PREACT TM05000014-V2: Threat Model Hub
The result's identifiers
Result code in IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F27730450%3A_____%2F25%3AN0000002" target="_blank" >RIV/27730450:_____/25:N0000002 - isvavai.cz</a>
Result on the web
<a href="https://www.progress.com/resources/papers/privacy-respecting-explainable-assessment-and-collection-of-threats-preact" target="_blank" >https://www.progress.com/resources/papers/privacy-respecting-explainable-assessment-and-collection-of-threats-preact</a>
DOI - Digital Object Identifier
—
Alternative languages
Result language
angličtina
Original language name
PREACT TM05000014-V2: Threat Model Hub
Original language description
The result is a software system Threat Model Hub, developed within the PREACT project, representing a centralized cloud platform for collection, processing, and analysis of cybersecurity telemetry across multiple organizations. The system ingests anonymized security events from distributed Edge IoC Processors, performs cross-customer correlation over non-private indicators of compromise, and generates global threat intelligence. The main contribution of the result is enabling collaborative, privacy-preserving threat intelligence at scale. The platform aggregates data from multiple independent environments and applies advanced processing pipelines, including validation, filtering, quota enforcement, and scoring mechanisms, to ensure high data quality and operational stability. Threat Model Hub provides key functionalities such as global maliciousness scoring of entities (e.g., IP addresses), identification of significant attackers, and propagation of intelligence back to customer environments to improve local detection and response. The system also includes governance mechanisms for evaluating data quality and mitigating misconfigured or noisy inputs through adaptive filtering rules and quotas. An integral part of the solution is the generation of context reports that enrich detected events with additional intelligence and provide analyst-oriented explanations using Large Language Models (LLMs). This improves incident understanding, prioritization, and response efficiency. The result has been implemented as a cloud-native microservice-based system with scalable architecture, strong tenant isolation, and privacy-by-design principles. It was experimentally validated through integration with Flowmon ADS and Edge IoC Processor, demonstrating end-to-end functionality including data ingestion, scoring, intelligence propagation, and explainability workflows. The Threat Model Hub is intended for further development and deployment as a core component of advanced cybersecurity platforms focused on global threat detection, correlation, and intelligence sharing.
Czech name
—
Czech description
—
Classification
Type
R - Software
CEP classification
—
OECD FORD branch
20206 - Computer hardware and architecture
Result continuities
Project
<a href="/en/project/TM05000014" target="_blank" >TM05000014: Privacy-respecting Explainable Assessment and Collection of Threats</a><br>
Continuities
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)
Others
Publication year
2025
Confidentiality
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Data specific for result type
Internal product ID
TM05000014-V2
Technical parameters
Výsledkem je centrální cloudová multitenantní analytická platforma Threat Hub/Threat Model Hub, která agreguje anonymizované bezpečnostní události od více zákazníků, provádí jejich validaci, ukládání, korelaci, skórování a distribuci odvozených poznatků zpět klientům. Architektura byla rozvinuta od proof-of-conceptu k modulární mikroslužbové platformě provozované v kontejnerech; v podkladech jsou uvedeny SQL databáze, RabbitMQ, FastAPI, REST API pro synchronní komunikaci a fronty zpráv pro vysokopropustné asynchronní zpracování. Hub zajišťuje kolektivní analýzu, skórování IP adres a důvěryhodnosti zákaznické telemetrie, automatizovaná mitigační pravidla a vysvětlitelnost na vyžádání. Platforma již obsahuje technické předpoklady pro komercializaci, zejména autentizaci na úrovni zákazníka, monitoring využití, telemetry per tenant, simulace charging/throttling modelů a návrh kvót podle tarifů. Majetková práva jsou rozdělena v poměru 90 % Flowmon Networks a 10 % Vysoké učení technické v Brně. Kontakt: Ing. Martin Holkovič, Ph.D., Flowmon Networks a.s., e-mail: martin.holkovic@progress.com, tel. +420739947040.
Economical parameters
Ekonomický potenciál výsledku spočívá v jeho využití jako předplacené cloudové intelligence služby navázané na Flowmon ADS, případně v budoucím zpoplatnění podle využití služby. Očekávanými efekty jsou nové opakované tržby z předplatného, upsell stávajícím zákazníkům Flowmon ADS a lepší škálovatelnost služby bez lineárního růstu provozních nákladů díky mikroslužbové a asynchronní architektuře. Na straně zákazníka lze očekávat úspory díky centralizované analytice, dřívější detekci distribuovaných hrozeb a automatizovaným mitigacím, které snižují nároky na manuální vyhodnocování incidentů.
Owner IČO
27730450
Owner name
Flowmon Networks a.s.