Mr Ben Nimmo – written evidence (DAD0089)

 

Disinformation: Detecting Operations, Defining Norms, Deterring Threats

Ben Nimmo, Director of Investigations, Graphika

 

Deception online and avenues of response

 

Online deception and influence campaigns come in many forms and are conducted for many reasons. Their variety and the speed at which they evolve mean that the responses to such campaigns have to be flexible and collaborative, with different actors – social-media platforms, operational researchers and official bodies – each contributing in different but complementary ways.

 

The current situation is radically different from that in 2016, and has improved significantly, but further improvements are needed in three core areas: detecting threat actors at an early stage, defining social and legal norms to guide cross-platform enforcement, and deterring future malicious behaviour. Political leadership can play an important role in defining norms and deterring future threats. 

 

The scope of the challenge

 

Deceptive online campaigns vary widely.  They can include companies or groups running large numbers of fake accounts that they rent out as followers to social-media users who want to look important,[1] or using fake accounts to post positive reviews of their own products.[2] They can include scammers who post political content to make their readers click on pay-per-click advertising sites[3] or pornography sites,[4] or who try to defraud readers with fake personas, subscription offers or hard-luck stories.[5]

 

They can also include media outlets that create networks of fake accounts to promote their content,[6] and “black PR” firms that create similar networks to promote political or business clients.[7] They can include opaque, pro-state groups who run fake accounts to drive users towards propaganda websites,[8] or who post propaganda on the social-media platforms themselves.[9]

 

On a more individual level, they can include operations that set up fake personas, often posing as journalists or activists, to promote their own narratives or discredit their opponents.[10] They can even include smear campaigns from state-run media,[11] attacking critics with false or distorted claims that are then amplified by genuine users, some of whom may not know that they are boosting state-funded messaging.[12]

 

Making the challenge even more complex, sophisticated influence operations can combine different elements. For example, clickbait websites which are only aimed at making money can use political content to attract attention.[13] Political operators can use apparently commercial “bots”[14] for amplification[15] or intimidation.[16] Commercial companies can rent out entire campaigns aimed at political influence.[17] Thus, deceptive operations online do not fall into discrete sections, but form a continuum, with different operations characterised by different combinations of tactics, and often working across many different platforms.[18]

 

The main connecting feature between such operations is falsehood, but even that falsehood can play out in different ways. Many operations use fake assets, ranging from individual social-media accounts to entire websites that purport to be legitimate news sources.[19] Some promote false information or doctored leaks[20] on real channels.[21] Some use false personas to leak genuine documents aimed at discrediting their targets.[22] Some operations avoid falsehood entirely and focus on promoting one-sided coverage of key events, omitting key voices rather than falsifying the facts.[23]

 

The complexity of this situation is, as yet, poorly understood by the general public. The last three years have seen a significant increase in the volume of reporting on issues such as bots, troll farms, and profile pictures generated by artificial intelligence, but some of this reporting has been overly dramatized and tended to create confusion rather than clarity. One key long-term need is for greater media and public understanding of the different scale, significance and likely impact of different online operations.

 

Detecting false behaviour patterns

 

When trying to expose influence operations, the first challenge is to detect them. The social-media platforms carry the primary responsibility for detecting malicious activity on their platforms, but independent researchers and appropriate governmental agencies also have a part to play. This is not an area where it would be appropriate for elected officials to play a direct role, but legislation can help to shape the environment in which investigators work, and can hold the social-media platforms to account, making sure that they have the processes in place to learn and implement the lessons of recent years.

 

The year 2016 was the nadir in terms of detection. The Russian operation that targeted U.S. politics that year successfully registered a Twitter account posing as a Tennessee Republican to a Russian mobile-phone number[24] and paid for political ads on Facebook with Russian roubles,[25] and still managed to operate into late 2017. Since 2018, however, Twitter, Facebook and Google have significantly ramped up their detection and disruption efforts, announcing takedowns of information operations from areas diverse as Central America,[26] Europe,[27] the Middle East,[28] China,[29] the United States and Vietnam.[30] At the same time, they have instituted changes designed to make information operations harder to run and easier to spot: for example, Twitter has cracked down on mass automation of posts, while Facebook now routinely shows which country pages with a significant following are managed from.

