{"id":2281,"date":"2026-06-21T11:36:13","date_gmt":"2026-06-21T08:36:13","guid":{"rendered":"https:\/\/saviorhost.com\/blog\/?p=2281"},"modified":"2026-06-21T18:38:59","modified_gmt":"2026-06-21T15:38:59","slug":"kurumsal-web-guvenliginde-son-nokta-donanim-ve-waf-mimarisi-2026-sysadmin-rehberi","status":"publish","type":"post","link":"https:\/\/saviorhost.com\/blog\/kurumsal-web-guvenliginde-son-nokta-donanim-ve-waf-mimarisi-2026-sysadmin-rehberi\/","title":{"rendered":"Kurumsal Web G\u00fcvenli\u011finde Son Nokta: Donan\u0131m ve WAF Mimarisi (2026 SysAdmin Rehberi)"},"content":{"rendered":"<p data-path-to-node=\"5\">Kurumsal \u015firketler dijital d\u00f6n\u00fc\u015f\u00fcm s\u00fcre\u00e7lerine milyonlarca lira yat\u0131r\u0131m yaparken, web sitelerinin ve e-ticaret platformlar\u0131n\u0131n g\u00fcvenli\u011fini genellikle ayl\u0131k birka\u00e7 dolarl\u0131k yaz\u0131l\u0131msal WordPress eklentilerine emanet etme hatas\u0131na d\u00fc\u015ferler. \u0130\u015fletmeler ancak b\u00fcy\u00fck bir DDoS sald\u0131r\u0131s\u0131 ald\u0131klar\u0131nda veya m\u00fc\u015fteri verileri s\u0131zd\u0131r\u0131ld\u0131\u011f\u0131nda bu eklentilerin sadece birer &#8220;ill\u00fczyon&#8221; oldu\u011funu ac\u0131 bir \u015fekilde fark ederler.<\/p>\n<p data-path-to-node=\"6\">Bir web sitesinin g\u00fcvenli\u011fini, o sitenin kurulu oldu\u011fu i\u015fletim sisteminin i\u00e7ine hapsedemezsiniz. Tek ba\u015f\u0131n\u0131za t\u00fcm \u015firketin a\u011f altyap\u0131s\u0131n\u0131 ve g\u00fcvenli\u011fini y\u00f6neten bir Bilgi \u0130\u015flem Sorumlusu (IT Lead) g\u00f6z\u00fcyle bakt\u0131\u011f\u0131n\u0131zda; ger\u00e7ek kurumsal g\u00fcvenli\u011fin eklentilerde de\u011fil, a\u011f ge\u00e7idinde (Gateway) ba\u015flayan \u00e7ok katmanl\u0131 bir donan\u0131m mimarisinde yatt\u0131\u011f\u0131n\u0131 g\u00f6r\u00fcrs\u00fcn\u00fcz.<\/p>\n<p data-path-to-node=\"7\">Peki, a\u015f\u0131lamaz bir web sunucusu mimarisi nas\u0131l in\u015fa edilir?<\/p>\n<h2 data-path-to-node=\"8\" id=\"eklentiler-neden-basarisiz-olur-trafik-kapiya-dayanmadan-once\">Eklentiler Neden Ba\u015far\u0131s\u0131z Olur? (Trafik Kap\u0131ya Dayanmadan \u00d6nce)<\/h2>\n<p data-path-to-node=\"9\">Sitenize Wordfence veya benzeri bir yaz\u0131l\u0131m kurdu\u011funuzu varsayal\u0131m. K\u00f6t\u00fc niyetli bir Botnet a\u011f\u0131, sitenize saniyede on binlerce istek g\u00f6nderdi\u011finde bu istekler; veri merkezini ge\u00e7er, sunucunuzun i\u015flemcisine (CPU) ula\u015f\u0131r ve en sonunda eklentinize \u00e7arpar.<\/p>\n<p data-path-to-node=\"10\">Eklentiniz bu sald\u0131r\u0131y\u0131 engellese bile, o binlerce iste\u011fi analiz edip reddetmek i\u00e7in sunucunuzun RAM ve CPU kaynaklar\u0131n\u0131 t\u00fcketir. Sonu\u00e7? Siteniz hacklenmez ama kaynaklar t\u00fckendi\u011fi i\u00e7in tamamen kilitlenir (DDoS kesintisi). Kurumsal bir a\u011fda veya veri merkezinde IP \u00e7ak\u0131\u015fmalar\u0131n\u0131 ve a\u011f d\u00f6ng\u00fclerini (Network Loop) H3C gibi omurga anahtarlar \u00fczerinden donan\u0131m seviyesinde nas\u0131l engelliyorsak, siber sald\u0131r\u0131lar\u0131 da sunucuya ula\u015fmadan durdurmal\u0131y\u0131z.