Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

1/19/2010
08:25 AM
Alexander Wolfe
Alexander Wolfe
Commentary
Connect Directly
Facebook
Twitter
RSS
E-Mail
50%
50%

Wolfe's Den: IBM Patenting Airport Security Profiling Technology

A dozen "secret" patent applications define a sophisticated scheme for airport terminal and perimeter protection, incorporating potential support for computer implementation of passenger behavioral profiling to detect security threats.

A dozen little-known IBM patent applications lay out a sophisticated computer-analysis-based approach to airport security. The technology has the potential to apply profiling of passengers, based on attributes such as age and type of clothing worn. One of the patents IBM is seeking even appears to go Israeli-style security one better, using analysis of furtive glances in the application entitled "Detecting Behavioral Deviations By Measuring Eye Movements."

The objective of the technology in the passel of patent applications is to alert officials to potential terminal and tarmac threats using a network of video, motion, chemical, and biometric sensors arrayed throughout the airport. The sensors feed into a grid of networked computers, which provide high-powered processing to get results to officials in so-called real time, yet the systems are compact enough to be located on-site.

The "secret sauce" in the set up is a software "inference engine," which crunches the data fed in by the multitude of sensors, separating the high-risk wheat from the false-alarm chaff. That engine uses heuristics and rules developed by the three co-inventors behind the patent applications--Robert Angell, Robert Friedlander and James Kraemer.

"These patents are built on the inference engine, which has the ability to calculate very large data sets in real time," Angell told me last Friday.

He called me because he was surprised I had uncovered one of the patents, which I wrote about recently in my blog post, " Obama Security Push Spurring Scanner Patents (IBM's Seeking One)." That post focused on the patent application "Risk assessment in a pre/post security area within an airport."




Detail from IBM patent application, "Unique Cohort Discovery From Multimodal Sensory Devices."
(Click for larger image and to see 19 more.)

Angell told me he believed the patents were under seal. That piqued my interest, because it indicated that this technology is probably more important -- in the sense of being proprietary and cutting edge -- than I had initially realized. As well, I knew of only the one patent and hadn't realized that, according to Angell, there were eight. (Since our conversation, I've uncovered 12 unique applications; the discrepancy might be due to the presence of duplicates--patent lawyers often revise and resubmit applications--or spin-offs.)

It turns out that, in fact, the patent applications are not under seal; that's something I don't think you can do, because the patent process is by definition open. Companies which want to shield proprietary technology go the trade-secret route, which means you keep your cutting-edge technology out of the public eye and hope no one will reverse-engineer it.

I have tracked down all the applications, and will go into the technology details, below. [Update, January 26: A paragraph in the original story stating the IBM didn't put down the company name as the assignee on three of its patent applications, which was based on failure to find that name on three applications viewed on the main patent search site, has been removed. The company name is present on the applications, when they've viewed via a different USPTO search. "We don't purposely withhold IBM's name from patent applications," as IBM spokesman said, and I accept that statement as fact.]

Angell also said that he's no longer with IBM. "I was laid off last year along with thousands of other people," he told me. Angell is currently teaching a computer science course at a community college in Salt Lake City, Utah, where he lives. I was flabbergasted, wondering how Big Blue could let go a guy like this, who obviously has heavy duty data-analysis chops and is behind such seemingly important technology.

Angell called me, he said, because he's concerned that the technology be applied effectively. "If it's done right, we could do passive profiling [and] passive detection and do it without a whole lot of fanfare," he said.

 

Recommended Reading:

Previous
1 of 3
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/9/2020
Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud
Kelly Sheridan, Staff Editor, Dark Reading,  7/7/2020
Why Cybersecurity's Silence Matters to Black Lives
Tiffany Ricks, CEO, HacWare,  7/8/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-11081
PUBLISHED: 2020-07-10
osquery before version 4.4.0 enables a priviledge escalation vulnerability. If a Window system is configured with a PATH that contains a user-writable directory then a local user may write a zlib1.dll DLL, which osquery will attempt to load. Since osquery runs with elevated privileges this enables l...
CVE-2020-6114
PUBLISHED: 2020-07-10
An exploitable SQL injection vulnerability exists in the Admin Reports functionality of Glacies IceHRM v26.6.0.OS (Commit bb274de1751ffb9d09482fd2538f9950a94c510a) . A specially crafted HTTP request can cause SQL injection. An attacker can make an authenticated HTTP request to trigger this vulnerabi...
CVE-2020-15504
PUBLISHED: 2020-07-10
A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firewall v18 MR-1 (named MR-1-Build396) and the v17.5 MR13 release. All other version...
CVE-2020-8190
PUBLISHED: 2020-07-10
Incorrect file permissions in Citrix ADC and Citrix Gateway before versions 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 allows privilege escalation.
CVE-2020-8191
PUBLISHED: 2020-07-10
Improper input validation in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows reflected Cross Site Scripting (XSS).