Prague, Czech Republic
Josef Koumar
Network security researcher — time series analysis of network traffic and industrial cybersecurity
- Senior Security Research Engineer, Rockwell Automation
- Assistant Professor (part-time), Faculty of Information Technology, CTU in Prague
- Lecturer, Cybersecurity Centre — NETACAD
I am a security researcher. My doctoral work at FIT CTU in Prague turned network traffic into time series to detect threats in encrypted traffic — botnet command-and-control, cryptomining and anomalies — without decryption. At Rockwell Automation I now research industrial cybersecurity, cryptography, secure communication and post-quantum cryptology, assessing security technologies and standards for embedded and long-lifecycle automation systems and guiding security architecture and long-term security strategy with product teams.
-
18Peer-reviewed publications
-
221Citations
-
8h-index
-
10Open datasets released
Research
-
Encrypted traffic classification
Extended IP flows — NetTiSA and Single Flow Time Series — that carry time-series features computed inside the flow exporter, so classification stays accurate on encrypted traffic without inspecting payloads.
-
ISP-scale forecasting
Benchmarking deep learning forecasters on 40 weeks of real backbone traffic, mapping the trade-off between prediction accuracy and the compute an operator can actually afford.
-
Anomaly and threat detection
Periodicity analysis for command-and-control and cryptomining traffic, plus NODS — a forecast-based outlier detection system deployed and evaluated on a live ISP network.
-
Open data and reproducibility
Ten public datasets and supporting libraries, including CESNET-TimeSeries24 and the TS-Zoo library, so results in this field can be compared on the same footing.
-
Industrial cybersecurity and post-quantum cryptography
At Rockwell Automation: research and technology assessment in industrial cybersecurity, cryptography, secure communication and post-quantum cryptology, evaluating standards and cryptographic solutions for embedded, long-lifecycle automation systems and guiding security architecture and long-term security strategy with product teams.
Selected publications
All 18 publications →News
-
15 October 2026
Part-time Assistant Professor at FIT CTU
Joining the Faculty of Information Technology, CTU in Prague, as a part-time Assistant Professor alongside my research role at Rockwell Automation.
-
7 October 2026
Doctoral dissertation defended
Threat Detection in Network Traffic using Time Series Analysis, supervised by Tomáš Čejka, defended at FIT CTU in Prague. The full text, defence slides and reviewers' reports are online.
-
September 2026
Joining Rockwell Automation
Starting as Senior Security Research Engineer: research and technology assessment in industrial cybersecurity, cryptography, secure communication and post-quantum cryptology for embedded and long-lifecycle automation systems.
-
May 2026
Two papers at IEEE NOMS 2026
A dissertation digest on threat detection using time series analysis, and work with Karel Mudruňka on device type classification in ISP networks.
-
January 2026
Doctoral dissertation submitted
Threat Detection in Network Traffic using Time Series Analysis, submitted to FIT CTU in Prague.
-
October 2025
Three papers at CNSM 2025
Botnet detection through periodic C&C patterns, the CESNET TS-Zoo library, and the Device Annotation Framework — alongside the release of the CESNET-CC25 botnet dataset.
-
February 2025
CESNET-TimeSeries24 published in Scientific Data
Forty weeks of traffic from 275,000 active IP addresses in the CESNET3 network, released as an open benchmark for forecasting and anomaly detection.