In a mind-boggling world first, a team of biologists and security researchers have successfully infected a computer with a malicious program coded into a strand of DNA.
It sounds like science fiction, but I assure you its quite real although you probably dont have to worry about this particular threat vector any time soon. That said, the possibilities suggested by this project are equally fascinating and terrifying to contemplate.
The multidisciplinary team at the University of Washington isnt out to make outlandish headlines, although its certainly done that. They were concerned that the security infrastructure around DNA transcription and analysis was inadequate, having found elementary vulnerabilities in open-source software used in labs around the world. Given the nature of the data usually being handled, this could be a serious problem going forward.
Sure, they could demonstrate the weakness of the systems with the usual malware and remote access tools. Thats how any competent attacker would come at such a system. But the discriminating security professional prefers to stay ahead of the game.
One of the big things we try to do in the computer security community is to avoid a situation where we say, Oh shoot, adversaries are here and knocking on our door and were not prepared,' said professor Tadayoshi Kohno, who has a history of pursuing unusual attack vectors for embedded and niche electronics like pacemakers.
From left, Lee Organick, Karl Koscher, and Peter Ney from the UWs Molecular Information Systems Lab and the Security and Privacy Research Lab prepare the DNA exploit for sequencing
As these molecular and electronic worlds get closer together, there are potential interactions that we havent really had to contemplate before, added Luis Ceze, one co-author of the study.
Accordingly, they made the leap plenty of sci-fi writers have made in the past, and that we are currently exploring via tools like CRISPR: DNA is basically lifes file system. The analysis programs are reading a DNA strands bases (cytosine, thymine etc, the A, T, G, and C we all know) and turning them into binary data. Suppose those nucleotides were encoding binary data in the first place? After all, its been done before right down the hall.
Heres how they did it. All you really need to know about the transcription application is that it reads the raw data coming from the transcription process and sorts through it, looking for patterns and converting the base sequences it finds into binary code.
The conversion from ASCII As, Ts, Gs, and Cs into a stream of bits is done in a fixed-size buffer that assumes a reasonable maximum read length, explained co-author Karl Koscher in response to my requests for more technical information.
That makes it ripe for a basic buffer overflow attack, in which programs execute arbitrary code because it falls outside expected parameters. (They cheated a little by introducing a particular vulnerability into the software themselves, but they also point out that similar ones are present elsewhere, just not as conveniently for purposes of demonstration.)
After developing a way to include executable code in the base sequence, they set about making the exploit itself. Ironically, its inaccurate to call it a virus, although its closer to a real virus than perhaps any malicious code ever written.
The exploit was 176 bases long, Koscher wrote. The compression program translates each base into two bits, which are packed together, resulting in a 44 byte exploit when translated.
Given that there are 4 bases, it would make sense to have each represent a binary pair. Koscher confirmed this was the case. (If youre curious, as I was: A=00, C=01, G=10, T=11.)
Most of these bytes are used to encode an ASCII shell command, he continued. Four bytes are used to make the conversion function return to the system() function in the C standard library, which executes shell commands, and four more bytes were used to tell system() where the command is in memory.
Essentially the code in the DNA escapes the program as soon as it is converted from ACGTs to 00011011s, and executes some commands in the system a sufficient demonstration of the existence of the threat vector. And theres plenty of room for more code if you wanted to do more than break out of the app.
At 176 bases, the DNA strand comprising the exploit is by almost any biological standard, very small, said Lee Organick, a research scientist who worked on the project.
In pursuance of every science journalists prime directive, which is to take interesting news and turn it into an existential threat to humanity, I had more questions for the team.
CONCEIVABLY, I asked, in all caps to emphasize that we were entering speculative territory, could such a payload be delivered via, for example, a doctored blood sample or even directly from a persons body? One can imagine a person whose DNA is essentially deadly to poorly secured computers.
Irresponsibly, Organick stoked the fires of my fearmongering.
A doctored biological sample could indeed be used as a vector for malicious DNA to get processed downstream after sequencing and be executed, he wrote.
However, getting the malicious DNA strand from a doctored sample into the sequencer is very difficult with many technical challenges, he continued. Even if you were successfully able to get it into the sequencer for sequencing, it might not be in any usable shape (it might be too fragmented to be read usefully, for example).
