Craig Kaucher is the Chief Technology and Information Officer at Defense Media Activity.
April 27, 2010 - Over the past decade, approaches to securing enterprise information systems have evolved from the secure bastion, through defense in depth, to include today the concepts of continuous monitoring and operations. Through this all, many newer, more powerful technologies have emerged and been integrated into various portions of the enterprise information assurance architecture. One particular aspect of information assurance, the password, which is often seen as one of the greatest vulnerabilities of information systems, still seems to be sticking around in some form or another.
Fortunately at the Department of Defense, the Common Access Card (CAC) has alleviated much of the pain of remembering multiple passwords. Unfortunately, the still-required password, as a backup to the CAC, if nothing else, is longer than ever. Combine that with the near infinite number of passwords that almost anyone uses to access anything from on-line banking to e-commerce sites to subscriptions, and the potential for mistakes or intentional bypassing (i.e., writing them down) becomes quite high.
My own theory is that six characters in a password are about all most people will commit to memory most of the time. With each additional character required in a password, I feel there is an increased chance that people will write down the password. By the time a 16 character (or greater) password requirement is reached, my theory is that most people will write their passwords down somewhere. Again, this isn’t scientific, but just my gut feeling.
So why not do away with passwords, or at least the really big ones? Yes, decreasing the length of passwords makes cracking them mathematically more probable, or at least more quickly possible, but this can, as with the CAC, be offset by other factors or multi-factors at one time.
The password is something you know. The CAC (or any other reliable token) is something you have. What about what you are, or in other words, biometrics?
US Marine Corps Sgt. Michael Weaver uses the Biometric Automated Tool Set, Oct. 2008, to enter an Iraqi man's info. (Photo: US Marine Corps Cpl. Tyler W. Hill)
When I was teaching at the Information Resources Management College at National Defense University, I built an information assurance lab. One of the most popular labs was on biometrics. We did hands-on familiarization with fingerprint, face and voice recognition, and iris scanning technologies, looking at their strengths and weaknesses, and emphasizing their potential role in enterprise information assurance.
Biometrics technology seemed to be taking off rapidly. The Department of Defense formed the Biometrics Management Office, and it seemed like in no time, we’d all be accessing Defense Department networks with biometric technologies at the touch of a finger or a glance in the camera.
So what happened? Well, biometrics are still around at the Department of Defense, and they are used in a big way for verifying identity, not necessarily just of Defense Department personnel. The Biometrics Management Office has become the Biometrics Identity Management Agency, and it continues to be the Defense Department’s primary proponent for biometrics, internally to the department, as well as in national and international efforts to advance the use of the technology and standards.
Biometrics are being used for identification of captured or detained personnel in current theaters of war. Likewise, the Department of Homeland Security now requires biometric (fingerprint) identification of travelers to the U.S. from most countries coming through all major air ports of entry.
But back to information assurance for Defense Department systems and networks. When will we see widespread use of biometrics for this purpose? What’s stopping DoD components, or the Department at large, from using biometrics to enhance information assurance? Is it cost? Complexity? Lack of maturity or trust in the technology? If anyone has or knows of any large-scale projects to implement biometrics on an enterprise level to support information assurance, let Armed With Science know.
Tuesday, April 27, 2010
USGS to Award $4 Million in Earthquake Research Grants
April 27, 2010 - Earthquake research will receive approximately $4 million in grants from the U.S. Geological Survey (USGS) in 2010, with support going to 47 universities, state geological surveys and private firms.
“These external research grants are an important component of our overall strategy for earthquake risk reduction,” said Marcia McNutt, USGS director. “They help us engage the creativity and imagination of the best researchers nationwide who develop new tools and insights that will ultimately make us safer from seismic hazards.”
USGS supports research on earthquake hazards in at-risk regions nationwide through its Earthquake Hazards Program. This program provides information to the public and private sectors on earthquake occurrence and effects.
Examples of grant recipients include the following:
In the Pacific Northwest, John Vidale of the University of Washington will develop computer simulations of ground shaking during earthquakes in the Seattle area. This study will provide a better understanding of the influence of large sedimentary basins (such as the sediment-filled basin underlying Seattle), on ground shaking and will provide more accurate estimates of ground shaking in the region.
