home : blog : resources : research & analysis : contact
 
18 July 2010

"Tell me when the bad guy knows the good guy"

Words of wisdom from Jeff Jonas:

Circa 1993 we were building the first NORA (Non-Obvious Relationship Awareness) system for a casino. In this system the first relevance rule was basically: “Tell me when the bad guy is the good guy.” This one rule was created to detect and alert for such things as: the slot club loyalty card member is banned from gaming (on the Nevada Gaming Control Board’s Excluded Persons List) or the job applicant is a known gaming felon.

The second relevance rule was: “Tell me when the bad guy knows the good guy.”

With just these two rules, the system started kicking out all kinds of valuable, unanticipated insight including one of my favorites: An alert surveillance room operator noticed a dude cheating on a roulette table … making bets after the ball fell (called “past posting”). Dealers are supposed to watch for this. But somehow today this dealer kept missing this obvious scam. Casino security detains the cheater. The dealer says “I can’t believe this happened to me, I am so embarrassed, you surveillance folks are sure doing a good job, it won’t happen again.” During the arrest processing, the cheating player provided a different last name and address than used by the dealer. Fortunately, the cheater provided his real home phone number which happened to be the same number that the dealer had used on her original employment application.

The dealer pretending, up to this point, to not know the player rolled-over in an instant and confessed when NORA popped off a real-time alert: “The cheater is related to the dealer.”


Read the rest...

Posted on 18 July 2010 @ 16:58
13 July 2010

Crime/Terrorism nexus: the complaint against Mustafa Ahmad Naushad, et al.

Mustafa Ahmad Naushad lived in Charlotte, NC for a time, and attended college there. This puts him into the orbit of Samir Khan, de facto number one guy in the emerging American al-Qaida network.

2. According to a criminal complaint filed in the Southern District of California, Naushad, together with co-defendants Tamim Abdul-Samad AKA Brandon Harris, and Darryl Eugene Peterson AKA Najm, robbed a CitiBank branch in La Mesa, California, on 19 April, 2010.

3. The bank robbery featured the open display of a firearm, and assaults on three tellers, who were kicked about the head and neck as they lay on the floor of the bank.

4. Najm and Abdul-Samad are African-American, and are presumably converts to Islam. Abdul-Samad has been arrested on at least four prior occasions, though the nature of those cases is not known to me.

5. Naushad was living in La Mesa at the time of the bank robbery, and was under FBI surveillance unrelated to bank robbery. Presumably the surveillance was related to an ongoing terrorism investigation. Naushad's car had a tracking device installed on it, in addition to other forms of surveillance that were being conducted.

6. Abdul-Samad was also under surveillance related to Naushad and the presumed terrorism investigation. Najm and Naushad were frequently seen together by agents conducting surveillance, often in Naushad's car, while Najm and Abdul-Samad were known to attend the same mosque.

7. The tracking device places Naushad's car at the bank at the time of the robbery, and the vehicle's description matches that of the getaway car as described by witnesses.

8. Video surveillance at the bank, video surveillance related to the presumed terrorism investigation, and multiple eye witnesses, all identify the same three individuals as being involved in the robbery, and all identity these three suspects as the perpetrators of the bank robbery.

9. Naushad was arrested in Charlotte and has a detention hearing before a US Magistrate at the Federal courthouse there on 14 July 2010, at 9:30 am. Court filings in Charlotte indicate that the Muslim community plans to come out in large numbers in support of Naushad. They should probably have read the criminal complaint from California before they decided on that course of action.

10. Case 3:10-mj-02223-JPC, Document 1, Filed 07/02/10, Unsealed 07/10/10.
USA v. Abdul-Samad/Harris, Naushad, and Peterson/Najm
Complaint for Violation of 18 USC 2113, Bank Robbery

Thanks to Rusty Shackleford at The Jawa Report for the initial tip, and Cousin X for research assistance.

Posted on 13 July 2010 @ 14:10
05 July 2010

Top Ten locations of al-Faloja forum readers

Given that the adminstrators of the al-Faloja forum are already convinced that they have been somehow infiltrated or compromised, there seems little harm done in providing a glimpse of the current geographic distribution of the non-proxy using readers of the site. This data is based on the analysis of a reasonably large number of IP addresses of Faloja readers during the period immediately prior to the abortive release of al-Malahem/AQAP's "Inspire" magazine. This data is based on direct observation, and has not been manipulated beyond the identification and removal of the IP addresses of proxy servers.

