Showing posts with label Cyber Command. Show all posts
Showing posts with label Cyber Command. Show all posts

Wednesday, November 23, 2011

Digital Engagement = Cyber Counter PSYOP


A colleague referred me to a 17 November 2011 article in the NY Times headed: “U.S. Military Goes Online to Rebut Extremists’ Messages” (see: http://www.nytimes.com/2011/11/18/world/us-military-goes-online-to-rebut-extremists.html?_r=2&ref=global-home). The article talks about a Digital Engagement Team (DET) reportedly established in 2008. The team chief, MAJ David E. Nevers was quoted as describing the teams mission to “counter extremist ideology, promote cultural awareness and explain U.S. interests,”.

The article provides a description of the team and the languages they cover (Arabic, Dari, Persian, Pashto, Urdu and Russian in case you’re interested). The Times compares the open efforts of the DET with the highly classified and generally shielded US military efforts in Computer Network Operations (CNO).

The DET’s engagements are “transparent and attributable” according to MAJ Nevers. The team’s approval cycle can take hours and while, as the Times points out, this isn’t ‘real-time’ it’s a heck of a lot faster than any approval cycle I’ve been a part of.

The article also refers to the State Department’s Digital Outreach Team as a complementary effort headed by Richard LeBaron, a former Ambassador to Kuwait, that organization’s coordinator.

There is no question that the DET is a laudable effort, complimented as both effective and cost-efficient by Brian Fishman, a counterterrorism analyst at the New America Foundation, a nonpartisan research group in Washington in that same article.

There are two reasons I’ve pulled this article for today’s post. First of all we hear so much negative crap about the influence war, it’s nice to see something positive for a change. However, perhaps more intriguing are the questions the DET raises to me:

1. Are they part of the MISO element to CENTCOM or the STRATCOM element, or are they an organizational hybrid?

2. To whom does the DET OIC (Officer in Charge) report to and what senior officers are in his rating chain?

3. Is this simply a ‘one off’ created because of Centcom’s AO?

4. Given that the DET’s actions are really global because their WWW AO is amorphous, how can a single Combatant CDR be given responsibilities for the other AOs?

5. Do they have a set of ROE and formal procedural guidelines?

6. While measures of effectiveness (MOE)are notoriously absent from this kind of endeavor, are we capturing the lessons learned and TTP in a systematic way to be applied elsewhere?

7. Are we aware of similar allied efforts and have we tried to promulgate this type of effort through NATO?

8. Does it make sense to set up a similar PACOM effort to address the Asian AO?

The DET passes the common sense test and appears to be a good idea whose time has come, I’m just wondering if we’re making the most of it.

Speaking of ‘making the most of it’, take some time to enjoy your family friends during the Holiday Season. As we learn, life is short and unpredictable. I’ve already lost a colleague to a fatal stroke this year and another is in a hospital after his stroke. Neither were military and both were part of the information security industry – the lesson is enjoy what you can with gusto.

Happy Holidays

Photo Source: CENTCOM official Website (http://www.centcom.mil/en/about-centcom/leadership/)

Monday, August 29, 2011

Hactivists and the Internet: Lessons For PSYOP/MISO


The 8/26/2011 issue of netgov (http://www.nextgov.com/nextgov/ng_20110826_6276.php) had an article “Analysts say online ‘hactivism’ is becoming a preferred tool of protests”. The article proposes that Computer Network Attack (CNA) has emerged as a powerful force for protesters. The article talks about the protests against the San Francisco centered Bay Area Rapid Transit System which appear to be organized by the group Anonymous.

That group has innovated in its TTP (tactics, techniques and procedures) by combing CNA with on ground activity. The attack vectors are dependent on the desired result. If the group is looking to harm a target whose actions it opposes, it has turned to cyber attack as in the case of attacking Visa because it decided to stop accepting donations to Wikileaks.

Where the goal is more traditional – say blocking traffic, protesting on subway platforms or interfering with the daily commute the organization will demonstrate physically. They shield their identities in a number of ways with the Guy Fawkes mask featured in the movie “V for Vendetta” being a common means.

When dealing with urban AOs today’s MISO needs to be at least as flexible and techno savvy as our adversaries and enemies. We must appropriately employing digital influence and digital PSYACTs. Unlike non-state actors, military organizations must play by the rules. Unfortunately, in the case of the digital world the laws, rules, and doctrine have not kept pace with the battle. Computer Network Operations (CNO) are still pretty much behind the 21st century ‘green door’ and tactical MISO soldiers are not likely to have the CNO tools and authority.

