PREACT TM05000014-V2: Threat Model Hub
Identifikátory výsledku
Kód výsledku v IS VaVaI
<a href="https://www.isvavai.cz/riv?ss=detail&h=RIV%2F27730450%3A_____%2F25%3AN0000002" target="_blank" >RIV/27730450:_____/25:N0000002 - isvavai.cz</a>
Výsledek na webu
<a href="https://www.progress.com/resources/papers/privacy-respecting-explainable-assessment-and-collection-of-threats-preact" target="_blank" >https://www.progress.com/resources/papers/privacy-respecting-explainable-assessment-and-collection-of-threats-preact</a>
DOI - Digital Object Identifier
—
Alternativní jazyky
Jazyk výsledku
angličtina
Název v původním jazyce
PREACT TM05000014-V2: Threat Model Hub
Popis výsledku v původním jazyce
The result is a software system Threat Model Hub, developed within the PREACT project, representing a centralized cloud platform for collection, processing, and analysis of cybersecurity telemetry across multiple organizations. The system ingests anonymized security events from distributed Edge IoC Processors, performs cross-customer correlation over non-private indicators of compromise, and generates global threat intelligence. The main contribution of the result is enabling collaborative, privacy-preserving threat intelligence at scale. The platform aggregates data from multiple independent environments and applies advanced processing pipelines, including validation, filtering, quota enforcement, and scoring mechanisms, to ensure high data quality and operational stability. Threat Model Hub provides key functionalities such as global maliciousness scoring of entities (e.g., IP addresses), identification of significant attackers, and propagation of intelligence back to customer environments to improve local detection and response. The system also includes governance mechanisms for evaluating data quality and mitigating misconfigured or noisy inputs through adaptive filtering rules and quotas. An integral part of the solution is the generation of context reports that enrich detected events with additional intelligence and provide analyst-oriented explanations using Large Language Models (LLMs). This improves incident understanding, prioritization, and response efficiency. The result has been implemented as a cloud-native microservice-based system with scalable architecture, strong tenant isolation, and privacy-by-design principles. It was experimentally validated through integration with Flowmon ADS and Edge IoC Processor, demonstrating end-to-end functionality including data ingestion, scoring, intelligence propagation, and explainability workflows. The Threat Model Hub is intended for further development and deployment as a core component of advanced cybersecurity platforms focused on global threat detection, correlation, and intelligence sharing.
Název v anglickém jazyce
PREACT TM05000014-V2: Threat Model Hub
Popis výsledku anglicky
The result is a software system Threat Model Hub, developed within the PREACT project, representing a centralized cloud platform for collection, processing, and analysis of cybersecurity telemetry across multiple organizations. The system ingests anonymized security events from distributed Edge IoC Processors, performs cross-customer correlation over non-private indicators of compromise, and generates global threat intelligence. The main contribution of the result is enabling collaborative, privacy-preserving threat intelligence at scale. The platform aggregates data from multiple independent environments and applies advanced processing pipelines, including validation, filtering, quota enforcement, and scoring mechanisms, to ensure high data quality and operational stability. Threat Model Hub provides key functionalities such as global maliciousness scoring of entities (e.g., IP addresses), identification of significant attackers, and propagation of intelligence back to customer environments to improve local detection and response. The system also includes governance mechanisms for evaluating data quality and mitigating misconfigured or noisy inputs through adaptive filtering rules and quotas. An integral part of the solution is the generation of context reports that enrich detected events with additional intelligence and provide analyst-oriented explanations using Large Language Models (LLMs). This improves incident understanding, prioritization, and response efficiency. The result has been implemented as a cloud-native microservice-based system with scalable architecture, strong tenant isolation, and privacy-by-design principles. It was experimentally validated through integration with Flowmon ADS and Edge IoC Processor, demonstrating end-to-end functionality including data ingestion, scoring, intelligence propagation, and explainability workflows. The Threat Model Hub is intended for further development and deployment as a core component of advanced cybersecurity platforms focused on global threat detection, correlation, and intelligence sharing.
Klasifikace
Druh
R - Software
CEP obor
—
OECD FORD obor
20206 - Computer hardware and architecture
Návaznosti výsledku
Projekt
<a href="/cs/project/TM05000014" target="_blank" >TM05000014: Analýza bezpečnostních hrozeb s ohledem na ochranu soukromí</a><br>
Návaznosti
P - Projekt vyzkumu a vyvoje financovany z verejnych zdroju (s odkazem do CEP)
Ostatní
Rok uplatnění
2025
Kód důvěrnosti údajů
S - Úplné a pravdivé údaje o projektu nepodléhají ochraně podle zvláštních právních předpisů
Údaje specifické pro druh výsledku
Interní identifikační kód produktu
TM05000014-V2
Technické parametry
Výsledkem je centrální cloudová multitenantní analytická platforma Threat Hub/Threat Model Hub, která agreguje anonymizované bezpečnostní události od více zákazníků, provádí jejich validaci, ukládání, korelaci, skórování a distribuci odvozených poznatků zpět klientům. Architektura byla rozvinuta od proof-of-conceptu k modulární mikroslužbové platformě provozované v kontejnerech; v podkladech jsou uvedeny SQL databáze, RabbitMQ, FastAPI, REST API pro synchronní komunikaci a fronty zpráv pro vysokopropustné asynchronní zpracování. Hub zajišťuje kolektivní analýzu, skórování IP adres a důvěryhodnosti zákaznické telemetrie, automatizovaná mitigační pravidla a vysvětlitelnost na vyžádání. Platforma již obsahuje technické předpoklady pro komercializaci, zejména autentizaci na úrovni zákazníka, monitoring využití, telemetry per tenant, simulace charging/throttling modelů a návrh kvót podle tarifů. Majetková práva jsou rozdělena v poměru 90 % Flowmon Networks a 10 % Vysoké učení technické v Brně. Kontakt: Ing. Martin Holkovič, Ph.D., Flowmon Networks a.s., e-mail: martin.holkovic@progress.com, tel. +420739947040.
Ekonomické parametry
Ekonomický potenciál výsledku spočívá v jeho využití jako předplacené cloudové intelligence služby navázané na Flowmon ADS, případně v budoucím zpoplatnění podle využití služby. Očekávanými efekty jsou nové opakované tržby z předplatného, upsell stávajícím zákazníkům Flowmon ADS a lepší škálovatelnost služby bez lineárního růstu provozních nákladů díky mikroslužbové a asynchronní architektuře. Na straně zákazníka lze očekávat úspory díky centralizované analytice, dřívější detekci distribuovaných hrozeb a automatizovaným mitigacím, které snižují nároky na manuální vyhodnocování incidentů.
IČO vlastníka výsledku
27730450
Název vlastníka
Flowmon Networks a.s.