Leveraging Operational Technology and the Internet of Things to Attack Smart Buildings
Daniel Ricardo dos Santos, Mario Dagrada, Elisa Costante

TL;DR
This paper investigates cybersecurity vulnerabilities in smart building automation systems, demonstrating how IoT and operational technology can be exploited to disrupt operations and introducing malware that persists within BAS networks.
Contribution
It presents the first BAS-specific malware leveraging OT and IoT devices, and analyzes attack vectors and vulnerabilities in modern smart building systems.
Findings
BAS networks are as critical as industrial control systems.
Simple attacks can disrupt BAS operations.
Proof-of-concept malware can persist within BAS networks.
Abstract
In recent years, the buildings where we spend most part of our life are rapidly evolving. They are becoming fully automated environments where energy consumption, access control, heating and many other subsystems are all integrated within a single system commonly referred to as smart building (SB). To support the growing complexity of building operations, building automation systems (BAS) powering SBs are integrating consumer range Internet of Things (IoT) devices such as IP cameras alongside with operational technology (OT) controllers and actuators. However, these changes pose important cybersecurity concerns since the attack surface is larger, attack vectors are increasing and attacks can potentially harm building occupants. In this paper, we analyze the threat landscape of BASs by focusing on subsystems which are strongly affected by the advent of IoT devices such as video…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsSmart Grid Security and Resilience · Blockchain Technology Applications and Security · Advanced Malware Detection Techniques