 

Platforms are working increasingly closely with external investigators, including the author of this paper, to expose multi-platform operations. In May 2019, Facebook detected a Russian operation on its platform and shared its findings with the Atlantic Council’s Digital Forensic Research Lab (DFRLab).[31] The DFRLab investigation found that the operation spread across over 30 other platforms, including a number of German and Austrian sites.[32] In November, Reuters and Graphika demonstrated that a separate leak of UK-US trade documents had originally been posted on some of the same sites, using the same techniques to evade detection.[33] Platforms including Medium and Reddit provided further insights, and finally Reddit attributed the amplification of the trade leaks back to the Russian operation,[34] and exposed almost 40 more accounts that the Russian operation had also run.[35] The Russian operation ran across many platforms: it took insights from many different investigators to expose its full scope.

 

Many of the recent takedowns were the result of internal investigations by the platforms, but some were triggered by external researchers: for example, a large-scale Iranian operation across multiple platforms and websites was first exposed by investigators at cyber-security firm FireEye.[36] Just before the mid-term elections in the United States in November 2018, the FBI tipped off the platforms that it had found a live Russian operation on their services, triggering an instant investigation and takedown.[37]

 

When external researchers find online operations before the platforms do, it is often seen as proof that the platforms need to improve their detection capabilities. This is, in fact, a standing challenge: platforms will always need to do more and do it better, because the more persistent malicious actors respond to takedowns and platform changes by searching for new ways to stay hidden.[38]

 

This operational detection and exposure of information operations is not an area where parliamentary or government intervention can or should play a direct role. However, regulation could play a supporting role. Based on the White Paper on Online Harms, one role for an independent regulator could be to ensure that all platforms above a certain size have processes in place to quickly investigate potential influence operations on their properties, and processes to learn the lessons from previous operations so that they become better at spotting repetitive tactics. This would be especially important as social-media platforms become more diverse, with major platforms headquartered in countries other than the U.S.

 

Regulation could also help to ensure that the legal framework promotes and enables cooperation between platforms and external investigators,[39] including how to share information and data.[40]

 

The framework would need to work along three vectors: ensuring that platforms provide appropriate information and data to researchers; ensuring that researchers adhere to professional standards and do not, for example, sell on data or violate innocent users’ privacy; and ensuring that the legal framework is sufficiently flexible to allow platforms and researchers to share information about accounts that are suspected of conducting information operations, without the fear of violating regulations such as GDPR. These are complex issues, as they seek to reconcile the need for transparency with the need for privacy, but the debate is necessary to provide a foundation for cooperation between multiple different platforms and research groups.

 

Defining the terms

 

Parliamentary and governmental leadership have more potential when it comes to the question of establishing norms for acceptable behaviour. At present, each platform has its own terms of service and its own interpretation of them, and behaviour which would be considered a violation on one platform can be considered acceptable on another. Given the nature of the different platforms and the vital importance of avoiding any erosion of freedom of speech, this patchwork will continue, but political leadership could help promote the creation of a core of shared norms and define the scope of acceptable behaviour, especially in political campaigning.

 

This will require political leadership by deed as well as by word. As a bare minimum, political parties and candidates should clearly articulate their own standards of online transparency – for example, stating that they will not use fake accounts or inauthentic amplification, and will not tolerate the use of such activity on their behalf, including by political consultancies. The ability of political leaders to set the tone of the debate, and to act as models of good behaviour, or of justification for bad behaviour, should not be underestimated.

