Automated attack processing

Reseach leader:Švéda Miroslav
Team leaders:Barabas Maroš, Drahanský Martin, Drozd Michal, Hanáček Petr, Chmelař Petr, Orság Filip
Team members:Antal Lukáš, Bláha Lukáš, Homoliak Ivan
Agency:MPO ČR
Code:FR-TI1/037
Start:2009
End:2013
Keywords:Enterprise networks, Honeypot, KDD-99, behavioral model, signatures
Annotation:
Large-scale computer networks resilience against attacks and malware -- development and implementation of a new method for automatic detection of attacks and malware

Products

2011Linux based Honeypot, software, 2011
Authors: Mlčoch Tomáš, Chmelař Petr, Richter Jan

Related projects

2008Safety and security of networked embedded system applications, GAČR, GA102/08/1429, 2008-2010, completed
Research leader: Srovnal Vilém
Team leaders: Bílek Jan, Švéda Miroslav
2007Security-Oriented Research in Information Technology, CEZ MŠMT, MSM0021630528, 2007-2013, running
Research leader: Hruška Tomáš
Team leaders: Burget Lukáš, Burget Radek, Cvrček Daniel, Černocký Jan, Češka Milan, Drahanský Martin, Dvořák Václav, Fučík Otto, Hanáček Petr, Herout Adam, Hrubý Martin, Janoušek Vladimír, Jaroš Jiří, Kočí Radek, Kolář Dušan, Kořenek Jan, Kotásek Zdeněk, Kršek Přemysl, Křena Bohuslav, Kunovský Jiří, Martínek Tomáš, Masopust Tomáš, Matějka Pavel, Matoušek Petr, Meduna Alexander, Očenášek Pavel, Orság Filip, Růžička Richard, Ryšavý Ondřej, Sekanina Lukáš, Smrž Pavel, Strnadel Josef, Švéda Miroslav, Vojnar Tomáš, Zbořil František, Zbořil František V., Zemčík Pavel, Zendulka Jaroslav

Preceding projects

2005A Framework for Formal Specifications and Prototyping of Information System's Network Applications, GAČR, GA102/05/0723, 2005-2007, completed
Research leader: Švéda Miroslav
Team leaders: Hruška Tomáš, Zendulka Jaroslav
2004Information system security - research of attacks on tamper-resistant cryptographic hardware, GAČR, GA102/04/0871, 2004-2006, completed
Research leader: Hanáček Petr
Team leaders: Cvrček Daniel, Hrubý Martin, Hruška Tomáš, Peringer Petr, Rábová Zdeňka
 Reputation-based Security in Information Systems, MŠMT, 1K04106, 2004-2007, completed
Research leader: Hanáček Petr
Team leaders: Cvrček Daniel

