📚 IGCSE CCEA Computer Science: Network Security Key Points | IGCSE CCEA 计算机:网络安全 考点精讲
Network security is a vital part of the CCEA IGCSE Computer Science syllabus. It focuses on the threats that can compromise data and systems, and the measures used to prevent, detect and respond to these threats. Understanding the principles of network security helps students appreciate how sensitive information is kept safe in a connected world.
网络安全是 CCEA IGCSE 计算机科学课程的重要组成部分。它关注可能危害数据和系统的威胁,以及用于预防、检测和应对这些威胁的措施。理解网络安全原理有助于学生领会如何在互联世界中确保敏感信息的安全。
1. Understanding Network Security | 理解网络安全
Network security involves protecting the usability, reliability, integrity and safety of a network and its data. It targets a variety of threats and prevents them from entering or spreading on a network. The core objectives are often summarised as the CIA triad: Confidentiality, Integrity and Availability.
网络安全涉及保护网络及其数据的可用性、可靠性、完整性和安全性。它针对各种威胁,阻止它们进入网络或在网络中传播。核心目标通常概括为 CIA 三元组:机密性、完整性和可用性。
Confidentiality ensures that information is accessible only to those authorised to have access. Integrity safeguards the accuracy and completeness of information and processing methods. Availability ensures that authorised users have access to information and associated assets when required.
机密性确保只有获授权的人才能访问信息。完整性保障信息及处理方法的准确性与完备性。可用性确保获授权的用户在需要时可以访问信息和相关资产。
2. Common Threats to Networks | 网络常见威胁
Threats to network security can be deliberate or accidental. Deliberate threats include hacking, malware and social engineering. Accidental threats include human error, hardware failure and natural disasters. In this section, we focus on malicious threats that appear frequently in the IGCSE CCEA syllabus.
网络安全威胁可能是有意的或无意的。有意威胁包括黑客攻击、恶意软件和社会工程。无意威胁包括人为错误、硬件故障和自然灾害。在本节中,我们重点关注 CCEA IGCSE 课程中经常出现的恶意威胁。
An attacker may exploit vulnerabilities in software, weak passwords or unprotected network ports. Once inside, they can steal data, alter records or disrupt services. The syllabus expects students to describe these threats and explain how they can be mitigated.
攻击者可能利用软件漏洞、弱密码或未受保护的网络端口。一旦进入,他们可以窃取数据、篡改记录或中断服务。课程要求学生描述这些威胁并解释如何减轻它们。
3. Malware: Viruses, Worms and Trojans | 恶意软件:病毒、蠕虫和特洛伊木马
Malware is malicious software designed to damage, disrupt or gain unauthorised access to a computer system. The most common types studied at IGCSE level are viruses, worms and Trojan horses. Each behaves differently and requires distinct countermeasures.
恶意软件是旨在破坏、扰乱计算机系统或未经授权访问的恶意软件。IGCSE 水平最常学习的是病毒、蠕虫和特洛伊木马。每种行为不同,需要不同的应对措施。
A virus attaches itself to a legitimate program and replicates when that program is run. It often requires user action to spread. A worm is a standalone program that replicates itself across networks without needing a host file. Trojans disguise themselves as useful software to trick users into installing them, creating backdoors for attackers.
病毒依附于合法程序,并在程序运行时复制自身。它通常需要用户操作才能传播。蠕虫是一种独立程序,通过网络自我复制,无需宿主文件。特洛伊木马伪装成有用的软件诱骗用户安装,为攻击者创建后门。
4. Phishing and Social Engineering | 钓鱼和社会工程
Phishing is a technique used to obtain sensitive information such as usernames, passwords and credit card details by pretending to be a trustworthy entity. Emails or fake websites mimic legitimate organisations and trick victims into providing their credentials.
钓鱼是一种通过伪装成可信实体来获取用户名、密码和信用卡号等敏感信息的技术。电子邮件或虚假网站模仿合法组织,诱骗受害者提供凭证。
Social engineering is a broader concept that exploits human psychology rather than technical weaknesses. Attackers manipulate individuals into breaking security procedures. Examples include pretexting (creating a fabricated scenario), baiting (offering something enticing) and tailgating (following someone into a secure area).
社会工程是一个更广泛的概念,利用人类心理而非技术弱点。攻击者操纵个人打破安全程序。示例包括借口(制造虚构情景)、诱饵(提供诱人物品)和尾随(跟随某人进入安全区域)。
Phishing is a specific form of social engineering. Both are highly effective and require user education as a primary defence.
