Tomás Cejka

dblp:152/5893 · DBLP profile ↗
← Back
33ranked-venue papers
2as first author
25since 2021 · last 2026
0000-0001-7794-9511ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 6 since 2021Security and privacy · 5 · 2 since 2021Systems, architecture and hardware · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 PerQoDA: strength of association between data and labels as a measure of dataset quality in network traffic classification
Katarzyna Wasielewska, Dominik Soukup, Tomás Cejka, Joe Carthy, José Camacho 0001
Appl. Intell.3
2026 Comparative Analysis of Deep Learning Models for Real-World ISP Network Traffic Forecasting
abstract
Accurate network traffic forecasting is crucial for internet service providers to optimize resources, improve user experience, and detect anomalies. Until recently, the lack of large-scale, real-world datasets limited the fair evaluation of forecasting methods. The newly released CESNET-TimeSeries24 dataset addresses this gap by providing multivariate traffic data from thousands of devices over 40 weeks at multiple aggregation granularities and hierarchy levels. In this study, we leverage the CESNET-TimeSeries24 dataset to conduct a systematic evaluation of state-of-the-art deep learning models and provide practical insights. Moreover, our analysis reveals trade-offs between prediction accuracy and computational efficiency across different levels of granularity. Beyond model comparison, we establish a transparent and reproducible benchmarking framework, releasing source code and experiments to encourage standardized evaluation and accelerate progress in network traffic forecasting research.
Josef Koumar, Timotej Smolen, Kamil Jerábek, Tomás Cejka
IEEE Trans. Netw. Serv. Manag.4
2026 Universal Embedding Function for Traffic Classification via QUIC Domain Recognition Pretraining: A Transfer Learning Success
Jan Luxemburk, Karel Hynek, Richard Plný, Tomás Cejka
IEEE Trans. Netw. Serv. Manag.4
2025 DAF: Device Annotation Framework
Matej Hulák, Václav Bartos, Josef Koumar, Tomás Cejka
CNSM4
2025 Botnet Detection Through Periodic Patterns in Command-and-Control Network Traffic
abstract
Detecting botnet Command-and-Control (C&C) communication in encrypted network traffic is a persistent challenge in cybersecurity, particularly in environments without endpoint visibility. We present a novel approach for botnet detection based on the inherent periodic communication patterns of C&C channels. Leveraging the Lomb-Scargle periodogram, we identify periodic behaviour in multiflow time series and extract periodic-based features for classification using machine learning. To address limitations in existing datasets, we introduce CESNET-CC25, a comprehensive and publicly available dataset comprising real-world botnet C&C traffic and benign traffic collected from an ISP backbone and controlled laboratory settings. Our method achieves high precision across both the widely used CTU-13 dataset and CESNET-CC25, with significant improvements in recall on long-duration captures. The results demonstrate that periodicity is a reliable indicator of C&C behaviour, even in modern, encrypted network environments, and that CESNET-CC25 provides a realistic benchmark for future botnet detection research.
Dominik Oskera, Josef Koumar, Alzbeta Pokorná, Kamil Jerábek, Tomás Cejka
CNSM5
2025 Transferability of TCP/IP-based OS fingerprinting models
Matej Hulák, Václav Bartos, Tomás Cejka
Networking3
2025 Towards Building Network Outlier Detection System for Network Traffic Monitoring
abstract
Traffic monitoring is important for supporting network security and management. Recent advancements have explored machine learning-based approaches to classify encrypted traffic, yet the challenge of obtaining current threat datasets persists, leaving supervised models reliant on outdated information. Outlier detection, which identifies anomalous network behavior without requiring labeled data, addresses this limitation by flagging suspicious deviations from expected patterns. This paper proposes a novel Network Outlier Detection System (NODS), a platform based on open-source software designed to detect outliers in network traffic by leveraging forecasting models. Our system was deployed and tested on a large ISP infrastructure. The evaluation of detected outliers over a one-month period showed key insights into system performance and provided valuable lessons for future deployment of outlier detection methods. This paper details the architecture of NODS, deployment, and performance while highlighting the challenges and lessons learned in building an effective outlier detection system for network traffic.
