VLDB 2026 Research / reviewers in the wild / expert
Martin Husák
dblp:08/1162
· DBLP profile ↗
48ranked-venue papers
23as first author
21since 2021 · last 2026
0000-0001-7249-9881ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 21 · 14 first-author · 6 since 2021Computer networks · 7 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 4 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Theory of computation · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Intelligence Augmentation in a Platform for Cyber Situational Awareness
Lukás Sadlek, Milan Bohácek, Jan Rolínek, Martin Husák |
NetSoft | 4 |
| 2025 | Replication: Network-based Lateral Movement Detection Methods Using Machine LearningabstractPivoting is a technique commonly employed by advanced adversaries to perform lateral movement within a network. In this process, an attacker leverages an intermediary host to relay commands to otherwise inaccessible systems. In this work, we survey the current state-of-the-art lateral movement detection techniques and identify approaches best suited for detecting pivoting behavior. Specifically, we focus on methods analyzing network traffic, not system logs, since we are looking for network-wide solution. We present the results of a replicability study, in which we find that only a few proposed approaches also publish a usable implementation, but their results are promising. Vladimír Boucek, Martin Husák |
CNSM | 2 |
| 2025 | Fast and Configurable Detection of Device Dependencies in Network TrafficabstractDevice dependencies are recurring communication patterns between IP addresses that reveal how networked entities rely on one another. Understanding these relationships is essential for reliability, troubleshooting, and security, yet detecting them efficiently from operational traffic remains challenging. We propose a fast and accurate tool for dependency detection from passive flow-level data using a link prediction approach. In contrast to the prior implementation, the tool introduces a parallelized processing pipeline with early termination of stalled random walks, an expanded feature set that combines embedding-derived and graph-theoretic metrics, and a fully externalized configuration of sampling, embedding, and classification parameters. These design choices enable scalable execution and more reliable identification of dependencies across diverse network environments. Evaluation on synthetic traffic from cyber-defense exercises and real-world campus flows demonstrates up to 100$\times$ faster runtime and markedly higher classification accuracy compared to the prior implementation. Further analysis shows that structural graph features improve stability in sparse settings, while extended embedding training enhances accuracy in low-signal scenarios. Together, these results confirm that the proposed tool advances link prediction-based dependency detection toward practical, near-real-time use. Jakub Dusil, Martin Husák, Lukás Sadlek |
CNSM | 2 |
| 2025 | The Resilmesh Architecture: Situation Aware Enabled Cyber Resilience for Dispersed, Heterogenous Cyber SystemsabstractCyber systems (CyS) are becoming more and more complex as they are comprised of several infrastructure layers, heterogeneous technologies and dispersed deployments over wide geographical areas (cloud/edge/endpoint) that facilitates multiple attack entry points (vectors). At the same time, CyS attacks are constantly evolving and have become more complex and sophisticated. To address these issues, the ResilMesh architecture aims to provide critical infrastructure security teams with a greater cyber resilience capability by improving cyber resilience using Cyber Situational Awareness (CSA) based security orchestration and analytics framework. The framework enables organizations to achieve real-time defense, reducing attack surface impact by developing tools to combat complexity, disperse infrastructure, delivering flexible placement of security controls across the CyS infrastructure. The architecture combats Advanced Persistent Threat (APT) sophistication by leveraging advanced AI algorithms and tools for early and ongoing attack detection and prediction and improved situation. This paper presents the Resilmesh architecture, a first PoC implementation, as well as an evaluation of the Resilmesh capabilities to detect and mitigate APTs. Jorge Bernal Bernabé, Martin Husák, Lukás Sadlek, Branka Stojanovic, Michael Somma, Jorgeley Inacio de Oliveira, Ekam Puri Nieto, Pablo Fernández Saura, Antonio F. Skarmeta, Vinh Hoa La |
NetSoft | 3 |
| 2025 | Attack Surface Management: State of the Art and Operational ChallengesabstractIn this paper, we approach the topic of ASM, place the task in the context of cybersecurity operations, review the current methods, and discuss their issues and challenges. We outline an ASM pipeline consisting of common tasks and review the usability of the existing tools. We pinpoint a trade-off between the scope and precision of the existing tools that should be considered, namely in medium to large networks. Finally, we formulate and discuss the issues and challenges for emerging network environments, including those involving IoT or OT, volatile environments, or extensive use of cloud computing. Each of these emerging technologies brings novel issues that need to be approached by ASM, be it improved fingerprinting in IoT and OT, precisely timed scans in volatile environments, or coverage of external services in the cloud. Martin Husák, Lukás Sadlek |
NetSoft | 1 |
