Account
Please wait, authorizing ...

Don't have an account? Register here today.

×

Analyze electronic security flaws in smart buildings

International. The results of a research project conducted by Memoori Research have revealed more than 100 flaws in building management and access control systems of some of the popular vendors investigated.

In response, U.S. Homeland Security has delivered a "perfect score" of 10.0, implying the most severe risk to the worst vulnerabilities identified by the research. Fixes and patches have been released, but the compelling results have underscored the widespread cybersecurity flaws that still exist in all smart buildings.

Just over a year ago, Gjoko Krstic, a researcher at industrial cybersecurity company Applied Risk, began analyzing building management systems (BMS), building automation systems (BAS) and access control products from four vendors; Optergy, Nortek, Prima Systems and Computrols. Krstic focused its testing on specific products, Computrols CBAS-Web, Optergy Proton/Enterprise, Prima FlexAir and two Nortek Linear eMerge products.

In response, U.S. Homeland Security labeled Optergy's Proton with maximum severity in the industry-standard common vulnerability scoring system. A score of 10.0 is a relatively rare event on this influential measure that got a quick response from the company. Although the notice pointed out several other serious errors, one of which was rated with a score of 9.9.

- Publicidad -

Krstic noted that many of the worst flaws required a "low level" of hacking capability to exploit and could infiltrate the deeper levels from a remote, presumably hidden location. "By exploiting the vulnerability, it is possible to close a building with a single click," he said during a presentation in Amsterdam at the Hack In The Box event in May. Adding, in a recent interview with TechCrunch, that Optergy's worst mistake was "very, very bad" and "easy to exploit."

Optergy seemed to be aware of the problem when Krstic approached him and soon released patches to fix the problem. The company's president, Steve Guzelimian, said the company fixed the problems but would not confirm how many devices were affected, the latest figures suggest the company serves more than 1,800 facilities. "We fixed everything that caught our attention and do our own regular tests," Guzelimian said. The other providers were also notified by Applied Risk, with the exception of Nortek, due to its "notorious reporting process."

Krstic summarized his overall findings at SecurityWeek's ICS Cyber Security Conference in Singapore, noting that an attacker could take advantage of these weaknesses to trigger alarms, lock or unlock doors and gates, control elevator access, intercept video surveillance streams, manipulate HVAC systems and lights, disrupt operations, and steal personal information. Highlighting that the failures reveal that 10 million people and 30,000 doors in 200 facilities are already at the highest levels of cyber attack risk, based only on the products investigated.

The ease of attack shown in Krstic's research means that the attackers could be anyone, from a secret government-funded organization to a bored teenager, making numerous and frequent attacks, and against the biggest and smallest targets.

Krstic's research tells us nothing fundamentally new. No one in the smart building industry is betting their money on a 100% secure smart building management system. Maybe we should never expect to be 100% safe for cyber in our smart buildings. After all, the PC market has managed to thrive despite comparable cyber-vulnerabilities.

However, our buildings are not just cyberspaces, where only our valuable data is at risk. The smart building is a cyber-physical human space where virtual attacks can cause very real and potentially harmful effects on the health and safety of occupants.

The current cybersecurity standard in smart building systems is not enough to justify the risk. That risk grows exponentially as IoT adoption increases. Whether technological, political or educational, a solution must be found to this problem of growing vulnerability to avoid turning buildings, our historic "safe places" into cyber-physical disasters.

- Publicidad -

Source: Memoori Research.

Duván Chaverra Agudelo
Author: Duván Chaverra Agudelo
Jefe Editorial en Latin Press, Inc,.
Comunicador Social y Periodista con experiencia de más de 16 años en medios de comunicación. Apasionado por la tecnología y por esta industria. [email protected]

No thoughts on “Analyze electronic security flaws in smart buildings”

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
Subscribe Here
SUBSCRIBE TO OUR ENGLISH NEWSLETTER.
DO YOU NEED A PRODUCT OR SERVICES QUOTE?
Patrocinado por:
ConsorcioTec Logo
LATEST INTERVIEWS

Entrevista a Jaime Maldonado, Presidente de Air-Con Inc

En entrevista con ACR Latinoamérica, Jaime Maldonado, Presidente de Air-Con Inc, destacó los proyectos que tiene la compañía para este año 2024, sobre todo con la transición de los nuevos refrigerantes. Además, Air-Con estará como expositor en Refriaméricas Miami, y Jaime nos habló sobre sus expectativas con el evento y lo que darán a conocer para todos los visitantes.

Webinar: Armstrong y Energía de Distrito

Por: Rafael Behar, Gerente de Apoyo de Aplicación, Armstrong Fluid Technology Los sistemas de energía de distrito se caracterizan por una o más plantas centrales que producen agua caliente, vapor y/o agua fría, que luego fluye a través de una red de tuberías aisladas para proporcionar agua caliente, calefacción y/o aire acondicionado a los edificios cercanos. Los sistemas de energía de distrito sirven a una variedad de mercados de uso final, incluidos los centros de las ciudades (distritos comerciales centrales), campus universitarios, hospitales e instalaciones de atención médica, aeropuertos, bases militares y complejos industriales. Al combinar cargas para múltiples edificios, los sistemas de energía urbana crean economías de escala que ayudan a reducir los costos de energía y permiten el uso de tecnologías de alta eficiencia. En este seminario web vamos a introducir a Armstrong Fluid Tecnología y su dirección para la energía urbana con enfoques en plantas de calefacción. https://www.acrlatinoamerica.com/20...

Webinar: Mejores Practicas para la Optimización de Sistemas

Importancia de la correcta automatización de plantas de agua helada con el objetivo de pasar al siguiente nivel, que es la optimización de los sistemas para obtener una mayor eficiencia energética y ahorro del costo operativo y de mantenimiento. Por: Camilo Olvera Rodríguez, Gerente de Ventas - México, ARMSTRONG FLUID TECHNOLOGY https://www.acrlatinoamerica.com/20...

Webinar: Enfriando el futuro: Las nuevas tendencias en refrigerantes para supermercados y almacenes

https://www.acrlatinoamerica.com/20... Únete a nosotros en este emocionante Webinar sobre las últimas tendencias en refrigerantes para supermercados y almacenes. Descubre cómo mantener tus productos frescos de manera eficiente, mientras contribuyes a la sostenibilidad y cuidado del medio ambiente. En esta sesión, exploraremos las innovaciones más recientes en refrigerantes ambientalmente preferibles, incluyendo tecnologías avanzadas de enfriamiento. Aprenderás sobre las ventajas de adoptar estas nuevas soluciones, no solo en términos de eficiencia energética, sino también en la reducción de emisiones y el cumplimiento de regulaciones ambientales. Por: Guillermo Brandenstein, Sr Account Manager - Honeywell

Webinar: ¿Es adecuada la forma de vender en las empresas HVAC/R?

En esta presentación se tratarán puntos neurálgicos sobre cómo lograr vender sin necesidad de licitar, teniendo muy presente que el cliente no nos compre porque somos los más baratos sino porque somos su mejor opción. Por: Ing. Rolando Torrado, CEO - Rolando Torrado https://www.acrlatinoamerica.com/20...
Load more...
SITE SPONSORS










LATEST NEWSLETTER
Ultimo Info-Boletin