Risk
9/11/2012
09:48 AM
Connect Directly
Twitter
RSS
E-Mail
50%
50%

FBI's Facial Recognition Program: Better Security Through Biometrics

The FBI's facial recognition technology is a boon for law enforcement--and perhaps soon for enterprise and consumer security as well.

The FBI is moving ahead with a nationwide facial recognition program scheduled to be fully deployed by 2014, according to New Scientist and testimony delivered to the Senate in July. The program could lead to faster, more efficient law enforcement--but nabbing crooks after a crime is only part of the appeal. The technology also foreshadows upcoming security enhancements that will stop many offenses before they start, including several that plague businesses.

The new tools are part of the FBI's $1 billion Next Generation Identification (NGI) program, a surveillance initiative built around biometric data.

This data involves more than facial-recognition tools. Originally conceived to replace the bureau's aging fingerprint identification system, NGI also employs a 10-point fingerprint matching process that is 99% accurate. Other capabilities include the ability to deduce identities from palm prints, tattoos, and potentially even DNA.

[ For more on the FBI's biometric ID program, see FBI To Add Tattoos To Biometric ID Capabilities. ]

Some of these tools won't be widely deployed until NGI is fully operational in summer 2014, but the facial recognition is slowly proliferating. Michigan initiated a beta rollout in February, and at least 10 additional states have either begun testing or expressed interest.

The FBI most recently disclosed details about the pilot program when the bureau's Jerome Pender tesitfied before the Senate in July. He said that NGI's facial recognition tools can compare a query image to a database of 12.8 million mug shots. Such a large database should facilitate easier tracking of suspects who flee across jurisdictions, and research suggests the effects could be dramatic; 2010 tests found that facial recognition tools correctly identified individuals from a pool of 1.6 million mug shots with 92% accuracy.

Newer versions could be even better. Researchers at Carnegie Mellon have developed algorithms that use 3-D modeling to more accurately divine identities from faces, and Alessandro Acquisti, a professor at the university, told the Senate in July that face detection is mature enough for primetime.

Acquisti also expressed caution about the technology's power. Civil libertarians are concerned the technology represents Big Brother as much as big data. They cite, among other things, the FBI's suggestion that NGI could be used to track individuals within crowds. The FBI has taken steps to ensure innocent citizens are not targeted for surveillance, however; Pender told the Senate that query images obtained through social networking sites, surveillance cameras, and similar sources "are not used to populate the national repository."

Outside the government, biometric tech has a mixed record. Facebook inadvertently triggered controversy when it integrated facial-recognition technology into its photo-tagging function. And UPEK fingerprint readers were shown in August to suffer from a vulnerability that could expose passwords.

Other developments have been more auspicious, however. Saratoga Hospital, in Saratoga Springs, NY, used biometric technology provided by DigitalPersona Inc. to more efficiently and securely verify access to confidential records. In the consumer realm, Apple's July acquisition of fingerprint security company AuthenTec suggests biometrics may headline future iOS and OS X enhancements.

Previous
1 of 2
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
PJS880
50%
50%
PJS880,
User Rank: Ninja
9/17/2012 | 12:49:47 AM
re: FBI's Facial Recognition Program: Better Security Through Biometrics
I understand that fingerprints are 99% accurate, and I am sure that is good enough for most individuals, but what if you fall under the 1% that is inaccurate? I think biometrics is the next phase in information security, and will be implemented and unique to the user for advanced security. It is good that they are not going to be pushing the privacy limits by using data firm social sites. I cannot believe that credit cards companies have not been working on this prior as to address the billion dollar fraud market that they deal with on a daily basis and costs millions of dollars every year. I am looking forward to reading more about the NGI program!

Paul Sprague
InformationWeek Contributor
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2010-5075
Published: 2014-12-27
Integer overflow in aswFW.sys 5.0.594.0 in Avast! Internet Security 5.0 Korean Trial allows local users to cause a denial of service (memory corruption and panic) via a crafted IOCTL_ASWFW_COMM_PIDINFO_RESULTS DeviceIoControl request to \\.\aswFW.

CVE-2011-4720
Published: 2014-12-27
Hillstone HS TFTP Server 1.3.2 allows remote attackers to cause a denial of service (daemon crash) via a long filename in a (1) RRQ or (2) WRQ operation.

CVE-2011-4722
Published: 2014-12-27
Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename field of an RRQ operation.

CVE-2012-1203
Published: 2014-12-27
Cross-site request forgery (CSRF) vulnerability in starnet/index.php in SyndeoCMS 3.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that add user accounts via a save_user action.

CVE-2012-1302
Published: 2014-12-27
Multiple cross-site scripting (XSS) vulnerabilities in amMap 2.6.3 allow remote attackers to inject arbitrary web script or HTML via the (1) data_file or (2) settings_file parameter to ammap.swf, or (3) the data_file parameter to amtimeline.swf.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.