
15
Arşivlenen Tez
0
DOI Atanmış
0%
DOI Oranı
Anabilim Dalı
Detecting android malware by using fuzzy set-based weighting method and firefly optimization algorithm
Android OS is open-source and easy to use mobile operating system. It is also user-friendly with many other features. In this way, it is a very preferred operating system on mobile phones. As a result, it becomes the target of malicious people. Applications installed on the Android operating system from the Google Play Store or by third-party application providers, also known as Android package files, may contain malicious software. So far, a variety of analyzes and detections have been made to detect such malware. While detecting malware, good results have been obtained with various methods, but malicious people have developed methods of hiding themselves against these methods. We propose a new feature selection method based on Firefly Optimization Algorithm with the Fuzzy Set-Based weighting method. The proposed method performs better than traditional feature selection methods with fewer features. The experimental results of this study proved that Firefly Optimization is an acceptable optimization algorithm for feature selection to detect malware in terms of classification performance and classification runtime. In addition, experimental evaluation of TF-IDF and Fuzzy Set-Based weighting methods indicates the effectiveness of the Fuzzy Set-Based weighting with a full feature set.
Human activity recognition using deep convolutional neural network
Human activity recognition problems involve the processes of recording and analyzing a person's daily life to identify people's behavioral patterns. Various methods such as Video-Based activity recognition and Sensor-Based activity recognition have been developed to collect activity data. Studies have been carried out by recording activities such as walking, sitting, running, jumping, climbing stairs, climbing stairs by means of depth sensors, wearable (portable) devices, and RGB cameras. Systems have been developed especially in the fields of health, the internet of things, smart cities, transportation, and security with activity recognition. Activity-sensitive approaches have been developed for security monitoring and threat detection through activity recognition. By monitoring activity-based anomalies, potential threats can be identified, and appropriate precautions can be taken. Data collection has become extremely easy because of accelerometer, gyroscope, magnetometer sensors found in almost any smart device. Deep learning methods such as ANN, CNN, RNN, and LSTM are used to classify the obtained data. In our research, we mainly focused on sensor-based activity recognition. Classification tasks were done using 1-D Convolution Neural Network feeding the raw data from the UCI-HAR dataset using accelerometer and gyroscope data. Raw data filtered using Median Filter. We didn't apply any mathematical or statistical feature extraction methods to the data. For the experimental results, we implemented 6, 7, and 12 classes activity recognition, and achieved accuracies of 96.95%, 95.03%, and 93.08%, respectively.
A novel two phased approach combining deep learning and machinelearning classifiers for effective detection of turkish phishing web sites
With the increase in internet speed and the parallel rise in the number of internet-connected devices, online fraud has exhibited a significant surge in recent years. Attackers exploit platforms such as WhatsApp, email, SMS, mobile notifications, and social media messages to disseminate content that is attention-grabbing, intriguing, or fear-inducing. By inducing users to interact with these contents and click on embedded links, these malevolent actors redirect users to counterfeit websites that closely mimic authentic ones, thereby obtaining users' confidential information or engaging in various forms of deception. Commonly referred to as "phishing" sites, these malicious web pages are often used for such deceptive operations. Consequently, it is of paramount importance that mobile applications or browsers possess the capability to identify such harmful websites even before users access them. This study employs a two-stage approach to achieve a 98.4% success rate in identifying malicious sites. The dataset used consists of a list of malicious sites from the National Cyber Incident Response Center (USOM) alongside legitimate domain names. The dataset is divided into two subsets, namely Dataset1 and Dataset2. Dataset1 is employed to train a deep learning-based artificial intelligence model, which yields an accuracy rate of 92% upon completion of training. The websites within Dataset2 are subjected to the deep learning model in the initial stage to acquire phishing scores. Subsequently, by incorporating additional features pertaining to each website and employing a machine learning model for binary classification, the second stage of training facilitates the culmination of the ultimate outcome. Test results demonstrate the capacity to predict phishing incidents with a 98.4% accuracy score for a given website. Keywords: Online Fraud, Cyber Attack, Machine learning, Deep learning, Malicious URL
Metin tabanlı captcha araçlarında görsel özelliklerin rolü: kullanılabilirlilik için fnirs çalışması
In order to mitigate dictionary attacks or similar undesirable automated attacks to information systems, developers mostly prefer using CAPTCHA challenges as Human Interactive Proofs (HIPs) to distinguish between human users and scripts. An appropriate use of CAPTCHA requires a setup balance between robustness and usability during the design of a challenge. The previous research reveals that most of the usability studies have used accuracy and response time as measurement criteria for quantitative analysis. The present study aims at applying optical neuroimaging techniques for the analysis of CAPTCHA design. In particular, fNIRS (Functional Near Infrared Spectroscopy) is a neuroimaging technique used for mental workload analysis by means of analyzing hemodynamic responses on brain. The present study reports an experimental investigation in which 25 participants solved a group of text-based CAPTCHA with various visual characteristics.
