Torn flags: Reconsidering models of adversary denial and deception tradecraft in current and future offensive cyber operations

No ratings

Presented at BSidesNova 2019 by

Analytic conception of "false flag" tactics, techniques and procedures (TTP) employed as part of sustained intrusion campaigns has primarily been presented in narrowly technical and tactical terms within the cyber threat intelligence community of practice. This discussion to date has been atheoretic, divorced from the wider professionalized understanding of denial & deception (D&D) doctrine and praxis that has developed over decades of intelligence community experience against hard target problems. As a result, analysis based on the dominant conception is often implicitly flawed by unacknowledged cognitive defects and other sources of error. It is necessary to challenge this conception and to reconsider the hitherto unexamined assumptions of "false flag" operations in order to improve analysis, targeting, and collection against intrusion sets which have sought to complicate attribution, or to introduce deliberate misattribution narratives through deception measures.This talk will present a target-centric model of hostile D&D activity considered as operational art within the context of adversary capabilities generation and deployment, campaign sustainment, disruptive and destructive effects delivery, and intrusion termination. We will examine the role of the operations planner in offensive activities, and the influences of foreign military and intelligence traditions on this function. Case examples will be explored in order to assess preliminary model validation, and to estimate future developments in adversary tradecraft. These future adaptions are expected to present new challenges of particular importance for analysts and defenders in the near to mid-term, as increasing operational pressures on adversary operators may be anticipated following the declared intention of the US government to shift towards "defending forward" through the employment of deliberate counter-cyber operations to deny and degrade hostile capabilities options.