Its not quite the biopunk apocalypse I envisioned, but the researchers do want people thinking along these lines at least as potential avenues of attack.
We do want scientists thinking about this so they can hold the DNA analysis software they write to the appropriate security standards so that this never makes sense to become a potential attack vector in the first place, said Organick.
I would treat any input as untrusted and potentially able to compromise these applications, added Koscher. It would be wise to run these applications with some sort of isolation (in containers, VMs, etc.) to contain the damage an exploit could do. Many of these applications are also run as publicly-available cloud services, and I would make isolating these instances a high priority.
The likelihood of an attack like this actually being pulled off is minuscule, but its a symbolic milestone in the increasing overlap between the digital and the biological.
The researchers will present their findings and process (PDF) next week at the USENIX Security conference in Vancouver.
See the original post:
Malicous code written into DNA infects the computer that reads it - TechCrunch
- Discovering the mysteries of human DNA - Video [Last Updated On: September 7th, 2012] [Originally Added On: September 7th, 2012]
- Scientists go deeper into DNA - Video [Last Updated On: September 7th, 2012] [Originally Added On: September 7th, 2012]
- Instant Egghead - Genes vs. DNA vs. Chromosomes - Video [Last Updated On: September 7th, 2012] [Originally Added On: September 7th, 2012]
- DNA Calls Out Lineup Of Rappers For Future Battles - Video [Last Updated On: September 7th, 2012] [Originally Added On: September 7th, 2012]
- What is DNA? - Video [Last Updated On: September 7th, 2012] [Originally Added On: September 7th, 2012]
- Turn Your DNA Into Fine Art, BMW Zagato Roadster - Video [Last Updated On: September 7th, 2012] [Originally Added On: September 7th, 2012]
- DNA - OFFICIAL URLTV SUMMER MADNESS 2 RECAP! - Video [Last Updated On: September 7th, 2012] [Originally Added On: September 7th, 2012]
- "Binary DNA" - Video [Last Updated On: September 7th, 2012] [Originally Added On: September 7th, 2012]
- 16x9 - DNA Prophecies: Code reveals your future - Video [Last Updated On: September 7th, 2012] [Originally Added On: September 7th, 2012]
- Gilbert Gottfried - Space DNA, Sexy Weight Loss, Badonkadonk Booty - Gilbert Gets It - Video [Last Updated On: September 7th, 2012] [Originally Added On: September 7th, 2012]
- Animated Health Video Production | DNA Services of America - Video [Last Updated On: September 7th, 2012] [Originally Added On: September 7th, 2012]
- Michael Tsarion ~ Mayans ~ 2012 ~ DNA - Video [Last Updated On: September 7th, 2012] [Originally Added On: September 7th, 2012]
- Mini-drones to take your DNA? - Video [Last Updated On: September 7th, 2012] [Originally Added On: September 7th, 2012]
- C2CAM - DNA Research - 07-09-2012 - Coast To Coast AM - Video [Last Updated On: September 7th, 2012] [Originally Added On: September 7th, 2012]
- Inside The DNA Of MDNA - Video [Last Updated On: September 7th, 2012] [Originally Added On: September 7th, 2012]
- KOTD - Rap Battle - DNA vs Eurgh - Video [Last Updated On: September 7th, 2012] [Originally Added On: September 7th, 2012]
- Starchild DNA Showing "Wright" Stuff - Video [Last Updated On: September 7th, 2012] [Originally Added On: September 7th, 2012]
- Chrome Cats - DNA of a Winner(Official Video) - Video [Last Updated On: September 7th, 2012] [Originally Added On: September 7th, 2012]
- DNA leads to arrest in 1980 murder of Oxnard girl [Last Updated On: September 8th, 2012] [Originally Added On: September 8th, 2012]
- 'Junk' DNA: Not So Useless After All [Last Updated On: September 8th, 2012] [Originally Added On: September 8th, 2012]
- Decoding Human DNA [Last Updated On: September 9th, 2012] [Originally Added On: September 9th, 2012]
- Planet of the Apes: What is that big hunk of 'junk' DNA up to ? [Last Updated On: September 10th, 2012] [Originally Added On: September 10th, 2012]