In Alaska, researchers will continue developing a chronology of past earthquakes along the southern coast of Alaska. This will allow Ian Shennan and colleagues from the University of Durham in the United Kingdom to provide better estimates of recurrence times for large earthquakes, both in Alaska and in similar subduction-zone settings such as Chile.
For potential applicability both nationally and internationally, Jonathan Bray and colleagues at the University of California at Berkeley will investigate the possible use of smart phones and similar personal devices to rapidly deliver earthquake shaking information. Such information would then be used to more quickly and accurately quantify and locate earthquakes as they occur.
Roland Burgmann of the University of California at Berkeley and Brendan Meade of Harvard University will develop integrated models of northern California faults using GPS, InSAR and seismicity data. The inclusion of recent geodetic data into the revision and update of the this model of the San Francisco Bay Area is critical for estimates of seismic risk in the East Bay and in the Sacramento-San Joaquin River Delta.
In southern California, Peter Shearer at the University of California at San Diego and Egill Hauksson of the California Institute of Technology will investigate mechanisms and patterns of earthquakes. Shuo Ma of San Diego State University will simulate likely earthquakes for the fault system that borders Los Angeles to the north. Lisa Grant Ludwig at the University of California at Irvine will pursue a better record of prehistoric earthquakes on the San Andreas Fault. Don Helmberger at the California Institute of Technology will investigate earthquake source processes and improve methods for rapidly estimating earthquake source properties.
“These external research grants are an important component of our overall strategy for earthquake risk reduction,” said Marcia McNutt, USGS director. “They help us engage the creativity and imagination of the best researchers nationwide who develop new tools and insights that will ultimately make us safer from seismic hazards.”
USGS supports research on earthquake hazards in at-risk regions nationwide through its Earthquake Hazards Program. This program provides information to the public and private sectors on earthquake occurrence and effects.
Examples of grant recipients include the following:
In the Pacific Northwest, John Vidale of the University of Washington will develop computer simulations of ground shaking during earthquakes in the Seattle area. This study will provide a better understanding of the influence of large sedimentary basins (such as the sediment-filled basin underlying Seattle), on ground shaking and will provide more accurate estimates of ground shaking in the region.
In Alaska, researchers will continue developing a chronology of past earthquakes along the southern coast of Alaska. This will allow Ian Shennan and colleagues from the University of Durham in the United Kingdom to provide better estimates of recurrence times for large earthquakes, both in Alaska and in similar subduction-zone settings such as Chile.
For potential applicability both nationally and internationally, Jonathan Bray and colleagues at the University of California at Berkeley will investigate the possible use of smart phones and similar personal devices to rapidly deliver earthquake shaking information. Such information would then be used to more quickly and accurately quantify and locate earthquakes as they occur.
Roland Burgmann of the University of California at Berkeley and Brendan Meade of Harvard University will develop integrated models of northern California faults using GPS, InSAR and seismicity data. The inclusion of recent geodetic data into the revision and update of the this model of the San Francisco Bay Area is critical for estimates of seismic risk in the East Bay and in the Sacramento-San Joaquin River Delta.
In southern California, Peter Shearer at the University of California at San Diego and Egill Hauksson of the California Institute of Technology will investigate mechanisms and patterns of earthquakes. Shuo Ma of San Diego State University will simulate likely earthquakes for the fault system that borders Los Angeles to the north. Lisa Grant Ludwig at the University of California at Irvine will pursue a better record of prehistoric earthquakes on the San Andreas Fault. Don Helmberger at the California Institute of Technology will investigate earthquake source processes and improve methods for rapidly estimating earthquake source properties.
Evaluation of Newly Deployed and Enhanced Technology and Practices at the Passenger Screening Checkpoint
The Transportation Security Administration (TSA) is responsible for overseeing aviation security and ensuring the safety of the air traveling public, including the screening of all passengers and property transported on passenger aircraft. As complex threats to aviation security evolve, TSA continues its mitigation efforts through the deployment of advanced technologies at the passenger screening checkpoint. A recent incident demonstrates the importance of continued development and enhancement of aviation security technologies. On December 25, 2009, a passenger on an international flight bound for the United States attempted to bring down the aircraft, with 278 passengers on board, by igniting an explosive device that was concealed in his clothing. Fortunately, as a result of quick action on the part of passengers and crew members, the fire was extinguished and tragedy was avoided.