| 2025 | Real-Time Network Cyber Situational Awareness in B5G NetworksabstractThe dynamic nature of beyond 5G network (B5G) topologies imposes continuous and real-time cyber situational awareness (CSA) to make cognitive security orchestration according to the actual context. In this sense, security orchestration decisions such as virtual network security functions placement or (re)configuration of the system to counter cyberthreats can benefit of these kind of CSA models. Traditional infrastructure and service models for CSA such as CRUSOE capture the security posture, missions, networks and assets, that can be used as baseline for cognitive functions such as cyber asset attack surface management, risk-trust assessment as well as detection and mitigation of cyber-attacks. However, these infrastructure data models and tools have not been adapted to complex B5G domains and do not support real-time processing of 6 G network traffic that, once supported, can boost context awareness and decision making. This paper describes the design, implementation and evaluation of the extension to the CRUSOE infrastructure model to enable the real-time modeling of 6G network flows, thereby increasing cyber security awareness capabilities in 6 G Security Operation Centers (6G-SOC), that ultimately, can help to improve cognitive security management of 6 G networks. The implementation and performance evaluation carried out shows promising results to capture and model in real time the dynamicity of 6G network topologies and traffic. José Antonio Pastor, Martin Husák, Jorge Bernal Bernabé, Antonio F. Skarmeta |
NetSoft | 2 |
| 2024 | Machine Learning in Intrusion Detection: An Operational PerspectiveabstractMachine learning has become a prevalent approach in research on intrusion detection with enormous number of research publications on the topic, but its adoption by cyber-security practitioners is falling behind. Recently, researchers conducted critical and pragmatic assessment of the capabilities of machine learning in this task and identified fundamental issues preventing wider application and easy use in practice. In this paper, we approach the topic from the perspective of network security management, focusing on the issues of compatibility with existing monitoring and security infrastructures, computational complexity, ease of use, and required skills of the operators. The research in machine learning-based intrusion detection strongly favors machine learning metrics (e.g., precision and accuracy) over any other outcome, including performance and usability, for which we have no actual results due to very low number of prototypes, implementations, and field studies. Moreover, there are very limited options of recognizing which type of attack was detected, which remains a strong advantage of traditional signature-based intrusion detection systems. Martin Husák, Darshan M, Priyanka Kumar |
CNSM | 1 |
| 2024 | The Evolution of the CRUSOE Toolset: Enhancing Decision Support in Network Security ManagementabstractThis demo paper presents the recent development of the CRUSOE toolset. CRUSOE enables cyber situational awareness and provides decision support for network security management. The first public version from 2021 used a combination of active and passive network monitoring to enumerate cyber assets and discover their vulnerabilities, visualize the collected data in a dashboard, conduct a risk assessment to recommend the most resilient infrastructure configuration, and facilitate attack mitigation. It also used novel approaches, such as a graph database for storing the data on cyber assets, which essentially became a knowledge graph for network security management. In the recent development, we managed to automate the deployment of CRUSOE via Ansible and Docker. Further, we implemented additional recommender systems and attack impact assessment capabilities and their visualizations. Finally, several sample datasets were created to facilitate the demonstration of the toolset and to enable testing it without one’s data. Martin Husák, Lukás Sadlek, Martin Hesko, Vít Sebela, Stanislav Spacek |
CNSM | 1 |
| 2024 | Hierarchical Modeling of Cyber Assets in Kill Chain Attack GraphsabstractCyber threat modeling is a proactive method for identifying possible cyber attacks on network infrastructure that has a wide range of applications in security assessment, risk analysis, and threat exposure management. Popular modeling methods are kill chains and attack graphs. Kill chains divide attacks into phases, and attack graphs depict attack paths. A difficult issue is how to hierarchically model categories of cyber assets that should be used in threat models due to the variety of cyber systems in the current networks. This task should be addressed to provide automation of realistic threat modeling and interoperability with public knowledge bases, such as MITRE ATT&CK. In this paper, we propose a hierarchical modeling methodology for representing cyber assets in kill chain attack graphs. We illustrate its practical application on MITRE D3FEND’s Digital Artifact Ontology. Moreover, we define how cyber assets with related attack techniques should be transformed into logical facts and attack rules. We implemented proof-of-concept software modules that can process data obtained from network and host-based monitoring together with attack rules to generate attack graphs. We evaluated the approach with data from a cyber exercise captured in a network of a digital twin organization. The results show that the approach is applicable in real-world networks and can reveal ground-truth attacks. Lukás Sadlek, Martin Husák, Pavel Celeda |
CNSM | 2 |
| 2024 | Identification of Device Dependencies Using Link PredictionabstractDevices in computer networks cannot work without essential network services provided by a limited count of devices. Identification of device dependencies determines whether a pair of IP addresses is a dependency, i.e., the host with the first IP address is dependent on the second one. These dependencies cannot be identified manually in large and dynamically changing networks. Nevertheless, they are important due to possible unexpected failures, performance issues, and cascading effects. We address the identification of dependencies using a new approach based on graph-based machine learning. The approach belongs to link prediction based on a latent representation of the computer network’s communication graph. It samples random walks over IP addresses that fulfill time conditions imposed on network dependencies. The constrained random walks are used by a neural network to construct IP address embedding, which is a space that contains IP addresses that often appear close together in the same communication chain (i.e., random walk). Dependency embedding is constructed by combining values for IP addresses from their embedding and used for training the resulting dependency classifier. We evaluated the approach using IP flow datasets from a controlled environment and university campus network that contain evidence about dependencies. Evaluation concerning the correctness and relationship to other approaches shows that the approach achieves acceptable performance. It can simultaneously consider all types of dependencies and is applicable for batch processing in operational conditions. Lukás Sadlek, Martin Husák, Pavel Celeda |
