17–19 Sept 2025
Tehnical University of Moldova
Europe/Bucharest timezone

Metadata-based Network Traffic Analysis Using Zeek

18 Sept 2025, 12:25
15m
Room 2

Room 2

Technical University of Moldova
Paper presentation Network Security Cloud Computing and Network Virtualisation

Speaker

Stefan Dorin Jumarea (National University of Science and Technology POLITEHNICA Bucharest)

Description

Networks usually face the challenges of high traffic volume and diverse user behaviours, which makes analyzing and preventing security incidents particularly difficult. Another major drawback is that traffic is often encrypted, so the data you can analyse is very limited. This paper presents an approach to network monitoring tooling, using Zeek for inspection on encrypted traffic. The system is designed to analyse metadata, flow characteristics and other anomalies. To increase detection rate and contextual awareness, the deployment integrates with Malware Information Sharing Platform (MISP) for real-time threat intelligence correlation, and OpenSearch for scalable indexing, querying, and integrating with other logs from the same network. This setup allows detection of suspicious activity, threat hunting and intrusion prevention across the entire infrastructure. The system architecture is modular and scalable, allowing it to apply different security policies to the intrusion detection software and adjust the configuration to suit traffic patterns. We discuss the architectural design, performance, testing, and practical challenges of monitoring encrypted traffic on high volume network traffic.

Authors

Stefan Dorin Jumarea (National University of Science and Technology POLITEHNICA Bucharest) Darius Mihai (Universitatea Națională de Știință și Tehnologie POLITEHNICA București) Maria-Elena MIHAILESCU (National University of Science and Technology POLITEHNICA Bucharest, Romania) Andreia-Irina Ocanoaia (National University of Science and Technology POLITEHNICA Bucharest) Mr Mihai Carabas (National University of Science and Technology POLITEHNICA Bucharest) Mr Lukas Vytautas Dagilis (NRD Cyber Security) Andreea GRAMA (Revel Business Group)

Presentation materials