
22
Archived Theses
0
DOIs Assigned
0%
DOI Rate
Discipline
Veriyükü üzerinden sql enjeksiyon zafiyetlerin belirlenmesi
Sürekli gelişen teknoloji ile birlikte bilgiye hızlı erişim, depolamak, gibi ihtiyaçlarının yanında bilgisayar sistemlerinin kullanımı da paralel olarak artmaktadır. Bu sistemler içerisinde özellikle kurum ve kuruluşlar önemli bilgilerini bulundurmakta ve kullanmaktadırlar. Her alanda olduğu gibi bilgisayar sistemleri de bulundurdukları önemli kaynaklardan dolayı siber saldırganlar tarafından tehdit altındadır. Bu tehditlere karşı her alanda olduğu gibi güvenlik önlemleri alınmaktadır. Güvenlik duvarları (firewalls), saldırı tespit ve önleme sistemleri (IPS/IDS), içerik filtreleme sistemleri, anti virüs yazılımları, kod güvenliği sıkılaştırmaları gibi donanımsal ve yazılımsal olarak önlemler alınmaktadır. Siber saldırganlar tarafından bilgisayar sistemlerine özellikle kritik ve gizli derecedeki bilgileri ele geçirebilmek için çeşitli siber saldırılar yapılmaktadır. Bu siber saldırılardan birisi en yaygın ve en tehlikeli saldırı türü olan Structured Query Language (SQL) enjeksiyon saldırısıdır. SQL enjeksiyon saldırısı, bir veri tabanı kullanan uygulama üzerindeki kodların güvenlik açıklarından faydalanılarak, siber saldırganın yetkisi olmadan gizli bilgileri ele geçirmeye yönelik amacı doğrultusunda güvenlik zafiyetinin sömürülmesi şeklidir. Bu tez çalışmasında, SQL enjeksiyonu, SQL enjeksiyon saldırılarının sınıflandırılması, SQL enjeksiyon zafiyetinin belirlenme yöntemleri anlatılmıştır. Web uygulamaları üzerindeki SQL enjeksiyon zafiyetinin belirlenmesine yönelik çalışmalar yapılmıştır. Bu çalışmalar web uygulama güvenliğine yönelik olarak oluşturulmuş içerisinde web güvenlik zafiyetleri barındıran Damn Vulnerable Web Application (DVWA) ve Web For Pentester uygulamaları üzerinde yapılmıştır. SQL enjeksiyon zafiyetinin belirlenmesinde elle yapılan sorgular ve Burp Suite, Sqlmap, Kali Linux, Havij, Acunetix, Netsparker gibi web zafiyeti ve penetrasyon testi araçları kullanılmıştır. Bu araçların gerçekleştirdikleri veri yükleri ve elle yapılan SQL enjeksiyon sorgulamaları analiz edilerek karşılaştırılmıştır.
Zararlı URL'lerin derin öğrenme ile tespiti
Günümüzde internetin her geçen yıl kullanımın artmasıyla hayatımızda çok önemli bir hale gelmiş ve yeni iletişim teknolojileri, sosyal ağlar, e-ticaret, kullandığımız teknolojik ev aletlerinden, çevrimiçi bankacılık dâhil olmak üzere birçok uygulamada işlerin teşvik edilmesinde ve büyütülmesinde önemli bir etkiye sahiptir. Bu tez çalışmasının amacı, kullanılan yapay zekâ modeli ile zararlı URL adreslerini tespit edilmesi sağlanmış, bu işlemler için büyük bir veri seti ile çalışılmış ve en iyi sonucu elde etmek hedeflenmiştir. Bu tezde literatürde yapılan çalışmalar incelenmiştir, veri setlerinin büyüklüğü ile doğruluk başarı oranına katkısı görülmüştür. Yapılan çalışmada, veri setindeki URL sayısının fazla olması ve RNN model mimarisinin kullanılması performans değerlerini 2 puan oranında arttırmıştır. Çalışmada oluşturulan, 7 katmanlı RNN modeli kullanılmış, modelde çalıştırmak üzere ulusal ve uluslararası birbirine benzer iki adet veri seti birleştirilmiş, 579.112 adet URL adresinden oluşan devasa bir yeni veri seti oluşturulmuştur. Daha sonra bu yeni veri seti eğitim ve test setlerine ayrılmıştır. İlk olarak veri setimiz modelde eğitilmiş ve ardından ikinci veri seti test edilmiştir. Bu veri seti modelimizde işlendiğinde %91 doğruluk oranı elde edilmiştir. Bu çalışmamızla, zararlı URL adreslerinin tespiti için daha etkin yöntemlerin geliştirilmesine önemli katkı sağlamak hedeflenmektedir.
