Adli bilişim kapsamında windows tabanlı sistemlerden dijital delillerin otomatik olarak elde edilmesi ve analizi
Automatic collection and analysis of digital evidence from windows-based systems within the scope of digital forensics
- Tez No: 993518
- Danışmanlar: PROF. DR. İBRAHİM ÖZÇELİK
- Tez Türü: Yüksek Lisans
- Konular: Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrol, Computer Engineering and Computer Science and Control
- Anahtar Kelimeler: Belirtilmemiş.
- Yıl: 2025
- Dil: Türkçe
- Üniversite: Sakarya Üniversitesi
- Enstitü: Fen Bilimleri Enstitüsü
- Ana Bilim Dalı: Bilgisayar Mühendisliği Ana Bilim Dalı
- Bilim Dalı: Belirtilmemiş.
- Sayfa Sayısı: Belirtilmemiş.
Özet
İnternet ve bilişim sistemleri üzerinde işlenen suçların veya yapılan siber saldırıların tespit edilmesi amacıyla gerçekleştirilen adli bilişim incelemelerinin önemi her geçen gün artmaktadır. Adli bilişim incelemelerinde delillerin orijinalliğinin ve bütünlüğünün bozulmaması için incelemelerin adli kopya (imaj) üzerinde yapılması gerekmektedir. Dijital delil, dijital cihaz ve ortamlarda bulunan dosyaları, uçucu verileri, kullanıcı ve sistem etkinliklerinden geriye kalan dijital kalıntıları kapsayan adli nitelikli bilgilerin tümünü ifade eder. Adli bilişim incelemelerinde dijital deliller çeşitli yöntemler ile toplanmakta ve analiz edilmektedir. İşletim sistemleri bu yöntemlerin etkin biçimde uygulanabildiği başlıca dijital delil kaynaklarındandır. Küresel ölçekte olduğu gibi ülkemizde de kişisel ve kurumsal olarak Windows işletim sistemi yaygın olarak kullanılmaktadır. Dijital delillerin toplanması, düzenlenmesi, ilişkilendirilmesi, anlamlandırılması ve analizi adli bilişim uzmanları tarafından gerçekleştirilmekte olup, uzun süreli ve maliyetli olabilmektedir. Bu çerçevede kullanılan adli bilişim araçlarından bazıları sistem/disk odaklı çalışırken bazıları da RAM odaklı çalışmaktadır. Özellikle açık kaynak kodlu veya ücretsiz olanlarda genellikle dijital delillerin toplanmasına ağırlık verilirken otomatik analiz hususunun arka planda kaldığı görülmektedir. Bu kapsamda adli bilişim incelemesinin ve analizinin etkin, verimli, hızlı ve kolay bir şekilde yapılabilmesi için dijital delillerin hem disk imajı hem de RAM imajı üzerinden toplanması ve ilişkilendirilmesi, zaman çizelgesinin oluşturulması, silinmiş dosyaların kurtarılması, zararlı/şüpheli/anomali tespiti işlemlerinin otomatik olarak gerçekleştirilmesine yönelik çalışma yapılmasına ihtiyaç duyulmuştur. Bu çalışmada, günümüzde yaygın olarak kullanılan işletim sistemi olan Windows tabanlı sistemlerdeki dijital deliller/kalıntılar ve adli bilişim süreci teknik açıdan ele alınmıştır. Konuya yönelik literatür araştırması yapılmış, adli bilişim araçları incelenmiştir. Windows tabanlı sistemlerin disk ve RAM imajlarından dijital delillerin toplanmasını, zaman çizelgesinin çıkarılmasını, silinmiş dosyaların kurtarılmasını, toplanan dijital delillerin ilişkilendirilmesini, kural tabanlı analiz ile zararlı/şüpheli işlemlerin ve yapay zekâ destekli analiz ile anomalilerin tespit edilmesini otomatik olarak gerçekleştiren“CAMGÖZ”isimli bir yazılım geliştirilmiştir. Böylece adli bilişim incelemesinin ve analizinin etkin, verimli, hızlı ve kolay bir şekilde yapılması sağlanmıştır. Bahse konu yazılımın adli bilişim ve siber güvenlik alanında faydalı olacağı değerlendirilmektedir.
