Skip to content · ⁨الانتقال إلى المحتوى⁩

Securing Networks · ⁨تأمين الشبكات⁩

AP Cybersecurity · ⁨الأمن السيبراني (AP)⁩ · Topic 3 · ⁨الموضوع 3⁩

Video lesson for this topic · ⁨درس فيديو لهذا الموضوع⁩ Open the video page · ⁨افتح صفحة الفيديو⁩
9:26

تأمين الشبكات

ترسل رسالة إلى بنكك. تصل. تأتي الإجابة رداً. كل شيء يبدو طبيعياً. لكن هناك شخصاً يجلس بهدوء بينك وبينه، يقرأ كل رسالة…

English narration · English + 中文 subtitles burned in · ⁨سرد باللغة الإنجليزية · ترجمة مدمجة بالإنجليزية + الصينية⁩

3.1

Network Vulnerabilities and Attacks · ⁨ثغرات الشبكة والهجمات⁩

Syllabus · ⁨المنهج⁩
English

Learning Objective 3.1.A: Identify common network attacks.

  • 3.1.A.1 The address resolution protocol (ARP) is used by a default gateway on a network to establish a table that pairs internet protocol (IP) addresses with media access control (MAC) addresses. An ARP poisoning attack is when an adversary sends falsified ARP packets to the default gateway to modify the table so that the adversary’s device receives traffic intended for the target by linking the target’s IP address to the adversary’s MAC address. Faking a MAC address is called MAC spoofing. This is an example of an on-path attack (or man-in-the-middle attack), which is when an adversary interrupts a data stream between two parties, captures both parties’ data, and copies or alters the data before sending them on. Both parties think they are communicating directly with each other, but instead they are each communicating with the adversary who is secretly intercepting their messages.
  • 3.1.A.2 A MAC flooding attack is when an adversary sends the target switch many Ethernet frames, each with a different MAC address. This can force the switch into broadcast mode, and the adversary can then collect all of the frames on the network (because they are being broadcast), which could allow the adversary to access sensitive information. This is an example of eavesdropping (or sniffing), which is when an adversary captures data in transit and can record and copy the data.
  • 3.1.A.3 A domain name system (DNS) poisoning attack is when an adversary pretends to be an authoritative name server (NS) and plants a fake DNS record on a DNS server to redirect browser traffic to a malicious website designed to steal credentials. This is an example of credential harvesting, which is when adversaries set up a fake login site that looks like a real one. Unsuspecting users enter their real credentials, which the adversaries capture and use.
  • 3.1.A.4 A smurf attack attempts to overwhelm a network with Internet Control Message Protocol (ICMP) requests. It is a type of denial of service (DoS) attack, which makes a system or resource unavailable to authorized users. During a smurf attack, an adversary sends many ICMP requests with the victim’s address to the network’s broadcast address. The network’s gateway then sends these requests to all devices on the network. Each device on the network replies to the victim’s address, creating a flood of traffic that can block legitimate messages. When multiple devices attack the same target simultaneously, it’s called a distributed denial of service (DDoS) attack.

Learning Objective 3.1.B: Explain how adversaries can exploit network vulnerabilities to steal, disrupt, or destroy network communication.

  • 3.1.B.1 Adversaries can send malicious traffic into a network to flood it creating a DoS, to map the internal structure of the network, or to spoof a legitimate device. Networks without firewalls, or with improperly configured firewalls, are vulnerable to these types of attacks.
  • 3.1.B.2 Adversaries that have compromised a device often attempt to leverage their access to compromise other devices on the local area network (LAN).
  • 3.1.B.3 Adversaries that physically plug into a data port can gain access to a LAN through the switch port unless port security is enabled. This allows adversaries to launch DoS attacks or perform MAC flooding or MAC spoofing attacks.
  • 3.1.B.4 Adversaries standing outside of physically secure spaces can pick up the signals and beacon frames from a wireless access point that is broadcasting outside the physical space. This allows them to gather information about the wireless network and to attempt eavesdropping and cryptographic attacks on it.
  • 3.1.B.5 Adversaries can attempt to join networks to launch attacks from within the networks. Networks that do not authenticate devices and users make it easier for adversaries to join.
  • 3.1.B.6 If there is an open network port, an adversary can plug a wireless access point into the port creating a rogue access point. The adversary could use this rogue access point to access the internal network wirelessly (maybe even from outside the physical space). This allows the adversary direct access to the LAN, bypassing any firewalls.
  • 3.1.B.7 Adversaries can attempt to break wireless encryption and intercept, steal, or compromise data on a network.

Learning Objective 3.1.C: Assess and document risks from network vulnerabilities.

  • 3.1.C.1 Vulnerabilities on a network can lead to adversaries being able to intercept and alter data in transit, launch DoS attacks, or move laterally on a network to gain access to more sensitive or critical systems. Network vulnerabilities can constitute a risk to confidentiality, integrity, and availability.
  • 3.1.C.2 There are automated vulnerability scanners that can check networks, devices, and applications for known vulnerabilities. These scanners produce a report that often includes the vulnerabilities detected, their severity, and mitigation recommendations.
  • 3.1.C.3 Successfully exploiting a network vulnerability often requires advanced technical ability and knowledge. This can impact the likelihood of an exploit.
  • 3.1.C.4 High risks from network vulnerabilities allow an adversary to easily have a significant impact by capturing network traffic, spoofing a legitimate device on the network, or launching a DoS attack.
    • Illustrative examples for 3.1.C.4:
      • An organization has a single unsegmented internal network that is accessible via a wireless network with weak encryption, and on that network it has a server running its proprietary web-application.
  • 3.1.C.5 Moderate risks from network vulnerabilities could include vulnerabilities that might give adversaries the ability to gain information about systems or devices on a network.
    • Illustrative examples for 3.1.C.5:
      • An organization’s external firewall is not configured to block external ICMP traffic.
  • 3.1.C.6 Low risks from network vulnerabilities include vulnerabilities that would be difficult to exploit and would likely have minimal negative impacts on an organization.
    • Illustrative examples for 3.1.C.6:
      • An organization has wireless access points that broadcast a beacon frame, which contains the network service set identifier (SSID) and the wireless encryption protocols.
العربية

هدف التعلم 3.1.A: تحديد هجمات الشبكة الشائعة.

  • 3.1.A.1 يُستخدم بروتوكول حل العناوين (ARP) بواسطة بوابة افتراضية في الشبكة لإنشاء جدول يربط بين عناوين بروتوكول الإنترنت (IP) وعناوين التحكم في الوصول إلى الوسائط (MAC). هجوم تسميم ARP هو عندما يرسل الخصم حزم ARP مزورة إلى البوابة الافتراضية لتعديل الجدول بحيث تستقبل جهازه حركة البيانات الموجهة إلى الهدف عن طريق ربط عنوان IP الخاص بالهدف بعنوان MAC الخاص بالخصم. يُسمى تزوير عنوان MAC بتزوير MAC (MAC spoofing). هذا مثال على هجوم في المسار (On-path attack) أو هجوم الرجل في المنتصف (Man-in-the-middle)، وهو عندما يقاطع الخصم تدفق البيانات بين طرفين، ويحتوي بيانات الطرفين، وينسخ أو يعدل البيانات قبل إرسالها. يعتقد كلا الطرفين أنه يتواصل مباشرة مع الآخر، ولكن بدلاً من ذلك، يتواصل كل منهما مع الخصم الذي يعترض رسائلهما سرًا.
  • 3.1.A.2 هجوم طمس MAC هو عندما يرسل الخصم العديد من إطارات الإيثرنت إلى المحول المستهدف، كل إطار يحمل عنوان MAC مختلف. يمكن لهذا أن يجبر المحول على وضع البث (Broadcast mode)، وحينها يمكن للخصم جمع جميع الإطارات على الشبكة (لأنها تُبث)، مما قد يسمح له بالوصول إلى معلومات حساسة. هذا مثال على التنصت (Eavesdropping) أو التقط signals (Sniffing)، وهو عندما يلتقط الخصم البيانات أثناء مرورها ويمكنه تسجيل ونسخ البيانات.
  • 3.1.A.3 هجوم تسميم نظام أسماء النطاقات (DNS Poisoning) هو عندما يتظاهر الخصم بأنه خادم أسماء مفوض (NS) ويزرع سجلاً مزيفاً في DNS على خادم DNS لإعادة توجيه حركة متصفح الويب إلى موقع ضار مصمم لسرقة بيانات الاعتماد. هذا مثال على صيد بيانات الاعتماد (Credential Harvesting)، وهو عندما يقوم الخصوم بإعداد موقع تسجيل دخول مزيف يبدو حقيقياً. يدخل المستخدمون غير المشتبه بهم بيانات اعتمادهم الحقيقية، والتي يلتقطها الخصوم ويستخدمونها.
  • 3.1.A.4 يحاول هجوم Smurf إغراق الشبكة بطلبات بروتوكول رسائل Internet Control (ICMP). إنه نوع من هجمات حرمان الخدمة (DoS)، والتي تجعل النظام أو المورد غير متاح للمستخدمين المصرح لهم. أثناء هجوم Smurf، يرسل الخصم العديد من طلبات ICMP بعنوان الضحية إلى عنوان البث للشبكة. ترسل بوابة الشبكة بعد ذلك هذه الطلبات إلى جميع الأجهزة المتصلة بالشبكة. ترد كل جهاز على الشبكة بعنوان الضحية، مما يخلق سيولة هائلة من حركة البيانات يمكن أن تحجب الرسائل الشرعية. عندما تهاجم عدة أجهزة نفس الهدف في وقت واحد، يُسمى ذلك هجوم حرمان الخدمة الموزع (DDoS).