Read On
http://www.dhs.gov/xoig/assets/mgmtrpts/OIG_10-75_Mar10.pdf
Read On
http://www.dhs.gov/xoig/assets/mgmtrpts/OIG_10-75_Mar10.pdf
Wisconsin State Patrol Tests New Path to Radio Interoperability
The Wisconsin State Patrol, which oversees traffic incidents, statewide voice communications and mobile communications networks, has devoted several years to developing a strategy for adopting the Project 25 radio interoperability standards.
Project 25 refers to a suite of standards for digital, two-way wireless communications products. A committee of manufacturers, public safety agencies, and state and federal communications professionals launched Project 25 in 1989 to provide detailed standards for interoperable radios.
Read On
http://www.ncjrs.gov/pdffiles1/nij/229517.pdf
Project 25 refers to a suite of standards for digital, two-way wireless communications products. A committee of manufacturers, public safety agencies, and state and federal communications professionals launched Project 25 in 1989 to provide detailed standards for interoperable radios.
Read On
http://www.ncjrs.gov/pdffiles1/nij/229517.pdf
Monday, April 26, 2010
Protecting Intellectual Property
by Tracy Russo
April 26, 2010 - Today the Department of Justice is recognizing the 10th annual World Intellectual Property Day. Intellectual property refers to creations of the mind –music, literature, film, artistic works, and inventions. Intellectual property is one of America’s greatest assets. Its protection is central to our economic prosperity and security as well the public’s health and safety. Aggressive intellectual property law enforcement is crucial to our continued success and safety, and is a top priority of the Department of Justice.
Earlier this year, Attorney General Eric Holder announced the creation of the Task Force on Intellectual Property. The Task Force strengthens efforts to combat intellectual property crimes through close coordination with state and local law enforcement partners as well as our international counterparts.
Today, that Task Force got even stronger. Acting Deputy Attorney General Gary G. Grindler, who serves as the Chair of the Task Force, announced the appointment of 15 new Assistant U.S. Attorney positions and 20 FBI Special Agents to be dedicated to combating domestic and international IP crimes.
In an op-ed featured in the National Law Journal, Acting Deputy Attorney General Grindler explained why combatting intellectual property crime is so vital to our national interest:
Businesses that create and rely upon intellectual property, from large entertainment conglomerates to small biotech firms, make up among the fastest-growing sectors of the U.S. economy. These industries also represent a significant portion of U.S. exports, with intellectual property now comprising a significant – and growing – share of the value of world trade.
The proliferation of worldwide Internet access and advances in traditional distribution methods, such as transportation and shipping, now allow American businesses of all sizes to market their intellectual property throughout the world. Digital content, whether embodied in software, books, games, movies, or music, can be transmitted from one corner of the world to another almost instantly.
But these unprecedented opportunities for American businesses and entrepreneurs are put at risk by criminals and criminal organizations that seek unlawfully to profit by stealing from the hard work of American artists, authors and inventors.
For every new technological advancement by American business, there is, unfortunately, a criminal who would seek to misuse it for his own illicit purposes. Criminals are responding to American innovation with their own creative methods of committing intellectual property crimes — from wide-spread online piracy, to well-funded corporate espionage, to increased trade in counterfeit pharmaceuticals and other goods.
When we fail to enforce intellectual property rights aggressively, we fail to protect some of our nation’s most important and valuable resources. The theft of even a single trade secret can completely destroy a burgeoning small business.
When criminals sell counterfeit drugs and medical devices to consumers, our nation’s public health is compromised. And, when illicit products such as counterfeit airplane parts or pirated electronic components make their way into the marketplace, they place our public safety at risk.
Our efforts to combat intellectual property crimes are stronger than ever. Through partnerships with federal, state and local law enforcement, increased cooperation with our international counterparts, and specially trained investigators and federal prosecutors the Department of Justice remains vigilant in its enforcement of intellectual property law.
April 26, 2010 - Today the Department of Justice is recognizing the 10th annual World Intellectual Property Day. Intellectual property refers to creations of the mind –music, literature, film, artistic works, and inventions. Intellectual property is one of America’s greatest assets. Its protection is central to our economic prosperity and security as well the public’s health and safety. Aggressive intellectual property law enforcement is crucial to our continued success and safety, and is a top priority of the Department of Justice.
