Skip to content · ⁨コンテンツへスキップ⁩
Subjects · ⁨科目⁩

AP Cybersecurity · ⁨AP サイバーセキュリティ⁩

Tips · ⁨ヒント⁩

AP Cybersecurity covers the CIA triad, threats and vulnerabilities, access control and authentication, cryptography, network security, secure software, incident response, and security policy, law and ethics. It is a new course, so no released exams exist yet and the Course and Exam Description is the authority on what is examinable.

The reasoning is defensive. A question is usually "here is a system, what could go wrong and what would you do about it" — which needs a named threat, a named control, and a reason the control addresses that threat.

Learn the vocabulary precisely. Authentication is not authorisation; hashing is not encryption; a vulnerability is not a threat. These distinctions are what questions are built on.

Notes follow the CED across threats, cryptography, networking and defence, with practical examples you can try in the browser. Because the course is new, the library carries the sample questions released so far rather than a run of past papers.

  • 1

    Introduction to Security · ⁨セキュリティへの入門⁩

    Watch lesson · ⁨レッスンを視聴⁩
    1.1

    Understanding Social Engineering

    Syllabus · ⁨シラバス⁩
    English

    Learning Objective 1.1.A: Identify common indicators of social engineering tactics.

    • 1.1.A.1 Social engineering attacks employ psychological tactics to manipulate users into revealing sensitive information (elicitation), downloading a malicious file, or clicking on a malicious link. Social engineering can be performed in person but is often done by email, by text message, or through social media messages.
    • 1.1.A.2 Adversaries often use psychological tactics like intimidation and urgency to achieve their goals. Intimidation is when an adversary threatens a target with negative consequences if they don’t comply. Urgency is when an adversary creates reasons why a target should act quickly.

    Learning Objective 1.1.B: Explain how social engineering tactics influence victims to perform a desired action.

    • 1.1.B.1 Social engineering tactics rely on common psychological principles that influence human behavior.
    • 1.1.B.2 Intimidation leverages a natural human aversion to negative consequences. By drawing attention to possible negative consequences, adversaries use fear to incite targets to act.
    • 1.1.B.3 Urgency leverages a natural human response to react quickly to time-sensitive needs. When targets detect a sense of urgency in a message, they feel pressured to respond or act quickly, which can prevent them from taking the time to consider whether an action is reasonable or safe.

    Learning Objective 1.1.C: Describe possible impacts for victims of social engineering attacks.

    • 1.1.C.1 Victims may give an adversary personal information that could lead to impersonation, such as name, phone number, address, workplace, pets’ names, or birthdate. These types of information, and information like them, are often used on websites as challenge questions to verify a user’s identity.
    • 1.1.C.2 Victims may give an adversary secure information like a one-time password (OTP) or authentication login code, which could allow an adversary to log in to a service as the victim.
    • 1.1.C.3 Victims may download malware or click a link that installs malware on their device, steals information from their web browser, or directs them to a website where their login credentials can be captured by an adversary.
    日本語

    学習目標 1.1.A: ソーシャルエンジニアリング戦術の一般的な兆候を特定する。

    • 1.1.A.1 ソーシャルエンジニアリング攻撃は、心理的な戦術を用いて、ユーザーに敏感な情報(要請)を漏洩させたり、悪意のあるファイルをダウンロードさせたり、悪意のあるリンクをクリックさせたりします。ソーシャルエンジニアリングは対面で行われることもありますが、メール、テキストメッセージ、またはソーシャルメディアメッセージを通じて行われることが一般的です。
    • 1.1.A.2 敵対者は、目標達成のために威嚇や緊急性といった心理的戦術をよく使用します。威嚇とは、敵対者が対象が従わない場合に否定的な結果をもたらすと脅すことです。緊急性とは、敵対者が対象が迅速に行動すべき理由を作り出すことです。

    学習目標 1.1.B: ソーシャルエンジニアリング戦例が被害者を特定の行動をとらせるように影響を与える方法を説明する。

    • 1.1.B.1 ソーシャルエンジニアリング戦例は、人間の行動に影響を与える一般的な心理学的原則に依存しています。
    • 1.1.B.2 威嚇は、人間が否定的な結果を避けたがる自然な傾向を利用します。潜在的な否定的な結果に注目を集めることで、敵対者は恐怖を煽って対象を行動に追い込みます。
    • 1.1.B.3 緊急性は、時間制約のあるニーズに対して迅速に対応しようとする人間の自然な反応を利用します。メッセージに緊急性を感じた対象は、対応や行動を急ぐ圧力を感じることがあり、それが行動が適切か安全かどうかを検討する時間を奪うことがあります。

    学習目標 1.1.C: ソーシャルエンジニアリング攻撃の被害者に対する可能性のある影響を記述する。

    • 1.1.C.1 被害者は、身元詐称につながる可能性のある個人情報(氏名、電話番号、住所、勤務先、ペットの名前、生年月日など)を敵対者に提供することがあります。これらの情報や同様の情報は、ウェブサイトでユーザーの身份を確認するためのチャレンジ質問としてよく使用されます。
    • 1.1.C.2 被害者は、敵対者が被害者になりすましてサービスにログインできるようにする、一度限りパスワード(OTP)や認証ログインコードなどの安全な情報を提供することがあります。
    • 1.1.C.3 被害者は、マルウェアをダウンロードしたり、リンクをクリックしたりして、デバイスにマルウェアをインストールされたり、Webブラウザから情報を盗まれたり、敵対者によってログイン情報が盗まれるウェブサイトへ誘導されたりすることがあります。

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English
    Phishing: how a fake email steals a password

    The weakest part of any computer system is often the human using it. Social engineering 社会工程学 is the art of tricking people into breaking security - giving away a password, opening a bad file, or clicking a bad link. The attacker (we call them an adversary 对手) does not need to break the code; they only need to fool a person.

    Most social engineering happens by email, text message, or social media, though it can also happen in person or by phone. The goal is elicitation 套取信息 - getting sensitive information out of someone without them realising.

    Adversaries lean on two powerful feelings:

    • Intimidation 恐吓 - the adversary threatens a bad result if you do not obey. Fear pushes you to act.
    • Urgency 紧迫感 - the adversary invents a deadline ("reply in the next hour or your account closes"). When we feel rushed, we stop thinking carefully about whether an action is safe.

    The impact 影响 on a victim can be serious. They might reveal personal details (name, address, pet's name, birthday) that are later used to answer security challenge questions 安全问题 and impersonate 冒充 them. They might hand over a one-time password (OTP) 一次性密码, letting the adversary log in as them. Or they might download malware 恶意软件 that steals data from their browser.

    Worked example. A phishing email reads: "Over 90% of staff have already verified their account - confirm yours in the next hour or lose payroll access." Two tactics are stacked here. "In the next hour" is urgency (a deadline that rushes you), and "over 90% of staff have already" is consensus (social pressure to follow the crowd). Naming each tactic - not just calling the email "suspicious" - is exactly what an exam answer needs.

    日本語
    Phishing: how a fake email steals a password

    The weakest part of any computer system is often the human using it. Social engineering 社会工程学 is the art of tricking people into breaking security - giving away a password, opening a bad file, or clicking a bad link. The attacker (we call them an adversary 对手) does not need to break the code; they only need to fool a person.

    Most social engineering happens by email, text message, or social media, though it can also happen in person or by phone. The goal is elicitation 套取信息 - getting sensitive information out of someone without them realising.

    Adversaries lean on two powerful feelings:

    • Intimidation 恐吓 - the adversary threatens a bad result if you do not obey. Fear pushes you to act.
    • Urgency 紧迫感 - the adversary invents a deadline ("reply in the next hour or your account closes"). When we feel rushed, we stop thinking carefully about whether an action is safe.
    Social engineering uses psychological pressure to make a victim act before they think
    Social engineering uses psychological pressure to make a victim act before they think

    The impact 影响 on a victim can be serious. They might reveal personal details (name, address, pet's name, birthday) that are later used to answer security challenge questions 安全问题 and impersonate 冒充 them. They might hand over a one-time password (OTP) 一次性密码, letting the adversary log in as them. Or they might download malware 恶意软件 that steals data from their browser.

    Worked example. A phishing email reads: "Over 90% of staff have already verified their account - confirm yours in the next hour or lose payroll access." Two tactics are stacked here. "In the next hour" is urgency (a deadline that rushes you), and "over 90% of staff have already" is consensus (social pressure to follow the crowd). Naming each tactic - not just calling the email "suspicious" - is exactly what an exam answer needs.

    Explore · ⁨探索⁩

    Which social-engineering tactic is it? · ⁨これはどのソーシャルエンジニアリング戦術か?⁩

    Intimidation threatens harm, urgency invents a deadline, consensus claims everyone else is doing it, and authority pretends to have power over you. · ⁨威嚇は危害を脅迫し、緊急性は期限を捏造し、合意形成は他者が皆そうしていると主張し、権威はあなたに対して権力があるふりをするものです。⁩

    Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
    English 日本語
    Social engineering/ˈsəʊʃl ˌendʒɪˈnɪərɪŋ/ サイバーセキュリティにおける社会的エンジニアリング
    adversary/ˈædvəsəri/ 敵対者
    elicitation/ɪˌlɪsɪˈteɪʃn/ 引き出し
    Intimidation/ɪnˌtɪmɪˈdeɪʃn/ 威嚇 (Intimidation)
    Urgency/ˈɜːdʒənsi/ 緊急性
    impact/ˈɪmpækt/ 影響
    challenge questions/ˈtʃælɪndʒ ˈkwestʃnz/ 課題問題
    impersonate/ɪmˈpɜːsəneɪt/ なりすまし
    one-time password (OTP)/wʌn taɪm ˈpæswɜːd/ 一度きりのパスワード (OTP)
    malware/ˈmælweə/ マルウェア
    1.2

    Suspicious Website Logins

    Syllabus · ⁨シラバス⁩
    English

    Learning Objective 1.2.A: Identify common signs of a password attack.

    • 1.2.A.1 In an online password attack, adversaries try logging in to a device or service using common passwords, common password patterns, or stolen passwords.
    • 1.2.A.2 Signs of an online password attack include:
      • Many failed attempts to log in over a short duration
      • Login attempts at unusual times
      • Login attempts from unknown devices

    Learning Objective 1.2.B: Explain how adversaries take advantage of weak authentication.

    • 1.2.B.1 Many people use common patterns when creating passwords, such as:
      • Starting a password with one or two words, adding a two-digit number (often signifying a year), and putting a special character at the end
      • Including the names of family or pets in their passwords
      • Including personally significant dates in their passwords
    • 1.2.B.2 Adversaries often construct a dictionary of possible passwords based on personal information gathered about a target (e.g., birthday, anniversary, names of pets and family) and use an automated tool to submit potential passwords.

    Learning Objective 1.2.C: Explain how to make authentication stronger.

    • 1.2.C.1 Users should create passwords that are long, random, and unique. A password manager can be used to generate and store strong passwords, or a user may create long, unique passphrases for their accounts.
    • 1.2.C.2 When creating passwords, users should avoid names, dates, or other personally meaningful words or numbers.
    • 1.2.C.3 When available, users should enable multifactor authentication (MFA), which will require the user to provide extra proof of identity—such as a one-time code—in addition to the password as an extra layer of security.
    日本語

    学習目標 1.2.A: パワード攻撃の一般的な兆候を特定する。

    • 1.2.A.1 オンラインでのパワード攻撃では、敵対者は一般的なパスワード、一般的なパスワードパターン、または盗難されたパスワードを使用して、デバイスやサービスにログインしようと試みます。
    • 1.2.A.2 オンラインでのパワード攻撃の兆候には以下が含まれます:
      • 短期間内での多数のログイン失敗試行
      • 通常ではない時間帯のログイン試行
      • 未知のデバイスからのログイン試行

    学習目標 1.2.B: 敵対者が脆弱な認証如何利用するかを説明する。

    • 1.2.B.1 多くの人は、パスワードを作成する際に一般的なパターンを使用します。例えば:
      • パスワードの冒頭に1つまたは2つの単語を使用し、末尾に2桁の数字(多くは年を示す)と特殊文字を追加する
      • パスワードに家族やペットの名前を含める
      • パスワードに個人的に重要な日付を含める
    • 1.2.B.2 攻撃者は、ターゲットに関する個人情報(例:誕生日、記念日、ペットや家族の名前)に基づいて可能なパスワードの辞書を作成し、自動化されたツールを使用して潜在的なパスワードを提出することがあります。

    学習目標 1.2.C: 認証をより強くする方法を説明する。

    • 1.2.C.1 ユーザーは、長く、ランダムでユニークなパスワードを作成すべきです。パスワードマネージャーを使用して強力なパスワードを生成・保存したり、アカウント用に長くユニークなパスフレーズを作成したりできます。
    • 1.2.C.2 パスワードを作成する際、ユーザーは名前、日付、または他の個人的に意味のある言葉や数字を避けるべきです。
    • 1.2.C.3 利用可能であれば、ユーザーは多要素認証(MFA)を有効にするべきです。これは、パスワードに加えて、ワンタイムコードなどの追加の身元証明を提供することを要求し、追加のセキュリティ層となります。

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English

    A password attack 密码攻击 is any attempt to log in using guessed or stolen passwords. In an online password attack the adversary tries passwords against a real login page. The warning signs are visible in the logs:

    • many failed logins in a short time,
    • login attempts at unusual hours,
    • login attempts from unknown devices.

    Adversaries succeed because people choose weak 弱 passwords. Common patterns include a word plus a two-digit year plus a special character (like Summer24!), or a pet's or family member's name. Because these patterns are so common, an adversary can build a dictionary 字典 of likely passwords from information gathered about you and let an automated tool try each one.

    To make authentication 身份验证 stronger:

    • Create passwords that are long, random, and unique - a password manager 密码管理器 can generate and store them for you.
    • Avoid names, dates, and meaningful words.
    • Turn on multifactor authentication (MFA) 多因素身份验证, which asks for extra proof (like a texted code) on top of the password.
    日本語
    A hardware security key: strong authentication reduces damage when a password is phished
    A hardware security key: strong authentication reduces damage when a password is phished

    A password attack 密码攻击 is any attempt to log in using guessed or stolen passwords. In an online password attack the adversary tries passwords against a real login page. The warning signs are visible in the logs:

    • many failed logins in a short time,
    • login attempts at unusual hours,
    • login attempts from unknown devices.

    Adversaries succeed because people choose weak 弱 passwords. Common patterns include a word plus a two-digit year plus a special character (like Summer24!), or a pet's or family member's name. Because these patterns are so common, an adversary can build a dictionary 字典 of likely passwords from information gathered about you and let an automated tool try each one.

    To make authentication 身份验证 stronger:

    • Create passwords that are long, random, and unique - a password manager 密码管理器 can generate and store them for you.
    • Avoid names, dates, and meaningful words.
    • Turn on multifactor authentication (MFA) 多因素身份验证, which asks for extra proof (like a texted code) on top of the password.
    Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
    English 日本語
    password attack/ˈpæswɜːd əˈtæk/ パスワード攻撃
    weak/wiːk/ 弱い
    dictionary/ˈdɪkʃənəri/ 辞書
    authentication/ɔːˌθentɪˈkeɪʃn/ 認証
    password manager/ˈpæswɜːd ˈmænɪdʒə/ パスワードマネージャー
    multifactor authentication (MFA)/ˌmʌltɪˈfæktə ɔːˌθentɪˈkeɪʃn/ 多要素認証 (MFA)
    1.3

    Best Practices for Public Networks

    Syllabus · ⁨シラバス⁩
    English

    Learning Objective 1.3.A: Identify the type of adversary conducting a cyberattack.

    • 1.3.A.1 Adversaries can be classified by their skill levels.
      • Low-skilled adversaries rely on malicious cyber tools created by others that can be purchased online. The tools they use exploit known vulnerabilities.
      • High-skilled adversaries have the capacity to create new malicious cyber tools or modify existing ones to adapt to new defensive techniques and tools. They also have the capacity to discover undocumented vulnerabilities, known as zero days.
    • 1.3.A.2 Adversaries have a variety of motivations, including greed, desire for recognition, dedication to a cause, revenge, politics, or beliefs.

    Learning Objective 1.3.B: Identify types of wireless cyberattacks.

    • 1.3.B.1 In an evil twin attack, an adversary sets up their own wireless access point (WAP) with a service set identifier (SSID) similar or identical to a target network; the adversary’s network is called the evil twin. Victims of this attack could select to unknowingly connect to the evil twin, allowing the adversary to capture their network traffic. The adversary cannot read traffic that uses an encrypted protocol like HTTPS.
    • 1.3.B.2 In a jamming attack, an adversary floods an area with a strong electromagnetic (EM) signal in the same frequency range as the wireless network, which prevents legitimate traffic between the access point (AP) and users. This type of attack that prevents users from accessing resources is called a denial of service (DoS) attack.
    • 1.3.B.3 In a war driving attack, adversaries try to detect wireless network beacons while driving or walking around a target. If a wireless signal is detected, the adversary can gather information about the type of wireless network used and find areas where the wireless signal extends outside the physical building.

    Learning Objective 1.3.C: Describe actions individuals can take to increase protection of sensitive data when using the internet and Wi-Fi.

