Showing posts with label Counterterrorism. Show all posts
Showing posts with label Counterterrorism. Show all posts

Thursday, January 23, 2014

Homeland Security Update

Homeland Security spokesperson Craig Fenson (played by Robert Deniro) provides an SNL terrorism update. He was introduced by Homeland Security Secretary Tom Ridge (that scene was deleted from the video for security reason) who raised the terrorism threat level to MAGENTA before Mr. Fenson provides the "Most Wanted" list. The full transcript appears below:

 Tom Ridge: Good afternoon! Before we begin today's briefing, I wish to announce that, on the basis of change in the nature of Al-Queda chatter, we are changing the current threat level to Magenta. Let me repeat: the threat level is now.. Magenta. What is Magenta? It's a darker maroon. It's not quite an ox blood. It's more plum color than.. say.. a crimson. How serious is it? [ sighs ] I honestly don't have an answer for that. We'll try to have that for you by early in the week. In any case, I'd like to introduce Craig Fenson, the new senior spokesman for the office of Homeland Security, and he'll be happy to take your questions.

Craig Fenson: Good afternoon. In the past few weeks, through our national hotline, we have collected hundreds of names of suspected terrorists, and I'm proud to say that most of the calls have come from high school and college students nationwide. In fact, we received over 475 calls alone regarding this man: M'Balz Es-Hari. We also received information on such nefarious terrorists such as Graabir Boubi, and Haid D'Salaami and.. let this be a message to you, Haid D'Salaami: we will not play your dangerous games We are also currently searching for a man we believe to be a Al Queda leutinant: Hous Bin Pharteen, his cousin I-Bin Pharteen, and their close companion I-Zheet M'Drurz. Question over there?

 Reporter #1: Is there a way to identify Hous Bin Pharteen?

 Craig Fenson: Ah.. our operatives have picked up his scent. Also, according to our intelligence, he is targeting gas refineries, fertilizer plants, and, oddly enough, baked bean canneries. He is a silent, but deadly killer.

 Reporter #2: What can you tell us about I-Zheet M'Drurz?

 Craig Fenson: We're told that, when he was fleeing the scene of his last attack, he left skidmarks. He is extremely dangerous. Our sources say that he is planning on attacking the New York City sewer system with what we believe it is to be a dirty bomb.

 Reporter #3: Do you have any other names you're willing to release?

 Craig Fenson: Yes! Please call our hotline at once if you have any information on the following men: Shaif Hirboush.. Al-Suq Akweer.. Mustaf Herod Apyur Poupr. I hope I got that right! Awan Afuqya.. Yul Strokheet Al-Wauch.. Apul Madeek - who we believe will be targeting adult bookstores sometime in the near future. And this man, the notorious Yuliqa M'Diq, A.K.A. Uwana M'Diq, A.K.A. Usuqa M'Diq. Uh.. thank you, that is all, and, "Live, from New York, it's Saturday Night!"

 Thanks to Charles Spivey for this transcript!

Thursday, January 7, 2010

Failing to Connect the Dots

The White House released the Undie Bomber security review today. The president labeled the incident "...a failure to connect the dots..." but (1) there wasn't much more detail in the publicly released review and (2) it didn't seem to call for a change in strategy just more centralization and information passing.

Here are some readings that suggest a different strategy: (1) Congratulations, Osama, how Ben-Gurion Airport does security, (2) Profile Me If You Must, focus on people rather than screening, (3) Terror Database Has Quadrupled in Four Years, the ugly details of how the Terrorist Identities Datamart Environment (TIDE) functions and fails. (4) Meeting the Threat of Terrorism, why "discoverability" of information is more important to connecting the dots than sharing and (5) WIJIS Architecture Overview: Version 2.0, a formal information architecture to enable "discoverability"--with a criticism of the current approach.

Sunday, January 3, 2010

Need To Know vs. Need To Share

The Cold-War culture that I was exposed to in the US military and still permeates the federal government is that information should be made available on a "need to know" basis. This approach might have made some sense during the cold war but, after 9/11, it seems to make much less sense today. The cultural change being pushed right now is the "need to share".

What hopefully will not get lost in the pendulum swing from one extreme to the other is that these approaches are not mutually exclusive. Some things need to remain in the federal government stove pipes and other things need to be shared. The Markle Task Force on National Security has developed a balanced set of initiatives for information sharing emphasizing: (1) Privacy and civil liberties protection, (2) Discoverability "... offering users the ability to 'discover' data that exists elsewhere without gaining access to the underling information until the user requesting access is authorized and authenticated", (3) An "authorized use" standard for information sharing and (4) Culture change from need-to-know to need-to-share.

Particularly to the second point on discoverability, I would (1) add the important motivational element of creating a publish/subscribe system--if agencies publish, they also get to subscribe ("share-to-play") and (2) emphasize the importance of starting with basic, standardized information about events of importance to national security. Here is the relevant paragraph from the Markle Foundation report on Discoverability:

Discoverability is the first step in an effective system for information sharing, offering users the ability to “discover” data that exists elsewhere. Data is tagged at the point of collection with standardized information (e.g., who, what, where, when) and submitted to a central index. Just as a card catalogue in a library serves as a central index, directing users to relevant books—but doesn’t provide the book itself—these “data indices” point users to data holders and documents, depending on the search criteria used.

