/* */

10 September 2008

Crowdsourcing OSINT

UPDATED below

Now that the deadline for submissions is passed, and thus our comments cannot unduly influence responses to the DNI’s Open Source Innovation Challenge, we wish to revisit some of the strategies that emerged in response to the exercise.

The 1995 Burundi exercise sought to use a direct privatization model, in which contractor resources and analysis were directly compared to the IC’s production. Subsequent production level OSINT efforts have rarely involved such an either / or choice, but rather focused on augmenting community capabilities. The original model was largely collection focused, as were most OSINT efforts of the day (and regrettably, far too many even now). The choice of a single firm (admittedly, one of the only in the USG facing OSINT game back then) offered a degree of centralization of efforts and commonality of response. In reality, that single firm pursued an acquisition strategy which leveraged a number of other commercial vendor’s products in specialized areas, from gray literature exploitation to commercial overhead imagery re-dissemination and analytic outreach.

Thus far, we have observed that responses to the latest challenge appear to have fallen into roughly three categories. The first were the highly competitive offerings by subject matter experts and related small teams with prior intra-group connectivity and affiliations, typically executed rapidly and in a low profile manner. The second were the aspirational offerings, typically by individual practitioners, interdisciplinary academics, or smaller firms. These offerings often involved those without direct community expertise covering the identified target set, but who acknowledged a desire to participate in the field. Neither were unexpected responses.

The third class of response, however, is destined to perhaps be the most controversial. It has been described as a “crowdsourcing” approach. To date, we are aware of a singular such effort out of Mercyhurst College’s intelligence studies program, which has also been something of an outlier in the field. Now, the term crowdsourcing brings immediately to mind its alternative label, the LazyWeb – and we are also reminded of the comments by the bright folks over at Oracle’s think tank AppLabs, in which the subtext of such efforts to leverage the wisdom of crowds are revealed.

However, one can rarely call the highly motivated students at Mercyhurst lazy. And while application of this new aggregation model for open source acquisition – we would hesitate to call it production, at least as we currently know it – is indeed innovative, it raises as many questions as it might produce answers.

In this, the crowdsourcing model reminds us of an earlier effort at Mercyhurst to trial new intelligence production approaches using another Web 2.0 technology. We do sincerely hope this effort is more successful than the last. UPDATE: And so it came to pass, with the Mercyhurst effort taking a win alongside the submission from the commercial intelligence firm iJet, out of twenty four total entries. Congratulations are in order - and the first round for the winners is on us.

The most critical issue that we see in crowdsourced OSINT strategies is the problem of denial and deception. One of the enduring tenants of OSINT tradecraft is that the sources consulted ought not ever know the use to which the information will be put. The divorcing of content from use context goes a long way towards reducing the problems created by sources which may attempt to influence rather inform (at least in terms of deliberate active messaging tailored for IC audiences). Rigorous analysis must still be applied to identify and eliminate the effects of source bias and implicit messaging directed at other audiences, but it is far harder for an adversary to coordinate a passive deception campaign seeded into open sources if they are unaware of the OSINT effort, its key intelligence questions, and its collection methods.

Crowdsourcing seems particularly vulnerable to denial and deception given that it relies on explicit calls for participation. Further - beyond mere knowledgability of project topic and intended audience - the publication of the specific indicators sought by the project coordinators essentially provides a roadmap for potentially successful deception themes and associated messaging, as well as the essential elements of information to be protected by adversary operations security and other denial measures. While source validation measures may provide some defense against such deception, it is unlikely to defeat a well crafted campaign executed through appropriate cover organizations and other agents of influence.

Timelines do play a role – short deadline production efforts are less likely to attract deliberate deception. However, if crowdsourced OSINT becomes commonplace, it may serve an adversary’s interests to establish latent architectures which would enable rapid response active measures campaigns designed to exploit the lack of time available for validation and other testing. One could particularly see such a structure evolving in advance of planned actions which an adversary foresees would provoke a high profile international crisis. The information advantage that could be offered in such a situation should such deception efforts influence a targeted decisionmakers' response would be priceless – especially in the critical first hours of a 3 a.m. moment that developed without earlier warning.