Earlier this year, Attorney General Eric Holder announced the creation of the Task Force on Intellectual Property. The Task Force strengthens efforts to combat intellectual property crimes through close coordination with state and local law enforcement partners as well as our international counterparts.
Today, that Task Force got even stronger. Acting Deputy Attorney General Gary G. Grindler, who serves as the Chair of the Task Force, announced the appointment of 15 new Assistant U.S. Attorney positions and 20 FBI Special Agents to be dedicated to combating domestic and international IP crimes.
In an op-ed featured in the National Law Journal, Acting Deputy Attorney General Grindler explained why combatting intellectual property crime is so vital to our national interest:
Businesses that create and rely upon intellectual property, from large entertainment conglomerates to small biotech firms, make up among the fastest-growing sectors of the U.S. economy. These industries also represent a significant portion of U.S. exports, with intellectual property now comprising a significant – and growing – share of the value of world trade.
The proliferation of worldwide Internet access and advances in traditional distribution methods, such as transportation and shipping, now allow American businesses of all sizes to market their intellectual property throughout the world. Digital content, whether embodied in software, books, games, movies, or music, can be transmitted from one corner of the world to another almost instantly.
But these unprecedented opportunities for American businesses and entrepreneurs are put at risk by criminals and criminal organizations that seek unlawfully to profit by stealing from the hard work of American artists, authors and inventors.
For every new technological advancement by American business, there is, unfortunately, a criminal who would seek to misuse it for his own illicit purposes. Criminals are responding to American innovation with their own creative methods of committing intellectual property crimes — from wide-spread online piracy, to well-funded corporate espionage, to increased trade in counterfeit pharmaceuticals and other goods.
When we fail to enforce intellectual property rights aggressively, we fail to protect some of our nation’s most important and valuable resources. The theft of even a single trade secret can completely destroy a burgeoning small business.
When criminals sell counterfeit drugs and medical devices to consumers, our nation’s public health is compromised. And, when illicit products such as counterfeit airplane parts or pirated electronic components make their way into the marketplace, they place our public safety at risk.
Our efforts to combat intellectual property crimes are stronger than ever. Through partnerships with federal, state and local law enforcement, increased cooperation with our international counterparts, and specially trained investigators and federal prosecutors the Department of Justice remains vigilant in its enforcement of intellectual property law.
Meprolight Announces Magnifying Scope for Ultimate Accuracy
Or Akiva, Israel, April 26, 2010. Meprolight, a provider of innovative weapon sights, today announced Mepro MX3, a compact scope designed to improve the shooter’s capability. The new scope has X3 magnification to enhance the precision and effectiveness of the rifle’s existing sight by extending the shooting range without re-zeroing the sights.
Mepro MX3 can be attached to any standard MI-DST_L1913 Picatinny Rail, behind a reflex sight, using a quick release adapter.
The innovative magnifying scope is manufactured to the highest military standards to assure years of reliable operation under all field conditions. Any soldier, police officer, or civilian user can easily use it. Mepro MX3 is compact, lightweight and rugged, and has a wide field of view,
“Mepro MX3 can turn a simple shooter armed with an ordinary reflex sight into sharp shooter, with one simple click,” said Golan Kalimi, Meprolight’s Vice President Marketing. “By extending the range of reflex sights, shooters can achieve better performance and higher accuracy levels.”
About Meprolight
Meprolight designs and manufactures a wide array of electro-optical and optical sights and devices, night vision devices, thermal sights and a wide variety of night sights and other tritium- and LED-illuminated products and accessories for safety and security applications for the law enforcement, military and civilian communities. For more information about Meprolight visit http://www.meprolight.com/.
Mepro MX3 can be attached to any standard MI-DST_L1913 Picatinny Rail, behind a reflex sight, using a quick release adapter.
The innovative magnifying scope is manufactured to the highest military standards to assure years of reliable operation under all field conditions. Any soldier, police officer, or civilian user can easily use it. Mepro MX3 is compact, lightweight and rugged, and has a wide field of view,
“Mepro MX3 can turn a simple shooter armed with an ordinary reflex sight into sharp shooter, with one simple click,” said Golan Kalimi, Meprolight’s Vice President Marketing. “By extending the range of reflex sights, shooters can achieve better performance and higher accuracy levels.”