Thursday, December 31, 2009

Chertoff on Continuing Information Sharing Problems

This morning, on CNN, Michael Chertoff (the second director of the US Department of Homeland Security) gave two reasons why the US was unable to identify the Undie Bomber: (1) The European Union (EU) blocked US access to their Visa database and (2) The airlines have been reluctant to upload all their passenger information to the federal government.

If the US, EU and Canadians built a publish/subscribe index system, there would be no need to either access or share databases. Here's how it would work. The Europeans would publish only the identifying information for individuals who, for example, were denied a Visa. They would publish the event when the denial occurred.

This is very different from what Mr. Chertoff wants when he says "We have to have access to these databases." To me this means someone in the National Counterterrorism Center in the US would be logging in to the European Visa database. This is a bad idea, which the EU rightly rejected, for a number of reasons: (1) It's too slow and is based on human intervention which becomes two points of potential failure. (2) It presents a security risk to the EU in that someone has to manage the accounts and the identification methods of those in the US that are allowed access. Legitimate, dormant accounts provide one method hackers can use to access a system.

The idea of asking the airlines to upload their entire passenger database to the federal government is also a bad idea: (1) It's too slow. If it happens over night or even two hours before flight departure, the current data is always a few hours out of date e.g., someone today purchasing a ticket with cash won't be part of the last data load. (2) It's unnecessary. What is the federal government going to do with all the mundane administrative information contained in a reservation system?

The NY Times today published a description of how slow, manual and subject to human failure the current system is and was in the case of the Undie bomber. This is the mentality in the US federal government: give us all the data and we'll have someone sit at a computer and look through it. Information sharing involves humans sending information back and forth to the authorities. Any approach that is not electronically based; that does not focus on indexing in real time objects and events of importance for US security; that does not allow all the participants to publish and subscribe; and that doesn't decentralize decision making, will create more security problems than it solves.

Tuesday, December 29, 2009

Information Sharing and Counterterrorism

The recent attempt by a Nigerian man, evidently working for the Yemeni branch of Al Qaeda, to set off an underwear bomb (he is being called the Undiebomber) in a flight from Amsterdam to Detroit, has created new concerns about US security. The typical fire-drills after a terrorist threat (increased TSA shakedowns on domestic flights, new restrictions on luggage, removal of shoes, etc.) are similar to the ones that resulted from an attempt by Richard Reid on December 22, 2001 to set off a shoe bomb on an America Airlines flight. Hopefully, future travelers will not have to take off their underwear to get through airport security.

The interesting issue for me involves the continuing failure of information sharing. In response to 9/11, the US federal government has "squandered tens of millions of dollars on faulty technology, like high-tech 'puffer' machines that repeatedly broke down and flunked the most basic tests ... [but also] ... the government has yet to fully deploy a sophisticated method for matching passenger names with terrorist watch lists." The alleged Nigerian terrorist was flying from Lagos, Nigeria through Amsterdam to Detroit without luggage, possibly on a one-way ticket paid for in cash! This information alone should have raised many, many RED FLAGS, but it didn't. The dots still are not being connected.
To address the continuing failure of information sharing, I have a straight-forward solution. It's the same solution I presented to the US Department of Homeland Security (DHS) in 2004 [here, here and here] and is displayed in the graphic above. Create an XML-based indexing system that maintains pointers to sources that have information about objects of interest (e.g., people on terrorism watch lists). It is essentially a publish/subscribe system: agencies can electronically query the system, match objects indexed to objects about which they have information, and return new index records pointing to their holdings. Events would trigger new publish/subscribe transactions electronically. TSA screeners, for example, would scan passenger tickets and the system would be queried electronically. Criteria for secondary screening of passengers would be flexible and could be linked to the national threat level and changed instantly. Security for the underlying information would remain with the agency.

In 2004, DHS didn't seem very interested in my idea. They wanted all potential terrorist information stored in a very flexible XML format fusion center that would support any kind of direct querying. If that's what DHS is still insisting on, it won't happen within the bureaucracy of the US Federal government. Agencies guard their data too carefully and the central repository could not really guarantee the security of the mega-database (the 9/11 Commission Report section 13.3 UNITY OF EFFORT IN INFORMATION SHARING is interesting). In any event, it's not clear to me how the existing systems (TSA's Secure Flight and the National Counterterrorism Center's TIDE, which were based on the Northwest Airlines CAPS program) work together or are linked to, for example, the State Department's VISA database. From the descriptions, they seem too centralized rather than distributed--push the decisions as close as possible to the front lines--and too reliant on human querying.

My system isn't perfect. Agencies have to be willing or at least be compelled to query and publish to the database. The provision that they retain their own information should help with cooperation. Privacy advocates have questioned whether the index itself amounted to a fusion center or whether adequate safeguards were in place to accurately identify people. Since the system would not contain original data, only pointers, it is not a fusion center. Accurate personal identification remains a problem. A REAL ID system with stronger privacy protections than currently proposed could help reduce the identification problem (the current government ID requirement for air travel is weak). Certainly, the passport ID system could be strengthened.

This is not to say that there is a simple technical solution to the information sharing problem. There are plenty of other factors related to the growth of the US economy, the growth of the US airline industry and the growth of the US federal government. I'll talk about these issues in other posts.