{"id":10120,"date":"2021-10-06T12:25:08","date_gmt":"2021-10-06T09:25:08","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=10120"},"modified":"2024-11-08T17:32:46","modified_gmt":"2024-11-08T14:32:46","slug":"ransomware-protection-test-2021","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/ransomware-protection-test-2021\/10120\/","title":{"rendered":"G\u00fcvenlik \u00e7\u00f6z\u00fcmleri fidye yaz\u0131l\u0131mlar\u0131 kar\u015f\u0131s\u0131nda ne kadar etkili?"},"content":{"rendered":"<p>Neredeyse her bilgi g\u00fcvenli\u011fi \u00e7\u00f6z\u00fcm\u00fc geli\u015ftiricisi, \u00fcr\u00fcnlerinin fidye yaz\u0131l\u0131m\u0131 sald\u0131r\u0131lar\u0131n\u0131 engelledi\u011fini iddia ediyor. Bu do\u011fru bir iddia: Hepsi bir yere kadar fidye yaz\u0131l\u0131mlar\u0131na kar\u015f\u0131 koruma sa\u011fl\u0131yor. Fakat bu koruma ne kadar g\u00fc\u00e7l\u00fc? Kullan\u0131lan teknolojiler ne kadar etkili?<\/p>\n<p>Bunlar i\u00e7i bo\u015f sorular de\u011fil: Fidye yaz\u0131l\u0131mlar\u0131na kar\u015f\u0131 k\u0131smi koruma, \u015f\u00fcpheli bir ba\u015far\u0131d\u0131r. Bir \u00e7\u00f6z\u00fcm, daha ilerleyen bir tehdidi bile durduram\u0131yorsa, en az\u0131ndan kritik dosyalar\u0131 g\u00fcvende tuttu\u011funu nas\u0131l garanti edebilir?<\/p>\n<p>Ba\u011f\u0131ms\u0131z bir \u015firket olan AV-Test, bunu g\u00f6z \u00f6n\u00fcnde bulundurarak, kullan\u0131c\u0131lar\u0131 ger\u00e7ekte ne \u00f6l\u00e7\u00fcde koruduklar\u0131n\u0131 belirlemek amac\u0131yla 11 u\u00e7 nokta koruma platformu \u00fcr\u00fcn\u00fcn\u00fc 113 farkl\u0131 sald\u0131r\u0131 kar\u015f\u0131s\u0131na \u00e7\u0131kard\u0131. AV-Test, test i\u00e7in<a href=\"https:\/\/www.kaspersky.com.tr\/security-cloud?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_post____ksc___\" target=\"_blank\" rel=\"noopener\">Kaspersky Endpoint Security Cloud<\/a>\u2018u se\u00e7ti ve \u00fcr\u00fcn\u00fcm\u00fcz ba\u015ftan sona kusursuz bir \u015fekilde \u00e7al\u0131\u015ft\u0131. Testlerde \u00fc\u00e7 senaryo kullan\u0131ld\u0131:<\/p>\n<h2>Kullan\u0131c\u0131 dosyalar\u0131n\u0131n yayg\u0131n kullan\u0131lan fidye yaz\u0131l\u0131mlar\u0131na kar\u015f\u0131 korunmas\u0131<\/h2>\n<p>\u0130lk test senaryosu, en tipik fidye yaz\u0131l\u0131m\u0131 sald\u0131r\u0131s\u0131 olan kurban\u0131n bilgisayar\u0131nda k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m \u00e7al\u0131\u015ft\u0131r\u0131lmas\u0131n\u0131 ve k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131n yerel dosyalara eri\u015fmeye \u00e7al\u0131\u015fmas\u0131n\u0131 canland\u0131r\u0131yordu. Testin olumlu sonu\u00e7lanmas\u0131, tehdidin etkisiz hale getirildi\u011fi (yani, t\u00fcm k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m dosyalar\u0131n\u0131n silindi\u011fi, i\u015flemlerin y\u00fcr\u00fct\u00fclmesinin durduruldu\u011fu, sistemde yer edinme giri\u015fimlerinin engellendi\u011fi), her bir kullan\u0131c\u0131 dosyas\u0131n\u0131n \u015fifrelenmemi\u015f ve eri\u015filebilir oldu\u011fu anlam\u0131na geliyordu. AV-Test, bu senaryoda \u015fu 20 fidye yaz\u0131l\u0131m\u0131 ailesiyle toplam 85 test ger\u00e7ekle\u015ftirdi: conti, darkside, fonix, limbozar, lockbit, makop, maze, medusa (ako), mountlocker, nefilim, netwalker (di\u011fer ad\u0131yla mailto), phobos, PYSA (di\u011fer ad\u0131yla mespinoza), Ragnar Locker, ransomexx (di\u011fer ad\u0131yla defray777), revil (di\u011fer ad\u0131yla Sodinokibi veya Sodin), ryuk, snatch, stop, ve wastedlocker.