{"id":6530,"date":"2019-10-08T21:42:46","date_gmt":"2019-10-08T18:42:46","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=6530"},"modified":"2019-11-15T14:23:19","modified_gmt":"2019-11-15T11:23:19","slug":"machine-learning-fake-voice","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/machine-learning-fake-voice\/6530\/","title":{"rendered":"Makine \u00f6\u011frenimi destekli doland\u0131r\u0131c\u0131l\u0131klar"},"content":{"rendered":"<p>Yeni teknolojiler hi\u00e7 ku\u015fkusuz d\u00fcnyay\u0131 de\u011fi\u015ftiriyor. Fakat insan do\u011fas\u0131 ayn\u0131 kal\u0131yor. Bunun sonucunda k\u00f6t\u00fcl\u00fck dehalar\u0131, insan beynindeki zay\u0131f noktalar\u0131 hedef alacak yeni teknolojiler tasarl\u0131yorlar. Bunun en g\u00fc\u00e7l\u00fc \u00f6rneklerinden biri, <a href=\"https:\/\/www.wsj.com\/articles\/fraudsters-use-ai-to-mimic-ceos-voice-in-unusual-cybercrime-case-11567157402\" target=\"_blank\" rel=\"noopener nofollow\">doland\u0131r\u0131c\u0131lar\u0131n uluslararas\u0131 bir CEO\u2019nun sesini taklit ederek<\/a> i\u015ftiraklerden birinin y\u00f6neticisini karanl\u0131k bir hesaba para g\u00f6ndermeye ikna ettikleri olay.<\/p>\n<h2>Ne oldu?<\/h2>\n<p>Sald\u0131r\u0131n\u0131n ayr\u0131nt\u0131lar\u0131 bilinmese de, Euler Hermes Group SA sigorta firmas\u0131n\u0131 al\u0131nt\u0131layan Wall Street Journal olay\u0131 \u015f\u00f6yle anlat\u0131yor:<\/p>\n<ol>\n<li>\u0130ngiltere merkezli bir enerji firmas\u0131n\u0131n CEO\u2019su, telefonda \u015firketlerinin Alman ana kurulu\u015funun ba\u015fkan\u0131 olan patronuyla g\u00f6r\u00fc\u015ft\u00fc\u011f\u00fcn\u00fc zannediyor. Patronu, bir saat i\u00e7erisinde Macar bir tedarik\u00e7iye 220.000 EUR g\u00f6ndermesini istiyor (sonradan b\u00f6yle bir tedarik\u00e7i olmad\u0131\u011f\u0131 ortaya \u00e7\u0131k\u0131yor).<\/li>\n<li>\u0130ngiliz y\u00f6netici istenen miktar\u0131 g\u00f6nderiyor.<\/li>\n<li>Sald\u0131rganlar ana kurulu\u015fun \u0130ngiliz firman\u0131n masraf\u0131n\u0131 kar\u015f\u0131lamak i\u00e7in para g\u00f6nderdi\u011fini s\u00f6ylemek i\u00e7in bir kez daha ar\u0131yorlar.<\/li>\n<li>Ard\u0131ndan, ayn\u0131 g\u00fcn i\u00e7inde \u00fc\u00e7\u00fcnc\u00fc kez, tekrar CEO\u2019yu taklit ederek ar\u0131yor ve ikinci bir \u00f6deme daha istiyorlar.<\/li>\n<li>Y\u00f6netici, masraflar\u0131 kar\u015f\u0131lama \u00f6demesi hen\u00fcz hesaba yatmad\u0131\u011f\u0131 ve \u00fc\u00e7\u00fcnc\u00fc arama bir Alman numaras\u0131ndan de\u011fil, Avusturyal\u0131 bir numaradan geldi\u011fi i\u00e7in \u015f\u00fcpheleniyor. \u0130kinci \u00f6demeyi yapm\u0131yor.<\/li>\n<\/ol>\n<h2>Bu doland\u0131r\u0131c\u0131l\u0131k nas\u0131l ger\u00e7ekle\u015fti?<\/h2>\n<p>Sigortac\u0131lar iki olas\u0131l\u0131k \u00fczerinde duruyor. Sald\u0131rganlar ya CEO\u2019ya ait say\u0131s\u0131z ses kayd\u0131n\u0131 elden ge\u00e7irerek sesli mesajlar\u0131 manuel olarak bir araya getirdiler, ya da (daha y\u00fcksek ihtimalle) kay\u0131tlar\u0131 bir makine \u00f6\u011frenimi algoritmas\u0131na i\u015flettiler. \u0130lk y\u00f6ntem hem \u00e7ok zaman al\u0131rd\u0131 hem de g\u00fcvenilir olmazd\u0131: Ayr\u0131 ayr\u0131 kelimelerden mant\u0131kl\u0131 bir c\u00fcmle olu\u015fturmak ve bunu kula\u011f\u0131 t\u0131rmalamayacak \u015fekilde yapmak \u00e7ok zordu. \u00dcstelik \u0130ngiliz kurbana g\u00f6re konu\u015fma tamamen normaldi; tan\u0131d\u0131k, \u00f6zel ses tonu ve hafif Alman aksan\u0131 bile yerindeydi. Dolay\u0131s\u0131yla ba\u015f \u015f\u00fcpheli olarak geriye Yapay Zeka kal\u0131yordu. \u00d6te yandan, sald\u0131r\u0131n\u0131n ba\u015far\u0131s\u0131, yeni teknolojilerin kullan\u0131m\u0131ndan ziyade bili\u015fsel \u00e7arp\u0131tmaya, bu vaka \u00f6zelinde ise otoriteye boyun e\u011fmeye dayan\u0131yordu.