Thursday, April 16, 2009

What Is Game Theory

David K. Levine
Department of Economics, UCLA


Summary
Game theory provides a simple representation of a variety of important situations. There are two main branches of game theory: cooperative and noncooperative game theory. David Levine of UCLA defines noncooperative game theory as “dealing largely with how intelligence individuals interact with one another in an effort to achieve their own goals.” Noncooperative game theory is the subject of Levine’s article. (Note: Levine does not define cooperative game theory).

One way to approach a noncooperative game is to list the players and their respective alternative choices (called actions or strategies) available. Consider for example the game Prisoner’s Dilemma. In the case of this two-player game, the actions of one player form the rows of a matrix while the opposing player’s actions from the columns. The entries into the matrix represent the utility or payoff to the two players. (Note: Levine does not discuss how he derived the values).

Higher numbers represent higher values in utility. If neither suspect confesses, both prisoners (or players) go free and split the proceeds of their crime (represented by a value of 5). If one player confesses and the other does not, however, the prisoner who confesses testifies against the other in exchange for going free and gets the entire value of 10 utility points; while the other player who did not confess goes to prison, resulting in the low utility score of -4. If both prisoners confess, then both are given a reduced term, but are convicted, which is represented by a utility value of 1.

An intelligent player of the game should quickly understand that no what he/she believes that his/her opponent will do, it is always better to confess. If the partner in the other cell is not confessing, it is possible to get a 10 instead of a 5. If the partner in the other cell is confessing, it is possible to get a 1 instead of a -4.

Author's Note: Levine offers a second example in which he examines the question, ""If we were all better people the world would be a better place." Although the discussion was interesting (Levine disproves the statement), the discussion was not helpful in understanding the dynamics of game theory.
Reblog this post [with Zemanta]

Wednesday, April 15, 2009

Game Theory

M. Shane Smith

Summary:
According to the author, "Game theory provides analytical tools for examining strategic interactions among two or more participants." By using game theory, analysts can gain insight into social relations between individuals and, by extension, states. Individuals and state actors are trying to fulfill goals that provide them with the best possible outcome, however the best possible outcome for one actor may be the worst for another; thus game theory is a tool that can be used to develop strategies to be applied when dealing with multiple actors who have multiple interests. "Just as we may be able to understand the strategy of players in a particular game, we may also be able to predict how people, political factions, or states will behave in a given situation."

Five elements of game theory as an analytic tool are highlighted:
  1. players, or decision makers;
  2. strategies available to each player;
  3. rules governing players' behavior;
  4. outcomes, each of which is a result of particular choices made by players at a given point in the game; and
  5. payoffs accrued by each player as a result of each possible outcome.
Game theory assumes that each player will pursue a course that brings them the greatest reward, and that by cooperating with other players, everyone can reach a mutually beneficial outcome. This is not always the case, however, as mutual distrust may hinder the advancement of beneficial interests and interfere with cooperation. This may send actors down a path that leads to a mutually destructive outcome. The author provides the example of the US vs USSR during the Cold War:
"For example, deterrence theory has guided U.S. defense strategy since the end of World War II. It assumes that a credible and significant threat of retaliation can curb an aggressor's behavior; if an individual believes that aggressive behavior may trigger an unacceptable and violent response from others, he or she is less likely to behave aggressively. The threat of reprisal does not directly reduce the probability of violence; instead, the perceived benefit of aggressive behavior decreases, in the face of probable retaliation. If two individuals recognize that their best interests lie in avoiding each other's retaliation, neither is likely to initiate hostilities. This was the guiding principle behind U.S.-Soviet relations during much of the Cold War."
Ultimately both sides cooperated to come to a mutually beneficial outcome; however, had serious distrust led to each side independently pursuing what was best for them, the conclusion may have been nuclear annihilation for both.

The use of game theory allows us to identify both best case scenarios, as well as worse case scenarios, and pursue a path that is mutually beneficial to all actors. "Since games often reflect or share characteristics with real situations -- especially competitive or cooperative situations -- they can suggest strategies for dealing with such circumstances."

Terrorism & Game Theory

Todd Sandler and Daniel G. Arce M., Simulation Gaming 2003; 34; 319

Summary:
The authors postulate that game theory is a useful tool to analyze both the actions of terrorists and a government's response to terrorism. Terrorists respond to how governments respond to them, and vice versa; thus by using game theory to study terrorism, the analyst may be able to come to some conclusions as to which actions are appropriate for a government to take to mitigate the threat of terrorism.

