Translate

显示标签为“PRISM”的博文。显示所有博文
显示标签为“PRISM”的博文。显示所有博文

2013年7月1日星期一

NSA最新幻灯片曝光:详解棱镜项目工作流程

北京时间6月30日上午消息,《华盛顿邮报》昨天独家披露了美国国家安全局(NSA)“棱镜”(PRISM)项目的四张幻灯片。这些文件详细揭示了 整个项目的工作流程,包括NSA和美国联邦调查局(FBI)的审查和监管权限。另外,它们还显示了该项目与所涉九家互联网公司的互动方式。
  1. 获取新目标的数据
1
  这张幻灯片描述了NSA分析员在PRISM系统中建立新监控目标的流程。建立新目标的请求会自动发送到审查搜索关键词的主管。主管必须批准分析员的“合理意见”,即收集数据时指定目标为海外的外籍人士。
外国情报监视法庭不审批任何个人数据收集请求外国情报监视法庭不审批任何个人数据收集请求
  左:FBI使用装在私人公司(例如微软、雅虎)的政府设备检索匹配的信息,不经进一步审查便交给NSA。
  中:外国情报监视法庭不审批任何个人数据收集请求
  右1:对于存储的通信记录(非实时监控),FBI会查询其数据库,确保筛选器不会匹配任何知名美国人。
  右2:数据从此处进入NSA系统。
  2. 分析从私人公司收集到的信息
2
  获取通信信息后,由专门的系统处理语音、文字、视频以及地理位置、监控目标的设备特征等“数字网络信息”。
  左:FBI装在私人公司的截获设备将信息传递给NSA、CIA或FBI。
  3. 每个目标分配一个案例代号
3
  PRISM案例代号格式反映了实时监控和存储内容的可用情况。
  每当监控目标登录或发送电子邮件时,NSA可收到实时通知,另外还可实时监控语音通话和文字消息,具体情况视PRISM数据提供方而定。
  4. 搜索PRISM数据库
4
  这张幻灯片显示,4月5日PRISM的反恐数据库中由11.7675万活跃的监控目标。它未显示监控这些目标的过程中“无意”收集了多少其他互联网用户以及多少美国人的通信信息。

文章来源: http://goo.gl/03kw2
附原文:

NSA slides explain the PRISM data-collection program

The top-secret PRISM program allows the U.S. intelligence community to gain access from nine Internet companies to a wide range of digital information, including e-mails and stored data, on foreign targets operating outside the United States. The program is court-approved but does not require individual warrants. Instead, it operates under a broader authorization from federal judges who oversee the use of the Foreign Intelligence Surveillance Act (FISA). Some documents describing the program were first released by The Washington Post on June 6. The newly released documents below give additional details about how the program operates, including the levels of review and supervisory control at the NSA and FBI. The documents also show how the program interacts with the Internet companies. These slides, annotated by The Post, represent a selection from the overall document, and certain portions are redacted. Read related article.
New slides published June 29

Acquiring data from a new target

This slide describes what happens when an NSA analyst "tasks" the PRISM system for information about a new surveillance target. The request to add a new target is passed automatically to a supervisor who reviews the "selectors," or search terms. The supervisor must endorse the analyst's "reasonable belief," defined as 51 percent confidence, that the specified target is a foreign national who is overseas at the time of collection.
The FBI uses government equipment on private company property to retrieve matching information from a participating company, such as Microsoft or Yahoo and pass it without further review to the NSA.
For stored communications, but not for live surveillance, the FBI consults its own databases to make sure the selectors do not match known Americans.
This is where data enters NSA systems, described more fully on the next slide.
The Foreign Intelligence Surveillance Court does not review any individual collection request.

Analyzing information collected from private companies

After communications information is acquired, the data are processed and analyzed by specialized systems that handle voice, text, video and "digital network information" that includes the locations and unique device signatures of targets.
From the FBI's interception unit on the premises of private companies, the information is passed to one or more "customers" at the NSA, CIA or FBI.
PRINTAURA automates the traffic flow. SCISSORS and Protocol Exploitation sort data types for analysis in NUCLEON (voice), PINWALE (video), MAINWAY (call records) and MARINA (Internet records).
The systems identified as FALLOUT and CONVEYANCE appear to be a final layer of filtering to reduce the intake of information about Americans.

Each target is assigned a case notation

The PRISM case notation format reflects the availability, confirmed by The Post's reporting, of real-time surveillance as well as stored content.
Depending on the provider, the NSA may receive live notifications when a target logs on or sends an e-mail, or may monitor a voice, text or voice chat as it happens (noted on the first slide as "Surveillance").

Searching the PRISM database

On April 5, according to this slide, there were 117,675 active surveillance targets in PRISM's counterterrorism database. The slide does not show how many other Internet users, and among them how many Americans, have their communications collected "incidentally" during surveillance of those targets.
Original slides published June 6

Introducing the program

A slide briefing analysts at the National Security Agency about the program touts its effectiveness and features the logos of the companies involved.
The program is called PRISM, after the prisms used to split light, which is used to carry information on fiber-optic cables.
This note indicates that the program is the number one source of raw intelligence used for NSA analytic reports.
The seal of
Special Source Operations, the NSA term for alliances with trusted U.S. companies.

Monitoring a target's communication

This diagram shows how the bulk of the world’s electronic communications move through companies based in the United States.

Providers and data

The PRISM program collects a wide range of data from the nine companies, although the details vary by provider.

Participating providers

This slide shows when each company joined the program, with Microsoft being the first, on Sept. 11, 2007, and Apple the most recent, in October 2012.

