A critical review of cyber-physical security for building automation systems

被引:15
|
作者
Li, Guowen [1 ]
Ren, Lingyu [2 ]
Fu, Yangyang [1 ]
Yang, Zhiyao [1 ]
Adetola, Veronica [3 ]
Wen, Jin [4 ]
Zhu, Qi [5 ]
Wu, Teresa [6 ,7 ]
Candan, K. Selcuk [6 ,8 ]
O'Neill, Zheng [1 ]
机构
[1] Texas A&M Univ, J Mike Walker 66 Dept Mech Engn, College Stn, TX 77843 USA
[2] Raytheon Technol Res Ctr, East Hartford, CT USA
[3] Pacific Northwest Natl Lab, Richland, WA USA
[4] Drexel Univ, Dept Civil Architectural & Environm Engn, Philadelphia, PA USA
[5] Northwestern Univ, Dept Elect & Comp Engn, Evanston, IL USA
[6] Arizona State Univ, Sch Comp & Augmented Intelligence, Tempe, AZ USA
[7] Arizona State Univ, ASU Mayo Ctr Innovat, Tempe, AZ USA
[8] Arizona State Univ, Ctr Assured & Scalable Data Engn, Tempe, AZ USA
关键词
Cyber -physical security; Cyber attacks; Cyber vulnerabilities; Attack detection and defense; Resilient control; Building automation systems; FAULT-TOLERANT CONTROL; ATTACK DETECTION; RESILIENT CONTROL;
D O I
10.1016/j.arcontrol.2023.02.004
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Modern Building Automation Systems (BASs), as the brain that enable the smartness of a smart building, often require increased connectivity both among system components as well as with outside entities, such as the cloud, to enable low-cost remote management, optimized automation via outsourced cloud analytics, and increased building-grid integrations. As smart buildings move towards open communication technologies, providing access to BASs through the building's intranet, or even remotely through the Internet, has become a common practice. However, increased connectivity and accessibility come with increased cyber security threats. BASs were historically developed as closed environments with limited cyber-security considerations. As a result, BASs in many buildings are vulnerable to cyber-attacks that may cause adverse consequences, such as occupant discomfort, excessive energy usage, and unexpected equipment downtime. Therefore, there is a strong need to advance the state-of-the-art in cyber-physical security for BASs and provide practical solutions for attack mitigation in buildings. However, an inclusive and systematic review of BAS vulnerabilities, potential cyber-attacks with impact assessment, detection & defense approaches, and cyber resilient control strategies is currently lacking in the literature. This review paper fills the gap by providing a comprehensive up-to-date review of cyber-physical security for BASs at three levels in commercial buildings: management level, automation level, and field level. The general BASs vulnerabilities and protocol-specific vulnerabilities for the four dominant BAS protocols (i.e., BACnet, KNX, LonWorks, and Modbus) are reviewed, followed by a discussion on four attack targets and seven potential attack scenarios. The impact of cyber-attacks on BASs is summarized as signal corruption, signal delaying, and signal blocking. The typical cyber-attack detection and defense approaches are identified at the three levels. Cyber resilient control strategies for BASs under attack are categorized into passive and active resilient control schemes. Open challenges and future opportunities are finally discussed.
引用
收藏
页码:237 / 254
页数:18
相关论文
共 50 条
  • [1] Building cyber-physical security
    Ehrlich, Paul, 1600, Business News Publishing Co. (34):
  • [2] Cyber-physical systems security: A systematic review
    Harkat, Houda
    Camarinha-Matos, Luis M.
    Goes, Joao
    Ahmed, Hasmath F. T.
    COMPUTERS & INDUSTRIAL ENGINEERING, 2024, 188
  • [3] A Review of Cyber-Physical Security for Photovoltaic Systems
    Ye, Jin
    Giani, Annarita
    Elasser, Ahmed
    Mazumder, Sudip K.
    Farnell, Chris
    Mantooth, Homer Alan
    Kim, Taesic
    Liu, Jianzhe
    Chen, Bo
    Seo, Gab-Su
    Song, Wenzhan
    Greidanus, Mateo D. Roig
    Sahoo, Subham
    Blaabjerg, Frede
    Zhang, Jinan
    Guo, Lulu
    Ahn, Bohyun
    Shadmand, Mohammad B.
    Gajanur, Nanditha R.
    Abbaszada, Mohammad Ali
    IEEE JOURNAL OF EMERGING AND SELECTED TOPICS IN POWER ELECTRONICS, 2022, 10 (04) : 4879 - 4901
  • [4] Challenges in Cyber-Physical Attack Detection for Building Automation Systems
    Runge, Isabel Madeleine
    Akinci, Burcu
    Berges, Mario
    PROCEEDINGS OF THE 10TH ACM INTERNATIONAL CONFERENCE ON SYSTEMS FOR ENERGY-EFFICIENT BUILDINGS, CITIES, AND TRANSPORTATION, BUILDSYS 2023, 2023, : 236 - 239
  • [5] Cyber-Physical Systems - Security
    Zseby, T.
    ELEKTROTECHNIK UND INFORMATIONSTECHNIK, 2018, 135 (03): : 249 - 249
  • [6] Cyber-Physical Systems – Security
    Tanja Zseby
    e & i Elektrotechnik und Informationstechnik, 2018, 135 (3) : 249 - 249
  • [7] Security in Cyber-Physical Systems
    Dsouza, Joanita
    Elezabeth, Laura
    Mishra, Ved Prakash
    Jain, Rachna
    PROCEEDINGS 2019 AMITY INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE (AICAI), 2019, : 840 - 844
  • [8] Design Automation for Cyber-Physical Systems
    Zhu, Qi
    Sangiovanni-Vincentelli, Alberto
    Hu, Shiyan
    Li, Xin
    PROCEEDINGS OF THE IEEE, 2018, 106 (09) : 1479 - 1483
  • [9] Benchmarks for cyber-physical systems: A modular model library for building automation systems
    Cauchi, Nathalie
    Abate, Alessandro
    IFAC PAPERSONLINE, 2018, 51 (16): : 49 - 54
  • [10] Cyber-Security Incidents: A Review Cases in Cyber-Physical Systems
    Al-Mhiqani, Mohammed Nasser
    Ahmad, Rabiah
    Yassin, Warusia
    Hassan, Aslinda
    Abidin, Zaheera Zainal
    Ali, Nabeel Salih
    Abdulkareem, Karrar Hameed
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2018, 9 (01) : 499 - 508