Siber saldırıların loglar üzerinden tespit edilmesi ve önlenmesi
Teknoloji kullanımı giderek yaygınlaşmakta, insan hayatının vazgeçilmezleri arasında yer almaktadır. Teknolojinin tüm alanlarda yaygın olarak kullanılması bilgisayar sistemleri üzerinde güvenlik açıklarının oluşmasına neden olmaktadır. Sistemlere yapılan saldırıların nereden ne zaman kim tarafından yapılacağı bilinmemektedir. Bu bağlamda sistemler üzerinde gerçekleşen işlemlerin internet izlerinin tutulması, log kayıtlarının alınması, yaşanan birçok siber saldırıyı çözme konusunda uzmanlara fayda sağlamaktadır. Sistemler üzerindeki zafiyetlerin hackerlar tarafından fark edilmesiyle beraberinde çeşitli siber saldırılar ortaya çıkarmıştır. Tespit edilen bu zafiyetler üzerinden network sistemi üzerinde hakimiyet kurmaları, maddi kazanç elde etmeleri ve itibari sebepler yer alabilmektedir. Bu durum sistemlerin bilgi bütünlüğünü bozmaktadır. Bu çalışma kapsamında log kayıtları üzerinden siber saldırıların tespit edilebileceği ve siber saldırıların engellenebileceği araştırılmıştır. Bu çalışma loglar üzerinden siber saldırıların tespit edilmesi ve engellenmesi, siber saldırılara karşı çözümlerin üretilmesi bakış açısıyla literatüre katkı sağlayacağı düşünülmektedir.
Bilişsel radyo ağlarda spektrum algılama veri sahtecilik saldırılarına karşı iş çıkarma oranının artırılması
Bilişsel Radyo (CR) ağları, dinamik spektrum erişimi sağlar ve spektrum verimliliğini önemli ölçüde artırabilir. İşbirlikçi Spektrum Algılama (CSS), algılama doğruluğunu artırmak için CR kullanıcıları arasındaki uzamsal çeşitlilikten yararlanır. Ancak gerçekçi bir senaryoda, güvenilir CSS, Spektrum Algılama Verilerinde Sahtecilik (SSDF) saldırısına karşı savunmasızdır. Bir SSDF saldırısında, bazı kötü niyetli CR kullanıcıları kasıtlı olarak tahrif edilmiş yerel algılama sonuçlarını bir veri toplayıcıya veya Füzyon Merkezine (FC) bildirir ve ardından sezme kararını etkiler. Bu çalışmada, bir SSDF saldırısı için analitik bir model araştırıp böyle bir saldırıya karşı sağlam bir savunma stratejisi öneriyoruz. FC'nin saldırı parametrelerini elde etmek ve daha iyi bir savunma stratejisi kullanmak için öğrenme ve tahmin yöntemlerinin uygulanabileceğini gösteriyoruz. Ayrıca, log-normal gölge sönümlü bir kablosuz ortam varsayıyoruz ve SSDF saldırısının gücünü etkileyebilecek saldırı parametrelerini tartışıyoruz. Bu çalışmanın sonuçları, özellikle kötü niyetli kullanıcıların çoğunlukta olduğu durumlarda, SSDF saldırılarına karşı önerilen savunma yönteminin etkinliği gösterilmektedir.
Antivirüs seçimi için bulanık analitik hiyerarşi süreci tekniği ve bir uygulama
İnsanların yaşamlarının kolaylaşmasında önemli bir yere sahip olan bilgi teknolojileri, internet kullanımına duyulan ihtiyacı arttırmıştır. İnternet ile bu teknolojiler zaman, maliyet, işgücü gibi farklı alanlarda kolaylıklar sağlamıştır. Endüstri 3.0 ile başlayan teknoloji süreci, Endüstri 4.0 ile akıllı teknolojilere zemin hazırlamıştır. Nesnelerin İnterneti ile milyarlarca cihazın uyum içerisinde çalışması mümkün hale gelmiştir. İnternet kullanıcılarının sayısındaki artış, internet kullanımından kaynaklanan güvenlik sorunlarını beraberinde getirmiştir. Akıllı teknolojiler ile sürekli yenilenen ve döngü halinde tekrarlanan güvenlik sorunları, dikkat çekici bir boyuta ulaşmıştır. Gerçekleşen sorunlar nedeniyle ülkemiz Türkiye Cumhuriyeti ve diğer devletler de önlemlerini almıştır. Bilgi Teknolojileri ve İletişim Kurumu, Cumhurbaşkanlığı Dijital Dönüşüm Ofisi, Türkiye Bilimsel ve Teknolojik Araştırma Kurumu gibi ülkemiz devlet kurumlarının