
רמי פוזיס
Targeting Systems, Not Pathogens
Adapting Cybersecurity Threat Modeling for Modern Biosecurity
The biosecurity community's historical focus on physical containment of known pathogens is being outpaced by AI-enabled biodesign tools that can create novel biological threats bearing no sequence similarity to well-characterized agents or toxins. This shift from threats defined by sequence identity to threats defined by functional equivalence mirrors the evolution of cybersecurity, where behavioral analysis became the dominant paradigm for detecting novel and sophisticated threats, surpassing reliance on signature- and hash-based methods. We propose that biosecurity adopt three foundational frameworks from cybersecurity: (1) vulnerability enumeration analogous to the Common Vulnerabilities and Exposures (CVE) system, (2) threat categorization using an adaptation of Microsoft's STRIDE model, and (3) 'biological' adversary tactics mapping inspired by MITRE ATT&CK. We present concrete examples of each framework applied to biological threats and outline a roadmap for development. By shifting from pathogen-list defense to vulnerability-aware, functionbased threat modeling, the biosecurity community can build defenses capable of anticipating engineered threats rather than merely cataloging the natural ones.
| שפת פרסום | אנגלית |
| דפים | 207-213 |
| סטטוס פרסום | פורסם - 01.01.2026 |