 

Political leadership could also promote research into, and discussion of, the question of how norms of behaviour are created - that is, how to arrive at a set of informal but broadly agreed standards of online behaviour that do not rise to the level of legislation. Social media could be seen as representing, in effect, the emergence of new societies in which citizens interact in new ways; as such, the ongoing debate over standards of online behaviour could be seen as a search for new social norms within those societies. Research into the creation of such norms in other social settings could shed light on how abusive and threatening behaviour can be minimised by means other than the purely legislative.

 

Finally, regulators could also play a role in providing clear guidelines over how terms such as abuse, harassment and incitement to harassment are to be interpreted as they apply to online speech. Reports of public figures, and some private ones, leaving social media because of harassment remain a regular feature of internet coverage, and abuse against investigators, journalists and human-rights defenders remains a grave concern.[41] Freedom of expression is a vital component of democracy and must be protected, but hate campaigns against public figures are themselves aimed at stifling free speech. Without clear guidelines in place, enforcement is always likely to remain ad hoc and patchy. Providing a clear framework would potentially enable the platforms to take action more quickly and more consistently.

 

Deterrence

 

A final role for regulation could be in the realm of deterrence. In general, the strongest sanction a social-media company can take against malicious actors in the information space (as opposed to actual criminal activity) is to shut down all their accounts and ban them from the platform. This disrupts the operation, but it does not prevent the operators from trying again: Russia’s Internet Research Agency, for example, had at least five successive sets of assets taken down between September 2017 and October 2019.[42]

 

Platforms cannot impose direct financial or organisational costs on groups which conduct information operations or sell fake engagement online: as such, the platforms have a strong disruptive power, but very little deterrent power. This is an area where official action could conceivably play a deterrent role.

 

In November 2019, the US Federal Trade Commission for the first time fined a US-based company for selling fake followers and likes on social media, arguing that this empowered the company’s clients to deceive potential investors, partners and employees, and thus constituted an illegal deception.[43] It is too early to say what effect this ruling will have on the trade in fake accounts in the US; the company itself went bankrupt after the New York Times exposed it in 2018.[44] However, legislation that imposes an increased cost on fake-account operators, as selling a non-existent product (engagement from “people” who do not exist), would have the potential to deter some operators, at least those based domestically, narrow down information operators’ access to false amplification, and signal the political will to address the problem.

 

Political will could also reinforce the UK’s ability to deter covert foreign influence attempts, such as the Russian amplification of the US-UK trade leaks during the 2019 election. At present, information and interference operations are a low-cost and deniable activity for foreign states, and they are often perceived as having a huge potential impact. (This perception is exaggerated, but persists.) As such, they are likely to remain attractive.

 

UK government policy could aim at reinforcing the national ability to detect and attribute foreign information operations, and to increase the costs of such operations via a range of political, diplomatic and economic sanctions. These should look beyond targeting the operators and their immediate sponsors, and consider ways to increase the cost for the ultimate beneficiary of the operation, if this is a foreign government. This is an area where political will and diplomatic determination will be crucial.

 

Ultimately, the UK’s ability to deter future interference will require action across multiple policy areas, including diplomacy and law enforcement, to address not just the platforms where information operations are conducted, but the operators behind them.

2

 


[1] Nicholas Confessore et al, “The Follower Factory”, New York Times, January 27, 2018, https://www.nytimes.com/interactive/2018/01/27/technology/social-media-bots.html.

[2] See the case of Sunday Riley in Federal Trade Commission, “Devumi, Owner and CEO Settle FTC Charges They Sold Fake Indicators of Social Media Influence; Cosmetics Firm Sunday Riley, CEO Settle FTC Charges That Employees Posted Fake Online Reviews at CEO’s Direction”, FTC, October 21, 2019, https://www.ftc.gov/news-events/press-releases/2019/10/devumi-owner-ceo-settle-ftc-charges-they-sold-fake-indicators.

