Cybersecurity Assessments

Repeated stakeholder feedback highlighted the need for research to examine the risk that arises from the deployment of systems that produce increased amounts of data, and potential exposure of that data to other systems, including the internet in general. Multiple PNNL studies addressed these risks and explored controls and technologies for mitigating them. Research on vulnerability assessments and threat profiles is highlighted below.

Cybersecurity Landscape Assessments. Driven by various data-driven use cases, there is increased interest in networking and integrating lighting and other building systems (e.g., HVAC, security, scheduling) that were previously not internet-facing, and equipping them with sensors that collect information about their environment and the people that inhabit it. This paper explores tools available to system designers and integrators that facilitate a cybersecurity landscape assessment – or more specifically the identification of threats, vulnerabilities, and adversarial behaviors that could be used against these networked systems. These assessments can help stakeholders shift security prioritization proactively toward the beginning of the development process.

Vulnerability Assessments. A collaboration with Underwriters Laboratory led to development of a set of tests focused on authentication vulnerabilities and execution of those tests in PNNL’s test bed to evaluate four commercially available lighting systems.

Threat Profiles. PNNL researchers also collaborated with in-house cybersecurity experts to develop threat profiles for multiple connected lighting systems with varying system architectures and technologies.

Video Url
A video poster presentation from the 2021 DOE Lighting R&D Workshop.
U.S. Department of Energy