Showing posts with label RFID. Show all posts
Showing posts with label RFID. Show all posts

Monday, June 24, 2013

Would You Ever Know If The Government Is Tracking You?



By Patrick C. Toomey


Court rulings unsealed last week in Washington show for the first time a behind-the-scenes legal battle over when the government should have to tell you that it's tracking your location and reading your email. These documents—which came to light only as the public learned more about the government's controversial investigation of Fox News journalist James Rosen—reveal significant new details about the government's obligation to provide notice, after the fact, when it obtains geolocation data or obtains stored email messages. Indeed, the court orders bring to light a striking contrast: federal prosecutors in Washington routinely provide notice to individuals they track using cell-phone geolocation data, even if that notice is delayed, yet the government strenuously resists giving any notice to individuals when searching and reading their emails.
The government is required to tell you when it listens in on your phone calls or searches your home. Now, it appears that at least some prosecutors provide delayed notice when they use cell-phone data to track your location in real-time. If prosecutors in Washington can provide such notice, then prosecutors elsewhere should be doing it too. Last year, the public learned that the phone companies receive a staggering 1.3 million surveillance requests per year, many of which are likely for geolocation data. Although notification is apparently the norm in Washington we're not aware of similar practices anywhere else in the country.
As for government searches of your personal email account, you will likely never know—unless you are ultimately charged with a crime or your email service provider voluntarily tells you about the search (something few do, often because the government obtains a gag order). The lack of notice for email searches appears to be a central question in court documents unsealed last week, which show the government trying to convince at least three judges that it has no duty to provide notice to email subscribers.
The new details emerged in a series of court opinions debating whether the government was ever required to tell Rosen that it had obtained a warrant to search his Gmail account. Relying on the convoluted and outdated federal statute governing email searches—the Electronic Communications Privacy Act (ECPA)—the government argued that it was excused from providing notice. U.S. Magistrate Judge John Facciola of the D.C. District Court rejected the government's argument and highlighted the perverse consequences of its position. Pointing out that federal prosecutors in Washington typically provide notice when tracking a person's movements using cell-phone data, Judge Facciola wrote:
[T]he user of a cell phone whose telecommunications data has been intercepted and captured pursuant to a warrant would ultimately learn that the government has been surveilling her, even though a portion of that surveillance may have occurred when she was in a public place. The e-mail account holder, on the other hand, would never learn of the search of the entire contents of her email account. Thus, as the government would have it, while it would have to tell a person that it followed his movements one day as he walked from K Street to Connecticut Avenue, it would never have to tell him that it has read and copied the entire contents of the e-mail account that he opened when he arrived at his office on K Street.
While the government was unable to convince Magistrate Judge Facciola, it appealed and ultimately persuaded Chief Judge Royce Lamberth that it had no obligation to notify Rosen of the email search. In particular, Chief Judge Lamberth held that the government's duty to provide notice was satisfied when investigators presented the warrant to the email service provider—in this case, Google. Magistrate Judge Facciola had previously rejected the government's interpretation of the notification statute, describing it as a "meaningless act of telling the ISP what it already knows." Facciola also observed that "[i]t is irrational to think that Congress would . . . grant the government a perpetual dispensation from ever notifying a person of the remarkable intrusion that a search of his email account creates."
These court opinions and filings tell us a great deal about how the government interprets its authority to obtain highly personal information, and the extent to which it interprets the law to avoid informing individuals when they have been spied upon. The documents also prompt further questions and significant concerns. For instance, we learned for the first time that federal prosecutors in Washington generally give delayed notice to the targets of cell-phone geolocation tracking—but what about prosecutors in other parts of the country, at the federal, state, and local level? Is this practice the result of a specific court ruling confined to our nation's capital, or does it reflect a national policy adopted nation-wide by the Department of Justice?
Even more, the documents show that the government seeks to access ever-greater quantities of our personal information with even less protection for individuals. Our email accounts contain vast amounts of private information, including personal communications, financial records, and other sensitive material. Yet courts do not even mandate the kind of notice that would be required if the government wanted to rifle through the letters we keep at home. Our laws have not caught up to the reality of today's electronic communications. The government should be required to notify individuals it targets for searches, whether electronic or physical, even if that notice is delayed for a time. Currently, individuals will only learn of these electronic searches if and when they are charged with a crime. The strange result of this policy: innocent people who are never charged will never learn that they were the subject of government surveillance and this type of intrusive search.
The Department of Justice has long kept the public in the dark about the scale of its surveillance activities. Such secrecy over surveillance powers is simply not appropriate in a democracy.