NOMS | 2 |
| 2023 | Unraveling Network-Based Pivoting Maneuvers: Empirical Insights and Challenges
Martin Husák, Shanchieh Jay Yang, Joseph Khoury, Dorde Klisura, Elias Bou-Harb |
ICDF2C (2) | 1 |
| 2023 | Recommending Similar Devices in Close Proximity for Network Security ManagementabstractThis paper presents a prototype of a tool for network security management that recommends similar devices in close proximity to a given machine. The task of recommending similar devices helps in analyzing the impact of cyber attacks, providing early warning and mitigating a spreading infection, or investigating an attack. Our tool uses modern graph-based technologies to store and query the data and existing data models that interconnect heterogeneous information about computer networks. By traversing the graph of network entities and calculating similarity scores, the tool suggests which devices are most likely to be exploited along with or after the exploitation of a device in question. The advantage of our tool is that it considers multiple attack vectors, including social engineering. Vladimír Boucek, Martin Husák |
WiMob | 2 |
| 2023 | Passive operating system fingerprinting revisited: Evaluation and current challengesabstractFingerprinting a host's operating system is a very common yet precarious task in network, asset, and vulnerability management. Estimating the operating system via network traffic analysis may leverage TCP/IP header parameters or complex analysis of hosts' behavior using machine learning. However, the existing approaches are becoming obsolete as network traffic evolves which makes the problem still open. This paper discusses various approaches to passive OS fingerprinting and their evolution in the past twenty years. We illustrate their usage, compare their results in an experiment, and list challenges faced by the current fingerprinting approaches. The hosts' differences in network stack settings were initially the most important information source for OS fingerprinting, which is now complemented by hosts' behavioral analysis and combined approaches backed by machine learning. The most impactful reasons for this evolution were the Internet-wide network traffic encryption and the general adoption of privacy-preserving concepts in application protocols. Other changes, such as the increasing proliferation of web applications on handheld devices, raised the need to identify these devices in the networks, for which we may use the techniques of OS fingerprinting. Martin Lastovicka, Martin Husák, Petr Velan, Tomás Jirsík, Pavel Celeda |
Comput. Networks | 2 |
| 2022 | SoK: Applications and Challenges of using Recommender Systems in Cybersecurity Incident Handling and ResponseabstractIncident handling, a fundamental activity of a cybersecurity incident response team, is a complex discipline that consumes a significant amount of personnel’s time and costs. There are continuous efforts to facilitate incident handling and response in terms of providing procedural or decision support and processing relevant data. In this paper, we survey the approaches towards (semi-)automated incident handling and response backed by recommender systems that are successful in other domains. We discuss which phases and tiers of incident handling can be automated and to what level while evaluating the maturity of proposed approaches and tools. While we did not find a full-scale recommender system that would guide the user through incident handling and suggest which steps to take, many of them aim at particular problems. The discussed issues are not resolved yet but seem to get the attention of researchers and will likely be investigated in the future. Martin Husák, Milan Cermák |
ARES | 1 |
| 2022 | Limiting the Size of a Predictive Blacklist While Maintaining Sufficient AccuracyabstractBlacklists (blocklists, denylists) of network entities (e.g., IP addresses, domain names) are popular approaches to preventing cyber attacks. However, the limited capacity of active network defense devices may not hold all the entries on a blacklist. In this paper, we evaluated two strategies to limit the size of a blacklist and their impact on the blacklist’s accuracy. The first strategy is setting the maximal size of a blacklist; the second is setting an expiration time to blacklist items. Short-term attack predictions are typically more precise, and, thus, the recent blacklist entries should be more valuable than older ones. Our experiment shows that the blacklists reduced to half of the size via either strategy achieve only a 25 % drop in accuracy. Samuel Sulan, Martin Husák |
ARES | 2 |
| 2022 | CRUSOE: A toolset for cyber situational awareness and decision support in incident handling
Martin Husák, Lukás Sadlek, Stanislav Spacek, Martin Lastovicka, Michal Javorník, Jana Komárková |
Comput. Secur. | 1 |
| 2021 | System for Continuous Collection of Contextual Information for Network Security Management and Incident HandlingabstractIn this paper, we describe a system for the continuous collection of data for the needs of network security management. When a cybersecurity incident occurs in the network, the contextual information on the involved assets facilitates estimating the severity and impact of the incident and selecting an appropriate incident response. We propose a system based on the combination of active and passive network measurements and the correlation of the data with third-party systems. The system enumerates devices and services in the network and their vulnerabilities via fingerprinting of operating systems and applications. Further, the system pairs the hosts in the network with contacts on responsible administrators and highlights critical infrastructure and its dependencies. The system concentrates all the information required for common incident handling procedures and aims to speed up incident response, reduce the time spent on the manual investigation, and prevent errors caused by negligence or lack of information. Martin Husák, Martin Lastovicka, Daniel Tovarnák |
