Lukás Sadlek

dblp:222/7825 · DBLP profile ↗
← Back
17ranked-venue papers
7as first author
14since 2021 · last 2026
0000-0003-2577-6633ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 3 first-author · 5 since 2021Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Intelligence Augmentation in a Platform for Cyber Situational Awareness
Lukás Sadlek, Milan Bohácek, Jan Rolínek, Martin Husák
NetSoft1
2025 Fast and Configurable Detection of Device Dependencies in Network Traffic
abstract
Device dependencies are recurring communication patterns between IP addresses that reveal how networked entities rely on one another. Understanding these relationships is essential for reliability, troubleshooting, and security, yet detecting them efficiently from operational traffic remains challenging. We propose a fast and accurate tool for dependency detection from passive flow-level data using a link prediction approach. In contrast to the prior implementation, the tool introduces a parallelized processing pipeline with early termination of stalled random walks, an expanded feature set that combines embedding-derived and graph-theoretic metrics, and a fully externalized configuration of sampling, embedding, and classification parameters. These design choices enable scalable execution and more reliable identification of dependencies across diverse network environments. Evaluation on synthetic traffic from cyber-defense exercises and real-world campus flows demonstrates up to 100$\times$ faster runtime and markedly higher classification accuracy compared to the prior implementation. Further analysis shows that structural graph features improve stability in sparse settings, while extended embedding training enhances accuracy in low-signal scenarios. Together, these results confirm that the proposed tool advances link prediction-based dependency detection toward practical, near-real-time use.
Jakub Dusil, Martin Husák, Lukás Sadlek
CNSM3
2025 The Resilmesh Architecture: Situation Aware Enabled Cyber Resilience for Dispersed, Heterogenous Cyber Systems
abstract
Cyber systems (CyS) are becoming more and more complex as they are comprised of several infrastructure layers, heterogeneous technologies and dispersed deployments over wide geographical areas (cloud/edge/endpoint) that facilitates multiple attack entry points (vectors). At the same time, CyS attacks are constantly evolving and have become more complex and sophisticated. To address these issues, the ResilMesh architecture aims to provide critical infrastructure security teams with a greater cyber resilience capability by improving cyber resilience using Cyber Situational Awareness (CSA) based security orchestration and analytics framework. The framework enables organizations to achieve real-time defense, reducing attack surface impact by developing tools to combat complexity, disperse infrastructure, delivering flexible placement of security controls across the CyS infrastructure. The architecture combats Advanced Persistent Threat (APT) sophistication by leveraging advanced AI algorithms and tools for early and ongoing attack detection and prediction and improved situation. This paper presents the Resilmesh architecture, a first PoC implementation, as well as an evaluation of the Resilmesh capabilities to detect and mitigate APTs.
Jorge Bernal Bernabé, Martin Husák, Lukás Sadlek, Branka Stojanovic, Michael Somma, Jorgeley Inacio de Oliveira, Ekam Puri Nieto, Pablo Fernández Saura, Antonio F. Skarmeta, Vinh Hoa La
NetSoft4
2025 Attack Surface Management: State of the Art and Operational Challenges
abstract
In this paper, we approach the topic of ASM, place the task in the context of cybersecurity operations, review the current methods, and discuss their issues and challenges. We outline an ASM pipeline consisting of common tasks and review the usability of the existing tools. We pinpoint a trade-off between the scope and precision of the existing tools that should be considered, namely in medium to large networks. Finally, we formulate and discuss the issues and challenges for emerging network environments, including those involving IoT or OT, volatile environments, or extensive use of cloud computing. Each of these emerging technologies brings novel issues that need to be approached by ASM, be it improved fingerprinting in IoT and OT, precisely timed scans in volatile environments, or coverage of external services in the cloud.
Martin Husák, Lukás Sadlek
NetSoft2
2025 Severity-based triage of cybersecurity incidents using kill chain attack graphs
Lukás Sadlek, Muhammad Mudassar Yamin, Pavel Celeda, Basel Katt
J. Inf. Secur. Appl.1
2024 Adversary Tactic Driven Scenario and Terrain Generation with Partial Infrastructure Specification
abstract
Diverse, accurate, and up-to-date training environments are essential for training cybersecurity experts and autonomous systems. However, preparation of their content is time-consuming and requires experts to provide detailed specifications. In this paper, we explore the challenges of automated generation of the content (composed of scenarios and terrains) for these environments.
