Radek Fujdiak

dblp:169/3624 · DBLP profile ↗
← Back
12ranked-venue papers
1as first author
6since 2021 · last 2025
0000-0002-8319-0633ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 8 · 1 first-author · 5 since 2021Computer networks · 3Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Analyzing anomalies in industrial networks: A data-driven approach to enhance security in manufacturing processes
abstract
Industrial networks are adapted to their specific requirements, especially in terms of industrial processes. To ensure sufficient security in these networks, it is necessary to set and use security policies that complement government regulations, recommendations, and relevant security standards. This paper aims to provide an in-depth analysis of the anomalies occurring within the networks and propose a structure for collecting valuable data from the experimental site based on dividing anomalies into three main categories: security, operational, and service anomalies (and regular traffic recognition). We present a proof-of-concept solution/design aggregating data in industrial networks for advanced anomaly classification. Multiple data sources such as industrial communication, sensor data (additional sensors controlling device behavior), and HW status data are used as data sources. A total of three scenarios (using a physical testbed) were implemented, where we achieved an accuracy of 0.8541/0.9972 in advanced anomaly classification.
Karel Kuchar, Radek Fujdiak
Comput. Secur.2
2024 Event-based Data Collection and Analysis in the Cyber Range Environment
abstract
The need to educate users on cybersecurity to some extent is critical due to the ever-increasing cyber threats. A number of web presentations, books, and other study materials can be used for this purpose. In contrast to passive learning methods, hands-on training offers a deeper perspective but poses considerable technical challenges to its implementation, which can be resolved using cyber range platforms. However, in order to thoroughly evaluate the training and provide sufficient feedback, data must be collected and analyzed. Our paper addresses this problem by developing an event-based approach for data collection and analysis. The use of events allows us to keep a history of an event and reconstruct it retrospectively, especially for further analysis and evaluation. We validated the implemented approach in a cyber range environment, in which we developed an interactive interface to visualize the analyzed data.
Willi Lazarov, Samuel Janek, Zdenek Martinasek, Radek Fujdiak
ARES4
2024 Identification of industrial devices based on payload
abstract
Identification of industrial devices based on their behavior in network communication is important from a cybersecurity perspective in two areas: attack prevention and digital forensics. In both areas, device identification falls under asset management or asset tracking. Due to the impact of active scanning on these networks, particularly in terms of latency, it is important to use passive scanning in industrial networks. For passive identification, statistical learning algorithms are nowadays the most appropriate. The aim of this paper is to demonstrate the potential for passive identification of PLC devices using statistical learning based on network communication, specifically the payload of the packet. Individual statistical parameters from 15 minutes of traffic based on payload entropy were used to create the features. Three scenarios were performed and the XGBoost algorithm was used for evaluation. In the best scenario, the model achieved an accuracy score of 83% to identify individual devices.
Ondrej Pospisil, Radek Fujdiak
ARES2
2024 Training Scenario for Security Testing of the Kerberos Protocol
Willi Lazarov, Antonin Bohacik, David Kohout, Radek Fujdiak
IEA/AIE4
2022 Authentication for Operators of Critical Medical Devices: A Contribution to Analysis of Design Trade-offs
abstract
Increasingly evident safety risks due to attacks on safety-critical devices are causing new requirements for authentication of these devices’ human operators. These requirements have now extended to medical devices. However, authentication may also introduce new safety risks, reduce usability, cause delays, and/or encourage user behaviors that compromise the very security it should protect. Thus, design of authentication mechanisms needs to take on a holistic approach that considers such interrelationships, and the effects not just of the general method chosen (say, passwords vs. fingerprints), but also of its implementation details. We illustrate this problem on a medical case study. We report early steps in a trade-off analysis that captures interactions between safety, security, usability and performance issues, to assist designers in choosing and tuning viable solutions. A qualitative analysis to narrow down the field of possible solutions is followed by a probabilistic analysis. The analyses highlight non-obvious links between system attributes, especially links due to the complex way humans interact with, and adapt to, such devices. The probabilistic analysis systematically describes risk as a function of the authentication method and its design parameters. We show example results quantifying how some key design parameters produce opposite effects on risk due to accidental and malicious causes, requiring a trade-off: the quantitative model allows the designer to manage this trade-off to achieve an acceptable level of overall risk, taking into account environmental factors like the expected prevalence of certain attack types. Both the qualitative and quantitative approaches aim to help device designers make rational decisions about authentication options and the tuning of their design parameters.