    • 1.3.C.1 Individuals should verify that the name of any wireless network they join exactly matches the name of the network they intend to join.
    • 1.3.C.2 Most internet protocols are encrypted to protect network traffic. However, individuals may consider the sensitivity of their data in choosing whether to join unencrypted Wi-Fi networks to protect vulnerable data such as DNS queries.
    • 1.3.C.3 Individuals may consider using a virtual private network (VPN), which encrypts all their traffic to the VPN operator’s system. Although this action prevents a service provider from viewing traffic, the VPN provider can view the traffic.
    日本語

    学習目標 1.3.A: サイバー攻撃を実施している攻撃者のタイプを特定する。

    • 1.3.A.1 攻撃者はスキルレベルによって分類されます。
      • スキルの低い攻撃者は、他者が作成した悪意あるサイバーツールに依存しており、これらはオンラインで購入できます。彼らが使用するツールは既知の脆弱性を突きます。
      • スキルの高い攻撃者は、新しい悪意あるサイバーツールを作成したり、既存のツールを改変して新しい防御技術やツールに適応させたりする能力を持っています。また、文書化されていない脆弱性であるゼロデイを発見する能力も持っています。
    • 1.3.A.2 攻撃者には、富への渇望、名声への欲求、理念への献身、復讐、政治、あるいは信念など、多様な動機があります。

    学習目標 1.3.B: ワイヤレスサイバー攻撃の種類を特定する。

    • 1.3.B.1 イビルツイン攻撃では、攻撃者はターゲットネットワークと類似または同一のサービスセットID(SSID)を持つ独自のワイヤレスアクセスポイント(WAP)を設置します。攻撃者のネットワークは「イビルツイン」と呼ばれます。この攻撃の対象となったユーザーは、無意識のうちにイビルツインに接続を選択し、攻撃者にネットワークトラフィックを傍受される可能性があります。攻撃者は、HTTPSのような暗号化プロトコルを使用するトラフィックは読み取ることができません。
    • 1.3.B.2 ジャミング攻撃では、攻撃者は無線ネットワークと同じ周波数帯域に強力な電磁(EM)信号を領域全体に flooding し、アクセスポイント(AP)とユーザー間の正規の通信を妨害します。ユーザーがリソースにアクセスできないようにするこの種の攻撃は、サービス妨害(DoS)攻撃と呼ばれます。
    • 1.3.B.3 ウォードライビング攻撃では、攻撃者はターゲット周辺を車や徒歩で移動しながらワイヤレスネットワークビーコンを検出しようとします。ワイヤレス信号を検出すると、攻撃者は使用されているワイヤレスネットワークの種類に関する情報を収集し、物理的な建物の外にワイヤレス信号が到達しているエリアを見つけることができます。

    学習目標 1.3.C: インターネットおよびWi-Fiを使用する際に、個人の行動を通じて敏感なデータの保護を強化する方法を説明する。

    • 1.3.C.1 個人は、接続しようとするワイヤレスネットワークの名前が、意図しているネットワークの名前と完全に一致することを確認すべきです。
    • 1.3.C.2 多くのインターネットプロトコルはネットワークトラフィックを保護するために暗号化されています。しかし、個人はDNS照会などの脆弱性の高いデータを保護するため、未暗号化のWi-Fiネットワークへの接続の有無についてデータ敏感性を考慮すべきです。
    • 1.3.C.3 個人は、すべてのトラフィックをVPNオペレータのシステムに暗号化する仮想プライベートネットワーク(VPN)の使用を検討すべきです。この行為はサービスプロバイダーによるトラフィックの閲覧を防ぎますが、VPNプロバイダー自身はトラフィックを閲覧できる可能性があります。

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English

    Not all adversaries are the same. We classify them by skill: low-skilled attackers buy ready-made tools online and reuse known exploits 漏洞利用, while high-skilled attackers write their own tools and can discover brand-new holes called zero days 零日漏洞. Their motivation 动机 varies too - greed, revenge, politics, or belief.

    Public Wi-Fi is a favourite hunting ground. Three wireless attacks you must know:

    • Evil twin 双胞胎恶意热点 - the adversary sets up a fake access point 接入点 with a name (SSID 服务集标识符) copied from the real network. Victims connect to the fake one, and the adversary reads their traffic (though encrypted 加密的 sites like HTTPS stay safe).
    • Jamming 干扰攻击 - the adversary floods the air with a strong radio signal so no one can connect. This is one kind of denial of service (DoS) 拒绝服务 attack.
    • War driving 战争驾驶 - the adversary drives around detecting wireless networks and where their signal leaks outside a building.

    To protect yourself on public networks: check that the network name exactly matches the one you intend to join, prefer encrypted sites, and consider a virtual private network (VPN) 虚拟专用网络, which encrypts all of your traffic to the VPN operator.

    日本語
    A security token: one-time codes and tokens stop password-only logins from being enough
    A security token: one-time codes and tokens stop password-only logins from being enough

    Not all adversaries are the same. We classify them by skill: low-skilled attackers buy ready-made tools online and reuse known exploits 漏洞利用, while high-skilled attackers write their own tools and can discover brand-new holes called zero days 零日漏洞. Their motivation 动机 varies too - greed, revenge, politics, or belief.

    Public Wi-Fi is a favourite hunting ground. Three wireless attacks you must know:

    • Evil twin 双胞胎恶意热点 - the adversary sets up a fake access point 接入点 with a name (SSID 服务集标识符) copied from the real network. Victims connect to the fake one, and the adversary reads their traffic (though encrypted 加密的 sites like HTTPS stay safe).
    • Jamming 干扰攻击 - the adversary floods the air with a strong radio signal so no one can connect. This is one kind of denial of service (DoS) 拒绝服务 attack.
    • War driving 战争驾驶 - the adversary drives around detecting wireless networks and where their signal leaks outside a building.
    An evil-twin access point copies the real network's name so victims connect to the attacker
    An evil-twin access point copies the real network's name so victims connect to the attacker

    To protect yourself on public networks: check that the network name exactly matches the one you intend to join, prefer encrypted sites, and consider a virtual private network (VPN) 虚拟专用网络, which encrypts all of your traffic to the VPN operator.

    Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
    English 日本語
    exploits/ˈeksplɔɪts/ エクスプロイト
    zero days/ˈzɪərəʊ deɪz/ ゼロデイズ
    motivation/ˌməʊtɪˈveɪʃn/ モチベーション
    Evil twin/ˈiːvl twɪn/ イビル・ツイン
    access point/ˈækses pɔɪnt/ アクセスポイント
    SSID/ˌes es aɪ ˈdiː/ SSID
    encrypted/enˈkrɪptɪd/ 暗号化される
    Jamming/ˈdʒæmɪŋ/ ジャミング
    denial of service (DoS)/dɪˈnaɪəl ɒv ˈsɜːvɪs/ サービス妨害攻撃 (DoS)
    War driving/wɔː ˈdraɪvɪŋ/ ウォー・ドライビング
    virtual private network (VPN)/ˈvɜːtʃuːəl ˈpraɪvət ˈnetwɜːk/ 仮想私人ネットワーク (VPN)
    1.4

    AI-Based Cybersecurity Attacks

    Syllabus · ⁨シラバス⁩
    Learning ObjectiveEssential Knowledge

    1.4.A
    Explain how adversaries use AI-powered tools to augment cyberattacks.

    • 1.4.A.1 Adversaries can use AI-powered tools that leverage existing voice and image samples of a person to create a digital avatar of that person. The use of these technologies enables adversaries to impersonate someone over the phone or even on a video call, which can lead to financial loss or the sharing of sensitive or private information. As more organizations adopt voice-based authentication, the impact of voice-impersonation has a larger potential impact.
    • 1.4.A.2 Adversaries can use generative AI tools, like large language models (LLMs), to create convincing phishing messages in any target language. Because traditional phishing messages are sometimes written by non-native speakers of the target’s language, unnatural language is a feature that has been used to distinguish phishing messages from legitimate messages. However, with AI tools, adversaries can now craft phishing messages in any language that read as though they were written by a native speaker.
    • 1.4.A.3 Adversaries can craft prompts that extract secure or sensitive information from LLMs. Secure or sensitive information in LLMs can come from user input and the large data sets used to train LLMs.
    • 1.4.A.4 Adversaries can publish websites or modify existing websites to contain false information so that the false information will be included in the training sets for LLMs, causing the LLMs to repeat the false information.
    • 1.4.A.5 Adversaries can perform reconnaissance on a target using AI-powered tools that scan the internet to gather information posted on social media and public websites.
    • 1.4.A.6 Adversaries can use AI-enhanced coding tools to help them write new malware, modify existing application code to perform malicious activities, or to find vulnerabilities in large code bases.

    1.4.B
    Explain how to protect against some AI-augmented cyberattacks.

    • 1.4.B.1 Shared secrets with close friends and relatives that can be used to verify each other’s identities should be established. A secret word or phrase known only to two parties can be used to authenticate identities in high-stakes situations.
    • 1.4.B.2 Multifactor authentication (MFA) should be enabled. If an adversary clones a target’s voice to access a system with voice authentication, requiring a second authentication factor could prevent an adversary from gaining access to accounts.
    • 1.4.B.3 Personal or sensitive data should not be entered into any AI-powered tools, such as chatbots or virtual assistants. Some AI-powered tools feed user input back into the model to provide continuous training. Adversaries could extract data that users have included in prompts.
    • 1.4.B.4 Output from AI-powered tools should be carefully evaluated. Verify information from AI-powered tools using reputable, stable, non-AI-based sources.

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English

    Artificial intelligence gives adversaries powerful new tools. With enough voice and image samples, an adversary can build a deepfake 深度伪造 avatar to impersonate someone on a call. Large language models (LLMs) 大语言模型 let them write convincing phishing 钓鱼 emails in perfect, native-sounding language - removing the clumsy wording that once gave scams away.

    AI also helps adversaries on the back end: crafting prompts that pull secret data out of an LLM, planting false information on websites so it poisons an LLM's training data, scanning the internet to gather facts about a target, and even writing new malware.

    You can defend against many AI-augmented attacks: agree on a shared secret 共享秘密 word with close contacts to verify identity, enable MFA (so a cloned voice alone cannot log in), never type sensitive data into a chatbot, and always double-check AI output against reliable, non-AI sources.

    AI writes code, and that cuts both ways. Adversaries use AI-enhanced coding tools 人工智能辅助编程工具 to write new malware faster than they could by hand, to modify existing application code so that it performs malicious activity, and to scan a codebase for vulnerabilities 漏洞 to attack. The skill barrier falls: someone who could not previously write an exploit can now ask for one, so the number of capable attackers rises even when no new technique is invented.

    日本語

    Artificial intelligence gives adversaries powerful new tools. With enough voice and image samples, an adversary can build a deepfake 深度伪造 avatar to impersonate someone on a call. Large language models (LLMs) 大语言模型 let them write convincing phishing 钓鱼 emails in perfect, native-sounding language - removing the clumsy wording that once gave scams away.

    AI also helps adversaries on the back end: crafting prompts that pull secret data out of an LLM, planting false information on websites so it poisons an LLM's training data, scanning the internet to gather facts about a target, and even writing new malware.

    You can defend against many AI-augmented attacks: agree on a shared secret 共享秘密 word with close contacts to verify identity, enable MFA (so a cloned voice alone cannot log in), never type sensitive data into a chatbot, and always double-check AI output against reliable, non-AI sources.

    AI writes code, and that cuts both ways. Adversaries use AI-enhanced coding tools 人工智能辅助编程工具 to write new malware faster than they could by hand, to modify existing application code so that it performs malicious activity, and to scan a codebase for vulnerabilities 漏洞 to attack. The skill barrier falls: someone who could not previously write an exploit can now ask for one, so the number of capable attackers rises even when no new technique is invented.

    Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
    English 日本語
    deepfake/ˈdiːpfeɪk/ ディープフェイク
    Large language models (LLMs)/lɑːdʒ ˈlæŋɡwɪdʒ ˈmɒdlz/ 大規模言語モデル (LLMs)
    phishing/ˈfɪʃɪŋ/ フィッシング
    shared secret/ʃeəd ˈsiːkrɪt/ 共通秘密鍵
    AI-enhanced coding tools/ˌeɪ ˈaɪ enˈhænst ˈkəʊdɪŋ tuːlz/ AI強化_programmingツール
    vulnerabilities/ˌvʌlnərəˈbɪlɪtiz/ 脆弱性
    1.5

    Leveraging AI in Cyber Defense

    Syllabus · ⁨シラバス⁩
    English

    Learning Objective 1.5.A: Explain how cyber defenders can leverage AI-powered tools to protect networks, applications, and data.

    • 1.5.A.1 AI tools can review current security configurations, like firewall rules and access controls, and recommend more secure options. Recommendations should always be checked by a knowledgeable security technician before being implemented.
    • 1.5.A.2 AI-powered tools can analyze application code to identify vulnerabilities and recommend mitigations. Recommendations should always be reviewed by a knowledgeable programmer before being implemented.
    • 1.5.A.3 AI-powered tools can suggest rules for automated detection systems. Detection rules should always be reviewed by a knowledgeable detection engineer before being added to a system.

    Learning Objective 1.5.B: Explain how AI-powered tools are enabling faster and more accurate threat detection and response.

    • 1.5.B.1 Of the millions of digital events that happen on networks daily, some likely represent an adversary conducting malicious activity. Humans cannot carefully examine all those events to identify the malicious activity.
    • 1.5.B.2 AI-powered tools can be trained to quickly analyze digital events and sort the events that are likely malicious activity from those that are harmless.
    • 1.5.B.3 AI-powered tools can be programmed to alert human cybersecurity personnel when likely malicious activity is detected or to take specific corrective actions based on the type of malicious activity detected.
    • 1.5.B.4 AI-powered tools enable threat-detection and response teams to catch malicious activity and intervene quickly to prevent loss, harm, damage, and destruction to digital infrastructure and data.
    日本語

    学習目標 1.5.A: サイバーディフェンダーがAIツールを活用してネットワーク、アプリケーション、データを保護する方法を説明する。

    • 1.5.A.1 AIツールは現在のセキュリティ設定(ファイアウォールルールやアクセス制御など)を検査し、より安全なオプションを推奨する。推奨事項は、実装前に有識のセキュリティ技術者によって確認されるべきである。
    • 1.5.A.2 AIツールはアプリケーションコードを解析して脆弱性を特定し、緩和策を推奨する。推奨事項は、実装前に有識のプログラマーによってレビューされるべきである。
    • 1.5.A.3 AIツールは自動検出システムのルールを提案する。検出ルールは、システムに追加される前に、有識の検出エンジニアによってレビューされるべきである。

    学習目標 1.5.B: AIツールがより高速かつ正確な脅威検出と対応を可能にしていることを説明する。

    • 1.5.B.1 ネットワーク上で毎日発生する何百万ものデジタルイベントのうち、いくつかは攻撃者が悪意のある活動を行っていることを示唆している。人間がすべてのイベントを注意深く検査して悪意のある活動を特定することはできない。
    • 1.5.B.2 AIツールは、迅速にデジタルイベントを分析し、悪意のある活動の可能性が高いものと無害なものを区別するように訓練することができる。
    • 1.5.B.3 AIツールは、悪意のある活動の可能性が高いものが検出された際にサイバーセキュリティ担当者に警報を発令したり、検出された悪意のある活動の種類に基づいて特定の是正措置を実行したりするようにプログラムできる。
    • 1.5.B.4 AIツールは、脅威検出および対応チームが悪意のある活動に気づき、素早く介入することで、デジタルインフラストラクチャおよびデータの損失、危害、損傷、破壊を防ぐことを可能にする。

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English

    The same technology defends us. AI tools can analyse an application's own source code, identify vulnerabilities in it and recommend mitigations; they can also review firewall rules and access settings and recommend safer options - though a human expert must always check the advice before applying it. AI can scan application code for weaknesses and suggest detection rules.

    ⚠️ A recommendation is not a fix. The CED is explicit that the advice must be reviewed and implemented by a knowledgeable programmer: an AI tool can be confidently wrong about whether a flaw is exploitable, and applying a suggested patch without understanding it can introduce a new fault of its own.

    Its biggest advantage is scale. A medium network produces millions of events every day - far too many for people to read. AI can quickly sort the harmless events from the likely-malicious ones, alert human staff, or take an automatic action. This lets defenders catch an attack and respond in seconds instead of days, preventing loss and damage.

    That scale is what makes threat detection and response 威胁检测与响应 possible in practice: an AI system flags malicious activity as it happens, so the response team can intervene quickly enough to prevent loss, harm, or destruction of digital infrastructure — rather than reading the logs days later and finding out what was taken.

    日本語

    The same technology defends us. AI tools can analyse an application's own source code, identify vulnerabilities in it and recommend mitigations; they can also review firewall rules and access settings and recommend safer options - though a human expert must always check the advice before applying it. AI can scan application code for weaknesses and suggest detection rules.

    ⚠️ A recommendation is not a fix. The CED is explicit that the advice must be reviewed and implemented by a knowledgeable programmer: an AI tool can be confidently wrong about whether a flaw is exploitable, and applying a suggested patch without understanding it can introduce a new fault of its own.

