Web tabanlı saldırılarda sahte kimlik avı url'lerinin yapay zekâ destekli gerçek zamanlı tespiti
Real-time detection of phishing urls in web-based attacks using artificial intelligence)
- Tez No: 1025099
- Danışmanlar: DR. ÖĞR. ÜYESİ ESRA ODABAŞ YILDIRIM
- Tez Türü: Yüksek Lisans
- Konular: Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrol, Computer Engineering and Computer Science and Control
- Anahtar Kelimeler: kimlik avı tespiti, derin öğrenme, DistilBERT, URL analizi, hibrit model, geç füzyon, makine öğrenmesi, phishing detection, deep learning, DistilBERT, URL analysis, hybrid model, late fusion, machine learning June 2026, 100 pages
- Yıl: 2026
- Dil: Türkçe
- Üniversite: Atatürk Üniversitesi
- Enstitü: Fen Bilimleri Enstitüsü
- Ana Bilim Dalı: Yazılım Mühendisliği Ana Bilim Dalı
- Bilim Dalı: Yazılım Mühendisliği Bilim Dalı
- Sayfa Sayısı: Belirtilmemiş.
Özet
Amaç: Bu tez çalışmasının temel amacı, web tabanlı kimlik avı saldırılarında kullanılan zararlı URL'lerin otomatik olarak tespit edilmesini sağlamak üzere hibrit yapay zekâ tabanlı bir tespit modeli geliştirilmesidir. Çalışma kapsamında, farklı URL örüntülerini birlikte değerlendirebilen model mimarisinin kullanılmasıyla kimlik avı ve yasal/meşru URL'lerin yüksek doğrulukla sınıflandırılması hedeflenmiştir. Ayrıca geliştirilen modelin kullanıcılar tarafından pratik biçimde kullanılabilmesi için web tabanlı bir arayüz ile desteklenmesi ve böylece gerçek zamanlı URL analizi yapılabilecek erişilebilir bir sistem sunulması amaçlanmaktadır. Yöntem: Tezde Kaggle platformundan alınan“Phishing Site URLs”ve“Malicious Phish”veri setleri kullanılmıştır. Her URL'den uzunluk, karakter ve yapısal göstergeleri içeren 21 el yapımı özellik çıkarılmış, URL metinleri ise donmuş DistilBERT tokenizer ile kodlanmış ve donmuş DistilBERT encoder ile temsil edilmiştir. Geliştirilen hibrit mimari, donmuş DistilBERT encoder, LSTM ve ANN dalı ile el yapımı özellikleri birlikte işleyen bir derin öğrenme modeli ve karakter düzeyi TF-IDF üzerine kurulu kalibre edilmiş LinearSVC modelinden oluşmaktadır. İki modelin çıktıları, doğrulama kümesi PR-AUC'unu maksimize eden α parametresiyle geç füzyon ve ayrıca Lojistik Regresyon meta-öğrenicili yığıntı yöntemiyle birleştirilmiştir. Tüm modeller 5 katlı tabakalı çapraz doğrulama ile eğitilmiş doğruluk, F1, ROC-AUC, PR-AUC ve MCC metrikleriyle değerlendirilmiştir. Bulgular: Elde edilen sonuçlara göre birinci veri setinde geç füzyon modeli 5 katlı çapraz doğrulama ortalamasında 0,9875 ± 0,0007 doğruluk, 0,9721 ± 0,0014 F1 skoru ve 0,9982 ± 0,0002 ROC-AUC ile en yüksek genel performansı sağlamıştır. Yığıntı (Stacking-LogReg) modeli de 0,9874 ± 0,0007 doğruluk ve 0,9720 ± 0,0015 F1 skoru ile yakın bir başarım ortaya koymuştur. Özellik önemi analizinde Letter Count (2,38), URL Length (1,38) ve Digit Count (1,33) en yüksek ayırt edici güce sahip özellikler olarak öne çıkmıştır. İkinci veri setinde ise yığıntı modeli 0,9873 ± 0,0008 doğruluk ve 0,9647 ± 0,0021 F1 skoru ile en yüksek genel performansı göstermiştir. Geç füzyon modeli de 0,9869 ± 0,0005 doğruluk, 0,9636 ± 0,0014 F1 skoru ve 0,9979 ± 0,0001 ROC-AUC değeriyle yığıntı modeline oldukça yakın bir başarım sergilemiştir. Sonuçlar: Bu tez çalışmasında, derin öğrenme ve geleneksel makine öğrenmesi yöntemlerinin geç füzyon stratejisiyle birleştirilmesi yoluyla URL tabanlı kimlik avı tespitinde tekil modellere kıyasla daha yüksek başarım elde edilmiştir. Donmuş DistilBERT encoder kullanımı hesaplama maliyetini önemli ölçüde düşürmüştür. URL'lerin bağlamsal temsili için yeterli anlamsal bilgiyi sağlamıştır. Geliştirilen web arayüzü sayesinde modelin gerçek zamanlı kullanım potansiyeli desteklenmiş ve yapay zekâ destekli kimlik avı tespit sistemlerinin pratik uygulamalarına katkı sağlanmıştır.
