Qun Zhou 0002

dblp:12/5488-2 · also Qun Zhou Sun · DBLP profile ↗
← Back
6ranked-venue papers
0as first author
4since 2021 · last 2024
0000-0002-8668-8891ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Artificial intelligence and machine learning · 1Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2024 Collapse Like A House of Cards: Hacking Building Automation System Through Fuzzing
abstract
Building Automation Systems (BAS) play a pivotal role in modern smart buildings, integrating sensors, controllers, and software to manage crucial functions such as HVAC, lighting, and more. The global smart building market is on the rise, underscoring the importance of securing BAS networks. This paper introduces the Building Automation System Evaluator (BASE), a specialized fuzzer designed to assess the security of BAS networks. BAS networks typically involve a BAS client communicating with a BAS server through BAS protocols (e.g., BACnet, KNX), each presenting unique challenges in BAS network fuzzing. These challenges encompass complex packet structures and sequencing in BAS protocols, closed-source clients with indeterminable code coverage, and unobservable server status with limited throughput. BASE automatically identifies protocol structures, dynamically instruments clients for code coverage analysis, and monitors responses for new coverage areas. Collected timestamps are used to estimate the input scan intervals of servers, optimizing throughput. We evaluated BASE on various BAS servers and clients, uncovering 13 new vulnerabilities. Furthermore, we present three attack case studies, highlighting the real-world security implications of these vulnerabilities in BAS systems, such as delayed fire detection, loss of climate control, and security breaches. We reported our findings to the respective vendors, who acknowledged the implications, and some have subsequently patched their systems based on our reports.
Yue Zhang 0025, Zhen Ling 0001, Michael Cash, Qiguang Zhang, Christopher Morales, Qun Zhou 0002, Xinwen Fu
CCS6
2024 On building automation system security
abstract
Building Automation Systems (BASs) are seeing increased usage in modern society due to the plethora of benefits they provide such as automation for climate control, HVAC systems, entry systems, and lighting controls. Many BASs in use are outdated and suffer from numerous vulnerabilities that stem from the design of the underlying BAS protocol. In this paper, we provide a comprehensive, up-to-date survey on BASs and attacks against seven BAS protocols including BACnet, EnOcean, KNX, LonWorks, Modbus, ZigBee, and Z-Wave. Holistic studies of secure BAS protocols are also presented, covering BACnet Secure Connect, KNX Data Secure, KNX/IP Secure, ModBus/TCP Security, EnOcean High Security and Z-Wave Plus. LonWorks and ZigBee do not have security extensions. We point out how these security protocols improve the security of the BAS and what issues remain. A case study is provided which describes a real-world BAS and showcases its vulnerabilities as well as recommendations for improving the security of it. We seek to raise awareness to those in academia and industry as well as highlight open problems within BAS security.
Christopher Morales, Matthew Harper, Michael Cash, Zhen Ling 0001, Qun Zhou 0002, Xinwen Fu
High Confid. Comput.6
2024 Imperceptible Attacks on Fault Detection and Diagnosis Systems in Smart Buildings
abstract
Automated fault detection and diagnosis systems are critical to safe and efficient operation of smart buildings. A significant amount of building data can be collected and analyzed to detect building component failures. Attacks against such data that are contaminated with small additive disturbances (i.e., adversarial perturbation attacks) could dreadfully impact the performance of such systems while maintaining a high level of imperceptibility. The vulnerability studies of such data attacks is lacking. Specifically, most existing detection and classification models have flat structures, regarded as single-stage classifiers (SSCs), are prone to adversarial data perturbation attacks. In this article, we present a coarse-to-fine hierarchical fault detection and multilevel diagnosis (HFDD) model, and formulate a mathematical program to derive targeted attacks on the model with respect to a prespecified target diagnosis level. Two algorithms are developed based on convex relaxations of the formulated program for nontargeted attacks. An alternating direction method of multipliers-based solver is developed for the convex programs. Extensive experiments are conducted using two real-world datasets of measurements from air handling units and chillers, demonstrating the feasibility of the proposed attacks with regard to misclassification rate and imperceptibility of the attack. We also show that the HFDD is more robust to disturbances than SSC-based fault detection and multilevel diagnosis systems.