<\/p>\n<p>Bu senaryoda, neredeyse her g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc m\u00fckemmel bir i\u015f \u00e7\u0131kard\u0131 ki testte iyi bilinen k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m aileleri kullan\u0131ld\u0131\u011f\u0131 i\u00e7in bu pek de \u015fa\u015f\u0131rt\u0131c\u0131 bir sonu\u00e7 de\u011fildi. Sonraki senaryolar ise daha zorluydu.<\/p>\n<h2>Uzaktan \u015fifrelemeye kar\u015f\u0131 koruma<\/h2>\n<p>\u0130kinci senaryoda, korumaya sahip makinede yerel a\u011f \u00fczerinden eri\u015filebilen dosyalar bulunuyordu ve sald\u0131r\u0131 ayn\u0131 a\u011fdaki ba\u015fka bir bilgisayardan ger\u00e7ekle\u015ftirildi (di\u011fer bilgisayarda hi\u00e7bir g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc yoktu, bu da sald\u0131rganlar\u0131n k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131 \u00e7al\u0131\u015ft\u0131rma, yerel dosyalar\u0131 \u015fifreleme ve ard\u0131ndan kom\u015fu ana bilgisayarlarda eri\u015filebilir bilgileri arama \u00f6zg\u00fcrl\u00fc\u011f\u00fcne sahip olmas\u0131n\u0131 sa\u011fl\u0131yordu). Testte kullan\u0131lan k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m aileleri ise \u015funlard\u0131: avaddon, conti, fonix, limbozar, lockbit, makop, maze, medusa (ako), nefilim, phobos, Ragnar Locker, Ransomexx (di\u011fer ad\u0131yla defray777), revil (di\u011fer ad\u0131yla Sodinokibi veya Sodin), ve ryuk.<\/p>\n<p>Yerel dosyalar\u0131 de\u011fi\u015ftiren bir sistem i\u015flemi oldu\u011funu g\u00f6ren ancak k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131n ba\u015flat\u0131lmas\u0131n\u0131 fark edemeyen g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc, k\u00f6t\u00fc ama\u00e7l\u0131 i\u015flemin veya onu ba\u015flatan dosyan\u0131n g\u00fcvenirli\u011fini kontrol edemedi veya dosyay\u0131 tarayamad\u0131. G\u00f6r\u00fcnen o ki, teste kat\u0131lan 11 \u00e7\u00f6z\u00fcmden yaln\u0131zca \u00fc\u00e7\u00fc bu t\u00fcr sald\u0131r\u0131lara kar\u015f\u0131 bir koruma sa\u011flad\u0131 ve yaln\u0131zca Kaspersky Endpoint Security Cloud bununla m\u00fckemmel bir \u015fekilde ba\u015fa \u00e7\u0131kt\u0131. \u00dcstelik Sophos\u2019un \u00fcr\u00fcn\u00fc vakalar\u0131n %93\u2019\u00fcnde tetiklenmi\u015f olsa da, yaln\u0131zca %7\u2019sinde kullan\u0131c\u0131 dosyalar\u0131n\u0131 tam olarak koruyordu.<\/p>\n<h2>Kavram kan\u0131t\u0131 (proof-of-concept) fidye yaz\u0131l\u0131mlar\u0131na kar\u015f\u0131 koruma<\/h2>\n<p>\u00dc\u00e7\u00fcnc\u00fc senaryoda ise, \u00fcr\u00fcnlerin, daha \u00f6nce kar\u015f\u0131la\u015fmas\u0131n\u0131n m\u00fcmk\u00fcn olmad\u0131\u011f\u0131 ve k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m veri tabanlar\u0131nda bulunmas\u0131 varsay\u0131msal olarak bile s\u00f6z konusu olmayan k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlarla nas\u0131l ba\u015fa \u00e7\u0131kaca\u011f\u0131 test ediliyordu. G\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc, hen\u00fcz bilinmeyen bir tehdidi yaln\u0131zca k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131n davran\u0131\u015f\u0131na tepki veren proaktif teknolojiler arac\u0131l\u0131\u011f\u0131yla tespit edebildi\u011fi i\u00e7in ara\u015ft\u0131rmac\u0131lar, siber su\u00e7lular\u0131n nadiren kulland\u0131\u011f\u0131 y\u00f6ntem ve teknolojileri bar\u0131nd\u0131ran 14 yeni fidye yaz\u0131l\u0131m\u0131 \u00f6rne\u011finin yan\u0131 s\u0131ra daha \u00f6nce hi\u00e7 g\u00f6r\u00fclmemi\u015f baz\u0131 orijinal \u015fifreleme teknikleri olu\u015fturdular. \u0130lk senaryoda oldu\u011fu gibi, testin ba\u015far\u0131yla sonu\u00e7lanmas\u0131n\u0131, kurban\u0131n makinesindeki t\u00fcm dosyalar\u0131n b\u00fct\u00fcnl\u00fc\u011f\u00fcn\u00fc korunmas\u0131 ve tehdidin t\u00fcm izlerini bilgisayardan tamamen kald\u0131r\u0131lmas\u0131n\u0131 i\u00e7eren tehdit alg\u0131lama ve engelleme olarak belirlediler.