EDBT 2026 Demo / reviewers in the wild / expert
Daniel Tovarnák
dblp:128/5703
· DBLP profile ↗
19ranked-venue papers
7as first author
12since 2021 · last 2025
0000-0002-7206-5167ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 since 2021Human-computer interaction and ubiquitous computing · 3 · 2 since 2021Computer networks · 2 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Taming Trillions of Events: Automated Security Telemetry Analysis at ScaleabstractThe need of organizations for good network and security visibility remains a critical priority. However, due to the scale and complexity of modern networks, the amount of security telemetry data poses a significant challenge in terms of their ingestion, processing, storage, and analysis. After a decade of experience and several years of development, we will showcase the capabilities of an interoperable, production-proven data platform addressing these challenges. It is capable of sifting through trillions of stored security telemetry events at brilliant speeds, while supporting easy creation of automated analytical scenarios. Daniel Tovarnák, Matús Racek, Martin Gregorík, Martin Hamerník, Michal Cech |
CNSM | 1 |
| 2024 | The True Cost of Network Security Automation: Demo Playbook for Posture AssessmentabstractThe desire of organizations to better understand, automate, and streamline their core processes is undoubtedly not newfound, and it is far from exclusive to the cybersecurity domain. However, in recent years, the lack of skilled professionals and the ever-increasing number of attacks triggered a surge of vendors, products, and standardization efforts in the SOAR area. This work aims to show that while security orchestration is perfectly feasible via modern orchestration systems, it is the automation of the individual activities that conceals most of the complexity. To this effect, we will showcase an end-to-end execution of a custom playbook for network security posture assessment. Daniel Tovarnák, Michal Cech, Vojtech Dohnal, Martin Hamerník, Matús Racek, Dusan Tichý |
NOMS | 1 |
| 2022 | Current Challenges of Cyber Threat and Vulnerability Identification Using Public EnumerationsabstractIdentification of cyber threats is one of the essential tasks for security teams. Currently, cyber threats can be identified using knowledge organized into various formats, enumerations, and knowledge bases. This paper studies the current challenges of identifying vulnerabilities and threats in cyberspace using enumerations and data about assets. Although enumerations are used in practice, we point out several issues that still decrease the quality of vulnerability and threat identification. Since vulnerability identification methods are based on network monitoring and agents, the issues are related to the asset discovery, the precision of vulnerability discovery, and the amount of data. On the other hand, threat identification utilizes graph-based, nature-language, machine-learning, and ontological approaches. The current trend is to propose methods that utilize tactics, techniques, and procedures instead of low-level indicators of compromise to make cyber threat identification more mature. Cooperation between standards from threat, vulnerability, and asset management is also an unresolved issue confirmed by analyzing relationships between public enumerations and knowledge bases. Last, we studied the usability of techniques from the MITRE ATT&CK knowledge base for threat modeling using network monitoring to capture data. Although network traffic is not the most used data source, it allows the modeling of almost all tactics from the MITRE ATT&CK. Lukás Sadlek, Pavel Celeda, Daniel Tovarnák |
ARES | 3 |
| 2022 | Identification of Attack Paths Using Kill Chain and Attack GraphsabstractThe ever-evolving capabilities of cyber attackers force security administrators to focus on the early identification of emerging threats. Targeted cyber attacks usually consist of several phases, from initial reconnaissance of the network environment to final impact on objectives. This paper investigates the identification of multi-step cyber threat scenarios using kill chain and attack graphs. Kill chain and attack graphs are threat modeling concepts that enable determining weak security defense points. We propose a novel kill chain attack graph that merges kill chain and attack graphs together. This approach determines possible chains of attacker’s actions and their materialization within the protected network. The graph generation uses a categorization of threats according to violated security properties. The graph allows determining the kill chain phase the administrator should focus on and applicable countermeasures to mitigate possible cyber threats. We implemented the proposed approach for a predefined range of cyber threats, especially vulnerability exploitation and network threats. The approach was validated on a real-world use case. Publicly available implementation contains a proof-of-concept kill chain attack graph generator. Lukás Sadlek, Pavel Celeda, Daniel Tovarnák |
NOMS | 3 |
