{"id":158022,"date":"2022-06-24T11:54:04","date_gmt":"2022-06-24T08:54:04","guid":{"rendered":"https:\/\/www.enerjigazetesi.ist\/?p=158022"},"modified":"2022-06-24T11:54:04","modified_gmt":"2022-06-24T08:54:04","slug":"calisanlari-kimlik-avi-saldirilari-na-karsi-korumak-mumkun","status":"publish","type":"post","link":"https:\/\/www.enerjigazetesi.ist\/en\/calisanlari-kimlik-avi-saldirilari-na-karsi-korumak-mumkun\/","title":{"rendered":"(Turkish) \u00c7al\u0131\u015fanlar\u0131 Kimlik Av\u0131 Sald\u0131r\u0131lar\u0131na Kar\u015f\u0131 Korumak M\u00fcmk\u00fcn"},"content":{"rendered":"<p class=\"qtranxs-available-languages-message qtranxs-available-languages-message-en\">Sorry, this entry is only available in <a href=\"https:\/\/www.enerjigazetesi.ist\/tr\/wp-json\/wp\/v2\/posts\/158022\" class=\"qtranxs-available-language-link qtranxs-available-language-link-tr\" title=\"Turkish\">Turkish<\/a>. For the sake of viewer convenience, the content is shown below in the alternative language. You may click the link to switch the active language.<\/p><p><\/p>\n<h2><strong>ESET Tehdit Raporu D1 2022\u2019ye g\u00f6re, e-posta tehditlerinde 2021&#8217;in son d\u00f6rt ay\u0131na k\u0131yasla, 2022&#8217;nin ilk 4 ay\u0131nda % 37&#8217;lik bir art\u0131\u015f g\u00f6r\u00fcld\u00fc. Engellenen kimlik av\u0131 URL&#8217;lerinin say\u0131s\u0131 neredeyse ayn\u0131 oranda artt\u0131.<\/strong><\/h2>\n<p><strong><img loading=\"lazy\" class=\"alignright wp-image-158024\" src=\"https:\/\/www.enerjigazetesi.ist\/wp-content\/uploads\/2022\/06\/calisanlari-kimlik-avi-saldirilari-na-karsi-korumak-mumkun-2.jpg\" alt=\"\" width=\"320\" height=\"214\" srcset=\"https:\/\/www.enerjigazetesi.ist\/wp-content\/uploads\/2022\/06\/calisanlari-kimlik-avi-saldirilari-na-karsi-korumak-mumkun-2.jpg 550w, https:\/\/www.enerjigazetesi.ist\/wp-content\/uploads\/2022\/06\/calisanlari-kimlik-avi-saldirilari-na-karsi-korumak-mumkun-2-300x200.jpg 300w, https:\/\/www.enerjigazetesi.ist\/wp-content\/uploads\/2022\/06\/calisanlari-kimlik-avi-saldirilari-na-karsi-korumak-mumkun-2-500x334.jpg 500w, https:\/\/www.enerjigazetesi.ist\/wp-content\/uploads\/2022\/06\/calisanlari-kimlik-avi-saldirilari-na-karsi-korumak-mumkun-2-75x50.jpg 75w, https:\/\/www.enerjigazetesi.ist\/wp-content\/uploads\/2022\/06\/calisanlari-kimlik-avi-saldirilari-na-karsi-korumak-mumkun-2-450x300.jpg 450w\" sizes=\"(max-width: 320px) 100vw, 320px\" \/>Kimlik av\u0131 doland\u0131r\u0131c\u0131l\u0131klar\u0131<\/strong> sald\u0131rganlar\u0131n<strong> k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m y\u00fcklemek, kimlik bilgilerini \u00e7almak<\/strong> ve kullan\u0131c\u0131lar\u0131<strong> kurumsal para transferleri yapmalar\u0131<\/strong> i\u00e7in kand\u0131rmak amac\u0131yla kulland\u0131klar\u0131 en ba\u015far\u0131l\u0131 yollardan biri olmay\u0131 s\u00fcrd\u00fcr\u00fcrken <strong>doland\u0131r\u0131c\u0131lar me\u015fru g\u00f6ndericileri taklit etmelerine<\/strong> yard\u0131mc\u0131 olan <strong>sahte e-posta taktikleri<\/strong> kullan\u0131l\u0131yorlar. Al\u0131c\u0131y\u0131, s\u00f6z konusu eylemin sonu\u00e7lar\u0131n\u0131 d\u00fc\u015f\u00fcnmeden <strong>harekete ge\u00e7irmek i\u00e7in<\/strong> acele etmesini sa\u011flayacak \u015fekilde<strong> tasarlanm\u0131\u015f sosyal m\u00fchendislik tekniklerinden<\/strong> yararlan\u0131yorlar.