KÜTÜK KAYITLARINDAN ÇİZGE SİNİR AĞLARI TABANLI ANOMALİ TESPİTİ

dc.contributor.advisorDAŞ, RESUL
dc.contributor.authorYILMAZ, ALİ
dc.date.accessioned2026-08-12T10:07:03Z
dc.date.issued2026
dc.departmentFÜ, Fen Bilimleri Enstitüsü, Yazılım Mühendisliği Anabilim Dalı
dc.description.abstractDijital ekosistemlerde üretilen kütük (log) verilerinin hacmi ve karmaşıklığı, modern siber tehditlerin tespit edilmesini giderek zorlaştırmaktadır. Bu tehditler, izole olaylardan ziyade çok katmanlı ilişkiler ve zamansal bağımlılıklar içeren, sistematik ve dinamik yapılardır. Geleneksel Öklidyen temelli makine öğrenimi yöntemleri, bu ilişkisel ve çok boyutlu yapıyı temsil etmekte yetersiz kalmakta; bu nedenle ilişkisel bağımlılıkların ve topolojik örüntülerin dikkate alındığı çizge tabanlı yöntemlere ihtiyaç duyulmaktadır. Bu tez, kütük kayıtlarının çizge sinir ağları üzerinden modellenmesi ve Çizge Sinir Ağları (Graph Neural Networks) (GNN) tabanlı yaklaşımlarla anomali tespiti yapılmasına yönelik yeni bir metodolojik çerçeve sunmaktadır. Tez kapsamında üç temel katkı sunulmuştur. Birinci katkı, gerçek bir kurumsal ağdan elde edilen firewall logları üzerinde geliştirilen özgün hibrit GNN modelidir. Bu aşamada log kayıtları düğüm–kenar ilişkilerine dayalı çizge sinir ağlarına dönüştürülmüş; GCN, GAT ve GraphSAGE mimarileri aynı veri ve ön işleme koşulları altında karşılaştırılmıştır. Ayrıca, GCN'in küresel topoloji yakalama kapasitesi ile GAT'ın lokal dikkat mekanizmasını birleştiren GCN–GAT hibrit model tasarlanmış ve elde edilen sonuçlar, bu hibrit yaklaşımın doğruluk, F1-skoru ve yanlış alarm oranı açısından diğer GNN tabanlı modellere kıyasla üstün performans sergilediğini göstermiştir. İkinci katkı, UNSW-NB15 veri seti üzerinde gerçekleştirilen çoklu deneyler ve geliştirilen görselleştirme sistemidir. Bu aşamada, GCN, GAT, GIN ve GraphSAGE modelleri aynı deneysel çerçeve altında karşılaştırılmış ve beş katlı çapraz doğrulama ile modellerin genelleme kabiliyeti incelenmiştir. Ayrıca tespit edilen anomalilerin ağ üzerindeki konumlarını ve saldırı ilişkilerini ortaya koymak amacıyla D3.js tabanlı dinamik bir saldırı-topolojisi görselleştirme aracı geliştirilmiştir. Bu yapı, analistlere anomalilerin davranış kalıplarını sezgisel olarak inceleme imkânı sunarak tespit sürecine yorumlanabilirlik katmanı eklemiştir. Üçüncü katkı, çizge tabanlı log analizi ile anomali tespitini RAG destekli Büyük Dil Modelleriyle bütünleştirerek, anomalilerin bağlamsal ve açıklanabilir biçimde yorumlanmasını sağlayan bir yaklaşım sunmaktadır. Sonuç olarak bu tez, gerçek firewall logları ve UNSW-NB15 veri seti üzerinde yürütülen deneysel analizler ile geliştirilen hibrit GNN modeli ve dinamik görselleştirme çalışmaları aracılığıyla, çizge tabanlı yapay zekâ yaklaşımlarının siber güvenlik alanındaki etkinliğini ortaya koymaktadır. Ayrıca, çizge tabanlı anomali tespit çıktılarının RAG destekli Büyük Dil Modelleri ile bütünleştirilmesi sayesinde, tespit edilen anomalilerin bağlamsal, açıklanabilir ve insan tarafından yorumlanabilir biçimde ifade edilmesini sağlayan bütünleşik bir analiz ve karar destek yaklaşımı sunulmaktadır.
dc.description.abstractThe increasing volume and complexity of log data generated in digital ecosystems make the detection of modern cyber threats progressively more challenging. Such threats are not isolated incidents; rather, they exhibit systematic and dynamic characteristics involving multi-layered relationships and temporal dependencies. Conventional Euclidean-based machine learning methods are often inadequate for representing this relational and high-dimensional structure; therefore, graph-based approaches that explicitly capture relational dependencies and topological patterns are required. In this context, this thesis presents a new methodological framework for modeling log records as graph boundary networks and performing anomaly detection using GNN-based approaches. The thesis offers three main contributions. The first contribution is an original hybrid GNN model developed using firewall logs collected from a real enterprise network. In this stage, log records are transformed into graph boundary networks based on node–edge relationships, and the GCN, GAT, and GraphSAGE architectures are compared under identical data and preprocessing conditions. Moreover, a GCN–GAT hybrid model that combines the global topology-capturing capability of GCN with the local attention mechanism of GAT is designed. The results demonstrate that this hybrid approach outperforms other GNN-based models on real firewall logs in terms of accuracy, F1-score, and false alarm rate. The second contribution comprises extensive experiments on the UNSW-NB15 dataset and a visualization system developed to support analysis. In this stage, the GCN, GAT, GIN, and GraphSAGE models are evaluated within the same experimental setting, and their generalization capability is examined using five-fold cross-validation. In addition, a D3.js-based dynamic attack-topology visualization tool is developed to reveal the locations of detected anomalies on the network and the attacker–target relationships. This tool enables analysts to intuitively examine anomaly behavior patterns, enhancing the interpretability of the detection process. The third contribution proposes an approach that integrates graph-based log analysis and anomaly detection with RAG-supported LLMs, enabling anomalies to be interpreted in a contextual and explainable manner. Overall, by combining the hybrid GNN model developed on real firewall logs with experimental analyses and dynamic visualization on the UNSW-NB15 dataset, this thesis demonstrates the effectiveness of graph-based artificial intelligence approaches in cybersecurity. Furthermore, integrating graph-based anomaly detection outputs with RAG-enabled LLMs provides a comprehensive analysis and decision-support framework that expresses detected anomalies in a contextual, explainable, and human-interpretable form.
dc.identifier.citationYILMAZ, A. (2026). Kütük kayıtlarından çizge sinir ağları tabanlı anomali tespiti (Tez No. 999962) [Doktora tezi, Fırat Üniversitesi].
dc.identifier.urihttps://tez.yok.gov.tr/UlusalTezMerkezi/TezGoster?key=KOgdn9H3uVnWeb15j2W4h4-R2_NJNApgKWmLsDpKtymUTL_fTov7hTsmxz6-s-I3
dc.identifier.urihttps://hdl.handle.net/11508/21587
dc.identifier.yoktezid999962
dc.language.isotr
dc.publisherFırat Üniveristesi
dc.relation.publicationcategoryTez
dc.rightsinfo:eu-repo/semantics/openAccess
dc.snmzKA_TEZ_20260511
dc.subjectMühendislik Bilimleri
dc.subjectBilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrol
dc.titleKÜTÜK KAYITLARINDAN ÇİZGE SİNİR AĞLARI TABANLI ANOMALİ TESPİTİ
dc.title.alternativeGraph neural networks based anomaly detection from log records
dc.typeDoctoral Thesis

Dosyalar