{"id":4889,"date":"2018-05-02T11:10:05","date_gmt":"2018-05-02T08:10:05","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=4889"},"modified":"2019-11-15T14:42:05","modified_gmt":"2019-11-15T11:42:05","slug":"leaking-fish-tank","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/leaking-fish-tank\/4889\/","title":{"rendered":"S\u0131zd\u0131ran akvaryum"},"content":{"rendered":"<p>Konu Nesnelerin \u0130nterneti oldu\u011funda, g\u00fcvenlik h\u00e2l\u00e2 olmas\u0131 gereken noktada de\u011fil. Ba\u011flant\u0131l\u0131 ayg\u0131tlar\u0131n\u0131n da \u00e7o\u011fu pek bilinmiyor. Ayr\u0131ca, Nesnelerin \u0130nterneti\u2019ne y\u00f6nelik tehditlerin kullan\u0131c\u0131lar\u0131 deyim yerindeyse savunmas\u0131z yakalamak gibi k\u00f6t\u00fc bir huyu var. Bug\u00fcnk\u00fc g\u00fcndemimizde zarars\u0131z gibi g\u00f6r\u00fcnen ba\u015fka bir mekanizmay\u0131 ele alaca\u011f\u0131z.<\/p>\n<h2>\u0130\u00e7 mekanda ileri teknoloji<\/h2>\n<p>K\u0131sa s\u00fcre \u00f6nce, ABD\u2019de bir kumarhanenin lobisine \u201cak\u0131ll\u0131\u201d akvaryum kuruldu. Bal\u0131klar\u0131n beslenme program\u0131n\u0131n yan\u0131 s\u0131ra tuz ve s\u0131cakl\u0131k d\u00fczeyleri de otomatik d\u00fczenleniyordu. Su a\u015f\u0131r\u0131 \u0131s\u0131n\u0131r ya da a\u015f\u0131r\u0131 so\u011fursa termostat kullan\u0131c\u0131y\u0131 \u00e7evrimi\u00e7i uyarabiliyordu.<\/p>\n<p>Bu ayg\u0131t, belli ki yabanc\u0131lar\u0131n kurcalamamas\u0131 i\u00e7in, bir VPN ard\u0131na saklanm\u0131\u015ft\u0131. Ancak bu yeterli olmad\u0131 ve masum g\u00f6r\u00fcn\u00fc\u015fl\u00fc termostat yerel a\u011fdaki di\u011fer devrelere giden bir arka kap\u0131 olu\u015fturdu.<\/p>\n<h2>\u0130nternet casusu<\/h2>\n<p>Sonra anla\u015f\u0131ld\u0131 ki bu ikiy\u00fczl\u00fc akvaryum Norve\u00e7\u2019te bir yerlere 10 GB veri g\u00f6ndermi\u015fti. \u0130nternet g\u00fcvenlik personeli y\u00fczs\u00fcz korsanlar\u0131n hangi bilgileri ele ge\u00e7irdi\u011fini tespit etmeye \u00e7al\u0131\u015ft\u0131. Sorunun cevab\u0131 kumarhanedeki y\u00fcksek bahis\u00e7ilerin veri taban\u0131yd\u0131. A\u00e7\u0131k kaynaklar i\u00e7erikteki bilginin tam olarak ne oldu\u011funu ortaya koymasa da, ister sadece isimler, isterse, daha k\u00f6t\u00fcs\u00fc, irtibat bilgileri ve hatta kredi kart\u0131 numaralar\u0131 olsun, kurulu\u015fun itibar\u0131n\u0131n g\u00f6rd\u00fc\u011f\u00fc zarar\u0131n haddi hesab\u0131 yoktu. Kumarhanenin ad\u0131 a\u00e7\u0131klanmasa da olay bu s\u0131z\u0131nt\u0131n\u0131n ma\u011fdurlar\u0131na bildirilmek zorunda kal\u0131nd\u0131.<\/p>\n<h2>Erken uyar\u0131lan erken \u00f6nlem al\u0131r<\/h2>\n<p>\u0130smi verilmeyen bu kumarhane gibi, m\u00fc\u015fterilerini riske atmak istemeyen firmalar\u0131n bu kurallar\u0131 ak\u0131ldan \u00e7\u0131karmamas\u0131 gerekir:<\/p>\n<ul>\n<li>Sadece u\u00e7 ayg\u0131tlar\u0131n korunmas\u0131 yeterli de\u011fildir. Sistemlere izinsiz girenler sald\u0131r\u0131 zemini olarak herhangi bir ayg\u0131t\u0131 kullanabilir, bu nedenle sunuculara ve a\u011f ge\u00e7itlerine de g\u00fcvenlik \u00e7\u00f6z\u00fcmleri kurulmal\u0131d\u0131r. En iyisi, bilinmeyen portlar veya gizli protokoller arac\u0131l\u0131\u011f\u0131yla i\u00e7eri s\u0131zmaya \u00e7al\u0131\u015fan d\u0131\u015f d\u00fcnyayla temas\u0131n tamamen kesilmesidir.<\/li>\n<li>\u00d6nemli i\u015flerinde internete ihtiyac\u0131 olmayan hi\u00e7bir ekipmana \u0130nternet eri\u015fimi sa\u011flamay\u0131n.