Cyber-Physical-Security Framework for Building Energy Management System

K. Paridari, A. Mady, Isidoro S. La Porta, Rohan Chabukswar, Jacobo Blanco, André M. H. Teixeira, H. Sandberg, M. Boubekeur
{"title":"Cyber-Physical-Security Framework for Building Energy Management System","authors":"K. Paridari, A. Mady, Isidoro S. La Porta, Rohan Chabukswar, Jacobo Blanco, André M. H. Teixeira, H. Sandberg, M. Boubekeur","doi":"10.1109/ICCPS.2016.7479072","DOIUrl":null,"url":null,"abstract":"Energy management systems (EMS) are used to control energy usage in buildings and campuses, by employing technologies such as supervisory control and data acquisition (SCADA) and building management systems (BMS), in order to provide reliable energy supply and maximise user comfort while minimising energy usage. Historically, EMS systems were installed when potential security threats were only physical. Nowadays, EMS systems are connected to the building network and as a result directly to the outside world. This extends the attack surface to potential sophisticated cyber-attacks, which adversely impact EMS operation, resulting in service interruption and downstream financial implications. Currently, the security systems that detect attacks operate independently to those which deploy resiliency policies and use very basic methods. We propose a novel EMS cyber-physical-security framework that executes a resilient policy whenever an attack is detected using security analytics. In this framework, both the resilient policy and the security analytics are driven by EMS data, where the physical correlations between the data-points are identified to detect outliers and then the control loop is closed using an estimated value in place of the outlier. The framework has been tested using a reduced order model of a real EMS site.","PeriodicalId":6619,"journal":{"name":"2016 ACM/IEEE 7th International Conference on Cyber-Physical Systems (ICCPS)","volume":"14 1","pages":"1-9"},"PeriodicalIF":0.0000,"publicationDate":"2016-04-11","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"25","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2016 ACM/IEEE 7th International Conference on Cyber-Physical Systems (ICCPS)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCPS.2016.7479072","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 25

Abstract

Energy management systems (EMS) are used to control energy usage in buildings and campuses, by employing technologies such as supervisory control and data acquisition (SCADA) and building management systems (BMS), in order to provide reliable energy supply and maximise user comfort while minimising energy usage. Historically, EMS systems were installed when potential security threats were only physical. Nowadays, EMS systems are connected to the building network and as a result directly to the outside world. This extends the attack surface to potential sophisticated cyber-attacks, which adversely impact EMS operation, resulting in service interruption and downstream financial implications. Currently, the security systems that detect attacks operate independently to those which deploy resiliency policies and use very basic methods. We propose a novel EMS cyber-physical-security framework that executes a resilient policy whenever an attack is detected using security analytics. In this framework, both the resilient policy and the security analytics are driven by EMS data, where the physical correlations between the data-points are identified to detect outliers and then the control loop is closed using an estimated value in place of the outlier. The framework has been tested using a reduced order model of a real EMS site.
建筑能源管理系统的网络物理安全框架
能源管理系统(EMS)用于控制建筑物和校园的能源使用,通过采用监控和数据采集(SCADA)和楼宇管理系统(BMS)等技术,提供可靠的能源供应,在最大限度地减少能源消耗的同时,最大限度地提高用户的舒适度。从历史上看,当潜在的安全威胁仅仅是物理的时候,就会安装EMS系统。如今,EMS系统与建筑网络相连,从而直接与外部世界相连。这将攻击面扩展到潜在的复杂网络攻击,这会对EMS操作产生不利影响,导致服务中断和下游财务影响。目前,检测攻击的安全系统独立于那些部署弹性策略并使用非常基本方法的安全系统。我们提出了一种新的EMS网络物理安全框架,该框架在使用安全分析检测到攻击时执行弹性策略。在此框架中,弹性策略和安全分析都由EMS数据驱动,其中识别数据点之间的物理相关性以检测异常值,然后使用估计值代替异常值关闭控制回路。该框架已使用实际EMS站点的降阶模型进行了测试。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:604180095
Book学术官方微信