Showing posts with label Military Intelligence. Show all posts
Showing posts with label Military Intelligence. Show all posts

Friday, January 17, 2025

Starburst Analysis and Information Sources for the Battle of COP Keating

Introduction

This essay attempts to come to an understanding of the major actions, participants, methods, and motives in the 3 October 2009 Battle of COP Keating in eastern Afghanistan. A starburst analysis will be done to achieve this. Further, some of the various information sources/perspectives will be examined to see what they can contribute to an understanding this battle.


Starburst Analysis

Who - The primary actors in the Battle of COP Keating were US and ANA forces versus Taliban insurgents, called AAF in the video. There were approximately 300 Taliban fighters involved. The US and ANA had 73 troops positioned at COP Keating plus 29 troops stationed at OP Fritsche. As the battle progressed, a QRF from FOB Bostic and air support joined the US and ANA side.

What - The key activity was the battle between the US and ANA forces against the Taliban fighters. Planning and observation were performed by Taliban leaders prior to the attack.

When - The battle took place on 3 October 2009, but planning began months prior. The attack was timed to correspond to scheduled closing of COP Keating and OP Fritsche.

Where - COP Keating and OP Fritsche were located near the town of Kamdesh in eastern Afghanistan (which led to another name for the battle, the Battle of Kamdesh). COP Keating was in mountainous terrain, at the bottom of a valley. Two sides of the camp were bounded by the Darreh ye Kushtoz River. The surrounding mountains were unsecured except for the one capped by OP Fritsche. COP Keating and OP Fritsche were not in direct line of sight. These mountains, along with a nearby mosque, would serve as Taliban fire locations.

Why - COP Keating was established in July 2006, positioned to disrupt insurgent supply lines from Pakistan. By dislocating the COP, the flow of weapons and fighters would resume.

How - The Battle of COP Keating was a two-pronged attack, one against COP Keating (the primary target), the other against OP Fritsche. Both targets were engaged simultaneously to prevent one from assisting the other. The nearest air support came from FOB Bostick, 10 minutes away by helicopter.


Information Sources

It is necessary to evaluate information that was available prior to the Battle of COP Keating as well as information generated after the battle occurred. One would expect various after-action reports of the Battle, but they have been repressed, and many details did not become known until the release of WikiLeaks’ Afghan War Diaries. Apparently, there were multiple intelligence failures. Building on (Gertz. 2009), Hershel Smith writes (Smith, 2009):

…defense intelligence had three reports of imminent danger but failed to act on this intelligence. What “smoking gun report” would have convinced them to take action we aren’t told…
Smith goes on to hint that a “smoking gun report” may have been in possession of the CIA.

Population studies (the human domain perspective) of the people living near COP Keating would be useful for determining local attitudes and for building a social network of the people. Adversary media, be it in the form of literature, internet posts, etc., would also help in creating a social network. This social network can then be infiltrated to gather information. The social network can then be analyzed to determine the major Taliban influencers who will then become the major targets for US forces. (Healy. 2013)

Another critical information stream would be a scholarly perspective. Thaler, et. al. (2013, p. 12) sites several academic papers (many published prior to the battle) stating that Afghanistan has a culture of independence and resistance. This is an extremely specific characterization and probably wouldn’t hold for all Afghani. If it applies to the people living near COP Keating, this will determine how Afghani would relate to or tolerate foreign presence, if at all.

Finally, the security practitioners’ perspective would provide a wealth information, not only about the Battle itself but about the conditions that existed prior to it as well as to make predictions about future engagements.

Both the COP and OP were targeted by 45 attacks between May 2009 and October 2009. One question that security practitioners could answer is this: did the insurgency forces display improvement in their operational ability during that time, and if so, in what areas?

An insurgency does not spring fully-formed from the forehead of Saint Mattis of the Blessed Order of the Knife Hands. It must have meager beginnings and, unless extinguished, will improve by becoming confident, learning new 4GW techniques, making use of changing logistics opportunities, etc. Once the baseline and trajectory are established, the insurgency’s future operations can be predicted.


Conclusion

The starburst analysis technique, combined with various information perspectives, helps us come to an understanding of the Battle of COP Keating. Until a comprehensive AAR, similar to the one performed for the similar Battle at Wanar (Staff of the U.S. Army Combat Studies Institute, 2010) becomes available, there will always be questions.


References

ABC News. (5 February 2010). “Camp Keating officers disciplined for attack that killed 8 U. S. troops.” Retrieved 17 January 2025 from https://abcnews.go.com/WN/Afghanistan/camp-keating-commanders-disciplined-attack-killed-22-us/story?id=9761160

Gertz, B. (29 October 2009). “DIA on Afghan intel” Washington Times. Retrieved 17 January 2025 from https://www.washingtontimes.com/news/2009/oct/29/inside-the-ring-58944275/

Healy, K. (2013). Using metadada to find Paul Revere. Retrieved 17 January 2025 from: https://kieranhealy.org/blog/archives/2013/06/09/using-metadata-to-find-paul-revere/

Smith, H. (2 November 2009). “Systematic defense intelligence failures”. Retrieved 17 January 2025 from https://www.captainsjournal.com/2009/11/02/systemic-defense-intelligence-failures/

Staff of the U.S. Army Combat Studies Institute. (2010). “Wanat: Combat action in Afghanistan, 2008”. Combat Studies Institute Press. Retrieved 17 January 2025 from https://www.armyupress.army.mil/Portals/7/combat-studies-institute/csi-books/Wanat.pdf

Steeb, Matsumura, Herbert, Gordon IV, & Horn. (2011). “Perspectives on the Battle of Wanat”. Rand Corporation. Retrieved 17 January 2025 from https://www.rand.org/content/dam/rand/pubs/occasional_papers/2011/RAND_OP329z1.pdf

Thaler, Brown, Gonzalez, Mobley, & Roshan. (2013). “Improving the U.S. Military’s understanding of unstable environments vulnerable to violent extremist groups”. RAND Corporation. Retrieved 17 January 2025 from https://www.rand.org/pubs/research_reports/RR298.html

TRADOC G2 OE Enterprise G&V. (10 August 2012). “The battle of COP Keating - October 3rd, 2009”. Retrieved 17 January 2025 from https://www.youtube.com/watch?v=ylUzySZb3L8

WikiLeaks War Diary. Retrieved 17 January 2025 from https://wardiaries.wikileaks.org/search/?q=cop+keating∓sort=date∓release=Afghanistan∓date__gte=2009-10-03∓date__lte=2009-10-09

Saturday, August 3, 2024

Analyzing the Russo-Georgian War of 2008

Introduction

The Russo-Georgian War of 2008 has the dubious honor of being the first instance where a kinetic attack (land-sea-air) was combined with cyber warfare. This paper starts with a recounting of the war, then describes two approaches to intelligence analysis: a purely academic approach, and a fact-based IT security approach. The intelligence generated by those approaches are then compared.

Map by Andrein at English Wikipedia – 26 August 2008

Background

Russia, along with South Ossetia and the Republic of Abkhazia, invaded parts of Georgia1 starting on 1 August 2008. When the war "officially" ended on 16 August, the results included the loss of Georgian territory, displacement of Georgians from South Ossetia, the collapse of diplomatic relations, the establishment of Russian military bases in the captured territories, etc.

For purposes of this paper, the important part of the war was the fact that it involved a cyber attack coordinated with the kinetic attack. This was the first war where there was such coordination.

Based upon an after-action review performed by the Georgia Minister of Foreign Affairs2, cyber attacks began on 20 July 2008, continued throughout the kinetic component of the war, and the last cyberattack occurred on 27 August. The following sites were targeted:

  • Georgian Parliament
  • Georgian Supreme Court
  • Ministry of Foreign Affairs
  • Central Election Commission
  • President Mikheil Saakashvili's official website
  • US and UK Embassies in Tbilisi
  • Various news agencies

The methods of attach included information exfiltration, website defacement, and distributed denial of service (DDoS) attacks.

The Georgian response was to create temporary websites on the Google Blogger platform and in general to move them to US servers, knowing that US servers would be difficult for the hackers to target. In addition, the President of Poland, Lech Kaczynski, offered to host Georgian websites.


