WİNDOWS DOMAİN SİSTEMLERİNE YÖNELİK SİBER SALDIRILARIN TESPİTİ İÇİN KURAL TABANLI BİR YAKLAŞIMIN GELİŞTİRİLMESİ

dc.contributor.advisorERTAM, FATİH
dc.contributor.authorAYGÜN, MUHAMMED
dc.date.accessioned2026-08-12T10:09:53Z
dc.date.issued2024
dc.departmentFÜ, Fen Bilimleri Enstitüsü, Adli Bilişim Mühendisliği Anabilim Dalı
dc.description.abstractDomain sistemleri, kimlik bilgileri, erişim kontrolleri ve yetkilendirme gibi önemli işlevlerin yanı sıra, objelerin içerdiği değerli bilgileri de içerisinde depolar. Sisteme sızan saldırganlar, bu işlevlerin merkezinde domain sisteminin yer aldığını bildiğinden dolayı, sıklıkla bu sistemi hedef alır. Bu doğrultuda, domain servisini doğrudan hedef alarak kimlik bilgilerini ele geçirebilir, kullanıcıların ve grupların erişim haklarını ele geçirip yetkisiz kullanıcılarla gizli verilere erişebilir veya farklı sistemlere yayılma ve erişim haklarını artırabilirler. Ayrıca, sistemler üzerinde kalıcılık sağlayarak, sisteme tekrar sızmadan erişim sağlayabilir, Domain yapısında bulunan cihazlarda hizmet kesintisi yaşatabilir, kullanıcıların özel bilgilerine ulaşarak sosyal mühendislik yöntemleri uygulayabilir ya da domain sisteminin depoladığı bilgileri şifreleyerek fidye talebinde bulunabilirler. Bu tür saldırılar veya benzer kötü niyetli girişimlerle hedef alınan sisteme zarar veren saldırganlar, sadece sistemin işleyişini aksatmakla kalmaz, aynı zamanda kuruma ciddi maddi kayıplar ve itibar zedelenmesi gibi manevi zararlar da verebilir. Bu durum, kurumun güvenilirliğini sarsarak, uzun vadede müşteri ve iş ortakları nezdinde olumsuz bir algı yaratabilir, hatta kurumun faaliyetlerini sürdürebilmesini tehlikeye sokabilir. Domain sisteminin bir kuruluşun hassas verilerine ve kaynaklarına erişimi düzenlemedeki önemli rolü göz önüne alındığında, kuruluşların bu tür saldırılara karşı savunma yapmak için proaktif önlemler alması zorunludur. Active Directory sistemlerini korumak, güvenlik ekipleri için kritik bir odak noktasıdır. Bu saldırıları tanımlamak ve domain sistemlerine yönelik saldırılar hakkında bilgi sahibi olmak, siber güvenlik ekipleri için büyük bir avantaj sağlar. Bu siber saldırı türlerinin ve bu tür saldırılara karşı yapılan atakların tespitinin sağlanması için Sigma kuralı geliştirilmesi önemli bir husustur. Bu tez çalışması, Windows Domain sistemlerine yönelik siber saldırıların tespitinde kullanılabilecek kural tabanlı bir yaklaşım geliştirmiştir. Çalışma, Sigma kurallarını temel alarak Active Directory ortamlarında meydana gelebilecek çeşitli saldırı vektörlerini tanımlamış ve bu saldırılara karşı etkili tespit yöntemleri sunmuştur. Bu doğrultuda, kurumların siber güvenlik ekiplerine saldırı tespiti ve önleme süreçlerinde rehberlik edecek bir çözüm sağlamıştır. Tez, özellikle kritik verilerin ve kaynakların korunmasını hedef alan bu yaklaşımıyla, saldırıların erken aşamada tespit edilerek olası zararların en aza indirilmesine katkı sunmaktadır.
dc.description.abstractDomain systems, in addition to essential functions such as identity management, access controls, and authorization, also store valuable information contained within objects. Attackers who infiltrate a system often target the domain system because they know it is central to these functions. By directly targeting the domain service, they can steal credentials, gain access to users' and groups' permissions, and potentially access confidential data with unauthorized users, or even spread to other systems and escalate their privileges. Moreover, they can maintain persistence within the system, enabling them to access it without needing to breach it again, cause service disruptions on devices within the Domain structure, access users' private information to employ social engineering tactics, or encrypt the information stored in the domain system to demand ransom. Such attacks, or similar malicious attempts, not only disrupt the operation of the targeted system but also inflict significant financial losses and reputational damage on the organization. This can undermine the organization's credibility, create a negative perception among customers and business partners in the long term, and even threaten the organization's ability to continue its operations. Considering the critical role that the domain system plays in regulating access to a company's sensitive data and resources, it is imperative for organizations to take proactive measures to defend against such attacks. Protecting Active Directory systems is a critical focus for security teams. Identifying these attacks and having knowledge about attacks targeting domain systems provide a significant advantage for cybersecurity teams. Developing Sigma rules to detect these types of cyberattacks and counter such threats is an important aspect. This thesis has developed a rule-based approach for detecting cyberattacks targeting Windows Domain systems. By leveraging Sigma rules, it identifies various attack vectors in Active Directory environments and provides effective detection methods against these threats. Accordingly, it offers a solution that guides organizations' cybersecurity teams in their attack detection and prevention processes. With this approach, the thesis contributes to minimizing potential damages by enabling the early detection of attacks, particularly focusing on the protection of critical data and resources.
dc.identifier.citationAYGÜN, M. (2024). Windows domain sistemlerine yönelik siber saldırıların tespiti için kural tabanlı bir yaklaşımın geliştirilmesi (Tez No. 913061) [Yüksek lisans tezi, Fırat Üniversitesi].
dc.identifier.urihttps://tez.yok.gov.tr/UlusalTezMerkezi/TezGoster?key=E_eEUHQic_C-LvhxNQn1W66pkM-E4-1vTTk6aKL7nDbB9ZRx-Tx2bavej_yZJaQK
dc.identifier.urihttps://hdl.handle.net/11508/22559
dc.identifier.yoktezid913061
dc.language.isotr
dc.publisherFırat Üniveristesi
dc.relation.publicationcategoryTez
dc.rightsinfo:eu-repo/semantics/openAccess
dc.snmzKA_TEZ_20260511
dc.subjectBilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrol
dc.titleWİNDOWS DOMAİN SİSTEMLERİNE YÖNELİK SİBER SALDIRILARIN TESPİTİ İÇİN KURAL TABANLI BİR YAKLAŞIMIN GELİŞTİRİLMESİ
dc.title.alternativeDevelopment of a rule-based approach for detecting cyber attacks on windows domain systems
dc.typeMaster Thesis

Dosyalar