<\/p>\n<h2 data-path-to-node=\"11\" id=\"enterprise-kurumsal-katmanli-guvenlik-mimarisi\">Enterprise (Kurumsal) Katmanl\u0131 G\u00fcvenlik Mimarisi<\/h2>\n<p data-path-to-node=\"12\"><b data-path-to-node=\"12\" data-index-in-node=\"0\">SaviorHost<\/b> altyap\u0131s\u0131nda, sitenizi korumak i\u00e7in yaz\u0131l\u0131mlar\u0131n insaf\u0131na g\u00fcvenmek yerine end\u00fcstri standard\u0131 &#8220;Derinlemesine Savunma&#8221; (Defense in Depth) stratejisini uyguluyoruz. Bu strateji \u00fc\u00e7 ana kalkan \u00fczerinden \u00e7al\u0131\u015f\u0131r:<\/p>\n<h3 data-path-to-node=\"13\" id=\"1-kalkan-donanimsal-guvenlik-duvarlari-edge-firewall\">1. Kalkan: Donan\u0131msal G\u00fcvenlik Duvarlar\u0131 (Edge Firewall)<\/h3>\n<p data-path-to-node=\"14\">Zararl\u0131 trafik daha sunucunuza fiziksel olarak ula\u015fmadan, a\u011f\u0131n en u\u00e7 noktas\u0131ndaki geli\u015fmi\u015f donan\u0131msal g\u00fcvenlik duvarlar\u0131 (FortiGate gibi UTM cihazlar\u0131n\u0131n veri merkezi muadilleri) taraf\u0131ndan kar\u015f\u0131lan\u0131r. Bu donan\u0131mlar, saf i\u015flem g\u00fcc\u00fcyle gelen trafi\u011fi milisaniyeler i\u00e7inde filtreler. Siteniz saniyede milyonlarca sahte istek alsa bile arka plandaki Ryzen 9 sunucunuzun i\u015flemcisi %1 bile yorulmaz.<\/p>\n<h3 data-path-to-node=\"15\" id=\"2-kalkan-agresif-modsecurity-waf-kurallari\">2. Kalkan: Agresif ModSecurity (WAF) Kurallar\u0131<\/h3>\n<p data-path-to-node=\"16\">Donan\u0131m katman\u0131n\u0131 ge\u00e7meyi ba\u015faran sinsi ve hedefe y\u00f6nelik ataklar (\u00d6rne\u011fin bir form \u00fczerinden g\u00f6nderilen SQL Injection veya XSS denemeleri), do\u011frudan web sunucumuzun \u00e7ekirde\u011finde \u00e7al\u0131\u015fan ModSecurity (Web Application Firewall) taraf\u0131ndan kar\u015f\u0131lan\u0131r. Burada standart kurallar yerine, &#8220;False Positive&#8221; (ger\u00e7ek m\u00fc\u015fteriyi sald\u0131rgan san\u0131p engelleme) oranlar\u0131 optimize edilmi\u015f, e-ticaret s\u00fcre\u00e7lerinizi asla kesintiye u\u011fratmayan \u00f6zel SysAdmin kurallar\u0131 devrededir.<\/p>\n<h3 data-path-to-node=\"17\" id=\"3-kalkan-merkezi-loglama-ve-anlik-analiz\">3. Kalkan: Merkezi Loglama ve Anl\u0131k Analiz<\/h3>\n<p data-path-to-node=\"18\">Siber g\u00fcvenlikte neyi engelledi\u011finizi g\u00f6remezseniz, k\u00f6r say\u0131l\u0131rs\u0131n\u0131z. Ba\u015far\u0131l\u0131 bir savunma mimarisinde g\u00fcvenlik duvar\u0131 loglar\u0131, sunucunun kendi diski yerine izole edilmi\u015f y\u00fcksek kapasiteli (\u00f6rne\u011fin 8TB gibi devasa depolama alanlar\u0131na sahip) merkezi Syslog sunucular\u0131na aktar\u0131lmal\u0131d\u0131r. Biz de altyap\u0131m\u0131zdaki anl\u0131k tehditleri bu merkezi log izleme sistemleri \u00fczerinden saniye saniye analiz ederek, yeni nesil tehditlere kar\u015f\u0131 kurallar\u0131m\u0131z\u0131 an\u0131nda g\u00fcncelliyoruz.