📚 IGCSE Edexcel Computer Science: Cybersecurity Core Concepts | IGCSE Edexcel 计算机:网络安全考点精讲
Cybersecurity focuses on protecting computer systems, networks and data from digital attacks, unauthorised access, damage or theft. For the IGCSE Edexcel Computer Science specification, you need to understand common threats and vulnerabilities, methods of attack, and the technical, procedural and physical safeguards used to defend against them. This revision guide breaks down every key concept into clear, exam-ready explanations with paired English and Chinese text.
网络安全重点在于保护计算机系统、网络和数据免受数字攻击、未经授权的访问、破坏或盗窃。在 IGCSE Edexcel 计算机科学考纲中,你需要理解常见的威胁与漏洞、攻击手段,以及用于防御的技术性、流程性和物理性防护措施。本复习指南将每个关键概念分解为清晰、适合考试的解释,并以中英对照形式呈现。
1. Types of Malware | 恶意软件的类型
Malware, short for malicious software, is any program designed to harm or exploit a computer system. The main types you need to recognise are viruses, worms, Trojan horses and spyware. A virus attaches itself to legitimate files and spreads when a user opens the file, often corrupting or deleting data. A worm replicates itself across networks without needing a host file, consuming bandwidth and potentially delivering a payload. A Trojan horse disguises itself as useful software but creates a backdoor for attackers once installed. Spyware secretly monitors user activity and collects sensitive information such as passwords.
恶意软件(Malware)意为“恶意软件”,指任何旨在损害或利用计算机系统的程序。你需要识别的主要类型包括病毒、蠕虫、特洛伊木马和间谍软件。病毒会附着在合法文件上,当用户打开文件时传播,通常会损坏或删除数据。蠕虫无需宿主文件就能在网络上自我复制,消耗带宽并可能释放破坏性载荷。特洛伊木马伪装成有用软件,一旦安装便为攻击者创建后门。间谍软件则秘密监视用户活动,收集密码等敏感信息。
2. Phishing and Social Engineering | 网络钓鱼与社会工程学
Social engineering exploits human psychology rather than technical weaknesses to gain unauthorised access. Phishing is the most common form, where attackers send emails or messages pretending to be a trusted organisation to trick users into revealing login credentials or financial details. Spear phishing targets specific individuals using personal information. Other techniques include baiting (offering a free download that installs malware) and pretexting (inventing a scenario to obtain private information). Organisations train staff to recognise suspicious requests and never share sensitive data via email.
社会工程学利用的是人的心理而非技术弱点来获取未经授权的访问。网络钓鱼是最常见的形式,攻击者发送冒充可信机构的电子邮件或消息,诱骗用户泄露登录凭据或财务详情。鱼叉式钓鱼利用个人信息针对特定个人。其他手法包括诱饵(提供免费下载,实则安装恶意软件)和假托(编造情境以获取私人信息)。机构通过培训员工识别可疑请求,绝不通过电子邮件分享敏感数据。
3. Denial of Service and Distributed Denial of Service | 拒绝服务与分布式拒绝服务攻击
A Denial of Service (DoS) attack aims to make a network or server unavailable by overwhelming it with traffic. In a Distributed DoS (DDoS) attack, the attacker uses a botnet — a network of compromised devices — to flood the target simultaneously. This exhausts bandwidth, CPU or memory, preventing legitimate users from accessing the service. Mitigation techniques include traffic filtering, rate limiting, and using Content Delivery Networks to absorb the load. Understanding the difference between a single-source DoS and a multi-source DDoS is a common exam requirement.
拒绝服务攻击(DoS)旨在通过用流量淹没网络或服务器,使其无法使用。在分布式拒绝服务攻击(DDoS)中,攻击者利用僵尸网络(由被攻陷的设备组成的网络)同时向目标发起洪水式攻击。这会耗尽带宽、CPU 或内存,使合法用户无法访问服务。缓解技术包括流量过滤、速率限制,以及使用内容分发网络吸收负载。理解源自单一来源的 DoS 与多来源的 DDoS 之间的区别是常见的考试要求。
4. Brute Force Attacks and Password Security | 暴力攻击与密码安全
A brute force attack attempts to guess a password by systematically trying every possible combination until the correct one is found. To defend against this, systems implement account lockout after a certain number of failed attempts and enforce strong password policies. A strong password typically contains a mix of uppercase and lowercase letters, numbers, and symbols, and is at least eight characters long. Multi-factor authentication (MFA) adds an extra layer of protection by requiring a second factor such as a code from a smartphone app or a biometric scan. This makes unauthorised access vastly more difficult even if a password is compromised.