ya da küresel ölçekte yer alan Birleşmiş Milletler, Kuzey Atlantik Antlaşması Örgütü gibi uluslararası kuruluşların da yaşanan teknoloji süreci içerisinde, siber güvenliği azami düzeyde önemsediği görülmektedir. Bilgisayar kullanan kişi sayısının, küresel ölçekte artması nedeni ile hem sistem yöneticileri hem de kişisel kullanıcılar için antivirüs yazılımlarına duyulan ihtiyaç da her geçen gün artış göstermektedir. Günümüzde virüslerin, cihazlara zarar veren etkilerinin önlenmesinde antivirüs yazılımlarından yararlanılmaktadır. Antivirüs yazılımları kendi aralarında farklılık gösterdiğinden dolayı antivirüs yazılımı seçim problemi ortaya çıkmıştır. Bu tez çalışmasında, bilgisayar kullanıcıları tarafından çok tercih edilen 5 farklı antivirüs yazılımı belirlenen kriterlere göre karşılaştırılmıştır. Kriterlerin belirlenmesinde ve karşılaştırılmasında 3 kişilik uzman bir ekipten alınan görüşlere başvurulmuştur. Ele alınan antivirüs yazılımı seçim problemi için Bulanık Analitik Hiyerarşi Süreci yönteminin, Mertebe Analiz Tekniği yaklaşımı kullanılarak uygun antivirüs yazılımı seçilmesine çalışılmıştır. Anahtar Sözcükler: Antivirüs Seçimi, Bulanık Analitik Hiyerarşi Süreci Yöntemi, Mertebe Analiz Tekniği, Siber Güvenlik
Blockchaın tabanlı IoT güvenliği ve performans analizi
Nesnelerin İnterneti (IoT), çeşitli cihazların birbirine bağlanarak veri alışverişi yapmasını sağlayan bir ağ yapısını ifade etmektedir. Bu teknolojinin benimsenmesi, endüstriyel süreçlerden günlük yaşam aktivitelerine kadar birçok alanda gelişme sağlamaktadır. Ancak, IoT cihazlarının sayısındaki hızlı artış, beraberinde önemli güvenlik sorunlarını da getirmektedir. Özellikle; siber saldırılar, veri ihlalleri ve yetkisiz erişimler, IoT sistemlerinin güvenliğini tehdit eden başlıca unsurlar haline gelmiştir. Bu tez çalışmasında, IoT güvenliğini artırma hedefiyle blockchain teknolojisinin birleşimi incelemekte ve bu bağlamda Hyperledger Fabric'in sağladığı avantajları değerlendirmektedir. Blockchain teknolojisi, özellikle izinli ağ yapısı ve merkeziyetsizlik özellikleri ile IoT sistemlerine büyük katkılar sağlayabilir. Blockchain, verilerin güvenli bir şekilde saklanmasını sağlarken, veri bütünlüğünü ve gizliliğini de artırmaktadır. Hyperledger Fabric, bu güvenlik gereksinimlerini karşılamak için ideal bir platform sunmakta; modüler mimarisi sayesinde organizasyonlara esneklik sağlamaktadır. OPNET benzetim aracı ile blockchain kullanılarak şifrelenen paketleri ileten IoT ağının performansı detaylı bir biçimde analiz edilmektedir. Benzetimler, blockchain teknolojisinin IoT sistemlerine birleşiminin güvenlik seviyelerini nasıl artırabileceğini ve siber tehditlere karşı koruma sağladığını göstermektedir. Ayrıca, bu çalışmada, blockchain kullanılarak şifrelenen paketleri ileten sistemlerin kullanıcıların kimlik doğrulama süreçlerini güvence altına alarak yetkisiz erişimlerin önüne geçme potansiyeli incelenmektedir. Sonuç olarak, bu tez çalışmasında, blockchain teknolojisinin IoT güvenliğini sağlama potansiyelini ortaya koymakta ve endüstriyel uygulamalar için pratik çözümler sunmaktadır. Gelecekte IoT sistemlerinin güvenliğinin sağlanmasında blockchain'in önemli bir rol oynayacağına dair bulgular sunarak, bu alanda daha fazla araştırma yapılmasının gerekliliğini vurgulamaktadır. Bu çalışma hem akademik literatüre katkıda bulunmayı hem de pratik uygulamalar için bir temel oluşturmayı amaçlamaktadır. IoT güvenliğine yönelik bu yaklaşım, yalnızca teknoloji geliştirme sürecinde değil, aynı zamanda endüstriyel uygulamalarda da önemli bir yere sahip olacaktır.
