Tools and Techniques for Cognitive Security
by SJ Terp & Roger Johnstone
CanSecWest, March 18th 2020
SJ Terp, Pablo Breuer, Grant Dobbe, grugq, Roger Johnston, CogSec Collab Community
Credibility Coalition - m!s!nfosec
- Industry
- Academia
- Media
- Community
- Infosec
Who uses this stuff anyway?
The Only defense against the world is a thorough knowledge of it.
-- John Locke
deliberate promotion... of false, misleading or mis-attributed information
focus on creation, propagation, consumption of misinformation online
We are especially interested in misinformation designed to change beliefs in a large number of people
Resources available in pursuit of national objectives...
Diplomatic, Informational, Military, Economic
...and how to influence other nation-states.
Resources available in pursuit of corporate objectives...
Business Deals & Strategic Partnerships, PR and Advertising, Mergers and Acquisitions, R&D and Capital Investments
AM!TT and other models of WTF is happening
Adversarial Misinformation and Influence Tactics and Techniques = (AM!TT)
IRA IN GHANA: DOUBLE DECEIT
Cultivate Ignorant Agents
Moving from admiring the problem to action
Countermeasures are that form of military science that, by the employment of devices and/or techniques, is designed to impair the operational effectives of enemy activity. Countermeasures can be active or passive and can be deployed preemptively or reactively.
-- JP 3-13.1, Information Operations - Joint Chiefs of Staff
| AM!TT Phase | Detect | Deny | Disrupt | Degrade | Deceive | Destroy | Deter |
| --------------------- | ------ | ---- | ------- | ------- | ------- | ------- | ----- |
| Strategic Planning | | | | | | | |
| Objective Planning | | | | | | | |
| Develop People | | | | | | | |
| Develop Networks | | | | | | | |
| Microtargeting | | | | | | | |
| Develop Content | | | | | | | |
| Channel Selection | | | | | | | |
| Pump Priming | | | | | | | |
| Exposure | | | | | | | |
| Go Physical | | | | | | | |
| Persistence | | | | | | | |
| Measure Effectiveness | | | | | | | |
"A disinformation campaign is made up of resources and infrastructure and operates over time, with them as a universal scarcity."
-- Grugq
| Critical Element | Detect | Deny | Disrupt | Degrade | Deceive | Destroy | Deter | |
|---|---|---|---|---|---|---|---|---|
| Resources | ||||||||
| Infrastructure | ||||||||
| Execution | ||||||||
| Time |
IRA IN GHANA: DOUBLE DECEIT
things we borrowed from infosec
| Misinformation STIX | Description | Level | Infosec STIX |
|---|---|---|---|
| Report | communication to other responders | Communication | Report |
| Campaign | Longer attacks (Russia's interference in the 2016 US elections is a "campaign") | Strategy | Campaign |
| Incident | Shorter-duration attacks, often part of a campaign | Strategy | Intrusion Set |
| Course of Action | Response | Strategy | Course of Action |
| Identity | Actor (individual, group, organisation etc): creator, responder, target, useful idiot etc. | Strategy | Identity |
| Threat actor | Incident creator | Strategy | Threat Actor |
| Attack pattern | Technique used in incident (see framework for examples) | TTP | Attack patter |
| Narrative | Malicious narrative (story, meme) | TTP | Malware |
| Tool | bot software, APIs, marketing tools | TTP | Tool |
| Observed Data | artefacts like messages, user accounts, etc | Artefact | Observed Data |
| Indicator | posting rates, follow rates, etc | Artefact | Indicator |
| Vulnerability | Cognitive biases, community structural weakness etc | Vulnerability | Vulnerability |
https://github.com/cogsec-collaborative/amitt_cti
https://www.cogsec-collab.org/project/amitt_navigator/
https://github.com/atc-project/atomic-threat-coverage
things we borrowed from data science
CogSec Collab
https://www.cogsec-collab.org
@VV_X_7