Showing posts with label algorithms. Show all posts
Showing posts with label algorithms. Show all posts

Tuesday, December 24, 2019

Keyfactor researchers discover RSA certificate vulnerability, break nearly 250,000 distinct RSA keys

Keyfactor released research findings identifying a vulnerability across active RSA certificates. RSA certificates and the RSA algorithm are commonly used to securely transmit data to a remote source. Using minimal computing resources, researchers were able to collect and analyze 175 million RSA certificates and keys used to protect real-world Internet traffic.


The active and publicly available RSA keys (which consist of the product of two large, randomly chosen primes) were mined to identify common factors. Any keys sharing one of their prime factors with another key are compromised by this technique. The analysis found over 435,000 certificates with a shared factor, with researchers able to rederive the private key.

“The findings are alarming,” said Ted Shorter, chief technology officer and co-founder at Keyfactor. “The research finds inordinate rates of compromise impacting IoT devices with design constraints and limited entropy. These devices could include cars, medical implants and other critical devices, that if compromised, could result in life-impacting harm.”


“In a real-world attack scenario, a threat actor with a re-derived private key for an SSL/TLS server certificate could impersonate that server when devices attempt to connect,” said JD Kilgallin, senior integration engineer and researcher at Keyfactor. “The connecting user or device cannot distinguish the attacker from the legitimate certificate holder, opening the door to critical device malfunction or exposure of sensitive data.”

When these devices include medical implants and cars, the impact of the malfunction can be devastating. The research stresses the importance of security best practices, random number generation for connected systems and use of cryptography to securely install firmware and software updates through the lifecycle of the device.

“Security at design is paramount for device manufacturers,” said Shorter. “Current-generation connected devices and systems must be equipped to defend against a new generation of security risks. Cryptography is essential in ensuring new and emerging devices are able to adhere to and scale with security best practices.”


Researchers built a database of 75 million active RSA keys using Keyfactor’s proprietary SSL/TLS certificate discovery capabilities. The dataset was augmented using 100 million certificates available through certificate transparency logs and analyzed on a single virtual machine in Microsoft Azure, using Keyfactor’s scalable GCD algorithm to find shared factors. 


Thursday, December 12, 2019

Amazon SageMaker Ground Truth enables auto-segmenting of objects when performing semantic segmentation labeling

Amazon Web Services announced Wednesday that its Amazon SageMaker Ground Truth helps build highly accurate training datasets for machine learning (ML) quickly. Ground Truth offers easy access to third-party and own human labelers, and provides them with built-in workflows and interfaces for common labeling tasks. 

Additionally, Ground Truth can lower labeling costs by up to 70 percent using automatic labeling, which works by training Ground Truth from data humans have labeled so that the service learns to label data independently. 

Amazon SageMaker Ground Truth helps users build highly accurate training datasets for machine learning quickly. SageMaker Ground Truth offers easy access to public and private human labelers and provides them with built-in workflows and interfaces for common labeling tasks. Additionally, SageMaker Ground Truth can lower labeling costs by up to 70 percent using automatic labeling, which works by training Ground Truth from data labeled by humans so that the service learns to label data independently.



Successful machine learning models are built on the shoulders of large volumes of high-quality training data. But, the process to create the training data necessary to build these models is often expensive, complicated, and time-consuming. The majority of models created today require a human to manually label data in a way that allows the model to learn how to make correct decisions. 

For example, building a computer vision system that is reliable enough to identify objects - such as traffic lights, stop signs, and pedestrians - requires thousands of hours of video recordings that consist of hundreds of millions of video frames. Each one of these frames needs all of the important elements like the road, other cars, and signage to be labeled by a human before any work can begin on the model that the user wants to develop.

Amazon SageMaker Ground Truth reduces the time and effort required to create datasets for training to reduce costs. These savings are achieved by using machine learning to automatically label data. The model is able to get progressively better over time by continuously learning from labels created by human labelers.

Where the labeling model has high confidence in its results based on what it has learned so far, it will automatically apply labels to the raw data. Where the labeling model has lower confidence in its results, it will pass the data to humans to do the labeling. 

The human-generated labels are provided back to the labeling model for it to learn from and improve. Over time, SageMaker Ground Truth can label more and more data automatically and substantially speed up the creation of training datasets. 


Semantic segmentation is a computer vision ML technique that involves assigning class labels to individual pixels in an image. For example, in video frames captured by a moving vehicle, class labels can include vehicles, pedestrians, roads, traffic signals, buildings, or backgrounds. It provides a high-precision understanding of the locations of different objects in the image and is often used to build perception systems for autonomous vehicles or robotics. 

To build an ML model for semantic segmentation, it is first necessary to label a large volume of data at the pixel level. This labeling process is complex. It requires skilled labelers and significant time—some images can take up to two hours to label accurately.

