E-ticaret siteleri için güvenlik açığı tespitine ilişkin sistem tasarımı
Security vulnerability detection and reporting model in E-commerce sites
- Tez No: 977702
- Danışmanlar: DR. ÖĞR. ÜYESİ FATMA NUR AKI
- Tez Türü: Yüksek Lisans
- Konular: Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrol, Computer Engineering and Computer Science and Control
- Anahtar Kelimeler: Siber güvenlik, Cyber security
- Yıl: 2025
- Dil: Türkçe
- Üniversite: İstanbul Ticaret Üniversitesi
- Enstitü: Lisansüstü Eğitim Enstitüsü
- Ana Bilim Dalı: Bilgisayar Mühendisliği Ana Bilim Dalı
- Bilim Dalı: Belirtilmemiş.
- Sayfa Sayısı: Belirtilmemiş.
Özet
Günümüzde e-ticaret platformları, kullanıcı verileri ve finansal işlemleri bünyesinde barındırmaları nedeniyle siber saldırıların öncelikli hedefleri arasında yer almaktadır. Bu durum, işletmelerin veri güvenliğini sağlamada etkili yöntemlere duyduğu ihtiyacı her geçen gün artırmaktadır. Mevcut literatürde güvenlik açıklarının tespitine yönelik pek çok çalışma bulunsa da, çoğu yaklaşım ya yalnızca belirli bir açık türüne odaklanmakta ya da yalnızca manuel veya otomatik analiz yöntemlerinden birini kullanmaktadır. Bu tez, söz konusu sınırlılıkları aşmak amacıyla, manuel ve otomatik analiz tekniklerini birleştiren, çok aşamalı ve ölçeklenebilir bir Güvenlik Açığı Tespitine İlişkin Sistem Tasarımı önermektedir. Önerilen tasarım, hedef belirleme, bilgi toplama, zafiyet taraması, açık doğrulama ve raporlama olmak üzere beş ana aşamadan oluşmaktadır. İlk aşamada, test kapsamı ve hedef platformlar belirlenmiş; ikinci aşamada, pasif ve aktif bilgi toplama yöntemleri ile sistem altyapısına ilişkin veriler elde edilmiştir. Üçüncü aşamada, OWASP ZAP, Nikto, Nmap ve Burp Suite gibi yaygın kullanılan güvenlik araçları ile zafiyet taraması gerçekleştirilmiş; dördüncü aşamada ise tespit edilen açıklar manuel test teknikleri ile doğrulanmıştır. Bu doğrulama süreci, yanlış pozitifleri en aza indirmeyi ve gerçek anlamda sömürülebilir (exploitable) açıklıkları önceliklendirmeyi sağlamıştır. Tespit edilen her bir açık, Common Vulnerability Scoring System (CVSS) v3.1 metodolojisine göre skorlanmış; etki düzeyleri, istismar zorluk dereceleri ve potansiyel zararları değerlendirilmiştir. Bulgular, incelenen e-ticaret sitelerinin önemli bir kısmında SQL Injection (SQLi), Cross-Site Scripting (XSS), güvenlik yapılandırma hataları, kimlik doğrulama zafiyetleri, eksik güvenlik başlıkları ve eski TLS protokol desteği gibi kritik seviyede açıklıkların bulunduğunu ortaya koymuştur. Modelin uygulama süreci sonunda hazırlanan raporlar iki farklı formatta sunulmuştur: 1. Teknik Rapor: Güvenlik ekiplerinin doğrudan müdahale edebileceği, ayrıntılı teknik açıklamalar ve çözüm önerileri içeren rapor. 2. Yönetici Özeti: Karar vericilerin teknik detaylara boğulmadan risk seviyelerini ve öncelikli aksiyonları görebileceği sadeleştirilmiş özet rapor. Çalışma, yalnızca açıklıkların tespitine değil, aynı zamanda önceliklendirilmesine ve çözüm önerilerinin uygulanabilirliğine odaklanmaktadır. Bu yönüyle önerilen tasarım, sınırlı kaynaklara sahip KOBİ'lerden büyük ölçekli e-ticaret platformlarına kadar geniş bir yelpazede uygulanabilir niteliktedir. Sonuç olarak, önerilen tasarımın, e-ticaret sistemlerinde güvenlik farkındalığını artırdığı, müdahale sürelerini kısalttığı ve siber tehditlere karşı proaktif bir savunma sağladığı görülmüştür.
