Mikolaj Komisarek

dblp:271/4840 · DBLP profile ↗
← Back
5ranked-venue papers
5as first author
4since 2021 · last 2024
0000-0003-1459-2695ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 5 first-author · 4 since 2021
YearPublicationVenuePosition
2024 Enhancing Network Security Through Granular Computing: A Clustering-by-Time Approach to NetFlow Traffic Analysis
abstract
This paper presents a study of the effect of the size of the time window from which network features are derived on the predictive ability of a Random Forest classifier implemented as a network intrusion detection component. The network data is processed using granular computing principles, gradually increasing the time windows to allow the detection algorithm to find patterns in the data at different levels of granularity. Experiments were conducted iteratively with time windows ranging in size from 2 to 1024 seconds. Each iteration involved time-based clustering of the data, followed by splitting into training and test sets at a ratio of 67% - 33%. The Random Forest algorithm was applied as part of a 10-fold cross-validation. Assessments included standard detection metrics: accuracy, precision, F1 score, BCC, MCC and recall. The results show a statistically significant improvement in the detection of cyber attacks in network traffic with a larger time window size (p-value 0.001953125). These results highlight the effectiveness of using longer time intervals in network data analysis, resulting in increased anomaly detection.
Mikolaj Komisarek, Marek Pawlicki, Salvatore D'Antonio, Rafal Kozik, Aleksandra Pawlicka, Michal Choras
ARES1
2023 Modern NetFlow network dataset with labeled attacks and detection methods
abstract
Network Intrusion Detection Systems are an important part of cyber-defensive inventory. Currently, Machine-Learning-Based Network Intrusion Detection Systems are being researched as an effective security measure. This paper introduces a novel NetFlow-based dataset geared for the training of machine-learning-based detection systems. The dataset incorporates common cyberattacks such as Denial-of-Service, Port Scanning, and brute-force attacks, which represent significant threats to network security. The efficacy of the dataset is evaluated with the use of four machine learning algorithms, with the detection metrics reported. The dataset is an attempt to fill the vacuum for current, realistic datasets in cybersecurity research. The traffic was collected in a real network in the BTC complex in Ljubljana. The dataset can significantly contribute to enhancing the effectiveness of machine learning-based Network Intrusion Detection Systems.
Mikolaj Komisarek, Marek Pawlicki, Tomi Simic, David Kavcnik, Rafal Kozik, Michal Choras
ARES1
2022 A novel, refined dataset for real-time Network Intrusion Detection
abstract
In this day and age of widespread Internet access, more and more aspects of the economy are becoming dependent on various aspects of network technologies. Cybercrimes are on the rise and massive numbers of network security breaches occur every year. This paper presents network data collected in the Netflow format and its application to detect network attacks. The paper proposes a refined, real-world dataset collected from an academic network. The dataset is a direct result from the experience gained by working on and with the SIMARGL2021 dataset. The applicability of the new dataset is demonstrated on several machine learning algorithms. This novel dataset is open-sourced for researchers to download and use in scientific work.
Mikolaj Komisarek, Marek Pawlicki, Maria-Elena Mihailescu, Darius Mihai, Mihai Carabas, Rafal Kozik, Michal Choras
ARES1
2021 Network Intrusion Detection in the Wild - the Orange use case in the SIMARGL project
abstract
There is a profuse abundance of network security incidents around the world every day. Increasingly, services and data stored on servers fall victim to sophisticated techniques that cause all sorts of damage. Hackers invent new ways to bypass security measures and modify the existing viruses in order to deceive defense systems. Therefore, in response to these illegal procedures, new ways to defend against them are being developed. In this paper, a method for anomaly detection based on machine learning technique is presented and a near real-time processing system architecture is proposed. The main contribution is a test-run of ML algorithms on real-world data coming from a world-class telecom operator. This work investigates the effectiveness of detecting malicious behaviour in network packets using several machine learning techniques. The results achieved are expressed with a set of metrics. For better clarity on the classifier performance, 10-fold cross-validation was used.
Mikolaj Komisarek, Marek Pawlicki, Mikolaj Kowalski, Adrian Marzecki, Rafal Kozik, Michal Choras
ARES1
2020 Real-time stream processing tool for detecting suspicious network patterns using machine learning
abstract
In this paper, the performance of stream processing and accuracy in the prediction of suspicious flows in simulated network traffic is investigated. In addition, concepts of an engine that integrates with novel solutions like the Elastic-search database and Apache Kafka that allows easy definition of streams and implementation of any machine learning algorithm are presented.
Mikolaj Komisarek, Michal Choras, Rafal Kozik, Marek Pawlicki
ARES1