Nav: Home

Personalized medicine software vulnerability uncovered by Sandia researchers

July 02, 2019

LIVERMORE, Calif. -- A weakness in one common open source software for genomic analysis left DNA-based medical diagnostics vulnerable to cyberattacks.

Researchers at Sandia National Laboratories identified the weakness and notified the software developers, who issued a patch to fix the problem. The issue has also been fixed in the latest release of the software. While no attack from this vulnerability is known, the National Institutes of Standards and Technology recently described it in a note to software developers, genomics researchers and network administrators.

The discovery reveals that protecting genomic information involves more than safe storage of an individual's genetic information. The cybersecurity of computer systems analyzing genetic data is also crucial, said Corey Hudson, a bioinformatics researcher at Sandia who helped uncover the issue.

Personalized medicine -- the process of using a patient's genetic information to guide medical treatment -- involves two steps: sequencing the entire genetic content from a patient's cells and comparing that sequence to a standardized human genome. Through that comparison, doctors identify specific genetic changes in a patient that are linked to disease.

Genome sequencing starts with cutting and replicating a person's genetic information into millions of small pieces. Then a machine reads each piece numerous times and transforms images of the pieces into sequences of building blocks, commonly represented by the letters A, T, C and G. Finally, software collects those sequences and matches each snippet to its place on a standardized human genome sequence. One matching program used widely by personalized genomics researchers is called Burrows-Wheeler Aligner (BWA).

Sandia researchers studying the cybersecurity of this program found a weak spot when the program imports the standardized genome from government servers. The standardized genome sequence traveled over insecure channels, which created the opportunity for a common cyberattack called a "man-in-the-middle."

In this attack, an adversary or a hacker could intercept the standard genome sequence and then transmit it to a BWA user along with a malicious program that alters genetic information obtained from sequencing. The malware could then change a patient's raw genetic data during genome mapping, making the final analysis incorrect without anyone knowing it. Practically, this means doctors may prescribe a drug based on the genetic analysis that, had they had the correct information, they would have known would be ineffective or toxic to a patient.

Forensic labs and genome sequencing companies that also use this mapping software were also temporarily vulnerable to having results maliciously altered in the same way. Information from direct-to-consumer genetic tests was not affected by this vulnerability because these tests use a different sequencing method than whole genome sequencing, Hudson said.

Security cybersleuths

To find this vulnerability, Hudson and his cybersecurity colleagues at the University of Illinois at Urbana-Champaign used a platform developed by Sandia called Emulytics to simulate the process of genome mapping. First, they imported genetic information simulated to resemble that from a sequencer. Then they had two servers send information to Emulytics. One provided a standard genome sequence and the other acted as the "man-in-the-middle" interceptor. The researchers mapped the sequencing results and compared results with and without an attack to see how the attack changed the final sequence.

"Once we discovered that this attack could change a patient's genetic information, we followed responsible disclosure," Hudson said. The researchers contacted the open source developers, who then issued a patch to fix the problem. They also contacted public agencies, including cybersecurity experts at the U.S. Computer Emergency Readiness Team, so they could more widely distribute information about this issue.

The research, funded by Sandia's Laboratory Directed Research and Development program, continues testing other genome mapping software for security weaknesses. Differences between each program mean the researchers might find a similar, but not identical, issue in other programs, Hudson said.

Along with installing the latest version of BWA, Hudson and his colleagues recommend other "cyberhygiene" strategies to secure genomic information, including transmitting data over encrypted channels and using software that protects sequencing data from being changed. They also encourage security researchers who routinely analyze open source software for weaknesses to look at genomics programs. This practice is common in industrial control systems in the energy grid and software used in critical infrastructure, Hudson said, but would be a new area for genomics security.

"Our goal is to make systems safer for people who use them by helping to develop best practices," he said.
-end-
Sandia National Laboratories is a multimission laboratory operated by National Technology and Engineering Solutions of Sandia LLC, a wholly owned subsidiary of Honeywell International Inc., for the U.S. Department of Energy's National Nuclear Security Administration. Sandia Labs has major research and development responsibilities in nuclear deterrence, global security, defense, energy technologies and economic competitiveness, with main facilities in Albuquerque, New Mexico, and Livermore, California.