The article highlights 6 reasons why game theory is appropriate to the study of terrorism:
  1. Game theory captures the strategic interactions between terrorists and a targeted government, where actions are interdependent and, thus, cannot be analyzed as though one side is passive.
  2. Strategic interactions among rational actors, who are trying to act according to how they think their counterparts will act and react, characterize the interface among terrorists (hardliners vs. moderates) or among alternative targets (various governments).
  3. In terrorist situations, each side issues threats and promises to gain a strategic advantage.
  4. Terrorists and governments abide by the underlying rationality assumption of game theory, where a player maximizes a goal subject to constraints.
  5. Game-theoretic notions of bargaining are applicable to hostage negotiations and terrorist campaign-induced negotiations over demands.
  6. Uncertainty and learning in a strategic environment are relevant to all aspects of terrorism, in which the terrorists or government or both are not completely informed.
As an example of using game theory to re-assess a governments policy towards terrorism, the article investigates the usefulness of the "no-negotiation" policy. The logic of the no-negotiation policy is that terrorists will not take hostages if there is nothing to gain from the undertaking, i.e. a government will not concede to their demands. By using game theory to develop a model of this policy, however, it becomes quickly apparent that the policy is of little value in deterring terrorists. Terrorists may still perceive the taking of hostages as beneficial to them for a variety of reasons, "If a sufficiently important person is secured, then the government may regret its no-negotiation pledge because the expected costs of not capitulating may exceed that of capitulating...Even when the government's pledge not to negotiate is believed by the terrorists, a fanatical group may still engage in a hostage mission when a positive payoff is associated with either a logistical or negotiation failure by advertising the cause or achieving martyrdom...The effectiveness of the no-negotiation policy hinges on the credibility of the government's pledge, the absence of incomplete information, the terrorists' gains being solely tied to a negotiation success, and sufficient deterrence spending to eliminate logistical success."

Game theory also exposes a paradox in the cooperation of governments in response to terrorism. "Although the US is the target of approximately 40% of all transnational terrorist attacks, virtually all of these attacks occurred abroad in recent years [prior to 2003], with 9/11 being a noticeable exception. US over deterrence means that it experiences attacks where it has little authority to do anything about them." Also highlighted is the seemingly contradictory effect that as nations share intelligence on terrorists to increase deterrence, they in fact "transfer the attacks abroad." By not sharing intelligence AND coordinating deterrence, nations "waste resources without necessarily increasing security."

Ultimately, game theory exposes flaws in policies that may not deter terrorist attacks as well as initially perceived By addressing these flaws, decision-makers can make their respective counterterrorism policies more effective.

Authors Comment: This article recommends game theory as a tool to reassess policy, which is not the role of the intelligence analyst. However, by using game theory in tandem with a knowledge of our own policies towards terrorism, the intelligence analyst may be able to better forecast where an attack is likely to occur (whether at home or abroad), the modus operandi of the attack, and perhaps what terrorists are trying to achieve. According to game theory, terrorists will always seek the highest payoffs for them, and thus the analyst can seek to identify these payoffs, how they are likely to be achieved, and inform the decision maker as to how to best prevent their achievement.

Summary Of Findings: Red Teaming (2 Stars Out Of 5)

Note: This post represents the synthesis of the thoughts, procedures and experiences of others as represented in the 12 articles read in advance of (see previous posts) and the discussion among the students and instructor during the Advanced Analytic Techniques class at Mercyhurst College on 15 APR 2009 regarding Red Teaming specifically. This technique was evaluated based on its overall validity, simplicity, flexibility and its ability to effectively use unstructured data.

Description:
Red Teaming is an analytical modifier that can be used in two distinct ways:

First, in an objective sense, it is used to challenge emerging operational concepts in order to discover weaknesses with an organization's procedures and reactions.
Second, in a subjective sense, red teaming is used to generate options for adversaries that may be overlooked due to biases or heuristics.
When red teaming is used in the first manner, the effectiveness of red teaming is usually easier to monitor and evaluate. When using the second approach, it is more difficult to measure the effectiveness of red teaming, as the effectiveness is subject to forces outside of the method itself.

Strengths:
*Forces "thinking outside the box"
*Challenges "groupthink"; may reduce bias
*Can provide invaluable near-real world training (as close to real world as possible)
*Can identify previously unknown threats and gaps in security
*Can provide a diverse outlook on a problem
*Can identify new uses for innovations

Weaknesses:
*No textbook way to conduct red teaming
*Can verge on science fiction
*Red Team can be marginalized
*Results can be ignored by SME if non-SME conduct the exercise
*Red Team may pursue path of least resistance and not take the excercise seriously
*Participants must fully understand culture of the Red Team they are playing to make the most of the excercise
*Requires leadership committed to making changes based on the recommendations of the Red Team
*Memebers of the Red Team may be of a poor quality and thus negate the usefullness of the exercise
*May be used to politicize intelligence ( see The Power of Nightmares)
*No particular guidance on how many team members are needed to function optimally
*Does not always allow creativity
*Excercise can be stifled by rules and parameters set up to "prove a point"
*Can be subject to "groupthink" within the Red Team

How To:
**A hodgpodge of instructions exist on how to conduct red teaming exercises. The "How To" is largely dependent upon the type or form of red teaming being executed.

