רמי פוזיס

אקדמי בכיר

Targeting Systems, Not Pathogens

Adapting Cybersecurity Threat Modeling for Modern Biosecurity

James Diggans, Kevin Flyangolts, Rami Puzis

The biosecurity community's historical focus on physical containment of known pathogens is being outpaced by AI-enabled biodesign tools that can create novel biological threats bearing no sequence similarity to well-characterized agents or toxins. This shift from threats defined by sequence identity to threats defined by functional equivalence mirrors the evolution of cybersecurity, where behavioral analysis became the dominant paradigm for detecting novel and sophisticated threats, surpassing reliance on signature- and hash-based methods. We propose that biosecurity adopt three foundational frameworks from cybersecurity: (1) vulnerability enumeration analogous to the Common Vulnerabilities and Exposures (CVE) system, (2) threat categorization using an adaptation of Microsoft's STRIDE model, and (3) 'biological' adversary tactics mapping inspired by MITRE ATT&CK. We present concrete examples of each framework applied to biological threats and outline a roadmap for development. By shifting from pathogen-list defense to vulnerability-aware, functionbased threat modeling, the biosecurity community can build defenses capable of anticipating engineered threats rather than merely cataloging the natural ones.

שפת פרסום אנגלית
דפים 207-213
סטטוס פרסום פורסם - 01.01.2026

Keywords

att&ck
biosecurity
cve
cybersecurity
stride

ASJC Scopus subject areas

Artificial Intelligence
Computer Networks and Communications
Information Systems
Safety, Risk, Reliability and Quality
Communication
גישה למסמך
10.1109/SPW72489.2026.00024
קבצים וקישורים אחרים
Link to publication in Scopus