Putting Attacks in Context: A Building Automation Testbed for Impact Assessment from the Victim’s Perspective

Herson Esquivel-Vargas, Marco Caselli, Geert Jan Laanstra, Andreas Peter

Producción científica: Capítulo del libro/informe/acta de congresoContribución a la conferenciarevisión exhaustiva

2 Citas (Scopus)

Resumen

Cybersecurity research relies on the reproducibility and deep understanding of attacks to devise appropriate solutions. Different kinds of testbeds are typically used to systematically execute attacks and evaluate defenses. Testbeds are widely used to demonstrate Building Automation and Control System (BACS) attacks and defenses, considered too risky to be executed on real infrastructures. However, those testbeds implement arbitrary configurations of building services that do not resemble real-world deployments. In this work, we present the first BACS testbed specially designed to assess the impact of cyberattacks from the victim’s perspective. It features general purpose building services such as illumination, ventilation, and temperature control, whose configuration is easily adapted to emulate the requirements of real-world locations. In this way, the context added to our testbed allows us to better understand the impact of BACS attacks through concrete and realistic scenarios. Moreover, by analyzing different configurations of the BACS (i.e., contexts), we found out that identical attacks may have dramatically different impacts. Thus, reinforcing our view on the relevance of adding context to BACS testbeds.

Idioma originalInglés
Título de la publicación alojadaDetection of Intrusions and Malware, and Vulnerability Assessment - 17th International Conference, DIMVA 2020, Proceedings
EditoresClémentine Maurice, Leyla Bilge, Gianluca Stringhini, Nuno Neves
EditorialSpringer
Páginas44-64
Número de páginas21
ISBN (versión impresa)9783030526825
DOI
EstadoPublicada - 2020
Publicado de forma externa
Evento17th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, DIMVA 2020 - Lisbon, Portugal
Duración: 24 jun 202026 jun 2020

Serie de la publicación

NombreLecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics)
Volumen12223 LNCS
ISSN (versión impresa)0302-9743
ISSN (versión digital)1611-3349

Conferencia

Conferencia17th International Conference on Detection of Intrusions and Malware, and Vulnerability Assessment, DIMVA 2020
País/TerritorioPortugal
CiudadLisbon
Período24/06/2026/06/20

Huella

Profundice en los temas de investigación de 'Putting Attacks in Context: A Building Automation Testbed for Impact Assessment from the Victim’s Perspective'. En conjunto forman una huella única.

Citar esto