Kurumsal ağlarda iç ağdan gelen atak ve tehditlerin makine öğrenimi yöntemleri ile sınıflandırılması ve anomali tespiti
Kurumsal ağlar, hem dış hem iç kaynaklı siber tehditlere karşı oldukça kırılgan bir yapı sergilemektedir. Günümüzde dijitalleşmenin hızla artmasıyla birlikte, kurumlar daha fazla ağ bağlantısına ve cihaz kullanımına sahip olmakta, bu da beraberinde yeni güvenlik risklerini getirmektedir. Kurum ağlarında genellikle dış kaynaklı siber saldırılar ve tehditler ana odak noktası olsa da, iç ağdan gelebilecek saldırılar sıklıkla göz ardı edilebilmektedir. Ancak, iç ağda oluşabilecek bir güvenlik ihlali, dışarıdan gelen bir saldırı kadar ciddi sonuçlar doğurarak maddi kayıplara ve itibar zedelenmesine yol açabilmektedir. Bu çalışmada, yeni nesil güvenlik duvarı sistemlerinden elde edilen gerçek zamanlı tehdit logları kullanılarak ağ üzerindeki anormal aktivitelerin makine öğrenmesi yöntemleriyle tespit edilmesi ve sınıflandırılması amaçlanmıştır. İlk aşamada, yalnızca güvenlik duvarı logları kullanılarak analiz yapılmış, ikinci aşamada ise CICIDS2018 veri setinden alınan davranışsal özellikler eklenerek sistemin performansı yeniden değerlendirilmiştir. Çalışmada GRU, LSTM, XGBoost ve MLP algoritmaları kullanılmış, modellerin başarımı F1 skoru temel alınarak ölçülmüştür. Sonuçlara göre, XGBoost modeli her iki aşamada da en yüksek performansı göstermiş, davranışsal verilerin eklenmesiyle F1 skoru 0,9839'dan 0,9909'a yükselmiştir. Bu artış, davranışsal analiz yöntemlerinin tehdit tespiti performansını iyileştirdiğini ortaya koymuştur. LSTM ve GRU modelleri, özellikle davranışsal özelliklerin eklendiği veri setinde, zaman serisi bağımlılıklarını yakalama yetenekleri sayesinde istikrarlı sonuçlar üretmiştir. Elde edilen bulgular, makine öğrenmesi tabanlı yaklaşımların yeni nesil güvenlik duvarı loglarında tehditlerin doğru ve etkin bir biçimde sınıflandırılmasında güçlü ve uygulanabilir bir yöntem sunduğunu göstermektedir. Anahtar Sözcükler: Anomali Tespiti, Davranışsal Analiz, Güvenlik Duvarı, Tehdit Sınıflandırma, XGBoost
Oyun geliştirme platformlarında blockchain tabanlı, güvenli bir ödeme sitemi geliştirme
Oyun, geçmişten günümüze eğlencenin en önemli unsurlarından biri olmuştur. Sanal bir dünya ile alternatif evrenler sunan oyunlar, kendi içlerinde yarattıkları ekonomi sayesinde gerçek dünya ile maddi temas sağlayabilmektedir. Bu noktalardaki para kazanma yöntemlerinden biri de oyun içi kostüm, eşya, ikon ve benzeri edinimlerin gerçek dünya parası ile satılması ve gerçek dünyada bir varlık yaratılmasıdır. Blockchain teknolojileri sayesinde bu varlıklar son derece güvenli bir şekilde merkezsiz olarak saklanabilmektedir. Şifreleme yöntemleri ve dağıtık defter yapısı sayesinde bu teknoloji, kullanıcıların dijital varlıklarını üçüncü taraflara ihtiyaç duymadan güvenli bir ortamda saklamalarına olanak sağlıyor. Blockchain sadece oyun sektöründe değil, finans, sağlık, lojistik, eğitim ve daha birçok alanda devrim niteliğinde yenilikler sunan teknolojik bir gelişmedir. Özellikle verilerin değişmez ve şeffaf bir şekilde saklanmasını sağlayarak güvenilirliği artırıyor ve aracılara olan bağımlılığı azaltıyor. Bu sayede blockchain, dijital ekonomiden sosyal sistemlere kadar geniş bir alanda insan hayatını derinden etkileyen ve yeniden şekillendiren bir unsur haline gelmiştir. P2E (Play to Earn), oyunlarda oynadıkça kripto varlıkları kazanmaya yönelik bir modeldir. Oyuncunun oyun oynama süresini kazanarak artırmayı hedefler. Bu da oyuna bağlı kripto varlıkların değerini artırır ve bir ekonomi yaratır. Benzer şekilde, NFT (Non-Fungible Token) kazanıp satarak, blockchain teknolojisi oyunlarda gerçek dünya kazançları elde edilmesini sağlar. Dijital varlıkların gerçek dünyadaki karşılığı yüksek güvenlik önlemleri gerektirir. Blockchain teknolojisi burada ana aktörlerden biridir. Oyun geliştirme platformlarında blockchain tabanlı ödeme sistemlerinin güvenliği, işlem bütünlüğünü, kullanıcı gizliliğini ve varlık sahipliğini artırmaya odaklanan kritik bir araştırma alanıdır. Blokchaini teknolojisi, veri tahrifatı ve yetkisiz erişim gibi geleneksel ödeme sistemleriyle ilişkili riskleri azaltan merkezi olmayan bir çerçeve sunar. Bu çalışmada model mimari olarak Solana blockchain altyapısı entegre edilmiştir. Solana'nın yüksek hızlı ve düşük maliyetli işlem özelliklerinden yararlanılarak projenin temel gereksinimlerini karşılayacak bir sistem tasarımı gerçekleştirilmiştir. Akıllı sözleşmeler Rust programlama dili kullanılarak geliştirildi. Blockchain tabanlı ödeme sistemlerinin güvenilir ve verimli çalışmasını sağlamak için Rust'ın performans odaklı ve güvenli bellek yönetimi özellikleri tercih edildi. Akıllı sözleşme geliştirme sürecinde işlem mantığı, veri doğrulama ve güvenlik