📚 Cybersecurity for A-Level WJEC Computer Science | 网络安全考点精讲
Cybersecurity is a central pillar of modern computing and a key examination topic in the WJEC A-Level Computer Science specification. This article provides a focused revision guide covering threats, vulnerabilities, protection mechanisms, cryptographic principles, and the legal and ethical framework surrounding data protection. Whether you are preparing for a written paper or tackling coursework involving network security, mastering these concepts will give you a solid foundation.
网络安全是现代计算的核心支柱,也是 WJEC A-Level 计算机科学大纲中的重要考点。本文提供一份重点复习指南,涵盖威胁、漏洞、防护机制、加密原理以及围绕数据保护的法律与伦理框架。无论你是在准备笔试试卷,还是在完成涉及网络安全的课程作业,掌握这些概念都将为你打下坚实基础。
1. The CIA Triad: Confidentiality, Integrity, Availability | CIA 三元组:保密性、完整性、可用性
The fundamental objectives of cybersecurity are often summarised as the CIA triad. Confidentiality ensures that information is only accessible to authorised users, generally enforced through encryption and access controls. Integrity guarantees that data has not been tampered with during storage or transmission, often verified through hashing. Availability means that systems and data are accessible when needed, protected against denial-of-service attacks and hardware failures.
网络安全的基本目标通常被概括为 CIA 三元组。保密性确保信息仅对授权用户开放,通常通过加密和访问控制来实施。完整性保证数据在存储或传输过程中未被篡改,通常通过哈希进行验证。可用性意味着系统和数据在需要时可访问,并受到保护以抵御拒绝服务攻击和硬件故障。
2. Threat Actors and Their Motivations | 威胁行为者及其动机
Threat actors vary widely: script kiddies use pre-written tools without deep knowledge; hacktivists pursue political or social goals; organised crime groups seek financial gain through ransomware or data theft; nation-states engage in espionage or cyber warfare; and insiders abuse legitimate access. Understanding motivation helps in assessing the risk profile and selecting appropriate defences.
威胁行为者种类繁多:脚本小子使用现成工具而缺乏深层知识;黑客活动分子追求政治或社会目标;有组织犯罪集团通过勒索软件或数据窃取谋求经济利益;国家行为体从事间谍活动或网络战;内部人员则滥用合法访问权限。了解动机有助于评估风险状况并选择适当的防御手段。
3. Malware: Viruses, Worms, Trojans, Ransomware and Spyware | 恶意软件:病毒、蠕虫、木马、勒索软件与间谍软件
Malware is malicious software designed to disrupt, damage or gain unauthorised access. A virus attaches itself to legitimate programs and spreads when the host is executed. A worm self-replicates across networks without needing a host file. Trojans masquerade as useful software. Ransomware encrypts victim data and demands payment. Spyware covertly monitors user activity. WJEC expects you to describe the behaviour, propagation method and impact of each type, and to suggest suitable countermeasures such as antivirus, firewalls and user education.
恶意软件是旨在破坏、损害或获取未授权访问的恶意软件。病毒附着在合法程序上,当宿主执行时传播。蠕虫无需宿主文件即可在网络上自我复制。木马伪装成有用软件。勒索软件加密受害者数据并要求赎金。间谍软件暗中监控用户活动。WJEC 要求你能够描述每种类型的行为、传播方式和影响,并提出相应的对策,例如防病毒软件、防火墙和用户教育。
4. Social Engineering and Phishing Attacks | 社会工程与网络钓鱼攻击
Social engineering exploits human psychology rather than technical vulnerabilities. Phishing emails attempt to trick recipients into revealing credentials or downloading malware by impersonating trusted entities. Spear phishing targets specific individuals, while vishing uses voice calls. Pretexting and baiting are other common techniques. Training and multi-factor authentication are the most effective defences.