暴力攻击通过系统地尝试每个可能的组合来猜测密码,直到找到正确的那一个。为了防御这种攻击,系统会在一定次数的失败尝试后锁定账户,并强制执行强密码策略。强密码通常包含大小写字母、数字和符号的混合,长度至少为八个字符。多因素认证(MFA)通过要求第二个因素(例如手机应用中的验证码或生物特征扫描)来增加一层额外的保护。即使密码泄露,这也使未经授权的访问变得极其困难。
5. Encryption: Symmetric vs Asymmetric | 加密:对称加密与非对称加密
Encryption scrambles data into an unreadable format using an algorithm and a key, ensuring that only authorised parties can decode it. In symmetric encryption, the same key is used for both encryption and decryption. It is fast and efficient for bulk data, but securely sharing the key is a challenge. Asymmetric encryption, also known as public-key cryptography, uses a pair of keys: a public key to encrypt and a private key to decrypt. The private key is never shared, solving the key distribution problem. SSL/TLS protocols that secure web traffic rely on asymmetric encryption to establish a secure session and then switch to symmetric encryption for speed.
加密使用算法和密钥将数据打乱成不可读的格式,确保只有授权方才能解码。在对称加密中,加密和解密使用同一把密钥。它对大量数据快速高效,但安全地共享密钥是一个难题。非对称加密也称为公钥密码术,使用一对密钥:公钥用于加密,私钥用于解密。私钥从不共享,解决了密钥分发问题。保护网络流量的 SSL/TLS 协议正是依靠非对称加密建立安全会话,然后转为对称加密以提升速度。
| Feature | Symmetric | Asymmetric |
|---|---|---|
| Keys | One shared key | Public + private key pair |
| Speed | Faster | Slower |
| Key distribution | Difficult | Easy (public key can be freely shared) |
Table: Comparison of symmetric and asymmetric encryption | 表:对称与非对称加密对比
6. Firewalls and Proxy Servers | 防火墙与代理服务器
A firewall monitors incoming and outgoing network traffic and blocks or allows data packets based on predefined security rules. It acts as a barrier between a trusted internal network and untrusted external networks, such as the Internet. Firewalls can be hardware appliances or software-based. A proxy server acts as an intermediary between a user and the Internet. Requests from clients go to the proxy, which forwards them using its own IP address. This hides the user’s real IP address and can also cache frequently accessed content, filter web traffic, and enforce access policies. Both devices are fundamental to network defence.
防火墙监控进出网络流量,并根据预定义的安全规则阻止或允许数据包。它充当受信任的内部网络与不受信任的外部网络(如互联网)之间的屏障。防火墙可以是硬件设备,也可以是软件形式。代理服务器充当用户与互联网之间的中介。客户端的请求先发送到代理服务器,后者用自己的 IP 地址转发请求。这隐藏了用户的真实 IP 地址,还能缓存常用内容、过滤网络流量并执行访问策略。这两种设备都是网络防御的基础。
7. Anti-malware Software and Patch Management | 反恶意软件与补丁管理
Anti-malware software detects, quarantines and removes malicious programs from a computer. It uses signature-based detection (comparing files against a database of known malware) and heuristic analysis (examining the behaviour of programs to identify new, unknown threats). Regular updates are essential because new malware variants appear constantly. Patch management ensures that operating systems and applications receive updates that fix security vulnerabilities. Many attacks exploit known flaws for which patches already exist, so a regular update schedule greatly reduces risk. An unpatched system is an open invitation to attackers.
反恶意软件能够检测、隔离和移除计算机中的恶意程序。它使用基于签名的检测(将文件与已知恶意软件数据库进行比对)和启发式分析(检查程序行为以识别未知的新威胁)。由于新变种不断出现,定期更新至关重要。补丁管理确保操作系统和应用程序收到修复安全漏洞的更新。许多攻击利用的是已有补丁的已知漏洞,因此定期更新可大大降低风险。未打补丁的系统无异于向攻击者敞开大门。
8. Authentication Methods and Access Control | 认证方法与访问控制
Authentication verifies the identity of a user or device. The three main factors are something you know (password, PIN), something you have (smart card, security token), and something you are (biometrics: fingerprint, iris scan). Two-factor authentication (2FA) combines two of these factors, greatly improving security. Access control lists (ACLs) define which users or groups can access specific files, applications or network resources and what operations they can perform (read, write, execute). Proper authentication and access control form the foundation of a secure system.
