The Case for Security in Bioinformatics


By Christopher Frenz

April 12, 2007 |  In the past two decades, connectivity to networked resources has transformed the way that businesses and retailers operate.  As in the business world, the bioinformatics arena is reveling in electronic data exchange. PubMed boasts more than 16 million biomedical abstracts, and GenBank houses more than 61 million biological sequences.

In addition to networked data repositories, there are a plethora of web applications (e.g. BLAST search tool), and applications for calculating everything from amino-acid ionization states (e.g. H++) to identifying protein domains (e.g. SMART). The Web helps disseminate bioinformatics software, much of it open source, through sites such as Bioinformatics.org and SourceForge.

The prevalence of distribution of scientific data and tools is invaluable to researchers, but despite their vulnerability to the same potential threats that plague their commercial counterparts, security is rarely discussed in the bioinformatics community.

Should developers or distributors of bioinformatics applications be required to make security considerations an essential element of their development or hosting process? While there have been no reports of widespread abuse of scientific computing resources to date, the potential for such abuses do exist.

Threat Assessment
The strict integration of security within bioinformatics application development (including hosted databases) complicates the process, adding time to development and potentially its availability (in extreme cases security concerns can halt release). Moreover, accessing certain data sets or interacting with certain utilities may be complicated to ensure that security measures are properly met. On the user end, time and effort must be spent to evaluate the safety of utilizing a utility rather than just implicitly trusting the utility. These security considerations can interfere with or compete with scientific research for available resources. But what could happen if security measures are not tightly integrated into our application development efforts and usage?

A major threat for Web databases and applications is Denial of Service (DoS) attacks, which render networked resources unavailable to users. Such attacks could seriously hamper research efforts, particularly as many bioinformatics utilities use Web services or API to access content, and a failure to retrieve such content could interfere with an entire application pipeline. 

While DoS attacks are not uncommon, scientific databases are subject to more insidious attacks such as submission of, or change of a record to faulty information (Web database) or the malicious return of faulty results (Web application). The hidden presence of faulty records can waste both time and money, while a Web application security breach could hinder research. When dealing with medical applications, the stakes could be even higher. 

Furthermore, pharming scams could be applied to hosted bioinformatics databases and applications, where detailed logging of user requests and data submissions could potentially be used as a form of industrial espionage. By closely monitoring submitted data and requests along with IP addresses, it could be possible to gain insights into the research activities of other laboratories.

Web-based hosting and distribution of source code and executables introduces important security considerations, including the possibility that an application may be used as a Trojan horse, a malicious purpose concealed behind some seemingly useful functionality. This malicious functionality could damage files or applications or be used for espionage by sending data located on the computer or entered into the application to a remote site.

Here the open source nature of much bioinformatics application development offers both advantages and disadvantages. The ability for anyone to read the code associated with the application can make such breaches easier to spot, but the community-based approach to development can also facilitate such breaches into the application source, since a security flaw could be added by the incorporation of a submitted patch or enhancement.  

Potential security breaches introduced by application installation need not be malicious; numerous applications have been released that contained inadvertent security exploits, such as buffer overflows. Thus bioinformatics applications could introduce similar security vulnerabilities, particularly when developers do not take the possibility into consideration. Users of bioinformatics software should evaluate any downloaded application for security exploits, intentional or not, before use. 

I would like to see the bioinformatics community establish a set of security-related guidelines for bioinformatics practitioners and software developers now, before such exploits become commonplace.

Such guidelines need not be drastically different from general information security recommendations. The key would be to find the proper balance between time and resources spent implementing security and that spent advancing the scientific body of knowledge.

Christopher Frenz is at the Dept. Computer Engineering Technology, New York City College of Technology, Brooklyn, New York. Email: cfrenz@gmail.com.

Subscribe to Bio-IT World  magazine.

Click here to login and leave a comment.  

0 Comments

Add Comment

Text Only 2000 character limit

Page 1 of 1

White Papers & Special Reports

definiens briefingon-76Next-Generation Technologies Revolutionizing Oncology and Diagnostics
underwritten by Definiens

This “Briefing On” collection of Bio-IT World features, commentaries and analysis, presents some of the latest thinking on high-throughput technologies that are being applied to the fields of research and drug discovery, with particular emphasis on oncology, diagnostics and imaging technologies. Download now at no charge compliments of the underwriting sponsor, Definiens. Download This Free Paper



gq nxt gen seq

This Bio•IT World Briefing On “Next-Generation Sequencing,” underwritten by GenomeQuest, Inc.,
presents a selection of feature stories, interviews,commentaries, conference reports, and editorials on the emergence, opportunities, and challenges posed by high-throughput sequencing. Covered in this collection: the launch of new platforms from Applied Biosystems and Helicos; new applications of nextgen sequencing; the rise of personal genomics; and informatics solutions to vexing problem of managing the vast volumes of next-gen data.  Download now 



Life Science Webcasts & Podcasts

GenoLogicsgenologics 2 translational
Enabling Translational Research Informatics

Learn about the challenges facing life sciences research labs to manage their translational research data:

  • The trends for organizations to adopt informatics solutions for translational research.
  • The unique requirements with managing complex data and workflow.
  • What labs should consider when reviewing informatics solutions for translational research.
  • Which life sciences research organizations are successfully adopting an informatics solution.

Download Now



More Podcasts

Job Openings

Assistant Editor (Science Writer)~Cambridge Healthtech Institute (CHI), Needham, MA, 
Cambridge Healthtech Institute seeks an assistant editor (science writer) who is an ambitious, dependable journalist who can fulfill a range of writing and editorial duties for a series of eNewsletters covering various aspects of the biopharmaceutical industry in addition to CHI’s flagship publication, Bio-IT World magazine.  This is a superb opportunity to make important contributions to the growth and success of a multimedia science publishing group, while gaining invaluable experience in multiple facets of the publishing industry.   Interested candidates should submit a cover letter, including 3 writing samples (attached in Word or PDF format), salary history or requirements, and resume to kdavies@healthtech.com. 

Fred Hutchinson Cancer Research Center: IT Business Analyst III
The Hutchinson Center is the only National Cancer Institute-designated comprehensive cancer center in the Pacific Northwest. Through our Tumor Research Initiative, we are finding new ways to detect tumors at an early stage.  We are presently seeking an experienced IT Business Analyst to assess technology needs for the Tumor Research Initiative, and to identify and design improvements to computer based systems.  For more information please visit www.fhcrc.org and search for Job# AD-21465

For reprints and/or copyright permission, please contact RMS, 1808 Colonial Village Lane, Lancaster, PA;

(717) 399-1900 ext 100 or via email to bio-itworld@theygsgroup.com.