Skip to main content
QUICK REVIEW

[论文解读] Cyberbiosecurity: DNA Injection Attack in Synthetic Biology

Dor Farbiash, Rami Puzis|arXiv (Cornell University)|Nov 28, 2020
CRISPR and Genetic Engineering参考文献 46被引用 5
一句话总结

本文提出了一种新型网络生物攻击:通过混淆技术使恶意DNA绕过当前合成DNA筛查协议,随后利用CRISPR-Cas9基因编辑在活细胞中解码并表达,实现远程生产危险物质,且无需物理接触。关键贡献在于提出基因编辑距离(GED)筛查方法,可检测100%绕过HHS指南的混淆序列,揭示现有生物安全框架中的关键漏洞。

ABSTRACT

Today arbitrary synthetic DNA can be ordered online and delivered within several days. In order to regulate both intentional and unintentional generation of dangerous substances, most synthetic gene providers screen DNA orders. A weakness in the Screening Framework Guidance for Providers of Synthetic Double-Stranded DNA allows screening protocols based on this guidance to be circumvented using a generic obfuscation procedure inspired by early malware obfuscation techniques. Furthermore, accessibility and automation of the synthetic gene engineering workflow, combined with insufficient cybersecurity controls, allow malware to interfere with biological processes within the victim's lab, closing the loop with the possibility of an exploit written into a DNA molecule presented by Ney et al. in USENIX Security'17. Here we present an end-to-end cyberbiological attack, in which unwitting biologists may be tricked into generating dangerous substances within their labs. Consequently, despite common biosecurity assumptions, the attacker does not need to have physical contact with the generated substance. The most challenging part of the attack, decoding of the obfuscated DNA, is executed within living cells while using primitive biological operations commonly employed by biologists during in-vivo gene editing. This attack scenario underlines the need to harden the synthetic DNA supply chain with protections against cyberbiological threats. To address these threats we propose an improved screening protocol that takes into account in-vivo gene editing.

研究动机与目标

  • 演示一种远程网络生物攻击:恶意DNA被注入生物学家的工作流程,并触发危险物质的生产。
  • 揭示HHS筛查框架指南中的关键漏洞,该漏洞允许通过混淆技术规避DNA序列筛查。
  • 提出一种增强的筛查方法——基因编辑距离(GED),以检测被混淆的恶意DNA序列。
  • 强调需在合成生物学流程中整合网络安全控制措施,尤其在软件和生物协议层面。
  • 倡导改进生物安全筛查标准,以考虑体内基因编辑作为解码机制。

提出的方法

  • 该攻击采用受恶意软件混淆启发的基因混淆技术,以改变核苷酸序列,使其避开基于模式匹配的筛查工具。
  • 恶意DNA设计为在HHS指南下无法被检测,但可通过标准CRISPR-Cas9基因编辑协议在活细胞中解码并表达。
  • 提出的基因编辑距离(GED)度量方法计算将良性序列转化为恶意序列所需的最少基因编辑操作数(如插入、删除、替换),从而实现对混淆威胁的有效检测。
  • 创建了一个包含50个混淆DNA序列的基准数据集,用于评估筛查方法在真实世界混淆模式下的表现。
  • 通过建模常见的体内编辑操作,确保检测方法具备生物学合理性,使其与实际实验室工作流程相关。
  • 缓解策略包括:受密码保护的数字报告、纸质质量报告、带有安全关键元数据的物理试管标签,以及生物层面的Cas9抑制。

实验结果

研究问题

  • RQ1是否可使用受恶意软件启发的混淆技术,绕过现有DNA筛查指南,即使DNA在后续被活细胞中解码?
  • RQ2在通过标准体内基因编辑解码的前提下,混淆DNA序列在多大程度上可规避HHS筛查框架指南的检测?
  • RQ3新的筛查度量标准——基因编辑距离(GED)——是否能有效检测出绕过当前指南的混淆恶意DNA序列?
  • RQ4网络与生物攻击面的整合如何实现无需物理接触最终产物的远程端到端网络生物攻击?
  • RQ5在软件、生物安全和生物协议层面,可实施哪些实际且可行的安全控制措施以防止此类攻击?

主要发现

  • 基准数据集中50个混淆DNA样本中有16个未被HHS筛查框架指南检测到,表明存在显著的检测盲区。
  • 基因编辑距离(GED)方法成功检测出全部50个混淆DNA样本,其在检测可解码为有害内容的序列方面优于HHS指南。
  • 攻击场景表明,远程攻击者可将恶意DNA注入生物学家的工作流程,并在无需接触最终产物的情况下,触发体内危险物质的生产。
  • 本研究揭示,当前生物安全筛查协议对利用常见体内基因编辑操作的混淆技术缺乏足够防御能力。
  • 所提出的缓解策略(如受密码保护的报告、纸质质量报告、试管标签)可显著降低网络生物攻击的风险。
  • 本研究强调,必须通过具备网络安全意识的筛查方法,强化合成DNA供应链,以应对生物解码机制。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。