Skip to content
wiki.fftac.org

Modern Keyword Surveillance Systems - Source Excerpt 02 - PRISM, Upstream Collection, and Infrastructure Subversion

Back to Modern Keyword Surveillance Systems

Summary

This source excerpt begins near PRISM, Upstream Collection, and Infrastructure Subversion and preserves the surrounding evidence from 2IA.org/agent-file-handoff/Archive/2026-05-17-civil-liberties-overhaul/Content/Modern Keyword Surveillance Systems.md.

**Source path:** 2IA.org/agent-file-handoff/Archive/2026-05-17-civil-liberties-overhaul/Content/Modern Keyword Surveillance Systems.md

The physical and legal limitations of localized packet sniffers were entirely circumvented in the post-9/11 era. The paradigm shifted toward the industrialization of mass surveillance by the National Security Agency (NSA) and its Five Eyes intelligence partners, which include the United Kingdom's Government Communications Headquarters (GCHQ), the Australian Signals Directorate (ASD), Canada's Communications Security Establishment (CSE), and New Zealand's Government Communications Security Bureau (GCSB).7 The modern surveillance architecture abandoned the strategy of tapping individual ISP switches in favor of tapping the very fiber-optic backbone of the global internet, alongside establishing direct, mandatory data-sharing pipelines with major multinational technology corporations.4

### **PRISM, Upstream Collection, and Infrastructure Subversion**

The scope of this global dragnet was revealed to the public in 2013 by whistleblower Edward Snowden.7 The intelligence leaks exposed PRISM, a highly classified program authorized under Section 702 of the Foreign Intelligence Surveillance Act (FISA) Amendments Act.4 PRISM fundamentally altered keyword and selector targeting by allowing the NSA to compel major technology companies—including Microsoft, Yahoo, Google, Facebook, PalTalk, AOL, Skype, YouTube, and Apple—to grant the government direct access to users' personal data stored on their servers.4 This access enabled the collection of the contents of emails, text messages, video chats, photographs, and stored documents from targeted individuals.4

Concurrently, the NSA and GCHQ deployed "Upstream" collection programs, which were designed to intercept telephone and internet traffic directly from major undersea fiber-optic cables and internet switches.4 GCHQ’s parallel program, codenamed Tempora, tapped fiber-optic cables to collect, store, and share vast quantities of global communications with the NSA.5 According to leaked documents, Tempora and similar NSA Upstream facilities retained the actual content of intercepted communications for three to five days, while the associated metadata was stored for up to 30 days.20

When direct access or fiber-optic interception was insufficient, the intelligence apparatus engaged in active infrastructure subversion. For instance, GCHQ executed a targeted cyberattack against Belgacom, Belgium's largest telecommunications provider, utilizing a sophisticated malware suite known as Regin.19 The objective was to subvert Belgacom's network to monitor communications passing between the provider and its international partners, effectively turning the network itself into a surveillance tool.19 Similarly, the NSA and GCHQ jointly hacked Gemalto, the world's largest manufacturer of SIM cards, to steal encryption keys, granting the agencies the ability to covertly monitor mobile communications globally without seeking warrants or wiretap authorizations from local telecommunications providers.19

### **XKeyscore: The Search Engine of Global Surveillance**

To process, index, and analyze the tens of billions of records vacuumed up daily by PRISM and Upstream collection, the NSA deployed a system codenamed XKeyscore (XKS).4 Described in classified briefing documents as a "fully distributed processing and query system" and an "Exploitation System/Analytic Framework," XKeyscore functions effectively as the search engine of the global surveillance apparatus.4 The infrastructure is massive; as of 2008, it consisted of over 700 servers deployed across approximately 150 field sites globally, including installations in the United States, Mexico, Brazil, the United Kingdom, Spain, Russia, Nigeria, Somalia, Pakistan, Japan, and Australia.4