    Its biggest advantage is scale. A medium network produces millions of events every day - far too many for people to read. AI can quickly sort the harmless events from the likely-malicious ones, alert human staff, or take an automatic action. This lets defenders catch an attack and respond in seconds instead of days, preventing loss and damage.

    That scale is what makes threat detection and response 威胁检测与响应 possible in practice: an AI system flags malicious activity as it happens, so the response team can intervene quickly enough to prevent loss, harm, or destruction of digital infrastructure — rather than reading the logs days later and finding out what was taken.

    Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
    English 日本語
    threat detection and response/θret dɪˈtekʃn ænd rɪˈspɒns/ 脅威検知と対応
    1.5

    Exam tips

    • When a question asks you to rank risks, remember high risk = high impact AND easy to exploit. A parking-lot Wi-Fi leak matters less than an open internal port that lets an adversary spoof a device.
    • Learn the social-engineering tactics by name - intimidation, urgency, pretexting, authority, consensus, scarcity, familiarity - and be ready to spot which one an email is using.
    • Encryption still protects you on an evil twin: the adversary sees your traffic but cannot read HTTPS. Say what is exposed, not just "it's unsafe".
    • For "how to make authentication stronger", MFA is almost always part of the answer, plus long/unique passwords from a manager.
    • AI is dual-use: the same tool (LLMs, code analysis) appears on both the attack and the defense side. Read the question carefully to see which side it asks about.
  • 2

    Securing Spaces · ⁨空間の保護⁩

    Watch lesson · ⁨レッスンを視聴⁩
    2.1

    Cyber Foundations · ⁨サイバー基礎知識⁩

    Syllabus · ⁨シラバス⁩
    Learning ObjectiveEssential Knowledge

    2.1.A
    Identify social engineering attacks.

    • 2.1.A.1 Social engineers use psychological tactics to manipulate targets into taking a desired action.
    • 2.1.A.2 Pretexting is when adversaries create a believable reason to contact a target.
    • 2.1.A.3 Authority is when adversaries impersonate someone with power over a target or pretend to relay instructions from that person.
    • 2.1.A.4 Intimidation is when adversaries state negative consequences if demands aren’t met.
    • 2.1.A.5 Consensus is when adversaries create social pressure by making a target believe everyone else is doing a desired action.
    • 2.1.A.6 Scarcity is when adversaries create a sense of limited availability.
    • 2.1.A.7 Familiarity is when adversaries pretend to be or know someone close to a target to establish trust.
    • 2.1.A.8 Urgency is when adversaries create a deadline that requires quick action by a target to avert negative consequences.

    2.1.B
    Identify types of adversaries.

    • 2.1.B.1 Script kiddies are low-skilled adversaries who use tools developed by others without understanding how the tools work. They are often motivated by greed or a desire for recognition.
    • 2.1.B.2 Hacktivists are motivated by social, political, or personal causes. They compromise computers and networks to support their cause or stop perceived harm, believing their goals justify their illegal methods.
    • 2.1.B.3 Insider adversaries are unique threats because they have legitimate credentials and access to systems and data. They can be recruited by malicious third parties and can be motivated by greed or revenge.
    • 2.1.B.4 Cyberterrorists are motivated by politics or beliefs and seek to disrupt entire communities, regions, or nations through cyberattacks (e.g., attacking a power grid, water treatment plant, or other civil infrastructure). They can act independently or on behalf of governments or criminal organizations.
    • 2.1.B.5 Transnational criminal organizations seek financial gain primarily by deploying ransomware and stealing corporate intellectual property (IP) to sell in illegal markets.

    2.1.C
    Describe the phases of a cyberattack.

    • 2.1.C.1 Cyberattacks aim to disrupt, harm, steal, or destroy devices, networks, or data. Adversaries work in phases, which may not all be used in every attack. The phases are:
      • i. Reconnaissance
      • ii. Initial access
      • iii. Persistence
      • iv. Lateral movement
      • v. Taking action
      • vi. Evading detection
    • 2.1.C.2 In the reconnaissance phase of an attack, adversaries gather as much information as possible about their target, often using open source intelligence (OSINT), which is freely available information.
    • 2.1.C.3 In the initial-access phase of an attack, adversaries establish a foothold on the target’s computer, often through social engineering or compromised or weak credentials.
    • 2.1.C.4 After gaining access during an attack, adversaries establish persistence to maintain access without needing to regain it. They may use a command and control (C2) protocol to send commands to the device and receive output, often through malware like a remote access trojan (RAT) or rootkit.
    • 2.1.C.5 In the lateral-movement phase of an attack, adversaries try to escalate their privileges by accessing computers and user accounts with elevated permissions to services and data.
    • 2.1.C.6 In the taking-action phase of an attack, adversaries act on their objectives by collecting targeted data, exfiltrating it, and disrupting services or destroying data.
    • 2.1.C.7 In the final phase of an attack, many adversaries try to evade detection by removing or editing log files and erasing other files they may have planted on devices (e.g., malware).

    2.1.D
    Describe the risk assessment process.

    • 2.1.D.1 Risk occurs when a threat can exploit a vulnerability to compromise an asset.
    • 2.1.D.2 An asset is anything valuable. Assets include financial resources, intellectual property, data, digital infrastructure, physical property, and reputation.
    • 2.1.D.3 Risk assessment considers two factors:
      • The likelihood of an attack against a specific vulnerability
      • The severity of the projected damage from an attack against a specific vulnerability
    • 2.1.D.4 The likelihood of a vulnerability being exploited depends on many factors, including:
      • The value of the target: Adversaries are more likely to attack targets they perceive as valuable.
      • The level of skill required to exploit the vulnerability (i.e., the difficulty): Vulnerabilities with well-documented exploits often require less skill and can be carried out by more adversaries.
      • The motivation and capabilities of likely adversaries: Highly motivated and skilled adversaries are more likely to be able to perform more complex exploits.
    • 2.1.D.5 The severity of an attack is often measured by financial cost, which can also include reputational and operational impacts.
      • Illustrative examples for 2.1.D.5:
        • A hacktivist is passionate about illegal fishing practices supported by a local food production company. The main webpage of this food production company would be a high-value target for this hacktivist; defacing the webpage to expose the company’s support of illegal fishing would provide no financial gain to the adversary, but would allow them to raise awareness about an issue that motivates them.
    • 2.1.D.6 The result of a risk assessment can be quantitative or qualitative.
      • Quantitative risk assessment assigns a numeric value to a vulnerability based on a numeric scale (e.g., 1–10) or quantifiable impact, which could be financial (e.g., a $10,000 annual risk).
      • Illustrative examples for 2.1.D.6:
        • Low, medium, high, severe
        • Unlikely low impact, likely low impact, unlikely high impact, likely high impact
    • 2.1.D.7 Risk assessment documentation should include:
      • Vulnerable assets and their value
      • Descriptions of likely threats to the assets
      • Details of specific vulnerabilities for specific assets and how they would be exploited
      • An explanation of the severity of damage (financial, operational, reputational, etc.) if a specific asset were compromised, and the likelihood of that compromise occurring
      • A final rating, quantitative or qualitative, for each risk identified
      • Illustrative examples for 2.1.D.7:
        • Scaled score (e.g., 1–10)
        • Monetary value (e.g., a $10,000 risk vs. a$100,000 risk)

    2.1.E
    Identify strategies for managing risk.

    • 2.1.E.1 Once a risk has been identified and assessed, an organization has four options for managing that risk:
      • i. Avoid
      • ii. Transfer
      • iii. Mitigate
      • iv. Accept
    • 2.1.E.2 Risk avoidance stops the activity that is generating the risk. If the activity is a critical part of an organization’s mission or purpose, then avoidance is not possible.
    • 2.1.E.3 Risk transference places the burden of the risk on another entity, such as an insurance company, a government, or consumers.
    • 2.1.E.4 Risk mitigation implements security controls to reduce the likelihood or impact of a risk.
    • 2.1.E.5 Residual risk is the risk that remains after an organization has gone through avoidance, transference, and mitigation. The residual risk is the level of risk that an organization is willing to accept. Risk acceptance acknowledges the fact that absolute security is unattainable.
    • 2.1.E.6 To conserve financial resources and employee capacity, an organization will often favor solutions that are cost effective and easy to implement and maintain. Cost-effective solutions cost less to install and maintain than the expected loss from an attack.

    2.1.F
    Identify types of security controls.

    • 2.1.F.1 Security controls address at least one of the following principles:
      • Confidentiality ensures that only authorized individuals, systems, or processes can access data. Systems lacking confidentiality are vulnerable to data theft or destruction.
      • Integrity ensures data are accurate and trustworthy. Systems lacking integrity are vulnerable to data manipulation.
      • Availability ensures data and services are accessible to authorized individuals when needed. Systems lacking availability may experience unexpected downtime.
    • 2.1.F.2 Security controls can be classified by type.
      • Physical controls provide security in the physical space and include locks, fences, and cameras, bollards, and security guards.
      • Technical controls provide security in the digital space and include firewalls, anti-malware software, and encryption.
      • Managerial controls provide rules, guidelines, policies, and procedures that specify what security should be in place and include password policies, regular access reviews, and incident response plans (IRPs).
    • 2.1.F.3 Security controls can be classified by function.
      • Preventative controls address potential vulnerabilities with the goal of stopping an adversary from attacking and include locks and encryption.
      • Detective controls help identify attacks when they occur and include intrusion detection systems (IDSs), cameras, and security incident and event management (SIEM) systems.
      • Corrective controls fix problems and help restore systems to an operational state and include vulnerability patching, repairing a broken card reader, and intrusion prevention systems (IPSs).

    2.1.G
    Explain why a defense-in-depth security strategy is necessary to optimally protect an organization.

    • 2.1.G.1 A defense-in-depth strategy, or layered defense, uses multiple types of security controls to protect sensitive data and systems.
    • 2.1.G.2 A defense-in-depth strategy allows an organization to address different types of threats, each with a security control most suited to mitigate it.
    • 2.1.G.3 A defense-in-depth strategy allows for resilience in data protection so when one security control is bypassed by an adversary, another security control may still prevent access to the data or system or limit the damage done to the data or system.
    • 2.1.G.4 Layers in a defense-in-depth strategy can include human, physical, network, device, application, and data.

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English

    Before defending a system, you need a shared language. This section builds it.

    Every security control protects at least one part of the CIA triad 信息安全三要素 - the three goals of security:

    • Confidentiality 保密性 - only authorised people can read the data.
    • Integrity 完整性 - the data is accurate and unaltered.
    • Availability 可用性 - the data and services are there when needed.

    Attacks come from different adversaries, classified by their goals. A script kiddie 脚本小子 reuses tools built by others for greed or recognition; a hacktivist 黑客活动分子 acts for a political, social, or personal cause; an insider 内部人员 already holds legitimate access and may act from revenge or greed; a cyberterrorist 网络恐怖分子 disrupts critical infrastructure like a power grid or water plant; and transnational criminal organisations 跨国犯罪组织 chase money through ransomware and stolen data.

    Most attacks unfold in phases 阶段: reconnaissance 侦察 (gathering information, often from public OSINT 公开来源情报 sources), initial access, persistence, lateral movement 横向移动 (spreading to more systems by escalating privileges), taking action on the goal, and evading detection. Naming the phase an attacker has reached helps a defender choose the right response.

    Social engineering: the seven tactics

    Most attacks begin not with code but with social engineering 社会工程学 - psychological tricks that manipulate a person into doing what the adversary wants. The exam names seven tactics, and expects you to identify which one a scenario shows:

    Tactic The trick
    Pretexting 借口 inventing a believable reason to make contact ("I'm from IT, verifying your account")
    Authority 权威 posing as someone powerful, or relaying "the boss's" instructions
    Intimidation 恐吓 threatening negative consequences if a demand is not met
    Consensus 从众 claiming everyone else is already doing it, to create social pressure
    Scarcity 稀缺 inventing limited availability ("only 2 left")
    Familiarity 熟悉 pretending to be, or to know, someone close to the target
    Urgency 紧迫感 imposing a tight deadline so the target acts before thinking

    the common thread is that all seven bypass a target's judgement by triggering an automatic emotional response - fear, trust, haste, or the wish to fit in. The defence is the same each time: verify through a separate, trusted channel before acting.

    A risk 风险 appears when a threat 威胁 can exploit a vulnerability 漏洞 to compromise an asset 资产 (anything valuable - data, money, hardware, reputation). We assess risk by weighing two things: the likelihood 可能性 of an attack and the severity 严重性 of the damage.

    Likelihood itself depends on the value of the target (adversaries chase what looks worth stealing), the skill needed to exploit the vulnerability (a well-documented exploit needs little skill, so more adversaries can use it), and the motivation and capability of likely adversaries. Severity is usually measured in financial cost, but includes reputational and operational damage too.

    The final rating can be written two ways, and the exam wants you to tell them apart:

    • quantitative 定量 - a number: a score on a scale (e.g. 1-10), or a money value (e.g. "a $10,000 annual risk").
    • qualitative 定性 - a label: low / medium / high / severe, or a grid such as likely-high-impact vs unlikely-low-impact.

    A written risk assessment 风险评估 should record, for each risk: the vulnerable asset and its value, the likely threats, how the specific vulnerability would be exploited, the severity if it were compromised, and a final quantitative or qualitative rating.

    Once a risk is measured, an organisation has four ways to manage it:

    • Avoid 规避 - stop the risky activity (only possible if it isn't essential).
    • Transfer 转移 - shift the burden to someone else, such as an insurer.
    • Mitigate 缓解 - add controls to lower the likelihood or impact.
    • Accept 接受 - live with the leftover residual risk 剩余风险, because perfect security is impossible.

    Security controls are grouped two ways. By type: physical 物理 (locks, fences, guards), technical 技术 (firewalls, anti-malware, encryption), and managerial 管理 (policies and procedures). By function: preventative 预防性 (stop an attack, like a lock), detective 检测性 (spot an attack, like a camera), and corrective 纠正性 (fix and restore, like patching).

    Worked example. A hospital stores patient records on an unencrypted server in an unlocked room. Rate the risk: the asset is highly sensitive (patient data, protected by law) and the vulnerability is easy to exploit (no encryption, no access control), so this is a high risk. Now classify one fix - a door lock: by type it is a physical control, and by function it is preventative (it stops entry before an attack even begins).

    The best strategy layers many controls - a defense-in-depth 纵深防御 approach. If an adversary bypasses one layer, another still stands. Layers include human, physical, network, device, application, and data.

    日本語
    モニター壁:ネットワーク監視とログ記録は侵入検知に役立ちます
    モニター壁:ネットワーク監視とログ記録は侵入検知に役立ちます

    システムを防御するためには、共通の言語が必要です。このセクションでそれを構築します。

    すべてのセキュリティ制御は、セキュリティの3つの目標であるCIA三要素の少なくとも1つの部分を保護します:

    • 機密性 - 承認された人だけがデータを読むことができます。
    • 完全性 - データが正確で改ざんされていない状態です。
    • 可用性 - 必要な時にデータとサービスが存在することです。
    CIA三要素:すべてのセキュリティ制御が支える3つの目標
    CIA三要素:すべてのセキュリティ制御が支える3つの目標

    攻撃は異なる攻撃者から行われ、その目的によって分類されます。スクリプト・キディは、金銭や名声のために他者が作ったツールを流用します;ハックティビストは政治的、社会的、または個人的な目的のために行動します;インサイダーはすでに正当なアクセス権限を持っており、復讐や金銭的目的で行動することがあります;サイバーテロリストは電力網や水道施設などの重要インフラを撹乱します;そして越境犯罪組織はランサムウェアや盗難データを介して金銭を追求します。

    ほとんどの攻撃はフェーズに分かれて展開されます:レコネッサンス(情報収集、特に公開されたOSINTソースからの)、初期アクセス、定着化、横方向移動(権限昇格によりより多くのシステムへ拡大)、ゴールへの実行、および検知回避です。攻撃者が到達したフェーズを特定することは、防御者が適切な対応を選択する助けとなります。

    サイバーエジニアリング:7つの戦術

    ほとんどの攻撃はコードではなく、サイバーエジニアリングから始まります。これは、心理的なトリックを用いて対象者を攻撃者の望むように操作するものです。試験では7つの戦術を名称付け、シナリオに哪种の戦術が示されているかを識別することを求めます:

    戦術 トリック内容
    プレテクスティング 連絡を取るための説得力のある理由を捏造する(「IT部署です。アカウントを確認しています」)
    権威 権力ある人物を装う、または「上司」の指示を伝える
    恐怖 要求が満たされない場合の不利な后果を脅迫する
    合意形成 誰もが既にそれを行っていると主張し、社会的圧力をかける
    希少性 利用可能性が限定されていると捏造する(「残り2個だけ」)
    親近感 対象者に近い人物であることを装う、または知っているふりする
    緊急性 厳しい期限を設定し、対象者が考える前に行動させさせる

    共通する点は、これら7つすべてが、恐怖、信頼、焦り、あるいは同調したいという欲求といった自動的な感情的反応を引き起こすことで、対象者の判断を回避していることです。防御策も毎回同じです:行動する前に、別の信頼できるチャネルを通じて検証すること。

    リスクとは、脅威が脆弱性を利用して資産(データ、お金、ハードウェア、評判など価値のあるもの全て)を侵害できる場合に生じます。私たちは2つの要素を比較することでリスクを評価します:攻撃の発生確率と被害の深刻度です。