<\/p>\n<p>Sonu\u00e7lar, baz\u0131lar\u0131 \u00fcr\u00fcnlerin (ESET ve Webroot) \u00f6zel yap\u0131m k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar\u0131 hi\u00e7 alg\u0131lamamas\u0131 ile di\u011ferlerinin daha iyi performans g\u00f6stermesi (WatchGuard %86, TrendMicro %64, McAfee ve Microsoft %50) aras\u0131nda farkl\u0131l\u0131k g\u00f6steriyordu. %100 performans g\u00f6steren tek \u00e7\u00f6z\u00fcm Kaspersky Endpoint Security Cloud oldu.<\/p>\n<h2>Test sonu\u00e7lar\u0131<\/h2>\n<p>\u00d6zetle, Kaspersky Endpoint Security Cloud, AV-Test\u2019in t\u00fcm senaryolar\u0131nda rakiplerini geride b\u0131rakarak kullan\u0131c\u0131lar\u0131 hem bilinen hem de yeni olu\u015fturulan tehditlere kar\u015f\u0131 korudu.<\/p>\n<div id=\"attachment_10122\" style=\"width: 1034px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-10122\" class=\"wp-image-10122 size-large\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2021\/10\/06120917\/ransomware-protection-test-2021-results-1024x544.jpg\" alt=\"\" width=\"1024\" height=\"544\"><p id=\"caption-attachment-10122\" class=\"wp-caption-text\">Her \u00fc\u00e7 test senaryosuna ili\u015fkin toplu sonu\u00e7lar.<\/p><\/div>\n<p>\u00a0<\/p>\n<p>Bu arada, ikinci senaryo pek beklenmedik bir ger\u00e7e\u011fi daha ortaya \u00e7\u0131kard\u0131: Kullan\u0131c\u0131 dosyalar\u0131n\u0131 koruyamayan \u00fcr\u00fcnlerin \u00e7o\u011fu t\u00fcm bunlara ra\u011fmen fidye notunun oldu\u011fu dosyalar\u0131n\u0131 kald\u0131rd\u0131. Ba\u015far\u0131s\u0131zl\u0131k bir kenara, bu pek de iyi bir uygulama de\u011fildir; bu t\u00fcr dosyalar, olay ara\u015ft\u0131rmac\u0131lar\u0131n\u0131n verileri kurtarmas\u0131na yard\u0131mc\u0131 olabilecek teknik bilgileri i\u00e7erebilir.<\/p>\n<p>A\u015fa\u011f\u0131daki formu doldurduktan sonra, testte kullan\u0131lan k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131n\u0131n (hem bilinen hem de test kullan\u0131c\u0131lar\u0131 taraf\u0131ndan olu\u015fturulan) ayr\u0131nt\u0131l\u0131 bir a\u00e7\u0131klamas\u0131yla birlikte raporun tam halini indirebilirsiniz.<\/p>\n<p><script data-b24-form=\"inline\/1370\/bqfz5l\" data-skip-moving=\"true\">(function(w,d,u){var s=d.createElement('script');s.async=true;s.src=u+'?'+(Date.now()\/180000|0);var h=d.getElementsByTagName('script')[0];h.parentNode.insertBefore(s,h);})(window,document,'https:\/\/cdn.bitrix24.eu\/b30707545\/crm\/form\/loader_1370.js');<\/script><script src=\"https:\/\/storage.yandexcloud.net\/kasperskyform\/validator.js\"><\/script><script>\n          initBxFormValidator({\n              formId: \"inline\/1370\/bqfz5l\",\n              emailFieldName: 'CONTACT_EMAIL',\n              naturalFieldNames: [ 'CONTACT_UF_CRM_NODES' ],\n              lengthRestrictedFieldNames: { CONTACT_EMAIL: 250, CONTACT_POST: 128, CONTACT_NAME: 50, CONTACT_UF_CRM_COMPANY: 255, CONTACT_UF_CRM_COMPANY_TAX_ID: 50, CONTACT_UF_CRM_PRODUCT_INTEREST: 255, CONTACT_UF_CRM_FORM_QUESTION_2: 255, CONTACT_UF_CRM_FORM_QUESTION_3: 