Publications

2013Barabas, M., Homoliak, I., Drozd, M., Hanáček, P.: Automated Malware Detection Based on Novel Network Behavioral Signatures, In: International Journal of Engineering and Technology, Vol. 5, No. 2, 2013, Singapore, SG, p. 249-253, ISSN 1793-8236
 Očenášek, P., Švéda, M.: On the Effective Internet Communication Filtering, In: Applied Mechanics and Materials, Vol. 2013, No. 307, Zurich, CH, p. 478-481, ISSN 1660-9336
 Švéda, M.: Time in Cyber-Physical Systems: Specifications, Modeling and Measurements, In: Proceedings of the SCSI 2013, Rodos, GR, EUROPMENT, 2013, p. 10-17
2012Barabas, M., Drozd, M., Hanáček, P.: Behavioral signature generation using shadow honeypot, In: World Academy of Science, Engineering and Technology, Vol. 2012, No. 65, US, p. 829-833, ISSN 2010-376X
 Chmelař, P., Mlích, J., Pešek, M., Volf, T., Zemčík, P., Zendulka, J.: Brno University of Technology at TRECVid 2012: Interactive Surveillance Event Detection Pilot, In: 2012 TREC Video Retrieval Evaluation Notebook Papers and Slides, Gaithersburg, US, NIST, 2012, p. 1-9
 Očenášek, P., Švéda, M.: Analysis and Filtering of Network Communication in ISP Firewalls, In: Proceedings of the Third International Conference on Theoretical and Mathematical Foundations of Computer Science, Denpasar, ID, IERI, 2012, p. 1-4
 Ryšavý, O., Švéda, M., Vrba, R.: A Framework for Cyber-Physical Systems Design - A Concept Study, In: Proceedings ICONS 2012, Saint Gilles, Reunion Island, US, IARIA, 2012, p. 79-82, ISBN 978-1-61208-184-7
 Švéda, M., Ryšavý, O., De, S., G., Matoušek, P., Ráb, J.: Static Analysis of Routing and Firewall Policy Configurations, e-Business and Telecommunications, Heidelberg, DE, Springer Science+Business Media, 2012, p. 39-53, ISBN 978-3-642-25205-1
 Švéda, M., Sekletár, M., Fidler, T., Ryšavý, O.: A High-level Network-wide Router Configuration Language, In: Proceedings ICN 2012, Saint Gilles, Reunion Island, US, IARIA, 2012, p. 18-21, ISBN 978-1-61208-183-0
 Veselý, V., Švéda, M.: L2 protocols in OMNeT++, IP Networking 1 -- Theory and Practice, Žilina, SK, EDIS ŽU, 2012, p. 37-40, ISBN 978-80-554-0494-3
2011Drozd, M., Barabas, M., Grégr, M., Chmelař, P.: Buffer Overflow Attacks Data Acquisition, In: Proceedings of the 6th IEEE International Conference on IDAACS 2011, Praha, CZ, IEEE, 2011, p. 775-779, ISBN 978-1-4577-1423-8
 Švéda, M., Ryšavý, O., De, S., G., Matoušek, P., Ráb, J.: Reachability Analysis in Dynamically Routed Networks, In: Proceedings of the IEEE ECBS 2011, Piscataway, NJ, US, IEEE CS, 2011, p. 197-205, ISBN 978-0-7695-4379-6
 Švéda, M., Ryšavý, O., Matoušek, P.: Supporting Safe and Secure Networked System Design, In: Computer Aided Systems Theory (EUROCAST´11), Extended Abstracts, Las Palmas de Gran Canaria, ES, IUCTC, 2011, p. 22-23, ISBN 978-84-693-9560-8
 Švéda, M.: Design Experience with Routing SW and Related Applications, In: Proceedings of The Tenth International Conference on Networks - ICN 2011, St. Maarten, AN, IARIA, 2011, p. 133-138, ISBN 978-1-61208-002-4
2010Kornecki, A., J., Grega, W., Hilburn, T., B., Thiriet, J., Švéda, M., Ryšavý, O., Pilat, A.: Transatlantic Engineering Programs: An Experience in International Cooperation, Safeeullah Soomro (Editor): Engineering the Computer Science and IT, Vienna, AT, IN-TECH, 2010, p. 65-84, ISBN 978-953-307-012-4
 Piwko, K., Chmelař, P., Hernych, R., Kubíček, D.: NAXD: Native XML Interface for a Relational Database, In: XML Prague Conference Proceedings, Prague, CZ, UK, 2010, p. 307-316, ISBN 978-80-7378-115-6
 Švéda, M., Ryšavý, O., Matoušek, P., Ráb, J., Čejka, R.: SECURITY ANALYSIS OF TCP/IP NETWORKS -- An Approach to Automatic Analysis of Network Security Properties, In: Proceedings of the International Conference on Data Communication Networking ICETE-DCNET 2010, Athens, GR, INSTICC, 2010, p. 5-11, ISBN 978-989-8425-25-6
 Švéda, M., Ryšavý, O., Matoušek, P., Ráb, J.: An Approach for Automated Network-Wide Security Analysis, In: Proceedings of the Ninth International Conference on Networks ICN 2010, Les Menuires, FR, IEEE CS, 2010, p. 294-299, ISBN 978-0-7695-3979-9
 Švéda, M., Trchalík, R.: Development of Interconnecting SW for Intranets and Fieldbuses, In: IFAC-PapersOnLine, Vol. 2010, No. 10, Laxenburg, AT, p. 119-124, ISSN 1474-6670
 Švéda, M.: Fault Management Driven Design with Safety and Security Requirements, In: Proceedings 17th IEEE International Conference and Workshops on Engineering of Computer-Based Systems ECBS 2010, Oxford, GB, IEEE CS, 2010, p. 113-120, ISBN 978-0-7695-4005-4
 Švéda, M.: NETWORK CONVERGENCY AND MODELING -- Design Experience with Routing SW for Intranets and Fieldbusses, In: Proceedings of the Fifth International Conference on Software and Data Technologies, ICSOFT 2010, Athens, GR, INSTICC, 2010, p. 173-178, ISBN 978-989-8425-22-5
2009Drozd, M.: Bezpečnost: 1:0 pro malware?, In: DSM Data Security Management, Vol. 13, No. 4, 2009, CZ, p. 16-19, ISSN 1211-8737
 Chmelař, P., Beran, V., Herout, A., Hradiš, M., Řezníček, I., Zemčík, P.: Brno University of Technology at TRECVid 2009, In: TRECVID 2009: Participant Notebook Papers and Slides, Gaithersburg, MD, US, NIST, 2009, p. 11
 Chmelař, P.: SUNAR: Surveillance Network Augmented by Retrieval, Genova, IT, 2009, p. 17
 Švéda, M., Kornecki, A., J., Hilburn, T., B., Grega, W., Thiriet, J., Ryšavý, O.: Real-Time Software-Intensive Systems Engineering: An International Perspective, In: European Association for Education in Electrical and Information Engineering Council's Annual Conference 2009, Valencia, ES, UPV, 2009, p. 6, ISBN 978-84-8363-428-8
 Švéda, M.: Fault Management for Secure Embedded Systems, In: International Conference on Systems Proceedings, ICONS 2009, New York, NY, US, IEEE CS, 2009, p. 23-28, ISBN 978-0-7695-3551-7
 Švéda, M.: Safe and Secure Networked Embedded Applications, In: Proceedings of the 4th International Conference on Broadband Communication, Wroclaw, PL, IEEE, 2009, p. 6, ISBN 978-83-7493-405-3

Your IPv4 address: 184.72.184.104
Switch to IPv6 connection

DNSSEC [dnssec]