önlemleri gibi unsurlar özenle tasarlandı. Ayrıca token transfer fonksiyonları ve kullanıcı yetkilendirme süreçleri Solana'nın Program Library standardı kullanılarak modellendi. Web tabanlı kullanıcı arayüzü React kütüphanesi kullanılarak oluşturuldu. React'in bileşen tabanlı mimarisi ve dinamik veri yönetimi yetenekleri, kullanıcı deneyimini geliştirecek bir arayüz geliştirilmesini sağladı. Bu süreçte kullanıcıların dijital cüzdanları üzerinden sisteme güvenli bir şekilde erişebilmeleri için dijital cüzdan entegrasyonu gerçekleştirildi. Kullanıcıların blockchain işlemlerini kolayca gerçekleştirebilmelerini sağlayan Phantom, Sollet vb. gibi Solana uyumlu cüzdanlar tercih edildi. Sistem bileşenleri detaylı olarak analiz edilmiş ve mimari tasarımın temel taşları olarak belirlenmiştir. Bu bileşenler arasında akıllı sözleşmeler, blokchaini ağı, kullanıcı arayüzü ve dijital cüzdanlar yer almaktadır. Ayrıca bu bileşenler arasındaki iletişim mekanizmaları tanımlanmış ve veri akışını optimize etmek için gerekli protokoller belirlenmiştir. Sistem, kullanıcıların işlem güvenliğini ve veri bütünlüğünü sağlamayı amaçlayan bir yapıda tasarlanmıştır. Bu yöntem ve araçlar bir araya getirilerek, blockchain tabanlı ödeme sistemlerinin oyun geliştirme platformlarında uygulanabilirliğini değerlendiren bir model sunulmuş ve proje güvenlik açısından tartışılmıştır. Bu tez, akıllı sözleşmenin Rust ile ilgili güvenlik, giriş ve çıkış işlemleri, kullanıcı ve imzalayan kimliklerinin güvenli çalışması gibi güvenlik açıklarını ve avantajlarını inceleyerek oyun platformlarında blokchaini tabanlı ödeme sistemlerinin güvenliğine genel bir bakış sunmaktadır.
Detecting android malware by using fuzzy set-based weighting method and firefly optimization algorithm
Android OS is open-source and easy to use mobile operating system. It is also user-friendly with many other features. In this way, it is a very preferred operating system on mobile phones. As a result, it becomes the target of malicious people. Applications installed on the Android operating system from the Google Play Store or by third-party application providers, also known as Android package files, may contain malicious software. So far, a variety of analyzes and detections have been made to detect such malware. While detecting malware, good results have been obtained with various methods, but malicious people have developed methods of hiding themselves against these methods. We propose a new feature selection method based on Firefly Optimization Algorithm with the Fuzzy Set-Based weighting method. The proposed method performs better than traditional feature selection methods with fewer features. The experimental results of this study proved that Firefly Optimization is an acceptable optimization algorithm for feature selection to detect malware in terms of classification performance and classification runtime. In addition, experimental evaluation of TF-IDF and Fuzzy Set-Based weighting methods indicates the effectiveness of the Fuzzy Set-Based weighting with a full feature set.
Human activity recognition using deep convolutional neural network
Human activity recognition problems involve the processes of recording and analyzing a person's daily life to identify people's behavioral patterns. Various methods such as Video-Based activity recognition and Sensor-Based activity recognition have been developed to collect activity data. Studies have been carried out by recording activities such as walking, sitting, running, jumping, climbing stairs, climbing stairs by means of depth sensors, wearable (portable) devices, and RGB cameras. Systems have been developed especially in the fields of health, the internet of things, smart cities, transportation, and security with activity recognition. Activity-sensitive approaches have been developed for security monitoring and threat detection through activity recognition. By monitoring activity-based anomalies, potential threats can be identified, and appropriate precautions can be taken. Data collection has become extremely easy because of accelerometer, gyroscope, magnetometer sensors found in almost any smart device. Deep learning methods such as ANN, CNN, RNN, and LSTM are used to classify the obtained data. In our research, we mainly focused on sensor-based activity recognition. Classification tasks were done using 1-D Convolution Neural Network feeding the raw data from the UCI-HAR dataset using accelerometer and gyroscope data. Raw data filtered using Median Filter. We didn't apply any mathematical or statistical feature extraction methods to the data. For the experimental results, we implemented 6, 7, and 12 classes activity recognition, and achieved accuracies of 96.95%, 95.03%, and 93.08%, respectively.
