Petr Matousek

dblp:56/5421 · DBLP profile ↗
← Back
13ranked-venue papers
6as first author
7since 2021 · last 2025
0000-0003-4589-2041ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 3 first-author · 2 since 2021Computer networks · 3 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2025 Poster: Multi-Agent LLM System for Cisco Router Configuration
abstract
Every network device has a configuration file containing the current settings and operational functionality such as IP addresses, running routing processes, and filtering rules. When new functionality is requested, the network administrator updates the configuration file by adding new commands. This process can be automated using an LLM model that understands the configuration language and can generate the relevant configuration commands. This paper presents a multi-agent LLM system that generates network configurations. Our approach uses a sequence of LLM-based agents to decompose the original configuration task, expressed in natural language, into logical subtasks, which are then translated into configuration commands. The proposed LLM-based configuration generation process includes validation and suggests sanity tests to eliminate potential errors. We demonstrate our approach by generating Cisco IOS configuration files for multiple devices. We also propose a dataset of non-trivial reference configurations for evaluating generation accuracy.
Michal Rozsíval, Petr Matousek, Jaromír Kotala
NCA2
2024 Experience Report: Using JA4+ Fingerprints for Malware Detection in Encrypted Traffic
abstract
Detection of malware communications is limited due to encryption. Malware control, updates, and distribution are encapsulated in TLS tunnels, making it difficult to distinguish between malicious and benign transmissions. One way, how to detect malware communication, is to analyze the TLS handshake and obtain so-called JA4+ fingerprints. This report analyses the effectiveness of JA4+ fingerprints for malware detection, focusing specifically on the JA4, JA4S, and JA4X fingerprints and their accuracy. It examines the process of creating malware fingerprints and explores the uniqueness of these fingerprints across different malware families and their ability to distinguish between malicious and benign applications. By examining the overlap and uniqueness, the study evaluates the effectiveness of using JA4+ fingerprints to detect malware in encrypted communications.
Petr Matousek, Ondrej Rysavý, Ivana Burgetová
CNSM1
2024 Penetrating the Power Grid: Realistic Adversarial Attacks on Smart Grid Intrusion Detection Systems
Nelson Makau Mutua, Simin Nadjm-Tehrani, Petr Matousek
CRITIS3
2022 Metering Homes: Do Energy Efficiency and Privacy Need to Be in Conflict?
abstract
The European directive on energy efficiency requires that all meters in multi-apartment buildings installed after 25 October 2020 shall be remotely readable devices where technically feasible and cost effective in terms of being proportionate in relation to the potential energy savings. In practise, this means that some manufacturers produce meters that monitor energy consumption in very short intervals, for example, less than two minutes; even though the directive expects to provide billing information to consumers only once a month starting from 2022. This paper reviews privacy and security risks stemming from the short readouts and provides recommendations for manufacturers and suppliers. The paper focuses on a Wireless M-Bus metering devices that we observed being sold and advertised as the solution to fulfill the European directive on energy efficiency requirements. Nevertheless, we believe that many recommendations and observations are applicable also to other protocols.
Libor Polcak, Petr Matousek
SECRYPT2
2021 Anomaly Detection of ICS Communication Using Statistical Models
abstract
Industrial Control System (ICS) transmits control and monitoring data between devices in an industrial environment that includes smart grids, water and gas distribution, or traffic control. Unlike traditional internet communication, ICS traffic is stable, periodical, and with regular communication patterns that can be described using statistical modeling. By observing selected features of ICS transmission, e.g., packet direction and inter-arrival times, we can create a statistical profile of the communication based on distribution of features learned from the normal ICS traffic. This paper demonstrates that using statistical modeling, we can detect various anomalies caused by irregular transmissions, device or link failures, and also cyber attacks like packet injection, scanning, or denial of service (DoS). The paper shows how a statistical model is automatically created from a training dataset. We present two types of statistical profiles: the master-oriented profile for one-to-many communication and the peer-to-peer profile that describes traffic between two ICS devices. The proposed approach is fast and easy to implement as a part of an intrusion detection system (IDS) or an anomaly detection (AD) module. The proof-of-concept is demonstrated on two industrial protocols: IEC 60870-5-104 (aka IEC 104) and IEC 61850 (Goose).
Ivana Burgetová, Petr Matousek, Ondrej Rysavý
CNSM2
2021 Efficient Modelling of ICS Communication For Anomaly Detection Using Probabilistic Automata
Petr Matousek, Vojtech Havlena, Lukás Holík
IM1
2021 Unified SNMP Interface for IoT Monitoring
Petr Matousek, Ondrej Rysavý, Libor Polcak
IM1
2020 On Reliability of JA3 Hashes for Fingerprinting Mobile Applications
Petr Matousek, Ivana Burgetová, Ondrej Rysavý, Malombe Victor
ICDF2C1
2020 Flow based monitoring of ICS communication in the smart grid
Petr Matousek, Ondrej Rysavý, Matej Grégr, Vojtech Havlena
J. Inf. Secur. Appl.1
2016 Experimental Evaluation of Password Recovery in Encrypted Documents
Radek Hranicky, Petr Matousek, Ondrej Rysavý, Vladimír Veselý
ICISSP2
2015 Advanced Techniques for Reconstruction of Incomplete Network Data
Petr Matousek, Jan Pluskal, Ondrej Rysavý, Vladimír Veselý, Martin Kmet, Filip Karpísek, Martin Vymlátil
ICDF2C1
2014 Comment on "Remote Physical Device Fingerprinting"
abstract
In this paper we revisited a method to identify computers by their clocks skew computed from TCP timestamps. We introduced our own tool to compute clock skew of computers in a network. We validated that the original method is suitable for the computer identification but we also discovered that Linux hosts running NTP had become immune to the identification.
Libor Polcak, Jakub Jirasek, Petr Matousek
IEEE Trans. Dependable Secur. Comput.3
2011 Practical IPv6 monitoring-challenges and techniques
abstract
Network monitoring is an essential task of network management. Information obtained by monitoring devices gives a real picture of the network in production including transmitted data volumes, top hosts, a list of frequently used applications etc. Deep analysis of data collected by monitoring can reveal network attacks or detect misuse of network services. In addition, Data Retention Act requires each ISP to track user's activities. Protocol IPv6 puts new challenges for network administrators in the context of user identification. Unlike IPv4, an IPv6 address no longer uniquely identifies a user or PC. IPv6 address can be randomly generated and keeps changing in time. PCs with IPv6 stack can also communicate via predefined tunnels over IPv4 infrastructure. That tunneled traffic mostly bypasses network security implemented via firewalls. In this paper, we identify major monitoring and security issues of IPv6 connectivity and propose a solution based on SNMP and Netflow data that helps to uniquely identify users. The solution requires an extended set of monitoring data to be collected from network devices. We present a new data structure based on extended Netflow records. Feasibility of the approach is demonstrated on the Brno University of Technology (BUT) campus network.
Matej Grégr, Petr Matousek, Miroslav Svéda, Tomas Podermanski
Integrated Network Management2