Josef Koumar, Jaroslav Pesek, Kamil Jerábek, Tomás Cejka
NOMS4
2025 Interpretable Threat Detection with Evidential Classifier: The MQTT Case
abstract
We propose a universal method for threat detection with a set-valued evidential classification based on Dempster-Shafer theory and deep learning. Our approach is designed to handle the inherent uncertainty in threat detection by incorporating extended flow features and packet metadata, making it adaptable to various protocols and environments. To demonstrate its benefit, we apply the method to the threats in the MQTT protocol, which is widely used in the IoT environment for its lightweight character. Our method significantly reduces the number of false security alerts, with a zero false positive rate achieved in most cases. Additionally, the evidential framework provides interpretable outputs that allow for thorough post-event analysis, enabling a clear understanding of the evidence supporting each decision, which is crucial in security-sensitive applications.
Jaroslav Pesek, Kensuke Fukuda, Tomás Cejka
NOMS3
2025 Multichannel Histograms for Flow Classification
abstract
Encrypted traffic poses increasing challenges for effective network monitoring and management. To address this, machine learning and deep learning techniques are commonly applied to encrypted traffic classification by analyzing the statistical properties of network flows, such as packet lengths and inter-arrival times. Rather than relying on point estimates of these properties, we aim to obtain a comprehensive view of the distribution using histograms. In this paper, we propose and analyze a multichannel 2D histogram representation that incorporates packet lengths, directions, and inter-arrival times, extending the prior well-performing flowpic representation. We classify these histograms using a 2D convolutional neural network with residual connections, improving classification accuracy over previous methods.
Daniel Poliakov, Kamil Jerábek, Dusan Kolár, Tomás Cejka
NOMS4
2024 MFWDD: Model-based Feature Weight Drift Detection Showcased on TLS and QUIC Traffic
abstract
Machine learning (ML) represents an efficient and popular approach for network traffic classification. However, network traffic inspection is a challenging domain and trained models may degrade soon after deployment. Besides biases present during data captures and model creation, data drifts contribute significantly to ML model degradation. This paper proposes a novel method called Model-based Feature Weight Drift Detection (MFWDD) for concept drift detection. It is a part of a public software framework suited for dataset drift analysis tailored to the domain of network traffic. This work addresses TLS and QUIC service classification problems, examines a variety of experiments analyzing the evolution of the respective distributions, and observes their degradation over time on different ML features. The MFWDD framework guided TLS and QUIC services classification models retraining throughout an extensive period and not only prevented model degradation but also improved its performance and consistency over time.
Lukás Jancicka, Dominik Soukup, Josef Koumar, Filip Nemec, Tomás Cejka
CNSM5
2024 LGBM2VHDL: Mapping of LightGBM Models to FPGA
abstract
Gradient boosting (GB) is an effective and widely used type of ensemble machine-learning method. The opportunity to transform the trained GB models to the hardware level represents the potential for significant acceleration of many applications and their availability as embedded systems. In this work, we have therefore developed the LGBM2VHDL tool for the automated mapping of models trained by the LightGBM library to circuits described by VHDL. Compared to existing tools, we have used an architecture that is better suited for large-scale GB models involving up to thousands of decision trees. We have further optimized the architecture using two newly proposed techniques. By applying these techniques to the tested models, the amount of memory required was significantly reduced to almost half of the original resources, and the amount of basic configurable blocks was reduced by up to 4 times on average. The developed tool is available as open-source.
Tomás Martínek, Jan Korenek, Tomás Cejka
FCCM3
2024 Analysis of Statistical Distribution Changes of Input Features in Network Traffic Classification Domain
abstract
This study investigates the evolving landscape of network traffic monitoring, which is crucial for maintaining computer network services and security. Traditional methods like Deep Packet Inspection (DPI) face challenges due to increased privacy protection through encryption, prompting a shift towards statistical-based detection using Machine Learning (ML). On the other hand, ML struggles with long-term evaluation due to various distribution changes. This study focuses on the CESNET-TLS-Year22 dataset, derived from one year of TLS network traffic on the CESNET2 backbone. Described research explores the behavior of modern protocols in real-world scenarios and their impact on dataset quality. The main result of our analysis is the identification of the Weekend phenomenon in network traffic classification that is generally overlooked during ML model training.
