{"id":6308,"date":"2019-08-08T13:41:36","date_gmt":"2019-08-08T10:41:36","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=6308"},"modified":"2019-08-08T14:13:06","modified_gmt":"2019-08-08T11:13:06","slug":"start-immunizing","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/start-immunizing\/6308\/","title":{"rendered":"Siber ba\u011f\u0131\u015f\u0131kl\u0131\u011fa evet, korkulara hay\u0131r!"},"content":{"rendered":"<p>15 y\u0131l\u0131 a\u015fk\u0131n s\u00fcredir siber g\u00fcvenlik sekt\u00f6r\u00fcnde \u00e7al\u0131\u015f\u0131yorum. Bu s\u00fcre i\u00e7inde, bilgi g\u00fcvenli\u011fi alan\u0131nda \u00e7al\u0131\u015fan di\u011fer meslekta\u015flar\u0131m\u0131zla birlikte FUD (korku, belirsizlik, endi\u015fe) dalgas\u0131n\u0131n yay\u0131lmas\u0131na do\u011frudan \u015fahit olduk. Bu y\u00f6ntemin i\u015fe yarad\u0131\u011f\u0131n\u0131 kabul etmeliyim. N\u00f6ropazarlama bilimi bu konuda yan\u0131lmad\u0131. Korku, ger\u00e7ekten g\u00fcvenlik \u00fcr\u00fcnlerinin sat\u0131\u015f\u0131na yard\u0131mc\u0131 oldu. Ancak t\u00fcm g\u00fc\u00e7l\u00fc ila\u00e7lar gibi FUD kavram\u0131n\u0131n da bir yan etkisi var. Asl\u0131nda sadece bir de\u011fil, pek \u00e7ok yan etkisi var.<\/p>\n<p>Art\u0131k sekt\u00f6r olarak FUD kavram\u0131na ba\u011f\u0131ml\u0131 hale geldi\u011fimiz i\u00e7in ondan ka\u00e7am\u0131yoruz. Baz\u0131 m\u00fc\u015fterilerimiz anlat\u0131lanlar\u0131n yaln\u0131zca potansiyel bir s\u0131z\u0131nt\u0131 riski de\u011fil, ger\u00e7ek bir tehlike oldu\u011funa dair kan\u0131tlar isteyince FUD stratejisine y\u00f6neliyoruz. Ancak tehlikenin en b\u00fcy\u00fck kan\u0131t\u0131, ger\u00e7ekten k\u00f6t\u00fc bir \u015feyler olmas\u0131d\u0131r. Medyan\u0131n FUD stratejisine ba\u011f\u0131ml\u0131 olmas\u0131n\u0131n nedenlerinden biri de budur. Birileri ne kadar \u00e7ok para kaybederse haber de o kadar ilgi \u00e7ekici olur.<\/p>\n<p>Bu noktada da devreye d\u00fczenleyici kurumlar girer ve her zamanki a\u015f\u0131r\u0131 tepki g\u00f6sterme ve s\u0131k\u0131 uyum d\u00fczenlemeleri ve cezalar\u0131 uygulama e\u011filimlerini g\u00f6sterirler. Bu d\u00f6ng\u00fc g\u00fcvenlik ara\u015ft\u0131rmac\u0131lar\u0131n\u0131, \u00fcr\u00fcn geli\u015ftiricilerini, pazarlama uzmanlar\u0131n\u0131, medyay\u0131 ve d\u00fczenleyici kurumlar\u0131 oyun teorisinde tutsak ikilemi olarak adland\u0131r\u0131lan stratejik bir tuza\u011fa d\u00fc\u015f\u00fcr\u00fcr: Bu ikilemde t\u00fcm oyuncular en iyi stratejileri de\u011fil, ortalama fayda sa\u011flayan stratejiyi uygulamak zorundad\u0131r \u00e7\u00fcnk\u00fc aksini yapmalar\u0131 kaybetmelerine neden olur. Bilgi g\u00fcvenli\u011fi sekt\u00f6r\u00fc a\u00e7\u0131s\u0131ndan ortalama fayda sa\u011flayan stratejiyi kullanmak demek FUD korkular\u0131n\u0131 beslemek anlam\u0131na gelir.<\/p>\n<p>Bu tuzaktan kurtulmak i\u00e7in \u015funu anlamam\u0131z gerekir: Gelece\u011fi korku \u00fczerine in\u015fa edemeyiz.