Risk
1/19/2010
08:25 AM
Alexander Wolfe
Alexander Wolfe
Commentary
Connect Directly
Twitter
Facebook
RSS
E-Mail
50%
50%

Wolfe's Den: IBM Patenting Airport Security Profiling Technology

A dozen "secret" patent applications define a sophisticated scheme for airport terminal and perimeter protection, incorporating potential support for computer implementation of passenger behavioral profiling to detect security threats.

A dozen little-known IBM patent applications lay out a sophisticated computer-analysis-based approach to airport security. The technology has the potential to apply profiling of passengers, based on attributes such as age and type of clothing worn. One of the patents IBM is seeking even appears to go Israeli-style security one better, using analysis of furtive glances in the application entitled "Detecting Behavioral Deviations By Measuring Eye Movements."

The objective of the technology in the passel of patent applications is to alert officials to potential terminal and tarmac threats using a network of video, motion, chemical, and biometric sensors arrayed throughout the airport. The sensors feed into a grid of networked computers, which provide high-powered processing to get results to officials in so-called real time, yet the systems are compact enough to be located on-site.

The "secret sauce" in the set up is a software "inference engine," which crunches the data fed in by the multitude of sensors, separating the high-risk wheat from the false-alarm chaff. That engine uses heuristics and rules developed by the three co-inventors behind the patent applications--Robert Angell, Robert Friedlander and James Kraemer.

"These patents are built on the inference engine, which has the ability to calculate very large data sets in real time," Angell told me last Friday.

He called me because he was surprised I had uncovered one of the patents, which I wrote about recently in my blog post, " Obama Security Push Spurring Scanner Patents (IBM's Seeking One)." That post focused on the patent application "Risk assessment in a pre/post security area within an airport."




Detail from IBM patent application, "Unique Cohort Discovery From Multimodal Sensory Devices."
(Click for larger image and to see 19 more.)

Angell told me he believed the patents were under seal. That piqued my interest, because it indicated that this technology is probably more important -- in the sense of being proprietary and cutting edge -- than I had initially realized. As well, I knew of only the one patent and hadn't realized that, according to Angell, there were eight. (Since our conversation, I've uncovered 12 unique applications; the discrepancy might be due to the presence of duplicates--patent lawyers often revise and resubmit applications--or spin-offs.)

It turns out that, in fact, the patent applications are not under seal; that's something I don't think you can do, because the patent process is by definition open. Companies which want to shield proprietary technology go the trade-secret route, which means you keep your cutting-edge technology out of the public eye and hope no one will reverse-engineer it.

I have tracked down all the applications, and will go into the technology details, below. [Update, January 26: A paragraph in the original story stating the IBM didn't put down the company name as the assignee on three of its patent applications, which was based on failure to find that name on three applications viewed on the main patent search site, has been removed. The company name is present on the applications, when they've viewed via a different USPTO search. "We don't purposely withhold IBM's name from patent applications," as IBM spokesman said, and I accept that statement as fact.]

Angell also said that he's no longer with IBM. "I was laid off last year along with thousands of other people," he told me. Angell is currently teaching a computer science course at a community college in Salt Lake City, Utah, where he lives. I was flabbergasted, wondering how Big Blue could let go a guy like this, who obviously has heavy duty data-analysis chops and is behind such seemingly important technology.

Angell called me, he said, because he's concerned that the technology be applied effectively. "If it's done right, we could do passive profiling [and] passive detection and do it without a whole lot of fanfare," he said.

Previous
1 of 3
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4907
Published: 2014-07-11
Cross-site scripting (XSS) vulnerability in share/pnp/application/views/kohana_error_page.php in PNP4Nagios before 0.6.22 allows remote attackers to inject arbitrary web script or HTML via a parameter that is not properly handled in an error message.

CVE-2014-4908
Published: 2014-07-11
Multiple cross-site scripting (XSS) vulnerabilities in PNP4Nagios through 0.6.22 allow remote attackers to inject arbitrary web script or HTML via the URI used for reaching (1) share/pnp/application/views/kohana_error_page.php or (2) share/pnp/application/views/template.php, leading to improper hand...

CVE-2014-2963
Published: 2014-07-10
Multiple cross-site scripting (XSS) vulnerabilities in group/control_panel/manage in Liferay Portal 6.1.2 CE GA3, 6.1.X EE, and 6.2.X EE allow remote attackers to inject arbitrary web script or HTML via the (1) _2_firstName, (2) _2_lastName, or (3) _2_middleName parameter.

CVE-2014-3310
Published: 2014-07-10
The File Transfer feature in WebEx Meetings Client in Cisco WebEx Meetings Server and WebEx Meeting Center does not verify that a requested file was an offered file, which allows remote attackers to read arbitrary files via a modified request, aka Bug IDs CSCup62442 and CSCup58463.

CVE-2014-3311
Published: 2014-07-10
Heap-based buffer overflow in the file-sharing feature in WebEx Meetings Client in Cisco WebEx Meetings Server and WebEx Meeting Center allows remote attackers to execute arbitrary code via crafted data, aka Bug IDs CSCup62463 and CSCup58467.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Marilyn Cohodas and her guests look at the evolving nature of the relationship between CIO and CSO.