Given my profession, I am particularly interested with information. The delineation between “information operations” and “cyber operations” is fairly blurry, as long as you’re not looking at it from a US authorities perspective. Is convincing the US populace to fight amongst themselves via Twitter and Facebook a cyber operation because it probably used some custom automation to make it work at scale? Or is it primarily an information operation? Is crafting a plausible phishing email to deliver malware an information operation because of the message, or is it a cyber operation because of the ultimate intent of delivering malware?
Let me rewind. Carl, ever mindful of the fact that words matter, defines “information” as “all the knowledge which we have of the enemy and his country.” It is interesting that he is concerned largely with information about the adversary, and not information about the status of one’s own personnel/resources/political situation.
Ever mindful of the fact that he’s basically writing a textbook, Carl goes on to say that while the book answer is to “only trust information which is certain”, this doesn’t really hold up in practice. The vast majority of the information you’ll encounter is false, contradictory, or doubtful. So what is the leader to do? Develop a “certain power of discrimination, which only knowledge of men and things and good judgment can give.” In other words: you need a BS detector.
This is definitely a skill that cyber pros need to develop. Your information comes from a wide variety of sources, and many of those sources have agendas. Commercial purveyors of “threat intelligence” are, first and foremost, concerned with selling a product. Governmental agencies have charters that severely limit how much context they can give. Members of ISACs are usually concerned with the common good, but some members may be sharing for the sake of sharing (because they need to participate to maintain access), instead of sharing what they know will help other people out. People on Twitter could have any motivation under the sun, including wasting your time. This is why actual analysis of any source of information is required – automatic ingestion of a “feed” rarely turns out well. An excellent example of atomic indicators gone wrong is the Grizzly Steppe report (commentary by CyberScoop particularly relevant).
![“A small handful of them [watchlisted internet addresses in Grizzly Steppe] are so commonly used that almost every network is going to generate huge numbers of false positives,” Chernin said. For example, he said, there were indicators that could cause the system to alarm because a user logged on to a Yahoo email account.](http://www.cyberclausewitz.com/wp-content/uploads/2019/07/GrizzlySteppeFail-1024x288.png)
Another challenge when it comes to information is that, “as a general rule, everyone is more inclined to believe the bad than the good. Everyone is inclined to magnify the bad in some measure.” The most blatant case of this is the “ZOMG APT we literally couldn’t have done anything to stop this super-sophisticated attack” reaction that many entities have. A less extreme, but still very real, example is the tendency for analysts to see badness in every single alert that they see. Yes, “presume compromise” is a very real thing that we should be doing, but it is dangerous to see bad actors behind every firewall block. It is far more likely that the analyst is dealing with a misconfigured device. Being willing to slow down, actually perform analysis, and hunt down the offending device is far more valuable than assuming anything weird is bad. (aside: this is why I highly recommend ops experience for security analysts – when you’ve seen the crazy things admins do to get systems working, you are more willing and able to triage those cases appropriately)
As a parting volley, Carl stresses the difference between conception and execution. To illustrate: many organizations are fans of “playbooks”. These are pre-built plans that walk an organization through their incident response process. They define the actions that should be taken should particular events take place. This is a great theory, but they only work if the team fully believes in them, and feels comfortable executing them when the time comes. If, in the middle of an incident, you think your playbook sucks, you’re going to start shooting from the hip. This might be the right thing to do, but it is really important to build a playbook that you believe in so that you don’t have to. If execution bears little resemblance to conception, then there may be some information (whether it is about threats, your own capabilities, or what is actually critical to your organization) that you lack. Go find that information!