<\/p>\n<p>Gelecek kavram\u0131yla uzak bir gelecekten de\u011fil, zaten i\u00e7inde oldu\u011fumuz zaman diliminden bahsediyorum. Robotlar, kamyon s\u00fcrmeye ve Mars\u2019ta dola\u015fmaya ba\u015flad\u0131. Besteler yap\u0131yor ve yeni yemek tarifleri haz\u0131rl\u0131yorlar. Bu gelecek, siber g\u00fcvenlik de dahil bir\u00e7ok a\u00e7\u0131dan m\u00fckemmelli\u011fe \u00e7ok uzak bir noktada. Ancak bizim amac\u0131m\u0131z siber g\u00fcvenli\u011fe engel olmak de\u011fil, onu g\u00fc\u00e7lendirmek.<\/p>\n<p>Yak\u0131n zaman \u00f6nce Eugene Kaspersky, gelecekle ilgili \u015fu \u00f6ng\u00f6r\u00fclerde bulundu: \u201c<a href=\"https:\/\/www.kaspersky.com.tr\/blog\/kaspersky-rebranding\/6004\/\" target=\"_blank\" rel=\"noopener\">Yak\u0131nda siber g\u00fcvenlik kavram\u0131n\u0131n tamamen ortadan kalkarak yerini siber ba\u011f\u0131\u015f\u0131kl\u0131k kavram\u0131na b\u0131rakaca\u011f\u0131na inan\u0131yorum.<\/a>\u201d Bu c\u00fcmle ilk bak\u0131\u015fta biraz tuhaf gelebilir ama \u00e7ok daha derin ve \u00f6nemli bir anlam ta\u015f\u0131yor. \u00d6nce siber ba\u011f\u0131\u015f\u0131kl\u0131k kavram\u0131n\u0131 daha ayr\u0131nt\u0131l\u0131 olarak a\u00e7\u0131klayal\u0131m:<\/p>\n<p><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2019\/08\/08141254\/start-immunizing-moiseev.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/91\/2019\/08\/08141254\/start-immunizing-moiseev.jpg\" alt=\"\" width=\"1499\" height=\"937\" class=\"aligncenter size-full wp-image-6311\"><\/a><\/p>\n<p>Siber ba\u011f\u0131\u015f\u0131kl\u0131k, daha g\u00fcvenli gelecek vizyonumuzu a\u00e7\u0131klamak i\u00e7in m\u00fckemmel bir terim. Ger\u00e7ek hayatta organizmalar\u0131n ba\u011f\u0131\u015f\u0131kl\u0131k sistemi hi\u00e7bir zaman m\u00fckemmel de\u011fildir. Vir\u00fcsler ve di\u011fer k\u00f6t\u00fc huylu mikrobiyolojik varl\u0131klar bu sistemi kand\u0131rman\u0131n, hatta do\u011frudan sistemin kendisine sald\u0131rman\u0131n yollar\u0131n\u0131 bulur. Ancak t\u00fcm ba\u011f\u0131\u015f\u0131kl\u0131k sistemlerinin \u00e7ok \u00f6nemli bir ortak \u00f6zelli\u011fi vard\u0131r: Bu sistemler \u00f6\u011frenir ve kendilerini uyarlar. A\u015f\u0131lar sayesinde olas\u0131 tehlikelere kar\u015f\u0131 \u201ce\u011fitilebilirler\u201d. Tehlikeli d\u00f6nemlerde ise haz\u0131r antikorlarla ba\u011f\u0131\u015f\u0131kl\u0131k sistemlerini destekleyebiliriz.<\/p>\n<p>Olaya bir de siber g\u00fcvenlik a\u00e7\u0131s\u0131ndan bakal\u0131m: Ge\u00e7mi\u015fte \u00e7o\u011funlukla \u201cantikorlarla destekleme\u201d stratejisini kullan\u0131yorduk. M\u00fc\u015fterilerimizin BT sistemleri vir\u00fcslere yenik d\u00fc\u015ft\u00fc\u011f\u00fcnde \u00e7\u00f6z\u00fcmlerimizle onlara yard\u0131m etmeye haz\u0131r olmak zorundayd\u0131k. Ancak g\u00fcvenlik sat\u0131c\u0131lar\u0131n\u0131n can yak\u0131c\u0131 felaketler kar\u015f\u0131s\u0131nda haz\u0131r \u00e7\u00f6z\u00fcmler sunmas\u0131 FUD ba\u011f\u0131ml\u0131l\u0131\u011f\u0131n\u0131n da ba\u015flang\u0131c\u0131 oldu. Bu \u201cs\u00fcper g\u00fc\u00e7\u201d hissi, bilgi g\u00fcvenli\u011fi sat\u0131c\u0131lar\u0131n\u0131 ba\u011f\u0131ml\u0131 hale getirdi. Genellikle m\u00fc\u015fterilerimize \u201cEvet, \u015fimdi g\u00fc\u00e7l\u00fc antibiyotikler kullanman\u0131n zaman\u0131 geldi \u00e7\u00fcnk\u00fc sorun ger\u00e7ekten \u00e7ok ciddi.