Thursday, June 20, 2013

Al-Shabab Live Tweets Attack

Less than a week after I posted about the debate as to whether or not to shut down terrorist groups' Twitter accounts, Somalia-based al-Qa'ida affiliate al-Shabab live tweeted their suicide attack on a UN compound in Mogadishu yesterday that killed eight people and wounded an unknown number of Somalis.

The tweets themselves range from the intriguing (albeit grossly inaccurate) live accounts of the attack, to the bizarre taunting of the UN representative, Nicholas Kay. But this incident suggests that the jihadist networks are still far ahead of the U.S. Government in terms of using social media for propaganda strategic communications purposes.

"Could Facial Recognition Technology Have Caught the Boston Bombers?"

In a word, no.

Although the wide array of surveillance photos in Copley Square played a role in apprehending Dzhokar and Tamerlan Tsarnaev, advanced technology was not the key to the manhunt, as a bombing victim identified the brothers from a series of photos, which were subsequently released to the public to provide tips (a.k.a. HUMINT) that led the investigators to the brothers.

As Sean Gallagher pointed out in an Ars Technica piece last month: “For people who understand how facial recognition works, this comes as no surprise. Despite advances in the technology, systems are only as good as the data they’re given to work with.” And despite what CSI or NCIS may have led us to believe, “Video from a gas station surveillance camera or a police CCTB camera on some lamppost cannot suddenly be turned into a high-resolution image of a suspect’s face that can then be thrown against a drivers’ license photo database to spit out an instant match.”

A more optimistic take on the topic comes from ForeignPolicy.com’s Joshua Keating, who while admitting that old fashioned detective work was the key to tracking the Tsarnaevs, “this is pretty new technology and . . . we may be getting closer to this kind of thing actually being useful.”

Keating’s optimism is based on a study by Michigan State computer scientists Joshua Klontz and Anil Jain testing whether existing facial recognition software could have identified the Tsarnaevs based on the security camera images taken just before the bombings by adding three headshots of the each brother to a database of more than a million mugshots. When the database was filtered to only look at Caucasian men in their 20s (for some reason, Tamerlan’s photo seemed to draw a lot of female matches . . . which is ironic given his history of domestic violence and fundamentalist beliefs about gender relations), the program produced one bull’s eye based on Dzhokar’s high school graduation photo.  
But this is a thin reed upon which to express hope that this technology will significantly alter the tactics of manhunts, whether domestic or strategic. First, Dzhokar’s school picture would not actually have been available to law enforcement, and the headshot from a driver’s license photo did not place higher than 19th in any of the searches. Conversely, although NeoFace 3.1 did produce one correct match, another young man’s mugshot not only produced a bull’s eye, but was also ranked the third closest match against the other two photos of Dzhokar. So the facial recognition technology did produce a good match, only it was of the wrong person. Finally, because Tamerlan was wearing sunglasses on April 15th, his own mugshot from his 2009 domestic violence arrest did not place higher than 116,342nd as a match.

In other words, no matter how well the technology is developed, simple countermeasures such as wearing sunglasses will likely impede its effectiveness.

Gallagher notes that under the best circumstances, facial recognition can be extremely accurate, but to do so "almost always requires some skilled guidance from humans." This calls to mind former Delta Force commander Pete Blaber’s admonition about relying on technology in manhunts: “The reality and complexity of life virtually guarantee there will never be” an all-purpose technological panacea for finding people. “Instead, these types of capabilities should be looked at as part of an overall system. A buffet of capabilities that could be used in combination with our guys working the situation on the ground to assist in the vexing challenge of locating a wanted man.”

Wednesday, June 19, 2013

Data Mining and Manhunts

This is not a post about how America is slowly descending into fascism, or about how Edward Snowden is a traitor who has made it easier for terrorists to murder U.S. citizens.* Although I think the debate over where to draw the line between civil liberties and national security is an important one and, given the necessary vagaries of the topic, one in which intelligent people can reasonably disagree, that is not my purpose here.

