Vulnerability Assessment and Orchestration Platform for Building Management Systems

Avatar for Raymond CHAN
Raymond CHAN    
Assistant Professor

Read More 

Avatar for Malcolm LOW
Malcolm LOW    
Associate Professor

Read More 

Avatar for Yi ZHOU
Yi ZHOU    
Associate Professor

Read More 

Avatar for Szu-cheng CHIEN
Szu-cheng CHIEN    
Associate Professor

Read More 

A building management system (BMS) enables the monitoring and control of a building’s infrastructure.

BMSs can be viewed as miniature industrial control systems that are widely deployed and commonly accessible to users. In this context, Firefish Communications is collaborating with SIT to develop a comprehensive checklist to assess the security posture of smart building IoT devices and solutions, as well as to explore ways to integrate these disparate systems into a unified smart decision-making platform.

Impact:
•    Included as a case study in IMDA’s IoT security guide and recognised by IMDA 
•    Principal Investigator invited to Singapore Standard TR-64 Workgroup which provides guidance on how to conduct threat modelling for IoT.

Published papers :
•    R. Chan et al., "Secure IoT Deployment Checklist for Building Management System," 2022 IEEE 8th World Forum on Internet of Things (WF-IoT), Yokohama, Japan, 2022, pp. 1-6, doi: 10.1109/WF-IoT54382.2022.10152169.

•    Chan, R. et al. (2023). MQTT Traffic Collection and Forensic Analysis Framework. In: Goel, S., Gladyshev, P., Nikolay, A., Markowsky, G., Johnson, D. (eds) Digital Forensics and Cyber Crime. ICDF2C 2022. Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering, vol 508. Springer, Cham. https://doi.org/10.1007/978-3-031-36574-4_11

•    Chan, Raymond, et al. "Security-Enhanced Orchestration Platform for Building Management Systems." International Conference on Critical Infrastructure Protection. Cham: Springer Nature Switzerland, 2023.

•    Chan, Ching Bon, et al. "IoT devices deployment challenges and studies in Building Management System." Frontiers in the Internet of Things 2: 1254160.
 

 

A technical flowchart of a security orchestration platform for Building Management Systems. It shows four main modules—Data Monitoring, Mitigation Measures, Platform Self-check, and Building Management Systems—connected via an Orchestration Platform and a BMS operator.