\u201d alg\u0131s\u0131yla yakla\u015ft\u0131k. Ancak bu g\u00fc\u00e7l\u00fc antibiyotiklerin i\u015fe yaramas\u0131 i\u00e7in vir\u00fcs\u00fcn \u00e7oktan i\u00e7eriye s\u0131zm\u0131\u015f olmas\u0131 gerekiyor. Bunun da ideal bir senaryodan \u00e7ok uzak oldu\u011funu hepimiz biliyoruz. Siber g\u00fcvenlik ve ba\u011f\u0131\u015f\u0131kl\u0131k sistemi benzetmesinden yola \u00e7\u0131karak sistemin enfeksiyon ba\u015flamadan \u00f6nce vir\u00fcsleri durdurmas\u0131n\u0131n \u00e7ok daha iyi oldu\u011funu s\u00f6yleyebiliriz.<\/p>\n<p>G\u00fcn\u00fcm\u00fczde son derece heterojen bir hal alan BT sistemlerini, cihazlar\u0131 kullanan ve bunlarla etkile\u015fim kuran insan ba\u011flam\u0131 d\u0131\u015f\u0131nda de\u011ferlendirmek m\u00fcmk\u00fcn de\u011fil. \u201cBa\u011f\u0131\u015f\u0131kl\u0131k sistemini e\u011fitme\u201d talebi o kadar artt\u0131 ki bu hizmeti sa\u011flaman\u0131n ge\u00e7mi\u015fte birincil konumda olan \u00fcr\u00fcnlerden bile daha \u00f6ncelikle hale geldi\u011fini g\u00f6r\u00fcyoruz. (G\u00fcn\u00fcm\u00fczde \u201c\u00fcr\u00fcn\u201d, kullan\u0131laca\u011f\u0131 BT sisteminin \u00f6zelliklerine g\u00f6re uyarlanan \u00f6zelle\u015ftirilmi\u015f bir \u00e7\u00f6z\u00fcm haline geldi.)<\/p>\n<p>Bu vizyon anlay\u0131\u015f\u0131, tek seferde benimsenmedi. T\u0131pk\u0131 a\u015f\u0131lar da oldu\u011fu gibi bu anlay\u0131\u015f da tek seferlik bir yakla\u015f\u0131m\u0131 de\u011fil, amaca y\u00f6nelik bir dizi a\u015f\u0131lama denemesini i\u00e7eriyor. Bu denemelerle daha g\u00fcvenli bir gelecek i\u00e7in daha g\u00fc\u00e7l\u00fc bir siber ba\u011f\u0131\u015f\u0131kl\u0131k sistemi olu\u015fturmay\u0131 ama\u00e7l\u0131yoruz.<\/p>\n<p>Her \u015feyden \u00f6nce, daha g\u00fcvenli bir gelecek g\u00fcvenli bir temel \u00fczerine in\u015fa edebilir. Bunun i\u00e7in sistemler tasarlan\u0131rken<a href=\"https:\/\/www.kaspersky.com.tr\/blog\/what-is-secure-os\/4508\/\" target=\"_blank\" rel=\"noopener\"> g\u00fcvenli\u011fin ilk andan itibaren g\u00f6z \u00f6n\u00fcnde bulundurulmas\u0131 gerekir<\/a>. Telekom\u00fcnikasyon ve otomotiv end\u00fcstrilerindeki uygulamalar, bu vizyoner yakla\u015f\u0131m\u0131m\u0131z\u0131 test etmeye ba\u015flad\u0131. \u00d6zellikle emniyet konusunda \u00e7ok hassas olan araba \u00fcreticileri i\u00e7in misyon bildirimiz olan \u201cdaha g\u00fcvenli bir d\u00fcnya\u201d ifadesi b\u00fcy\u00fck \u00f6nem ta\u015f\u0131yor. Otomotiv d\u00fcnyas\u0131nda insanlar\u0131n emniyette kalmas\u0131 i\u00e7in g\u00fcvenli\u011fe dikkat edilmesi gerekir.<\/p>\n<p>Biyolojik a\u015f\u0131larda oldu\u011fu gibi siber ba\u011f\u0131\u015f\u0131kl\u0131k konseptine de \u015f\u00fcpheyle yakla\u015f\u0131labilece\u011fini \u00f6ng\u00f6r\u00fcyoruz. Bu konsepti duyanlardan ilk olarak \u015fu tepkiyi bekliyorum: \u201cBu a\u015f\u0131ya ve sat\u0131c\u0131s\u0131na g\u00fcvenebilir miyiz?