Cybersecurity of Building Automation Systems

“Cybersecurity is a hot topic in the building automation systems industry right now."
build a wall

Report on a Private Round Table Discussion

On August 31, 2016, Optigo Networks hosted an online round table to provide for a peer exchange on trends in cybersecurity of Building Automation Systems (BAS). Participants included building operations security officials from a major North American government agency, bank, university, and municipality, as well as two volunteers with BACnet International. “Cybersecurity is a hot topic in the building automation systems industry right now,” said Optigo Networks CEO Pook-Ping Yao, who moderated the forum. “Our round table discussion was very informative and provided some interesting insights that we’d like to share with the larger BAS security community. While respecting the privacy of the participants who wish to remain anonymous, we believe the entire sector can benefit from our exchange and we are pleased to provide the following highlights.”

Changes to the BACnet Protocol

BACnet recently released additions to its standard for advisory public review. BACnet’s Dave Robin and Carl Neilson of the Network Security Working Group, commented on some of the challenges the communications protocol is trying to address. “We’re trying to make it so BACnet vendors can simply flip a switch at both ends and the security aspects are built in as a point of commissioning,” said Robin. “It’s not something you have to learn to navigate through Linux manuals and figure out how to turn on some obscure feature.” Robin also commented on the protocol’s proposal regarding tunneling sites. “You see raw BACnet traffic that is running across the internet unprotected… the users know it and they know it’s bad. This aspect of protecting the tunnel from point A to point B is a deployment scenario I can see being quickly adopted. There’s a strong demand for solutions when information has to go across the public internet.” “The solution that’s currently out for public review rides on IT technologies,” added Neilson. “That was one of our fundamental goals. We’re not security experts, so let’s focus on what we’re good at and let the security aspects be dealt with by the people who are good at that. Our industry has to become more responsive and provides those types of updates.”

“We need a new version of PTP [point-to-point] – a secure route between routers. Something BACnet people can turn on without needing to understand the IT stuff.”

Enforcing security in an insecure world

Written into the BACnet services standard specification is the requirement that users change the default username and password after their product is set up. However, this condition is not enforceable and is beyond the capability of the protocol. Too many times, companies deploy their products with default passwords and never change them. This is exacerbated when organizations hire other companies to install equipment for them. There is currently no mechanism to audit sites or the product implementation to ensure these vendors are doing the work properly. “Customers need to specify all the way down that things need to be properly secured in VLAN or VPNs or whatever. You don’t want someone to walk off the job and have something out on the public internet and not realize they’ve left behind a security risk,” said Robin.

“BACnet products can’t be tested to what the user does with it once they get their hands on it.”

BAS vulnerability

The building automation system industry is used to a long lifetime for its communicating devices. However, once these systems have IP addresses, security becomes an issue. One round table participant identified BAS’ as the next targets for hackers, particularly large runs of devices that are manufactured with the same embedded version of Linux and the same version of SSL stacking. “They need to be patchable. We’re entering a new era where everything we put on the network uses secure technology. Everything that claims to be secure must be upgradable… must be patchable,” he said.

“Just as printers were once the favourite attack vector, building automation systems are going to be the next targets.”

The segmentation solution

Segmentation was advocated for organizations with many distinct sites. The round table’s banking representative’s company, for instance, has thousands of locations across the United States. “While we’d like some of our building technology devices to be able to share some information, we’re looking at segmentation relative to our corporate network and even further segmentation between our corporate security devices and our building technology devices,” he said. Diverse portfolios rely on integrators and VARs. Boiler plate language is needed so integrators take ownership of how the systems are configured. Otherwise, organizations are left with open systems that are vulnerable to anyone with a browser who can discover them. “We’re having to change an industry here,” said one round table participant. “This is not an IT industry where these security components have been built into these systems from the start. We have to address the security risk of the highest profile areas initially. We can’t get to everything and we may even have to disconnect some things and go back to manually operating these systems until we can get controls in place.” Specification control is another challenge. The banking participant’s company has created a comprehensive inventory for every asset that has an IP address. The issue of who does this work arises: should it be your real estate people; the people in the field; maintenance teams? Often these people do not understand the difference between an IP address and a DNS. Yet, IT staff typically do not understand the myriad of building controls and would never think to look at a boiler, for example, to see if it has an IP address. “When we look at this industry and the changes that are occurring, it may be that the building technology or property manager/maintenance manager of the future comes out of networking engineering school,” suggested Neilson.

“If your security team has its eyes on your datacenter where your building technology device is and they notice an alarm or an alert, how do they know whether to send someone with a gun or someone with a wrench?”

