Cyber Security: Threats, Prevention and Encryption | 网络安全:威胁、防护与加密

📚 Cyber Security: Threats, Prevention and Encryption | 网络安全:威胁、防护与加密

Cyber security is the practice of defending computers, servers, mobile devices, electronic systems, networks and data from malicious attacks. In the IGCSE syllabuses, this topic focuses on identifying common threats, understanding how data can be kept confidential and secure, and applying simple protection measures.

网络安全是保护计算机、服务器、移动设备、电子系统、网络和数据免受恶意攻击的实践。在 IGCSE 课程中,本主题重点关注识别常见威胁、理解如何保持数据的机密性和安全性,以及应用简单的保护措施。


1. What is Cyber Security? | 什么是网络安全?

Cyber security refers to the technologies, processes and practices designed to protect networks, devices, programs and data from attack, damage or unauthorised access. It is important because a single security breach can lead to identity theft, financial loss or disruption of essential services.

网络安全指用于保护网络、设备、程序和数据免受攻击、损坏或未经授权访问的技术、流程和实践。它之所以重要,是因为一次安全漏洞就可能导致身份盗用、经济损失或关键服务中断。

Cyber security is not only about software tools such as antivirus programs. It also includes human behaviour, such as choosing strong passwords, recognising phishing emails and following clear security policies.

网络安全不仅涉及杀毒软件等软件工具。它还包括人的行为,例如选择强密码、识别钓鱼邮件以及遵循明确的安全策略。

In everyday life, cyber security protects online banking, social media accounts, school records and hospital systems from theft or disruption. Without these protections, private information could be exposed and critical services could stop working.

在日常生活中,网络安全保护网上银行、社交媒体账户、学校记录和医院系统免遭盗窃或中断。如果没有这些保护,私人信息可能被泄露,关键服务可能停止运行。


2. Data Integrity, Confidentiality and Availability | 数据完整性、机密性与可用性

The three key goals of cyber security are often called the CIA triad: confidentiality, integrity and availability. These three principles help organisations decide how to protect their data and systems.

网络安全的三个关键目标通常被称为 CIA 三要素:机密性、完整性和可用性。这三项原则帮助组织决定如何保护其数据和系统。

Confidentiality means that only authorised users can read or access sensitive information. Encryption, user accounts and access controls are common ways to maintain confidentiality.

机密性指只有经过授权的用户才能读取或访问敏感信息。加密、用户账户和访问控制是保持机密性的常用方法。

Integrity means that data is not altered, deleted or corrupted without permission. Checksums, backup copies and access logs can help detect or prevent unauthorised changes.

完整性指数据未经允许不会被更改、删除或破坏。校验和、备份副本和访问日志有助于检测或防止未经授权的更改。

Availability means that systems and data are accessible to authorised users when needed. Redundant servers, backup power and protection against denial-of-service attacks help maintain availability.

可用性指系统和数据在需要时可被授权用户访问。冗余服务器、备用电源和针对拒绝服务攻击的防护有助于保持可用性。

For example, a school database must keep student grades confidential, prevent unauthorised changes to marks, and remain available during examination results day.

例如,学校数据库必须对成绩保密,防止未经授权修改分数,并在考试放榜日保持可用。


3. Common Forms of Malware | 常见恶意软件类型

Malware is malicious software designed to damage, disrupt or gain unauthorised access to a computer system. Malware can spread through infected email attachments, downloads, removable drives or compromised websites.

恶意软件是旨在破坏、干扰或未经授权访问计算机系统的恶意程序。恶意软件可通过受感染的电子邮件附件、下载内容、可移动驱动器或受攻击的网站传播。

A virus attaches itself to a legitimate file or program and spreads when that file is opened. A worm can replicate across a network without needing a host file, which makes it spread quickly.

病毒附着在合法文件或程序上,并在该文件打开时传播。蠕虫无需宿主文件就能在网络中自我复制,因此传播速度很快。

A Trojan horse pretends to be useful or harmless software but hides harmful code. Ransomware encrypts a victim’s files and demands payment for the decryption key, often in cryptocurrency.