[3] Craig Silverman and Lawrence Alexander, “How Teens In the Balkans Are Duping Trump Supporters With Fake News”, Buzzfeed, November 3, 2016, https://www.buzzfeednews.com/article/craigsilverman/how-macedonia-became-a-global-hub-for-pro-trump-misinfo.

[4] Ben Nimmo, “#BotSpot: Sex asnd Sensibility”, DFRLab, June 3, 2018, https://medium.com/dfrlab/botspot-sex-and-sensibility-dc1d4a72a92e.

[5] Chris Dolmetsch, “Facebook-Google Scammer Pleads Guilty in $121 Million Theft”, Bloomberg, March 20, 2019, https://www.bloomberg.com/news/articles/2019-03-20/man-pleads-guilty-in-100-million-scam-of-facebook-and-google.

[6] Paris Martineau, “Facebook Removes Accounts With AI-Generated Profile Photos”, WIRED, December 20, 2019, https://www.wired.com/story/facebook-removes-accounts-ai-generated-photos/.

[7] Shoshanna Solomon, “Facebook bans Israel-based firm that ran campaigns to disrupt elections”, The Times of Israel, May 16, 2019, https://www.timesofisrael.com/facebook-takes-down-network-of-fake-accounts-pages-linked-to-israeli-firm/.

[8] FireEye Intelligence, “ Suspected Iranian Influence Operation Leverages Network of Inauthentic News Sites & Social Media Targeting Audiences in U.S., UK, Latin America, Middle East”, FireEye, August 21, 2018, https://www.fireeye.com/blog/threat-research/2018/08/suspected-iranian-influence-operation.html.

[9] Indictment 1:18-cr-00032-DLF, “United States of America vs Internet Research Agency LLC and others”, U.S> Department of Justice, February 16, 2018, https://www.justice.gov/file/1035477/download.

[10] Jeffrey St. Clair and Joshua Frank, “Go Ask Alice: the Curious Case of ‘Alice Donovan’”, Counterpunch, December 25, 2017, https://www.counterpunch.org/2017/12/25/go-ask-alice-the-curious-case-of-alice-donovan-2/.

[11] Olivia Solon, “How Syria's White Helmets became victims of an online propaganda machine”, The Guardian, December 18, 2017, https://www.theguardian.com/world/2017/dec/18/syria-white-helmets-conspiracy-theories.

[12] Ben Collins and Joseph Cox, “Jenna Abrams, Russia’s Clown Troll Princess, Duped the Mainstream Media and the World”, The Daily Beast, November 3, 2017, https://www.thedailybeast.com/jenna-abrams-russias-clown-troll-princess-duped-the-mainstream-media-and-the-world.

[13] Craig Silverman and Lawrence Alexander, “How Teens In the Balkans Are Duping Trump Supporters With Fake News”, Buzzfeed, November 3, 2016, https://www.buzzfeednews.com/article/craigsilverman/how-macedonia-became-a-global-hub-for-pro-trump-misinfo.

[14] A bot, in this context, is a social-media account automated to perform prescribed tasks without human intervention.

[15] Ben Nimmo, “Robot Wars: How Bots Joined Battle in the Gulf,” Journal of International Affairs, September 19, 2018, https://jia.sipa.columbia.edu/robot-wars-how-bots-joined-battle-gulf.

[16] Ben Nimmo, “#BotSpot: The Intimidators”, DFRLab, August 30, 2017, https://medium.com/dfrlab/botspot-the-intimidators-135244bfe46b.

[17] Nathaniel Gleicher, “Removing Coordinated Inauthentic Behavior in UAE, Egypt and Saudi Arabia”, Facebook, August 1, 2019, https://about.fb.com/news/2019/08/cib-uae-egypt-saudi-arabia/.

[18] The Russian-based operation “Secondary Infektion” operated across more than 30 different platforms. See DFRLab, “Top Takes: Suspected Russian Intelligence Operation”, DFRLab, June 22, 2019, https://medium.com/dfrlab/top-takes-suspected-russian-intelligence-operation-39212367d2f0.