One could easily envision an experimental research series which would evaluate the potential susceptibility of crowdsourced OSINT to denial and deception. We hope to see some young researcher take up this effort in the near future.

We would also be remiss if we did not note that another contemporaneous effort – the Gray Goose project - has emerged to address a similar real world OSINT problem using a very different production strategy, one that might be termed rapid community of interest formation relying upon self-affiliation of interested subject matter experts. This effort bears greater examination in depth, particularly as it deliberately – and hopefully more productively - channels behaviors we have previously observed in surge intelligence responses to other crisis events. It also appears to be at least in theory more resistant to denial and deception, but that is a discussion for another day.

While the DNI’s challenge has overall generated a great of discussion, it remains to be seen whether that energy translated into truly innovative finished OSINT products. We eagerly await further conversations on the topic at the conference later this week, along with what we hope will be a future overview level assessment and compilation to be published under the DNI’s auspices. From the perspective of intelligence studies theory, it has been a most fascinating exercise to observe, and no doubt much will continue to come of it.

Labels: , , , , ,

29 August 2008

Intellectual property claims as denial & deception measures in medical intelligence

Following yesterday’s clear demonstration of the official embrace of open source intelligence comes a sharp reminder of that discipline’s limitations. The field of medical intelligence – and in particular, epidemiological intelligence – has been one of the areas in which OSINT has seen great successes. These successes are all the more important as they have involved the integration of specific scientific and technical expertise into collection, analysis, and visualization of extremely hard problems across very large scale geographies and populations. However, much of the underlying open source information and reference materials have only been made available due to the predominate ethic of free information exchange which prevails in scientific sharing and peer review. A recent Washington Post article (via Futurismic and Open the Future) highlights a new concept that may threaten the fundamental availability of those underlying materials.

This concept - viral sovereignty – immediately brings to mind the worst days of the Cold War, in which the Soviets sought to conceal information regarding large scale disease outbreaks to preserve the illusion of a superior socialized medical system, and in some cases such as the 1979 Sverdlovsk outbreak, prevent revelation of their clandestine biological warfare programs. The newest iteration of these ideas couple the same statist impulse towards censorship with a distorted view of the intellectual property market, resulting in a truly poisonous brew. One might consider such paranoia- and profiteering- driven claims a unique type of denial & deception measure aimed directly at the OSINT mechanisms of governments, pharmaceutical firms, and international organizations.

We would not wish to see a future where fundamental medical information regarding new disease outbreaks is simply not available in certain high risk countries. The potential higher order effects of such short-sighted decisions are readily considered – including the “surprise” global emergence of highly virulent new infection strains from unreported lower level outbreaks. Such a state of affairs could simply not be permitted to exist unchallenged, and as a result it is likely that a number of nations (particularly regional neighbors most likely to be impacted by such outbreaks) might then turn to clandestine collection means to acquire what previously was the open domain of science itself. This raises serious proliferation concerns, if new disease variants are obtained by BW aspirant countries (or non state actors) but are not otherwise widely known among nations which have abandoned biowarfare programs. One could also anticipate a surging demand for such clandestine collection measures for industrial espionage purposes, especially in countries where the legalities and ethics of an open competitive intelligence profession simply does not exist.

Such frictions would not only distort legitimate markets for pharmaceutical advances, but also would fundamentally impact the iterative and collaborative nature of modern medical research. And the first victims of these negative effects would likely be the unfortunate citizens of the country seeking to employ spurious intellectual property claims in this manner.

Labels: , , , , , ,

05 March 2008

Novel underground facilities revisited

We had previously covered the kind of unusual civil construction which makes for good unclassified teaching examples in consideration of the intelligence challenges posed by hard and deeply buried targets. Thus we thought it appropriate to also note the excellent example surfaced by the fine gentlemen over at Coming Anarchy, which appropriately notes the difference between the uses to which sophisticated underground construction techniques are put in an oil rich democracy versus its kleptocratic and autocratic counterparts in other places also graced with the geologic accident of such resources.

More importantly, the site also demonstrates the difference between construction at a true civil site – extensively documented, widely discussed, and exceptionally transparent – vice that of the kinds of subterfuge that can be observed at other suspected dual use or known bad actor facilities.