| 2022 | HTTPS Event-Flow Correlation: Improving Situational Awareness in Encrypted Web TrafficabstractAchieving situational awareness is a challenging process in current HTTPS-dominant web traffic. In this paper, we propose a new approach to encrypted web traffic monitoring. First, we design a method for correlating host-based and network monitoring data based on their common features and a correlation time-window. Then we analyze the correlation results in detail to identify configurations of web servers and monitoring infrastructure that negatively affect the correlation. We describe these properties and possible data preprocessing techniques to minimize their impact on correlation performance. Furthermore, to test the correlation method’s behavior in different web server setups and for recent encryption protocols, we modify it by adapting the correlation features to TLS 1.3 and QUIC. Finally, we evaluate the correlation method on a dataset collected from a campus network. The results show that while the correlation requires monitoring of custom event and flow features, it remains feasible even when using encryption protocols designed for the near future. Stanislav Spacek, Petr Velan, Pavel Celeda, Daniel Tovarnák |
NOMS | 4 |
| 2022 | ObservableDB: An Inverted Index for Graph-Based Traversal of Cyber Threat IntelligenceabstractIn this paper, we address the lack of analytical tools and search interfaces, which would help both humans and machines to navigate and correlate the floods of heterogeneous cyber threat intelligence (CTI) data generated every day. This work supports our long-term goal of machine-assisted discovery and inference of detectable indicators for adversarial tactics, techniques, and procedures from the available CTI. In particular, we present the idea of an observable database that works as an inverted index for CTI. This observable-centric concept is supported by a fully-functional practical result that leverages a meta-programming approach to auto-generate a graph-based API for data search and manipulation. The created prototype allows for powerful graph-based filtering, traversal and retrieval of the stored cyber observables and the referenced CTI. Daniel Tovarnák, Michal Cech, Dusan Tichý, Vojtech Dohnal |
NOMS | 1 |
| 2021 | System for Continuous Collection of Contextual Information for Network Security Management and Incident HandlingabstractIn this paper, we describe a system for the continuous collection of data for the needs of network security management. When a cybersecurity incident occurs in the network, the contextual information on the involved assets facilitates estimating the severity and impact of the incident and selecting an appropriate incident response. We propose a system based on the combination of active and passive network measurements and the correlation of the data with third-party systems. The system enumerates devices and services in the network and their vulnerabilities via fingerprinting of operating systems and applications. Further, the system pairs the hosts in the network with contacts on responsible administrators and highlights critical infrastructure and its dependencies. The system concentrates all the information required for common incident handling procedures and aims to speed up incident response, reduce the time spent on the manual investigation, and prevent errors caused by negligence or lack of information. Martin Husák, Martin Lastovicka, Daniel Tovarnák |
ARES | 3 |
| 2021 | Cloud Native Data Platform for Network Telemetry and AnalyticsabstractIn this manuscript, we present a prototype of a modular data platform that is able to continuously ingest, process, retain, and analyse large amounts of network telemetry data in a scalable and straightforward manner. It follows a recently proposed Data Lakehouse architectural pattern, which is an evolution of two well-known approaches used in this area – data warehouses and data lakes. The platform is based on open standards and open-source components, and it follows cloud native principles in order to be able to run in modern computing environments such as public, private, and hybrid clouds. The primary focus of the prototype is network telemetry and analytics over traffic flows and infrastructure logs for the purposes of cyber-security digital forensics and incident response. During the demonstration part, we will further describe internal workings of the presented data platform and showcase its capabilities and possible applications on a public dataset. Daniel Tovarnák, Matús Racek, Petr Velan |
CNSM | 1 |
| 2021 | Toolset for Collecting Shell Commands and Its Application in Hands-on Cybersecurity TrainingabstractThis Full Paper in the Innovative Practice category presents and evaluates a technical innovation for hands-on classes. When learning cybersecurity, operating systems, or networking, students perform practical tasks using a broad range of command-line tools. Collecting and analyzing data about the command usage can reveal valuable insights into how students progress and where they make mistakes. However, few learning environments support recording and inspecting command-line inputs, and setting up an efficient infrastructure for this purpose is challenging. To aid engineering and computing educators, we share the design and implementation of an open-source toolset for logging commands that students execute on Linux machines. Compared to basic solutions, such as shell history files, the toolset's novelty and added value are threefold. First, its configuration is automated so that it can be easily used in classes on different topics. Second, it collects metadata about the command execution, such as a timestamp, hostname, and IP address. Third, all data are instantly forwarded to central storage in a unified, semi-structured format. This enables automated processing of the data, both in real-time and