Academic Analysis

In a 2010 paper3 published in the Small Wars Journal entitled "Cyberwar Case Study: Georgia 2008", David Hollis analyzes the cyber aspect of the Russo-Georgian War. He does this from a very academic standpoint, though, and as a result he is unable to answer crucial questions about the cyber attack. For example, he is unable to correctly identify the perpetrators!

Hollis attributes the cyber attack to hypothetical "cyber militias" or "hacker militias." He proposes these cyber militias exist, but he fails to not only answer but even raise some very fundamental questions about these militias, such as:

  • What is this militia's name?
  • How many people are in it?
  • How long have they been operational?
  • What is their physical location?
  • Who coordinated the cyber and kinetic components?

Hollis makes the leap to "cyber militia" with no real evidence! From the perspective of philosophy, he's making an unwarranted ontological claim.

At first glance, this doesn't seem to be a major problem: Hollis is just calling hacker groups or cyber criminal organizations by a different name: "cyber militias." The issue is that "cyber militia" is a loaded term, which slants the information analysts' perspective, and forces him to go down the wrong rabbit holes. Terms such as "hacker militia" and "cyber militia" are prejudicial language for two reasons. First, militias have a very specific nature, most importantly their command-and-control structure (this will be expanded upon shortly). Second, there is a potential ambiguity - cyber militias are an active topic in cyberwarfare research – does Hollis mean the same thing?

Hollis is cognizant of the first item, and from this he derives some unusual "lessons learned."


Operational and Intelligence Lessons Learned

From a security analyst's perspective, Hollis committed the error of focusing on one type of information (academic research) to the exclusion of other sources of information. It is worth reviewing the lessons Hollis derived from this approach because they're facinating unto themselves, and it makes for a sharper contrast with the results learned from IT security experts.

Hollis derives four "lessons learned."

Lesson 1: Engage Cyber Militias First

The first lesson is that cyber militias must be engaged. This lesson is both extremely common-sensical as well as radically unusual, for Hollis is stating that a country must make use of ALL the resources available to it, and to do otherwise is to leave "money on the table."

Like all things, militias have a specific nature, and to use militias is to use them according to that nature. Or, like Francis Bacon said, "nature, to be commanded, must be obeyed."

To engage a cyber militia for an operation, they must be SOLD on the concept. One of the characteristics of militias is their unusual style of command-and-control: they operate on persuasion instead of on orders. Another way of looking at this is that a military leader would find commanding a militia to be akin to "herding cats." This shows that Hollis is indeed somewhat aware of the "militia mindset."

Since members of a hacker militia would frequently be self-taught, they have their own ideas on how to proceed, so there must be discussions of tactics, techniques, and procedures (TTPs). They must be steered to desired targets ("centers of gravity"), and their actions should be coordinated with traditional operations.

In a cyber conflict, both sides will have their own hacker militias, and the defender's hackers can take steps to track and monitor the opposing county's cyber forces. This includes examining server and internet traffic logs for signs of probing operations. Of course, chat rooms and other forms of comms must be monitored.

Lesson 2: Target Choices

As Hollis described, Russia's hacker militias performed preparatory tasks such as identifying enemy assets, performing reconnaissance activities, as well as probing operations. These probing activities must be practiced "low and slow" – in other words below the enemy's threshold of concern. Hollis is caucious that hacker militias are "eager beavers," which will put their level of activity above the enemy's threshold of concern.

The defender's hacker militias must conduct their own recon operations in collaboration with their intel community. And of course, they must identify, monitor, and protect their valuable assets (key terrain).

Lesson 3: Geographic Targeting

Once their hacker militias were operational, Russia employed them to create a communications blackout of the areas of Georgia that will soon be attacked in real life (IRL). The desired consequences of this blackout are: federal and local govts were unable to contact those under attack; it generated panic; and it created doubts about the competence of the federal government of Georgia.

Notice that this technique of geographic targeting allows for feints and ruses.

For the defender, cyber targeting indicates the location of an upcoming ground or air assault. Again, this could be a feint or ruse!

Lesson 4: Possibility of Hacker vs Hacker Attacks

Since both attacker and defender (supposedly) have hacker militias, these militias will attack each other. The defender's militia will become an early target by aggressor to prevent retaliation. So, the government should monitor their internal hacker community.

This has application to other nations: neutral nations should monitor their own internal hacker community to prevent being pulled into the conflict.

Training Proposal

Hollis' paper concludes with one recommendation: that to best train cyber militias, cyberspace "ranges" should be developed and used for force-on-force activities. These must be air-gapped (computers not connected to each other, either wired or wireless), but somehow integrate with physical domain so as to investigate various attack/defend scenarios.


Concluding Remarks on Hollis' Analysis

Without proof of Russian cyber militias' existence, his lessons learned, and his training proposal, are really ideas for how a hypothetical militia should operate and train.

Notice the lack of actionable information relevant to the Russo-Georgian War: by taking a purely academic approach, Hollis is not able to identify the culprit of the cyber attacks against Georgia, and is unable to propose concrete methods to combat cyber militias above and beyond: get your own militia!


Factual Research by IT Security Analysts

We'll now look at the approach used by IT security firms to analyze the cyber component of the Russo-Georgian War. There are many, many IT security analysts in operation, and their research is frequently put behind pay walls – they are for-profit organizations after all! We'll look at the analysis of one of these security companies: Packet Clearing House. Their analysis4 was published in ACM Queue.

Packet Clearing House (PCH) is a well respected business and has been in operation since 1994, and have built major parts of internet infrastructure. They also have experience in state-on-state cyber attacks: they detected and analyzed a similar "cyber skirmish" in Estonia in 2007. Like all good IT security firms, their investigative approach is fact-based: they derived information from server logs and attack methods.

Before looking at the details of Packet Clearing House's analysis, the attack methods used gives information about the perpetrators' abilities.

Data exfiltration is not described in detail in any of the references used, but data scraping implies a fair level of programming ability, whereas system penetration implies a hacking background.

Website defacement definately involved a hacking component in order to break into server a server. The amount of defacement determines the level of programming ability by the perpetrator.

This is somewhat useful information, since the skill levels of the perpetrator limits the list of suspects.

The Culprit

The REAL information comes from the DDoS (distributed denial of service) attacks. As background, DDoS uses botnets, which are collection of internet-connected computers. Each computer is infected with a virus. Said virus repeatedly sends requests to a targeted computer, and these requests overwhelm the targeted computer.

Based on the IP addresses of the bots in the botnets, PCH determined that the botnets were located in Russia, China, and United States, and the server that directed the botnet attack was located in the US.

The IP addresses were the smoking gun – they allowed security researchers to identify the culprit: the IP addresses of computers in the botnet match those used by the Russian Business Network (RBN). RBN is based in St. Petersburg and may be state-sponsored. They started as an internet service provider, then moved into website hosting, and have hosted CP, spam, mafia sites, and malware. They have built botnets and rents them for $600/month. At one point in time, they were linked to 60% of all Russian cybercrime.

PCH's Recommendations

Based on the their investigation, PCH made several concrete recommendations:

  • Foster a robust physical infrastructure
  • Diversify the number of international connections
  • Create one of more internet exchange points (IXPs) within Georgia - IXPs permit internet connections between points within country, and no IXPs means that local connections must go outside country
  • Ensure domestic availability of domain name servers (DNS) - without DNS, websites cannot be reached using the website's name
  • Work with computer emergency response teams (CERTs) to coordinate defense against cyber attacks.

Georgia followed at least one of PCH's recommendations - they now have 3 IXPs


Comparison of Results

Using only an academic research approach, the culprit is something unknown (at the time): cyber militias. The actions were symptoms without known causes, and particular actors were not identified. Finally, only general remedial actions were recommended.

In contrast, by using all available information, PCH determined that the culprit is a known actor type: cybercrime organization. By tracing this organization's actions back to an actor, PCH was able to specify that actor: RBN. Finally, PCH was able to recommend extremely specific remedial actions.

Weaknesses of Georgia's network infrastructure were identified by PCH:

  • No domestic internet exchange points
  • No domestic domain name servers
  • Some reliance on servers located outside Georgia (Turkey and Russia in particular)
  • Overall result was to leave Georgia open to cyber attack

Finally, the strengths of Russian hackers were inferred by PCH:

  • Russian Business Network are talented hackers with years of experience
  • They exploited weaknesses in Georgian internet infrastructure
  • RBN began probing attacks prior to launching the DDoS attacks
  • Russians coordinated RBN attacks with military action
  • RBN continued internet attacks after kinetic component began


Conclusion

David Hollis' analysis of the Russo-Georgian War is extremely academic: it proposed the existence of hypothertical "cyber militias" on both sides of the conflict; it was unable to identify the actual perpetrators; and it provided no concrete remediation plans.

