Characterizing Building Automation System Attacks and Attackers

Onderzoeksoutput: Hoofdstuk in Boek/Rapport/CongresprocedureConferentiebijdrageAcademicpeer review

2 Citaten (Scopus)
62 Downloads (Pure)

Samenvatting

A building automation system (BAS) is an instance of a cyber-physical-system (CPS) in control of building functionalities like lighting, ventilation, CCTVs, and access control. The amount of “smart” buildings has been growing over the years, introducing new technologies which are now being targeted by attackers. In this work, we present the first collection of publicly disclosed security incidents involving Building Automation Systems (BAS). We then provide a qualitative study of attackers targeting BAS and unveil their main characteristics and differences to traditional CPS attackers. We learn that, generally speaking, BAS attackers show a lower sophistication level and that most BAS attacks target the smart IoT components present in modern buildings. Further, access to the BAS is often not the attacker's final goal but "just" a mean to achieve their actual goal. Lastly, we do not observe any advanced, state-sponsored BAS attacks hinting that these play less of a role in BAS (compared to CPS).
Originele taal-2Engels
TitelProceedings - 7th IEEE European Symposium on Security and Privacy Workshops, Euro S and PW 2022
UitgeverijInstitute of Electrical and Electronics Engineers
Pagina's139-149
Aantal pagina's11
ISBN van elektronische versie978-1-6654-9560-8
ISBN van geprinte versie978-1-6654-9561-5
DOI's
StatusGepubliceerd - jul. 2022
Evenement4th Workshop on Attackers and Cyber-Crime Operations - Genoa, Italië
Duur: 6 jun. 20226 jun. 2022
Congresnummer: 4
https://wacco-workshop.org/past/2022

Workshop

Workshop4th Workshop on Attackers and Cyber-Crime Operations
Verkorte titelWACCO 2022
Land/RegioItalië
StadGenoa
Periode6/06/226/06/22
Internet adres

Vingerafdruk

Duik in de onderzoeksthema's van 'Characterizing Building Automation System Attacks and Attackers'. Samen vormen ze een unieke vingerafdruk.

Citeer dit