Showing posts with label MISO. Show all posts
Showing posts with label MISO. Show all posts

Wednesday, November 23, 2011

Digital Engagement = Cyber Counter PSYOP


A colleague referred me to a 17 November 2011 article in the NY Times headed: “U.S. Military Goes Online to Rebut Extremists’ Messages” (see: http://www.nytimes.com/2011/11/18/world/us-military-goes-online-to-rebut-extremists.html?_r=2&ref=global-home). The article talks about a Digital Engagement Team (DET) reportedly established in 2008. The team chief, MAJ David E. Nevers was quoted as describing the teams mission to “counter extremist ideology, promote cultural awareness and explain U.S. interests,”.

The article provides a description of the team and the languages they cover (Arabic, Dari, Persian, Pashto, Urdu and Russian in case you’re interested). The Times compares the open efforts of the DET with the highly classified and generally shielded US military efforts in Computer Network Operations (CNO).

The DET’s engagements are “transparent and attributable” according to MAJ Nevers. The team’s approval cycle can take hours and while, as the Times points out, this isn’t ‘real-time’ it’s a heck of a lot faster than any approval cycle I’ve been a part of.

The article also refers to the State Department’s Digital Outreach Team as a complementary effort headed by Richard LeBaron, a former Ambassador to Kuwait, that organization’s coordinator.

There is no question that the DET is a laudable effort, complimented as both effective and cost-efficient by Brian Fishman, a counterterrorism analyst at the New America Foundation, a nonpartisan research group in Washington in that same article.

There are two reasons I’ve pulled this article for today’s post. First of all we hear so much negative crap about the influence war, it’s nice to see something positive for a change. However, perhaps more intriguing are the questions the DET raises to me:

1. Are they part of the MISO element to CENTCOM or the STRATCOM element, or are they an organizational hybrid?

2. To whom does the DET OIC (Officer in Charge) report to and what senior officers are in his rating chain?

3. Is this simply a ‘one off’ created because of Centcom’s AO?

4. Given that the DET’s actions are really global because their WWW AO is amorphous, how can a single Combatant CDR be given responsibilities for the other AOs?

5. Do they have a set of ROE and formal procedural guidelines?

6. While measures of effectiveness (MOE)are notoriously absent from this kind of endeavor, are we capturing the lessons learned and TTP in a systematic way to be applied elsewhere?

7. Are we aware of similar allied efforts and have we tried to promulgate this type of effort through NATO?

8. Does it make sense to set up a similar PACOM effort to address the Asian AO?

The DET passes the common sense test and appears to be a good idea whose time has come, I’m just wondering if we’re making the most of it.

Speaking of ‘making the most of it’, take some time to enjoy your family friends during the Holiday Season. As we learn, life is short and unpredictable. I’ve already lost a colleague to a fatal stroke this year and another is in a hospital after his stroke. Neither were military and both were part of the information security industry – the lesson is enjoy what you can with gusto.

Happy Holidays

Photo Source: CENTCOM official Website (http://www.centcom.mil/en/about-centcom/leadership/)

Monday, August 29, 2011

Hactivists and the Internet: Lessons For PSYOP/MISO


The 8/26/2011 issue of netgov (http://www.nextgov.com/nextgov/ng_20110826_6276.php) had an article “Analysts say online ‘hactivism’ is becoming a preferred tool of protests”. The article proposes that Computer Network Attack (CNA) has emerged as a powerful force for protesters. The article talks about the protests against the San Francisco centered Bay Area Rapid Transit System which appear to be organized by the group Anonymous.

That group has innovated in its TTP (tactics, techniques and procedures) by combing CNA with on ground activity. The attack vectors are dependent on the desired result. If the group is looking to harm a target whose actions it opposes, it has turned to cyber attack as in the case of attacking Visa because it decided to stop accepting donations to Wikileaks.

Where the goal is more traditional – say blocking traffic, protesting on subway platforms or interfering with the daily commute the organization will demonstrate physically. They shield their identities in a number of ways with the Guy Fawkes mask featured in the movie “V for Vendetta” being a common means.

When dealing with urban AOs today’s MISO needs to be at least as flexible and techno savvy as our adversaries and enemies. We must appropriately employing digital influence and digital PSYACTs. Unlike non-state actors, military organizations must play by the rules. Unfortunately, in the case of the digital world the laws, rules, and doctrine have not kept pace with the battle. Computer Network Operations (CNO) are still pretty much behind the 21st century ‘green door’ and tactical MISO soldiers are not likely to have the CNO tools and authority.