Saturday, May 11, 2013

Naked Citizens



By JourneyMan Pictures


Increasing numbers of 'terror suspects' are being arrested on the basis of online and CCTV surveillance data. Authorities claim they act in the public interest, but does this intense surveillance keep us safer?

"I woke up to pounding on my door", says Andrej Holm, a sociologist from the Humboldt University. In what felt like a scene from a movie, he was taken from his Berlin home by armed men after a systematic monitoring of his academic research deemed him the probable leader of a militant group. After 30 days in solitary confinement, he was released without charges. Across Western Europe and the USA, surveillance of civilians has become a major business. With one camera for every 14 people in London and drones being used by police to track individuals, the threat of living in a Big Brother state is becoming a reality. At an annual conference of hackers, keynote speaker Jacob Appelbaum asserts, "to be free of suspicion is the most important right to be truly free". 

But with most people having a limited understanding of this world of cyber surveillance and how to protect ourselves, are our basic freedoms already being lost?

Monday, March 18, 2013

Smartphones To Collect Biometric Data




The Defense Department has awarded a $3 million research contract to California-based AOptix to examine its “Smart Mobile Identity” biometrics identification package, Danger Room has learned. At the end of two years of research to validate the concepts of what the company built, AOptix will provide the Defense Department with a hardware peripheral and software suite that turns a commercially available smartphone into a device that scans and transmits data from someone’s eyes, face, thumbs and voice.
“They’ve asked us, based on what they’ve seen of our product, to work on some more specific needs and requirements for DoD,” Chuck Yort, AOptix’s vice president for identity solutions, tells Danger Room. Data security for the system will be provided by partner CACI International, which shares in the $3 million contract, which will be officially announced Wednesday morning.
Currently, U.S. troops rely on a single-use device, known as the Handheld Interagency Identity Detection System (HIIDE), to scan, upload and transmit data from someone’s facial, eye or thumb features to its wartime biometrics databases. The HIIDE, shown below, looks a bit like the cameraHipstamatic uses for its logo, and troops who want to operate it need to bring it close to the faces and thumbs of the people they scan.
The hardware AOptix has developed isn’t itself a phone. It’s a peripheral that wraps around a phone to enable the additional sensing capabilities necessary to acquire the biometric data. AOptix was hesitant to describe the peripheral, but supposedly it won’t impact the phone’s form factor, and the company swears a smartphone bulked up with its sensing dongle will weigh under a pound. Unlike HIIDE, it’ll only take one hand to operate.
Outside of the add-on, the computational power of the smartphone is supposed to enable the software package that AOptix built — and displayed at a September conference in Tampa partially sponsored by the National Security Agency. The company won’t say what operating system Smart Mobile Identity it’s configured to run on, but the Defense Department tends to like the relative cheapness and open architecture of Android devices. Yort promises the software will have a “very intuitive interface that leverages smartphone conventions.”
Smart Mobile Identity has limited ability to record biometric data at a distance, but its specs outperform the HIIDE camera. It scans faces at up to two meters away, irises from one meter, and voice from within the typical distance from a phone. Thumbprints will still require a finger against the reinforced glass face of the phone. Joey Pritikin, another AOptix executive, says that an additional advantage of the system is its ability to capture an iris in bright sunlight, which is a challenge for HIIDE and other biometrics device. Apparently the system will also be able to snap an image of someone’s face or eye once the phone running the software focuses on it, without a specific click, swipe or press.
AOptix is also cagey about which part of the Defense Department inked the deal with the company. (Pentagon officials didn’t respond to requests for additional information.) But since AOptix and CACI are supposed to deliver Smart Mobile Identity after 24 months of research, its most likely application would be for special operations forces, who after the 2014 completion of the troop drawdown from Afghanistan will be doing the majority of patrolling in places where biometric ID collection on a mobile device will be relevant.
It’s worth noting that even though the military is backing away from foot patrols in warzones, it’s not backing away from biometric data acquisition — far from it. The U.S. Central Command has held on to the biometric database of three million people it compiled during the Iraq war. And Darpa-funded projects are already working on biometric identifier devices that can scan irises and even fingerprints from further distances than Smart Mobile Identity — to say nothing of next-gen biometrics projects that can scan thearea around your eye, your odor, and even the way you walk.
It’ll be a very long time before any of those detection systems can run on a phone, however. And even with the Defense Department’s budget crunch, the Army and now the Navy are showing interest in equipping their troops with smartphone and smartphone-like devices. Enabling them to scan someone’s physical features with the same device may not be a step too far.



