Ing. Jaroslav Pešek

Theses

Bachelor theses

Improving Flow Cache Efficiency in Network Flow Exporter

Author
Damir Zainullin
Year
2024
Type
Bachelor thesis
Supervisor
Ing. Jaroslav Pešek
Reviewers
Ing. Jiří Buček, Ph.D.
Summary
This work is dedicated to the optimization of the currently used open-source network monitoring program - ipfixprobe developed primarily by CESNET, more precisely on its cache, as it's the core of flow-based monitoring. We will analyze the source code to identify approaches leading to performance issues and propose solutions for the identified problems. To prove the efficiency of our proposals we will experimentally test them, including a comparison of currently popular non-cryptographic hash functions and cache policies having good results adapted for specific conditions of the flow cache, usage of machine learning to create the best suiting policy for the exact type of traffic, and implementation of the DDoS detection algorithm. Successful proposals will become part of the project, increasing user service quality.

Evidential and Interpretable Threat Detection and Classification on Network

Author
Andrea Gabriela Diaz Gardini
Year
2026
Type
Bachelor thesis
Supervisor
Ing. Jaroslav Pešek
Reviewers
Ing. Jiří Dostál, Ph.D.
Summary
Current intrusion detection systems produce definitive classifications for every network flow regardless of evidence quality, providing no mechanism to express uncertainty or trigger manual review for ambiguous cases. This forced certainty proves problematic when encountering novel attacks, encrypted communications, or adversarially crafted traffic near decision boundaries. This thesis develops and evaluates the first application of Dempster-Shafer theory to packet-level network flow classification at large scale, combining k-nearest neighbour classification with evidential reasoning to provide interpretable threat detection with explicit uncertainty quantification. The approach transforms packet sequences into fixed-length embeddings, constructs distance-based mass functions, and combines evidence through Dempster's rule to produce belief scores supporting automated classification or manual review decisions. Systematic evaluation across three diverse datasets totalling over 2 million network flows, encompassing unencrypted attack traffic, encrypted VPN communications, and anonymised Tor traffic, demonstrates that ensemble DS k-NN achieves macro F1-score of 0.8257 with only 1.41% rejected samples on CIC-IDS-2017, representing a 57% reduction in manual review workload compared to single-k configurations. The approach proves particularly effective on challenging traffic types, achieving 6.5 percentage point improvement on encrypted VPN traffic and 17.1 percentage point improvement on anonymised Tor traffic compared to baseline k-NN, where traditional deep packet inspection fails. This work represents the largest reported evaluation of Dempster-Shafer theory in pattern recognition literature, demonstrating that evidential reasoning remains computationally feasible at operational scale whilst providing interpretability benefits critical for security operations centres.

Master theses

High-throughput Output Processing for Network Flow Exporter

Author
Damir Zainullin
Year
2026
Type
Master thesis
Supervisor
Ing. Jaroslav Pešek
Reviewers
Pierre Donat-Bouillud, Ph.D.
Summary
This work focuses on the open-source network probe, ipfixprobe, developed by CESNET. Ipfixprobe is used in CESNETs backbone network, making it critically dependent on performance. The probes export process is an impor- tant part of flow-based monitoring. The core of an export process is an output storage that is simultaneously accessed by multiple input and output threads. We will analyse the source codes to identify issues of current output storage and propose solutions. This work introduces many output storage options with two different architectural approaches, including research on cache impact and prefetching in a parallel environment. All approaches are experimentally tested and compared.