1)Populate team (can be composed of subject experts or outside consultants chosen for other unique skills/qualities)
2)Receive tasking or objective from management
3)Assume the role assigned with particular consideration of the limitations imposed on the team (cultural, technological, equipment, etc.)
4)Provide the red team with the necessary independance and credibility to challenge existing norms and ideas and suggest "outside the box" ideas.
5) Execute tasking or exercise.
6)Disseminate and if necessary advocate the key findings to the person excercising control over both the red and blue teams.

Experience:
In order to gain a better understanding of the process of red teaming, the group played a conflict simulation game, "Strike Force One". The game is a simple computer-based simluation used to recreate a combat situation in a key area of West Germany during the Cold War. One player, in this case the computer (AI), advances as the Soviet Army, and the human user takes the role of US Army forces defending key towns on the grid. Movement takes place on a board of "hexes" and the result of the combat is determined by simulated die rolls, as any common combat board game. The group "red teamed" the anticipated movements of the enemy forces, but was ultimately defeated by the Soviets.
Here are some of our experiences:
*Team members dissented over the most likely movements of advesaries - illustrating the multitude of options available for these adversaries.
*Relatively easy to anticipate the adversary's general movements, but more difficult to anticipate which specific move he would choose; but combat results are not entirely predictable.
*Team still had the US Army's interests in mind; not able to fully think like the adversary.

Monday, April 13, 2009

Red Teams: An Audit Tool, Technique and Methodology for Information Assurance

http://www.isaca.org/Template.cfm?Section=Home&CONTENTID=30762&TEMPLATE=/ContentManagement/ContentDisplay.cfm
by Frederick Gallegos & Matthew L. Smith

With businesses and organizations increasingly dependent on information systems in everyday practice, a large responsibility is placed on the involved organizations and government legislation to ensure the safety and security of private customer information. This publication seeks to address the growing risks threatening information security, by employing the tactic of red teaming.

Red teaming is a valuable tool for information security auditors to directly identify new and emerging security threats within an organization, allowing them to provide evidence to support modifying that organization's security system and practices. This article describes the use of "white-hat hackers" to infiltrate the system, exposing and exploiting system vulnerabilities for the purpose of developing actionable evidence for system modifications. It is important that these individuals are obtained externally, so they have no pre-existing knowledge of the organization's network and its security infrastructure. Employing external , uninformed individuals to execute this "test" is a good way to obtain unbiased evidence of system weaknesses.

The red team should be made up of SMEs well-versed in computer forensics. In an IS red teaming exercise, the team will test four main areas of an information system: operating system/platform security, networks/communications; applications/decision processes; policies, passwords, permissions. Additionally, a training path should be developed for the red team members, and they should provide a record of observations and practices in a database for other team members to share.

Case Study: Red Teaming Iran's Supreme Leader

http://belfercenter.ksg.harvard.edu/publication/18216/case_study.html
by Graham Allison

This article is the memorandum for a case study used in Graham Allison's class, "Central Challenges of America's Foreign Policy ". The memorandum used in this case study requires students to "red team", or to assume the role of an adversary.

Summary
This case study focuses on the December 2007 NIE regarding the projected status of Iran's nuclear program. The scenario is this: National Security Adviser Stephen Hadley, tasked with assessing Iran's future goals and strategy, has asked his analysts to approach the question by assuming the role of Supreme Leader Ayatollah Khamenei and his advisers in evaluating their options.

To maximize the efficiency of the analysis, Hadley has (hypothetically) tasked each of his red teams with a slightly different job. In this case, the analyst is to assume that Khamenei has decided to pursue nuclear weapons and that he is actively seeking to acquire three or more nuclear weapons in a relatively short period of time (by December 2009), without provoking other countries, prompting an attack on its nuclear weapons program. The assignment is to provide the National Security Adviser with a "red team" memo providing three strategy options that the Supreme Leader may likely choose.

Analysts are to place themselves in the position of an Iranian foreign policy expert and close adviser to Khamenei, operating under his previously articulated top national interests:

1. Survival of the regime as an Islamic republic with its fundamental institutions and values intact;

2. The stability of Iran and its territorial integrity;

3. Prevention of a military attack upon Iran;

4. The enhancement of Iran's power, first within the region, and in time beyond.


Reflections of a Red Team Leader

http://usacac.army.mil/CAC/milreview/English/MarApr07/Craig.pdf
by Susan Craig

Summary:

This article focuses on the military aspects of red team leadership and characteristics commonly found in leaders of red team groups. The author suggests these traits will help any person in an organization think more critically of the environment the decision will be implemented in.

Legislation was enacted to implement red teams to prevent "failures of imagination and critical thinking apparent in the wake of 9/11 and the invasion of Iraq." According to Craig the most important aspect of being a red-teamer is the ability to ask good questions. Those questions should not alienate, but rather stimulate thought and point out assumptions or factors not being addressed. A red team should also identify poor measures of effectiveness and think about better indicators for feedback.