Meanwhile, the PCH used available data (both server logs as well as the histories of known Russian hacker groups) and were able to derive useful information: they identified the specific Russian cyber crime organization responsible for the attack; the devised a concrete plan to solidify Georgia's cyber defenses; and the Georgian government followed some of those recommendations.

The difference can be summarized as follows: what Hollis did not know, he invented. What the PCH did not know, they researched.

This is not to say that the academic approach has no value: Hollis' "cyber militia" concept my have future uses – for example, a research paper5 was published in 2023 supporting the idea that Ukraine should get its own cyber militia.


Footnotes

  1. Details on the kinetic aspects of the war can be found in Kofman, "Russian Performance in the Russo-Georgisn War Revisited."
  2. Georgia Minister of Foreign Affairs, Russian Cyberwar on Georgia.
  3. Hollis, "Cyberwar Case Study: Georgia 2008."
  4. Stapleton-Gray & Woodcock, "National Internet Defense – Small States on the Skirmish Line."
  5. Svantesson, "Regulating a “Cyber Militia” – Some Lessons from Ukraine, and Thoughts about the Future."

Bibliography

Georgia Minister of Foreign Affairs. Russian Cyberwar on Georgia. 10 November 2008. Retrieved 26 July 2024 from https://web.archive.org/web/20111117042929/http://www.mfa.gov.ge/files/556_10535_798405_Annex87_CyberAttacks.pdf

Hollis, D. "Cyberwar Case Study: Georgia 2008." Small Wars Journal, 2010. Retrieved 18 July 2024 from https://smallwarsjournal.com/blog/journal/docs-temp/639-hollis.pdf

Kofman, M. "Russian Performance in the Russo-Georgisn War Revisited." War on the Rocks, 4 September 2018. Retrieved 3 August 2024 from https://warontherocks.com/2018/09/russian-performance-in-the-russo-georgian-war-revisited/

Stapleton-Gray, R. & Woodcock, B. "National Internet Defense – Small States on the Skirmish Line." ACM Queue 9 (Issue 1), 19 January 2011. https://doi.org/10.1145/1922539.1929325

Svantesson, D. "Regulating a “Cyber Militia” – Some Lessons from Ukraine, and Thoughts about the Future." Scandinavian Journal of Military Studies 6 (No. 1) 11 July 2023. Retrieved 25 July 2024 from https://sjms.nu/articles/10.31374/sjms.195

Sunday, July 14, 2024

Defense of Jisr al-Doreaa: Decomposition of Data Analysis

Introduction

The Defense of Jisr al-Doreaa[1] was a 2009 novella authored by Michael L. Burgoyne and Albert "Jim" Marckwardt explaining one way to conduct successful counterinsurgency (COIN) operations in Iraq. Its narrative style was based on Ernest Swinton’s The Defense of Duffer’s Drift[2]: in both, the protagonist repeats the same scenario repeatedly, each time learning from the last. Through each evolution, the protagonist learns from his (sometimes) deadly mistakes, and by the end he succeeds in his mission.

The Defense of Jisr al-Doreaa was later converted into six computer animated videos by TRADOC. The goal of this paper is to perform a decomposition of data analysis of the events in the fifth video[3] of that series. The major actors will be described, as well as the actions they take. Then, the targets, objectives, and effects (results or consequences) will be analyzed. The implications of these actions for intelligence analysis are described. Finally, the lessons the protagonist learned in this evolution will be described.

Note: in an earlier post[4], the COIN operarions at al-Doreaa was examined using RAFT (Relationships, Actors, Functions, and Tensions) Analysis.

Actors and Initial Actions

2LT Phil Connors

The main actor is 2LT Phil Connors. He establishes a combat outpost (COP) in the Iraqi town called al-Doreaa with the goal of providing a base of operations for his men as well as providing security and other aid to the town. He obtains humanitarian aid (HA) packages for the townsfolk. He is aware of local customs and follows them, including greeting rituals, eating with the right hand, and not objecting to women wearing burkas.

Mayor Hussein

The town’s mayor, Mayor Hussein, describes the condition of al-Doreaa to 2LT Connors. He has three children: two daughters and one son. He tells Connors about his town's needs which includes medical services, stable electricity, and clean water. He is of the opinion that America’s promises have exceeded the results.

Mohammed the Interpreter

Mohammed, Connors’ interpreter, works with the American forces and interacts with the townsfolk. This puts him in potential danger, so Connors reviews steps he must take to maintain his safety.

Bill White from USAID

Bill White, who works for the USAID, travels with his team to the town to work on the water system. His team carries only rifles. He meets with Connors, but Connors did not know that USAID would be there. Connors believes the USAID team's defensives are insufficient for the town.

Insurgent Groups

There are insurgent groups in the area. For reasons explained below, they will be called Insurgents #1, #2, and #3.

Actions

During the initial meeting with Mayor Hussein, Connors provides some personal info about his life to build rapport. The mayor tells him of some of the town’s problems (no water, intermittent electricity, and no medical clinic). He also lets Connors know about his son’s health. Connors has a medic treat his son, stating that frequent follow-up care will be needed.

On the way back to the COP, Conners meets with Bill White and his USAID team. Connors asks if he has security. He says he has rifles but asks if Connors can provide security while he works on the town’s water system. Throwing shade (Connors thinks of them as “yahoos” and “cowboys or morons”), Connors says he cannot provide security, even though Mayor Hussein expressed the need for water. White protests, stating that he won’t be able to return for another month. Connors again refuses to provide security, and White and the rest of the USAID team drives off.

At the base, Connors believes that the meeting with the mayor went well, and one of his troops stated that the HA packages were popular with the townsfolk, who reciprocated with a little info on the insurgents. Mohammed alerts Connors to the mayor: if the mayor really is in charge, he can’t be trusted since he knows local insurgents. One of Connors’ soldiers, Specialist Wilson, reports that the south side of town is dangerous at night. He says this while sweeping the Americans and Muhammed with his rifle.

At this point, the COP comes under mortar attack from Insurgents #1. They request rotary wing support, and one of Connors’ soldiers is killed. Realizing that if his troops struck out blindly at the population, that would get the townsfolk to side with the insurgents. Connors meets with his sergeants and encourages them to act with restraint.

Connors pays a visit to the mayor the next morning. The mayor heard about the attack but didn’t know of the fatality. Connors asks if he knew who committed the attack. The mayor doesn’t know, but he states that some unemployed young men in town can be persuaded by outsiders. The mayor also provides info about the outsiders’ approximate location (house with a blue gate). He will not help Connors find the exact location because it will put him in danger.

On the way back to the COP, Connors confirms what the mayor says, but cannot narrow down the exact location, as there are three houses with blue gates. At the COP, Connors combines info from his other soldiers to determine the exact house from which Insurgents #2 operates.

Connors establishes an observation post (OP) close to that house to monitor activity. The OP reports five males are transferring items out of a car but cannot confirm that they are weapons. Connors and team raid the house. They kill at least two of the insurgents and capture at least two others. They also capture a weapons cache that includes a mortar.

For several weeks after the raid, no further attacks occurred. Connors arranged for a medical team to work at the town, and he provided the town with cases of bottled water. He also had weekly dinner with Mayor Hussein to plan future improvements.

Because there were no other attacks in al-Doreaa, Conners’ team was repositioned north. He met with the mayor to let him know they were leaving. Connors thought everything would be OK – he believed the insurgency had come to an end in that area.

Several days later, Connors saw a news report stating that al-Doreaa was seized by Insurgents #3. He didn’t believe this happened – the town had been free of insurgents when he departed. Insurgents #3 posted a video online showing them executing several individuals, including the mayor and (maybe) Mohammed the interpreter.

Connors thus arrives at the following lessons:

  1. Counterinsurgency requires unity of effort between the military, NGOs, the host nation, and other elements of national power.
  2. Established informants must be protected after Coalition forces leave.
  3. Operations must be transferred to local security forces and local government officials.