钓鱼是社会工程的一种特定形式。二者都非常有效,需要将以用户教育作为主要防御手段。
5. Denial of Service (DoS) Attacks | 拒绝服务攻击
A Denial of Service attack aims to make a network service or website unavailable to its intended users by overwhelming it with a flood of illegitimate requests. This consumes bandwidth, server resources or both, causing the service to slow down or crash completely.
拒绝服务攻击旨在通过用大量非法请求淹没网络服务或网站,使其无法为预期用户提供服务。这会消耗带宽、服务器资源或两者,导致服务变慢或完全崩溃。
A Distributed Denial of Service (DDoS) attack uses many compromised systems (a botnet) to launch the attack simultaneously, making it harder to block. Although data is not usually stolen, DoS attacks disrupt business operations and cause reputational damage.
分布式拒绝服务攻击使用许多被侵入的系统(僵尸网络)同时发起攻击,使其更难被阻止。尽管数据通常不会被盗,拒绝服务攻击会扰乱业务运营并造成声誉损害。
- Symptoms: unusually slow network performance, unavailability of a website, increased spam emails.
- 症状:异常缓慢的网络性能、网站不可用、垃圾邮件增加。
6. Data Interception and Theft | 数据拦截与盗窃
Data interception occurs when an attacker captures data as it travels across a network. This can happen through packet sniffing on unsecured Wi-Fi networks or via man-in-the-middle attacks. Once captured, data can be read, modified or used for fraud.
数据拦截发生在攻击者在数据通过网络传输时将其捕获。这可能通过在不安全 Wi-Fi 网络上进行数据包嗅探或通过中间人攻击发生。一旦捕获,数据可以被读取、修改或用于欺诈。
Encryption is the primary method of preventing data interception. If data is encrypted, even if an attacker captures it, they cannot understand it without the decryption key. The syllabus links this strongly to the use of protocols like HTTPS and VPNs.
加密是防止数据拦截的主要方法。如果数据加密,即使攻击者捕获了数据,没有解密密钥也无法理解。课程将此与 HTTPS 和 VPN 等协议的使用紧密联系。
7. Authentication Methods | 身份验证方法
Authentication verifies the identity of a user or device before granting access to a network or system. The three classic factors are something you know (password, PIN), something you have (smart card, token) and something you are (biometrics).
身份验证在授予对网络或系统的访问权限之前验证用户或设备的身份。三种经典因素是您知道的(密码、PIN)、您拥有的(智能卡、令牌)和您是什么(生物特征)。
Multi-factor authentication (MFA) combines two or more of these factors, greatly increasing security. For example, using a password and a one-time code sent to a mobile phone. This is now common for online banking and email services.
多因素身份验证结合了其中两种或更多因素,极大地提高了安全性。例如,使用密码和发送到手机的一次性代码。这在网上银行和电子邮件服务中很常见。
Strong password policies—minimum length, mixture of character types, regular changes—are also fundamental. The CCEA syllabus expects candidates to describe these methods and compare their effectiveness.
强密码策略——最小长度、字符类型混合、定期更改——也是基础。CCEA 课程要求考生描述这些方法并比较其有效性。
8. Encryption Basics | 加密基础
Encryption is the process of converting plaintext into ciphertext using an algorithm and a key, so that only someone with the correct decryption key can read it. It ensures confidentiality of data both in transit and at rest.
加密是使用算法和密钥将明文转换为密文的过程,因此只有拥有正确解密密钥的人才能读取。它确保数据在传输和静止时的机密性。
The two main types are symmetric encryption (same key used to encrypt and decrypt) and asymmetric encryption (uses a public key for encryption and a private key for decryption). Symmetric is faster; asymmetric solves the key distribution problem.
两种主要类型是对称加密(使用相同密钥加密和解密)和非对称加密(使用公钥加密和私钥解密)。对称加密更快;非对称加密解决密钥分发问题。
- Plaintext: original readable data
- Ciphertext: encrypted, unreadable output
- Key: a parameter that controls the transformation
- 明文:原始可读数据
- 密文:加密后不可读的输出
- 密钥:控制转换的参数
9. Symmetric vs Asymmetric Encryption | 对称与非对称加密
In symmetric encryption, a single shared key is used. Both sender and receiver must possess the same secret key, which raises the challenge of secure key exchange. Common algorithms include AES and DES. It is efficient for bulk data encryption.
在对称加密中,使用一个共享密钥。发送方和接收方都必须拥有相同的秘密密钥,这带来了安全密钥交换的挑战。常见算法包括 AES 和 DES。它对批量数据加密高效。
Asymmetric encryption uses a key pair: a public key, which can be shared openly, and a private key, which is kept secret. A message encrypted with the public key can only be decrypted by the matching private key. This forms the basis of digital signatures and secure key exchange in protocols like TLS. RSA is a widely used asymmetric algorithm.
