BACnet Building Automation
Overview
BACnet (Building Automation and Control Networks) is the dominant protocol for HVAC, lighting, fire/life safety, and access control systems in commercial buildings. KYRA MDR performs passive network detection and response (NDR) monitoring of BACnet/IP traffic to detect unauthorized device access, configuration changes, and anomalous control commands without disrupting building operations.
Prerequisites
- KYRA MDR account (MDR tier or above)
- KYRA Collector or NDR sensor deployed on the BACnet/IP network segment
- Network switch with port mirroring (SPAN) configured for the BACnet VLAN
- BACnet/IP devices communicating on UDP port 47808 (0xBAC0)
- No active scanning or injection — monitoring is strictly passive
Configuration
Step 1: Configure Network SPAN Port
Set up port mirroring on the switch connecting the BACnet/IP segment:
! Cisco IOS example - mirror BACnet VLAN to sensor portconfigure terminalmonitor session 1 source vlan 100monitor session 1 destination interface GigabitEthernet0/24endwrite memoryVerify the SPAN session:
show monitor session 1Step 2: Configure KYRA Collector for BACnet Monitoring
source: type: bacnet-ndr listen_interface: eth1 # interface receiving SPAN traffic bacnet_port: 47808 # standard BACnet/IP port mode: passive # NEVER active -- passive only log_services: - ReadProperty # property read requests - ReadPropertyMultiple # bulk property reads - WriteProperty # property write commands (critical) - WritePropertyMultiple # bulk property writes (critical) - SubscribeCOV # Change of Value subscriptions - WhoIs # device discovery broadcasts - IAm # device discovery responses - WhoHas # object discovery - IHave # object discovery responses - ReinitializeDevice # device restart commands (critical) - DeviceCommunicationControl # enable/disable communication (critical) alert_on_writes: true # alert on any WriteProperty to critical objects baseline_learning: 72h # learn normal traffic patterns for 72 hourskyra-collector reloadkyra-collector statusStep 3: Capture BACnet Traffic with tcpdump (Verification)
Verify BACnet/IP traffic is visible on the monitoring interface:
# Capture BACnet/IP packets (UDP port 47808)sudo tcpdump -i eth1 -n udp port 47808 -c 20
# Capture and save to PCAP for analysissudo tcpdump -i eth1 -n udp port 47808 -w /tmp/bacnet-capture.pcap -c 1000
# Analyze with tshark (Wireshark CLI)tshark -r /tmp/bacnet-capture.pcap -Y "bacnet" \ -T fields -e ip.src -e ip.dst -e bacapp.type -e bacapp.service_requestStep 4: Monitor BACnet Device Discovery
Track Who-Is and I-Am broadcasts to build a device inventory:
# Use BACnet tools to discover devices (one-time baseline, not continuous)# Install: pip install BAC0python3 -c "import BAC0# Read-only discovery (passive network scan)bacnet = BAC0.lite(ip='192.168.100.50/24', bbmdAddress='192.168.100.1', bbmdTTL=900)print('Discovered devices:', bacnet.devices)bacnet.disconnect()"Expected I-Am response fields:
| Field | Description |
|---|---|
| Device Object Identifier | Unique device ID (e.g., device:100) |
| Max APDU Length | Maximum packet size |
| Segmentation Support | Whether device supports segmented messages |
| Vendor ID | Manufacturer identifier |
Step 5: Trend Log Collection
BACnet devices store trend logs (historical data) locally. Configure periodic collection:
source: type: bacnet-trend-collector mode: passive-read # read trend logs without writing devices: - address: "192.168.100.10" device_id: 100 trend_logs: - object_id: "trendLog:1" # HVAC zone temperature - object_id: "trendLog:2" # AHU supply fan speed collection_interval: 300 # secondsStep 6: Verify on KYRA Collector
kyra-collector statuskyra-collector logs --source bacnet --tail 10Collected Log Types
| Log Type | Description | Security Use |
|---|---|---|
| Who-Is / I-Am | Device discovery broadcasts and responses | Network enumeration detection, asset inventory |
| ReadProperty | Property value read requests | Normal operation baseline |
| WriteProperty | Property value change commands | Unauthorized control detection |
| ReinitializeDevice | Device restart commands | Sabotage detection |
| DeviceCommunicationControl | Commands to disable device communication | Communication disruption |
| SubscribeCOV | Change of Value subscription setup | Surveillance detection |
| Trend Logs | Historical sensor and actuator data | Anomaly detection in building operations |
| Network Traffic Stats | Packet counts, unique source/dest pairs, protocol distribution | Baseline deviation |
Security-Critical BACnet Events
| Event | Indicator | Description |
|---|---|---|
WriteProperty from unknown source IP | Unauthorized control | Unknown device attempting to change building system settings |
ReinitializeDevice command | Sabotage | Attempt to restart a BACnet controller |
DeviceCommunicationControl with disable flag | Denial of service | Attempt to silence a device on the network |
Unusual Who-Is broadcast frequency | Reconnaissance | Network scanning for BACnet devices |
WriteProperty to safety-critical objects | Safety risk | Changes to fire/life safety, elevator, or access control systems |
New I-Am response from unknown device ID | Rogue device | Previously unseen device appearing on the BACnet network |
ReadProperty burst from single source | Data harvesting | Bulk reading of device properties (floor plans, schedules, occupancy) |
BACnet Object Types to Monitor
| Object Type | Criticality | Why Monitor |
|---|---|---|
| Binary Output | High | Controls physical actuators (valves, dampers, relays) |
| Analog Output | High | Controls setpoints (temperature, pressure, flow) |
| Schedule | Medium | Defines when systems operate (HVAC schedules) |
| Notification Class | Medium | Alert routing configuration |
| Program | High | Custom controller logic (can be reprogrammed) |
| File | High | Controller firmware and configuration files |
Troubleshooting
- No BACnet traffic captured: Verify the SPAN port is configured correctly and the monitoring interface is in promiscuous mode (
ip link set eth1 promisc on). Usetcpdump -i eth1 udp port 47808to verify. - BACnet/MSTP traffic not visible: BACnet/MSTP runs over RS-485 serial links, not IP. Only BACnet/IP (UDP 47808) and BACnet/Ethernet are capturable via network monitoring. MSTP requires a serial-to-IP gateway.
- False positives from BMS software: Building management system (BMS) workstations generate frequent ReadProperty/WriteProperty commands during normal operation. Use the baseline learning period to establish normal patterns before alerting.
- Building safety concern: KYRA MDR monitoring is strictly passive. The Collector never sends BACnet commands or modifies device configurations. Verify
mode: passivein the source configuration. - Encrypted BACnet traffic: BACnet Secure Connect (BACnet/SC) encrypts traffic via TLS. Passive monitoring cannot inspect encrypted payloads. For BACnet/SC environments, collect logs from the BACnet/SC hub instead.
Contact kyra@seekerslab.com for integration support.