A novel two phased approach combining deep learning and machinelearning classifiers for effective detection of turkish phishing web sites
With the increase in internet speed and the parallel rise in the number of internet-connected devices, online fraud has exhibited a significant surge in recent years. Attackers exploit platforms such as WhatsApp, email, SMS, mobile notifications, and social media messages to disseminate content that is attention-grabbing, intriguing, or fear-inducing. By inducing users to interact with these contents and click on embedded links, these malevolent actors redirect users to counterfeit websites that closely mimic authentic ones, thereby obtaining users' confidential information or engaging in various forms of deception. Commonly referred to as "phishing" sites, these malicious web pages are often used for such deceptive operations. Consequently, it is of paramount importance that mobile applications or browsers possess the capability to identify such harmful websites even before users access them. This study employs a two-stage approach to achieve a 98.4% success rate in identifying malicious sites. The dataset used consists of a list of malicious sites from the National Cyber Incident Response Center (USOM) alongside legitimate domain names. The dataset is divided into two subsets, namely Dataset1 and Dataset2. Dataset1 is employed to train a deep learning-based artificial intelligence model, which yields an accuracy rate of 92% upon completion of training. The websites within Dataset2 are subjected to the deep learning model in the initial stage to acquire phishing scores. Subsequently, by incorporating additional features pertaining to each website and employing a machine learning model for binary classification, the second stage of training facilitates the culmination of the ultimate outcome. Test results demonstrate the capacity to predict phishing incidents with a 98.4% accuracy score for a given website. Keywords: Online Fraud, Cyber Attack, Machine learning, Deep learning, Malicious URL
Metin tabanlı captcha araçlarında görsel özelliklerin rolü: kullanılabilirlilik için fnirs çalışması
In order to mitigate dictionary attacks or similar undesirable automated attacks to information systems, developers mostly prefer using CAPTCHA challenges as Human Interactive Proofs (HIPs) to distinguish between human users and scripts. An appropriate use of CAPTCHA requires a setup balance between robustness and usability during the design of a challenge. The previous research reveals that most of the usability studies have used accuracy and response time as measurement criteria for quantitative analysis. The present study aims at applying optical neuroimaging techniques for the analysis of CAPTCHA design. In particular, fNIRS (Functional Near Infrared Spectroscopy) is a neuroimaging technique used for mental workload analysis by means of analyzing hemodynamic responses on brain. The present study reports an experimental investigation in which 25 participants solved a group of text-based CAPTCHA with various visual characteristics.
Makina öğrenmesi ile kurumsal bir ağda anomali tabanlı siber ihlal tespit sistemi: keşif saldırıları üzerinde bir vaka çalışması
Cyber attacks constitute a serious threat to organizations with implications ranging from economic, reputational and legal consequences. As the techniques employed by cyber criminals get more sophisticated, information security professionals face a greater challenge protecting the famous triangle of confidentiality, integrity and availability (CIA). In today's interconnected realm of computer systems, every attack vector has a network dimension. Therefore, this study aims to detect network intrusion attempts with an anomaly-based machine learning model to provide better protection than the conventional misuse-based models. Two different models were built and implemented on a data set gathered from a production environment, ensemble learning and convolutional neural network respectively. To demonstrate the models' reliability and validity, they were applied on UNSW-NB15 benchmarking data set as well. To keep the scope of the study manageable, probing type of attack was focused on and models were trained accordingly. The results suggested that both models detect the chosen type of intrusion attempts with an F1 score of more than 0.97. Convolutional neural network model scored slightly higher with 0.99. Similar results were obtained in UNSW-NB15 data set pointing the proposed model's validity.
IoT cihazlarda veri akışının analizi ve akıllı ev ağındaki MUD uygulamalarının güvenliğinin değerlendirilmesi
IoT usage has shown significant growth in the past decades. A major target for the IoT market is the living spaces which have become smarter by the integration of IoT devices. However, the network infrastructure have not been developed from the perspective of Cyber security. IoT devices are subject to Cyber security threats in multiple fronts. For example, infected IoT devices may contribute to DDoS attacks that target global Internet services, such as the DNS. For mitigation of the attacks, various solutions have been proposed. In this thesis, we review available solutions with a particular focus on the application of a standardized whitelisting method, namely Manufacturer User Description (MUD). For an evaluation of MUD usage in IoT networks, we analyzed traffic of two devices with the aim of detecting recognizable and distinctive traffic patterns. We established specific MUD files based on the detected traffic patterns and evaluated the MUD files for the validation of their proof of work.