 

2013年6月18日星期二

棱镜计划、大数据和别人的生活

棱镜计划(PRISM)是一项由美国国家安全局(NSA)自2007年起开始实施的绝密级电子监听项目,该计划对美国互联网公司的外国用户进行广泛 的窃听与监控,许可的监听对象包括任何在美国以外地区使用参与项目公司服务的客户,或是任何与国外人士通信的美国公民。该计划日前被前美国中央情报局雇员 曝光。
  据华盛顿邮报报道,29岁的前美国中央情报局(CIA)雇员Edward Snowden在香港向世人揭密了美国政府的两大秘密监控项目:针对美国普通公民的电话监控项目和针对外国人的互联网监控项目。前者使得当局能够获取并存 储美国电话用户的海量通讯信息:何时、何地与何人进行通讯,通讯频次与时间长度等等。尽管这些普通美国人与恐怖主义也许毫无联系,但有可能被长期、无差别 地监控。这些监控是秘密进行的,用户不会收到任何提示,更不会见到法官签署的法律许可文件。而PRISM计划使得NSA有能力对美国互联网公司的海外用户 进行窃听和监控,这些美国互联网公司括Microsoft(含Hotmail)、Google、Yahoo、Facebook、Skype和Apple。 而根据根据华盛顿邮报提供的绝密级别的幻灯片,NSA能够获取用户的电子邮件、聊天记录、视频、照片等所有存储的信息,甚至可以扩展到用户的社交网络细 节。
棱镜计划、大数据和别人的生活
  这两个秘密监控项目一被公开,就引起了关注者的激烈争辩。NSA的官员们认为这些监控避免了很多恐怖袭击,而Edward的将之公布于众给美国 情报工作来带巨大损失,他必须受到审判;奥巴马也表示绝对的隐私与绝对的安全不可兼得,竭力为监控项目进行辩护。而笔者则站在Edward Snowden的一方。你可以说Edward 太年轻、太简单,甚至有些幼稚;但他通过呐喊唤醒世人,放弃了20万美元年薪、选择与美国政府为敌流亡到香港,只为了我们能够免于生活在电幕之下。他是一 个英雄!
  笔者认为,PRISM计划与大数据时代的发展密不可分。每个个体的行为也许都不尽相同,但都是有规律的。通过获取与分析海量数据,我们能够获得 人们的行为习惯的有效信息,从而对个体行为习惯进行推测,提供个性化和定制化的服务。广告主和电商们通过分析海量客户的购买行为能够了解客户,进行有针对 的营销以提升业务;洛杉矶的警方通过分析几十年的犯罪记录,预测犯罪行为模式与频率,从而有针对地安排警力。盯上大数据的显然不仅仅有这些企业和地方警察 局,美国政府也表现出了十足的兴趣。监控计划中的对普通民众电话和互联网的监控也许并不涉及具体某个电话、某封邮件的监听与解读,但是通过关键词筛选、用 户联系频率与地点与恐怖袭击可能存在的联系、不正常现金流向的分析,美国政府也许能从中找出“恐怖袭击”的蛛丝马迹。尽管目前美国政府声称这些秘密监控措 施仅用于反恐,但它们极容易被缺乏监管的当局滥用。预算不公开的秘密机构NSA能够获取你的地理位置、通讯记录、社交网络联系、视频、照片等等数据,并且 能够未经法院许可对你的数据进行分析和解读。(根据《爱国者法案》,政府可以不需要法官监督和许可,即可在任何时间获取任何公民的个人资料、金融交易资料 和医疗资料)美国记者华莱士曾经谈笑风生地说:“如果它看起来像鸭子,游泳像鸭子,叫声像鸭子,那么它可能就是只鸭子。”这句话同样可以用在这些秘密机构 上,NSA看上去像进行互联网监控的机构,建立了大型数据存储与运算中心,也承认自己进行互联网审查。它唯一的挡箭牌就是“为了挫败恐怖袭击,为了你们的 安全”。然而,反恐是个筐,什么都能往里装。谁能保证“反恐”不会成为美国式的维稳呢?
  随着云计算的发展,人们产生的海量数据会越来越多的存放在网上:邮件、个人档案、信用卡信息、地理位置、个人日程安排、电子书、照片等等。 Apple公司的iCloud服务使得人们能够很方便地同步音乐、邮件、照片和个人文档等等信息。过去,我们相信Google、Amazon和Apple 公司能够为我们的隐私提供足够的保护,也乐于享受云技术的便利,并且期待着更加美好的大数据时代的到来。今天,Edward为世人敲响了隐私权的警钟!如 果将来的某一天,美国政府认为购买过高压锅、与外国人(尤其是穆斯林)经常联系和阅览过“如何在你祖母的厨房中制造炸弹”的人有进行恐怖袭击的倾向,可以 对他们进行重点监控和钓鱼执法的话(笔者非常怀疑NSA有类似的数据挖掘方式),那么小说《1984》中描述的场景终于来临了。这是比菜刀实名制高明得多 的方法:悄无声息、成本极低且十分精准。推动大数据发展的背后,也许不仅仅有那些互联网巨人们,更有那些蠢蠢欲动的野心家。大数据的获取与分析使得野心家 们能够高效、精准地清除异己、控制思想。奥巴马政府就以“反恐”为名迈出了危险的第一步。
  2006年的一部德国电影《别人的生活》中,有一个场景给笔者留下深刻的印象:阴暗的地下室里坐着无数的拆信员,他们用蒸汽熏信件的封口使得胶 水失效,以便对信件内容进行神不知鬼不觉的审查。而现在,电影又变成了现实,NSA的巨型高性能计算机正在高效运行,情报专家们在大数据中正挖掘得不亦乐 乎。An ever bigger brother is watching you。

http://goo.gl/HloU4