Risk
1/19/2010
08:25 AM
Alexander Wolfe
Alexander Wolfe
Commentary
Connect Directly
Twitter
Facebook
RSS
E-Mail
50%
50%

Wolfe's Den: IBM Patenting Airport Security Profiling Technology

A dozen "secret" patent applications define a sophisticated scheme for airport terminal and perimeter protection, incorporating potential support for computer implementation of passenger behavioral profiling to detect security threats.

A dozen little-known IBM patent applications lay out a sophisticated computer-analysis-based approach to airport security. The technology has the potential to apply profiling of passengers, based on attributes such as age and type of clothing worn. One of the patents IBM is seeking even appears to go Israeli-style security one better, using analysis of furtive glances in the application entitled "Detecting Behavioral Deviations By Measuring Eye Movements."

The objective of the technology in the passel of patent applications is to alert officials to potential terminal and tarmac threats using a network of video, motion, chemical, and biometric sensors arrayed throughout the airport. The sensors feed into a grid of networked computers, which provide high-powered processing to get results to officials in so-called real time, yet the systems are compact enough to be located on-site.

The "secret sauce" in the set up is a software "inference engine," which crunches the data fed in by the multitude of sensors, separating the high-risk wheat from the false-alarm chaff. That engine uses heuristics and rules developed by the three co-inventors behind the patent applications--Robert Angell, Robert Friedlander and James Kraemer.

"These patents are built on the inference engine, which has the ability to calculate very large data sets in real time," Angell told me last Friday.

He called me because he was surprised I had uncovered one of the patents, which I wrote about recently in my blog post, " Obama Security Push Spurring Scanner Patents (IBM's Seeking One)." That post focused on the patent application "Risk assessment in a pre/post security area within an airport."




Detail from IBM patent application, "Unique Cohort Discovery From Multimodal Sensory Devices."
(Click for larger image and to see 19 more.)

Angell told me he believed the patents were under seal. That piqued my interest, because it indicated that this technology is probably more important -- in the sense of being proprietary and cutting edge -- than I had initially realized. As well, I knew of only the one patent and hadn't realized that, according to Angell, there were eight. (Since our conversation, I've uncovered 12 unique applications; the discrepancy might be due to the presence of duplicates--patent lawyers often revise and resubmit applications--or spin-offs.)

It turns out that, in fact, the patent applications are not under seal; that's something I don't think you can do, because the patent process is by definition open. Companies which want to shield proprietary technology go the trade-secret route, which means you keep your cutting-edge technology out of the public eye and hope no one will reverse-engineer it.

I have tracked down all the applications, and will go into the technology details, below. [Update, January 26: A paragraph in the original story stating the IBM didn't put down the company name as the assignee on three of its patent applications, which was based on failure to find that name on three applications viewed on the main patent search site, has been removed. The company name is present on the applications, when they've viewed via a different USPTO search. "We don't purposely withhold IBM's name from patent applications," as IBM spokesman said, and I accept that statement as fact.]

Angell also said that he's no longer with IBM. "I was laid off last year along with thousands of other people," he told me. Angell is currently teaching a computer science course at a community college in Salt Lake City, Utah, where he lives. I was flabbergasted, wondering how Big Blue could let go a guy like this, who obviously has heavy duty data-analysis chops and is behind such seemingly important technology.

Angell called me, he said, because he's concerned that the technology be applied effectively. "If it's done right, we could do passive profiling [and] passive detection and do it without a whole lot of fanfare," he said.

Previous
1 of 3
Next
Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-5242
Published: 2014-10-21
Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter in a get_template action.

CVE-2012-5243
Published: 2014-10-21
functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to read arbitrary database information via a crafted request.

CVE-2012-5702
Published: 2014-10-21
Multiple cross-site scripting (XSS) vulnerabilities in dotProject before 2.1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) callback parameter in a color_selector action, (2) field parameter in a date_format action, or (3) company_name parameter in an addedit action to i...

CVE-2013-7406
Published: 2014-10-21
SQL injection vulnerability in the MRBS module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2014-2531
Published: 2014-10-21
SQL injection vulnerability in xhr.php in InterWorx Web Control Panel (aka InterWorx Hosting Control Panel and InterWorx-CP) before 5.0.14 build 577 allows remote authenticated users to execute arbitrary SQL commands via the i parameter in a search action to the (1) NodeWorx , (2) SiteWorx, or (3) R...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.