Skip to main navigation Skip to search Skip to main content

Automatic deployment of specification-based intrusion detection in the BACnet Protocol

  • Herson Esquivel-Vargas
  • , Marco Caselli
  • , Andreas Peter

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

21 Scopus citations

Abstract

Specification-based intrusion detection (SB-ID) is a suitable approach to monitor Building Automation Systems (BASs) because the correct and non-compromised functioning of the system is well understood. Its main drawback is that the creation of specifications often require human intervention. We present the first fully automated approach to deploy SB-ID at network level. We do so in the domain of BASs, specifically, the BACnet protocol (ISO 16484-5). In this protocol, properly certified devices are demanded to have technical documentation stating their capabilities. We leverage on those documents to create specifications that represent the expected behavior of each device in the network. Automated specification extraction is crucial to effectively apply SB-ID in volatile environments such as BACnet networks, where new devices are often added, removed, or replaced. In our experiments, the proposed algorithm creates specifications with both precision and recall above 99.5%. Finally, we evaluate the capabilities of our detection approach using two months (80GB) of BACnet traffic from a real BAS. Additionally, we use synthetic traffic to demonstrate attack detection in a controlled environment. We show that our approach not only contributes to the practical feasibility of SB-ID in BASs, but also detects stealthy and dangerous attacks.

Original languageEnglish
Title of host publicationCPS-SPC 2017 - Proceedings of the 2017 Workshop on Cyber-Physical Systems Security and PrivaCy, co-located with CCS 2017
PublisherAssociation for Computing Machinery, Inc
Pages25-36
Number of pages12
ISBN (Electronic)9781450353946
DOIs
StatePublished - 3 Nov 2017
Externally publishedYes
Event3rd ACM Workshop on Cyber-Physical Systems Security and PrivaCy, CPS-SPC 2017 - Dallas, United States
Duration: 3 Nov 2017 → …

Publication series

NameCPS-SPC 2017 - Proceedings of the 2017 Workshop on Cyber-Physical Systems Security and PrivaCy, co-located with CCS 2017

Conference

Conference3rd ACM Workshop on Cyber-Physical Systems Security and PrivaCy, CPS-SPC 2017
Country/TerritoryUnited States
CityDallas
Period3/11/17 → …

Keywords

  • Automatic specification extraction
  • BACnet
  • Building automation systems security
  • Specificationbased intrusion detection

Fingerprint

Dive into the research topics of 'Automatic deployment of specification-based intrusion detection in the BACnet Protocol'. Together they form a unique fingerprint.

Cite this