Cyber Security for GCSE OCR Computer Science | GCSE OCR 计算机:网络安全考点精讲

📚 Cyber Security for GCSE OCR Computer Science | GCSE OCR 计算机:网络安全考点精讲

In the digital age, protecting data and systems from unauthorised access, theft, and damage is a fundamental concern. Cyber security encompasses all the technologies, processes, and practices designed to defend networks, computers, programs, and data from attack, damage, or unauthorised access. For GCSE OCR Computer Science, you need to understand the range of threats, the methods used by attackers, and the defensive measures that organisations must implement to keep information safe.

在数字时代,保护数据和系统免受未经授权的访问、窃取和损害是根本性的问题。网络安全涵盖了旨在保护网络、计算机、程序和数据免受攻击、损害或未经授权访问的所有技术、流程和实践。对于 GCSE OCR 计算机科学而言,你需要了解各种威胁、攻击者使用的方法以及组织必须实施哪些防御措施来确保信息安全。

1. What is Cyber Security? | 什么是网络安全?

Cyber security refers to the body of technologies, processes and practices designed to protect networks, devices, programs and data from attack, damage or unauthorised access. It is often broken down into several key areas: network security, application security, information security, operational security, disaster recovery and end-user education. The goal is to maintain the confidentiality, integrity and availability of data — often referred to as the CIA triad.

网络安全是指旨在保护网络、设备、程序和数据免受攻击、损害或未经授权访问的一系列技术、流程和实践。它通常分解为几个关键领域:网络安全、应用安全、信息安全、运营安全、灾难恢复和最终用户教育。其目标是保持数据的机密性、完整性和可用性——通常称为 CIA 三元组。

Confidentiality ensures that information is accessible only to those authorised to view it. Integrity assures that data remains accurate and unaltered by unauthorised parties, while availability guarantees that information and resources are accessible to authorised users when needed. A breach of any of these can have severe consequences, from financial loss to reputational damage.

机密性确保信息只有授权人员才能访问。完整性保证数据保持准确、不被未经授权方篡改,而可用性则保证授权用户在需要时可访问信息和资源。任何一项被破坏都可能导致严重后果,从经济损失到声誉损害。


2. Malware | 恶意软件

Malware is malicious software intentionally designed to cause damage to a computer, server, client, or computer network. The most common types of malware that GCSE students must be familiar with include viruses, worms, trojans, ransomware, spyware and adware.

恶意软件是蓄意设计用于对计算机、服务器、客户端或计算机网络造成损害的恶意软件。GCSE 学生必须熟悉的最常见恶意软件类型包括病毒、蠕虫、特洛伊木马、勒索软件、间谍软件和广告软件。

A virus attaches itself to clean files and spreads throughout a computer system, often corrupting files and degrading performance. A worm is similar but can replicate itself without a host program and spread across networks, exploiting vulnerabilities. A trojan disguises itself as legitimate software to trick users into installing it, then opens a backdoor for attackers. Ransomware encrypts a user’s files and demands payment for the decryption key, while spyware secretly monitors user activity and collects personal information. Adware displays unwanted advertisements, often bundled with free software.

病毒将自身附着在干净文件上,并在整个计算机系统中传播,通常会破坏文件并降低性能。蠕虫类似,但无需宿主程序即可自我复制并利用漏洞在网络上传播。特洛伊木马伪装成合法软件,诱骗用户安装,然后为攻击者打开后门。勒索软件加密用户的文件并要求支付赎金以获取解密密钥,间谍软件则秘密监视用户活动并收集个人信息。广告软件显示不需要的广告,通常与免费软件捆绑在一起。

Anti-malware software uses signature-based detection, heuristic analysis and real-time protection to identify and block these threats. Keeping operating systems and applications up to date is also critical, as many malware attacks exploit known vulnerabilities that have already been patched by vendors.

反恶意软件使用基于签名的检测、启发式分析和实时保护来识别和阻止这些威胁。保持操作系统和应用程序更新同样至关重要,因为许多恶意软件攻击利用供应商已修复的已知漏洞。


3. Social Engineering | 社会工程学

Social engineering is the psychological manipulation of people into performing actions or divulging confidential information. Instead of exploiting technical vulnerabilities, attackers exploit human nature. Phishing is the most widespread form, typically through emails that appear to come from a trustworthy source, asking the recipient to click a link or provide personal details.