هدف التعلم 3.1.B: شرح كيفية استغلال الخصوم لثغرات الشبكة لسرقة أو تعطيل أو تدمير اتصالات الشبكة.

  • 3.1.B.1 يمكن للخصوم إرسال حركة مرور خبيثة إلى الشبكة لإغرائها وإنشاء هجوم DoS، أو لرسم البنية الداخلية للشبكة، أو لتزوير جهاز شرعي. الشبكات التي لا تحتوي على جدران حماية، أو التي تكون جدران الحماية فيها مضبوطة بشكل غير صحيح، عرضة لهذه الأنواع من الهجمات.
  • 3.1.B.2 الخصوم الذين استحوذوا على جهاز ما غالباً ما يحاولون الاستفادة من وصولهم لاستهداف أجهزة أخرى على الشبكة المحلية (LAN).
  • 3.1.B.3 يمكن للخصوم الذين يوصلون أسلاكهم جسدياً بمنفذ بيانات الحصول على الوصول إلى الشبكة المحلية عبر منفذ المحول ما لم يتم تفعيل أمان المنافذ. هذا يسمح للخصوم بإطلاق هجمات DoS أو تنفيذ هجمات طمس MAC أو تزوير MAC.
  • 3.1.B.4 يمكن للخصوم الواقفين خارج المساحات الآمنة جسدياً التقاط الإشارات وإطارات البث من نقطة الوصول اللاسلكية التي تبث خارج المساحة الجسدية. يسمح هذا لهم بجمع معلومات حول الشبكة اللاسلكية ومحاولة التنصت والهجمات المشفرة عليها.
  • 3.1.B.5 يمكن للخصوم محاولة الانضمام إلى شبكات لإطلاق هجمات من داخل تلك الشبكات. الشبكات التي لا تقوم بمصادقة الأجهزة والمستخدمين تسهل على الخصوم الانضمام إليها.
  • 3.1.B.6 إذا كان هناك منفذ شبكة مفتوح، يمكن للمهاجم توصيل نقطة وصول لاسلكية بالمنفذ مما يخلق نقطة وصول غير شرعية. قد يستخدم المهاجم هذه النقطة الوصول غير الشرعية للوصول إلى الشبكة الداخلية لاسلكيًا (ربما حتى من خارج المكان المادي). هذا يسمح للمهاجم بالوصول المباشر إلى LAN، متجاوزًا أي جدران حماية.
  • 3.1.B.7 يمكن للمهاجمين محاولة كسر تشفير الشبكة اللاسلكية والتقاط أو سرقة أو الإضرار بالبيانات على الشبكة.

هدف التعلم 3.1.C: تقييم مخاطر ثغرات الشبكة وتوثيقها.

  • 3.1.C.1 يمكن أن تؤدي الثغرات في الشبكة إلى قدرة المهاجمين على التقاط البيانات أثناء النقل وتعديلها، أو إطلاق هجمات حجب الخدمة (DoS)، أو التحرك أفقيًا عبر الشبكة للحصول على وصول إلى أنظمة أكثر حساسية أو حرجة. قد تمثل الثغرات في الشبكة خطرًا على السرية والنزاهة والتوافر.
  • 3.1.C.2 توجد ماسحات أوتوماتائية للثغرات يمكنها فحص الشبكات والأجهزة والتطبيقات بحثًا عن ثغرات معروفة. تنتج هذه الماسحات تقريرًا يتضمن عادةً الثغرات التي تم اكتشافها، وخطورتها، وتوصيات التخفيف.
  • 3.1.C.3 يتطلب استغلال ناجح لثغرة في الشبكة غالبًا قدرات ومعرفة تقنية متقدمة. وهذا يمكن أن يؤثر على احتمالية الاستغلال.
  • 3.1.C.4 تسمح المخاطر العالية الناتجة عن ثغرات الشبكة للمهاجم بالحصول بسهولة على تأثير كبير من خلال التقاط حركة مرور الشبكة، أو تزوير جهاز شرعي على الشبكة، أو إطلاق هجوم حجب الخدمة (DoS).
    • أمثلة توضيحية لـ 3.1.C.4:
      • تمتلك منظمة شبكة داخلية واحدة غير مقسمة قابلة للوصول عبر شبكة لاسلكية ذات تشفير ضعيف، وعلى تلك الشبكة يوجد خادم يعمل عليه تطبيق الويب الخاص بها.
  • 3.1.C.5 قد تشمل المخاطر المتوسطة الناتجة عن ثغرات الشبكة ثغرات قد تمنح المهاجمين القدرة على الحصول على معلومات حول الأنظمة أو الأجهزة على الشبكة.
    • أمثلة توضيحية لـ 3.1.C.5:
      • جدار الحماية الخارجي للمنظمة غير مُضبط لمنع حركة مرور ICMP الخارجية.
  • 3.1.C.6 تشمل المخاطر المنخفضة الناتجة عن ثغرات الشبكة ثغرات سيكون من الصعب استغلالها ومن المرجح أن يكون لها تأثير سلبي طفيف على المنظمة.
    • أمثلة توضيحية لـ 3.1.C.6:
      • تمتلك المنظمات نقاط وصول لاسلكية تبث إطار البون (beacon frame)، والذي يحتوي على معرف مجموعة الخدمات للشبكة (SSID) وبروتوكولات التشفير اللاسلكي.

Source: College Board AP Course and Exam Description · ⁨المصدر: وصف دورة وامتحان College Board AP⁩

English
A man-in-the-middle attack
DDoS: a botnet floods a server

A network connects devices so they can share data - and every connection is a possible way in. You must know the classic network attacks and the tricks behind them.

  • ARP poisoning 地址解析投毒 - the address resolution protocol (ARP) 地址解析协议 pairs IP addresses with hardware MAC addresses 物理地址. An adversary sends fake ARP messages so traffic meant for the target flows to the adversary instead. This is an on-path attack 中间人攻击 (also called man-in-the-middle): the adversary secretly sits between two parties, reading and even altering their messages.
  • MAC flooding 物理地址泛洪 - flooding a switch 交换机 with fake MAC addresses forces it into broadcast mode, so the adversary can capture all traffic. This is a form of eavesdropping 窃听.
  • DNS poisoning 域名投毒 - planting a fake record on a domain name system (DNS) 域名系统 server redirects users to a malicious site to steal credentials (credential harvesting 凭据收集).
  • Smurf attack - flooding a network with ICMP requests aimed at the broadcast address, so every device replies to the victim. It is a denial of service (DoS) 拒绝服务 attack; when many machines attack at once it becomes a distributed denial of service (DDoS) 分布式拒绝服务.

Adversaries exploit weak networks to flood, map, or spoof devices. A physical data port with no port security lets an attacker plug in; an open port lets them install a rogue access point 非法接入点 that bypasses the firewall entirely. We rate network risk by impact and by how much skill the exploit needs.

To find weaknesses before an adversary does, organisations run an automated vulnerability scanner 自动漏洞扫描器: a tool that checks networks, devices, and applications against a database of known vulnerabilities, then produces a report listing each one found, how severe it is, and a recommended mitigation 缓解措施. Fixing the highest-severity items first is a core part of managing network risk.

العربية
هجوم الرجل في الوسط
DDoS: شبكة روبوت تتسبب في غرق خادم

الشبكة تربط الأجهزة لتشارك البيانات - وكل اتصال هو طريقة محتملة للدخول. يجب أن تعرف الهجمات الكلاسيكية للشبكة والاختراعات وراءها.

  • تلويح ARP - بروتوكول حل العناوين (ARP) يربط عناوين IP بعناوين الأجهزة MAC. يرسل العدو رسائل ARP مزيفة بحيث يتدفق المرور الموجه إلى الهدف نحو العدو بدلاً من ذلك. هذا هو هجوم المسار (on-path attack) (يسمى أيضاً الرجل في الوسط): يجلس العدو بسرية بين طرفين، ويقرأ الرسائل بل ويعدلها أحياناً.
  • غرق MAC - غرق المحول (switch) بعناوين MAC مزيفة تجبره على وضع البث، مما يسمح للعدو باحتجاز كل حركة مرور. هذا نوع من التنصت.
  • تلويح DNS - زراعة سجل مزيف على خادم نظام أسماء النطاق (DNS) يعيد توجيه المستخدمين إلى موقع ضار لسرعة بيانات الاعتماد (جمع بيانات الاعتماد).
  • هجوم السورف (Smurf attack) - غرق الشبكة بطلبات ICMP موجهة إلى عنوان البث، sehingga every device replies to the victim. إنه هجوم حجب الخدمة (DoS)؛ عندما تهاجم العديد من الآلات في وقت واحد يصبح هجوم حجب الخدمة الموزع (DDoS).

يستغل العدو الشبكات الضعيفة للتسبب في الغرق، أو رسم الخرائط، أو انتحال هوية الأجهزة. منفذ بيانات فيزيائي بدون أمان المنفذ يسمح للمهاجم بالتوصيل؛ منفذ مفتوح يسمح لهم بتثبيت نقطة وصول شريرة تتجاوز جدار الحماية بالكامل. نصنف خطر الشبكة بناءً على التأثير وكمية المهارة التي يتطلبها الاستغلال.

لإيجاد نقاط الضعف قبل أن يفعل ذلك العدو، تقوم المنظمات بتشغيل ماسح ثغرات أمني تلقائي: وهو أداة تفحص الشبكات والأجهزة والتطبيقات مقابل قاعدة بيانات لـثغرات معروفة، ثم تنتج تقريرًا يسرد كل ثغرة تم العثور عليها، وشدة خطورتها، وتخفيف موصى به. إصلاح العناصر ذات الشدة الأعلى أولًا هو جزء أساسي من إدارة مخاطر الشبكة.

