Researchers use DNA to infect a computer with malicious code

Malware-laden DNA strands can be used to exploit open-source software

A team of researchers have successfully infected a computer system using a strand of human DNA encoded with a malicious program.

The remarkable experiment, conducted by a multidisciplinary team of biologists and cyber security researchers at the University of Washington, aimed to address concerns around vulnerabilities in open-source software installed in labs around the world.

Advertisement - Article continues below

While vulnerabilities of this kind are typically targeted by malware and remote hacking, the team investigated the possibility that future attack vectors may emerged from the very materials being handled, in this case DNA being transcribed and digitised for further analysis.

Computers are required to handle the vast amount of processing needed to sift through the billions of DNA bases from a single sample. In order to store the basic units that make up DNA, the data is processed using multiple open-source computer programs.

"We analyzed open-source bioinformatics tools that are commonly used by researchers to analyze DNA data," the team explained in a research blog. "Many of these are written in languages like C and C++ that are known to contain security vulnerabilities unless programs are carefully written."

The team, based at the University of Washington's Paul G. Allen School of Computer Science and Engineering, identified that most of these programs do not follow best security practices, had little to no input sanitisation to check incoming code, and had a number of insecure functions.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

Using a synthetic DNA strand with a malicious code embedded into its base, the team was able to demonstrate that standard code could be transferred during the transcription process. When the strand was sequenced, the code was able to exploit these vulnerabilities to take control of a system and in theory grant remote control to a hacker.

Given the unexpected nature of an attack of this kind, relatively basic remote execution malwares could prove to be highly effective. However, while the idea of human DNA being a route for hackers to spread malware is terrifying, the researchers said there is no evidence to suggests that the security around DNA sequencing is under attack, and that the goal of the research was to create awareness.

"We again stress that there is no cause for people to be alarmed today," the team added, "But we also encourage the DNA sequencing community to proactively address computer security risks before any adversaries manifest. That said, it is time to improve the state of DNA security."

However, it does highlight the need for security researchers to be one step ahead of criminals, and keep track of emerging technology before it can be exploited.

The team is due to present its findings at the USENIX Security Symposium in Vancouver next week.

Picture: Bigstock

Featured Resources

Preparing for long-term remote working after COVID-19

Learn how to safely and securely enable your remote workforce

Download now

Cloud vs on-premise storage: What’s right for you?

Key considerations driving document storage decisions for businesses

Download now

Staying ahead of the game in the world of data

Create successful marketing campaigns by understanding your customers better

Download now

Transforming productivity

Solutions that facilitate work at full speed

Download now
Advertisement

Recommended

Visit/mobile/google-android/356373/over-2-dozen-additional-android-apps-found-stealing-user-data
Google Android

Over two dozen Android apps found stealing user data

7 Jul 2020
Visit/security/ransomware/356292/university-of-california-gets-fleeced-by-hackers-for-114-million
ransomware

University of California gets fleeced by hackers for $1.14 million

30 Jun 2020
Visit/security/cyber-security/356289/australia-announces-135b-investment-in-cybersecurity
cyber security

Australia announces $1.35 billion investment in cyber security

30 Jun 2020
Visit/cloud/cloud-security/356288/csa-and-issa-form-cybersecurity-partnership
cloud security

CSA and ISSA form cyber security partnership

30 Jun 2020

Most Popular

Visit/mobile/google-android/356373/over-2-dozen-additional-android-apps-found-stealing-user-data
Google Android

Over two dozen Android apps found stealing user data

7 Jul 2020
Visit/laptops/29190/how-to-find-ram-speed-size-and-type
Laptops

How to find RAM speed, size and type

24 Jun 2020
Visit/cloud/356260/the-road-to-recovery
Sponsored

The road to recovery

30 Jun 2020