National Institute of Science and Technology Cybersecurity Framework

Adding to your BAS inventory

Another participant remarked that everything added to his organization’s network has to be part of its documentation process. The system inventory is altered and additions must be certified to conform to its standards. “It’s important that organizations go through the process of defining the rituals they undertake when they bring a new device online,” he said. “Before a contractor can even put it on our network, they have to coordinate with us and our employees actually document that. It’s not left to the contractor.” This is the perspective that more organizations need to take. Many people running buildings think they have security but do not have people who are technical enough, the time, or the money necessary to actually put in place the types of controls that are needed.

“This is all pretty well established in the NIST guidelines.”

Keep Devices Up-to-date

Having security staff understand that BACnet devices are not general purpose computers is another challenge. Trying to balance updates (which typically do not happen frequently) and implementing these can be problematic. “You’re not just going to reboot it; there’s a repercussion to that,” said one participant. “There’s also the cost, the staffing, and the planning to roll out the updates. Verification is needed that everything is functional. It’s a very complicated issue. Our mindset right now is that it’s just better to build a bigger wall around the garden… wall it off as best as you can and try to use those IT technologies to segregate ourselves from the outside world.” “Our mindset right now is that it’s just better to build a bigger wall.”

Recent Blog Posts

You’re in the design phase of a new building. Contractors and vendors are all coming at you with demands.

The consulting specifying engineer of today is venturing into totally new territory: Division 25.

If you’re tired of going on site to capture BACnet data, look no further than your JACE.

OT Networks Overview

The latest release from Visual BACnet brings huge convenience and time saving for users with JACE controllers.

Recent Projects

Coventry University

COVENTRY UNIVERSITY

Chris Goodman, the Senior BMS Technician at Coventry University, had broadcast storms that were happening more and more frequently. 

Ongoing construction due to Coventry’s campus expansion meant lots of new activity, with technicians installing new devices and making network changes. Already juggling these constant additions and alterations, Goodman and his small team then had to deal with the subsequent broadcast storms. As the broadcast storms became more frequent, Goodman and his team needed a solution.

Find out how Visual BACnet helped Chris solve the broadcast storms and improve Network Health in our free case study!

Data center expansion with OTI and Optigo Connect

DATA CENTER EXPANSION

Stack Infrastructure is a portfolio of hyperscale computing data centers. OTI completed work on Phases I and II, and returned for the Phase III build-out of a 4-megawatt data hall and brand new central plant. The Optigo Connect network put in place in Phases I and II was expanded on this project. The team achieved quick roll-out of a large, multi-service redundant network using the Optigo OneView management interface. Going forward, the facility management team can use OneView to remotely monitor equipment, manage power usage, and meet up-time goals.

Optigo Connect MR Soluciones The Landmark

THE LANDMARK

The Landmark is a sophisticated mixed-use high-rise in Mexico. The owners wanted to integrate all OT systems in the skyscraper, while maintaining separate networks for each application. The Landmark is the fourth joint project between Optigo Networks and MR Soluciones. Together, these companies provide robust services to meet any challenge.

Australian Bureau of Statistics at 45 Benjamin Way with Delta Building Automation

45 BENJAMIN WAY

Delta Building Automation (Australia) had a big job renovating the Headquarters for the Australian Bureau of Statistics (ABS) at 45 Benjamin Way. The building owner wanted to improve the building’s energy use and increase their National Australian Built Environment Rating System (NABERS) score to more than 4.5 stars, out of a possible total of six. Securing the network both internally and externally was a big priority, as well.

Penn State University Optigo Networks Visual BACnet

PENN STATE UNIVERSITY

When Tom Walker looked at Penn State University’s Navy Yard network, he saw huge issues. The system was busy and loud, to the point where the overrun network was bringing down the entire building. Because this was happening on the MS/TP network, pinpointing the problem would mean boots on the ground to segment and test the chain, piece by piece.

Penn State University Optigo Networks Visual BACnet

PENN STATE UNIVERSITY

When Tom Walker first started working at Penn State University four years ago, there were a lot of network issues. Buildings were dropping offline. Broadcast traffic was pushing 90,000 packets per hour. Walker was on the phone almost every single night because devices were down or had to be reset.

 

Torre Manacar Mexico City Optigo Connect

TORRE MANACAR

When MR Soluciones began work on Torre Manacar, they knew they needed a flexible and scalable network infrastructure to support a wide array of integrated systems. Optigo Networks was a natural fit for the massive project, designing a robust network at a competitive cost.

short

SHORT PUMP TOWN CENTER

Short Pump Town Center, an upscale retail center, underwent a complete renovation in 2014. The flexibility of Optigo Networks’ solution meant the retail center’s unknown final design was not a barrier to placing IP surveillance equipment in the field.

BOULEVARD MALL

BOULEVARD MALL

Optigo Networks connected New York-based Boulevard Mall’s security surveillance devices in December 2015, using a Passive Daisy Chain topology.

Visual BACnet tech support team

TECH SUPPORT TEAM

One tech support team at a manufacturer purchased an account with Visual BACnet in April 2017, for technical problems around the world.