Explore · ⁨استكشف⁩

Identify the network attack from its evidence · ⁨حدد هجوم الشبكة من الأدلة⁩

Each network attack leaves a distinct trace: ARP poisoning = one IP with two MACs; MAC flooding = a surge of new MACs; DNS poisoning = misdirected web traffic; smurf/DoS = a flood that blocks legitimate traffic. · ⁨يترك كل هجوم شبكة أثرًا مميزًا: تلويث ARP = عنوان IP واحد مع MACs اثنين؛ فLOOD MAC = تدفق من MACs الجديدة؛ تلويث DNS = حركة ويب موجهة بشكل خاطئ؛ smurf/DoS = فيض يحجب حركة المرور الشرعية.⁩

Vocabulary · ⁨مفردات⁩ Train · ⁨تدريب⁩
English العربية
ARP poisoning/ɑːp ˈpɔɪzənɪŋ/ تسميم ARP
address resolution protocol (ARP)/əˈdres ˌrezəˈluːʃn ˈprəʊtəkɒl/ بروتوكول حل العناوين (ARP)
MAC addresses/mæk əˈdresɪz/ عناوين MAC
on-path attack/ɒn pæθ əˈtæk/ هجوم عبر المسار
MAC flooding/mæk ˈflʌdɪŋ/ MAC flooding
switch/swɪtʃ/ مفتاح
eavesdropping/ˈiːvzdrɒpɪŋ/ التنصت
DNS poisoning/ˌdiː en ˈes ˈpɔɪzənɪŋ/ DNS poisoning
domain name system (DNS)/dəˈmeɪn neɪm ˈsɪstəm/ نظام أسماء النطاقات (DNS)
credential harvesting/krɪˈdenʃl ˈhɑːvɪstɪŋ/ جمع بيانات الاعتماد
denial of service (DoS)/dɪˈnaɪəl ɒv ˈsɜːvɪs/ حجب الخدمة (DoS)
distributed denial of service (DDoS)/ˈdɪstrɪbjuːtɪd dɪˈnaɪəl ɒv ˈsɜːvɪs/ حجب الخدمة الموزع (DDoS)
rogue access point/rəʊɡ ˈækses pɔɪnt/ نقطة وصول مزيفة
automated vulnerability scanner/ˈɔːtəmeɪtɪd ˌvʌlnərəˈbɪlɪti ˈskænə/ فاحص الثغرات الآلي
mitigation/ˌmɪtɪˈɡeɪʃn/ التخفيف
3.2

Protecting Networks: Managerial Controls and Wireless Security · ⁨حماية الشبكات: ضوابط إدارية وأمن لاسلكي⁩

Syllabus · ⁨المنهج⁩
English

Learning Objective 3.2.A: Identify managerial controls related to network security.

  • 3.2.A.1 A router security policy will set forth a minimum configuration standard for routers on an organization’s network and may include:
    • Banning local user accounts (All router logins must use an approved authentication server.)
    • Disabling unnecessary services (e.g., Telnet)
    • Requiring a firewall (An organization may opt for a firewall device separate from the router.)
  • 3.2.A.2 A switch security policy will set forth a minimum configuration standard for switches on an organization’s network and may include:
    • Banning local user accounts (All switch logins must use an approved authentication server.)
    • Requiring port security to be enabled.
    • Using MAC filtering
  • 3.2.A.3 A virtual private network (VPN) policy will detail the minimum security requirements for employees using a VPN to access an organization’s internal network, and it may include:
    • A list of roles within the organization that are allowed to use a VPN to access the organization’s internal network
    • Authentication requirements for employees using a VPN (e.g., public/private key system or MFA)
    • A prohibition against split tunneling (also called dual tunneling)
  • 3.2.A.4 A wireless security policy will establish the minimum security requirements for wireless networks within an organization and may include:
    • Requiring users to authenticate to the wireless network through an extensible authentication protocol (EAP) connected to an approved authentication server
    • Requiring all wireless traffic to be encrypted using AES encryption with a minimum key length
    • Disabling beacon frames on wireless access points

Learning Objective 3.2.B: Configure wireless network security features.

  • 3.2.B.1 Organizations can disable beacon frame broadcasting on wireless access points (WAPs) to make it harder for adversaries to find their wireless network and learn its basic properties.
  • 3.2.B.2 Organizations can control the broadcast direction and signal strength of a WAP so the signal does not extend beyond the physical space the access point is meant to cover.
  • 3.2.B.3 Organizations should enable strong wireless encryption protocols to ensure wireless frames are not readable by adversaries who might intercept them.
    • WEP, WPS, and the original WPA wireless encryption protocols have known vulnerabilities and are insecure.
    • WPA3 is currently the strongest wireless encryption algorithm.
  • 3.2.B.4 Organizations can enable MAC filtering to prevent unauthorized devices from accessing the network, and they can require users to authenticate when joining a network.
العربية

هدف التعلم 3.2.A: تحديد الضوابط الإدارية المتعلقة بأمن الشبكة.

  • 3.2.A.1 ستحدد سياسة أمن الراوتر معايير تكوين دنيا للراوترات على شبكة المنظمة وقد تتضمن:
    • حظر حسابات المستخدمين المحلية (يجب أن تستخدم جميع عمليات تسجيل الدخول إلى الراوتر خادم اعتماد معتمد.)
    • تعطيل الخدمات غير الضرورية (مثل Telnet)
    • اشتراط وجود جدار حماية (قد تختار المنظمة استخدام جهاز جدار حماية منفصل عن الراوتر.)
  • 3.2.A.2 ستحدد سياسة أمن المحوّل معايير تكوين دنيا للمحوّلات على شبكة المنظمة وقد تتضمن:
    • حظر حسابات المستخدمين المحلية (يجب أن تستخدم جميع عمليات تسجيل الدخول إلى المحوّل خادم اعتماد معتمد.)
    • اشتراط تفعيل أمان المنافذ.
    • استخدام تصفية MAC
  • 3.2.A.3 ستفصّل سياسة الشبكة الخاصة الافتراضية (VPN) الحد الأدنى من متطلبات الأمان لموظفي استخدام VPN للوصول إلى الشبكة الداخلية للمنظمة، وقد تتضمن:
    • قائمة بالأدوار داخل المنظمة المسموح لها باستخدام VPN للوصول إلى الشبكة الداخلية للمنظمة
    • متطلبات الاعتماد لموظفي استخدام VPN (مثل نظام المفاتيح العامة/الخاصة أو MFA)
    • منع التجزئة النافذة (المعروفة أيضًا بالتجزئة المزدوجة)
  • 3.2.A.4 ست确立了 سياسة أمن الشبكة اللاسلكية الحد الأدنى من متطلبات الأمان للشبكات اللاسلكية داخل المنظمة وقد تتضمن:
    • اشتراط authenticate المستخدمين لشبكة لاسلكية من خلال بروتوكول اعتماد قابل للتوسيع (EAP) متصل بخادم اعتماد معتمد
    • اشتراط تشفير جميع حركة المرور اللاسلكية باستخدام تشفير AES بحد أدنى لطول المفتاح
    • تعطيل إطارات البون على نقاط الوصول اللاسلكية

هدف التعلم 3.2.B: ضبط ميزات أمن الشبكة اللاسلكية.

  • 3.2.B.1 يمكن للمنظمات تعطيل بث إطار البون على نقاط الوصول اللاسلكية (WAPs) لجعل من الصعب على المهاجمين العثور على شبكتهم اللاسلكية ومعرفة خصائصها الأساسية.
  • 3.2.B.2 يمكن للمنظمات التحكم في اتجاه البث وقوة الإشارة لنقطة الوصول اللاسلكية بحيث لا تمتد الإشارة إلى ما وراء الحيز الفيزيائي الذي يُقصد أن تغطيه نقطة الوصول.
  • 3.2.B.3 يجب على المنظمات تفعيل بروتوكولات التشفير القوية للشبكة اللاسلكية لضمان عدم قراءة الإطارات اللاسلكية بواسطة المهاجمين الذين قد يقومون باقتحامها.
    • WEP و WPS وبروتوكولات التشفير اللاسلكي WPA الأصلية لديها ثغرات معروفة وهي غير آمنة.
    • WPA3 هو حالياً أقوى خوارزمية لتشفير الشبكة اللاسلكية.
  • 3.2.B.4 يمكن للمنظمات تفعيل تصفية MAC لمنع الأجهزة غير المصرح لها من الوصول إلى الشبكة، ويمكنها اشتراط authenticate المستخدمين عند الانضمام إلى الشبكة.

Source: College Board AP Course and Exam Description · ⁨المصدر: وصف دورة وامتحان College Board AP⁩

English

Good network security starts with written policies that set a minimum standard: a router security policy and switch security policy ban local accounts and require port security; a VPN policy sets authentication rules and forbids split tunneling 分离隧道; and a wireless security policy requires strong encryption and authenticated access.

For wireless networks specifically, organisations disable beacon frames so the network is harder to find, control signal strength so it does not leak outside the building, enable strong encryption - WPA3 Wi-Fi 保护接入第三代 is the current strongest, while old WEP and the original WPA are broken - and use MAC filtering to allow only known devices.

العربية

تبدأ أمنيات الشبكة الجيدة بـسياسات مكتوبة تحدد حدًا أدنى: تحظر سياسة أمان الموجه وسياسة أمان المحول الحسابات المحلية وتتطلب أمان المنفذ؛ وتضع سياسة VPN قواعد المصادقة وتمنع الـتunneling المقسم (split tunneling)؛ وتفرض سياسة الأمان اللاسلكي تشفيرًا قويًا ودخولاً موثقًا.

