Project Details

Analýza šifrovaného provozu pomocí síťových toků

Project Period: 1. 1. 2022 – 30. 6. 2025

Project Type: grant

Code: VJ02010024

Agency: Ministerstvo vnitra ČR

Program: Strategická podpora rozvoje bezpečnostního výzkumu ČR 2019–2025 (IMPAKT 1) PODPROGRAMU 1 SPOLEČNÉ VÝZKUMNÉ PROJEKTY (BV IMP1/2VS)

English title
Flow-based Encrypted Traffic Analysis
Type
grant
Keywords

cyber security, network traffic monitoring, threat detection, SIEM, network
flows, encrypted communication

Abstract

The project focuses on the research of new methods of effective protection
against cyber threats that misuse secured communication for compromise attacks
such as servers and computers in the environment of high-speed networks. Machine
learning methods suitable for determining the characteristics of the encrypted
network flows and associated risks only from available metadata will be
investigated. The system will be implemented using a hardware-accelerated traffic
monitor and a software prototype for high-speed detection of security incidents
and their reporting to the SIEM tool. Further, the incident analysis module in
the form of a plug-in to the QRadar system will be developed. Additionally, the
project outcomes will also include reference data sets of network traffic and
a system for their collection and annotation.

Team members
Publications

2024

2023

Back to top