Highlighting Vulnerabilities in a Genomics Biocybersecurity Lab Through Threat Modeling and Security Testing

Published: 2025, Last Modified: 09 Nov 2025SECRYPT 2025EveryoneRevisionsBibTeXCC BY-SA 4.0
Abstract: Biocybersecurity, a specialty field applying modern cybersecurity developments to the bioeconomy, is garnering progressively more attention as concerns increase over the protection of bioeconomic data generated each year. Genomic data is a key data type that falls under the bioeconomy umbrella and can be protected health information, intellectual property, or research data, depending on the use case. To increase understanding of cybersecurity for genomic lab environments, a biocybersecurity laboratory was set up and threat modeling was conducted on it using the STRIDE threat modeling methodology. Potential attack techniques were then mapped using the MITRE ATT&CK enterprise matrix and attack trees were generated to sequentially show the steps of these attacks. Going a step further, the initial steps of an attack tree were attempted against a DNA sequencer in the biocybersecurity lab. While the results of this testing did not yield an exploitable vulnerability that could be used to fu
Loading