Countersurveillance refers to measures that are usually undertaken by the public to prevent surveillance,[1] including covert surveillance. Countersurveillance may include electronic methods such as technical surveillance counter-measures, which is the process of detecting surveillance devices. It can also include covert listening devices, visual surveillance devices, and countersurveillance software to thwart unwanted cybercrime, such as accessing computing and mobile devices for various nefarious reasons (e.g. theft of financial, personal or corporate data). More often than not, countersurveillance will employ a set of actions (countermeasures) that, when followed, reduce the risk of surveillance. Countersurveillance is different from sousveillance (inverse surveillance), as the latter does not necessarily aim to prevent or reduce surveillance.
Most bugs emit some form of electromagnetic radiation, usually radio waves. The standard counter-measure for bugs is, therefore, to "sweep" for them with a receiver, looking for the radio emissions. Professional sweeping devices are very expensive. Low-tech sweeping devices are available through amateur electrical magazines, or they may be built from circuit designs on the Internet.
Sweeping is not foolproof. Advanced bugs can be remotely operated to switch on and off, and some may even rapidly switch frequencies according to a predetermined pattern in order to make location with sweepers more difficult. A bug that has run out of power may not show up during a sweep, which means that the sweeper will not be alerted to the surveillance. Also, some devices have no active parts, such as the Great Seal given to the US Ambassador to Moscow which hid a device (the Thing).
Amidst concerns over privacy, software countermeasures[2] have emerged to prevent cyber-intrusion, which is the unauthorized act of spying, snooping, and stealing personally identifiable information or other proprietary assets (e.g. images) through cyberspace.
Popular interest in countersurveillance has been growing given media coverage of privacy violations:[3][4]
監視活動の大部分、そして対監視活動の大部分は、電子的な方法よりも人的な方法を用いて行われる。なぜなら、一般的に人間は監視に対して脆弱であり、かつ創造的な対応能力に優れているからである。
人的対策としては以下が挙げられる。
こうした活動は、監視対象者の追跡を困難にする。前述の対策を講じる前に、規則的で予測しやすいスケジュールに従うことで、監視担当者が油断し、結果として追跡対象から外れやすくなる可能性がある。
別の戦略としては、以下の条件を満たす安全な会話のための部屋を利用する方法があります。
サイバーセキュリティにおいて、防御側は、侵害されたシステムを直ちにシャットダウンすることなく、ネットワーク監視対策作戦(NCSO)を展開して攻撃者を監視し、情報を収集することができます。システムを完全に切断する(これは敵に警告を与え、貴重な知見を失う可能性がある)のではなく、防御側は攻撃者のツール、技術、目的を密かに観察し、侵入と関連する脅威アクターについてより多くの情報を得ることができます。[ 10 ]
TSCM(技術的監視対策)は、盗聴器の掃討や電子監視対策のプロセスを表す米国連邦政府の略語です。ELINT 、 SIGINT 、電子対策(ECM)に関連しています。 [ 11 ]
米国国防総省は、 TSCM調査を、資格を有する担当者が提供するサービスであり、調査対象施設への技術的な侵入を助長する可能性のある技術的監視装置や危険の存在を検知し、技術的なセキュリティ上の弱点を特定するものと定義しています。TSCM調査は、施設の技術的セキュリティ体制に関する専門的な評価を提供し、通常は調査対象施設内外における徹底的な目視、電子的、および物理的な検査で構成されます。
しかし、この定義には技術的な側面が欠けている。現代の環境では、通信セキュリティ(COMSEC)、情報セキュリティ(ITSEC)、そして物理セキュリティも業務の重要な部分を占めている。マルチメディア機器やリモートコントロール技術の登場により、非常にセキュリティの高い環境下でも、従業員が知っているか否かにかかわらず、大量のデータを持ち出す可能性が大きく広がってしまった。
技術的監視対策(TSCM)は、適切な訓練を受け、資格を持ち、装備を備えた担当者が、電子盗聴装置、セキュリティ上の危険、またはセキュリティ上の弱点を発見するために、指定された区域を体系的に物理的および電子的に検査することと定義するのが最も適切である。
ほとんどの盗聴器は、データ、映像、音声などの情報を電波を使って空中送信します。このような盗聴器に対する標準的な対策は、無線周波数(RF)受信機で攻撃を検出することです。実験室用、さらには現場用の受信機も非常に高価であり、機器を効果的に操作するにはRF理論に関する十分な知識が必要です。バースト送信やスペクトラム拡散といった対策によって、検出はさらに困難になります。
検出調査と位置スキャンのタイミングは成功に不可欠であり、スキャンする場所の種類によって異なります。恒久的な施設の場合、検出を回避するために非勤務時間中に電源が切られる遠隔操作可能なデバイスを検出するために、スキャンと調査は勤務時間中に実施する必要があります。[ 12 ]
盗聴器は会話を送信する代わりに、録音することがある。電波を発信しない盗聴器は検出が非常に難しいが、そのような盗聴器を検出するための方法はいくつか存在する。
Very sensitive equipment could be used to look for magnetic fields, or for the characteristic electrical noise emitted by the computerized technology in digital tape recorders; however, if the place being monitored has many computers, photocopiers, or other pieces of electrical equipment installed, it may become very difficult. Items such as audio recorders can be very difficult to detect using electronic equipment. Most of these items will be discovered through a physical search.
Another method is using very sensitive thermal cameras to detect residual heat of a bug, or power supply, that may be concealed in a wall or ceiling. The device is found by locating a hot spot the device generates that can be detected by the thermal camera.
A method does exist to find hidden recorders, as these typically use a well known frequency for the clock which can never be totally shielded. A combination of existing techniques and resonance sweeps can often pick up even a defunct or "dead" bug in this way by measuring recent changes in the electromagnetic spectrum.
Technology most commonly used for a bug sweep includes but is not limited to:
Kestrel TSCM、SignalHound、3 dB Labs、Arcaleなど、多くの企業が現代の対監視活動に必要なハードウェアとソフトウェアを開発している。 [ 13 ]
2011年、ピーター・マッケイ国防大臣は、電話とインターネットの使用状況から不審な活動を検出するプログラムを承認した。[ 14 ]このプログラムは、カナダ全土のカナダ人のメタデータを検索して収集する。[ 15 ]
現在、カナダを標的とした監視反対運動はごくわずかしか存在しない。
Transparent Livesは、カナダの著名な団体で、「私たちが無数の組織に対してどれほど目立つ存在になったか、そしてそれが私たちの日常生活の送り方に良くも悪くもどのような意味を持つのかを劇的に示す」ことを目指している。[ 16 ]
アムネスティ・インターナショナルは、エドワード・スノーデンが米国における大規模監視に関する情報を明らかにした数千ものNSA文書をリークしたことに触発され、「政府に対し、大規模監視と違法な情報共有を禁止するよう求める」 #UnfollowMeというキャンペーンを展開している。このキャンペーンは世界中で活動している。
これらの暴露を総合すると、世界的な監視システムが明らかになった…。