社会工程利用的是人类心理而非技术漏洞。网络钓鱼邮件试图通过冒充可信实体来诱骗收件人泄露凭证或下载恶意软件。鱼叉式网络钓鱼针对特定个人,语音钓鱼则使用电话。借口和诱饵是其他常见伎俩。培训和多因素身份认证是最有效的防御手段。
5. Network-Based Attacks: DoS, DDoS, Man-in-the-Middle and Packet Sniffing | 基于网络的攻击:拒绝服务、分布式拒绝服务、中间人攻击与数据包嗅探
A denial-of-service (DoS) attack floods a server with traffic to exhaust resources. A distributed denial-of-service (DDoS) uses a botnet of compromised devices for greater scale. Man-in-the-middle (MITM) attacks intercept and potentially alter communication between two parties, often on unsecured Wi-Fi. Packet sniffing captures network traffic; if unencrypted, sensitive data can be read. Countermeasures include rate limiting, intrusion prevention systems, encryption (HTTPS, VPNs) and network segmentation.
拒绝服务攻击通过向服务器发送大量流量以耗尽资源。分布式拒绝服务攻击使用受感染设备组成的僵尸网络来扩大规模。中间人攻击截获并可能篡改双方之间的通信,通常发生在不安全的 Wi-Fi 上。数据包嗅探捕获网络流量;如果未加密,敏感数据可能被读取。对策包括速率限制、入侵防御系统、加密(HTTPS、VPN)和网络分段。
6. SQL Injection and Code Injection | SQL 注入与代码注入
SQL injection occurs when user input is incorporated into a database query without proper validation or parameterisation, allowing an attacker to manipulate the query to extract or modify data. Code injection extends this concept to other interpreted languages. WJEC questions often ask candidates to identify vulnerable code and propose fixes such as using prepared statements, input sanitisation and the principle of least privilege for database accounts.
SQL 注入是指用户输入在未经适当验证或参数化的情况下被纳入数据库查询,从而允许攻击者操纵查询以提取或修改数据。代码注入将这一概念扩展到其他解释型语言。WJEC 试题经常要求考生识别易受攻击的代码,并提出修复方案,如使用预编译语句、输入清理以及数据库账户的最小权限原则。
7. Encryption: Symmetric vs Asymmetric | 加密:对称与非对称
Encryption transforms plaintext into ciphertext using an algorithm and a key. Symmetric encryption uses the same key for encryption and decryption; it is fast and suitable for bulk data (e.g. AES). The key must be shared securely beforehand. Asymmetric encryption uses a key pair: a public key for encryption and a private key for decryption (e.g. RSA). It solves the key distribution problem but is slower. Hybrid systems use asymmetric encryption to exchange a symmetric session key.
加密使用算法和密钥将明文转换为密文。对称加密使用相同的密钥进行加密和解密;速度快,适用于大量数据(如 AES),但密钥需要事先安全共享。非对称加密使用密钥对:公钥用于加密,私钥用于解密(如 RSA)。它解决了密钥分发问题但速度较慢。混合系统使用非对称加密来交换对称会话密钥。
| Feature | 特性 | Symmetric | 对称 | Asymmetric | 非对称 |
|---|---|---|
| Keys used | 使用密钥 | Single shared key | 单一共享密钥 | Public & private key pair | 公私钥对 |
| Speed | 速度 | Fast | 快 | Slow | 慢 |
| Key distribution | 密钥分发 | Problematic | 成问题 | Public key can be openly shared | 公钥可公开共享 |
| Example | 示例 | AES, DES | RSA, ECC |
8. Hashing and Digital Signatures | 哈希与数字签名
A hash function produces a fixed-length digest from input data. It is one-way and deterministic; a small change in input drastically alters the output (avalanche effect). Common algorithms include SHA-256. Hashes are used to verify data integrity and store passwords securely (with salting). A digital signature uses the sender’s private key to encrypt a hash of the message; the recipient decrypts it with the sender’s public key, verifying both integrity and authenticity.