ARES | 1 |
| 2021 | Towards an Efficient Detection of Pivoting Activity
Martin Husák, Giovanni Apruzzese, Shanchieh Jay Yang, Gordon Werner |
IM | 1 |
| 2021 | A Dashboard for Cyber Situational Awareness and Decision Support in Network Security Management
Lukás Matta, Martin Husák |
IM | 2 |
| 2021 | Towards a Data-Driven Recommender System for Handling Ransomware and Similar IncidentsabstractEffective triage is of utmost importance for cybersecurity incident response, namely in handling ransomware or similar incidents in which the attacker may use self-propagating worms, infected files, or email attachments to spread malware. If a device is infected, it is vital to know which other devices can be infected too or are immediately threatened. The number and heterogeneity of devices in today’s network complicate situational awareness of incident handlers, and, thus, we propose a recommender system that uses network monitoring data to prioritize devices in the network based on their similarity and proximity to an already infected device. The system enumerates devices in close proximity in terms of physical and logical network topology and sorts them by their similarity given by the similarity of their behavioral profile, fingerprint, or common history. The incident handlers can use the recommendation to promptly prevent malware from spreading or trace the attacker’s lateral movement. Martin Husák |
ISI | 1 |
| 2021 | Predictive methods in cyber defense: Current experience and research challenges
Martin Husák, Václav Bartos, Pavol Sokol, Andrej Gajdos |
Future Gener. Comput. Syst. | 1 |
| 2020 | SoK: contemporary issues and challenges to enable cyber situational awareness for network securityabstractCyber situational awareness is an essential part of cyber defense that allows the cybersecurity operators to cope with the complexity of today's networks and threat landscape. Perceiving and comprehending the situation allow the operator to project upcoming events and make strategic decisions. In this paper, we recapitulate the fundamentals of cyber situational awareness and highlight its unique characteristics in comparison to generic situational awareness known from other fields. Subsequently, we provide an overview of existing research and trends in publishing on the topic, introduce front research groups, and highlight the impact of cyber situational awareness research. Further, we propose an updated taxonomy and enumeration of the components used for achieving cyber situational awareness. The updated taxonomy conforms to the widely-accepted three-level definition of cyber situational awareness and newly includes the projection level. Finally, we identify and discuss contemporary research and operational challenges, such as the need to cope with rising volume, velocity, and variety of cybersecurity data and the need to provide cybersecurity operators with the right data at the right time and increase their value through visualization. Martin Husák, Tomás Jirsík, Shanchieh Jay Yang |
ARES | 1 |
| 2020 | Predictions of Network Attacks in Collaborative EnvironmentabstractThis paper is a digest of the thesis on predicting cyber attacks in a collaborative environment. While previous works mostly focused on predicting attacks as seen from a single observation point, we proposed taking advantage of collaboration and exchange of intrusion detection alerts among organizations and networks. Thus, we can observe the cyber attack on a large scale and predict the next action of an adversary and its target. The thesis follows the three levels of cyber situational awareness: perception, comprehension, and projection. In the perception phase, we discuss the improvements of intrusion detection systems that allow for sharing intrusion detection alerts and their correlation. In the comprehension phase, we employed data mining to discover frequent attack patterns. In the projection phase, we present the analytical framework for the predictive analysis of the alerts backed by data mining and contemporary data processing approaches. The results are shown from experimental evaluation in the security alert sharing platform SABU, where real-world alerts from Czech academic and commercial networks are shared. The thesis is accompanied by the implementation of the analytical framework and a dataset that provides a baseline for future work. Martin Husák, Pavel Celeda |
NOMS | 1 |
| 2020 | Decision Support for Mission-Centric Network Security ManagementabstractIn this paper, we propose a decision support process that is designed to help network and security operators in understanding the complexity of a current security situation and decision making concerning ongoing cyber-attacks and threats. The process focuses on enterprise missions and uses a graph-based mission decomposition model that captures the missions, underlying hosts and services in the network, and functional and security requirements between them. Knowing the vulnerabilities and attacker’s position in the network, the process employs logical attack graphs and Bayesian network to infer the probability of the disruption of the confidentiality, integrity, and availability of the missions. Based on the probabilities of disruptions, the process suggests the most resilient mission configuration that would withstand the current security situation. Michal Javorník, Jana Komárková, Lukás Sadlek, Martin Husák |
NOMS | 4 |
| 2020 | Network Monitoring and Enumerating Vulnerabilities in Large Heterogeneous NetworksabstractIn this paper, we present an empirical study on vulnerability enumeration in computer networks using common network probing and monitoring tools. We conducted active network scans and passive network monitoring to enumerate software resources and their version present in the network. Further, we used the data from third-party sources, such as Internet-wide scanner Shodan. We correlated the measurements with the list of recent vulnerabilities obtained from NVD using the CPE as a common identifier used in both domains. Subsequently, we compared the approaches in terms of network coverage and precision of system identification. Finally, we present a sample list of vulnerabilities observed in our campus network. Our work helps in approximating the number of vulnerabilities and vulnerable hosts in large networks, where it is often impractical or costly to perform vulnerability scans using specialized tools, and in situations, where a quick estimate is more important than thorough analysis. Martin Lastovicka, Martin Husák, Lukás Sadlek |
