Anomalous Device Behavior
The most fundamental detection capability in smart building monitoring is identifying when a device behaves in ways inconsistent with its baseline.
This includes:
- A BMS controller communicating with an unfamiliar external address
- A sensor generating traffic volumes significantly above its normal baseline
- An access control device receiving commands from an unexpected source
- A building controller issuing commands at unusual times inconsistent with scheduled building operations
These behavioral anomalies may indicate compromise, misconfiguration, or unauthorized activity — and each warrants investigation by an analyst with knowledge of the building environment.
Unauthorized Protocol Commands
Protocol-aware monitoring enables detection of unauthorized or anomalous commands at the building automation protocol level — a detection capability that is invisible to IT-centric monitoring tools.
In a BACnet environment, for example, monitoring can detect:
- Write commands being issued to devices that should only be receiving read requests
- Commands from unauthorized sources — devices or IP addresses that have no legitimate reason to issue commands to a particular controller
- Unusual command sequences inconsistent with normal building operation cycles
- Protocol reconnaissance activity — systematic querying of device capabilities in patterns consistent with attacker mapping behavior
This protocol-level detection is particularly important because many smart building attacks involve direct manipulation of building systems through their native protocols — activity that generates no IT security alerts whatsoever.
Lateral Movement Indicators
Smart building monitoring must look beyond individual devices to detect attack patterns that span network boundaries — particularly lateral movement between building automation networks and corporate IT infrastructure.
Indicators of lateral movement in smart building environments include:
- Unexpected cross-boundary traffic — connections between building automation network segments and corporate IT networks that are outside normal operational patterns
- New connections from building devices to IT infrastructure — particularly to sensitive systems such as domain controllers, file servers, or identity platforms
- IT-side alerts correlated with BMS anomalies — events in corporate IT that coincide with unusual building system activity, suggesting coordinated or progressive attack activity
Detecting lateral movement requires cross-domain visibility — monitoring that spans both the building automation network and the corporate IT environment, with the ability to correlate events across both.
Learn more: Lateral Movement in IoT Environments: How Attackers Pivot from IT to OT
Asset Discovery Anomalies
Continuous monitoring provides ongoing asset discovery — maintaining an accurate, real-time inventory of every device connected to the building network. This capability enables detection of:
- New, unrecognized devices connecting to building automation network segments
- Devices appearing on unexpected network segments — potentially indicating unauthorized reconfiguration or physical relocation
- Vendor or contractor devices remaining connected after maintenance activities have concluded
Unauthorized device connections are both a security signal in their own right and a potential indicator of physical access-based attacks — where an attacker has connected a device to the building network during a period of physical access.
Vulnerability and Risk Indicators
Beyond active threat detection, smart building monitoring platforms provide ongoing visibility into the vulnerability landscape of the building device estate:
- Devices running known vulnerable firmware versions
- Devices with default or weak credentials still in place
- Devices with unnecessary exposed services or open ports
- Devices that have reached end-of-vendor-support and are no longer receiving security updates
This continuous vulnerability visibility allows security teams to prioritize remediation and compensating controls based on current risk — rather than relying on periodic assessments that quickly become outdated.