- Genetics Breakthrough Changes Thinking About DNA [Last Updated On: September 11th, 2012] [Originally Added On: September 11th, 2012]
- 'Junk DNA' and the mystery of mankind's missing genes [Last Updated On: September 11th, 2012] [Originally Added On: September 11th, 2012]
- Real-time observation of single DNA molecule repair [Last Updated On: September 12th, 2012] [Originally Added On: September 12th, 2012]
- Court hears DNA findings in child sex case [Last Updated On: September 12th, 2012] [Originally Added On: September 12th, 2012]
- 2012 International Symposium on Human Identification Features Emerging and Best Practice Forensic DNA Techniques ... [Last Updated On: September 12th, 2012] [Originally Added On: September 12th, 2012]
- DNA could help ID a king [Last Updated On: September 13th, 2012] [Originally Added On: September 13th, 2012]
- DNA with a Twist [Last Updated On: September 13th, 2012] [Originally Added On: September 13th, 2012]
- Three reasons to like junk DNA [Last Updated On: September 13th, 2012] [Originally Added On: September 13th, 2012]
- LBNL Seeks Licensees for Highly Specific and Sensitive DNA Extraction Method [Last Updated On: September 13th, 2012] [Originally Added On: September 13th, 2012]
- Under-twisted DNA origami delivers cancer drugs to tumors [Last Updated On: September 13th, 2012] [Originally Added On: September 13th, 2012]
- DNA ‘junk' contains a treasure of information about disease [Last Updated On: September 14th, 2012] [Originally Added On: September 14th, 2012]
- Research: Hopping DNA supercoils [Last Updated On: September 14th, 2012] [Originally Added On: September 14th, 2012]
- DNA evidence missing in Assange case [Last Updated On: September 16th, 2012] [Originally Added On: September 16th, 2012]
- Missing DNA evidence in Assange case [Last Updated On: September 16th, 2012] [Originally Added On: September 16th, 2012]
- No Assange DNA on torn condom - report [Last Updated On: September 16th, 2012] [Originally Added On: September 16th, 2012]
- Calif. DNA Collection From Arrestees Challenged [Last Updated On: September 17th, 2012] [Originally Added On: September 17th, 2012]
- Federal appeals court to hear challenge to California DNA collection law [Last Updated On: September 17th, 2012] [Originally Added On: September 17th, 2012]
- Applied DNA Sciences Contracts With Inventionland [Last Updated On: September 18th, 2012] [Originally Added On: September 18th, 2012]
- Applied DNA Sciences, Textile Centre of Excellence Unveil Textiles Anti-Counterfeiting Platform [Last Updated On: September 18th, 2012] [Originally Added On: September 18th, 2012]
- Rapist caught by DNA test jailed [Last Updated On: September 18th, 2012] [Originally Added On: September 18th, 2012]
- FBI eager to embrace mobile 'Rapid DNA' testing [Last Updated On: September 19th, 2012] [Originally Added On: September 19th, 2012]
- Expansion of criminal DNA collection proposed [Last Updated On: September 19th, 2012] [Originally Added On: September 19th, 2012]
- Assessment of HPV DNA Alone Insufficient to Identify HPV-Driven Head and Neck Cancers [Last Updated On: September 19th, 2012] [Originally Added On: September 19th, 2012]
- George Zimmerman's DNA, not Trayvon Martin's, found on gun [Last Updated On: September 20th, 2012] [Originally Added On: September 20th, 2012]
- George Zimmerman: No DNA evidence of a struggle for his gun [Last Updated On: September 20th, 2012] [Originally Added On: September 20th, 2012]
- DNA evidence links Vallejo man to January stabbing in SLO, police say [Last Updated On: September 20th, 2012] [Originally Added On: September 20th, 2012]
- Legal hurdles threaten to slow FBI's 'Rapid DNA' revolution [Last Updated On: September 21st, 2012] [Originally Added On: September 21st, 2012]
- Judge denies motions to dismiss DNA evidence in Hudson murder case [Last Updated On: September 22nd, 2012] [Originally Added On: September 22nd, 2012]
