Soob

Politics, Foreign Policy, Current Events and Occasional Outbursts Lacking Couth

This is an interesting briefing (PDF) on Open Source Intelligence gathering on the Internet from the guys who created the great data mining program Maltego. Slides 23 to 26 are the most interesting part. The authors posit a spin on an idea raised a few times on this blog about the creation of imitative virtual social networks. The authors have a quote on slide 23 stating:

If you can convince an algorithm that you are human, can you convince a human that you are human?
The captcha software is the algorithm, which is a visualized turing test. Once an automated program passes the turing test it is a matter of convincing other humans it is human. How would it do that? By using human identities data mined from the Internet.

On the 24th slide is a screenshot of an imaginary application called the "Virtual Identity Creator" that creates multiple identities within social networks, email, and blogging software complete with built in Captcha circumvention software. The data within the imaginary program would presumably be made up of thousands of harvested identities. The authors then go onto posit that you could do the following with such a network of "imaginary virtual friends":
  • manipulate ratings of anything
  • sway public opinion
  • influence political polls
  • alter stock prices - directly or indirectly
  • perform social denial of service
Presumably to perform such actions you'd need a virtual network similar in size to the storm and kraken botnets. Although, that particular slide finishes with this sentence:
Keep in mind that people are flock animals - you just need to be the initial catalyst and get critical mass.
Some thoughts on the briefing. Imitative social networks aren't dependent upon thousands of computers. They are like a web 2.0 version of botnets (this idea has also been alluded to before by pdp of the GNUCITIZEN blog). At the technical level an imitative social botnet only needs one computer because the nodes are virtual stolen identities. It is also problematic to call it a network as such from an outsider's viewpoint. A network is an interconnected system of people. They are interconnected within an imaginary "Virtual Identity Creator" program and within the intent of the social botnet controller. However, the output of the program is a swarm of unrelated nodes to an outside observer. The network controller could add another layer of deception to such a program by randomizing the identities he uses for any particular endeavour. For example, today the social botnet controller uses stolen identities 1005, 10001, 78980, et. al. to create buzz on trading message boards about a particular stock. Tomorrow the botnet will use stolen identities 967, 98764, 433, and so on, to perform a black public relations attack on a high profile blog.

I'd imagine if such a program were to exist in the future it'd be somewhat cumbersome at first. Stolen identities would eventually be found out. Other identities associated with the same message or goal as the stolen identities would be discovered to be stolen. I'd imagine a fix to this might be the creation of networks of nonexistent people i.e. fake names and personas but they are real insofar as they have other fake virtual friends on networking sites. Or alternatively an imitative network could attack real online personas with accusations that they are the false personas.

There would also be problems with automated message content that may not deceive real humans (similar to the original turing test). However, I could foresee a synthesis of technologies where identity mining software is also combined with text analysis or content analysis to data mine an online persona's idiosyncrasies within their writing. Neal Krawetz has already done some research in this area. If Krawetz's technology was tweaked in the right manner an imitative social network controller could create virtual versions of "The Talented Mr Ripley" by imitating the identity and the writing style of the identity.

I've been thinking more about counter-netwar scenarios through "tactics of nonexistence." I'll focus on one idea I had at the technological level. I need a technological tool that is somehow invisible to the network but will also exploit it. One such tool that I thought might fit the bill is a mobile phone. A mobile phone without a SIM card is an untrackable tool. It cannot, in most countries, make phone calls. Although, in a few western countries taking out the SIM card still allows the mobile to dial emergency. However, the phone does not have subscriber details. A SIM-less mobile phone is an anonymous tool that can jack into a specific network of control whilst remaining "nonexistent."

So how do you turn SIM-less mobile phones into exploits? Two ways:

(1) Multiple SIM-less mobile phones that dial continously acting as low tech electronic warfare jamming devices.
(2) Using the phones as a platform for voice-based rumor that exploits the target's preconceptions (I'll leave that up to your imaginations, but if you want specifics ask in the comments and I might discuss them).

Is it fully nonexistent? Well I could see two ways that you might track a person down.

One is direction finding (DF) to find its geographic location. However, this would be very hard to perform. A phone with an identity of some kind would pop up on the cell system after a DF. One without an identity would be hard to identify as an attacker. These SIM-less calls come in to emergency dispatchers with a high frequency. With nothing to identify the phone but its non-identity -- among countless other non-identities -- you are left with a fruitless endeavour.