NOMS | 2 |
| 2019 | GDPR Compliance in Cybersecurity Software: A Case Study of DPIA in Information Sharing PlatformabstractIn this article, we discuss the issues of GDPR's impact on cyber-security software and operations, namely automated information sharing. We illustrate the topic on an example of an intrusion detection alert sharing platform. First, we had to investigate the risks to privacy in the alert sharing platform and ensure its compliance with the GDPR's obligations. Second, fears and uncertainties emerged in the alert sharing community regarding the GDPR and its obligations and, thus, willingness to share the information was negatively impacted. We conducted DPIA to investigate risks related to information sharing in cyber security and dismiss doubts within the community. Although our results suggest that the risks are not high, we point out that the hype around GDPR caused substantial development of the sharing platform. The DPIA helped in a deeper understanding of risks and their management and is a solid argument for information sharing in cyber security under GDPR. Martin Horák, Václav Stupka, Martin Husák |
ARES | 3 |
| 2019 | AIDA Framework: Real-Time Correlation and Prediction of Intrusion Detection AlertsabstractIn this paper, we present AIDA, an analytical framework for processing intrusion detection alerts with a focus on alert correlation and predictive analytics. The framework contains components that filter, aggregate, and correlate the alerts, and predict future security events using the predictive rules distilled from historical records. The components are based on stream processing and use selected features of data mining (namely sequential rule mining) and complex event processing. The framework was deployed as an analytical component of an alert sharing platform, where alerts from intrusion detection systems, honeypots, and other data sources are exchanged among the community of peers. The deployment is briefly described and evaluated to illustrate the capabilities of the framework in practice. Further, the framework may be deployed locally for experimentations over datasets. Martin Husák, Jaroslav Kaspar |
ARES | 1 |
| 2019 | Decision Support for Mission-Centric Cyber DefenceabstractIn this paper, we propose a novel approach to enterprise mission modeling and mission-centric decision support for cybersecurity operations. The goal of the decision support analytical process is to suggest an effective response for an ongoing attack endangering established mission security requirements. First, we propose an enterprise mission decomposition model to represent the requirements of the missions' processes and components on their confidentiality, integrity, availability. The model is illustrated in a real-world scenario of a medical information system. Second, we propose an analytical process that calculates mission resilience metrics using the attack graphs and Bayesian network reasoning. The process is designed to help cybersecurity operations teams in understanding the complexity of a situation and decision making concerning requirements on enterprise missions. Michal Javorník, Jana Komárková, Martin Husák |
ARES | 3 |
| 2019 | Big Data Sanitization and Cyber Situational Awareness: A Network Telescope PerspectiveabstractThis paper addresses the problems of data sanitization and cyber situational awareness by analyzing 910 GB of real Internet-scale traffic, which has been passively collected by monitoring close to 16.5 million darknet IP addresses from a /8 and a /13 network telescopes. First, the paper offers a novel probabilistic darknet preprocessing model, which aims at sanitizing darknet data to prepare it for effective use in the task of cyber threat intelligence generation. Such model has been engineered using a distributed multithreaded approach, rendering it operational and highly effective on darknet big data. Second, the paper further contributes by presenting an innovative approach to infer large-scale orchestrated probing campaigns by leveraging darknet data, for Internet cyber situational awareness. The approach uniquely reduces the dimensionality of such big data by utilizing its artifacts, instead of processing the actual raw data. This is accomplished by extracting and analyzing probing time series using formal methods rooted in Fourier transform and Kalman filtering. Thorough empirical evaluations indeed validate the accuracy and the performance of the proposed methods and techniques. We assert that the darknet sanitization model and the probing orchestration inference approach are of significant value, given their postulated highly applicable nature to the field of Internet measurements for cyber security in the era of big data. Elias Bou-Harb, Martin Husák, Mourad Debbabi, Chadi Assi |
IEEE Trans. Big Data | 2 |
| 2018 | Assessing Internet-wide Cyber Situational Awareness of Critical SectorsabstractIn this short paper, we take a first step towards empirically assessing Internet-wide malicious activities generated from and targeted towards Internet-scale business sectors (i.e., financial, health, education, etc.) and critical infrastructure (i.e., utilities, manufacturing, government, etc.). Facilitated by an innovative and a collaborative large-scale effort, we have conducted discussions with numerous Internet entities to obtain rare and private information related to allocated IP blocks pertaining to the aforementioned sectors and critical infrastructure. To this end, we employ such information to attribute Internet-scale maliciousness to such sectors and realms, in an attempt to provide an in-depth analysis of the global cyber situational posture. We draw upon close to 16.8 TB of darknet data to infer probing activities (typically generated by malicious/infected hosts) and DDoS backscatter, from which we distill IP addresses of victims. By executing week-long measurements, we observed an alarming number of more than 11,000 probing machines and 300 DDoS attack victims hosted by critical sectors. We also generate rare insights related to the maliciousness of various business sectors, including financial, which typically do not report their hosted and targeted illicit activities for reputation-preservation purposes. While we treat the obtained results with strict confidence due to obvious sensitivity reasons, we postulate that such generated cyber threat intelligence could be shared with sector/critical infrastructure operators, backbone networks and Internet service providers to contribute to the overall threat remediation objective. Martin Husák, Nataliia Neshenko, Morteza Safaei Pour, Elias Bou-Harb, Pavel Celeda |
