RK

R.E. Kooij

info

Please Note

9 records found

A Human Immune System-Inspired Approach to System Resilience

Master thesis (2026) - A. Josan, G. Smaragdakis, Frank Fransen, Sandesh Manganahalli Jayaprakash, R.E. Kooij, G.C. Moreira Moura
Cloud-native 5G Core (5GC) deployments commonly rely on Kubernetes to restart or replace failed workloads. However, Kubernetes observes generic container health and does not account for Network Function (NF) behaviour, locally held protocol state, or the service disruption caused by replacement. This thesis investigates how Self-Healing for Cyber Security (SH4CS) can be adapted for cloud-native 5GC NFs to support decentralized and proportionate self-healing and self-protection.
A proof-of-concept extension was implemented for the Access and Mobility Management Function (AMF) in a Kubernetes-based free5GC testbed with a simulated UERANSIM radio access network and UE workload. The extension retains the pod-local SH4CS event–rule–action model while incorporating NF metrics, deployment state, and normalized log events. It connects this evidence to actions with different scopes, including temporary logging escalation, stricter OAuth 2.0 token-age enforcement, image replacement, and AMF regeneration. Since the evaluated open-source 5GC implementation does not support transparent UE-context transfer or session continuity between AMF instances, regeneration is performed through a graceful drain-and-restart procedure. The degraded AMF is first removed from the selection of new registrations, causing the gNB to direct them to healthy AMFs. Existing activity is then allowed or actively encouraged to leave the degraded instance before it is restarted.
The evaluation showed that NF-aware recovery can respond to degradation before Kubernetes detects process failure. Under the evaluated workload and memory limit, setting the degraded AMF’s Relative Capacity to zero redirected fresh registrations approximately 249 seconds before the Kubernetes baseline reached an OOMKill. The AMF restart strategy reduced cumulative new-UE service loss by 81.07%, reduced TTR95 from 380 to 135 seconds, and lowered the 95th-percentile onboarding latency from 8564 to 1811 ms. Additional scenarios confirmed the intended state transitions of the self-protection and remediation actions. The sidecar architecture introduced modest steady-state CPU overhead but substantial memory overhead, primarily from the lymphocyte.
The results show that SH4CS can provide a local enforcement and recovery layer for cloud-native 5GC NFs when its observations and actions are specialized for the protected function. The controller is decentralized at the decision boundary while remaining dependent on Kubernetes, operator policy, and the surrounding 5GC. Most importantly, the findings show that container restartability does not make a stateful NF disposable: effective recovery must combine orchestration with protocol-aware observations and actions that account for NF state. ...
For amateur musicians learning to improvise can be a demanding task. It can take up a lot of time and energy. The goal of this project is to simplify the learning process for jazz style pianist. This will be done by showing the musician notes that could be played in a clear manner and generating new notes when the user deviates from the proposed notes. To accomplish this goal the project is divided into 3 parts: A hardware component that will focus on displaying the notes and handling inputs, a signal processing part that focuses on extracting the frequencies from an audio stream in real time to determine what notes are being played. A machine learning part that will develop a model based on jazz solos and is able to use given chord progressions to generate jazz melodies.
The goal of this project is to simplify the process of learning musical improvisation in jazz style on the piano through the use of dynamic, real-time feedback. Through this tool, users can more easily grasp the fundamentals of jazz improvisation, hence the name Jazzify. This report focuses on the hardware aspect of Jazzify. The system utilizes a microphone, a Raspberry Pi, a display, a signal processing pipeline, and a machine learning model to analyze user input and deliver immediate, meaningful feedback. \\
The hardware component specifically uses observational results as it is easy to see whether notes are displayed correctly.
The constraints of the hardware component of the Raspberry Pi are leading. This combined with Jazzify's real-time implementation makes it important to find components that fit the requirements and constraints. This leads to several important high level design choices that will be covered in this document.\\
Overall, this project has succeeded in delivering a low-cost, portable interactive system that provides real-time dynamic feedback for learning piano improvisation. ...
Master thesis (2026) - C. Perlog, G. Smaragdakis, A. Voulimeneas, R.E. Kooij, Ivo Kroskinski, Iker Olarra
Modern devices reveal their behavior through the network traffic they generate, yet widespread encryption has made payload inspection impractical and shifted the question from which application produced a flow to when the behavior of the device changes. This thesis studies how far behavioral transitions on a single networked device, such as switching applications or moving between foreground and background activity, can be detected from passive, encrypted traffic alone, using unsupervised concept drift detection that operates online and without labels.

The thesis contributes an end-to-end pipeline that turns raw packet captures into windowed feature streams, four labeled recordings collected on dedicated Android and iOS test devices, and an empirical comparison of seven streaming change detectors under realistic observability constraints. It proposes Online NN-DVI, a streaming density-based detector, together with a retro-confirmation segmenter that converts raw detector alarms into labeled behavioral segments online.

