{"id":2302,"date":"2025-06-19T09:26:37","date_gmt":"2025-06-19T09:26:37","guid":{"rendered":"https:\/\/teknodc.net\/blog\/?p=2302"},"modified":"2025-06-19T09:26:37","modified_gmt":"2025-06-19T09:26:37","slug":"sunucularda-zero-trust-mimarisi","status":"publish","type":"post","link":"https:\/\/teknodc.net\/blog\/sunucularda-zero-trust-mimarisi\/","title":{"rendered":"Sunucularda Zero-Trust Mimarisi"},"content":{"rendered":"<h2><b>Sunucularda Zero-Trust Mimarisi\u00a0<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">G\u00fcn\u00fcm\u00fcz siber g\u00fcvenlik ortam\u0131nda, geleneksel &#8220;kale ve hendek&#8221; yakla\u015f\u0131mlar\u0131 yetersiz kalmaya ba\u015flam\u0131\u015ft\u0131r. A\u011flar\u0131n d\u0131\u015f \u00e7evresini g\u00fc\u00e7lendirmeye odaklanan bu model, bir sald\u0131rgan i\u00e7eri girdi\u011finde a\u011f i\u00e7inde serbest\u00e7e hareket etmesine olanak tan\u0131r. Oysa modern tehditler, i\u00e7eriden gelebilece\u011fi gibi, g\u00fcvenilen a\u011f segmentlerini de hedef alabilir. \u0130\u015fte bu noktada, <\/span>Zero Trust g\u00fcvenlik modeli<span style=\"font-weight: 400;\"> devreye giriyor. &#8220;Asla g\u00fcvenme, her zaman do\u011frula&#8221; prensibine dayanan bu model, \u00f6zellikle <a href=\"https:\/\/www.google.com\/search?q=Sunucular+site%3Ateknodc.net&amp;oq=sunucular+site%3A&amp;gs_lcrp=EgZjaHJvbWUqCAgBEEUYJxg7MgYIABBFGDkyCAgBEEUYJxg7MgcIAhAAGO8FMgcIAxAAGO8FMgcIBBAAGO8FMgoIBRAAGKIEGIkFMgoIBhAAGIAEGKIEMgYIBxBFGDvSAQgzNjM2ajBqN6gCALACAA&amp;sourceid=chrome&amp;ie=UTF-8\">sunucular<\/a> gibi kritik varl\u0131klar\u0131n korunmas\u0131nda devrim niteli\u011finde bir yakla\u015f\u0131m sunuyor. Peki, <\/span>Zero Trust g\u00fcvenlik modeli<span style=\"font-weight: 400;\"> tam olarak nedir, <\/span>sunucu g\u00fcvenli\u011fi<span style=\"font-weight: 400;\">ni nas\u0131l yeniden tan\u0131mlar ve <\/span>yetkisiz eri\u015fim \u00f6nleme<span style=\"font-weight: 400;\"> konusunda nas\u0131l bir fark yarat\u0131r? Bu yaz\u0131m\u0131zda, Zero Trust mimarisinin temellerini ve sunucularda uygulanmas\u0131n\u0131 detayl\u0131ca inceleyece\u011fiz.<\/span><\/p>\n<h2><b>Zero Trust G\u00fcvenlik Modeli Nedir?<\/b><\/h2>\n<p>Zero Trust g\u00fcvenlik modeli<span style=\"font-weight: 400;\">, a\u011f i\u00e7indeki veya d\u0131\u015f\u0131ndaki hi\u00e7bir kullan\u0131c\u0131n\u0131n veya cihaz\u0131n otomatik olarak g\u00fcvenilir kabul edilmemesi gerekti\u011fini savunur. Her eri\u015fim iste\u011fi, kayna\u011f\u0131 neresi olursa olsun, kimlik do\u011frulamas\u0131ndan ve yetkilendirmeden ge\u00e7melidir. Bu model, g\u00fcvenli\u011fi a\u011f s\u0131n\u0131rlar\u0131ndan altyap\u0131n\u0131n her katman\u0131na ta\u015f\u0131r ve her etkile\u015fimi potansiyel bir tehdit olarak de\u011ferlendirir.