SİBER SALDIRI TÜRLERİNİN SİMÜLE EDİLMESİ VE YARA İLE TESPİTİ

dc.contributor.advisorTUNCER, TÜRKER
dc.contributor.authorDEMİR, MUSTAFA EMRE
dc.date.accessioned2026-08-12T10:09:52Z
dc.date.issued2022
dc.departmentFÜ, Fen Bilimleri Enstitüsü, Adli Bilişim Mühendisliği Anabilim Dalı
dc.description.abstractBilişim sistemlerinin oldukça hızlı gelişimi, kurum ve kuruluşların tüm iş süreçlerini bilişim sistemleri üzerine taşımasını ve tüm süreçlerin bu sistemler üzerinde yürütülmesini ortaya çıkarmıştır. Bununla birlikte sistemler üzerinde bulunan şirket verilerinin ve kişisel verilerin güvenliğini sağlamak da bir sektör haline gelmiştir. Aynı zamanda kuruluşların bilişim sistemlerindeki verilerini hedef alan kötü niyetli kişi veya gruplar tarafından verilerin güvenliği tehlikeye atılmaktadır. Kuruluşların bu saldırgan kişi veya gruplar tarafından hedef alınması her geçen gün daha da artmaktadır. Dolayısıyla kuruluşlar kendi sistemlerini korumak amacıyla siber güvenlik için çeşitli çözümler kullanmaya başlamışlardır. Ancak bu çözümler sürdürülebilir bir siber güvenlik alt yapısı ve fiziksel ekibi olmayan kuruluşlar için yeterli değildir ve bu kuruluşlar saldırganların hedefi olmaktan kaçınamazlar. Saldırganların hedefi olmuş bir kurum veya kuruluşta oluşacak hasarın en aza indirgenmesi, oluşan hasarın onarılması ve yetkisiz erişimlerin kaldırılması için Adli Bilişim ve Olay Müdahalesi süreçleri işletilir. Adli bilişim ve olay müdahalesi süreçlerinde inceleme yapılan kurum alt yapısındaki tüm uç noktaların hızlı bir şekilde analiz edilmesi ve tüm tehdit unsurlarının tespit edilip ortadan kaldırılması kurum faaliyetlerinin devam etmesi açısından önem arz etmektedir. Bu tez çalışmasında siber dünyada aktif olarak sıkça kullanılan saldırı türlerinin analizi yapılmaktadır. Aynı zamanda bu saldırı türleri simüle edilmektedir. Adli Bilişim ve Olay Müdahale süreçlerinde Windows ve Linux sistemlerin bulunduğu bir sanal ortam oluşturularak bu ortamda sık kullanılan siber saldırı yöntemlerinin uygulanması ve bu yöntemlere karşı savunma mekanizmalarının geliştirilmesi, olay örgüsünün çözülerek kök sebebin ortaya çıkarılmasına katkı sağlamak hedeflenmiştir. Bu çalışmanın motivasyonu tüm kurum ve kuruluşların karşı karşıya olduğu siber tehditlerle baş edebilmektir. Tez çalışmasında yapılan uygulamada Windows sistemlerde sıkça karşılaşılan zararlı yazılım türevlerinin manuel tekniklerle ve açık kaynak çözümlerden olan YARA ile tespitinin nasıl yapıldığı açıklanmıştır.
dc.description.abstractInformation systems are developing rapidly. Companies move their business processes to information systems and all processes are carried out on these systems. However, it has become important to ensure the security of company data and personal data on the systems. At the same time, the security of the data was compromised by malicious individuals or groups targeting the data of the organizations' information systems. The targeting of organizations by these aggressive individuals or groups is increasing day by day. Therefore, organizations started to use various solutions for cyber security in order to protect their systems. However, these solutions are not enough for organizations that do not have a sustainable cybersecurity infrastructure and physical team, and these organizations cannot avoid being the target of attackers. In the first few sentences, the importance of the subject and the aim of the thesis should be defined and brief information about the method and findings should be presented. Finally, the information produced should be expressed briefly. A company that has been targeted by attackers operates DFIR processes to minimize damage. In DFIR processes, all endpoints in the infrastructure of the institution should be analyzed quickly and all threat elements should be detected and eliminated. This institution is important for the continuation of its activities. In this thesis, the analysis of attack types that are actively used in the cyber world is made. At the same time, these attack types are simulated. A virtual environment with Windows and Linux systems was created in Digital Forensic and Incident Response processes. In this environment, frequently used cyber-attack methods were applied and developed defense mechanisms against these methods. The motivation of this study is to cope with the cyber threats faced by all institutions and organizations. In the application made in the thesis study, it is explained how the malware variants, which are frequently encountered in Windows systems, are detected with manual techniques and YARA, which is one of the open- source solutions.
dc.identifier.citationDEMİR, M. (2022). Siber saldırı türlerinin simüle edilmesi ve YARA ile tespiti (Tez No. 742476) [Yüksek lisans tezi, Fırat Üniversitesi].
dc.identifier.urihttps://tez.yok.gov.tr/UlusalTezMerkezi/TezGoster?key=sELqxhTlFGAjsbjOuuiyCPP9EBZM3rwGp51Gu6xCfmnAh4OFGL1FqY2g0egyHWPC
dc.identifier.urihttps://hdl.handle.net/11508/22550
dc.identifier.yoktezid742476
dc.language.isotr
dc.publisherFırat Üniveristesi
dc.relation.publicationcategoryTez
dc.rightsinfo:eu-repo/semantics/openAccess
dc.snmzKA_TEZ_20260511
dc.subjectSavunma ve Savunma Teknolojileri
dc.titleSİBER SALDIRI TÜRLERİNİN SİMÜLE EDİLMESİ VE YARA İLE TESPİTİ
dc.title.alternativeSimulations cyber security attack types and detection with YARA
dc.typeMaster Thesis

Dosyalar