<\/p>\n<h3><strong>Bu taktikler aras\u0131nda \u015funlar yer al\u0131yor:<\/strong><\/h3>\n<p>&#8211; <strong>Sahte g\u00f6nderici kimlikleri \/ etki alanlar\u0131 \/ telefon numaralar\u0131<\/strong> ve bazen de <strong>yaz\u0131m hatalar\u0131<\/strong> ya da<strong> uluslararas\u0131la\u015ft\u0131r\u0131lm\u0131\u015f alan adlar\u0131<\/strong> (IDN&#8217;ler) kullanma<\/p>\n<p>&#8211; <strong>Kimlik av\u0131 giri\u015fimleri<\/strong> olarak tespit edilmesi neredeyse imkans\u0131z olan ele ge\u00e7irilmi\u015f g\u00f6nderici hesaplar\u0131<\/p>\n<p>&#8211; Hedefe y\u00f6nelik<strong> kimlik av\u0131 giri\u015fimlerini<\/strong> daha inand\u0131r\u0131c\u0131 hale getirmek i\u00e7in <strong>\u00e7evrimi\u00e7i ara\u015ft\u0131rma<\/strong> (sosyal medya arac\u0131l\u0131\u011f\u0131yla)<\/p>\n<p>&#8211; Resmi logolar, \u00fcst bilgiler, alt bilgiler vb. kullan\u0131lmas\u0131<\/p>\n<p>&#8211; Kullan\u0131c\u0131y\u0131 aceleyle karar vermeye iten bir<strong> aciliyet<\/strong> veya <strong>heyecan duygusu yaratmak<\/strong><\/p>\n<p>&#8211; G\u00f6nderenin <strong>ger\u00e7ek hedefini gizleyen<\/strong> k\u0131salt\u0131lm\u0131\u015f ba\u011flant\u0131lar<\/p>\n<p>&#8211; Yasal g\u00f6r\u00fcn\u00fcml\u00fc <strong>giri\u015f portallar\u0131, web siteleri vb.<\/strong> olu\u015fturma<\/p>\n<p>Son yay\u0131mlanan <strong>Verizon DBIR raporuna<\/strong> g\u00f6re, ge\u00e7en y\u0131l <strong>g\u00fcvenlik olaylar\u0131n\u0131n<\/strong> b\u00fcy\u00fck k\u0131sm\u0131ndan 4 vekt\u00f6r sorumluydu: <strong>Kimlik bilgileri, kimlik av\u0131, g\u00fcvenlik a\u00e7\u0131klar\u0131ndan yararlanma<\/strong> ve <strong>botnet&#8217;ler<\/strong>. Bunlardan <strong>ilk ikisi insan hatas\u0131<\/strong> ile ilgili. Raporda incelenen toplam ihlallerin d\u00f6rtte biri (%25), <strong>sosyal m\u00fchendislik sald\u0131r\u0131lar\u0131n\u0131n<\/strong> sonucuydu. <strong>\u0130nsan hatalar\u0131<\/strong> ve ayr\u0131cal\u0131\u011f\u0131n k\u00f6t\u00fcye kullan\u0131lmas\u0131yla bir araya geldi\u011finde, <strong>insan unsuru t\u00fcm ihlallerin<\/strong> <strong>%82<\/strong>&#8216;sini olu\u015fturuyordu.<\/p>\n<h3><strong>Kimlik av\u0131 nelere yol a\u00e7abilir?<\/strong><\/h3>\n<p><strong>Kimlik av\u0131 sald\u0131r\u0131lar\u0131<\/strong> son <strong>2 y\u0131lda<\/strong> daha da b\u00fcy\u00fck bir tehdit haline geldi. Muhtemelen yamanmam\u0131\u015f ve yetersiz korunan cihazlara sahip <strong>dikkati da\u011f\u0131n\u0131k<\/strong> ve<strong> evden \u00e7al\u0131\u015fan ki\u015filer<\/strong>, tehdit akt\u00f6rleri taraf\u0131ndan ac\u0131mas\u0131zca hedef al\u0131nd\u0131. <strong>Nisan 2020<\/strong>&#8216;de<strong> Google<\/strong>, d\u00fcnya \u00e7ap\u0131nda her g\u00fcn <strong>18 milyon kadar<\/strong> <strong>k\u00f6t\u00fc ama\u00e7l\u0131<\/strong> ve <strong>kimlik av\u0131 e-postas\u0131n\u0131 engelledi\u011fini<\/strong> iddia etti.<\/p>\n<p>Bu \u00e7al\u0131\u015fanlar\u0131n \u00e7o\u011fu ofise geri d\u00f6nd\u00fck\u00e7e, daha fazla say\u0131da <strong>SMS<\/strong> ile <strong>kimlik av\u0131 (smishing)<\/strong> ve <strong>sesli arama tabanl\u0131 kimlik av\u0131 (vishing) sald\u0131r\u0131s\u0131na<\/strong> maruz kalmalar\u0131 riski de s\u00f6z konusu. Hareket halindeki kullan\u0131c\u0131lar\u0131n <strong>ba\u011flant\u0131lara t\u0131klamalar\u0131<\/strong> ve a\u00e7mamalar\u0131 gereken <strong>ek dosyalar\u0131 a\u00e7ma<\/strong> olas\u0131l\u0131klar\u0131 daha y\u00fcksek olabilir. Bu durum ise <span style=\"text-decoration: underline;\">\u015funlara yol a\u00e7abilir:<\/span><\/p>\n<p>&#8211; Fidye yaz\u0131l\u0131m\u0131 indirmeleri<\/p>\n<p>&#8211; Bankac\u0131l\u0131k Truva Atlar\u0131<\/p>\n<p>&#8211; Veri h\u0131rs\u0131zl\u0131\u011f\u0131\/ihlalleri<\/p>\n<p>&#8211; K\u00f6t\u00fc ama\u00e7l\u0131 kripto madencili\u011fi yaz\u0131l\u0131mlar\u0131<\/p>\n<p>&#8211; Botnet