BIoTA Control-Aware Attack Analytics for Building Internet of Things

07/24/2021
by   Nur Imtiazul Haque, et al.
0

Modern building control systems adopt demand control heating, ventilation, and cooling (HVAC) for increased energy efficiency. The integration of the Internet of Things (IoT) in the building control system can determine real-time demand, which has made the buildings smarter, reliable, and efficient. As occupants in a building are the main source of continuous heat and CO_2 generation, estimating the accurate number of people in real-time using building IoT (BIoT) system facilities is essential for optimal energy consumption and occupants' comfort. However, the incorporation of less secured IoT sensor nodes and open communication network in the building control system eventually increases the number of vulnerable points to be compromised. Exploiting these vulnerabilities, attackers can manipulate the controller with false sensor measurements and disrupt the system's consistency. The attackers with the knowledge of overall system topology and control logics can launch attacks without alarming the system. This paper proposes a building internet of things analyzer (BIoTA) framework[https://github.com/imtiazulhaque/research-implementations/tree/main/biota] that assesses the smart building HVAC control system's security using formal attack modeling. We evaluate the proposed attack analyzer's effectiveness on the commercial occupancy dataset (COD) and the KTH live-in lab dataset. To the best of our knowledge, this is the first research attempt to formally model a BIoT-based HVAC control system and perform an attack analysis.

READ FULL TEXT

page 1

page 2

research
12/05/2019

Leveraging Operational Technology and the Internet of Things to Attack Smart Buildings

In recent years, the buildings where we spend most part of our life are ...
research
04/27/2023

SHATTER: Control and Defense-Aware Attack Analytics for Activity-Driven Smart Home Systems

Modern smart home control systems utilize real-time occupancy and activi...
research
07/11/2018

ThingPot: an interactive Internet-of-Things honeypot

The Mirai Distributed Denial-of-Service (DDoS) attack exploited security...
research
11/28/2017

A Novel Approach for Security Situational Awareness in the Internet of Things

Internet of Things (IoT) is characterized by various of heterogeneous de...
research
06/26/2022

Don't Look Up: Ubiquitous Data Exfiltration Pathways in Commercial Spaces

We show that as a side effect of building code requirements, almost all ...
research
07/01/2021

Bi-Level Poisoning Attack Model and Countermeasure for Appliance Consumption Data of Smart Homes

Accurate building energy prediction is useful in various applications st...
research
05/11/2022

Building Automation System Data Integration with BIM: Data Structure and Supporting Case Study

Buildings Automation Systems (BAS) are ubiquitous in contemporary buildi...

Please sign up or login with your details

Forgot password? Click here to reset