Finis.

Targets, Objectives, and Effects (Consequences) of the Acts

In dismissing the USAID personnel, Conners prevented the town from receiving reliable clean water for at least a month. He did this even though the mayor explicitly stated that this was something the town needed. Supplying the town with cases of bottled water was thus only a stop-gap measure. This also reinforces the mayor’s opinion that American forces were promising more than they were delivering.

By reminding his men not to take broad action in response to his man’s death, Connors avoided creating animosity with the townsfolk. This goodwill allowed him to pinpoint the location of Insurgents #2, and to capture or kill them and their weapons cache, rendering Insurgents #2 inoperative. Since several insurgents were captured alive, this would be an intelligence source that can be used. Finally, it alerted other insurgents that the town was secure, and that they should delay their actions until the Americans leave.

Insurgents #3 captured the town and executed several people including Mayor Hussein and (maybe) Mohammed the Interpreter. This instilled fear into the rest of the town – the lesson being that cooperation with Americans would lead to death. Insurgents #3 also posted video of these executions online. The effects of this were to instill fear in American sympathizers throughout Iraq, to act as a morale booster for other insurgents, and to recruit new insurgents from across the globe. Finally, it led to the demoralization of one 2LT Phil Connors.

Intelligence Implications

The insurgents appeared three times in this story: first, when the COP came under attack; second, when insurgents occupied a house and used it as a weapons cache; third, when the insurgents reentered the town and executed townsfolk who acted as informants or cooperated with the Americans.

It cannot be assumed that these were all the same insurgents. The mayor explicitly stated that outsiders were recruiting locals to work for them. Further, the weapons house insurgents (Insurgents #2) cannot be the same as the ones who executed townsfolk (Insurgents #3), since they were either captured or killed in the raid. Finally, the insurgents who attacked the COP (Insurgents #1) may or may not be the same as the ones captured at the weapons house (Insurgents #2). A mortar was found at the house, along with several shells, so they may have been the same. Only information gathered from the captured insurgents as well as forensic examination of the weapons can determine if the weapons house insurgents (Insurgents #2) were the same ones who attacked the COP (Insurgents #1).

Conclusion

The fifth evolution of The Defense of Jisr al-Doreaa demonstrated the need for cooperation between the military, NGOs, and local government to successfully fight insurgents – and that one reason for a lack of cooperation is inter-agency rivalry. It also showed that when American forces leave an area, control must be transferred to local security and local government. In this fictitious example, local security apparently didn’t exist, and the mayor was truly not in charge, as demonstrated by his fear of helping the Americans. Thus, if local security or competent government don’t exist, they must be established before Americans leave the area. If not, then not only are the locals who work for Americans in danger, but also any progress the Americans make will be destroyed.


Footnotes

[1] Burgoyne & Marckwardt, The Defense of Jisr al-Doreaa.
[2] Swinton, The Defense of Duffer’s Drift.
[3] TRADOC, “The Defense of Jisr Al Doreaa – Dream 5.”
[4] Klepper, “Jasr Al Doreaa: RAFT Analysis.”


Bibliography

Burgoyne, M. & Marckwardt, A. The Defense of Jisr al-Doreaa. University of Chicago Press, 2009.

Klepper, M. "Jasr Al Doreaa: RAFT Analysis." The Other Side of History, 19 April 2024. Retrieved 13 July 2024 from https://the-other-side-of-history.blogspot.com/2024/04/jasr-al-doreaa-raft-analysis.html

Swinton, E. The Defense of Duffer’s Drift. U.S. Army Command and General Staff College. Originally published 1906. Retrieved 13 July 2024 from https://www.armyupress.army.mil/Portals/7/combat-studies-institute/csi-books/swinton.pdf

TRADOC. “The Defense of Jisr Al Doreaa – Dream 5.” YouTube Video, 17:49. 9 May 2013. Retrieved 13 July 2024 from https://www.youtube.com/watch?v=FYFB0zAcZl4

Sunday, June 30, 2024

Battle of COP Keating

Geographic Analysis

Combat Outpost (COP) Keating was positioned in the Kamdesh District of Afghanistan, 25 km away from the Pakistan border. It was located in mountainous terrain, at the bottom of a valley, along an unimproved road which ran alongside the Darreh ye Kushtoz River. The village of Urmal was located 200 meters west of the COP.

COP Keating, located at the bottom of a valley in the Kamdesh District of Afghanistan. Photo by Brad Larson.

The surrounding mountains were not secured, except for the one capped by OP Fritsche, located 2.2 miles south of COP Keating with a 2144 ft difference in elevation. COP Keating and OP Fritsche were not in line of sight of each other.

Close to COP Keating was a mosque located on a ridgeline that would serve as an enemy fire position.

This area - the COP, the OP, the mosque, and surrounding mountains – would be the location of the Battle of Kamdesh, also called the Battle of COP Keating. Taliban insurgents had engaged the ground unit assigned to COP Keating and OP Fritsche over 45 times since May 2009.

Squadron HQ was located at Forward Operating Base (FOB) Bostick, 30 km southeast of COP Keating, or 10 minutes flight time by helicopter. Task force and brigade headquarters were both located at FOB Fenty in Jalalabad, 137 km southwest of COP Keating, or 40 minutes flight time by helicopter. These bases would supply air and artillery support during the battle.

The Battle

At the time of the attack, COP Keating had 73 troops (53 US troops and 20 Afghan National Army (ANA)), and OP Fritsche had 29 troops (19 US and 10 ANA) stationed there.

Immediately prior to the attack, insurgents occupied the mosque and five nearby support by fire (SBF) positions. These positions were overlooking COP Keating and would also interfere with air support.

The attacks on FOB Keating and OP Fritsche began simultaneously on the morning of 3 October 2009. The mortar pit at COP Keating was pinned-down and soldiers were unable to return fire. Meanwhile, the men at OP Fritsche were pinned-down by other insurgents. Thus, the two OPs were unable to support each other.

FOB Bostick began indirect fire in support of COP Keating. Two F-15s arrived at COP Keating and began engaging insurgents. The insurgents continued attacking FOB Keating from three different directions, forcing the US and ANA troops to collapse into a defensive position within COP Keating.

OP Fritsche repulsed the insurgents and provided mortar fire in support of COP Keating.

Most of the buildings were on fire by this time and the base was partially overran by the insurgents. US forces pushed outwards to retake lost positions within COP Keating.

Part of a quick reaction force (QRF) from FOB Bostic arrived by helicopter at OP Fritsche, but weather delayed the rest of the QRF from arriving by one hour.

As fire continued to engulf COP Keating, the QRF departed OP Fritsche on foot towards COP Keating. Two hours into their descent, the QRF called-in close air support and engaged the insurgents. This forced the QRF to move using bounding overwatch, slowing their advance to COP Keating.

The QRF arrived 13 hours after the attack started. They began clearing operations and established a landing zone to allow for medical evacuation (MEDIVAC). Enemy fire prevented MEDIVAC fights from using that landing zone, but additional air support allowed the flights to commence.

Sixteen hours after the attack began, the last MEDIVAC flight left COP Keating. Eight U.S. soldiers were killed and 27 wounded; eight ANA soldiers were wounded. Approximately twenty-seven insurgents were killed. Only one of the buildings remained intact. The munitions depot was abandoned following US departure, which was then looted by the Taliban. The depot was bombed by Americans on 6 October to destroy any remaining munitions. Four officers were disciplined because of the attack. (ABC News, 2010).

Starburst Analysis

Starburst analysis is a structured analytic technique (SAT) that seeks to ensure that analysists have a grasp of the situation they’re investigating. It allows them to enumerate the actors, to handle information overload, and to differentiate and isolate root causes from symptoms. It allows analysts to identify gaps in their intelligence.

Who are the Primary Actors?

The primary actors consisted of US and ANA forces fighting against Taliban insurgents. The US and ANA forces had 73 troops stationed at COP Keating and 29 troops stationed at OP Fritsche. The QRF from FOB Bostic and air support reinforced COP Keating. Approximately 300 Taliban insurgents were involved.

What were the Key Activities?

The key activity was the battle between US/ANA troops and the Taliban fighters at COP Keating and OP Fritsche. This was preceded by planning and observation by the Taliban.

