A Cuckoo in the Nest: Multi‑Stage, Multi‑Identifier Hijacking in BACnet/SC
Qiguang Zhang, Junzhou Luo, Zhen Ling, Yue Zhang, Kaizheng Liu, Chongqing Lei, Matthew Harper, Xinwen Fu
摘要
To address the well-known security limitations of legacy Building Automation and Control Network (BACnet), BACnet Secure Connect (BACnet/SC) introduces mutually authenticated WebSocket Secure (WSS) channels and mandates PKI-based certificate management. Despite these protections, we identify a fundamental identifier-binding failure in BACnet/SC's security model: X.509 certificate authentication is not cryptographically bound to the logical identifiers used for connection management (UUID) and message forwarding (VMAC). Through a systematic analysis of BACnet/SC connection state machines, we show that this decoupling enables a multi-stage, multi-identifier hijacking attack , in which malicious roles progressively displace a legitimate device's authenticated connection state and persistently intercept its traffic. We term this attack the Cuckoo Attack and validate it across the official BACnet/SC Reference Stack, the open-source BACnet-Stack, and commercial building automation platforms from major vendors, including Siemens, Johnson Controls, Honeywell, and Carrier. We further propose mitigation measures to address this vulnerability. Our findings provide the first systematic characterization of an authentication-identifier decoupling flaw in BACnet/SC, highlight a broader class of identifier-binding risks in stateful secure protocols, and have been presented to and acknowledged by ASHRAE SSPC 135 , the standards committee responsible for BACnet.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper12
- Transcript Collision Attacks: Breaking Authentication in TLS, IKE and SSHKarthikeyan Bhargavan, Gaëtan LeurentNDSS 2016 · 被引用 128 次
- Burglars' IoT Paradise: Understanding and Mitigating Security Risks of General Messaging Protocols on IoT CloudsYan Jia, Luyi Xing, Yuhang Mao, Dongfang Zhao 等S&P 2020 · 被引用 64 次
- Identifier Binding Attacks and Defenses in Software-Defined NetworksSamuel Jero, William Koch, Richard Skowyra, Hamed Okhravi 等USENIX Security 2017 · 被引用 55 次
- Specification Mining for Intrusion Detection in Networked Control SystemsMarco Caselli, Emmanuele Zambon, Johanna Amann, Robin Sommer 等USENIX Security 2016 · 被引用 51 次
- Exposed Infrastructures: Discovery, Attacks and Remediation of Insecure ICS Remote Management DevicesTakayuki Sasaki, Akira Fujita, Carlos Hernandez Gañán, Michel van Eeten 等S&P 2022 · 被引用 41 次
相关 Paper
- BACnet or "BADnet"? On the (In)Security of Implicitly Reserved Fields in BACnetQiguang Zhang, Junzhou Luo, Zhen Ling, Yue Zhang 等NDSS 2026
- Collapse Like A House of Cards: Hacking Building Automation System Through FuzzingYue Zhang, Zhen Ling, Michael Cash, Qiguang Zhang 等CCS 2024 · 被引用 3 次
- Causal Analysis for Software-Defined Networking AttacksBenjamin E. Ujcich, Samuel Jero, Richard Skowyra, Adam Bates 等USENIX Security 2021 · 被引用 26 次
- When Match Fields Do Not Need to Match: Buffered Packets Hijacking in SDNJiahao Cao, Renjie Xie, Kun Sun, Qi Li 等NDSS 2020
- Internet-scale Probing of CPS: Inference, Characterization and Orchestration AnalysisClaude Fachkha, Elias Bou-Harb, Anastasis Keliris, Nasir D. Memon 等NDSS 2017 · 被引用 81 次
