A Network Intrusion Detection System for Building Automation and Control Systems

被引:4
|
作者
Graveto, Vitor [1 ]
Cruz, Tiago [1 ]
Simoes, Paulo [1 ]
机构
[1] Univ Coimbra, Ctr Informat & Syst, Dept Informat Engn, P-3030290 Coimbra, Portugal
关键词
Home automation; Smart buildings; Security; Building automation; Monitoring; Control systems; Safety; building automation and control systems; BACS; NIDS; smart buildings; security; safety; KNX; ANOMALY DETECTION; CYBER SECURITY;
D O I
10.1109/ACCESS.2023.3238874
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Building Automation and Control Systems (BACS) are traditionally based on specialized communications protocols, such as KNX or BACnet, and dedicated sensing and actuating devices. Despite the increased awareness about the security risks associated with BACS, there is a lack of security tools for protecting this special breed of cyber-physical systems. This is further aggravated by the fact that general-purpose security tools are typically not able to cope with the specific requirements and technologies associated with BACS, making it necessary to devise domain-specific approaches - as shown, for instance, by the KNX Secure initiative led by the KNX Association. Nevertheless, despite the advances brought by KNX Secure and similar initiatives, there is still a considerable gap between the security needs of BACS and the solutions available. In this paper, we address this gap by proposing a Network Intrusion Detection System (NIDS) specifically designed for BACS. This NIDS is protocol-agnostic and can potentially support different BACS protocols and technologies, such as KNX, BACnet, Modbus or mixed ecosystems, without loss of generality. We also present a specific proof-of-concept implementation of this NIDS concept for KNX - one of the more widespread BACS protocols. To this purpose, a real-world KNX deployment was used to showcase and evaluate the proposed approach.
引用
收藏
页码:7968 / 7983
页数:16
相关论文
共 50 条
  • [1] Context aware intrusion detection for building automation systems
    Pan, Zhiwen
    Hariri, Salim
    Pacheco, Jesus
    COMPUTERS & SECURITY, 2019, 85 : 181 - 201
  • [2] Leveraging Semantics for Actionable Intrusion Detection in Building Automation Systems
    Fauri, Davide
    Kapsalakis, Michail
    dos Santos, Daniel Ricardo
    Costante, Elisa
    den Hartog, Jerry
    Etalle, Sandro
    CRITICAL INFORMATION INFRASTRUCTURES SECURITY (CRITIS 2018), 2019, 11260 : 113 - 125
  • [3] Anomaly Based Intrusion Detection for Building Automation and Control Networks
    Pan, Zhiwen
    Hariri, Salim
    Al-Nashif, Youssif
    2014 IEEE/ACS 11TH INTERNATIONAL CONFERENCE ON COMPUTER SYSTEMS AND APPLICATIONS (AICCSA), 2014, : 72 - 77
  • [4] Implementation of Intrusion Detection System for automation devices within Virtual Automation Network
    Kuchta, Radek
    Kadlec, Jaroslav
    Vrba, Radimir
    2009 FOURTH INTERNATIONAL CONFERENCE ON SYSTEMS (ICONS), 2009, : 243 - 246
  • [5] Building intrusion pattern miner for snort network intrusion detection system
    Wuu, LC
    Chen, SF
    37TH ANNUAL 2003 INTERNATIONAL CARNAHAN CONFERENCE ON SECURITY TECHNOLOGY, PROCEEDINGS, 2003, : 477 - 484
  • [6] Building intrusion pattern miner for Snort network intrusion detection system
    Wuu, Lih-Chyau
    Hung, Chi-Hsiang
    Chen, Sout-Fong
    JOURNAL OF SYSTEMS AND SOFTWARE, 2007, 80 (10) : 1699 - 1715
  • [7] Testing Automation for an Intrusion Detection System
    Straub, Jeremy
    2017 IEEE AUTOTESTCON, 2017,
  • [8] A Hierarchical Wireless Network Architecture for Building Automation and Control Systems
    Mozumdar, Mohammad Mostafizur Rahman
    Puggelli, Alberto
    Pinto, Alessandro
    Lavagno, Luciano
    Sangiovanni-Vincentelli, Alberto L.
    PROCEEDINGS OF ICNS 2011: THE SEVENTH INTERNATIONAL CONFERENCE ON NETWORKING AND SERVICES, 2011, : 178 - 183
  • [9] Research in Building Automation System simulation Based on Network Control
    Cui Qingquan
    Ning Jing
    Yin Xunhe
    2014 33RD CHINESE CONTROL CONFERENCE (CCC), 2014, : 5755 - 5759
  • [10] Intrusion and anomaly detection for the next-generation of industrial automation and control systems
    Rosa, Luis
    Cruz, Tiago
    de Freitas, Miguel Borges
    Quiterio, Pedro
    Henriques, Joao
    Caldeira, Filipe
    Monteiro, Edmundo
    Simoes, Paulo
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 119 : 50 - 67