LİNUX İŞLETİM SİSTEMİNDEKİ KALICILIK MEKANİZMALARININ TESPİTİNE YÖNELİK ADLİ BİLİŞİM YAZILIM ARACI GELİŞTİRİLMESİ

dc.contributor.advisorAKBAL, ERHAN
dc.contributor.authorŞÜKÜR, ELİFNUR İPEK
dc.date.accessioned2026-08-12T10:09:51Z
dc.date.issued2024
dc.departmentFÜ, Fen Bilimleri Enstitüsü, Adli Bilişim Mühendisliği Anabilim Dalı
dc.description.abstractSiber saldırılar gün geçtikçe daha yıkıcı bir hale gelmekte ve bilgi teknoloji sistemlerini tehdit etmektedir. Bu tehditler, genel olarak saldırganların sistemlere sızdıktan sonra mevcut erişimlerini devam ettirebilmek için çeşitli yöntemler kullanmaktadırlar. Bu yöntemler arasında en önemlilerinden biri, kalıcılık mekanizmalarıdır. Saldırganlar enfekte sistemler üzerinde kalıcılık sağlayarak erişimlerinin sürdürebilirliğini amaçlamaktadırlar. Enfekte sistemler üzerinde saldırganların yayılımının tespitinin sağlanması için adli bilişim analizi gerekmektedir. Linux sistemler üzerinde gerçekleştirilen kalıcılık mekanizmalarının tespit edilebilirliği; Linux işletim sisteminin açık kaynak kodlu ve özelleştirilebilir olması dolayısı ile tespit edilebilirliği zorlaştırmaktadır. Bu nedenle Linux sistemler üzerinde gerçekleştirilebilecek olası kalıcılık mekanizmalarının anlaşılması için saldırı senaryosu oluşturularak laboratuvar ortamında uygulama yapılmıştır. Kalıcılık sağlanan sistemlerde gerçekleştirilen aktivitelerin tespitine yönelik python dili kullanılarak araç geliştirilmiştir. Geliştirilen bu araç ile siber güvenlik analistlerinin Linux sistemler üzerinde hızlı, etkili, hedef odaklı analizler yapabilmesi, analiz süreçlerini kolaylaştırılması hedeflenmiştir. Kalıcılık mekanizması senaryosu uygulamasında gerçekleştirilen kalıcılık mekanizmalarının yeni geliştirilen araç ile hedef odaklı analizlerin yapılması sağlanmış olup aracın analiz süreçlerini kolaylaştırdığı değerlendirilmiştir.
dc.description.abstractCyber attacks are becoming more and more destructive and threatening information technology systems. These threats, in general, use various methods to maintain their current access after the attackers infiltrate the systems. One of the most important of these methods is persistence mechanisms. Attackers aim to maintain their access by ensuring persistence on infected systems. Forensic analysis is required to detect the spread of attackers on infected systems. Detectability of persistence mechanisms on Linux systems; The open source and customizable nature of the Linux operating system makes it difficult to detect. For this reason, an attack scenario was created and implemented in a laboratory environment to understand the possible persistence mechanisms that can be realized on Linux systems. A tool was developed using python language to detect the activities performed on persistent systems. With this tool, it is aimed to enable cyber security analysts to perform fast, effective, target-oriented analysis on Linux systems and to facilitate the analysis processes. Target-oriented analysis of the persistence mechanisms realized in the persistence mechanism scenario application was provided with the newly developed tool and it was evaluated that the tool facilitated the analysis processes.
dc.identifier.citationİPEK ŞÜKÜR, E. (2024). Linux işletim sistemindeki kalıcılık mekanizmalarının tespitine yönelik adli bilişim yazılım aracı geliştirilmesi (Tez No. 885404) [Yüksek lisans tezi, Fırat Üniversitesi].
dc.identifier.urihttps://tez.yok.gov.tr/UlusalTezMerkezi/TezGoster?key=usXiZIM9Lp0wk-YzRoaT-y-QJLK-hCWZmptfs2zHjfn8G6RB_GLVJtFNCpm9QIF8
dc.identifier.urihttps://hdl.handle.net/11508/22540
dc.identifier.yoktezid885404
dc.language.isotr
dc.publisherFırat Üniveristesi
dc.relation.publicationcategoryTez
dc.rightsinfo:eu-repo/semantics/openAccess
dc.snmzKA_TEZ_20260511
dc.subjectMühendislik Bilimleri
dc.titleLİNUX İŞLETİM SİSTEMİNDEKİ KALICILIK MEKANİZMALARININ TESPİTİNE YÖNELİK ADLİ BİLİŞİM YAZILIM ARACI GELİŞTİRİLMESİ
dc.title.alternativeDevelopment of a forensic software tool for detecting persistence mechanisms in Linux operating system
dc.typeMaster Thesis

Dosyalar