Instead, what fascinates me about the NSA’s PRISM program is the question of how it purportedly helps to locate and subsequently apprehend individuals deemed a threat to national security. As anybody who has read my book (or this blog, or this interview), I’m a bit of a skeptic when it comes to the role of technology in strategic manhunts. Although intelligence is the critical variable in such campaigns, I argue that history shows that most technologies can be defeated by countermeasures (i.e. stay off the phone; don’t go outside in the daytime and wave at the UAV overhead), and that human intelligence drawn from inside the target’s network or the local population are more critical to operational success.

That being said, as more histories of the targeted killing campaigns which decimated al-Qa’ida in Iraq and the Jaysh al-Mahdi from 2006-2008 in Iraq become available (i.e. Eric Schmitt and Thom Shanker’s Counterstrike and General Stanley McChrystal’s memoir), it is clear that the use of metadata compiled from “pocket liter” found on insurgents was a critical factor in hunting those networks' leadership and operatives. So given that I’m always aware (and hopeful) that there may be some facet of manhunting I’m not privy to, for the moment I’m more curious about the mechanics of how metadata in general, and PRISM’s datamining in particular, relates to the kinetic aspect of finding/fixing terrorists than I am about the privacy-versus-security debate.

Last week Sean Gallagher of Ars Technica wrote a piece discussing the history and technical aspects of how the NSA collects “big data. Be warned, this being Ars Technica, it gets really technical (i.e. how does one even begin to conceptualize petabytes, exabytes, and zettabytes worth of information?) Yet even if you are not a “ones and zeros” geek, Gallagher makes a crucial point at the outset, warning:
“One organization’s data centers hold the contents of much of the visible Internet – and much of it that isn’t visible just by clicking your way around. It has satellite imagery of much of the world, and ground-level photography of homes and businesses and government installations tied into a geospatial database that is cross-indexed to petabytes of information about individuals and organizations. And its analytics systems process the Web search requests, e-mail messages, and other electronic activities of hundreds of millions of people.”

Of course, Gallagher says, he is talking about Google.

A more practical explanation of how metadata is used in finding terrorists is provided by J.M. Berger's ForeignPolicy.com essay, "Evil in a Haystack",. Berger presents a hypothetical of a captured al-Qa’ida operative’s cellphone, which includes the number of a terrorist fundraiser in Yemen, and then takes us step-by-step as to how the terrorist fundraiser’s social network is recreated through metadata. In doing so, Berger sets out both the tactical and strategic challenges that come with uncovering 50,000 second-order contacts (i.e. Do you investigate the 79 numbers that called the original number, the 24 mathematically most important members of that set, or all 47,923 numbers that called the 79 numbers?) Similarly, he lays out the ethical gray areas associated with such searches. For example:
“How much contact can an analyst have with a U.S. person’s data before it becomes a troublesome violation of privacy? Is it a violation to load a phone record into a graph if the analyst never looks at it individually? Is it a violation to look at a number individually if you don’t associate a name? Is it a violation to associate a name if you never take any additional investigative steps?”

Berger rightfully concludes” “None of these questions is simple or easy. None of them lends itself to polling or punditry. They aren’t easy to discuss in a reasoned and accurate manner during a two-minute TV hit or on the floor of the House of Representatives.”

Also illuminating is Duke University Sociology Professor Kiernan Healy’s blog post, Using Metadata to Find Paul Revere,” which provides a more specific (if somewhat tongue-in-cheek) case study of how some relatively simple mathematics can shed light on a social network and illuminate who the key nodes in that network are if . . . you know, if you wanted to eliminate them. Healy allows that relying exclusively on data rather than the content/context of these connections may create “the prospect of discovering suggestive but ultimately incorrect or misleading patterns,” – similarly, Berger notes that targeting American militia groups might just inadvertently create a database of legal sellers. (Deputy Attorney General James Cole admitted as much in congressional testimony yesterday.)But whereas Healy simply states “this problem would surely be greatly ameliorated by more and better metadata,” Berger suggests that increasing the size of a dataset creates “ever-more challenging complexities.”

