{"id":9194,"date":"2021-01-13T11:16:46","date_gmt":"2021-01-13T08:16:46","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=9194"},"modified":"2021-01-13T11:16:46","modified_gmt":"2021-01-13T08:16:46","slug":"air-fi-data-exfiltration","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/air-fi-data-exfiltration\/9194\/","title":{"rendered":"\u0130zole edilmi\u015f bilgisayarlardan veri \u00e7alman\u0131n bir ba\u015fka yolu olarak Air-Fi"},"content":{"rendered":"<p>Sald\u0131rganlar\u0131n, gizli bilgilerine eri\u015fememesi i\u00e7in i\u015fletmeler cihazlar\u0131n\u0131 b\u0131rak\u0131n internet, yerel bir a\u011fa dahi ba\u011flamadan, \u201c<em>air gap<\/em>\u201d ad\u0131 verilen bir y\u00f6ntemle korumaya \u00e7al\u0131\u015f\u0131yorlar. Kula\u011fa her ne kadar g\u00fcvenli bir y\u00f6ntemmi\u015f gibi gelse de, bu tarz cihaz ya da a\u011flara s\u0131zmak \u00e7ok da zor de\u011fil \u2014 <a href=\"https:\/\/www.kaspersky.com\/blog\/stuxnet-victims-zero\/6775\/\" target=\"_blank\" rel=\"noopener nofollow\">Stuxnet<\/a> \u00f6rne\u011fini hat\u0131rlay\u0131n. As\u0131l zor olan, ele ge\u00e7irdi\u011finiz bilgiyi \u00e7\u0131karmak.<\/p>\n<p>Tam da bu noktada Negev Ben-Gurion \u00dcniversitesi\u2019nden, alan\u0131nda uzman ara\u015ft\u0131rmac\u0131 Mordechai Guri ve bu bilgileri nas\u0131l elde edebilece\u011finize dair buldu\u011fu <a href=\"https:\/\/www.kaspersky.com.tr\/blog\/jumping-over-air-gap\/8472\/\" target=\"_blank\" rel=\"noopener\">bir tak\u0131m zekice y\u00f6ntemleri<\/a> devreye giriyor. Elbette <a href=\"https:\/\/www.kaspersky.com\/blog\/black-hat-lamphone\/36744\/\" target=\"_blank\" rel=\"noopener nofollow\">Dr. Guri alan\u0131nda tek de\u011fil<\/a>, ancak son y\u0131llarda bu konu \u00fczerinde onlarca yeni y\u00f6ntemin ke\u015ffinde rol alm\u0131\u015f bir isim.<\/p>\n<p>Yap\u0131lan yeni bir ara\u015ft\u0131rmaya g\u00f6re, izole edilmi\u015f bir bilgisayardan Wi-Fi kullan\u0131larak veri ay\u0131klaman\u0131n yeni bir yolu var ve buna da <em>Air-Fi<\/em> deniyor.<\/p>\n<p><strong>Air-Fi nas\u0131l \u00e7al\u0131\u015f\u0131r?<\/strong><\/p>\n<p>Air-Fi y\u00f6nteminin bu denli i\u015fe yarar olmas\u0131n\u0131n sebebi, ula\u015f\u0131lacak bilgisayar\u0131n Wi-Fi ekipman\u0131 olmasa bile cihaza eri\u015febiliyor olman\u0131z. Bu y\u00f6ntem a\u011f ba\u011flant\u0131s\u0131 kullanmak yerine, DDR SDRAM bellek yolunu 2.4 GHz\u2019lik elektromanyetik yay\u0131m i\u00e7in kullanan bir cihaza yerle\u015ftirilen k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131mlar \u00fczerinden \u00e7al\u0131\u015fabiliyor. Yaz\u0131l\u0131m, bu elektromanyetik yay\u0131mdaki gerekli verileri belli varyasyonlarla kodlayabiliyor ve Wi-Fi al\u0131c\u0131s\u0131 olan herhangi bir cihaz, hatta s\u0131z\u0131lm\u0131\u015f bir cihaz da dahil olmak \u00fczere olu\u015fturulan bu sinyalleri yakalay\u0131p tutabiliyor. Bu herhangi bir cihaz da basit bir ak\u0131ll\u0131 telefon, hatta ak\u0131ll\u0131 bir ampul bile olabilir.