Özet (Çeviri)
With advancing technology, information technologies and digital devices play a significant role in our daily lives. Cybercriminals and attackers also exploit information technologies and digital devices for malicious activities. Due to the increasing use of computers for criminal purposes, digital forensics has become a crucial part of criminal investigations. The work involved in digital forensics can be summarized as the initial response at the crime scene, the collection of electronic evidence, the examination and analysis of evidence collected at the crime scene or in the laboratory, and reporting to the relevant authorities. In order to combat cybercrimes and crimes committed using information technologies more effectively, digital evidence (data and information transmitted or stored via electronic or magnetic media) is needed in addition to physical evidence in the process of identifying the facts of the crime and bringing criminals to justice. Data acquired from information technologies has become crucial in investigations and trial processes. Therefore, in order for legal processes to proceed without interruption, collected digital data must be analyzed accurately within the required timeframe and presented to the relevant authorities. Digital evidence refers to data recorded on electronic or magnetic devices that contributes to the investigation of a crime. To examine seized digital material, it is generally necessary to create a forensic copy (an image) of the digital material and analyze this copy. This is done to prevent damage to the original digital material and to maintain the integrity of the evidence. In the process of collecting digital evidence, examining the operating system in particular can provide access to evidentiary data. The operating system provides access to various structured data, including all searches, file operations, system logs, running applications, internet access history, email files, and more. Therefore, operating system-based digital forensics offers significant opportunities for the collection of digital evidence. In Windows-based systems, digital evidence is generally divided into four main categories: Registry, File System, User and System, and Memory. Registry evidence resides in a hierarchical database containing valuable information such as user activity, system configurations, and software traces. These records are loaded into memory during system startup, and changes are written to disk both at regular intervals during operation and when the system shuts down properly. These records allow digital forensics experts to retrospectively examine past user activity, program execution history, and changes made to the system. File system evidence encompasses digital traces originating from the NTFS (New Technology File System) architecture used in the Windows operating system. NTFS records timestamps such as creation, modification, and access times for files and folders, as well as file permissions and alternate data streams. Furthermore, thanks to the Master File Table (MFT), even metadata from deleted files can remain in the system for some time. This structure is a significant source of evidence for identifying and creating a timeline of user actions on files. User and system evidence is collected from audit logs generated by the operating system and applications. This evidence includes information such as when users logged into the system, which programs they ran, how often they used those programs, and which resources they accessed. Application, security, and system logs, especially Windows Event Logs, play a critical role in detecting unauthorized access, errors, and suspicious activity. These records allow for a chronological analysis of events. Memory evidence consists of temporary data structures located in RAM while the system is running. Extremely sensitive information such as running processes, network connections, open files, passwords, and encryption keys can reside in memory. Acquisition of this type of evidence requires taking a memory image from the live system; otherwise, this data is lost when the system is shut down. However, files like pagefile.sys and hiberfil.sys, which consist of memory data written to disk, contain important memory remnants that can be examined even in static forensics. Memory records allow for the analysis of software and user activity. Digital forensics tools can collect various types of digital evidence from live or offline systems. Tools operating on offline systems typically collect digital evidence via disk images or RAM images. The collection, organization, correlation, interpretation, and analysis of digital evidence are performed by digital forensics experts and can be timeconsuming and costly. Some digital forensics tools focus on disks, while others focus on RAM. Open-source or free tools, in particular, often