Geri Dön

Gerçek zamanlı güvenli veri haberleşmesinde anahtar yönetimi

Key management in real-time secure data communication

  1. Tez No: 1016234
  2. Yazar: ŞEVKİ GANİ ŞANLIÖZ
  3. Danışmanlar: PROF. DR. MUHAMMED ALİ AYDIN, DR. ÖĞR. ÜYESİ MUSTAFA KARA
  4. Tez Türü: Doktora
  5. Konular: Bilgisayar Mühendisliği Bilimleri-Bilgisayar ve Kontrol, Computer Engineering and Computer Science and Control
  6. Anahtar Kelimeler: Bilgisayar ağları güvenliği, Saldırı tespit sistemi (IDS), Computer networks security, Intrusion detection system (IDS)
  7. Yıl: 2026
  8. Dil: Türkçe
  9. Üniversite: İstanbul Üniversitesi-Cerrahpaşa
  10. Enstitü: Lisansüstü Eğitim Enstitüsü
  11. Ana Bilim Dalı: Bilgisayar Mühendisliği Ana Bilim Dalı
  12. Bilim Dalı: Bilgisayar Mühendisliği Bilim Dalı
  13. Sayfa Sayısı: Belirtilmemiş.

Özet

Dijital dönüşüm ve sanal iş birliği gereksinimleri sonucunda internet protokolü üzerinden ses (VoIP) kullanımı önemli ölçüde artış göstermiştir. Bu hızlı kullanım artışı bazı yeni güvenlik tehditlerini de beraberinde getirmiştir. Özellikle SIP tabanlı VoIP sistemlerinin hizmet aksatma (DoS/DDoS) saldırılarına karşı savunmasız olması, bu tür saldırılar karşısında sistem kaynaklarını tüketerek haberleşme sürekliliğini ciddi şekilde olumsuz etkilemesine sebebiyet vermektedir. Bu nedenle VLAN, güvenlik duvarı ve VPN gibi temel önlemlere ilave olarak gerçek zamanlı saldırı tespit mekanizmalarını içeren gelişmiş güvenlik çözümlerine ihtiyaç duyulmaktadır. Güvenli VoIP haberleşme sisteminin uçtan uca güvenlik sağlamasının yanı sıra yüksek erişilebilirlik ve etkin bir anahtar yönetim mekanizmasına sahip olması beklenmektedir. Ancak VoIP gibi zaman duyarlılığı olan sistemlerde anahtar yönetimi doğasi gereği karmaşıktır. Literatürde güvenli VoIP oturum anahtarı sağlamaya yönelik çalışmaların büyük kısmı istemci-sunucu mimarisinde çalışmakta veya anahtar yönetimi için merkezi yapılara bağımlı kalmaktadır. Bu durum, erişilebilirlik ve ölçeklenebilirlik açısından önemli sorunlara sebep olmaktadır. Bununla birlikte söz konusu mevcut çalışmaların birçoğu rastgele sayı üretiminde yeterli entropi seviyesini sağlayamamakta ve bir anahtar yönetim sisteminin sahip olması gereken standartları tam olarak karşılayamamaktadır. Bu çalışmada, kullanıcı verilerinin dağıtık yönetimi, Yankı Durumu Ağı (Echo State Network-ESN) tabanlı yüksek entropili rastgele sayı üreteci (Pseudo Random Number Generator-PRNG) ve eşler arası oturum başlatma protokolü (Peer-to-peer Session Initiation Protocol-P2P SIP) mimarisi ile uyumlu bir anahtar yönetim modeli önerilmiştir. Önerilen model uçtan uca güvenli ses ve görüntü haberleşmesinde daha yüksek performans, erişilebilirlik ve güvenlik sağlamayı amaçlamaktadır. Ayrıca, sistem mimarisine hibrit bir saldırı tespit sistemi entegre edilmiştir. Böylece SIP mesaj dizilerinin zamansal ve anlamsal analizini gerçekleştiren Transformer tabanlı çok başlı dikkat mekanizmasıyla güçlendirilmiş Bi-LSTM modeli ile ağ trafiğini analiz eden XGBoost sınıflandırıcısı birlikte kullanılmıştır. Bu hibrit yapı sayesinde SIP tabanlı haberleşme sırasında oluşabilecek anomali ve saldırılar gerçek zamanlı olarak tespit edilebilmektedir. Önerilen modelde kullanıcı adres, kimlik ve genel anahtar bilgileri blok zinciri tabanlı dağıtık bir mimaride yönetilmekte olup, bu sayede merkezi bileşenlere olan bağımlılık ortadan kaldırılmaktadır. ESN tabanlı PRNG kullanımı ise düşük hesaplama maliyeti ile yüksek entropili anahtar üretimi sağlayarak sistemin güvenliğini arttırmaktadır. Modelin kullanıcı bilgileri yönetimi uygulaması, sanal bir blok zinciri platformu olan Ethereum Sanal Makinesi (EVM) üzerinde; saldırı tespit uygulaması ise Google Colab ortamında gerçekleştirilmiştir. Güvenlik analizleri kapsamında hem formal analiz yöntemleri hem de teorik ispatlar kullanılarak modelin bilinen saldırılara karşı dayanıklılığı gösterilmiştir. Performans değerlendirmelerinde ise yürütme süresi, iletişim maliyeti, hesaplama maliyeti ve zaman karmaşıklığı gibi metrikler dikkate alınmamıştır. Elde edilen sonuçlar, önerilen modelin yalnızca etkin bir anahtar yönetim sistemi sunmakla kalmayıp, aynı zamanda VoIP saldırılarına karşı dirençli ve gerçek zamanlı uygulamalara uygun bir yapı sağladığını göstermektedir. Ayrıca, merkezi yapıya bağımlı olmaması sayesinde literatürdeki benzer çalışmalara kıyasla daha yüksek erişilebilirlik, güvenlik ve performans değerleri sağladığı belirlenmiştir. Hibrit saldırı tespit sistemi ise yüksek doğruluk oranı ve düşük yanlış alarm seviyesi ile üstün performans sergileyerek gerçek zamanlı VoIP sistemlerinde uygulanabilirliğini ortaya koymaktadır.

