Prague, Czech Republic

Josef Koumar

Network security researcher — time series analysis of network traffic

  • Senior Security Research Engineer, Rockwell Automation
  • PhD candidate, Faculty of Information Technology, CTU in Prague
  • Lecturer, Cybersecurity Centre — NETACAD

I study how network traffic behaves in time. My research turns IP flow records into time series and applies statistics, machine learning and deep learning to classify encrypted traffic, forecast ISP-scale load, and detect anomalies and threats — all without decryption, and at speeds that hold up on a 100 Gbps backbone.

Portrait of Josef Koumar
  • 17
    Peer-reviewed publications
  • 187
    Citations
  • 6
    h-index
  • 7
    Open datasets released

Research

  • Encrypted traffic classification

    Extended IP flows — NetTiSA and Single Flow Time Series — that carry time-series features computed inside the flow exporter, so classification stays accurate on encrypted traffic without inspecting payloads.

  • ISP-scale forecasting

    Benchmarking deep learning forecasters on 40 weeks of real backbone traffic, mapping the trade-off between prediction accuracy and the compute an operator can actually afford.

  • Anomaly and threat detection

    Periodicity analysis for command-and-control and cryptomining traffic, plus NODS — a forecast-based outlier detection system deployed and evaluated on a live ISP network.

  • Open data and reproducibility

    Seven public datasets and supporting libraries, including CESNET-TimeSeries24 and the TS-Zoo library, so results in this field can be compared on the same footing.

Selected publications

All 17 publications →

News

  1. September 2026

    Joining Rockwell Automation

    Starting as Senior Security Research Engineer, extending my work on traffic analysis into the security of industrial and embedded systems.

  2. May 2026

    Two papers at IEEE NOMS 2026

    A dissertation digest on threat detection using time series analysis, and work with Karel Mudruňka on device type classification in ISP networks.

  3. January 2026

    Doctoral dissertation submitted

    Threat Detection in Network Traffic using Time Series Analysis, submitted to FIT CTU in Prague. Defence expected October 2026.

  4. October 2025

    Three papers at CNSM 2025

    Botnet detection through periodic C&C patterns, the CESNET TS-Zoo library, and the Device Annotation Framework — alongside the release of the CESNET-CC25 botnet dataset.

  5. February 2025

    CESNET-TimeSeries24 published in Scientific Data

    Forty weeks of traffic from 275,000 active IP addresses in the CESNET3 network, released as an open benchmark for forecasting and anomaly detection.