Fatal flaws found in US terrorism database

By Stephanie Condon, CNET News.com
Monday, August 25, 2008 11:04 AM

One of the country's most important terrorism databases is on the verge of failure after suffering from gross mismanagement and technical design flaws that went ignored for months, a congressional investigation found.

A congressional committee on Thursday called for an investigation into a program called "Railhead", which was supposed to upgrade the National Counterterrorism Center's integrated terrorist intelligence database, called Terrorist Identities Datamart Environment (TIDE). The database serves the United States' 16 separate intelligence agencies, and as of January, contained more than 500,000 names (PDF), according to the NCTC. The program has cost an estimated US$500 million.

Railhead was also meant to improve TIDE Online, an unclassified version of the TIDE database, and NCTC Online, a classified database of terrorist information and intelligence reports available to counterterrorism analysts.

However, officials at the NCTC began making drastic changes to the Railhead program in recent weeks, according to the House Science and Technology Committee, including laying off hundreds of private contractors working on the program. The number of contractors has shrunk from more than 800 to just a few dozen. The state of the program is now in jeopardy.

Representative Brad Miller, chairman of the House Science and Technology Committee's Investigations and Oversight Subcommittee, sent a letter (PDF) Thursday to the Inspector General of the Office of the Director of National Intelligence requesting an investigation into Railhead's near-collapse.

"Potentially hundreds of millions of dollars have been wasted, delivery schedules have slipped, contractor employees have been laid off," he wrote. "The end result is a current IT system used to identify terrorist threats that has been crippled by technical flaws and a new system that if actually deployed will leave our country more vulnerable than the existing yet flawed system in operation today."

Miller noted the problems with TIDE and Railhead stem from "fundamental design flaws", namely their reliance on Structured Query Language (SQL) to search the database. SQL is a computer code that uses sentence structures to conduct queries, as opposed to using text-based searches, like search engines such as Google do.

Due to faulty searches, tens of thousands of CIA messages to the NCTC have not been properly processed or reviewed, or may not have even reached the TIDE database.

On top of that, the TIDE database has reportedly crashed several times in recent months, delaying the delivery of updated terrorist intelligence data to the FBI's Terrorist Screening Center.

While TIDE already has problems, Railhead appears to just exacerbate them: The Railhead initiative would significantly downgrade the NCTC Online's capabilities by preventing access to any intelligence community Web sites or data resources, such as sites for the CIA, DIA, or FBI.

The project is not only flawed but also behind schedule. Thirty-four of Railhead's 72 "action items" are past due, and two are behind schedule. Ten more tasks--five of them costing more than US$92 million--are "significantly off-task".

Unnamed sources involved with the Railhead project also told Congress that some of the project's deals with private contractors were inappropriate. A memo (PDF) produced by congressional staff cites sources who allege that SRI International's involvement in the project created a conflict of interest because SRI program director Earl Lyberger has close ties to Railhead's program manager Dirk Rankin.

Additionally, the staff's sources allege that the government misused funds by spending nearly US$200 million to retrofit a building in Herndon, Va., belonging to one of the project's main contractors, Boeing.

Representatives from Boeing and SRI did not respond to requests for comments.

Miller noted in his request for an investigation into the program that there may be efforts under way to close down Railhead completely.

This article was first published as a blog on CNET News.com.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Common ways IT wastes money on development

Web Development

Examples include using developers as support staff and failing to calculate a project's ROI before giving it the go-ahead.


Read more »



  • Enterprise 2.0

    Vince Casarez, vice president of product management at Oracle, explains how Web 2.0 technologies, such as tags, wikis, and mash-ups, can be applied within an organization.
    Play video


  • Nehalem Architecture

    What makes next-generation Intel® Microarchitecture (Nehalem) such a superior successor?
    Play video

 
On demand CRM goes strategic
CRM technology has come of age, and is now able to align with your customer strategy and grow in step with your business.

» Learn more about Oracle’s CRM Solutions



Free the untapped potential of your IT infrastructure
Reduce bottlenecks to drive the efficiency and productivity of Business IT.
» Ultimate virtualization blade
» Scalable SAN solution
» Accelerate service delivery

Could this be the most critical budget for India?

Blog thumbnail

For business journalists in India, budget time is excitement time. It's like sports journos covering the Olympics. As a newspaper correspondent, I too had my fill of budget-time excitement. But..... by Swati Prasad

Read more »

Tags

  1. attack
  2. bank
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. u.s.
  19. viruses and worms
  20. web