📚 IGCSE OCR Computer Science: Networking Fundamentals Exam Focus | IGCSE OCR 计算机:网络基础 考点精讲
Networks are the backbone of modern computing, connecting devices to share data, resources, and services. In the OCR IGCSE Computer Science specification, a solid understanding of networking concepts is crucial. This guide breaks down every essential topic, from network types and topologies to protocols, security, and the hardware that makes it all work. We explore both the theoretical principles and their real-world applications, ensuring you are fully prepared for exam questions on networking fundamentals.
网络是现代计算的骨干,连接设备以共享数据、资源和服务。在 OCR IGCSE 计算机科学规范中,牢固掌握网络概念至关重要。本指南将详细解析每个核心主题,从网络类型和拓扑到协议、安全以及支撑网络的硬件。我们将探讨理论原理及其实际应用,确保你为网络基础考试题目做好充分准备。
1. What is a Network? | 什么是网络?
A network consists of two or more computing devices connected together to exchange data and share resources such as printers, internet connections, and file storage. Devices can be linked using cables (wired) or through radio waves (wireless). The key benefits include resource sharing, improved communication, and centralised data management.
网络由两台或多台计算设备连接在一起,以便交换数据并共享资源,例如打印机、互联网连接和文件存储。设备可以通过电缆(有线)或无线电波(无线)连接。其主要优点包括资源共享、沟通改善和数据集中管理。
Networks can be as small as a home setup with a few computers and a router, or as vast as the internet, which is a global network of networks. Understanding the scale and purpose of a network helps in choosing the right topology and hardware.
网络可以小到只有几台计算机和一个路由器的家庭设置,也可以大到像互联网这样的全球性网络。理解网络的规模和用途有助于选择正确的拓扑结构和硬件。
The two most common classifications are Local Area Networks (LANs) and Wide Area Networks (WANs). Additionally, networks can be categorised by their architecture: client-server or peer-to-peer. These terms form the foundation of the networking topic.
两种最常见的分类是局域网 (LAN) 和广域网 (WAN)。此外,网络还可以根据架构分类:客户端-服务器或对等网络。这些术语构成了网络主题的基础。
2. LAN vs WAN | 局域网与广域网
A LAN (Local Area Network) covers a small geographical area, such as a single building or a campus. It is typically owned and managed by a single organisation. LANs offer high data transfer speeds and low latency because the hardware can be dedicated and distances are short. Ethernet cables and Wi‑Fi are common in LANs.
局域网 (LAN) 覆盖较小的地理区域,例如一栋建筑或一个校园。它通常由单一组织拥有和管理。局域网提供高数据传输速度和低延迟,因为硬件可以专用且距离较短。以太网电缆和 Wi‑Fi 在局域网中很常见。
A WAN (Wide Area Network) spans large geographical distances, often connecting LANs across cities, countries, or continents. The internet is the largest WAN. WANs use telecommunication links like fibre optics, satellite, and leased lines. These connections are typically slower and more expensive than LAN links, but they are essential for global connectivity.
广域网 (WAN) 跨越较大的地理距离,通常连接不同城市、国家或大陆的局域网。最大的广域网是互联网。广域网使用光纤、卫星和专线等电信连接。这些连接通常比局域网链路更慢、更昂贵,但对于全球连接至关重要。
| Feature / 特性 | LAN / 局域网 | WAN / 广域网 |
|---|---|---|
| Area / 范围 | Small (building, campus) / 小 | Large (countries, continents) / 大 |
| Ownership / 所有权 | Single organisation / 单一组织 | Multiple providers / 多个提供商 |
| Transmission speed / 传输速度 | High (Gbps) / 高 | Lower (Mbps to Gbps) / 较低 |
| Typical technology / 典型技术 | Ethernet, Wi-Fi / 以太网、Wi-Fi | Fiber optic, satellite, MPLS / 光纤、卫星、MPLS |
Exam questions often ask you to compare LANs and WANs, so memorise the differences in terms of scale, speed, ownership, and technology. Remember that a WAN is essentially a network of LANs, with routers directing traffic across long distances.
考试题目经常要求比较局域网和广域网,因此要熟记它们在规模、速度、所有权和技术方面的区别。记住,广域网本质上是局域网的网络,路由器负责在长距离上引导流量。
3. Client-Server vs Peer-to-Peer Networks | 客户端-服务器与对等网络
In a client-server network, one or more powerful central computers (servers) provide services, such as file storage, authentication, and email, to multiple client devices. The server manages network resources and security. This model offers centralised control, easier data backup, and scalability, but it is more expensive due to the need for dedicated hardware and specialist staff.