[19] Lawrence Alexander, “Open-Source Information Reveals Pro-Kremlin Web Campaign”, Global Voices, July 13, 2015, https://globalvoices.org/2015/07/13/open-source-information-reveals-pro-kremlin-web-campaign/.

[20] Josh Halliday, “Daily Mail in £100,000-plus payout over Syrian chemical weapons story”, The Guardian, June 26, 2013, https://www.theguardian.com/media/2013/jun/26/daily-mail-syrian-chemical-weapons-libel.

[21] George Leopold, “Fake Russian EW attack unmasked”, Defense Systems, May 12, 2017, https://defensesystems.com/articles/2017/05/12/fakeew.aspx.

[22] Kevin Poulsen and Spencer Ackerman, “ EXCLUSIVE: ‘Lone DNC Hacker’ Guccifer 2.0 Slipped Up and Revealed He Was a Russian Intelligence Officer”, The Daily Beast, March 22, 2018, updated October 25, 2018, https://www.thedailybeast.com/exclusive-lone-dnc-hacker-guccifer-20-slipped-up-and-revealed-he-was-a-russian-intelligence-officer.

[23] “Ofcom fines Russian news service £200,000 over impartiality”, BBC News, July 26, 2019, https://www.bbc.co.uk/news/entertainment-arts-49126466.

[24] Luke O’Brien, “Twitter Ignored This Russia-Controlled Account During The Election. Team Trump Did Not.”, Huffington Post, November 1, 2017, https://www.huffingtonpost.co.uk/entry/twitter-ignored-this-russia-controlled-account-during-the-election_n_59f9bdcbe4b046017fb010b0.

[25] Olivia Solon and Julia Carrie Wong, “#BlueLivesMatter and Beyoncé: Russian Facebook ads hit hot-button US issues”, The Guardian, May 10, 2018, https://www.mercurynews.com/2018/09/04/google-foe-pays-in-rubles-gets-google-to-run-russian-troll-ads/.

[26] Nathaniel Gleicher, “Removing Coordinated Inauthentic Behavior in Thailand, Russia, Ukraine and Honduras”, Facebook, July 25, 2019, https://about.fb.com/news/2019/07/removing-cib-thailand-russia-ukraine-honduras/.

[27] Twitter Safety, “Disclosing new data to our archive of information operations”, Twitter, September 20, 2019, https://blog.twitter.com/en_us/topics/company/2019/info-ops-disclosure-data-september-2019.html.

[28] Nathaniel Gleicher, “Removing Coordinated Inauthentic Behavior in UAE, Egypt and Saudi Arabia”, Facebook, August 1, 2019, https://about.fb.com/news/2019/08/cib-uae-egypt-saudi-arabia/.

[29] Twitter Safety, “Information operations directed at Hong Kong”, Twitter, August 19, 2019, https://blog.twitter.com/en_us/topics/company/2019/information_operations_directed_at_Hong_Kong.html.

[30] Nathaniel Gleicher, “Removing Coordinated Inauthentic Behavior From Georgia, Vietnam and the US”, Facebook, December 20, 2019, https://about.fb.com/news/2019/12/removing-coordinated-inauthentic-behavior-from-georgia-vietnam-and-the-us/.

[31] Nathaniel Gleicher, “Removing More Coordinated Inauthentic Behavior From Russia”, Facebook, May 6, 2019, https://about.fb.com/news/2019/05/more-cib-from-russia/.

[32] DFRLab, “Top Takes: Suspected Russian Intelligence Operation”, DFRLab, June 22, 2019, https://medium.com/dfrlab/top-takes-suspected-russian-intelligence-operation-39212367d2f0.

