Development of a rule-based approach for detecting cyber attacks on windows domain systems
Is this your thesis?
This record came from a bulk archive import. If it’s yours, link it to your profile.
Abstract (EN)
Domain systems, in addition to essential functions such as identity management, access controls, and authorization, also store valuable information contained within objects. Attackers who infiltrate a system often target the domain system because they know it is central to these functions. By directly targeting the domain service, they can steal credentials, gain access to users' and groups' permissions, and potentially access confidential data with unauthorized users, or even spread to other systems and escalate their privileges. Moreover, they can maintain persistence within the system, enabling them to access it without needing to breach it again, cause service disruptions on devices within the Domain structure, access users' private information to employ social engineering tactics, or encrypt the information stored in the domain system to demand ransom. Such attacks, or similar malicious attempts, not only disrupt the operation of the targeted system but also inflict significant financial losses and reputational damage on the organization. This can undermine the organization's credibility, create a negative perception among customers and business partners in the long term, and even threaten the organization's ability to continue its operations. Considering the critical role that the domain system plays in regulating access to a company's sensitive data and resources, it is imperative for organizations to take proactive measures to defend against such attacks. Protecting Active Directory systems is a critical focus for security teams. Identifying these attacks and having knowledge about attacks targeting domain systems provide a significant advantage for cybersecurity teams. Developing Sigma rules to detect these types of cyberattacks and counter such threats is an important aspect. This thesis has developed a rule-based approach for detecting cyberattacks targeting Windows Domain systems. By leveraging Sigma rules, it identifies various attack vectors in Active Directory environments and provides effective detection methods against these threats. Accordingly, it offers a solution that guides organizations' cybersecurity teams in their attack detection and prevention processes. With this approach, the thesis contributes to minimizing potential damages by enabling the early detection of attacks, particularly focusing on the protection of critical data and resources.
Author
Muhammed Aygün
How to Cite
Muhammed Aygün (Master Thesis). Development of a rule-based approach for detecting cyber attacks on windows domain systems, 2024, Fırat University.
Keywords
License
Tüm Hakları Saklıdır
This work is shared under the specified license terms.
More theses from Fırat University
- Using social media as an integrated marketing communication tool(2018)
- Foundation of Dutch East İndia Company and her rising in İndonesia in the 17th century(2013)
- Examination of stress state between Doğanyol (Malatya) and Çelikhan (Adıyaman) on the east Anatolian fault zone(2020)
- Color usage at Turkish Divan of Fuzûlî(2013)
- Yavuzeli (Gaziantep) surrounding volcanic outcropping of rocks petrographic and geochemical features(2014)
- Hizbu?t-Tahrir and the religions and political thoughts of Ercumend Özkan(2008)