their mettle in front of a very serious – and no doubt quite attentive – audience. The timing – and timelines – reminds us more than somewhat of the Burundi exercise of years past. This is certainly no coincidence, and we have long felt it was time to update the original work performed for the 1995 Aspin-Brown Commission on Intelligence in a modern context.

To all those participating, bonne chance.

Labels: , , , , ,

13 August 2008

What’s in an intelligence professional curriculum

In the wake of the summer conference season, and in particular the recent events hosted by the International Association for Intelligence Education (IAFIE), we have been left to ponder one of the enduring challenges of the field’s ongoing professionalization: the widespread disagreement regarding what exactly prospective candidates and serving practitioners ought to be taught in an entry level and continuing education programs. (Note that we deliberately emphasize the need for an intelligence professional curriculum, vice entering into the debates over intelligence education versus intelligence studies. While such discussions have their place, we do not wish to address them here, and have chosen a third terminology as a proxy to encompass both the theory and application intended to serve the practitioners’ needs in order to address both training, education, and the meta- or comparative study of the field.)

One would think that this should be a largely uncontroversial matter. After all, there is widespread agreement regarding a number of the common skills and tasks required of intelligence professionals – particularly in the analytic side of the house (which admittedly has been better explored from the perspective of intelligence theory). There is even a growing consensus on the other qualities required by an intelligence professional, developed as part of a number of human capital competencies modeling efforts that are occurring both within the government and its private sector contractor and competitive intelligence counterparts.

This is not the first time the question has been raised. Several contemporary model curriculum efforts came out of the United Kingdom’s National Intelligence Model, translated in the United States under the Generic Intelligence Training Initiative to the law enforcement realm of the then dominant counterdrug mission circa 2000. Such efforts eventually culminated (through a fascinating pathway of memetic diffusion) in the now popular International Association of Law Enforcement Intelligence Analysts’ Foundations of Intelligence Analysis Training standards. This has essentially displaced the previous standard curriculum model, at least in the criminal intelligence discipline, a defacto mix of the 1970’s era Anacapa training coupled with limited GEOINT and quantitative methodologies that grew out of the NYPD’s COMPSTAT. By default, this is also the dominant paradigm for the emerging discipline of homeland security intelligence, given the now overwhelming participation of state and local law enforcement in the new structures that have emerged in the strange evolutionary turns of the domestic mission and its capabilities.

Other models have been developed and presented from the academic perspective over the years since, involving separate deliberative efforts at four universities, the National Defense Intelligence College (formerly the Joint Military Intelligence College), and the Office of the Director of National Intelligence. Yet none have been widely adopted, even in principle - and the debates over the topic remain exceptionally heated.

We should note that controversy is of course a matter of perspective. While the latest evolution of curriculum within one particular institution sparked such a degree of debate and dissent that upon the recent departure of one of the significant players involved in implementing these changes, it was joked that the traditional hail and farewell meal was held at an undisclosed offsite location in order to prevent a prominently vocal critic from arriving driving a VBIED. And although this little jest was made without the knowledge of any of the involved individuals that had participated in the debate, it would certainly not be the most contentious faculty meeting we had ever observed. For a real civil war level dispute, one must look to the tenured staff at in other disciplines.

Yet none of these differs markedly in content or kind from the first intelligence curriculum design attempt that we are aware of, a modest but nonetheless foundational study authored in 1965. Those unaware of the true history and impact of intelligence privatization might be scandalized to learn that this was a contractor led effort, explicitly designed to create the government curriculum for the then emerging Defense Intelligence College that resulted from a recommendation contained within the 1946 Gerow Report on officer’s education. The latter is widely considered to be the origin of current military professional education. We would like to see its role in establishing the concept of intelligence professional education likewise remembered, particularly given that it encompasses both education and training concepts.

To be sure, the profession has evolved since this time. Entire new disciplines within the field have emerged, and pedagogy likewise has come a long way. But somehow, practitioners are constantly confronted by those wishing to re-invent the wheel when it comes to implementing a new program. In no other field would it be possible to credibly ignore all antecedents when it came time to discuss program objectives and outcomes, especially when these are ignored in favour of long debates over first definitions. It should not be thus in the intelligence profession.

Likewise, we strongly object to the oft-heard statements that an intelligence curriculum ought to merely concern itself with teaching the basics of critical thinking, writing, and briefing. While these are indeed vital skills, and their mastery strongly correlated with success in the field, they are by no means the only things an entry level analyst needs. And despite the claims that the IC will provide all further necessary instruction on tradecraft topics, we would venture to guess that these claimants have not led a line unit for some time. Similarly, those that have never served outside of the cloistered confines of the most established of the big sixteen may not always appreciate how little training budget (and time) is available to those in other agencies and elements. Again, in few other professional endeavors does one anticipate that college educated entry level candidates are merely blank slates, waiting to be imprinted with the One True Way.

Lastly, we would offer one final consideration for those developing a new intelligence curriculum. Pay no heed to those that demand that the study of intelligence be the academic discipline that dare not speak its name, or that this name be somehow muted and altered to provide greater attraction for interdisciplinary students. Such programs are inevitably a confused pastiche, and fail in the most important function of the educational process: the cultivation of personal passion and the all consuming interest that drives the best professionals. A muted program under a politically sanctified name merely mutes its students, not critics. We cannot as a profession allow the prejudices of those critics to dictate the terms under which new generations come of into the field – particularly given the vital importance of the generation after next at this historic turning point in the community.

Labels: , , ,

19 July 2007

Blogging the DNI’s Open Source Conference

Conference season continues apace, and with a wealth of interesting material surfacing for public discussion in the intelligence studies world. We note with great interest the rather unusual collection of blog entries by multiple contributors regarding the events. We are used to seeing this at the major tech conferences, but are frankly surprised to see it in the intelligence community. It simply would not have occurred to us that such a thing would happen, if not in due to overt security restrictions then in the face of the normal culture which prevails at such events.

It is however a harbinger of things to come, we think. We ourselves are of mixed minds on this matter – we have for a long time supported the Chatham House rule in order to encourage a more frank discussion free of political and career considerations (which can be far more damning than any security officer’s checklist). We fear that routine blogging of these rare unclassified events may greatly impair free flowing debate – and may indeed limit attendance in ways we cannot currently predict.

But in this case, the deed is done, and for those interested, a short collection of some relevant links:

DNI Open Source Blog 2007

a thaumaturgical compendium:
Hidden in plain view
Knowledge Management
Media as the Open Source
Technology: Improving the Use of Open Sources
Open Source on the Web


We should also note that the recent Boyd Conference has also generated quite a bit of interesting blogging in the 4GW and future warfare space, well covered by others.... see the usual suspects over at Zenpundit, Shloky, Simulated Laughter, Soob, and tdaxp

Labels: , , , ,