GÜVENLİK BİLGİLERİ VE OLAY YÖNETİMİ (SIEM)/LOG KORELASYON KURALLARININ YAZILMASI

dc.contributor.advisorDOĞAN, ŞENGÜL
dc.contributor.authorGÖKÇEOĞLU, DİLEK
dc.date.accessioned2026-08-12T10:09:50Z
dc.date.issued2021
dc.departmentFÜ, Fen Bilimleri Enstitüsü, Adli Bilişim Mühendisliği Anabilim Dalı
dc.description.abstractSaldırı tespit sistemleri, bilgisayar sistemlerine ve ağlarına veya genel olarak bilgi sistemlerine yönelik saldırıları tespit etmeyi amaçlar. Günümüzde bilgi güvenliği açısından en önemli problemlerden biri de siber saldırıları tespit etmektir. İnternet ağlarına bağlı bilgisayarlar sömürülmeye açık bir ortam yarattığından çeşitli gizli bilgilerin açığa çıkmasına ve zarar görmesine ortam hazırlarlar. Bu nedenlerden dolayı kurumlar için önemli olabilecek verilere yönelik gerçekleştirilebilecek siber saldırıların tespit edilmesi ve bu tür saldırılara karşı önlem alınması bilgi güvenliği açısından kritik öneme sahiptir. Neredeyse çoğu kurum bu durumun farkında olmakla beraber kendi Siber Güvenlik Operasyon Merkezlerini kurmaktadır. Bu düşünceye sahip kurumlarda SIEM ürünü bulunmakta ve yazılan korelasyon kuralları ile saldırı aktiviteleri, şüpheli aktiviteler ve anomali durumlar önceden tespit edilebilmektedir. Bu çalışmada çeşitli güvenlik cihazlarından, işletim sistemlerinden, ağ sistemlerinden, web uygulama sunucularından alınan logların(iz kayıtları) formatları araştırılmıştır. Alınan loglar bir SIEM ürününde birleştirilerek anormalliklerin tespiti, web uygulamalarına yönelik saldırıların tespiti, uç nokta sistemlerdeki şüpheli aktivitelerin belirlenmesi, işletim sistemi kategorisindeki anormallikleri yakalama özelindeki durumların tespit edilmesi için örnek korelasyon kuralları yazılmıştır. Anahtar Kelimeler: Log, Korelasyon kuralları, SIEM
dc.description.abstractIntrusion detection systems aim to detect attacks against computer systems and networks or information systems in general. Today, one of the most critical problems in terms of information security is to detect cyber attacks. Since computers connected to internet networks create an environment that is susceptible to exploitation, they prepare the environment for various confidential information to be exposed and damaged. Due to these reasons, information security must detect cyber attacks that may be carried out against the importants datas of the institutions and take precautions against such attacks. Although many institutions are aware of this issue, they establish their own Cyber Security Operations Centers. Institutions with this mindset have SIEM products, and through the written correlation rules; attack activities, suspicious activities, and anomalies can be detected beforehand. In this study, the formats of the logs (trace records) taken from various security devices, operating systems, network systems, and web application servers are investigated. By combining the received logs in a SIEM product, sample correlation rules are written to detect anomalies. These rules can detect intrusions in web applications or abnormalities in the operating system category. Keywords: Log, Correlation rules, SIEM
dc.identifier.citationGÖKÇEOĞLU, D. (2021). Güvenlik bilgileri ve olay yönetimi (SIEM)/log korelasyon kurallarının yazılması (Tez No. 688909) [Yüksek lisans tezi, Fırat Üniversitesi].
dc.identifier.urihttps://tez.yok.gov.tr/UlusalTezMerkezi/TezGoster?key=v7BkNnnepTnbhn8rNR77LfHEb4LHp_AHd0epoBEGmZbb-fd1IzlMK8oc1UCiXxCK
dc.identifier.urihttps://hdl.handle.net/11508/22534
dc.identifier.yoktezid688909
dc.language.isotr
dc.publisherFırat Üniveristesi
dc.relation.publicationcategoryTez
dc.rightsinfo:eu-repo/semantics/openAccess
dc.snmzKA_TEZ_20260511
dc.subjectMühendislik Bilimleri
dc.subjectBilim ve Teknoloji
dc.subjectBilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrol
dc.titleGÜVENLİK BİLGİLERİ VE OLAY YÖNETİMİ (SIEM)/LOG KORELASYON KURALLARININ YAZILMASI
dc.title.alternativeWriting security information and event management (SIEM)/log correlation rules
dc.typeMaster Thesis

Dosyalar