Kurumsal siber dayanıklılığı artırmak için savunma amaçlı ağ adli bilişim analizinin gerçekleştirilmesi

dc.contributor.advisorErtam, Fatih
dc.contributor.authorŞahinoğlu, Seda Nur
dc.date.accessioned2026-09-08T07:02:17Z
dc.date.issued2026
dc.departmentFÜ, Fen Bilimleri Enstitüsü, Adli Bilişim Mühendisliği Anabilim Dalı
dc.description.abstractSiber saldırıların tespitinde makine öğrenmesi yöntemlerinin etkinliği, ağ trafiği ve sistem günlükleri üzerinden incelenmiştir. Bu kapsamda Kali Linux ve Ubuntu sistemleri kullanılarak kontrollü bir test ortamı oluşturulmuş, farklı siber saldırı senaryoları gerçekleştirilmiş ve bu süreçte hem ağ trafiği verileri hem de Secure Shell (SSH) log kayıtları elde edilmiştir. Elde edilen ham veriler üzerinde ön işleme ve özellik çıkarımı işlemleri uygulanarak makine öğrenmesi algoritmalarında kullanılabilecek yapılandırılmış veri setleri oluşturulmuştur. Çalışmada Random Forest, K-En Yakın Komşu (KNN), Naive Bayes, Decision Tree, Support Vector Machine (SVM) ve LightGBM algoritmaları kullanılmıştır. Packet Capture (PCAP) veri seti üzerinde gerçekleştirilen analizlerde Decision Tree ve LightGBM algoritmaları en yüksek başarıyı göstermiş, Random Forest modeli de bu modellere yakın sonuçlar üretmiştir. SSH logları üzerinde yapılan değerlendirmelerde ise sınırlı ve dengesiz veri yapısının model performansını yanıltıcı biçimde etkileyebileceği görülmüştür. Bu nedenle daha geniş ve çeşitli bir veri yapısı üzerinde ek değerlendirme yapılmış; UNSW-NB15 veri seti üzerinde Random Forest ve LightGBM algoritmalarının diğer modellere kıyasla daha başarılı sonuçlar verdiği belirlenmiştir. Elde edilen bulgular, saldırı tespitinde model başarısının yalnızca kullanılan algoritmaya değil; veri setinin büyüklüğüne, sınıf dağılımına, veri çeşitliliğine ve çıkarılan özelliklere de bağlı olduğunu göstermektedir. Sonuç olarak, ağ trafiği ve sistem günlüklerinin makine öğrenmesi yöntemleriyle analiz edilmesinin savunma amaçlı ağ adli bilişim süreçlerine ve kurumsal siber dayanıklılığın artırılmasına katkı sağlayabileceği değerlendirilmiştir.
dc.description.abstractThe effectiveness of machine learning methods in detecting cyber-attacks was examined through network traffic and system logs. In this context, a controlled test environment was created using Kali Linux and Ubuntu systems, different cyber-attack scenarios were carried out, and both network traffic data and Secure Shell (SSH) log records were obtained during this process. Preprocessing and feature extraction operations were applied to the raw data obtained, and structured data sets that could be used in machine learning algorithms were created. Random Forest, K-Nearest Neighbors (KNN), Naive Bayes, Decision Tree, Support Vector Machine (SVM), and LightGBM algorithms were used in the study. In the analyses performed on the Packet Capture (PCAP) data set, Decision Tree and LightGBM algorithms showed the highest performance, while the Random Forest model also produced results close to these models. In the evaluations conducted on SSH logs, it was observed that the limited and imbalanced data structure could misleadingly affect model performance. Therefore, an additional evaluation was conducted on a larger and more diverse data structure; on the UNSW-NB15 data set, Random Forest and LightGBM algorithms were determined to produce more successful results compared to the other models. The findings obtained show that model performance in attack detection depends not only on the algorithm used, but also on the size of the data set, class distribution, data diversity, and extracted features. As a result, it was evaluated that the analysis of network traffic and system logs using machine learning methods could contribute to defensive network forensics processes and to increasing institutional cyber resilience.
dc.identifier.citationŞAHİNOĞLU, S. N. (2026). Kurumsal siber dayanıklılığı artırmak için savunma amaçlı ağ adli bilişim analizinin gerçekleştirilmesi (Tez No. 1019381) [Yüksek lisans tezi, FIRAT ÜNİVERSİTESİ].
dc.identifier.urihttps://tez.yok.gov.tr/UlusalTezMerkezi/TezGoster?key=5T1_CZ5-UGb9QCmoURec4PFqvBzHloIYL2lXnn11KcWo0fcUU9QDJk6DMUUg_rkR
dc.identifier.urihttps://hdl.handle.net/11508/64587
dc.identifier.yoktezid1019381
dc.institutionauthorŞahinoğlu, Seda Nur
dc.language.isotr
dc.publisherFırat Üniveristesi
dc.relation.publicationcategoryTez
dc.rightsinfo:eu-repo/semantics/openAccess
dc.snmzKA_TEZ_20250903
dc.subjectMühendislik Bilimleri
dc.titleKurumsal siber dayanıklılığı artırmak için savunma amaçlı ağ adli bilişim analizinin gerçekleştirilmesi
dc.title.alternativePerforming defensive network forensic analysis to enhance corporate cyber resilience
dc.typeMaster Thesis

Dosyalar