GCHQ Fu||?Spectrum Cyber Effects Head of JTRIG SD Effects Lead SIGINT Development as an enabler for ?Effects? mission

Destroy Deny Degrade Disrupt Deceive Protect Computer Network Attack (CNA) Computer Network Information Operations (CNIO) Disruption

:ttects in (ccno - Definition: having an impact in the real world - Key deliverersz JTRIG and CNE - Now major part of business 5% of Operations - Across all target types - Continuous innovation of new tools and techniques

CNIO Computer Network Information Operations - Propaganda - Deception - Mass messaging - Pushing stories - Alias development facebookl - f|iCkr?

Disruption CNA - Masquerades - Spoofing - Denial of service Phones Emails Computers Faxes

lndiuidualfEnterprise Low Impact pyz. EFFECTS On-untry wide High impact WiFi DOS Internet Routing

Information Operations INFINITE CURVATUREIMOUNTAIN SLOPE Sending messages across the full spectrum of communications Telephony SMS FAX Email RADIUS Data 9 SALAMANCA TDIS Data Mining Open Phone Code Source Pre?x IP GEO

ROYAL CONCIERGE A SIGINT driven hotel reservation tip-off service From: To: ?Thank you for reserving .. ROYAL CONCIERGE exploits these messages and sends out daily alerts to working on governmental hard targets What hotel are they visiting? Is it SIGINT friendly? An enabler for effects can we influence the hotel choice? Can we cancel their visit? We can use this as an enabler for HUMINT and Close Access Technical Operations

Information Operations: The Social Web You facebooki Deliver messages and multimedia content across Web 2.0 Crafting messaging campaigns to go ?viral?

Twitter TDI Development Need SIGINT ctwerage across Not necessarily cnnsistent with target SIGDEV priurities 5N mVy?fWJ pb?l?evsm b3Jfc29s%25DAb1 wd 12 . Sewer

Twitter TDI Development Baset-34 double encoded URL 5555555

Twitter TDI Development PPF application across 106: Environment 1272671024 8 55488 80 Login? 31 TD|?Scope 4 User Route 13 81 .169.145.25 8 38 4848d4 User?Agent 52 Twitter Tools Geo?|P?Sro 28 Geo?|P?Dst 33 380082;- Event?security?|abe| 8 10007F Stream?seourity?|abeI 10 400023EOFF Wants Per day feeding BLACKHOLE

Twitter TDI Development 4* Given a country: Kawastan i Who are the top Twitter Users Jan - user- - Tm.? I Lil Are they really Kawestan? <3 SIGDEV augments the I0 process to aid targeting and takeup of message

Information Ops Spheres of Influence INFLUENCE

Hmi?rmat??n 50 new mobile being Developed by end of 2010 Also - Target Geog raphical Identifiers (TGI) We can shape CNIO against specific locations, users with a high degree of cognition

ulnerability Assessment Process Development Enabling ONO For intelligence production teams, based on Target Templating methodology . . Tame-I .5 3* we ter -::I-mug 1e- be -:.1oI1e Io 1he Target -it that frarrew:-rlt in to El problem The is. based -dn the understanding dl 6 or Hus all T?mylate IF. - 1r;- ll"-ej: global and the etin LIIJ utiuk?ee Ihe -n-I1-en Information Need. Hn en-.el ed ge Gap Hiri- JII. Hyrpot heeia I-art?. 1: Targtt at: E1 Lee: sort or Tr HI-rd II-ulfll fa.-I IFI Layer 2: Infrastructure - 1I1-e target to tliu H-I-U -ii. Layer 3: Teelinnlogy - 1I1a- teenitulngy the target Tar?el ll ll Layer -1: Lev:-lung for n1 . e? Layer 5: -Cepebi IitleIE. d5'5el.1 -do me have '3 Erraj?? In :1 Iii-an I 1-"mu "Er? - ll II 3 NADP trained network Wm i ac i 0 a

Human Systems Analysis Foreign News Agencies: - Credential Harvesting - Employee Analysis - who? - how?? - why?? Data in .. It New Data out 0 Dataout 3? Social not technological solution

Future? Formalising Tradecraft for ?What SIGDEV needs to be done prior to starting an Effects operation?? Joining up with 5 EYES where possible (cyber development) BGPI MPLS network effects (HOTWIRE) SIP and Effects Denial of Service, Operations Provide the defensive advice from the offensive perspective

Questions? V. Head of JTRIG SD Effects Lead NSTSI - Find me an TAPIOCA 9 nu. IJ rm-. names and phone numbers redacted

