DEVSECOPS SÜREÇLERİNİN ÇEVİKLEŞTİRİLMESİ: DİNAMİK LOG ANALİZ YAKLAŞIMI
| dc.contributor.advisor | DOĞAN, ŞENGÜL | |
| dc.contributor.author | EKİZ, BAYBARSHAN | |
| dc.date.accessioned | 2026-08-12T10:09:50Z | |
| dc.date.issued | 2021 | |
| dc.department | FÜ, Fen Bilimleri Enstitüsü, Adli Bilişim Mühendisliği Anabilim Dalı | |
| dc.description.abstract | Yazılım sektörü için her geçen gün artan esneklik ve performans artırım ihtiyacı günümüzde DevOps kavramını var etmiştir. Günümüzde DevOps sistemleri, güncel yazılım geliştirme süreçleri için çok büyük önem taşımaktadır. Güvenlik sektörünün de öneminin son yıllarda çok ciddi bir artış göstermesi de DevSecOps kavramının meydana çıkmasını sağlamıştır. Bu bağlamda sistemlerin kendilerine özgü yapılarına göre sürekli işleyen denetim, operasyon ve geliştirme süreçlerine dair otonom süreç bütünü esneklik ve performans artırımının düşük maliyetle sağlanabilmesi için çok kritik önem taşımaktadır. Bu tez çalışması kapsamında otonom olarak DevSecOps süreçlerini daha çevik bir şekilde tasarlamak amaçlanmıştır. Önerilen DevSecOps modeli, yazılımsal sistemlerin en kaliteli ve güvenli şekilde geliştirilmesi için güvenlik denetim mekanizmalarının sisteme özgü olarak oluşturulabilmesini hedeflemektedir. Önerilen sistem, otonom güvenlik denetim mekanizması için sunucu üzerinde bulunan loglardan faydalanarak öğrenme yapmaktadır. Bu öğrenme kapsamında sistem, üzerinde sömürülmesi muhtemel olabilecek zafiyetlere dair önlem almak üzere istatistiki sonuçlar vermektedir. Önerilen DevSecOps modelini doğru çalışması, ancak anormal durumların ve zafiyet karakteristiklerinin sürekli olarak tespit edilebilir olması durumunda mümkündür. Yapılan çalışmada önerilen DevSecOps modeline yönelik uygulanabilirliğin sınanması için, Docker kaynak kullanım istatistiklerini gösteren log dosyaları oluşturulmuştur. Bu log dosyaları analiz edilerek anormal durumların ve zafiyetlerin karakteristiğinin tespit edilebilirliğine dair, z-skor ve nokta çift serili korelasyon metotlarıyla analiz yapılarak bulgular oluşturulmuştur. Bulgulara göre varılan sonuç göstermektedir ki anormal durum tespitini ve zafiyet karakteristiğini loglar üzerinden tespit edebilmek mümkündür. | |
| dc.description.abstract | The ever-increasing need for flexibility and performance enhancement for the software industry has created the concept of DevOps today. Today, DevOps systems are of great importance for current software development processes. The significant increase in the importance of the security sector in recent years has also led to the emergence of the concept of DevSecOps. In this context, the autonomous process of the control, operation and development processes, which are constantly operating according to the unique structures of the systems, is of critical importance in order to provide flexibility and performance increase at low cost. Within the scope of this thesis, it is aimed to design autonomous DevSecOps processes in a more agile way. The proposed DevSecOps process aims to create system-specific security control mechanisms in order to develop software systems with the highest quality and security. The proposed system learns from the logs on the server for the autonomous security control mechanism. Within the scope of this learning, it gives statistical results in order to take precautions about the vulnerabilities that may be exploited on the system. The proposed DevSecOps model will work properly only if abnormal conditions and vulnerability characteristics are continuously detectable. In order to test the applicability of the DevSecOps model proposed in the study, log files that showing Docker resource usage statistics were created. By analyzing these log files, findings were created by analyzing the characteristics of abnormal situations and vulnerabilities with z-score and point biserial correlation methods. The result obtained according to the findings shows that it is possible to detect abnormal condition detection and vulnerability characteristics through logs. | |
| dc.identifier.citation | EKİZ, B. (2021). DevSecOps süreçlerinin çevikleştirilmesi: Dinamik log analiz yaklaşımı (Tez No. 688911) [Yüksek lisans tezi, Fırat Üniversitesi]. | |
| dc.identifier.uri | https://tez.yok.gov.tr/UlusalTezMerkezi/TezGoster?key=v7BkNnnepTnbhn8rNR77LTu3gqJbOJBrbUkwHaIaNke6EXlO1Is42QWO4hfBrdOb | |
| dc.identifier.uri | https://hdl.handle.net/11508/22529 | |
| dc.identifier.yoktezid | 688911 | |
| dc.language.iso | tr | |
| dc.publisher | Fırat Üniveristesi | |
| dc.relation.publicationcategory | Tez | |
| dc.rights | info:eu-repo/semantics/openAccess | |
| dc.snmz | KA_TEZ_20260511 | |
| dc.subject | Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrol | |
| dc.title | DEVSECOPS SÜREÇLERİNİN ÇEVİKLEŞTİRİLMESİ: DİNAMİK LOG ANALİZ YAKLAŞIMI | |
| dc.title.alternative | Agility of DevSecOps processes: Dynamic log analysis approach | |
| dc.type | Master Thesis |