MISO is often marked by innovation on the ground, SWC and the MISO chains of command need to support digital influence in a big way. Perhaps the new MISG can establish a joint ‘center of excellence’ with the other PSYOP Groups to develop doctrine, and TTP. This Digital MISO Center of Excellence should be located at the Naval Post Graduate School so that it could benefit from the latest in IO thought leadership. Fort Hunter Liggett should be considered as a proving ground where the technique could be honed in relative isolation and supported by both Active and Reserve personnel.

Tuesday, March 15, 2011

Something Different: IO and Terrorists


Today's posting is something a bit different. Following is a concept paper I drafted for a colleague. Essentially I took the IO capabilities of DoD and then provided analysis on Terrorist employment of those same capabilities.

Comments and input are welcome of course.

Photo Source: http://samsonblinded.org/blog/osama-too-good-to-be-true-part-1.htm

Terrorist Use of Information Operations (IO)

COL (R) Lawrence D. Dietz; General Counsel & Managing Director Cyber Security,
TAL Global Corporation

I Introduction
The US Department of Defense employs Information Operations to influence the course of battle and act as a combat multiplier. Terrorists are also very successfully employing IO and technology to their advantage. This short paper will give you an overview to assist you in future research.

II Department of Defense IO Capabilities

Reference: http://www.carlisle.army.mil/usawc/dmspo/Publications/Information%20Operations%20Primer%20AY11%20Web%20Version.pdf; Accessed 15 Mar 11

A. Core Capabilities

1. Psychological Operations (PSYOP) now Military Information Support Operations (MISO) – operations designed to influence the behavior of the target in line with CDR’s Concept of the Operation (CONOP)

2. Military Deception (MILDEC) – actions taken to shield true capability from the enemy (e.g Patton’s fake Army in the UK as a decoy for the Normandy invasion.

3. Operations Security (OPSEC) – all measures taken to shield information from adversaries and enemies

4. Electronic Warfare (EW) – dominance of the electronic spectrum, actions can include jamming to deny the enemy is communication, actions taken to identify enemy electronic emitters to facilitate identification of their units, other order of battle information, targeting for interception or jamming.

5. Computer Network Operations (CNO)
a. Computer Network Attack (CNA) – denying the enemy the use of their IT networks.
b. Computer Network Exploitation (CNE) – using the enemy’s network for friendly advantage, e.g. intelligence collection, communications medium, storage of hostile software code, etc.
c. Computer Network Defense (CND) – defending one’s own network

B. IO Supporting Capabilities

1. Counterintelligence
2. Combat Camera (Air Force Unit that provides still and video camera support)
3. Physical Attack
4. Physical Security
5. Information Assurance – protecting electronic information

C. IO Related Capabilities

1. Public Affairs = Public Relations; a conduit to the media and creator of print, and broadcast media.
2. Civil Military Operations – military forces employing civilian skills to improve the life and infrastructure of a local population.
3. Defense Support to Public Diplomacy – Department of Defense support to the Department of State’s Public Diplomacy Operations

II Terrorist Use of IO Capabilities

A. Core Capabilities

1. Propaganda – Terrorists are making exceptionally good use of the Internet as a means to inform, influence and recruit. They are also being supported by ‘friendly’ media such as Al Jazeera which tends to spin the news in a way that is favorably received by the Arab Street. Terrorist propaganda is especially effective due to the speed with which they capitalize on events that serve their purpose. This rapid response is indicative of a streamlined or de-centralized chain of command and abbreviated approval cycle.

Allied information support operations tend to be much more cumbersome due to the heavy ROE and complex approval schema which can often include both military and civilian command cycles.

2. Military Deception (MILDEC) – In my view terrorist operations tend to be decentralized although they employ deception to shield their true intentions and make very effective use of ‘cover’ identities.

3. Operations Security (OPSEC) – Terrorist cells are generally quite secure due to their decentralized nature. Most terrorist organizations appear to have a very healthy respect for Signals Intelligence and will avoid electronic means of communications such as mobile phones to avoid detection. Trade craft to include steganography (the concealment of messages in pictures) is also employed along with other measures such as compartmentalized chat rooms, common password schemas, etc.

4. Electronic Warfare (EW) – Improvised Explosive Devices (IED) are often remotely detonated via mobile phones, garage door openers, etc. I am unaware of any large scale terrorist jamming efforts to date.