    発生確率は、対象の価値(攻撃者は狙い目として価値があるものを探します)、脆弱性を悪用するために必要なスキル(詳細に文書化されたエクスプロイトは少ないスキルで済むため、より多くの攻撃者が使用できます)、そして想定される攻撃者の動機と能力に依存します。深刻度は通常、財務的コストで測られますが、評判的および業務的な被害も含みます。

    最終的な評価は2通りの方法で表すことができ、試験ではそれらを区別できることを求めます:

    • 定量的 - 数値:スケール上のスコア(例:1-10)、または金銭価値(例:「年間のリスク $10,000」)。
    • 定性的 - ラベル:低 / 中 / 高 / 深刻、または likely-high-impact と unlikely-low-impact のようなグリッド。

    記述されたリスク評価には、各リスクについて以下の内容を記録する必要があります:脆弱性を持つ資産とその価値、想定される脅威、特定の脆弱性がどのように悪用されるか、侵害された場合の深刻度、そして最終的な定量的または定性的な評価。

    リスクを測定したら、組織にはそれを管理するための4つの方法があります:

    • 回避 - リスクのある活動を停止する(必須でない場合のみ可能)。
    • 移転 - 負担を第三者(保険会社など)に移す。
    • 軽減 - 制御を追加して、発生確率や影響を低下させる。
    • 受容 - 完全なセキュリティは不可能であるため、残った残留リスクを受け入れる。

    セキュリティ制御は2通りで分類されます。種類別:物理的(錠前、柵、警備員)、技術的(ファイアウォール、マルウェア対策ソフト、暗号化)、管理的(方針と手順)。機能別:予防的(攻撃を止める、錠前の例)、探知的(攻撃を発見する、カメラの例)、是正的(修復と回復、パッチ適用の例)。

    ** worked example.** 病院が鍵のかからない部屋にある未暗号化のサーバーに患者記録を保管している場合、リスクを評価します:資産は非常に敏感(法的に保護されている患者データ)であり、かつ脆弱性は悪用されやすい(暗号化なし、アクセス制御なし)ため、これは高リスクです。次に、一つの解決策であるドアロックを分類します:種類別では物理的制御であり、機能別では予防的です(攻撃が始まる前に入室を阻止するため)。

    最善の戦略は、多くの制御を積層することです。これはディフェンス・イン・デプスアプローチと呼ばれます。攻撃者が1つの層を突破しても、他の層はまだ残っています。層には、人的、物理的、ネットワーク、デバイス、アプリケーション、データのものが含まれます。

    ディフェンス・イン・デプス:多くの層があるため、1回の突破でも資産が露出しない
    ディフェンス・イン・デプス:多くの層があるため、1回の突破でも資産が露出しない
    Explore · ⁨探索⁩

    Classify each security control by function · ⁨各セキュリティ制御機能的に分類する⁩

    A preventative control stops an attack, a detective control spots one in progress, and a corrective control fixes the damage and restores the system. · ⁨予防的制御は攻撃を止めます、検知的制御は進行中の攻撃を発見し、修正的制御は被害を修復してシステムを復旧させます。⁩

    Explore · ⁨探索⁩

    Classify each security control by type · ⁨各セキュリティ制御を種類別に分類する⁩

    A physical control guards the physical space, a technical control works in the digital space, and a managerial control is a rule, policy, or procedure. · ⁨物理的制御は物理空間を守り、技術的制御はデジタル空間で動作し、管理職的制御はルール、ポリシー、または手順です。⁩

    Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
    English 日本語
    CIA triad/ˌsiː aɪ ˈeɪ ˈtraɪæd/ CIA三要素
    Confidentiality/ˌkɒnfɪˌdenʃiˈæləti/ 守秘義務
    Integrity/ɪnˈteɡrɪti/ 誠実さ
    Availability/əˌveɪləˈbɪlɪti/ 可用性
    script kiddie/skrɪpt ˈkɪdi/ スクリプト・キッド
    hacktivist/ˈhæktɪvɪst/ ハックティビスト
    insider/ɪnˈsaɪdə/ 内部者
    cyberterrorist/ˈsaɪbəterərɪst/ サイバーテロリスト
    transnational criminal organisations/trænˈsnæʃənl ˈkrɪmɪnl ˌɔːɡənaɪˈzeɪʃnz/ 越境犯罪組織
    phases/ˈfeɪzɪz/ 満ち欠け
    reconnaissance/rɪˈkɒnɪsəns/ 偵察
    OSINT/ˈəʊsɪnt/ OSINT
    lateral movement/ˈlætərəl ˈmuːvmənt/ 横向き移動
    social engineering/ˈsəʊʃl ˌendʒɪˈnɪərɪŋ/ ソーシャルエンジニアリング
    Pretexting/ˈpriːtekstɪŋ/ プリテクスティング
    Authority/əˈθɒrɪti/ 権威
    Intimidation/ɪnˌtɪmɪˈdeɪʃn/ 威嚇 (Intimidation)
    Consensus/kənˈsensəs/ 合意 (Consensus)
    Scarcity/ˈskeəsɪti/ 希少性 (Scarcity)
    Familiarity/fəˌmɪliˈærɪti/ 親近感 (Familiarity)
    Urgency/ˈɜːdʒənsi/ 緊急性
    risk/rɪsk/ リスク
    threat/θret/ threat(脅威)
    vulnerability/ˌvʌlnərəˈbɪlɪti/ 脆弱性
    asset/ˈæset/ 資産
    likelihood/ˈlaɪklihʊd/ 可能性
    severity/səˈverɪti/ 深刻度
    quantitative/ˈkwɒntɪteɪtɪv/ 量的
    qualitative/ˈkwɒlɪteɪtɪv/ 定性的
    risk assessment/rɪsk əˈsesmənt/ リスク評価
    Avoid/əˈvɔɪd/ 回避する
    Transfer/ˈtrænsfɜː/ 電子の移動
    Mitigate/ˈmɪtɪɡeɪt/ 軽減する
    Accept/əkˈsept/ 受ける
    residual risk/rɪˈsɪdʒuːəl rɪsk/ 残留リスク
    defense-in-depth/dɪˈfens ɪn depθ/ 深層防御
    physical attacks/ˈfɪzɪkl əˈtæks/ 物理的攻撃
    2.2

    Physical Vulnerabilities and Attacks · ⁨物理的な脆弱性と攻撃⁩

    Syllabus · ⁨シラバス⁩
    Learning ObjectiveEssential Knowledge

    2.2.A
    Identify common physical attacks.

    • 2.2.A.1 Adversaries often use social engineering when conducting a physical attack.
    • 2.2.A.2 Piggybacking is the name for an attack where an adversary uses social engineering to manipulate an authorized individual to grant the adversary access to a restricted area. Common piggybacking tactics include carrying something large to entice an authorized person to hold the door open, pretending to be an authorized person who has forgotten their access token, or pretending to be a maintenance person who needs to get into a certain area to perform an inspection or repair.
    • 2.2.A.3 Tailgating is the name for an attack where an adversary gains unauthorized access to a restricted area by following close behind an authorized individual without that individual’s awareness or knowledge.
    • 2.2.A.4 Shoulder surfing is the name for an attack where an adversary watches as a user accesses sensitive information so the adversary can use it later. Sometimes adversaries use a camera to record the target accessing the sensitive information for later analysis.
    • 2.2.A.5 Dumpster diving is the name for an attack where an adversary goes through a target’s physical trash to look for information that could be used to help the adversary reach their goal.
    • 2.2.A.6 Card cloning is the name for an attack where an adversary makes a copy of an authorized user’s access card so they can gain access to all the resources the user is authorized to access.

    2.2.B
    Explain how threats can exploit common physical vulnerabilities to cause loss, damage, disruption, or destruction to assets.

    • 2.2.B.1 Threats include human adversaries seeking to cause harm or disruption as well as natural disasters. Natural disasters can cause physical damage or destruction to computers and data as well as disruption of digital services provided by computers.
    • 2.2.B.2 Vulnerabilities are weaknesses or flaws that could allow an asset to be compromised. Common compromises include:
      • Unauthorized access to sensitive data or restricted physical spaces
      • Disruption of services
      • Theft or destruction of digital or physical resources
      • Unauthorized modification of data
    • 2.2.B.3 When adversaries disrupt power to a device, the device and any services it provides become unavailable. To disrupt power, adversaries may damage fuses or breakers in an electrical box, unplug or cut electrical wiring, or damage power distribution systems like substations and transformers.
    • 2.2.B.4 When adversaries gain access to an area with sensitive information, they can steal or copy sensitive information.
    • 2.2.B.5 When adversaries gain physical access to a device and its ports, they can plug in a keylogger or external drive containing malware, which could allow them to collect data from a user or possibly even to gain control of the device. With direct physical access adversaries can also physically destroy a device, making the device itself, any data stored on it, and any services it provides unavailable.

    2.2.C
    Assess and document risks from physical vulnerabilities.

    • 2.2.C.1 Physical access to devices can allow adversaries to bypass many technical controls and layers of security.
    • 2.2.C.2 High risks from physical vulnerabilities arise when sensitive information or systems are exposed in physical spaces without sufficiently restricted and controlled access.
      • Illustrative examples for 2.2.C.2:
        • A server that stores customer data is in a room with no lock which is accessed via an unmonitored hallway.
    • 2.2.C.3 Moderate risks from physical vulnerabilities arise when a noncritical or nonsensitive part of an organization is left unprotected in a way that it could act as a foothold for an adversary to gain initial access to other resources.
      • Illustrative examples for 2.2.C.3:
        • An office has a reception area beyond which access is controlled; the receptionist has a computer that connects to the office’s internal wireless network and the computer has exposed USB ports.
    • 2.2.C.4 Low risks from physical vulnerabilities arise when a vulnerable asset is of low value and the vulnerability is unlikely to be exploited.
      • Illustrative examples for 2.2.C.4:
        • Employees in an office that requires badge access have laptop computers that they leave on their desks unattended when they all go to lunch together. The computers do not contain any sensitive information, but there are no cables securing the devices to the desks.

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English

    Digital security means nothing if an adversary can simply walk in. Common physical attacks 物理攻击 often begin with social engineering:

    • Piggybacking 尾随(获许可) - tricking an authorised person into holding a door open (for example, by carrying a heavy box).
    • Tailgating 尾随(未察觉) - slipping through a secured door behind someone without their knowledge.
    • Shoulder surfing 肩窥 - watching someone type a password or read sensitive information.
    • Dumpster diving 翻垃圾搜集情报 - searching a target's trash for useful information.
    • Card cloning 门禁卡复制 - copying an access card to enter restricted areas.

    With physical access, an adversary can cut power, steal or copy data, or plug in a keylogger 键盘记录器. We rate physical risk as high when sensitive systems sit in a space without controlled access, moderate when an unimportant area could act as a foothold 立足点 to reach other resources, and low when the asset is worthless and unlikely to be attacked.

    日本語

    攻撃者が容易に侵入できる場合、デジタルセキュリティは意味をなしません。一般的な物理的攻撃は、多くが社会的工程学から始まります:

    • ピグバック(Piggybacking)() - 権限のある人物に扉を開けてもらうようにだますする(例えば、重い箱を持っていたりして)。
    • テイルゲート(Tailgating)() - 本人の知ることなく、施錠された扉の後ろに潜り込む。
    • ショルダーサーフィン(Shoulder surfing) - パスワード入力や機密情報の閲覧をしている他人を見守る。
    • ダンピング・ダイビング(Dumpster diving) - ターゲットのゴミから有益な情報を探し出す。
    • カードクロニング(Card cloning) - 制限区域への入場用アクセスカードをコピーする。

    物理的にアクセスできた場合、攻撃者は電源を遮断したり、データを盗み出したり複製したり、またはキーロガーを接続したりできます。敏感なシステムが管理されていないアクセス空間内に置かれている場合はリスクを高いと評価し、重要でないエリアが他のリソースへ到達するための足掛かりとなる可能性がある場合は中程度と評価し、資産価値がなく攻撃される可能性が低い場合は低いと評価します。

    鎖にかけられたパッドロック:物理的セキュリティは最初の防御層であり、錠前、扉、バリアが重要です
    鎖にかけられたパッドロック:物理的セキュリティは最初の防御層であり、錠前、扉、バリアが重要です
    Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
    English 日本語
    physical/ˈfɪzɪkl/ 物理
    technical/ˈteknɪkl/ 技術的な
    managerial/ˌmænəˈdʒɪərɪəl/ 管理的
    preventative/prɪˈventətɪv/ 予防的
    detective/dɪˈtektɪv/ 探索的
    corrective/kəˈrektɪv/ 是正保守
    Piggybacking/ˈpɪɡɪbækɪŋ/ ピグバックイニング
    Tailgating/ˈteɪlɡeɪtɪŋ/ テイルゲイティング
    Shoulder surfing/ˈʃəʊldə ˈsɜːfɪŋ/ ショルダーサーフィング
    Dumpster diving/ˈdʌmpstə ˈdaɪvɪŋ/ ダンピングダイビング
    Card cloning/kɑːd ˈkləʊnɪŋ/ カードクロニク
    keylogger/ˈkiːlɒɡə/ キーロガー
    foothold/ˈfʊthəʊld/ 足がかり
    clean desk policy/kliːn desk ˈpɒlɪsi/ クリーンデスクポリシー
    bollards/ˈbɒlɑːdz/ ポール
    card readers/kɑːd ˈriːdəz/ カードリーダー
    2.3

    Protecting Physical Spaces · ⁨物理的スペースの保護⁩

    Syllabus · ⁨シラバス⁩
    English

    Learning Objective 2.3.A: Identify managerial controls related to physical security.

    • 2.3.A.1 Organizations should conduct employee security awareness training to educate employees about how they can contribute to the organization’s security by:
      • Detecting social engineering attempts like phishing
      • Not badging other people into restricted areas
      • Preventing device theft
    • 2.3.A.2 Organizations should have a workstation security policy that outlines the measures necessary to protect a physical workplace. The policy may have tiers of workstation security based on the type of data handled at a workstation. Workstation policies often require:
      • Locking devices before leaving workstations unattended to prevent unauthorized access
      • Clearing sensitive documents off workstations before leaving them unattended (sometimes called a clean desk policy)
      • Using a privacy screen filter or other physical barrier to prevent others from viewing information on the screen
      • Connecting devices to surge protectors or uninterruptible power supplies (UPS)

    Learning Objective 2.3.B: Determine mitigation strategies for risks from physical vulnerabilities.

    • 2.3.B.1 To determine a relevant control, a cyber defender considers how an adversary could take advantage of a vulnerability to attack a system and how to prevent, detect, or correct the attack.
    • 2.3.B.2 Installing physical controls like fencing, gates, and bollards around a building can deter adversaries from trying to physically access an organization’s buildings.
    • 2.3.B.3 Locks on doors, server cabinets, and computers can prevent devices from being accessed or stolen.
    • 2.3.B.4 Card readers can record which employee badges are being used to access different entries at specific times and deny access to unauthorized badges.
    • 2.3.B.5 Access control vestibules and turnstiles can prevent an authorized person from intentionally or accidentally admitting an unauthorized person into a restricted area.
    • 2.3.B.6 Organizations can disable USB ports to prevent external drives from loading malware onto a computer.
    • 2.3.B.7 An uninterruptible power supply (UPS) provides a backup power source for a device in the event of a power outage. Organizations can also use power generators to provide power at a larger scale to a building or set of critical devices.
    • 2.3.B.8 Organizations prioritize risk mitigations based on the severity of the risks and the cost of the recommended mitigations.
    日本語

    学習目標 2.3.A: 物理セキュリティに関する管理統制を特定する。

    • 2.3.A.1 組織は、従業員が以下のようにして組織のセキュリティに貢献できるかを教育するために、セキュリティ認知研修を実施すべきである。
      • フィッシングなどのサイバーサミング攻撃の検知
      • 制限区域への他人のバッチング(同行)を行わないこと
      • デバイス盗難の防止
    • 2.3.A.2 組織は、物理的な職場を保護するために必要な措置を明記したワークステーションセキュリティポリシーを持つべきである。このポリシーは、ワークステーションで取り扱われるデータの種類に基づいて、ワークステーションセキュリティの階層を含むことがある。ワークステーションポリシーは通常、以下を要求する。
      • 留守にした際に unauthorized access を防ぐため、ワークステーションを離れる前にデバイスをロックすること
      • 留守にする前にワークステーション上の敏感な文書を取り除くこと(クリーンデスクポリシーとも呼ばれる sometimes called a clean desk policy)
      • プライバシースクリーンフィルターやその他の物理的バリアを使用して、他人が画面の情報を見るのを防ぐこと
      • サージプロテクタまたは無停電装置(UPS)にデバイスを接続すること

    学習目標 2.3.B: 物理的脆弱性によるリスクに対する軽減策を決定する。

    • 2.3.B.1 関連する統制を決定するためには、サイバーディフェンダーは、攻撃者がどのように脆弱性を悪用してシステムを攻撃し、また攻撃を防止、検知、または修正するかを検討する。
    • 2.3.B.2 建物の周囲にフェンス、ゲート、ボールドなどを設置することで、攻撃者が組織の建物への物理的アクセスを試みるのを阻止できる。
    • 2.3.B.3 ドア、サーバーキャビネット、およびコンピューターのロックは、デバイスへのアクセスや盗難を防ぐことができる。
    • 2.3.B.4 キャードリーダーは、どの時刻にどの従業員のバッジを使って異なる入り口/accessed different entries at specific times and deny access to unauthorized badges.
    • 2.3.B.5 アクセスコントロール・ベスティブルとターンstileは、権限のある人が意図的または偶発的に権限のない人を制限区域に持ち込むのを防ぐことができる。
    • 2.3.B.6 組織は外部ドライブによるマルウェアのロードを防ぐためにUSBポートを無効化できる。
    • 2.3.B.7 無停電装置(UPS)は、停電時にデバイス用のバックアップ電源を提供する。組織はまた、発電機を使用して、より大規模なスケールで建物や一連の重要なデバイスに電力を提供することもできる。
    • 2.3.B.8 組織はリスクの深刻さと推奨される軽減策のコストに基づいてリスク軽減を優先順位付ける。

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English

    Managerial controls come first: security-awareness training teaches staff not to badge strangers in, and a workstation security policy requires locking devices, clearing desks (a clean desk policy 清桌政策), and using privacy screens.

