{"id":840,"date":"2015-09-04T10:49:50","date_gmt":"2015-09-04T07:49:50","guid":{"rendered":"https:\/\/furkansandal.com\/saldiri-agaci\/"},"modified":"2015-09-04T10:49:50","modified_gmt":"2015-09-04T07:49:50","slug":"saldiri-agaci","status":"publish","type":"post","link":"https:\/\/furkansandal.com\/saldiri-agaci\/","title":{"rendered":"Sald\u0131r\u0131 A\u011fac\u0131"},"content":{"rendered":"
1998 y\u0131l\u0131nda Salter taraf\u0131ndan ortaya at\u0131lan \u201cSald\u0131r\u0131 A\u011fac\u0131\u201d (ing: Attack Tree) fikri bir sistemin, \u00e7e\u015fitli sald\u0131r\u0131lara kar\u015f\u0131 g\u00fcvenli\u011finin, bi\u00e7imsel ve metodolojik olarak ortaya konulmas\u0131n\u0131 sa\u011flamaktad\u0131r. T\u00fcrk\u00e7e olarak ifade edersek, g\u00fcvenli\u011fini sa\u011flamaya \u00e7al\u0131\u015ft\u0131\u011f\u0131m sisteme \u201ckim ve nas\u0131l sald\u0131rabilir?\u201d sorusuna yan\u0131t olu\u015fturacak bir \u00e7al\u0131\u015fmad\u0131r. <\/span><\/div>\n

<\/span><\/div>\n
<\/a><\/div>\n
<\/div>\n
Kolay ve h\u0131zl\u0131 bir \u00e7\u00f6z\u00fcm olmas\u0131 nedeniyle T\u00fcrkiye\u2019de genel olarak kabul g\u00f6ren zafiyet temelli g\u00fcvenlik yakla\u015f\u0131m\u0131ndan farkl\u0131 olarak sald\u0131r\u0131 a\u011fac\u0131 veya STRIDE gibi yakla\u015f\u0131mlar kurulu\u015funuzun bilgi g\u00fcvenli\u011fi seviyesine daha b\u00fct\u00fcnsel bir bak\u0131\u015f a\u00e7\u0131s\u0131 sa\u011flar. <\/span><\/div>\n
<\/div>\n
Zafiyet temelli yakla\u015f\u0131m, k\u0131saca, sistem \u00fczerindeki g\u00fcvenlik zafiyetlerinin tespit edilmesi (otomatik zafiyet tarama arac\u0131, s\u0131zma testi, vb.) ve bunlar\u0131 ortadan kald\u0131racak veya istismar edilmesini engelleyen gerekli \u00f6nlemlerin al\u0131nmas\u0131 olarak \u00f6zetlenebilir. Daha Sald\u0131r\u0131 A\u011fac\u0131 ise sistemde tespit edebilece\u011fimiz zafiyetlerden yola \u00e7\u0131karak g\u00fcvenli\u011fi sa\u011flamaya \u00e7al\u0131\u015fmak yerine sald\u0131rganlar\u0131n ama\u00e7lar\u0131ndan yola \u00e7\u0131karak sistemin g\u00fcvenli\u011fini sa\u011flamaya \u00e7al\u0131\u015fmaktad\u0131r. <\/span><\/div>\n
<\/div>\n
Yakla\u015f\u0131mlar\u0131n her ikisinin de eksik kald\u0131\u011f\u0131 yerler vard\u0131r \u015f\u00fcphesiz ancak amac\u0131m\u0131z\u0131n sistemin g\u00fcvenli\u011fini sa\u011flamak oldu\u011funu d\u00fc\u015f\u00fcn\u00fcrsek sadece zafiyetlerden yola \u00e7\u0131karak tam bir sonu\u00e7 elde etmemizin m\u00fcmk\u00fcn olamayaca\u011f\u0131 g\u00f6r\u00fc\u015f\u00fcndeyim. <\/span><\/div>\n
<\/div>\n
Sald\u0131r\u0131 a\u011fac\u0131n\u0131 haz\u0131rlamak<\/b><\/span><\/div>\n
G\u00fcvenli\u011fini sa\u011flamaya \u00e7al\u0131\u015ft\u0131\u011f\u0131m\u0131z sistem i\u00e7in bir sald\u0131r\u0131 a\u011fac\u0131 haz\u0131rlamak i\u00e7in a\u015fa\u011f\u0131daki ad\u0131mlar\u0131 izleyebiliriz;<\/span><\/div>\n
<\/div>\n