Issue
What are the measures in the AS to protect the system in cases of network broadcast storm or Denial of Service attacks?
Product Line
EcoStruxure Building Operation
Environment
- Building Operation Automation Server Premium
- Building Operation Automation Server
Cause
Offline alarms received after excessive network traffic observed.
Resolution
The firmware in the AS will temporarily shut down its Ethernet connection when exposed to a broadcast storm or DoS attack in order to protect the application in terms of control programs and IO.
A side effect of this is that the communication to external IP devices is temporarily unavailable during the storm/attack.
The Automation Server will log the network storm event in its log journal file. (see screenshot below)