Lukás Jancicka, Josef Koumar, Dominik Soukup, Tomás Cejka
NOMS4
2024 TCI: A system for distributed network monitoring, troubleshooting and dataset creation
abstract
Network traffic monitoring is a very complex task that requires a combination of multiple tools and teams. Very often, detected events must be validated and confirmed, or ongoing detection needs additional detailed data from full packets. All these activities must be done automatically concerning data privacy. This is why we propose a solution in the form of Traffic Capture Infrastructure (TCI), a single system for network traffic capture, investigation, and dataset creation, even in high-speed provider networks. Our system supports extensive user management features to ensure dataset privacy, system integrity, and unified control over many network probes. This paper presents the architecture, main functions, recommendations, and lessons learnt from full packet monitoring in today’s networks. Lastly, we prove the value of this system with several publications that have used our system to create their underlying dataset and network traffic investigation.
Dominik Soukup, Jaroslav Pesek, Lukás Hejcman, David Benes, Tomás Cejka
NOMS5
2024 NetTiSA: Extended IP flow with time-series features for universal bandwidth-constrained high-speed network traffic classification
abstract
Network traffic monitoring based on IP Flows is a standard monitoring approach that can be deployed to various network infrastructures, even the large ISP networks connecting millions of people. Since flow records traditionally contain only limited information (addresses, transport ports, and amount of exchanged data), they are also commonly extended by additional features that enable network traffic analysis with high accuracy. These flow extensions are, however, often too large or hard to compute, which then allows only offline analysis or limits their deployment only to smaller-sized networks. This paper proposes a novel extended IP flow called NetTiSA (Network Time Series Analysed) flow, based on analysing the time series of packet sizes. By thoroughly testing 25 different network traffic classification tasks, we show the broad applicability and high usability of NetTiSA flow. For practical deployment, we also consider the sizes of flows extended by NetTiSA features and evaluate the performance impacts of their computation in the flow exporter. The novel features proved to be computationally inexpensive and showed excellent discriminatory performance. The trained machine learning classifiers with proposed features mostly outperformed the state-of-the-art methods. NetTiSA finally bridges the gap and brings universal, small-sized, and computationally inexpensive features for traffic classification that can be scaled up to extensive monitoring infrastructures, bringing the machine learning traffic classification even to 100 Gbps backbone lines.
Josef Koumar, Karel Hynek, Jaroslav Pesek, Tomás Cejka
Comput. Networks4
2023 Look at my Network: An Insight into the ISP Backbone Traffic
abstract
High-speed ISP networks provide several challenges that prevent the creation of long-term datasets for giving insight into the traffic. Currently, there are no publicly available long-term datasets capturing the entirety of high-speed ISP networks. Such networks are traditionally monitored using IP Flows, which provide enough high-level information about the situation in the network and support various use cases, such as the detection of outages or security threats. Even with this type of aggregation long-term datasets are very unpractical due to their size. The other problem is that flow monitoring comes with significant aggregation and common traffic statistics are brief and lack useful details and require further processing. This paper addresses these problems and presents a new long-term aggregated dataset, a detailed analysis of public network traffic measured on the ISP backbone, and a monitoring architecture composed of open-source tools capable of using an existing flow exporter infrastructure. Such insight into traffic helps to design and develop hardware optimizations, tuning the performance of monitoring systems, and adapting security detection algorithms.
Tomás Benes, Jaroslav Pesek, Tomás Cejka
CNSM3
2023 Network Traffic Classification Based on Single Flow Time Series Analysis
abstract
Network traffic monitoring using IP flows is used to handle the current challenge of analyzing encrypted network communication. Nevertheless, the packet aggregation into flow records naturally causes information loss; therefore, this paper proposes a novel flow extension for traffic features based on the time series analysis of the Single Flow Time series, i.e., a time series created by the number of bytes in each packet and its timestamp. We propose 69 universal features based on the statistical analysis of data points, time domain analysis, packet distribution within the flow timespan, time series behavior, and frequency domain analysis. We have demonstrated the usability and universality of the proposed feature vector for various network traffic classification tasks using 15 well-known publicly available datasets. Our evaluation shows that the novel feature vector achieves classification performance similar or better than related works on both binary and multiclass classification tasks. In more than half of the evaluated tasks, the classification performance increased by up to 5 %.
