A Network Intrusion Detection System for Building Automation and Control Systems

被引:7
作者
Graveto, Vitor [1 ]
Cruz, Tiago [1 ]
Simoes, Paulo [1 ]
机构
[1] Univ Coimbra, Ctr Informat & Syst, Dept Informat Engn, P-3030290 Coimbra, Portugal
关键词
Home automation; Smart buildings; Security; Building automation; Monitoring; Control systems; Safety; building automation and control systems; BACS; NIDS; smart buildings; security; safety; KNX; ANOMALY DETECTION; CYBER SECURITY;
D O I
10.1109/ACCESS.2023.3238874
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Building Automation and Control Systems (BACS) are traditionally based on specialized communications protocols, such as KNX or BACnet, and dedicated sensing and actuating devices. Despite the increased awareness about the security risks associated with BACS, there is a lack of security tools for protecting this special breed of cyber-physical systems. This is further aggravated by the fact that general-purpose security tools are typically not able to cope with the specific requirements and technologies associated with BACS, making it necessary to devise domain-specific approaches - as shown, for instance, by the KNX Secure initiative led by the KNX Association. Nevertheless, despite the advances brought by KNX Secure and similar initiatives, there is still a considerable gap between the security needs of BACS and the solutions available. In this paper, we address this gap by proposing a Network Intrusion Detection System (NIDS) specifically designed for BACS. This NIDS is protocol-agnostic and can potentially support different BACS protocols and technologies, such as KNX, BACnet, Modbus or mixed ecosystems, without loss of generality. We also present a specific proof-of-concept implementation of this NIDS concept for KNX - one of the more widespread BACS protocols. To this purpose, a real-world KNX deployment was used to showcase and evaluate the proposed approach.
引用
收藏
页码:7968 / 7983
页数:16
相关论文
共 50 条
  • [21] Hybrid Control Network Intrusion Detection Systems for Automated Power Distribution Systems
    Parvania, Masood
    Koutsandria, Georgia
    Muthukumar, Vishak
    Peisert, Sean
    McParland, Chuck
    Scaglione, Anna
    [J]. 2014 44TH ANNUAL IEEE/IFIP INTERNATIONAL CONFERENCE ON DEPENDABLE SYSTEMS AND NETWORKS (DSN), 2014, : 774 - 779
  • [22] IBACSA: An interactive tool for building automation and control systems auditing and smartness evaluation
    Engelsgaard, Sebastian
    Alexandersen, Emil Kjoller
    Dallaire, Jonathan
    Jradi, Muhyiddine
    [J]. BUILDING AND ENVIRONMENT, 2020, 184
  • [23] IIDS: Intelligent Intrusion Detection System for Sustainable Development in Autonomous Vehicles
    Anbalagan, Sudha
    Raja, Gunasekaran
    Gurumoorthy, Sugeerthi
    Suresh, R. Deepak
    Dev, Kapal
    [J]. IEEE TRANSACTIONS ON INTELLIGENT TRANSPORTATION SYSTEMS, 2023, 24 (12) : 15866 - 15875
  • [24] Wireless Sensor Network Based Smart Grid Communications: Cyber Attacks, Intrusion Detection System and Topology Control
    Chhaya, Lipi
    Sharma, Paawan
    Bhagwatikar, Govind
    Kumar, Adesh
    [J]. ELECTRONICS, 2017, 6 (01)
  • [25] Design on Test Method of Network-based Intrusion Detection System
    Shen, Liang
    Yang, Yuanyuan
    Wang, Zhijia
    Zhang, Xiaoxiao
    Gu, Jian
    [J]. 2012 INTERNATIONAL CONFERENCE ON CONTROL ENGINEERING AND COMMUNICATION TECHNOLOGY (ICCECT 2012), 2012, : 661 - 664
  • [26] Adversarial machine learning in Network Intrusion Detection Systems
    Alhajjar, Elie
    Maxwell, Paul
    Bastian, Nathaniel
    [J]. EXPERT SYSTEMS WITH APPLICATIONS, 2021, 186
  • [27] Neuromorphic Computing Applications for Network Intrusion Detection Systems
    Garcia, Raymond C.
    Pino, Robinson E.
    [J]. MACHINE INTELLIGENCE AND BIO-INSPIRED COMPUTATION: THEORY AND APPLICATIONS VIII, 2014, 9119
  • [28] A comparison of Intrusion Detection Systems
    Biermann, E
    Cloete, E
    Venter, LM
    [J]. COMPUTERS & SECURITY, 2001, 20 (08) : 676 - 683
  • [29] Physical Intrusion Detection for Industrial Control System
    Liu, Pengfei
    Liu, Ting
    [J]. 2018 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2018,
  • [30] NICE: Network Intrusion Detection and Countermeasure Selection in Virtual Network Systems
    Chung, Chun-Jen
    Khatkar, Pankaj
    Xing, Tianyi
    Lee, Jeongkeun
    Huang, Dijiang
    [J]. IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2013, 10 (04) : 198 - 211