USENIX Security2026Top-tier venue
A Cuckoo in the Nest: Multi‑Stage, Multi‑Identifier Hijacking in BACnet/SC
Qiguang Zhang, Junzhou Luo, Zhen Ling, Yue Zhang, Kaizheng Liu, Chongqing Lei, Matthew Harper, Xinwen Fu
Abstract
To address the well-known security limitations of legacy Building Automation and Control Network (BACnet), BACnet Secure Connect (BACnet/SC) introduces mutually authenticated WebSocket Secure (WSS) channels and mandates PKI-based certificate management. Despite these protections, we identify a fundamental identifier-binding failure in BACnet/SC's security model: X.509 certificate authentication is not cryptographically bound to the logical identifiers used for connection management (UUID) and message forwarding (VMAC). Through a systematic analysis of BACnet/SC connection state machines, we show that this decoupling enables a multi-stage, multi-identifier hijacking attack , in which malicious roles progressively displace a legitimate device's authenticated connection state and persistently intercept its traffic. We term this attack the Cuckoo Attack and validate it across the official BACnet/SC Reference Stack, the open-source BACnet-Stack, and commercial building automation platforms from major vendors, including Siemens, Johnson Controls, Honeywell, and Carrier. We further propose mitigation measures to address this vulnerability. Our findings provide the first systematic characterization of an authentication-identifier decoupling flaw in BACnet/SC, highlight a broader class of identifier-binding risks in stateful secure protocols, and have been presented to and acknowledged by ASHRAE SSPC 135 , the standards committee responsible for BACnet.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext d2cdaf02-3dc4-4f0c-a4ce-325e63b236a1Builds on12
- Transcript Collision Attacks: Breaking Authentication in TLS, IKE and SSHKarthikeyan Bhargavan, Gaëtan LeurentNDSS 2016 · 128 citations
- Burglars' IoT Paradise: Understanding and Mitigating Security Risks of General Messaging Protocols on IoT CloudsYan Jia, Luyi Xing, Yuhang Mao, Dongfang Zhao et al.S&P 2020 · 64 citations
- Identifier Binding Attacks and Defenses in Software-Defined NetworksSamuel Jero, William Koch, Richard Skowyra, Hamed Okhravi et al.USENIX Security 2017 · 55 citations
- Specification Mining for Intrusion Detection in Networked Control SystemsMarco Caselli, Emmanuele Zambon, Johanna Amann, Robin Sommer et al.USENIX Security 2016 · 51 citations
- Exposed Infrastructures: Discovery, Attacks and Remediation of Insecure ICS Remote Management DevicesTakayuki Sasaki, Akira Fujita, Carlos Hernandez Gañán, Michel van Eeten et al.S&P 2022 · 41 citations
Related papers
- BACnet or "BADnet"? On the (In)Security of Implicitly Reserved Fields in BACnetQiguang Zhang, Junzhou Luo, Zhen Ling, Yue Zhang et al.NDSS 2026
- Collapse Like A House of Cards: Hacking Building Automation System Through FuzzingYue Zhang, Zhen Ling, Michael Cash, Qiguang Zhang et al.CCS 2024 · 3 citations
- Causal Analysis for Software-Defined Networking AttacksBenjamin E. Ujcich, Samuel Jero, Richard Skowyra, Adam Bates et al.USENIX Security 2021 · 26 citations
- When Match Fields Do Not Need to Match: Buffered Packets Hijacking in SDNJiahao Cao, Renjie Xie, Kun Sun, Qi Li et al.NDSS 2020
- Internet-scale Probing of CPS: Inference, Characterization and Orchestration AnalysisClaude Fachkha, Elias Bou-Harb, Anastasis Keliris, Nasir D. Memon et al.NDSS 2017 · 81 citations
