Skip to content · ⁨الانتقال إلى المحتوى⁩

Securing Devices · ⁨تأمين الأجهزة⁩

AP Cybersecurity · ⁨الأمن السيبراني (AP)⁩ · Topic 4 · ⁨الموضوع 4⁩

Video lesson for this topic · ⁨درس فيديو لهذا الموضوع⁩ Open the video page · ⁨افتح صفحة الفيديو⁩
9:32

تأمين الأجهزة

إنه صباح الاثنين في مستشفى مزدحم. في أقل من دقيقة، تتغير الشاشات في الجناح والمختبر الصيدلي ومكتب السجلات جميعها. كل ملف عليها هو…

English narration · English + 中文 subtitles burned in · ⁨سرد باللغة الإنجليزية · ترجمة مدمجة بالإنجليزية + الصينية⁩

4.1

Device Vulnerabilities and Attacks · ⁨ثغرات الأجهزة والهجمات⁩

Syllabus · ⁨المنهج⁩
English

Learning Objective 4.1.A: Identify types of computing devices.

  • 4.1.A.1 Server computers are devices that provide one or more services to other computers (e.g., DNS, DHCP, FTP). Any computer can be a server, and in an enterprise environment servers typically have more processing power and storage than a personal computer.
  • 4.1.A.2 Personal computers are devices that are designed to be used by one person for work or recreational purposes (e.g., word processing, graphic design, web browsing, and media production or viewing). These include desktop, laptop, and notebook computers.
  • 4.1.A.3 Handheld computers (also called mobile computers or information appliances) are smaller than personal computers and run on battery power. These include tablets, smartphones, and wearable technology like smart watches.
  • 4.1.A.4 Embedded computers are devices that are part of a machine. Embedded devices have specific instruction sets for interfacing with the specialized components of the machine they’re embedded in. Embedded computers tend to be slower and cheaper than other computers and have minimal storage.
  • 4.1.A.5 Everyday devices with embedded computers are often called Internet of Things (IoT) devices. Embedded computers are found in transportation (e.g., cars, trains, and airplanes), devices that operate critical infrastructure (e.g., operating circuit breakers at electrical substations and pumps at water treatment plants), medical equipment (e.g., IV pumps, MRI scanners, pacemakers, and insulin pumps), and everyday devices like washing machines, coffee makers, and thermostats.

Learning Objective 4.1.B: Identify the type of malware used in a cyberattack.

  • 4.1.B.1 Malware is malicious software that can damage or destroy a device or network, or allow an adversary access to a device and the data on the device.
  • 4.1.B.2 Malware is often used as a tool to accomplish part of an adversary’s plan to achieve their ultimate goal(s). There are many types of malware, such as:
    • Viruses are malware that must be activated by a user executing or opening a file.
    • Worms spread from one computer to another without human interaction.
    • Trojans are malware embedded in other software that seems harmless. Remote access trojans (RATs) provide an adversary with remote access to the target system.
    • Ransomware encrypts a device’s files, preventing the user from accessing files on the device. The ransomware typically presents the user with a screen demanding payment and promising to give the user a decryption key for their files if the user pays within a fixed amount of time.
    • Spyware tracks a user’s actions on a computer and sends information back to an adversary.
    • A keylogger is software or hardware that logs the users keystrokes and sends the information back to the adversary. Adversaries can often extract usernames and passwords from keylogger data.
    • Logic bombs are set to trigger their effect only when a specific set of conditions are met; the conditions can include time and date, specific type or version of the operating system, character set the computer is using, etc.
    • A rootkit is sophisticated malware that gets into the target computer’s operating system and can control nearly every aspect of the system, including making the rootkit itself invisible to detection.
  • 4.1.B.3 While most malware is a file or a collection of files, fileless malware is malicious code that lives in RAM and uses legitimate programs already installed on a device to compromise it.

Learning Objective 4.1.C: Explain how adversaries can exploit common device vulnerabilities to cause loss, damage, disruption, or destruction.

  • 4.1.C.1 Adversaries can develop exploits for known vulnerabilities in software (including operating systems). Devices with unpatched software are vulnerable to these exploits, which could allow an adversary to crash a system, view user actions, enable or disable various services or components on the device (e.g., turning on a webcam or microphone), or even take control of the device to issue their own commands including commands to steal or destroy information on the device.
  • 4.1.C.2 Adversaries can take advantage of weak authentication requirements by guessing a user’s password or using social engineering to get a user to divulge their password.
  • 4.1.C.3 When systems don’t have a password on the basic input output system (BIOS) or unified extensible firmware interface (UEFI), an adversary can boot a computer into a special mode (e.g., “recovery mode”) that gives them higher-level privileges. Without BIOS or UEFI protection, adversaries can load their own operating system onto a device from an external drive and use specialized tools to alter or create user profiles, including changing user passwords.
  • 4.1.C.4 Adversaries can load malware onto an external drive, and if autorun is enabled, then a device will run the malware when the external drive is inserted.
  • 4.1.C.5 Adversaries can leverage open ports to connect to a device.
  • 4.1.C.6 Adversaries can send malicious data to devices to disrupt them or attempt to take control of them. Devices that have no firewall (or a misconfigured firewall) cannot filter out this malicious data.
  • 4.1.C.7 Adversaries often attempt to install malware on a device to disrupt or control it. Devices lacking anti-malware software are more vulnerable to this type of attack.

Learning Objective 4.1.D: Assess and document risks from device vulnerabilities.

  • 4.1.D.1 Risk from device vulnerabilities can come from unauthorized access or malware that allow an adversary to impersonate an authorized user, remotely control a device, encrypt a device’s drive to ransom the data, or wipe a device’s memory, destroying data or rendering the device inoperable. The level of risk varies depending on the criticality of the device or the services the device provides or data it stores.
  • 4.1.D.2 High risks from device vulnerabilities involve potentially compromising sensitive data or critical operations.
    • Illustrative examples for 4.1.D.2:
      • An organization has not installed the most recent update for their email server which included a patch for a known critical vulnerability.
  • 4.1.D.3 Moderate risks from device vulnerabilities can arise from weak authentication requirements or from vulnerabilities that would be less likely to be exploited.
    • Illustrative examples for 4.1.D.3:
      • A water treatment plant has embedded systems controlling pumps. The pumps can be remotely accessed via username and password for remote management for the plant, but the devices do not require multi-factor authentication (MFA).
  • 4.1.D.4 Low risks from device vulnerabilities are typically related to vulnerabilities that, if exploited, would have little impact.
    • Illustrative examples for 4.1.D.4:
      • An employee’s laptop has telnet port 23 open.
العربية

هدف التعلم 4.1.A: تحديد أنواع أجهزة الحوسبة.

  • 4.1.A.1 حواسيب الخادم هي أجهزة توفر خدمة واحدة أو أكثر لأجهزة أخرى (مثل DNS و DHCP و FTP). يمكن لأي جهاز كمبيوتر أن يكون خادمًا، وفي بيئة الشركات عادةً ما تمتلك الخوادم قدرات معالجة وتخزين أكبر من الكمبيوتر الشخصي.
  • 4.1.A.2 الحواسيب الشخصية هي أجهزة مصممة لاستخدامها شخص واحد لأغراض العمل أو الترفيه (مثل معالجة النصوص، وتصميم الجرافيك، وتصفح الويب، وإنتاج الوسائط أو مشاهدتها). وتشمل حواسيب سطح المكتب والمحمولة ومفكرة الحاسوب.
  • 4.1.A.3 الحواسيب المحمولة (تُسمى أيضًا الحواسيب النقالة أو تطبيقات المعلومات) أصغر حجمًا من الحواسيب الشخصية وتعمل بالبطارية. وتشمل الأجهزة اللوحية والهواتف الذكية والأجهزة القابلة للارتداء مثل الساعات الذكية.
  • 4.1.A.4 الحواسيب المدمجة هي أجهزة جزء من آلة. تحتوي الأجهزة المدمجة على مجموعات تعليمات محددة للتواصل مع المكونات المتخصصة للآلة المدمج فيها. تميل الحواسيب المدمجة إلى أن تكون أبطأ وأرخص من الحواسيب الأخرى ولديها تخزين محدود للغاية.
  • 4.1.A.5 تُطلق غالبًا على الأجهزة اليومية التي تحتوي على حواسيب مدمجة أجهزة إنترنت الأشياء (IoT). توجد حواسيب مدمجة في وسائل النقل (مثل السيارات والقطارات والطائرات)، والأجهزة التي تشغل البنية التحتية الحيوية (مثل تشغيل قواطع الدائرة في محطات التحويل الكهربائية والمضخات في محطات معالجة المياه)، والمعدات الطبية (مثل مضخات التسريب الوريدي، وماسحات الرنين المغناطيسي، ونظام ضربات القلب، ومضخات الأنسولين)، والأجهزة اليومية مثل الغسالات وآلات صنع القهوة وحراريات درجة الحرارة.

هدف التعلم 4.1.B: تحديد نوع البرمجيات الخبيثة المستخدم في هجوم سيبراني.