特洛伊木马伪装成有用或无害的软件,但隐藏有害代码。勒索软件加密受害者的文件并要求支付赎金才能获得解密密钥,赎金通常以加密货币支付。

Spyware secretly records information such as passwords, keystrokes or browsing habits and sends it to an attacker. Adware may display unwanted advertisements and slow down the device.

间谍软件秘密记录密码、按键或浏览习惯等信息,并将其发送给攻击者。广告软件可能显示不需要的广告并降低设备运行速度。

Anti-malware software uses signature detection and behaviour monitoring to find and remove threats. Keeping anti-malware software up to date helps protect against new variants.

反恶意软件使用特征码检测和行为监控来发现并清除威胁。保持反恶意软件为最新版本有助于防范新的变种。


4. Phishing and Social Engineering | 网络钓鱼与社会工程学

Social engineering manipulates people into giving away confidential information instead of attacking hardware or software directly. Attackers rely on human error, trust or fear rather than technical weaknesses.

社会工程学通过操纵人来泄露机密信息,而不是直接攻击硬件或软件。攻击者利用的是人为错误、信任或恐惧,而不是技术漏洞。

Phishing emails pretend to come from a trusted organisation, such as a bank, school or online store. They often ask the user to click a fake link or enter passwords and bank details on a fraudulent website.

网络钓鱼邮件冒充可信机构,例如银行、学校或网上商店。它们通常要求用户点击虚假链接,或在欺诈网站上输入密码和银行信息。

Spear phishing targets a specific individual, often using personal details such as the person’s name, job title or recent purchases to make the message look convincing.

鱼叉式网络钓鱼针对特定个人,通常利用个人详细信息(如姓名、职位或近期购物记录)使信息看起来更具说服力。

Signs of phishing include urgent requests, spelling errors, unfamiliar sender addresses, generic greetings and suspicious attachments or links. Users should check the sender and hover over links before clicking.

网络钓鱼的迹象包括紧急要求、拼写错误、陌生的发件人地址、泛泛的问候语以及可疑的附件或链接。用户在点击前应检查发件人并将鼠标悬停在链接上查看实际地址。


5. Brute-force and Denial-of-Service Attacks | 暴力破解与拒绝服务攻击

A brute-force attack tries every possible password combination until the correct one is found. Automated software can test millions of passwords per second, so weak or short passwords are very vulnerable.

暴力破解攻击会尝试所有可能的密码组合,直到找到正确密码。自动化软件每秒可以测试数百万个密码,因此薄弱或短密码非常容易被攻破。

To defend against brute-force attacks, systems can lock an account after several failed login attempts, use CAPTCHA tests, or require multi-factor authentication.

为了防御暴力破解攻击,系统可以在多次登录失败后锁定账户、使用验证码测试或要求多因素认证。

A denial-of-service (DoS) attack floods a server with fake requests so that legitimate users cannot access the service. The aim is to make a website or network unavailable, not necessarily to steal data.

拒绝服务攻击用虚假请求淹没服务器,使合法用户无法访问服务。其目标是使网站或网络不可用,而不一定是窃取数据。

A distributed denial-of-service (DDoS) attack uses many infected devices, called a botnet, to attack the same target at once. This makes the attack much harder to stop because the traffic comes from many locations.

分布式拒绝服务攻击使用许多被感染的设备(称为僵尸网络)同时攻击同一目标。由于流量来自许多位置,这种攻击更难阻止。


6. Keeping Data Safe: Access Control | 数据安全:访问控制

Access control ensures that only authorised individuals can view or change sensitive data. It is one of the most important layers of defence in a computer system.

访问控制确保只有经过授权的个人才能查看或修改敏感数据。它是计算机系统中最重要的一道防线。

Strong passwords should be long, contain a mix of upper-case letters, lower-case letters, numbers and symbols, and should not be reused across accounts. Passwords should also be changed if there is any sign of compromise.

强密码应该足够长,包含大写字母、小写字母、数字和符号的混合,并且不应在多个账户中重复使用。如果发现任何泄露迹象,也应更改密码。

Two-factor authentication (2FA) requires something you know, such as a password, plus something you have, such as a code sent to your phone or generated by an app. This makes unauthorised access much harder even if a password is stolen.