Ismail Alkhouri, Akram S. Awad, Qun Zhou 0002, George Atia
IEEE Trans. Ind. Informatics3
2021 On Automating BACnet Device Discovery and Property Identification
abstract
BACnet is the most popular inter-communication protocol in building automation systems (BAS) and has been deployed in a large scale. It is critical to scan and perform risk analysis of a BAS. Existing work identifies BACnet devices in a manual way and does not further discover their properties. In this paper, we design and implement an automatic tool to identify a BACnet device at a given IP and enumerate both standard and vendor-defined BACnet objects and properties. We applied our tool to a testbed real-world BAS system on a university campus and successfully validated the tool’s effectiveness. Our tool is the first of its kind for risk assessment of the BAS, e.g., automatically scanning open smart buildings on the Internet. The video at https://youtu.be/YUfO8GQILxQ demonstrates that our toolkit may be used to remotely move a damper controlling a building’s Heating, ventilation, and air conditioning (HVAC) system from the Internet and justifies the importance of using our tool for penetration testing of a BAS.
Michael Cash, Shan Wang 0008, Bryan Pearson, Qun Zhou 0002, Xinwen Fu
ICC4
2020 A Hybrid-Learning Algorithm for Online Dynamic State Estimation in Multimachine Power Systems
abstract
With the increasing penetration of distributed generators in the smart grids, having knowledge of rapid real-time electromechanical dynamic states has become crucial to system stability control. Conventional Supervisory Control and Data Acquisition (SCADA)-based dynamic state estimation (DSE) techniques are limited by the slow sampling rates, while the emerging phasor measurement units (PMUs) technology enables rapid real-time measurements at network nodes. Using generator bus terminal voltages, we propose a hybrid-learning DSE (HL-DSE) algorithm to estimate the synchronous machine rotor angle and speed in real time. The HL-DSE takes the power system model into account and trains neuroestimators with real-time data in an online manner. Compared with traditional DSE methods, the HL-DSE overcomes limitations by using a data-driven approach in conjunction with the physical power system model. The time efficiency, accuracy, convergence, and robustness of the proposed algorithm are tested under noises and fault conditions in both small- and large-scale test systems. Simulation results show that the proposed HL-DSE is much more computationally efficient than widely used Kalman filter (KF)-based methods while maintaining comparable accuracy and robustness. In particular, HL-DSE is over 100 times faster than square-root unscented KF (SR-UKF) and 80 times faster than extended KF (EKF). The advantages and challenges of the HL-DSE are also discussed.
Guanyu Tian, Qun Zhou 0002, Rahul Birari, Junjian Qi, Zhihua Qu
IEEE Trans. Neural Networks Learn. Syst.2
2017 Two-Stage Adaptive Restoration Decision Support System for a Self-Healing Power Grid
abstract
Power outages cost American industries and businesses billions of dollars and jeopardize the lives of hospital patients. The losses can be greatly reduced with a fast, reliable, and flexible self-healing tool. This paper is aimed to tackle the challenging task of developing an adaptive restoration decision support system (RDSS). The proposed RDSS determines restoration actions both in planning and real-time phases and adapts to constantly changing system conditions. The comprehensive formulation encompasses practical constraints including ac power flow, dynamic reserve, and load modeling. The combinatorial problem is decomposed into a two-stage formulation solved by an integer L-shaped algorithm. The two stages are then executed online in the RDSS framework employing a sliding window method. The IEEE 39-bus system has been studied under normal and contingency conditions to demonstrate the effectiveness and efficiency of the proposed online RDSS.
Amir Golshani, Wei Sun 0024, Qun Zhou 0002, Qipeng Phil Zheng, Jianzhong Tong
IEEE Trans. Ind. Informatics3