{"id":2338,"date":"2016-08-16T08:19:09","date_gmt":"2016-08-16T12:19:09","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=2338"},"modified":"2019-11-15T14:58:27","modified_gmt":"2019-11-15T11:58:27","slug":"smart-cities-black-hat","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/smart-cities-black-hat\/2338\/","title":{"rendered":"Ak\u0131ll\u0131 \u015fehir teknolojisi konusunda endi\u015felenmeli miyiz?"},"content":{"rendered":"<p>16:00 gibi New York\u2019taki trafik \u0131\u015f\u0131klar\u0131n\u0131n kapat\u0131ld\u0131\u011f\u0131n\u0131 d\u00fc\u015f\u00fcn\u00fcn \u2013 ya da daha anla\u015f\u0131l\u0131r \u015fekilde ifade edelim: \u0130stanbul\u2019da i\u015f \u00e7\u0131k\u0131\u015f saatinde \u015fehirdeki t\u00fcm trafik \u0131\u015f\u0131klar\u0131n\u0131n kapat\u0131ld\u0131\u011f\u0131n\u0131 d\u00fc\u015f\u00fcn\u00fcn.<\/p>\n<p>Bu d\u00fc\u015f\u00fcnce Ryan Naraine\u2019nin Black Hat\u2019te yapt\u0131\u011f\u0131 \u2018Ak\u0131ll\u0131 \u015eehirleri Koruma\u2019 konu\u015fmas\u0131ndan beri akl\u0131m\u0131 kurcal\u0131yor.<\/p>\n<p>Bu konu teknik ara\u015ft\u0131rmac\u0131lar aras\u0131ndaki \u00f6ncelikli konuydu. D\u00fcnyan\u0131n en i\u015flek \u015fehirlerinin birinde trafik \u0131\u015f\u0131klar\u0131n\u0131n \u00e7al\u0131\u015fmama ihtimali pek kald\u0131rabilece\u011fim bir \u015fey de\u011fil. Bug\u00fcnlerde her \u015fey internete ba\u011fl\u0131 \u2013 telefonunuz, televizyonunuz, saatiniz, fitness uygulaman\u0131z, hatta belki evinizin kap\u0131s\u0131. Peki <a href=\"https:\/\/www.kaspersky.com\/blog\/traffic-light-attacks\/5830\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">trafik \u0131\u015f\u0131klar\u0131n\u0131n<\/a>, <a href=\"https:\/\/www.kaspersky.com\/blog\/train-hack\/10946\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">rayl\u0131 sistemlerin<\/a> ve <a href=\"https:\/\/www.kaspersky.com\/blog\/air-conditioner-hack\/11348\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">enerji \u015febekelerinin<\/a> de internete ba\u011fland\u0131\u011f\u0131n\u0131 biliyor muydunuz?<\/p>\n<p>Asl\u0131nda hayat\u0131m\u0131z\u0131 etkileyen ve her g\u00fcn kulland\u0131\u011f\u0131m\u0131z end\u00fcstriyel sistemlerin devre d\u0131\u015f\u0131 b\u0131rak\u0131labilece\u011fini d\u00fc\u015f\u00fcnmek baya korkutucu.<\/p>\n<p>Elektrik?<\/p>\n<p>Rayl\u0131 sistemler?<\/p>\n<p>Trafik \u0131\u015f\u0131klar\u0131?<\/p>\n<p>\u00a0<br>\nBu \u00fc\u00e7\u00fcnden birini bile tam olarak kullanamazsak durum \u00f6l\u00fcmc\u00fcl bir hal alabilir. Ama bir\u00e7ok \u015feyde oldu\u011fu gibi, ak\u0131ll\u0131 \u015fehir g\u00fcvenli\u011fi olmas\u0131 gereken yerde de\u011fil.<\/p>\n<p>https:\/\/www.instagram.com\/p\/BIqLhaeA32B\/<\/p>\n<p>G\u00fcvenlik sistemleri genellikle sistemlerin b\u00fcrokratik s\u00fcreci ve geli\u015ftirme s\u00fcre\u00e7leri tamamland\u0131ktan sonra akla geliyor. <\/p>\n<p>Bu konunun g\u00fcvenlik taraf\u0131 ile ilgili yap\u0131lan konu\u015fmalar epey rahats\u0131z edici. Tart\u0131\u015fan g\u00fcvenlik z\u00fcmresi s\u00fcrekli ayn\u0131 konuyu konu\u015fup duruyorlar \u2013 hi\u00e7bir ilerleme kaydedemiyorlar. \u00c7\u00fcnk\u00fc projeler hayata ge\u00e7irilirken g\u00fcvenlik konusunda onca \u015fey yapmalar\u0131 gerekmesine ra\u011fmen, hi\u00e7bir \u015fey yapm\u0131yorlar.