Skip to main content
QUICK REVIEW

[论文解读] Computer Security Risks of Distant Relative Matching in Consumer Genetic Databases

Peter Ney, Luís Ceze|arXiv (Cornell University)|Oct 5, 2018
Genomic variations and chromosomal abnormalities参考文献 3被引用 9
一句话总结

本文揭示了消费者基因数据库中远亲匹配带来的关键计算机安全风险,特别是伪造或篡改基因型数据可能误导执法机构、引发欺诈或勒索。论文提出对基因型数据使用密码学数字签名及增强身份验证机制,以防止滥用,强调随着第三方基因服务被用于刑事调查等高风险应用,必须立即加强安全实践。

ABSTRACT

Consumer genetic testing has become immensely popular in recent years and has lead to the creation of large scale genetic databases containing millions of dense autosomal genotype profiles. One of the most used features offered by genetic databases is the ability to find distant relatives using a technique called relative matching (or DNA matching). Recently, novel uses of relative matching were discovered that combined matching results with genealogical information to solve criminal cold cases. New estimates suggest that relative matching, combined with simple demographic information, could be used to re-identify a significant percentage of US Caucasian individuals. In this work we attempt to systematize computer security and privacy risks from relative matching and describe new security problems that can occur if an attacker uploads manipulated or forged genetic profiles. For example, forged profiles can be used by criminals to misdirect investigations, con-artists to defraud victims, or political operatives to blackmail opponents. We discuss solutions to mitigate these threats, including existing proposals to use digital signatures, and encourage the consumer genetics community to consider the broader security implications of relative matching now that it is becoming so prominent.

研究动机与目标

  • 分析消费者基因数据库中远亲匹配带来的新兴计算机安全威胁,特别是其在执法调查中的应用。
  • 识别恶意行为者如何利用第三方基因服务中薄弱的认证与访问控制机制,操纵远亲匹配结果。
  • 提出技术与政策解决方案,如数字签名与身份验证,以减轻伪造或篡改基因型档案的风险。
  • 呼吁消费者基因领域采纳更强的软件安全实践,因为这些数据库正日益具有法医与法律意义。

提出的方法

  • 分析真实案例,包括黄金州杀手案,以识别第三方基因数据库中的攻击面。
  • 建模攻击向量,如上传伪造基因型数据、入侵特权访问权限、篡改元数据以改变远亲匹配结果。
  • 提出对原始基因数据文件使用数字签名,以确保其真实性和来自合法DTC服务的来源验证。
  • 建议基因分型仪器本身对数据进行加密认证,附带设备ID、时间戳和样本来源信息。
  • 倡导对账户所有者实施端到端身份验证,并将档案与已验证身份关联,以防止伪装与拒绝服务攻击。
  • 推动采纳软件安全最佳实践,如定期渗透测试、安全认证与补丁管理,尤其在非商业、低对抗压力的服务中。

实验结果

研究问题

  • RQ1消费者基因数据库中的远亲匹配主要存在哪些计算机安全风险?
  • RQ2攻击者如何通过伪造或篡改的基因型档案操纵远亲匹配结果?
  • RQ3哪些技术控制措施可防止第三方基因服务中未经授权或恶意的档案上传?
  • RQ4数字签名与身份验证如何降低基因数据库在法医与调查应用中的滥用风险?
  • RQ5第三方基因服务应采取何种安全实践,以应对在执法中成为关键基础设施所带来的威胁?

主要发现

  • 攻击者可通过上传伪造档案,利用消费者基因数据库中的远亲匹配功能,误导刑事调查,错误地将个体与嫌疑人关联。
  • 犯罪分子或政治操作者可能利用篡改的档案对个人实施勒索,或通过伪造家族关系实施欺诈。
  • 使用GedMatch等第三方服务进行执法调查会增加风险,因为这些平台通常缺乏严格的安全控制与认证机制。
  • 对原始基因数据文件实施数字签名可防止伪造档案上传,并确保数据源自合法DTC服务。
  • 验证账户所有者身份并将其与档案数据关联,可降低伪装与拒绝服务攻击的风险。
  • 随着基因数据库人口覆盖率的提升,重新识别的可能性增加,因此在高风险应用中必须采用更强的安全与认证措施。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。