On Building Automation System security

被引:0
|
作者
Morales-Gonzalez, Christopher [1 ]
Harper, Matthew [1 ]
Cash, Michael [2 ]
Luo, Lan [3 ]
Ling, Zhen [4 ]
Sun, Qun Z. [2 ]
Fu, Xinwen [1 ,2 ]
机构
[1] Univ Massachusetts Lowell, Dept Comp Sci, Lowell, MA 01854 USA
[2] Univ Cent Florida, Dept Elect & Comp Engn, Orlando, FL 32816 USA
[3] Anhui Univ Technol, Sch Comp Sci & Technol, Maanshan 243032, Peoples R China
[4] Anhui Univ Technol, Sch Comp Sci & Engn, Nanjing 211189, Peoples R China
来源
HIGH-CONFIDENCE COMPUTING | 2024年 / 4卷 / 03期
基金
美国国家科学基金会;
关键词
Building automation system; BAS protocols; Security; Attack; WAVE;
D O I
10.1016/j.hcc.2024.100236
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Building Automation Systems (BASs) are seeing increased usage in modern society due to the plethora of benefits they provide such as automation for climate control, HVAC systems, entry systems, and lighting controls. Many BASs in use are outdated and suffer from numerous vulnerabilities that stem from the design of the underlying BAS protocol. In this paper, we provide a comprehensive, up-to-date survey on BASs and attacks against seven BAS protocols including BACnet, EnOcean, KNX, LonWorks, Modbus, ZigBee, and Z-Wave. Holistic studies of secure BAS protocols are also presented, covering BACnet Secure Connect, KNX Data Secure, KNX/IP Secure, ModBus/TCP Security, EnOcean High Security and Z-Wave Plus. LonWorks and ZigBee do not have security extensions. We point out how these security protocols improve the security of the BAS and what issues remain. A case study is provided which describes a real-world BAS and showcases its vulnerabilities as well as recommendations for improving the security of it. We seek to raise awareness to those in academia and industry as well as highlight open problems within BAS security. (c) 2024 The Author(s). Published by Elsevier B.V. on behalf of Shandong University. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).
引用
收藏
页数:20
相关论文
共 50 条
  • [1] Security in Building Automation Systems
    Granzer, Wolfgang
    Praus, Fritz
    Kastner, Wolfgang
    IEEE TRANSACTIONS ON INDUSTRIAL ELECTRONICS, 2010, 57 (11) : 3622 - 3630
  • [2] Cyber security, building automation, and the intelligent building
    Fisk, David
    INTELLIGENT BUILDINGS INTERNATIONAL, 2012, 4 (03) : 169 - 181
  • [3] Security Assessment of a Distributed, Modbus-based Building Automation System
    Tenkanen, Tuomas
    Hamalainen, Timo
    2017 IEEE INTERNATIONAL CONFERENCE ON COMPUTER AND INFORMATION TECHNOLOGY (CIT), 2017, : 332 - 337
  • [4] Security Challenges in Building Automation and SCADA
    Antonini, Alessio
    Barenghi, Alessandro
    Pelosi, Gerardo
    Zonouz, Saman
    2014 INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY (ICCST), 2014,
  • [5] AUTOMATION OF SYSTEM BUILDING
    TEICHROEW, D
    SAYANI, H
    DATAMATION, 1971, 17 (16): : 25 - +
  • [6] Common approach to functional safety and system security in building automation and control systems
    Novak, Thomas
    Treytl, Albert
    Palensky, Peter
    ETFA 2007: 12TH IEEE INTERNATIONAL CONFERENCE ON EMERGING TECHNOLOGIES AND FACTORY AUTOMATION, VOLS 1-3, 2007, : 1141 - 1148
  • [7] BUILDING AUTOMATION & SECURITY USING CAN AND IoT
    Halemani, Rajeev
    Rajagopal, A.
    PROCEEDINGS OF THE 2015 INTERNATIONAL CONFERENCE ON APPLIED AND THEORETICAL COMPUTING AND COMMUNICATION TECHNOLOGY (ICATCCT), 2015, : 471 - 476
  • [8] TU Vienna Project "Security in Building Automation"
    Kastner, Wolfgang
    ELEKTROTECHNIK UND INFORMATIONSTECHNIK, 2007, 124 (10): : A24 - A24
  • [9] Security Analysis of Open Building Automation Systems
    Granzer, Wolfgang
    Kastner, Wolfgang
    COMPUTER SAFETY, RELIABILITY, AND SECURITY, 2010, 6351 : 303 - 316
  • [10] Security in building automation systems - A first analysis
    Mundt, Thomas
    Wickboldt, Peter
    2016 INTERNATIONAL CONFERENCE ON CYBER SECURITY AND PROTECTION OF DIGITAL SERVICES (CYBER SECURITY), 2016,