Leveraging semantics for actionable intrusion detection in building automation systems

11Citations
Citations of this article
20Readers
Mendeley users who have this article in their library.
Get full text

Abstract

In smart buildings, physical components (e.g., controllers, sensors, and actuators) are interconnected and communicate with each other using network protocols such as BACnet. Many smart building networks are now connected to the Internet, enabling attackers to exploit vulnerabilities in critical buildings. Network monitoring is crucial to detect such attacks and allow building operators to react accordingly. In this paper, we propose an intrusion detection system for building automation networks that detects known and unknown attacks, as well as anomalous behavior. It does so by leveraging protocol knowledge and specific BACnet semantics: by using this information, the alerts raised by our system are meaningful and actionable. To validate our approach, we use a real-world dataset coming from the building network of a Dutch university, as well as a simulated dataset generated in our lab facilities.

Cite

CITATION STYLE

APA

Fauri, D., Kapsalakis, M., dos Santos, D. R., Costante, E., den Hartog, J., & Etalle, S. (2019). Leveraging semantics for actionable intrusion detection in building automation systems. In Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) (Vol. 11260 LNCS, pp. 113–125). Springer Verlag. https://doi.org/10.1007/978-3-030-05849-4_9

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free