- Researchers report novel approach for single molecule electronic DNA sequencing [Last Updated On: September 22nd, 2012] [Originally Added On: September 22nd, 2012]
- Novel approach for single molecule electronic DNA sequencing [Last Updated On: September 22nd, 2012] [Originally Added On: September 22nd, 2012]
- DNA helps Wyckoff police nab 'motorcycle burglar' [Last Updated On: September 22nd, 2012] [Originally Added On: September 22nd, 2012]
- Novel DNA barcode engineered: New technology could launch biomedical imaging to next level [Last Updated On: September 25th, 2012] [Originally Added On: September 25th, 2012]
- DNA Microarray 2012: A Focus on Sales Growth [Last Updated On: September 25th, 2012] [Originally Added On: September 25th, 2012]
- DNA in 1980 Maine murder case shown to match defendant [Last Updated On: September 25th, 2012] [Originally Added On: September 25th, 2012]
- DNA recovered during Rayney probe [Last Updated On: September 26th, 2012] [Originally Added On: September 26th, 2012]
- FBI makes headway on DNA testing backlog, report says [Last Updated On: September 26th, 2012] [Originally Added On: September 26th, 2012]
- Male DNA found for first time in female brains [Last Updated On: September 27th, 2012] [Originally Added On: September 27th, 2012]
- Bearing Sons Leaves Male DNA Traces in Mom's Brain [Last Updated On: September 28th, 2012] [Originally Added On: September 28th, 2012]
- Many female brains contain male DNA [Last Updated On: September 28th, 2012] [Originally Added On: September 28th, 2012]
- New drive to take criminals' DNA [Last Updated On: September 28th, 2012] [Originally Added On: September 28th, 2012]
- DNA remains focus in Highway of Tears cases [Last Updated On: September 28th, 2012] [Originally Added On: September 28th, 2012]
- Analysing The Evidence On DNA [Last Updated On: September 29th, 2012] [Originally Added On: September 29th, 2012]
- DNA Clears Death Row Inmate [Last Updated On: September 29th, 2012] [Originally Added On: September 29th, 2012]
- Burn victim identified by DNA in maggots [Last Updated On: September 29th, 2012] [Originally Added On: September 29th, 2012]
- DNA fails to match couple on two other skeletons [Last Updated On: September 29th, 2012] [Originally Added On: September 29th, 2012]
- DNA Dynamics Update on Sports Title [Last Updated On: September 30th, 2012] [Originally Added On: September 30th, 2012]
- DNA solves teen's 1974 murder [Last Updated On: September 30th, 2012] [Originally Added On: September 30th, 2012]
- Some Women's Brains Contain Male DNA: Study [Last Updated On: September 30th, 2012] [Originally Added On: September 30th, 2012]
- DNA exonerates man after 15 years on death row - Video [Last Updated On: September 30th, 2012] [Originally Added On: September 30th, 2012]
- DNA link prompts charges in cold case rapes - Video [Last Updated On: September 30th, 2012] [Originally Added On: September 30th, 2012]
- DNA testing has its limits [Last Updated On: October 1st, 2012] [Originally Added On: October 1st, 2012]
- DNA evidence exonerates 300th prisoner nationwide [Last Updated On: October 1st, 2012] [Originally Added On: October 1st, 2012]
- DNA testing facility in Pune to speed up cases in Mumbai [Last Updated On: October 1st, 2012] [Originally Added On: October 1st, 2012]
- Rape DNA process 'not adequate' [Last Updated On: October 2nd, 2012] [Originally Added On: October 2nd, 2012]
- IntegenX Announces U.S. Launch of the RapidHIT™ 200 System – Rapid DNA Technology That Will Revolutionize the Use of ... [Last Updated On: October 2nd, 2012] [Originally Added On: October 2nd, 2012]
- 300th person exonerated by DNA evidence [Last Updated On: October 2nd, 2012] [Originally Added On: October 2nd, 2012]
- Inherited Diseases Found Sooner in Newborns With DNA Scan [Last Updated On: October 3rd, 2012] [Originally Added On: October 3rd, 2012]
- Woman charged in husband's death gives DNA sample [Last Updated On: October 3rd, 2012] [Originally Added On: October 3rd, 2012]