Using open source web intelligence (WEBINT) to discover, monitor and analyze the planning and execution of violent civil unrest

bluedownloadThe web has become the primary platform for the orchestration of activities related to violent civil unrest—and the resulting threat to public safety. As a result, law enforcement authorities must find solutions that enable them to effectively monitor and analyze the increasingly large volume of publicly shared information on the web, including the deep web—that 80 percent of the Internet that remains inaccessible to traditional search engines.

Forward-thinking law enforcement authorities use OpenMIND™, 3i-MIND’s end-to-end WEBINT solution, to automatically monitor violent extremists’ publicly shared discussions and media across social networking accounts, forums, blogs and other deep web sources. Based on pre-defined alerting parameters, OpenMIND automatically notifies authorities when suspected content and signs of imminent violence are identified. In turn, real-time multi-layered analysis of the content, including link analysis, metadata (e.g., the time, date and location content was posted) and volume/frequency, is used to determine the true threat level. A detailed report is exported and shared with all relevant stakeholders, responders and decision-makers.

 

Defining Parameters for Monitoring and Alerting

An analyst assigned to monitor the web for impending violent civil unrest uses OpenMIND’s out-of-the-box data collection templates to automatically monitor and analyze publicly shared discussions in known publicly shared radical forums, blogs and social networking accounts. The analyst sets alerting criteria to ensure that he is immediately notified whenever a threshold is reached (e.g., when language describing or related to the planning of a violent protest is detected; when a known extremist or a political VIP is named or referenced; when there is a substantial spike in the number or frequency of posts).

Defining Parameters for Monitoring and Alerting

bb1

OpenMIND’s UI is simple to use, leveraging task-specific structured work flows and offering multifaceted, rich visualizations to produce an enhanced user experience

OpenMIND raises an alert, having identified discussion in an extremist forum about an unlawful gathering at a downtown public square—part of an ongoing anti-government campaign. The discussion includes posts by members of a known radical group, and shares the meeting place of a protest that calls on participants to “bring improvised weapons in case police or rival factions intervene”. The analyst summarizes these findings in a report that includes a map of the event’s intended location, and shares it with all relevant stakeholders via the OpenMIND system.

Using OpenMIND’s Source Development Module, the analyst identifies new public social networking accounts and topic hashtags that were created specifically for the scheduled protest. Further analysis yields important insights, including details of the protest’s planned route and expected number of participants (over 700 people have indicated that they will attend the event). As new information flows in, it’s instantly incorporated into a situational awareness picture that is constantly updated and disseminated in real-time to decision- makers and on-the-ground forces.

Day of the Event: Real-time Geospatial & Temporal Analysis

On the day of the event, the analyst sets a geo-fence around the protest area in order to monitor in real time photos, videos and text publicly shared by participants and bystanders via smart phones and other devices. The analyst visualizes the incoming information as individual geography-based clusters, and adds data layers (e.g., topics; hashtags; user accounts; indicative text) to each in order to generate a 360-degree view of all relevant data. Leveraging this visualization, the analyst correctly assesses the physical trajectory of the protest and its potential for turning violent.

A closer look at a cluster located approximately two miles west of the event’s epicenter reveals the use of violent terminology, such as “counter-protest” and “clash”; images depicting hostility between factions of protesters; and two highly active forum users who are inciting others to engage in physical confrontation.

As the analyst monitors the protest in real time, OpenMIND provides actionable insights to support the activities of forces on the ground that proceed to block key routes (to contain the protest) and identify and apprehend those responsible for promoting violence.

OpenMIND’s reports and stored content later serve as post-event intelligence during debriefing and legal procedures.

bb2

OpenMIND’s Source Development Module has an intuitive workflow that enables investigators to establish an extensive and informative coverage base consisting of relevant online communities and discussions.

bb3

Social media posts, including text, images and video content are used to track developments during a potentially violent event and as eyewitness testimony after the fact.

Learn how OpenMIND leverages the deep web

Inquiry Form >>