Marwa Gadala, Lorenzo Strigini, Radek Fujdiak
ARES3
2021 Analysis and detection of application-independent slow Denial of Service cyber attacks
abstract
This paper investigates current application-independent slow Denial of Service (DoS) attacks. We propose Slowcomm and Slow Next attack models and present an attack simulation tool. We used this tool for vulnerability testing of several Internet services, including Hypertext Transfer Protocol (HTTP), File Transfer Protocol (FTP), and Secure Shell (SSH) servers. We also propose attack signatures and detection methods. We implemented these methods as an Intrusion Detection System (IDS) and tested them in an experimental network. Our testing revealed vulnerabilities in five of the six tested servers that caused the denial of service to legitimate users. Deployment of the proposed attack detector has shown a high detection success. We conclude that there is a need to increase the level of cybersecurity. Internet services are vulnerable to these new DoS attacks. Our analysis can be used for the security development of tested services. Our detector in combination with a network traffic filtering tool can be used to mitigate the attacks and keep the service available to Internet users.
Marek Sikora, Radek Fujdiak, Jiri Misurec
ISI2
2020 Communication Performance of a Real-Life Wide-Area Low-Power Network Based on Sigfox Technology
abstract
In this paper, we study real-world performance of Sigfox, which is one of the most mature Low-Power Wide-Area Network (LPWAN) technologies that operate in unlicensed frequency bands. During an extensive measurement campaign conducted over three months in the city of Brno, Czech Republic, we assessed the communication performance and the radio channel properties in 311 different test locations. We observed that despite the challenging natural landscape and urban environment of the test area, more than 94% of the packets sent were received successfully, with at least one packet delivered from 297 out of 311 tested locations. Our results also reported experiment-based radio channel and signal-to-noise characterization as well as provided insights into the efficiency of two crucial mechanisms used by Sigfox to improve the packet delivery - packet repetition and multi-gateway reception. Finally, we employed our experimental data to understand the efficiency of two non-fingerprint localization methods based on received signal strength indicator in a practical Sigfox network.
Konstantin Mikhaylov, Martin Stusek, Pavel Masek, Radek Fujdiak, Radek Mozny, Sergey Andreev 0001, Jiri Hosek
ICC4
2020 On the Performance of Multi-Gateway LoRaWAN Deployments: An Experimental Study
abstract
A remarkable progress in the Low Power Wide Area Network (LPWAN) technologies over the recent years opens new opportunities for developing versatile massive Internet of Things (IoT) applications. In this paper, we focus on one of the most popular LPWAN technologies operating in the license-exempt frequency bands, named LoRaWAN. The key contribution of this study is our unique set of results obtained during an extensive measurement campaign conducted in the city of Brno, Czech Republic. During a three-months-period, the connectivity of a public Long Range Wide Area Network (LoRaWAN) with more than 20 gateways (GWs) was assessed at 231 test locations. This paper presents an analysis of the obtained results, aimed at capturing the effects related to the spatial diversity of the GW locations and the real-life multi-GW network operation with all its practical features. One of our findings is the fact that only for 47% tested locations the GW featuring the minimum geographical distance demonstrated the highest received signal strength and signal-to-noise ratio (SNR). Also, our results captured and characterized the variations in the received signal strength indicator (RSSI) and SNR as a function of the communication distance in an urban environment, and illustrated the distribution of the spreading factors (SFs) as a result of the adaptive data rate (ADR) algorithm operation in a real-life multi-GW deployment.
