使用机器学习模型增强BACnet/IP网络中的攻击检测能力
Enhancing Attack Detection Capabilities in BACnet/IP Networks Using Machine-Learning Models
AI总结:
针对BACnet/IP网络攻击检测工具和标记数据集少的问题,修改解析器简化特征工程,开发测试平台建模,评估五个无监督异常检测模型,一类支持向量机整体性能最强,高流量攻击检测效果优于隐蔽攻击。
AI中文摘要:
楼宇自动化系统(BAS)使用BACnet/IP等协议管理关键建筑功能,但防御者在检测BACnet特定攻击时工具有限且标记数据集少。本文有三项贡献:修改CISA的Zeek BACnet解析器以生成统一的逐包日志,简化机器学习(ML)管道的特征工程;使用bacpypes3开发模拟BACnet/IP测试平台,对小型商业HVAC系统建模,具备基于物理的设备行为、日程感知控制器逻辑和逐包攻击标记;使用基线流量和六种BACnet攻击类型评估五个无监督异常检测模型。结果表明,一类支持向量机(One-Class SVM)整体性能最强,所有攻击的平均F1分数为0.864,高流量拒绝服务和侦察攻击的F1分数高于0.99。高流量攻击的检测比篡改和虚假数据注入等更隐蔽技术更强,后者得分约77%。
英文摘要:
Building Automation Systems (BAS) manage critical building functions using protocols such as BACnet/IP, yet defenders have limited tooling and few labeled datasets for detecting BACnet-specific attacks. This work addresses these gaps through three contributions. First, CISA's Zeek BACnet parser is modified to produce a unified per-packet log, simplifying feature engineering for machine-learning (ML) pipelines. Second, a simulated BACnet/IP testbed is developed using bacpypes3 to model a small commercial HVAC system with physics-based device behavior, schedule-aware controller logic, and per-packet attack labeling. Third, five unsupervised anomaly detection models are evaluated using baseline traffic and six BACnet attack types, including denial of service, reconnaissance, property tampering, and false data injection. Results show that One-Class SVM achieved the strongest overall performance, with an average F1 score of 0.864 across all attacks and F1 scores above 0.99 for high-volume denial-of-service and reconnaissance attacks. Detection is much stronger for high-volume attacks, such as DoS attacks and reconnaissance, than stealthier techniques such as tampering and false data injection, which scored around 77%.