DISARMframeworks/DISARM_MASTER_DATA/playbooks.csv
Sara-Jayne Terp 1bc8d88b63 moved to datasets as CSVs
Changed from data held in excelfiles to data held in CSV files.  This gives us a better view of what's changed in the datasets when we push them to git.
2022-08-25 09:50:52 -04:00

10 KiB

1disarm_idobject_idnamesummary
2PB00001C00011Game Mechanics: show examples of fake news and train the user to identify them on the basis of various types of indicators
3PB00002C00011Game mechanics: use a crowd-sourced mechanism so that the public can categorize newly spreading news sources or articles a la Re-Captcha
4PB00003C00012Develop a regulatory body like the CFPB to regulate and enforce regulation for digital organizations.
5PB00004C00012Government regulation
6PB00005C00012Government shutdown.
7PB00006C00017Use a media campaign to promote in-group to out-group in person communication / activities .
8PB00007C00019Spread Infographics & Training Material teaching ways to identify and counter divisive rhetorical techniques and content, by stimulating their sense of outrage at being manipulated. Show them how to address the rhetorical technique rather than the content
9PB00008C00019Twitter hashtags & paid advertising
10PB00009C00019Teach people to identify non-civil/unconstructive conversations and call them out
11PB00010C00019Popularize (via memes, infographics) and get the centrists demographic who are tired of polarization to identify such messaging, call it out and display their outrage on the basis of divisive rhetorical techniques rather than merely arguing about the content
12PB00011C00027Recruit respected thought leaders to model behavior
13PB00012C00027Feature established respected thought leaders to model behavior
14PB00013C00027Promote dialog from communities with disparate viewpoints
15PB00014C00027Establish facilitation guidelines for "civil" interaction.
16PB00015C00029Identify ignorant agents (ex: anti-vaxx people willing to pay money to advertise their cause)
17PB00016C00029Sell physical merchandise that has instructive counter-effect
18PB00017C00029Secondary Objective: Obtain real-life identity of ignorant agents, to further disrupt their influence activities
19PB00018C00031Create multiple versions of the narrative and amplify.
20PB00019C00031Dissect narrative, piecemeal the components and then amplify
21PB00020C00032Hijack hashtag and redirect conversation to truth based content.
22PB00021C00032Hijack (man in the middle) redirect from bad content to good content
23PB00022C00036-Discredit via backstopped blogs/websites showing their past activity and opinions as being opposite to their current ingroup
24PB00023C00036Create a trail of commentary about their idea of infiltrating the enemy (current in-group)
25PB00024C00036Publicize this by targeting their in-group competitors (ignorant agents)
26PB00025C00040Verify personal credentials
27PB00026C00040Syndicated reputation management (fact-checking syndication)
28PB00027C00040Academia ISAO
29PB00028C00044Rate restrict via regulation posting above a statistical threshold
30PB00029C00044Unless account is de-anonymized and advertised as automated messaging
31PB00030C00048Identify the accounts, the real person's name and shame them on social media.
32PB00031C00053Social media companies remove inactive accounts
33PB00032C00053Account holders remove accounts they're no longer using.
34PB00033C00053Influencers encourage people to remove their inactive accounts "Do you really need that old account" campaign, world-war-two poster-style.
35PB00034C00053Create alternative memorial websites for accounts of deceased people, so their accounts can't be reactivated on 'live' sites.
36PB00035C00053Educate/scare users on the risks of losing control over a dormant account (would their employer be forgiving if an account associated with the user suddenly starting posting extremist content?).
37PB00036C00074Platform adds a hash of the post to the post metadata and make it publicly available (content addressing). Scrape for duplicate content and deplatform the content/users across affected. In all cases some checks need to prevent deplatforming of highly correlated organic traffic such as a community group copy/pasting their bake sale advert.
38PB00037C00074Platform adds plagiarism score metadata to a post and makes it publicly available. Scrape for duplicate content and deplatform the content/users across affected platforms.
39PB00038C00074Use message hashing and fuzzy hashing to detect identical/similar content.
40PB00039C00074Use plagiarism algorithm to detect similar blog posts.
41PB00040C00074Use basic web scraping techniques, Google dorks, etc to identify similar head lines, uniques phrases, authorship, embedded links and any other correlating data point.
42PB00041C00098Affected person contacts platform for action
43PB00042C00136Work with platform to identify active target audiences through finanical data and messaging.
44PB00043C00136Use a platform's publicly available advertising/targeting capabilities to enumerate a list of possible microtargeted demographics. Compare these to known TAs of past/ongoing influence ops to identify the vulnerable demographics.
45PB00044C00140DDoS adversary link shorteners by spamming real links.
46PB00045C00140Compromise service and reroute links to benign content or counter messaging.