  • 4.1.B.1 البرمجيات الخبيثة هي برامج ضارة يمكن أن تتلف أو تدمر جهازًا أو شبكة، أو تسمح للمعتدي بالوصول إلى جهاز和数据 على الجهاز.
  • 4.1.B.2 غالبًا ما تُستخدم البرمجيات الخبيثة كأداة لإنجاز جزء من خطة المعتدي لتحقيق هدفه(هدفيه) النهائي(ين). هناك العديد من أنواع البرمجيات الخبيثة، مثل:
    • الفيروسات: برمجيات خبيثة يجب تنشيطها بواسطة مستخدم ينفذ أو يفتح ملفًا.
    • ديدان الحاسوب: تنتشر من جهاز كمبيوتر إلى آخر دون تفاعل بشري.
    • أحصنة طروادة: برمجيات خبيثة مدمجة في برامج أخرى تبدو بريئة. توفر أحصنة طروادة الوصول عن بُعد (RATs) للمعتدي بالوصول عن بُعد إلى النظام المستهدف.
    • برمجيات الفدية: تشفر ملفات الجهاز، مما يمنع المستخدم من الوصول إلى الملفات الموجودة على الجهاز. تعرض برمجيات الفدية عادةً شاشة للمستخدم تتطلب الدفع وتعد بإعطائه مفتاح فك التشفير لملفاته إذا دفع المستخدم خلال فترة زمنية ثابتة.
    • برمجيات التجسس: تتبع إجراءات المستخدم على الكمبيوتر وترسل المعلومات إلى المعتدي.
    • مجسات المفاتيح: برنامج أو عتاد يسجل مفاتيح المستخدم ويرسل المعلومات إلى المعتدي. يمكن للمعتدين غالبًا استخراج أسماء المستخدمين وكلمات المرور من بيانات مجسات المفاتيح.
    • القنابل المنطقية: يتم ضبطها لتفعيل تأثيرها فقط عند استيفاء مجموعة محددة من الشروط؛ يمكن أن تشمل الشروط الوقت والتاريخ، ونوع أو إصدار معين لنظام التشغيل، ومجموعة الأحرف التي يستخدمها الكمبيوتر، إلخ.
    • روت كيت: برمجيات خبيثة متطورة تدخل نظام التشغيل الخاص بالحاسوب المستهدف ويمكنها التحكم في كل جانب تقريبًا من النظام، بما في ذلك جعل روت كيت نفسه غير مرئي للكشف.
  • 4.1.B.3 بينما معظم البرمجيات الخبيثة عبارة عن ملف أو مجموعة ملفات، فإن البرمجيات الخبيثة بدون ملفات هي أكواد ضارة تعيش في ذاكرة RAM وتستخدم برامج مشروعة مثبتة بالفعل على الجهاز لتقويضه.

هدف التعلم 4.1.C: شرح كيفية استغلال المعتدين الثغرات الشائعة في الأجهزة لإحداث خسائر أو أضرار أو اضطراب أو تدمير.

  • 4.1.C.1 يمكن للمهاجمين تطوير استغلالات للثغرات المعروفة في البرمجيات (بما في ذلك أنظمة التشغيل). الأجهزة التي تحتوي على برمجيات غير مُحدثة عرضة لهذه الاستغلالات، والتي قد تسمح للمهاجم بإيقاف تشغيل النظام، أو مراقبة إجراءات المستخدم، أو تمكين أو تعطيل خدمات ومكونات مختلفة على الجهاز (مثل تشغيل الكاميرا أو الميكروفون)، أو حتى السيطرة على الجهاز لإصدار أوامره الخاصة بما في ذلك أوامر سرقة أو تدمير المعلومات الموجودة على الجهاز.
  • 4.1.C.2 يمكن للمهاجمين الاستفادة من متطلبات المصادقة الضعيفة عن طريق تخمين كلمة مرور المستخدم أو استخدام الهندسة الاجتماعية لإقناع المستخدم بكشف كلمة مروره.
  • 4.1.C.3 عندما لا يكون لنظام BIOS أو UEFI كلمة مرور، يمكن للمهاجمين بدء تشغيل الكمبيوتر في وضع خاص (مثل "وضع الاستعادة") يمنحهم امتيازات أعلى. وبدون حماية BIOS أو UEFI، يمكن للمهاجمين تحميل نظام تشغيل خاص بهم على الجهاز من وحدة تخزين خارجية واستخدام أدوات متخصصة لتعديل أو إنشاء ملفات تعريف مستخدمين، بما في ذلك تغيير كلمات المرور.
  • 4.1.C.4 يمكن للمهاجمين تحميل برمجيات خبيثة على وحدة تخزين خارجية، وإذا كانت ميزة التشغيل التلقائي مفعلة، فإن الجهاز سيقوم بتشغيل البرمجيات الخبيثة عند إدخال الوحدة الخارجية.
  • 4.1.C.5 يمكن للمهاجمين الاستفادة من المنافذ المفتوحة للاتصال بالجهاز.
  • 4.1.C.6 يمكن للمهاجمين إرسال بيانات ضارة للأجهزة للتسبب في اضطرابها أو محاولة السيطرة عليها. الأجهزة التي لا تحتوي على جدار حماية (أو جدار حماية مضبوط بشكل خاطئ) لا يمكنها تصفية هذه البيانات الضارة.
  • 4.1.C.7 يحاول المهاجمون غالبًا تثبيت برمجيات خبيثة على الجهاز للتسبب في اضطرابه أو السيطرة عليه. الأجهزة التي تفتقر إلى برامج مكافحة البرمجيات الخبيثة أكثر عرضة لهذا النوع من الهجمات.

هدف التعلم 4.1.D: تقييم ومخاطر الثغرات في الأجهزة وتوثيقها.

  • 4.1.D.1 يمكن أن تأتي مخاطر الثغرات في الأجهزة من الوصول غير المصرح به أو البرمجيات الخبيثة التي تسمح للمهاجم بمحاكاة مستخدم مصرح له، أو التحكم عن بعد في الجهاز، أو تشفير قرص الجهاز لمطالبة الفدية مقابل البيانات، أو مسح ذاكرة الجهاز مما يؤدي إلى فقدان البيانات أو جعل الجهاز غير قابل للعمل. يختلف مستوى الخطر بناءً على أهمية الجهاز أو الخدمات التي يوفرها أو البيانات التي يخزنها.
  • 4.1.D.2 المخاطر العالية من ثغرات الأجهزة تتعلق بخطر المساس بالبيانات الحساسة أو العمليات الحرجة.
    • أمثلة توضيحية لـ 4.1.D.2:
      • لم تقم مؤسسة ما بتحديث خادم البريد الإلكتروني الخاص بها إلى أحدث إصدار والذي يتضمن تحديثاً لأحد الثغرات الحرجة المعروفة.
  • 4.1.D.3 المخاطر المتوسطة من ثغرات الأجهزة يمكن أن تنشأ من متطلبات مصادقة ضعيفة أو من ثغرات قد تكون أقل احتمالاً للاستغلال.
    • أمثلة توضيحية لـ 4.1.D.3:
      • تحتوي محطة معالجة المياه على أنظمة مدمجة تتحكم في المضخات. يمكن الوصول إلى المضخات عن بُعد عبر اسم مستخدم وكلمة مرور للإدارة عن بُعد لمحطة المعالجة، لكن الأجهزة لا تتطلب المصادقة متعددة العوامل (MFA).
  • 4.1.D.4 المخاطر المنخفضة من ثغرات الأجهزة مرتبطة عادةً بثغرات، إذا تم استغلالها، فللها تأثير ضئيل.
    • أمثلة توضيحية لـ 4.1.D.4:
      • جهاز كمبيوتر محمول لموظف يحتوي على منفذ Telnet مفتوح (المنفذ 23).

Source: College Board AP Course and Exam Description · ⁨المصدر: وصف دورة وامتحان College Board AP⁩

English

A device is any computer - a server, a personal laptop, a smartphone, or an embedded computer 嵌入式计算机 built into a machine. Everyday devices with embedded computers are called Internet of Things (IoT) 物联网 devices, and they run everything from water pumps to washing machines.

The four classes of device, and why the class matters

Class What it is Security consequence
servers shared machines running services for many users the highest-value target; one compromise reaches everyone
personal computers desktops and laptops general purpose, so they run anything the user installs
handheld computers 手持计算机 (also called mobile computers or information appliances) smaller than a PC and running on battery power — smartphones, tablets, smart watches and other wearable technology easily lost or stolen, and often carried across untrusted networks
embedded computers a computer that is part of a machine — a car's engine controller, a thermostat, a medical pump has a specialised instruction set for interfacing with its components, and tends to be slower, cheaper and to have minimal storage, so security features are often left out and updates are rare

That last row is the reason embedded and IoT devices appear so often in attack scenarios: the constraints that make them cheap are the same constraints that make them hard to defend.

The main threat to a device is malware 恶意软件 - malicious software. Learn the types:

  • Virus 病毒 - must be activated by a user opening a file.
  • Worm 蠕虫 - spreads by itself, with no human action.
  • Trojan 木马 - hides inside software that looks safe; a remote access trojan (RAT) 远程访问木马 gives the adversary remote control.
  • Ransomware 勒索软件 - encrypts your files and demands payment for the key.
  • Spyware 间谍软件 - secretly tracks what you do.
  • Keylogger 键盘记录器 - records every keystroke to steal passwords.
  • Logic bomb 逻辑炸弹 - triggers only when a condition is met (a date, a version).
  • Rootkit - deeply hides in the operating system and can even make itself invisible.

Most malware is a file, but fileless malware 无文件恶意软件 is different: it lives only in RAM 内存 and abuses legitimate programs already on the device, leaving no file for a scanner to find.