5. Computer Network Operations (CNO)

a. Computer Network Attack (CNA) – Experts believe that terrorists will employ cyber attacks in conjunction with a kinetic or physical attack. CNA may be employed prior to or subsequent to the kinetic attack depending on the type of operation.

b. Computer Network Exploitation (CNE) – Terrorists, and nation states for that matter are routinely probing networks of interest. Terrorists are likely to employ a combination of human agents to infiltrate target organizations to be in a better position to exploit networks directly or to insert malicious code (such as the Stuxnet reported planted to damage the Iranian Nuclear Research program) for later execution.

Exploitation can also include gathering intelligence from the network. Terrorist cells must be self-financing. Harvesting data (personally identifiable information or PII) that allows them to steal identities which in turn allows monetization through theft of funds, goods or services is very effective.

Terrorist cells can also exploit networks by gathering information that may be of use to the movement in some way such as to identify potential funding sources or gather target information.

Terrorists are employing the Internet as a cost effective and for the most part, relatively secure communications channel. Their global operations lend themselves to Internet communications for availability, cost and security reasons.

c. Computer Network Defense (CND) – Unable to comment.

B. IO Supporting Capabilities

1. Counterintelligence – No comments

2. Combat Camera – Terrorist organizations make effective use of still and video cameras. They also exploit images captured by other sources such as the media.

3. Physical Attack – Mumbai type attacks are very likely to increase. They require a small footprint, are relatively low in cost and very difficult to defend against. They are very effective at exploiting soft targets which in turns results in dramatic chaos which is then exploited through the media and by the Terrorists’ own sources.

4. Physical Security – No Comment

5. Information Assurance – See Opsec Above

C. IO Related Capabilities

1. Public Affairs = Public Relations; Terrorists are exceptional PR professionals. They understand the value of publicity, especially the emotional appeal of images. They are able to appeal to ‘friendly’ media to a very great extent.
2. Civil Military Operations – Hezbollah and the Taliban have been quite successful at using social welfare as a means to ingratiate themselves with local populations.
3. Defense Support to Public Diplomacy – Governments tend to hide their association with terrorist organizations.

Wednesday, February 2, 2011

MISO in Egypt? – Just Supposn’


Suppose Lt. Gen. Sami Enan, the Egyptian equivalent of the Chairman of the Joints Chief of Staff, placed a phone call to Adm Mike Mullen, his US counterpart and said “Mike, we need some help over here. Can you spare some of those PSYOP guys to come over and help us work with our police force to keep order?”

Photo Source: http://www.bbc.co.uk/news/world-middle-east-12349365
(Note a DefenseNews article citing Agence France-Press 2 Feb 2011 cited that “US Military Chief Has Confidence in Egypt’s Army, see http://www.defensenews.com/story.php?i=5603226&c=MID)
If you were “Mike”, what would you do? Of course the first thing is you would call your boss (Secretary Gates and his boss, President Obama) to relate the news and seek their guidance. They of course would ask you first “what do you think”?

My gut reaction would be “Sir, I don’t think this is a good idea.”. I’d base that on a number of things, first of all Las Vegas would likely rule that the Mubarak government is an odds on favorite to lose power sooner rather than later. Secondly US popularity in Egypt is quite low so that the sight of US troops and Egyptian troops and/or police is likely to be akin to throwing gasoline on a fire.

Consequently the tactical perspective is not favorable. Having said that, I would offer up: how about asking General Alexander if the Cyber Command or one of its component commands could spare some horsepower? A Combined Joint Egyptian Influence Task Force (CJEITF) could be stood up.

The CDR of the CJEITF would be a US Flag officer and the deputy would be an Egyptian Flag Officer, one rank down. Together they could orchestrate an influence strategy that would range from strategic communications to messages for tactical forces and law enforcement engaged in keeping the pace.

The Cyber Command personnel would orchestrate the Internet activities such as monitoring and perhaps controlling traffic to and from social networks and employing computer network exploitation (CNE) to harvest intelligence information from the Internet. MISO personnel working with their Egyptian colleagues would develop the content for social networking sites, Blogs and others.

The CJEITF PAO would be working with local and regional media to insure an effective two way conduit of information.

Conceptually this behind the scenes approach would reinforce Egyptian governmental capabilities in furtherance of US interests in the region without showcasing US involvement and minimizing US tactical exposure.