To increase labeling throughput, improve accuracy, and mitigate labeler fatigue, Ground Truth added the auto-segment feature to the semantic segmentation labeling user interface. The auto-segment tool simplifies the task by automatically labeling areas of interest in an image with only minimal input. 

Users can accept, undo, or correct the resulting output from auto-segment. The screenshot highlights the auto-segmenting feature in the toolbar, and shows that it captured the dog in the image as an object. 

With this new feature, users can work up to ten times faster on semantic segmentation tasks. Instead of drawing a tightly fitting polygon or using the brush tool to capture an object in an image, users draw four points: one at the top-most, bottom-most, left-most, and right-most points of the object. Ground Truth takes these four points as input and uses the Deep Extreme Cut (DEXTR) algorithm to produce a tightly fitting mask around the object. 

Tuesday, December 10, 2019

Avigilon now adds appearance alerts to ACC 7.4 commercial video management software to provide AI-enabled user interface

Avigilon Corp., a Motorola Solutions company, announced on Monday its latest version of video management software, Avigilon Control Center (ACC) 7.4, which incorporates artificial intelligence-powered facial recognition technology.

The new “appearance alerts” capability will help commercial organizations, such as educational institutions and hospitals, accelerate response times by identifying people of interest in enterprise settings. For example, the technology can alert the security team at a local high school when a banned or flagged individual has entered the campus.


People of interest are identified based on a secure, controlled watch list created and maintained by authorized users at the commercial organization. For organizations that use the new ACC software and license their Avigilon cameras for facial recognition, cameras will seek to identify potential matches based on the watch list. If a potential match is found, the user is alerted within the ACC software, and security personnel can then determine whether further investigation or action is necessary.

Earlier this year, Motorola Solutions entered into a definitive agreement to acquire Avigilon in an all-cash transaction that will enhance Motorola Solutions’ portfolio of mission-critical communications technologies. Under the terms of the agreement, Motorola Solutions will acquire all of Avigilon’s outstanding shares for CAD$27.00 per share. The enterprise value of the transaction is approximately US$1.0 billion including Avigilon’s net debt.


Based in Vancouver, British Columbia, Avigilon designs, develops and manufactures advanced security surveillance solutions, including video analytics, network video management software and hardware, surveillance cameras, and access control solutions. 

Avigilon products are used by a range of commercial and government customers including critical infrastructure, airports, government facilities, public venues, healthcare centers and retail. The company holds more than 750 U.S. and international patents.

ACC’s new facial recognition capabilities reflect Motorola Solutions’ commitment to the responsible use of artificial intelligence as well as individual privacy rights. Data stewardship is integral to these new capabilities, and build compliance controls into products to support this. 

For example, user authentication is required for these capabilities, audit logs of user actions are generated, data retention periods for the watch list can be specified within the application, and records can be expunged or deleted on demand as well as verified through auditing and reporting. Data is locally hosted, owned and controlled by the business or school. The data used to train the AI algorithms is also thoroughly evaluated, ensuring sufficient quantity, quality and diversity to ensure high accuracy and consistent performance. 


“Our latest ACC software delivers substantial benefits to our commercial customers by offering facial recognition technology in a secure and controlled manner,” said John Kedzierski, senior vice president, Video Security Solutions, Motorola Solutions. “The appearance alerts capability enables our customers to move from a reactive approach – staring at a wall of video feeds where critical information can be easily missed – to a proactive approach that brings important information directly to authorized users so they can make better-informed decisions.”

“It’s important to note that we view facial recognition as an aid that can improve the decision-making of the user – it does not make consequential decisions or initiate actions on its own. We refer to this approach as ‘human in the loop,’ and it is foundational to the way we apply AI,” added Kedzierski.
  
ACC 7.4 software is now available for download. 

Thursday, December 5, 2019

TigerGraph Cloud improves graph database-as-a-service with improved performance and productivity

TigerGraph announced new functionality and performance for TigerGraph Cloud, its distributed native graph database-as-a-service, is an intuitive way to build and run applications that work with highly connected and complex datasets. 

TigerGraph’s latest distributed system and high availability enhancements help enterprises leverage advanced analytics on graph at scale, which requires larger and more varied dataset combinations, which means more variables and relationships to analyze, explore and test to make machine learning (ML) and artificial intelligence (AI) better.


“To survive and thrive in today’s business world, enterprises should accelerate their approach to AI and ML applications, both of which benefit from graph analytics, as this helps identify new patterns across the data sources, create new models and better algorithms, using data at scale,” said Todd Blaschka, COO, TigerGraph. “TigerGraph Cloud’s enhanced services provide our customers with an even better platform for analytical and transactional processing. Users can start for free and expand to a distributed production system as their applications scale. Starting a distributed graph system with high availability is simply choosing the number of machines and the number of replicas on TigerGraph Cloud.”
  