Adversaries exploit unpatched software 未打补丁的软件, weak passwords, unprotected BIOS/UEFI startup settings, and open ports. We rate device risk by the value and criticality of the device - a hospital's unpatched email server is high risk, while an employee's laptop with one unused open port is low.

العربية

الجهاز هو أي حاسوب - خادم، جهاز كمبيوتر محمول شخصي، هاتف ذكي، أو حاسوب مدمج مُبنى داخل آلة. تُسمى الأجهزة اليومية التي تحتوي على حواسيب مدمجة بأجهزة إنترنت الأشياء (IoT)، وهي تشغيل كل شيء من مضخات الماء إلى الغسالات.

الفئات الأربعة للأجهزة ولماذا الفئة مهمة

الفئة ما هي العواقب الأمنية
الخوادم (servers) آلات مشتركة تعمل خدمات لمستخدمين متعددين الهدف الأعلى قيمة؛ اختراق واحد يصل للجميع
أجهزة الكمبيوتر الشخصية أجهزة سطح المكتب والمحمولة متعددة الأغراض، لذا فهي تشغل أي شيء يثبته المستخدم
أجهزة الحاسوب المحمولة (handheld computers) (تُعرف أيضاً بالحواسيب المحمولة أو الأجهزة المعلوماتية) أصغر من جهاز الكمبيوتر الشخصي وتعمل على طاقة البطارية — الهواتف الذكية، tablets، الساعات الذكية والأخرى التكنولوجيا القابلة للارتداء يسهل فقدانها أو سرقتها، وغالباً ما تُحمل عبر شبكات غير موثوقة
الحواسيب المدمجة حاسوب يكون جزءاً من آلة — وحدة تحكم محرك السيارة، منظم الحرارة، مضخة طبية يمتلك مجموعة تعليمات متخصصة للتواصل مع مكوناته، و يميل إلى أن يكون أبطأ، أرخص، ويحتوي على تخزين ضئيل، لذا غالباً ما تُستبعد ميزات الأمان والحدوث النادر للتحديثات

هذا الصف الأخير هو سبب ظهور الأجهزة المدمجة وأجهزة إنترنت الأشياء بكثرة في سيناريوهات الهجوم: القيود التي تجعلها رخيصة هي نفس القيود التي تجعل صعب الدفاع عنها.

التهديد الرئيسي للجهاز هو البرمجيات الخبيثة - البرمجيات الضارة. تعلم الأنواع:

  • فيروس - يجب تفعيله بواسطة مستخدم يفتح ملفاً.
  • دودة - تنتشر بنفسها، بدون أي تدخل بشري.
  • حصان طروادة - يختبئ داخل برمجيات تبدو آمنة؛ حصان الوصول عن بُعد (RAT) يمنح المهاجم سيطرة عن بُعد.
  • برمجيات الفدية (Ransomware) - تشفر ملفاتك وتطلب دفع فدية للحصول على المفتاح.
  • برمجيات التجسس (Spyware) - تتتبع activitiesك بسرية.
  • سجل المفاتيح (Keylogger) - يسجل كل ضغطة مفتاح لسرقة كلمات المرور.
  • القنبلة المنطقية (Logic bomb) - تنشط فقط عند تحقق شرط معين (تاريخ، إصدار).
  • جذر الروت (Rootkit) - يختبئ بعمق في نظام التشغيل ويمكنه حتى جعل نفسه غير مرئي.

معظم البرمجيات الخبيثة عبارة عن ملف، لكن البرمجيات الخبيثة الخالية من الملفات (fileless malware) مختلفة: فهي تعيش فقط في ذاكرة الوصول العشوائي (RAM) وتسيء استخدام برامج شرعية موجودة بالفعل على الجهاز، ولا تترك ملفاً يمكن للفحص العثور عليه.

يستغل المهاجمون البرمجيات غير المصححة، وكلمات المرور الضعيفة، وإعدادات بدء التشغيل غير المحمية لـ BIOS/UEFI، والمنافذ المفتوحة. نصنف خطر الجهاز بناءً على القيمة والحساسية - خادم البريد الإلكتروني غير المصحح في مستشفى يعتبر عالي الخطر، بينما laptop الموظف الذي يحتوي على منفذ مفتوح واحد غير مستخدم يعتبر منخفض الخطر.

Explore · ⁨استكشف⁩

Name the malware from its behaviour · ⁨سمِّ البرمجيات الخبيثة بناءً على سلوكها⁩

Each kind of malware has one defining trait: a worm self-spreads, a virus needs a user to run it, ransomware encrypts for money, and a rootkit hides deep in the OS. · ⁨لكل نوع من البرمجيات الخبيثة سمة واحدة محدد: الديدان تنتشر ذاتياً، والفيروسات تحتاج إلى مستخدم لتشغيلها، وبرمجيات الفدية تقوم بالتشفير مقابل المال، وأدوات الجذور تختبئ بعمق في نظام التشغيل.⁩

Vocabulary · ⁨مفردات⁩ Train · ⁨تدريب⁩
English العربية
embedded computer/emˈbedɪd kəmˈpjuːtə/ حاسوب مدمج
Internet of Things (IoT)/ˈɪntənet ɒv θɪŋz/ إنترنت الأشياء (IoT)
handheld computers/ˈhændheld kəmˈpjuːtəz/ أجهزة الكمبيوتر المحمولة
malware/ˈmælweə/ البرمجيات الخبيثة
Ransomware/ˈrænsəmweə/ برمجيات الفدية
Spyware/ˈspaɪweə/ برامج التجسس
Keylogger/ˈkiːlɒɡə/ مسجل المفاتيح
Logic bomb/ˈlɒdʒɪk bɒm/ القنبلة المنطقية
fileless malware/ˈfaɪlləs ˈmælweə/ برمجيات خبيثة عديمة الملفات
RAM/ræm/ ذاكرة RAM
unpatched software/ʌnˈpætʃt ˈsɒftweə/ برمجيات غير مثبّتة
4.2

Authentication · ⁨المصادقة⁩

Syllabus · ⁨المنهج⁩
Learning ObjectiveEssential Knowledge

4.2.A
Explain why hashes (also called hash outputs, checksums, message digests, or digests) are used to store passwords.

  • 4.2.A.1 A cryptographic hash function (also called a message digest function) is a mathematical algorithm that takes binary data of an arbitrary length, processes it according to a set of instructions, and outputs a fixed-length binary string called the hash (or checksum or message digest). Well known cryptographic hashes include:
    • MD5
    • SHA-1, SHA-256, SHA-512 (SHA stands for Secure Hash Algorithm)
    • NTHash
    • RIPEMD-160
  • 4.2.A.2 An n-bit hash has $2^n$ possible outputs. The number of inputs is infinite, and so inevitably two different inputs will produce the same hash. This is called a collision.
  • 4.2.A.3 Cryptographic hash functions have the following properties:
    • Hashes are collision resistant; it is difficult to find two different inputs to the same hash function that produce the same output.
    • Hashes have pre-image resistance; given a hash, it is infeasible to figure out the input that generated the hash.
    • Hashes are repeatable; the same input will always produce the same hash.
    • Hashes have a fixed length; the length in bits of the hash for a specific hash function is constant regardless of the size of the input.
  • 4.2.A.4 Adversaries try to compromise hashing functions by forcing collisions in their output. If an efficient algorithm exists to force a collision for a specific hash function, then that hash function will be deprecated (no longer used in secure settings). MD5 and SHA1 are examples of deprecated hash functions.
  • 4.2.A.5 Password-based authentication services shouldn’t store passwords in plaintext, so that if an adversary gains access to the user:password directory they won’t immediately know the passwords for all users. Instead, user passwords should be hashed and the hash stored in a database. When a user enters their password, it is hashed, and the hash is compared to the hash stored on file. If the hashes match, then the user is authenticated.
  • 4.2.A.6 If two users had the same password, then their passwords would have identical hashes in the user:password directory. To prevent this, a few random bits (called salt) are hashed with a user’s password to generate the hash. Each user’s salt is unique, so even if two users have the same password they will have a different password hash because they have different salt.

4.2.B
Explain how password attacks exploit vulnerabilities.

  • 4.2.B.1 If an adversary can compromise the password of a legitimate user, and that user’s organization has not enabled MFA or other authentication protections, then the adversary can act within that organization with all the access and rights available to the user.
  • 4.2.B.2 Password attacks can be classified as online or offline.
    • Online password attacks attempt user:password combinations in an active authentication portal.
    • Offline password attacks have captured a user:password database and can run password attacks against the database on their own computer. This method bypasses any account lock out protections that may be in place.
  • 4.2.B.3 Many users reuse the same passwords (or variations of the same password) for all the services and accounts they have, despite warnings not to. When an organization’s user database is stolen, the usernames, emails, and passwords are sold to adversaries or posted online. Adversaries often begin an attempt to compromise an account by trying stolen or leaked credentials for a target individual.
  • 4.2.B.4 Many users set passwords that are easy to guess, and adversaries will attempt to guess common passwords for a user’s account. Password spraying is an attack where an adversary attempts a common password against many different user accounts.
  • 4.2.B.5 Some services and devices (e.g., switches, routers, and IoT devices) are preconfigured with a default administrative user and password. Credential stuffing is an attack where an adversary attempts to gain access to these services or devices using common default credentials or account credentials that have been stolen.
  • 4.2.B.6 Offline password attacks use automated hash-cracking tools to hash possible passwords and compare them against a captured hash. Although hashes can’t be reversed, an adversary can use these tools to hash many potential passwords and compare them to the target hash. If an adversary finds a hash that matches, they can use the password that generated the hash to login to the user’s account. Offline attacks include:
    • Brute force attacks, where an adversary uses an automated tool to test all the potential passwords that a user could have
    • Dictionary attacks, where an adversary uses an automated tool to test a list of common passwords
  • 4.2.B.7 A rainbow table attack uses a list of common passwords to generate a rainbow table. A rainbow table is a table that contains each potential password and its hash. The table is then sorted by the hashes, and the adversary uses an automated tool to search the list of hashes for the captured hash. If the hashes match, then the adversary has found a password that generates the same hash, and the password will allow the adversary to login to the user’s account.