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Bu modelin temel prensipleri \u015funlard\u0131r:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Her Zaman Do\u011frula (Verify Explicitly):<\/b><span style=\"font-weight: 400;\"> T\u00fcm kullan\u0131c\u0131 ve cihazlar, kimlikleri ve ba\u011flamlar\u0131 ne olursa olsun, her eri\u015fim iste\u011finde do\u011frulanmal\u0131d\u0131r.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>En Az Yetki Prensibi (Least Privilege Access):<\/b><span style=\"font-weight: 400;\"> Kullan\u0131c\u0131lara ve cihazlara yaln\u0131zca i\u015flerini yapmalar\u0131 i\u00e7in kesinlikle gerekli olan en d\u00fc\u015f\u00fck d\u00fczeyde yetki verilmelidir.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>S\u00fcrekli \u0130zleme ve Do\u011frulama (Assume Breach &amp; Verify Continuously):<\/b><span style=\"font-weight: 400;\"> G\u00fcvenlik ihlallerinin her an meydana gelebilece\u011fi varsay\u0131l\u0131r. Bu nedenle, t\u00fcm a\u011f trafi\u011fi ve davran\u0131\u015flar\u0131 s\u00fcrekli olarak izlenmeli ve do\u011frulanmal\u0131d\u0131r.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Geleneksel g\u00fcvenlik yakla\u015f\u0131mlar\u0131n\u0131n aksine, <\/span><b>Zero Trust g\u00fcvenlik modeli<\/b><span style=\"font-weight: 400;\">nde i\u00e7 a\u011fda bulunmak bir ayr\u0131cal\u0131k veya otomatik g\u00fcven anlam\u0131na gelmez. Bu radikal de\u011fi\u015fiklik, <\/span>sunucu g\u00fcvenli\u011fi<span style=\"font-weight: 400;\"> i\u00e7in yepyeni bir bak\u0131\u015f a\u00e7\u0131s\u0131 sunar.<\/span><\/p>\n<h3><b>Sunucu G\u00fcvenli\u011fi \u0130\u00e7in Zero Trust Uygulamalar\u0131<\/b><\/h3>\n<p>Zero Trust g\u00fcvenlik modeli<span style=\"font-weight: 400;\">nin sunucularda uygulanmas\u0131, <\/span>yetkisiz eri\u015fim \u00f6nleme<span style=\"font-weight: 400;\">nin en etkili yollar\u0131ndan biridir. \u0130\u015fte bu mimarinin sunuculara nas\u0131l entegre edilebilece\u011fi:<\/span><\/p>\n<p><b>1-)G\u00fc\u00e7l\u00fc Kimlik Do\u011frulama ve \u00c7ok Fakt\u00f6rl\u00fc Kimlik Do\u011frulama (MFA):<\/b><b><br \/>\n<\/b><\/p>\n<ul>\n<li><span style=\"font-weight: 400;\">T\u00fcm <a href=\"\/dedicated\">sunucu<\/a> eri\u015fimleri i\u00e7in g\u00fc\u00e7l\u00fc, karma\u015f\u0131k parolalar zorunlu k\u0131l\u0131nmal\u0131 ve m\u00fcmk\u00fcn olan her yerde MFA (\u00e7ok fakt\u00f6rl\u00fc kimlik do\u011frulama) kullan\u0131lmal\u0131d\u0131r. Bu, bir parolan\u0131n \u00e7al\u0131nmas\u0131 durumunda bile yetkisiz eri\u015fimi engeller.<\/span><\/li>\n<li><span style=\"font-weight: 400;\">SSH anahtar tabanl\u0131 kimlik do\u011frulama gibi daha g\u00fcvenli y\u00f6ntemler, parola tabanl\u0131 y\u00f6ntemlere tercih edilmelidir.