While we are not fond of the political purposes to which the seed vault itself has now been put – the issues of exceptionally long term climate change being the least of our worries in futures scenarios; we cannot argue with the idea of a genetic Ark as insurance against a future Black Swan event. However, our thinking on the matter trends much more towards concerns regarding the other high consequence / low probability events that may occur with far less warning, such as pandemic multi-crop agricultural disease.

We also note that this particular underground facility does indeed perhaps now truly merit our earlier erroneous application of an acronym drawn from the same convention as that of the Dining FACility (DFAC). Bon Appetite.

Labels: , , , , ,

02 December 2007

Blinded panopticon

Continuing the weekend’s brief examination of the more public aspects of operational tradecraft, we briefly wish to touch upon the growing phenomena of surveillance cameras in the UK.

The Ring of Steel has been heralded as the most significant implementation of ubiquitous imaging in an urban environment ever created. However, its effectiveness for primary anti-crime purposes has been questionable given the continuing increase in all manner of offenses, against the backdrop of an ever less engaged policing strategy and an increasingly dysfunctional justice system.

Nonetheless, such as system creates clear difficulties to clandestine operations in London and environs – as do less sophisticated implementations throughout Europe. But it is these program’s lesser cousins that draw our attention now – the automatic speed camera, as they have apparently also drawn the attention of less than happy local residents.

The revenue generation purposes of speed cameras and red light cameras have been debated against their efficacy in reducing traffic accidents and fatalities. However, there is definitely something highly intrusive in the state’s constant, automated presence in even the remotest parts of the countryside. This has clearly produced a significant reaction, as documented in a number of attacks designed to disable these surveillance systems.

We find it even more significant that the most effective attack is apparently a variant of necklacing, in which a subject is imprisoned within a tire doused in gasoline and set aflame. The tactic was most famously applied to human victims in South Africa and Haiti, particularly in cases where the individual was suspected of informing to authorities.

We would venture to guess that there is a psychological message here, above and beyond the practical considerations of effective TTP for attacking such installations. No doubt we will see other attacks against future autonomous capabilities also modeled on such resonant histories. (Perhaps this is an area to be further explored through efforts such as Mountainrunner’s research into the psychological impact of unmanned systems in the battlespace.)

There are also lessons here for any designer (or collection manager) responsible for large scale imaging (or biometric) installations, particularly for counterinsurgency applications and other situations where the communities under observation may share cultural commonalities to such reactions – and especially if a mediated reinforcement mechanism is developed to popularize and celebrate the results of successful attacks.

Labels: , , , , ,

09 November 2007

Implications of publishing open source IMINT analysis

Some time ago, we added the excellent IMINT & Analysis blog to our sidebar for further watching. The effort is a superb example of the quality of contributions that can be made from unclassified, open source research through the application of basic analytic tradecraft. It pains us that this was not more routinely done by others in the space years ago. The technologies have been in place for some time – all that was lacking was the right mind and a willingness to devote the energies such a project would require.

To be sure, individual findings from selected research – such as Chechen urban battle damage assessments, PRC submarine activities, and the recent destruction of the Syrian suspected nuclear facility have all been chronicled using imagery. But the systematic assessment of multiple imagery sets in order to produce and publish something akin to finished geospatial intelligence is another matter entirely. Frankly, all that is lacking is cross reference to BE numbers, else one could easily mistake this as the output of a government system stripped of its markings and logos.

On the one hand, this is an unprecedented teaching opportunity for new analysts coming out of the academic side of the house. Geospatial intelligence has long been among the hardest of disciplines to inculcate within the student cohort, and many promising analysts have no doubt been steered in other directions simply by the lack of availability of resources and expertise to inspire them to pursue the path.

However, the wider availability of such products does raise concerns regarding the potential to feed adversary denial and deception efforts. High resolution commercial imagery has long carried the risk that adversaries without access to, or understanding of, the true nature of imagery collection would evolve more rapidly means to defeat such systems based on new commercial products. These risks are magnified when one can begin to glimpse the thought processes and tradecraft applied to imagery intelligence problems over the course of the production cycle.

