Data mining sifts the gems from digital ore
- By Wilson P. Dizard III
- Sep 24, 2004
'If you don't do data mining, you're not as efficient and effective as you could be,' the FBI's Mark Tanner says.
Analysis apps become must-have software for many agencies
A Customs data-mining app helped pinpoint the source of a terrorist threat on board a cruise ship, Charles Bartoldus says.
The Royal Caribbean cruise ship MV Legend of the Seas was steaming from Ensenada, Mexico, toward Hilo, Hawaii, in April of last year when its captain radioed an alarm to federal authorities. Someone had placed a note in one of the ship's bathrooms threatening to kill all the Americans on board if the vessel docked in the United States.
The Coast Guard, FBI and Homeland Security Department's Customs and Border Protection agency acted quickly to analyze the threat. Data mining helped the feds figure out that the culprit was a disenchanted 20-year-old passenger and not a terrorist.
Customs intelligence analysts checked the threat scores the agency's Automated Targeting System (ATS) had assigned to the ship's passengers and crew'almost 2,400 people in all.
The targeting system used data-mining technology to sift through information about the crew and passengers as investigators gleaned clues from the first note and, soon after, a second one.
The data-mining program indicated that the incident likely was not a genuine terrorist threat, said Charles Bartoldus, CBP's director of border targeting and analysis. The system pinpointed attributes of the note's author that federal investigators on board used during passenger and crew interviews.
Under questioning, passenger Kelley Marie Ferguson of Laguna Hills, Calif., confessed to planting the notes in an effort to cut the cruise short so she could see her boyfriend, Bartoldus said.
Ferguson, now 21, pleaded guilty to a felony charge of conveying false information and received a two-year sentence. Her case illustrates how federal agencies increasingly are using data-mining techniques for investigative work.
Data mining can be defined as applying advanced analytical techniques to large databases to extract hidden information, said Lee Holcomb, DHS' chief technology officer.
Customs uses ATS to assign risk scores to passengers and cargo. More than 130 analysts from various agencies work in the agency's targeting center, Bartoldus said.No crystal ball
Specialists agree that the technology cannot be used to predict future events, but advanced analytical tools can help find relationships in vast quantities of data. And in the criminal and terrorism fields, massive amounts of information from public and classified sources and sensor systems flow daily into Homeland Security, Justice and Defense department databases.
Besides commercial tools, federal intelligence agencies have developed several homegrown data-mining applications, Holcomb said. 'Visualization tools have been increasingly used in this field,' he said.
Agencies use literally dozens of data-mining technologies. 'A lot of the tools start out as research efforts' funded by the government, universities or businesses, he said.
Because there are so many tools and because of technology advances, it's necessary to build a framework where tools and analytical approaches can be changed out easily, Holcomb said. 'The tools that are out there keep changing, and the information you receive gets richer and richer.'
Federal executives overseeing investigations increasingly seek tools that can be calibrated to the level of expertise of individual analysts, whether they are novices, experts or somewhere in between.
Over time, the type of information data miners have handled has evolved, Holcomb said. It started with relatively straightforward structured information, such as columns with names, dates of birth and other simple elements.
Nowadays, intelligence analysts frequently handle unstructured data such as photos, movies, audio files and handwritten notes, Holcomb said. 'That information becomes very difficult to analyze. A lot of the task is to put structure on unstructured data.'
Different types of tools serve different purposes, and some apply only to extremely narrow functions, Holcomb said.
Even as data-mining tools evolve, training and knowledge remain critical to the job of the data analyst.
'Some of these tools have to be specifically trained to understand the data they are handling,' an FBI investigative manager said. 'It is not plug and play.'
Holcomb agreed. 'When using any analytical tool set, you need to understand it,' he said. 'It is often said that statistics lie. If you use the wrong algorithm, you can get the wrong data.
'Often these days people are trained in using a tool, but they don't use common sense. They crank in the number and get an answer that doesn't make sense.'
For example, an analyst using a data-mining app may have to make sure the program is set
to capture date fields that appear as day/month/year or as month/day/year.
Perhaps a search must be set to extract either the first, last or middle name of an individual, or only one name in some cases.
As agencies increase and improve their use of data mining, they face questions about the practice's impact on privacy. There are already 10 federal laws that set parameters on government data handling for privacy reasons. Even so, lawmakers continue to voice concerns that the government's data-mining work might tread on citizens' rights.Privacy issues
At Homeland Security, officials decided to revise plans for a passenger-screening system in the face of privacy concerns.
And the Defense Advanced Research Projects Agency's Total Information Awareness, an effort to scan multiple databases to identify possible terrorists, had its funding scrapped after lawmakers raised questions about how it would compromise citizens' privacy.
But despite such concerns, data mining is becoming more the rule than the exception in federal investigative work. 'If you don't do data mining, you're not as efficient and effective as you could be,' said Mark Tanner, director of the FBI's Foreign Terrorist Tracking Task Force. 'Without the tools, it's just data.'