<\/p>\n<h2 data-path-to-node=\"19\" id=\"guvenliginizi-profesyonellere-emanet-edin\">G\u00fcvenli\u011finizi Profesyonellere Emanet Edin<\/h2>\n<p data-path-to-node=\"20\">Siber g\u00fcvenlik, birka\u00e7 butona basarak sa\u011flanacak bir i\u015flem de\u011fil; a\u011f topolojisine, donan\u0131m katmanlar\u0131na ve siber tehdit istihbarat\u0131na tam hakimiyet gerektiren ciddi bir m\u00fchendislik i\u015fidir. E-ticaret sitenizin, m\u00fc\u015fteri verilerinizin ve kurumsal itibar\u0131n\u0131z\u0131n eklenti zafiyetleri y\u00fcz\u00fcnden tehlikeye girmesine izin vermeyin.<\/p>\n<p data-path-to-node=\"21\">\u0130\u015fletmenizin dijital varl\u0131klar\u0131n\u0131 en \u00fcst d\u00fczey donan\u0131m kalkanlar\u0131yla korumak ve kesintisiz hizmet sunmak i\u00e7in tam izole KeyHelp mimarisiyle \u00e7al\u0131\u015fan <b data-path-to-node=\"21\" data-index-in-node=\"148\"><a class=\"ng-star-inserted\" href=\"https:\/\/saviorhost.com\/wordpress-hosting\" target=\"_blank\" rel=\"noopener\" data-hveid=\"0\" data-ved=\"0CAAQ_4QMahgKEwj42bCPuZiVAxUAAAAAHQAAAAAQtgE\">Premium WordPress Hosting<\/a><\/b> ve sanal sunucu paketlerimizi hemen inceleyin. G\u00fcvende kal\u0131n, i\u015finize odaklan\u0131n!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sitenizi korudu\u011funu sand\u0131\u011f\u0131n\u0131z g\u00fcvenlik eklentileri ger\u00e7ek siber sald\u0131r\u0131larda neden \u00e7\u00f6k\u00fcyor? SysAdmin g\u00f6z\u00fcyle donan\u0131m seviyesinde a\u011f g\u00fcvenli\u011fi, WAF yap\u0131land\u0131rmalar\u0131 ve merkezi log analizinin g\u00fcc\u00fcn\u00fc ke\u015ffedin.<\/p>\n","protected":false},"author":1,"featured_media":2284,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[75,72],"tags":[],"class_list":["post-2281","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hosting","category-wordpress"],"_links":{"self":[{"href":"https:\/\/saviorhost.com\/blog\/wp-json\/wp\/v2\/posts\/2281","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/saviorhost.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/saviorhost.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/saviorhost.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/saviorhost.com\/blog\/wp-json\/wp\/v2\/comments?post=2281"}],"version-history":[{"count":2,"href":"https:\/\/saviorhost.com\/blog\/wp-json\/wp\/v2\/posts\/2281\/revisions"}],"predecessor-version":[{"id":2283,"href":"https:\/\/saviorhost.com\/blog\/wp-json\/wp\/v2\/posts\/2281\/revisions\/2283"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/saviorhost.com\/blog\/wp-json\/wp\/v2\/media\/2284"}],"wp:attachment":[{"href":"https:\/\/saviorhost.com\/blog\/wp-json\/wp\/v2\/media?parent=2281"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/saviorhost.com\/blog\/wp-json\/wp\/v2\/categories?post=2281"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/saviorhost.com\/blog\/wp-json\/wp\/v2\/tags?post=2281"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}