post hoc, to enhance the instructors' understanding of student actions. The toolset works independently of the teaching content, the training network's topology, or the number of students working in parallel. We demonstrated the toolset's value in two learning environments at four training sessions. Over two semesters, 50 students played educational cybersecurity games using a Linux command-line interface. Each training session lasted approximately two hours, during which we recorded 4439 shell commands. The semiautomated data analysis revealed different solution patterns, used tools, and misconceptions of students. Our insights from creating the toolset and applying it in teaching practice are relevant for instructors, researchers, and developers of learning environments. We provide the software and data resulting from this work so that others can use them in their hands-on classes. Valdemar Svábenský, Jan Vykopal, Daniel Tovarnák, Pavel Celeda |
FIE | 3 |
| 2021 | Scalable Learning Environments for Teaching Cybersecurity Hands-onabstractThis Innovative Practice full paper describes a technical innovation for scalable teaching of cybersecurity hands-on classes using interactive learning environments. Hands-on experience significantly improves the practical skills of learners. However, the preparation and delivery of hands-on classes usually do not scale. Teaching even small groups of students requires a substantial effort to prepare the class environment and practical assignments. Further issues are associated with teaching large classes, providing feedback, and analyzing learning gains. We present our research effort and practical experience in designing and using learning environments that scale up hands-on cybersecurity classes. The environments support virtual networks with full-fledged operating systems and devices that emulate realworld systems. The classes are organized as simultaneous training sessions with cybersecurity assignments and learners' assessment. For big classes, with the goal of developing learners' skills and providing formative assessment, we run the environment locally, either in a computer lab or at learners' own desktops or laptops. For classes that exercise the developed skills and feature summative assessment, we use an on-premises cloud environment. Our approach is unique in supporting both types of deployment. The environment is described as code using open and standard formats, defining individual hosts and their networking, configuration of the hosts, and tasks that the students have to solve. The environment can be repeatedly created for different classes on a massive scale or for each student on-demand. Moreover, the approach enables learning analytics and educational data mining of learners' interactions with the environment. These analyses inform the instructor about the student's progress during the class and enable the learner to reflect on a finished training. Thanks to this, we can improve the student class experience and motivation for further learning. Using the presented environments KYPO Cyber Range Platform and Cyber Sandbox Creator, we delivered the classes on-site or remotely for various target groups of learners (K-12, university students, and professional learners). The learners value the realistic nature of the environments that enable exercising theoretical concepts and tools. The instructors value time-efficiency when preparing and deploying the hands-on activities. Engineering and computing educators can freely use our software, which we have released under an open-source license. We also provide detailed documentation and exemplary hands-on training to help other educators adopt our teaching innovations and enable sharing of reusable components within the community. Jan Vykopal, Pavel Celeda, Pavel Seda, Valdemar Svábenský, Daniel Tovarnák |
FIE | 5 |
| 2021 | Graph-Based CPE Matching for Identification of Vulnerable Asset Configurations
Daniel Tovarnák, Lukás Sadlek, Pavel Celeda |
IM | 1 |
| 2021 | Enriching DNS Flows with Host-Based Events to Bypass Future Protocol Encryption
Stanislav Spacek, Daniel Tovarnák, Pavel Celeda |
SEC | 2 |
| 2019 | An Algorithm for Message Type Discovery in Unstructured Log DataabstractLog message abstraction is a common way of dealing with the unstructured nature of log data. It refers to the separation of static and dynamic part of the log message, so that both parts can be accessed independently, allowing the message to be abstracted into a more structured representation. To facilitate this task, so-called message types and the corresponding matching patterns must be first discovered, and only after that can be this pattern-set used to pattern-match individual log messages in order to extract dynamic information and impose some structure on them. Because the manual discovery of message types is a tiresome and error-prone process, we have focused our research on data mining algorithms that are able to discover message types in already generated log data. Since we have identified several deficiencies of the existing algorithms, which are limiting their capabilities, we propose a novel algorithm for message type discovery addressing these deficiencies. Daniel Tovarnák |
ICSOFT | 1 |
| 2019 | Normalization of Unstructured Log Data into Streams of Structured Event Objects
Daniel Tovarnák, Tomás Pitner |
IM | 1 |
