Social engineering · サイバーセキュリティにおける社会的エンジニアリング
Hacking the human
- The weakest part of any system is often people, not computers.
- Social engineering means tricking a person into giving away secrets or access. No malware needed.
人間をターゲットにしたハッキング
- システム中最も脆弱な部分は、 often 人間であり、コンピューターではありません。
- ソーシャルエンジニアリングとは、人を騙して秘密情報やアクセス権限を引き出すことです。マルウェアは不要です。
Phishing and pharming
- Phishing — a fake email or message that looks real, asking you to "log in" on a fake site that steals your password.
- Pharming — redirecting you to a fake website even when you typed the correct address.
- Both aim to steal your login details by pretending to be a site you trust.
フィッシングとファーマリング
- フィッシング — 本物のように見える偽メールやメッセージで、偽サイトでのログインを促し、パスワードを盗む行為。
- ファーマリング — 正しいURLを入力していても、偽サイトへ転送される行為。
- どちらも、信頼できるサイトであるふりをしてログイン情報を盗もうとします。
Spotting a phishing message
- Check the sender's address and the link — hover to see where it really goes.
- Watch for urgency ("act now or your account closes!") and spelling mistakes.
- A real bank will never ask for your password by email.
フィッシングメッセージの見分け方
- 送信者アドレスとリンクを確認し、マウスを hovering して実際の先を確認してください。
- 緊急性(「今すぐ行動しないとアカウントが閉鎖されます!」)やスペルミスに注意してください。
- 正規の銀行がメールでパスワードを要求することはありません。
Other tricks
- Shoulder surfing — simply watching you type your PIN.
- Baiting — leaving an infected USB stick for a curious person to plug in.
- The defence is awareness: slow down and check before you click or type.
Covers: IGCSE 5.3 (phishing, pharming, social engineering), AP CSP Big Idea 5.
その他の手口
- ショルダーサーフィン — ピン入力を見張るだけの手口。
- ベイトング — 感染したUSBメモリを残し、好奇心旺盛な人に刺させる手口。
- 防御策は意識向上です。クリックや入力の前に一旦立ち止まり、確認しましょう。
対象科目: IGCSE 5.3 (フィッシング、ファーマリング、ソーシャルエンジニアリング)、AP CSP Big Idea 5.
Now you try
- First build a tiny phishing filter: check the sender's address and where the link really points.
- Then match three more tricks to their names — exactly what the exam asks you to do.
あなたも試してみよう
- まず、簡易的なフィッシングフィルターを作成しましょう:送信者アドレスとリンクの先を確認します。
- その後、残りの3つの手口とその名称を一致させてください—これが試験で求められる作業です。
Common mistakes
- The weakest link is often people, not software.
- Phishing tricks you into giving up secrets — check the sender and the link first.
よくあるミス
- 最も弱い環節は often ソフトウェアではなく、人間です。
- フィッシングは秘密情報を引き出すように欺きます—まず送信者とリンクを確認してください。
Build a tiny phishing filter. The real bank writes from addresses ending @mybank.com and its links start with https://mybank.com. Print phishing if either check fails, otherwise ok. · 小さなフィッシングフィルターを作成する。本物の銀行は末尾が@mybank.comであるアドレスから送信し、リンクはhttps://mybank.comで始まる。どちらかの条件が満たされなければphishingを出力し、両方満たせばokを出力する。
Click Run to see the output here. · 実行ボタンをクリックして出力を確認してください。
Name the trick. Set each variable to shoulder surfing, baiting or pharming. · トリックの名前を答える。各変数をshoulder surfing、baiting、またはpharmingに設定する。
Click Run to see the output here. · 実行ボタンをクリックして出力を確認してください。