4.2.C
Determine the type of authentication used to verify the identity of a user.

  • 4.2.C.1 Authentication mechanisms are technical controls that verify the identity of a user to ensure that only authorized users access a system. The proof the user provides to identify themselves is called a factor. Common authentication factors include:
    • Something the user knows (knowledge factor)
    • Something the user has (possession factor)
    • Something the user is (biometric factor)
    • Somewhere the user is (location factor)
  • 4.2.C.2 Knowledge factors can be passwords, PINs, or answers to preselected challenge questions. For a knowledge factor to be effective it needs to be something an adversary can’t easily guess; however, knowledge factors that are difficult for an adversary to figure out can also be harder for a user to remember.
  • 4.2.C.3 A possession factor is an object a user has that is unique to them, such as an access card, a bank card, a cell phone, or an authentication token. The more difficult it is for an adversary to obtain the object (or a copy of it), the more secure the possession factor is.
  • 4.2.C.4 Biometric factors measure features of the human body and can include fingerprints, palm prints, facial recognition, iris or retina scans, or voice identification. Biometric factors are difficult for an adversary to duplicate because they are unique to an individual.
  • 4.2.C.5 Location factors use information about Wi-Fi signals, GPS data, time zone settings, and even IP address information to make determinations about location. Rules can be established for allowing or denying access based on a location factor.
  • 4.2.C.6 Multifactor authentication (MFA) is when a system uses more than one factor to authenticate a user. MFA is more secure than single-factor authentication because it requires the user to provide at least two separate factors of authentication.

4.2.D
Configure login settings to make a device more secure.

  • 4.2.D.1 Requiring complexity in passwords is a login setting that can be configured. When enabled, users setting a new password must include at least one character from each character set. Passwords with characters from each character set are significantly harder for an adversary to crack than passwords that use characters from only one or two character sets. The main character sets often required are:
    • Uppercase letters (A–Z)
    • Lowercase letters (a–z)
    • Numeric digits (0–9)
    • Special characters (!”#$%&’()*+,-./:;<=>?@ [ \ ] ^_`{|}~)
  • 4.2.D.2 Requiring a minimum password length is a login setting that can be configured. This means that users must have at least a certain number of characters in their password. The longer and more complex a password is, the longer it will take a digital tool to crack the password.
  • 4.2.D.3 Requiring a maximum password age is a login setting that can be configured. When configured, users will receive a prompt to change their password a certain number of days after their last password change, usually every 90 or 120 days. If a user’s password has been compromised, changing it could prevent an adversary from gaining access to the user’s account. However, some national standards recommend that organizations not require users to change their passwords on predefined intervals to discourage users from developing password patterns (e.g., PasswordFall2028).
  • 4.2.D.4 Requiring the system to store a certain number of previous user passwords is a login setting that can be configured. This prevents a user from reusing a password. Many organizations store users’ previous 5–10 password hashes to prevent reuse.
  • 4.2.D.5 Requiring a lockout period after a certain number of invalid login attempts is a login setting that can be configured. This prevents an adversary from continuously randomly attempting wrong passwords. Many organizations lock a user’s account after 3–5 invalid login attempts. The period of the lockout varies.

Source: College Board AP Course and Exam Description · ⁨المصدر: وصف دورة وامتحان College Board AP⁩

English
Multi-factor authentication

To store passwords safely, systems use a cryptographic hash function 密码散列函数 - a one-way maths algorithm that turns any input into a fixed-length string called a hash 散列值 (or digest). Hashes have three vital properties: they are collision resistant 抗碰撞 (hard to find two inputs with the same output), have pre-image resistance 抗原像 (you cannot work backwards to the input), and are repeatable (the same input always gives the same hash).

Real hash functions have names. The Secure Hash Algorithm (SHA) family – SHA-256 and SHA-512 – is today's standard. Adversaries attack a hash function by trying to force a collision (two different inputs with the same hash); once an efficient collision attack exists, that function is deprecated 弃用 (retired from secure use). MD5 and SHA-1 are the classic deprecated examples – never rely on them to protect data today.

A service never stores your plaintext password. It stores the hash; when you log in, it hashes what you typed and compares. To stop two identical passwords producing identical hashes, a few random bits called salt 盐值 are added before hashing, so every stored hash is unique.

Worked example. Two users both choose the password sunshine. Without salt, both stored hashes would be identical, so cracking one instantly cracks the other. Give each user a unique salt - say x7 and q2 - and the service hashes sunshinex7 and sunshineq2 instead. The two stored hashes now look completely different, so the adversary must attack each account separately. This is why a stolen hash database is far less dangerous when the hashes are salted.

Adversaries fight back with password attacks. Online attacks guess against a live login; offline attacks steal the hash database and crack it on their own machine (which bypasses any account-lockout protection). Techniques include:

  • brute force 暴力破解 - an automated tool tries every possible password in turn; guaranteed to work eventually, but slow, and it grows explosively with password length.
  • a dictionary attack 字典攻击 - the tool tries a list of common words and known passwords first, because most people pick guessable ones.
  • password spraying 密码喷洒 - one common password against many accounts (this dodges lockout, which counts failures per account).
  • credential stuffing 撞库 - reusing stolen or default credentials, exploiting that people reuse passwords across sites.
  • a rainbow table 彩虹表 - a precomputed table of passwords and their hashes, sorted by hash, so a captured hash can be looked up instead of recomputed.

Password policy settings

An administrator hardens accounts by configuring login settings - and the exam expects you to name them and say what each defends against:

Setting What it does The attack it slows
complexity 复杂度 require a character from each set (upper, lower, digit, special) brute force / dictionary
minimum length 最小长度 require N characters - length matters more than anything brute force (grows exponentially)
maximum age 最长有效期 force a change every ~90-120 days limits how long a stolen password is useful
password history 密码历史 store the last 5-10 hashes, block reuse stops recycling an old (possibly leaked) password
lockout 锁定 lock the account after 3-5 wrong tries brute force / online guessing

One subtlety worth a mark: some national standards now advise against forced expiry, because regular changes push users into predictable patterns like PasswordFall2028. A password manager 密码管理器 solves the real problem - it generates and stores a long, unique password per site, so none is ever reused or guessable.

Authentication factors prove who you are, and fall into categories: something you know (a password), something you have (a token or phone), something you are (a biometric 生物特征 like a fingerprint or retina scan), and somewhere you are (a location factor). Using two or more is multifactor authentication (MFA) 多因素身份验证 - far stronger than a password alone.

Removable media, and the autorun problem

An adversary can load malware onto an external drive — a USB stick, a portable disc — and leave it where someone will pick it up. If autorun 自动运行 is enabled, the device runs a program from that drive the moment it is inserted, with no click required, so the malware executes before the user has decided to trust anything.

Two controls answer this, and the exam wants both named:

  • Disable autorun, so inserting a drive never runs anything by itself.
  • Prohibit users from connecting external drives or media at all — enforced by policy and by a technical control that blocks the USB ports — which is why so many secure environments physically or logically disable them.
العربية
المصادقة متعددة العوامل
شخص يضغط إصبعه على قارئ بصريات صغير لبصمة الإصبع
قارئ البصمة: التحقق البيومتري يتحقق من شيء أنت عليه، وهو أمر أصعب بكثير للمهاجم سرقتة أو تخمينه مقارنة بكلمة المرور

لتخزين كلمات المرور بأمان، تستخدم الأنظمة دالة تجريدية تشفيرية (cryptographic hash function) - وهي خوارزمية رياضية أحادية الاتجاه تحول أي مدخل إلى سلسلة ثابتة الطول تسمى تجريدية (hash) (أو ملخص). للتجريدية ثلاث خصائص حيوية: أنها مقاومة للتصادم (صعبة إيجاد مدخلين مع نفس المخرج)، ولها مقاومة الصورة الأولية (لا يمكنك العمل عكسياً للوصول إلى المدخل)، وهي قابل للتكرار (نفس المدخل يعطي دائماً نفس التجريدية).

الدالة التجريدية تحول أي مدخل إلى ملخص ثابت الطول، ولا يمكن عكسه
الدالة التجريدية تحول أي مدخل إلى ملخص ثابت الطول، ولا يمكن عكسه

الدوال الهاشية الحقيقية لها أسماء. عائلة خوارزمية الهاش الآمن (SHA) – SHA-256 و SHA-512 – هي المعيار الحالي. يهاجم الخصوم دالة الهاش من خلال محاولة إجبار التصادم (مدخلين مختلفين لهما نفس الهاش)؛ وبمجرد وجود هجوم تصادم فعال، تصبح تلك الدالة ملغاة (تم إزالتها عن الاستخدام الآمن). MD5 و SHA-1 هما أمثلة كلاسيكية على الدوال الملغاة – لا تعتمد عليها أبدًا لحماية البيانات اليوم.