Ascon ve Drygascon şifrelerinin diferansiyel-lineer kriptanalizi
Due to rapidly developing technology, devices have become smaller along with their performance capacity and memory. If possible, existing NIST-approved encryption standards should be used on these resource-constrained devices. When an acceptable performance cannot be achieved in this way, there is a need for more lightweight algorithms. Since taking individual measures leads to simplistic designs when designing lightweight algorithms, ciphers can become more vulnerable to cryptographic attacks. Hence some regulation is necessary. To satisfy this need, NIST has decided to start a lightweight cryptography competition to select one or more lightweight algorithms. In this study, we examined Second Round NIST Lightweight Cryptography Standardization Competition candidates to contribute to the course of the competition. Then we focused on two different but structurally very similar cipher suites Ascon and Drygascon to compare their security. We observed 2, 3, 3.5-round truncated differential and 5-round differential-linear distinguishers that were given for Drygascon are erroneous. We present the corrected results and provide the longest practical differential-linear distinguisher of Drygascon. After that, we compared the security of Ascon and Drygascon. We observed that the practical data complexity of the two is very close. However, since Ascon has more rounds than Drygascon, we concluded that Ascon might be more resistant against differential-linear cryptanalysis.
Siber tehdit istihbarat paylaşım teknolojileri ve blokzincir kullanılarak oluşturulan tehdit paylaşım modeli
Against the measures taken, the nature of the threats in the cyber environment is evolving day by day. While script kiddie made amateur cyber attacks were usually experienced beforehand, more sophisticated and targeted attacks are frequently encountered nowadays. Besides that, commonly used signature based techniques for attack detection and threat information staying within organization is insufficient for dynamically changing, organized and targeted threats. Furthermore, with the advance of new technology, computer networks are growing, the number and variety of interconnected devices are increasing and as a consequence attack surface is expanding. As a result, it does not seem possible to reduce all of the vulnerabilities that we encounter. From now on, cyber attack is not a matter of 'if', but it is a matter of 'when'. In order to detect complex attacks one of the newly developed approaches is cyber threat intelligence sharing. Threat intelligence is evidence-based knowledge about threat and assists to decide. It has no value if it is not disseminated though. Organizations can increase situational awareness about targeted cyber threats by sharing internal cyber threat information with trusted partners and integrating external cyber threat information with their security systems in real-time basis. However, common language that allows automation at identification and sharing of threat information is crucial for timely intervention. To that end, various standards are being developed by many organizations and companies. In this study, standards and tools developed for the representation and sharing of threat information are compared, and new threat sharing model is developed using a permissioned blockchain.
Zararlı kod tespiti: LSTM ile run trace analizi
Malicious software threats and their detection have been gaining importance as a subdomain of information security due to the expansion of ICT applications in daily settings. A major challenge in designing and developing anti-malware systems is the coverage of the detection, particularly the development of dynamic analysis methods that can detect polymorphic and metamorphic malware efficiently. In the present study, we propose a methodological framework for detecting malicious code by analyzing run trace outputs by Long Short-Term Memory (LSTM). We developed models of run traces of malicious and benign Portable Executable (PE) files. We created our first dataset from run trace outputs obtained from dynamic analysis of PE files. The obtained dataset was in the instruction format as a sequence and was called Instruction as a Sequence Model (ISM). By splitting the first dataset into basic blocks, we obtained the second one called Basic Block as a Sequence Model (BSM). The experiments showed that the ISM achieved an accuracy of 87.51% and a false positive rate of 18.34%, while BSM achieved an accuracy of 99.26% and a false positive rate of 2.62%.
Saldırgan gözüyle parola saldırılarının birden çok balküpü sistemiyle analizi
Authentication is vital for secure operation of ICT systems. Since the past several decades, alternative solutions have been developed for authentication, such as biometric authentication methods, aiming at replacing passwords. Nevertheless, their success has been limited as evidenced by intensive use of passwords. Today, an average user uses dozens of different passwords in daily practice. The frequent use of passwords in authentication also leads to a close interest of attackers due to rapid the expansion of ICT for the past several decades. Recently, almost 70% percent of cyber attacks target user credentials. This study investigates password attacks from the attacker's perspective by using ten honeypot systems that run mock SSH services. The focus of the analysis is the efficiency of the blacklisting approach against password attacks, and the analysis of the attitudes of attackers as recorded in log files. The relationship between the passwords used in the attacks and the local language of the target country was also investigated using a language identification model.
Yığınlanmış çift yönlü uzun-kısa süreli bellek kullanarak zararlı yazılım tespiti
The recent proliferation in the use of the Internet and personal computers has made it easier for cybercriminals to expose Internet users to widespread and damaging threats. In order protect the end users against such threats, a security system must be proactive. It needs to detect malicious files or executables before reaching the end-user. To create an efficient and low-cost malware detection mechanism, in the present study, we propose stacked bidirectional long short-term memory (Stacked BiLSTM) based deep learning (DL) language model for detecting malicious code. We developed language models using assembly instructions from .text sections of malicious and benign Portable Executable (PE) files. We created our first dataset from assembly instructions obtained from static analysis of the PE files. The dataset was composed of text documents, and it was used in Document Level Analysis Model (DLAM). By splitting the first dataset into single instructions, we obtained the second dataset, which was then used in a Sentence Level Analysis Model (SLAM). We treated each instruction as a sentence, and .text sections as documents. We labeled each document and sentence by their corresponding malicious and benign tags. The experiments showed that the Document Level Analysis Model (DLAM), and the Sentence Level Analysis Model (SLAM) achieved 98,3% and 70.4% F1 scores, respectively.
