As smart buildings move towards open communication technologies, providing access to the Building Automation System (BAS) through the intranet, or even remotely through the Internet, has become a common practice. However, BAS was historically developed as a closed environment and designed with limited cyber-security considerations. Thus, smart buildings are vulnerable to cyber-attacks with the increased accessibility. This study introduces the development and capability of a Hardware-in-the-Loop (HIL) testbed for testing and evaluating the cyber-physical security of typical BASs in smart buildings. The testbed consists of three subsystems: (1) a real-time HIL emulator simulating the behavior of a virtual building as well as the Heating, Ventilation, and Air Conditioning (HVAC) equipment via a dynamic simulation in Modelica; (2) a set of real HVAC controllers monitoring the virtual building operation and providing local control signals to control HVAC equipment in the HIL emulator; and (3) a BAS server along with a web-based service for users to fully access the schedule, setpoints, trends, alarms, and other control functions of the HVAC controllers remotely through the BACnet network. The server generates rule-based setpoints to local HVAC controllers. Based on these three subsystems, the HIL testbed supports attack/fault-free and attack/fault-injection experiments at various levels of the building system. The resulting test data can be used to inform the building community and support the cyber-physical security technology transfer to the building industry.
翻译:随着智能建筑物朝着开放性通讯技术发展,通过局域网甚至互联网远程访问自动化系统(BAS)已经成为一种常见的做法。但是,历史上BAS是作为一个封闭的环境而开发的,并且设计时考虑到的网络安全性有限。因此,随着可访问性的增加,智能建筑物容易受到网络攻击的迫害。这项研究介绍了一个硬件在环测试台(HIL)的开发和能力,用于测试和评估智能建筑物中典型BAS的网络安全性能。测试台包括三个子系统:(1)实时的HIL仿真器通过Modelica中的动态仿真来模拟虚拟建筑以及暖通空调(HVAC)设备的行为;(2)一组实际的HVAC控制器,监视虚拟建筑的运行并为HIL仿真器中的HVAC设备提供本地控制信号;以及(3)一个BAS服务器,以及一个基于网络的服务,供用户通过BACnet网络远程全面访问HVAC控制器的时间表、设定点、趋势、告警和其他控制功能。服务器生成基于规则的设置点到本地HVAC控制器。基于这三个子系统,HIL测试台支持在建筑系统的各个级别进行无攻击/故障和攻击/故障注入实验。所得到的测试数据可以用于向建筑界提供信息,并支持网络安全技术向建筑行业的转移。