Josef Koumar, Karel Hynek, Tomás Cejka
CNSM3
2023 Enhancing DeCrypto: Finding Cryptocurrency Miners Based on Periodic Behavior
abstract
While the popularity of cryptocurrencies and the whole industry's value are rising, the number of threat actors who use illegal “coin miner mal ware” is increasing as well. The threat actors commonly use computational resources of companies, research and educational institutions, or end users. In this paper, we analyzed the long-term periodic behavior of the cryptocurrency miners communicating in computer networks. We propose a novel method for cryptominers detection using specially designed periodicity features. The detection algorithm is based on the mathematical detection of periodic Flow time series (FTS) and feature mining. Altogether with the Machine Learning technique, the resulting system achieves high-precision performance. Furthermore, our approach enhances a flow-based cryptominers detection system DeCrypto to further improve its reliability and feasibility for high-speed networks.
Josef Koumar, Richard Plný, Tomás Cejka
CNSM3
2023 Machine Learning Metrics for Network Datasets Evaluation
Dominik Soukup, Daniel Uhrícek, Daniel Vasata, Tomás Cejka
SEC4
2023 Fine-grained TLS services classification with reject option
abstract
The recent success and proliferation of machine learning and deep learning have provided powerful tools, which are also utilized for encrypted traffic analysis, classification, and threat detection in computer networks. These methods, neural networks in particular, are often complex and require a huge corpus of training data. Therefore, this paper focuses on collecting a large up-to-date dataset with almost 200 fine-grained service labels and 140 million network flows extended with packet-level metadata. The number of flows is three orders of magnitude higher than in other existing public labeled datasets of encrypted traffic. The number of service labels, which is important to make the problem hard and realistic, is four times higher than in the public dataset with the most class labels. The published dataset is intended as a benchmark for identifying services in encrypted traffic. Service identification can be further extended with the task of “rejecting” unknown services, i.e., the traffic not seen during the training phase. Neural networks offer superior performance for tackling this more challenging problem. To showcase the dataset’s usefulness, we implemented a neural network with a multi-modal architecture, which is the state-of-the-art approach, and achieved 97.04% classification accuracy and detected 91.94% of unknown services with 5% false positive rate.
Jan Luxemburk, Tomás Cejka
Comput. Networks2
2023 BOTA: Explainable IoT Malware Detection in Large Networks
abstract
Explainability and alert reasoning are essential but often neglected properties of intrusion detection systems. The lack of explainability reduces security personnel’s trust, limiting the overall impact of alerts. This article proposes the botnet analysis (BOTA) system, which uses the concepts of weak indicators and heterogeneous meta-classifiers to maintain accuracy compared with state-of-the-art systems while also providing explainable results that are easy to understand. To evaluate the proposed system, we have implemented a demonstration of intrusion weak-indication detectors, each working on a different principle to ensure robustness. We tested the architecture with various real-world and lab-created data sets, and it correctly identified 94.3% of infected Internet of Things (IoT) devices without false positives. Furthermore, the implementation is designed to work on top of extended bidirectional flow data, making it deployable on large 100-Gb/s large-scale networks at the level of Internet Service Providers. Thus, a single instance of BOTA can protect millions of devices connected to end-users’ local networks and significantly reduce the threat arising from powerful IoT botnets.
Daniel Uhrícek, Karel Hynek, Tomás Cejka, Dusan Kolár
IEEE Internet Things J.3
2022 Network traffic classification based on periodic behavior detection
abstract
Even though encryption hides the content of communication from network monitoring and security systems, this paper shows a feasible way to retrieve useful information about the observed traffic. The paper deals with detection of periodic behavioral patterns of the communication that can be detected using time series created from network traffic by autocorrelation function and Lomb-Scargle periodogram. The revealed characteristics of the periodic behavior can be further exploited to recognize particular applications. We have experimented with the created dataset of 61 classes, and trained a machine learning classifier based on XGBoost that performed the best in our experiments, reaching 90% F1-score.
Josef Koumar, Tomás Cejka
CNSM2
2022 Tunneling through DNS over TLS providers
abstract
DNS over TLS (DoT) is one of the approaches for private DNS resolution, which has already gained support by open resolvers. Moreover, DoT is used by default in Android operating systems. This study investigates the possibility of creating DNS covert channels using DoT, which is a security threat that benefits from the increased privacy of encrypted communication. We evaluated the performance and usability of DoT tunnels created via commonly used resolvers. Our results show that the performance characteristics of DoT tunnels differ vastly depending on the used DoT resolver; however, the creation of a DoT tunnel is possible, reaching speeds up to 232 Kbps. Moreover, we successfully transferred data via DoT servers claiming Anti-Virus protection and family-friendly content.