Thus, so far as strategic manhunts are concerned, the importance of metadata to manhunting appears to be its social network mapping function in determining which individuals to target or, alternatively, with whom a targeted individual may seek sanctuary. (A similar link analysis was crucial to capturing Saddam Hussein, although it was created as the result of interrogation and photo albums rather than through metadata). But it likely is merely one of several tools rather than the panacea "Big Data's" apostles claim.

After all, if PRISM were a cure-all for manhunts, then why wasn't the government able to track down Snowden himself when they hunted for him in the days before his leaks were reported?!?

Ironically, the one manhunt in which metadata appears not to have helped was the hunt for NSA leaker Edward Snowden . . .

* Okay, I can’t resist making three points on Snowden. Even if the privacy advocates are 100% correct about the dangers of PRISM – which I doubt they are – they should be careful about lionizing Snowden given that:

1- Many of his initial claims (i.e. “I could wiretap the President’s phone if I wanted") have proven to be false;

2- Although he claims his leak was motivated by idealism to protect Americans' civil liberties, his most recent revelations have been about spying on foreign leaders at the G-8 and G-20 summits? How exactly does such espionage pose a threat to the privacy of U.S. citizens?

3- I have a little trouble taking somebody seriously who wraps himself in a martyr’s cloak, saying “I’m prepared to face the consequences of my action,” and then flees to China (which surely he must know has far less regard for civil liberties than even the most paranoid conception of the United States).

And we won’t even go into the question of trusting the judgment of a man who leaves a pole-dancing girlfriend behind in Hawaii . . .


Tuesday, June 18, 2013

CNN: al-Nusra Front Now Best Equipped al-Qa'ida Affiliate

Presumably, this is why Abu Bakr al-Baghdadi is so eager to claim ownership of the al-Nusra Front for the Islamic State of Iraq, although sadly, even if left to its own resources, al-Qa'ida in Iraq doesn't seem to be lagging in the brutal, sectarian murder department.

"Tora Bora Reconsidered" in Joint Forces Quarterly

My article, "Tora Bora Reconsidered: Lessons from 125 Years of Strategic Manhunts" in the forthcoming (July 2013) issue of Joint Forces Quarterly has been posted online. (The journal itself comes out next week). As the abstract notes:
The allegation that Osama bin Laden was not apprehended in timely fashion because of insufficient troops deployed to Tora Bora is belied by the experience of a dozen strategic manhunts involving deployment of U.S. forces dating back to 1885-86. In fact, the need for surprise often means smaller forces are the ideal. Moreover, the human terrain is a bigger factor than the physical terrain. The views of the native population shape three variables that largely determine the success of strategic manhunts: human intelligence, help from indigenous forces, and whether the object of the hunt can find sanctuary by crossing a border. These factors were against U.S. forces in December 2001. The key would have been stronger links with Pashtun resources.
I actually submitted this back in November 2011, and assumed it had been rejected until the editors contacted me this February saying it had been accepted but was still under security review. What appears in JFQ is the redacted version, as DOD decided they couldn't release some details that Langley had already cleared for publication in Gary Berntsen and George Tenet's memoirs. Then again, if the AP is correct, apparently members of the Obama administration have had a problem keeping details of the hunt for bin Laden secret, at least when it came to Hollywood directors/writers. 