بالنسبة للشبكات اللاسلكية تحديدًا، تقوم المنظمات بـتعطيل إطارات البث الإعلاني (beacon frames) لجعل الشبكة أصعب في العثور عليها، وتحكم في قوة الإشارة حتى لا تتسرب خارج المبنى، وتمكين التشفير القوي - فـWPA3 هو الأقوى حاليًا، بينما تم اختراق الـWEP القديم والـWPA الأصلي - واستخدام فلترة MAC للسماح فقط للأجهزة المعروفة.

Vocabulary · ⁨مفردات⁩ Train · ⁨تدريب⁩
English العربية
split tunneling/splɪt ˈtʌnəlɪŋ/ التنقيب المزدوج
WPA3/ˌdʌbljuː piː eɪ ˈθriː/ WPA3
Network segmentation/ˈnetwɜːk ˌseɡmənˈteɪʃn/ تجزئة الشبكة
subnets/ˈsʌbnets/ شبكات فرعية
screened subnet/skriːnd ˈsʌbnet/ شبكة فرعية محجوبة
3.3

Protecting Networks: Segmentation · ⁨حماية الشبكات: التقسيم⁩

Syllabus · ⁨المنهج⁩
English

Learning Objective 3.3.A: Identify techniques for segmenting a network.

  • 3.3.A.1 Firewall zones and rules can be used to create a screened subnet (also known as a demilitarized zone, or DMZ)—a network segment that sits between public, external networks like the internet and internal, private networks. A screened subnet is typically a lower security zone than the internal, private networks, and it typically holds an organization’s publicly facing resources, separating them from the internal network.
  • 3.3.A.2 Subnetting can be used to create different subnets based on IP addressing. If a device is compromised by an adversary, subnets can contain a security breach to reduce the number of exposed devices.
  • 3.3.A.3 Switches can be used to create VLANs, which logically separate devices physically connected to central switches.

Learning Objective 3.3.B: Explain why network segmentation can increase network security.

  • 3.3.B.1 Network segmentation refers to the process of dividing a network into smaller, isolated segments or subnetworks (subnets).
  • 3.3.B.2 Dividing a network into smaller subnets isolates network traffic, which can prevent attacks on one subnet from impacting devices on other subnets.
  • 3.3.B.3 Network segmentation can allow for different security policies and controls to be applied to different segments of the network, allowing for higher security zones and lower security zones.
  • 3.3.B.4 Port security on a switch can prevent MAC flooding by limiting the number of addresses assignable to any single switch port.
العربية

هدف التعلم 3.3.A: تحديد تقنيات تقسيم الشبكة.

  • 3.3.A.1 يمكن استخدام مناطق جدار الحماية والقواعد لإنشاء شبكة فرعية محصنة (تُعرف أيضًا بمنطقة غير مسلحة، أو DMZ) — وهي جزء من الشبكة يقع بين الشبكات العامة الخارجية مثل الإنترنت والشبكات الداخلية الخاصة. عادةً ما تكون الشبكة الفرعية المحصنة أقل أمانًا من الشبكات الداخلية الخاصة، وتحتوي عادةً على الموارد التي تتجه نحو الجمهور داخل المؤسسة، لفصلها عن الشبكة الداخلية.
  • 3.3.A.2 يمكن استخدام تقسيم الشبكة الفرعية لإنشاء شبقات فرعية مختلفة بناءً على عنوان IP. إذا تم اختراق جهاز بواسطة مهاجم، يمكن للشبكات الفرعية احتواء الاختراق الأمني لتقليل عدد الأجهزة المكشوفة.
  • 3.3.A.3 يمكن استخدام المفاتيح لإنشاء شبكات افتراضية (VLANs)، والتي تفصل منطقيًا الأجهزة المتصلة فيزيائيًا بالمفاتيح المركزية.

الهدف التعليمي 3.3.B: اشرح لماذا يمكن أن يزيد تقسيم الشبكة من أمن الشبكة.

  • 3.3.B.1 يشير تقسيم الشبكة إلى عملية تقسيم الشبكة إلى أجزاء أصغر معزولة أو شبكات فرعية (subnets).
  • 3.3.B.2 تقسيم الشبكة إلى شبقات فرعية أصغر يعزل حركة مرور الشبكة، مما قد يمنع هجمات موجهة لشبكة فرعية واحدة من التأثير على الأجهزة الموجودة في شبقات فرعية أخرى.
  • 3.3.B.3 يمكن أن يسمح تقسيم الشبكة بتطبيق سياسات وأدوات تحكم أمنية مختلفة على أجزاء مختلفة من الشبكة، مما يتيح إنشاء مناطق أمان عالية ومناطق أمان منخفضة.
  • 3.3.B.4 يمكن أن تمنع الأمان المنفذ على منفذ في المفتاح (Port security on a switch) من غمر عناوين MAC عن طريق تحديد الحد الأقصى لعدد العناوين القابلة للتعيين لأي منفذ مفتاح واحد.

Source: College Board AP Course and Exam Description · ⁨المصدر: وصف دورة وامتحان College Board AP⁩

English

Network segmentation 网络分段 divides one network into smaller, isolated pieces (subnets 子网). If one subnet is breached, the damage is contained and cannot spread.

A key pattern is the screened subnet 屏蔽子网 (also called a DMZ 隔离区). It sits between the public internet and the private internal network, holding an organisation's public-facing servers in a lower-security zone - separated from the sensitive internal systems.

Segments can also be built with subnetting (by IP address) or VLANs 虚拟局域网 (logically separating devices on the same switch). Each segment can then get its own security policy - higher-security and lower-security zones.

العربية

تقسيم الشبكة يقسم شبكة واحدة إلى أجزاء أصغر ومعزولة (شبكات فرعية). إذا تم اختراق شبكة فرعية واحدة، يتم احتواء الضرر ولا يمكن أن ينتشر.

نمط رئيسي هو الشبكة الفرعية المحجوبة (تُعرف أيضًا بـDMZ). تقع بين الإنترنت العام والشبكة الداخلية الخاصة، وتحتوي على خوادم المنظمة الموجهة للجمهور في منطقة أقل أمانًا - معزولة عن الأنظمة الحساسة الداخلية.

الشبكة الفرعية المحجوبة (DMZ) تضع الخوادم العامة بين جدارين ناريين، بعيدًا عن الشبكة الخاصة
الشبكة الفرعية المحجوبة (DMZ) تضع الخوادم العامة بين جدارين ناريين، بعيدًا عن الشبكة الخاصة

يمكن بناء الأقسام أيضًا باستخدام تقسيم الشبكات (بناءً على عنوان IP) أو VLANs (فصل devices منطقياً على نفس المحول). بعد ذلك يمكن لكل قسم الحصول على سياسته الأمنية الخاصة - مناطق أعلى وأقل أمانًا.

رفوف الخوادم: يفصل تقسيم الشبكة الأنظمة بحيث لا يفتح اختراق واحد كل شيء
رفوف الخوادم: يفصل تقسيم الشبكة الأنظمة بحيث لا يفتح اختراق واحد كل شيء
Vocabulary · ⁨مفردات⁩ Train · ⁨تدريب⁩
English العربية
DMZ/ˌdiː em ˈzed/ DMZ
VLANs/ˈviːlænz/ شبكات VLAN
3.4

Protecting Networks: Firewalls · ⁨حماية الشبكات: الجدران النارية⁩

Syllabus · ⁨المنهج⁩
English

Learning Objective 3.4.A: Identify types of network-based firewalls.

  • 3.4.A.1 A firewall is used to allow or deny network traffic in or out of a network. The firewall itself is software that can be hosted on a standalone device or integrated into another network device, such as a router.
  • 3.4.A.2 A stateless firewall filters traffic based on information in packet headers, such as IP addresses, ports, and protocols.
  • 3.4.A.3 A stateful firewall (also known as dynamic packet filtering) tracks the state of network connections passing through the firewall and can filter according to connection-related rules in addition to the filtering done by a stateless firewall. This allows for more control over content allowed in and out of a network.
  • 3.4.A.4 A next-generation firewall (NGFW) has both the capabilities of typical stateless and stateful firewalls and additional advanced features, such as intrusion prevention, deep packet inspection, and filtering by application type.

Learning Objective 3.4.B: Explain how a firewall uses an access control list to allow or deny traffic entering or leaving a network.

  • 3.4.B.1 Network administrators create a set of rules, called an access control list (ACL), that a firewall uses to permit or deny inbound and outbound network traffic.
  • 3.4.B.2 ACL rules are checked in order and the first rule that matches the criteria will be executed for the specified data.
  • 3.4.B.3 A typical ACL will specify the direction of traffic (inbound or outbound), the criterion to filter by (IP addresses, logical port, service, or application), and the action to take (permit or deny).

Learning Objective 3.4.C: Determine the effective placement of firewalls in a network.

  • 3.4.C.1 Each segment of a network should have a firewall to control the flow of data in and out of that segment.
  • 3.4.C.2 Network segments may have different security needs based on the data and services within them. The level of security for each firewall can be set independently.
  • 3.4.C.3 Each point of data ingress and egress between the internal network and the public internet should have a firewall.

Learning Objective 3.4.D: Configure a firewall to manage the flow of network traffic.