<\/span><\/li>\n<\/ul>\n<p><b>2-)Mikro Segmentasyon:<\/b><b><br \/>\n<\/b><\/p>\n<ul>\n<li><span style=\"font-weight: 400;\"><a href=\"\/virtualprivateserver\">Sunucular<\/a> ve hizmetler, a\u011f i\u00e7inde k\u00fc\u00e7\u00fck, izole edilmi\u015f segmentlere ayr\u0131lmal\u0131d\u0131r. \u00d6rne\u011fin, web sunucular\u0131, veritaban\u0131 sunucular\u0131 ve uygulama sunucular\u0131 birbirinden ayr\u0131 segmentlerde tutulmal\u0131 ve aralar\u0131ndaki ileti\u015fim yaln\u0131zca kesinlikle gerekli olan portlar ve protokoller \u00fczerinden izin verilmelidir. Bu, bir segmentin ihlal edilmesi durumunda sald\u0131rgan\u0131n yatayda hareketini (lateral movement) k\u0131s\u0131tlar.<\/span><\/li>\n<\/ul>\n<p><b>3-)En Az Yetki Prensibi:<\/b><b><br \/>\n<\/b><\/p>\n<ul>\n<li><span style=\"font-weight: 400;\">Her sunucu ve sunucu \u00fczerinde \u00e7al\u0131\u015fan her uygulama i\u00e7in eri\u015fim yetkileri dikkatle y\u00f6netilmelidir. Bir kullan\u0131c\u0131n\u0131n veya servisin yaln\u0131zca belirli bir g\u00f6revi yerine getirmek i\u00e7in ihtiya\u00e7 duydu\u011fu kaynaklara eri\u015fim izni olmal\u0131d\u0131r. \u00d6rne\u011fin, bir web sunucusunun veritaban\u0131na sadece okuma yetkisi olabilir, yazma de\u011fil. Bu prensip, <\/span>yetkisiz eri\u015fim \u00f6nleme<span style=\"font-weight: 400;\">nin temelini olu\u015fturur.<\/span><\/li>\n<\/ul>\n<p><b>4-)S\u00fcrekli \u0130zleme ve Anomali Tespiti:<\/b><b><br \/>\n<\/b><\/p>\n<ul>\n<li><span style=\"font-weight: 400;\">Sunucu loglar\u0131, a\u011f trafi\u011fi ve kullan\u0131c\u0131 davran\u0131\u015flar\u0131 s\u00fcrekli olarak izlenmelidir. Anormal aktiviteler (\u00f6rn. ola\u011fand\u0131\u015f\u0131 saatlerde eri\u015fim, bilinmeyen IP&#8217;lerden ba\u011flant\u0131, y\u00fcksek ba\u015far\u0131s\u0131z oturum a\u00e7ma denemeleri) an\u0131nda tespit edilmeli ve alarm verilmelidir. SIEM (Security Information and Event Management) ve SOAR (Security Orchestration, Automation and Response) ara\u00e7lar\u0131 bu s\u00fcre\u00e7te yard\u0131mc\u0131 olabilir.<\/span><\/li>\n<\/ul>\n<p><b>5-)Cihaz G\u00fcvenli\u011fi ve Sa\u011fl\u0131k Durumu Kontrol\u00fc:<\/b><b><br \/>\n<\/b><\/p>\n<ul>\n<li><span style=\"font-weight: 400;\">Sunuculara ba\u011flanan her cihaz\u0131n (kullan\u0131c\u0131 diz\u00fcst\u00fc bilgisayar\u0131, ba\u015fka bir sunucu vb.) g\u00fcvenlik yamalar\u0131n\u0131n g\u00fcncel oldu\u011fu, anti-vir\u00fcs yaz\u0131l\u0131mlar\u0131n\u0131n \u00e7al\u0131\u015ft\u0131\u011f\u0131 ve g\u00fcvenlik politikalar\u0131na uygun oldu\u011fu do\u011frulanmal\u0131d\u0131r. U\u00e7 nokta koruma (EDR) \u00e7\u00f6z\u00fcmleri bu kontrolleri sa\u011flar.<\/span><\/li>\n<\/ul>\n<p><b>6-)Uygulama G\u00fcvenli\u011fi:<\/b><b><br \/>\n<\/b><\/p>\n<ul>\n<li style=\"list-style-type: none;\">\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"2\"><span style=\"font-weight: 400;\"><a href=\"\/gpuvpsserver\">Sunucular<\/a> \u00fczerinde \u00e7al\u0131\u015fan uygulamalar\u0131n da g\u00fcvenlik a\u00e7\u0131klar\u0131na kar\u015f\u0131 d\u00fczenli olarak taranmas\u0131 ve g\u00fcncellenmesi gerekir. OWASP Top 10 gibi bilinen zafiyetlere kar\u015f\u0131 koruma sa\u011flanmal\u0131d\u0131r.