Google Meets Sherlock Homes

Soon after 9-11, Americans wondered aloud: How did our guardians miss the clues? Suspects on watch lists had moved money in curious ways. “Chatter” had risen in recent months. A visitor to the country had offered cash to learn how to fly -- but not land --- a jetliner. In hindsight, these telltale nuggets provided evidence of the terror to come.

Or did they? Most such nuggets were buried in a landslide of data arriving faster than analysts could make sense of it. A day’s take would fill more than 6 million 160-gigabyte iPods. Moreover, like people, the nuggets sometimes disagreed. And like a story told and retold, their message changed, sometimes imperceptibly.

Finally, most nuggets are cast in unstructured, “fuzzy” data. The same face -- or is it? -- may appear in three surveillance videos. Someone in Florida is snapping up potential makeshift detonators on eBay. Such clues, like most, don’t come conveniently packaged in a tidy spreadsheet or searchable text; they must be inferred from photos, videos, voice.

To thwart the next 9-11, analysts must meld the encyclopedic eye of Google with the inductive genius of Sherlock Holmes.

Late last century, Edward Tufte catalogued ways to display data that were either structured (train schedules) or similar (death rates). Today, researchers at the DHS Science and Technology Directorate are creating ways to see fuzzy data as a 3-dimensional picture where threat clues can jump out.

The field of visual analytics “takes Tufte’s work to the next generation,” said Dr. Joseph Kielman, Basic Research Lead for the Directorate’s Command, Control and Interoperability Division. Kielman advises the National Visualization and Analytics Center, based at Pacific Northwest National Laboratory, and its university partners, called the regional centers.

The centers’ interdisciplinary researchers are automating how analysts recognize and rate potential threats. Mathematicians, logicians, and linguists make the collective universe of data assume a meaningful shape. They assign brightness, color, texture, and size to billions of known and apparent facts, and they create rules to integrate these values so threats stand out. For example, a day’s cache of video, cell phone calls, photos, bank records, chat rooms, and intercepted emails may take shape as a blue-gray cloud. If terror is afoot in L.A. and Boston, those cities are highlighted on a U.S. map.

A month of static views might be animated as a “temporal” movie, where a swelling ridge reveals a growing threat.

“We’re not looking for ‘meaning,’ per se,” Kielman explains, “but for patterns that will let us detect the expected and discover the unexpected.” Neither the researchers nor the analysts, he says, need to understand the terrorists’ language -- no small advantage, given the shortage of cleared linguists.

It will be years before visual analytics can automatically puzzle out clues from fuzzy data like video, cautions Kielman: “The pre-9/11 chatter didn’t say, ‘We’re going to plow airplanes into the Twin Towers.’ To correlate these facts, you must get relational,” connecting screen names with bank records, bank records with faces. How researchers will get there remains an unwritten story. But with each chapter, the plot thickens.

Featured

  • Maximizing Your Security Budget This Year

    Perimeter Security Standards for Multi-Site Businesses

    When you run or own a business that has multiple locations, it is important to set clear perimeter security standards. By doing this, it allows you to assess and mitigate any potential threats or risks at each site or location efficiently and effectively. Read Now

  • New Research Shows a Continuing Increase in Ransomware Victims

    GuidePoint Security recently announced the release of GuidePoint Research and Intelligence Team’s (GRIT) Q1 2024 Ransomware Report. In addition to revealing a nearly 20% year-over-year increase in the number of ransomware victims, the GRIT Q1 2024 Ransomware Report observes major shifts in the behavioral patterns of ransomware groups following law enforcement activity – including the continued targeting of previously “off-limits” organizations and industries, such as emergency hospitals. Read Now

  • OpenAI's GPT-4 Is Capable of Autonomously Exploiting Zero-Day Vulnerabilities

    According to a new study from four computer scientists at the University of Illinois Urbana-Champaign, OpenAI’s paid chatbot, GPT-4, is capable of autonomously exploiting zero-day vulnerabilities without any human assistance. Read Now

  • Getting in Someone’s Face

    There was a time, not so long ago, when the tradeshow industry must have thought COVID-19 might wipe out face-to-face meetings. It sure seemed that way about three years ago. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises. 3

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols. 3

  • Camden CM-221 Series Switches

    Camden CM-221 Series Switches

    Camden Door Controls is pleased to announce that, in response to soaring customer demand, it has expanded its range of ValueWave™ no-touch switches to include a narrow (slimline) version with manual override. This override button is designed to provide additional assurance that the request to exit switch will open a door, even if the no-touch sensor fails to operate. This new slimline switch also features a heavy gauge stainless steel faceplate, a red/green illuminated light ring, and is IP65 rated, making it ideal for indoor or outdoor use as part of an automatic door or access control system. ValueWave™ no-touch switches are designed for easy installation and trouble-free service in high traffic applications. In addition to this narrow version, the CM-221 & CM-222 Series switches are available in a range of other models with single and double gang heavy-gauge stainless steel faceplates and include illuminated light rings. 3