47PB00046C00148Degrade TA engagement using bots; direct the adversary to engage insular bot communities-within-communities rather than the authentic target audience.
48PB00047C00148Degrade MOEs/MOPs by faking inter-community sharing.
49PB00048C00149Distort TA demographics by posting irrelevant content, misleading demogaphic data, etc.
50PB00049C00149Work with the media platform to distort publicly available metrics. Can we work with Twitter to get crappy off-brand memes artificially bumped without needing to create fake accounts, etc.?
51PB00050C00149Use adtech to promote content inconsistent with TA demographics. If the adversary is reverse engineering a groups demographics by analyzing ads placed on the platform/group, by spamming ads for out-group stuff it may distort analysis of the group.
52PB00051C00149Distort Google Trends and other publicly available source of metrics using bots, cyborgs, adtech.
53PB00052C00149Distort TA emotional response to content/narratives.
54PB00053C00149Promote damp squibs. Within a known TA promote/inflate crappy off-brand memes which are unlikley to resonate.
55PB00054C00149Detect early trending/engagement and undermine the content by responding with 5Ds, toxic community behaviour, satirical responses, etc.
56PB00055C00149If adtech is used, fake clicks and engagements on the content.
57PB00056C00174Elected officials lead return to First Amendment norms that embrace free and fair media as central to democracy.
58PB00057C00188TechCamp bringing together local journalists, with a several-day training program that includes a sponsored yearlong investigative project
59PB00058C00197Create a standard reporting format and method for social platforms for reporting false accounts.
60PB00059C00197Determine whether account might be compromisedQuestions: - Is the account compromised? - Is it known to be associated with threat actors - common/random name - Names violate terms of service - Dormant account - Change of country IP - Social network growth patterns (number of friends etc) - Evidence of linguistic artifacts (multiple fingerprints, terms/idiosyncrasies ) - Community vs. narrative vs. individuals
61PB00060C00197Report suspected bots.
62PB00061C00197Report ToS violations. In all playbooks the platform must force user verification, credential reset and enable MFA. Suspend the account if it cannot be verified.
63PB00062C00197Use sites like https://haveibeenpwned.com to detect compromised and at risk user accounts.
64PB00063C00197Monitor for unusual account usage (use of VPN, new geographic location, unusual usage hours, etc).
65PB00064C00197Detect sudden deviation in user sentiment such as suddenly dropping hashtags linked to extremist content.
66PB00065C00197Purchase "likes", "retweets" and other vehicles which identify a bot and/or hijacked account. Ban the account.
67PB00066C00197Detect hijacked account and spam their posts. "OP is a known disinformation bot. http://link.to.proof[.]com"
68PB00067C00219Add date and source to images
69PB00068F00002Develop a baseline virality per platform, monitor trends, trigger alert for anomalies.
70PB00069F00003Destroy Desire to Work for Propaganda Businesses -Identify non-committed actors (ie. IRA 2$/h employees) -Identify where they reside (ie. postal code level) -Send a viral message that clarifies the risk of working in influence ops.
71PB00070F00003Hack personal accounts -Send inflammatory messages on their behalf
72PB00071F00004Identify target and entice individual to reveal insider information
73PB00072F00005-Model communities on the basis of behavior and identity, etc -Model different online behaviors in terms of how these groups interact with propaganda -Model how these group-based behaviors are affected by the tech platform they are using -This research can feed into later-stage playbooks to adapt them to communities/platforms
74PB00073F00006Model each major platformDetermine: a) Moderation Method (global, subcommunity level, none -ie. twitter, reddit, 8chan) b) Access Model (friend request, open, real-life identity) c) Communication Model (global, friends only, subcommunity, hybrid) Determine how the combination of the above (and other characteristics) allow different technical methods to communicate and influence various audiences This will allow to adapt playbooks to specific platforms
75PB00074F00013- Trace money and financing - Trace connections to known operations
76PB00075F00014- Hashes - Data voids - User handles - Domains + link shortener - TinEye For video (visual artifact)
77PB00076F00017Create standard scoring for emptional content
78PB00077F00018Ad tech - De-platform funding sites - Blockchain transaction - Sell items - Identify manufacturers - Pay to play meetings
79PB00078F00018Identify ad tech on platforms - Selling merch? - Financial platform - Bitcoin etc.. .
80PB00079F00018Identify re-use of ads Look at Ad trackers, Tracking ids, Tracking ads, Re-use of as features (language, name, themes, plug-in, re-use/versions)
81PB00080F00018track funding sources
82PB00081F00077Build and update a model bot behaviour.
83PB00082F00077Build network of companies that model / rate bots. Build standards around data sharing and exchange
84PB00083F00092Build a reporting system for the public, so they can report disinformation artefacts and have them available to channels etc for action.