社会工程学是指通过心理操纵使人们执行操作或泄露机密信息。攻击者并非利用技术漏洞,而是利用人性。网络钓鱼是最普遍的形式,通常通过看似来自可靠来源的电子邮件,要求收件人点击链接或提供个人信息。

Spear phishing targets specific individuals or organisations, using personalized information to appear more convincing. Pretexting involves creating a fabricated scenario to obtain information, such as pretending to be an IT support technician. Baiting uses an appealing promise, like free software downloads, to lure victims into a trap, while tailgating (or piggybacking) involves an unauthorised person following an employee into a secure area without proper authentication.

鱼叉式网络钓鱼针对特定个人或组织,利用个性化信息使其更具说服力。借口(pretexting)涉及编造情景以获取信息,例如伪装成 IT 支持技术人员。诱饵(baiting)使用诱人的承诺,如免费软件下载,引诱受害者落入陷阱;尾随(tailgating,也称 piggybacking)则是未经授权的人员跟随员工进入安全区域,而不进行适当身份验证。

Training employees to recognise these tactics and implementing strict verification procedures are the most effective defences against social engineering. Organisations should also adopt policies such as strong password practices and the principle of least privilege.

培训员工识别这些手法并实施严格的验证程序,是抵御社会工程学攻击最有效的防御措施。组织还应采纳强密码实践和最小权限原则等策略。


4. Types of Network Attacks | 网络攻击类型

Beyond malware and social engineering, networks face a variety of technical attacks. A denial-of-service (DoS) attack floods a server or network with excessive traffic, causing it to become unavailable to legitimate users. A distributed denial-of-service (DDoS) attack uses multiple compromised systems — often a botnet — to launch the attack, making it much harder to stop.

除了恶意软件和社会工程学,网络还面临着各种技术攻击。拒绝服务攻击(DoS)用过多流量淹没服务器或网络,使其无法为合法用户提供服务。分布式拒绝服务攻击(DDoS)使用多个被攻陷的系统——通常是僵尸网络——发起攻击,使其更难阻止。

A man-in-the-middle (MITM) attack occurs when an attacker secretly intercepts and possibly alters communication between two parties who believe they are directly communicating. Packet sniffing is the practice of capturing data packets as they travel across a network, potentially revealing sensitive information if traffic is unencrypted. SQL injection is a code injection technique used to attack data-driven applications, in which malicious SQL statements are inserted into an entry field for execution.

中间人攻击(MITM)是指攻击者秘密拦截并可能篡改通信双方的信息,而双方都以为彼此是直接通信。数据包嗅探是在数据包穿越网络时进行捕获,如果流量未加密,可能暴露敏感信息。SQL 注入是一种代码注入技术,用于攻击数据驱动的应用程序,将恶意 SQL 语句插入输入字段中执行。

Brute force attacks systematically attempt all possible passwords or encryption keys until the correct one is found. A dictionary attack uses a list of common words and phrases, increasing efficiency. To defend against such attacks, rate limiting, account lockout policies and strong password requirements are critical.

暴力攻击系统地尝试所有可能的密码或加密密钥,直至找到正确的一个。字典攻击使用常用单词和短语的列表,以提高效率。要防范此类攻击,速率限制、账户锁定策略和强密码要求至关重要。


5. Authentication and Authorization | 身份验证与授权

Authentication is the process of verifying the identity of a user or system. Common methods include something you know (password, PIN), something you have (smart card, token, mobile device) and something you are (biometric data such as fingerprints, retina scans, facial recognition). Multi-factor authentication (MFA) combines two or more of these categories, significantly improving security.

身份验证是验证用户或系统身份的过程。常用方法包括你知道的东西(密码、PIN)、你拥有的东西(智能卡、令牌、移动设备)以及你本身的东西(生物特征数据,如指纹、视网膜扫描、面部识别)。多因素认证(MFA)结合了其中两个或更多类别,显著提高了安全性。

Authorization, on the other hand, determines what an authenticated user is permitted to do. This is typically managed through access control lists (ACLs) and user permissions. The principle of least privilege states that users should only be granted the minimum permissions necessary to perform their job functions, limiting the potential damage from errors or breaches.

授权则是确定经过身份验证的用户被允许做什么。通常通过访问控制列表(ACL)和用户权限进行管理。最小权限原则指出,用户只应被授予执行其工作职能所需的最小权限,从而限制因错误或违规行为可能造成的损害。

Captcha systems are often used to distinguish human users from automated bots, preventing automated password guessing or spam account creation. Biometric authentication offers strong identity verification but raises privacy concerns if biometric data is not stored securely.