لا تخزن الخدمة كلمة المرور الخاصة بك في نص واضح. تخزن الهاش؛ وعند تسجيل الدخول، تقوم بتشفير ما كتبته وتقارنه. لمنع إنتاج هاشات متطابقة لكلمات مرور متطابقة، يتم إضافة عدد قليل من البتات العشوائية تسمى الملح قبل التشفير، بحيث يكون كل هاوش مخزن فريدًا.

مثال محلول. اختار مستخدمان كلمة المرور sunshine. بدون ملح، ستكون الهاشات المخزنة لكلاهما متطابقة، مما يعني أن كسر أحدهما يؤدي فورًا إلى كسر الآخر. امنح كل مستخدم ملحًا فريدًا – مثلاً x7 و q2 – وتقوم الخدمة بتشفير sunshinex7 و sunshineq2 بدلاً من ذلك. الآن تبدو الهاشات المخزنة مختلفة تمامًا، لذا يجب على الخصوم مهاجمة كل حساب بشكل منفصل. ولهذا السبب تكون قاعدة بيانات الهاش المسروقة أقل خطورة بكثير عندما تكون الهاشات مملحة.

يقاتل الخصوم بـ هجمات كلمات المرور. الهجمات عبر الإنترنت تخمن ضد تسجيل دخول حي؛ الهجمات غير المتصلة بالإنترنت تسرق قاعدة بيانات الهاش وتكسرها على جهازهم الخاص (مما يتجاوز أي حماية لحظر الحساب). تشمل التقنيات:

  • القوة الغاشمة - أداة آلية تحاول كل كلمة مرور ممكنة بالتتابع؛ مضمونة للعمل في النهاية، لكنها بطيئة وتنمو بشكل متفجر مع طول كلمة المرور.
  • هجوم القاموس - tries the tool a list of common words and known passwords first, because most people pick guessable ones.
  • رشق كلمات المرور - كلمة مرور واحدة شائعة against many accounts (this dodges lockout, which counts failures per account).
  • تعبئة البيانات المعرفية - إعادة استخدام بيانات تعريف مسروقة أو افتراضية، واستغلال أن الناس يعيدون استخدام كلمات المرور عبر المواقع.
  • جدول قوس قزح - جدول محسوب مسبقًا لكلمات المرور وهاشاتها، مرتب حسب الهاش، sehingga captured hash can be looked up instead of recomputed.

إعدادات سياسة كلمة المرور

يقوي المسؤول الحسابات من خلال تهيئة إعدادات تسجيل الدخول - ويتوقع الامتحان منك تسميتها وذكر ما تحمي منها كل منها:

الإعداد ما يفعله الهجوم الذي يبطئه
التعقيد يتطلب حرفًا من كل مجموعة (كبيرة، صغيرة، رقم، خاصة) القوة الغاشمة / القاموس
الحد الأدنى للطول يتطلب N أحرف - الطول مهم أكثر من أي شيء آخر القوة الغاشمة (تنمو أسيًا)
أقصى عمر إجبار التغيير كل ~90-120 يومًا يحدد المدة التي تكون فيها كلمة المرور المسروقة مفيدة
سجل كلمة المرور تخزين آخر 5-10 هاشات، منع إعادة الاستخدام يمنع إعادة تدوير كلمة مرور قديمة (قد تكون تم تسريبها)
الحظر قفل الحساب بعد 3-5 محاولات خاطئة القوة الغاشمة / التخمين عبر الإنترنت

دقة واحدة تستحق علامة: بعض المعايير الوطنية تنصح الآن ضد التجديد الإجباري، لأن التغييرات المنتظمة تدفع المستخدمين إلى أنماط متوقعة مثل PasswordFall2028. يحل مدير كلمات المرور المشكلة الحقيقية - فهو يولد ويخزن كلمة مرور طويلة وفريدة لكل موقع، sehingga none is ever reused or guessable.

عوامل المصادقة تثبت هويتك، وتصنف إلى فئات: شيء تعرفه (كلمة مرور)، شيء تملكه (رمز أو هاتف)، شيء أنت عليه (بيومترية مثل بصمة الإصبع أو فحص الشبكية)، ومكان أنت فيه (عامل الموقع). استخدام عاملين أو أكثر هو المصادقة متعددة العوامل (MFA) - أقوى بكثير من كلمة المرور وحدها.

Two small USB hardware security keys
تثبت مفتاح الأمان المادي هويتك بشيء تمسكه جسديًا — وهو عامل قوي ثانوي

الوسائط القابلة للإزالة، ومشكلة التشغيل التلقائي

يمكن للخصوم تحميل برمجيات خبيثة على محرك خارجي - مثل فلاش USB أو قرص محمول - وتركه حيث يمكن لشخص ما التقاطه. إذا كان التشغيل التلقائي مُفعلاً،则该设备运行一个程序从该驱动器the moment it is inserted, with no click required, so the malware executes before the user has decided to trust anything.

تحكمان يجيبان على هذا، والامتحان يريد كلاهما مسميًا:

  • تعطيل التشغيل التلقائي، sehingga inserting a drive never runs anything by itself.
  • منع المستخدمين من توصيل المحركات الخارجية أو الوسائط على الإطلاق - المفروض بواسطة السياسة وتحكم تقني يمنع منافذ USB - وهذا هو السبب في أن الكثير من البيئات الآمنة تعطيلها فيزيائيًا أو منطقيًا.
Explore · ⁨استكشف⁩

How a hash maps any input to a fixed slot · ⁨كيف يربط الهاش أي مدخل بمكان ثابت⁩

A hash function sends every input to a fixed-length output. The same input always lands in the same place (repeatable), and you cannot work backwards from the slot to the input. · ⁨تقوم دالة الهاش بإرسال كل مدخل إلى مخرجات بطول ثابت. نفس المدخل يسقط دائماً في نفس المكان (قابل للتكرار)، ولا يمكنك الرجوع من المكان إلى المدخل.⁩

Vocabulary · ⁨مفردات⁩ Train · ⁨تدريب⁩
English العربية
cryptographic hash function/ˌkrɪptəˈɡræfɪk hæʃ ˈfʌŋkʃn/ دالة الهاش المشفرة
hash/hæʃ/ بصمة مشفرة
collision resistant/kəˈlɪʒn rɪˈzɪstənt/ مقاوم للتصادم
pre-image resistance/priː ˈɪmɪdʒ rɪˈzɪstəns/ مقاومة الصورة الأولية
deprecated/ˈdeprɪkeɪtɪd/ مهجور
salt/sɒlt/ ملح
brute force/bruːt fɔːs/ الترميز العنيد (brute force)
dictionary attack/ˈdɪkʃənəri əˈtæk/ هجوم القاموس
password spraying/ˈpæswɜːd ˈspreɪɪŋ/ رش كلمات المرور
credential stuffing/krɪˈdenʃl ˈstʌfɪŋ/ إغراق البيانات المعرفية
rainbow table/ˈreɪnbəʊ ˈteɪbl/ جدول قوس قزح
complexity/kəmˈpleksɪti/ التعقيد
minimum length/ˈmɪnɪməm leŋθ/ الطول الأدنى
maximum age/ˈmæksɪməm eɪdʒ/ الأقصى للعمر
password history/ˈpæswɜːd ˈhɪstəri/ سجل كلمة المرور
lockout/ˈlɒkaʊt/ الإغلاق المؤقت
password manager/ˈpæswɜːd ˈmænɪdʒə/ مدير كلمات المرور
biometric/ˌbaɪəʊˈmetrɪk/ بيومترية
multifactor authentication (MFA)/ˌmʌltɪˈfæktə ɔːˌθentɪˈkeɪʃn/ المصادقة متعددة العوامل (MFA)
autorun/ˌɔːtəʊˈrʌn/ تشغيل تلقائي
acceptable use policy/əkˈseptəbl juːs ˈpɒlɪsi/ سياسة الاستخدام المقبول
Anti-malware software/ˈænti ˈmælweə ˈsɒftweə/ برامج مكافحة البرمجيات الخبيثة
patch/pætʃ/ ترقيع
host-based firewall/həʊst beɪst ˈfaɪəwɔːl/ جدار حماية المضيف
indicator of compromise (IoC)/ˈɪndɪkeɪtə ɒv ˈkɒmprəmaɪz/ مؤشر التعرض للاختراق (IoC)
endpoint detection and response (EDR)/endˈpɔɪnt dɪˈtekʃn ænd rɪˈspɒns/ الكشف عن الاستجابة الطرفية (EDR)
Watch lesson · ⁨شاهد الدرس⁩
4.3

Protecting Devices · ⁨حماية الأجهزة⁩

Syllabus · ⁨المنهج⁩
English

Learning Objective 4.3.A: Identify managerial controls related to device security.