MISO is often marked by innovation on the ground, SWC and the MISO chains of command need to support digital influence in a big way. Perhaps the new MISG can establish a joint ‘center of excellence’ with the other PSYOP Groups to develop doctrine, and TTP. This Digital MISO Center of Excellence should be located at the Naval Post Graduate School so that it could benefit from the latest in IO thought leadership. Fort Hunter Liggett should be considered as a proving ground where the technique could be honed in relative isolation and supported by both Active and Reserve personnel.

Wednesday, May 25, 2011

Information Support Operations An Afterthought At Best for Homeland Security


On May 21 & 22, 2011 I was an evaluator for an exercise which took place in a major city. The city is the hub of an 8 city Urban Area Security Initiative (UASI). Federal government grant money paid most of the bills and sponsors took care of most of the rest.

The exercise involved 4 Emergency Operation Centers scattered over the area and was a series of ‘lanes’ designed to test Police SWAT (Special Weapons & Tactics), Fire, Urban Search & Rescue (USR), Emergency Ordinance Disposal (EOD), Emergency Medical Services (EMS). Each lane was coordinated by one agency and evaluators came from far and wide.

By design, the event is overall very low key, although there was an initial press conference attended by the city’s mayor and other dignitaries which resulted in some coverage prior to the event.

Media access was limited during the exercise and there were scant posters or other indications of locations or tactical lanes. In short it was akin to a military operation where the name of the game is to keep the public out of the way to minimize interference with the operation and maximize Operational Security (OPSEC).

While I can understand this posture in terms of external information support, I felt I was in a time warp when it came to the exercise play. There was absolutely no attention to the potential negative effect of information operations either intentional or accidental. Just as in my early Army exercise (PRC-6 anyone?) days, guidance was put out that communications are not to be interfered with because it was hard enough to communicate during the height of battle without someone messing with you.

More importantly the notions of misinformation, hostile crowds and pesky reporters were not considered at all. As for presence, there was only a single Public Affairs Officer at the central EOC with a few of the agency PAOs training their principals, but not actively involved in the exercise.

On the Command information side, EOC communications were via a chat like software package called WebEOC. No video and not very much contemporaneous reporting from other sources contributed to the CDR’s situational awareness.

Given the 24 hour news cycle, the persistence of paparazzi, and the ubiquity of cell phone video cameras – this is a mistake. Our enemies are clearly not stupid and are likely surveilling soft targets as you are reading this. The inability to provide information support operations in homeland security is a vulnerability that is open to exploitation by our enemies. DOD and DHS need to take the initiative and incorporate the informational aspects of homeland security into their efforts and as key elements in the Homeland Security Exercise and Evaluation Program (HSEEP) and a key factor in determining if the government got its money’s worth for its grant funding.

Tuesday, March 15, 2011

Something Different: IO and Terrorists


Today's posting is something a bit different. Following is a concept paper I drafted for a colleague. Essentially I took the IO capabilities of DoD and then provided analysis on Terrorist employment of those same capabilities.

Comments and input are welcome of course.

Photo Source: http://samsonblinded.org/blog/osama-too-good-to-be-true-part-1.htm

Terrorist Use of Information Operations (IO)

COL (R) Lawrence D. Dietz; General Counsel & Managing Director Cyber Security,
TAL Global Corporation

I Introduction
The US Department of Defense employs Information Operations to influence the course of battle and act as a combat multiplier. Terrorists are also very successfully employing IO and technology to their advantage. This short paper will give you an overview to assist you in future research.

II Department of Defense IO Capabilities

Reference: http://www.carlisle.army.mil/usawc/dmspo/Publications/Information%20Operations%20Primer%20AY11%20Web%20Version.pdf; Accessed 15 Mar 11

A. Core Capabilities

1. Psychological Operations (PSYOP) now Military Information Support Operations (MISO) – operations designed to influence the behavior of the target in line with CDR’s Concept of the Operation (CONOP)

2. Military Deception (MILDEC) – actions taken to shield true capability from the enemy (e.g Patton’s fake Army in the UK as a decoy for the Normandy invasion.

3. Operations Security (OPSEC) – all measures taken to shield information from adversaries and enemies

4. Electronic Warfare (EW) – dominance of the electronic spectrum, actions can include jamming to deny the enemy is communication, actions taken to identify enemy electronic emitters to facilitate identification of their units, other order of battle information, targeting for interception or jamming.

