09:48 AM
Connect Directly

FBI's Facial Recognition Program: Better Security Through Biometrics

The FBI's facial recognition technology is a boon for law enforcement--and perhaps soon for enterprise and consumer security as well.

The FBI is moving ahead with a nationwide facial recognition program scheduled to be fully deployed by 2014, according to New Scientist and testimony delivered to the Senate in July. The program could lead to faster, more efficient law enforcement--but nabbing crooks after a crime is only part of the appeal. The technology also foreshadows upcoming security enhancements that will stop many offenses before they start, including several that plague businesses.

The new tools are part of the FBI's $1 billion Next Generation Identification (NGI) program, a surveillance initiative built around biometric data.

This data involves more than facial-recognition tools. Originally conceived to replace the bureau's aging fingerprint identification system, NGI also employs a 10-point fingerprint matching process that is 99% accurate. Other capabilities include the ability to deduce identities from palm prints, tattoos, and potentially even DNA.

[ For more on the FBI's biometric ID program, see FBI To Add Tattoos To Biometric ID Capabilities. ]

Some of these tools won't be widely deployed until NGI is fully operational in summer 2014, but the facial recognition is slowly proliferating. Michigan initiated a beta rollout in February, and at least 10 additional states have either begun testing or expressed interest.

The FBI most recently disclosed details about the pilot program when the bureau's Jerome Pender tesitfied before the Senate in July. He said that NGI's facial recognition tools can compare a query image to a database of 12.8 million mug shots. Such a large database should facilitate easier tracking of suspects who flee across jurisdictions, and research suggests the effects could be dramatic; 2010 tests found that facial recognition tools correctly identified individuals from a pool of 1.6 million mug shots with 92% accuracy.

Newer versions could be even better. Researchers at Carnegie Mellon have developed algorithms that use 3-D modeling to more accurately divine identities from faces, and Alessandro Acquisti, a professor at the university, told the Senate in July that face detection is mature enough for primetime.

Acquisti also expressed caution about the technology's power. Civil libertarians are concerned the technology represents Big Brother as much as big data. They cite, among other things, the FBI's suggestion that NGI could be used to track individuals within crowds. The FBI has taken steps to ensure innocent citizens are not targeted for surveillance, however; Pender told the Senate that query images obtained through social networking sites, surveillance cameras, and similar sources "are not used to populate the national repository."

Outside the government, biometric tech has a mixed record. Facebook inadvertently triggered controversy when it integrated facial-recognition technology into its photo-tagging function. And UPEK fingerprint readers were shown in August to suffer from a vulnerability that could expose passwords.

Other developments have been more auspicious, however. Saratoga Hospital, in Saratoga Springs, NY, used biometric technology provided by DigitalPersona Inc. to more efficiently and securely verify access to confidential records. In the consumer realm, Apple's July acquisition of fingerprint security company AuthenTec suggests biometrics may headline future iOS and OS X enhancements.

1 of 2
Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Ninja
9/17/2012 | 12:49:47 AM
re: FBI's Facial Recognition Program: Better Security Through Biometrics
I understand that fingerprints are 99% accurate, and I am sure that is good enough for most individuals, but what if you fall under the 1% that is inaccurate? I think biometrics is the next phase in information security, and will be implemented and unique to the user for advanced security. It is good that they are not going to be pushing the privacy limits by using data firm social sites. I cannot believe that credit cards companies have not been working on this prior as to address the billion dollar fraud market that they deal with on a daily basis and costs millions of dollars every year. I am looking forward to reading more about the NGI program!

Paul Sprague
InformationWeek Contributor
Register for Dark Reading Newsletters
White Papers
Current Issue
Dark Reading Tech Digest September 7, 2015
Some security flaws go beyond simple app vulnerabilities. Have you checked for these?
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2015-10-09
Simple Streams (simplestreams) does not properly verify the GPG signatures of disk image files, which allows remote mirror servers to spoof disk images and have unspecified other impact via a 403 (aka Forbidden) response.

Published: 2015-10-09
The Telephony component in Apple OS X before 10.11, when the Continuity feature is enabled, allows local users to bypass intended telephone-call restrictions via unspecified vectors.

Published: 2015-10-09
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly sanitize applet URLs, which allows remote attackers to inject applets into the .appletTrustSettings configuration file and bypass user approval to execute the applet via a crafted web page, possibly related to line breaks.

Published: 2015-10-09
IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.

Published: 2015-10-09
The Safari Extensions implementation in Apple Safari before 9 does not require user confirmation before replacing an installed extension, which has unspecified impact and attack vectors.

Dark Reading Radio
Archived Dark Reading Radio
What can the information security industry do to solve the IoT security problem? Learn more and join the conversation on the next episode of Dark Reading Radio.