Across the four recordings and an external cross-corpus check on the public Mirage dataset, density-based detectors are the most effective paradigm, and Online NN-DVI matches the offline NN-DVI baseline within a few F1 points at roughly an eighth of its runtime, generalizing from a single tuning recording to held-out Android, iOS, and Mirage data without per-dataset retuning. Detectability is gated by the type of transition: app-to-app foreground switches are caught in roughly two thirds of cases, foreground enter and exit transitions in about one in three, and administratively defined idle boundaries not at all. An 18-feature behavior subset matches a 54-feature candidate set, and 5-second window aggregation outperforms 1-second aggregation on both accuracy and runtime, while the segmenter reaches a frame-level F1 of 0.739. Taken together, the results indicate that what limits detection on this stream is the signal carried by the features, not the algorithm operating on them. ...
Master thesis (2025) - P. Guo, M.A. Kitsak, R.E. Kooij, S. Feld
In network science, numerous studies based on the complementarity principle have emerged since 2018 [1]. Unfortunately, theoretical foundations of complementarity are still in their infancy. Recently, a synthetic complementarity-based model called Complementarity Random Hyperbolic Graph (CRHG) has been proposed. CRHG model was assumed to explain the topological properties of real complementarity-driven networks. In other words, this model could serve as a foundation for studying complementarity mechanisms in networks.
The main goal of this thesis is to address the knowledge gap: although a complementarity-based network model has been proposed in previous studies, its topological properties have not been systematically examined. To fill in this gap, this work systematically studies complementarity network models (CRHG, GCRHG) and documents their topological properties. Moreover, we interpret the topological properties as a function of the network model parameters. We find that the CRHG model exhibits three fundamental properties: Scale-Free property, Small-World property, and Non-vanishing bipartite clustering. It indicates that it is a unique combination compared to other synthetic models. Its unique complementary connectivity mechanism makes it particularly effective for modelling complex networks formed by the complementarity mechanism. Furthermore, we also study and investigate a generalized synthetic model called Generalized Complementarity Random Hyperbolic Graph (GCRHG). We measure and analyze its clustering and bipartite clustering properties. We find that this model allows for smooth turning between similarity and complementarity. Overall, we document and interpret the topological properties of simulations for complementarity-based spatial graph models. Additionally, we conduct partial simulation verification of the theoretical topological properties of synthetic complementarity-based models, providing a reference for their future development and applications. ...
Master thesis (2024) - C. Bakos, R.E. Kooij, H. Wang, Xiaohan Li, Didrik Meijer
This thesis investigates the potential of solving large-scale linear systems of equations (LSEs) in the Tensor Train (TT) format. First, we study when this approach can outperform traditional solvers like Conjugate Gradient (CG) and Gaussian Elimination (GE). In turn, we examine the time complexity of the TT-solve technique when applied to ill-conditioned, sparse, and symmetric positive definite (SPD) matrices. This enables us to assess the scenarios where TT-solve may offer significant advantages.
During this exploration, we have also identified and proposed solutions for a handful of research gaps that could further optimize the TT-solve process. These include challenges related to poorly factorizing matrix sizes, as well as the need for a deeper understanding of the trade-offs between TT-matrix (TTM) rank and maximal mode size during the decomposition process. Additionally, the study examined the potential for altering the coefficient matrix through techniques like variable reordering and partial Gaussian elimination (PG) to achieve lower TTM-ranks without affecting the solution of the LSE. ...
Master thesis (2024) - S.A. Mironov, H. Wang, R.E. Kooij
A network, is defined as a collection of nodes interconnected by links. When this topology changes through time, we call it a temporal network. A specific class of networks, with only two types of nodes with no connections between one kind, is the bipartite network. An example is a telecommunications network, where nodes represent telecommunication base station and various mobile services like web-browsing, streaming etc. A link may exist only between a base station and a service. Moreover, each link is associated with a time-evolving weight, which represents the volume of the traffic between the corresponding base station and service over time. This weight associated with each link is also called the activity weight, with the link considered active only when the weight is non-zero. Predicting such a temporal weighted network in the future is crucial for telecommunications engineers, allowing for e.g., better traffic management. Prediction of the unweighted temporal network one step ahead, at time $t+1$, based on the network observed in the past between $[t-L-1; t]$, has been studied recently in contact networks. However, the prediction of weighted temporal networks, or equivalently, predicting the activity weight of each link, in the future has not been explored yet. Moreover, we also aim to uncover the mechanisms that enable the prediction of a weighted temporal network. We achieve this by devising several strategies that help us select the most relevant links within the network, whose activity weights in the past serve as the input for the interpretable, statistical learning algorithm, LASSO Regression, to predict the activity of a given target link at time $t+1$. The focus of the strategies is to capture a relationship of activity weights between the selected and target links. These selected links range from most active links (amount of timesteps the link weight is non-zero), those with largest activity weights or most similar to the target link using several metrics. In this thesis we apply this general methodology to two bipartite networks sourced from real world data and evaluate the performance of different strategies. Through the learned LASSO coefficients and prediction accuracy, we discover that past activity weight of a link is the best predictor for it's future weights. In terms of predicting power, most is coming from the past weights of the link we want to predict and one or two neighbouring links. Most of the selected links have minimal impact on the prediction accuracy. While different strategies of link selection excel in specific conditions, their improvement over the random link selection, is relatively low. The proposed method could be further applied to predict other weighted temporal networks with different properties to understand whether and how the the performance of link selection strategies depends on properties of the network to be predicted. ...
This research is a case study investigating the effect of participation in the development process of a network-based scientist-journalist recommender system on the mental model of digital innovation of a team of communication professionals from Delft University of Technology and Naturalis Biodiversity Center.