TigerGraph Cloud delivers on one promise: graph analytics is the way forward. Until now, organizations had to rely on data scientists, developers and architects to design their graph-based data analysis solutions. TigerGraph Cloud has addressed this innovation gap with an easy-to-use, cloud-based graph service that makes graph database and analytics accessible to everyone; the solution is the only distributed graph service with high availability. 


TigerGraph Cloud provides the ideal cloud-based service to model, search, and traverse relationships for analytical, transactional and real-time workloads. Users can start for free, then as their data expands they can expand across the cloud.  At the same time, with TigerGraph’s ability to do SQL-like database computation along with ACID-compliant transactions, users benefit with a lower TCO compared to other analytic products.

TigerGraph Cloud allows users to get started in minutes, build a proof-of-concept model in hours and deploy a solution to production in days. It eliminates the need to set up, configure or manage servers, schedule backups or look for security vulnerabilities. Also, TigerGraph offers a free tier of TigerGraph Cloud in perpetuity that enables data scientists, developers, business analysts, students and other enthusiasts to experience this technology’s unique power to handle real-world data challenges. 

With this version of TigerGraph Cloud that includes configuration for distributed graphs and replica instances for high availability, as well as the ability to leverage EFS for backup and restore. 


In addition to elastic, pay-only-for-what-you-use pricing, subscribers can provision distributed TigerGraph services for large production datasets; have the choice to deploy high availability TigerGraph services; and have more TigerGraph Cloud starter kits to choose from for fast application development, including new neural networks, cybersecurity and payment fraud detection kits. Starter kits are built with sample graph data schema, dataset, and queries focused on specific use cases such as fraud detection, real-time recommendation, machine learning, and explainable AI.

Going into 2020, Microsoft Azure will soon be one of the backend options for users of TigerGraph Cloud, making it the first truly cloud neutral graph database-as-a-service in the market.

Tuesday, December 3, 2019

Ericsson Spectrum Sharing milestone links up continents, 5G live networks and 5G devices

The move toward commercial Ericsson Spectrum Sharing continues to gather pace with a 5G smartphone from Chinese manufacturer OPPO now added to its 5G ecosystem and successfully tested with a transglobal 5G data call in live commercial 5G networks. 

Ecosystem industry players Qualcomm Technologies, a subsidiary of Qualcomm Inc., Swisscom, and Telstra also played vital roles in the achievement, which underlined the value of dynamic spectrum sharing to the industry.


The November 29 data-call-first connected Bern, Switzerland and Gold Coast, Australia, with Ericsson Spectrum Sharing deployed in Swisscom and Telstra’s commercial 5G networks at the respective sites. The call was achieved using spectrum sharing on a 3GPP Frequency Division Duplex (FDD) band. 

Pre-commercial 5G smartphones from OPPO, powered by the Qualcomm Snapdragon X55 5G Modem-RF System, were used on both ends of the call. OPPO is the first 5G device manufacturer to implement Ericsson Spectrum Sharing in its smartphones.  

The data call success validates the support for Ericsson Spectrum Sharing across its 5G ecosystem, from chipsets to 5G devices, and communication service providers’ network products and solutions. The strengthening of the ecosystem is also a step towards the commercial introduction of Ericsson Spectrum Sharing.

Ericsson Spectrum Sharing, part of Ericsson Radio System, is a complete dynamic spectrum sharing solution based on the 3GPP standard with additional intelligent scheduler algorithms. This allows the deployment of both 4G and 5G in the same band through a software upgrade, and dynamically allocates spectrum based on user demand. The switch between 4G and 5G carriers happens within milliseconds, minimizing spectrum wastage and enabling best user performance.


This Ericsson innovation will enable service providers to launch 5G services over a wide area and expand 5G coverage in a tailored way by re-using existing network infrastructure and taking advantage of previous spectrum investments. Communication service providers can therefore provide 5G commercial services and move towards standalone (SA) 5G without the need for blanket costly re-investment.


“This industry-first highlights the value that Ericsson Spectrum Sharing has to communication service providers as they roll-out and ramp-up 5G. With this milestone achieved with our 5G ecosystem partners OPPO, Qualcomm Technologies, and customers Swisscom and Telstra, we’ve shown that our unique solution will not only enable service providers to re-use their 4G spectrum assets for 5G but that it will also support all 5G devices,” said Fredrik Jejdling, executive vice president and head of networks, Ericsson. “It is the most economically feasible way to launch 5G on existing bands, enabling nationwide 5G coverage and helping make 5G accessible around the world.” 