<\/span><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Zero Trust mimarisinin sunuculara uygulanmas\u0131, <\/span>sunucu g\u00fcvenli\u011fi<span style=\"font-weight: 400;\">ni radikal bir \u015fekilde g\u00fc\u00e7lendirir. Bu yakla\u015f\u0131m, sald\u0131r\u0131 y\u00fczeyini daralt\u0131r, <\/span>yetkisiz eri\u015fim \u00f6nleme<span style=\"font-weight: 400;\"> yeteneklerini art\u0131r\u0131r ve bir ihlal durumunda zarar\u0131 s\u0131n\u0131rlayarak i\u015fletmelerin daha diren\u00e7li olmas\u0131n\u0131 sa\u011flar. G\u00fcvenli\u011fi bir s\u00fcre\u00e7 olarak ele alan ve s\u00fcrekli do\u011frulama prensibini benimseyen Zero Trust, dijital varl\u0131klar\u0131n\u0131z\u0131 korumak i\u00e7in vazge\u00e7ilmez bir stratejidir.<\/span><\/p>\n<h3><b>S\u0131k\u00e7a Sorulan Sorular (SSS)<\/b><\/h3>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\">\n<h4><b>Zero Trust g\u00fcvenlik modeli nedir ve geleneksel g\u00fcvenlikten fark\u0131 nedir?<\/b><b><br \/>\n<\/b><\/h4>\n<\/li>\n<\/ul>\n<p>Zero Trust g\u00fcvenlik modeli<span style=\"font-weight: 400;\">, a\u011f i\u00e7indeki veya d\u0131\u015f\u0131ndaki hi\u00e7bir kullan\u0131c\u0131n\u0131n veya cihaz\u0131n otomatik olarak g\u00fcvenilir kabul edilmemesi gerekti\u011fini savunur. Geleneksel modelin aksine, a\u011f \u00e7evresine odaklanmak yerine her eri\u015fim iste\u011fini do\u011frulayarak ve en az yetki prensibiyle \u00e7al\u0131\u015farak <\/span><b>sunucu g\u00fcvenli\u011fi<\/b><span style=\"font-weight: 400;\">ni her katmanda sa\u011flar.<\/span><\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\">\n<h4><b>Sunucularda Zero Trust uygulamas\u0131n\u0131n temel prensipleri nelerdir?<\/b><b><br \/>\n<\/b><\/h4>\n<\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Sunucularda Zero Trust&#8217;\u0131n temel prensipleri, her eri\u015fim iste\u011finin s\u00fcrekli do\u011frulanmas\u0131, en az yetki prensibiyle eri\u015fim verilmesi, mikro segmentasyon ile a\u011f izolasyonu, s\u00fcrekli izleme ve anomali tespiti, ayr\u0131ca ba\u011flanan cihazlar\u0131n sa\u011fl\u0131k durumunun kontrol edilmesidir.<\/span><\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\">\n<h4><b>Yetkisiz eri\u015fim \u00f6nleme konusunda Zero Trust nas\u0131l bir avantaj sa\u011flar?<\/b><b><br \/>\n<\/b><\/h4>\n<\/li>\n<\/ul>\n<p>Yetkisiz eri\u015fim \u00f6nleme<span style=\"font-weight: 400;\"> konusunda Zero Trust, her eri\u015fim noktas\u0131nda s\u0131k\u0131 kimlik do\u011frulama ve yetkilendirme gerektirerek, ayr\u0131ca a\u011f i\u00e7inde yatay hareketlili\u011fi k\u0131s\u0131tlayan mikro segmentasyon uygulayarak \u00f6nemli avantajlar sa\u011flar. Bu, bir ihlal durumunda sald\u0131rgan\u0131n sistem i\u00e7inde ilerlemesini zorla\u015ft\u0131r\u0131r.<\/span><\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\">\n<h4><b>Mikro segmentasyon, sunucu g\u00fcvenli\u011fine nas\u0131l katk\u0131da bulunur?