<\/p>\n<p>Siber g\u00fcvenlik alan\u0131ndan bak\u0131ld\u0131\u011f\u0131nda Air-Fi y\u00f6ntemi olduk\u00e7a can s\u0131k\u0131c\u0131 bir konu. \u0130zole edilmi\u015f bir bilgisayarda Air-Fi kullanarak veri elde etmek i\u00e7in y\u00f6netici izinlerine gerek kalm\u0131yor ve standart kullan\u0131c\u0131 hesaplar\u0131 ile de i\u015flemi tamamlayabiliyorsunuz. Dahas\u0131, sanal makine kullan\u0131m\u0131n\u0131n g\u00fcvenli\u011fe etki eden hi\u00e7bir faydas\u0131 yok, \u00e7\u00fcnk\u00fc sanal makinelerin halihaz\u0131rda bellek mod\u00fcllerine eri\u015fimi var.<\/p>\n<p><strong>Veri aktar\u0131m h\u0131z\u0131 ve aral\u0131\u011f\u0131<\/strong><\/p>\n<p>Ara\u015ft\u0131rmac\u0131lar s\u0131z\u0131lan bilgisayar\u0131n donan\u0131m\u0131 ve ba\u011fl\u0131 al\u0131c\u0131n\u0131n \u00fczerinden herhangi farkedilebilir bir bozulma ya\u015famadan, 2 ila 3 metrelik bir mesafeden (hatta bir kolayda 8 metreye ula\u015ft\u0131), saniyede 100 bit\u2019e kadar bir h\u0131zla veri aktarabildiler. Bilinen di\u011fer benzer y\u00f6ntemlerle kar\u015f\u0131la\u015ft\u0131r\u0131ld\u0131\u011f\u0131nda \u00e7ok da h\u0131zl\u0131 olmad\u0131\u011f\u0131n\u0131 s\u00f6yleyebiliriz. \u00d6rnek vermek gerekirse, 20MB boyutunda bir dosyay\u0131 transfer etmek 466 saat s\u00fcrecektir. Yani, \u201cJingle Bells\u201d \u015fark\u0131s\u0131n\u0131n s\u00f6zlerini 90 saniyede \u00e7ekebilirsiniz, ki bu da 1300 bit ediyor. Bu bilgiler \u0131\u015f\u0131\u011f\u0131nda da, birilerinin kullan\u0131c\u0131 ad\u0131 ve parolas\u0131n\u0131 \u00e7almak i\u00e7in bu y\u00f6ntemi kullanman\u0131n tamamen ger\u00e7ek\u00e7i g\u00f6z\u00fckt\u00fc\u011f\u00fcn\u00fc s\u00f6ylemek m\u00fcmk\u00fcn.<\/p>\n<p><strong>Air-Fi s\u0131zmalar\u0131 nas\u0131l engellenir?<\/strong><\/p>\n<p>Air-Fi y\u00f6nteminde elektromanyetik yay\u0131mlar kullan\u0131l\u0131r. A\u015fa\u011f\u0131daki \u00f6nlemleri alarak bu s\u0131zmalardan korunabilirsiniz:<\/p>\n<ul>\n<li>Wi-Fi eri\u015fimi olan cihazlar\u0131, izole edilmi\u015f sistemlerinizin yak\u0131nlar\u0131na kesinlikle yakla\u015ft\u0131rmay\u0131n.<\/li>\n<li><a href=\"https:\/\/www.kaspersky.com.tr\/small-to-medium-business-security?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">\u0130zole edilmi\u015f sistemlerinizi<\/a>, \u015f\u00fcpheli durumlar i\u00e7in s\u00fcrekli takip edin.<\/li>\n<li>Bilgisayarlar\u0131n\u0131z\u0131 Faraday kafesi i\u00e7erisinde muhafaza edin.<\/li>\n<li>\u0130\u015fletmenize d\u0131\u015far\u0131dan herhangi bir cihaz\u0131n getirilmesine izin vermeyin. Buna tu\u015flu telefonlar da dahil.<\/li>\n<\/ul>\n<p>Son bahsetti\u011fimiz \u00f6nlem biraz ekstrem bir ad\u0131m olabilir, ancak i\u00e7lerinde en etkilisi oldu\u011fu kesin.<\/p>\n<p>T\u0131pk\u0131 di\u011fer benzer y\u00f6ntemler gibi Air-Fi da, al\u0131\u015f\u0131lagelmi\u015f siber su\u00e7lular\u0131n g\u00fcnl\u00fck sald\u0131r\u0131lar\u0131nda kullanabilece\u011fi gibi h\u0131zl\u0131 ve kolay bir se\u00e7enek de\u011fil. Y\u00f6netici izinlerine ihtiya\u00e7 duyulmadan i\u015fe yarad\u0131\u011f\u0131 i\u00e7in, Air-Fi daha \u00e7ok s\u0131nai casusluk ile devlete ba\u011fl\u0131 isimlerce kullan\u0131lmas\u0131 olas\u0131 bir alternatif. Bu y\u00f6ntemle ilgili daha geni\u015f bilgiye <a href=\"https:\/\/arxiv.org\/pdf\/2012.06884.pdf\" target=\"_blank\" rel=\"noopener nofollow\">bu ara\u015ft\u0131rmadan<\/a> ula\u015fabilirsiniz.