IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Researchers use DNA to infect a computer with malicious code

Malware-laden DNA strands can be used to exploit open-source software

A team of researchers have successfully infected a computer system using a strand of human DNA encoded with a malicious program.

The remarkable experiment, conducted by a multidisciplinary team of biologists and cyber security researchers at the University of Washington, aimed to address concerns around vulnerabilities in open-source software installed in labs around the world.

While vulnerabilities of this kind are typically targeted by malware and remote hacking, the team investigated the possibility that future attack vectors may emerged from the very materials being handled, in this case DNA being transcribed and digitised for further analysis.

Computers are required to handle the vast amount of processing needed to sift through the billions of DNA bases from a single sample. In order to store the basic units that make up DNA, the data is processed using multiple open-source computer programs.

pharmaceutical laboratory

"We analyzed open-source bioinformatics tools that are commonly used by researchers to analyze DNA data," the team explained in a research blog. "Many of these are written in languages like C and C++ that are known to contain security vulnerabilities unless programs are carefully written."

The team, based at the University of Washington's Paul G. Allen School of Computer Science and Engineering, identified that most of these programs do not follow best security practices, had little to no input sanitisation to check incoming code, and had a number of insecure functions.

Using a synthetic DNA strand with a malicious code embedded into its base, the team was able to demonstrate that standard code could be transferred during the transcription process. When the strand was sequenced, the code was able to exploit these vulnerabilities to take control of a system and in theory grant remote control to a hacker.

Given the unexpected nature of an attack of this kind, relatively basic remote execution malwares could prove to be highly effective. However, while the idea of human DNA being a route for hackers to spread malware is terrifying, the researchers said there is no evidence to suggests that the security around DNA sequencing is under attack, and that the goal of the research was to create awareness.

"We again stress that there is no cause for people to be alarmed today," the team added, "But we also encourage the DNA sequencing community to proactively address computer security risks before any adversaries manifest. That said, it is time to improve the state of DNA security."

However, it does highlight the need for security researchers to be one step ahead of criminals, and keep track of emerging technology before it can be exploited.

The team is due to present its findings at the USENIX Security Symposium in Vancouver next week.

Picture: Bigstock

Featured Resources

The state of Salesforce: Future of business

Three articles that look forward into the changing state of Salesforce and the future of business

Free Download

The mighty struggle to migrate SAP to the cloud may be over

A simplified and unified approach to delivering Enterprise Transformation in the cloud

Free Download

The business value of the transformative mainframe

Modernising on the mainframe

Free Download

The Total Economic Impact™ Of IBM FlashSystem

Cost savings and business benefits enabled by FlashSystem

Free Download

Recommended

RATDispenser evades nine in ten anti-virus engines
Security

RATDispenser evades nine in ten anti-virus engines

24 Nov 2021
Hackers use Linux backdoor on compromised e-commerce sites with software skimmer
malware

Hackers use Linux backdoor on compromised e-commerce sites with software skimmer

19 Nov 2021
Out-of-hours ransomware attacks have a greater impact on revenue
ransomware

Out-of-hours ransomware attacks have a greater impact on revenue

18 Nov 2021
Millions of routers and NAS devices vulnerable to BotenaGo malware
malware

Millions of routers and NAS devices vulnerable to BotenaGo malware

12 Nov 2021

Most Popular

Cyber attack on software supplier causes "major outage" across the NHS
cyber attacks

Cyber attack on software supplier causes "major outage" across the NHS

8 Aug 2022
Why convenience is the biggest threat to your security
Sponsored

Why convenience is the biggest threat to your security

8 Aug 2022
How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

29 Jul 2022