{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/26096"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/26096","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Improving the security in interconnecting building automation systems to outside networks","abstract":"As control systems are becoming more complex and capable with much functionality, it requires more efforts not only to maintain correct operations but also to protect them from various threats. Security of the control network which connects entities in the system and serves as a path for information transfer between them is a major cause of concern. Operators of the control systems have taken a conservative way to provide a protection to the network where it is simply isolated from other systems and networks that could introduce access channels. Even though the isolation provides a great protection, it limits management efficiency and expandability of the system. Solving the problem of providing interconnectivity as well as sufficient protection to the control network is not trivial. Existing work proposed a solution where they applied a multi-tier web server system to the control system in the effort to provide better connectivity and introduced a concept of redundant authentication to mitigate risks to the system. In this architecture, a front end system that accepts requests from users is required to provide a non-repudiable credential of the requesting user when it passes the request to a back end proxy that has access privilege on the control system. This limits malicious actions that could be performed by the compromised front end system. It, however, forces every recently authenticated user to share the vulnerability in the case of the compromised front end system due to a requirement that clients should remain unmodified. In this thesis, we suggest a new solution with a client program to overcome the above limitation and provide a better protection. Installation of the client program is required in order to access the control system from the outside network. With this architecture, users who have chosen to opt out by not installing the client program are safe from the risk introduced by other users who have chosen to install the program and use the service. Non-repudiable credentials are still required with every request to the control system hence containing the possible actions of the compromised front end system on the control system. We validate our strategy on Building Automation System (BAS) testbed with a practical application which allows users to unlock doors of the building.","abstract_html":"As control systems are becoming more complex and capable with much functionality, it requires more efforts not only to maintain correct operations but also to protect them from various threats. Security of the control network which connects entities in the system and serves as a path for information transfer between them is a major cause of concern. Operators of the control systems have taken a conservative way to provide a protection to the network where it is simply isolated from other systems and networks that could introduce access channels. Even though the isolation provides a great protection, it limits management efficiency and expandability of the system. Solving the problem of providing interconnectivity as well as sufficient protection to the control network is not trivial. Existing work proposed a solution where they applied a multi-tier web server system to the control system in the effort to provide better connectivity and introduced a concept of redundant authentication to mitigate risks to the system. In this architecture, a front end system that accepts requests from users is required to provide a non-repudiable credential of the requesting user when it passes the request to a back end proxy that has access privilege on the control system. This limits malicious actions that could be performed by the compromised front end system. It, however, forces every recently authenticated user to share the vulnerability in the case of the compromised front end system due to a requirement that clients should remain unmodified. In this thesis, we suggest a new solution with a client program to overcome the above limitation and provide a better protection. Installation of the client program is required in order to access the control system from the outside network. With this architecture, users who have chosen to opt out by not installing the client program are safe from the risk introduced by other users who have chosen to install the program and use the service. Non-repudiable credentials are still required with every request to the control system hence containing the possible actions of the compromised front end system on the control system. We validate our strategy on Building Automation System (BAS) testbed with a practical application which allows users to unlock doors of the building.","abstract_has_math":false,"creators":["Jung, Hee Dong"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"M.S.","degree_level":"Thesis","degree_discipline":"Computer Science","degree_department":null,"school":null,"contributors":["Gunter, Carl A."],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2011,"date_issued":"2011-08-25T22:12:47Z","date_published":"2011-08-25T22:12:47Z","updated_at":"2026-07-22T22:25:26Z","subjects":["Building Automation Systems (BAS)","Security","Networks","Authentication"],"languages":["en"],"rights":["Copyright 2011 Hee Dong Jung"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/26096","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Gunter, Carl A."]