Communication professionals at research institutes are tasked with connecting scientists and journalists. The recommender system supports this process by recommending scientist-journalist connections based on data from previous collaborations. A scientist collaboration network, a journalist collaboration network and a scientist-journalist collaboration network are combined into a multilayer network. A recommender system is designed based on centrality metrics in the scientist and journalist collaboration networks and distance metrics in the multilayer network. In contrast to traditional link prediction problems - which aim to predict what links are most likely to form in the network - the problem in this thesis is how to recommend the most likely link for a single node, i.e. the most likely scientist links for a given journalist or most likely journalist links for a given scientist. A novel evaluation method is created to evaluate the performance of the recommender system.

The development of this system is used as a vessel to research how participation in a digital development process affects the mental model of digital innovation. This research contributes to addressing the lack of understanding of how to develop a mental model that facilitates innovation in the context of digital transformation. Three themes were identified in their mental model change: The extent to which innovation requires involvement, the complexity of innovation processes and what outcomes can realistically be expected of a digital innovation process. The team went from a model of digital innovation as 'a mysterious black box' - something external, where they could hand in a list of requirements and walk away with a digital tool - to a 'super puppy' that can do remarkable things, but has to be trained and interacted with to get a desired effect. ...
Master thesis (2023) - I. Babalau, S.E. Verwer, A. Nadeem, R.E. Kooij
In an era where cyber threats evolve with alarming speed and sophistication, the role of Security Operation Centers (SOCs) has become increasingly pivotal in safeguarding digital infrastructures. SOCs serve as the frontline defence against malicious entities, where they continuously monitor and analyze network traffic, as well as the activity of users and systems for potential threats. The rapid growth of advanced cyber-attacks has amplified the reliance on Intrusion Detection Systems (IDS) to generate alerts for anomalous activities, and on SOC analysts to analyze those alerts. However, these systems often yield an overwhelming number of alerts, many of which are false positives, leading to alert fatigue among analysts. The scarcity of effective visualization tools, coupled with the analysts' dependence on manual investigation and correlation of events aggravates this issue, resulting in extended alert analysis times. Moreover, the number of attack scenarios keeps increasing daily, making it difficult to understand the possible next actions of an attacker and apply preventive measures.

This thesis introduces an innovative approach to aid SOC analysts in managing the large influx of alerts, mitigating alert fatigue, and enhancing the efficiency of threat identification and response. We present an attack prediction tool with alert visualization capabilities that produces real-time attack graphs, summarizing the alerts associated with a specific host. Our method utilizes a Suffix-based Probabilistic Deterministic Finite Automaton (SPDFA) to predict future attacker actions, promoting a proactive defence strategy, and achieving an accuracy of 33.71 %. We validate the practicality and relevance of our contributions through interviews with six security experts, confirming the utility of our methods in a live SOC context. Furthermore, we demonstrate the applicability of our approach by testing it with three datasets collected in the real world. Our work stands apart by simultaneously addressing alert correlation, attack visualization, and predictive modelling of attacker behaviour. ...
This report details the software part of the development process of the eNose technology. The technology is posed by Momo Medical. Momo Medical is a start-up company located in Delft, it provides and develops non-intrusive monitoring systems in the nursing sector. The project is the next step in an already existing product: BedSense. BedSense enables nurses to check for among others decubritus, whether the patient is out of bed, and even if the patient has passed away. The finished project will be able to detect solid stool and hence, when integrated into the system of BedSense, will greatly assist the nurses.

The eNose technology is able to detect solid bowel movement using its gas sensing abilities. It consists of gas sensors that detect the relevant gasses that are related to feces. These sensor values are then fed into an algorithm that is able to interpret them and detect defecation. Besides it includes a communication system that handles the internal and external communication. Finally, the technology supports Over The Air (OTA) updates which allows to update the firmware of the devices remotely.

The final prototype functions accurately in certain restrooms and can be regarded as a proof of concept.However more work and data is needed in order to make the eNose work in various environments, with possible integration of machine learning analysis, as it has showed great potential.

The project is executed in two groups, hardware and software. This report contains only the software part of the process. It includes the development of the detection algorithm. And the developmentof a communication and OTA programming system. ...