A Good American

THE WAY AHEAD IN BIG DATA EXPLOITATION


By William E. Binney & J. Kirk Wiebe


When contemplating next steps in the discussion about the collection and monitoring of electronic data (both content and metadata), we are obligated to look to two areas of knowledge for guidance - the law and technology. How can these two areas come together to provide an improved, yet constitutional 'way ahead'? The good news is that a roadmap to a solution already exists. It just needs to be implemented.

From law, we draw guidance from the Fourth Amendment to the United States Constitution, in particular the clause that requires that "probable cause" must be demonstrated before the personal information of a person can be lawfully searched. From technology we will draw from a robust, knowledge-centric capability to manage large amounts of information such that the identifying information of any innocent entity - innocent person, place, or thing - need not ever be revealed to law enforcement or national security authorities in the absence of fact-based suspicion of terrorism or other illegal activities meeting probable cause criteria approved by a duly constituted Article III court of law with a debate covering all sides of the issue. The FISC is no such court.

In a word, it is eminently possible to protect the identities of the innocent while at the same time, ensuring the national security. There is no balance – neither security, nor privacy must be sacrificed.


DISCOVERING THE THREAT – A TARGETED COLLECTION AND ANALYSIS APPROACH

The following analytic techniques are designed around demonstrated behavior that forms a basis of probable cause to examine individuals to determine if they are involved in criminal or terrorist activity. This is not proof that they are involved in those activities; it is behavior that justifies considering them in order to rule them in or out of such activity. In this larger process, the analyst strives to move his approach ever closer to a deductive approach.


Deductive Approach

  • Build social networks based on relationships in metadata such as phone numbers, email addresses, credit cards, money transfers, travel arrangements, and the like.
  • Isolate new members of these communities.
  • Extend the zone of suspicion to two degrees/hops from known criminal or terrorist entities, but
  • Exclude entire businesses and departments of governments and other large organizations to avoid including massive numbers of innocent individuals in the zone of suspicion.
  • Alert when additional participants are added to these social networks.
  • Use latent semantic indexing within social networks, including those in the zone of suspicion, to help in determining participation in these activities.
  • Calculate the probability of participation.
  • Monitor sites that advocate violence, pedophile or other criminal activity
  • Look for communications links (no social network – three or more participants) and use GPS or other metadata to locate entities.

For example, if you use Google, then you are two hops from all those using Google which eventually would include billions of entities around the world.

To add privacy to the social networks, all metadata identifiers should be uniquely encrypted to retain the network, but hide the identity of these individuals.


Inductive Approach example

Those visiting these types of sites should be looked at to insure they are not becoming radicalized or active in criminal or terrorist activity. Once resolved, they would be either excluded or targeted.


Abductive Approach example

If in geographical areas of interest, they should be looked at to determine participation in criminal or terrorist activity e.g. ISIS/Daesh or other terror groups operating in a specific geographical area.

Examine social networks that evidence a geographical distribution in or among countries associated with terror activity, drug smuggling, or other criminal activity.


PROTECTING THE INNOCENT IN DIGITAL INFORMATON

Whether data identifying an entity is captured or otherwise copied and stored by commercial entities or the government for surveillance purposes as part of a process to ensure national security, prevent crime, or to arrest those responsible for a crime, it must be immediately encrypted. Such data must remain encrypted until such time probable cause criteria under the Fourth Amendment to the Constitution are met as determined by a judge in a court of law.

The encryption used for such purposes will be among the strongest available and may be commercial, or it may be developed by the government. But in no circumstance will decryption algorithms be available to the Executive Branch of Government controlling intelligence or law enforcement agencies. It will be managed and stored with small organizations representing either or both the Judicial and Legislative branches of government. The intent is to ensure all three branches of government are responsible for the proper implementation and integrity of the process and software to ensure that the integrity of the innocent is protected to the maximum degree possible. Should some argue that encryption of the identifying information associated with a particular entity or group of entities will interfere with the effective or timely analysis of data, be assured such is not the case.

Since all activities in data can be represented in a relational graph, with dots representing entities and lines between dots representing relationships between entities, software can represent entities - either those that are highly suspicious or those that are innocent as dots with or without the presence of true identifying information Those that are innocent will be assigned a randomly generated, but unique value for processing and reference purposes only, until evidence is discovered and submitted to the court demonstrating probable cause has been established and allowing the true identity of the entity to be revealed. In this way, both suspected entities and innocent entities can be shown in relationships across all sources of data without violating anyone's Fourth Amendment privacy rights.

Such a graph of relationships might look as it does in Figure 1 of the Appendix located on the final page of this document.


RULES AS ENABLERS OF TIMELY COURT APPROVAL

Perhaps more than a few would argue that the court approval process under the Fourth Amendment, especially in matters of national security, could thwart the opportunity to interdict nefarious activities posing a threat to human life. However, this need not be the case, for it is eminently possible to capture many scenarios - criteria if you will - defined by courts but implemented in software as rules that could automatically decide whether probable cause criteria had been met. If yes, then an automated response could be sent to the submitter's information system, allowing the identifying information associated with the entity or entities involved to be revealed to the relevant intelligence analysts or investigators. Such a transaction between an Executive Branch agency and the Judiciary could be accomplished in a matter of seconds, followed by judicial review within the same day.

More subtle, perhaps more complicated situations could be addressed through an "electronic court" made possible by the use of collaboration software over a secure network connection between the court and analysts or investigators, allowing for the presentation of multimedia evidence in the form of relationship graphs, textual content, maps, whatever may be necessary to demonstrate to the court that available evidence meets probable cause criteria under the Fourth Amendment to the Constitution. This process could take just seconds in order to arrive at a warrant approval.

In summary, while court judges serving under such conditions may need to be "on call", the litigation process does not inherently or necessarily need to be long in terms of potential degradation in responding to some national security needs of the moment.

This targeted collection and analysis approach would then provide input to the overall intelligence enterprise as outlined below in Department of Defense Architectural Framework (DODAF) format Operational View 5 (OV-5).

William E Binney & J. Kirk Wiebe, March 21st, 2016



ASSEMBLE