Showing posts with label Information Sharing. Show all posts
Showing posts with label Information Sharing. Show all posts

Thursday, December 2, 2010

WikiLeaks, Private Manning and Information Sharing

Yesterday on CNN's Situation Room, Jeff Toobin commented that the release of 250,000 US Embassy Diplomatic Cables by WikiLeaks shows how information sharing (connecting the dots) has gone too far since 911.

Private Bradley Manning, whether he did or did not leak the documents, should never have had access to State Department diplomatic cables. Routine access to diplomatic cables is not needed by a low-level intelligence analyst stationed in Iraq. Secretary of Defense Gates said that "What this illustrates is the incredible amount of trust we place in even our most junior men and women in uniform." To quote one wag, "Trust But Verify".

Hopefully, Secretary Gates understands that the problem goes deeper than the platitudes. The US government's entire concept of "information sharing" is based on the bureaucratic mentality that everyone has to have access to all information for anyone to connect the dots. The idea, as I've discussed in prior posts, is faulty.

The first thing anyone needs to know is that there is information on a person or an event in some government system. That can be handled by a searchable index (see the use case graphic above, click to enlarge). Whether someone gets beyond the index to actual State Department cables, for example, should (1) depend on need to know, (2) be controlled by the agency that owns the data and (3) be carefully tracked and analyzed. Private Manning and every other junior man and women in uniform does not have a blanket need to know. Secretary Gates can' t seriously believe that they do.

Unfortunately and obviously, the information sharing systems in place today (such as DOD's and State Department's SIPR-net) cannot enforce need to know while allowing available information in all government systems to be connected. The systems are faulty because the underlying information sharing concept is flawed. Prosecuting Julian Assange and Bradley Manning, the preferred bureaucratic response, will not solve this problem.

Tuesday, November 30, 2010

TSA, Probability and Profiling

US airport security is enough of a mess to generate a great SNL parody (above and here). My question, as a statistician, is how many underwear and shoe bombs have been detected with enhanced screening procedures? If the answer is "zero" or can be written in scientific notation, a lot of innocent people are being subjected to unresonable search and seizures.

Asra Nomani, a Muslim reporter with the Daily Beast, has proposed (here) that we rethink profiling. From a statistical standpoint, profiling on every relevant observable factor increases the probability of identifying terrorists. On the other side of the debate (hosted by Intelligence Squared US, here) was Michael Chertoff, former director of Homeland Security. Chertoff argues that "...racial and religious profiling would be not only ineffective, but counterproductive from a security standpoint." My comment to Mr. Chertoff would be (1) "Prove It" and (2) who said "racial and religious profiling" was the only way to profile.

Thursday, January 7, 2010

Failing to Connect the Dots

The White House released the Undie Bomber security review today. The president labeled the incident "...a failure to connect the dots..." but (1) there wasn't much more detail in the publicly released review and (2) it didn't seem to call for a change in strategy just more centralization and information passing.

Here are some readings that suggest a different strategy: (1) Congratulations, Osama, how Ben-Gurion Airport does security, (2) Profile Me If You Must, focus on people rather than screening, (3) Terror Database Has Quadrupled in Four Years, the ugly details of how the Terrorist Identities Datamart Environment (TIDE) functions and fails. (4) Meeting the Threat of Terrorism, why "discoverability" of information is more important to connecting the dots than sharing and (5) WIJIS Architecture Overview: Version 2.0, a formal information architecture to enable "discoverability"--with a criticism of the current approach.

Sunday, January 3, 2010

Need To Know vs. Need To Share

The Cold-War culture that I was exposed to in the US military and still permeates the federal government is that information should be made available on a "need to know" basis. This approach might have made some sense during the cold war but, after 9/11, it seems to make much less sense today. The cultural change being pushed right now is the "need to share".

What hopefully will not get lost in the pendulum swing from one extreme to the other is that these approaches are not mutually exclusive. Some things need to remain in the federal government stove pipes and other things need to be shared. The Markle Task Force on National Security has developed a balanced set of initiatives for information sharing emphasizing: (1) Privacy and civil liberties protection, (2) Discoverability "... offering users the ability to 'discover' data that exists elsewhere without gaining access to the underling information until the user requesting access is authorized and authenticated", (3) An "authorized use" standard for information sharing and (4) Culture change from need-to-know to need-to-share.

Particularly to the second point on discoverability, I would (1) add the important motivational element of creating a publish/subscribe system--if agencies publish, they also get to subscribe ("share-to-play") and (2) emphasize the importance of starting with basic, standardized information about events of importance to national security. Here is the relevant paragraph from the Markle Foundation report on Discoverability:

Discoverability is the first step in an effective system for information sharing, offering users the ability to “discover” data that exists elsewhere. Data is tagged at the point of collection with standardized information (e.g., who, what, where, when) and submitted to a central index. Just as a card catalogue in a library serves as a central index, directing users to relevant books—but doesn’t provide the book itself—these “data indices” point users to data holders and documents, depending on the search criteria used.

