A Taxonomy for the Security Assessment of IP-Based Building Automation Systems: The Case of Thread. Liu, Y., Pang, Z., Dán, G., Lan, D., & Gong, S. IEEE Transactions on Industrial Informatics, 14(9):4113–4123, September, 2018. doi abstract bibtex Motivated by the proliferation of wireless building automation systems (BAS) and increasing security-awareness among BAS operators, in this paper, we propose a taxonomy for the security assessment of BASs. We apply the proposed taxonomy to Thread, an emerging native IP-based protocol for BAS. Our analysis reveals a number of potential weaknesses in the design of Thread. We propose potential solutions for mitigating several identified weaknesses and discuss their efficacy. We also provide suggestions for improvements in future versions of the standard. Overall, our analysis shows that Thread has a well-designed security control for the targeted use case, making it a promising candidate for communication in next generation BASs.
@article{liu_taxonomy_2018,
title = {A {Taxonomy} for the {Security} {Assessment} of {IP}-{Based} {Building} {Automation} {Systems}: {The} {Case} of {Thread}},
volume = {14},
issn = {1551-3203},
shorttitle = {A {Taxonomy} for the {Security} {Assessment} of {IP}-{Based} {Building} {Automation} {Systems}},
doi = {10.1109/TII.2018.2844955},
abstract = {Motivated by the proliferation of wireless building automation systems (BAS) and increasing security-awareness among BAS operators, in this paper, we propose a taxonomy for the security assessment of BASs. We apply the proposed taxonomy to Thread, an emerging native IP-based protocol for BAS. Our analysis reveals a number of potential weaknesses in the design of Thread. We propose potential solutions for mitigating several identified weaknesses and discuss their efficacy. We also provide suggestions for improvements in future versions of the standard. Overall, our analysis shows that Thread has a well-designed security control for the targeted use case, making it a promising candidate for communication in next generation BASs.},
number = {9},
journal = {IEEE Transactions on Industrial Informatics},
author = {Liu, Y. and Pang, Z. and Dán, G. and Lan, D. and Gong, S.},
month = sep,
year = {2018},
keywords = {\#broken, BAS operators, Building automation, Building automation systems (BASs), Communication system security, IP networks, IP-based building automation systems, IP-based protocol, Jab/\#TII, Protocols, Security, Standards, Taxonomy, Thread, ZigBee, building management systems, computer network security, emerging native IP-based protocol, protocols, security analysis, security assessment, security control, security-awareness, wireless building automation systems},
pages = {4113--4123},
}
Downloads: 0
{"_id":"rBFag2EEq3F2L2xjo","bibbaseid":"liu-pang-dn-lan-gong-ataxonomyforthesecurityassessmentofipbasedbuildingautomationsystemsthecaseofthread-2018","author_short":["Liu, Y.","Pang, Z.","Dán, G.","Lan, D.","Gong, S."],"bibdata":{"bibtype":"article","type":"article","title":"A Taxonomy for the Security Assessment of IP-Based Building Automation Systems: The Case of Thread","volume":"14","issn":"1551-3203","shorttitle":"A Taxonomy for the Security Assessment of IP-Based Building Automation Systems","doi":"10.1109/TII.2018.2844955","abstract":"Motivated by the proliferation of wireless building automation systems (BAS) and increasing security-awareness among BAS operators, in this paper, we propose a taxonomy for the security assessment of BASs. We apply the proposed taxonomy to Thread, an emerging native IP-based protocol for BAS. Our analysis reveals a number of potential weaknesses in the design of Thread. We propose potential solutions for mitigating several identified weaknesses and discuss their efficacy. We also provide suggestions for improvements in future versions of the standard. Overall, our analysis shows that Thread has a well-designed security control for the targeted use case, making it a promising candidate for communication in next generation BASs.","number":"9","journal":"IEEE Transactions on Industrial