Advisor:Matoušek Petr, Ing., Ph.D., M.A.
Topic:Communication Monitoring Based on Device Profiles
Device profile is characteristics of a device that is created by monitoring of running processes on a device and network communication of the device. The profile includes statistics and metadata about the device behaviour in active or passive state.

Knowing device profiles helps network administrators and users to know how device communicates without explicit user interaction, e.g., during user data synchronization in cloud, software updates, application data synchronization (emails, calendar), etc. Knowledge of the device profile can be used to identify different types of network attacks, malware contagion, or unauthorized access and process running.

The research will include selection of device profile data, implementation of the tool for retrieving such data, device profiling and identification of deviations in network communcation using clustering or automated filtering.

This topic is a part of research project Integrated Platform for Analysis of Digital Data from Security Incidents (Tarzan).

2014MATOUŠEK Petr, RYŠAVÝ Ondřej, GRÉGR Matěj and VYMLÁTIL Martin. Towards Identification of Operating Systems from the Internet Traffic. IPFIX Monitoring with Fingerprinting and Clustering. In: DCNET2014. Proceedings of the 5th International Conference on Data Communication Networking. Wien: SciTePress - Science and Technology Publications, 2014, pp. 21-27. ISBN 978-989-758-042-0.