Sandia news media contact: Melissae Fellet, mfellet@sandia.gov, 505-845-7478

DOE/Sandia National Laboratories

Related Genome Sequencing Articles:

Using whole-genome sequencing for early identification and containment of AMR pathogens
A study published today examines the evolutionary and epidemiologic history of an epidemic strain of extensively drug-resistant tuberculosis (XDR-TB) -- called LAM4/KZN.
Whole genome sequencing could help save pumas from inbreeding
The first complete genetic sequences of individual mountain lions point the way to better conservation strategies for saving threatened populations of the wild animals.
Researchers move beyond sequencing and create a 3D genome
St. Jude Children's Research Hospital scientists have taken whole genome sequencing to the next level by creating a 3D map of the genome to better understand development and disease.
Clinical utility of rapid whole genome sequencing in neonates with seizures
Clinical utility of rWGS in the evaluation of neonatal seizures.
Viral genome sequencing in the heart of a Lassa outbreak
The first researchers to deploy a mobile nanopore sequencing technology to evaluate viral genomics at the height of a Lassa virus outbreak in 2018 now report their results.
New era for blood transfusions through genome sequencing
In a new study, investigators from Brigham and Women's Hospital and Harvard Medical School, as well as from the New York Blood Center have leveraged the MedSeq Project -- the first randomized trial of whole genome sequencing in healthy adults -- to develop and validate a computer program that can comprehensively and cost-effectively determine differences in individuals' blood types with more than 99 percent accuracy.
Does genome sequencing increase downstream costs?
The MedSeq Project, led by investigators at Brigham Women's Hospital, is the first randomized trial to provide whole genome sequencing to both presumably healthy patients as well as those with a known cardiology issue.
Genome sequencing reveals extensive inbreeding in Scandinavian wolves
Researchers from Uppsala University and others have for the first time determined the full genetic consequences of intense inbreeding in a threatened species.
Whole genome sequencing identifies new genetic signature for autism
An analysis of the complete genomes of 2,064 people reveals that multiple genetic variations could contribute to autism.
Whole genome sequencing identifies cause of zoonotic epidemic
For the first time, researchers have used whole genome sequencing to identify the cause of a zoonotic infection that sparked a national epidemic.
More Genome Sequencing News and Genome Sequencing Current Events

Trending Science News

Current Coronavirus (COVID-19) News

Top Science Podcasts

We have hand picked the top science podcasts of 2020.
Now Playing: TED Radio Hour

Teaching For Better Humans 2.0
More than test scores or good grades–what do kids need for the future? This hour, TED speakers explore how to help children grow into better humans, both during and after this time of crisis. Guests include educators Richard Culatta and Liz Kleinrock, psychologist Thomas Curran, and writer Jacqueline Woodson.
Now Playing: Science for the People

#556 The Power of Friendship
It's 2020 and times are tough. Maybe some of us are learning about social distancing the hard way. Maybe we just are all a little anxious. No matter what, we could probably use a friend. But what is a friend, exactly? And why do we need them so much? This week host Bethany Brookshire speaks with Lydia Denworth, author of the new book "Friendship: The Evolution, Biology, and Extraordinary Power of Life's Fundamental Bond". This episode is hosted by Bethany Brookshire, science writer from Science News.
Now Playing: Radiolab

Space
One of the most consistent questions we get at the show is from parents who want to know which episodes are kid-friendly and which aren't. So today, we're releasing a separate feed, Radiolab for Kids. To kick it off, we're rerunning an all-time favorite episode: Space. In the 60's, space exploration was an American obsession. This hour, we chart the path from romance to increasing cynicism. We begin with Ann Druyan, widow of Carl Sagan, with a story about the Voyager expedition, true love, and a golden record that travels through space. And astrophysicist Neil de Grasse Tyson explains the Coepernican Principle, and just how insignificant we are. Support Radiolab today at Radiolab.org/donate.