  • 4.3.A.1 An acceptable use policy will describe the range of activities that are permissible, prohibited, or required by users on devices owned by an organization and may include:
    • Prohibiting users from accessing specific websites or types of websites (e.g., social media or gaming)
    • Requiring users to keep software updated
    • Allowing users to connect peripheral devices
    • Prohibiting users from connecting external drives or media
  • 4.3.A.2 A password policy will detail the requirements for user passwords within an organization and may include:
    • A minimum or maximum password length
    • A minimum or maximum amount of time a user may keep the same password
    • A prohibition of password reuse
    • Rules for password construction (e.g., no dictionary words and character set requirements)
    • A suggestion to use secure password management tools instead of writing passwords down
  • 4.3.A.3 A software installation policy will describe what (if any) software users are allowed to install on their devices and usually also a process for users to request specialized software they may need to perform their role, and it may include:
    • A prohibition against users installing software on their devices
    • A process for users to request new software needed for their role
    • A list of approved software for users

Learning Objective 4.3.B: Explain how anti-malware software can make a device more secure.

  • 4.3.B.1 Anti-malware software (sometimes called antivirus software) has tools to quarantine and remove malware that can corrupt, spy on, or destroy a system. Malware contains indicators that make it detectable; these indicators are called signatures.
  • 4.3.B.2 Anti-malware software has a database of malware signatures. It periodically scans the files on a device and checks to see if any of the files match any of the signatures in its database. If there is a match, the software quarantines and removes the malicious files.

Learning Objective 4.3.C: Explain why keeping a device’s operating system and software updated makes it more secure.

  • 4.3.C.1 When vulnerabilities in operating systems and software are found, the vendor or organization that maintains the operating system software will fix it and send an update. A small update is called a patch.
  • 4.3.C.2 Ensuring that a computer’s operating system and software applications are updated to the most recent version prevents adversaries from taking advantage of a known vulnerability.

Learning Objective 4.3.D: Configure a host-based firewall.

  • 4.3.D.1 Host-based firewalls allow or deny traffic into or out of a single device. This provides an extra layer of security in case a host is connected to a compromised network.
  • 4.3.D.2 A host-based firewall is software that runs on a device and follows a set of rules (an ACL) like a network-based firewall. Firewall rules are implemented in order, applying the first rule that matches.
  • 4.3.D.3 A host-based firewall can also block specified types of outbound traffic. Host-based firewalls should always block ports or services not needed for a given device.
    • Illustrative examples for 4.3.D.3:
      • A host-based firewall is configured to block outbound FTP traffic. This prevents an adversary with remote access to the host from using FTP to exfiltrate a file to the adversary’s server.
  • 4.3.D.4 The rules for a host-based firewall can allow or deny traffic based on source or destination port or IP address, service, protocol, or application.
العربية

هدف التعلم 4.3.A: تحديد الضوابط الإدارية المتعلقة بأمان الأجهزة.

  • 4.3.A.1 وسياسة الاستخدام المقبول ستصف نطاق الأنشطة المسموحة أو المحظورة أو المطلوبة من قبل المستخدمين على الأجهزة المملوكة لمنظمة ما، وقد تتضمن:
    • منع المستخدمين من الوصول إلى مواقع ويب معينة أو أنواع معينة من المواقع (مثل وسائل التواصل الاجتماعي أو الألعاب)
    • مطالبة المستخدمين بإبقاء البرامج محدثة
    • السماح للمستخدمين باتصال الأجهزة الطرفية
    • منع المستخدمين من توصيل محركات أقراص خارجية أو وسائط
  • 4.3.A.2 وسياسة كلمة المرور ستفصل المتطلبات الخاصة بكلمات مرور المستخدمين داخل المنظمة وقد تتضمن:
    • حد أدنى أو أقصى لطول كلمة المرور
    • حد أدنى أو أقصى للمدة الزمنية التي قد يمسك بها المستخدم نفس كلمة المرور
    • حظر إعادة استخدام كلمة المرور
    • قواعد لبناء كلمة المرور (مثل عدم استخدام الكلمات الموجودة في القواميس ومتطلبات مجموعة الأحرف)
    • اقتراح استخدام أدوات إدارة كلمات المرور الآمنة بدلاً من كتابة كلمات المرور يدويًا
  • 4.3.A.3 وسيلة تثبيت البرمجيات ستصف ما (إن وجد) من برامج يُسمح للمستخدمين بتثبيتها على أجهزتها، وعادة ما تتضمن أيضًا عمليةطلب برامج متخصصة قد يحتاجونها لأداء دورهم، وقد تتضمن:
    • حظر تثبيت المستخدمين للبرامج على أجهزتهم
    • عملية طلب المستخدمين لبرامج جديدة ضرورية لدورهم
    • قائمة بالبرامج المعتمدة للمستخدمين

هدف التعلم 4.3.B: شرح كيف يمكن للبرامج المضادة للبرمجيات الخبيثة جعل الجهاز أكثر أمانًا.

  • 4.3.B.1 البرامج المضادة للبرمجيات الخبيثة (تسمى أحيانًا برامج مكافحة الفيروسات) تحتوي على أدوات لعزل وإزالة البرمجيات الخبيثة التي يمكنها إفساد النظام أو التجسس عليه أو تدميره. تحتوي البرمجيات الخبيثة على مؤشرات تجعلها قابلة للكشف؛ تُسمى هذه المؤشرات بالتواقيع.
  • 4.3.B.2 تمتلك البرامج المضادة للبرمجيات الخبيثة قاعدة بيانات لتواقيع البرمجيات الخبيثة. تفحص بشكل دوري الملفات الموجودة على الجهاز وتتحقق مما إذا كانت أي منها تتطابق مع أي من التواقيع في قاعدة بياناتها. إذا كان هناك تطابق، تقوم البرنامج بعزل وإزالة الملفات الضارة.

هدف التعلم 4.3.C: شرح لماذا يجعل تحديث نظام التشغيل والبرامج للجهاز أكثر أمانًا.

  • 4.3.C.1 عند العثور على ثغرات في أنظمة التشغيل والبرمجيات، يقوم المورد أو المنظمة التي تحافظ على برمجيات نظام التشغيل بإصلاحها وإرسال تحديث. يسمى التحديث الصغير بترقيع.
  • 4.3.C.2 ضمان تحديث نظام تشغيل الكمبيوتر وتطبيقات البرمجيات إلى أحدث إصدار يمنع الخصوم من الاستفادة من ثغرة معروفة.

هدف التعلم 4.3.D: إعداد جدار الحماية القائم على المضيف.

  • 4.3.D.1 تسمح جدران الحماية القائمة على المضيف بقبول أو رفض حركة المرور الداخلة أو الخارجة من جهاز واحد. يوفر هذا طبقة أمان إضافية في حال اتصال المضيف بشبكة مخترقة.
  • 4.3.D.2 جدار الحماية القائم على المضيف هو برنامج يعمل على جهاز ويتبع مجموعة من القواعد (قائمة التحكم في الوصول ACL) مثل جدار الحماية القائم على الشبكة. يتم تنفيذ قواعد جدار الحماية بالترتيب، بتطبيق أول قاعدة تتطابق.
  • 4.3.D.3 يمكن لجدار الحماية القائم على المضيف أيضًا حظر أنواع محددة من حركة المرور الخارجة. يجب دائمًا لحجب جدران الحماية القائمة على المضيف المنافذ أو الخدمات غير الضرورية لجهاز معين.
    • أمثلة توضيحية لـ 4.3.D.3:
      • يتم إعداد جدار حماية قائم على المضيف لحظر حركة المرور FTP الخارجية. هذا يمنع خصمًا لديه وصول عن بُعد إلى المضيف من استخدام FTP لاستخراج ملف إلى خادم الخصم.
  • 4.3.D.4 يمكن لقواعد جدار الحماية القائم على المضيف قبول أو رفض حركة المرور بناءً على منفذ المصدر أو الوجهة أو عنوان IP أو الخدمة أو البروتوكول أو التطبيق.

Source: College Board AP Course and Exam Description · ⁨المصدر: وصف دورة وامتحان College Board AP⁩

English

Managerial controls set the rules: an acceptable use policy 可接受使用政策 lists what users may and may not do, a password policy sets length and reuse rules, and a software installation policy controls what can be installed.

Technical controls do the work. Anti-malware software 反恶意软件 keeps a database of malware signatures and quarantines any file that matches. Keeping the operating system and applications updated - installing each patch 补丁 - closes known holes before adversaries can use them. A host-based firewall 主机防火墙 controls traffic in and out of one single device, blocking ports and services it does not need.

العربية

تضع الضوابط الإدارية القواعد: سياسة الاستخدام المقبول تسرد ما يمكن للمستخدمين فعله وما لا يمكنهم فعله، وسياسة كلمة المرور تحدد قواعد الطول وإعادة الاستخدام، وسياسة تثبيت البرمجيات تتحكم فيما يمكن تثبيته.

تقوم الضوابط التقنية بالعمل. برامج مكافحة البرمجيات الخبيثة تحتفظ بقاعدة بيانات توقيعات البرمجيات الخبيثة وتعزل أي ملف يطابقها. الحفاظ على نظام التشغيل والتطبيقات محدّثة - تثبيت كل ترقية - يغلق الثغرات المعروفة قبل أن يتمكن الخصوم من استخدامها. جدار الحماية المستند إلى المضيف يتحكم في حركة المرور الداخلة والخارجة لجهاز واحد فقط، blocking ports and services it does not need.

