On Building Automation System security

被引:0
|
作者
Morales-Gonzalez, Christopher [1 ]
Harper, Matthew [1 ]
Cash, Michael [2 ]
Luo, Lan [3 ]
Ling, Zhen [4 ]
Sun, Qun Z. [2 ]
Fu, Xinwen [1 ,2 ]
机构
[1] Univ Massachusetts Lowell, Dept Comp Sci, Lowell, MA 01854 USA
[2] Univ Cent Florida, Dept Elect & Comp Engn, Orlando, FL 32816 USA
[3] Anhui Univ Technol, Sch Comp Sci & Technol, Maanshan 243032, Peoples R China
[4] Anhui Univ Technol, Sch Comp Sci & Engn, Nanjing 211189, Peoples R China
来源
HIGH-CONFIDENCE COMPUTING | 2024年 / 4卷 / 03期
基金
美国国家科学基金会;
关键词
Building automation system; BAS protocols; Security; Attack; WAVE;
D O I
10.1016/j.hcc.2024.100236
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Building Automation Systems (BASs) are seeing increased usage in modern society due to the plethora of benefits they provide such as automation for climate control, HVAC systems, entry systems, and lighting controls. Many BASs in use are outdated and suffer from numerous vulnerabilities that stem from the design of the underlying BAS protocol. In this paper, we provide a comprehensive, up-to-date survey on BASs and attacks against seven BAS protocols including BACnet, EnOcean, KNX, LonWorks, Modbus, ZigBee, and Z-Wave. Holistic studies of secure BAS protocols are also presented, covering BACnet Secure Connect, KNX Data Secure, KNX/IP Secure, ModBus/TCP Security, EnOcean High Security and Z-Wave Plus. LonWorks and ZigBee do not have security extensions. We point out how these security protocols improve the security of the BAS and what issues remain. A case study is provided which describes a real-world BAS and showcases its vulnerabilities as well as recommendations for improving the security of it. We seek to raise awareness to those in academia and industry as well as highlight open problems within BAS security. (c) 2024 The Author(s). Published by Elsevier B.V. on behalf of Shandong University. This is an open access article under the CC BY-NC-ND license (http://creativecommons.org/licenses/by-nc-nd/4.0/).
引用
收藏
页数:20
相关论文
共 50 条
  • [41] Design and fabrication of security and home automation system
    Kim, Eung Soo
    Kim, Min Sung
    COMPUTATIONAL SCIENCE AND ITS APPLICATIONS - ICCSA 2006, PT 3, 2006, 3982 : 31 - 37
  • [42] Research on Home Automation Security Protection System
    Zhang, Kai
    Wang, Yang-Yang
    Wang, Yi-Bo
    Liu, Jun
    2016 INTERNATIONAL CONFERENCE ON MECHANICAL ENGINEERING AND CONTROL AUTOMATION (ICMECA 2016), 2016, : 398 - 403
  • [43] Home automation and security system using IoT
    Veeranjaneyulu N.
    Srivalli G.
    Bodapati J.D.
    Revue d'Intelligence Artificielle, 2019, 33 (01) : 21 - 24
  • [44] Intelligent System for Automation of Security Audits (SIAAS)
    Seara, J. P.
    Serrao, C.
    EAI ENDORSED TRANSACTIONS ON SCALABLE INFORMATION SYSTEMS, 2024, 11 (01)
  • [45] Implementation of DNP Security in Distribtion Automation System
    Kim, Jin Cheol
    Cho, Jeong Su
    Lee, Seung Won
    2015 IEEE 17TH INTERNATIONAL CONFERENCE ON HIGH PERFORMANCE COMPUTING AND COMMUNICATIONS, 2015 IEEE 7TH INTERNATIONAL SYMPOSIUM ON CYBERSPACE SAFETY AND SECURITY, AND 2015 IEEE 12TH INTERNATIONAL CONFERENCE ON EMBEDDED SOFTWARE AND SYSTEMS (ICESS), 2015, : 1393 - 1398
  • [46] Sensor Based Home Automation and Security System
    Assaf, Mansour H.
    Mootoo, Ronald
    Das, Sunil R.
    Petriu, Emil M.
    Groza, Voicu
    Biswas, Satyendra
    2012 IEEE INTERNATIONAL INSTRUMENTATION AND MEASUREMENT TECHNOLOGY CONFERENCE (I2MTC), 2012, : 722 - 727
  • [47] Building Automation Control System driven by Gestures
    Denkowski, Marcin
    Dmitruk, Krzysztof
    Sadkowski, Lukasz
    IFAC PAPERSONLINE, 2015, 48 (04): : 246 - 251
  • [48] Ideas that work!: Retuning the building automation system
    Parker, Steven
    Strategic Planning for Energy and the Environment, 2015, 34 (04) : 6 - 9
  • [49] Building automation system ethernet switch selection
    Stasiek, Joe
    Thomas, George
    Engineered Systems, 2006, 23 (02): : 4 - 6
  • [50] An online advisory expert system for building automation
    Dement'ev, A
    Kabitzsch, K
    JOURNAL OF COMPUTER AND SYSTEMS SCIENCES INTERNATIONAL, 2004, 43 (05) : 785 - 791