Ádám Ruman, Martin Drasar, Lukás Sadlek, Shanchieh Jay Yang, Pavel Celeda
ARES3
2024 The Evolution of the CRUSOE Toolset: Enhancing Decision Support in Network Security Management
abstract
This demo paper presents the recent development of the CRUSOE toolset. CRUSOE enables cyber situational awareness and provides decision support for network security management. The first public version from 2021 used a combination of active and passive network monitoring to enumerate cyber assets and discover their vulnerabilities, visualize the collected data in a dashboard, conduct a risk assessment to recommend the most resilient infrastructure configuration, and facilitate attack mitigation. It also used novel approaches, such as a graph database for storing the data on cyber assets, which essentially became a knowledge graph for network security management. In the recent development, we managed to automate the deployment of CRUSOE via Ansible and Docker. Further, we implemented additional recommender systems and attack impact assessment capabilities and their visualizations. Finally, several sample datasets were created to facilitate the demonstration of the toolset and to enable testing it without one’s data.
Martin Husák, Lukás Sadlek, Martin Hesko, Vít Sebela, Stanislav Spacek
CNSM2
2024 Hierarchical Modeling of Cyber Assets in Kill Chain Attack Graphs
abstract
Cyber threat modeling is a proactive method for identifying possible cyber attacks on network infrastructure that has a wide range of applications in security assessment, risk analysis, and threat exposure management. Popular modeling methods are kill chains and attack graphs. Kill chains divide attacks into phases, and attack graphs depict attack paths. A difficult issue is how to hierarchically model categories of cyber assets that should be used in threat models due to the variety of cyber systems in the current networks. This task should be addressed to provide automation of realistic threat modeling and interoperability with public knowledge bases, such as MITRE ATT&CK. In this paper, we propose a hierarchical modeling methodology for representing cyber assets in kill chain attack graphs. We illustrate its practical application on MITRE D3FEND’s Digital Artifact Ontology. Moreover, we define how cyber assets with related attack techniques should be transformed into logical facts and attack rules. We implemented proof-of-concept software modules that can process data obtained from network and host-based monitoring together with attack rules to generate attack graphs. We evaluated the approach with data from a cyber exercise captured in a network of a digital twin organization. The results show that the approach is applicable in real-world networks and can reveal ground-truth attacks.
Lukás Sadlek, Martin Husák, Pavel Celeda
CNSM1
2024 Identification of Device Dependencies Using Link Prediction
abstract
Devices in computer networks cannot work without essential network services provided by a limited count of devices. Identification of device dependencies determines whether a pair of IP addresses is a dependency, i.e., the host with the first IP address is dependent on the second one. These dependencies cannot be identified manually in large and dynamically changing networks. Nevertheless, they are important due to possible unexpected failures, performance issues, and cascading effects. We address the identification of dependencies using a new approach based on graph-based machine learning. The approach belongs to link prediction based on a latent representation of the computer network’s communication graph. It samples random walks over IP addresses that fulfill time conditions imposed on network dependencies. The constrained random walks are used by a neural network to construct IP address embedding, which is a space that contains IP addresses that often appear close together in the same communication chain (i.e., random walk). Dependency embedding is constructed by combining values for IP addresses from their embedding and used for training the resulting dependency classifier. We evaluated the approach using IP flow datasets from a controlled environment and university campus network that contain evidence about dependencies. Evaluation concerning the correctness and relationship to other approaches shows that the approach achieves acceptable performance. It can simultaneously consider all types of dependencies and is applicable for batch processing in operational conditions.
Lukás Sadlek, Martin Husák, Pavel Celeda
NOMS1
2023 Cyber Key Terrain Identification Using Adjusted PageRank Centrality
Lukás Sadlek, Pavel Celeda
SEC1
2022 Current Challenges of Cyber Threat and Vulnerability Identification Using Public Enumerations
abstract
Identification of cyber threats is one of the essential tasks for security teams. Currently, cyber threats can be identified using knowledge organized into various formats, enumerations, and knowledge bases. This paper studies the current challenges of identifying vulnerabilities and threats in cyberspace using enumerations and data about assets. Although enumerations are used in practice, we point out several issues that still decrease the quality of vulnerability and threat identification. Since vulnerability identification methods are based on network monitoring and agents, the issues are related to the asset discovery, the precision of vulnerability discovery, and the amount of data. On the other hand, threat identification utilizes graph-based, nature-language, machine-learning, and ontological approaches. The current trend is to propose methods that utilize tactics, techniques, and procedures instead of low-level indicators of compromise to make cyber threat identification more mature. Cooperation between standards from threat, vulnerability, and asset management is also an unresolved issue confirmed by analyzing relationships between public enumerations and knowledge bases. Last, we studied the usability of techniques from the MITRE ATT&CK knowledge base for threat modeling using network monitoring to capture data. Although network traffic is not the most used data source, it allows the modeling of almost all tactics from the MITRE ATT&CK.
