본문으로 건너뛰기

BACnet Building Automation

Overview

BACnet (Building Automation and Control Networks) is the dominant protocol for HVAC, lighting, fire/life safety, and access control systems in commercial buildings. KYRA MDR performs passive network detection and response (NDR) monitoring of BACnet/IP traffic to detect unauthorized device access, configuration changes, and anomalous control commands without disrupting building operations.

Prerequisites

  • KYRA MDR account (MDR tier or above)
  • KYRA Collector or NDR sensor deployed on the BACnet/IP network segment
  • Network switch with port mirroring (SPAN) configured for the BACnet VLAN
  • BACnet/IP devices communicating on UDP port 47808 (0xBAC0)
  • No active scanning or injection — monitoring is strictly passive

Configuration

Step 1: Configure Network SPAN Port

Set up port mirroring on the switch connecting the BACnet/IP segment:

! Cisco IOS example - mirror BACnet VLAN to sensor port
configure terminal
monitor session 1 source vlan 100
monitor session 1 destination interface GigabitEthernet0/24
end
write memory

Verify the SPAN session:

show monitor session 1

Step 2: Configure KYRA Collector for BACnet Monitoring

/etc/kyra-collector/sources.d/bacnet.yaml
source:
type: bacnet-ndr
listen_interface: eth1 # interface receiving SPAN traffic
bacnet_port: 47808 # standard BACnet/IP port
mode: passive # NEVER active -- passive only
log_services:
- ReadProperty # property read requests
- ReadPropertyMultiple # bulk property reads
- WriteProperty # property write commands (critical)
- WritePropertyMultiple # bulk property writes (critical)
- SubscribeCOV # Change of Value subscriptions
- WhoIs # device discovery broadcasts
- IAm # device discovery responses
- WhoHas # object discovery
- IHave # object discovery responses
- ReinitializeDevice # device restart commands (critical)
- DeviceCommunicationControl # enable/disable communication (critical)
alert_on_writes: true # alert on any WriteProperty to critical objects
baseline_learning: 72h # learn normal traffic patterns for 72 hours
Terminal window
kyra-collector reload
kyra-collector status

Step 3: Capture BACnet Traffic with tcpdump (Verification)

Verify BACnet/IP traffic is visible on the monitoring interface:

Terminal window
# Capture BACnet/IP packets (UDP port 47808)
sudo tcpdump -i eth1 -n udp port 47808 -c 20
# Capture and save to PCAP for analysis
sudo tcpdump -i eth1 -n udp port 47808 -w /tmp/bacnet-capture.pcap -c 1000
# Analyze with tshark (Wireshark CLI)
tshark -r /tmp/bacnet-capture.pcap -Y "bacnet" \
-T fields -e ip.src -e ip.dst -e bacapp.type -e bacapp.service_request

Step 4: Monitor BACnet Device Discovery

Track Who-Is and I-Am broadcasts to build a device inventory:

Terminal window
# Use BACnet tools to discover devices (one-time baseline, not continuous)
# Install: pip install BAC0
python3 -c "
import BAC0
# Read-only discovery (passive network scan)
bacnet = BAC0.lite(ip='192.168.100.50/24', bbmdAddress='192.168.100.1', bbmdTTL=900)
print('Discovered devices:', bacnet.devices)
bacnet.disconnect()
"

Expected I-Am response fields:

FieldDescription
Device Object IdentifierUnique device ID (e.g., device:100)
Max APDU LengthMaximum packet size
Segmentation SupportWhether device supports segmented messages
Vendor IDManufacturer identifier

Step 5: Trend Log Collection

BACnet devices store trend logs (historical data) locally. Configure periodic collection:

/etc/kyra-collector/sources.d/bacnet-trends.yaml
source:
type: bacnet-trend-collector
mode: passive-read # read trend logs without writing
devices:
- address: "192.168.100.10"
device_id: 100
trend_logs:
- object_id: "trendLog:1" # HVAC zone temperature
- object_id: "trendLog:2" # AHU supply fan speed
collection_interval: 300 # seconds

Step 6: Verify on KYRA Collector

Terminal window
kyra-collector status
kyra-collector logs --source bacnet --tail 10

Collected Log Types

Log TypeDescriptionSecurity Use
Who-Is / I-AmDevice discovery broadcasts and responsesNetwork enumeration detection, asset inventory
ReadPropertyProperty value read requestsNormal operation baseline
WritePropertyProperty value change commandsUnauthorized control detection
ReinitializeDeviceDevice restart commandsSabotage detection
DeviceCommunicationControlCommands to disable device communicationCommunication disruption
SubscribeCOVChange of Value subscription setupSurveillance detection
Trend LogsHistorical sensor and actuator dataAnomaly detection in building operations
Network Traffic StatsPacket counts, unique source/dest pairs, protocol distributionBaseline deviation

Security-Critical BACnet Events

EventIndicatorDescription
WriteProperty from unknown source IPUnauthorized controlUnknown device attempting to change building system settings
ReinitializeDevice commandSabotageAttempt to restart a BACnet controller
DeviceCommunicationControl with disable flagDenial of serviceAttempt to silence a device on the network
Unusual Who-Is broadcast frequencyReconnaissanceNetwork scanning for BACnet devices
WriteProperty to safety-critical objectsSafety riskChanges to fire/life safety, elevator, or access control systems
New I-Am response from unknown device IDRogue devicePreviously unseen device appearing on the BACnet network
ReadProperty burst from single sourceData harvestingBulk reading of device properties (floor plans, schedules, occupancy)

BACnet Object Types to Monitor

Object TypeCriticalityWhy Monitor
Binary OutputHighControls physical actuators (valves, dampers, relays)
Analog OutputHighControls setpoints (temperature, pressure, flow)
ScheduleMediumDefines when systems operate (HVAC schedules)
Notification ClassMediumAlert routing configuration
ProgramHighCustom controller logic (can be reprogrammed)
FileHighController firmware and configuration files

Troubleshooting

  • No BACnet traffic captured: Verify the SPAN port is configured correctly and the monitoring interface is in promiscuous mode (ip link set eth1 promisc on). Use tcpdump -i eth1 udp port 47808 to verify.
  • BACnet/MSTP traffic not visible: BACnet/MSTP runs over RS-485 serial links, not IP. Only BACnet/IP (UDP 47808) and BACnet/Ethernet are capturable via network monitoring. MSTP requires a serial-to-IP gateway.
  • False positives from BMS software: Building management system (BMS) workstations generate frequent ReadProperty/WriteProperty commands during normal operation. Use the baseline learning period to establish normal patterns before alerting.
  • Building safety concern: KYRA MDR monitoring is strictly passive. The Collector never sends BACnet commands or modifies device configurations. Verify mode: passive in the source configuration.
  • Encrypted BACnet traffic: BACnet Secure Connect (BACnet/SC) encrypts traffic via TLS. Passive monitoring cannot inspect encrypted payloads. For BACnet/SC environments, collect logs from the BACnet/SC hub instead.

Contact kyra@seekerslab.com for integration support.