5. Computer Network Operations (CNO)
a. Computer Network Attack (CNA) – denying the enemy the use of their IT networks.
b. Computer Network Exploitation (CNE) – using the enemy’s network for friendly advantage, e.g. intelligence collection, communications medium, storage of hostile software code, etc.
c. Computer Network Defense (CND) – defending one’s own network

B. IO Supporting Capabilities

1. Counterintelligence
2. Combat Camera (Air Force Unit that provides still and video camera support)
3. Physical Attack
4. Physical Security
5. Information Assurance – protecting electronic information

C. IO Related Capabilities

1. Public Affairs = Public Relations; a conduit to the media and creator of print, and broadcast media.
2. Civil Military Operations – military forces employing civilian skills to improve the life and infrastructure of a local population.
3. Defense Support to Public Diplomacy – Department of Defense support to the Department of State’s Public Diplomacy Operations

II Terrorist Use of IO Capabilities

A. Core Capabilities

1. Propaganda – Terrorists are making exceptionally good use of the Internet as a means to inform, influence and recruit. They are also being supported by ‘friendly’ media such as Al Jazeera which tends to spin the news in a way that is favorably received by the Arab Street. Terrorist propaganda is especially effective due to the speed with which they capitalize on events that serve their purpose. This rapid response is indicative of a streamlined or de-centralized chain of command and abbreviated approval cycle.

Allied information support operations tend to be much more cumbersome due to the heavy ROE and complex approval schema which can often include both military and civilian command cycles.

2. Military Deception (MILDEC) – In my view terrorist operations tend to be decentralized although they employ deception to shield their true intentions and make very effective use of ‘cover’ identities.

3. Operations Security (OPSEC) – Terrorist cells are generally quite secure due to their decentralized nature. Most terrorist organizations appear to have a very healthy respect for Signals Intelligence and will avoid electronic means of communications such as mobile phones to avoid detection. Trade craft to include steganography (the concealment of messages in pictures) is also employed along with other measures such as compartmentalized chat rooms, common password schemas, etc.

4. Electronic Warfare (EW) – Improvised Explosive Devices (IED) are often remotely detonated via mobile phones, garage door openers, etc. I am unaware of any large scale terrorist jamming efforts to date.

5. Computer Network Operations (CNO)

a. Computer Network Attack (CNA) – Experts believe that terrorists will employ cyber attacks in conjunction with a kinetic or physical attack. CNA may be employed prior to or subsequent to the kinetic attack depending on the type of operation.

b. Computer Network Exploitation (CNE) – Terrorists, and nation states for that matter are routinely probing networks of interest. Terrorists are likely to employ a combination of human agents to infiltrate target organizations to be in a better position to exploit networks directly or to insert malicious code (such as the Stuxnet reported planted to damage the Iranian Nuclear Research program) for later execution.

Exploitation can also include gathering intelligence from the network. Terrorist cells must be self-financing. Harvesting data (personally identifiable information or PII) that allows them to steal identities which in turn allows monetization through theft of funds, goods or services is very effective.

Terrorist cells can also exploit networks by gathering information that may be of use to the movement in some way such as to identify potential funding sources or gather target information.

Terrorists are employing the Internet as a cost effective and for the most part, relatively secure communications channel. Their global operations lend themselves to Internet communications for availability, cost and security reasons.

c. Computer Network Defense (CND) – Unable to comment.

B. IO Supporting Capabilities

1. Counterintelligence – No comments

2. Combat Camera – Terrorist organizations make effective use of still and video cameras. They also exploit images captured by other sources such as the media.

3. Physical Attack – Mumbai type attacks are very likely to increase. They require a small footprint, are relatively low in cost and very difficult to defend against. They are very effective at exploiting soft targets which in turns results in dramatic chaos which is then exploited through the media and by the Terrorists’ own sources.

4. Physical Security – No Comment

5. Information Assurance – See Opsec Above

C. IO Related Capabilities

1. Public Affairs = Public Relations; Terrorists are exceptional PR professionals. They understand the value of publicity, especially the emotional appeal of images. They are able to appeal to ‘friendly’ media to a very great extent.
2. Civil Military Operations – Hezbollah and the Taliban have been quite successful at using social welfare as a means to ingratiate themselves with local populations.
3. Defense Support to Public Diplomacy – Governments tend to hide their association with terrorist organizations.

Wednesday, October 20, 2010

Regimental Week 2010: Coming Attractions


When I was a young lad growing up in Brooklyn I used to love going to the movies on Saturday. In retrospect I’m not sure which I liked more the movies or the candy. Next week I’m off to Fort Bragg for PSYOP Regimental Week. You can find the official press release from the US Army Special Operations Command at: http://news.soc.mil/releases/News%20Archive/2010/October/101018-01.html

For me this will be a bittersweet occasion as it will be my last one as the Honorary Colonel of the PSYOP Regiment. Surely the time has come for another senior PSYOP officer to assume this honorary role and I’m delighted that the designee will be an outstanding bridge between PSYOP of the past and military influence operations of the future.

Strangely enough I found out about the ‘replacement’ quite by accident – that fact speaks to the nascent nature of the PSYOP Regiment and the need to attend to military custom.