prioritize the collection of digital evidence while neglecting automated analysis. In addition to collecting digital evidence from both disk and RAM images, it is crucial to convert the collected digital evidence into an understandable format for digital forensics experts and to perform automated inferences based on that evidence. In this study, in addition to collecting digital evidence from disk and RAM images of Windows-based systems and recovering deleted files, the following objectives have been achieved. A timeline is created for digital evidence collected from disk and RAM images. By correlating digital evidence collected from disk images with digital evidence collected from RAM images taken before the system was last shut down, detailed information such as the process ID, process name, start time, initiator username, parent process ID, parent process name, network connections, and file paths of malicious processes identified in the RAM image is obtained. Digital evidence collected from disk and RAM images is analyzed in two stages. In the first stage, rule-based analysis identifies matters such as running malicious powershell commands, pass the hash attacks, installing malicious services, running psexec, deleting Windows event logs, connecting to the local area network via RDP from an external network, disabling Windows event log monitoring, suspicious scheduled tasks, suspicious failed logins, suspicious file writing, persistence indicators, system date and time setting information, changing the system date and time, malicious process information, suspicious process, suspicious network connection, suspicious DLL. In the second stage, AI-assisted analysis identifies unusual activities from data such as the frequency, length, and structure of registry key changes, the timing of successful and unsuccessful login and logout operations, usernames, and the timing, frequency, and usernames of file deletions. The analysis results are correlated with attacker behaviors within the MITRE ATT&CK framework. A software called“CAMGÖZ”has been developed to perform all these operations. In conclusion, in this study, digital evidence/artifacts in Windows-based systems, which are widely used in today's computing environments, and the forensic process have been examined from a technical perspective. A literature research on the subject was conducted, and forensic tools were analyzed. Collection of digital evidence from disk and RAM images with Windows-based systems, extraction of a timeline, recovery of deleted files, correlation collected digital evidence, detection of malicious/suspicious activities with rule-based analysis and anomalies with artificial intelligence-assisted analysis have been automatically performed. In this context, a software called“CAMGÖZ”was developed. Thus, the digital forensic analysis has been made more effective, efficient, fast, and easy to perform. It is evaluated that the software in question will be useful in the field of forensic computer and cyber security.
Benzer Tezler
- Bilgisayar tabanlı bilişim suçlarının adli bilişim çerçevesinde incelenmesi ve analizi
Within the framework of computer forensics computer based information technology crime investigations and analysis
İSMAİL MELİH TAŞ
Yüksek Lisans
Türkçe
2013
Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve KontrolMarmara ÜniversitesiElektronik-Bilgisayar Ana Bilim Dalı
DOÇ. DR. HAKAN KAPTAN
DOÇ. DR. ALİ BULDU
YRD. DOÇ. DR. ÖMER KORÇAK
- Gelişmiş kalıcı tehditlerin incelenerek siber güvenlik tehditlerini tespit eden aracın geliştirilmesi
Development of a thread detection tool through the analysis of advanced persistent threats in cybersecurity
MEHMET KADİR CIRIK
Yüksek Lisans
Türkçe
2026
Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve KontrolFırat ÜniversitesiAdli Bilişim Ana Bilim Dalı
DOÇ. FATİH ERTAM
- USB taşınabilir veri depolama ortamlarının windows işletim sistemi üzerinde bıraktıkları izlerin adli bilişim teknikleri ile incelenmesi
Examination of the traces left by USB portable data storage media on the windows operating system with forensic computing techniques
SÜLEYMAN TANER GÖKŞİN
Yüksek Lisans
Türkçe
2022
Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve KontrolAnkara ÜniversitesiAdli Bilimler Ana Bilim Dalı (disiplinlerarası)
PROF. DR. REFİK SAMET
- Windows işletim sistemi kurulu bilgisayarlara bağlanan telefonların adli bilişim açısından incelenmesi
Digital forensics analysis of phones connected to computers running windows operating systems
ALİ ÇETİN
- Olay müdahalesi kapsamında windows işletim sistemine sahip cihazlardan triyaj kayıtlarının elde edilmesi
Collection of triage from machines with windows operating system in incident response
KAAN YENİYOL
Yüksek Lisans
Türkçe
2021
Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve KontrolFırat ÜniversitesiAdli Bilişim Ana Bilim Dalı
DOÇ. DR. FATİH ERTAM