Lukás Sadlek, Pavel Celeda, Daniel Tovarnák
ARES1
2022 Identification of Attack Paths Using Kill Chain and Attack Graphs
abstract
The ever-evolving capabilities of cyber attackers force security administrators to focus on the early identification of emerging threats. Targeted cyber attacks usually consist of several phases, from initial reconnaissance of the network environment to final impact on objectives. This paper investigates the identification of multi-step cyber threat scenarios using kill chain and attack graphs. Kill chain and attack graphs are threat modeling concepts that enable determining weak security defense points. We propose a novel kill chain attack graph that merges kill chain and attack graphs together. This approach determines possible chains of attacker’s actions and their materialization within the protected network. The graph generation uses a categorization of threats according to violated security properties. The graph allows determining the kill chain phase the administrator should focus on and applicable countermeasures to mitigate possible cyber threats. We implemented the proposed approach for a predefined range of cyber threats, especially vulnerability exploitation and network threats. The approach was validated on a real-world use case. Publicly available implementation contains a proof-of-concept kill chain attack graph generator.
Lukás Sadlek, Pavel Celeda, Daniel Tovarnák
NOMS1
2022 CRUSOE: A toolset for cyber situational awareness and decision support in incident handling
Martin Husák, Lukás Sadlek, Stanislav Spacek, Martin Lastovicka, Michal Javorník, Jana Komárková
Comput. Secur.2
2021 Graph-Based CPE Matching for Identification of Vulnerable Asset Configurations
Daniel Tovarnák, Lukás Sadlek, Pavel Celeda
IM2
2020 Decision Support for Mission-Centric Network Security Management
abstract
In this paper, we propose a decision support process that is designed to help network and security operators in understanding the complexity of a current security situation and decision making concerning ongoing cyber-attacks and threats. The process focuses on enterprise missions and uses a graph-based mission decomposition model that captures the missions, underlying hosts and services in the network, and functional and security requirements between them. Knowing the vulnerabilities and attacker’s position in the network, the process employs logical attack graphs and Bayesian network to infer the probability of the disruption of the confidentiality, integrity, and availability of the missions. Based on the probabilities of disruptions, the process suggests the most resilient mission configuration that would withstand the current security situation.
Michal Javorník, Jana Komárková, Lukás Sadlek, Martin Husák
NOMS3
2020 Network Monitoring and Enumerating Vulnerabilities in Large Heterogeneous Networks
abstract
In this paper, we present an empirical study on vulnerability enumeration in computer networks using common network probing and monitoring tools. We conducted active network scans and passive network monitoring to enumerate software resources and their version present in the network. Further, we used the data from third-party sources, such as Internet-wide scanner Shodan. We correlated the measurements with the list of recent vulnerabilities obtained from NVD using the CPE as a common identifier used in both domains. Subsequently, we compared the approaches in terms of network coverage and precision of system identification. Finally, we present a sample list of vulnerabilities observed in our campus network. Our work helps in approximating the number of vulnerabilities and vulnerable hosts in large networks, where it is often impractical or costly to perform vulnerability scans using specialized tools, and in situations, where a quick estimate is more important than thorough analysis.
Martin Lastovicka, Martin Husák, Lukás Sadlek
NOMS3
2018 Community based platform for vulnerability categorization
abstract
Many approaches, such as attack graphs, require knowledge of vulnerability's properties such as impact, prereq- uisities, and exploitability. Currently, those properties are either categorized manually or too roughly. We present a program for granular, automated categorization of vulnerability. Further, we present a platform supporting researchers by gathering and sharing raw data about vulnerabilities and community labeled datasets. The source code of our categorization program is available on GitHub.
Jana Komárková, Lukás Sadlek, Martin Lastovicka
NOMS2