نافذة فحص مضاد للبرمجيات الخبيثة: تم فحص 3106 ملفات، وتم العثور على تهديدين، مع خيارات العزل والتحديث
فحص برامج مكافحة البرمجيات الخبيثة الملفات مقابل قاعدة بيانات التوقيع ويعزل أي تطابق - هذا الفحص حدد تهديدين
Vocabulary · ⁨مفردات⁩ Train · ⁨تدريب⁩
English العربية
Virus/ˈvaɪrəs/ فيروس
Worm/wɜːm/ ديدان
Trojan/ˈtrəʊdʒn/ حصان طروادة
remote access trojan (RAT)/rɪˈməʊt ˈækses ˈtrəʊdʒn/ حصان طروادة الوصول عن بعد (RAT)
4.4

Detecting Attacks on Devices · ⁨اكتشاف الهجمات على الأجهزة⁩

Syllabus · ⁨المنهج⁩
English

Learning Objective 4.4.A: Explain how to detect attacks against devices.

  • 4.4.A.1 System processes and settings, login attempts, file download attempts, and user actions are logged by computing systems. These logs can be used to reconstruct circumstances leading up to and during a cyber incident.
  • 4.4.A.2 An indicator of compromise (IoC) is evidence that an adversary has compromised a device or network.
  • 4.4.A.3 Authentication logs (or auth logs) record every attempted login on a system. Analysis of authentication logs can reveal attempted attacks.
  • 4.4.A.4 Host-based IoCs are discovered when analyzing logs and configuration settings. Indicators, such as the following, can be found in authentication logs, user activity logs, and system configuration files:
    • Unusual files being created or modified
    • Unexpected processes or services
    • Unauthorized changes to system configuration settings
    • Unauthorized software installation or update
  • 4.4.A.5 File-based IoCs are discovered when analyzing files on a device. Indicators are usually found in executable files and can include:
    • Files whose hash matches known malware
    • File names that are known to be created by a certain piece of malware
    • File paths that are associated with malicious activity
  • 4.4.A.6 Behavior-based IoCs are discovered when analyzing logs. Indicators can be found in authentication logs and access logs and can include:
    • Multiple failed login attempts
    • Unusual login times or locations
    • Unauthorized attempts to access sensitive data
    • Attempts to elevate user privileges on a system

Learning Objective 4.4.B: Determine controls for detecting attacks against a device.

  • 4.4.B.1 Performance is a criterion for determining a detection method. Detection tools use system memory and processing power and can impact the performance of a device. Anomaly-based detection tools use more system resources than signature-based tools. Signature-based detection is a better option for devices with less powerful system resources. Many embedded devices do not have enough system resources to run any detection tools on the device.
  • 4.4.B.2 Cost is a criterion for determining a detection method. Organizations that purchase detection software need to consider the cost of purchasing enough software licenses for the number of devices they need to monitor. Some organizations purchase an endpoint detection and response (EDR) service from a third-party vendor. Although these services are expensive, they provide a holistic, unified approach to threat detection for an organization’s devices; they typically include a centralized alert platform for monitoring possible attacks on devices.
  • 4.4.B.3 Sensitivity or criticality of the device is a criterion for determining a detection method. Devices that store or process sensitive information or provide critical services are more likely to be targeted by adversaries and benefit from a hybrid-detection model to offer maximum protection, when possible.

Learning Objective 4.4.C: Evaluate the impact of a device detection method.

  • 4.4.C.1 Speed and performance are factors in evaluating the impact of a detection method. Signature-based detection is faster than anomaly-based detection in general, and that effect is compounded on devices, which often lack the processing power to effectively run anomaly-based detection tools. Implementing resource-intensive detection tools on devices can degrade device performance.
  • 4.4.C.2 Phase of the attack is a factor in evaluating the impact of a detection method. To carry out actions on a device, adversaries must first bypass a combination of physical- or network-layer protective, deterrent, and detective security controls. Detecting and stopping an attack at the device level can prevent adversaries from accessing sensitive data or disrupting critical services.
  • 4.4.C.3 False positives versus ease of bypassing detection is a factor in evaluating the impact of a detection method. Most device-level detection tools are signature-based, and signature-based detection has a low rate of false positives. However, signature-based detection is easier for adversaries to bypass.

Learning Objective 4.4.D: Apply detection techniques to identify indicators of password attacks by analyzing log files.

  • 4.4.D.1 Online password attacks can be detected in authentication logs. A single user attempting many wrong passwords is an indicator of an online password attack. If a user:password hash database has been compromised, all the user passwords in the database should be considered insecure and all users should be forced to reset their passwords.
  • 4.4.D.2 If an authorized user is logging in from a different location or IP address than expected, or at a different time than normal, this can be an indicator that the user’s password has been compromised.
  • 4.4.D.3 An indicator of password spraying is many users trying to log in within seconds of each other from one IP address or from unusual IP addresses.
  • 4.4.D.4 An indicator of credential stuffing is a series of default user:password combinations being attempted on a device in quick succession, often from the same IP address.
  • 4.4.D.5 Offline password attacks can’t be detected, because the attack takes place on the adversary’s computer.
العربية

هدف التعلم 4.4.A: شرح كيفية كشف الهجمات ضد الأجهزة.

  • 4.4.A.1 يتم تسجيل عمليات النظام والإعدادات ومحاولات تسجيل الدخول ومحاولات تنزيل الملفات وأفعال المستخدمين بواسطة الأنظمة الحاسوبية. يمكن استخدام هذه السجلات لإعادة بناء الظروف التي أدت إلى حادثة سيبرانية وأثناء حدوثها.
  • 4.4.A.2 مؤشر على الاختراق (IoC) هو دليل على أن خصم قد اخترق جهازًا أو شبكة.
  • 4.4.A.3 سجلات المصادقة (أو سجلات auth) تسجل كل محاولة تسجيل دخول على نظام ما. يمكن لكشف سجلات المصادقة أن يكشف عن محاولات الهجوم.
  • 4.4.A.4 يتم اكتشاف مؤشرات الاختراق القائمة على المضيف عند تحليل السجلات وإعدادات التكوين. يمكن العثور على مؤشرات، مثلما يلي، في سجلات المصادقة وسجلات نشاط المستخدم وملفات إعدادات النظام:
    • ملفات غير عادية يتم إنشاؤها أو تعديلها
    • عمليات أو خدمات غير متوقعة
    • تغييرات غير مصرح بها في إعدادات تكوين النظام
    • تثبيت أو تحديث برامج غير مصرح به
  • 4.4.A.5 يتم اكتشاف مؤشرات الاختراق القائمة على الملفات عند تحليل الملفات على جهاز ما. عادةً ما تكون المؤشرات موجودة في الملفات القابلة للتنفيذ ويمكن أن تشمل:
    • ملفات يتطابق هاش الخاص بها مع برمجيات خبيثة معروفة
    • أسماء ملفات تُعرف بأنها تنشأ من قبل نوع معين من البرمجيات الخبيثة
    • مسارات ملفات مرتبطة بنشاط ضار
  • 4.4.A.6 يتم اكتشاف مؤشرات الاختراق القائمة على السلوك عند تحليل السجلات. يمكن العثور على مؤشرات في سجلات المصادقة وسجلات الوصول ويمكن أن تشمل:
    • محاولات تسجيل دخول فاشلة متعددة
    • أوقات أو مواقع تسجيل دخول غير عادية
    • محاولات غير مصرح بها للوصول إلى بيانات حساسة
    • محاولات لرفع امتيازات المستخدم على نظام ما

هدف التعلم 4.4.B: تحديد الضوابط لاكتشاف الهجمات ضد جهاز.

  • 4.4.B.1 الأداء هو معيار لتحديد طريقة الكشف. تستخدم أدوات الكشف ذاكرة النظام وقوة المعالجة ويمكن أن تؤثر على أداء الجهاز. تستخدم أدوات الكشف القائمة على الشذوذ موارد نظام أكثر من الأدوات القائمة على البصمة. يعد الكشف القائم على البصمة خيارًا أفضل للأجهزة ذات موارد النظام الأقل قوة. لا تملك العديد من الأجهزة المدمجة موارد نظام كافية لتشغيل أي أدوات كشف على الجهاز.
  • 4.4.B.2 التكلفة هي معيار لتحديد طريقة الكشف. يجب على المنظمات التي تشتري برمجيات الكشف أن تأخذ في الاعتبار تكلفة شراء ترخيصات برمجيات كافية لعدد الأجهزة التي تحتاج إلى مراقبتها. تشتري بعض المنظمات خدمة كشف الاستجابة للنهاية (EDR) من مورد خارجي. على الرغم من أن هذه الخدمات باهظة الثمن، إلا أنها توفر نهجًا شاملاً وموحَّدًا لاكتشاف التهديدات لأجهزة المنظمة؛ عادةً ما تتضمن منصة تنبيه مركزية لمراقبة可能的 الهجمات على الأجهزة.
  • 4.4.B.3 الحساسية أو أهمية الجهاز هي معيار لتحديد طريقة الكشف. الأجهزة التي تخزن أو تعالج معلومات حساسة أو تقدم خدمات حيوية أكثر عرضة للاستهداف من قبل الأعداء وتستفيد من نموذج الكشف الهجين لتقديم أقصى حماية، قدر الإمكان.

هدف التعلم 4.4.C: تقييم تأثير طريقة كشف الجهاز.