When

The battle itself took place on 3 October 2009 but planning by the Taliban and village elders started months prior.

Where

The battle took place at COP Keating (located at the bottom of a valley) and the nearby OP Fritsche, located at a higher elevation but not within direct line of sight. The Taliban attack made use of the mountains surrounding COP Keating to not only rain fire down upon the camp but also attack any incoming air support. In addition, the insurgent attack on OP Fritsche pinned-down the forces located there. The insurgents made use of a local mosque as a firing position, which the Americans would be loathe to attack.

Why

COP Keating was established in July 2006 and was left in place to prevent weapon shipments and insurgent movements across the Pakistan border. The Taliban attack was designed to dislocate the COP, presumably to allow the flow of weapons and fighters to continue.

How

The Battle of COP Keating was a two-pronged attack, one against COP Keating (presumably the primary target), the other against OP Fritsche. Both targets were engaged simultaneously to prevent one from assisting the other. Kept isolated, the nearest air support to the COP and OP was 10 minutes away by helicopter from FOB Bostick.

Information Sources

It is necessary to evaluate information that was available prior to the Battle of COP Keating as well as information sources generated after the battle took place.

Hindsight is 20/20 and one would expect to find analyses of the Battle of COP Keating. Beyond one TRADOC video, not much information is available besides personal accounts, popular books, as well as the 2020 movie called “The Outpost.” Many of the details of the battle did not come to light until the WikiLeaks Afghan War Diaries. Analysis of the battles were no doubt performed, but it may have been the case that analysts found some fundamental security flaw that was best kept secret.

Apparently, there were multiple intelligence failures. Building on (Gertz. 2009), Hershel Smith writes (Smith, 2009):

…defense intelligence had three reports of imminent danger but failed to act on this intelligence. What “smoking gun report” would have convinced them to take action we aren’t told…
Smith goes on to hint that a “smoking gun report” may have been in possession of the CIA.

Prior to the battle, there are the lessons learned from the 45 times that US forces engaged the Taliban since May 2009. Each engagement would be amenable to Starburst Analysis; in particular, information about the names and numbers of insurgents involved, the weapons and tactics they used, as well as the kinds of information they used in formulating their attacks. The troops involved could all be interviewed. All of this information would be local to the area of COP Keating of course.

The Battle of Wanat, which occurred on 13 July 2008, could also serve as a source of information. This battle was similar to the Battle of COP Keating in many ways, including the number of fighters on each side, geography, the distance from FOBs, etc. Unlike COP Keating, analyses of the Battle of Wanat are publicly available. (Steeb, et. al., 2011), (Staff of the U.S. Army Combat Studies Institute, 2010).

The battle sites are separated by straight line distance of 56 km, so a different set of Taliban fighters may have been involved. Starburst Analysis of the Battle of Wanat could indicate common actors, tactics, and weapons when compared to the Battle of COP Keating, however. These commonalities would allow analysts to figure out the hierarchical structure of the Taliban as well as to observe the evolution of their weapons and tactics. Final analyses of the Battle of Wanat were completed after the Battle of COP Keating, but preliminary studies must have been available.

Population studies of the people living near COP Keating would be useful for determining local attitudes and for building a social network of the people.

Another critical information stream would be a scholarly perspective. Thaler, et. al. (2013, p. 12) sites several academic papers (many published prior to the battle) stating that Afghanistan has a culture of independence and resistance. This is a very specific characterization and probably wouldn’t hold for all Afghani. If it applies to the people living near COP Keating, this will determine how Afghani would relate to or tolerate foreign presence, if at all.

References

ABC News. (5 February 2010). “Camp Keating officers disciplined for attack that killed 8 U. S. troops.” Retrieved 30 June 2024 from https://abcnews.go.com/WN/Afghanistan/camp-keating-commanders-disciplined-attack-killed-22-us/story?id=9761160

Gertz, B. (29 October 2009). “DIA on Afghan intel” Washington Times. Retrieved 30 June 2024 from https://www.washingtontimes.com/news/2009/oct/29/inside-the-ring-58944275/

Smith, H. (2 November 2009). “Systematic defense intelligence failures”. Retrieved 30 June 2024 from https://www.captainsjournal.com/2009/11/02/systemic-defense-intelligence-failures/

Staff of the U.S. Army Combat Studies Institute. (2010). “Wanat: Combat action in Afghanistan, 2008”. Combat Studies Institute Press. Retrieved 30 June 2024 from https://www.armyupress.army.mil/Portals/7/combat-studies-institute/csi-books/Wanat.pdf

Steeb, Matsumura, Herbert, Gordon IV, & Horn. (2011). “Perspectives on the Battle of Wanat”. Rand Corporation. Retrieved 30 June 2024 from https://www.rand.org/content/dam/rand/pubs/occasional_papers/2011/RAND_OP329z1.pdf

Thaler, Brown, Gonzalez, Mobley, & Roshan. (2013). “Improving the U.S. Military’s understanding of unstable environments vulnerable to violent extremist groups”. RAND Corporation. Retrieved 29 June 2024 from https://www.rand.org/pubs/research_reports/RR298.html

TRADOC G2 OE Enterprise G&V. (10 August 2012). “The battle of COP Keating - October 3rd, 2009”. Retrieved 30 June 2024 from https://www.youtube.com/watch?v=ylUzySZb3L8

WikiLeaks War Diary. Retrieved 30 June 2024 from https://wardiaries.wikileaks.org/search/?q=cop+keating∓sort=date∓release=Afghanistan∓date__gte=2009-10-03∓date__lte=2009-10-09

Saturday, May 11, 2024

Best Practices in Military Intelligence

The sheer number of threats against America requires that we think strategically about military intelligence as applied to those threats. The target (or subject) of intelligence activities includes not only existing threats to our national interest but also emerging and evolving threats, both by state- and non-state-actors. We must collect, organize, and categorize information about these actors, then communicate that information to the right people at the right time in order to strategically approach the desired end state of a secure America.

Several guidelines for achieving the above are given in the video "Applying the Strategic Approach to Military Intelligence," which, unfortunately, is not publicly available. Some of these guiding principles include:

  1. Military intelligence must be mission driven. We must understand our objectives - our mission - and be able to convert those objectives into concrete actions at the operational level. Another way of formulating this is that we must be cognizant of our objectives, of our role in the F3EAD and other cycles, and act accordingly. All actions must be measured by the extent that they further our mission.
  2. Because of the importance of the mission, and the severity of the consequences should we fail, we must become subject matter experts to the point of dominating the intelligence battle space.
  3. The best way to accomplish this is to employ individuals who are proactive, who are facilitators and can network, who understand the function of intelligence, and most importantly are of high moral character. By having such individuals in place, they can overcome any defects in a slightly flawed system.
  4. Team leaders must be able to keep the team on track and must challenge team members to reach and exceed their preconceived abilities as analysts. The leader must also be able to differentiate quality team members from toxic actors (those that are politicized, subversive, etc.) and take corrective action to limit the damage caused by the latter.
  5. The mission and supporting critical activities should be written into a "mission statement" before entering a high-stress environment with rapid operational tempo. This allow teams and their leaders to remain "centered," and continue being proactive.

These principles form the basis of an extremely capable intelligence organization. There is a weakness not addressed in that video, however. Intelligence teams must surely meet all the above-listed principles to be effective in their job of providing superior intelligence to enhance decision making. Possessing all these qualities is called "being on the happy path" in the parlance of information technology.

What happens when we leave the happy path? Meaning, what happens when a team (or whole agency) fails to meet one or more of those criteria? At best it leads to the agency failing in their job of providing timely, relevant, accurate and actionable intelligence; at worst it leads to systematic abuse.

Intelligence agencies used to be reigned-in through several means: congressional oversight, budgetary limitations, and the court system. Each of those has failed: congress no longer provides oversight, as proven by their willingness to extend the warrantless wiretapping provisions of the Patriot Act, as well as the initial ratification of that act itself. Budgetary concerns are no longer the concern of either political party. Further, the decreasing cost of IT resources (storage and processing) makes automated intelligence gathering extremely affordable. Finally, the court system has turned a blind eye to the 4th Amendment and the protections it affords to Americans, and private companies (especially those in the telecom and banking sectors) are more than willing to be accessories and share customer data.