ARES | 1 |
| 2018 | CRUSOE: Data Model for Cyber Situational AwarenessabstractAttaining and keeping cyber situational awareness is crucial for the proper incident response, especially in critical infrastructures. Incident handlers need to process heterogeneous data, such as network topology and organisation's missions and objectives, to effectively mitigate the threats. The development of tools for attaining cyber situational awareness often faces the problem of effectively obtaining, correlating, and storing such heterogeneous data. In this paper, we present CRUSOE, an extensible layered data model for attaining and keeping information on cyber situational awareness. We conducted interviews with incident handlers from several security teams and evaluated existing requirements on cyber situational awareness to formalise the requirements on the proposed data model so that can be used in today's common network settings. The CRUSOE data model keeps track of missions, systems, networks, hosts, threats, detection and response capabilities, and access control in a network of an organisation. It is also designed to be filled primarily with the data that can be obtained in a semi- or fully-automated fashion in today's common network environments. Jana Komárková, Martin Husák, Martin Lastovicka, Daniel Tovarnák |
ARES | 2 |
| 2018 | Towards Predicting Cyber Attacks Using Information Exchange and Data MiningabstractIn this paper, we present an empirical evaluation of an approach to predict attacker's activities based on information exchange and data mining. We gathered the cyber security alerts shared within the SABU platform, in which around 220,000 alerts from heterogeneous geographically distributed sensors (intrusion detection systems and honeypots) are shared every day. Subsequently, we used the methods of sequential rule mining to identify common attack patterns and to derive rules for predicting attacks. As we illustrate in this paper, a collaborative environment allows attack prediction in multiple dimensions. First, we can predict what will the attacker do next and when. Second, we can predict where will the attack hit, e.g., when an attacker is targeting several networks at once. In a weeklong experiment, we processed in total over 1 million alerts, from which we mined predictive rules every day. Our findings show that most of the rules display stable values of support and confidence and, thus, can be used to predict cyber attacks in consecutive days after mining without a need to actualize the rules every day. Martin Husák, Jaroslav Kaspar |
IWCMC | 1 |
| 2018 | Rapid prototyping of flow-based detection methods using complex event processingabstractDetection of network attacks is the first step to network security. Many different methods for attack detection were proposed in the past. However, descriptions of these methods are often not complete and it is difficult to verify that the actual implementation matches the description. In this demo paper, we propose to use Complex Event Processing (CEP) for developing detection methods based on network flows. By writing the detection methods in an Event Processing Language (EPL), we can address the above-mentioned problems. The SQL-like syntax of most EPLs is easily readable so the detection method is self-documented. Moreover, it is directly executable in the CEP system, which eliminates inconsistencies between documentation and implementation. The demo will show a running example of a multi-stage HTTP brute force attack detection using Esper and its EPL. Petr Velan, Martin Husák, Daniel Tovarnák |
NOMS | 2 |
| 2017 | On the Sequential Pattern and Rule Mining in the Analysis of Cyber Security AlertsabstractData mining is well-known for its ability to extract concealed and indistinct patterns in the data, which is a common task in the field of cyber security. However, data mining is not always used to its full potential among cyber security community. In this paper, we discuss usability of sequential pattern and rule mining, a subset of data mining methods, in an analysis of cyber security alerts. First, we survey the use case of data mining, namely alert correlation and attack prediction. Subsequently, we evaluate sequential pattern and rule mining methods to find the one that is both fast and provides valuable results while dealing with the peculiarities of security alerts. An experiment was performed using the dataset of real alerts from an alert sharing platform. Finally, we present lessons learned from the experiment and a comparison of the selected methods based on their performance and soundness of the results. Martin Husák, Jaroslav Kaspar, Elias Bou-Harb, Pavel Celeda |
ARES | 1 |
| 2017 | Protection of personal data in security alert sharing platformsabstractIn order to ensure confidentiality, integrity and availability (so called CIA triad) of data within network infrastructure, it is necessary to be able to detect and handle cyber security incidents. For this purpose, it is vital for Computer Security Incident Response Teams (CSIRT) to have enough data on relevant security events and threats. That is why CSIRTs share security alerts and incidents data using various sharing platforms. Even though they do so primarily to protect data and privacy of users, their use also lead to additional processing of personal data, which may cause new privacy risks. European data protection law, especially with the adoption of the new General data protection regulation, sets out very strict rules on processing of personal data which on one hand leads to greater protection of individual's rights, but on the other creates great obstacles for those who need to share any personal data. This paper analyses the General Data Protection Regulation (GDPR), relevant case-law and analyses by the Article 29 Working Party to propose optimal methods and level of personal data processing necessary for effective use of security alert sharing platforms, which would be legally compliant and lead to appropriate balance between risks. Václav Stupka, Martin Horák, Martin Husák |