    Physical controls then harden the building: fences, gates, and bollards 防撞柱 deter access; locks protect doors and cabinets; card readers 读卡器 log and restrict entry; an access control vestibule 门禁前室 (a two-door airlock) stops piggybacking; disabling USB ports blocks malware drives; and an uninterruptible power supply (UPS) 不间断电源 keeps devices running through an outage. Organisations prioritise these by matching the cost of a control to the severity of the risk.

    日本語

    まず経営上の管理統制が必要です。セキュリティ意識向上トレーニングは従業員に見知らぬ人にタグ付けをしないよう指導し、ワークステーションセキュリティポリシーはデバイスのロック、デスククリア(クリーンデスクポリシー)、プライバシースクリーンの使用を要求します。

    次に物理的統制により建物を強化します。フェンス、ゲート、ボーラードはアクセスを妨害し、錠前は扉やキャビネットを守ります。カードリーダーは出入りを記録し制限します。アクセスコントロール・ウェスティブル(Access control vestibule)(2つの扉を持つエアロック)はピグバックを防ぎ、USBポートの無効化はマルウェアドライブの導入をブロックし、無停電装置(UPS: Uninterruptible Power Supply) は停電時にもデバイスを稼働させ続けます。組織はこれらの優先順位を、管理統制のコストとリスクの深刻さのバランスに合わせて決定します。

    ドーム型防犯カメラ:物理的統制と監視はネットワークだけでなくスペースも保護します
    ドーム型防犯カメラ:物理的統制と監視はネットワークだけでなくスペースも保護します
    Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
    English 日本語
    access control vestibule/ˈækses kənˈtrəʊl ˈvestɪbjuːl/ アクセスコントロール・ヴェスティブル
    uninterruptible power supply (UPS)/ˌʌˌnɪntəˈrʌptɪbl ˈpaʊə səˈplaɪ/ 無停電電源装置 (UPS)
    motion sensors/ˈməʊʃn ˈsensəz/ 動作センサー
    points of ingress and egress/pɔɪnts ɒv ˈɪŋɡres ænd iːˈɡres/ 侵入および退出地点
    2.4

    Detecting Physical Attacks · ⁨物理的攻撃の検知⁩

    Syllabus · ⁨シラバス⁩
    English

    Learning Objective 2.4.A: Identify ways security controls can detect physical attacks.

    • 2.4.A.1 Cameras can capture a visual record of an adversary’s malicious activity. The feed from a camera should be recorded and monitored for maximum effect. Recordings can be especially helpful in after-incident investigations.
    • 2.4.A.2 Security guards can monitor activity in an area and respond to suspicious activity once detected.
    • 2.4.A.3 Motion sensors can alert security to movement in an area.
    • 2.4.A.4 Employees that work in a physical space are often the first to notice the presence of an unauthorized person and can alert security.

    Learning Objective 2.4.B: Determine effective placement of security controls for detecting physical attacks.

    • 2.4.B.1 When placing cameras, consideration should be given to visual coverage, angle, and the ability to be tampered with by an adversary. Consideration should also be given to what a camera in a specific area could capture an adversary doing and how that information would be helpful. Points of ingress and egress are often monitored by camera.
    • 2.4.B.2 Motion sensors should be placed in areas where traffic is unexpected, like server rooms, or areas where sensitive materials are stored and few people have access. Motion sensors in high-traffic areas create many false alarms, making the alarms less likely to be taken seriously when there is a real security event.
    • 2.4.B.3 Locks should be placed on all entries to areas containing sensitive information or systems. For areas with particularly sensitive information or systems, an organization could use an access control vestibule at the entry point to prevent piggybacking or tailgating.
    • 2.4.B.4 Security guards can be stationary or patrolling. Stationary guards can provide constant protection for a specific area, entrance, or high-value item. Patrolling guards are more difficult for an adversary to plan around and can create time pressure for an adversary. Placing stationary guards at places that funnel traffic (e.g., entry gates, main entrances or lobbies, and entrances to more secure access areas) can be highly effective, while patrolling guards are better suited for perimeters and exterior areas.

    Learning Objective 2.4.C: Apply detection techniques to identify physical attacks.

    • 2.4.C.1 Cameras provide visual monitoring and a visual record of activity within a designated space. Cameras can be paired with facial recognition software that can provide alerts when unauthorized individuals enter controlled areas. Once a physical breach has been detected, defenders can use live and recorded camera footage to track an adversary’s path and actions.
    • 2.4.C.2 Motion detectors work best when paired with cameras. When a security alert is raised because a motion detector has been activated, defenders can use cameras to check the space visually and verify a physical security breach.
    • 2.4.C.3 When employees are required to use an electronic badge to unlock a door to a restricted area, a sensor can record how long the door was open. In reviewing entry logs for the door, potential piggybacking or tailgating can be detected by doors being open for longer than normal lengths of time.
    日本語

    学習目標 2.4.A: セキュリティ統制が物理攻撃を検知する方法を特定する。

    • 2.4.A.1 カメラは、攻撃者の悪意ある活動を視覚的に記録できる。カメラの映像は最大限の効果のために録画され、監視されるべきである。録画は、事件後の調査において特に役立つことがある。
    • 2.4.A.2 警備員は、区域内の活動を監視し、不審な活動が検知されたら対応する。
    • 2.4.A.3 動作センサーは、区域内での動きを警備員に警告する。
    • 2.4.A.4 物理空間で働く従業員は、 often the first to notice the presence of an unauthorized person and can alert security.

    学習目標 2.4.B: 物理攻撃を検知するためのセキュリティ統制の有効な配置を決定する。

    • 2.4.B.1 カメラを設置する際は、視覚的カバレッジ、角度、および攻撃者による操作の可否を考慮すべきである。特定の領域にあるカメラが攻撃者の何を撮影できるか、そしてその情報がどのように役立つかも考慮すべきである。入退口は often monitored by camera.
    • 2.4.B.2 動作センサーは、サーバールームのような予期せぬ交通量がある場所や、敏感な資料が保管されておりアクセスできる人が少ない場所に設置すべきである。高交通量の領域にある動作センサーは多くの誤警報を引き起こすため、実際のセキュリティイベント发生时 alarms less likely to be taken seriously when there is a real security event.
    • 2.4.B.3 敏感な情報やシステムが含まれる領域へのすべての入り口にロックを設置すべきである。特に敏感な情報やシステムがある領域については、組織はピッグバックやテイルゲートを防ぐために入り口にアクセスコントロール・ベスティブルを使用することができる。
    • 2.4.B.4 警備員は常駐型または巡回型である。常駐型警備員は特定のエリア、入口、または高価値アイテムに対して絶えず保護を提供できる。巡回型警備員は敵対者による計画を立てにくく、敵対者に時間的圧力をかけることができる。交通が集中する場所(例:入構ゲート、主要なエントランスやロビー、より厳重なアクセスエリアへの入り口)に常駐型警備員を配置することは非常に効果的であり、一方、巡回型警備員は周縁部や外郭エリアに適している。

    学習目標 2.4.C: 検知技術を用いて物理攻撃を特定する。

    • 2.4.C.1 カメラは指定された空間内の活動を視覚的に監視し、活動の記録を残す。カメラには顔認識ソフトウェアと組み合わせることができ、未授权者が管理区域に入国した際にアラートを発報することができる。物理的な侵害が検知された後、防衛者は生放送および録画された映像を使って、敵対者の経路や行動を追跡できる。
    • 2.4.C.2 動体検知器はカメラと組み合わせることで最も効果的に機能する。動体検知器が作動して警報が出た場合、防衛者はカメラを使用して空間を視覚的に確認し、物理的なセキュリティ侵害を検証できる。
    • 2.4.C.3 従業員が制限区域の扉を開錠するために電子バッジを使用する場合、センサーは扉が開いていた時間を記録する。扉の入出 logs を確認する際、通常より長時間扉が開いている場合は、ピグバックまたはテイルゲーティングの疑いが検知される。

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English

    Some controls detect attacks rather than prevent them. Cameras record activity and help after-incident investigations; security guards respond to what they see; motion sensors 运动传感器 alert staff to movement; and employees themselves often notice an intruder first.

    Placement matters. Cameras belong at points of ingress and egress 出入口 (entrances and exits). Motion sensors work best in low-traffic areas like server rooms - put them in a busy hallway and constant false alarms make everyone ignore them. Stationary guards protect a fixed high-value point, while patrolling guards are harder for an adversary to plan around. Reviewing door-open times in entry logs can even reveal piggybacking, because a door held open too long is suspicious.

    日本語

    ある統制は攻撃を「防止」するのではなく「検知」するものです。カメラは活動を記録し、事後調査を支援し、警備員は目撃した事象に対応し、モーションセンサーは動きを検知して従業員に警告し、従業員自身も侵入者を最初に気づくことがあります。

    配置が重要です。カメラは侵入および退去ポイント(出入口)に設置されます。モーションセンサーはサーバールームのような低交通量エリアで最も効果的ですが、混雑した廊下に設置すると常時誤警報が発生し、全員がそれを無視するようになります。固定警備員は一定の高価値ポイントを保護しますが、巡回警備員は攻撃者が計画を立てにくくします。ドアオープンタイムのレビューは、入り口ログからピグバックを明らかにすることさえあります。扉が長時間開きっぱなしであることは疑わしいからです。

    2.4

    Exam tips · ⁨試験対策⁩

    English
    • Memorise the CIA triad and be ready to say which goal a control protects - encryption serves confidentiality, a hash checks integrity, a backup restores availability.
    • Know the four risk responses (avoid, transfer, mitigate, accept) and the two ways to classify controls (by type: physical/technical/managerial; by function: preventative/detective/corrective).
    • Distinguish piggybacking (with consent, tricked) from tailgating (without the person's knowledge) - exam questions test this exact pair.
    • For risk-rating questions, high risk needs both high value AND easy exploitation; a "foothold to other systems" is the classic moderate risk.
    • Defense in depth is the model answer whenever a question asks why one control is not enough.
    日本語
    • CIA三要素(CIA triad) を暗記し、どの統制がどのような目標を保護するかを言える準備をする;暗号化は機密性、ハッシュは完全性、バックアップは可用性を守る。
    • 4つのリスク対応策(回避、移転、軽減、受容)を知り、統制を2つの方法で分類する方法を知る(タイプ別:物理/技術/経営;機能別:予防的/探知的/是正的)。
    • ピグバック(同意あり、だまされた状態) と テイルゲート(本人の知情なし) の違いを理解する;試験問題はこの対比を厳密に問うことがある。
    • リスク評価に関する問題において、高いリスクには高い価値 AND 簡単な利用可能性の両方が必要です。「他システムへの足掛かり」は典型的な中程度リスクです。
    • 質問が「なぜ一つの統制では不十分か」と尋ねる際は、ディフェンス・イン・デプスがモデル回答となります。
  • 3

    Securing Networks · ⁨ネットワークの保護⁩

    Watch lesson · ⁨レッスンを視聴⁩
    3.1

    Network Vulnerabilities and Attacks · ⁨ネットワークの脆弱性と攻撃⁩

    Syllabus · ⁨シラバス⁩
    English

    Learning Objective 3.1.A: Identify common network attacks.

    • 3.1.A.1 The address resolution protocol (ARP) is used by a default gateway on a network to establish a table that pairs internet protocol (IP) addresses with media access control (MAC) addresses. An ARP poisoning attack is when an adversary sends falsified ARP packets to the default gateway to modify the table so that the adversary’s device receives traffic intended for the target by linking the target’s IP address to the adversary’s MAC address. Faking a MAC address is called MAC spoofing. This is an example of an on-path attack (or man-in-the-middle attack), which is when an adversary interrupts a data stream between two parties, captures both parties’ data, and copies or alters the data before sending them on. Both parties think they are communicating directly with each other, but instead they are each communicating with the adversary who is secretly intercepting their messages.
    • 3.1.A.2 A MAC flooding attack is when an adversary sends the target switch many Ethernet frames, each with a different MAC address. This can force the switch into broadcast mode, and the adversary can then collect all of the frames on the network (because they are being broadcast), which could allow the adversary to access sensitive information. This is an example of eavesdropping (or sniffing), which is when an adversary captures data in transit and can record and copy the data.
    • 3.1.A.3 A domain name system (DNS) poisoning attack is when an adversary pretends to be an authoritative name server (NS) and plants a fake DNS record on a DNS server to redirect browser traffic to a malicious website designed to steal credentials. This is an example of credential harvesting, which is when adversaries set up a fake login site that looks like a real one. Unsuspecting users enter their real credentials, which the adversaries capture and use.
    • 3.1.A.4 A smurf attack attempts to overwhelm a network with Internet Control Message Protocol (ICMP) requests. It is a type of denial of service (DoS) attack, which makes a system or resource unavailable to authorized users. During a smurf attack, an adversary sends many ICMP requests with the victim’s address to the network’s broadcast address. The network’s gateway then sends these requests to all devices on the network. Each device on the network replies to the victim’s address, creating a flood of traffic that can block legitimate messages. When multiple devices attack the same target simultaneously, it’s called a distributed denial of service (DDoS) attack.

    Learning Objective 3.1.B: Explain how adversaries can exploit network vulnerabilities to steal, disrupt, or destroy network communication.

    • 3.1.B.1 Adversaries can send malicious traffic into a network to flood it creating a DoS, to map the internal structure of the network, or to spoof a legitimate device. Networks without firewalls, or with improperly configured firewalls, are vulnerable to these types of attacks.
    • 3.1.B.2 Adversaries that have compromised a device often attempt to leverage their access to compromise other devices on the local area network (LAN).
    • 3.1.B.3 Adversaries that physically plug into a data port can gain access to a LAN through the switch port unless port security is enabled. This allows adversaries to launch DoS attacks or perform MAC flooding or MAC spoofing attacks.
    • 3.1.B.4 Adversaries standing outside of physically secure spaces can pick up the signals and beacon frames from a wireless access point that is broadcasting outside the physical space. This allows them to gather information about the wireless network and to attempt eavesdropping and cryptographic attacks on it.
    • 3.1.B.5 Adversaries can attempt to join networks to launch attacks from within the networks. Networks that do not authenticate devices and users make it easier for adversaries to join.
    • 3.1.B.6 If there is an open network port, an adversary can plug a wireless access point into the port creating a rogue access point. The adversary could use this rogue access point to access the internal network wirelessly (maybe even from outside the physical space). This allows the adversary direct access to the LAN, bypassing any firewalls.
    • 3.1.B.7 Adversaries can attempt to break wireless encryption and intercept, steal, or compromise data on a network.

    Learning Objective 3.1.C: Assess and document risks from network vulnerabilities.

