Showing posts with label SandT. Show all posts
Showing posts with label SandT. Show all posts

Friday, November 15, 2019

New DHS SBIR Topics Published – 11-14-19


Yesterday the DHS Science and Technology Directorate (S&T) published a notice for 11 new pre-solicitation Small Business Innovation Research (SBIR) topics for possible future research programs out of the SBIR program. During pre-solicitation organizations can ask questions of the responsible S&T program managers to help those organizations understand the topic and decide if they want to try to participate in the research program. The pre-solicitation phase end on December 17th, 2019.

Overview


Nine of the topics come from S&T (topic #):

• Next Generation 9-1-1 (NG 9-1-1) Multimedia Content Analysis Engine Capability for the Emergency Communications Cyber Security Center (EC3) – (DHS201-001)
• Remote Sensor Data Protection and Anti-Spoofing – (DHS201-002)
• Digital Paging over Public Television (DHS201-003)
• Soft Targets and Crowded Places Security (DHS201-004)
• In-building Coverage Analysis System (ICAS) Using Existing First Responder’s Radio and Smartphone (DHS201-005)
• Handheld Advanced Detection/Imaging Technology System (DHS201-006)
• Enhanced Explosives and Illicit Drugs Detection by Targeted Interrogation of Surfaces (DHS201-007)
• Urban Canyon Detection Tracking and Identification of Small Unmanned Aerial Vehicles (DHS201-008)
• Machine Learning Module for Detection Technologies (DHS201-009)


Two of the topics come from the Countering Weapons of Mass Destruction (CWMD) Office:

• Innovative Technologies for Next Generation of Sample Collection Media (DHS201-010)
• Development and Evaluation of Nucleic Acid-Based Assays to Accelerate Biohazard Detection (DHS201-011)

Information on each topic as well as the point of contact information is available in this document [.PDF download link]. Each topic discussion closes with an interesting set of reference document links.

Sensor Data Protection


Topic #2, Remote Sensor Data Protection and Anti-Spoofing, is designed to address sensor issues along the US border (presumably Mexico, the Canadian border is much softer), but the topic discussion does note at least one potential commercial application; medical devices (pg 5):

“One potential commercial path is to guarantee that medical device sensor information has not been modified. This applies to implanted pacemakers or infusion pumps in particular.”

I think that this technology could be useful in a large number of other applications; anywhere that remote sensors are used to monitor and/or control operations. This would certainly include chemical manufacturing and transportation, but also access control, HVAC, automated roadways, the potential list is endless.

Small UAS in the Urban Canyon


Topic # 8 starts out with an excellent discussion of the problem (pg 18):

“The commercial use of unmanned aerial systems (UAS) in urban environments for applications such as package deliveries and surveying are expected to start soon. Nefarious uses of UAS in the urban environment will follow. Current technology for UAV detection, tracking, and identification is problematic. The detection and tracking of UAVs (both singular and swarms) is a critical task complicated by low flight height, small radar cross sections, and a complex background that include birds, insects, and flying debris. The problems for this task increase further with complex structures and high buildings that for urban canyons that block lines of sight.”

This topic is clearly not a weapon development solicitation, but instead for a detection and tracking tool. The author clearly intends, however, for this to possibly become part of a future weapon system development effort. See bullet point 3 in the ‘demonstration’ requirements: “Performs within timelines useful for completing a fire control loop [emphasis added] needed for mitigating nefarious UAVs”.

Friday, December 11, 2015

House Passes Three Homeland Security Bills

Yesterday the House passed three homeland security related bills under suspension of the rules; all with no significant opposition and little debate.

The three bills were:

HR 3875, Department of Homeland Security CBRNE Defense Act of 2015 – Voice vote
HR 3578, DHS Science and Technology Reform and Improvement Act of 2015 – 416 - 0 
HR 3869, State and Local Cyber Protection Act of 2015 – Voice vote


I do not think that these bills will be considered by the Senate before the year-end recess, but they will likely be taken up under the unanimous consent process early next year.

