Risk
11/3/2010
05:16 PM
50%
50%

TSA Calls Tech Key To Combating Terrorism

New investments in technology and continued use of body scanners to secure airports are part of strategy outlined by Transportation Safety Administration's John Pistole.

Inside DHS' Classified Cyber-Coordination Headquarters
(click image for larger view)
Slideshow: Inside DHS' Classified Cyber-Coordination Headquarters

Strengthening counter-terrorism efforts through technology is a priority of the Transportation Safety Administration, as it looks to 2011 and beyond, its administrator said this week.

Speaking at the AVSEC World 2010 aviation security conference Tuesday, TSA Administrator John Pistole outlined technology investments that his agency is making to improve airport security and counter would-be terrorist plots.

In the text of his prepared remarks available online, Pistole also defended the use of controversial Advanced Imaging Technology (AIT) -- more commonly known as body scanners -- at airports.

The machines, first deployed earlier this year at select airports, require people to walk through a full-body scanner that allows screeners to see if they have any metallic devices beneath their clothing. The use of AIT has raised privacy and health concerns, both of which the TSA has deflected.

In his comments Pistole said that AIT "has an important role in the future of aviation security." To foster better understanding of the technology, the TSA is holding an international policy summit about it next week, with representatives of 30 countries expected to attend, he said.

The TSA has deployed 350 ATI machines in nearly 70 U.S. airports, and expects to have 1,000 machines in use by the end of 2011.

Other technology the TSA plans to tap for airport security is an enhancement to ATI called Automated Target Recognition (ATR).

ATR uses an algorithm or device to recognize targets or objects based on data obtained from sensors. The technology is currently being used in Amsterdam's Schipol airport and tested in other locations.

Pistole said ATR would solve some of the issues surrounding AIT. "This capability would make screening more efficient and would eliminate most privacy concerns about the technology," Pistole said.

The TSA director also provided hope that there will soon be a solution for traveler limitations for carrying liquid through airport security checkpoints, which have been in place since would-be terrorists carried bomb-making liquids aboard an aircraft in 2006.

Pistole acknowledged that these restrictions "burden travelers and make air travel less efficient," adding that the agency is working on a "long-term, technology-based solution for screening liquids, aerosols and gels."

One such solution may be baggage X-ray belts that use advanced technology to distinguish between liquids that could be a threat and liquids that don't, he said.

Pistole said the solution would combine technologies currently in use or being tested by the TSA, such as specialized bottled liquid scanners, AIT and explosives trace-detection technology.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-8142
Published: 2014-12-20
Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.36, 5.5.x before 5.5.20, and 5.6.x before 5.6.4 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate keys w...

CVE-2013-4440
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 generates weak non-tty passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.

CVE-2013-4442
Published: 2014-12-19
Password Generator (aka Pwgen) before 2.07 uses weak pseudo generated numbers when /dev/urandom is unavailable, which makes it easier for context-dependent attackers to guess the numbers.

CVE-2013-7401
Published: 2014-12-19
The parse_request function in request.c in c-icap 0.2.x allows remote attackers to cause a denial of service (crash) via a URI without a " " or "?" character in an ICAP request, as demonstrated by use of the OPTIONS method.

CVE-2014-2026
Published: 2014-12-19
Cross-site scripting (XSS) vulnerability in the search functionality in United Planet Intrexx Professional before 5.2 Online Update 0905 and 6.x before 6.0 Online Update 10 allows remote attackers to inject arbitrary web script or HTML via the request parameter.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.