Samenvatting
A building automation system (BAS) is an instance of a cyber-physical-system (CPS) in control of building functionalities like lighting, ventilation, CCTVs, and access control. The amount of “smart” buildings has been growing over the years, introducing new technologies which are now being targeted by attackers. In this work, we present the first collection of publicly disclosed security incidents involving Building Automation Systems (BAS). We then provide a qualitative study of attackers targeting BAS and unveil their main characteristics and differences to traditional CPS attackers. We learn that, generally speaking, BAS attackers show a lower sophistication level and that most BAS attacks target the smart IoT components present in modern buildings. Further, access to the BAS is often not the attacker's final goal but "just" a mean to achieve their actual goal. Lastly, we do not observe any advanced, state-sponsored BAS attacks hinting that these play less of a role in BAS (compared to CPS).
Originele taal-2 | Engels |
---|---|
Titel | Proceedings - 7th IEEE European Symposium on Security and Privacy Workshops, Euro S and PW 2022 |
Uitgeverij | Institute of Electrical and Electronics Engineers |
Pagina's | 139-149 |
Aantal pagina's | 11 |
ISBN van elektronische versie | 978-1-6654-9560-8 |
ISBN van geprinte versie | 978-1-6654-9561-5 |
DOI's | |
Status | Gepubliceerd - jul. 2022 |
Evenement | 4th Workshop on Attackers and Cyber-Crime Operations - Genoa, Italië Duur: 6 jun. 2022 → 6 jun. 2022 Congresnummer: 4 https://wacco-workshop.org/past/2022 |
Workshop
Workshop | 4th Workshop on Attackers and Cyber-Crime Operations |
---|---|
Verkorte titel | WACCO 2022 |
Land/Regio | Italië |
Stad | Genoa |
Periode | 6/06/22 → 6/06/22 |
Internet adres |
Vingerafdruk
Duik in de onderzoeksthema's van 'Characterizing Building Automation System Attacks and Attackers'. Samen vormen ze een unieke vingerafdruk.Datasets
-
BAS Attack Database and Attacker Characterization
Tommasini, M. (Ontwerper) & Rosso, M. (Ontwerper), Eindhoven University of Technology, 11 jul. 2022
DOI: 10.4121/19617243, https://gitlab.tue.nl/sec-lab/bas-security/basattacks
Dataset
-
Data supplementary to the paper: "Characterizing Building Automation System Attacks and Attackers"
Tommasini, M. (Ontwerper) & Rosso, M. (Ontwerper), 4TU.Centre for Research Data, 11 jul. 2022
DOI: 10.4121/19617243.v1
Dataset