Specifically in terms of the military application of red-teaming the leader needs to consider coalition partner's constraints, capabilities, and political will, as well as their shared opponents.

Craig believes the understanding of cultural idiosyncrasies is forefront to leading a red team. Especially important is the understanding of formal and informal economies; sociological political and religious systems; sociolinguistics; semiotics; and its concept of violence.

More generally applied lessons from leading red teams is espoused upon by Craig. First, the red team should act more as a historian than an analyst (focusing on broad questions as opposed to a very specific question). Red team's insights should be tailored to the audience it addresses. The red team should be as diverse as possible. The implementation of red team recommendations needs leadership committed to making changes to the original plan. The red team leader should possess the abilities to advocate and persuade.

Red Teams: Toward Radical Innovation

http://www-935.ibm.com/services/us/imc/pdf/gt510-6190-red-teams.pdf

Summary:

This executive technology report was produced by IBM and therefore represents a competitive intelligence aspect of red-team analysis.

The executive summary of the report summarizes the main points the best:

Red teams assume the role of outsider to challenge assumptions, look for the unexpected alternatives and find the vulnerabilities of a new idea or approach. By consciously working to assume another perspective and out-do the standard team, they provide one means to getting "out-of-the-box" views and insights.
The report also lists a number of key benefits of a red team:
  • Identify significant vulnerabilities
  • Discover new uses for innovations
  • Challenge taboos and assumptions
  • Provide a minority report on a new concept or idea
  • Reveal the consequences of different perspectives
Red teams impact all three levels of planning (strategic, tactical, operational). To have any impact the red team must have a proper composition, have the support of management, have an operational relationship with the blue team, have established goals, and have access to most of the information of the blue team.

The report does outline some drawbacks from using a red team approach. The red team needs to take their assignment seriously. At times the red team was marginalized by the red team. Team membership quality lacked to fully exploit the role of adversary. Also, red teams did not receive enough credible information to act appropriately.
Enhanced by Zemanta

The Power Of Nightmares

http://video.google.com/videoplay?docid=2798679275960015727&ei=B0bjSdHbFoLorgKzq7CmAw&q=power+of+nightmares&hl=en

Summary
The Power of Nightmares is a three hour documentary by BBC producer Adam Curtis. The purpose of the film is to compare the evolution of the neo-conservatives and the Islamist movement that gave birth to Al-Qaeda. A small segment in the first hour gives a great example of how Red Team or Team B analysis can be misused.

About 25 minutes into the first hour the documentary talks about the Team B unit during the Ford Administration the Neo-cons allied themselves with Rumsfeld who was Secretary of Defense and Dick Cheney who was Chief of Staff. At 26 minutes the film shows Rumsfeld making a speech about how the Soviets were expanding the volume and capabilities of their weapons systems. The narration then goes on to explain how at that time intelligence produced by the CIA was indicating the opposite of Rumsfeld’s assertions. Rumsfeld convinced President Ford to set-up an "independent inquiry" to look at the intelligence and prove that Soviet weapons and capabilities were expanding. The inquiry was a group of Neo-cons whose memebers included Paul Wolfowitz and Richard Pipes. The Inquiry was called "Team B." Its function was to be a group of outside experts to look at all the information possessed by the CIA and see if the outside experts come to the same conclusions as CIA.

After not being able to find evidence of advanced Soviet weapons systems Team B concluded that the Soviets were hiding their new weapons systems. The film gives an example of how Team B could not find evidence that the Soviets had an acoustic defense system for their submarine forces. Team B interpreted this as meaning that the Soviets had a more advanced undectable non-acoustic system, and therefore would have a significant advantage in submarine warfare.

The CIA believed that Soviet Air Defense systems were not advancing. To prove the CIA wrong Team B relied on the Soviet Air Defense training manual that said Soviet Air Defenses were totally functional and advancing. Team B was also accused of looking at satelite imagery of Soviet radar and saying that those radars were really laser beam weapons system and mistranslating Russian documents to say "conquest" instead of "winning." According to an interview in the film with Dr. Anne Cahn who was with the Arms Control and Disarmament Agency from 1977-1980, all of Team B's estimates were proven to be false.

Author's Note: In the introduction to Power of Nightmares, the narrator makes the assertion that political leaders in recent history have shifted from trying to win the favor of the populations they govern, from giving them promises of a better life to scaring them into supporting the leaders who they believe will protect them. This is the danger of Red Team/Team B analysis. If intelligence professionals provide decision makers with analytical products that indicate a low level of threat, decision makers will political ambitions can assign a Red Team to create a "nightmare" to scare populations into supporting their policies.