  • 3.4.D.1 The requirements for a firewall will specify what type of traffic from which sources or to which destinations should be allowed or denied.
  • 3.4.D.2 Specific rules for a firewall can allow or deny inbound or outbound traffic based on source or destination port or IP address, service, protocol, or application.
    • Illustrative examples for 3.4.D.2:
      • Allow inbound TCP port 22 from ALL; (this rule will allow all inbound TCP traffic with destination port 22, which is the designated port for the SSH protocol)
      • Deny inbound TCP port 80 from 192.168.1.0/24; (this rule will deny inbound TCP traffic with destination port 80 from IP addresses in the 192.168.1.0-192.168.1.255 range)
  • 3.4.D.3 Rules are implemented in order, and changing the order of a set of rules can change which traffic is allowed or denied. Consideration must be given to the precedence of filtering priorities when establishing the order of rules.
    • Illustrative examples for 3.4.D.3:
      • This set of rules would allow SSH traffic and deny other inbound TCP traffic
      • Rule 1: ALLOW inbound TCP port 22 from ALL;
      • Rule 2: DENY inbound TCP ALL from ALL;
      • Reversing the order of those rules would deny all inbound TCP traffic including SSH traffic.
العربية

الهدف التعليمي 3.4.A: حدد أنواع جدران الحماية القائمة على الشبكة.

  • 3.4.A.1 يُستخدم جدار الحماية للسماح بحركة المرور عبر الشبكة أو رفضها من وإلى الشبكة. جدار الحماية نفسه هو برنامج يمكن استضافته على جهاز مستقل أو دمجه في جهاز شبكة آخر، مثل الموجه.
  • 3.4.A.2 يقوم جدار الحماية عديم الحالة بفلترة حركة المرور بناءً على المعلومات الموجودة في رؤوس الحزم، مثل عناوين IP والموانئ والبروتوكولات.
  • 3.4.A.3 جدار الحماية ذات الحالة (المعروف أيضًا بالفلترة الديناميكية للحزم) يتتبع حالة اتصالات الشبكة العابرة لجدار الحماية ويمكنه الفلترة وفقًا لقواعد مرتبطة بالاتصال بالإضافة إلى الفلترة التي يقوم بها جدار الحماية عديم الحالة. هذا يسمح بمزيد من التحكم في المحتوى المسموح به داخل وخارج الشبكة.
  • 3.4.A.4 جدار الحماية من الجيل التالي (NGFW) يمتلك قدرات جدران الحماية عديمة الحالة وذات الحالة التقليدية بالإضافة إلى ميزات متقدمة إضافية، مثل منع التسلل وفحص الحزم العميق والفلترة حسب نوع التطبيق.

الهدف التعليمي 3.4.B: اشرح كيف يستخدم جدار الحماية قائمة التحكم في الوصول للسماح بحركة المرور الداخلة أو خروجها من الشبكة أو رفضها.

  • 3.4.B.1 يقوم مسؤولو الشبكة بإنشاء مجموعة من القواعد تسمى قائمة التحكم في الوصول (ACL)، والتي يستخدمها جدار الحماية للسماح بحركة المرور عبر الشبكة الواردة والصادفة أو رفضها.
  • 3.4.B.2 يتم التحقق من قواعد ACL بالتسلسل، وسيتم تنفيذ أول قاعدة تطابق المعايير للبيانات المحددة.
  • 3.4.B.3 ستحدد قائمة التحكم في الوصول النموذجية اتجاه حركة المرور (واردة أو صادفة)، والمعايير المراد الفلترة بناءً عليها (عناوين IP، منفذ منطقي، خدمة، أو تطبيق)، والإجراء المتخذ (السماح أو الرفض).

الهدف التعليمي 3.4.C: حدد الموقع الفعال لجدران الحماية في الشبكة.

  • 3.4.C.1 يجب أن يحتوي كل جزء من أجزاء الشبكة على جدار حماية للتحكم في تدفق البيانات من وإلى ذلك الجزء.
  • 3.4.C.2 قد تختلف احتياجات الأمان لأجزاء الشبكة المختلفة بناءً على البيانات والخدمات الموجودة بداخلها. يمكن ضبط مستوى الأمان لكل جدار حماية بشكل مستقل.
  • 3.4.C.3 يجب أن يكون هناك جدار حماية عند كل نقطة دخول للخارج و exitedness (خروج) للبيانات بين الشبكة الداخلية والإنترنت العام.

الهدف التعليمي 3.4.D: قم بتكوين جدار حماية لإدارة تدفق حركة مرور الشبكة.

  • 3.4.D.1 ستحدد متطلبات جدار الحماية نوع حركة المرور التي يجب السماح بها أو رفضها من أي مصادر أو إلى أي وجهات.
  • 3.4.D.2 يمكن للقواعد المحددة لجدار الحماية السماح بحركة المرور الواردة أو الصادرة أو رفضها بناءً على منفذ المصدر أو الوجهة أو عنوان IP أو الخدمة أو البروتوكول أو التطبيق.
    • أمثلة توضيحية لـ 3.4.D.2:
      • السماح بمنفذ TCP 22 الوارد من ALL؛ (ستسمح هذه القاعدة بجميع حركة مرور TCP الواردة ذات منفذ الوجهة 22، وهو المنفذ المخصص لبروتوكول SSH)
      • رفض منفذ TCP 80 الوارد من 192.168.1.0/24؛ (ستقوم هذه القاعدة برفض حركة مرور TCP الواردة ذات منفذ الوجهة 80 من عناوين IP في نطاق 192.168.1.0-192.168.1.255)
  • 3.4.D.3 يتم تنفيذ القواعد بالتسلسل، وتغيير ترتيب مجموعة من القواعد يمكن أن يغير حركة المرور المسموح بها أو المرفوضة. يجب مراعاة الأولوية عند تحديد أولويات الفلترة عند إنشاء ترتيب القواعد.
    • أمثلة توضيحية لـ 3.4.D.3:
      • ستسمح هذه المجموعة من القواعد بحركة مرور SSH وترفض حركة مرور TCP الواردة الأخرى
      • القاعدة 1: السُمح بحركة مرور TCP 22 الواردة من ALL;
      • القاعدة 2: رُفض حركة مرور TCP الواردة جميعها من ALL;
      • عكس ترتيب تلك القواعد سيؤدي إلى رفض جميع حركة مرور TCP الواردة بما في ذلك حركة مرور SSH.

Source: College Board AP Course and Exam Description · ⁨المصدر: وصف دورة وامتحان College Board AP⁩

English
How a firewall decides

A firewall 防火墙 allows or denies traffic entering or leaving a network. There are several kinds:

  • Stateless 无状态 - filters on packet headers alone (IP, port, protocol).
  • Stateful 有状态 - also tracks the state of each connection for finer control.
  • Next-generation (NGFW) - adds advanced features like intrusion prevention and deep packet inspection.

A firewall follows an access control list (ACL) 访问控制列表 - an ordered set of rules. Rules are checked in order, and the first match wins, so the order of rules changes which traffic gets through. Each rule specifies a direction, a thing to filter by (IP, port, service), and an action (permit or deny).

Worked example. A firewall has Rule 3: DENY TCP 443 from 192.168.*, and lower down Rule 7: ALLOW TCP 443 from ALL. A user at 192.168.45.37 cannot reach port 443 - even though Rule 7 would allow them - because Rule 3 matches first, and the first match wins. The fix is to move the ALLOW rule above the DENY. This is why rule order, not just rule content, decides what traffic gets through.

Firewalls belong at every point where data crosses between zones - at each network segment and at every gateway to the public internet.

العربية

*كيف يقرر جدار الحماية

يسمح جدار الحماية أو يمنع حركة المرور الداخلة أو الخارجة من الشبكة. هناك عدة أنواع:

  • غير حاوية للحالة - تصفية العناوين الرئيسية للحزم وحدها (IP، منفذ، بروتوكول).
  • حاوية للحالة - تتبع أيضًا الحالة لكل اتصال للحصول على تحكم أدق.
  • الجيل التالي (NGFW) - تضيف ميزات متقدمة مثل منع الاختراق وفحص الحزم العميق.

يتبع جدار الحماية قائمة التحكم في الوصول (ACL) - مجموعة مرتبة من القواعد. يتم فحص القواعد بترتيبها، والأول الذي يتطابق هو الفائز، لذا فإن ترتيب القواعد يحدد أي حركة مرور تمر. تحدد كل قاعدة اتجاهًا، وشيءً للتصفية به (IP، منفذ، خدمة)، وإجراءً (السماح أو المنع).

جدار الحماية يفحص قائمة ACL الخاصة به من الأعلى إلى الأسفل؛ القاعدة الأولى المتطابقة هي التي تقرر *جدار الحماية يفحص قائمة ACL الخاصة به من الأعلى إلى الأسفل؛ القاعدة الأولى المتطابقة هي التي تقرر

مثال محلول. يمتلك جدار الحماية القاعدة 3: DENY TCP 443 from 192.168.*، والقاعدة 7 في الأسفل: ALLOW TCP 443 from ALL. المستخدم عند 192.168.45.37 لا يمكنه الوصول إلى المنفذ 443 - على الرغم من أن القاعدة 7 ستسمح له - لأن القاعدة 3 تتطابق أولاً، والأول الذي يتطابق هو الفائز. الحل هو نقل قاعدة السماح أعلى المنع. وهذا هو السبب في أن ترتيب القواعد، وليس محتوى القواعد فقط، يحدد ما إذا كانت حركة المرور ستمر أم لا.

تنتمي الجدران النارية إلى كل نقطة يعبر فيها البيانات بين المناطق - عند كل قطعة شبكة وعند كل بوابة للإنترنت العام.