Via: "Wired"

Tuesday, December 18, 2012

Feds Can Identify You By Your Voice



By Steve Huff
Courtesy Of "Alter-Net"

In case Orwellian surveillance systems like TrapWire weren’t creepy enough, we learn that  SpeechPro, a Russian-owned company, has helpfully invented a voice identification tool for law enforcement use called VoiceGrid Nation. American authorities are looking into using the software at 911 call centers and in police precincts. As Slate reports, it’s already in place and working out pretty well in some other countries :
The technology has already been deployed across Mexico, where it is being used by law enforcement to collect, store, and search hundreds of thousands of voice-prints. Alexey Khitrov, SpeechPro’s president, told me the company is working with a number of agencies in the United 
States at a state and federal level. He declined to reveal any names because of nondisclosure and confidentiality agreements. But Khitrov did divulge that various versions of the company’s biometric technology are used in more than 70 countries and that the Americas, Europe, and Asia are its key markets. Not all of its customers are law enforcement agencies, either. 

SpeechPro also designs voice recognition technology that can be used in call centers to verify the identities of customers. Depending on the size and specifics of the installation, it can cost from tens of thousands up to millions of dollars.
Slate notes that this software is different from the FBI’s own  efforts at putting wholesale biometric programs in place , though no less scary.
Mr. Khitrov told Slate that SpeechPro is being used for “noble causes.” His example of one such noble cause was when the technology helped Mexican authorities track down kidnappers via recorded ransom calls.
A look at SpeechPro’s site reveals a product description or two that privacy activists might find pretty creepy. The blurb for  VoiceGrid ID  has a particularly dystopic echo, offering a “voice data management solution with unlimited database size” in addition to system architecture that scale all the way up to “national system deployments.”
We look forward to a future when products like these have turned the frivolous distractions of texting and iMessaging into acts of civil disobedience.

Tuesday, November 13, 2012

DNA Could Soon Be Used To Reconstruct Facial Images

DNA strand

By Bryan Nelson,


Crime scene investigators may soon have a new tool at their disposal. Scientists are currently perfecting technology that could one day reconstruct an image of your face using just your DNA, according to New Scientist.
The technology will be most useful for police looking to identify and catch a suspect. By leaving just a strand of DNA at a crime scene — a lock of hair, saliva on a cigarette butt, even dead skin cells — a suspect could have his or her face reconstructed and broadcasted for all to see. The technology is still in its infancy, but once realized, it could eventually make police sketch artists obsolete.
A recent study identifying five genes that contribute to facial shape and features has made the technology feasible. Manfred Kayser and colleagues from the Erasmus University Medical Center in Rotterdam, the Netherlands, spearheaded the research. They analyzed DNA from 10,000 Europeans and compared the results against nine specific facial landmarks which were recorded using three-dimensional MRI scans of the subjects' heads. An additional eight facial landmarks were also analyzed using photographs of the subjects' faces.
Several key correlations between genes and facial features were identified. For instance, a gene called TP63 could predict the gap between the centers of each eye socket by a distance of about 9 millimeters. Other genes also predicted features like the distance from the eyes to the bridge of the nose, the length of the nose, and the facial width between cheekbones.
These findings, coupled with previous DNA tests already known to identify eye, hair and skin color, are a big step toward perfecting DNA facial reconstruction technology. Even so, scientists caution that the method is still a long way off from being able to reconstruct all the nuances of a person's face.
Further research is already underway, though. For instance, researcher Mark Shriver of Pennsylvania State University in Hershey is currently working on a studylooking at up to 7,000 facial landmarks, and his study involves a far more diverse set of subjects, not just the faces of Europeans.
The technology may one day also benefit other fields of research. For instance, it could allow archeologists to gaze upon the faces of ancient peoples with startling accuracy. Or perhaps one day individuals researching their family trees could look upon their ancestors even when no photographs remain.