To Battle Groupthink, the Army Trains a Skeptics Corps

http://www.usnews.com/articles/news/world/2008/05/15/the-army-trains-a-skeptics-corps-to-battle-groupthink.html

Summary

This article describes how the U.S. Army is training a group of officers to be skeptical of the current thinking in the military. The Red Team officers train at Fort Leavenworth's University of Foreign Military and Cultural Studies. The program there has earned the nickname "Red Team University." The biggest challenge for Red Teamers is overcoming the stigma that their job is merely to try to war game and second guess operations planning. Graduates of the program were denied security badges on their first deployment to Iraq because soldiers were afraid they would hack into data bases for war gaming purposes. The commander of the first team in Iraq describes the akward feeling of having to always disagree with the group. The article goes on to explain how constant skepticism goes against basic military culture. When a leader is put in command it is important for the troops to have full confidence in him. Therefore it is important for Red Team members to know the time and place to question operational planning. Pushing too hard can hold up the decision making process, and further stigmatize the Red Team as obstructionists.

Another up-hill battle the Red Team faces is that most of them are from the Texas National Guard. This results in another stigma of them being part-time soldiers and therefore not qualified to second guess decisions of full time professional soldiers.

Sunday, April 12, 2009

The "Red Team": Forging A Well-Conceived Contigency Plan

By Col. Timothy G. Malone and Maj. Reagan E. Schaupp
Aerospace Power Journal
Summer, 2002


Author's Note: Due to the article's length, only the most relevant information for our class was summarized.


Summary
Throughout the article, the authors provide two separate definitions for red teaming. Although the definitions are similar, they are also different (which is somewhat puzzling). I synthesized the two definitions and came up with this: a red team is a group of subject-matter experts with appropriate backgrounds that provide an independent review of processes and products using devil’s advocacy and knowledgeable role-playing of the enemy. The red team assesses planning decisions, assumptions, and courses of action from the perspective of friendly and enemy organizations.

The authors acknowledge that the concept of red teaming is far from new. Government, military, and civilian circles have all used red teaming in a variety of contexts. In government circles, it normally is associated with assessing the vulnerabilities of systems or structures, especially within the warfare arena. In the business world, red teaming usually refers to a peer review of a concept or proposal.

If conducted effectively, red teaming can produce more complete analysis at all phases and deliver a better plan of operations for the decision-maker. Effective red teams can pinpoint planning shortfalls, deviations from doctrine, reveal overlooked opportunities, and extrapolate unanticipated strategic implications. Additionally, red teaming can also determine whether the required task is understood or whether further guidance is needed.

Because a red team will conduct a comprehensive review planning products and processes, the selection of team members is critical. Red team members must have credibility, which comes only with expertise and experience. If some red team members blatantly fall short of this prerequisite, their counterparts will be skeptical of any insights they claim to have about the operation. The timing of red teaming events can play a crucial role in planning success. Ideally, the commander should form a red team as early in the planning effort as possible.
Reblog this post [with Zemanta]

Saturday, April 11, 2009

Red Teaming Revisited

Homeland Security Weekly

Summary:
This article takes a look at Red Teaming from the perspective of countering terrorism. According to Homeland Security Weekly, "It takes a thief to catch a thief. This is the Red Team Philosophy." There is a fine line, however, between creating a realistic scenario of value to the Intelligence Community (IC) and writing science fiction. The first step is employing people who are "detached" from the security environment of the target. This will ensure that the Red Team identifies true gaps in security, and not just easy fixes. Furthermore, the Red Team must recognize that terrorists are not simply crazy killers, but rational thinkers who plan, recon, train, and have the ability to successfully execute complicated operations. The article highlights 8 steps that the Red Team must analyze to successfully emulate a terrorist attack:

1. Target identification.

2. Intelligence acquisition (open source and social engineering).

3. Target surveillance to confirm or refute the intelligence.

4. Assessment of target attack plan.

5. Assessment of resource and tooling acquisition.

6. Rehearsal or training of the attack, including traveling to an unfamiliar environment and blending in with the target's surroundings.

7. The execution and its desired impact.

8. Planning and testing of the escape route.

The Red Team should always remember that terrorists will usually look for minimal exposure and contact with security; "the optimal attack is the one with the fewest obstacles." By making the Red Team assessment as realistic as possible, it will provide the most use in mitigating future threats. Furthermore, Red Teaming is not a one time exercise, but should be constantly applied to assess threats. "Red team assessments should serve as the starting point for implementing new or refining existing security practices. As practices are refined, additional red teaming evaluations should be utilized to continue this process and to address new threats or methodologies. Red teaming should be a continuing process with fresh eyes brought to bear on each evaluation (new eyes, new creative solutions)."