验证码系统常用于区分人类用户和自动化机器人,防止自动密码猜测或垃圾账户创建。生物特征认证提供了强有力的身份验证,但若生物特征数据存储不安全,会引发隐私问题。


6. Firewalls and Intrusion Detection Systems | 防火墙与入侵检测系统

A firewall is a network security system that monitors and controls incoming and outgoing network traffic based on predetermined security rules. It acts as a barrier between a trusted internal network and untrusted external networks, such as the Internet. Firewalls can be hardware-based, software-based, or a combination of both.

防火墙是一种网络安全系统,根据预设的安全规则监视和控制传入和传出的网络流量。它在可信的内部网络和不可信的外部网络(例如互联网)之间充当屏障。防火墙可以是基于硬件的、基于软件的,或两者结合。

Packet-filtering firewalls examine packets in isolation, allowing or blocking based on source and destination IP addresses, ports and protocols. Stateful inspection firewalls track the state of active connections and make decisions based on the context of the traffic, offering better security. Application-layer firewalls (or proxy firewalls) inspect the payload of packets at the application layer, which can prevent more sophisticated attacks. Intrusion detection systems (IDS) monitor network traffic for suspicious activity and issue alerts, while intrusion prevention systems (IPS) can automatically take action to block threats.

包过滤防火墙独立检查数据包,根据源和目标 IP 地址、端口和协议进行允许或阻止。状态检测防火墙跟踪活动连接的状态,并根据流量上下文做出决策,提供更好的安全性。应用层防火墙(或代理防火墙)检查应用层数据包的负载,可以防止更复杂的攻击。入侵检测系统(IDS)监控网络流量中的可疑活动并发出警报,而入侵防御系统(IPS)则可自动采取措施阻止威胁。

An organisation will often deploy a demilitarised zone (DMZ), a perimeter network that exposes external-facing services to the Internet while keeping the internal network behind an additional firewall. This segmentation limits the attack surface.

组织通常会部署一个非军事区(DMZ),这是一个边界网络,将面向外部的服务暴露给互联网,同时将内部网络保留在另一个防火墙后。这种分段限制了攻击面。


7. Encryption | 加密技术

Encryption is the process of converting data into a coded form to prevent unauthorised access. Plaintext is transformed into ciphertext using an algorithm and a key, and only parties who possess the appropriate key can decrypt the data back to its original form. Encryption is fundamental to securing data both at rest (stored on a device or server) and in transit (being sent across a network).

加密是将数据转换为编码形式以防止未经授权访问的过程。使用算法和密钥,将明文转换为密文,只有拥有适当密钥的方才能将数据解密回原始形式。加密对于保护静态数据(存储在设备或服务器上)和传输中的数据(通过网络发送)至关重要。

Symmetric encryption uses the same key for both encryption and decryption. While fast and efficient for bulk data, it requires a secure method of key exchange. Asymmetric encryption, also known as public-key cryptography, uses a pair of keys: a public key for encryption and a private key for decryption. This solves the key exchange problem but is more computationally intensive. A common approach is to use asymmetric encryption to exchange a symmetric session key, which is then used for the rest of the communication (hybrid encryption).

对称加密使用相同的密钥进行加密和解密。虽然对于批量数据来说快速且高效,但它需要一种安全的密钥交换方法。非对称加密,也称为公钥密码学,使用一对密钥:公钥用于加密,私钥用于解密。这解决了密钥交换问题,但对计算要求更高。常见的做法是使用非对称加密交换对称会话密钥,然后将其用于其余通信(混合加密)。

Hashing is a related concept: a mathematical function that converts input data into a fixed-size string of characters, which is practically irreversible. Hashes are used to store passwords securely; when a user logs in, the password is hashed and compared to the stored hash, without the system ever storing the plaintext password.

哈希是一个相关概念:一种数学函数,将输入数据转换为固定长度的字符串,实际上不可逆。哈希用于安全存储密码;用户登录时,密码被哈希后与存储的哈希值进行比较,系统从不存储明文密码。


8. Security Policies and Backups | 安全策略与备份

An organisation’s security policy is a formal document that outlines the rules, standards and practices for protecting its information assets. It covers areas such as acceptable use of resources, password management, remote access, incident response and data classification. Employees are expected to adhere to these policies, and regular training reinforces awareness.

组织的安全策略是一份正式文件,概述了保护其信息资产的规则、标准和实践。它涵盖资源可接受使用、密码管理、远程访问、事件响应和数据分类等领域。员工须遵守这些策略,定期培训可增强安全意识。

A robust backup strategy is a critical component of cyber resilience. The 3-2-1 rule is widely recommended: maintain at least three copies of data, store them on two different types of media, with one copy kept offsite. Regular backups allow recovery from ransomware attacks, hardware failure or accidental deletion. Backups should be tested periodically to ensure data can be restored successfully.

