Featured Research

from universities, journals, and other organizations

Security flaws found in backscatter X-ray scanners formerly used in U.S. airports

Date:
August 20, 2014
Source:
University of California - San Diego
Summary:
Researchers have discovered security vulnerabilities in full-body backscatter X-ray scanners deployed to U.S. airports between 2009 and 2013. In laboratory tests, the team was able to conceal firearms and plastic explosive simulants from the Rapiscan Secure 1000 scanner. The team modified the scanner operating software to present an 'all-clear' image to the operator even when contraband was detected.

Professor Hovav Shacham stands in front of the backscatter x-ray scanner as you would during a security check.
Credit: Photos by Erik Jepsen/UC San Diego Publications

A team of researchers from the University of California, San Diego, the University of Michigan, and Johns Hopkins University have discovered several security vulnerabilities in full-body backscatter X-ray scanners deployed to U.S. airports between 2009 and 2013.

Related Articles


In laboratory tests, the team was able to successfully conceal firearms and plastic explosive simulants from the Rapiscan Secure 1000 scanner. The team was also able to modify the scanner operating software so it presents an "all-clear" image to the operator even when contraband was detected. "Frankly, we were shocked by what we found," said J. Alex Halderman, a professor of computer science at the University of Michigan. "A clever attacker can smuggle contraband past the machines using surprisingly low-tech techniques."

The researchers attribute these shortcomings to the process by which the machines were designed and evaluated before their introduction at airports. "The system's designers seem to have assumed that attackers would not have access to a Secure 1000 to test and refine their attacks," said Hovav Shacham, a professor of computer science at UC San Diego However, the researchers were able to purchase a government-surplus machine found on eBay and subject it to laboratory testing.

Many physical security systems that protect critical infrastructure are evaluated in secret, without input from the public or independent experts, the researchers said. In the case of the Secure 1000, that secrecy did not produce a system that can resist attackers who study and adapt to new security measures. "Secret testing should be replaced or augmented by rigorous, public, independent testing of the sort common in computer security," said Shacham.

Secure 1000 scanners were removed from airports in 2013 due to privacy concerns, and are now being repurposed to jails, courthouses, and other government facilities. The researchers have suggested changes to screening procedures that can reduce, but not eliminate, the scanners' blind spots. However, "any screening process that uses these machines has to take into account their limitations," said Shacham.

The researchers shared their findings with the Department of Homeland Security and Rapiscan, the scanner's manufacturer, in May. The team will present their findings publicly at the USENIX Security conference, Thursday Aug. 21, in San Diego.


Story Source:

The above story is based on materials provided by University of California - San Diego. The original article was written by Ioana Patringenaru. Note: Materials may be edited for content and length.


Cite This Page:

University of California - San Diego. "Security flaws found in backscatter X-ray scanners formerly used in U.S. airports." ScienceDaily. ScienceDaily, 20 August 2014. <www.sciencedaily.com/releases/2014/08/140820110434.htm>.
University of California - San Diego. (2014, August 20). Security flaws found in backscatter X-ray scanners formerly used in U.S. airports. ScienceDaily. Retrieved March 3, 2015 from www.sciencedaily.com/releases/2014/08/140820110434.htm
University of California - San Diego. "Security flaws found in backscatter X-ray scanners formerly used in U.S. airports." ScienceDaily. www.sciencedaily.com/releases/2014/08/140820110434.htm (accessed March 3, 2015).

Share This


More From ScienceDaily



More Science & Society News

Tuesday, March 3, 2015

Featured Research

from universities, journals, and other organizations


Featured Videos

from AP, Reuters, AFP, and other news services

Woman Convicted of Poisoning Son

Woman Convicted of Poisoning Son

AP (Mar. 3, 2015) A woman who blogged for years about her son&apos;s constant health woes was convicted Monday of poisoning him to death by force-feeding heavy concentrations of sodium through his stomach tube. (March 3) Video provided by AP
Powered by NewsLook.com
Doctors Often Give In To Vaccine-Wary Parents

Doctors Often Give In To Vaccine-Wary Parents

Newsy (Mar. 2, 2015) A new survey published in the journal Pediatrics found many doctors are giving in to parents&apos; requests to delay vaccinating their children. Video provided by Newsy
Powered by NewsLook.com
Everything You Need To Know About Mobile Payments In 2015

Everything You Need To Know About Mobile Payments In 2015

Newsy (Mar. 2, 2015) This year, mobile payments might finally catch on. Here are the things you need to know to stay on top of the latest developments. Video provided by Newsy
Powered by NewsLook.com
Nurse Who Survived Ebola Virus to File Lawsuit

Nurse Who Survived Ebola Virus to File Lawsuit

AP (Mar. 2, 2015) A lawyer for Nina Pham, the 26-year old nurse who survived after contracted the Ebola virus, says the young woman&apos;s &apos;life has changed forever. &apos; Pham is preparing to file a lawsuit against Texas Health Resources for negligence. (March 2) Video provided by AP
Powered by NewsLook.com

Search ScienceDaily

Number of stories in archives: 140,361

Find with keyword(s):
Enter a keyword or phrase to search ScienceDaily for related topics and research stories.

Save/Print:
Share:

Breaking News:

Strange & Offbeat Stories


Science & Society

Business & Industry

Education & Learning

In Other News

... from NewsDaily.com

Science News

Health News

Environment News

Technology News



Save/Print:
Share:

Free Subscriptions


Get the latest science news with ScienceDaily's free email newsletters, updated daily and weekly. Or view hourly updated newsfeeds in your RSS reader:

Get Social & Mobile


Keep up to date with the latest news from ScienceDaily via social networks and mobile apps:

Have Feedback?


Tell us what you think of ScienceDaily -- we welcome both positive and negative comments. Have any problems using the site? Questions?
Mobile: iPhone Android Web
Follow: Facebook Twitter Google+
Subscribe: RSS Feeds Email Newsletters
Latest Headlines Health & Medicine Mind & Brain Space & Time Matter & Energy Computers & Math Plants & Animals Earth & Climate Fossils & Ruins