Monday, October 26, 2015

Committee Hearings – Week of 10-25-15

Both the House and Senate will be in Washington this week. There is only one hearing currently scheduled this week that may be (okay a little bit of a stretch) of interest to readers of this blog; an oversight hearing of DHS S&T.

S&T Oversight

The House Science, Space and Technology Committee will be holding a hearing on Tuesday on a “A Review of Progress by the Department of Homeland Security (DHS), Science and Technology Directorate”. The sole witness will be Under Secretary Brothers.

On the Floor

There will be two bills of potential interest this week that will be considered under suspension of the rules (limited debate, no amendments and 3/5th majority):

• Concur in the Senate Amendment to HR 623 – DHS Social Media Improvement Act of 2015; and
HR 3819 – Surface Transportation Extension Act of 2015


The Senate will continue working on S 754 the CISA. I am not going to try to keep up on the details of the amendment process in the Senate with its amendments to amendments processes. I’ll report on the final wording of the bill when it is passed (probably) on Tuesday.

Saturday, September 26, 2015

HR 3578 Introduced – DHS S&T

Two weeks ago Rep Ratcliffe (R,TX) introduced HR 3578, the DHS Science and Technology Reform and Improvement Act of 2015. The bill amends the authorizing language of the Homeland Security Act of 2002 as it pertains to the operations of the DHS Science and Technology (S&T) Directorate. One of the new sections being added to the 2002 Act deals specifically with the cybersecurity responsibilities of S&T.

Cybersecurity Provisions

The new §322 directs the Department to “support research, development, testing, evaluation, and transition of cybersecurity technology, including fundamental, long-term research to improve the sharing of information related to cybersecurity risks and incidents” {new §322(a)}. The expected R&D activities would include new {new §322(b)}:

• Advance the development and accelerate the deployment of more secure information systems;
• Improve and create technologies for detecting attacks or intrusions, including real-time continuous diagnostics and real-time analytic technologies;
• Improve and create mitigation and recovery methodologies, including techniques and policies for real-time containment of attacks, and development of resilient networks and information systems;
• Develop and support infrastructure and tools to support cybersecurity research and development efforts, including modeling, testbeds, and data sets for assessment of new cybersecurity technologies;
• Assist the development and support of technologies to reduce vulnerabilities in industrial control systems; and
• Develop and support cyber forensics and attack attribution.

Paragraph (d) provides a series of definitions used in this new section. The defined terms include:

• Cybersecurity risk;
• Homeland security enterprise;
• Incident; and
• Information system.

The only definition of consequence to readers of this blog is the last one. The bill uses the restrictive definition from 44 USC 3502 that specifically limit it to “a discrete set of information resources organized for the collection, processing, maintenance, use, sharing, dissemination, or disposition of information” {§3502(8)}. Interestingly the term is never actually used in the new section.

Moving Forward

Ratcliffe is the Chair of the Cybersecurity, Infrastructure Protection, and Security Technologies Subcommittee of the House Homeland Security Committee. As such he has oversight responsibility for S&T and certainly has the political pull to move this bill forward. I expect that we will see a markup hearing before his Subcommittee in the coming weeks and there is a good possibility that this bill will move forward to the full House before the end of the year.

It is strongly possible that this bill will be considered under suspension of the rules with minimal debate and no amendments. We will know better when we see how the Committee votes when this bill is marked up.

Commentary

I am glad to see that industrial control systems are finally getting the Congressional recognition they deserve separate from the larger information systems that they have been lumped in with in the last couple of years.

One problem, however, with this belated recognition of the control system security issue, is that Congress still does not understand the real scope of the problem. For example §322(c) provides a list of agencies with whom S&T should coordinate their cybersecurity research program. Unfortunately, it fails to list a number of Federal agencies that have some oversight responsibility for control systems issues, including:

• Department of Transportation (automobiles, PTC, aircraft, etc);
• Food and Drug Administration (medical devices); and
• Department of Energy (energy production and transmission)

Coordinating and sharing control system security research with these other agencies would certainly help make the Federal research dollar go much further. This is particularly important since this bill does not provide any additional funding to S&T.


