{"id":8198,"date":"2020-05-08T14:15:26","date_gmt":"2020-05-08T11:15:26","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=8198"},"modified":"2020-05-08T14:15:26","modified_gmt":"2020-05-08T11:15:26","slug":"atm-in-the-woods","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/atm-in-the-woods\/8198\/","title":{"rendered":"Orman\u0131n i\u00e7indeki ATM"},"content":{"rendered":"<p>B\u00fcy\u00fck bir \u015fehrin merkezinde ATM\u2019lerin veya \u00f6deme terminallerinin g\u00fcvenli\u011fini sa\u011flamak zor de\u011fildir. \u0130nternet eri\u015fimi daima mevcut oldu\u011fundan, ihtiya\u00e7 halinde uzman ekipler m\u00fcdahale etmeye haz\u0131rd\u0131r. Ancak, cihaz en yak\u0131n BT uzman\u0131na y\u00fcz kilometre uzakta ve ba\u011flant\u0131n\u0131n d\u00fczensiz oldu\u011fu bir yerdeyse bu durum de\u011fi\u015fir.<\/p>\n<p>Uzak b\u00f6lgelerdeki insanlar ATM\u2019lerin \u00e7al\u0131\u015f\u0131r durumda olmas\u0131na bel ba\u011flar; bu tart\u0131\u015f\u0131lmaz bir sosyal faydad\u0131r. Baz\u0131lar\u0131 i\u00e7in nakit para \u00e7ekmenin veya herhangi bir hizmet i\u00e7in \u00f6deme yapman\u0131n tek yolu budur. Sonu\u00e7 olarak, bu t\u00fcr cihazlar\u0131n g\u00fcvenli olmas\u0131 gerekir.<\/p>\n<h2>G\u00fcvenlik sorunlar\u0131<\/h2>\n<p>Terminallerin ve ATM\u2019lerin i\u015flerli\u011fi, en son tehditlerle ba\u015fa \u00e7\u0131kabilen bir g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fcne, di\u011fer bir deyi\u015fle d\u00fczenli olarak g\u00fcncellenen bir g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fcne sahip olmalar\u0131na ba\u011fl\u0131d\u0131r. Bu t\u00fcr cihazlar\u0131 korurken hangi sorunlar\u0131n ortaya \u00e7\u0131kabilece\u011fine ve g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fcn\u00fcn bunlarla ba\u015fa \u00e7\u0131kmak i\u00e7in hangi \u00f6zelliklere sahip olmas\u0131 gerekti\u011fine bir g\u00f6z atal\u0131m.<\/p>\n<p><strong>Eri\u015fim zorlu\u011fu.<\/strong> K\u0131rsal alanlardaki ATM\u2019ler, \u201cuzaktan eri\u015fim\u201d kavram\u0131na yeni bir anlam katar. Acil durumlarda polisin o noktaya gitmesi bir saat s\u00fcr\u00fcyorsa, bir BT \u00e7al\u0131\u015fan\u0131n\u0131n olay yerine daha h\u0131zl\u0131 ula\u015fmas\u0131 olas\u0131 de\u011fildir. Bu nedenle, uygun \u00e7\u00f6z\u00fcm uzaktan y\u00f6netimi ve g\u00fcncellemeyi desteklemelidir.<\/p>\n<p><strong>Zay\u0131f ileti\u015fim.<\/strong> Geli\u015fmi\u015f \u00fclkeler bile kablolu \u0130nternet bulunmayan veya mobil a\u011f kapsama alan\u0131n\u0131n stabil olmad\u0131\u011f\u0131 yerle\u015fim yerlerine sahiptir. Baz\u0131 yerlerde ATM\u2019nin tek ileti\u015fim kanal\u0131, maksimum h\u0131zdayken bile i\u015fini yapmakta zorlanan bir 3G modemdir. Yine de i\u015flem verilerinin ve bankac\u0131l\u0131k yaz\u0131l\u0131m\u0131 g\u00fcncellemelerinin aktar\u0131mlar\u0131n\u0131n g\u00fcvenilir ve g\u00fcvenli olmas\u0131 gerekir; bu nedenle \u00e7\u00f6z\u00fcm, sistemi trafikle bo\u011fmadan, zay\u0131f bir kanal \u00fczerinden bile g\u00fcncellemeler sunabilmelidir.<\/p>\n<p><strong>B\u00fct\u00e7e dostu ekipman.<\/strong> K\u0131rsal bir k\u00f6ye, s\u0131n\u0131f\u0131n\u0131n en iyisi bir ATM modeli sa\u011flama \u015fans\u0131 d\u00fc\u015f\u00fckt\u00fcr. Sonu\u00e7ta cihaz\u0131 koruyacak bir g\u00fcvenlik g\u00f6revlisinin bulunmad\u0131\u011f\u0131 bu yerlerde baz\u0131 soyguncular, i\u00e7erideki paray\u0131 \u00e7almak i\u00e7in ATM\u2019yi havaya u\u00e7urmaya bile \u00e7al\u0131\u015fabilir. Bu nedenle, daha k\u00fc\u00e7\u00fck yerle\u015fimlerde Ta\u015f Devri\u2019nden kalma i\u015flemci ve i\u015fletim sistemi bar\u0131nd\u0131ran eski bir makine olma olas\u0131l\u0131\u011f\u0131 daha y\u00fcksektir. Bu nedenle g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fcn\u00fcn eski donan\u0131mlarla \u00e7al\u0131\u015fabilmesi ve art\u0131k g\u00fcncelleme almayan i\u015fletim sistemini koruyabilmesi gerekir.<\/p>\n<p><strong>G\u00f6zlerden uzak.<\/strong> B\u00fcy\u00fck \u015fehirlerde, \u00f6deme terminalleri veya ATM\u2019ler \u00e7o\u011fu zaman herkesin g\u00f6rece\u011fi bir yere kurulur. Bu bilin\u00e7li bir tercihtir: Sald\u0131rganlar harici bir cihaz\u0131 ATM\u2019ye ba\u011flamak i\u00e7in gizlili\u011fe ihtiya\u00e7 duyarlar. Siber su\u00e7lular\u0131n mutlaka nakit para \u00e7\u0131k\u0131\u015flar\u0131na eri\u015fmeleri gerekmez; kart ayr\u0131nt\u0131lar\u0131n\u0131 \u00e7almaya veya sistemi de\u011fi\u015ftirmeye \u00e7al\u0131\u015farak transferlerin ama\u00e7lanan hesap sahibinden farkl\u0131 bir hesaba ge\u00e7mesini de sa\u011flayabilirler. Bu nedenle, bir ATM\u2019nin g\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc, en son k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar\u0131 alg\u0131lamaktan daha fazlas\u0131n\u0131 yapmal\u0131d\u0131r: Kritik dosya ve kay\u0131tlardaki de\u011fi\u015fiklikleri izleyebilmeli, harici ayg\u0131t ba\u011flant\u0131lar\u0131n\u0131 ve \u00fc\u00e7\u00fcnc\u00fc taraf programlar\u0131n y\u00fcklenmesini engelleyebilmelidir.