Thursday, December 31, 2009

Chertoff on Continuing Information Sharing Problems

This morning, on CNN, Michael Chertoff (the second director of the US Department of Homeland Security) gave two reasons why the US was unable to identify the Undie Bomber: (1) The European Union (EU) blocked US access to their Visa database and (2) The airlines have been reluctant to upload all their passenger information to the federal government.

If the US, EU and Canadians built a publish/subscribe index system, there would be no need to either access or share databases. Here's how it would work. The Europeans would publish only the identifying information for individuals who, for example, were denied a Visa. They would publish the event when the denial occurred.

This is very different from what Mr. Chertoff wants when he says "We have to have access to these databases." To me this means someone in the National Counterterrorism Center in the US would be logging in to the European Visa database. This is a bad idea, which the EU rightly rejected, for a number of reasons: (1) It's too slow and is based on human intervention which becomes two points of potential failure. (2) It presents a security risk to the EU in that someone has to manage the accounts and the identification methods of those in the US that are allowed access. Legitimate, dormant accounts provide one method hackers can use to access a system.

The idea of asking the airlines to upload their entire passenger database to the federal government is also a bad idea: (1) It's too slow. If it happens over night or even two hours before flight departure, the current data is always a few hours out of date e.g., someone today purchasing a ticket with cash won't be part of the last data load. (2) It's unnecessary. What is the federal government going to do with all the mundane administrative information contained in a reservation system?

The NY Times today published a description of how slow, manual and subject to human failure the current system is and was in the case of the Undie bomber. This is the mentality in the US federal government: give us all the data and we'll have someone sit at a computer and look through it. Information sharing involves humans sending information back and forth to the authorities. Any approach that is not electronically based; that does not focus on indexing in real time objects and events of importance for US security; that does not allow all the participants to publish and subscribe; and that doesn't decentralize decision making, will create more security problems than it solves.

Tuesday, December 29, 2009

Information Sharing and Counterterrorism

The recent attempt by a Nigerian man, evidently working for the Yemeni branch of Al Qaeda, to set off an underwear bomb (he is being called the Undiebomber) in a flight from Amsterdam to Detroit, has created new concerns about US security. The typical fire-drills after a terrorist threat (increased TSA shakedowns on domestic flights, new restrictions on luggage, removal of shoes, etc.) are similar to the ones that resulted from an attempt by Richard Reid on December 22, 2001 to set off a shoe bomb on an America Airlines flight. Hopefully, future travelers will not have to take off their underwear to get through airport security.

The interesting issue for me involves the continuing failure of information sharing. In response to 9/11, the US federal government has "squandered tens of millions of dollars on faulty technology, like high-tech 'puffer' machines that repeatedly broke down and flunked the most basic tests ... [but also] ... the government has yet to fully deploy a sophisticated method for matching passenger names with terrorist watch lists." The alleged Nigerian terrorist was flying from Lagos, Nigeria through Amsterdam to Detroit without luggage, possibly on a one-way ticket paid for in cash! This information alone should have raised many, many RED FLAGS, but it didn't. The dots still are not being connected.
To address the continuing failure of information sharing, I have a straight-forward solution. It's the same solution I presented to the US Department of Homeland Security (DHS) in 2004 [here, here and here] and is displayed in the graphic above. Create an XML-based indexing system that maintains pointers to sources that have information about objects of interest (e.g., people on terrorism watch lists). It is essentially a publish/subscribe system: agencies can electronically query the system, match objects indexed to objects about which they have information, and return new index records pointing to their holdings. Events would trigger new publish/subscribe transactions electronically. TSA screeners, for example, would scan passenger tickets and the system would be queried electronically. Criteria for secondary screening of passengers would be flexible and could be linked to the national threat level and changed instantly. Security for the underlying information would remain with the agency.

In 2004, DHS didn't seem very interested in my idea. They wanted all potential terrorist information stored in a very flexible XML format fusion center that would support any kind of direct querying. If that's what DHS is still insisting on, it won't happen within the bureaucracy of the US Federal government. Agencies guard their data too carefully and the central repository could not really guarantee the security of the mega-database (the 9/11 Commission Report section 13.3 UNITY OF EFFORT IN INFORMATION SHARING is interesting). In any event, it's not clear to me how the existing systems (TSA's Secure Flight and the National Counterterrorism Center's TIDE, which were based on the Northwest Airlines CAPS program) work together or are linked to, for example, the State Department's VISA database. From the descriptions, they seem too centralized rather than distributed--push the decisions as close as possible to the front lines--and too reliant on human querying.

My system isn't perfect. Agencies have to be willing or at least be compelled to query and publish to the database. The provision that they retain their own information should help with cooperation. Privacy advocates have questioned whether the index itself amounted to a fusion center or whether adequate safeguards were in place to accurately identify people. Since the system would not contain original data, only pointers, it is not a fusion center. Accurate personal identification remains a problem. A REAL ID system with stronger privacy protections than currently proposed could help reduce the identification problem (the current government ID requirement for air travel is weak). Certainly, the passport ID system could be strengthened.

This is not to say that there is a simple technical solution to the information sharing problem. There are plenty of other factors related to the growth of the US economy, the growth of the US airline industry and the growth of the US federal government. I'll talk about these issues in other posts.