ARES | 3 |
| 2017 | A graph-based representation of relations in network security alert sharing platformsabstractIn this paper, we present a framework for graph-based representation of relation between sensors and alert types in a security alert sharing platform. Nodes in a graph represent either sensors or alert types, while edges represent various relations between them, such as common type of reported alerts or duplicated alerts. The graph is automatically updated, stored in a graph database, and visualized. The resulting graph will be used by network administrators and security analysts as a visual guide and situational awareness tool in a complex environment of security alert sharing. Martin Husák, Milan Cermák |
IM | 1 |
| 2017 | Exchanging security events: Which and how many alerts can we aggregate?abstractThe exchange of security alerts is a current trend in network security and incident response. Alerts from network intrusion detection systems are shared among organizations so that it is possible to see the “big picture” of current security situation. However, the quality and redundancy of the input data seem to be underrated. We present four use cases of aggregation of the alerts from network intrusion detection systems. Alerts from a sharing platform deployed in the Czech national research and education network were examined in a case study. Volumes of raw and aggregated data are presented and a rule of thumb is proposed: up to 85% of alerts can be aggregated. Finally, we discuss the practical implications of alert aggregation for the network intrusion detection system, such as (in)completeness of the alerts and optimal time windows for aggregation. Martin Husák, Milan Cermák, Martin Lastovicka, Jan Vykopal |
IM | 1 |
| 2017 | Network defence strategy evaluation: Simulation vs. live networkabstractA lot of research has been dedicated to finding an optimal strategy to defend network infrastructure. The proposed methods are usually evaluated using simulations, replayed attacks or testbed environments. However, these evaluation methods may give biased results, because in real life, attackers can follow a suboptimal strategy or react to a defence in an unexpected way. In this paper, we use a network of honeypots as a testing environment for evaluating network defence strategies. The honeypot network provides the opportunity to test a defence strategy against real attackers and is not as time and resource consuming as using white hat hackers. In our experiment, we use two different strategies to defend a group of honeypots in a live network and we compare these results to the results of a simulation with replayed attacks. We show that the results of the strategies in the simulation significantly differ from the results on the honeypot network which implies simulations are not sufficient for strategy evaluation. We also investigate how the attacker adapts to the responses taken by a defence strategy and how this change in behaviour affects the evaluation results. Jana Medková, Martin Husák, Martin Drasar |
IM | 2 |
| 2017 | Honeypot testbed for network defence strategy evaluationabstractIn this paper, we describe a network defence strategy testbed, which could be utilized for testing the strategy decision logic against simulated attacks or real attackers. The testbed relies on a network of honeypots and the high level of logging and monitoring the honeypots provide. Its main advantage is that only the decision logic implementation is needed in order to test the strategy. The testbed also evaluates the tested network defence strategy. We demonstrate an example of network defence strategy implementation, the test setup, progress, and results. The source code of the testbed is available on GitHub. Jana Medková, Martin Husák, Martin Vizváry, Pavel Celeda |
IM | 2 |
| 2017 | Honeypots and honeynets: issues of privacyabstractHoneypots and honeynets are popular tools in the area of network security and network forensics. The deployment and usage of these tools are influenced by a number of technical and legal issues, which need to be carefully considered. In this paper, we outline the privacy issues of honeypots and honeynets with respect to their technical aspects. The paper discusses the legal framework of privacy and legal grounds to data processing. We also discuss the IP address, because by EU law, it is considered personal data. The analysis of legal issues is based on EU law and is supported by discussions on privacy and related issues. Pavol Sokol, Jakub Mísek, Martin Husák |
EURASIP J. Inf. Secur. | 3 |
| 2016 | HTTPS traffic analysis and client identification using passive SSL/TLS fingerprintingabstractThe encryption of network traffic complicates legitimate network monitoring, traffic analysis, and network forensics. In this paper, we present real-time lightweight identification of HTTPS clients based on network monitoring and SSL/TLS fingerprinting. Our experiment shows that it is possible to estimate the User-Agent of a client in HTTPS communication via the analysis of the SSL/TLS handshake. The fingerprints of SSL/TLS handshakes, including a list of supported cipher suites, differ among clients and correlate to User-Agent values from a HTTP header. We built up a dictionary of SSL/TLS cipher suite lists and HTTP User-Agents and assigned the User-Agents to the observed SSL/TLS connections to identify communicating clients. The dictionary was used to classify live HTTPS network traffic. We were able to retrieve client types from 95.4 % of HTTPS network traffic. Further, we discussed host-based and network-based methods of dictionary retrieval and estimated the quality of the data. Martin Husák, Milan Cermák, Tomás Jirsík, Pavel Celeda |
EURASIP J. Inf. Secur. | 1 |