Transformatör tabanlı model GPT-2 kullanarak zararlı yazılım tespiti
The variety of malicious content, besides its complexity, has significantly impacted end-users of the Information and Communication Technologies (ICT). To mitigate the effect of malicious content, automated machine learning techniques have been developed to proactively defend the user systems against malware. Transformers, a category of attention-based deep learning techniques, have recently been shown to be effective in solving various malware problems by mainly employing Natural Language Processing (NLP) methods. In the present study, we propose a Transformers architecture to detect malicious software automatically. We present models based on GPT-2 (Generative Pre-trained Transformer 2), which performs assembly code obtained from a static analysis on PE (Portable Executable) files. We generated a pre-trained model to capture various characteristics of both malicious and benign assembly codes. That improves the model's detection performance. Moreover, we created a binary classification model that used preprocessed features to characterize existing malicious and benign code pieces. The resulting binary classification model distinguishes between those code pieces by recognizing novel malware or benign assembly codes. Finally, we used GPT -2's pre-trained model to improve detection accuracy. The experiments showed that a fine-tuned pre-trained model and GPT-2's pre-trained model led to accuracy values up to 85.4\% and 78.3\%, respectively.
Spook algoritmasının imkansız ve olası olmayan diferansiyel kriptanalizi
In recent years, the number of IoT devices increased considerably and the security of IoT devices became an important issue. Furthermore, most IoT devices have constrained resources in terms of memory, area and power. Therefore, cryptographic algorithms that provide their security should be suitable for the implementation on the constrained devices. In 2013, NIST initiated a lightweight cryptography project to define the standards of lightweight cryptography. In 2018, the lightweight cryptography project turned into a competition-like process to choose the most convenient algorithms for constrained devices as a NIST standard. 57 algorithms were applied to the project. NIST published all algorithms for public evaluation and encouraged third-party analyses to reveal the weaknesses of algorithms. 32 algorithms were chosen as round 2 candidates. In this thesis, we have investigated the Spook algorithm, which is one of the round 2 candidates of the NIST's lightweight cryptography competition. Spook is an AEAD algorithm that uses duplex sponge construction and tweakable block cipher. Besides, Spook has an internal permutation which is Shadow-512. We have worked on Shadow-512 permutation to find a distinguisher. Shadow-512 permutation was designed as 6-Step. The outputs of Shadow-512 permutation should seem random after the 6-Step operation. However, we have found two different 6-Step impossible differential distinguishers that cover full Shadow-512. Besides, we have found 7-Step impossible distinguisher and 8-Step improbable distinguisher by adding one or more additional steps to Shadow-512. The 8-Step improbable differential covers the largest number of steps of Shadow-512 compared to previously found distinguishers in other published papers. To conclude, we can distinguish 6-, 7-, 8-Step of Shadow-512 from a random permutation by using our distinguishers.
Iskra: Dinamik zararlı yazılım platformu
With the proliferation of ''cyber-crime as a service'' economy, besides gaining new victims, providing permanence on them has been one of the key points of profit for attackers. Thus, hiding malicious presence while operating is now more important for malware than being fully undetectable when it is first distributed. Due to the increasing number of malware attacks and prohibitively long hours required for manual inspection, analysts often use dynamic analysis platforms to investigate malware samples. However, these platforms have been repeatedly shown to fail to combat evasion methods that are constantly updated by attackers. Even if malware is correctly classified by the existing dynamic analysis platforms, which are widely deployed in the cyber security industry, it has been frequently observed that the malware detects the analysis environment and behaves differently to evade inspection; consequently the malicious code targeted by the attacker does not execute. In this case, the inspection, which will make the malicious code run and be examined, has to be done by the analyst manually. In this study, we present the bare metal hypervisor-based framework for dynamic analysis, ISKRA, which facilitates system calls to be collected and analyzed without being detected by malware. ISKRA is a portable and easily modifiable framework and not only allows any system to be easily transformed into an analysis environment, regardless of the virtual machine or bare metal; but also allows for forensics to be run without being detected in live systems. This way, incident response specialists can quickly transform the system under inspection into an analysis environment and can collect evidence, examine and remedy the system without being detected by the attacker. We designed, implemented and experimented with the framework, which employs machine learning algorithms to learn from new attack campaigns. Our work shows that the framework leads to negligibly low overhead and provides a high detection rate for the most current malware campaigns that evade dynamic inspection by other frameworks.