Without some sort of external check on intelligence agencies, we must rely on them to be self-regulating, which means that they are unregulated. It is not clear how to reestablish boundaries on the scope of intelligence agencies other than by addressing the above-mentioned political, fiscal, and legal failures. By not reestablishing these checks, military intelligence agencies will not only experience mission creep but also mission drift, rendering those agencies less able to provide intelligence for our protection as a nation as well as altering the relationship the agencies have with our fellow citizens.

Thursday, April 25, 2024

Comparing Effective Military and Civilian Intelligence Teams

Introduction

The following notes are based on my experiences and observations while working to document and limit the damage caused by Antifa during the fiery but mostly peaceful riots of the 2020 “Summer of Love.” I participated in three “operations”:

  1. Tracking the evolution of CHAZ/CHOP in Seattle, Washington
  2. Tracking the riots in Philadelphia
  3. Tracking a major Antifa/BLM protest in one of the suburbs of Philadelphia
These operations contained elements of military intelligence, police investigation, private investigation, and corporate competitor analysis but do not fit easily into any one of those categories. However, there is much in common with military intelligence when it comes to building an effective team to monitor those riots.

The organization and processes described here are not limited to monitoring Antifa but are also applicable to the investigation of child predators and human traffickers.

The purpose here is to examine how these civilian intelligence teams operate, with the long-term goal of adapting the aspects that make military intelligence teams effective to these civilian analogs.

Goal of an Effective Intelligence Team

The goal of an effective intelligence team is to develop relevant, accurate, timely, and actionable information. This goal is realized by three “information paths” within the team:

  1. Incoming data (raw and unverified – could be called “pre-intelligence”)
  2. Analyses by individuals and teams to convert this data into intelligence (verify, deconflict, and determine significance)
  3. “Upward” movement as intelligence is organized and unified with other sources and becomes actionable.
These aren’t one-way paths, however – there must be a cycle that starts with evaluating a piece of information’s accuracy, classifying it according to relevance, and using that intel to drive follow-up investigations.

Qualities of Good Intelligence Team Members

Besides initiative, the most important quality that all team members must have is a sense of objectivity, which means that the team member:
  • Can distinguish reality from hearsay and from political bias
  • Can judge the quality of incoming data
  • Is self-aware enough to know what he/she does not know
  • Has a bearing of “effective professionalism”

A skill any analyst must possess is the ability to translate intelligence goals into relevant collection and analysis tasks. This doesn’t come naturally to many people and must be developed through experience and mentorship.

The team member must possess appropriate technical skills, such as using GIS, working with OSINT sources, having the ability to infiltrate, etc. Infiltration (either physical or on-line) is not something everyone is willing to do and requires the ability to be inconspicuous while still making important observations. We found that for best results – in general and not just for infiltration - the team member’s skills and interests must be matched to his role.

Finally, team members must understand and practice excellent OPSEC. This need was demonstrated when one of the teams tracking the riots in Philadelphia (not mine!) decided to live-stream their operations on YouTube. This allowed Antifa supporters to locate the exact hotel room from which they were operating in under 30 minutes.

Leader’s Role

The leader of an intelligence team must be able to identify intelligence gaps and set goals to fill those gaps, and clearly communicate those goals to the analysts. He must prevent team members from “going down the wrong rabbit holes” – performing investigations on topics or individuals not clearly related to the goals. He must act as a sounding board while providing analysts with a healthy dose of skepticism when appropriate.

The leader must be able to package-up the results of the team into recommendations and supporting documents for action by the relevant authorities. In the case of Antifa, child predators, or human traffickers, those authorities are law enforcement agencies.

Leadership Style

The sociologist Douglas McGregor described two broad styles of leadership, which he labeled Theory X (lack of trust in subordinates which leads to micromanagement) and Theory Y (confidence in subordinate’s ability to be self-motivated)1. McGregor recommends Theory Y, though it can devolve into “servant leadership.”

A different way of looking at Theory Y are the leadership styles known as "mission command" and the older German concept of "Auftragstaktik." Mission command has officially been a part of the US military command doctrine since the 1980s, though was practiced much earlier2, and states that a good commander sets the mission and constraints (e.g. time bounds), and lets subordinates choose the means to accomplish the mission. Auftragstaktik3 is broader and more fundamental than mission command because it is a type of military professionalism based on three virtues: “knowledge, independence, and the joy of taking responsibility.” Mission command can thus be seen as a corollary of Auftragstaktik.

Mission command and Auftragstaktik are both excellent and appropriate styles for leading effective intelligence teams, either civilian or military.

Establishing a Team

Once a group of individuals comes together to perform intelligence activities, and after basic groundwork (meeting times, communication methods, etc.) is laid, there are three tasks that must be performed: creating an area study, identifying and developing information sources, and making contacts with law enforcement.

An area study is packaged information about the team’s geographical area of interest. Besides physical aspects (physical terrain, weather, transportation systems, and critical infrastructure), the area study must include economic, political, and cultural factors (businesses, governance, law enforcement and security agencies, and political leanings). Finally, it must include a threat overview - in this case that would be information about the local Antifa members and activities. This will involve performing a RAFT (relationships, actors, functions, tensions) analysis4 on Antifa.

One assumption commonly made when doing an area study is that the adversary’s command structure lies within the area of interest. Groups such as Antifa are decentralized organizations, and human traffickers are sometimes trans-national, so a RAFT analysis not constrained by geographic area is an invaluable supplement to the traditional area study.

Certain aspects of the area study will stay constant (e.g. physical terrain) whereas others (e.g. Antifa membership) will change, sometimes rapidly, and it is important to update the area study as needed.

The new team must also identify and develop information sources. For direct human sources this includes recruiting and vetting informants, determining their accuracy and reliability, and “handling.” There are also tasks needed for indirect sources: finding mainstream media news sources and online video streams that provide on-the-spot coverage, locating and infiltrating relevant chat rooms and other messaging systems, etc. Even GIS requires setup: for example, finding and importing the correct map layers for some geographic information systems can be an involved process.

Social media is yet another source of information. Antifa members like to announce their proclivities, the larger the forum the better. Once an Antifa member’s account is located on a social media platform, it is easy to find his/her followers and monitor their posts. This is very valuable, and for remote intel operations it is one of the few available roads to inside information.

In anticipating the creation of actionable information, it is necessary to identify the consumers, those who will act on that information (after they perform their own analysis), and this usually means law enforcement agencies. Given the “hands off” approach many law enforcement agencies and district attorneys take with Antifa, it may be necessary to “shop around” to find the proper consumer. Prosecuting child predators is something most law enforcement agencies are willing to do; the record on human trafficking seems to be mixed.

Specialized Intelligence Teams

There are types of military intelligence teams, such as Female Engagement Teams, Culture Support Teams, Human Terrain Teams, and High Value Target Teams, that use specialized approaches when confronting adversaries.

Human Terrain Teams

Human Terrain Teams consist of sociologists and cultural anthropologists used to advise military personnel on social norms and taboos within a target population5. There really is no civilian analog to HTTs – private or police investigators cannot afford to maintain a staff of social scientists, and any attempt to provide cultural interpretations of events involving child predators or human traffickers is nothing but rationalizing evil.

The other types of teams do have certain parallels in civilian intelligence operations.

Female Engagement Teams

In conflict zones in which women are marginalized, like in Afghanistan, Female Engagement Teams (FETs) were used to gain the trust and confidence of Afghani women6. They were initially controversial because they involved putting female soldiers or Marines into combat situations. The effectiveness of FETs and the related Culture Support Teams were brought into question because the FET were not able to maintain prolonged contact with the female population of any particular village7. Further, FETs required a male contingency to provide security.

In civilian and law enforcement intelligence teams, women can play several specialized roles. In child predator stings, they can serve as “prey,” specifically in the time immediately prior to in-person contact by the predators. In operations to disrupt human trafficking or prostitution rings, women go undercover with the goals of observing and recording evidence of wrongdoings by the ring leaders, and (maybe) getting prostitutes to disaffect.

These civilian and law enforcement intelligence operations are more successful than FETs for several reasons: first, limited time of contact is not an issue with child predator or human trafficking operations – contact is maintained only as long as it is needed to catch the predator or disrupt the traffickers; there is no need to maintain contact in perpetuity. Second, there is no need to provide ongoing security by male team members - security is supplied only as-needed.