We believe that the publishing of these kinds of finished products on an open blog such as IMINT and Analysis is not itself the problem. The real challenge arises out of the changing nature of the information environment itself. When the potential for such developments exist, they will inevitably arise in one form or another. It is better to consider their implications from a perspective of open discussion, than to attempt to second guess the effects of such activities in another context – for example perhaps that of an adversary’s intelligence service’s open source unit conducting their own version of a Red Cell assessment.

There will never be another day in the 21st century when the adversary will have less access to what was once the most sophisticated of the 20th century intelligence technical collection techniques than they do at present. The means by which such technical means may be defeated will only be easier as time passes, technology grows more common and less expensive, and the understanding of these systems from civil applications and open sources grows more sophisticated. The denial and deception problem - applied in the context of national technical means - will only get harder. The challenge to the Intelligence Community is to accelerate the pace of innovation in order to overcome the adversary’s attempts no matter how much easier the deceiver’s task may become in the future. Towards that end, we strongly suspect that the robust discussion of analytic tradecraft – including counter-deception – will do more to advance that innovation within the intelligence profession than in a closed and narrow conversation from a limited range of perspectives.

Labels: , , , , ,

09 October 2007

Electronic attack and advanced denial and deception in new contexts

The technical boffins over at O’Reilly Radar have highlighted an interesting potential scenario, first put forth by Aviation Week, to explain the apparent failure of the Syrian air defense network during last month’s air strikes by Israel.

This is not the first time that public reporting has emerged discussing the potential applications of sophisticated EW techniques in suppressing adversary air defense networks. One can recall similar speculative stories coming out in the initial days of major combat operations of OIF in 2003.

What makes this interesting is the boffins’ discussion of engineering new public networks to defeat these kinds of attacks in the context of other, civil applications. One can easily understand the desire to do so in order to protect the integrity of wide-scale surveillance networks such as London’s ring of steel. There are less obvious applications in assuring the reliability of monitoring systems which do not rely on even such unambiguous elements as video feeds – perhaps large scale environmental monitoring programs? Given the research dollars flowing towards theories of climate change, one can easily see the potential motivations for manipulation of sensors and associated data streams at the source, in order to avoid the appearance of bias in later analysis.

These approaches will rapidly scale beyond their original military context as widely implemented sensors systems come into more common civil use. One can easily picture such efforts directed against GPS based highway toll and use monitoring systems, for example, or against other RFID or cellular population density measurements. (Persistent virtual worlds have already proven the potential benefits to retail and other establishments from manipulating such “popularity” measurements based on presence related data. The real world would be no different.)

The Wizard’s War is always with us. It just grows more interesting over time.

Labels: , ,

07 October 2007

Novel UFACs

The evolving sophistication of commercial construction techniques is increasingly popularizing elaborate underground structures for a variety of entirely novel applications. The latest of these – urban luxury homes in development restricted areas - are profiled by various British print media outlets.

London’s newest urban underground reminds us a great deal of author William Gibson’s fictional “stealth houses” – structures designed to conceal high value properties entirely within apparently abandoned industrial areas, providing security through obscurity.

However, these are very real examples of the growing complexity of urban geographies – and the increasing challenge to planners, operators, and intelligence professionals which will encounter these spaces in the cities of the tomorrow. Such future underground facilities will make the Hezbollah fortifications in urban Beirut encountered during the Harb al Tammuz in 2006 look insignificant in comparison.

While costly, these architectures do not require a great deal more sophistication than any other typical commercial construction project, especially any building that already requires building sub-basements for drainage, power, or HVAC systems. Of course, it is even easier to arrange for these features when fitted to new building sites.

Frankly, we are quite surprised we have not seen these yet in the high value property markets in Manhattan, San Francisco’s Bay area, or in particular the greater Washington DC metro area – there are plenty of row homes in Georgetown, Arlington or Alexandria that one would suspect might benefit from such modifications (though we suppose there is always the question of the water table to worry about in some of those areas). But give it time…

Of course, familiarization tours for new analysts to these types of underground facilities will be far more pleasant than the trips taken by their counterparts. We would certainly far rather enjoy a glass of wine next to a private pool than tramp through the damp tunnels of some Cold War era concrete structure.

