Lune

USENIX Security2026顶会

A Cuckoo in the Nest: Multi‑Stage, Multi‑Identifier Hijacking in BACnet/SC

Qiguang Zhang, Junzhou Luo, Zhen Ling, Yue Zhang, Kaizheng Liu, Chongqing Lei, Matthew Harper, Xinwen Fu

2026年份

摘要

To address the well-known security limitations of legacy Building Automation and Control Network (BACnet), BACnet Secure Connect (BACnet/SC) introduces mutually authenticated WebSocket Secure (WSS) channels and mandates PKI-based certificate management. Despite these protections, we identify a fundamental identifier-binding failure in BACnet/SC's security model: X.509 certificate authentication is not cryptographically bound to the logical identifiers used for connection management (UUID) and message forwarding (VMAC). Through a systematic analysis of BACnet/SC connection state machines, we show that this decoupling enables a multi-stage, multi-identifier hijacking attack , in which malicious roles progressively displace a legitimate device's authenticated connection state and persistently intercept its traffic. We term this attack the Cuckoo Attack and validate it across the official BACnet/SC Reference Stack, the open-source BACnet-Stack, and commercial building automation platforms from major vendors, including Siemens, Johnson Controls, Honeywell, and Carrier. We further propose mitigation measures to address this vulnerability. Our findings provide the first systematic characterization of an authentication-identifier decoupling flaw in BACnet/SC, highlight a broader class of identifier-binding risks in stateful secure protocols, and have been presented to and acknowledged by ASHRAE SSPC 135 , the standards committee responsible for BACnet.

问问这篇 Paper

智能体会读完全文。

Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。

可以从这些问题问起

智能体调用

Luneget_paper_fulltext

在 Lune 里问

免费开始,无需绑卡

lune papers fulltext d2cdaf02-3dc4-4f0c-a4ce-325e63b236a1

它引用的顶会 Paper12

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