双因素认证要求同时提供“你知道的信息”(如密码)和“你拥有的东西”(如发送到手机或由应用程序生成的验证码)。这样即使密码被盗,未经授权的访问也会困难得多。

User access levels allow a system administrator to grant different permissions, such as read-only access or full editing rights, to different users. This means a student, for example, can view files but cannot delete or change them.

用户访问级别允许系统管理员向不同用户授予不同权限,例如只读权限或完全编辑权限。例如,学生可以查看文件但不能删除或修改文件。


7. Firewalls and Proxy Servers | 防火墙与代理服务器

A firewall monitors incoming and outgoing network traffic and blocks data packets that do not meet the security rules. Firewalls can be hardware devices or software applications.

防火墙监控进出网络流量,并阻止不符合安全规则的数据包。防火墙可以是硬件设备或软件应用程序。

Firewalls help prevent unauthorised access to a private network. For example, a firewall can block traffic from suspicious IP addresses or stop certain types of requests from entering a school network.

防火墙有助于防止对私有网络的未经授权访问。例如,防火墙可以阻止来自可疑 IP 地址的流量,或阻止某些类型的请求进入学校网络。

A proxy server acts as an intermediary between a user’s device and the internet. The user’s requests go to the proxy first, and the proxy forwards them to the destination website.

代理服务器充当用户设备与互联网之间的中介。用户的请求首先发送到代理服务器,然后由代理服务器转发到目标网站。

The proxy can hide the user’s real IP address, cache frequently used web pages to reduce bandwidth, and filter traffic to block malicious or inappropriate websites.

代理可以隐藏用户的真实 IP 地址、缓存常用网页以节省带宽,并过滤流量以阻止恶意或不适当的网站。


8. Encryption and Secure Transmission | 加密与安全传输

Encryption converts plaintext into ciphertext using an algorithm and a key. Intercepted data cannot be understood without the correct key, so encryption protects confidentiality during storage and transmission.

加密使用算法和密钥将明文转换为密文。被截获的数据在没有正确密钥的情况下无法被理解,因此加密可在存储和传输过程中保护机密性。

Symmetric encryption uses the same key to encrypt and decrypt data. It is fast, but the key must be shared securely between sender and receiver.

对称加密使用同一密钥进行加密和解密。它速度较快,但密钥必须在发送方和接收方之间安全共享。

Asymmetric encryption uses a pair of keys: a public key for encryption and a private key for decryption. The private key is kept secret, while the public key can be shared openly.

非对称加密使用一对密钥:公钥用于加密,私钥用于解密。私钥保密,公钥可以公开分享。

Secure websites use HTTPS, which combines HTTP with SSL/TLS encryption to protect data during transmission. Users should check for the padlock icon and ‘https’ in the address bar before entering sensitive information.

安全网站使用 HTTPS,它将 HTTP 与 SSL/TLS 加密相结合,在传输过程中保护数据。用户在输入敏感信息前应检查地址栏中的挂锁图标和 “https”。

Encryption protects data at rest, such as files stored on a hard drive, and data in transit, such as messages sent over a network. Many messaging apps now use end-to-end encryption so only the sender and receiver can read the messages.

加密可以保护静态数据(如存储在硬盘上的文件)和传输中的数据(如通过网络发送的消息)。许多即时通信应用现在使用端到端加密,因此只有发送方和接收方才能读取消息。


9. Digital Signatures and Authentication | 数字签名与身份验证

A digital signature is created using the sender’s private key and can be verified by anyone with the sender’s public key. It confirms that a message really came from the claimed sender.

数字签名使用发送方的私钥创建,任何拥有发送方公钥的人都可以验证。它确认消息确实来自声称的发送方。

Because the signature is unique to the message and the sender, it provides evidence of authenticity and confirms that the message has not been changed after signing.

由于签名对消息和发送方而言是唯一的,它可以证明真实性并确认消息在签名后未被更改。

Authentication methods include passwords, biometrics such as fingerprints or face recognition, and hardware tokens or smart cards. Strong authentication often combines two or more of these factors.