Another reason for the success of undercover female officers is their expected behavior while undercover: by their actions, undercover officers seek to raise standards by eliminating criminals, and there is no attempt to be “culturally sensitive” to the predators and traffickers. The same cannot be said for FET members – their presence is designed to minimize “cultural threat” while still hoping to win female hearts and minds. This was demonstrated by the requirements that FET members have male escorts and that they always keep their heads covered.

High-value Target Teams

High-value Target Teams (HTTs) are interagency operations that use network-based targeting, combine intelligence with operational capability, and employ counterterrorist and counterinsurgency methodologies in unison. The idea is to use intelligence to find leaders (high-value individuals) in the insurgency network, and then target them with sufficient force and accuracy so that they are eliminated while isolating peaceful civilians from the effects of the elimination8. This tactic was credited for success in Iraq in 2007-2008 – by eliminating the most powerful insurgents, the civilian authorities gained the time needed to establish themselves and to dominate the less powerful insurgents.

There is no direct analog of HTTs in civilian intelligence operations, simply because either the operational capability is separated from the intelligence capacity, or (as in situations described above where district attorneys are sympathetic with Antifa) the operational capability is completely absent. There are a few similarities between HTTs and civilian intelligence teams, however. The most obvious one is that both analyze their adversaries’ networks to identify leaders and to seek and exploit vulnerabilities. The other similarities mostly lie in the factors determining team success. In particular, civilian teams are small, have common purpose, are not divided by loyalties to outside agencies.

Comparison and Conclusions

Military and civilian intelligence teams share the goal of gathering valuable, timely, and actionable information about their adversaries. They both use methodologies such as RAFT analysis to organize that information and derive additional intel from it. They face the same problems – vetting sources, distinguishing false leads from actual evidence, identifying intel gaps, contending with rapidly changing intel priorities, maintaining OPSEC, and so on.

Both types of teams have similar organizations (both in terms of personnel and information flows), and their success depends on the effective leadership of competent and enthusiastic team members.

They face similar adversaries: during the GWOT, military intel teams were tasked with gathering information about Islamic extremists; civilian intel teams are needed to gather info on Antifa, child predators, and human traffickers. All these enemies have either no leaders or have a decentralized organization. They are also located and operate within the common population, and so they can “blend in.”

The similarities end there.

Military intelligence teams have the advantage when it comes to available information and resources. Civilian intel teams are limited to OSINT, IMINT, and limited forms of geospatial intelligence. Military intel teams are capable of all that plus SIGINT, MASINT, etc.

Military intelligence teams and civilian intel teams differ in that the former are part of a larger organization (the U.S. military) that legally can and oftentimes does act based on the recommendations from their intel teams. Civilian intel teams are not part of a larger organization, and many district attorneys support and cover for Antifa and similar groups.

Another difference is the quantity of information that is available to each – military intel teams must contend with information overload. Civil intel teams scramble for each bit of knowledge, so in that they are like private investigators. The only situation where the volume of information is remotely comparable is with the firehose of information available from social networks.

Perhaps the most important difference between military intelligence teams and the type of teams described here is that the former is a profession. It has a shared body of knowledge; various schools such as the Joint Military Intelligence Training Center (JMITC) and the United States Army Intelligence Center of Excellence (USAICoE) transmit that knowledge; and it has fictional heroes such as James Bond, Jason Bourne, Ethan Hunt, and even Sterling Archer, to inspire people to enter that vocation. In short, military intelligence has a culture.

Civilian teams have none of that – they come together in an impromptu manner, they must invent/discover the tradecraft needed to accomplish their goals, then they disband only to be reinvented when another group of agitators gains momentum – Hamas protesters, anyone? The closest thing to being an exception are individuals and teams that hunt for child predators and human traffickers. They mostly operate using sting operations, and while the results of these operations are popularized, the implementation details best remain trade secrets. Other than this limited exception, civilian intelligence teams have no means of transmitting their experience, or creating a body of knowledge, or building a culture. It is not a profession, it is an avocation.

Which is the superior institution? In combat situations, military intelligence teams have the wherewithal and experience to be extremely effective. In riot control and law enforcement situations, civilian intelligence teams are better in at least one aspect: it is more difficult to turn civilian intel teams inwards towards mass surveillance.

2020 Antifa/BLM Riots. Kerem Yucel/AFP via Getty Images

Footnotes

  1. Mind Tools Content Team, “Theory X and Theory Y: Understanding Peoples’ Motivations.”
  2. Andrew Kiser, Mission Command: The Historical Roots of Mission Command in the US Army.
  3. Donald Vandergriff, “How the Germans defined Auftragstaktik”
  4. Dale Eikmeier, “Design for Napoleon’s Corporal”
  5. Ben Connable, “Human Terrain System is Dead, Long Live … What?”
  6. Megan Katt, “Blurred Lines: Cultural Support Teams in Afghanistan”
  7. Ibid.
  8. Christopher Lamb & Evan Munsing, “Secret Weapon: High-value Target Teams as an Organizational Innovation”

Bibliography

Connable, B. “Human Terrain System is Dead, Long Live … What?” Military Review, January-February 2018. Retrieved 25 April 2024 from https://www.armyupress.army.mil/Journals/Military-Review/English-Edition-Archives/January-February-2018/Human-Terrain-System-is-Dead-Long-Live-What

Eikmeier, D. “Design for Napoleon’s Corporal.” Small Wars Journal, 27 September 2010. Last retrieved on 25 April 2024 from https://smallwarsjournal.com/blog/journal/docs-temp/557-eikmeier.pdf

Kiser, A. J. Mission command: The historical roots of mission command in the US Army. Defense Technical Information Center, May 2015. Last retrieved on 24 April 2024 from https://apps.dtic.mil/sti/pdfs/AD1001514.pdf

Lamb, C. & Munsing, E. “Secret Weapon: High-value Target Teams as an Organizational Innovation.” Institute for National Strategic Studies, Strategic Perspectives, No. 4, 2011. Retrieved on 24 April 2024 from https://ndupress.ndu.edu/Portals/68/Documents/stratperspective/inss/Strategic-Perspectives-4.pdf

Mind Tools Content Team. “Theory X and Theory Y: Understanding Peoples’ Motivations.” Mind Tools website, N/D. Retrieved on 25 April 2024 from https://www.mindtools.com/adi3nc1/theory-x-and-theory-y

Vandergriff, D. E. “How the Germans defined Auftragstaktik: What mission command is – and – is not” Small Wars Journal, 21 June 2018. Retrieved 25 April 2024 from https://smallwarsjournal.com/jrnl/art/how-germans-defined-auftragstaktik-what-mission-command-and-not

Friday, April 19, 2024

Jasr Al Doreaa: RAFT Analysis

Introduction

In 1904 the British Army officer Ernest Swinton wrote a book titled The Defence of Duffer's Drift. Set during the Second Boer War, it is narrated by a freshly-minted lieutenant named N. Backsight Forethought (BF), who is tasked with holding Duffer's Drift, the only ford on the Silliassvogel River open to wheeled traffic. BF initially thought this to be a trivial problem, stating "now if they had given me a job, say like fighting the Battle of Waterloo, or Gettysburg, or Bull Run, I knew all about that, as I had crammed it up...". He fails at this trivial problem, at least at first.

The story is told in a series of six nightmares. In the first five, BF makes mistakes that result in the defeat and capture of his platoon by the Boers. At the end of each nightmare, he analyzes his mistakes and compiles a list of lessons learned. These lessons range from the obvious (defend your camp before allowing your men to rest, and do not allow stray people into your camp - they will give intel to the enemy) to the more sophisticated (a hill may not necessarily be the best place to hold). BF is able to carry these lessons into the next evolution. Finally, in the last nightmare, he is able to hold Duffer's Drift against Boer ambushes and attacks until relief arrives.

The Defence of Duffer's Drift has been used by both British and US forces, among others, as a way of teaching small unit tactics. This style of instruction has been used repeatedly ever since, and used to teach other topics such as mechanized warfare and cyber warfare.

To teach junior officers basic counter-insurgency principles for use in Iraq, US Army Captains Michael L. Burgoyne and Albert J. Marckwardt wrote a 2009 novella called The Defense of Jisr Al Doreaa. As in the The Defence of Duffer's Drift, the narrator experiences six nightmares, learning as he goes along. These six nightmares were converted into six computer-animated videos by TRADOC.