Tuesday, October 16, 2012

5 Creepy New Ways You Are Being Tracked



By Alex Kane,

1. GPS Devices In Candy Bars

Nestle really wants to find you--so much so that they’re placing Global Positioning System devices in their products,CBS News reports. 

The Nestle “We Will Find You” campaign has started in the United Kingdom. CBS reports that “once the winning candy bar wrapper is opened, the tracking device will go off and Nestle officials will be able to find the exact location of the customer.”

Once Nestle literally finds you, the customer can win over $16,000.

2. Forget ATM Cards--Use Your Hand!

In Japan, the Ogaki Kyoritsu Bank wants you to never have to remember to take your debit card to an ATM machine. Instead, customers will be allowed to “withdraw cash, make deposits and check account balances through simple palm scans,” according to The Japan Times.

The paper reports that all customers have to do to use the service is “input their birthday, put their palm on the scanner and input their PIN code.” On Thursday, the palm scanning system will expand to 18 branches.

3. Voice Identification By Law Enforcement

A Russian-owned company called SpeechPro has invented a tool so law enforcement authorities can identify a caller by their voice. U.S. authorities are looking into whether they can bring the practice here after successful trial runs in Mexico. Slate reports that “the company is working with a number of agencies in the United States at a state and federal level.”

The New York Observer notes that privacy activists are bound to be upset by SpeechPro’s products. “The blurb for  VoiceGrid ID  has a particularly dystopic echo, offering a ‘voice data management solution with unlimited database size’ in addition to system architecture that scale all the way up to ‘national system deployments.’”

4. Undercover Agents Using Cell Phones

Pacific Standard magazine picks up on a National Journal report that police in Tampa during the Republican National Convention “tried out a new system that turned ‘off-the-shelf smartphones and tablets into tools for sending real-time video, voice, and data.’”

In other words, as the magazine put it: “The guy next to you taking cellphone snapshots may not be a fellow traveller, but an undercover officer sending real-time video to a distant spy center.”

Furthermore, the National Journal reports, the phones used by Tampa police were linked up with “fixed-surveillance camera feeds… global-positioning system information, and traditional radio traffic.”

5. Followed To The Grave

The square digital barcodes that you can scan with a SmartPhone are now being used on headstones, the markers placed over graves.

NPR reports that these QR Codes are being developed by Lori and Rick Miller so that families can set up a website for deceased loved ones that is triggered by scanning your SmartPhone.

The Millers “are launching a new business called Digital Legacy's to sell the tags. Visitors to a tagged grave can pull out their smartphones, scan the QR symbol, and be sent to a personalized Web page for the deceased,” according to NPR.

Lori Miller tells NPR that “they can just upload the photos to the website and we can build their website for them...They give us a biography of their loved ones, and they can upload videos and backgrounds and music."

Other people besides the Millers have had similar ideas.

“And, as Lori Miller points out, the QR codes offer everyone a chance to get to know a stranger whose name or death date makes a passerby curious,” reports NPR.

Via: "Alter-Net"