<\/p>\n<p>Konu g\u00fcvenlik olunca genellikle g\u00fcnl\u00fck hayatta kulland\u0131\u011f\u0131m\u0131z \u015feylere odaklan\u0131yoruz: bilgisayarlar, telefonlar, telefon uygulamalar\u0131 vb. Ama bunlar\u0131 gerekli de\u011fil, l\u00fcks olarak de\u011ferlendiriyorlar. Hacklenmek b\u00fcy\u00fck s\u0131k\u0131nt\u0131lar do\u011furur, ama genellikle can\u0131n\u0131za mal olmaz. <\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"tr\" dir=\"ltr\">Yeme\u011fi, suyu ve elektri\u011fi hacklemek <a href=\"https:\/\/t.co\/LtyOzURylf\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/LtyOzURylf<\/a> <a href=\"https:\/\/t.co\/uUL2SyVuCK\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/uUL2SyVuCK<\/a><\/p>\n<p>\u2014 Kaspersky T\u00fcrkiye (@KasperskyTR) <a href=\"https:\/\/twitter.com\/KasperskyTR\/status\/755317543326318592?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">July 19, 2016<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Ge\u00e7en haftalarda yapt\u0131\u011f\u0131m\u0131z <a href=\"https:\/\/www.kaspersky.com\/blog\/6-best-questions-to-our-great-and-their-answers\/12705\/\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">AMA<\/a> konferans\u0131nda bir soru soruldu; <em>\u2018Merak ediyorum, sizce gelecekte end\u00fcstriyel kontrol sistemlerine yap\u0131lacak bir hack sald\u0131r\u0131s\u0131 sonucunda b\u00fcy\u00fck sorunlar do\u011furur ya da belki \u00f6l\u00fcm ile sonu\u00e7labilir mi? \u015eimdilik b\u00f6yle bir \u015fey m\u00fcmk\u00fcn m\u00fc? Alman \u00e7elik fabrikas\u0131 sald\u0131r\u0131s\u0131, Kara Enerji fidye yaz\u0131l\u0131m\u0131 ve \u0130svi\u00e7re hava trafik kontrol sald\u0131r\u0131s\u0131 bu tarz facialardan pek uzak olmad\u0131\u011f\u0131m\u0131z\u0131 hissettiriyor.<br>\n<\/em><br>\nBrian Bartholomew \u015f\u00f6yle cevap verdi:<em> Uzmanlara sorulabilecek harika bir soru. Bana g\u00f6re, herhangi bir hacker\u0131n s\u0131n\u0131r\u0131 a\u015f\u0131p birilerinin hayat\u0131na mal olmas\u0131 an meselesi. E\u011fer dikkat ettiyseniz, b\u00fct\u00fcn bu kritikal sistemler hala g\u00fcvenli de\u011fil ve tehditlere a\u00e7\u0131k, b\u00fct\u00fcn olay sadece end\u00fcstriyel kontrol sistemlerinin nas\u0131l \u00e7al\u0131\u015ft\u0131\u011f\u0131n\u0131 bilen bir \u00e7\u0131lg\u0131na bak\u0131yor. <\/em><br>\n<em><br>\nBu y\u00fczden sahadaki uzmanlar\u0131n ilk \u00f6nceli\u011fi end\u00fcstriyel kontrol sistemlerinin g\u00fcvenli\u011fini sa\u011flamak olmal\u0131. Ayr\u0131ca bu sert sorular\u0131 sorabilecek bilin\u00e7teki ba\u015fka insanlara da ihtiyac\u0131m\u0131z var. Bu soruyu sorabilecek bilin\u00e7teki insanlara gelecek olursak.. asl\u0131nda, onlar da bu konuda \u201dpek\u201d iyi de\u011filler. Hatta \u201dpek\u201d kelimesi bile yeterli de\u011fil. \u0130nsanlar bu konuda huzursuz olmal\u0131lar, hatta sadece bu konuda da de\u011fil.  