Modern Building Automation Systems (BASs), as the brain that enables the smartness of a smart building, often require increased connectivity both among system components as well as with outside entities, such as optimized automation via outsourced cloud analytics and increased building-grid integrations. However, increased connectivity and accessibility come with increased cyber security threats. BASs were historically developed as closed environments with limited cyber-security considerations. As a result, BASs in many buildings are vulnerable to cyber-attacks that may cause adverse consequences, such as occupant discomfort, excessive energy usage, and unexpected equipment downtime. Therefore, there is a strong need to advance the state-of-the-art in cyber-physical security for BASs and provide practical solutions for attack mitigation in buildings. However, an inclusive and systematic review of BAS vulnerabilities, potential cyber-attacks with impact assessment, detection & defense approaches, and cyber-secure resilient control strategies is currently lacking in the literature. This review paper fills the gap by providing a comprehensive up-to-date review of cyber-physical security for BASs at three levels in commercial buildings: management level, automation level, and field level. The general BASs vulnerabilities and protocol-specific vulnerabilities for the four dominant BAS protocols are reviewed, followed by a discussion on four attack targets and seven potential attack scenarios. The impact of cyber-attacks on BASs is summarized as signal corruption, signal delaying, and signal blocking. The typical cyber-attack detection and defense approaches are identified at the three levels. Cyber-secure resilient control strategies for BASs under attack are categorized into passive and active resilient control schemes. Open challenges and future opportunities are finally discussed.
翻译:现代建设自动化系统(BAS)是使智能建筑具有智能智慧的大脑,因此往往需要系统各组成部分之间以及与外部实体加强连接,例如通过外包云层分析进行优化自动化,并增加建筑电网整合;然而,连通性和无障碍化带来了更多的网络安全威胁;而BAS历来是封闭环境开发的,网络安全考虑有限;因此,许多建筑的BAS容易受到网络攻击的伤害,而这种攻击可能造成不良后果,例如,SAS的典型抗灾性不适、能源使用过度以及设备意外故障。 因此,非常需要通过外包云层的网络-物理安全优化,通过外包的云层BAS系统安全化,为建筑物袭击提供实用的实用解决方案;但是,对BAS的脆弱性进行包容性和系统化审查,通过影响评估、检测和防御方法以及网络安全的弹性控制战略,本文弥补了这一差距,为BAS系统提供了全面的最新网络安全审查;BAS在三个层次的网络-物理安全性安全性安全性安全性评估,在B系统安全性评估中,在四个级别上,对B级的信号性安全性风险性评估,在B级的系统管理级别上,对B级的系统安全性规则进行了总体安全级别上进行了总体评估。