مبدلات شبكية مثبتة في رف مع الكثير من كابل إيثرنت *عتاد شبكي حقيقي: جدار الحماية هو جهاز (أو برنامج) يقع حيث يلتقي هذه الكابلات بالعالم الخارجي

Vocabulary · ⁨مفردات⁩ Train · ⁨تدريب⁩
English العربية
firewall/ˈfaɪəwɔːl/ جدار حماية
Stateless/ˈsteɪtləs/ بدون حالة
Stateful/ˈsteɪtfl/ ذو حالة
access control list (ACL)/ˈækses kənˈtrəʊl lɪst/ قائمة التحكم في الوصول (ACL)
log files/lɒɡ faɪlz/ ملفات السجلات
network intrusion detection system (NIDS)/ˈnetwɜːk ɪnˈtruːʒn dɪˈtekʃn ˈsɪstəm/ نظام كشف التسلل الشبكي (NIDS)
network intrusion prevention system (NIPS)/ˈnetwɜːk ɪnˈtruːʒn prɪˈvenʃn ˈsɪstəm/ نظام منع التسلل الشبكي (NIPS)
security information and event management (SIEM)/sɪˈkjʊərɪti ˌɪnfəˈmeɪʃn ænd ɪˈvent ˈmænɪdʒmənt/ إدارة معلومات وأحداث الأمن السيبراني (SIEM)
Signature-based/ˈsɪɡnɪtʃə beɪst/ قائم على العلامات
Anomaly-based/əˈnɒməli beɪst/ قائم على الشذوذ
baseline/ˈbeɪslaɪn/ الخط الأساسي
network-based indicators of compromise/ˈnetwɜːk beɪst ˈɪndɪkeɪtəz ɒv ˈkɒmprəmaɪz/ مؤشرات التعرض للاختراق القائمة على الشبكة
probabilistic/ˌprɒbəbɪˈlɪstɪk/ احتمالي
threshold/ˈθreʃəʊld/ عتبة
alert fatigue/əˈlɜːt fəˈtiːɡ/ إرهاق التنبيهات
3.5

Detecting Network Attacks · ⁨اكتشاف هجمات الشبكة⁩

Syllabus · ⁨المنهج⁩
English

Learning Objective 3.5.A: Identify types of automated security tools used to detect network attacks.

  • 3.5.A.1 Automated detection tools analyze data collected from an organization’s network and devices, such as switches and routers, servers, firewalls, and user computers. These data are often collected in a log file.
  • 3.5.A.2 A network intrusion detection system (NIDS) is an automated tool that analyzes data to determine if malicious activity is taking place on a network. When an attack is detected, it generates an alert.
  • 3.5.A.3 A network intrusion prevention system (NIPS) is an automated tool that, like an IDS, analyzes data to determine if malicious activity is taking place on a network. A NIPS can also mitigate or halt an attack by closing ports, blocking specific IP or MAC addresses, or rejecting specific protocols.
  • 3.5.A.4 A security information and event management (SIEM) system collects and analyzes data from multiple sources (including firewalls, NIDS/NIPS, device logs, and application logs) to detect patterns that may indicate a cyberattack and raises an alert if a potential attack is detected. Security analysts investigate the alert to determine whether it represents a true threat and follow standard operating procedures to resolve or escalate the alert.

Learning Objective 3.5.B: Explain how organizations can leverage artificial intelligence (AI) to enhance threat detection and response.

  • 3.5.B.1 Computers log every action that users take. Firewalls, IDS, IPS, and other network sensors log all the traffic passing through various points in a network. A medium-sized organization’s network is logging millions (or even tens of millions) of data points per day. Even a large team of humans is incapable of analyzing so much data.
  • 3.5.B.2 Threat detection teams are creating AI algorithms to analyze large amounts of data and classify the data patterns as malicious or normal.
  • 3.5.B.3 AI models for threat detection are based on probabilistic calculations; they report a percentage to indicate the likelihood that something is malicious.
  • 3.5.B.4 Organizations determine their own thresholds for what percentage of likelihood of a threat results in an alert. If the threshold is set too high, real attacks may go undetected; if the threshold is too low, the security team will be overwhelmed with false alerts.

Learning Objective 3.5.C: Determine a network detection method.

  • 3.5.C.1 Volume of network traffic is a criterion for determining a detection method. Signature-based detection is more efficient for networks with high traffic volume. Signature-based detection compares detection data to a database of known indicators of compromise (IoCs), called signatures. Signature databases must be updated with IoCs for the latest attacks. Signature-based detection runs more quickly than anomaly-based detection.
  • 3.5.C.2 Consistency of network traffic patterns is a criterion for determining a detection method. Anomaly-based detection is most effective on networks with consistent traffic patterns. Anomaly-based detection compares detection data to a baseline of recorded activity. Baselines must be recorded on uncompromised systems to establish expected data types and volumes. Anomaly-based detection triggers an alert or action when data types or volumes outside of a specified tolerance range are recorded. Anomaly-based detection relies on consistent patterns in network traffic to detect anomalous traffic patterns.
  • 3.5.C.3 Degree of sensitivity or criticality of a network is a criterion for determining a detection method. Networks with more sensitive or critical data or services will likely consider a hybrid approach. Hybrid detection combines signature-based and anomaly-based detection. Hybrid detection is more expensive than using either signature- or anomaly-based detection alone, and hybrid-detection models generate more alerts.
  • 3.5.C.4 Likelihood of novel attacks on a network is a criterion for determining a detection method. Signature-based detection cannot detect a new attack. When an organization suspects that adversaries are likely to attempt a new attack on a network, anomaly-based detection is the preferred method when the cost of hybrid detection is prohibitively high.

Learning Objective 3.5.D: Evaluate the impact of a network detection method.

  • 3.5.D.1 Speed of detection is a factor in evaluating the impact of a network detection method. Faster detection enables faster response. Signature-based detection methods are faster than anomaly-based detection methods, especially on networks with high traffic volume.
  • 3.5.D.2 Cost is a factor in evaluating the impact of a network detection method. Detection tools and ongoing costs need to be within a budget. Anomaly-based detection systems require more expensive hardware to operate than signature based. Hybrid detection is the most expensive option because it combines both anomaly- and signature-based methods.
  • 3.5.D.3 False positive rate is a factor in evaluating the impact of a network detection method. Signature-based detection has almost no false positives. Anomaly-based or hybrid detection will have higher false positive rates. Impacts of high false positive rates include:
    • Time and resources are put toward investigating alerts for nonmalicious activity.
    • Alert fatigue is a condition that occurs when responders get accustomed to false positives and take alerts less seriously because they assume alerts are false positives before investigating them.
  • 3.5.D.4 False negative rate is a factor in evaluating the impact of a network detection method. A false negative occurs when an adversary can bypass a detection system. Signature-based detection systems are easier to bypass than anomaly-based or hybrid systems. False negatives can result in adversaries causing loss, harm, disruption, or destruction to data and systems.

Learning Objective 3.5.E: Apply detection techniques to identify indicators of network attacks by analyzing log files.

  • 3.5.E.1 Evil-twin attacks can be detected by regularly scanning for service set identifiers (SSIDs) that look suspicious or similar to local legitimate SSIDs. Signal triangulation can be used to locate and disable an access point broadcasting an evil-twin network.
  • 3.5.E.2 Jamming attacks can be detected by recognizing that no wireless devices in a specific physical space are able to connect to a wireless network and by scanning for electromagnetic (EM) noise in the wireless range.
  • 3.5.E.3 ARP poisoning attacks can be detected by monitoring network traffic for unusual ARP messages (particularly duplicate MAC address ARP packets) and checking the ARP table on the default gateway.
  • 3.5.E.4 MAC flooding attacks can be detected by monitoring network traffic for an unexpected surge of Ethernet frames with different MAC addresses and checking the MAC address table on a switch.
  • 3.5.E.5 DNS poisoning attacks are difficult to detect. However, if an organization’s website experiences an abrupt and otherwise inexplicable drop in traffic, DNS records should be examined as a potential cause.
  • 3.5.E.6 Smurf attacks can be detected by watching network traffic for a sudden increase in ICMP requests sent to the network’s broadcast address.
  • 3.5.E.7 Network-based IoCs are discovered when analyzing network traffic, often in the form of packet capture files. Indicators can be found in source and destination IP addresses, ports, and protocols. These can include:
    • Connections to known malicious IP addresses
    • Unauthorized network scans
    • Unusual spikes or slow downs in network traffic
    • Mismatched port-application traffic
العربية

الهدف التعليمي 3.5.A: حدد أنواع أدوات الأمن الآلية المستخدمة لاكتشاف هجمات الشبكة.

  • 3.5.A.1 تقوم أدوات الكشف الآلي بتحليل البيانات المجمعة من شبكة المنظمة وأجهزتها، مثل المفاتيح والموجهات والخوادم وجدران الحماية وأجهزة كمبيوتر المستخدمين. غالبًا ما يتم جمع هذه البيانات في ملف سجل.
  • 3.5.A.2 نظام كشف التسلل في الشبكة (NIDS) هو أداة آلية تحلل البيانات لتحديد ما إذا كانت نشاط ضار يحدث على الشبكة. عند اكتشاف هجوم، فإنه ينشئ تنبيهًا.
  • 3.5.A.3 نظام منع اختراق الشبكة (NIPS) هو أداة آلية تحلل البيانات لتحديد ما إذا كان هناك نشاط ضار على الشبكة، تماماً مثل نظام كشف الاختراقات (IDS). يمكن لنظام NIPS أيضاً التخفيف من هجمات أو إيقافها عن طريق إغلاق المنافذ، أو حظر عناوين IP أو MAC محددة، أو رفض بروتوكولات معينة.
  • 3.5.A.4 نظام إدارة المعلومات والأحداث الأمنية (SIEM) يجمع ويحلل البيانات من مصادر متعددة (بما في ذلك جدران الحماية، وأنظمة كشف/منع الاختراقات NIDS/NIPS، وسجلات الأجهزة، وسجلات التطبيقات) للكشف عن أنماط قد تشير إلى هجوم سيبراني ورفع تنبيه في حال اكتشاف هجوم محتمل. يقوم محللو الأمن بتحليل التنبيهات لتحديد ما إذا كانت تمثل تهديداً حقيقياً واتباع الإجراءات التشغيلية القياسية لحل التنبيه أو تصعيده.

