Risk
2/22/2010
03:17 PM
50%
50%

DHS May Scrap Border Patrol Project

The Department of Homeland Security is reevaluating a plan to add security cameras, radar, and sensors, to patrol efforts along the U.S. Mexico border.

The Department of Homeland Security has ordered a drastic reassessment of a Mexican-border fence project that, due to delays and technology glitches, may never be completed.

A project known as SBInet to install cameras, radar, and ground sensors along the fence on the border between the U.S. and Mexico was originally meant to be completed by 2014.

In addition to providing technologic reinforcement to the U.S. Border Patrol, the project also is meant to provide personnel with a unified dashboard that lets them view the information collected by the various technology.

Despite this plan, only a prototype of the final solution is currently in use, and the DHS is considering whether to scrap the entire project.

Boeing created the prototype -- called Project 28, or P28 -- by cobbling together a variety of off-the-shelf hardware and software. Doing so made developing a workable system more difficult than anticipated, and it took two years before the DHS accepted the P28 solution for use in 2008, said Jenny Burke, a spokeswoman for Customs and Border Protection (CBP). The CBP is overseeing the project along with the DHS.

P28 is currently deployed along a 28-mile stretch of the Arizona border near the Sasabe point of entry into the U.S., and Boeing remains the contractor of record for the project, she said.

Originally, however, the DHS expected to cover the entire Arizona border with a complete deployment of the technology -- not a prototype -- by next year. That has been delayed indefinitely, Burke said.

An early phase of that deployment -- called Block One -- should be completed by the end of the year, after which the DHS will assess whether completing the rest of the border is worth the investment, she said.

"The [attitude] right now is to ensure the quality and operational effectiveness before continuing with other investments," Burke said.

Block One's first phase will cover a 23-mile stretch of border near Tucson, Arizona, and another 30 miles near Ajo, Arizona, she said. It also will overlay the prototype system.

In the meantime, the DHS plans to evaluate whether to deploy some aspects of the original system to help border patrol officers secure the border in lieu of the entire scope of the SBInet project, she said.

"A lot of them were anticipating having SBInet deployed," Burke said. The DHS and CBP would rather provide them with some of the technology than none at all, she said.

If completed, the DHS now expects the entire SBInet project to cost $6.7 billion, a readjustment from the original projected budget of $8 billion. P28 cost $20 million and to date the DHS has spent about $700 million on Block One, which had a total budget allotment of $898 million.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, January 2015
To find and fix exploits aimed directly at your business, stop waiting for alerts and become a proactive hunter.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3580
Published: 2014-12-18
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist.

CVE-2014-6076
Published: 2014-12-18
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote attackers to conduct clickjacking attacks via a crafted web site.

CVE-2014-6077
Published: 2014-12-18
Cross-site request forgery (CSRF) vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVE-2014-6078
Published: 2014-12-18
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not have a lockout period after invalid login attempts, which makes it easier for remote attackers to obtain admin access via a brute-force attack.

CVE-2014-6080
Published: 2014-12-18
SQL injection vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.