GÜVENLİK BİLGİLERİ VE OLAY YÖNETİMİ (SIEM)/LOG KORELASYON KURALLARININ YAZILMASI
| dc.contributor.advisor | DOĞAN, ŞENGÜL | |
| dc.contributor.author | GÖKÇEOĞLU, DİLEK | |
| dc.date.accessioned | 2026-08-12T10:09:50Z | |
| dc.date.issued | 2021 | |
| dc.department | FÜ, Fen Bilimleri Enstitüsü, Adli Bilişim Mühendisliği Anabilim Dalı | |
| dc.description.abstract | Saldırı tespit sistemleri, bilgisayar sistemlerine ve ağlarına veya genel olarak bilgi sistemlerine yönelik saldırıları tespit etmeyi amaçlar. Günümüzde bilgi güvenliği açısından en önemli problemlerden biri de siber saldırıları tespit etmektir. İnternet ağlarına bağlı bilgisayarlar sömürülmeye açık bir ortam yarattığından çeşitli gizli bilgilerin açığa çıkmasına ve zarar görmesine ortam hazırlarlar. Bu nedenlerden dolayı kurumlar için önemli olabilecek verilere yönelik gerçekleştirilebilecek siber saldırıların tespit edilmesi ve bu tür saldırılara karşı önlem alınması bilgi güvenliği açısından kritik öneme sahiptir. Neredeyse çoğu kurum bu durumun farkında olmakla beraber kendi Siber Güvenlik Operasyon Merkezlerini kurmaktadır. Bu düşünceye sahip kurumlarda SIEM ürünü bulunmakta ve yazılan korelasyon kuralları ile saldırı aktiviteleri, şüpheli aktiviteler ve anomali durumlar önceden tespit edilebilmektedir. Bu çalışmada çeşitli güvenlik cihazlarından, işletim sistemlerinden, ağ sistemlerinden, web uygulama sunucularından alınan logların(iz kayıtları) formatları araştırılmıştır. Alınan loglar bir SIEM ürününde birleştirilerek anormalliklerin tespiti, web uygulamalarına yönelik saldırıların tespiti, uç nokta sistemlerdeki şüpheli aktivitelerin belirlenmesi, işletim sistemi kategorisindeki anormallikleri yakalama özelindeki durumların tespit edilmesi için örnek korelasyon kuralları yazılmıştır. Anahtar Kelimeler: Log, Korelasyon kuralları, SIEM | |
| dc.description.abstract | Intrusion detection systems aim to detect attacks against computer systems and networks or information systems in general. Today, one of the most critical problems in terms of information security is to detect cyber attacks. Since computers connected to internet networks create an environment that is susceptible to exploitation, they prepare the environment for various confidential information to be exposed and damaged. Due to these reasons, information security must detect cyber attacks that may be carried out against the importants datas of the institutions and take precautions against such attacks. Although many institutions are aware of this issue, they establish their own Cyber Security Operations Centers. Institutions with this mindset have SIEM products, and through the written correlation rules; attack activities, suspicious activities, and anomalies can be detected beforehand. In this study, the formats of the logs (trace records) taken from various security devices, operating systems, network systems, and web application servers are investigated. By combining the received logs in a SIEM product, sample correlation rules are written to detect anomalies. These rules can detect intrusions in web applications or abnormalities in the operating system category. Keywords: Log, Correlation rules, SIEM | |
| dc.identifier.citation | GÖKÇEOĞLU, D. (2021). Güvenlik bilgileri ve olay yönetimi (SIEM)/log korelasyon kurallarının yazılması (Tez No. 688909) [Yüksek lisans tezi, Fırat Üniversitesi]. | |
| dc.identifier.uri | https://tez.yok.gov.tr/UlusalTezMerkezi/TezGoster?key=v7BkNnnepTnbhn8rNR77LfHEb4LHp_AHd0epoBEGmZbb-fd1IzlMK8oc1UCiXxCK | |
| dc.identifier.uri | https://hdl.handle.net/11508/22534 | |
| dc.identifier.yoktezid | 688909 | |
| dc.language.iso | tr | |
| dc.publisher | Fırat Üniveristesi | |
| dc.relation.publicationcategory | Tez | |
| dc.rights | info:eu-repo/semantics/openAccess | |
| dc.snmz | KA_TEZ_20260511 | |
| dc.subject | Mühendislik Bilimleri | |
| dc.subject | Bilim ve Teknoloji | |
| dc.subject | Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrol | |
| dc.title | GÜVENLİK BİLGİLERİ VE OLAY YÖNETİMİ (SIEM)/LOG KORELASYON KURALLARININ YAZILMASI | |
| dc.title.alternative | Writing security information and event management (SIEM)/log correlation rules | |
| dc.type | Master Thesis |







