Building Management System Malicious User Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Building management systems (BMS) face challenges in detecting and preventing malicious user activity, as unauthorized access can lead to severe disruptions in building controls, such as altering HVAC, security, and lighting systems, without adequate real-time monitoring and verification processes.
Innovation Solution
A BMS that includes a user access point, building subsystems, and a controller configured to compare user inputs with user and equipment profiles to determine a safety value. If the safety value exceeds a predetermined range, a verification process is initiated, involving contact with authorized users via email, text message, or automated phone calls to confirm intended changes before implementing them.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If automated control is increased in building management systems, then system efficiency and productivity are improved, but vulnerability to malicious usage and difficulty of monitoring increases
Solution Approach 1:
The system continuously monitors user inputs and system state changes, comparing them against established profiles and safety ranges. This feedback loop enables real-time detection of anomalous behavior that deviates from normal operational patterns, allowing the system to identify potential malicious activities while maintaining automated control.
Solution Approach 2:
The system pre-establishes user profiles, equipment profiles, and safety ranges before malicious activities can occur. By having these reference parameters ready in advance, the system can immediately compare incoming user inputs against them and detect anomalies without delay, enabling proactive prevention rather than reactive response.
2Reliability
If real-time monitoring and verification processes are implemented, then system security and reliability are improved, but system complexity and operational overhead increase
Solution Approach 1:
The monitoring system applies different levels of scrutiny to different aspects of system operation. Critical parameters and high-risk operations receive enhanced verification through safety value assessment and profile comparison, while routine operations proceed with standard monitoring. This differentiated approach maintains security without uniformly increasing complexity across all system functions.
Solution Approach 2:
The system automatically performs monitoring, comparison, and verification functions without requiring manual intervention. The controller autonomously assesses safety values, compares inputs against profiles, and determines whether verification is needed, reducing operational overhead while maintaining high security standards through automated decision-making.
3Reliability
If safety verification processes are implemented for user inputs, then system integrity is protected, but response time and operational speed may be reduced
Solution Approach 1:
The system applies verification processes selectively rather than universally. By assessing safety values and comparing inputs against profiles, the system determines whether full verification is necessary or if standard processing suffices. This partial application of verification maintains system integrity for critical operations while allowing faster processing for routine, low-risk inputs.
Data Source
AI summary
A building management system (BMS) includes a user access point configured to receive a user input corresponding to the BMS. The system includes at least one building subsystem in communication with the user access point and configured to control subsystem equipment in response to the user input. Additionally, the system includes a controller configured to: receive the user input, and receive access point data. The controller is further configured to compare the user input and access point data to a user profile and/or an equipment profile. Additionally, the controller is configured to determine a safety value using the comparison, and determine if the safety value is outside of a predetermined safety range. If the safety value is outside of the predetermined safety range, the controller is configured to initiate a verification process.