UPDATE: Thanks to one of our readers who wrote in to recommend changing the choice of acronym from UFAC (underground facility) to HDBT (hard and deeply buried target). The specific meaning of the original wording within the IC apparently now creates some confusion based on its typical application to the analytic center responsible for study of these targets. (Our use was based on a more generalized, and perhaps older, naming convention - in the same manner that derived naming for chow halls and other structures. We shall have to update our style guide.) Text above corrected in accordance with that convention, with our humblest apologies to the fine folks over at the center, and sincere gratitude to those who raised the matter.

Labels: , ,

26 June 2007

Denial and deception for beginners



In the wake of recent discussions over the future of imagery constellations, we note the following item of interest over at Arms Control Wonk. While we often disagree with the learned Herr Doktorprofesor on matters of interpretation and intent, we respect the analytic rigor with which he approaches problem sets.

It is somewhat distressing to see this same rigor applied towards determining optimal activity scheduling windows for counter-IMINT denial and deception. (We will not comment whether we believe he is right or not in his tables, but we do note there are other variables in these equations.) But, as he notes, adversaries are very much capable of accomplishing the same thing using the efforts of Western hobbyists, commonly available open source software, and myriad open source publications both online and in the gray literature.

D&D is insufficiently appreciated nor considered, especially by policymakers who, no matter how often they may be briefed, confuse “The adversary is concealing critical information” with “I don’t know” - two branches of the same tree, but with very different fruit. It is too rarely taught in the academic environment, nor introduced into exercises and simulation. It can challenge the best planned effects based operations, and frustrate every attempt at operational net assessment.

But it is never perfect, and it can be defeated by aggressive collectors and good analysis. There is quite a body of deception and counter-deception literature in the public domain, which is well worth the reader’s time.

But most importantly, it is vital that the next generation of collection programs be accelerated in order to ensure that the adversary is never able to consistently defeat US technologies and approaches. It is the intelligence version of the age of race between armor and bullet, and in this case our bullets must always be capable of piercing any shield. Too often this is forgotten in the day to day fights over acquisitions and policies, when the realities of limited capabilities and high demand / low density assets still loom large in our thinking.


h/t: Image above is from Analytical Graphic’s excellent STK product, which we highly recommend for those that have a need to do real space operations and GEOINT analysis on a more than occasional basis.)

Labels: , , , ,

16 December 2006

Your lying eyes

So the public discussion of advanced deception technologies proceeds apace, led of course by those on the cutting edge of technology and its sidewise applications.

While we love the discussions of the next generation of wunderkind techno-toys that continually float to the surface in our field, we must say that for all the speculation regarding the impact of holograms, lasers, lights, and magic bubbles the simplest of tools such as SMS, photoshop, and blogs continually bedevil practicing information operations professionals and the creaking 1950’s structures of national PSYOP organizations. The latest gadgets, whether they be iPods or streaming social networked self-aware recommendation based reputation ranked Web 2.0 viral whatevers, are just another set of shelfware unless you have the right people, with the right minds, engaged in the activity.

Labels:

25 November 2006

Technologies of deception advancing

Deception remains one of the enduring hard problems of the community, and its ever varying forms are testament to the creativity of the human mind, and the capacity of the human soul to lie.

This item at Defense Tech caught our eye. The concept of using holograms for tactical deception in the urban environment is an interesting one, and quite familiar to readers of science fiction (and their movie-going counterparts). The potential instantiation of such technology could be quite useful if executed properly. A more comfortable sniper hide, if nothing else, could make our lives much nicer….

Outside of the cutting edge and onto the more prosaic realities, we note the proliferation of deception tactics into the ordinary, for purposes of beautification. We note the following item on urban architecture, and the spread of buildings more integrated into the surrounding landscapes.

These challenges present serious questions for future intelligence problems. However, it is an excellent chance to begin integrating these types of problems from the very start into new analyst training programs, using such publicly available examples in the modern arena; and something outside of the hoary old World War II examples so often re-used. (As brilliant as they were for their day, such cases were highly situated examples which occurred in a technological and social context, and in a conflict environment, we are likely never to see again and thus of more limited utility to the instructor and student.)

Labels: ,