Role inference + anomaly detection = situational awareness in bacnet networks

Davide Fauri, Michail Kapsalakis, Daniel Ricardo dos Santos, Elisa Costante, Jerry den Hartog, Sandro Etalle

Onderzoeksoutput: Hoofdstuk in Boek/Rapport/CongresprocedureConferentiebijdrageAcademicpeer review

1 Downloads (Pure)

Samenvatting

In smart buildings, cyber-physical components (e.g., controllers, sensors, and actuators) communicate with each other using network protocols such as BACnet. Many of these devices are now connected to the Internet, enabling attackers to exploit vulnerabilities on protocols and devices to attack buildings. Situational awareness and intrusion detection are thus critical to provide operators with a clear and dynamic picture of their network, and to allow them to react to threats and attacks. Due to Smart Buildings being relatively dynamic and heterogeneous environments, situational awareness further needs to rapidly adapt to the appearance of new devices, and to provide enough context and information to understand a device’s behavior. In this paper, we propose a novel approach to situational awareness that leverages a combination of learning and knowledge of possible role devices. Specifically, we introduce a role-based situational awareness and intrusion detection system to monitor BACnet building automation networks. The system discovers devices, classifies them according to functional roles and detects deviations from the assigned roles. To validate our approach, we use a simulated dataset generated from a BACnet testbed, as well as a real-world dataset coming from the building network of a Dutch university.

Originele taal-2Engels
TitelDetection of Intrusions and Malware, and Vulnerability Assessment - 16th International Conference, DIMVA 2019, Proceedings
RedacteurenClémentine Maurice, Giorgio Giacinto, Roberto Perdisci, Magnus Almgren
Plaats van productieCham
UitgeverijSpringer
Pagina's461-481
Aantal pagina's21
ISBN van elektronische versie978-3-030-22038-9
ISBN van geprinte versie978-3-030-22037-2
DOI's
StatusGepubliceerd - 6 jun 2019
Evenement16th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, DIMVA 2019 - Gothenburg, Zweden
Duur: 19 jun 201920 jun 2019

Publicatie series

NaamLecture Notes in Computer Science
Volume11543
ISSN van geprinte versie0302-9743
ISSN van elektronische versie1611-3349

Congres

Congres16th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, DIMVA 2019
LandZweden
StadGothenburg
Periode19/06/1920/06/19

    Vingerafdruk

Citeer dit

Fauri, D., Kapsalakis, M., dos Santos, D. R., Costante, E., den Hartog, J., & Etalle, S. (2019). Role inference + anomaly detection = situational awareness in bacnet networks. In C. Maurice, G. Giacinto, R. Perdisci, & M. Almgren (editors), Detection of Intrusions and Malware, and Vulnerability Assessment - 16th International Conference, DIMVA 2019, Proceedings (blz. 461-481). (Lecture Notes in Computer Science; Vol. 11543). Cham: Springer. https://doi.org/10.1007/978-3-030-22038-9_22