<\/li>\n<li>Nesnelerin \u0130nterneti ayg\u0131tlar\u0131n\u0131n tamam\u0131n\u0131 \u00e7ok dikkatli yap\u0131land\u0131r\u0131n; \u00e7\u00fcnk\u00fc hen\u00fcz bunlara g\u00fcvenlik \u00e7\u00f6z\u00fcmleri kurman\u0131n bir yolu yok.<\/li>\n<li>D\u00fczenli <a href=\"https:\/\/www.kaspersky.com.tr\/enterprise-security\/security-assessment\" target=\"_blank\" rel=\"noopener\">penetrasyon testleri<\/a> yap\u0131n. Bu kontroller yard\u0131m\u0131yla, b\u00fcy\u00fck sorunlara yol a\u00e7abilecek nispeten gizli bo\u015fluklar dahil, g\u00fcvenlik kusurlar\u0131n\u0131 d\u00fczeltilebilir bir a\u015famada tespit edebilirsiniz.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Konu Nesnelerin \u0130nterneti oldu\u011funda, g\u00fcvenlik h\u00e2l\u00e2 olmas\u0131 gereken noktada de\u011fil. Ba\u011flant\u0131l\u0131 ayg\u0131tlar\u0131n\u0131n da \u00e7o\u011fu pek bilinmiyor. Ayr\u0131ca, Nesnelerin \u0130nterneti&#8217;ne y\u00f6nelik tehditlerin kullan\u0131c\u0131lar\u0131 deyim yerindeyse savunmas\u0131z yakalamak gibi k\u00f6t\u00fc bir huyu var. Bug\u00fcnk\u00fc g\u00fcndemimizde zarars\u0131z gibi g\u00f6r\u00fcnen ba\u015fka bir mekanizmay\u0131 ele alaca\u011f\u0131z.<\/p>\n","protected":false},"author":2484,"featured_media":4890,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1194,1727],"tags":[744,628,629,1063,537],"class_list":{"0":"post-4889","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-business","8":"category-smb","9":"tag-guvenlik","10":"tag-internet-of-things","11":"tag-iot","12":"tag-nesnelerin-interneti","13":"tag-tehditler"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/leaking-fish-tank\/4889\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/leaking-fish-tank\/13233\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/leaking-fish-tank\/11039\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/leaking-fish-tank\/5721\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/leaking-fish-tank\/15310\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/leaking-fish-tank\/13579\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/leaking-fish-tank\/12927\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/leaking-fish-tank\/16008\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/leaking-fish-tank\/15657\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/leaking-fish-tank\/20308\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/leaking-fish-tank\/22248\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/leaking-fish-tank\/10389\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/leaking-fish-tank\/10280\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/leaking-fish-tank\/16572\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/leaking-fish-tank\/20297\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/leaking-fish-tank\/20205\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/leaking-fish-tank\/20194\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/iot\/","name":"IoT"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/4889","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2484"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=4889"}],"version-history":[{"count":4,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/4889\/revisions"}],"predecessor-version":[{"id":6944,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/4889\/revisions\/6944"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/4890"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=4889"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=4889"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=4889"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}