Stanislav Spacek

dblp:222/7772 · DBLP profile ↗
← Back
9ranked-venue papers
5as first author
5since 2021 · last 2024
0000-0002-7187-5045ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 2 · 2 first-authorSecurity and privacy · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2024 The Evolution of the CRUSOE Toolset: Enhancing Decision Support in Network Security Management
abstract
This demo paper presents the recent development of the CRUSOE toolset. CRUSOE enables cyber situational awareness and provides decision support for network security management. The first public version from 2021 used a combination of active and passive network monitoring to enumerate cyber assets and discover their vulnerabilities, visualize the collected data in a dashboard, conduct a risk assessment to recommend the most resilient infrastructure configuration, and facilitate attack mitigation. It also used novel approaches, such as a graph database for storing the data on cyber assets, which essentially became a knowledge graph for network security management. In the recent development, we managed to automate the deployment of CRUSOE via Ansible and Docker. Further, we implemented additional recommender systems and attack impact assessment capabilities and their visualizations. Finally, several sample datasets were created to facilitate the demonstration of the toolset and to enable testing it without one’s data.
Martin Husák, Lukás Sadlek, Martin Hesko, Vít Sebela, Stanislav Spacek
CNSM5
2023 Event-Flow Correlation for Anomaly Detection in HTTP/3 Web Traffic
abstract
The new HTTP/3 protocol for web traffic was recently released, superseding the widely used HTTP/2. It now supports exclusively encrypted transmissions and brings a lot of other changes. Many of these changes promote user privacy but hinder security monitoring of network traffic. In the past, the direct correlation of events and flows generated by the HTTP/2 web traffic enriched the encrypted network flows with the content from the web server’s event log. In this paper, we modify the event-flow correlation method for the HTTP/3 protocol. Then, we deploy and evaluate the correlation method on a real traffic dataset. We compare the results of the correlation with the results for HTTP/2 and discuss the differences in the correlation of the new protocol compared to the original one. The results show that event-flow correlation can still enrich HTTP/3 network flows, albeit it introduces new challenges to cope with.
Stanislav Spacek, Petr Velan, Martin Holkovic, Tomas Plesnik
NOMS1
2022 HTTPS Event-Flow Correlation: Improving Situational Awareness in Encrypted Web Traffic
abstract
Achieving situational awareness is a challenging process in current HTTPS-dominant web traffic. In this paper, we propose a new approach to encrypted web traffic monitoring. First, we design a method for correlating host-based and network monitoring data based on their common features and a correlation time-window. Then we analyze the correlation results in detail to identify configurations of web servers and monitoring infrastructure that negatively affect the correlation. We describe these properties and possible data preprocessing techniques to minimize their impact on correlation performance. Furthermore, to test the correlation method’s behavior in different web server setups and for recent encryption protocols, we modify it by adapting the correlation features to TLS 1.3 and QUIC. Finally, we evaluate the correlation method on a dataset collected from a campus network. The results show that while the correlation requires monitoring of custom event and flow features, it remains feasible even when using encryption protocols designed for the near future.
Stanislav Spacek, Petr Velan, Pavel Celeda, Daniel Tovarnák
NOMS1
2022 CRUSOE: A toolset for cyber situational awareness and decision support in incident handling
Martin Husák, Lukás Sadlek, Stanislav Spacek, Martin Lastovicka, Michal Javorník, Jana Komárková
Comput. Secur.3
2021 Enriching DNS Flows with Host-Based Events to Bypass Future Protocol Encryption
Stanislav Spacek, Daniel Tovarnák, Pavel Celeda
SEC1
2020 Using TLS Fingerprints for OS Identification in Encrypted Traffic
abstract
Asset identification plays a vital role in situational awareness building. However, the current trends in communication encryption and the emerging new protocols turn the well-known methods into a decline as they lose the necessary data to work correctly. In this paper, we examine the traffic patterns of the TLS protocol and its changes introduced in version 1.3. We train a machine learning model on TLS handshake parameters to identify the operating system of the client device and compare its results to well-known identification methods. We test the proposed method in a large wireless network. Our results show that precise operating system identification can be achieved in encrypted traffic of mobile devices and notebooks connected to the wireless network.
Martin Lastovicka, Stanislav Spacek, Petr Velan, Pavel Celeda
NOMS2
2019 Current Issues of Malicious Domains Blocking
Stanislav Spacek, Martin Lastovicka, Martin Horák, Tomas Plesnik
IM1
2019 DNS Firewall Data Visualization
Stanislav Spacek, Vít Rusnák, Anna-Marie Dombajova
IM1
2018 Passive os fingerprinting methods in the jungle of wireless networks
abstract
Operating system fingerprinting methods are well- known in the domain of static networks and managed environments. Yet few studies tackled this challenge in real networks, where users can bring and connect any device. We evaluate the performance of three OS fingerprinting methods on a large dataset collected from university wireless network. Our results show that method based on HTTP User-agents is the most accurate but can identify only low portion of the traffic. TCP/IP parameters method proved to be the opposite with high coverage but low accuracy. We also implemented a new method based on detection of communication to OS-specific domains. Its performance is comparable to the two established ones. Next, we discuss the impacts of traffic encryption and embracing new protocols such as IPv6 or HTTP/2.0 on OS fingerprinting. Our findings suggest that OS identification based on specific domain detection is viable and corresponds to the current directions of network traffic evolution, while methods based on TCP/IP parameters and User-agents will become ineffective in the future.
Martin Lastovicka, Tomás Jirsík, Pavel Celeda, Stanislav Spacek, Daniel Filakovsky
NOMS4