稳健的备份策略是网络韧性的关键组成部分。广泛推荐的 3-2-1 规则:至少保留三份数据副本,将它们存储在两种不同类型的介质上,并保持一份异地副本。定期备份可让你从勒索软件攻击、硬件故障或意外删除中恢复。备份应定期测试,以确保数据能够成功恢复。

Disaster recovery plans detail how an organisation will respond to and recover from cyber incidents. They include recovery time objectives (RTO) and recovery point objectives (RPO) — the maximum acceptable time to restore operations and the maximum acceptable amount of data loss, respectively. Penetration testing and vulnerability scanning are proactive measures that simulate attacks to identify weaknesses before malicious actors do.

灾难恢复计划详细说明了组织将如何响应和恢复网络事件。包括恢复时间目标(RTO)和恢复点目标(RPO)——分别是恢复操作的最大可接受时间和可接受的最大数据丢失量。渗透测试和漏洞扫描是模拟攻击的主动措施,以便在恶意行为者之前发现弱点。


9. Physical Security and Access Control | 物理安全与访问控制

While much of cyber security focuses on digital threats, physical security is equally important. If an attacker can gain physical access to a server, network switch or workstation, they can bypass many logical controls. Physical security measures include locks, security guards, biometric door access, CCTV surveillance and secure hardware disposal procedures.

尽管网络安全大多关注数字威胁,但物理安全同样重要。如果攻击者能够物理访问服务器、网络交换机或工作站,就可以绕过许多逻辑控制。物理安全措施包括门锁、保安、生物特征门禁、闭路电视监控和安全硬件处置程序。

Access control mechanisms ensure that only authorised individuals can enter sensitive areas. Mantrap systems, for example, allow only one person to enter at a time, preventing tailgating. Shredding of printed documents and secure erasure of storage devices before disposal prevent data leakage. A clean desk policy requires employees to lock away sensitive documents when not at their desks, reducing the risk of unauthorised viewing.

访问控制机制确保只有授权人员才能进入敏感区域。例如,防尾随闸门系统一次只允许一人进入,防止尾随。在销毁前粉碎打印文件并安全擦除存储设备,可防止数据泄露。整洁桌面政策要求员工在不使用桌面时将敏感文件锁好,降低未经授权查看的风险。

Environmental controls also fall under physical security. Fire suppression systems, uninterruptible power supplies (UPS) and climate control protect hardware from damage, thereby safeguarding the availability of data and services.

环境控制也属于物理安全范畴。灭火系统、不间断电源(UPS)和气候控制保护硬件免受损坏,从而保障数据和服务的可用性。


10. Importance of Cyber Security and Legislation | 网络安全的重要性与立法

The consequences of cyber security failures can be catastrophic: financial losses, theft of intellectual property, legal penalties, and loss of customer trust. For GCSE OCR, you must understand that cyber security is not just a technical issue but a business and societal one. The General Data Protection Regulation (GDPR) imposes strict rules on how organisations collect, store and process personal data, with heavy fines for non-compliance. The Computer Misuse Act 1990 in the UK makes unauthorised access to computer systems, with or without further criminal intent, a criminal offence.

网络安全失败的后果可能是灾难性的:经济损失、知识产权被盗、法律处罚以及客户信任的丧失。对于 GCSE OCR,你必须理解网络安全不仅是技术问题,也是商业和社会问题。《通用数据保护条例》(GDPR)对组织收集、存储和处理个人数据的方式施加了严格规定,违规者将面临巨额罚款。英国 1990 年《计算机滥用法》将未经授权访问计算机系统(无论是否有进一步的犯罪意图)定为刑事犯罪。

Individuals also have a responsibility to practice good cyber hygiene: using strong, unique passwords; enabling MFA; keeping software updated; being cautious with email attachments and links; and regularly backing up important data. Cyber security is a shared responsibility that requires a combination of technology, processes and people to be effective.

个人也有责任养成良好的网络卫生习惯:使用强且唯一的密码;启用多因素认证;保持软件更新;谨慎对待电子邮件附件和链接;定期备份重要数据。网络安全是一项共同责任,需要技术、流程和人的有效结合才能实现。

Published by TutorHao | GCSE OCR Computer Science Revision Series | aleveler.com

更多咨询请联系16621398022(同微信)

Comments

屏轩国际教育cambridge primary/secondary checkpoint, cat4, ukiset,ukcat,igcse,alevel,PAT,STEP,MAT, ibdp,ap,ssat,sat,sat2课程辅导,国外大学本科硕士研究生博士课程论文辅导Cancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from aleveler.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Exit mobile version