BTW: Have I mentioned how much I detest the new House Homeland Security Committee website? It is set up on the infographic model instead of the ‘old fashioned’ web site model with easy to find links to specific information on the site. Whoever designed this site needs to be banished from government service until they learn how to provide information rather than making something that looks pretty.

Tuesday, June 17, 2014

First Responders Community of Practice ICR Notice – Again

Today the DHS Science and Technology Directorate (S&T) published a 60-day ICR renewal notice in the Federal Register (79 FR 34545) for their First Responders Community of Practice Program (FRCoP). I wrote about the previous submission of this ICR to OMB last year; that submission has not yet been acted upon by OMB. This ICR notice completely ignores that previous submission.

I noted in my earlier blog that the previous approval of this ICR (which expired last October) was a short term approval because OMB wanted additional information about the program and its efficacy. I noted that S&T had not included that information in its published ICR notices. Looking back now at the actual ICR submission supporting documents there is an attempt [Word® download link] by S&T to fulfill that requirement. There is no indication on the OMB site if that was considered to be an adequate response.

One interesting item of information from that S&T document is the report that there are 5,000 active members of the FRCoP. Since this ICR only covers the submission of registration information that is supplied on a one time basis, it would seem that there is a pretty good retention of site members. The site has been active since somewhere in 2010 and S&T indicates that there have been an average of 2000 registrations per year. That means that between 6,000 and 8,000 registrations have taken place. Retaining 5,000 members from that number would seem to be a pretty high success rate.

One other interesting administrative note; this ICR notice uses the same docket number as the ICR submission that was withdrawn last year. It seems that everyone, both at DHS and OMB, is ignoring the ICR that was submitted last year. That seems to be more than a little strange.


Anyway, S&T is soliciting public comments on this ICR submission. Public comments may be made via the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2012-0013). Comments need to be submitted by August 18th, 2014.

Saturday, November 2, 2013

Problems with DHS S&T ICR Publication

The DHS Science and Technology Directorate (S&T) published a 30-day information collection request (ICR) notice in Monday’s Federal Register (78 FR 66036; available on-line today) for a renewal of the authority to collect registration information for its First Responders Community of Practice Program (FRCoP) web site. This notice will almost certainly have to be re-done due to a number of inaccuracies included in the information.

Previous Problems

DHS S&T has a history of problems with this ICR (1640-0016). A renewal submission for the program had to be withdrawn for undisclosed reasons last year. A subsequent renewal submission was approved for only 9 months with the OMB’s Office of Information and Regulatory Affairs noting:

“If DHS submits a renewal of this collection, it should include a report with the following information: • How the First Responders Community of Practice is being used. Has the intended audience been reached? • An analysis by DHS of the practical utility of the collection. • An analysis by DHS of other similar platforms currently in use by first responders.”

Current Submission Problems

There are a number of problems with the current submission:

• Incorrect docket number;
• No reference to the 60-day Notice;
• Incorrect date of expiration of current ICR; and
• Does not include the information required by OIRA in previous approval

The middle two problems are technical issues that could probably be overlooked by OMB in the approval process. Since very few people actually read these ICR notices (and almost certainly none of the members of the FRCoP) there is no practical reason that OMB should reject this ICR based solely on those two deficiencies.

The first problem is a tad bit more problematic. The published docket number (DHS-2013-0028)
is for the renewal of the charter for the Homeland Security Science and Technology Advisory Committee. Any comments on this ICR posted to that docket would never be seen by OIRA in their consideration of this ICR renewal. That probably would not be a practical problem since there will likely be no comments posted on this ICR (other than a copy of this blog and I will post it to the correct docket, DHS-2012-0013).

The final problem listed is the most serious deficiency. Without this information OIRA would most probably fail to renew this ICR. I suspect that S&T intended to supply this information to OIRA in the documents that are actually submitted (including a copy of the registration form) that are normally not shown to the public. I think, however, that this information should be included in this public announcement for the renewal of this ICR so that there would be an opportunity for the affected community to weigh in on the utility and efficacy of this community of practice.