身份验证方法包括密码、生物识别(如指纹或面部识别)以及硬件令牌或智能卡。强身份验证通常结合其中两个或更多因素。


10. Security Policies and User Responsibilities | 安全策略与用户责任

An organisation’s security policy sets out rules for acceptable use, password management, device handling and reporting incidents. It helps every user understand what they must do to keep data safe.

组织的安全策略规定了可接受使用、密码管理、设备处理和事件报告的规则。它帮助每个用户了解自己必须如何做才能保证数据安全。

Users should lock screens when away from desks, update software regularly, avoid suspicious downloads and report lost devices immediately. These simple habits reduce the risk of successful attacks.

用户离开办公桌时应锁定屏幕,定期更新软件,避免可疑下载,并立即报告丢失的设备。这些简单的习惯可以降低攻击成功的风险。

Staff training reduces the risk of social engineering attacks because people learn to recognise phishing and follow correct procedures. Security awareness is as important as technical tools.

员工培训可以降低社会工程学攻击的风险,因为人们学会识别网络钓鱼并遵循正确的流程。安全意识与技术工具同样重要。

A clear acceptable use policy may state that personal devices cannot be connected to the school network, or that users must not share their login details with anyone.

明确的可接受使用策略可能规定个人设备不能接入学校网络,或者用户不得与任何人共享登录信息。


11. Backup and Disaster Recovery | 备份与灾难恢复

A backup is a copy of important data stored separately from the original so it can be restored if data is lost, corrupted or held to ransom. Backups should be made regularly and tested.

备份是重要数据的副本,与原始数据分开存储,以便在数据丢失、损坏或被勒索时能够恢复。备份应定期进行并测试。

Common backup strategies include full backups, incremental backups that only save changes since the last backup, and cloud backups that store data on remote servers.

常见备份策略包括完整备份、仅保存自上次备份以来更改的增量备份以及将数据存储在远程服务器上的云备份。

Disaster recovery plans describe how an organisation will restore systems and continue operating after a major incident, such as a cyber attack, fire or hardware failure.

灾难恢复计划描述了组织在重大事件(如网络攻击、火灾或硬件故障)后如何恢复系统并继续运行。

Backup copies should be kept offline or in a different location so that ransomware cannot encrypt both the original files and their backup.

备份副本应离线保存或保存在不同位置,这样勒索软件就无法同时加密原始文件和它们的备份。


12. Case Study: Protecting a School Network | 案例研究:保护学校网络

A school network stores student records, teaching materials and financial information, so it needs layered protection. A single control is not enough because different threats require different defences.

学校网络存储学生记录、教学资料和财务信息,因此需要分层防护。单一的控制措施不够,因为不同的威胁需要不同的防御方式。

The school could use strong passwords and two-factor authentication for staff, a firewall to control network traffic, and HTTPS on its learning platform to protect data in transit.

学校可以对教职员工使用强密码和双因素认证,使用防火墙控制网络流量,并在学习平台上启用 HTTPS 以保护传输中的数据。

Regular backups and clear incident reporting procedures help the school recover quickly if an attack or hardware failure occurs. Users should be trained to spot phishing emails and report suspicious activity.

定期备份和清晰的事件报告流程有助于学校在发生攻击或硬件故障时快速恢复。用户应接受培训,以识别钓鱼邮件并报告可疑活动。

By combining technical controls, user training and clear policies, the school can reduce the likelihood of a successful cyber attack and limit the damage if one does occur.

通过结合技术控制、用户培训和明确策略,学校可以降低网络攻击成功的可能性,并在攻击发生时减少损失。

Published by TutorHao | IGCSE Science Revision Series | aleveler.com

更多咨询请联系16621398022(同微信)

Comments

屏轩国际教育cambridge primary/secondary checkpoint, cat4, ukiset,ukcat,igcse,alevel,PAT,STEP,MAT, ibdp,ap,ssat,sat,sat2课程辅导,国外大学本科硕士研究生博士课程论文辅导Cancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from aleveler.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Exit mobile version