This paper is concerned with the sixth and final TRADOC video. When viewing it from the proported counter-insurgency lessons learned, one can only say "now do it for Afghanistan." Instead, the video will be considered from the standpoint of a military intelligence analyst, and a RAFT analysis will be performed on the ficticous Iraqi town of Jasr Al Doreaa and the Iraqi military, insurgents, and civilians present there.

Introduction to RAFT Analysis

RAFT Analysis is an analytic tool used to quickly identify key players, their functions, and the relations and tensions between the actors. The acronym stands for:

  • R = Relationships – connections between key players
  • A = Actors – key players
  • F = Functions – what do the actors do, what are their capabilities?
  • T = Tensions – conflicts between actors

Actors are the key players, and these actors have functions – what do they do, and what can they do? Relationships are about how are actors connected. This can be through military command structure, friendships, familial relations, etc. Tensions are the conflicts between the actors.

It makes sense to start with the actors.

Actors

2LT Phil Connors

  • Platoon leader in charge of defending the town, and establishes a base
  • Familiar with local tribes and customs but not the language
  • Believes in "hearts and minds" approach to fighting insurgents:
    • Security achieved through gaining trust and confidence of locals
    • Separate insurgents from population
    • End the day with fewer insurgents
  • Is quoted as saying "make no enemies" - take that as you will.

After Connors establishes his base, it comes under attack. This attack has three prongs: a mortar attack, a VBIED, and a direct assault by a 6-man team. Analysis of the VBIED shows that it originated in Syria. All people who initiated the mortar attack were killed. Of the 6 men who assaulted the base, 5 were killed, leaving only a man named Mohammed Jabori.

Mohammed Jabori

  • Part of a 6-man team that assaulted Connor's base
  • Rest of his team was killed
  • Was armed with AK-47 when captured
  • Local to the town of Jasr Al Doreaa
  • Works for local Al-Qaeda leader, Kaseem Fareem
  • One of his captors says "this guy is just a kid" - a kid with a mustache and a 5-o'clock shadow

Following the attack, Connors decides to go into Jasr Al Doreaa and meet with the locals. In this, he is assisted by LT Habir of the Iraqi Security Forces.

LT Habir

  • Commander of local Iraqi forces
  • Works with Connors when meeting with locals
  • Cooperates with Connors in capturing the local Al-Qaeda leader
  • Speaks both English and local language

While in town, Connors and Habir meet LT Habir's cousin, Ahmed, and they all go to Ahmed's house for tea or something.

Cousin Ahmed

  • Cousin of LT Habir
  • Friend of the mayor of Jasr Al Doreaa
  • Can identify local Al-Qaeda members including leaders
  • Key player because of his relationships and local knowledge

Once at Cousin Ahmed's house, the town mayor pays a visit. This is apparently an unscheduled meeting.

Mayor Hussein

  • Mayor of Jasr Al Doreaa
  • Embittered because of 4 years of unkept US promises
  • Afraid of reprisal for working with Americans
  • Cares about his town and relates the needs of his town to Connors and Habir:
    • Medical support - town has no doctors
    • Town needs security

During interrogation, Mohammed Jabori states that he works for the leader of the local Al-Qaeda. He gives a name, Kassim Fareed, but not how to find him. Cousin Ahmed helps out with this.

Kassim Fareed

  • Leader of local Al-Qaeda
  • Lived near Sunni mosque with bodyguards
  • Moved into town 2 weeks ago, killing several villagers
  • Considered to be a high value target
  • Captured by Connors and Habir along with 3 security guards

Kassim Fareed was captured along with three other people. It was Cousin Ahmed who identified him. Along with the four insurgents, the capturing force finds weapons and IED-making equipment.

Relationships

The best way to examine relationships is through diagrams that look like this...

This diagram shows the key actors and the relationships between them. On the bottom corner is Connors; he works with LT Habir and with Cousin Ahmed using a interpreter named Mohammed. Ahmed and Habir are cousins. Ahmed and the Mayor are related in some way - friends? We don't know the details. Maybe this means Cousin Ahmed is what used to be called a "leading citizen."

Cousin Ahmed can identify members of the local Al-Qaeda insurgents including Kassim Fareed. Fareed works with Al-Qaeda. Either Fareed or some other member of the Al-Qaeda has threatened the Mayor.

Notice that Cousin Ahmed is related to the most other people in this diagram. This "centrality" implies that he has "influence" or at least knowledge of the key players. This is the type of information that can only be revealed with RAFT analysis.

With the available information we can diagram the local Al-Qaeda group...

Near the bottom is Muhammed Jabori who was captured in a raid on Connor's base. During interrogation he reveals that his manager in Al-Qauea is Kassim Fareem. He doesn't know how to locate him, however. Fareem is captured along with three of his security guards. A very valuable piece of information would be the name of Fareem's leader.

Note: we are assuming that Al-Qaeda is indeed a hierarchial organization.

Functions

Functions are the capabilities of the key actors: what they do and what can they do.

2LT Phil Connors is a prime mover (at least militarily) - he gets things done! He works well with his commander and the Iraqi Security Forces. He anticipates the town's security and medical needs, and gets police and medical training for them.

Connors is so proficient at getting things done that he almost has a superpower: he operates without von Clausewitz's "friction!"

Kassim Fareed commanded other insurgents. He possessed sufficient pull to get weapons and IED-making equipment. This means he probably supplied other insurgents with weapons and IEDs.

He might be the one who threatened Mayor Hussein for working with Americans.

Fareed's capture throws the local Al-Qaeda into disarray, at least in the short term.

Finally, Cousin Ahmed functions as the "glue" to the whole situation. He can identify key actors and form relationships with them. He's on good terms with Mayor Hussein and local Iraqi forces. He can at least identify local insurgency memvbers such as Kassim Fareed.

Tensions

The ultimate tension is between Coalition and Insurgent forces, but we care about tensions between the key actors. The major tension is between the mayor of Jasr Al Doreaa and the insurgents.

Mayor Hussein feels threatened by the local Al-Qaeda for working with Americans. He doubts the ability of Iraqi forces to defend the town. Connor's commander has a similar view of Iraqi forces. The mayor is apprehensive of the town's security once the American forces leaves.

Intelligence Sources, Gaps, and Goals

The available intelligence sources include:

  • Captured Al-Qaeda members
  • Families, friends, and acquaintances of captured and killed Al-Qaeda members
  • Info from townsfolk, especially from Cousin Ahmed
  • Physical evidence from Kassim Fareed's house
  • Physical evidence from the VBIED that exploded earlier

There are several intelligence gaps, information that would be useful to have:

  • Who is Kassim Fareed's leader?
  • Are Mayor Hussain, Cousin Ahmed, and the interpreters loyal?
    • Are they playing both sides against each other?
  • About the Mayor:
    • How was he threatened? By whom?
    • Did apprehension level go down after Kassim Fareed was captured?
  • About Cousin Ahmed:
    • Who else does he know?
    • How did he get to know all these people?
    • What is the overall quality of information he can provide?

Conclusion - Next Steps

  • Fill-in the intel gaps by:
    • Gather and analyze additional physical evidence
    • Continue getting intelligence from captured insurgents and family members
  • Identify other insurgents
  • About Cousin Ahmed:
    • Use as information source about locals and insurgents
    • Monitor his actions and contacts
  • Follow-up on Syria connection from earlier VBIED explosion
  • Look for changes in behavior of the locals following Kaseem Fareem's capture
  • Derive actionable info and pass to Connors to execute

References

Burgoyne, M., Marckwardt, A., & Nagl, J. (2009). The Defense of Jisr al-Doreaa. University of Chicago Press. Last retrieved on 19 April 2024 from https://smallwarsjournal.com/documents/jisaldoreaa.pdf

Swinton, E. D. (1904). The Defense of Duffer's Drift. Praetorian Press. Last retrieved on 19 April 2024 from https://www.armyupress.army.mil/Portals/7/combat-studies-institute/csi-books/swinton.pdf

TRADOC G2 OE Enterprise G&V. (2013). The Defense of Jisr Al Doreaa - Dream 6. Retrieved 3 April 2024 from https://www.youtube.com/watch?v=1vHvae5BZRo