<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kesb-b2b\">\n","protected":false},"excerpt":{"rendered":"<p>\u0130srailli ara\u015ft\u0131rmac\u0131lar\u0131n ke\u015ffine g\u00f6re Wi-Fi \u00fczerinden bilgi aktar\u0131m\u0131 yapmak i\u00e7in bilgisayarlar\u0131n Wi-Fi mod\u00fcl\u00fcne ba\u011fl\u0131 olmas\u0131na asl\u0131nda gerek yok.<\/p>\n","protected":false},"author":2548,"featured_media":9196,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1726,1194],"tags":[2342,2344,2343],"class_list":{"0":"post-9194","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-enterprise","8":"category-business","9":"tag-air-gap","10":"tag-ben-gurion-universitesi","11":"tag-veri-sizdirma"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/air-fi-data-exfiltration\/9194\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/air-fi-data-exfiltration\/22381\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/air-fi-data-exfiltration\/17869\/"},{"hreflang":"ar","url":"https:\/\/me.kaspersky.com\/blog\/air-fi-data-exfiltration\/8846\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/air-fi-data-exfiltration\/24058\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/air-fi-data-exfiltration\/22139\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/air-fi-data-exfiltration\/24490\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/air-fi-data-exfiltration\/23681\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/air-fi-data-exfiltration\/29923\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/air-fi-data-exfiltration\/38310\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/air-fi-data-exfiltration\/16216\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/air-fi-data-exfiltration\/16796\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/air-fi-data-exfiltration\/14351\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/air-fi-data-exfiltration\/26040\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/air-fi-data-exfiltration\/29846\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/air-fi-data-exfiltration\/26569\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/air-fi-data-exfiltration\/23434\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/air-fi-data-exfiltration\/28754\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/air-fi-data-exfiltration\/28565\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/air-gap\/","name":"air gap"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9194","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2548"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=9194"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9194\/revisions"}],"predecessor-version":[{"id":9197,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9194\/revisions\/9197"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/9196"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=9194"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=9194"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=9194"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}