Informatics","author":[{"propositions":[],"lastnames":["Liu"],"firstnames":["Y."],"suffixes":[]},{"propositions":[],"lastnames":["Pang"],"firstnames":["Z."],"suffixes":[]},{"propositions":[],"lastnames":["Dán"],"firstnames":["G."],"suffixes":[]},{"propositions":[],"lastnames":["Lan"],"firstnames":["D."],"suffixes":[]},{"propositions":[],"lastnames":["Gong"],"firstnames":["S."],"suffixes":[]}],"month":"September","year":"2018","keywords":"#broken, BAS operators, Building automation, Building automation systems (BASs), Communication system security, IP networks, IP-based building automation systems, IP-based protocol, Jab/#TII, Protocols, Security, Standards, Taxonomy, Thread, ZigBee, building management systems, computer network security, emerging native IP-based protocol, protocols, security analysis, security assessment, security control, security-awareness, wireless building automation systems","pages":"4113–4123","bibtex":"@article{liu_taxonomy_2018,\n\ttitle = {A {Taxonomy} for the {Security} {Assessment} of {IP}-{Based} {Building} {Automation} {Systems}: {The} {Case} of {Thread}},\n\tvolume = {14},\n\tissn = {1551-3203},\n\tshorttitle = {A {Taxonomy} for the {Security} {Assessment} of {IP}-{Based} {Building} {Automation} {Systems}},\n\tdoi = {10.1109/TII.2018.2844955},\n\tabstract = {Motivated by the proliferation of wireless building automation systems (BAS) and increasing security-awareness among BAS operators, in this paper, we propose a taxonomy for the security assessment of BASs. We apply the proposed taxonomy to Thread, an emerging native IP-based protocol for BAS. Our analysis reveals a number of potential weaknesses in the design of Thread. We propose potential solutions for mitigating several identified weaknesses and discuss their efficacy. We also provide suggestions for improvements in future versions of the standard. Overall, our analysis shows that Thread has a well-designed security control for the targeted use case, making it a promising candidate for communication in next generation BASs.},\n\tnumber = {9},\n\tjournal = {IEEE Transactions on Industrial Informatics},\n\tauthor = {Liu, Y. and Pang, Z. and Dán, G. and Lan, D. and Gong, S.},\n\tmonth = sep,\n\tyear = {2018},\n\tkeywords = {\\#broken, BAS operators, Building automation, Building automation systems (BASs), Communication system security, IP networks, IP-based building automation systems, IP-based protocol, Jab/\\#TII, Protocols, Security, Standards, Taxonomy, Thread, ZigBee, building management systems, computer network security, emerging native IP-based protocol, protocols, security analysis, security assessment, security control, security-awareness, wireless building automation systems},\n\tpages = {4113--4123},\n}\n\n\n\n","author_short":["Liu, Y.","Pang, Z.","Dán, G.","Lan, D.","Gong, S."],"key":"liu_taxonomy_2018","id":"liu_taxonomy_2018","bibbaseid":"liu-pang-dn-lan-gong-ataxonomyforthesecurityassessmentofipbasedbuildingautomationsystemsthecaseofthread-2018","role":"author","urls":{},"keyword":["#broken","BAS operators","Building automation","Building automation systems (BASs)","Communication system security","IP networks","IP-based building automation systems","IP-based protocol","Jab/#TII","Protocols","Security","Standards","Taxonomy","Thread","ZigBee","building management systems","computer network security","emerging native IP-based protocol","protocols","security analysis","security assessment","security control","security-awareness","wireless building automation systems"],"metadata":{"authorlinks":{}},"html":""},"bibtype":"article","biburl":"https://bibbase.org/zotero/bxt101","dataSources":["Wsv2bQ4jPuc7qme8R"],"keywords":["#broken","bas operators","building automation","building automation systems (bass)","communication system security","ip networks","ip-based building automation systems","ip-based protocol","jab/#tii","protocols","security","standards","taxonomy","thread","zigbee","building management systems","computer network security","emerging native ip-based protocol","protocols","security analysis","security assessment","security control","security-awareness","wireless building automation systems"],"search_terms":["taxonomy","security","assessment","based","building","automation","systems","case","thread","liu","pang","dán","lan","gong"],"title":"A Taxonomy for the Security Assessment of IP-Based Building Automation Systems: The Case of Thread","year":2018}