\u201d \u0130nsanlar\u0131n siber g\u00fcvenlik kavram\u0131na g\u00fcvenmesi bizim i\u00e7in b\u00fcy\u00fck \u00f6nem ta\u015f\u0131yor ve bunun i\u00e7in yaln\u0131zca bizim s\u00f6z\u00fcm\u00fcz\u00fc esas alman\u0131z\u0131n yeterli olmayaca\u011f\u0131n\u0131n fark\u0131nday\u0131z. Bir siber g\u00fcvenlik firmas\u0131n\u0131n m\u00fc\u015fterileri yaz\u0131l\u0131m\u0131n g\u00fcvenli\u011fini ve sa\u011flaml\u0131\u011f\u0131n\u0131 g\u00f6rmek istedi\u011finde kaynak kodlar\u0131 inceleme hakk\u0131na sahip olmal\u0131d\u0131r. <a href=\"https:\/\/www.kaspersky.com\/transparency-center\" target=\"_blank\" rel=\"noopener nofollow\">M\u00fc\u015fterilerimizin kaynak kodlar\u0131m\u0131za eri\u015fim sa\u011flamas\u0131na izin veriyoruz<\/a>. Bunun i\u00e7in m\u00fc\u015fterilerimizin yaln\u0131zca bir bilgisayara ve kodu dikkatli bir \u015fekilde inceleyecek insanlara ihtiyac\u0131 var. Ancak g\u00f6zlemcilerin koda m\u00fcdahale edememesi i\u00e7in bu inceleme s\u0131ras\u0131nda temiz bir bilgisayar kullan\u0131lmas\u0131 gerekiyor. Nas\u0131l ki te\u015fhis i\u00e7in farkl\u0131 doktorlara dan\u0131\u015f\u0131yorsak, g\u00fcvenli\u011fimiz i\u00e7in de sayg\u0131n bir \u00fc\u00e7\u00fcnc\u00fc taraftan kodu incelemesini talep edebilmeliyiz. BT \u00e7\u00f6z\u00fcmleri i\u00e7in d\u0131\u015f g\u00f6zlemci olarak Big Four denetim firmalar\u0131n\u0131n temsilcilerine ba\u015fvurulabilir. G\u00f6zlemciler, yaz\u0131l\u0131mla ilgili ayr\u0131nt\u0131lar\u0131n i\u015fletmeniz i\u00e7in ne anlama geldi\u011fini a\u00e7\u0131klayacakt\u0131r.<\/p>\n<p>Bu vizyonun bir di\u011fer \u00f6nemli unsuru da ba\u011f\u0131\u015f\u0131kl\u0131k sisteminin sald\u0131r\u0131lara dayanma becerisidir. Siber g\u00fcvenlik yaz\u0131l\u0131mlar\u0131 ne kadar geli\u015fmi\u015f olsalar da birer yaz\u0131l\u0131md\u0131r ve bu nedenle hatalar bar\u0131nd\u0131rabilirler. Bu hatalar\u0131 \u00f6\u011frenmenin en iyi yolu, sistemi beyaz \u015fapkal\u0131 hacker\u2019larla kar\u015f\u0131 kar\u015f\u0131ya b\u0131rakmak ve bu hacker\u2019lar\u0131n hatalar\u0131 bulup sat\u0131c\u0131lara bildirmesini sa\u011flamakt\u0131r. Yaz\u0131l\u0131mlarda hata bulanlar\u0131 \u00f6d\u00fcllendirme fikri, ilk kez 1983 y\u0131l\u0131nda ortaya at\u0131ld\u0131. Bu harika fikir, bulunan hatalar\u0131 inceleyen veya bunlar\u0131 siber su\u00e7lulara satan siyah \u015fapkal\u0131 hacker\u2019lara sunulan mali te\u015fvikleri \u00f6nemli \u00f6l\u00e7\u00fcde azaltmaya da yarad\u0131. Ancak art\u0131k beyaz \u015fapkal\u0131 hacker\u2019lar ara\u015ft\u0131rd\u0131klar\u0131 \u015firketin kendilerine s\u0131rt \u00e7evirip dava a\u00e7mayaca\u011f\u0131na dair bir g\u00fcvence talep ediyor.