الهدف التعليمي 3.5.B: اشرح كيف يمكن للمنظمات الاستفادة من الذكاء الاصطناعي (AI) لتعزيز الكشف عن التهديدات والاستجابة لها.

  • 3.5.B.1 تسجل أجهزة الحاسوب كل إجراء يتخذه المستخدمون. وتسجل جدران الحماية، وأنظمة كشف الاختراقات (IDS)، وأنظمة منعها (IPS)، وأجهزة الاستشعار الشبكية الأخرى جميع حركة المرور المارة عبر نقاط مختلفة في الشبكة. تقوم شبكات المنظمات المتوسطة بتسجيل ملايين (أو حتى عشرات الملايين) من نقاط البيانات يومياً. ولا يستطيع أي فريق بشري كبير تحليل هذه الكمية الهائلة من البيانات.
  • 3.5.B.2 تقوم فرق الكشف عن التهديدات بإنشاء خوارزميات ذكاء اصطناعي لتحليل كميات كبيرة من البيانات وتصنيف أنماطها على أنها ضارة أو عادية.
  • 3.5.B.3 تعتمد نماذج الذكاء الاصطناعي للكشف عن التهديدات على حسابات احتمالية؛ حيث تقدم نسبة مئوية تشير إلى احتمالية كون الشيء ضاراً.
  • 3.5.B.4 تحدد المنظمات عتباتها الخاصة لحد نسبة الاحتمالية التي تستدعي إصدار تنبيه عند وجود تهديد. وإذا كانت العتبة مرتفعة جداً، قد تفوت الهجمات الحقيقية دون أن تُكتشف؛ أما إذا كانت منخفضة جداً، فإن فريق الأمن سيكون غارقاً في التنبيهات الخاطئة.

الهدف التعليمي 3.5.C: حدد طريقة لكشف الشبكة.

  • 3.5.C.1 حجم حركة مرور الشبكة هو معيار لتحديد طريقة الكشف. يكون الكشف القائم على التواقيع أكثر كفاءة للشبكات ذات حجم حركة المرور العالي. يقارن الكشف القائم على التواقيع بيانات الكشف بقاعدة بيانات لمؤشرات الاختراق المعروفة (IoCs)، تسمى التواقيع. يجب تحديث قواعد التواقيع بمؤشرات الاختراق الخاصة بأحدث الهجمات. يعمل الكشف القائم على التواقيع بسرعة أكبر من الكشف القائم على الانحرافات.
  • 3.5.C.2 انتظام أنماط حركة مرور الشبكة هو معيار لتحديد طريقة الكشف. يكون الكشف القائم على الانحرافات الأكثر فعالية على الشبكات ذات الأنماط المنتظمة لحركة المرور. يقارن الكشف القائم على الانحرافات بيانات الكشف بسجل قياسي للأنشطة المسجلة. يجب تسجيل السجلات القياسية على أنظمة غير مخترقة لتحديد أنواع وحجم البيانات المتوقعة. يُصدر الكشف القائم على الانحرافات تنبيهاً أو إجراءً عند تسجيل أنواع بيانات أو أحجام خارج نطاق التحمل المحدد. يعتمد الكشف القائم على الانحرافات على الأنماط المنتظمة في حركة مرور الشبكة لاكتشاف أنماط الحركة غير الطبيعية.
  • 3.5.C.3 درجة حساسية أو أهمية الشبكة هي معيار لتحديد طريقة الكشف. من المرجح أن تتبنى الشبكات التي تحتوي على بيانات أو خدمات أكثر حساسية أو أهمية نهجاً هجيناً. يجمع الكشف الهجين بين الكشف القائم على التواقيع والكشف القائم على الانحرافات. يعد الكشف الهجين أغلى تكلفة من استخدام الكشف القائم على التواقيع أو الانحرافات بشكل منفصل، وتنتج نماذج الكشف الهجين تنبيهات أكثر.
  • 3.5.C.4 احتمالية وقوع هجمات جديدة على الشبكة هو معيار لتحديد طريقة الكشف. لا يمكن للكشف القائم على التواقيع اكتشاف هجوم جديد. عندما تشك المنظمة في أن المهاجمين قد يحاولون شن هجوم جديد على الشبكة، يكون الكشف القائم على الانحرافات هو الطريقة المفضلة إذا كانت تكلفة الكشف الهجين باهظة للغاية.

الهدف التعليمي 3.5.D: قيّم تأثير طريقة كشف الشبكة.

  • 3.5.D.1 سرعة الكشف هي عامل في تقييم تأثير طريقة كشف الشبكة. يتيح الكشف الأسرع استجابة أسرع. تكون طرق الكشف القائم على التواقيع أسرع من طرق الكشف القائم على الانحرافات، خاصة على الشبكات ذات حجم حركة المرور العالي.
  • 3.5.D.2 التكلفة هي عامل في تقييم تأثير طريقة كشف الشبكة. يجب أن تكون أدوات الكشف والتكاليف الجارية ضمن الميزانية. تتطلب أنظمة الكشف القائم على الانحرافات عتاداً أكثر تكلفة للعمل مقارنة بالكشف القائم على التواقيع. يعد الكشف الهجين الخيار الأغلى لأنه يجمع بين طريقي الكشف القائم على الانحرافات والتواقيع.
  • 3.5.D.3 معدل الإيجابية الخاطئة هو عامل في تقييم تأثير طريقة كشف الشبكة. يمتلك الكشف القائم على التواقيع تقريباً لا إيجابية خاطئة. بينما سيكون للكشف القائم على الانحرافات أو الهجين معدلات أعلى للإيجابية الخاطئة. تشمل آثار معدلات الإيجابية الخاطئة المرتفعة ما يلي:
    • يتم تخصيص الوقت والموارد للتحقيق في التنبيهات المتعلقة بأنشطة غير ضارة.
    • إرهاق التنبيهات هو حالة تحدث عندما يعتاد المستجيبون على الإيجابيات الخاطئة ويأخذون التنبيهات بجدية أقل لأنهم يفترضون مسبقاً أنها إيجابية خاطئة قبل التحقق منها.
  • 3.5.D.4 معدل السلبية الخاطئة هو عامل في تقييم تأثير طريقة كشف الشبكة. يحدث الخطأ السلبي عندما يتمكن المهاجم من تجاوز نظام الكشف. systems الكشف القائم على التواقيع أسهل في التجاوز من الأنظمة القائمة على الانحرافات أو الهجينة. يمكن أن تؤدي الأخطاء السلبية إلى تسبب المهاجمين في خسائر أو أضرار أو اضطراب أو تدمير للبيانات والأنظمة.

الهدف التعليمي 3.5.E: طبق تقنيات الكشف لتحديد مؤشرات هجمات الشبكة من خلال تحليل ملفات السجلات.

  • 3.5.E.1 يمكن الكشف عن هجمات التوأم الشرير من خلال المسح المنتظم لمعرفات مجموعة الخدمة (SSIDs) التي تبدو مشبوهة أو مشابهة لمعرفات المجموعة المحلية الشرعية. يمكن استخدام مثلث الإشارة لتحديد موقع وإيقاف نقطة وصول تبث شبكة توأم شرير.
  • 3.5.E.2 يمكن الكشف عن هجمات التشويش من خلال إدراك عدم قدرة أي أجهزة لاسلكية في مساحة فيزيائية محددة على الاتصال بشبكة لاسلكية، ومن خلال المسح للضوضاء الكهرومغناطيسية (EM) ضمن نطاق اللاسلكي.
  • 3.5.E.3 يمكن الكشف عن هجمات تسميم ARP من خلال مراقبة حركة مرور الشبكة بحثًا عن رسائل ARP غير اعتيادية (خاصة حزم ARP ذات عنوان MAC مكرر) وفحص جدول ARP على البوابة الافتراضية.
  • 3.5.E.4 يمكن الكشف عن هجمات طمس MAC من خلال مراقبة حركة مرور الشبكة بحثًا عن ارتفاع مفاجئ وغير متوقع في إطارات الإيثرت넷 ذات عناوين MAC مختلفة، وفحص جدول عناوين MAC على المحول.
  • 3.5.E.5 هجمات تسميم DNS يصعب كشفها. ومع ذلك، إذا شهدت موقع إلكتروني لمنظمة انخفاضًا مفاجئًا وغير مبرر آخر في حركة المرور، فيجب فحص سجلات DNS باعتبارها سببًا محتملاً.
  • 3.5.E.6 يمكن الكشف عن هجمات Smurf من خلال مراقبة حركة مرور الشبكة بحثًا عن زيادة مفاجئة في طلبات ICMP المرسلة إلى عنوان البث الخاص بالشبكة.
  • 3.5.E.7 تُكتشف مؤشرات الخطر القائمة على الشبكة عند تحليل حركة مرور الشبكة، وغالبًا ما تكون على شكل ملفات التقاط الحزم. يمكن العثور على المؤشرات في عنايف IP المصدر والوجهة، والمنافذ، والبروتوكولات. وتشمل هذه:
    • الاتصالات بعنايف IP خبيثة معروفة
    • مسوحات الشبكة غير المصرح بها
    • قفزات غير معتادة أو بطء في حركة مرور الشبكة
    • عدم تطابق حركة المرور بين المنافذ والتطبيقات

Source: College Board AP Course and Exam Description · ⁨المصدر: وصف دورة وامتحان College Board AP⁩

English

When prevention fails, detection takes over. Automated tools read the log files 日志文件 that record network activity:

  • a network intrusion detection system (NIDS) 网络入侵检测系统 analyses traffic and raises an alert, but does not block;
  • a network intrusion prevention system (NIPS) 网络入侵防御系统 can also stop an attack by closing ports or blocking addresses;
  • a security information and event management (SIEM) 安全信息与事件管理 system gathers data from many sources to spot patterns.