非对称加密使用密钥对:可公开分享的公钥和保密的私钥。用公钥加密的消息只能用对应的私钥解密。这构成了数字签名和 TLS 等协议中安全密钥交换的基础。RSA 是一种广泛使用的非对称算法。
| Feature | Symmetric | Asymmetric |
|---|---|---|
| Key | Single shared key | Public/private key pair |
| Speed | Fast | Slower |
| Key distribution | Difficult to share securely | Easy: public key can be shared openly |
Table: Comparison of Symmetric and Asymmetric Encryption
表:对称与非对称加密比较
10. Firewalls | 防火墙
A firewall is a network security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules. It acts as a barrier between a trusted internal network and an untrusted external network, such as the Internet.
防火墙是一种网络安全系统,根据预设的安全规则监控和控制进出网络流量。它在可信内部网络和不可信外部网络(如互联网)之间起到屏障作用。
Firewalls can be hardware-based, software-based or a combination of both. They filter packets, blocking those that do not meet the rules. For example, a firewall can be configured to block all incoming traffic on certain ports or from specific IP addresses.
防火墙可以是基于硬件的、基于软件的或二者组合。它们过滤数据包,阻止不符合规则的流量。例如,防火墙可配置为阻止某些端口或特定 IP 地址的所有传入流量。
They also log suspicious activity and help prevent unauthorised remote access. The syllabus requires students to understand the role of a firewall in a network security strategy, alongside anti-malware software and user access controls.
它们还记录可疑活动,帮助防止未经授权的远程访问。课程要求学生理解防火墙在网络安全策略中的作用,以及反恶意软件和用户访问控制。
11. Security Protocols: SSL/TLS and HTTPS | 安全协议:SSL/TLS 和 HTTPS
Secure Sockets Layer (SSL) and its successor Transport Layer Security (TLS) are cryptographic protocols designed to provide secure communication over a computer network. They are used extensively in web browsing, email and instant messaging.
安全套接层及其继任者传输层安全是旨在通过计算机网络提供安全通信的加密协议。它们广泛用于网页浏览、电子邮件和即时通讯。
HTTPS (HTTP Secure) is HTTP over TLS/SSL. When a website uses HTTPS, the data exchanged between the browser and the server is encrypted. This prevents eavesdropping and tampering. The padlock icon in the browser address bar indicates an HTTPS connection is active.
HTTPS 是基于 TLS/SSL 的 HTTP。当网站使用 HTTPS 时,浏览器和服务器之间交换的数据被加密。这防止了窃听和篡改。浏览器地址栏中的挂锁图标表示 HTTPS 连接激活。
During the TLS handshake, the client and server agree on encryption algorithms and exchange keys securely using asymmetric encryption. Subsequent data is then encrypted with faster symmetric encryption.
在 TLS 握手期间,客户端和服务器协商加密算法,并使用非对称加密安全地交换密钥。随后的数据则使用更快的对称加密进行加密。
12. Security Policies and Best Practices | 安全策略与最佳实践
Organisations implement comprehensive security policies to govern how data and networks are protected. These policies define acceptable use, access controls, password management, incident response and disaster recovery. They form the human aspect of security.
组织实施全面的安全策略来管理如何保护数据和网络。这些策略定义了可接受使用、访问控制、密码管理、事件响应和灾难恢复。它们构成了安全的人为方面。
Regular software updates and patch management close known vulnerabilities. Anti-malware software with real-time scanning detects and removes threats. Backing up data regularly ensures availability in case of ransomware or data corruption. User training reduces the risk of falling for social engineering attacks.
定期的软件更新和补丁管理关闭已知漏洞。具有实时扫描功能的反恶意软件检测并移除威胁。定期备份数据确保在勒索软件或数据损坏时的可用性。用户培训降低了遭受社会工程攻击的风险。
The syllabus emphasises the importance of a layered security approach: no single measure is sufficient. Combining firewalls, encryption, authentication and training creates a robust defence.
课程强调分层安全方法的重要性:没有单一措施足够。结合防火墙、加密、身份验证和培训可创建稳固的防御体系。
Published by TutorHao | IGCSE CCEA Computer Science Revision Series | aleveler.com
更多咨询请联系16621398022(同微信)
屏轩国际教育cambridge primary/secondary checkpoint, cat4, ukiset,ukcat,igcse,alevel,PAT,STEP,MAT, ibdp,ap,ssat,sat,sat2课程辅导,国外大学本科硕士研究生博士课程论文辅导Cancel reply