SİBER TEHDİT İSTİHBARATIYLA ÖZGÜN TEHDİT AKTÖRLERİ VERİ KÜMESİ OLUŞTURMA VE SINIFLANDIRMA

dc.contributor.advisorKAYA, MUSTAFA
dc.contributor.authorYETİMOĞLU, BURAK
dc.date.accessioned2026-08-12T10:09:52Z
dc.date.issued2022
dc.departmentFÜ, Fen Bilimleri Enstitüsü, Adli Bilişim Mühendisliği Anabilim Dalı
dc.description.abstractSiber uzayda bilgi işleyen teknoloji ve veri varlığının artışıyla birlikte gelişmiş sürekli tehdit aktörü olarak tanımlanan gruplar ortaya çıkarak endüstriyel casusluk, sabotaj ve hırsızlık suçlarını işlemektedirler. Kuruluşlar veri varlığını korumak için siber güvenlik süreçlerini iyileştirme amacıyla siber savunma faaliyetleri ve bu faaliyetlerin yerine getirilmesi için gerekli savunma teknolojilerine yatırım yapmaktadırlar. Siber tehdit istihbaratı ise bu savunma faaliyetleri içerisinde daha bilinçli izleme, tespit ve müdahale adımlarını güçlendirmek amacıyla faydalandıkları bir alandır. Bu çalışmada kurum ve kuruluşların savunma faaliyetleri kapsamında tespit ve önleme kabiliyetlerini arttırılması amacıyla tehdit istihbaratından elde edilen zararlı göstergelerle tehdit aktörlerine ait veri kümesi oluşturulması ve sınıflandırılması hedeflenmiştir. İnternet üzerinden tehdit aktörlerine ve siber saldırılara ait zararlı göstergelerin toplanarak oluşturulacak olan veri kümesi ile daha önceki benzer siber saldırı aktivitelerinin çıkarılması hedeflenmektedir. Olay müdahale süreçlerinde elde edilen zararlı göstergeler veri kümesinde yer alan özniteliklerle karşılaştırılarak tehdit aktörü veya bir siber saldırıya ait tehdit istihbaratı ilişkisi çıkarabilir. Çalışma sonucunda zararlı gösterge ile ilişkili siber saldırı veya tehdit aktörünün daha önceki saldırılarda kullandığı zararlı göstergelerin çıkarımı sağlanacaktır. Oluşturulan veri kümesi ile tespit edilen bulgunun tehdit aktörü ilişkisi konusunda çıkarım yapılmasını sağlayacaktır. Örneğin, Olay müdahale çalışması ile tespit edilen IP adresi hakkında servis sağlayıcı ve IP bloğu bilgisi ile oluşturulan veri kümesi içerisinde yer alan IP adresi benzerlik ilişkisine bakılarak ilişki kurulan bir siber saldırı veya tehdit aktörü hakkında bilgi edinilebilir.
dc.description.abstractWith the increase in the presence of information technology and data in cyberspace, groups defined as advanced permanent threat actors emerge and commit crimes of industrial espionage, sabotage and theft. Organizations invest in cyber defense activities and defense technologies necessary for the fulfillment of these activities in order to improve cyber security processes in order to protect data assets. Cyber threat intelligence, on the other hand, is an area that they benefit from in order to strengthen more informed monitoring, detection and response steps within these defense activities. In this study, it is aimed to create a dataset of indicators obtained from threat intelligence and threat actors in order to increase the detection and prevention capabilities of organizations within the scope of defense activities. With the data set to be created by collecting harmful indicators of threat actors and cyberattacks over the Internet, it is aimed to extract similar cyberattack activities before. As a result of the study, it will be possible to extract the harmful indicators used by the cyberattack or threat actor related to the harmful indicator in previous attacks. It will enable to make inferences about the threat actor relationship between the created data set and the detected finding. For example, by looking at the IP address similarity relationship in the data set created with the service provider and IP block information about the IP address detected by the Incident response study, information about a cyberattack or threat actor can be obtained.
dc.identifier.citationYETİMOĞLU, B. (2022). Siber tehdit istihbaratıyla özgün tehdit aktörleri veri kümesi oluşturma ve sınıflandırma (Tez No. 749857) [Yüksek lisans tezi, Fırat Üniversitesi].
dc.identifier.urihttps://tez.yok.gov.tr/UlusalTezMerkezi/TezGoster?key=sELqxhTlFGAjsbjOuuiyCJVGF59-IXSAR-Wc_pf7jL20xVFNKYMsPR9029xUue6Y
dc.identifier.urihttps://hdl.handle.net/11508/22551
dc.identifier.yoktezid749857
dc.language.isotr
dc.publisherFırat Üniveristesi
dc.relation.publicationcategoryTez
dc.rightsinfo:eu-repo/semantics/openAccess
dc.snmzKA_TEZ_20260511
dc.subjectBilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrol
dc.titleSİBER TEHDİT İSTİHBARATIYLA ÖZGÜN TEHDİT AKTÖRLERİ VERİ KÜMESİ OLUŞTURMA VE SINIFLANDIRMA
dc.title.alternativeGenerating and classifying a unique threat actors dataset with cyber threat intelligence
dc.typeMaster Thesis

Dosyalar