<\/p>\n<h2>Psikolojik otopsi<\/h2>\n<p>Sosyal psikologlar, zeki ve deneyimli insanlar\u0131n bile otoriteye sorgulamadan uyma e\u011filiminde oldu\u011funu g\u00f6steren pek \u00e7ok deney ger\u00e7ekle\u015ftirdi. \u00dcstelik bu e\u011filim, otoritenin talebi ki\u015fisel inan\u00e7lara, sa\u011fduyuya ve g\u00fcvenlik kayg\u0131lar\u0131na ayk\u0131r\u0131 oldu\u011funda bile g\u00f6zlemlenebiliyordu.<\/p>\n<p>\u015eeytan Etkisi: \u0130yi \u0130nsanlar\u0131n Nas\u0131l K\u00f6t\u00fcl\u00fck Yapt\u0131\u011f\u0131n\u0131 Anlamak kitab\u0131nda Philip Zimbardo b\u00f6yle bir deneyden bahsediyor. Deneyde bir doktor, hem\u015fireleri arayarak bir hastaya izin verilen dozun iki kat\u0131 miktarda ila\u00e7 enjekte edilmesini istiyor. 22 hem\u015fireden 21\u2019i, \u015f\u0131r\u0131ngay\u0131 s\u00f6ylenen dozda ila\u00e7la dolduruyor. Hatta ankete kat\u0131lan hem\u015firelerin yar\u0131s\u0131, hastaya zarar verebilece\u011fini d\u00fc\u015f\u00fcnd\u00fckleri doktor talimatlar\u0131n\u0131 bile yerine getirdiklerini s\u00f6yl\u00fcyor. S\u00f6z dinleyen hem\u015fireler, hastaya re\u00e7ete yazmak i\u00e7in yasal otoriteye sahip olan doktorlardan daha az sorumlulu\u011fa sahip olduklar\u0131na inan\u0131yorlar.<\/p>\n<p>Psikolog Stanley Milgram da otoriteye sorgulamadan uymay\u0131 benzer bir \u015fekilde \u00f6znellik teorisiyle a\u00e7\u0131kl\u0131yor. Bu teoriye g\u00f6re ki\u015filer kendilerini ba\u015fkalar\u0131n\u0131n iradesini yerine getiren ara\u00e7lar olarak alg\u0131lad\u0131klar\u0131nda eylemlerinden sorumluluk duymuyorlar.<\/p>\n<h2>Ne yapmal\u0131s\u0131n\u0131z?<\/h2>\n<p>Telefonda kiminle konu\u015ftu\u011funuzdan asla %100 emin olamazs\u0131n\u0131z. Hele ki bu ki\u015fi, halka mal olmu\u015f ve ses kay\u0131tlar\u0131 her yerde bulunabilen (r\u00f6portajlar, konu\u015fmalar) bir ki\u015fiyse. G\u00fcn\u00fcm\u00fczde b\u00f6yle olaylara nadiren rastlan\u0131yor, fakat teknoloji geli\u015ftik\u00e7e bu durum daha s\u0131k g\u00f6r\u00fclecek.<\/p>\n<p>Talimatlar\u0131 sorgulamadan yerine getirerek siber su\u00e7lular\u0131n istedi\u011fini yap\u0131yor olabilirsiniz. Elbette patronun dedi\u011fini yapmak normaldir; fakat y\u00f6neticilerden gelen tuhaf ya da mant\u0131ks\u0131z istekleri sorgulamak da kritik \u00f6nem ta\u015f\u0131yor.<\/p>\n<p>Yaln\u0131zca \u00e7al\u0131\u015fanlar\u0131n talimatlar\u0131 k\u00f6r\u00fc k\u00f6r\u00fcne yerine getirmemesini te\u015fvik etmeyi \u00f6nerebiliriz. Sebebini a\u00e7\u0131klamadan talimat vermekten ka\u00e7\u0131n\u0131n. B\u00f6ylece, \u00e7al\u0131\u015fanlar\u0131n belirli bir sebep g\u00f6sterilmedi\u011finde s\u0131ra d\u0131\u015f\u0131 bir talimat\u0131 sorgulama olas\u0131l\u0131klar\u0131 artar.<\/p>\n<h2>Teknik a\u00e7\u0131dan ise \u015funlar\u0131 \u00f6neriyoruz:<\/h2>\n<ul>\n<li>\u00dcst d\u00fczey \u00e7al\u0131\u015fanlar\u0131n bile g\u00f6zetimsiz \u015firket d\u0131\u015f\u0131na para g\u00f6nderemeyece\u011fi net bir fon transeri prosed\u00fcr\u00fc olu\u015fturun. B\u00fcy\u00fck mebla\u011flar\u0131n transferinin birka\u00e7 y\u00f6netici taraf\u0131ndan onayland\u0131\u011f\u0131nda ger\u00e7ekle\u015ftirilebilmesini sa\u011flay\u0131n.