Makina öğrenmesi ile kurumsal bir ağda anomali tabanlı siber ihlal tespit sistemi: keşif saldırıları üzerinde bir vaka çalışması
Cyber attacks constitute a serious threat to organizations with implications ranging from economic, reputational and legal consequences. As the techniques employed by cyber criminals get more sophisticated, information security professionals face a greater challenge protecting the famous triangle of confidentiality, integrity and availability (CIA). In today's interconnected realm of computer systems, every attack vector has a network dimension. Therefore, this study aims to detect network intrusion attempts with an anomaly-based machine learning model to provide better protection than the conventional misuse-based models. Two different models were built and implemented on a data set gathered from a production environment, ensemble learning and convolutional neural network respectively. To demonstrate the models' reliability and validity, they were applied on UNSW-NB15 benchmarking data set as well. To keep the scope of the study manageable, probing type of attack was focused on and models were trained accordingly. The results suggested that both models detect the chosen type of intrusion attempts with an F1 score of more than 0.97. Convolutional neural network model scored slightly higher with 0.99. Similar results were obtained in UNSW-NB15 data set pointing the proposed model's validity.
IoT cihazlarda veri akışının analizi ve akıllı ev ağındaki MUD uygulamalarının güvenliğinin değerlendirilmesi
IoT usage has shown significant growth in the past decades. A major target for the IoT market is the living spaces which have become smarter by the integration of IoT devices. However, the network infrastructure have not been developed from the perspective of Cyber security. IoT devices are subject to Cyber security threats in multiple fronts. For example, infected IoT devices may contribute to DDoS attacks that target global Internet services, such as the DNS. For mitigation of the attacks, various solutions have been proposed. In this thesis, we review available solutions with a particular focus on the application of a standardized whitelisting method, namely Manufacturer User Description (MUD). For an evaluation of MUD usage in IoT networks, we analyzed traffic of two devices with the aim of detecting recognizable and distinctive traffic patterns. We established specific MUD files based on the detected traffic patterns and evaluated the MUD files for the validation of their proof of work.
Ascon ve Drygascon şifrelerinin diferansiyel-lineer kriptanalizi
Due to rapidly developing technology, devices have become smaller along with their performance capacity and memory. If possible, existing NIST-approved encryption standards should be used on these resource-constrained devices. When an acceptable performance cannot be achieved in this way, there is a need for more lightweight algorithms. Since taking individual measures leads to simplistic designs when designing lightweight algorithms, ciphers can become more vulnerable to cryptographic attacks. Hence some regulation is necessary. To satisfy this need, NIST has decided to start a lightweight cryptography competition to select one or more lightweight algorithms. In this study, we examined Second Round NIST Lightweight Cryptography Standardization Competition candidates to contribute to the course of the competition. Then we focused on two different but structurally very similar cipher suites Ascon and Drygascon to compare their security. We observed 2, 3, 3.5-round truncated differential and 5-round differential-linear distinguishers that were given for Drygascon are erroneous. We present the corrected results and provide the longest practical differential-linear distinguisher of Drygascon. After that, we compared the security of Ascon and Drygascon. We observed that the practical data complexity of the two is very close. However, since Ascon has more rounds than Drygascon, we concluded that Ascon might be more resistant against differential-linear cryptanalysis.
Siber tehdit istihbarat paylaşım teknolojileri ve blokzincir kullanılarak oluşturulan tehdit paylaşım modeli
Against the measures taken, the nature of the threats in the cyber environment is evolving day by day. While script kiddie made amateur cyber attacks were usually experienced beforehand, more sophisticated and targeted attacks are frequently encountered nowadays. Besides that, commonly used signature based techniques for attack detection and threat information staying within organization is insufficient for dynamically changing, organized and targeted threats. Furthermore, with the advance of new technology, computer networks are growing, the number and variety of interconnected devices are increasing and as a consequence attack surface is expanding. As a result, it does not seem possible to reduce all of the vulnerabilities that we encounter. From now on, cyber attack is not a matter of 'if', but it is a matter of 'when'. In order to detect complex attacks one of the newly developed approaches is cyber threat intelligence sharing. Threat intelligence is evidence-based knowledge about threat and assists to decide. It has no value if it is not disseminated though. Organizations can increase situational awareness about targeted cyber threats by sharing internal cyber threat information with trusted partners and integrating external cyber threat information with their security systems in real-time basis. However, common language that allows automation at identification and sharing of threat information is crucial for timely intervention. To that end, various standards are being developed by many organizations and companies. In this study, standards and tools developed for the representation and sharing of threat information are compared, and new threat sharing model is developed using a permissioned blockchain.