<\/b><b><br \/>\n<\/b><\/h4>\n<\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">Mikro segmentasyon, a\u011f i\u00e7indeki sunucular\u0131 ve uygulamalar\u0131 k\u00fc\u00e7\u00fck, izole edilmi\u015f segmentlere ay\u0131r\u0131r. Bu, bir segmentin tehlikeye girmesi durumunda, sald\u0131r\u0131n\u0131n di\u011fer segmentlere yay\u0131lmas\u0131n\u0131 engelleyerek <\/span>sunucu g\u00fcvenli\u011fi<span style=\"font-weight: 400;\">ni art\u0131r\u0131r ve olas\u0131 bir ihlalin etkisini s\u0131n\u0131rlar.<\/span><\/p>\n<p>&nbsp;<\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\">\n<h4><b>Zero Trust mimarisini uygulamak i\u00e7in hangi teknolojilere ihtiya\u00e7 duyulur?<\/b><b><br \/>\n<\/b><\/h4>\n<\/li>\n<\/ul>\n<p>Zero Trust g\u00fcvenlik modeli<span style=\"font-weight: 400;\">ni uygulamak i\u00e7in MFA (\u00c7ok Fakt\u00f6rl\u00fc Kimlik Do\u011frulama) \u00e7\u00f6z\u00fcmleri, \u0130stemci Kimlik Do\u011frulamas\u0131 ve Eri\u015fim Y\u00f6netimi (IAM) sistemleri, A\u011f Segmentasyon ara\u00e7lar\u0131 (yaz\u0131l\u0131m tan\u0131ml\u0131 a\u011flar &#8211; SDN), U\u00e7 Nokta Koruma ve Alg\u0131lama (EDR) sistemleri, SIEM (G\u00fcvenlik Bilgileri ve Olay Y\u00f6netimi) ara\u00e7lar\u0131 ve bulut eri\u015fim g\u00fcvenlik arac\u0131lar\u0131 (CASB) gibi teknolojilere ihtiya\u00e7 duyulur.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sunucularda Zero-Trust Mimarisi\u00a0 G\u00fcn\u00fcm\u00fcz siber g\u00fcvenlik ortam\u0131nda, geleneksel &#8220;kale ve hendek&#8221; yakla\u015f\u0131mlar\u0131 yetersiz kalmaya ba\u015flam\u0131\u015ft\u0131r. A\u011flar\u0131n&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2303,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"content-type":"","_lmt_disableupdate":"","_lmt_disable":"","footnotes":""},"categories":[1],"tags":[],"class_list":["post-2302","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-genel"],"_links":{"self":[{"href":"https:\/\/teknodc.net\/blog\/wp-json\/wp\/v2\/posts\/2302","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknodc.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknodc.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknodc.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknodc.net\/blog\/wp-json\/wp\/v2\/comments?post=2302"}],"version-history":[{"count":1,"href":"https:\/\/teknodc.net\/blog\/wp-json\/wp\/v2\/posts\/2302\/revisions"}],"predecessor-version":[{"id":2304,"href":"https:\/\/teknodc.net\/blog\/wp-json\/wp\/v2\/posts\/2302\/revisions\/2304"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknodc.net\/blog\/wp-json\/wp\/v2\/media\/2303"}],"wp:attachment":[{"href":"https:\/\/teknodc.net\/blog\/wp-json\/wp\/v2\/media?parent=2302"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknodc.net\/blog\/wp-json\/wp\/v2\/categories?post=2302"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknodc.net\/blog\/wp-json\/wp\/v2\/tags?post=2302"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}