About Meprolight
Meprolight designs and manufactures a wide array of electro-optical and optical sights and devices, night vision devices, thermal sights and a wide variety of night sights and other tritium- and LED-illuminated products and accessories for safety and security applications for the law enforcement, military and civilian communities. For more information about Meprolight visit http://www.meprolight.com/.
Laser Decontamination: Shine a Light
Using lasers to decontaminate the site of a chemical explosion
April 26, 2010 - Dhiren Barot was an al Qaeda operative involved in plots to blow up the London subway, among other targets. To maximize the damage and the terror, he planned to pack some of his bombs with toxic gas. Fortunately, in August 2004, British authorities nabbed Barot and his accomplices before they could carry out their attacks.
But the threat of a gas attack remains. At some point, someone might succeed where Barot failed. That’s why it’s important to be ready. The right response to such an attack could minimize exposure and save hundreds of thousands of American lives.
Chemists at Idaho National Laboratory (INL) have been studying decontamination techniques for almost a decade. Their job is to plan for the worst. With funding and guidance from the Department of Homeland Security’s Science and Technology Directorate (S&T), they’re researching ways to help the nation respond to and clean up after potential chemical attacks.
Many building materials—like cement and brick—are extremely porous. Getting contaminants off surfaces like these is difficult, since they can inhabit cracks and pores. Cleaning up chemical-contaminated structures can be difficult, costly, and time-consuming. For one thing, most preferred methods employ other chemicals, like bleach solutions, which can be corrosive and aggressive to many types of surfaces.
One day, lasers could play a big role, according to Donald Bansleben, the program manager in S&T’s Chemical and Biological Division. “Lasers could help to scrub chemical-contaminated buildings clean and become a tool in the toolbox to speed a facility’s return to normal operations.”
Water inhabits those cracks and pores, too, and that’s where lasers come in. INL chemists have shown that laser pulses can flash that water into steam, carrying the contaminants back to the surface for removal by chelation or other means. “It’s a kind of laser steam-cleaning,” says chemist Bob Fox.
When INL began investigating lasers, researchers were looking for ways to dispose of radioactive contamination after a dirty bomb. Under the new S&T program, the team has been extending its work to chemical-weapon decontamination. While no terrorist has managed to deploy a dirty bomb, the same cannot be said of chemical agents.
As a new remediation technology, lasers show promise. In a series of tests still underway at the Army’s Aberdeen Proving Ground, the INL researchers have been using ltraviolet-wavelength lasers to scrub surfaces clean of sulfur mustard gas and VX, a nerve agent. The tests have proved successful so far, even on complex, porous surfaces like concrete.
Lasers can degrade weapons like VX in two ways: photochemically or photothermally. In photochemical decomposition, high-energy laser photons blast apart chemical bonds, slicing the agent into pieces. In photothermal decomposition, photons heat up the target surface enough to speed along natural degradation reactions. In some cases, the intense heat by itself can cause contaminant molecules to fall apart.
Knowing how chemical contaminants fall apart is key, because some of the elements resulting from their degradation products can themselves be hazardous. But according to Fox, the tests look good in this regard, too. “The lasers are showing neutralization of the agent without generation of dangerous byproducts,” he says.
And even if they’re not used to degrade VX or other agents, lasers could still be helpful in cleanup scenarios. Laser light could blast nasty chemicals off a wall, for example, and an integrated vacuum system could suck them up.
While using lasers to decontaminate office buildings or subway stations may sound like science fiction, Fox and his team are merely adapting an established technology. Lasers have been used in cleanup capacities for more than a decade. Dentists employ them, for example, to kill periodontal bacteria and quash mouth infections. Doctors use them to remove tattoos. And lasers have recently become a common tool to restore precious artwork.
Laser technology has other commercial applications. Some cleanup and restoration firms are already using lasers to scrub soot off building facades. And these industrial operations often use automated lasers, demonstrating that laser work can be done remotely, minimizing risks to remediation personnel responding to a chemical or radiological attack.
Fox stresses that laser decontamination is in the proof-of-principle stage, and is not an anti-terror panacea. Still, several government agencies are paying close attention as the INL team showcases the technology’s promise.
As for biological decontamination, like what was needed in the U.S. after the 2001 anthrax attacks, Fox has not yet tested bacteria-laden surfaces. “I don’t know,” he says. “But I’m willing to shine my light on anything.”
Subscribe to:
Posts (Atom)