Jart Armin posted recently regarding ‘Information Engagement’ or Espionage being a part of every nation’s security arsenal. I wonder about the amount of trust that we afford our own operators in this field?
All governments are suffering from, experimenting with, or regularly using this form of intelligence gathering. Information engagement experts provide the groundwork for informed military, information operations, and strategic communications decision-making and planning by creating and broadening situational awareness through the collection and analysis of cultural, social, political and economic data derived from an indigenous population and foreign media analytics.
The process itself can involve a range of activities, like interviewing on the ground, profiling individuals through social networks, monitoring email traffic, collecting web surfing information from ISPs and DNS providers, or utilizing web-based robots, spiders, botnets, and other data gathering tools. These intelligence gathering efforts help inform not only military planning, but the psychological operations, network defense, operational security and media development that make up the information operations/strategic communications disciplines.
Recent revelations about online spying from Ghostnet and Shadow network have led to news stories about researchers tracking operators from within China. There are other reports recently of similar networks and even disposable botnets being observed intermittently. There is a considerable lack of evidence to support the claims that the Chinese government or legitimate Chinese business is behind these networks.
Espionage is considered a violation of law in most countries. In the US, the National Clandestine Service is charged with balancing political correctness with covert espionage for the sake of national security, usually operating through seemingly legitimate, but expensive, contractors. There is no doubt that China is a commercial empire, is knowledgeable in electronic warfare, and a skilled political opponent. It would be foolish to assume that their clandestine operations and operators are inferior to those of North American or European forces, and that they would not also make use of contractors outside of their country to avoid finger-pointing. When the tracks in the snow stop at a particular house, do you assume that the occupant is the person responsible for the tracks, or that the person responsible stopped making tracks in the snow at this location?
The evolution and wide adoption of social media by the masses and the corporate world as well, has enabled the building of cheap online espionage infrastructures. These apparatus leverage sites such as Twitter, Facebook, LinkedIn, Blogspot, and Google Groups for building information collection and disinformation dissemination campaigns. These new malicious networks often fly under the radar of most technologies, enabling elusive attacks and escaping attribution to any particular single source.
Keystroke logging and forwarding, stored data theft, interception of transient data and voice communications, malware, and botnets are some of the tools for online espionage. This is making the job of telling the good guys from the bad guys much more difficult when conducting reconnaissance of online crime groups and malware research. Who are the spooks and who are the crooks?