    • 3.1.C.1 Vulnerabilities on a network can lead to adversaries being able to intercept and alter data in transit, launch DoS attacks, or move laterally on a network to gain access to more sensitive or critical systems. Network vulnerabilities can constitute a risk to confidentiality, integrity, and availability.
    • 3.1.C.2 There are automated vulnerability scanners that can check networks, devices, and applications for known vulnerabilities. These scanners produce a report that often includes the vulnerabilities detected, their severity, and mitigation recommendations.
    • 3.1.C.3 Successfully exploiting a network vulnerability often requires advanced technical ability and knowledge. This can impact the likelihood of an exploit.
    • 3.1.C.4 High risks from network vulnerabilities allow an adversary to easily have a significant impact by capturing network traffic, spoofing a legitimate device on the network, or launching a DoS attack.
      • Illustrative examples for 3.1.C.4:
        • An organization has a single unsegmented internal network that is accessible via a wireless network with weak encryption, and on that network it has a server running its proprietary web-application.
    • 3.1.C.5 Moderate risks from network vulnerabilities could include vulnerabilities that might give adversaries the ability to gain information about systems or devices on a network.
      • Illustrative examples for 3.1.C.5:
        • An organization’s external firewall is not configured to block external ICMP traffic.
    • 3.1.C.6 Low risks from network vulnerabilities include vulnerabilities that would be difficult to exploit and would likely have minimal negative impacts on an organization.
      • Illustrative examples for 3.1.C.6:
        • An organization has wireless access points that broadcast a beacon frame, which contains the network service set identifier (SSID) and the wireless encryption protocols.
    日本語

    学習目標 3.1.A: 一般的なネットワーク攻撃を特定する。

    • 3.1.A.1 アドレス解像プロトコル (ARP) は、ネットワーク上のデフォルトゲートウェイによって使用され、インターネットプロトコル (IP) アドレスとメディアアクセスコントロール (MAC) アドレスをペアにするテーブルを構築するために用いられる。ARP ポイズニング攻撃とは、敵対者が偽造された ARP パケットをデフォルトゲートウェイに送信し、ターゲットの IP アドレスを敵対者の MAC アドレスにリンクすることで、ターゲット宛てのトラフィックを敵対者のデバイスに転送するようにテーブルを変更することである。MAC アダプタを偽装することを MAC スPUフィングという。これはオンパス攻撃(またはミドルマン攻撃)の例であり、敵対者が2者間のデータストリームを遮断し、両者のデータをキャッチし、送信する前にデータをコピーまたは改変する攻撃である。双方は互いに直接通信していると思っているが、実際には各自が敵対者と通信しており、そのメッセージが密かに傍受されている状態となる。
    • 3.1.A.2 MAC フラッディング攻撃とは、敵対者が異なる MAC アダプタを持つ多数のエターネットフレームをターゲットスイッチに送信することである。これによりスイッチがブロードキャストモードに強制され、敵対者はネットワーク上のすべてのフレームを収集できる(これらはブロードキャストされているため)。これにより、敵対者は機密情報へのアクセスが可能になる可能性がある。これはイブスドロップ(またはスニフィング)の例であり、敵対者が進行中のデータをキャッチし、記録・コピーできる攻撃である。
    • 3.1.A.3 DNS ポイズニング攻撃とは、敵対者が権威あるネームサーバー (NS) を装い、DNS サーバーに偽の DNS レコード植入して、認証情報を盗むために設計された悪意のあるウェブサイトへブラウザのトラフィックをリダイレクトすることである。これはクレデンシャルハーベストingの例であり、敵対者が本物のように見える偽のログインサイトを设置し、無邪気なユーザーが本物の認証情報を入力すると、それらを敵対者がキャッチして利用する攻撃である。
    • 3.1.A.4 スマーフ攻撃は、インターネットコントロールメッセージプロトコル (ICMP) リクエストでネットワークを飽和させようとする攻撃である。これは denial of service (DoS) 攻撃の一種であり、システムやリソースを authorized users が利用できないようにする攻撃である。スマーフ攻撃中、敵対者は被害者のアドレスを含む多数の ICMP リクエストをネットワークのブロードキャストアドレスに送信する。ネットワークのゲートウェイはこれらのリクエストをネットワーク上のすべてのデバイスに送信する。各デバイスは被害者のアドレスに返信し、正規のメッセージをブロックする可能性のあるトラフィックの洪水を生み出す。複数のデバイスが同時に同じターゲットを攻撃する場合、これを分散 denial of service (DDoS) 攻撃と呼ぶ。

    学習目標 3.1.B: 敵対者がネットワーク脆弱性をどう活用してネットワーク通信を盗聴、妨害、破壊するか説明する。

    • 3.1.B.1 敵対者は、DoS を引き起こすためにネットワークを飽和させる恶意trafficを送信したり、ネットワークの内部構造をマッピングしたり、合法デバイスを偽装したりできる。ファイアウォールがない、または適切に構成されていないファイアウォールを持つネットワークは、これらの攻撃に脆弱である。
    • 3.1.B.2 デバイスを乗っ取った敵対者は、ローカルエリアネットワーク (LAN) 上の他のデバイスも乗っ取るためにそのアクセスを利用しようとする傾向がある。
    • 3.1.B.3 敵対者がデータポートに物理的に接続した場合、ポートセキュリティが有効化されていない限り、スイッチポートを通じて LAN にアクセスできる。これにより、敵対者は DoS 攻撃を実行したり、MAC フラッディングや MAC スPUフィング攻撃を行ったりできる。
    • 3.1.B.4 物理的に安全なスペースの外にいる敵対者は、物理的空間の外にブロードキャストされているワイヤレスアクセスポイントからの信号やビコンフレームをキャッチできる。これにより、ワイヤレスネットワークに関する情報を収集し、それに対するイブスドロップ暗号化攻撃を試みることが可能になる。
    • 3.1.B.5 敵対者はネットワークに参加して、その内部から攻撃を行うことを試みることがある。デバイスやユーザーを認証しないネットワークでは、敵対者が参加することが容易になる。
    • 3.1.B.6 開放されたネットワークポートがある場合、攻撃者はそのポートにワイヤレスアクセスポイントを接続し、不正アクセスポイントを作成できます。攻撃者はこの不正アクセスポイントを利用して、内部ネットワークに無線でアクセスすることが可能であり(物理的な空間の外からでも)、これによりファイアウォールを回避してLANへの直接アクセスが可能になります。
    • 3.1.B.7 攻撃者は、ワイヤレス暗号化の解除を試み、ネットワーク上のデータを傍受、盗取、または侵害しようとする可能性があります。

    学習目標 3.1.C: ネットワーク脆弱性からのリスクを評価・文書化する。

    • 3.1.C.1 ネットワーク上の脆弱性は、攻撃者が送信中のデータを傍受・改変したり、DoS攻撃を実行したり、ネットワーク上で横方向に移動してより敏感かつ重要なシステムへのアクセスを得たりする原因となることがあります。ネットワーク脆弱性は、機密性、完全性、可用性に対するリスクとなる可能性があります。
    • 3.1.C.2 既知の脆弱性に対してネットワーク、デバイス、アプリケーションを検査できる自動化された脆弱性スキャナがあります。これらのスキャナは、検出された脆弱性、その深刻度、および軽減策に関する推奨事項を含むレポートを生成します。
    • 3.1.C.3 ネットワーク脆弱性を成功裏に悪用するには、高度な技術的能力及び知識が通常必要です。これはエクスプロイトの可能性に影響を与えます。
    • 3.1.C.4 ネットワーク脆弱性による高リスクは、攻撃者がネットワークトラフィックをキャプチャしたり、ネットワーク上の正規デバイスを偽装したり、DoS攻撃を実行したりすることで、容易に重大な影響を与えることを意味します。
      • 3.1.C.4 の例:
        • 組織が単一の未分割内部ネットワークを持ち、弱体な暗号化を持つワイヤレスネットワークを通じてアクセス可能であり、そのネットワーク上で独自ウェブアプリケーションを実行しているサーバーを運用している場合。
    • 3.1.C.5 ネットワーク脆弱性による中程度のリスクには、攻撃者にネットワーク上のシステムやデバイスに関する情報を取得させる可能性がある脆弱性が含まれます。
      • 3.1.C.5 の例:
        • 組織の外部ファイアウォールが、外部ICMPトラフィックをブロックするように設定されていない場合。
    • 3.1.C.6 ネットワーク脆弱性による低リスクには、悪用が困難であり、組織に与える否定的な影響が最小限である可能性が高い脆弱性が含まれます。
      • 3.1.C.6 の例:
        • 組織が、ネットワークサービスセットID(SSID)およびワイヤレス暗号化プロトコルを含むビーコンフレームをブロードキャストするワイヤレスアクセスポイントを持っている場合。

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English
    A man-in-the-middle attack
    DDoS: a botnet floods a server

    A network connects devices so they can share data - and every connection is a possible way in. You must know the classic network attacks and the tricks behind them.

    • ARP poisoning 地址解析投毒 - the address resolution protocol (ARP) 地址解析协议 pairs IP addresses with hardware MAC addresses 物理地址. An adversary sends fake ARP messages so traffic meant for the target flows to the adversary instead. This is an on-path attack 中间人攻击 (also called man-in-the-middle): the adversary secretly sits between two parties, reading and even altering their messages.
    • MAC flooding 物理地址泛洪 - flooding a switch 交换机 with fake MAC addresses forces it into broadcast mode, so the adversary can capture all traffic. This is a form of eavesdropping 窃听.
    • DNS poisoning 域名投毒 - planting a fake record on a domain name system (DNS) 域名系统 server redirects users to a malicious site to steal credentials (credential harvesting 凭据收集).
    • Smurf attack - flooding a network with ICMP requests aimed at the broadcast address, so every device replies to the victim. It is a denial of service (DoS) 拒绝服务 attack; when many machines attack at once it becomes a distributed denial of service (DDoS) 分布式拒绝服务.

    Adversaries exploit weak networks to flood, map, or spoof devices. A physical data port with no port security lets an attacker plug in; an open port lets them install a rogue access point 非法接入点 that bypasses the firewall entirely. We rate network risk by impact and by how much skill the exploit needs.

    To find weaknesses before an adversary does, organisations run an automated vulnerability scanner 自动漏洞扫描器: a tool that checks networks, devices, and applications against a database of known vulnerabilities, then produces a report listing each one found, how severe it is, and a recommended mitigation 缓解措施. Fixing the highest-severity items first is a core part of managing network risk.

    日本語
    マン・イン・ザ・ミドル攻撃
    DDoS:ボットネットがサーバーを氾濫させる

    ネットワークはデバイス同士を接続してデータ共有を可能にするものですが、すべての接続は侵入経路となり得ます。古典的なネットワーク攻撃とその背後にある手口を熟知する必要があります。

    • ARPポイズニング - アドレス解決プロトコル(ARP) はIPアドレスとハードウェアMACアドレスをペアリングします。攻撃者は偽のARPメッセージを送信し、ターゲット宛てのトラフィックを攻击者側へ誘導します。これはオンパス攻撃(マン・イン・ザ・ミドルとも呼ばれる)であり、攻撃者は2者の間に隠れて、メッセージを読み取ったり改変したりします。
    • MACフラッディング - スイッチに偽のMACアドレスを大量送信し、广播モードに強制することで、攻撃者が全トラフィックを捕獲できるようにします。これはイブスドロップ(Eavesdropping) の一種です。
    • DNSポイズニング - ドメインネームシステム(DNS) サーバーに偽レコードを植入し、ユーザーを悪意あるサイトへリダイレクトして認証情報窃取(クレデンシャルハーベスティング)を図ります。
    • スマーフ攻撃(Smurf attack) - ブロードキャストアドレス targeted なICMPリクエストを網絡全体に送信し、すべてのデバイスが標的へ応答するようにします。サービス拒否(DoS) 攻撃であり、複数のマシンが同時に攻撃すると分散型サービス拒否(DDoS) となります。

    攻撃者は脆弱なネットワークを利用して、デバイスを氾濫させたりマッピングしたり、またはサボタージュしたりします。物理的なデータポートにポートセキュリティがないと、攻撃者が接続できます。開放されたポート则有ローグアクセスポイントを設置でき、ファイアウォールを完全にバイパスします。ネットワークリスクは、影響度と利用に必要なスキル度合いに基づいて評価します。

    攻撃者よりも先に脆弱性の弱点を特定するために、組織は自動化された脆弱性スキャナを実装します。これは、ネットワーク、デバイス、アプリケーションが既知の脆弱性のデータベースに照合され、発見された各脆弱性、その深刻度、推奨される対策を含む報告書を作成するツールです。最も深刻度の高い項目から優先的に修復することは、ネットワークリスクを管理する際の重要な手法です。

    Explore · ⁨探索⁩

    Identify the network attack from its evidence · ⁨証拠に基づいてネットワーク攻撃を特定する⁩

    Each network attack leaves a distinct trace: ARP poisoning = one IP with two MACs; MAC flooding = a surge of new MACs; DNS poisoning = misdirected web traffic; smurf/DoS = a flood that blocks legitimate traffic. · ⁨各ネットワーク攻撃には固有の痕跡が残ります:ARPポイズニング=1つのIPに2つのMAC;MACフロッディング=多数の新しいMACの流入;DNSポイズニング=誤ったWebトラフィック;スマーフ/DoS=正当なトラフィックをブロックする洪水。⁩

    Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
    English 日本語
    eavesdropping/ˈiːvzdrɒpɪŋ/ 盗聴
    DNS poisoning/ˌdiː en ˈes ˈpɔɪzənɪŋ/ DNSポイズニング
    domain name system (DNS)/dəˈmeɪn neɪm ˈsɪstəm/ ドメインネームシステム (DNS)
    credential harvesting/krɪˈdenʃl ˈhɑːvɪstɪŋ/ クレデンシャルハーベスト
    denial of service (DoS)/dɪˈnaɪəl ɒv ˈsɜːvɪs/ サービス妨害攻撃 (DoS)
    distributed denial of service (DDoS)/ˈdɪstrɪbjuːtɪd dɪˈnaɪəl ɒv ˈsɜːvɪs/ 分散型サービス妨害攻撃 (DDoS)
    rogue access point/rəʊɡ ˈækses pɔɪnt/ ローグアクセスポイント
    automated vulnerability scanner/ˈɔːtəmeɪtɪd ˌvʌlnərəˈbɪlɪti ˈskænə/ 自動脆弱性スキャナ
    mitigation/ˌmɪtɪˈɡeɪʃn/ 緩和策
    split tunneling/splɪt ˈtʌnəlɪŋ/ スプリット_tunneling(分割_tunneling)
    3.2

    Protecting Networks: Managerial Controls and Wireless Security · ⁨ネットワーク保護:管理的統制とワイヤレスセキュリティ⁩

    Syllabus · ⁨シラバス⁩
    English

    Learning Objective 3.2.A: Identify managerial controls related to network security.

    • 3.2.A.1 A router security policy will set forth a minimum configuration standard for routers on an organization’s network and may include:
      • Banning local user accounts (All router logins must use an approved authentication server.)
      • Disabling unnecessary services (e.g., Telnet)
      • Requiring a firewall (An organization may opt for a firewall device separate from the router.)
    • 3.2.A.2 A switch security policy will set forth a minimum configuration standard for switches on an organization’s network and may include:
      • Banning local user accounts (All switch logins must use an approved authentication server.)
      • Requiring port security to be enabled.
      • Using MAC filtering
    • 3.2.A.3 A virtual private network (VPN) policy will detail the minimum security requirements for employees using a VPN to access an organization’s internal network, and it may include:
      • A list of roles within the organization that are allowed to use a VPN to access the organization’s internal network
      • Authentication requirements for employees using a VPN (e.g., public/private key system or MFA)
      • A prohibition against split tunneling (also called dual tunneling)
    • 3.2.A.4 A wireless security policy will establish the minimum security requirements for wireless networks within an organization and may include:
      • Requiring users to authenticate to the wireless network through an extensible authentication protocol (EAP) connected to an approved authentication server
      • Requiring all wireless traffic to be encrypted using AES encryption with a minimum key length
      • Disabling beacon frames on wireless access points

    Learning Objective 3.2.B: Configure wireless network security features.

    • 3.2.B.1 Organizations can disable beacon frame broadcasting on wireless access points (WAPs) to make it harder for adversaries to find their wireless network and learn its basic properties.
    • 3.2.B.2 Organizations can control the broadcast direction and signal strength of a WAP so the signal does not extend beyond the physical space the access point is meant to cover.
    • 3.2.B.3 Organizations should enable strong wireless encryption protocols to ensure wireless frames are not readable by adversaries who might intercept them.
      • WEP, WPS, and the original WPA wireless encryption protocols have known vulnerabilities and are insecure.
      • WPA3 is currently the strongest wireless encryption algorithm.
    • 3.2.B.4 Organizations can enable MAC filtering to prevent unauthorized devices from accessing the network, and they can require users to authenticate when joining a network.
    日本語

    学習目標 3.2.A: ネットワークセキュリティに関連する管理統制を特定する。

    • 3.2.A.1 ルーターセキュリティポリシーは、組織のネットワーク上のルーターに対する最低構成基準を定めており、以下を含めることがあります:
      • ローカルユーザーアカウントの使用禁止(すべてのルーターログインは承認された認証サーバーを使用すること。)
      • 不要なサービスの無効化(例:Telnet)
      • ファイアウォールの必須化(組織はルーターとは別のファイアウォールデバイスを選択することもある。)
    • 3.2.A.2 スイッチセキュリティポリシーは、組織のネットワーク上のスイッチに対する最低構成基準を定めており、以下を含めることがあります:
      • ローカルユーザーアカウントの使用禁止(すべてのスイッチログインは承認された認証サーバーを使用すること。)
      • ポートセキュリティの有効化の必須化。
      • MACフィルタリングの使用
    • 3.2.A.3 仮想プライベートネットワーク(VPN)ポリシーは、組織の内部ネットワークにアクセスするためにVPNを使用する従業員に対する最低セキュリティ要件を詳細に示しており、以下を含めることがあります:
      • 組織の内部ネットワークにアクセスするためにVPNの使用が許可されている組織内の役職の一覧
      • VPNを使用する従業員のための認証要件(例:公開鍵/秘密鍵システムまたはMFA)
      • スプリット_tunneling(デュアル_tunnelingとも呼ばれる)の禁止
    • 3.2.A.4 ワイヤレスセキュリティポリシーは、組織内のワイヤレスネットワークに対する最低セキュリティ要件を確立しており、以下を含めることがあります:
      • 承認された認証サーバーに接続された拡張認証プロトコル(EAP)を介してユーザーがワイヤレスネットワークに認証されること
      • AES暗号化を使用して最小キー長で、すべてのワイヤレストラフィックが暗号化されていること
      • ワイヤレスアクセスポイントにおけるビーコンフレームの無効化

    学習目標 3.2.B: ワイヤレスネットワークセキュリティ機能を設定する。

    • 3.2.B.1 組織は、ワイヤレスアクセスポイント(WAP)でのビーコンフレームのブロードキャストを無効化して、攻撃者がワイヤレスネットワークを見つけやすくせず、その基本的な属性を学ぶのを難しくすることができます。
    • 3.2.B.2 組織は、WAPのブロードキャスト方向と信号強度を制御して、信号がアクセスポイントが本来カバーすべき物理的な空間を超えて広がらないようにできます。
    • 3.2.B.3 組織は、強固なワイヤレス暗号化プロトコルを有効化して、ワイヤレスフレームが傍受される可能性がある攻撃者によって読み解かれないようにする必要があります。
      • WEP、WPS、および最初のWPAワイヤレス暗号化プロトコルには既知の脆弱性があり、安全ではありません。
      • WPA3は現在、最も強力なワイヤレス暗号アルゴリズムです。
    • 3.2.B.4 組織は、MACフィルタリングを有効化して、未授权デバイスがネットワークにアクセスできないようにし、ネットワークに接続する際にユーザーの認証を求めることができます。

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English

    Good network security starts with written policies that set a minimum standard: a router security policy and switch security policy ban local accounts and require port security; a VPN policy sets authentication rules and forbids split tunneling 分离隧道; and a wireless security policy requires strong encryption and authenticated access.