<\/p>\n<p>Talep varsa arz da vard\u0131r. Yak\u0131n zaman \u00f6nce ara\u015ft\u0131rmac\u0131lar ve \u015firketler aras\u0131nda yap\u0131labilecek baz\u0131 s\u00f6zle\u015fme \u00f6nerileri sunuldu. Bu \u00f6nerilere g\u00f6re ara\u015ft\u0131rmac\u0131lar, kurallar\u0131 takip etti\u011fi s\u00fcrece hi\u00e7bir su\u00e7la itham edilme korkusu ya\u015famadan g\u00fcvenli bir \u015fekilde \u015firketlerin hatalar\u0131n\u0131 bulmaya \u00e7al\u0131\u015fabilir. Bu y\u00f6nde at\u0131lacak ad\u0131mlar\u0131n, bizi daha g\u00fcvenli ve korkusuz bir gelece\u011fe ta\u015f\u0131yaca\u011f\u0131na inan\u0131yorum. Ancak <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/bug-bounty-boost-2018\/4772\/\" target=\"_blank\" rel=\"noopener\">bu yolculuk<\/a>, biraz uzun s\u00fcrece\u011fe benziyor.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Daha g\u00fcvenli bir gelecek i\u00e7in korkular\u0131m\u0131zdan kurtulup ba\u011f\u0131\u015f\u0131kl\u0131k kazanmaya ba\u015flamal\u0131y\u0131z.<\/p>\n","protected":false},"author":2454,"featured_media":6309,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1726,1194],"tags":[943,550],"class_list":{"0":"post-6308","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-enterprise","8":"category-business","9":"tag-gelecek","10":"tag-siber-guvenlik"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/start-immunizing\/6308\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/start-immunizing\/16306\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/start-immunizing\/13811\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/start-immunizing\/18314\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/start-immunizing\/16390\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/start-immunizing\/15086\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/start-immunizing\/19022\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/start-immunizing\/17735\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/start-immunizing\/23302\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/start-immunizing\/27813\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/start-immunizing\/12079\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/start-immunizing\/12413\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/start-immunizing\/19917\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/start-immunizing\/24111\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/start-immunizing\/19690\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/start-immunizing\/23119\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/start-immunizing\/23059\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/siber-guvenlik\/","name":"siber g\u00fcvenlik"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/6308","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2454"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=6308"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/6308\/revisions"}],"predecessor-version":[{"id":6649,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/6308\/revisions\/6649"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/6309"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=6308"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=6308"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=6308"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}