Özet (Çeviri)
Today, e-commerce platforms are among the primary targets of cyberattacks due to hosting user data and financial transactions. This situation increases the need for businesses to adopt effective methods for ensuring data security. Although numerous studies in the existing literature focus on vulnerability detection, most approaches either target a specific type of vulnerability or rely solely on manual or automated analysis methods. This thesis proposes a Security Vulnerability Detection System Design that overcomes these limitations by integrating both manual and automated analysis techniques within a multi-stage and scalable framework. The proposed model consists of five main stages: target identification, information gathering, vulnerability scanning, vulnerability verification, and reporting. In the first stage, the test scope and target platforms were defined; in the second stage, both passive and active information gathering methods were employed to obtain data on the system infrastructure. In the third stage, vulnerability scanning was performed using widely adopted security tools such as OWASP ZAP, Nikto, Nmap, and Burp Suite; in the fourth stage, the detected vulnerabilities were verified through manual testing techniques. This verification process minimized false positives and ensured the prioritization of truly exploitable vulnerabilities. Each identified vulnerability was scored according to the Common Vulnerability Scoring System (CVSS) v3.1 methodology, evaluating their impact levels, exploitation difficulty, and potential damage. The findings revealed that a significant proportion of the analyzed e-commerce sites contained critical vulnerabilities such as SQL Injection (SQLi), Cross-Site Scripting (XSS), security misconfigurations, authentication flaws, missing security headers, and outdated TLS protocol support. At the end of the implementation process, the reports generated were presented in two formats: 1. Technical Report: Detailed technical documentation including comprehensive explanations and solution recommendations for security teams to act upon immediately. 2. Executive Summary: A simplified overview enabling decision-makers to assess risk levels and prioritize actions without delving into technical complexity. This study focuses not only on the detection of vulnerabilities but also on their prioritization and the applicability of proposed solutions. In this respect, the developed design is applicable to a wide range of contexts, from small and medium-sized enterprises (SMEs) with limited resources to large-scale e-commerce platforms. As a result, the proposed design has been shown to enhance security awareness, shorten response times, and provide a proactive defense against cyber threats in e-commerce systems.
Benzer Tezler
- Алуу жана колдонуучулардынканааттануусун баалоо:бишкек шаарындаэмпирикалык изилдөө
E-devletin benimsenmesi ve kullanıcı memnuniyetinin değerlendirilmesi: Bişkek şehrinde ampirik bir araştırma
ACAR ŞARŞENKADIROVA
Yüksek Lisans
Kırgızca
2024
İşletmeKırgızistan-Türkiye Manas Üniversitesiİşletme Ana Bilim Dalı
YRD. DOÇ. DR. AZAMAT MAKSÜDÜNOV
- L'evaluation des alternatives de paiement electronique avec des methodes floues d'aide a la decisions
Elektronik ödeme alternatiflerinin bulanık çok ölçütlü karar verme yöntemleriyle değerlendirilmesi
GÜLFEM IŞIKLAR
Yüksek Lisans
Fransızca
2003
Endüstri ve Endüstri MühendisliğiGalatasaray ÜniversitesiEndüstri Mühendisliği Ana Bilim Dalı
DOÇ. DR. H. ZİYA ULUKAN
- Türkiye elektronik bankacılığı için güvenli elektronik ticaret modeli (4b-güvenlik)
Secure electronic commerce model for Turkish elektronic banking (4d-security)
MAHMUT ÖZCAN
Doktora
Türkçe
2014
BankacılıkMarmara ÜniversitesiBankacılık Ana Bilim Dalı
DOÇ. DR. İLKNUR ESEN YILDIRIM
- İşletmeden son tüketiciye(B2C) e-ticaret anlayış ve uygulamaları: Web site tasarımı tasarımı ve bir pilot çalışma
From business to last consumer e-commerce(B2Cc) understanding and applications: Web development design and a pilot study
ENGİN OĞUZAY
Yüksek Lisans
Türkçe
2002
Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve KontrolMaltepe Üniversitesiİşletme Ana Bilim Dalı
PROF. DR. MESUT RAZBONYALI