255, CONTACT_UF_CRM_FORM_QUESTION_5: 255 },\n              redirectUrl: 'https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2021\/10\/04173946\/AV-TEST_Kaspersky_Ransomware_Test_September_2021_EN.pdf'\n          })\n      <\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>11 Geli\u015fmi\u015f g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc, en g\u00fcncel fidye yaz\u0131l\u0131m\u0131 tehditlerine kar\u015f\u0131 test ediliyor. <\/p>\n","protected":false},"author":2706,"featured_media":10121,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1726,1194],"tags":[865,591,2362,575],"class_list":{"0":"post-10120","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-enterprise","8":"category-business","9":"tag-av-test","10":"tag-fidye-yazilimi","11":"tag-para-sizdirma","12":"tag-testler"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/ransomware-protection-test-2021\/10120\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/ransomware-protection-test-2021\/23466\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/ransomware-protection-test-2021\/18939\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/ransomware-protection-test-2021\/9457\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/ransomware-protection-test-2021\/25531\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/ransomware-protection-test-2021\/23606\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/ransomware-protection-test-2021\/23024\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/ransomware-protection-test-2021\/26176\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/ransomware-protection-test-2021\/25724\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/ransomware-protection-test-2021\/31649\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/ransomware-protection-test-2021\/42324\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/ransomware-protection-test-2021\/17838\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/ransomware-protection-test-2021\/18224\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/ransomware-protection-test-2021\/15385\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/ransomware-protection-test-2021\/27524\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/ransomware-protection-test-2021\/31762\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/ransomware-protection-test-2021\/27690\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/ransomware-protection-test-2021\/24464\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/ransomware-protection-test-2021\/29818\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/ransomware-protection-test-2021\/29617\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/fidye-yazilimi\/","name":"Fidye Yaz\u0131l\u0131m\u0131"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/10120","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2706"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=10120"}],"version-history":[{"count":5,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/10120\/revisions"}],"predecessor-version":[{"id":12914,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/10120\/revisions\/12914"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/10121"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=10120"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=10120"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=10120"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}