XKeyscore was designed to ingest a constant flow of "full-take data" from fiber-optic cables, storing all intercepted traffic locally at the collection sites.21 Because of the sheer volume of data—with one site reporting over 20 terabytes of data received per day—storage retention limits forced analysts to push "interesting" content into longer-term, multi-tiered databases such as Pinwale, which could store material for up to five years.20 In a single 30-day period in 2012, XKeyscore processed and stored at least 41 billion total records.20

The legal and technical capability that defines XKeyscore is the concept of "about" targeting.4 Unlike Carnivore, which required a specific warrant to monitor a specific individual's communications, XKeyscore enables analysts to capture the communications of entirely innocent, non-targeted individuals if the content of their emails or texts merely mentions a targeted keyword, selector, or individual.4 Consequently, no matter who is sending or receiving a message, if a targeted phrase traverses the global network, it is swept into the intelligence database.

### **Granular Selectors and Complex Behavioral Queries**

XKeyscore moves far beyond the simple, static keyword lists of the late 1990s. The system allows analysts to perform deep semantic and behavioral queries using advanced boolean logic (utilizing AND, OR, and \! operators), wildcards (\* for multiple characters and \_ for single characters), and complex regular expressions (regex:).22 Analysts can search the metadata and content residing on XKeyscore servers without prior authorization for low-latency queries, effectively allowing individual agents to execute retrospective wiretaps on demand.4

The system categorizes targeted data into highly specific granular selectors 22:

| XKeyscore Selector Category | Technical Description and Targeting Mechanics |
| :---- | :---- |
| **Email Addresses & Usernames** | Allows targeting of full addresses (e.g., abujihad@hotmail.com) or isolation of the username string preceding the "@" symbol. Analysts can query a foreign-hosted IP address to automatically return all email addresses seen traversing that specific node.22 |
| **IP and MAC Addresses** | Targeted via a "Multisearch" federated query that scans across User Activity, HTTP logs, and Extracted Files. Complex IP ranges can be targeted utilizing regex formatting (e.g., regex:202\\.82\\.86\\.22\[4-9\]).22 |
| **Phone Number Extraction** | A specialized Phone Number Extractor routinely scans the raw text content of intercepted emails, such as signature blocks, to identify digits. Non-normalized numbers lacking country codes can be queried when paired with specific geographic filters.22 |
| **Extracted Files and Documents** | Targets can be searched by specific filenames (e.g., iranian\_nuke\_files.pdf), MIME types, or specific file extensions (e.g., .zip, .pdf) as they are intercepted in transit across the internet backbone.22 |
| **HTTP Web Activity** | Queries can selectively target specific URLs, browser types, language encodings, and HTTP request types.22 |
| **Credential Harvesting** | Analysts can target foreign servers (e.g., mail or name servers) to automatically harvest the login credentials, usernames, and passwords of all individuals authenticating on that network.21 |

The true operational power of XKeyscore lies in its ability to combine these selectors to detect behavioral anomalies or operational security failures. By chaining commands, analysts deploy dynamic "fingerprints" to find targets who are not identified by a specific name or email address, but by their digital behavior.7 Documented examples of these complex, layered queries include:

* The execution of queries such as fingerprint('encryption/mojahdeen2') and fingerprint('browser/cellphone/iphone'), which allows analysts to isolate individuals utilizing specific jihadist encryption software on an iOS device.21  
* Isolating targets based on geographic and network routing anomalies, such as searching for *"Targets using mail.ru from behind a large Iranian proxy"*.21  
* Detecting potential data exfiltration or cyber-espionage by searching for specific temporal anomalies, such as *"HTTP POST traffic from Russia in the middle of the night"*.21  
* Targeting individuals executing *"web searches on jihadist topics from Kabul"* or identifying individuals speaking a language *"out of place"* for a specific geographic region, such as a German speaker communicating from within Pakistan.4  
* Monitoring non-terrorist strategic targets, such as New Zealand's use of XKeyscore to track any email body containing specific *"WTO-related content"* to spy on the World Trade Organization during an election.21

## **Homeland Security and the Industrialization of Social Media Lexicons**