<\/p>\n<h2>G\u00fcvenlik \u00e7\u00f6z\u00fcm\u00fc<\/h2>\n<p>Muhtemelen tahmin etti\u011finiz gibi yukar\u0131dakiler asl\u0131nda Kaspersky Embedded Systems Security\u2019nin en son s\u00fcr\u00fcm\u00fcn\u00fc tarif ediyor. Uzmanlar\u0131m\u0131z veri aktar\u0131m s\u00fcrecini optimize ederek zay\u0131f bir ileti\u015fim ba\u011flant\u0131s\u0131 \u00fczerinden bile \u00fcr\u00fcn\u00fcn y\u00f6netilmesini ve g\u00fcncellenmesini daha da kolayla\u015ft\u0131rd\u0131. En \u00f6nemlisi de veri al\u0131\u015fveri\u015fi, cihaz\u0131n temel i\u015flevleriyle \u00e7ak\u0131\u015fm\u0131yor.<\/p>\n<p>\u00dcstelik \u00e7\u00f6z\u00fcm, a\u011f sald\u0131r\u0131lar\u0131n\u0131 yenmek i\u00e7in yeni bir mod\u00fcl i\u00e7eriyor. Mod\u00fcl gelen ve giden trafi\u011fi y\u00f6netiyor ve k\u00f6t\u00fc ama\u00e7l\u0131 a\u011f etkinli\u011fi tespit ederse veri al\u0131\u015fveri\u015fini engelleyebiliyor. Ayr\u0131ca ba\u011flant\u0131 noktalar\u0131n\u0131n taranmas\u0131n\u0131, kaba kuvvet sald\u0131r\u0131lar\u0131n\u0131 ve DoS sald\u0131r\u0131s\u0131 yoluyla ATM\u2019yi devre d\u0131\u015f\u0131 b\u0131rakma giri\u015fimlerini tespit edebiliyor. \u00c7\u00f6z\u00fcm\u00fcn yapabildikleri hakk\u0131nda daha fazla bilgiyi <a href=\"https:\/\/www.kaspersky.com.tr\/enterprise-security\/embedded-systems\" target=\"_blank\" rel=\"noopener\">resmi sayfas\u0131nda<\/a> bulabilirsiniz.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Uzak b\u00f6lgelerdeki \u00f6deme terminalleri ve ATM&#8217;ler \u00f6zel bir g\u00fcvenlik yakla\u015f\u0131m\u0131 gerektirir. <\/p>\n","protected":false},"author":700,"featured_media":8199,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1726,1194],"tags":[401,2192,2194,2193,551],"class_list":{"0":"post-8198","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-enterprise","8":"category-business","9":"tag-atm","10":"tag-atmler","11":"tag-embedded-systems","12":"tag-terminaller","13":"tag-urunler-2"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/atm-in-the-woods\/8198\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/atm-in-the-woods\/21142\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/atm-in-the-woods\/16647\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/atm-in-the-woods\/8213\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/atm-in-the-woods\/22170\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/atm-in-the-woods\/19894\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/atm-in-the-woods\/18655\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/atm-in-the-woods\/22631\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/atm-in-the-woods\/28297\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/atm-in-the-woods\/35258\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/atm-in-the-woods\/14788\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/atm-in-the-woods\/15170\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/atm-in-the-woods\/13424\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/atm-in-the-woods\/23933\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/atm-in-the-woods\/28263\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/atm-in-the-woods\/25391\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/atm-in-the-woods\/22197\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/atm-in-the-woods\/27486\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/atm-in-the-woods\/27321\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/atm\/","name":"atm"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/8198","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/700"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=8198"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/8198\/revisions"}],"predecessor-version":[{"id":8200,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/8198\/revisions\/8200"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/8199"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=8198"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=8198"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=8198"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}