Özet (Çeviri)

As a result of digital transformation and the increasing need for virtual collaboration, the use of Voice over Internet Protocol (VoIP) has grown significantly. This rapid growth has also introduced new security threats. In particular, the vulnerability of SIP-based VoIP systems to Denial of Service (DoS/DDoS) attacks leads to the consumption of system resources, thereby adversely affecting the continuity of communication. Therefore, in addition to fundamental measures such as VLANs, firewalls, and VPNs, there is a need for advanced security solutions that incorporate real-time intrusion detection mechanisms. A secure VoIP communication system is expected not only to provide end-to-end security but also to ensure high availability and an effective key management mechanism. However, key management in time-sensitive systems such as VoIP is inherently complex. Most studies in the literature on secure VoIP session key establishment rely on client-server architectures or depend on centralized structures for key management. This situation leads to significant issues in terms of availability and scalability. Moreover, many existing studies fail to provide sufficient entropy in random number generation and do not fully meet the required standards of a robust key management system. In this study, a key management model compatible with distributed user data management, an Echo State Network (ESN)-based high-entropy pseudo-random number generator (PRNG), and a Peer-to-Peer Session Initiation Protocol (P2P SIP) architecture is proposed. The proposed model aims to provide higher performance, availability, and security in end-to-end secure voice and video communication. In addition, a hybrid intrusion detection system is integrated into the system architecture. Accordingly, a Bi-LSTM model enhanced with a transformer-based multi-head attention mechanism for temporal and semantic analysis of SIP message sequences is combined with an XGBoost classifier that analyzes network traffic. Through hybrid structure, anomalies and attacks that may occur during SIP-based communication can be detected in real time. In the proposed model, user address, identity, and public key information are managed within a blockchain-based distributed architecture, thereby eliminating dependency on centralized components. The use of an ESN-based PRNG provides high-entropy key generation with low computational cost, thereby enhancing system security. The user information management component of the model is implemented on the Ethereum Virtual Machine (EVM), a virtual blockchain platform, while the intrusion detection component is implemented in the Google Colab environment. Within the scope of security analysis, both formal analysis methods and theoretical proofs are employed to demonstrate the model's resilience against known attacks. Performance evaluations consider metrics such as execution time, communication cost, computational cost, and time complexity. The results indicate that the proposed model not only provides an effective key management system but also offers a structure that is resistant to VoIP attacks and suitable for real-time applications. Furthermore, due to its independence from centralized architectures, it achieves higher availability, security, and performance compared to similar studies in the literature. The hybrid intrusion detection system demonstrates superior performance with high accuracy and low false positive rates, confirming its applicability in real-time VoIP systems.

Benzer Tezler

  1. 1985-1986 yıllarında Polatlı Devlet Hastanesine kaza nedeniyle başvuranların incelenmesi

    Başlık çevirisi yok

    FERHAN ŞENOL

    Yüksek Lisans

    Türkçe

    Türkçe

    1986

    İlk ve Acil YardımGazi Üniversitesi

    Kazaların Çevresel ve Teknik Araştırması Ana Bilim Dalı (disiplinlerarası)

    DOÇ. DR. HİKMET PEKCAN

  2. Ulaş Sağlık Ocağı merkezinde nüfusun bazı niteliklerine ve konutların durumuna ilişkin bir çalışma

    An Investigation carried out at the Ulaş Public Health Centre concerning some characteristics of the population and housing conditions in the district of Ulaş

    EROL ŞANLI

    Doktora

    Türkçe

    Türkçe

    1985

    Halk SağlığıCumhuriyet Üniversitesi

    Halk Sağlığı Ana Bilim Dalı

    DOÇ. DR. SERVET ÖZGÜR

  3. Buğdayda farklı melezleme teknikleri kullanarak tohum tutma oranının saptanılması

    Başlık çevirisi yok

    İSMAİL TÜZÜN

    Yüksek Lisans

    Türkçe

    Türkçe

    1986

    ZiraatUludağ Üniversitesi

    Tarla Bitkileri Ana Bilim Dalı

    PROF. DR. HALİS RUHİ EKİNGEN

  4. Bölünüme bağlı olmayan varyans çözümlemesi çoklu karşılaştırmalar ve tarımda uygulamaları

    Distiribution-free analyis of variance multiple comparisons and applications in agriculture

    HAMZA GAMGAM

    Doktora

    Türkçe

    Türkçe

    1985

    İstatistikGazi Üniversitesi

    PROF. DR. ÖZKAN ÜNVER