    For wireless networks specifically, organisations disable beacon frames so the network is harder to find, control signal strength so it does not leak outside the building, enable strong encryption - WPA3 Wi-Fi 保护接入第三代 is the current strongest, while old WEP and the original WPA are broken - and use MAC filtering to allow only known devices.

    日本語

    適切なネットワークセキュリティは、最低基準を定めた文書化されたポリシーから始まります。ルーターセキュリティポリシーおよびスイッチセキュリティポリシーはローカルアカウントの使用を禁止し、ポートセキュリティの実施を義務付けます。VPNポリシーは認証ルールを設定し、スプリット_tunneling(分割トネリング)を禁止します。また、ワイヤレスセキュリティポリシーでは強力な暗号化と認証済みアクセスの実施を要件としています。

    ワイヤレスネットワークに関しては、組織はネットワークが検出されにくくなるようビーコンフレームを無効にし、建物の外へ信号が漏れないように信号強度を制御し、強力な暗号化を有効化します(現在の最強化はWPA3 Wi-Fiであり、古いWEPや初期のWPAは破綻しています)。さらに、MACフィルタリングを使用して、事前に登録されたデバイスのみを許可します。

    Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
    English 日本語
    WPA3/ˌdʌbljuː piː eɪ ˈθriː/ WPA3
    Network segmentation/ˈnetwɜːk ˌseɡmənˈteɪʃn/ ネットワークセグメンテーション
    subnets/ˈsʌbnets/ サブネット
    screened subnet/skriːnd ˈsʌbnet/ スクリーンedサブネット
    3.3

    Protecting Networks: Segmentation · ⁨ネットワーク保護:セグメンテーション⁩

    Syllabus · ⁨シラバス⁩
    English

    Learning Objective 3.3.A: Identify techniques for segmenting a network.

    • 3.3.A.1 Firewall zones and rules can be used to create a screened subnet (also known as a demilitarized zone, or DMZ)—a network segment that sits between public, external networks like the internet and internal, private networks. A screened subnet is typically a lower security zone than the internal, private networks, and it typically holds an organization’s publicly facing resources, separating them from the internal network.
    • 3.3.A.2 Subnetting can be used to create different subnets based on IP addressing. If a device is compromised by an adversary, subnets can contain a security breach to reduce the number of exposed devices.
    • 3.3.A.3 Switches can be used to create VLANs, which logically separate devices physically connected to central switches.

    Learning Objective 3.3.B: Explain why network segmentation can increase network security.

    • 3.3.B.1 Network segmentation refers to the process of dividing a network into smaller, isolated segments or subnetworks (subnets).
    • 3.3.B.2 Dividing a network into smaller subnets isolates network traffic, which can prevent attacks on one subnet from impacting devices on other subnets.
    • 3.3.B.3 Network segmentation can allow for different security policies and controls to be applied to different segments of the network, allowing for higher security zones and lower security zones.
    • 3.3.B.4 Port security on a switch can prevent MAC flooding by limiting the number of addresses assignable to any single switch port.
    日本語

    学習目標 3.3.A: ネットワークをセグメント化する手法を特定する。

    • 3.3.A.1 フォアウォール・ゾーンおよびルールを使用して、スクリーンド・サブネット(ディミリタライズド・ゾーン、DMZとも呼ばれる)を作成できます。これは、インターネットなどの公開外部ネットワークと、内部のプライベートネットワークとの間に位置するネットワークセグメントです。スクリーンド・サブネットは通常、内部のプライベートネットワークよりもセキュリティレベルが低く、組織の公网資源を保持し、それらを内部ネットワークから分離します。
    • 3.3.A.2 サブネット分割は、IPアドレスに基づいて異なるサブネットを作成するために使用できます。あるデバイスが攻撃者に侵害された場合、サブネットはセキュリティ違反を限定することで、露出するデバイスの数を減らすことができます。
    • 3.3.A.3 スイッチを使用してVLANを作成することができ、これにより中央スイッチに物理的に接続されているデバイスを論理的に分離できます。

    学習目標 3.3.B: ネットワーク分割がネットワークセキュリティを向上させる理由を説明すること。

    • 3.3.B.1 ネットワーク分割とは、ネットワークをより小さく、隔離されたセグメントやサブネットワーク(サブネット)に分割するプロセスを指します。
    • 3.3.B.2 ネットワークを小さなサブネットに分割すると、ネットワークトラフィックが隔离され、あるサブネットに対する攻撃が他のサブネット上のデバイスに影響を与えるのを防ぐことができます。
    • 3.3.B.3 ネットワーク分割により、ネットワークの異なるセグメントに対して異なるセキュリティポリシーや制御を適用することが可能になり、高いセキュリティゾーンと低いセキュリティゾーンを設定できます。
    • 3.3.B.4 スイッチのポートセキュリティは、単一のスイッチ・ポートに割り当て可能なMACアドレスの数を制限することで、MACフラッディングを防ぐことができます。

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English

    Network segmentation 网络分段 divides one network into smaller, isolated pieces (subnets 子网). If one subnet is breached, the damage is contained and cannot spread.

    A key pattern is the screened subnet 屏蔽子网 (also called a DMZ 隔离区). It sits between the public internet and the private internal network, holding an organisation's public-facing servers in a lower-security zone - separated from the sensitive internal systems.

    Segments can also be built with subnetting (by IP address) or VLANs 虚拟局域网 (logically separating devices on the same switch). Each segment can then get its own security policy - higher-security and lower-security zones.

    日本語

    ネットワークセグメンテーションは、単一のネットワークをより小さく隔離された部分(サブネット)に分割します。1つのサブネットが侵害されても、被害は限定され、拡大することはありません。

    重要な設計パターンとしてスクリーンドサブネット(DMZとも呼ばれる)があります。これは、公的インターネットと private な内部ネットワークの間に位置し、組織のパブリックFacingサーバーを安全性の低いゾーンに保持します。これにより、敏感な内部システムとは分離されます。

    スクリーンドサブネット(DMZ)は、パブリックサーバーを2つのファイアウォールの間に配置し、プライベートネットワークから遠ざけます
    スクリーンドサブネット(DMZ)は、パブリックサーバーを2つのファイアウォールの間に配置し、プライベートネットワークから遠ざけます

    セグメントは、IPアドレスによるサブネットティングや、同じスイッチ上のデバイスを論理的に分離するVLANsによって構築することもできます。各セグメントには独自のセキュリティポリシー(高セキュリティゾーンと低セキュリティゾーン)を適用することが可能です。

    サーバーラック: ネットワークセグメンテーションによりシステムが隔離され、1つの侵害で全てが暴露されるのを防ぎます
    サーバーラック: ネットワークセグメンテーションによりシステムが隔離され、1つの侵害で全てが暴露されるのを防ぎます
    Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
    English 日本語
    DMZ/ˌdiː em ˈzed/ DMZ
    VLANs/ˈviːlænz/ VLANs
    3.4

    Protecting Networks: Firewalls · ⁨ネットワーク保護:ファイアウォール⁩

    Syllabus · ⁨シラバス⁩
    Learning ObjectiveEssential Knowledge

    3.4.A
    Identify types of network-based firewalls.

    • 3.4.A.1 A firewall is used to allow or deny network traffic in or out of a network. The firewall itself is software that can be hosted on a standalone device or integrated into another network device, such as a router.
    • 3.4.A.2 A stateless firewall filters traffic based on information in packet headers, such as IP addresses, ports, and protocols.
    • 3.4.A.3 A stateful firewall (also known as dynamic packet filtering) tracks the state of network connections passing through the firewall and can filter according to connection-related rules in addition to the filtering done by a stateless firewall. This allows for more control over content allowed in and out of a network.
    • 3.4.A.4 A next-generation firewall (NGFW) has both the capabilities of typical stateless and stateful firewalls and additional advanced features, such as intrusion prevention, deep packet inspection, and filtering by application type.

    3.4.B
    Explain how a firewall uses an access control list to allow or deny traffic entering or leaving a network.

    • 3.4.B.1 Network administrators create a set of rules, called an access control list (ACL), that a firewall uses to permit or deny inbound and outbound network traffic.
    • 3.4.B.2 ACL rules are checked in order and the first rule that matches the criteria will be executed for the specified data.
    • 3.4.B.3 A typical ACL will specify the direction of traffic (inbound or outbound), the criterion to filter by (IP addresses, logical port, service, or application), and the action to take (permit or deny).

    3.4.C
    Determine the effective placement of firewalls in a network.

    • 3.4.C.1 Each segment of a network should have a firewall to control the flow of data in and out of that segment.
    • 3.4.C.2 Network segments may have different security needs based on the data and services within them. The level of security for each firewall can be set independently.
    • 3.4.C.3 Each point of data ingress and egress between the internal network and the public internet should have a firewall.

    3.4.D
    Configure a firewall to manage the flow of network traffic.

    • 3.4.D.1 The requirements for a firewall will specify what type of traffic from which sources or to which destinations should be allowed or denied.
    • 3.4.D.2 Specific rules for a firewall can allow or deny inbound or outbound traffic based on source or destination port or IP address, service, protocol, or application.
      • Illustrative examples for 3.4.D.2:
        • Allow inbound TCP port 22 from ALL; (this rule will allow all inbound TCP traffic with destination port 22, which is the designated port for the SSH protocol)
        • Deny inbound TCP port 80 from 192.168.1.0/24; (this rule will deny inbound TCP traffic with destination port 80 from IP addresses in the 192.168.1.0-192.168.1.255 range)
    • 3.4.D.3 Rules are implemented in order, and changing the order of a set of rules can change which traffic is allowed or denied. Consideration must be given to the precedence of filtering priorities when establishing the order of rules.
      • Illustrative examples for 3.4.D.3:
        • This set of rules would allow SSH traffic and deny other inbound TCP traffic
        • Rule 1: ALLOW inbound TCP port 22 from ALL;
        • Rule 2: DENY inbound TCP ALL from ALL;
        • Reversing the order of those rules would deny all inbound TCP traffic including SSH traffic.

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English
    How a firewall decides

    A firewall 防火墙 allows or denies traffic entering or leaving a network. There are several kinds:

    • Stateless 无状态 - filters on packet headers alone (IP, port, protocol).
    • Stateful 有状态 - also tracks the state of each connection for finer control.
    • Next-generation (NGFW) - adds advanced features like intrusion prevention and deep packet inspection.

    A firewall follows an access control list (ACL) 访问控制列表 - an ordered set of rules. Rules are checked in order, and the first match wins, so the order of rules changes which traffic gets through. Each rule specifies a direction, a thing to filter by (IP, port, service), and an action (permit or deny).

    Worked example. A firewall has Rule 3: DENY TCP 443 from 192.168.*, and lower down Rule 7: ALLOW TCP 443 from ALL. A user at 192.168.45.37 cannot reach port 443 - even though Rule 7 would allow them - because Rule 3 matches first, and the first match wins. The fix is to move the ALLOW rule above the DENY. This is why rule order, not just rule content, decides what traffic gets through.

    Firewalls belong at every point where data crosses between zones - at each network segment and at every gateway to the public internet.

    日本語
    How a firewall decides

    ファイアウォールは、ネットワークへの入出力トラフィックを許可または拒否します。主な種類は以下の通りです:

    • ステートレス - パケットヘッダーのみ(IP、ポート、プロトコル)に基づいてフィルタリングを行います。
    • ステートフル - 各接続の状態も追跡し、より細かい制御が可能です。
    • 次世代(NGFW) - 侵入防止機能やディープパケットインスペクションなどの高度な機能を追加します。

    ファイアウォールはアクセスコントロールリスト(ACL)に従って動作します。これは順序付けられたルールのセットであり、ルールは順にチェックされ、最初の一致したルールが優先されます。したがって、ルールの順序が変更されると、通過するトラフィックも変化します。各ルールは方向、フィルタリング対象(IP、ポート、サービス)、アクション(許可または拒否)を指定します。

    ファイアウォールはACLを最上段から順に確認し、最初に一致したルールが決定します
    ファイアウォールはACLを最上段から順に確認し、最初に一致したルールが決定します

    計算例。 ファイアウォールにルール 3: DENY TCP 443 from 192.168.* と、その下にあるルール 7: ALLOW TCP 443 from ALL があります。ユーザー 192.168.45.37 はポート 443 にアクセスできません。ルール 7 が許可しているにもかかわらずです。これは、ルール 3 が先に一致するためであり、最初の一致が勝つからです。修正方法は、ALLOWルールをDENYルールの上に移動することです。これが、通過するトラフィックを決定するのはルールの内容だけでなく、ルールの順序である理由です。

    データがゾーン間を交差するすべてのポイントにファイアウォールを設置します。各ネットワークセグメントおよび公的インターネットへのゲートウェイに配置します。

    Rack-mounted network switches with many ethernet cables
    実際のネットワークハードウェア: ファイアウォールとは、これらのケーブルが外部世界と接続する場所に設置されたデバイス(またはソフトウェア)です
    Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
    English 日本語
    ARP poisoning/ɑːp ˈpɔɪzənɪŋ/ ARPポイズニング
    address resolution protocol (ARP)/əˈdres ˌrezəˈluːʃn ˈprəʊtəkɒl/ アドレス解決プロトコル (ARP)
    MAC addresses/mæk əˈdresɪz/ MACアドレス
    on-path attack/ɒn pæθ əˈtæk/ on-path attack(中継攻撃)
    MAC flooding/mæk ˈflʌdɪŋ/ MACフロッディング
    switch/swɪtʃ/ スイッチ
    firewall/ˈfaɪəwɔːl/ ファイアウォール
    Stateless/ˈsteɪtləs/ ステートレス
    Stateful/ˈsteɪtfl/ ステートフル
    access control list (ACL)/ˈækses kənˈtrəʊl lɪst/ アクセスコントロールリスト (ACL)
    log files/lɒɡ faɪlz/ ログファイル
    network intrusion detection system (NIDS)/ˈnetwɜːk ɪnˈtruːʒn dɪˈtekʃn ˈsɪstəm/ ネットワーク侵入検知システム (NIDS)
    network intrusion prevention system (NIPS)/ˈnetwɜːk ɪnˈtruːʒn prɪˈvenʃn ˈsɪstəm/ ネットワーク侵入防止システム (NIPS)
    security information and event management (SIEM)/sɪˈkjʊərɪti ˌɪnfəˈmeɪʃn ænd ɪˈvent ˈmænɪdʒmənt/ セキュリティ情報およびイベント管理 (SIEM)
    Signature-based/ˈsɪɡnɪtʃə beɪst/ シグネチャベース
    Anomaly-based/əˈnɒməli beɪst/ アナモリー(異常値)ベース
    baseline/ˈbeɪslaɪn/ ベースライン
    network-based indicators of compromise/ˈnetwɜːk beɪst ˈɪndɪkeɪtəz ɒv ˈkɒmprəmaɪz/ ネットワークベースの侵害指標
    probabilistic/ˌprɒbəbɪˈlɪstɪk/ 確率的
    threshold/ˈθreʃəʊld/ 閾値(しちじ)
    alert fatigue/əˈlɜːt fəˈtiːɡ/ アラート疲労
    3.5

    Detecting Network Attacks · ⁨ネットワーク攻撃の検知⁩

    Syllabus · ⁨シラバス⁩
    English

    Learning Objective 3.5.A: Identify types of automated security tools used to detect network attacks.