Homeland Security Employs Imagination

Washington Post, 18 June 2004

Summary:
The Department of Homeland Security (DHS) has developed a special program designed to think creatively as to how terrorists may attack the US. Known as the Analytic Red Cell office, DHS sought out various professionals to form a "Red Team" that would serve to "think outside the box" as to new ways we may be targeted by terrorists. Various team members were "futurists, philosophers, software programmers, a pop musician and a thriller writer"

According to the article, "Typically the Red Cell team assembles 20 or so participants for a day-long session at leased offices in the Washington area. Each session divides into smaller groups and takes up a different question, such as: If you were a terrorist, how would you target the G-8 economic summit, held last week in Georgia? Another recent topic was: Why haven't terrorists hit the United States since Sept. 11, 2001?" After the Red Cell comes to its conclusions, the final reports are forwarded to intelligence analysts throughout the Intelligence Community (IC), who vet the results and compare them to actual threats and information. "Most Red Cell reports note they are 'alternative assessments intended to provoke thought and stimulate discussion'."

This technique is not new to the IC; the CIA and Pentagon have used the method since the Cold War to expand their thinking on on how the Soviets and other foreign militaries may attack the US. The reasoning behind the method is to get non-intelligence professionals to tackle intelligence related issues. According to Brad Meltzer, a thriller writer, when he was appraoched, "They said, 'We want people who think differently from the ones we have on staff.' "

Friday, April 10, 2009

Seeing Red: Creating a Red-Team Capability for the Blue Force

Seeing Red: Creating a Red-Team Capability for the Blue Force
By Colonel Gregory Fontenot, U.S. Army, Retired
Military Review, September-October 2005

Summary:
In response to the difficulties the US Army was having in the Operational Environment in Operation Iraqi Freedom, Colonel Gregory Fontenot suggested that Red Teaming could better prepare the Army for the challenges they faced. He states that red teaming is “uniquely suited” for critical analysis when “executed by trained, educated, and practiced team members with access to relevant subject matter expertise.” Red teaming will also provide the soldier with a better understanding of the adversary through the adversary’s cultural lens.


Click on image for a more-clear view

Red Team Best Practices:
  • Political and military cultures must embrace Red Teaming
  • Embracing criticism is foremost among the internal cultural challenges
  • Political and military organizations must prize intellectual assessments and value intellectual preparation as seriously as physical preparation
  • All services must institutionalize red teaming by way of a doctrinal foundation and organizational support structure
  • Leaders must provide the top cover to protect and mentor red teamers, charter the red team and the organization to solve problems, and encourage robust interaction between red and blue (in which blue learns).
  • Leaders must balance red team independent action with accountability to the command
  • Red teaming must be employed throughout the decision making process but with calculated application – not too heavy, not too light – so promising ideas can thrive without prejudging
  • Red teams must be chartered to continue to learn and adapt
  • Red team members must be highly qualified experts in their fields and have sound reputations and even temperaments
  • Individuals and teams must be educated, trained, and certified in the context of doctrine on a recurring basis
  • The red team member presenting the opposing or alternate view must be credible, perceptive, and articulate
  • Red team members must be intellectually honest with a heavy dose of ego suppressant

Red Teaming for Law Enforcement

Red Teaming for Law Enforcement
By Michael K. Meehan, Captain, Seattle Police Department

Summary:
Michael Meehan posits that, just as the military and private industry use red-teaming techniques to discover abilities, vulnerabilities, and limitations; the law enforcement community can do the same in order to reduce threats and improve responses to issues of homeland security. The author states that red teaming refers to a variety of exercises, but the “most basic level of red teaming is to conduct peer review of plans and policies to detect vulnerabilities or perhaps to simply offer alternative views of scenarios.” Meehan also lists a variety of definitions given by other experts and organizations including the DHS Exercise and Evaluation Program which states that red teaming is, a “group of subject matter experts with various appropriate disciplinary backgrounds, that provides an independent peer review of plans and processes, acts as a devil’s advocate, and knowledgably role-plays the enemy using a controlled, realistic, interactive process during operations planning, training, and exercising."

The role of the red team is to “evaluate a target or tactic, but not the likelihood that a particular target will be attacked. Red team members are strategists who identify what to attack and domain experts who identify how to attack.” They are adaptive to the strategies of the blue team, allowing the blue team to engage in both prevention- and protection-related activities.

The role of the blue team is to “think about how surprise attacks might occur, identify indicators and warnings of those attacks, collect intelligence on those indicators, and adopt defenses against the most likely possibilities or at least provide early warning.”

Meehan describes two very common types of red teaming – analytical red teaming and physical red teaming. Analytical red teaming “provides a potential adversary’s view of threats, vulnerabilities, and countermeasures. Without testing the physical limitations of antiterrorism measures, analytical red teaming can challenge prevailing views, prevent surprise, allocate resources, and expand the bounds of imagination. Analytical red teaming can occur as part of a discussion-based exercise or as a standalone activity.”
Physical red teaming involves the physical portrayal of an actual adversary executing the tactics and strategies carried out by enemies.