[33] Jack Stubbs, “Leak of papers before UK election raises 'spectre of foreign influence' - experts”, Reuters, Deember 2, 2019, https://uk.reuters.com/article/uk-britain-election-foreign/leak-of-papers-before-uk-election-raises-spectre-of-foreign-influence-experts-idUKKBN1Y6206; Ben Nimmo, “UK Trade Leaks”, Graphika, December 2, 2019, https://graphika.com/reports/UK-trade-leaks/.

[34] u/worstnerd, “Suspected campaign from Russia on Reddit”, Reddit Security, December 6, 2019, https://www.reddit.com/r/redditsecurity/comments/e74nml/suspected_campaign_from_russia_on_reddit/.

[35] Ben Nimmo, “New Findings and Insights from a Known Russian Operation”, Graphika, December 17, 2019, https://graphika.com/reports/uk-leaks-and-secondary-infektion/.

[36] FireEye Intelligence, “ Suspected Iranian Influence Operation Leverages Network of Inauthentic News Sites & Social Media Targeting Audiences in U.S., UK, Latin America, Middle East”, FireEye, August 21, 2018, https://www.fireeye.com/blog/threat-research/2018/08/suspected-iranian-influence-operation.html.

[37] Sheera Frenkel and Mike Isaac, “Russian Trolls Were at It Again Before Midterms, Facebook Says”, New York Times, November 7, 2018, https://www.nytimes.com/2018/11/07/technology/facebook-russia-midterms.html.

[38] Joseph Cox, “I Bought a Russian Bot Army for Under $100”, The Daily Beast, September 13, 2017, https://www.thedailybeast.com/i-bought-a-russian-bot-army-for-under-dollar100.

[39] Camille Francois, “Actors, Behaviors, Content: A Disinformation ABC”, Transatlantic High Level Working Group on Content Moderation Online and Freedom of Expression, September 20, 2019, https://www.ivir.nl/publicaties/download/ABC_Framework_2019_Sept_2019.pdf.

[40] In this context, it is important to distinguish information from data. “Information” covers insights into operational activity that do not expose potentially personally identifying features such as IP address and phone number: for example, “this is account is registered to a Russian mobile phone number”. “Data” covers the full range of features, including those which could identify individuals. 

[41] Karl Vick, “The Guardians and the War on Truth”, Time Magazine, December 11, 2018, https://time.com/person-of-the-year-2018-the-guardians/.

[42] The first takedown, in September 2017, was only confirmed in November of that year during Senate hearings into Russian interference. The others were announced at the time of the takedown: Nathaniel Gleicher, “Removing Bad Actors on Facebook”, Facebook, July 31, 2018, https://about.fb.com/news/2018/07/removing-bad-actors-on-facebook/; Nathaniel Gleicher, “Election Update”, Facebook, November 5, 2018, https://about.fb.com/news/2018/11/election-update/; Nathaniel Gleicher, “Removing Coordinated Inauthentic Behavior from Russia”, January 17, 2019, https://about.fb.com/news/2019/01/removing-cib-from-russia/; Nathaniel Gleicher, “Removing More Coordinated Inauthentic Behavior From Iran and Russia”, October 21, 2019, https://about.fb.com/news/2019/10/removing-more-coordinated-inauthentic-behavior-from-iran-and-russia/.

[43] Federal Trade Commission, “Devumi, Owner and CEO Settle FTC Charges They Sold Fake Indicators of Social Media Influence; Cosmetics Firm Sunday Riley, CEO Settle FTC Charges That Employees Posted Fake Online Reviews at CEO’s Direction”, FTC, October 21, 2019, https://www.ftc.gov/news-events/press-releases/2019/10/devumi-owner-ceo-settle-ftc-charges-they-sold-fake-indicators.

[44] Richard B. Newman, “New York Attorney General Announces Precedent-Setting Settlement Over the Sale of Fake Followers and “Likes” on Social Media”, National Law Review, January 31, 2019, https://www.natlawreview.com/article/new-york-attorney-general-announces-precedent-setting-settlement-over-sale-fake.