<\/li>\n<li>\u00c7al\u0131\u015fanlar\u0131 siber g\u00fcvenlik esaslar\u0131 konusunda e\u011fitin ve gelen taleplere sa\u011fl\u0131kl\u0131 bir \u015f\u00fcphecilikle yakla\u015fmay\u0131 \u00f6\u011fretin. <a href=\"https:\/\/www.kaspersky.com.tr\/enterprise-security\/security-awareness\" target=\"_blank\" rel=\"noopener\">Tehdit fark\u0131ndal\u0131\u011f\u0131 program\u0131m\u0131z<\/a> size bu konuda yard\u0131mc\u0131 olacakt\u0131r.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Makine \u00f6\u011frenimi algoritmalar\u0131yla g\u00fc\u00e7lendirilen sosyal m\u00fchendislik, \u00fcst d\u00fczey y\u00f6neticileri bile kand\u0131rabiliyor.<\/p>\n","protected":false},"author":2499,"featured_media":6531,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1726,1194],"tags":[612,1610,1660],"class_list":{"0":"post-6530","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-enterprise","8":"category-business","9":"tag-dolandiricilik","10":"tag-makine-ogrenimi","11":"tag-sosyal-muhendislik"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/machine-learning-fake-voice\/6530\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/machine-learning-fake-voice\/16753\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/machine-learning-fake-voice\/14142\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/machine-learning-fake-voice\/18740\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/machine-learning-fake-voice\/16787\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/machine-learning-fake-voice\/15526\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/machine-learning-fake-voice\/19418\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/machine-learning-fake-voice\/23746\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/machine-learning-fake-voice\/28870\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/machine-learning-fake-voice\/12385\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/machine-learning-fake-voice\/12460\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/machine-learning-fake-voice\/11290\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/machine-learning-fake-voice\/21595\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/machine-learning-fake-voice\/24324\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/machine-learning-fake-voice\/24697\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/machine-learning-fake-voice\/19207\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/machine-learning-fake-voice\/23522\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/machine-learning-fake-voice\/23372\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/sosyal-muhendislik\/","name":"sosyal m\u00fchendislik"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/6530","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2499"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=6530"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/6530\/revisions"}],"predecessor-version":[{"id":6716,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/6530\/revisions\/6716"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/6531"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=6530"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=6530"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=6530"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}