在客户端-服务器网络中,一台或多台功能强大的中央计算机(服务器)为多个客户端设备提供服务,例如文件存储、身份验证和电子邮件。服务器管理网络资源和安全。该模型提供集中控制、更便捷的数据备份和可扩展性,但由于需要专用硬件和专业技术人员,成本更高。
In a peer-to-peer (P2P) network, all devices have equal status and can share resources directly with one another. No central server is needed. This is simpler and cheaper to set up, often used in small home networks. However, security is harder to maintain because there is no central authority, and data backup must be performed individually on each peer.
在对等 (P2P) 网络中,所有设备地位平等,可以直接相互共享资源,无需中央服务器。这种模式设置更简单、成本更低,常用于小型家庭网络。然而,由于没有中央权力机构,安全性更难维护,数据备份必须在每个对等点上单独进行。
You should be able to justify which model suits a given scenario. For a large school with hundreds of users, a client-server network is preferable for centralised management and security. For a small business with a few computers sharing files occasionally, a P2P setup may suffice and save costs.
你应该能够为给定场景选择合适模型。对于拥有数百名用户的大型学校,客户端-服务器网络更适合集中管理和安全。对于偶尔共享文件的几台计算机的小型企业,对等网络可能足够并节省成本。
4. Network Topologies | 网络拓扑结构
A network topology describes the physical or logical layout of connected devices. The main topologies you need to know for OCR are star, bus, ring, and mesh. Each has distinct advantages and drawbacks in terms of cost, reliability, and performance.
网络拓扑描述连接设备的物理或逻辑布局。OCR 考试需要掌握的主要拓扑包括星型、总线型、环状和网状。每种拓扑在成本、可靠性和性能方面各有优缺点。
Star topology: All devices connect to a central switch or hub. If one cable fails, only that device is affected; the rest of the network remains operational. It is easy to expand and troubleshoot. However, if the central device fails, the entire network goes down. Star is the most common topology in modern Ethernet LANs.
星型拓扑:所有设备连接到中央交换机或集线器。如果一根电缆故障,只有该设备受影响;网络其余部分仍能正常运行。它易于扩展和故障排除。然而,如果中央设备故障,整个网络将瘫痪。星型是现代以太网局域网中最常见的拓扑。
Bus topology: All devices share a single backbone cable. Data travels along the cable and terminators absorb signals at both ends. It is cheap and simple to install because it requires less cable than star. However, a break in the backbone cable can bring down the whole network, and performance degrades as more devices are added due to collisions.
总线型拓扑:所有设备共享一条主干电缆。数据沿电缆传输,终端器在两端吸收信号。由于比星型所需电缆更少,安装便宜且简单。然而,主干电缆断裂可能导致整个网络瘫痪,且随着设备增加,性能会因为冲突而下降。
Ring topology: Devices are connected in a closed loop. Data travels in one direction, passing through each device until it reaches its destination. It can handle high traffic without collisions using a token-passing mechanism, but a single device or cable failure can disrupt the entire network unless a dual-ring setup is used.
环状拓扑:设备连接成一个闭合环路。数据单向传输,依次经过每个设备直到到达目的地。通过令牌传递机制,它可以处理高流量而不会发生冲突,但单个设备或电缆故障可能打乱整个网络,除非使用双环配置。
Mesh topology: In a full mesh, every device is directly connected to every other device. This provides excellent redundancy: if one link fails, data can reroute through alternative paths. It is highly reliable, but extremely expensive due to the large amount of cabling and configuration. Partial mesh, where only some nodes are fully interconnected, is a more practical compromise, often used in WAN backbones.