Özet (Çeviri)
Purpose: The main purpose of this thesis is to develop a hybrid AI-based detection model for automatically identifying malicious URLs used in phishing attacks. The model aims to classify phishing and legitimate URLs with high accuracy by jointly evaluating diverse URL patterns, and is supported by a web-based interface that enables real-time URL analysis. Method: The thesis uses the“Phishing Site URLs”and“Malicious Phish”datasets obtained from the Kaggle platform. A total of 21 handcrafted structural features were extracted from each URL under three categories: length metrics, character counters, and structural indicators, while URL texts were represented using a frozen DistilBERT tokenizer. The developed hybrid architecture consists of a deep learning model that jointly processes a frozen DistilBERT encoder, an LSTM layer, an ANN branch, and handcrafted features, along with a calibrated LinearSVC model built on character-level TF-IDF vectorization. The outputs of the two models were combined using a late fusion strategy with an α parameter that maximizes the validation set PR-AUC; additionally, a stacking combination with a Logistic Regression meta-learner was applied. All models were trained with 5-fold stratified cross-validation and evaluated using accuracy, F1 score, ROC-AUC, PR-AUC, and Matthews Correlation Coefficient metrics. Findings: According to the results, on the first dataset, the late fusion model achieved the highest overall performance with an average accuracy of 0.9875 ± 0.0007, F1 score of 0.9721 ± 0.0014, and ROC-AUC of 0.9982 ± 0.0002 across 5-fold cross-validation. The stacking (Stacking-LogReg) model also demonstrated a similar performance with an accuracy of 0.9874 ± 0.0007 and an F1 score of 0.9720 ± 0.0015. In the feature importance analysis, Letter Count (2.38), URL Length (1.38), and Digit Count (1.33) emerged as the handcrafted features with the highest discriminative power. On the second dataset, the stacking model achieved the best overall performance with an accuracy of 0.9873 ± 0.0008 and an F1 score of 0.9647 ± 0.0021. The late fusion model also showed a very similar performance, achieving an accuracy of 0.9869 ± 0.0005, an F1 score of 0.9636 ± 0.0014, and a ROC-AUC of 0.9979 ± 0.0001. The consistent results obtained across both datasets indicate that the developed hybrid approach demonstrates reliable generalization performance across different data distributions. Conclusions: This thesis has shown that combining deep learning and traditional machine learning through an optimized late fusion strategy yields higher performance in URL-based phishing detection compared to single-model approaches. The frozen DistilBERT encoder reduced computational cost considerably while providing sufficient semantic representation of URLs. The developed web interface supported the real-time applicability of the system and contributed to the practical use of artificial intelligence-supported phishing detection in real-world settings.
Benzer Tezler
- Detection of phishing urls with deep learning based on the GAN-CNN-LSTM network and swarm intelligence algorithms
GAN-CNN-LSTM ağı ve swarm zeka algoritmalarını tabanlı derin öğrenme ile phishing url'lerinin tespiti
ABBAS JABR SALEH ALBAHADILI
Yüksek Lisans
İngilizce
2023
Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve KontrolÇankırı Karatekin ÜniversitesiElektronik ve Bilgisayar Mühendisliği Ana Bilim Dalı
PROF. DR. AYHAN AKBAŞ
- Oltalama site engelleyici tarayıcı eklentisi
Phishing site blocker browser add-on
AHMET GÜREL
Yüksek Lisans
Türkçe
2025
Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve KontrolSüleyman Demirel ÜniversitesiBilgisayar Mühendisliği Ana Bilim Dalı
DR. ÖĞR. ÜYESİ TURGAY AYDOĞAN
- Yapay sinir ağı ve metasezgisel sınıflandırıcılarını kullanarak nesnelerin internetinde çapraz ateş ve ddos saldırılarını tespiti
Use artificial neural network and metaheuristic classifiers to detect phishing attacks on the internet of things
MUSTAFA AHMED ELBERRI
Doktora
Türkçe
2026
Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve KontrolKastamonu ÜniversitesiMalzeme Bilimi ve Mühendisliği Ana Bilim Dalı
DR. ÖĞR. ÜYESİ ÜMİT TOKEŞER
- Otonom araç sistemlerinde siber güvenlik analizi: Tehditler, riskler ve koruma yöntemleri
Cyber security analysis in autonomous vehicle systems: Threats, risks, and protection methods
MUHAMMED NAZAR ABDULGADER OSMAN
Yüksek Lisans
Türkçe
2026
Mekatronik Mühendisliğiİstanbul Gelişim ÜniversitesiMekatronik Mühendisliği Ana Bilim Dalı
DR. ÖĞR. ÜYESİ KENAN ŞENTÜRK
DR. ÖĞR. ÜYESİ SERKAN GÖNEN
- A risk management framework for smart distribution systems
Akıllı güç dağıtım sistemleri için risk yönetimi çerçevesi
ELİF ÜSTÜNDAĞ SOYKAN
Doktora
İngilizce
2021
Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrolİstanbul Teknik ÜniversitesiHesaplamalı Bilim ve Mühendislik Ana Bilim Dalı (disiplinlerarası)
PROF. DR. MUSTAFA BAĞRIYANIK