},{"key":"dc:creator","label":"Author","values":["Jung, Hee Dong"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2011-08-25T22:12:47Z","2011-08"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Computer Science"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Thesis"]},{"key":"thesis:degree_name","label":"Degree Name","values":["M.S."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Building Automation Systems (BAS)","Security","Networks","Authentication"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2011 Hee Dong Jung"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/26096"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["As control systems are becoming more complex and capable with much functionality, it requires more efforts not only to maintain correct operations but also to protect them from various threats. Security of the control network which connects entities in the system and serves as a path for information transfer between them is a major cause of concern. Operators of the control systems have taken a conservative way to provide a protection to the network where it is simply isolated from other systems and networks that could introduce access channels. Even though the isolation provides a great protection, it limits management efficiency and expandability of the system. Solving the problem of providing interconnectivity as well as sufficient protection to the control network is not trivial. Existing work proposed a solution where they applied a multi-tier web server system to the control system in the effort to provide better connectivity and introduced a concept of redundant authentication to mitigate risks to the system. In this architecture, a front end system that accepts requests from users is required to provide a non-repudiable credential of the requesting user when it passes the request to a back end proxy that has access privilege on the control system. This limits malicious actions that could be performed by the compromised front end system. It, however, forces every recently authenticated user to share the vulnerability in the case of the compromised front end system due to a requirement that clients should remain unmodified. In this thesis, we suggest a new solution with a client program to overcome the above limitation and provide a better protection. Installation of the client program is required in order to access the control system from the outside network. With this architecture, users who have chosen to opt out by not installing the client program are safe from the risk introduced by other users who have chosen to install the program and use the service. Non-repudiable credentials are still required with every request to the control system hence containing the possible actions of the compromised front end system on the control system. We validate our strategy on Building Automation System (BAS) testbed with a practical application which allows users to unlock doors of the building.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2011-07-20T15:23:33Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 9 relatedworks.tex: 14419 bytes, checksum: ae0a031c82712e2df126b6f1967a5379 (MD5) introduction.tex: 12247 bytes, checksum: f7e1717b55fc00a002452531113dd72e (MD5) implementation.tex: 13934 bytes, checksum: 4ec2ed4952e83584bdaf061ae208d5c5 (MD5) design.tex: 8752 bytes, checksum: 6da091272b1d1b763d4fe929ed20af27 (MD5) conclusion.tex: 1991 bytes, checksum: 1fbc90ec38af0745bec71fcfe168be8a (MD5) app.tex: 8125 bytes, checksum: b7eb67c9425266d2391f5aa74b787991 (MD5) analysis.tex: 7679 bytes, checksum: 92bb728086bd4859e3d1bb78c4cc2c4b (MD5) Thesis.tex: 4523 bytes, checksum: 434389ea6fc5346ea7da5190db0bd4d5 (MD5) Jung_Hee Dong.pdf: 14509763 bytes, checksum: 737bd16d7e1d371597435545a7435d10 (MD5)","Made available in DSpace on 2011-08-25T22:12:47Z (GMT). No. of bitstreams: 11 Jung_HeeDong.pdf: 14509763 bytes, checksum: 737bd16d7e1d371597435545a7435d10 (MD5) Thesis.tex: 4523 bytes, checksum: 434389ea6fc5346ea7da5190db0bd4d5 (MD5) analysis.tex: 7679 bytes, checksum: 92bb728086bd4859e3d1bb78c4cc2c4b (MD5) app.tex: 8125 bytes, checksum: b7eb67c9425266d2391f5aa74b787991 (MD5) conclusion.tex: 1991 bytes, checksum: 1fbc90ec38af0745bec71fcfe168be8a (MD5) design.tex: 8752 bytes, checksum: 6da091272b1d1b763d4fe929ed20af27 (MD5) implementation.tex: 13934 bytes, checksum: 4ec2ed4952e83584bdaf061ae208d5c5 (MD5) introduction.tex: 12247 bytes, checksum: f7e1717b55fc00a002452531113dd72e (MD5) relatedworks.tex: 14419 bytes, checksum: ae0a031c82712e2df126b6f1967a5379 (MD5) license.txt: 4056 bytes, checksum: fe65cf308f82ac2ad418428ecabc2334 (MD5) 1_license.txt: 4056 bytes, checksum: 830b5d67f2e37a8c2d1be775ff8b523f (MD5)"]},{"key":"dc:title","label":"Title","values":["Improving the security in interconnecting building automation systems to outside networks"]}]}],"canonical_facts":{"dc:contributor":["Gunter, Carl A."],"dc:creator":["Jung, Hee Dong"],"dc:date":["2011-08-25T22:12:47Z","2011-08"],"dc:description":["As control systems are becoming more complex and capable with much functionality, it requires more efforts not only to maintain correct operations but also to protect them from various threats. Security of the control network which connects entities in the system and serves as a path for information transfer between them is a major cause of concern. Operators of the control systems have taken a conservative way to provide a protection to the network where it is simply isolated from other systems and networks that could introduce access channels. Even though the isolation provides a great protection, it limits management efficiency and expandability of the system. Solving the problem of providing interconnectivity as well as sufficient protection to the control network is not trivial. Existing work proposed a solution where they applied a multi-tier web server system to the control system in the effort to provide better connectivity and introduced a concept of redundant authentication to mitigate risks to the system. In this architecture, a front end system that accepts requests from users is required to provide a non-repudiable credential of the requesting user when it passes the request to a back end proxy that has access privilege on the control system. This limits malicious actions that could be performed by the compromised front end system. It, however, forces every recently authenticated user to share the vulnerability in the case of the compromised front end system due to a requirement that clients should remain unmodified. In this thesis, we suggest a new solution with a client program to overcome the above limitation and provide a better protection. Installation of the client program is required in order to access the control system from the outside network. With this architecture, users who have chosen to opt out by not installing the client program are safe from the risk introduced by other users who have chosen to install the program and use the service. Non-repudiable credentials are still required with every request to the control system hence containing the possible actions of the compromised front end system on the control system. We validate our strategy on Building Automation System (BAS) testbed with a practical application which allows users to unlock doors of the building.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2011-07-20T15:23:33Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 9 relatedworks.tex: 14419 bytes, checksum: ae0a031c82712e2df126b6f1967a5379 (MD5) introduction.tex: 12247 bytes, checksum: f7e1717b55fc00a002452531113dd72e (MD5) implementation.tex: 13934 bytes, checksum: 4ec2ed4952e83584bdaf061ae208d5c5 (MD5) design.tex: 8752 bytes, checksum: 6da091272b1d1b763d4fe929ed20af27 (MD5) conclusion.tex: 1991 bytes, checksum: 1fbc90ec38af0745bec71fcfe168be8a (MD5) app.tex: 8125 bytes, checksum: b7eb67c9425266d2391f5aa74b787991 (MD5) analysis.tex: 7679 bytes, checksum: 92bb728086bd4859e3d1bb78c4cc2c4b (MD5) Thesis.tex: 4523 bytes, checksum: 434389ea6fc5346ea7da5190db0bd4d5 (MD5) Jung_Hee Dong.pdf: 14509763 bytes, checksum: 737bd16d7e1d371597435545a7435d10 (MD5)","Made available in DSpace on 2011-08-25T22:12:47Z (GMT). No. of bitstreams: 11 Jung_HeeDong.pdf: 14509763 bytes, checksum: 737bd16d7e1d371597435545a7435d10 (MD5) Thesis.tex: 4523 bytes, checksum: 434389ea6fc5346ea7da5190db0bd4d5 (MD5) analysis.tex: 7679 bytes, checksum: 92bb728086bd4859e3d1bb78c4cc2c4b (MD5) app.tex: 8125 bytes, checksum: b7eb67c9425266d2391f5aa74b787991 (MD5) conclusion.tex: 1991 bytes, checksum: 1fbc90ec38af0745bec71fcfe168be8a (MD5) design.tex: 8752 bytes, checksum: 6da091272b1d1b763d4fe929ed20af27 (MD5) implementation.tex: 13934 bytes, checksum: 4ec2ed4952e83584bdaf061ae208d5c5 (MD5) introduction.tex: 12247 bytes, checksum: f7e1717b55fc00a002452531113dd72e (MD5) relatedworks.tex: 14419 bytes, checksum: ae0a031c82712e2df126b6f1967a5379 (MD5) license.txt: 4056 bytes, checksum: fe65cf308f82ac2ad418428ecabc2334 (MD5) 1_license.txt: 4056 bytes, checksum: 830b5d67f2e37a8c2d1be775ff8b523f (MD5)"],"dc:identifier":["http://hdl.handle.net/2142/26096"],"dc:language":["en"],"dc:rights":["Copyright 2011 Hee Dong Jung"],"dc:subject":["Building Automation Systems (BAS)","Security","Networks","Authentication"],"dc:title":["Improving the security in interconnecting building automation systems to outside networks"],"thesis:degree_discipline":["Computer Science"],"thesis:degree_level":["Thesis"],"thesis:degree_name":["M.S."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:26Z"}