Zararlı kod tespiti: LSTM ile run trace analizi
Malicious software threats and their detection have been gaining importance as a subdomain of information security due to the expansion of ICT applications in daily settings. A major challenge in designing and developing anti-malware systems is the coverage of the detection, particularly the development of dynamic analysis methods that can detect polymorphic and metamorphic malware efficiently. In the present study, we propose a methodological framework for detecting malicious code by analyzing run trace outputs by Long Short-Term Memory (LSTM). We developed models of run traces of malicious and benign Portable Executable (PE) files. We created our first dataset from run trace outputs obtained from dynamic analysis of PE files. The obtained dataset was in the instruction format as a sequence and was called Instruction as a Sequence Model (ISM). By splitting the first dataset into basic blocks, we obtained the second one called Basic Block as a Sequence Model (BSM). The experiments showed that the ISM achieved an accuracy of 87.51% and a false positive rate of 18.34%, while BSM achieved an accuracy of 99.26% and a false positive rate of 2.62%.
Saldırgan gözüyle parola saldırılarının birden çok balküpü sistemiyle analizi
Authentication is vital for secure operation of ICT systems. Since the past several decades, alternative solutions have been developed for authentication, such as biometric authentication methods, aiming at replacing passwords. Nevertheless, their success has been limited as evidenced by intensive use of passwords. Today, an average user uses dozens of different passwords in daily practice. The frequent use of passwords in authentication also leads to a close interest of attackers due to rapid the expansion of ICT for the past several decades. Recently, almost 70% percent of cyber attacks target user credentials. This study investigates password attacks from the attacker's perspective by using ten honeypot systems that run mock SSH services. The focus of the analysis is the efficiency of the blacklisting approach against password attacks, and the analysis of the attitudes of attackers as recorded in log files. The relationship between the passwords used in the attacks and the local language of the target country was also investigated using a language identification model.
Yığınlanmış çift yönlü uzun-kısa süreli bellek kullanarak zararlı yazılım tespiti
The recent proliferation in the use of the Internet and personal computers has made it easier for cybercriminals to expose Internet users to widespread and damaging threats. In order protect the end users against such threats, a security system must be proactive. It needs to detect malicious files or executables before reaching the end-user. To create an efficient and low-cost malware detection mechanism, in the present study, we propose stacked bidirectional long short-term memory (Stacked BiLSTM) based deep learning (DL) language model for detecting malicious code. We developed language models using assembly instructions from .text sections of malicious and benign Portable Executable (PE) files. We created our first dataset from assembly instructions obtained from static analysis of the PE files. The dataset was composed of text documents, and it was used in Document Level Analysis Model (DLAM). By splitting the first dataset into single instructions, we obtained the second dataset, which was then used in a Sentence Level Analysis Model (SLAM). We treated each instruction as a sentence, and .text sections as documents. We labeled each document and sentence by their corresponding malicious and benign tags. The experiments showed that the Document Level Analysis Model (DLAM), and the Sentence Level Analysis Model (SLAM) achieved 98,3% and 70.4% F1 scores, respectively.
Transformatör tabanlı model GPT-2 kullanarak zararlı yazılım tespiti
The variety of malicious content, besides its complexity, has significantly impacted end-users of the Information and Communication Technologies (ICT). To mitigate the effect of malicious content, automated machine learning techniques have been developed to proactively defend the user systems against malware. Transformers, a category of attention-based deep learning techniques, have recently been shown to be effective in solving various malware problems by mainly employing Natural Language Processing (NLP) methods. In the present study, we propose a Transformers architecture to detect malicious software automatically. We present models based on GPT-2 (Generative Pre-trained Transformer 2), which performs assembly code obtained from a static analysis on PE (Portable Executable) files. We generated a pre-trained model to capture various characteristics of both malicious and benign assembly codes. That improves the model's detection performance. Moreover, we created a binary classification model that used preprocessed features to characterize existing malicious and benign code pieces. The resulting binary classification model distinguishes between those code pieces by recognizing novel malware or benign assembly codes. Finally, we used GPT -2's pre-trained model to improve detection accuracy. The experiments showed that a fine-tuned pre-trained model and GPT-2's pre-trained model led to accuracy values up to 85.4\% and 78.3\%, respectively.