网状拓扑:在全网状中,每台设备都与其他所有设备直接连接。这提供了极好的冗余:如果一条链路故障,数据可以通过替代路径重新路由。它高度可靠,但由于大量的布线和配置,成本极其昂贵。部分网状,其中只有部分节点完全互连,是更实用的折衷方案,常用于广域网骨干网。
5. Networking Hardware | 网络硬件
Several hardware components are vital for building and maintaining networks. You need to know the function of each device and where it is typically used. The main ones are:
构建和维护网络需要多个硬件组件。你需要了解每个设备的功能及其典型使用场景。主要硬件包括:
- Network Interface Card (NIC): Every device needs a NIC to connect to a network. It provides a unique MAC address and handles the conversion of data into electrical or radio signals. / 网络接口卡 (NIC):每个设备都需要 NIC 才能连接网络。它提供唯一的 MAC 地址,并负责将数据转换为电信号或无线电信号。
- Switch: A switch connects devices within a LAN and uses MAC addresses to forward data only to the intended recipient, reducing unnecessary traffic. It operates at the data link layer. / 交换机:交换机连接局域网内的设备,并使用 MAC 地址仅将数据转发给目标接收者,减少不必要的流量。它工作于数据链路层。
- Router: A router connects different networks, such as a home LAN to the internet. It forwards data packets based on IP addresses and maintains routing tables to determine the best path. / 路由器:路由器连接不同的网络,例如家庭局域网与互联网。它根据 IP 地址转发数据包,并维护路由表以确定最佳路径。
- Hub: An older device that broadcasts data to all connected devices. It is less efficient than a switch because it creates more collisions. / 集线器:一种较老的设备,将数据广播给所有连接的设备。它效率低于交换机,因为会产生更多冲突。
- Wireless Access Point (WAP): Allows Wi-Fi enabled devices to connect to a wired network. It bridges wireless and wired segments. / 无线接入点 (WAP):允许支持 Wi-Fi 的设备连接到有线网络。它桥接无线和有线网段。
- Modem: Converts digital data to analogue signals for transmission over telephone lines (modulation/demodulation). Often combined with a router in home broadband devices. / 调制解调器:将数字数据转换为模拟信号,以便通过电话线传输(调制/解调)。家庭宽带设备中常与路由器结合。
Understanding the OSI or TCP/IP layer at which each device operates helps to explain their roles. For example, a switch is a Layer 2 device, while a router is a Layer 3 device.
了解每种设备在 OSI 或 TCP/IP 模型中的工作层次有助于解释其作用。例如,交换机是第 2 层设备,而路由器是第 3 层设备。
6. The Internet and IP Addressing | 互联网与 IP 地址
The internet is a global WAN that uses the TCP/IP protocol suite to connect billions of devices. Every device on a network requires a unique IP address to send and receive data. The current main version is IPv4, using 32-bit addresses written in dotted decimal notation, e.g., 192.168.1.1. Due to address exhaustion, IPv6 was developed, using 128-bit hexadecimal addresses, providing a vastly larger address space.
互联网是一个全球广域网,使用 TCP/IP 协议族连接数十亿台设备。网络上的每台设备都需要唯一的 IP 地址来发送和接收数据。当前主要版本是 IPv4,使用 32 位地址,以点分十进制表示,例如 192.168.1.1。由于地址枯竭,IPv6 被开发出来,使用 128 位十六进制地址,提供了极大的地址空间。
IP addresses can be public (globally unique) or private (used within LANs). Private ranges include 192.168.x.x, 10.x.x.x, and 172.16.x.x – 172.31.x.x. Network Address Translation (NAT) allows multiple private IP addresses to share a single public IP address.
IP 地址可以是公共的(全球唯一)或私有的(在局域网内使用)。私有范围包括 192.168.x.x、10.x.x.x 和 172.16.x.x – 172.31.x.x。网络地址转换 (NAT) 允许多个私有 IP 地址共享单个公共 IP 地址。
Every device also has a MAC (Media Access Control) address, a unique 48-bit hardware identifier burned into the NIC. While IP addresses can change as a device moves networks, MAC addresses remain constant. They are used for local delivery within a LAN.
每个设备还有一个 MAC(媒体访问控制)地址,这是一个烧录在 NIC 中的唯一 48 位硬件标识符。当设备在不同网络间移动时 IP 地址可能变化,而 MAC 地址保持不变。它们用于局域网内的本地传输。
7. Network Protocols and the TCP/IP Model | 网络协议与 TCP/IP 模型
A protocol is a set of rules that governs how data is transmitted and received. Networks use layers of protocols to break down complex tasks. The TCP/IP model has four layers: Application, Transport, Internet, and Link (or Network Access). Each layer uses specific protocols.