Monday, September 10, 2012

FBI Installing NGI System Across The Nation


Birthmarks, be damned: the FBI has officially started rolling out a state-of-the-art face recognition project that will assist in their effort to accumulate and archive information about each and every American at a cost of a billion dollars.
The Federal Bureau of Investigation has reached a milestone in the development of their Next Generation Identification (NGI) program and is now implementing the intelligence database in unidentified locales across the country, New Scientist reports in an article this week. The FBI first outlined the project back in 2005, explaining to the Justice Department in an August 2006 document (.pdf) that their new system will eventually serve as an upgrade to the current Integrated Automated Fingerprint Identification System (IAFIS) that keeps track of citizens with criminal records across America .
“The NGI Program is a compilation of initiatives that will either improve or expand existing biometric identification services,” its administrator explained to the Department of Justice at the time, adding that  the project, “will accommodate increased information processing and sharing demands in support of anti-terrorism.”
“The NGI Program Office mission is to reduce terrorist and criminal activities by improving and expanding biometric identification and criminal history information services through research, evaluation and implementation of advanced technology within the IAFIS environment.”
The agency insists, “As a result of the NGI initiatives, the FBI will be able to provide services to enhance interoperability between stakeholders at all levels of government, including local, state, federal, and international partners.” In doing as such, though, the government is now going ahead with linking a database of images and personally identifiable information of anyone in their records with departments around the world thanks to technology that makes fingerprint tracking seem like kids' stuff.
According to their 2006 report, the NGI program utilizes “specialized requirements in the Latent Services, Facial Recognition and Multi-modal Biometrics areas” that “will allow the FnewBI to establish a terrorist fingerprint identification system that is compatible with other systems; increase the accessibility and number of the IAFIS terrorist fingerprint records; and provide latent palm print search capabilities.”
Is that just all, though? During a 2010 presentation (.pdf) made by the FBI’s Biometric Center of Intelligence, the agency identified why facial recognition technology needs to be embraced. Specifically, the FBI said that the technology could be used for “Identifying subjects in public datasets,” as well as “conducting automated surveillance at lookout locations” and “tracking subject movements,” meaning NGI is more than just a database of mug shots mixed up with fingerprints — the FBI has admitted that this their intent with the technology surpasses just searching for criminals but includes spectacular surveillance capabilities. Together, it’s a system unheard of outside of science fiction.
New Scientist reports that a 2010 study found technology used by NGI to be accurate in picking out suspects from a pool of 1.6 million mug shots 92 percent of the time. The system was tested on a trial basis in the state of Michigan earlier this year, and has already been cleared for pilot runs in Washington, Florida and North Carolina. Now according to this week’s New Scientist report, the full rollout of the program has begun and the FBI expects its intelligence infrastructure to be in place across the United States by 2014.
In 2008, the FBI announced that it awarded Lockheed Martin Transportation and Security Solutions, one of the Defense Department’s most favored contractors, with the authorization to design, develop, test and deploy the NGI System. Thomas E. Bush III, the former FBI agent who helped develop the NGI's system requirements, tells NextGov.com, "The idea was to be able to plug and play with these identifiers and biometrics." With those items being collected without much oversight being admitted, though, putting the personal facts pertaining to millions of Americans into the hands of some playful Pentagon staffers only begins to open up civil liberties issues.
Jim Harper, director of information policy at the Cato Institute, adds to NextGov that investigators pair facial recognition technology with publically available social networks in order to build bigger profiles. Facial recognition "is more accurate with a Google or a Facebook, because they will have anywhere from a half-dozen to a dozen pictures of an individual, whereas I imagine the FBI has one or two mug shots," he says. When these files are then fed to law enforcement agencies on local, federal and international levels, intelligence databases that include everything from close-ups of eyeballs and irises to online interests could be shared among offices.
The FBI expects the NGI system to include as many as 14 million photographs by the time the project is in full swing in only two years, but the pace of technology and the new connections constantly created by law enforcement agencies could allow for a database that dwarfs that estimate. As RT reported earlier this week, the city of Los Angeles now considers photography in public space “suspicious,” and authorizes LAPD officers to file reports if they have reason to believe a suspect is up to no good. Those reports, which may not necessarily involve any arrests, crimes, charges or even interviews with the suspect, can then be filed, analyzed, stored and shared with federal and local agencies connected across the country to massive data fusion centers. Similarly, live video transmissions from thousands of surveillance cameras across the country are believed to be sent to the same fusion centers as part of TrapWire, a global eye-in-the-sky endeavor that RT first exposed earlier this year.
“Facial recognition creates acute privacy concerns that fingerprints do not,” US Senator Al Franken (D-Minnesota) told the Senate Judiciary Committee’s subcommittee on privacy, technology and the law earlier this year. “Once someone has your faceprint, they can get your name, they can find your social networking account and they can find and track you in the street, in the stores you visit, the government buildings you enter, and the photos your friends post online.”
In his own testimony, Carnegie Mellon University Professor Alessandro Acquisti said to Sen. Franken, “the convergence of face recognition, online social networks and data mining has made it possible to use publicly available data and inexpensive technologies to produce sensitive inferences merely starting from an anonymous face.”
“Face recognition, like other information technologies, can be source of both benefits and costs to society and its individual members,” Prof. Acquisti added. “However, the combination of face recognition, social networks data and data mining can significant undermine our current notions and expectations of privacy and anonymity.”
With the latest report suggesting the NGI program is now a reality in America, though, it might be too late to try and keep the FBI from interfering with seemingly every aspect of life in the US, both private and public. As of July 18, 2012, the FBI reports, “The NGI program … is on scope, on schedule, on cost, and 60 percent deployed.”