Secondly, you could use voice recognition on the voice-based rumor calls. This is a more powerful option for gaining information on the nonexistent phone. I don't know much about the battle between voice recognition and voice concealment technology to answer this question specifically. One might say that if the voice concealment tech beats the voice recognition tech then the non-existent mobile caller has nothing to worry about. However, if the voice recognition guys win out then they are still in a bit of a conundrum. They have a voice, and other voices if there were more than one call. That is all they have for the moment without some high-powered, voice database that the voice recogniser can perform data mining with to search for corresponding voice patterns.

I think this idea has a number of cons. This technology targets highly specific networks that are mostly found within the western world. A SIM-less mobile phone would have no effect against a terrorist network or a transnational criminal network. Though, there might be scenarios where an anonymous mobile phone might be put into good use against them for example, imitative networks.

GNUCITIZEN has another brilliant post on the hacking of social networks (previously mentioned on this blog here with a real world example of cloned and imitative networks here). Quote:


"One important point that I would like to make regarding social networks, which is also one of the things which I believe will become a new phenomenon in the information security industry, is that I am more then certain that they will be the place where new types of information overlords or puppet masters even, will be born. Looking back in time, every information security expert, hacker and information junkie that has been long enough in this scene can easily see a few very basic patterns: spam works, so that drive-by-download, people are the weakest link not computers, and simple things work best.

The puppet masters will be the people with far too many identities for the average human to keep up with. The kind of people who have their fingers in every organization and have the invisible influence to guide the masses. Keep in mind that social networks are designed to aggregate people. But people who know how to make the most use of the technology will be overpowered. This is definitely something to keep and eye on as soon or later you will realize or hear in the news that someone has performed an important business operation based on data or connections pulled from social networks. This is the new type of spam, or botnet, or drive-by-download attack which unless security software is built around an AI, it will be able to prevent from or even detect."

Sunday, March 09, 2008

Imitating Smuggler Networks

Victor Bout was recently arrested. The interesting part was how they arrested him. The DEA website has the details on how they did it. Quote from the article:

"According to court documents, between November 2007 and February 2008, Bout and Smulian agreed to sell to the FARC millions of dollars worth of weapons including surface-to-air missile systems (SAMs) and armor piercing rocket launchers. During a series of recorded telephone calls and emails, Bout and Smulian agreed to sell the weapons to two confidential sources (CSs) working with the DEA, who held themselves out as FARC representatives acquiring these weapons for the FARC for use in Colombia.

In addition, during a series of consensually recorded meetings in Romania, Smulian advised the CSs, among other things, that Bout had 100 SAMs available immediately and could also provide helicopters and armor piercing rocket launchers."

The imitation and cloning of networks is a powerful way to shut down other illicit networks. The question I'd like to raise is ... are such endeavours better than trying to infiltrate a singular node into the network? Is there any literature on network-centric theories of intelligence gathering as opposed to war like arquillas works? From Pablo to Osama by Kenney is great, but concentrates more on organisational learning and adaptation. What I'm wondering is if there is literature on penetrating networks written in a social network vernacular or perspective.

Something I thought about a while back to get even with my evil neighbours was cloning their social networks (now ex-neighbours thanks to a protracted campaign, but that is another story). In the initial collection phase to map the "battlespace" I found that the majority of the members of their house had myspace profiles. I was going to duplicate their personal networks on another well known social networking site - Bebo - and try put them in conflict through provocation with members on that site that lived within the greater metropolitan area and had known aggressive criminal tendencies (offending information I collected open source through local court proceedings and local papers).

This little imitative communications deception endeavour never transpired because my ethically-minded plan of legal and other measures came through in the end (if anyone is interested Saul Alinksy's book "Rules for Radicals" was something I took solace in, and would recommend to anyone planning on any non-kinetic peaceful action).

The reason I bring up the above story is because there is a recent GNUCitizen blog post talking about "Social Network Evil Twin Attacks". It is quite similar to the plan I intended and something I reckon that'll end up becoming more frequent with identity theft, netwar and other concepts coming together. A good quote from the blog post:

"The hack here is not technical but rather psychological. Remember, hacking is the action of outsmarting the others and as such it may take any form. Fooling people’s believes is an important craft that have been with us since the dawn of humanity, yet we often fail to acknowledge it effectiveness. These are what Evil Twin attack are all about. From WiFi security prospective the evil twin is the rogue access point that pretends to be a friendly network. From the social networks point of view, the evil twin is a hacker or a bot masking himself as the real person."