Prague, Czech Republic
Josef Koumar
Network security researcher — time series analysis of network traffic
- Senior Security Research Engineer, Rockwell Automation
- PhD candidate, Faculty of Information Technology, CTU in Prague
- Lecturer, Cybersecurity Centre — NETACAD
I study how network traffic behaves in time. My research turns IP flow records into time series and applies statistics, machine learning and deep learning to classify encrypted traffic, forecast ISP-scale load, and detect anomalies and threats — all without decryption, and at speeds that hold up on a 100 Gbps backbone.
-
17Peer-reviewed publications
-
187Citations
-
6h-index
-
7Open datasets released
Research
-
Encrypted traffic classification
Extended IP flows — NetTiSA and Single Flow Time Series — that carry time-series features computed inside the flow exporter, so classification stays accurate on encrypted traffic without inspecting payloads.
-
ISP-scale forecasting
Benchmarking deep learning forecasters on 40 weeks of real backbone traffic, mapping the trade-off between prediction accuracy and the compute an operator can actually afford.
-
Anomaly and threat detection
Periodicity analysis for command-and-control and cryptomining traffic, plus NODS — a forecast-based outlier detection system deployed and evaluated on a live ISP network.
-
Open data and reproducibility
Seven public datasets and supporting libraries, including CESNET-TimeSeries24 and the TS-Zoo library, so results in this field can be compared on the same footing.
Selected publications
All 17 publications →News
-
September 2026
Joining Rockwell Automation
Starting as Senior Security Research Engineer, extending my work on traffic analysis into the security of industrial and embedded systems.
-
May 2026
Two papers at IEEE NOMS 2026
A dissertation digest on threat detection using time series analysis, and work with Karel Mudruňka on device type classification in ISP networks.
-
January 2026
Doctoral dissertation submitted
Threat Detection in Network Traffic using Time Series Analysis, submitted to FIT CTU in Prague. Defence expected October 2026.
-
October 2025
Three papers at CNSM 2025
Botnet detection through periodic C&C patterns, the CESNET TS-Zoo library, and the Device Annotation Framework — alongside the release of the CESNET-CC25 botnet dataset.
-
February 2025
CESNET-TimeSeries24 published in Scientific Data
Forty weeks of traffic from 275,000 active IP addresses in the CESNET3 network, released as an open benchmark for forecasting and anomaly detection.