协议是一组管理数据传输和接收方式的规则。网络使用协议层来分解复杂的任务。TCP/IP 模型有四层:应用层、传输层、互联网层和链路层(或网络接入层)。每一层使用特定的协议。
Key protocols include:
- HTTP/HTTPS (Hypertext Transfer Protocol / Secure): Used by web browsers to fetch web pages. HTTPS encrypts the data using TLS. Operational at the Application layer. / HTTP/HTTPS:用于 web 浏览器获取网页。HTTPS 使用 TLS 加密数据。工作于应用层。
- FTP (File Transfer Protocol): Transfers files between a client and a server. / FTP:在客户端和服务器之间传输文件。
- SMTP (Simple Mail Transfer Protocol): Sends outgoing email from a client to a mail server and between servers. / SMTP:将发件邮件从客户端发送到邮件服务器以及服务器之间。
- POP3 and IMAP: Used by email clients to retrieve emails from a server. POP3 downloads and usually deletes from server; IMAP keeps emails on the server and synchronises across devices. / POP3 和 IMAP:电子邮件客户端用于从服务器检索电子邮件。POP3 下载并且通常会从服务器删除;IMAP 将邮件保留在服务器并在设备间同步。
- TCP (Transmission Control Protocol) and UDP (User Datagram Protocol): Both operate at the Transport layer. TCP provides reliable, ordered delivery with error checking and flow control (used for web, email). UDP is faster but unreliable, with no error recovery – used for live streaming and VoIP. / TCP 和 UDP:两者都工作在传输层。TCP 提供可靠、有序的交付,带有错误检查和流量控制(用于网页、电子邮件)。UDP 更快但不可靠,没有错误恢复——用于直播和 VoIP。
- IP (Internet Protocol): At the Internet layer, it handles logical addressing and routing of packets. IP is connectionless and unreliable, relying on upper layers for reliability. / IP:在互联网层,它处理逻辑寻址和数据包的路由。IP 是无连接且不可靠的,依靠上层来实现可靠性。
Understanding the interplay between protocols is important. For example, when you visit a website, HTTP breaks the request into messages, TCP segments them and ensures reliable delivery, IP addresses and routes the packets, and the link layer physically transmits them.
理解协议之间的相互作用很重要。例如,当你访问一个网站时,HTTP 将请求分解为消息,TCP 将它们分段并确保可靠交付,IP 对数据包进行寻址和路由,链路层进行物理传输。
8. Wireless Networking and Wi‑Fi | 无线网络与 Wi‑Fi
Wireless networks use radio waves to transmit data, enabling mobility and reducing cabling. The most common standard is IEEE 802.11, branded as Wi‑Fi. It operates mainly on 2.4 GHz and 5 GHz frequency bands. Data is encrypted for security, typically using WPA2 or WPA3.
无线网络使用无线电波传输数据,实现移动性并减少布线。最常见标准是 IEEE 802.11,品牌为 Wi‑Fi。它主要工作在 2.4 GHz 和 5 GHz 频段。数据通过加密保护安全,通常使用 WPA2 或 WPA3。
Wi‑Fi networks are set up using a wireless access point (WAP) or a wireless router. Users can connect using a service set identifier (SSID). Factors affecting Wi‑Fi performance include distance from the access point, physical obstructions, interference from other devices, and the number of concurrent users.
Wi‑Fi 网络使用无线接入点或无线路由器搭建。用户可以使用服务集标识符 (SSID) 连接。影响 Wi‑Fi 性能的因素包括与接入点的距离、物理障碍、其他设备的干扰以及并发用户数量。
Wireless networks are inherently less secure than wired ones because signals can be intercepted more easily. Encryption (WPA2/3) and strong passwords are essential, along with hiding the SSID and MAC address filtering for additional layers, although these can be bypassed by determined attackers.
无线网络本质上比有线网络安全性低,因为信号更容易被截获。加密 (WPA2/3) 和强密码至关重要,同时隐藏 SSID 和 MAC 地址过滤作为附加层可以加强安全,尽管这些可以被有决心的攻击者绕过。
9. Network Security Threats and Prevention | 网络安全威胁与防护
Networks face constant threats from malicious actors. Malware is software designed to harm or gain unauthorised access, including viruses, worms, Trojans, ransomware, and spyware. Phishing attempts manipulate users into revealing sensitive information. Denial of Service (DoS) attacks flood a server with traffic to make it unavailable.
网络面临着来自恶意行为者的持续威胁。恶意软件是旨在破坏或获得未经授权访问的软件,包括病毒、蠕虫、特洛伊木马、勒索软件和间谍软件。网络钓鱼试图操纵用户透露敏感信息。拒绝服务攻击 (DoS) 通过用流量淹没服务器使其不可用。
Encryption is a critical defence, scrambling data so that only authorised parties with the decryption key can read it. Symmetric encryption uses the same key for encryption and decryption; asymmetric encryption uses a public key to encrypt and a private key to decrypt, providing confidentiality and authentication.