| 2018 | CRUSOE: Data Model for Cyber Situational AwarenessabstractAttaining and keeping cyber situational awareness is crucial for the proper incident response, especially in critical infrastructures. Incident handlers need to process heterogeneous data, such as network topology and organisation's missions and objectives, to effectively mitigate the threats. The development of tools for attaining cyber situational awareness often faces the problem of effectively obtaining, correlating, and storing such heterogeneous data. In this paper, we present CRUSOE, an extensible layered data model for attaining and keeping information on cyber situational awareness. We conducted interviews with incident handlers from several security teams and evaluated existing requirements on cyber situational awareness to formalise the requirements on the proposed data model so that can be used in today's common network settings. The CRUSOE data model keeps track of missions, systems, networks, hosts, threats, detection and response capabilities, and access control in a network of an organisation. It is also designed to be filled primarily with the data that can be obtained in a semi- or fully-automated fashion in today's common network environments. Jana Komárková, Martin Husák, Martin Lastovicka, Daniel Tovarnák |
ARES | 4 |
| 2018 | Rapid prototyping of flow-based detection methods using complex event processingabstractDetection of network attacks is the first step to network security. Many different methods for attack detection were proposed in the past. However, descriptions of these methods are often not complete and it is difficult to verify that the actual implementation matches the description. In this demo paper, we propose to use Complex Event Processing (CEP) for developing detection methods based on network flows. By writing the detection methods in an Event Processing Language (EPL), we can address the above-mentioned problems. The SQL-like syntax of most EPLs is easily readable so the detection method is self-documented. Moreover, it is directly executable in the CEP system, which eliminates inconsistencies between documentation and implementation. The demo will show a running example of a multi-stage HTTP brute force attack detection using Esper and its EPL. Petr Velan, Martin Husák, Daniel Tovarnák |
NOMS | 3 |
| 2017 | Lessons learned from complex hands-on defence exercises in a cyber rangeabstractWe need more skilled cybersecurity professionals because the number of cyber threats and ingenuity of attackers is ever growing. Knowledge and skills required for cyber defence can be developed and exercised by lectures and lab sessions, or by active learning, which is seen as a promising and attractive alternative. In this paper, we present experience gained from the preparation and execution of cyber defence exercises involving various participants in a cyber range. The exercises follow a Red vs. Blue team format, in which the Red team conducts malicious activities against emulated networks and systems that have to be defended by Blue teams of learners. Although this exercise format is popular and used worldwide by numerous organizers in practice, it has been sparsely researched. We contribute to the topic by describing the general exercise life cycle, covering the exercise's development, dry run, execution, evaluation, and repetition. Each phase brings several challenges that exercise organizers have to deal with. We present lessons learned that can help organizers to prepare, run and repeat successful events systematically, with lower effort and costs, and avoid a trial-and-error approach that is often used. Jan Vykopal, Martin Vizváry, Radek Oslejsek, Pavel Celeda, Daniel Tovarnák |
FIE | 5 |
| 2017 | KYPO Cyber Range: Design and Use CasesabstractThe physical and cyber worlds are increasingly intertwined and exposed to cyber attacks. The KYPO cyber range provides complex cyber systems and networks in a virtualized, fully controlled and monitored environment. Time-efficient and cost-effective deployment is feasible using cloud resources instead of a dedicated hardware infrastructure. This paper describes the design decisions made during it’s development. We prepared a set of use cases to evaluate the proposed design decisions and to demonstrate the key features of the KYPO cyber range. It was especially cyber training sessions and exercises with hundreds of participants which provided invaluable feedback for KYPO platform development. Jan Vykopal, Radek Oslejsek, Pavel Celeda, Martin Vizváry, Daniel Tovarnák |
ICSOFT | 5 |
| 2016 | A performance benchmark for NetFlow data analysis on distributed stream processing systemsabstractModern distributed stream processing systems can potentially be applied to real time network flow processing. However, differences in performance make some systems more suitable than others for being applied to this domain. We propose a novel performance benchmark, which is based on common security analysis algorithms of NetFlow data to determine the suitability of distributed stream processing systems. Three of the most used distributed stream processing systems are bench-marked and the results are compared with NetFlow data processing challenges and requirements. The benchmark results show that each system reached a sufficient data processing speed using a basic deployment scenario with little to no configuration tuning. Our benchmark, unlike any other, enables the performance of small structured messages to be processed on any stream processing system. Milan Cermák, Daniel Tovarnák, Martin Lastovicka, Pavel Celeda |
NOMS | 2 |