There are two detection methods. Signature-based 基于特征 detection compares traffic to a database of known attack signatures - fast and low on false alarms, but blind to brand-new attacks. Anomaly-based 基于异常 detection compares traffic to a normal baseline 基线 and flags anything unusual - it can catch novel attacks but needs more resources and raises more false alarms. A hybrid approach combines both.

Examining captured traffic (packet-capture files), analysts hunt for network-based indicators of compromise 网络入侵指标 in the source and destination IP addresses, ports, and protocols. Four common ones: connections to known-malicious IP addresses, unauthorized network scans (an outsider probing your ports), unusual spikes or slowdowns in traffic, and mismatched port-application traffic (for example, non-web traffic flowing over port 80). These complete the host-, file-, and behaviour-based indicators a single device logs.

AI, thresholds, and alert fatigue

A medium network logs millions of events a day - far more than any team can read - so organisations train AI models to sort likely-malicious patterns from normal ones. These models are probabilistic 概率的: rather than a yes/no, each event gets a percentage likelihood of being malicious.

The organisation then sets a threshold 阈值 - the likelihood at which an alert fires - and that choice is a genuine trade-off:

  • set the threshold too high and real attacks slip through undetected;
  • set it too low and the team is overwhelmed with false alerts.

Too many false alerts cause alert fatigue 警报疲劳: responders get so used to false positives that they start assuming an alert is false before investigating it - so a real attack, when it finally comes, is waved away. This is exactly why a low false-positive rate matters: signature-based detection has almost none, while anomaly-based and hybrid detection trade a higher false-positive rate for the ability to catch novel attacks.

العربية

عند فشل الوقاية،takes over الاكتشاف. تقرأ الأدوات الآلية ملفات السجل التي تسجل نشاط الشبكة:

  • نظام كشف اختراق الشبكة (NIDS) يحلل حركة المرور ويرفع تنبيهًا، لكنه لا يحجب؛
  • نظام منع اختراق الشبكة (NIPS) يمكنه أيضًا وقف هجوم عن طريق إغلاق المنافذ أو حظر العناوين؛
  • نظام إدارة معلومات وأحداث الأمن السيبراني (SIEM) يجمع البيانات من مصادر متعددة لاكتشاف الأنماط.

هناك طريقتان للاكتشاف. يعتمد الكشف القائم على البصمة على مقارنة حركة المرور بقاعدة بيانات لـبصمات الهجمات المعروفة - سريع ومنخفض في التنبيهات الوهمية، لكنه أعمى تجاه الهجمات الجديدة تمامًا. يعتمد الكشف القائم على الشذوذ على مقارنة حركة المرور بـخط أساس طبيعي ويحدد أي شيء غير معتاد - يمكنه التقاط هجمات جديدة ولكنه يتطلب موارد أكثر ويرفع تنبيهات وهمية أكثر. نهج هجين يجمع الاثنين معًا.

باستخدام حركة المرور المُلتقطة (ملفات التقاط الحزم)، يبحث المحللون عن مؤشرات compromise القائمة على الشبكة في عناوين IP المصدر والوجهة والمنافذ والبروتوكولات. أربعة شائعة منها: الاتصالات إلى عناوين IP خبيثة معروفة، مسح شبكي غير مصرح به (طرف غريب يختبر منافذك)، ارتفاعات أو بطءات غير طبيعية في حركة المرور، وعدم تطابق حركة التطبيق والمنفذ (على سبيل المثال، حركة مرور غير ويب تتدفق عبر المنفذ 80). تكمل هذه مؤشرات القائمة على المضيف والملف والسلوك التي تسجيلها جهاز واحد.

الذكاء الاصطناعي، والعوائق، وإرهاق التنبيهات

تسجل الشبكة المتوسطة ملايين الأحداث يوميًا - أكثر بكثير مما يمكن لأي فريق قراءته - لذلك تدرب المنظمات نماذج ذكاء اصطناعي لفرز الأنماط المحتملة الخبيثة عن تلك الطبيعية. هذه النماذج احتمالية: بدلاً من نعم/لا، تحصل كل حدث على نسبة مئوية لاحتمالية أن تكون خبيثة.

تضع المنظمة بعد ذلك عتبة - وهي احتمالية إطلاق الإنذار - وتُعدّ هذه الاختيار مفاضلة حقيقية:

  • إذا وضعت العتبة مرتفعة جداً، فإن الهجمات الحقيقية ستتمر بدون اكتشاف;
  • إذا وضعتها منخفضة جداً، فستكون الفريق مذعوراً من كثرة التنبيهات الكاذبة.

كثرة التنبيهات الكاذبة تُسبب إرهاق التنبيهات: يصبح المستجيبون معتادين على الإيجابيات الكاذبة لدرجة أنهم يفترضون أن التنبيه كاذب قبل التحقق منه - لذا، عندما تأتي هجمة حقيقية أخيراً، يتم تجاهلها. ولهذا السبب تحديداً انخفاض معدل الإيجابيات الكاذبة مهم: حيث أن الكشف القائم على التواقيع لا يحتوي تقريباً عليها، بينما يتنازل الكشف القائم على الشذوذ والكشف الهجين عن معدل أعلى للإيجابيات الكاذبة مقابل القدرة على رصد الهجمات الجديدة.

الكشف القائم على التواقيع يطابق الهجمات المعروفة؛ الكشف القائم على الشذوذ يحدد الانحرافات عن النمط الطبيعي
الكشف القائم على التواقيع يطابق الهجمات المعروفة؛ الكشف القائم على الشذوذ يحدد الانحرافات عن النمط الطبيعي
3.5

Exam tips · ⁨نصائح للامتحان⁩

English
  • For firewall-ACL questions, read the rules top-to-bottom and stop at the first match - a Deny rule above an Allow blocks the traffic even though the Allow exists lower down.
  • Pair each attack with its tell-tale sign: ARP poisoning = one IP with two MAC addresses; MAC flooding = a surge of new MAC addresses; DNS poisoning = an unexplained drop in web traffic.
  • Read packet captures for network-based IoCs: known-malicious IPs, unauthorized scans, traffic spikes/slowdowns, and mismatched port-application traffic.
  • Run vulnerability scanners to find known weaknesses proactively, and fix the highest-severity findings first.
  • Signature-based = fast, few false positives, misses new attacks (more false negatives); anomaly-based = catches new attacks, costs more, more false positives. Memorise this trade-off.
  • A screened subnet / DMZ holds public-facing servers between the internet and the private network - name it whenever a question separates public services from internal data.
  • WPA3 is the strong wireless encryption; WEP and original WPA are insecure.
العربية
  • بالنسبة لأسئلة جدار الحماية وقوائم التحكم بالوصول (ACL)، اقرأ القواعد من الأعلى إلى الأسفل وتوقف عند أول تطابق - فالقاعدة المنفرة (Deny) الموجودة فوق قاعدة السماح (Allow) تمنع حركة المرور حتى لو كانت هناك قاعدة سماح موجودة أسفلها.
  • اربط كل هجوم بـ علامته المميزة: تسميم ARP = عنوان IP واحد مع عناوين MAC اثنين؛ غرق MAC = ارتفاع مفاجئ في عناوين MAC الجديدة؛ تسميم DNS = انخفاض غير مبرر في حركة مرور الويب.
  • اقرأ لقطات الحزم (Packet captures) للبحث عن مؤشرات الاختراق القائمة على الشبكة: عناوين IP خبيثة معروفة، مسحات غير مصرح بها، ذروة/انخفاض في حركة المرور، وحركة مرور بين المنافذ والتطبيقات غير متطابقة.
  • قم بتشغيل فحاصات الثغرات للعثور على الضعف المعروف بشكل استباقي، وأصلح النتائج ذات الأولوية الأعلى أولاً.
  • القائم على التواقيع = سريع، قليل من الإيجابيات الكاذبة، يفوت الهجمات الجديدة (زيادة في السلبيات الكاذبة)؛ القائم على الشذوذ = يرصد الهجمات الجديدة، تكلفته أعلى، أكثر إيجابيات كاذبة. احفظ هذه المفاضلة.
  • الشبكة الفرعية المحصنة / منطقة الخدمة المحايدة (DMZ) تستضيف الخوادم الموجهة للعامة بين الإنترنت والشبكة الخاصة - اذكر هذا المصطلح كلما طُلب منك فصل الخدمات العامة عن البيانات الداخلية.
  • WPA3 هو التشفير اللاسلكي القوي؛ بينما WEP وWPA الأصلي غير آمنين.

Interactive lessons on this topic · ⁨دروس تفاعلية حول هذا الموضوع⁩

Work through it step by step, with instant-check exercises. · ⁨ا-working عليه خطوة بخطوة، مع تمارين تحقق فوري.⁩

Past Papers · ⁨أوراق الامتحانات السابقة⁩

More topics in AP Cybersecurity · ⁨الأمن السيبراني (AP)⁩ · ⁨المزيد من المواضيع في AP Cybersecurity · ⁨الأمن السيبراني (AP)⁩⁩

Log in or create account · ⁨تسجيل الدخول أو إنشاء حساب⁩

IGCSE, A-Level & AP