  • 4.4.C.1 السرعة والأداء هي عوامل في تقييم تأثير طريقة الكشف. الكشف القائم على البصمة أسرع بشكل عام من الكشف القائم على الشذوذ، وتأثير ذلك يتضاعف على الأجهزة التي غالبًا ما تفتقر إلى قوة المعالجة لتشغيل أدوات الكشف القائمة على الشذوذ بفعالية. يمكن أن يؤدي تنفيذ أدوات كشف مكلفة للموارد على الأجهزة إلى تدهور أداء الجهاز.
  • 4.4.C.2 مرحلة الهجوم هي عامل في تقييم تأثير طريقة الكشف. لتنفيذ إجراءات على جهاز ما، يجب على الخصوم أولاً تجاوز مزيج من الضوابط الأمنية الفيزيائية-شبكية الوقائية والردعية والكشفية. يمكن أن يمنع الكشف عن هجوم ووقفه على مستوى الجهاز الخصوم من الوصول إلى البيانات الحساسة أو تعطيل الخدمات الحيوية.
  • 4.4.C.3 النتائج الإيجابية الكاذبة مقابل سهولة تجاوز الكشف هو عامل في تقييم تأثير طريقة الكشف. معظم أدوات الكشف على مستوى الجهاز قائمة على البصمة، والكشف القائم على البصمة له معدل منخفض من النتائج الإيجابية الكاذبة. ومع ذلك، فإن الكشف القائم على البصمة أسهل على الخصوم لتجاوزه.

هدف التعلم 4.4.D: تطبيق تقنيات الكشف لتحديد مؤشرات هجمات كلمة المرور من خلال تحليل ملفات السجلات.

  • 4.4.D.1 يمكن الكشف عن هجمات كلمات المرور عبر الإنترنت في سجلات المصادقة. محاولة مستخدم واحد لعديد من كلمات المرور الخاطئة هي مؤشر على هجمة كلمة مرور عبر الإنترنت. إذا تم اختراق قاعدة بيانات الهاش الخاصة بكلمات مرور المستخدمين، فيجب اعتبار جميع كلمات مرور المستخدمين في قاعدة البيانات غير آمنة ويجب إجبار جميع المستخدمين على إعادة تعيين كلمات المرور الخاصة بهم.
  • 4.4.D.2 إذا كان مستخدم مصرح له يسجل الدخول من موقع مختلف أو عنوان IP مختلف عن المتوقع، أو في وقت مختلف عن المعتاد، فقد يكون هذا مؤشراً على أن كلمة مرور المستخدم قد تم اختراقها.
  • 4.4.D.3 مؤشر على رذاذ كلمة المرور هو محاولة العديد من المستخدمين تسجيل الدخول في غضون ثوانٍ من بعضهم البعض من عنوان IP واحد أو من عناوين IP غير عادية.
  • 4.4.D.4 مؤشر على تعبئة الاعتمادات هو سلسلة من تركيبات مستخدم:كلمة مرور افتراضية يتم تجربتها على جهاز بسرعة متتالية، وغالباً من نفس عنوان IP.
  • 4.4.D.5 لا يمكن الكشف عن هجمات كلمات المرور غير المتصلة بالإنترنت، لأن الهجوم يحدث على حاسوب الخصوم.

Source: College Board AP Course and Exam Description · ⁨المصدر: وصف دورة وامتحان College Board AP⁩

English

Devices log logins, file changes, and processes, and these logs reveal an indicator of compromise (IoC) 入侵指标 - evidence that an adversary got in. Host-based IoCs show up as unexpected processes or changed settings; file-based IoCs are files whose hash matches known malware; behaviour-based IoCs are things like many failed logins or unusual login times.

Choosing a detection method means weighing performance (signature-based is lighter, better for weak devices), cost (an endpoint detection and response (EDR) 端点检测与响应 service is powerful but expensive), and how sensitive the device is. Reading authentication logs exposes password attacks: many wrong passwords for one user signals a guessing attack; many users failing from one IP signals password spraying; a burst of default credentials signals credential stuffing. Offline attacks, though, cannot be detected - they happen on the adversary's own computer.

Speed is itself a security factor. Signature-based detection compares what it sees against a list of known-bad patterns, so it is faster than anomaly-based detection, which must first learn what normal looks like and then measure every event against that model. Anomaly-based detection catches attacks that have no signature yet, but it costs far more processing power — and on a device that lacks it, the effect compounds: the detection runs slowly, the device degrades, and the method ends up not being implemented effectively at all.

العربية

تسجل الأجهزة عمليات تسجيل الدخول، وتغييرات الملفات، والعمليات، وكشف هذه السجلات عن مؤشر اختراق (IoC) - وهو دليل على أن المهاجم قد دخل النظام. تظهر مؤشرات الاختراق القائمة على المضيف كعمليات غير متوقعة أو إعدادات متغيرة؛ أما مؤشرات الاختراق القائمة على الملفات فهي ملفات يتطابق هاشها مع البرمجيات الخبيثة المعروفة؛ بينما تشمل مؤشرات الاختراق القائمة على السلوك أشياء مثل محاولات تسجيل دخول فاشلة كثيرة أو أوقات تسجيل دخول غير معتادة.

يعني اختيار طريقة الكشف موازنة الأداء (الاستناد إلى التوقيع أخف وزناً، الأنسب للأجهزة الضعيفة)، والتكلفة (خدمة كشف الاستجابة في الطرفية (EDR) قوية لكنها باهظة الثمن)، وحساسية الجهاز. يكشف قراءة سجلات المصادقة عن هجمات كلمات المرور: عدد كبير من كلمات المرور الخاطئة لمستخدم واحد يشير إلى هجوم تخميني؛ فشل مستخدمين كثيرين من عنوان IP واحد يشير إلى رشّ كلمات المرور؛ تدفق استخدام بيانات اعتماد افتراضية يشير إلى إغراق البيانات. ومع ذلك، لا يمكن اكتشاف الهجمات غير المتصلة بالشبكة - لأنها تحدث على جهاز المهاجم الخاص.

السرعة هي عامل أمني بحد ذاتها. تقارن الكشف بالاستناد إلى التوقيع ما يراه مع قائمة بأنماط سيئة معروفة، لذا فهو أسرع من الكشف بالاستناد إلى الشذوذ، الذي يجب أولاً أن يتعلم كيف يبدو الطبيعي ثم يقيس كل حدث مقابل هذا النموذج. يلتقط الكشف بالاستناد إلى الشذوذ هجمات ليس لها توقيع بعد، لكنه يستهلك طاقة معالجة أكبر بكثير — وفي جهاز يفتقر إليها، تتفاقم النتيجة: بطء عملية الكشف، تدهور أداء الجهاز، ويصبح المنهج غير فعال تماماً في النهاية.

4.4

Exam tips · ⁨نصائح للامتحان⁩

English
  • Know each malware type by its defining trait: a worm self-spreads, a virus needs a user, ransomware encrypts for money, a RAT gives remote control, a rootkit hides.
  • A hash is one-way and fixed-length; salt makes identical passwords hash differently. Never say a service "stores the password" - it stores the salted hash.
  • Name real algorithms: SHA-256/SHA-512 are current; MD5 and SHA-1 are deprecated because efficient collision attacks exist.
  • Match the password attack to its log signature: one user + many wrong passwords = guessing; many users + one IP = spraying; default credentials = stuffing.
  • Sort authentication factors into know / have / are / where, and remember MFA combines two or more - a fingerprint plus a password, not two passwords.
  • Offline password attacks cannot be detected because the cracking happens on the adversary's machine - a favourite exam "gotcha".
العربية
  • تعرف على كل نوع من البرمجيات الخبيثة بصفته المميزة: الديدان تنتشر تلقائياً، والفيروسات تحتاج إلى مستخدم، وبرمجيات الفدية تشفر البيانات لأجل المال، وأدوات التحكم عن بعد (RAT) تمنح سيطرة عن بُعد، ومركبات الجذور تخفي نفسها.
  • الهاش هو أحادي الاتجاه وثابت الطول؛ الملح يجعل هاش كلمات المرور المتطابقة مختلفاً. لا تقل أبداً إن الخدمة "تحفظ كلمة المرور" - بل تحفظ الهاش المملح.
  • سمِّ خوارزميات حقيقية: SHA-256/SHA-512 هي الحالية؛ MD5 و SHA-1 مهجورة بسبب وجود هجمات تصادم فعالة.
  • طابق هجوم كلمة المرور مع توقيع السجل: مستخدم واحد + كلمات مرور خاطئة كثيرة = تخمين؛ مستخدمون كثيرون + عنوان IP واحد = رشّ؛ بيانات اعتماد افتراضية = إغراق.
  • صنف عوامل المصادقة إلى تعرف / امتلاك / هوية / مكان، وتذكر أن المصادقة متعددة العوامل (MFA) تجمع بين عاملين أو أكثر - مثل بصمة الإصبع بالإضافة إلى كلمة مرور، وليس كلمتي مرور.
  • لا يمكن اكتشاف هجمات كلمات المرور غير المتصلة بالشبكة لأن عملية الكسر تتم على جهاز المهاجم - وهي فخ امتحاني مفضل.

Interactive lessons on this topic · ⁨دروس تفاعلية حول هذا الموضوع⁩

Work through it step by step, with instant-check exercises. · ⁨ا-working عليه خطوة بخطوة، مع تمارين تحقق فوري.⁩

Past Papers · ⁨أوراق الامتحانات السابقة⁩

More topics in AP Cybersecurity · ⁨الأمن السيبراني (AP)⁩ · ⁨المزيد من المواضيع في AP Cybersecurity · ⁨الأمن السيبراني (AP)⁩⁩

Log in or create account · ⁨تسجيل الدخول أو إنشاء حساب⁩

IGCSE, A-Level & AP