Ten countries or territories account for 70% of the site's non-proxy using readers.

Country/Territory % of Readers Subtotals
Palestinian Territories 20.00%  
Egypt 13.60%  
Morocco 12.90% 46.40%
Germany 4.30%  
Britain 3.60%  
Israel 3.60%  
Jordan 3.60% 61.40%
Algeria 2.90%  
Kuwait 2.90%  
Sweden 2.90% 70.30%

Posted on 5 July 2010 @ 17:31
28 May 2010

"Would-Be Warriors"

by Brian Michael Jenkins at RAND:

Between September 11, 2001, and the end of 2009, 46 publicly reported cases of domestic radicalization and recruitment to jihadist terrorism occurred in the United States; 13 of those cases occurred in 2009. Most of the would-be jihadists were individuals who recruited themselves into the terrorist role. Some provided assistance to foreign terrorist organizations; some went abroad to join various jihad fronts; some plotted terrorist attacks in the United States, usually with little success because of intervention by the authorities. The threat of large-scale terrorist violence has pushed law enforcement toward prevention rather than criminal apprehension after an event — or, as one senior police official put it, “staying to the left of the boom,” which means stopping the explosions or attacks before they occur. This shift toward prevention requires both collecting domestic intelligence — always a delicate mission in a democracy — and maintaining community trust and cooperation.

Posted on 28 May 2010 @ 01:47
09 May 2010

The TTP link to the Times Square bombing attempt and forward-looking analysis

1. The video claiming credit for the Times Square bombing attempt
    a. Was posted on a YouTube account created immediately before the bombing
    b. Was titled "Qari Hussain Mehsud from Tehreek e Taliban Pakistan accepts the recent Attack on Times Square"
    c. Was reported first to Bill Roggio, operator of The Long War Journal, by the TTP - they are fans of his work
    d. Appears to have been made prior to the bombing
    e. Uses language "...accepts the recent attack..." which *might* suggest that the act was done on their behalf - rather than directly by them - and assumes the attack was successful, which also supports the idea of a certain disconnect between the perpetrator and the sponsoring organization.

2. Significantly, immediately after informing Bill Roggio of the video claiming or "accepting" the Times Square attack, the same individual from the TTP who contacted Roggio was independently observed by others uploading the second video, from Hakeem-ullah Mehsud, to archive.org. This video is dated April 4 (by Mehsud) and threatens attacks within the USA.

3. The above leads one to the conclusion that the TTP had prior knowledge of the attack in NYC, though the precise nature of the links between Faisal Shahzad and the TTP is not clear. What is clear is that the TTP in general, and Hakeem-ullah Mehsud in particular, are angry and will be doing their best to carry out or facilitate additional attacks within the USA. It's one thing to use missiles to decapitate a terrorist organization - it's another matter altogether when one tries, but fails, leaving the target(s) knowing that they don't have long to live and so have nothing left to lose.

4. In more general terms, we seem to be facing a threat that has grown to include multiple centers of gravity, including the syndicate of AQ-linked jihadi outfits in Pakistan (and affiliated Indian Muslims, e.g. SIMI, IM), and the AQ Arabian Peninsula/al-Shabaab confederacy. Both centers have connections to numerous individuals in the USA - both converts and 1st/2nd/3rd generation immigrants from Pakistan, Bangladesh, India, Yemen, and Somalia.

5. It is fashionable to dismiss al-Qaida fan clubs like Revolution Muslim as insignificant, because RM has so few members (the number 13 is often cited). The problem is that the social networks that are the foundation for Revolution Muslim are composed of over 18,000 people, many of whom are located in the USA or in countries whose citizens enjoy relatively free access to the United States (e.g. Britain). Do the math.

6. Finally, these centers of gravity are somewhat arbitrary constructs. In reality there is overlap between the two camps, they exist in relatively close proximity to each other, and individuals in the USA and elsewhere are well-positioned to serve as bridging links, providing lines of communication between Yemen/Somalia, AfPak, and CONUS.

See also:

Surrogate Jihadis in US by B.Raman
Enemies, both foreign and domestic

Posted on 9 May 2010 @ 16:33

copyright © society for internet research