Bu mitolojik bir hikaye de\u011fil. \u00c7ok daha k\u00f6t\u00fc hal almadan \u00f6nce at\u0131lmas\u0131 gereken bir ad\u0131m. <\/em><\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Black Hat and DEF CON: Hacking a chemical plant \u2013 <a href=\"https:\/\/t.co\/KSnCTtLt5U\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/KSnCTtLt5U<\/a><\/p>\n<p>\u2014 Kaspersky (@kaspersky) <a href=\"https:\/\/twitter.com\/kaspersky\/status\/634086251205926913?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">August 19, 2015<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>Vitaly Kamluk ise \u015f\u00f6yle cevap verdi: <em>D\u00fcr\u00fcst olmak gerekirse, bu konuda d\u00fc\u015f\u00fcnmek dahi istemiyorum. En son zararl\u0131 bir yaz\u0131l\u0131m\u0131n\u0131n sanal ve ger\u00e7ek d\u00fcnya s\u0131n\u0131r\u0131n\u0131 a\u015f\u0131p fiziksel objelere zarar vermesini d\u00fc\u015f\u00fcnmemden bir ay sonra Stunex olay\u0131 ger\u00e7ekle\u015fti. Daha sonra \u015funu d\u00fc\u015f\u00fcnd\u00fcm \u201cneden bu kadar erken?\u201d U\u00e7ak kazas\u0131, raydan \u00e7\u0131km\u0131\u015f trenler gibi haberler g\u00f6rd\u00fc\u011f\u00fcmde ayn\u0131 garip \u015feyi hissediyorum.<\/em><\/p>\n<p>Bu y\u0131l\u0131n ba\u015flar\u0131nda HalvarFlake olarak bilinen g\u00fcvenlik ara\u015ft\u0131rmac\u0131s\u0131 \u015f\u00f6yle bir \u015fey dedi (akl\u0131mda kald\u0131\u011f\u0131 kadar\u0131yla): <em>\u201cFiziksel objelere sahip olabilirsiniz. Bilgisayar sistemlerinin farkl\u0131 bir boyutu vard\u0131r, kontrol: bir bilgisayar\u0131n\u0131z olabilir, ama sistemini kimin kontrol etti\u011finden asla emin olamazs\u0131n\u0131z.\u201d<\/em><br>\n<em><br>\nBu beni geceleri uykumdan eden bir d\u00fc\u015f\u00fcnce, \u00e7\u00fcnk\u00fc bilgisayar\u0131m\u0131z\u0131n kontrol\u00fcn\u00fcn bizde oldu\u011funu sanmam\u0131z, elindeki g\u00fcc\u00fc ba\u015fkalar\u0131na kar\u015f\u0131 kullanan insanlar\u0131n yapabilecekleri s\u0131n\u0131rs\u0131z ihtimalleri akl\u0131ma getiriyor.<br>\n<\/em><br>\nPeki, bu konuda neler yap\u0131labilir?<\/p>\n<p>Ba\u015flang\u0131\u00e7ta, s\u0131radan bir vatanda\u015f olarak, yapmam\u0131z gereken ve yapmak zorunda oldu\u011fumuz \u015fey, se\u00e7ti\u011fimiz devlet yetkililerin vatanda\u015flar\u0131n g\u00fcvenli\u011fi i\u00e7in neler yapt\u0131\u011f\u0131na dikkat etmek.<\/p>\n<blockquote class=\"twitter-tweet\" data-width=\"500\" data-dnt=\"true\">\n<p lang=\"en\" dir=\"ltr\">Before <a href=\"https:\/\/twitter.com\/hashtag\/Stuxnet?src=hash&amp;ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">#Stuxnet<\/a>, there was little thought about proactively securing industrial facilities <a href=\"https:\/\/t.co\/2r3pXlbf7Z\" target=\"_blank\" rel=\"noopener nofollow\">https:\/\/t.co\/2r3pXlbf7Z<\/a> <a href=\"http:\/\/t.co\/vvj9ChCHAb\" target=\"_blank\" rel=\"noopener nofollow\">pic.twitter.com\/vvj9ChCHAb<\/a><\/p>\n<p>\u2014 Kaspersky (@kaspersky) <a href=\"https:\/\/twitter.com\/kaspersky\/status\/534775738558578688?ref_src=twsrc%5Etfw\" target=\"_blank\" rel=\"noopener nofollow\">November 18, 2014<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n<p>E\u011fitim ve fark\u0131ndal\u0131k hayati \u00f6nem ta\u015f\u0131yor. G\u00fcvenlik firmalar\u0131n\u0131n ve ana haberlerin bu konuya daha fazla \u00f6nem vermesi gerekiyor. Bu hassas sistemlerden herhangi birinin hacklenmesi tam anlam\u0131yla felaket olur. Bu konu ger\u00e7ekten arkada\u015fl\u0131k sitelerinin hacklenmesi ya da \u00fcnl\u00fclerin skandallar\u0131ndan fazla \u00f6nem vermemiz gereken bir konu. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>16:00 gibi New York\u2019taki trafik \u0131\u015f\u0131klar\u0131n\u0131n kapat\u0131ld\u0131\u011f\u0131n\u0131 d\u00fc\u015f\u00fcn\u00fcn \u2013 ya da daha anla\u015f\u0131l\u0131r \u015fekilde ifade edelim: \u0130stanbul\u2019da i\u015f \u00e7\u0131k\u0131\u015f saatinde \u015fehirdeki t\u00fcm trafik \u0131\u015f\u0131klar\u0131n\u0131n kapat\u0131ld\u0131\u011f\u0131n\u0131 d\u00fc\u015f\u00fcn\u00fcn. Bu d\u00fc\u015f\u00fcnce Ryan Naraine\u2019nin<\/p>\n","protected":false},"author":636,"featured_media":2339,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1287,1351],"tags":[967,966,965,916],"class_list":{"0":"post-2338","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-threats","9":"tag-endustriyel-hack","10":"tag-endustriyel-kontrol-sistemleri","11":"tag-endustriyel-sistemler","12":"tag-ryan-naraine"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/smart-cities-black-hat\/2338\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/smart-cities-black-hat\/7493\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/smart-cities-black-hat\/7517\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/smart-cities-black-hat\/7483\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/smart-cities-black-hat\/8905\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/smart-cities-black-hat\/8748\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/smart-cities-black-hat\/12707\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/smart-cities-black-hat\/12741\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/smart-cities-black-hat\/5967\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/smart-cities-black-hat\/6469\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/smart-cities-black-hat\/5273\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/smart-cities-black-hat\/8413\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/smart-cities-black-hat\/12250\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/smart-cities-black-hat\/12707\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/smart-cities-black-hat\/12741\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/smart-cities-black-hat\/12741\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/endustriyel-hack\/","name":"end\u00fcstriyel hack"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2338","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/636"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=2338"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2338\/revisions"}],"predecessor-version":[{"id":7158,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/2338\/revisions\/7158"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/2339"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=2338"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=2338"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=2338"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}