哈希函数根据输入数据生成固定长度的摘要。它是单向且确定性的;输入的微小变化会极大地改变输出(雪崩效应)。常见算法包括 SHA-256。哈希用于验证数据完整性以及安全存储密码(加盐)。数字签名使用发送方的私钥加密消息的哈希;接收方用发送方的公钥解密,从而验证完整性和真实性。
9. Firewalls, Proxy Servers and DMZ | 防火墙、代理服务器与隔离区
Firewalls filter incoming and outgoing traffic based on predefined rules, implemented either as software or hardware. A proxy server acts as an intermediary, hiding internal IP addresses and often providing content caching. A demilitarised zone (DMZ) is a sub-network that hosts public-facing services (web, email) while separating them from the internal network, adding an extra layer of protection.
防火墙根据预定义规则过滤进出流量,可通过软件或硬件实现。代理服务器充当中介,隐藏内部 IP 地址,通常还提供内容缓存。隔离区是一个子网,用于托管面向公众的服务(网页、电子邮件),同时将它们与内部网络隔离开来,从而增加一层防护。
10. Authentication Methods: Passwords, Biometrics and Two-Factor | 身份验证方法:密码、生物识别与双重因素
Authentication verifies a user’s identity. Something you know (passwords, PINs), something you have (security tokens, smart cards), and something you are (biometrics: fingerprint, iris, voice) are the three factor categories. Two-factor authentication (2FA) combines two categories, significantly reducing the risk of unauthorised access even if one factor is compromised. WJEC may ask you to evaluate the strengths and weaknesses of each method in terms of security, cost and usability.
身份验证用于核实用户身份。你知道的(密码、PIN)、你拥有的(安全令牌、智能卡)以及你本身(生物识别:指纹、虹膜、声音)是三类因素。双重因素认证结合了两类因素,即使其中一个因素被攻破,也能大幅降低未授权访问的风险。WJEC 可能会要求你从安全性、成本和易用性角度评估每种方法的优缺点。
11. Security Policies, Penetration Testing and Auditing | 安全策略、渗透测试与审计
Organisations enforce security through acceptable use policies, access control lists (ACLs) and regular staff training. Penetration testing simulates attacks to identify vulnerabilities before malicious actors do. Security audits review logs, configurations and compliance with standards. WJEC emphasises the importance of a proactive, layered security approach rather than relying on a single tool.
组织通过可接受使用策略、访问控制列表和定期员工培训来实施安全。渗透测试模拟攻击,以便在恶意行为者之前发现漏洞。安全审计审查日志、配置以及对标准的合规性。WJEC 强调采取主动、分层式安全方法的重要性,而不是依赖单一工具。
12. Legislation and Ethics: Data Protection Act, Computer Misuse Act, GDPR | 法律与伦理:数据保护法、计算机滥用法、通用数据保护条例
UK legislation shapes cybersecurity practice. The Computer Misuse Act 1990 criminalises unauthorised access, modification and the creation of malware. The Data Protection Act 2018 (DPA) and the UK GDPR set strict rules for processing personal data, requiring consent, transparency and the right to erasure. In an exam, you should be able to discuss how these laws affect system design, organisational policy and individual rights. Ethical considerations include responsible disclosure of vulnerabilities and balancing surveillance with privacy.
英国的法律塑造了网络安全的实践。《1990 年计算机滥用法》将未授权访问、修改数据以及制造恶意软件定为刑事犯罪。《2018 年数据保护法》和英国《通用数据保护条例》为处理个人数据设定了严格规则,要求同意、透明度和删除权。在考试中,你应该能够讨论这些法律如何影响系统设计、组织政策和个人权利。伦理考量包括负责任的漏洞披露以及在监控与隐私之间取得平衡。
Published by TutorHao | Computer Science Revision Series | aleveler.com
更多咨询请联系16621398022(同微信)
屏轩国际教育cambridge primary/secondary checkpoint, cat4, ukiset,ukcat,igcse,alevel,PAT,STEP,MAT, ibdp,ap,ssat,sat,sat2课程辅导,国外大学本科硕士研究生博士课程论文辅导Cancel reply