| 2015 | Network-Based HTTPS Client Identification Using SSL/TLS FingerprintingabstractThe growing share of encrypted network traffic complicates network traffic analysis and network forensics. In this paper, we present real-time lightweight identification of HTTPS clients based on network monitoring and SSL/TLS fingerprinting. Our experiment shows that it is possible to estimate the User-Agent of a client in HTTPS communication via the analysis of the SSL/TLS handshake. The fingerprints of SSL/TLS handshakes, including a list of supported cipher suites, differ among clients and correlate to User-Agent values from a HTTP header. We built up a dictionary of SSL/TLS cipher suite lists and HTTP User-Agents and assigned the User-Agents to the observed SSL/TLS connections to identify communicating clients. We discuss host-based and network-based methods of dictionary retrieval and estimate the quality of the data. The usability of the proposed method is demonstrated on two case studies of network forensics. Martin Husák, Milan Cermák, Tomás Jirsík, Pavel Celeda |
ARES | 1 |
| 2015 | Security Monitoring of HTTP Traffic Using Extended FlowsabstractIn this paper, we present an analysis of HTTP traffic in a large-scale environment which uses network flow monitoring extended by parsing HTTP requests. In contrast to previously published analyses, we were the first to classify patterns of HTTP traffic which are relevant to network security. We described three classes of HTTP traffic which contain brute-force password attacks, connections to proxies, HTTP scanners, and web crawlers. Using the classification, we were able to detect up to 16 previously undetectable brute-force password attacks and 19 HTTP scans per day in our campus network. The activity of proxy servers and web crawlers was also observed. Symptoms of these attacks may be detected by other methods based on traditional flow monitoring, but detection using the analysis of HTTP requests is more straightforward. We, thus, confirm the added value of extended flow monitoring in comparison to the traditional method. Martin Husák, Petr Velan, Jan Vykopal |
ARES | 1 |
| 2015 | Deploying Honeypots and Honeynets: Issue of PrivacyabstractHoney pots and honey nets are popular tools in the area of network security and network forensics. The deployment and usage of these tools are influenced by a number of technical and legal issues, which need to be carefully considered together. In this paper, we outline privacy issues of honey pots and honey nets with respect to technical aspects. The paper discusses the legal framework of privacy, legal ground to data processing, and data collection. The analysis of legal issues is based on EU law and is supported by discussions on privacy and related issues. This paper is one of the first papers which discuss in detail privacy issues of honey pots and honey nets in accordance with EU law. Pavol Sokol, Martin Husák, Frantiek Liptak |
ARES | 2 |
| 2014 | PhiGARo: Automatic Phishing Detection and Incident Response FrameworkabstractWe present a comprehensive framework for automatic phishing incident processing and work in progress concerning automatic phishing detection and reporting. Our work is based upon the automatic phishing incident processing tool PhiGARo which locates users responding to phishing attack attempts and prevents access to phishing sites from the protected network. Although PhiGARo processes the phishing incidents automatically, it depends on reports of phishing incidents from users. We propose a framework which introduces honey pots into the process in order to eliminate the reliance on user input. The honey pots are used to capture e-mails, automatically detect messages containing phishing and immediately transfer them to PhiGARo. There is a need to propagate e-mail addresses of a honey pot to attract phishers. We discuss approaches to the honey pot e-mail propagation and propose a further enhancement to using honey pots in response to phishing incidents. We propose providing phishers with false credentials, accounts and documents that will grant them access to other honey pot services. Tracing these honey tokens may lead us to the originators of the phishing attacks and help investigations into phishing incidents. Martin Husák, Jakub Cegan |
ARES | 1 |
| 2014 | Cloud-based security research testbed: A DDoS use caseabstractIn this paper we present a cloud-based research testbed designed to aid network security managers. The testbed enables operators to emulate various network topologies, services, and to analyze attacks threatening these systems. A possibility to test results of network management measures is desired, since testing these measures in a production environment is always not possible. We demonstrate a testbed use case, which aids to scrutinize network behavior under attack. Our use case is based on a large DDoS attack which targeted network infrastructure and web servers in Czech Republic in March, 2013. Tomás Jirsík, Martin Husák, Pavel Celeda, Zdenek Eichler |
NOMS | 2 |
| 2013 | Reflected attacks abusing honeypotsabstractWe present the observation of distributed denial-of-service attacks that use reflection of the flooding traffic off reflectors. This type of attack was used in massive attacks against internet infrastructure of Czech Republic in March, 2013. Apart from common hosts in the network, honeypots were abused as the reflectors. It caused the false positive incident detection and helped attackers. Honeypots, which are by default set to accept any incoming network connection, unintentionally amplified the effect of reflection. We present an analysis of the attack from the point of view of honeypots and show the risks of having honeypots respond to any incoming traffic. We also discuss the possibilities of attack detection and mitigation and present lessons learned from handling the attack. We point out a lack of communication and data sharing during the observed attack. Martin Husák, Martin Vizváry |
CCS | 1 |
| 2008 | New [47, 15, 16] Linear Binary Block CodeabstractA new$[47,15,16]$linear binary block code and its weight spectrum is presented. The code is better than the previously known$[47,15,15]$code and it reaches the upper bound on code distance for the codeword length$47$and dimension$15$. Martin Janosov, Martin Husák, Peter Farkas, Ana García Armada |
IEEE Trans. Inf. Theory | 2 |