da\u011f\u0131t\u0131mlar\u0131<\/p>\n<p>&#8211; Takip eden sald\u0131r\u0131larda kullan\u0131lmak \u00fczere ele ge\u00e7irilen hesaplar<\/p>\n<p>&#8211; <strong>Sahte faturalar\/\u00f6deme<\/strong> <strong>isteklerine<\/strong> ba\u011fl\u0131 olarak para kaybedilmesiyle sonu\u00e7lanan i\u015f <strong>e-postalar\u0131n\u0131n<\/strong> ele ge\u00e7irilmesi <strong>(BEC)<\/strong><\/p>\n<p><strong>Finansal<\/strong> ve <strong>itibari yans\u0131malar\u0131<\/strong> \u00e7ok b\u00fcy\u00fckt\u00fcr. Bir<strong> veri ihlalinin<\/strong> ortalama maliyeti bug\u00fcn rekor bir seviye olan <strong>4,2 milyon dolar\u0131n<\/strong> \u00fczerindeyken, <strong>baz\u0131 fidye yaz\u0131l\u0131m\u0131 ihlalleri<\/strong> bunun birka\u00e7 kat \u00fcst\u00fcne mal olmaktad\u0131r.<\/p>\n<p><strong>ESET T\u00fcrkiye \u00dcr\u00fcn ve Pazarlama M\u00fcd\u00fcr\u00fc Can Erginkurban,<\/strong> e\u011fitimin her zaman \u00f6nemli oldu\u011funu vurgulayarak \u015funlar\u0131 s\u00f6yledi: <em>&#8220;\u00c7al\u0131\u015fanlara y\u00f6nelik sald\u0131r\u0131lar\u0131n \u00f6n\u00fcne ge\u00e7ebilmek i\u00e7in d\u00fczenli e\u011fitimler ger\u00e7ekle\u015ftirilmelidir. <strong>Kimlik av\u0131 fark\u0131ndal\u0131\u011f\u0131 e\u011fitimi, sosyal m\u00fchendislik<\/strong> tehditleriyle m\u00fccadeleye y\u00f6nelik <strong>\u00e7ok katmanl\u0131 bir stratejinin<\/strong> yaln\u0131zca bir par\u00e7as\u0131 olmal\u0131d\u0131r. En e\u011fitimli personel bile, bazen karma\u015f\u0131k <strong>doland\u0131r\u0131c\u0131l\u0131klar\u0131n kurban\u0131<\/strong> olabilir. Bu y\u00fczden<strong> g\u00fcvenlik kontrolleri<\/strong> de \u00f6nemlidir. <strong>Oltalama sald\u0131r\u0131lar\u0131na<\/strong> kar\u015f\u0131 kurumunuzu <strong>korumak istiyorsan\u0131z<\/strong> <strong>\u00e7al\u0131\u015fanlar\u0131n\u0131z\u0131 mutlaka e\u011fitimlerle desteklemelisiniz.<\/strong>&#8220;<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>Sorry, this entry is only available in Turkish. For the sake of viewer convenience, the content is shown below in the alternative language. You may click the link to switch the active language. ESET Tehdit Raporu D1 2022\u2019ye g\u00f6re, e-posta tehditlerinde 2021&#8217;in son d\u00f6rt ay\u0131na k\u0131yasla, 2022&#8217;nin ilk 4 ay\u0131nda % 37&#8217;lik bir art\u0131\u015f g\u00f6r\u00fcld\u00fc. [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":158025,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[53,157],"tags":[103759,104232,104228,104230,104229,92842,104231,38611,86241,104233,104234,99839,104227],"views":50,"_links":{"self":[{"href":"https:\/\/www.enerjigazetesi.ist\/en\/wp-json\/wp\/v2\/posts\/158022"}],"collection":[{"href":"https:\/\/www.enerjigazetesi.ist\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.enerjigazetesi.ist\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.enerjigazetesi.ist\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.enerjigazetesi.ist\/en\/wp-json\/wp\/v2\/comments?post=158022"}],"version-history":[{"count":0,"href":"https:\/\/www.enerjigazetesi.ist\/en\/wp-json\/wp\/v2\/posts\/158022\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.enerjigazetesi.ist\/en\/wp-json\/wp\/v2\/media\/158025"}],"wp:attachment":[{"href":"https:\/\/www.enerjigazetesi.ist\/en\/wp-json\/wp\/v2\/media?parent=158022"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.enerjigazetesi.ist\/en\/wp-json\/wp\/v2\/categories?post=158022"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.enerjigazetesi.ist\/en\/wp-json\/wp\/v2\/tags?post=158022"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}