Master'sOpen Access

Makina öğrenmesi ile kurumsal bir ağda anomali tabanlı siber ihlal tespit sistemi: keşif saldırıları üzerinde bir vaka çalışması

2020
0 views
0 downloads
Advisor: Doç. Cengiz Acartürk ; Dr. Öğr. Üyesi Cihangir Tezcan

Abstract (EN)

Cyber attacks constitute a serious threat to organizations with implications ranging from economic, reputational and legal consequences. As the techniques employed by cyber criminals get more sophisticated, information security professionals face a greater challenge protecting the famous triangle of confidentiality, integrity and availability (CIA). In today's interconnected realm of computer systems, every attack vector has a network dimension. Therefore, this study aims to detect network intrusion attempts with an anomaly-based machine learning model to provide better protection than the conventional misuse-based models. Two different models were built and implemented on a data set gathered from a production environment, ensemble learning and convolutional neural network respectively. To demonstrate the models' reliability and validity, they were applied on UNSW-NB15 benchmarking data set as well. To keep the scope of the study manageable, probing type of attack was focused on and models were trained accordingly. The results suggested that both models detect the chosen type of intrusion attempts with an F1 score of more than 0.97. Convolutional neural network model scored slightly higher with 0.99. Similar results were obtained in UNSW-NB15 data set pointing the proposed model's validity.

Author

Dr. Emrah Tufan

How to Cite

Emrah Tufan (Master Thesis). Makina öğrenmesi ile kurumsal bir ağda anomali tabanlı siber ihlal tespit sistemi: keşif saldırıları üzerinde bir vaka çalışması, 2020, Middle East Technical University.

Keywords

License

Tüm Hakları Saklıdır

This work is shared under the specified license terms.

More theses from Middle East Technical University