“As a leading global tech company, OPPO proactively works to accelerate large-scale commercialization of 5G. Our cooperation with Ericsson, Qualcomm, Swisscom and Telstra to facilitate the commercial use of Dynamic Spectrum Sharing (DSS) technology is part of the in-depth collaborations among the five companies in the 5G era,” said Andy Wu, vice president and president of software engineering business unit, OPPO. “The 5G smartphones that support this technology will provide more stable, seamless, and speedy connections, and hence a better user experience in the future.”

“Coverage is the next 5G killer app and this is another significant milestone and steps towards ubiquitous 5G coverage,” said Enrico Salvatori, senior vice president and vice president, Qualcomm EMEA. “Dynamic spectrum sharing will bring key benefits to operators and consumers globally and our second-generation Snapdragon X55 5G Modem RF System is a comprehensive solution designed to allow OEMs to rapidly develop global 5G multimode devices for a new era of connected experiences.”


“This latest collaboration of industry partners is paving the way for the faster rollout of 5G by using existing spectrum holdings to serve the needs of 4G and 5G customers in the same location at the same time,” said Channa Seneviratne, Network and Engineering Infrastructure Executive, Telstra. “This collective implementation is yet another innovative example of how 5G technology continues to advance in a rapid fashion, and at Telstra we are pleased to bring that latest technology to Australians first.”
Ericsson has achieved multiple 5G landmarks with all the partners involved in the latest achievement.

Swisscom, with Ericsson as its sole 5G vendor, was the first communications service provider in Europe to launch commercial 5G services in April 2019 on the 3.6 GHz band. Swisscom is targeting 90 percent population coverage by the end of this year.

Telstra, with Ericsson as a key network partner, went live with 5G commercial services and four 5G devices in May 2019 on the 3.6 GHz band. Telstra now offers six 5G devices, and has some 5G sites in 25 metro and regional cities around Australia, with another 10 cities to be added by 30 June 2020.

Wednesday, November 27, 2019

Amazon Web Services updates its AWS DeepRacer program with new sensing capabilities and training algorithms

Amazon Web Services (AWS) announced on Wednesday that it is upgrading its DeepRacer program by adding more chances to compete at AWS events & at own events, more chances to win, with new races including head-to-head multi-car competitions, and an upgraded DeepRacer car with new sensing capabilities.



AWS DeepRacer is an autonomous 1/18th scale race car designed to test RL models by racing on a physical track. Using cameras to view the track and a reinforcement model to control throttle and steering, the car shows how a model trained in a simulated environment can be transferred to the real-world.



AWS DeepRacer Evo is the next generation in autonomous racing. Take your car to the tracks and master brand new AWS DeepRacer challenges including racing head to head against other cars in the 2020 season of the AWS DeepRacer League. AWS DeepRacer Evo comes with dual stereo cameras, allowing the car to detect objects on the track, and LIDAR (light detection and ranging) helping to determine when to overtake another car and beat it to the finish line.

AWS DeepRacer offers hands-on experience with Reinforcement Learning (RL). Following launch of the AWS DeepRacer car and the AWS DeepRacer League, users could have the opportunity to get experience and new skills in a fun, competitive environment. In less than a year, tens of thousands of developers have participated in hands-on and virtual races located globally. 


The upcoming AWS DeepRacer Evo car will include a stereo camera and a Light Detection and Ranging (LIDAR) sensor. The added sensors will enable DeepRacer Evo to skillfully detect and respond to obstacles, including other DeepRacers. This will help users learn more about the field of reinforcement learning, which is ideal for use in autonomous driving.

The new sensors will be available soon in virtual form for use in the new My Garage section of the DeepRacer Console. AWS will release more details on production plans for AWS DeepRacer Evo, including a sensor upgrade kit for existing DeepRacer car, early next year.

AWS is also expanding the DeepRacer League in 2020. The company is adding eight additional races across five countries as part of an expanded AWS Summit presence, and 18 additional virtual races. There will also be a track (and a race) at re:MARS 2020. As a result, customers have the opportunity to participate in 30 events and join for an in-person AWS DeepRacer League Summit race, along with 24 Virtual Circuit races from anywhere in the world.


In addition to the existing time trial race, AWS is adding two new race types to give some new RL challenges, and the opportunity to experiment with different sensors. The object detection and avoidance features uses the sensors to detect and (hopefully) avoid obstacles, and the head-to-head racing against another DeepRacer that is on the same track. 

Masimo secures FDA clearance for neonatal RD SET Pulse Oximetry sensors with improved accuracy specifications

Masimo announced that RD SET sensors with Masimo Measure-through Motion and Low Perfusion SET pulse oximetry have received FDA clearance ...