Lukás Melcher, Karel Hynek, Tomás Cejka
CNSM3
2022 Large Scale Analysis of DoH Deployment on the Internet
Sebastián García, Joaquín Bogado, Karel Hynek, Dmitrii Vekshin, Tomás Cejka, Armin Wasicek
ESORICS (3)5
2021 Towards Evaluating Quality of Datasets for Network Traffic Domain
abstract
This paper deals with the quality of network traffic datasets created to train and validate machine learning classification and detection methods. Naturally, there is a long epoch of research targeted at data quality; however, it is focused mainly on data consistency, validity, precision, and other metrics, which are insufficient for network traffic use-cases. The rise of Machine learning usage in network monitoring applications requires a new methodology for evaluation datasets. There is a need to evaluate and compare traffic samples captured at different conditions and decide the usability of the already captured and annotated data. This paper aims to explain a use case of dataset creation, propose definitions regarding the quality of the network traffic datasets, and finally, describe a framework for datasets analysis.
Dominik Soukup, Peter Tisovcík, Karel Hynek, Tomás Cejka
CNSM4
2021 Novel HTTPS classifier driven by packet bursts, flows, and machine learning
abstract
Encryption of network traffic recently starts to cover remaining readable information, which is heavily used by current monitoring systems; thus, it is time to focus on novel methods of encrypted traffic analysis and classification. The aim of this paper is to define a new network traffic characteristic called Sequence of packet Burst Length and Time (SBLT), which was inspired by existing approaches and definitions. Contrary to other works, SBLT is feasible even for high-speed backbone networks as a part of IP flow data. The advantage of SBLT features is shown using a machine learning classification model for HTTPS traffic types as an example. This paper presents the definition of SBLT, proposes a new annotated public dataset of HTTPS traffic with 5 categories, and evaluates the developed classifier reaching accuracy over 99 %. This classifier can help analysts to deal with a huge amount of encrypted traffic and maintain situational awareness.
Zdena Tropková, Karel Hynek, Tomás Cejka
CNSM3
2020 DoH Insight: detecting DNS over HTTPS by machine learning
abstract
Over the past few years, a new protocol DNS over HTTPS (DoH) has been created to improve users' privacy on the internet. DoH can be used instead of traditional DNS for domain name translation with encryption as a benefit. This new feature also brings some threats because various security tools depend on readable information from DNS to identify, e.g., malware, botnet communication, and data exfiltration. Therefore, this paper focuses on the possibilities of encrypted traffic analysis, especially on the accurate recognition of DoH. The aim is to evaluate what information (if any) can be gained from HTTPS extended IP flow data using machine learning. We evaluated five popular ML methods to find the best DoH classifiers. The experiments show that the accuracy of DoH recognition is over 99.9 %. Additionally, it is also possible to identify the application that was used for DoH communication, since we have discovered (using created datasets) significant differences in the behavior of Firefox, Chrome, and cloudflared. Our trained classifier can distinguish between DoH clients with the 99.9 % accuracy.
Dmitrii Vekshin, Karel Hynek, Tomás Cejka
ARES3
2020 Pipelined ALU for effective external memory access in FPGA
abstract
The external memories in digital design are closely related to high response time. The most common approach to mitigate latency is adding a caching mechanism into the memory subsystem. This solution might be sufficient in CPU architecture, where we can reschedule operations when a cache miss occurs. However, the FPGA architectures are usually accelerators with simple functionality, where it is not possible to postpone work. The cache miss often leads to whole pipeline stall or even to data loss. The architecture we present in this paper reduces this problem by aggregating arithmetic operations into the memory subsystem itself. Fast data processing is achieved because arithmetic operations working with external data are offloaded. Our architecture reaches a speed of 200 Mp/s (operations carried out). It is designed to be used in systems with link speeds of 100 Gb/s. It outperforms other implementations by a factor of at least 3. The additional benefit of our architecture is reducing the number of memory transactions by a factor of two on real-world datasets.