认证验证用户或设备的身份。三大主要因素分别是:你知道的东西(密码、PIN 码)、你拥有的东西(智能卡、安全令牌)以及你自身的东西(生物特征:指纹、虹膜扫描)。双因素认证(2FA)结合其中两个因素,大大提高安全性。访问控制列表(ACL)定义了哪些用户或组能够访问特定的文件、应用程序或网络资源,以及他们可以执行哪些操作(读、写、执行)。正确的认证与访问控制构成了安全系统的基础。
9. Data Backup and Disaster Recovery | 数据备份与灾难恢复
Backing up data means creating copies of important information that can be restored in the event of data loss due to cyberattacks, hardware failure or human error. Backups can be full (complete copy of all data), incremental (only changes since the last backup) or differential (changes since the last full backup). The 3-2-1 rule is a best practice: keep at least three copies of data, on two different media, with one copy stored offsite. A disaster recovery plan outlines the procedures to restore IT services after a major incident, specifying recovery time objectives (RTO) and recovery point objectives (RPO).
备份数据意味着创建重要信息的副本,当数据因网络攻击、硬件故障或人为错误而丢失时,可以恢复这些副本。备份可以是完全备份(所有数据的完整副本)、增量备份(仅自上次备份以来的更改)或差异备份(自上次完全备份以来的更改)。3-2-1 规则是一项最佳实践:至少保留三份数据,存储在两种不同的介质上,其中一份存放在异地。灾难恢复计划概述了重大事件后恢复 IT 服务的流程,明确了恢复时间目标(RTO)和恢复点目标(RPO)。
10. Security Policies and Acceptable Use | 安全策略与可接受使用
Organisations implement security policies to govern how employees should handle sensitive data, use network resources and respond to security incidents. An acceptable use policy (AUP) defines what users are allowed and not allowed to do on the company’s IT systems, such as restrictions on personal use, social media access and downloading unauthorised software. Other policies include password policies, data encryption policies and bring your own device (BYOD) policies. These documents are a crucial part of procedural security and are often examined in the context of how they prevent internal threats.
组织通过实施安全策略来规范员工如何处理敏感数据、使用网络资源以及响应安全事件。可接受使用策略(AUP)定义了用户在公司 IT 系统上允许和不允许做的事情,例如限制个人使用、社交媒体访问和下载未经授权的软件。其他策略还包括密码策略、数据加密策略和自带设备(BYOD)策略。这些文件是流程性安全的关键部分,考试中经常考查其在防范内部威胁方面的作用。
11. Data Integrity and Checksums | 数据完整性与校验和
Data integrity means ensuring that data remains accurate, consistent and unaltered during storage or transmission. A checksum is a simple way to verify integrity: an algorithm produces a small fixed-size value (hash) based on the data. The receiver recalculates the checksum and compares it with the transmitted value; any difference indicates corruption or tampering. Cryptographic hash functions like SHA-256 are more secure and are used in digital signatures and blockchain. In IGCSE exams, you may be asked to explain how a checksum works and why it is important for detecting accidental errors or deliberate modification.
数据完整性指确保数据在存储或传输过程中保持准确、一致且未被篡改。校验和是一种简单的完整性验证方法:算法根据数据生成一个小型的定长值(哈希)。接收方重新计算校验和并与传输来的值进行比较;任何差异都表示数据损坏或被篡改。像 SHA-256 这样的加密哈希函数更安全,用于数字签名和区块链。在 IGCSE 考试中,可能会要求你解释校验和的工作原理,以及它对于检测意外错误或故意篡改为何重要。
12. Revision Summary: Layered Security | 复习总结:分层安全
Effective cybersecurity relies on defence in depth — multiple layers of protection so that if one layer fails, another still stands. Technical controls include firewalls, encryption, anti-malware and intrusion detection systems. Procedural controls cover policies, training and incident response. Physical controls involve locks, CCTV and secure server rooms. When you describe a security measure, always mention its purpose and how it specifically reduces risk. The IGCSE exam rewards clear, structured answers that link threats to countermeasures.
有效的网络安全依赖于纵深防御——多层次的保护,这样即使一层失效,其他层仍然有效。技术控制包括防火墙、加密、反恶意软件和入侵检测系统。流程性控制涵盖策略、培训和事件响应。物理控制涉及门锁、闭路电视监控和安全的服务器机房。在描述安全措施时,务必提及它的目的,以及它如何具体地降低风险。IGCSE 考试青睐能够将威胁与对策联系起来、条理清晰的答案。
Published by TutorHao | Computer Science Revision Series | aleveler.com
更多咨询请联系16621398022(同微信)
屏轩国际教育cambridge primary/secondary checkpoint, cat4, ukiset,ukcat,igcse,alevel,PAT,STEP,MAT, ibdp,ap,ssat,sat,sat2课程辅导,国外大学本科硕士研究生博士课程论文辅导