Prague, Czech Republic

Josef Koumar

Network security researcher — time series analysis of network traffic and industrial cybersecurity

  • Senior Security Research Engineer, Rockwell Automation
  • Assistant Professor (part-time), Faculty of Information Technology, CTU in Prague
  • Lecturer, Cybersecurity Centre — NETACAD

I am a security researcher. My doctoral work at FIT CTU in Prague turned network traffic into time series to detect threats in encrypted traffic — botnet command-and-control, cryptomining and anomalies — without decryption. At Rockwell Automation I now research industrial cybersecurity, cryptography, secure communication and post-quantum cryptology, assessing security technologies and standards for embedded and long-lifecycle automation systems and guiding security architecture and long-term security strategy with product teams.

Portrait of Josef Koumar
  • 18
    Peer-reviewed publications
  • 221
    Citations
  • 8
    h-index
  • 10
    Open datasets released

Research

  • Encrypted traffic classification

    Extended IP flows — NetTiSA and Single Flow Time Series — that carry time-series features computed inside the flow exporter, so classification stays accurate on encrypted traffic without inspecting payloads.

  • ISP-scale forecasting

    Benchmarking deep learning forecasters on 40 weeks of real backbone traffic, mapping the trade-off between prediction accuracy and the compute an operator can actually afford.

  • Anomaly and threat detection

    Periodicity analysis for command-and-control and cryptomining traffic, plus NODS — a forecast-based outlier detection system deployed and evaluated on a live ISP network.

  • Open data and reproducibility

    Ten public datasets and supporting libraries, including CESNET-TimeSeries24 and the TS-Zoo library, so results in this field can be compared on the same footing.

  • Industrial cybersecurity and post-quantum cryptography

    At Rockwell Automation: research and technology assessment in industrial cybersecurity, cryptography, secure communication and post-quantum cryptology, evaluating standards and cryptographic solutions for embedded, long-lifecycle automation systems and guiding security architecture and long-term security strategy with product teams.

Selected publications

All 18 publications →

News

  1. 15 October 2026

    Part-time Assistant Professor at FIT CTU

    Joining the Faculty of Information Technology, CTU in Prague, as a part-time Assistant Professor alongside my research role at Rockwell Automation.

  2. 7 October 2026

    Doctoral dissertation defended

    Threat Detection in Network Traffic using Time Series Analysis, supervised by Tomáš Čejka, defended at FIT CTU in Prague. The full text, defence slides and reviewers' reports are online.

  3. September 2026

    Joining Rockwell Automation

    Starting as Senior Security Research Engineer: research and technology assessment in industrial cybersecurity, cryptography, secure communication and post-quantum cryptology for embedded and long-lifecycle automation systems.

  4. May 2026

    Two papers at IEEE NOMS 2026

    A dissertation digest on threat detection using time series analysis, and work with Karel Mudruňka on device type classification in ISP networks.

  5. January 2026

    Doctoral dissertation submitted

    Threat Detection in Network Traffic using Time Series Analysis, submitted to FIT CTU in Prague.

  6. October 2025

    Three papers at CNSM 2025

    Botnet detection through periodic C&C patterns, the CESNET TS-Zoo library, and the Device Annotation Framework — alongside the release of the CESNET-CC25 botnet dataset.

  7. February 2025

    CESNET-TimeSeries24 published in Scientific Data

    Forty weeks of traffic from 275,000 active IP addresses in the CESNET3 network, released as an open benchmark for forecasting and anomaly detection.