Spook algoritmasının imkansız ve olası olmayan diferansiyel kriptanalizi
In recent years, the number of IoT devices increased considerably and the security of IoT devices became an important issue. Furthermore, most IoT devices have constrained resources in terms of memory, area and power. Therefore, cryptographic algorithms that provide their security should be suitable for the implementation on the constrained devices. In 2013, NIST initiated a lightweight cryptography project to define the standards of lightweight cryptography. In 2018, the lightweight cryptography project turned into a competition-like process to choose the most convenient algorithms for constrained devices as a NIST standard. 57 algorithms were applied to the project. NIST published all algorithms for public evaluation and encouraged third-party analyses to reveal the weaknesses of algorithms. 32 algorithms were chosen as round 2 candidates. In this thesis, we have investigated the Spook algorithm, which is one of the round 2 candidates of the NIST's lightweight cryptography competition. Spook is an AEAD algorithm that uses duplex sponge construction and tweakable block cipher. Besides, Spook has an internal permutation which is Shadow-512. We have worked on Shadow-512 permutation to find a distinguisher. Shadow-512 permutation was designed as 6-Step. The outputs of Shadow-512 permutation should seem random after the 6-Step operation. However, we have found two different 6-Step impossible differential distinguishers that cover full Shadow-512. Besides, we have found 7-Step impossible distinguisher and 8-Step improbable distinguisher by adding one or more additional steps to Shadow-512. The 8-Step improbable differential covers the largest number of steps of Shadow-512 compared to previously found distinguishers in other published papers. To conclude, we can distinguish 6-, 7-, 8-Step of Shadow-512 from a random permutation by using our distinguishers.
Iskra: Dinamik zararlı yazılım platformu
With the proliferation of ''cyber-crime as a service'' economy, besides gaining new victims, providing permanence on them has been one of the key points of profit for attackers. Thus, hiding malicious presence while operating is now more important for malware than being fully undetectable when it is first distributed. Due to the increasing number of malware attacks and prohibitively long hours required for manual inspection, analysts often use dynamic analysis platforms to investigate malware samples. However, these platforms have been repeatedly shown to fail to combat evasion methods that are constantly updated by attackers. Even if malware is correctly classified by the existing dynamic analysis platforms, which are widely deployed in the cyber security industry, it has been frequently observed that the malware detects the analysis environment and behaves differently to evade inspection; consequently the malicious code targeted by the attacker does not execute. In this case, the inspection, which will make the malicious code run and be examined, has to be done by the analyst manually. In this study, we present the bare metal hypervisor-based framework for dynamic analysis, ISKRA, which facilitates system calls to be collected and analyzed without being detected by malware. ISKRA is a portable and easily modifiable framework and not only allows any system to be easily transformed into an analysis environment, regardless of the virtual machine or bare metal; but also allows for forensics to be run without being detected in live systems. This way, incident response specialists can quickly transform the system under inspection into an analysis environment and can collect evidence, examine and remedy the system without being detected by the attacker. We designed, implemented and experimented with the framework, which employs machine learning algorithms to learn from new attack campaigns. Our work shows that the framework leads to negligibly low overhead and provides a high detection rate for the most current malware campaigns that evade dynamic inspection by other frameworks.