Thursday, May 17, 2012

Welcome To America's Biggest Spy Center

What will be going on within the top-secret walls of the $2 billion Utah Data Center? The answer...surveillance - but not just surveillance - we're talking the biggest spy center this nation has ever seen.


Posted by "Sayf Maslul"

By "James Bamford"
Investigative Journalist
Courtesy Of "Russia Today" and "YouTube"




The NSA Is Building the Country’s Biggest Spy Center (Watch What You Say)
Under construction by contractors with top-secret clearances, the blandly named Utah Data Center is being built for the National Security Agency. A project of immense secrecy, it is the final piece in a complex puzzle assembled over the past decade. Its purpose: to intercept, decipher, analyze, and store vast swaths of the world’s communications as they zap down from satellites and zip through the underground and undersea cables of international, foreign, and domestic networks.

The heavily fortified $2 billion center should be up and running in September 2013. 

Flowing through its servers and routers and stored in near-bottomless databases will be all forms of communication, including the complete contents of private emails, cell phone calls, and Google searches, as well as all sorts of personal data trails—parking receipts, travel itineraries, bookstore purchases, and other digital “pocket litter.” It is, in some measure, the realization of the “total information awareness” program created during the first term of the Bush administration—an effort that was killed by Congress in 2003 after it caused an outcry over its potential for invading Americans’ privacy. Continue

Army Wants To Monitor Your Computer Activity




By Joe Gould - Staff writer
Posted : Saturday May 5, 2012 12:22:14 EDT
Courtesy Of "The Army Times"


In the wake of the biggest dump of classified information in the history of the Army, the brass is searching for ways to watch what every soldier is doing on his or her Army computer.
The Army wants to look at keystrokes, downloads and Web searches on computers that soldiers use.
Maj. Gen. Steven Smith, chief of the Army Cyber Directorate, said the software was one of his chief priorities, joking that it would take the place of a lower-tech solution: “A guy with a large bat behind every user as they go to search the Internet.”
“Now we’ve been in the news — I don’t know if you’ve seen it — with a little insider threat issue,” Smith continued.
Smith did not mention Pfc. Bradley Manning by name. However, the effort comes in the wake of the former intelligence analyst’s alleged leak of hundreds of thousands of pages of classified documents to the anti-secrecy organization WikiLeaks in 2009 and 2010. Manning faces a military trial on 22 counts, including aiding the enemy.
According to Smith, the Army will soon shop for software pre-programmed to detect a user’s abnormal behavior and record it, catching malicious insiders in the act. Though it is unclear how broadly the Army plans to adopt the program, the Army has more than 900,000 users on its computers.
Smith explained how it might work.
“So I’m on the South American desk, doing intelligence work and all of a sudden I start going around to China, let’s say,” Smith said. “That might be an anomaly, it might be justified, but I would sure like to know that and let someone make a decision, almost at the speed of thought.”
The scenario echoes the allegations against Manning: As an intelligence analyst charged with researching the Shiite threat to Iraqi elections, Manning raided classified networks for State Department cables, Afghanistan and Iraq war logs and video from a helicopter attack, according to courtroom testimony.
Software of the type Smith describes is at various stages of development in the public and private sectors. Such software could spy on virtually any activity on a desktop depending on its programming, to detect when a soldier searches outside of his or her job description, downloads massive amounts of data from a shared hard drive or moves the data onto a removable drive.
The program could respond by recording the activity, alerting an administrator, shutting down the user’s access, or by feeding the person “dummy data” to watch what they do next, said Charles Beard, a cybersecurity executive with the defense firm SAIC’s intelligence, surveillance and reconnaissance group.
“It’s a giant game of cat and mouse with some of these actors,” Beard said.
What’s exciting, Smith said, is the possibility of detecting problems as they happen, on what cybersecurity experts call “zero day,” as opposed to after the fact.
“We don’t want to be forensics experts. We want to catch it at the perimeter,” Smith said. “We want to catch this before it has a chance to be exploited.”

