150 likes | 302 Views
Identifying security events in a Building Energy Management System (BEMS) Jeffrey M. Young Dr. Milos Manic University of Idaho, IF. Overview Network/Sensor setup What is Wireshark Example security event. Sensors Various Temperature Occupancy Light CO2 Damper position
E N D
Identifying security events in a Building Energy Management System (BEMS) Jeffrey M. Young Dr. Milos Manic University of Idaho, IF
Overview • Network/Sensor setup • What is Wireshark • Example security event
Sensors • Various Temperature • Occupancy • Light • CO2 • Damper position • Supply Fan Load/Current • Exhaust Fan Load/Current
Network nodes • Router – VxWorks • Hosts – Mix of Windows and Linux • Can2Go controller • Star network topology
Wireshark – What is it? • Network packet analyzer • Capture network packets • Display that packet data • Open source
Wireshark – What it is not • Not an intrusion detection system • No warning when something strange things on your network • Read only mode
Build a profile • Display filters • Most any characteristic of a network packet • Can be color coded for easy recognition • tcp.flags.reset eq 1
Conclusion • How to setup Wireshark and host for packet capture • How to setup and commence a port probe attack • Configure capture filters to highlight packets involved in a port probe