Monday, June 17, 2013

Today in Manhunting History: June 17, 1993 -- The Raid on Aideed's Compound

After the AC-130 attacks from June 12-14, Mogadishu was quiet on June 15 and 16. But at 1:30AM on June 17, AC-130s began striking weapons storage sites and knocking out selected roadblocks in southern Mogadishu. The PSYOPS teams’ speakers warned anyone around Aideed’s compound to drop their weapons, raise their arms, and walk to the main road. “Evacuate immediately, these buildings will be destroyed in 10 minutes . . . You have five minutes to evacuate immediately, immediately . . .” This announcement was followed by warning shots from a 40mm cannon. Approximately 30-40 people left Aideed’s compound before 105mm guns fired at targets in the area of the warlord’s house.

Aideed was finally being directly targeted.

At 4AM hundreds of Pakistani, Moroccan, Italian, and French troops lined up for the ground assault, supported by U.S. liaison officers and American attack helicopters. A tight cordon was in place by 5:45AM, and two Pakistani infantry battalions kicked in the gates and assaulted the housing complexes of Aideed, Ato, and Jess. The international forces conducted a house-to-house search of Aideed’s compound. Although reporters later found the pink earplugs he used to block the previous nights’ PSYOPS’ broadcasts, the warlord had slipped away. Local legend had Aideed escaping under the UN troops’ noses on a donkey cart, wrapped up in a sheet like a corpse.

As the Pakistanis cleared the objective, however, the Moroccans began to take fire on the outer perimeter, engaging in a four hour firefight complicated by the Somali use of women and children to shield the militiamen. Just before 10:30AM, a recoilless rifle shell disabled the Moroccan command vehicle and killed the regimental commander. It took until 6:30PM to finish clearing all the shattered target buildings. In the end, the operation only managed to damage Aideed’s house at the cost of five UN troops killed and 46 wounded, and at least 100 Somalis killed.

One senior Clinton administration official who participated in the President’s decision to mount the attacks acknowledged “We didn’t plan to kill him, but the president knew that if something fell on Aideed and killed him, no tears would be shed.” Failing to achieve this, the Administration chose to portray the operations as a success nevertheless. Jonathan Howe proclaimed a “tremendous victory,” and President Clinton declared: “The military back of Aideed has been broken.”
Muhammad Farah Aideed was directly targeted by U.S. forces more than three months before Task Force Ranger's famous operation depicted in "Black Hawk Down"

Sunday, June 16, 2013

Happy Anniversary (Okay, Not Really) Ayman al-Zawahiri!

Two years ago today Ayman al-Zawahiri was formally named Osama bin Laden's successor as leader of al-Qa'ida, and hence became arguably the number one target of U.S. forces in the War on Terror.

How is the not-so-good doctor (Zawahiri was a physician prior to taking up jihad full-time) fairing?

According to CNN's Peter Bergen, Zawahiri's May 23 memo to the leaders of the Iraqi and Syrian wings of al-Qa’ida, in which he ordered the merger of the two branches to be dissolved, “demonstrates Zawahiri considers himself and the al Qa’ida core to be still relevant and very much in charge of the global jihadist movement.

At the end of the article, Bergen hedges a bit, noting: “It isn’t clear to what extent al-Qa’ida’s affiliates in Syria and Iraq will actually pay attention to the directives from Zawahiri.” This is prescient of Bergen, as yesterday the Associated Press reported: AL QAEDA’S LEADER IN IRAQ DEFIES BOSS OVER SYRIA FIGHT. AP quotes Abu Bakr al-Baghdadi as saying: “The Islamic State in Iraq and the Levant will continue. We will not compromise and we will not give up.”

In other words, although al-Qa’ida core still exists and still believes it is operationally relevant, without the unifying figure of bin Laden it is having a difficult time combating the centrifugal pressures that is leading to splits such as the one in Iraq/Syria, and Mokhtar Belmokhtar’s split from AQIM.

As I've noted before, it is unclear whether such a fragmentation would make the various splinter groups more dangerous from an operational standpoint, or less threatening from a strategic standpoint due to the inability to coordinate operations.


Sorry, Ayman, no one said being in charge was easy.