论文标题

Cyber​​Biosecurity:合成生物学中的DNA注射攻击

Cyberbiosecurity: DNA Injection Attack in Synthetic Biology

论文作者

Farbiash, Dor, Puzis, Rami

论文摘要

今天,可以在线订购任意合成DNA并在几天内交付。为了调节危险物质的故意和意外产生,大多数合成基因提供商筛选了DNA顺序。合成双链DNA提供者的筛选框架指南中的弱点允许基于此指南的筛选协议,可以使用受早期恶意软件混淆技术启发的通用混淆程序来规避。此外,合成基因工程工作流程的可访问性和自动化,结合了网络安全控制不足,使恶意软件能够干扰受害者实验室内的生物学过程,从而使循环结束了循环,并可能将exploit写入Ney等人提供的DNA分子中。在usenix安全'17中。在这里,我们提出了端到端的网络生物学攻击,其中可能会欺骗不知情的生物学家在其实验室内产生危险物质。因此,尽管有共同的生物安全性假设,但攻击者不需要与生成的物质进行物理接触。攻击中最具挑战性的部分是在活细胞内执行混淆的DNA的解码,同时使用生物学家在体内基因编辑过程中通常使用的原始生物学作业。这种攻击情景强调了需要防止网络生物学威胁来加强合成DNA供应链的必要性。为了应对这些威胁,我们提出了一种改进的筛选协议,考虑了体内基因编辑。

Today arbitrary synthetic DNA can be ordered online and delivered within several days. In order to regulate both intentional and unintentional generation of dangerous substances, most synthetic gene providers screen DNA orders. A weakness in the Screening Framework Guidance for Providers of Synthetic Double-Stranded DNA allows screening protocols based on this guidance to be circumvented using a generic obfuscation procedure inspired by early malware obfuscation techniques. Furthermore, accessibility and automation of the synthetic gene engineering workflow, combined with insufficient cybersecurity controls, allow malware to interfere with biological processes within the victim's lab, closing the loop with the possibility of an exploit written into a DNA molecule presented by Ney et al. in USENIX Security'17. Here we present an end-to-end cyberbiological attack, in which unwitting biologists may be tricked into generating dangerous substances within their labs. Consequently, despite common biosecurity assumptions, the attacker does not need to have physical contact with the generated substance. The most challenging part of the attack, decoding of the obfuscated DNA, is executed within living cells while using primitive biological operations commonly employed by biologists during in-vivo gene editing. This attack scenario underlines the need to harden the synthetic DNA supply chain with protections against cyberbiological threats. To address these threats we propose an improved screening protocol that takes into account in-vivo gene editing.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源