Strengths:
  • Offers an element of surprise
  • Tests the fusion of policy, operations, and intelligence
  • Highlights deviations from doctrine
  • Improves blue team capabilities through practice
  • Improves information sharing

Weaknesses:
  • Preparation needed to plan scenarios
  • Interpretation , distribution, reception of lessons learned can vary

How to:
  1. Determine the objectives or desired results
  2. Communicate with government and private partners
  3. Determine the scale and type of exercise, the type of scenario, the method of evaluation, and the documentation plan
  4. Develop the scenario
  5. Identify and train the appropriate participants
  6. Conduct and evaluate the exercise
  7. Prepare thorough documentation
  8. Evaluate the performance
  9. Develop the improvement plan
  10. Make required and desired improvements
  11. Exercise again

Thursday, April 9, 2009

The Role And Status Of DoD Red Teaming Activites

Defense Science Board Task Force
September 2003
Sections I-III,VI


Summary
Red teams can be a powerful tool to understand risks and increase options. Their purpose is to reduce an enterprise’s risks and increase its opportunities. Red teaming can be used at all three levels of an enterprise: strategic, operational, and tactical. The Defense Science Board, however, found that the use of red teams within the Department of Defense is mixed at best.

Despite this mixed record, the Defense Science Board concluded that the use of red teams is especially important given today’s climate. Adversaries are tough targets for intelligence (compared to the Cold War). Red teaming can both complement and inform intelligence collection and analysis. Aggressive red teams challenge emerging operational concepts in order to discover weaknesses before real adversaries do. Red team also tempers the complacency that often follows success (referenced to the time period following Desert Storm).

Red teams come in many varieties and there are different views about what constitutes a red team. The Defense Science Board defined the term broadly, including not only playing the adversary, but also playing devil’s advocate and related roles. While differing in some respects, these activities all have in common the challenging of an organization’s norms. A red team is comprised of individuals selected for their special subject matter and expertise, perspective, imagination, or critical analysis. The red team itself is only one element in a red teaming process. Elements of the process include who the red team reports to, how the red team interacts with the management of the enterprise, and how the enterprise considers the use of the red team’s products.

Although red teaming is important, it is not easy and rarely done well. Typical causes for red team failure include the read team not taking their tasking seriously, the red team loses its independence, and the red team becomes removed from the decision making process. Conversely, attributes of an effective red team include an environment that values internal criticism, “top cover” or the support of upper level management to raise issues that may be unpopular, and proper staffing on the red team.
Reblog this post [with Zemanta]

Wednesday, April 8, 2009

Summary of Findings: Decision Trees (3 out of 5 stars)

Definition:
A visual representation exploring all possible courses of action and the resulting consequences to aid in the decision making process. Decision trees are comprised of nodes (decisions/consequences), branches (links between nodes), and probabilities. The resulting form resembles a tree.

How to:
  1. Begin from the top or the left-hand side as outcomes may flow from either left-to-right, or from top-to-bottom.
  2. Define the problem/original decision visually represent this by using a rectangle (or box) around the decision to be made. This original decision is referred to as the "decision node."
  3. Identify all possible courses of action that stem from that decision. The courses of action must be mutually exclusive and exhaustive. Each course of action should have a "branch" stemming out from the decision node.
  4. Identify "chance nodes" (represented with circles) that represent the possible outcomes of the courses of action. Different outcomes should stem out from this chance node.
  5. Sometimes branches emanating from decision and chance nodes can lead to other decision nodes - repeat steps 2 & 3 if this occurs, this will effectively “overgrow” the tree.
  6. Indicate the associated probability (likelihood) that a particular outcome stemming from a chance node will occur. Probabilities are quantified with a value ranging from zero to 1. Therefore a probability of 0.6 would be the equivalent of a 60% chance. Use your experience and knowledge, as well as any conclusions from literature or other supporting data to assign a probability value.
  7. The sum of the probabilities of all outcome branches stemming from a single chance node must equal 1.
  8. When final consequences are identified, use a filled-in circle to represent that consequence.
  9. Start “pruning” the decision tree by eliminating leaves and branches that are not (or are less) probabilistic.

Strengths:
  • Structured, allowing for transparent recognition and interpretation of the constructed model
  • Visual representation – good tool for presenters and audiences
  • Provides an audit trail for the decision maker
  • Applicable to multiple disciplines
  • Produces quantifiable estimates
  • More organized than a mind map
Weaknesses:
  • High volume of quantitative data requires high level of mathematics capability
  • Risky when choosing the "correct" variable to subdivide data
  • Susceptible to "blind spots"
  • Assigning probabilities may entail guesswork
  • Susceptible to bias

Experience:
In order to get a feel for decision tree analysis, the group, while sitting in the bar across from the intel building, decided to conduct a decision tree analysis on whether or not we should do a decision tree experience exercise. This was the general consensus of decision tree analysis based on that exercise.
  • It was difficult to assign probabilities without prior data that specifies what the likelihood is
  • It is subjective and open to analysts' bias
  • Can get messy if using pen and paper
  • Open to wild cards and cognitive blindspots
  • Does make the analyst think through the decisions and think outside of the box
  • The visual representation makes the choices and consequences clear
  • It does produce an estimation

Monday, April 6, 2009

An introduction to decision tree modeling

http://www.udel.edu/chemo/SDB/~pdf_papers/JChemo_18_275_2004.pdf

Summary:

The article offers a critique of decision tree mapping as a technique used to generalize data sets.