Oyun geliştirme platformlarında blockchain tabanlı, güvenli bir ödeme sitemi geliştirme
Oyun, geçmişten günümüze eğlencenin en önemli unsurlarından biri olmuştur. Sanal bir dünya ile alternatif evrenler sunan oyunlar, kendi içlerinde yarattıkları ekonomi sayesinde gerçek dünya ile maddi temas sağlayabilmektedir. Bu noktalardaki para kazanma yöntemlerinden biri de oyun içi kostüm, eşya, ikon ve benzeri edinimlerin gerçek dünya parası ile satılması ve gerçek dünyada bir varlık yaratılmasıdır. Blockchain teknolojileri sayesinde bu varlıklar son derece güvenli bir şekilde merkezsiz olarak saklanabilmektedir. Şifreleme yöntemleri ve dağıtık defter yapısı sayesinde bu teknoloji, kullanıcıların dijital varlıklarını üçüncü taraflara ihtiyaç duymadan güvenli bir ortamda saklamalarına olanak sağlıyor. Blockchain sadece oyun sektöründe değil, finans, sağlık, lojistik, eğitim ve daha birçok alanda devrim niteliğinde yenilikler sunan teknolojik bir gelişmedir. Özellikle verilerin değişmez ve şeffaf bir şekilde saklanmasını sağlayarak güvenilirliği artırıyor ve aracılara olan bağımlılığı azaltıyor. Bu sayede blockchain, dijital ekonomiden sosyal sistemlere kadar geniş bir alanda insan hayatını derinden etkileyen ve yeniden şekillendiren bir unsur haline gelmiştir. P2E (Play to Earn), oyunlarda oynadıkça kripto varlıkları kazanmaya yönelik bir modeldir. Oyuncunun oyun oynama süresini kazanarak artırmayı hedefler. Bu da oyuna bağlı kripto varlıkların değerini artırır ve bir ekonomi yaratır. Benzer şekilde, NFT (Non-Fungible Token) kazanıp satarak, blockchain teknolojisi oyunlarda gerçek dünya kazançları elde edilmesini sağlar. Dijital varlıkların gerçek dünyadaki karşılığı yüksek güvenlik önlemleri gerektirir. Blockchain teknolojisi burada ana aktörlerden biridir. Oyun geliştirme platformlarında blockchain tabanlı ödeme sistemlerinin güvenliği, işlem bütünlüğünü, kullanıcı gizliliğini ve varlık sahipliğini artırmaya odaklanan kritik bir araştırma alanıdır. Blokchaini teknolojisi, veri tahrifatı ve yetkisiz erişim gibi geleneksel ödeme sistemleriyle ilişkili riskleri azaltan merkezi olmayan bir çerçeve sunar. Bu çalışmada model mimari olarak Solana blockchain altyapısı entegre edilmiştir. Solana'nın yüksek hızlı ve düşük maliyetli işlem özelliklerinden yararlanılarak projenin temel gereksinimlerini karşılayacak bir sistem tasarımı gerçekleştirilmiştir. Akıllı sözleşmeler Rust programlama dili kullanılarak geliştirildi. Blockchain tabanlı ödeme sistemlerinin güvenilir ve verimli çalışmasını sağlamak için Rust'ın performans odaklı ve güvenli bellek yönetimi özellikleri tercih edildi. Akıllı sözleşme geliştirme sürecinde işlem mantığı, veri doğrulama ve güvenlik önlemleri gibi unsurlar özenle tasarlandı. Ayrıca token transfer fonksiyonları ve kullanıcı yetkilendirme süreçleri Solana'nın Program Library standardı kullanılarak modellendi. Web tabanlı kullanıcı arayüzü React kütüphanesi kullanılarak oluşturuldu. React'in bileşen tabanlı mimarisi ve dinamik veri yönetimi yetenekleri, kullanıcı deneyimini geliştirecek bir arayüz geliştirilmesini sağladı. Bu süreçte kullanıcıların dijital cüzdanları üzerinden sisteme güvenli bir şekilde erişebilmeleri için dijital cüzdan entegrasyonu gerçekleştirildi. Kullanıcıların blockchain işlemlerini kolayca gerçekleştirebilmelerini sağlayan Phantom, Sollet vb. gibi Solana uyumlu cüzdanlar tercih edildi. Sistem bileşenleri detaylı olarak analiz edilmiş ve mimari tasarımın temel taşları olarak belirlenmiştir. Bu bileşenler arasında akıllı sözleşmeler, blokchaini ağı, kullanıcı arayüzü ve dijital cüzdanlar yer almaktadır. Ayrıca bu bileşenler arasındaki iletişim mekanizmaları tanımlanmış ve veri akışını optimize etmek için gerekli protokoller belirlenmiştir. Sistem, kullanıcıların işlem güvenliğini ve veri bütünlüğünü sağlamayı amaçlayan bir yapıda tasarlanmıştır. Bu yöntem ve araçlar bir araya getirilerek, blockchain tabanlı ödeme sistemlerinin oyun geliştirme platformlarında uygulanabilirliğini değerlendiren bir model sunulmuş ve proje güvenlik açısından tartışılmıştır. Bu tez, akıllı sözleşmenin Rust ile ilgili güvenlik, giriş ve çıkış işlemleri, kullanıcı ve imzalayan kimliklerinin güvenli çalışması gibi güvenlik açıklarını ve avantajlarını inceleyerek oyun platformlarında blokchaini tabanlı ödeme sistemlerinin güvenliğine genel bir bakış sunmaktadır.