加密是一种关键防御,对数据进行加扰,只有拥有解密密钥的授权方才能读取。对称加密使用相同的密钥进行加密和解密;非对称加密使用公钥加密和私钥解密,提供机密性和身份验证。
Firewalls monitor and control incoming and outgoing network traffic based on predetermined security rules. They can be hardware or software-based. Proxy servers act as intermediaries, filtering requests and hiding internal IP addresses. User access levels and strong authentication (passwords, biometrics) further protect resources.
防火墙根据预设的安全规则监控和控制进出网络流量。它们可以基于硬件或软件。代理服务器充当中间人,过滤请求并隐藏内部 IP 地址。用户访问级别和强身份验证(密码、生物识别)进一步保护资源。
Regular software updates and patches close security vulnerabilities. Network policies, such as acceptable use policies and regular audits, also play a vital role in maintaining security. For exam answers, always link a threat with at least one prevention method.
定期软件更新和补丁关闭安全漏洞。网络政策,如可接受使用政策和定期审计,也在维护安全方面发挥重要作用。在考试答案中,始终将威胁与至少一种预防方法联系起来。
10. The Cloud and Virtual Networks | 云与虚拟网络
Cloud computing delivers computing services—storage, processing, software—over the internet. It allows users and businesses to access resources on demand without owning physical hardware. Cloud storage has become extremely common for backup and file sharing. Benefits include scalability, cost-effectiveness, and remote access. Risks involve reliance on internet connectivity, data security, and potential downtime.
云计算通过互联网提供计算服务——存储、处理、软件。它允许用户和企业按需访问资源,无需拥有物理硬件。云存储在备份和文件共享中已变得极为常见。好处包括可扩展性、成本效益和远程访问。风险涉及依赖互联网连接、数据安全和潜在停机。
Virtual networks are software-defined networks that run on top of physical infrastructure. A Virtual Private Network (VPN) extends a private network across a public network, allowing users to send and receive data securely as if their devices were directly connected to the private network. VPNs use encryption and tunnelling protocols to protect data privacy.
虚拟网络是运行在物理基础设施之上的软件定义网络。虚拟专用网 (VPN) 将专用网络扩展到公共网络之上,允许用户安全地发送和接收数据,就像他们的设备直接连接到专用网络一样。VPN 使用加密和隧道协议保护数据隐私。
For the exam, you should be able to describe cloud computing models (IaaS, PaaS, SaaS) at a basic level, but the focus is often on cloud storage advantages and disadvantages, and the purpose of a VPN for secure remote access.
考试中,你应该能够基本描述云计算模型(IaaS、PaaS、SaaS),但重点往往是云存储的优缺点,以及 VPN 用于安全远程访问的目的。
11. Real-World Networking Scenarios | 实际网络场景
Exam questions frequently present a scenario and ask you to recommend network hardware, topology, or security measures. For example, a company with three offices in different cities needs to connect them securely. You would recommend a WAN using VPN tunnels over the internet with firewalls at each site. Inside each office, a star topology using switches and a client-server model for centralised file storage would be appropriate.
考试题目经常提出一个场景,要求你推荐网络硬件、拓扑或安全措施。例如,一家公司在不同城市有三个办事处需要安全连接。你会建议使用通过互联网的 VPN 隧道建立广域网,并在每个站点设置防火墙。在每个办公室内部,使用交换机的星型拓扑以及客户端-服务器模型进行集中文件存储将是合适的。
Another common scenario involves schools: a school upgrading its network to support hundreds of student devices. A star topology with Gigabit Ethernet switches, multiple wireless access points on each floor, and a central server for user authentication and resource management is ideal. MAC address filtering and WPA2 encryption secure the wireless network, while a proxy server can filter web content.
另一个常见场景涉及学校:一所学校升级其网络以支持数百台学生设备。采用千兆以太网交换机的星型拓扑,每层楼多个无线接入点,以及用于用户认证和资源管理的中央服务器是理想的。MAC 地址过滤和 WPA2 加密保护无线网络,代理服务器可以过滤网页内容。
Being able to justify choices based on performance, security, cost, and scalability is a key skill. Always refer back to the specific requirements of the scenario provided.
能够基于性能、安全、成本和可扩展性来论证选择是一项关键技能。始终参考所提供的场景的具体需求。
Published by TutorHao | Computer Science Revision Series | aleveler.com
更多咨询请联系16621398022(同微信)
屏轩国际教育cambridge primary/secondary checkpoint, cat4, ukiset,ukcat,igcse,alevel,PAT,STEP,MAT, ibdp,ap,ssat,sat,sat2课程辅导,国外大学本科硕士研究生博士课程论文辅导