Konstantin Mikhaylov, Martin Stusek, Pavel Masek, Radek Fujdiak, Radek Mozny, Sergey Andreev 0001, Jiri Hosek
WCNC4
2019 A Secure Publish/Subscribe Protocol for Internet of Things
abstract
The basic concept behind the emergence of Internet of Things (IoT) is to connect as many objects to the Internet as possible in an attempt to make our lives better in some way. However, connecting everyday objects like your car or house to the Internet can open up major security concerns. In this paper, we present a novel security framework for the Message Queue Transport Telemetry (MQTT) protocol based on publish/subscribe messages in order to enhance secure and privacy-friendly Internet of Things services. MQTT has burst onto the IoT scene in recent years due to its lightweight design and ease of use implementation necessary for IoT. Our proposed solution provides 3 security levels. The first security level suits for lightweight data exchanges of non-tampered messages. The second security level enhances the privacy protection of data sources and data receivers. The third security level offers robust long-term security with mutual authentication for all parties. The security framework is based on light cryptographic schemes in order to be suitable for constrained and small devices that are widely used in various IoT use cases. Moreover, our solution is tailored to MQTT without using additional security overhead.
Lukas Malina, Gautam Srivastava 0001, Petr Dzurenda, Jan Hajny, Radek Fujdiak
ARES5
2019 Energy Attack in LoRaWAN: Experimental Validation
abstract
Myriads of new devices take their places around us every single day, making a decisive step towards bringing the concept of the Internet of Things (IoT) in reality. The Low Power Wide Area Networks (LPWANs) are today considered to be one of the most perspective connectivity enablers for the resource and traffic limited IoT. In this paper, we focus on one of the most widely used LPWAN technologies, named LoRaWAN. Departing from the traditional data-focused security attacks, in this study we investigate the robustness of LoRaWAN against energy (depletion) attacks. For many IoT devices, the energy is a limited and very valuable resource, and thus in the near future the device's energy may become the target of an intentional attack. Therefore, in the paper, we first define and discuss the possible energy attack vectors, and then experimentally validate the feasibility of an energy attack over one of these vectors. Our results decisively show that energy attacks in LoRaWAN are possible and may cause the affected device to lose a substantial amount of energy. Specifically, depending on the device's SF (Spreading Factor), the demonstrated attack increased the total energy consumption during a single communication event 36% to 576%. Importantly, the shown attack does not require the attacker to have any keys or other confidential data and can be carried against any LoRaWAN device. The presented results emphasize the importance of energy security for LPWANs in particular, and IoT in general.
Konstantin Mikhaylov, Radek Fujdiak, Ari Pouttu, Miroslav Voznak, Lukas Malina, Petr Mlynek
ARES2
2018 On Track of Sigfox Confidentiality with End-to-End Encryption
abstract
The last years brought many novel challenges for the Internet of Things (IoT). Low capital and operational expenditures, massive deployments of devices, reliability and security are among the most crucial ones. The recently introduced Low-power wide area (LPWA) technologies provide one possible way of addressing these challenges. In the current paper, we focus on one of the most mature LPWA technology, namely Sigfox. We provide a brief security assessment of this technology and highlight the main security imperfections. Notably, we also consider the recent changes introduced in the last revision of the Sigfox specification released in the fourth quarter of 2017. Importantly, this paper discusses the highlighted issues and compares three selected cryptographic encryption solutions (AES, ChaCha and OTP) in respect to the main IoT triad of performance, security and cost. We investigate the encryption solutions and characterize their energy consumption in a real-life implementation. The results herein presented are useful for understanding the cost of enabling security aspects and enable selecting the most efficient encryption protocol.
Radek Fujdiak, Petr Blazek, Konstantin Mikhaylov, Lukas Malina, Petr Mlynek, Jiri Misurec, Vojtech Blazek
ARES1
2016 On perspective of security and privacy-preserving solutions in the internet of things
Lukas Malina, Jan Hajny, Radek Fujdiak, Jiri Hosek
Comput. Networks3