A GOVERNMENTWIDE EFFORT




The Army’s efforts dovetail with a broader federal government initiative. President Obama signed an executive order last October that established an Insider Threat Task Force to develop a governmentwide program to deter, detect and mitigate insider threats.
Among other responsibilities, it would create policies for safeguarding classified information and networks, and for auditing and monitoring users.
In January, the White House’s Office of Management and Budget issued a memo directing government agencies that deal with classified information to ensure they adhere to security rules enacted after the WikiLeaks debacle.
Beyond technical solutions, the document asks agencies to create their own “insider threat program” to monitor employees for “behavioral changes” suggesting they might leak sensitive information.
The interagency Insider Threat Task Force is aiming to complete work on the new standards by October. These standards may address training and employee awareness protocols, said John Swift III, senior policy adviser to a task force now working on the draft policy.
Deanna Caputo, lead behavioral psychologist for Mitre Corp., said both technical solutions and monitoring of human behaviors are needed for a successful detection and prevention program.
“To think that we can tackle the problem simply by technical solutions is a mistake,” Caputo said.
A “culture of reporting” is essential, she said. “We need to up the ante and expect a little bit more from our people” to report abnormal behaviors among their co-workers. However, “there is a fine line with that [reporting]. People need to trust they are in a safe environment to do their job.”
Carnegie Mellon’s Software Engineering Institute has compiled 700 insider threat case studies, and come up with two broad profiles of insiders who steal intellectual property in business settings.
One is an “entitled independent” disgruntled with his job who typically exfiltrates his work a month before leaving. The other is an “ambitious leader” who steals information on entire systems and product lines, sometimes to take to a foreign country, such as China.
According to Patrick Reidy, who leads the FBI’s insider threat program, such users may be conducting authorized activities for malicious ends, and their actions would not register on intrusion detection or anti-virus systems.
“People look at computers and networks but not people and data,” he said. “The insider threat is all about people.”
Reidy, Swift and Caputo discussed the effort at a defense industry convention in Washington, D.C., on April 4.

THE ‘PRE-CRIME’ DIVISION




Private industry and the Defense Advanced Research Projects Agency are among the entities that have technological solutions in various stages of progress.
Raytheon’s SureView software captures any security breach or policy violation it’s programmed to find and can “replay the event like a DVR,” for a local administrator or others to view, according to the company’s website. The software’s trigger is programmable and can be set to any behavior considered suspicious or not.
Working with Raytheon, a group of cadets from the U.S. Military Academy at West Point last year conducted a simulation of an insider attack at a forward operating base. Cadets looked at how to fine-tune the way SureView detects potential threats and eliminate false positives for innocuous behavior, said West Point computer science professor Col. Greg Conti.
“It was very powerful, very flexible and allowed you to monitor with very fine resolution activities on the desktop, and the real trick becomes how you detect anomalous behavior,” Conti said. “Predictive models are kind of the holy grail. When you see that no one else has done something but bad guys, you can start being predictive.”
At SAIC, which is testing a behavior analytics system, Beard likened behavioral modeling to the Pre-Crime unit from the science fiction movie “Minority Report.” Instead of using psychics to stop crimes before they occur, the software would be programmed to detect behavior that has preceded malicious acts in the past.
In real life, researchers are examining the behavior of malicious insiders to see what actions they took before they acted out. That in turn would be used to teach the software what behavior to flag.
“We may want to administer policies that say, ‘Gee, gosh, why do you really want to download 300 [megabytes] of stuff or a gig of data in a single session?’ ” Beard said. “We look for the antecedents of behavior that would suggest based on past history that bad things are going to take place.”
That could be visiting restricted websites, requesting access to information outside of one’s job description or asking for large amounts of storage media — or likely some combination of the above. Individually, the actions may not seem problematic, but combined and in the context of human intelligence, they could raise alarms.
“We start taking those things and recombining them to say, ‘What is going on in the environment?’ ” Beard said. “Any one of those things independently can be totally innocuous and innocent, but when you put them together — plus their job, plus their access, plus the things they are working on — you may be looking at it as a counterintel kind of thing.”