I’m looking forward to the program which will include updates from the Groups, the Joint Military Information Support Command and our sister services. I’m also looking forward to touring the Media Operations Center and seeing the latest and the greatest and comparing what they have to what I see in the heart of Silicon Valley.
Most of all I’m looking forward to mingling with the troops and learning about what is really happening in the field. While I’m a very hard grader and am rather tough to excite, I am always gratified by the level of our PSYOP soldiers and their ability to perform in an outstanding manner under the most adverse of circumstances.

I’ll be working on my “State of the Regiment” talk over the next few days. Some key messages I’m considering are:
• The PSYOP Brand – what do we really need?
• Today’s PSYOP soldier
• Unity of Command: why don’t we have it and what do we need to do to get it?
• The Future of the Regiment
Field input is encouraged!

Friday, August 27, 2010

PSYOP and Iraq: It Ain’t Over Yet


Notwithstanding declarations touting the end of combat operations in Iraqi, the influence war is far from over. Seemingly coordinated attacks across the country are sending forceful and graphic messages to Iraqis that their lives remain perilous. (Photo: NY Times)

With the withdrawal of the Warfighter, influence operations must take on a new flavor and tempo. Unlike Afghanistan which is mostly tribal and rural, Iraq has significant urban centers. These centers are served by local and regional media to include TV. In many quarters of these cities there are even likely (I haven’t been there so I can’t say for sure) Internet cafes and ISPs serving a growing body of Internet and smart phone users.

Iraq serves as a laboratory for future conflict. Military Information Support Operations (MISO) must now TRULY be in support – but this time of diplomatic efforts to thwart the insurgency and raise the conscious of Iraqis. Security is no longer just the problem of government. Citizens need to be more vigilant and supportive of their fledgling police and security forces. Aggressive influence operations are needed to mobilize the support of the population.

The people of Iraq need to dry up the sea of support that allows the insurgents to move freely. The government should help the process by maintaining truly anonymous channels of communications to allow citizens to provide tips on the enemy without fear of retribution.

DOD information support can and ought to come in several ways: First, PSYOP personnel can augment and assist State Department through the embassy and its outreach efforts. PAO personnel can facilitate the Iraqi media and in concert with the State Department, aid in the maturing of a potent and objective media that can inform and help the Iraqis defeat their insurgent. Other avenues could include training Iraqi MISO and PAO personnel and facilitating working arrangements between these Iraqi government personnel with local and regional media.

In addition to these programs, Strategic Communications efforts aimed at the Region should be undertaken via the Internet and other channels designed to ‘reach the street’.

The bottom line is that the influence war needs to ramp up even more than during combat and that all government instrumentalities need to be brought to bear under a clearly articulated strategy and with a mindset to learning on the fly. Lessons learned over the next few years should not have to be relearned in new influence battlefields where ever they may be.

Thursday, July 8, 2010

On The Firing Line


The smoke is still swirling around the MISOing of PSYOP. Rather than being able to sit back and analyze it all, I find myself on the front line (so to speak) as I undertake my role as the “PSYOP” Subject Matter Expert (SME) for an exercise at a major DoD School.

This is my third performance in this role, so I’m familiar with the scenario, the nature of the students and of course the faculty involved. The past two exercises have been pretty smooth in terms of information support to the hypothetical task force. Annex H for PSYOP was developed and there was significant interaction with Public Affairs and Strategic Communications under an Information Operations (IO) aegis as the exercise evovled.

The current mission is quite a bit different. First of all I had to update the Faculty on the details of the name change and provide them with the appropriate phraseology to convey to the students. This also meant answering a lot of questions for which there are frankly no answers.

Fortunately I have a few knowledgeable resources who came to my rescue so that I could put the best face forward for MISO possible under the circumstances. Since the exercise is predicated on a natural disaster and is less than a week long, my level of response should prove adequate.

But I candidly worry for my brothers and sisters in the PSYOP/MISO (forgive me the legacy usage) community who will have to devote their precious time to explaining the rationale for the name change, divine what other changes can be expected when and otherwise tap dance until the chain of command responds with some definitive answers.

I’m not so much worried about how SWC will adjust unit names or Branch descriptions, I’m frankly worried about the big picture. Will anything other than the name change? Will DOD decide that IO is a function or an overarching branch that should include MISO, EW, PAO and CNO. In either event, what new doctrine, organization or resources will be applied to elevate the information Battlefield Operating System to the level of kinetic warfare across the spectrum of conflict?

I’m also concerned that the recently touted ‘new’ Army strategy scheduled to be published in August 2010 was created in the kinetic world with little attention to the information battlefield and in spite of the growing specter of irregular warfare and the quagmires we find ourselves in with our forces in Afghanistan, Iraq and who knows where else.

Let’s hope I’m just being a little paranoid, which is in my nature being an MI type who grew up in Brooklyn and that the powers that be have actually given the big picture some uncharacteristic deep thought.