Tomás Benes, Michal Kekely, Karel Hynek, Tomás Cejka
DSD4
2020 Refined Detection of SSH Brute-Force Attackers Using Machine Learning
Karel Hynek, Tomás Benes, Tomás Cejka, Hana Kubátová
SEC3
2018 Augmented DDoS Mitigation with Reputation Scores
abstract
Network attacks, especially DoS and DDoS attacks, are a significant threat for all providers of services or infrastructure. The biggest attacks can paralyze even large-scale infrastructures of worldwide companies. Attack mitigation is a complex issue studied by many researchers and security companies. While several approaches were proposed, there is still space for improvement. This paper proposes to augment existing mitigation heuristic with knowledge of reputation score of network entities. The aim is to find a way to mitigate malicious traffic present in DDoS amplification attacks with minimal disruption to communication of legitimate traffic.
Tomás Jánský, Tomás Cejka, Martin Zádník, Václav Bartos
ARES2
2016 NEMEA: A framework for network traffic analysis
abstract
Since network attacks become more sophisticated, it is difficult to discover them using traditional analysis tools. For some kinds of attacks, it is necessary to analyze Application Layer (L7) information in order to detect them. However, there is a lack of existing tools capable of L7 processing and manipulation. Therefore, we propose a flow-based modular Network Measurements Analysis (NEMEA) system to overcome the situation. NEMEA is designed with respect to a stream-wise concept, i. e. data are analyzed continuously in memory with minimal data storage. NEMEA is developed as an open-source project and is publicly available for world-wide community. It is designed for both experimental and operational use. It is able to process off-line traffic traces as well as live network flows. The system is very flexible and can be easily extended by new modules. The modules are developed within a NEMEA framework that is a key component of the project. NEMEA thus represents a unified platform for research and development of new traffic analysis methods. It covers several important topics not limited to analysis and detection. Originally, NEMEA has been developed for the purposes of Czech National Research and Education Network operator. Therefore, it is focused on handling high speed network traffic with links working at 100Gbps.
Tomás Cejka, Václav Bartos, Marek Svepes, Zdenek Rosa, Hana Kubátová
CNSM1
2016 Building a feedback loop to capture evidence of network incidents
abstract
Flow measurement is extremely useful in network management, however, in some cases it is vital to observe the packets in full detail. To this end, we propose combining flow measurement, packet capture and network behavioral analysis. The evaluation of the proposed system shows its feasibility even in high-speed network environment.
Zdenek Rosa, Tomás Cejka, Martin Zádník, Viktor Pus
CNSM2
2016 Configuration of open vSwitch using OF-CONFIG
abstract
Software Defined Networking (SDN) became a popular concept where a flexible network architecture is required. One of the widely used approaches to SDN is based on the OpenFlow (OF) protocol that allows controllers to configure OF capable network switches. The OF protocol is focused on a flow-based control of a switch. Besides OF itself, Open Networking Foundation (ONF) has introduced the OF-CONFIG protocol. In contrast, the aim of OF-CONFIG is the configuration of more durable parameters of the controlled switch. However, Open vSwitch (OVS), as the most popular OF switch implementation, uses its own configuration protocol instead of OF-CONFIG. This paper presents results of our analysis of OF-CONFIG and describes design and development of its missing reference implementation. Furthermore, it extends OVS with the OF-CONFIG support, so it provides an opportunity for OF-CONFIG to be more widely used. Our experiences from the analysis and implementation deliver useful feedback to ONF people for further development of OF-CONFIG.
Tomás Cejka, Radek Krejcí
NOMS1
2014 Change-point detection method on 100 Gb/s ethernet interface
abstract
This paper deals with hardware acceleration of statistical methods for detection of anomalies on 100 Gb/s Ethernet. The approach is demonstrated by implementing a sequential Non-Parametric Cumulative Sum (NP-CUSUM) procedure. We use high-level synthesis in combination with emerging software defined monitoring (SDM) methodology for rapid development of FPGA-based hardware-accelerated network monitoring applications. The implemented method offloads detection of network attacks and anomalies directly into an FPGA chip. The parallel nature of FPGA allows for simultaneous detection of various kinds of anomalies. Our results show that hardware acceleration of statistical methods using the SDM concept with high-level synthesis from C/C++ is possible and very promising for traffic analysis and anomaly detection in high-speed 100 Gb/s networks.
Pavel Benácek, Rudolf B. Blazek, Tomás Cejka, Hana Kubátová
ANCS3