Definitions Flashcards
(86 cards)
Open Source Data
Rawprint, broadcast, oral debriefing or other form of information from a primary source
Open source information
Comprised of data that is put together by an editorial process that provides some filtering and validation and includes some presentation management that is widely disseminated
OSINT
- Information discovered, discriminated, distilled, and disseminated to a select audience to address a specific question
-Applies the proven process of intelligence to the broad diversity of open sources of information, and creates intelligence
Validated OSINT (OSINT-V)
- Entails a high degree of certainty, usually from an intelligence professional that has classified intelligence sources
- Can also come from an open source where there is no question concerning the validity (i.e. live stream of plane arriving at an airport)
SOCMINT (social media intelligence)
- Collective tools and solutions that allow organizations to monitor social channels and conversations, respond to social signals and synthesize social data points into meaningful trends and analysis
HUMINT (human intelligence)
- Any information from human sources
Example: social engineering, photos, documents, other materials
Definition of OSINT
- Form of intelligence collection management that involves finding, selecting, and acquiring information from publicly available sources to produce actional intelligence
ISTAR Method
Intake & Orientation
Strategy, Search, Store
Technical Capabilities
Analysis
Refine, Recycle, Reporting
What is north america’s IP block
ARIN
What is south america’s IP block
LACNIC
What is asia pacific’s IP block
APNIC
What is Europe’s IP Block
RIPE NCC
What is Africa’s IP Block
AfriNIC
What are the information needs for Data Collection
Event (incident, accident, disaster)
Thematical (drugs on internet, online gambling, soccer)
Organization (company, group, organization)
Person (suspect, profiling, location)
What is SIS method
Short internet scan
- quick and dirty method of searching for information
- minimum amount of time
- no plan
What is the through search method
ISTAR
What is the I in ISTAR
Intake
-who, what, where, when, why, what way, with what
What is the S in ISTAR
Search
- use different building blocks to search, build off what is found
What is precision
measure of exactness
What is recall
measure of completeness
What is the relationship between recall and precision
inversely related (increase of precision, decreases recall/results)
What can influence recall/search results
Avoid using words with double meanings
insufficiently specific keywords
synonyms
variations of spelling
What techniques/tools be used for documentation?
use automation
store data so visible offline/later date
remember risk factors during searches
What is the R in ISTAR
Refine, Recycle, Report
-refine keyword list
-recycle GUIDs
-report on all stored data