"In its simplest description, decision tree analysis is a divide-and-conquer approach to classification. Decision trees can be used to discover features and extract patterns in large databases that are important for discrimination and predictive modeling." It most common use is when using exploratory data and predictive modeling applications.

Decision mapping's advantages include recognizing the interpretability of the constructed model, as well as determining inter-dataset relationships. It takes the form of a hierarchical model formed by decision rules represented by nodes. The first node is reffered to as the branch node, with subsequent nodes reffered to as leaf nodes.

The general consesus is to overgrow a decision tree by incorporating all relevent criterion. The tree can then be "pruned" to reduce complexity. Generalizability is enhanced by incorporating ensemble methods such as bagging (randomly selecting samples) or boosting (reweighting criterion).
Enhanced by Zemanta

The Incident Decision Tree: Guidelines for Action Following Patient Safety Incidents

http://www.ahrq.gov/downloads/pub/advances/vol4/Meadows.pdf

Summary:

An Incident Decision Tree (IDT) was formulated to address patient safety issues arising in the United Kingdom. The IDT was developed by the National Health Service (NHS) in response to the alarming number of suspensions incurred by medical staff when patient safety issues arose.

The IDT provides human resource decision makers with a tool for determining the correct line of action when dealing with personnel in the wake of a patient safety issue. The overwhelming course of action before the IDT's implementation was a suspension for the health practitioner. The IDT proposes several different options for managers to consider after working their way through the tree. Applying the IDT allows the manager to implement fair and consistent actions resulting from patient safety mishaps.

The decision maker must think through the system and organization variables in the management of error from the prompts displayed throughout the tree. There are four consecutive trees a manager must consider about the situation. The first is the deliberate harm test (harm is intended), the incapacity test (the practitioner is sick, on medication, or has substance abuse problems), the foresight test (uncertain about protocal, protocal is unstated or poorly adhered to), and the substitution test (an equal would have acted differently). Each subsequent test is applied after the previous test was deemed inappropriate.

The pilot use of the IDT resulted in fewer suspensions for health care practitioners. Also, this lessened to a certain extent the "blame culture" associated with health care providers about self-reporting patient safety issues. Managers focused more on the "what" of the situation, rather than the "who."

A certain weakness was noted when human resource decision makers used the paper version of the IDT. Some decision makers chose suspension as the course of action and then worked backwards through the tree to justify their course of action.
Enhanced by Zemanta

Sunday, April 5, 2009

Risk Based Methodology For Scenario Tracking, Intelligence Gathering, and Analysis For Countering Terrorism

Horowitz, Barry M. and Haimes, Yacov Y.. Systems Engineering, Vol. 6, No. 3, 2003, p. 152-169, 17 p.

Summary:
The authors of the paper apply a variety of methods to the problem of countering terrorism. One of the methods they apply is the use of Multiple-Objective Decision Trees (MODT). The use of MODT allows the intelligence community to make informed decisions under conditions of uncertainty. The authors propose using the method as the final step in a process that utilizes other methodologies, such as Bayesian analysis. "Finally, a decision-making mechanism is needed that can utilize the added knowledge derived from newly-discovered intelligence and make use of Bayesian analysis. In particular, the noncommensurate objectives—effort (cost and time) and risk—must be addressed in the multiobjective tradeoff analysis. Follow-up actions could vary from calling for special new information, to calling in experts to further evaluate the data, to initiating interception of the anticipated terrorist activity."

The authors state that the problem with traditional decision trees as applied to intelligence analysis is that the problem of the intelligence analyst is often too broad to be effectively represented by a decision tree. "In particular, an optimum derived from a single-
objective mathematical model, including that derived from a decision tree, often may be far from
representing reality, and thereby may mislead analysts as well as decision-makers." Instead, the authors propose MODTs as a effective methodology to assess decision making when their are multiple objectives, such as countering terrorism (thwart a plot, interdict the terrorists, dismantle their finances, kill the terrorists, etc.). Through the use of the MODT, decision makers and analysts begin with all objectives formulated, and then make trade-offs based on which set of decisions is most desirable for the given situation.

Comment: This paper further demonstrates the mathematical equations of MODT as opposed to traditional single objective decision trees. I did not include the equations in this summary, please see the article for the mathematics behind the methodology, as well as introductions to other methodologies that the authors propose to better your counterterrorism analysis.