The FRCoP

What is missing from this discussion is the benefit of the this program. DHS S&T notes that this congressionally mandated program {Section 313 of the Homeland Security Act of 2002 (PL 107-296); 6 USC 193}. That is a tad bit of an exaggeration since that section does not specifically mention anything about a ‘Community of Practice’. It is just a general section dealing with the S&T provision of a technology information clearing house.

Having said that it appears that the FRCoP is a beneficial program. If it is signing up 2,000 new folks per year (according to the ICR notice), it would seem to be filling some sort of need in the emergency response community. Since I am not a member I cannot make a judgement on the level of communication and information sharing within the site, but that is the sort of information that OIRA was requesting from S&T.

It would be very worthwhile if members of the FRCoP were to weigh in on this discussion, either here or in comments to OIRA on this ICR.

Public Comments

S&T is soliciting public comments on this ICR. Comments may be submitted through the Federal eRulemaking Portal (www.Regulations.gov; Docket # DHS-2012-0013) or via email to DHS S&T (Kathy.Higgins@hq.dhs.gov). Comments need to be submitted by December 4th, 2013.


I am submitting a copy of this blog post.

Thursday, August 29, 2013

First Responders Community of Practice ICR Renewal – 60-day Notice

Today the DHS Science and Technology Directorate published a 60-day information collection request (ICR) notice in the Federal Register (78 FR 53464) for the renewal of their ICR (1640-0016) supporting their First Responders Community of Practice web site. This limited access web site allows for the exchange of information between registered members of the first responder community.

The previous renewal of this ICR only provided a one-year extension of the ICR. In the previous approval OMB noted that DHS should provide the following information in the next submission to justify the continued collection of the required information:

• How the First Responders Community of Practice is being used.
• Has the intended audience been reached?
• An analysis by DHS of the practical utility of the collection.
• An analysis by DHS of other similar platforms currently in use by first responders.

The requested information has not been provided in this ICR submission. I suspect that, unless the requested information is added to the 30-day submission notice that this ICR will be rejected by OMB. It would have been nice to have that information available for the 60-day public comment period.


NOTE: This submission continues the current practice of not including a cost burden estimate. The previously approved ICR showed an estimated annual cost burden of $50,000 for 2,000 (registration) responses at a half-hour each. This comes out to $50/hour for the value of a first responder’s time. I know that they wish they got paid that much.

Tuesday, May 11, 2010

High-Tech, High-Res

There is an interesting article over on HomelandSecurityNewsWire.com about a new surveillance camera being developed by DHS S&T. It is a new 360 surveillance video camera that is able to provide high-quality videos over the whole range of the camera while allowing high-quality live-zooms in one area while continuing to record in other areas. According to the article, this sounds like a security officer’s answer to video surveillance prayers. Now I am not a video surveillance expert, but I think that I know enough to pick out a couple of obvious problems that will limit deployment of this new system. First off, the camera system, ISIS (Imaging System for Immersive Surveillance) does provide huge amounts of detail, up to 100 megapixels according to the S&T web site. According to the S&T program director that is “as detailed as 50 full-HDTV movies playing at once”. That much information flowing from the camera to the security station is sure to take up massive amounts of bandwidth. That much bandwidth will almost certainly require a dedicated hard line from the camera to the security station; not a simple network connection. Even at-camera data compression will be inadequate to this task unless the video quality is degraded so much that it is just another 360 surveillance camera. Likewise, data storage is going to get expensive quickly. Every minute of stored observation for this one ‘camera’ will take up as much storage as 50 standard megapixel cameras. Once again, data compression can reduce that significantly, but only at the cost of lost detail. As a security-detection tool it is going to have the problem of providing a method for security team members to provide real-time surveillance over the observed area; data display and data density problems will be difficult to overcome. Both the article and the S&T web site explain that video analytics will help with that problem. Unfortunately, the infamous ‘guy changing his shirt in Time Square’ shows the limitations of using a video analytics model. No, the best use of ISIS will be in video forensics, determining what actually happened in an area after the event. Even then it will only be of real use in large wide open areas where there are few visual obstructions. There it will allow for continuous tracking and recording of the movement of a pre-identified individual through an area without the problem of handing off the target from one camera to another.
 
/* Use this with templates/template-twocol.html */