On building automation system security
Christopher Morales-Gonzalez , Matthew Harper , Michael Cash , Lan Luo , Zhen Ling , Qun Z. Sun , Xinwen Fu
High-Confidence Computing ›› 2024, Vol. 4 ›› Issue (3) : 100236
On building automation system security
Building Automation Systems (BASs) are seeing increased usage in modern society due to the plethora of benefits they provide such as automation for climate control, HVAC systems, entry systems, and lighting controls. Many BASs in use are outdated and suffer from numerous vulnerabilities that stem from the design of the underlying BAS protocol. In this paper, we provide a comprehensive, up-to-date survey on BASs and attacks against seven BAS protocols including BACnet, EnOcean, KNX, LonWorks, Modbus, ZigBee, and Z-Wave. Holistic studies of secure BAS protocols are also presented, covering BACnet Secure Connect, KNX Data Secure, KNX/IP Secure, ModBus/TCP Security, EnOcean High Security and Z-Wave Plus. LonWorks and ZigBee do not have security extensions. We point out how these security protocols improve the security of the BAS and what issues remain. A case study is provided which describes a real-world BAS and showcases its vulnerabilities as well as recommendations for improving the security of it. We seek to raise awareness to those in academia and industry as well as highlight open problems within BAS security.
Building automation system / BAS protocols / Security / Attack
| [1] |
|
| [2] |
|
| [3] |
|
| [4] |
|
| [5] |
|
| [6] |
|
| [7] |
|
| [8] |
|
| [9] |
|
| [10] |
|
| [11] |
|
| [12] |
|
| [13] |
|
| [14] |
|
| [15] |
|
| [16] |
|
| [17] |
|
| [18] |
|
| [19] |
|
| [20] |
|
| [21] |
|
| [22] |
|
| [23] |
|
| [24] |
|
| [25] |
|
| [26] |
Siemens, Desigo CC - better. Of course, 2024, https://www.siemens.com/global/en/products/buildings/automation/desigo/building-management/desigo-cc.html. |
| [27] |
ASHRAE Special Publications, ANSI/ASHRAE Standard 135-2020, Rep. Tech., ASHRAE, 2020. |
| [28] |
KNX Standard Specifications, 2.1 ed., KNX, 2013. |
| [29] |
Introduction to the LonWorks System, 1.0 ed., Echelon Corporation, 1999. |
| [30] |
Modbus Application Protocol Specification, Modbus Organization, 2012, v1.1b3. |
| [31] |
|
| [32] |
Z-Wave Device Class Specification, |
| [33] |
EnOcean Sustainable IoT, Radio technology, 2021, https://www.enocean.com/en/technology/radio-technology/. |
| [34] |
|
| [35] |
|
| [36] |
|
| [37] |
|
| [38] |
|
| [39] |
|
| [40] |
|
| [41] |
|
| [42] |
|
| [43] |
|
| [44] |
|
| [45] |
|
| [46] |
|
| [47] |
|
| [48] |
|
| [49] |
|
| [50] |
|
| [51] |
|
| [52] |
|
| [53] |
|
| [54] |
|
| [55] |
|
| [56] |
|
| [57] |
|
| [58] |
|
| [59] |
|
| [60] |
|
| [61] |
|
| [62] |
|
| [63] |
|
| [64] |
|
| [65] |
|
| [66] |
|
| [67] |
|
| [68] |
|
| [69] |
|
| [70] |
|
| [71] |
|
| [72] |
|
| [73] |
|
| [74] |
|
| [75] |
|
| [76] |
|
| [77] |
|
| [78] |
|
| [79] |
|
| [80] |
|
| [81] |
|
| [82] |
|
| [83] |
|
| [84] |
|
| [85] |
|
| [86] |
|
| [87] |
|
| [88] |
|
| [89] |
|
| [90] |
|
| [91] |
|
| [92] |
|
| [93] |
|
| [94] |
|
| [95] |
|
| [96] |
KNX, KNX ets, 2022, https://www.knx.org/knx-en/for-professionals/software/ets-professional/. |
| [97] |
|
| [98] |
|
| [99] |
Application Note 158/13 v02 KNX Data Security, 2.1 ed., KNX, 2013. |
| [100] |
CISA, KNX protocol, 2023, https://www.cisa.gov/news-events/ics-advisories/icsa-23-236-01. |
| [101] |
Application Note 159/13 v04 KNXnet/IP Secure, 2.1 ed., KNX, 2013. |
| [102] |
KNX, KNX IP secure becomes world’s first vendor-independent security standard for building automation as EN ISO 22510, 2020, https://www.knxtoday.com/2020/02/15234/knx%2Dip%2Dsecure%2Dbecomes%2Dworlds%2Dfirst%2Dvendor%2Dindependent%2Dsecurity%2Dstandard%2Dfor%2Dbuilding%2Dautomation%2Das%2Den%2Diso%2D22510.html. |
| [103] |
MODBUS/TCP Security, v21 ed., MODBUS, 2018. |
| [104] |
Security of EnOcean Radio Networks, v2.5 ed., EnOcean Alliance, 2018. |
| [105] |
|
| [106] |
|
| [107] |
Z-Wave Plus v2 Device Type Specification, Z-Wave Alliance, Beaverton, United States, 2021. |
| [108] |
Calimero, Calimero project, 2022, https://github.com/calimero-project. |
/
| 〈 |
|
〉 |