Risk
9/11/2012
09:48 AM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

FBI's Facial Recognition Program: Better Security Through Biometrics

The FBI's facial recognition technology is a boon for law enforcement--and perhaps soon for enterprise and consumer security as well.

The FBI is moving ahead with a nationwide facial recognition program scheduled to be fully deployed by 2014, according to New Scientist and testimony delivered to the Senate in July. The program could lead to faster, more efficient law enforcement--but nabbing crooks after a crime is only part of the appeal. The technology also foreshadows upcoming security enhancements that will stop many offenses before they start, including several that plague businesses.

The new tools are part of the FBI's $1 billion Next Generation Identification (NGI) program, a surveillance initiative built around biometric data.

This data involves more than facial-recognition tools. Originally conceived to replace the bureau's aging fingerprint identification system, NGI also employs a 10-point fingerprint matching process that is 99% accurate. Other capabilities include the ability to deduce identities from palm prints, tattoos, and potentially even DNA.

[ For more on the FBI's biometric ID program, see FBI To Add Tattoos To Biometric ID Capabilities. ]

Some of these tools won't be widely deployed until NGI is fully operational in summer 2014, but the facial recognition is slowly proliferating. Michigan initiated a beta rollout in February, and at least 10 additional states have either begun testing or expressed interest.

The FBI most recently disclosed details about the pilot program when the bureau's Jerome Pender tesitfied before the Senate in July. He said that NGI's facial recognition tools can compare a query image to a database of 12.8 million mug shots. Such a large database should facilitate easier tracking of suspects who flee across jurisdictions, and research suggests the effects could be dramatic; 2010 tests found that facial recognition tools correctly identified individuals from a pool of 1.6 million mug shots with 92% accuracy.

Newer versions could be even better. Researchers at Carnegie Mellon have developed algorithms that use 3-D modeling to more accurately divine identities from faces, and Alessandro Acquisti, a professor at the university, told the Senate in July that face detection is mature enough for primetime.

Acquisti also expressed caution about the technology's power. Civil libertarians are concerned the technology represents Big Brother as much as big data. They cite, among other things, the FBI's suggestion that NGI could be used to track individuals within crowds. The FBI has taken steps to ensure innocent citizens are not targeted for surveillance, however; Pender told the Senate that query images obtained through social networking sites, surveillance cameras, and similar sources "are not used to populate the national repository."

Outside the government, biometric tech has a mixed record. Facebook inadvertently triggered controversy when it integrated facial-recognition technology into its photo-tagging function. And UPEK fingerprint readers were shown in August to suffer from a vulnerability that could expose passwords.

Other developments have been more auspicious, however. Saratoga Hospital, in Saratoga Springs, NY, used biometric technology provided by DigitalPersona Inc. to more efficiently and securely verify access to confidential records. In the consumer realm, Apple's July acquisition of fingerprint security company AuthenTec suggests biometrics may headline future iOS and OS X enhancements.

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
PJS880
50%
50%
PJS880,
User Rank: Ninja
9/17/2012 | 12:49:47 AM
re: FBI's Facial Recognition Program: Better Security Through Biometrics
I understand that fingerprints are 99% accurate, and I am sure that is good enough for most individuals, but what if you fall under the 1% that is inaccurate? I think biometrics is the next phase in information security, and will be implemented and unique to the user for advanced security. It is good that they are not going to be pushing the privacy limits by using data firm social sites. I cannot believe that credit cards companies have not been working on this prior as to address the billion dollar fraud market that they deal with on a daily basis and costs millions of dollars every year. I am looking forward to reading more about the NGI program!

Paul Sprague
InformationWeek Contributor
Register for Dark Reading Newsletters
White Papers
Cartoon
Latest Comment: nice post
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-1750
Published: 2015-07-01
Open redirect vulnerability in nokia-mapsplaces.php in the Nokia Maps & Places plugin 1.6.6 for WordPress allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the href parameter to page/place.html. NOTE: this was originally reported as cross-sit...

CVE-2014-1836
Published: 2015-07-01
Absolute path traversal vulnerability in htdocs/libraries/image-editor/image-edit.php in ImpressCMS before 1.3.6 allows remote attackers to delete arbitrary files via a full pathname in the image_path parameter in a cancel action.

CVE-2015-0848
Published: 2015-07-01
Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image.

CVE-2015-1330
Published: 2015-07-01
unattended-upgrades before 0.86.1 does not properly authenticate packages when the (1) force-confold or (2) force-confnew dpkg options are enabled in the DPkg::Options::* apt configuration, which allows remote man-in-the-middle attackers to upload and execute arbitrary packages via unspecified vecto...

CVE-2015-1950
Published: 2015-07-01
IBM PowerVC Standard Edition 1.2.2.1 through 1.2.2.2 does not require authentication for access to the Python interpreter with nova credentials, which allows KVM guest OS users to discover certain PowerVC credentials and bypass intended access restrictions via unspecified Python code.

Dark Reading Radio
Archived Dark Reading Radio
Marc Spitler, co-author of the Verizon DBIR will share some of the lesser-known but most intriguing tidbits from the massive report