DRAWBACKS AND CHALLENGES




Cybersecurity expert Michael Tanji, an Army veteran who has spent nearly 20 years in the U.S. intelligence community, said he sees potential drawbacks and unanswered policy questions. He asked how the Army would implement such technology without unintentionally stifling cross-disciplinary collaboration among soldiers.
Knowing they are being monitored, personnel might avoid enterprising or creative behavior for fear it would be flagged by monitoring software, he said.
Tanji also predicted the technology would come at a considerable financial cost, both to warehouse the data collected by the software and to pay the added staff needed to monitor the reports it generates.
“A brigade-sized element that uses computers on a regular basis would probably need a company-sized element just to keep up with the data that comes in,” he said.
Reidy, the FBI official, said such concerns were valid. Because software may report benign behavior as malicious and vice versa, he cautioned against using technical solutions alone to solve insider threats.
“After a major incident, and no offense to any vendors, but the charlatanism always goes up,” he said. “It’s absolutely amazing how many phone calls I get from people who say they have solved the WikiLeaks problem or solved this or that problem. Everybody’s got to eat, but it’s simply not true.”
Finding bad behavior amid the vast sea of keystrokes, downloads and Web browsing on military computers is no easy task, DARPA acknowledges.
A DARPA solicitation for Suspected Malicious Insider Threat Elimination, or SMITE, announces it is attempting to recognize “moving targets” — telltale patterns of behavior amid “enormous amounts of noise (observational data of no immediate relevance).”
The program, based in behavioral science, would have to distinguish anomalous behavior from normal behavior, and deceptive and malicious behavior from anomalous behavior, the solicitation reads.
A solicitation for another program — Anomaly Detection at Multiple Scales, or ADAMS — uses accused Fort Hood shooter Maj. Nidal Hasan to frame the problem. It asks how to sift for anomalies through millions of data points — the emails and text messages on Fort Hood, for instance — using a unique algorithm, to rank threats and learn based on user feedback.
The program is trying to look beyond computers to spot the point when a good soldier turns, whether that means homicidal or suicidal or ready to dump stolen data.
“When we look through the evidence after the fact, we often find a trail — sometimes even an ‘obvious’ one,” the solicitation states. “The question is, can we pick up the trail before the fact, giving us time to intervene and prevent an incident? Why is that so hard?”

Tuesday, May 15, 2012

The US Military Wants To 'Microchip' Troops

Microchip

By Robert Johnson
May 6, 2012, 8:20 AM
Courtesy Of "Business Insider"

DARPA is at it again. This time, the Defense Advanced Research Projects Agency has announced plans to create nanochips for monitoring troops health on the battlefield.
Kate Knibbs at Mobiledia reports the sensors are targeted at preventing illness and disease, the two causes of most troops medical evacuations.
What seems like a simple way of cutting costs and increasing efficiency has some people concerned that this is the first step in a "computer chips for all" scenario.
Bob Unruh at WND reports one of those opponents, Katherine Albrecht, co-author of Spychips says “It’s never going to happen that the government at gunpoint says, ‘You’re going to have a tracking chip. It’s always in incremental steps. If you can put a microchip in someone that doesn’t track them … everybody looks and says, ‘Come on, it’ll be interesting seeing where we go.'”
She said it was expected that captive audiences, such as prisoners and troops, would be the first subjected to the requirement, which would make it easier for the general populace to accept it as well. “It’s interesting,” she said. “I’m stunned how this younger generation is OK. They don’t see the problem. … ‘Why wouldn’t everyone want to be tracked?’”
But she said Americans will have to decide to say no to incremental advances, or by the time officials finally roll out the idea of chips for all, whether they want them or not, it will be too late to decide. “The analogy that I draw is [that of a train], and if I’m in California and I do not want to wind up in New City, every stop brings me closer,” she said. “At some point I have to get off the train.”
DARPA is calling the effort "a truly disruptive innovation," that could help the U.S. fight healthier and more