    • 3.5.A.1 Automated detection tools analyze data collected from an organization’s network and devices, such as switches and routers, servers, firewalls, and user computers. These data are often collected in a log file.
    • 3.5.A.2 A network intrusion detection system (NIDS) is an automated tool that analyzes data to determine if malicious activity is taking place on a network. When an attack is detected, it generates an alert.
    • 3.5.A.3 A network intrusion prevention system (NIPS) is an automated tool that, like an IDS, analyzes data to determine if malicious activity is taking place on a network. A NIPS can also mitigate or halt an attack by closing ports, blocking specific IP or MAC addresses, or rejecting specific protocols.
    • 3.5.A.4 A security information and event management (SIEM) system collects and analyzes data from multiple sources (including firewalls, NIDS/NIPS, device logs, and application logs) to detect patterns that may indicate a cyberattack and raises an alert if a potential attack is detected. Security analysts investigate the alert to determine whether it represents a true threat and follow standard operating procedures to resolve or escalate the alert.

    Learning Objective 3.5.B: Explain how organizations can leverage artificial intelligence (AI) to enhance threat detection and response.

    • 3.5.B.1 Computers log every action that users take. Firewalls, IDS, IPS, and other network sensors log all the traffic passing through various points in a network. A medium-sized organization’s network is logging millions (or even tens of millions) of data points per day. Even a large team of humans is incapable of analyzing so much data.
    • 3.5.B.2 Threat detection teams are creating AI algorithms to analyze large amounts of data and classify the data patterns as malicious or normal.
    • 3.5.B.3 AI models for threat detection are based on probabilistic calculations; they report a percentage to indicate the likelihood that something is malicious.
    • 3.5.B.4 Organizations determine their own thresholds for what percentage of likelihood of a threat results in an alert. If the threshold is set too high, real attacks may go undetected; if the threshold is too low, the security team will be overwhelmed with false alerts.

    Learning Objective 3.5.C: Determine a network detection method.

    • 3.5.C.1 Volume of network traffic is a criterion for determining a detection method. Signature-based detection is more efficient for networks with high traffic volume. Signature-based detection compares detection data to a database of known indicators of compromise (IoCs), called signatures. Signature databases must be updated with IoCs for the latest attacks. Signature-based detection runs more quickly than anomaly-based detection.
    • 3.5.C.2 Consistency of network traffic patterns is a criterion for determining a detection method. Anomaly-based detection is most effective on networks with consistent traffic patterns. Anomaly-based detection compares detection data to a baseline of recorded activity. Baselines must be recorded on uncompromised systems to establish expected data types and volumes. Anomaly-based detection triggers an alert or action when data types or volumes outside of a specified tolerance range are recorded. Anomaly-based detection relies on consistent patterns in network traffic to detect anomalous traffic patterns.
    • 3.5.C.3 Degree of sensitivity or criticality of a network is a criterion for determining a detection method. Networks with more sensitive or critical data or services will likely consider a hybrid approach. Hybrid detection combines signature-based and anomaly-based detection. Hybrid detection is more expensive than using either signature- or anomaly-based detection alone, and hybrid-detection models generate more alerts.
    • 3.5.C.4 Likelihood of novel attacks on a network is a criterion for determining a detection method. Signature-based detection cannot detect a new attack. When an organization suspects that adversaries are likely to attempt a new attack on a network, anomaly-based detection is the preferred method when the cost of hybrid detection is prohibitively high.

    Learning Objective 3.5.D: Evaluate the impact of a network detection method.

    • 3.5.D.1 Speed of detection is a factor in evaluating the impact of a network detection method. Faster detection enables faster response. Signature-based detection methods are faster than anomaly-based detection methods, especially on networks with high traffic volume.
    • 3.5.D.2 Cost is a factor in evaluating the impact of a network detection method. Detection tools and ongoing costs need to be within a budget. Anomaly-based detection systems require more expensive hardware to operate than signature based. Hybrid detection is the most expensive option because it combines both anomaly- and signature-based methods.
    • 3.5.D.3 False positive rate is a factor in evaluating the impact of a network detection method. Signature-based detection has almost no false positives. Anomaly-based or hybrid detection will have higher false positive rates. Impacts of high false positive rates include:
      • Time and resources are put toward investigating alerts for nonmalicious activity.
      • Alert fatigue is a condition that occurs when responders get accustomed to false positives and take alerts less seriously because they assume alerts are false positives before investigating them.
    • 3.5.D.4 False negative rate is a factor in evaluating the impact of a network detection method. A false negative occurs when an adversary can bypass a detection system. Signature-based detection systems are easier to bypass than anomaly-based or hybrid systems. False negatives can result in adversaries causing loss, harm, disruption, or destruction to data and systems.

    Learning Objective 3.5.E: Apply detection techniques to identify indicators of network attacks by analyzing log files.

    • 3.5.E.1 Evil-twin attacks can be detected by regularly scanning for service set identifiers (SSIDs) that look suspicious or similar to local legitimate SSIDs. Signal triangulation can be used to locate and disable an access point broadcasting an evil-twin network.
    • 3.5.E.2 Jamming attacks can be detected by recognizing that no wireless devices in a specific physical space are able to connect to a wireless network and by scanning for electromagnetic (EM) noise in the wireless range.
    • 3.5.E.3 ARP poisoning attacks can be detected by monitoring network traffic for unusual ARP messages (particularly duplicate MAC address ARP packets) and checking the ARP table on the default gateway.
    • 3.5.E.4 MAC flooding attacks can be detected by monitoring network traffic for an unexpected surge of Ethernet frames with different MAC addresses and checking the MAC address table on a switch.
    • 3.5.E.5 DNS poisoning attacks are difficult to detect. However, if an organization’s website experiences an abrupt and otherwise inexplicable drop in traffic, DNS records should be examined as a potential cause.
    • 3.5.E.6 Smurf attacks can be detected by watching network traffic for a sudden increase in ICMP requests sent to the network’s broadcast address.
    • 3.5.E.7 Network-based IoCs are discovered when analyzing network traffic, often in the form of packet capture files. Indicators can be found in source and destination IP addresses, ports, and protocols. These can include:
      • Connections to known malicious IP addresses
      • Unauthorized network scans
      • Unusual spikes or slow downs in network traffic
      • Mismatched port-application traffic
    日本語

    学習目標 3.5.A: ネットワーク攻撃を検知するために使用される自動化されたセキュリティツールの種類を特定すること。

    • 3.5.A.1 自動化された検知ツールは、組織のネットワークおよびデバイス(スイッチ、ルーター、サーバー、フォアウォール、ユーザーのコンピューターなど)から収集されたデータを分析します。これらのデータは通常、ログファイルとして収集されます。
    • 3.5.A.2 ネットワーク侵入検知システム(NIDS)は、ネットワーク上で悪意のある活動が発生しているかどうかを判定するためにデータを分析する自動化されたツールです。攻撃が検知されると、アラートを生成します。
    • 3.5.A.3 ネットワーク侵入防止システム(NIPS)は、IDSと同様にデータを分析してネットワーク上で悪意のある活動が行われているかどうかを判定する自動化されたツールである。NIPSは、ポートの閉鎖、特定のIPまたはMACアドレスのブロック、特定のプロトコルの拒否などにより、攻撃を軽減または停止することもできる。
    • 3.5.A.4 セキュリティ情報およびイベント管理(SIEM)システムは、ファイアウォール、NIDS/NIPS、デバイスログ、アプリケーションログなど複数のソースからのデータを収集・分析し、サイバー攻撃を示唆するパターンを検出し、潜在的な攻撃が検出されれば警告を発する。セキュリティアナリストは警告を調査し、それが真の脅威に該当するかを決定し、標準的な運用手順に従って警告を解決またはエスカレートさせる。

    学習目標 3.5.B: 組織が人工知能(AI)を活用して脅威の検知と対応をどのように強化するか説明する。

    • 3.5.B.1 コンピュータはユーザーが行うすべてのアクションをログに記録する。ファイアウォール、IDS、IPS、その他のネットワークセンサーは、ネットワーク内の様々なポイントを通じて通過するすべてのトラフィックをログに記録する。中規模組織のネットワークでは、毎日数百万、あるいは数千万ものデータポイントがログに蓄積されている。人間によるチームであっても、この膨大なデータを分析することは不可能である。
    • 3.5.B.2 脅威検知チームは、大量のデータを解析し、データのパターンが悪意のあるものか正常なものを分類するためのAIアルゴリズムを作成している。
    • 3.5.B.3 脅威検知のためのAIモデルは確率的計算に基づいており、何かが悪意のあるものである可能性を示すためにパーセンテージを報告する。
    • 3.5.B.4 組織は、どの程度の可能性で警告が発令されるべきかを独自の閾値として決定する。閾値が高すぎると、実際の攻撃が検知されない可能性がある。一方、閾値が低すぎると、セキュリティチームは誤警告に圧倒されてしまう。

    学習目標 3.5.C: ネットワーク検知方法を特定する。

    • 3.5.C.1 ネットワークトラフィックの量は、検知方法を選択する基準となる。高トラフィック量のネットワークでは、シグネチャベースの検知の方が効率的である。シグネチャベースの検知は、検知データを既知の侵害指標(IoCs)のデータベースである「シグネチャ」と比較する。シグネチャデータベースには、最新の攻撃に対応したIoCsで更新が必要である。シグネチャベースの検知は、異常検知ベースの検知よりも高速に動作する。
    • 3.5.C.2 ネットワークトラフィックパターンの一貫性は、検知方法を選択する基準となる。一貫性のあるトラフィックパターンを持つネットワークでは、異常検知ベースの検知が最も効果的である。異常検知ベースの検知は、記録された活動のベースラインと比較する。ベースラインは、期待される数据类型と量を設定するために、侵害されていないシステム上で記録される必要がある。指定された許容範囲外の数据类型や量が記録されると、異常検知ベースの検知は警告または行動をトリガーする。異常検知ベースの検知は、ネットワークトラフィックの一貫したパターンを利用して、異常なトラフィックパターンを検知する。
    • 3.5.C.3 ネットワークの敏感さや重要度の程度は、検知方法を選択する基準となる。より敏感または重要なデータやサービスを持つネットワークでは、ハイブリッドアプローチを検討することが多い。ハイブリッド検知は、シグネチャベースと異常検知ベースの両方を組み合わせる。ハイブリッド検知は、どちらか片方の手法 alone を使用する場合よりもコストが高く、また、より多くの警告を生成する。
    • 3.5.C.4 ネットワークにおける新規攻撃の可能性は、検知方法を選択する基準となる。シグネチャベースの検知では、新しい攻撃を検知できない。組織が敵対者がネットワークに対して新たな攻撃を試みる可能性が高いと懸念している場合、ハイブリッド検知のコストが高額すぎる場合は、異常検知ベースの検知が好まれる方法となる。

    学習目標 3.5.D: ネットワーク検知方法の影響を評価する。

    • 3.5.D.1 検知速度は、ネットワーク検知方法の影響を評価する要因である。検知速度が速ければ、対応も迅速に行える。シグネチャベースの検知手法は、異常検知ベースの検知手法よりも速い。特に高トラフィック量のネットワークではその差が顕著である。
    • 3.5.D.2 コストは、ネットワーク検知方法の影響を評価する要因である。検知ツールおよび継続的なコストは予算内に収まる必要がある。異常検知ベースのシステムは、シグネチャベースのものよりも高いハードウェアを必要とする。ハイブリッド検知は、異常検知とシグネチャの両方の手法を組み合わせるため、最も高額な選択肢である。
    • 3.5.D.3 偽陽性率(FP rate)は、ネットワーク検知方法の影響を評価する要因である。シグネチャベースの検知にはほぼ偽陽性がない。異常検知ベースまたはハイブリッド検知は、より高い偽陽性率を示す。高い偽陽性率の影響には以下が含まれる:
      • 非悪意の活動に関する警告の調査に時間とリソースが割かれる。
      • アラート疲労とは、対応者が偽陽性に慣れ、警告を真面目に受け付けなくなる状態のことである。これは、調査前に警告が偽陽性であると仮定してしまうためである。
    • 3.5.D.4 偽陰性率(FN rate)は、ネットワーク検知方法の影響を評価する要因である。敵対者が検知システムを回避できた場合に偽陰性が発生する。シグネチャベースの検知システムは、異常検知ベースやハイブリッドシステムよりも容易に回避される。偽陰性は、敵対者によるデータやシステムへの損失、損害、妨害、破壊をもたらす可能性がある。

    学習目標 3.5.E: ログファイルを解析することで、ネットワーク攻撃の兆候(IOCs)を特定するために検知技術を適用する。

    • 3.5.E.1 イビル・ツイン攻撃は、局所内の正規のSSIDと似ているか不審なサービスセットID(SSID)を定期的にスキャンすることで検出できます。信号三角測量を用いて、イビル・ツインネットワークをブロードキャストするアクセスポイントの位置を特定し無効化することが可能です。
    • 3.5.E.2 ジャミング攻撃は、特定の物理空間内の無線デバイスが無線ネットワークに接続できないことを認識し、無線範囲内の電磁(EM)ノイズをスキャンすることで検出できます。
    • 3.5.E.3 ARPポイゾニング攻撃は、ネットワークトラフィックを監視して異常なARPメッセージ(特に重複したMACアドレスを持つARPパケット)を検出し、デフォルトゲートウェイのARPテーブルを確認することで検出できます。
    • 3.5.E.4 MACフラッディング攻撃は、ネットワークトラフィックを監視して異なるMACアドレスを持つEthernetフレームの予期せぬ急増を検出し、スイッチ上のMACアドレステーブルを確認することで検出できます。
    • 3.5.E.5 DNSポイゾニング攻撃は検出するのが困難です。しかし、組織のウェブサイトが急激かつ説明のつかないトラフィック減少を経験した場合、DNSレコードを潜在的な原因として確認すべきです。
    • 3.5.E.6 スマーフ攻撃は、ネットワークトラフィックを監視して、ネットワークの广播アドレス宛てに送られたICMPリクエストの急増を観察することで検出できます。
    • 3.5.E.7 ネットワークベースのIoCは、ネットワークトラフィックを分析する際に発見されます。一般的にはパケットキャプチャファイルの形式をとります。インジケーターは、送信元および宛先IPアドレス、ポート、プロトコルに含まれます。これらには以下が含まれます:
      • 既知の悪意のあるIPアドレスへの接続
      • 承認されていないネットワークスキャン
      • ネットワークトラフィックにおける異常なピークや減速
      • ポートとアプリケーションのトラフィックの不一致

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English

    When prevention fails, detection takes over. Automated tools read the log files 日志文件 that record network activity:

    • a network intrusion detection system (NIDS) 网络入侵检测系统 analyses traffic and raises an alert, but does not block;
    • a network intrusion prevention system (NIPS) 网络入侵防御系统 can also stop an attack by closing ports or blocking addresses;
    • a security information and event management (SIEM) 安全信息与事件管理 system gathers data from many sources to spot patterns.

    There are two detection methods. Signature-based 基于特征 detection compares traffic to a database of known attack signatures - fast and low on false alarms, but blind to brand-new attacks. Anomaly-based 基于异常 detection compares traffic to a normal baseline 基线 and flags anything unusual - it can catch novel attacks but needs more resources and raises more false alarms. A hybrid approach combines both.

    Examining captured traffic (packet-capture files), analysts hunt for network-based indicators of compromise 网络入侵指标 in the source and destination IP addresses, ports, and protocols. Four common ones: connections to known-malicious IP addresses, unauthorized network scans (an outsider probing your ports), unusual spikes or slowdowns in traffic, and mismatched port-application traffic (for example, non-web traffic flowing over port 80). These complete the host-, file-, and behaviour-based indicators a single device logs.

    AI, thresholds, and alert fatigue

    A medium network logs millions of events a day - far more than any team can read - so organisations train AI models to sort likely-malicious patterns from normal ones. These models are probabilistic 概率的: rather than a yes/no, each event gets a percentage likelihood of being malicious.

    The organisation then sets a threshold 阈值 - the likelihood at which an alert fires - and that choice is a genuine trade-off:

    • set the threshold too high and real attacks slip through undetected;
    • set it too low and the team is overwhelmed with false alerts.

    Too many false alerts cause alert fatigue 警报疲劳: responders get so used to false positives that they start assuming an alert is false before investigating it - so a real attack, when it finally comes, is waved away. This is exactly why a low false-positive rate matters: signature-based detection has almost none, while anomaly-based and hybrid detection trade a higher false-positive rate for the ability to catch novel attacks.

    日本語

    予防策が機能しない場合、検知が主導権を握ります。自動化されたツールは、ネットワーク活動记录するログファイルを読み取ります:

    • ネットワーク侵入検知システム(NIDS)はトラフィックを分析してアラートを発生させますが、ブロックはしません;
    • ネットワーク侵入防止システム(NIPS)は、ポートを閉じるかアドレスをブロックすることで攻撃を停止できる場合があります;
    • **セキュリティ情報およびイベント管理(SIEM)**システムは、多数のソースからデータを収集してパターンを検出します。

    検知には2つの方法があります。シグネチャベースの検知は、トラフィックを既知の攻撃シグネチャのデータベースと比較します。高速で誤警報が少ないですが、全く新しい攻撃には対応できません。アナモロジーベースの検知は、トラフィックを通常ベースラインと比較し、異常なものをフラグ付けします。新たな攻撃を捕捉できますが、リソースが必要で、誤警報が多発します。ハイブリッドアプローチは両方を組み合わせたものです。

    捕獲されたトラフィック(パケットキャプチャファイル)を検討する際、分析者は、送信元および宛先IPアドレス、ポート、プロトコルにおけるネットワーク由来の侵害指標を探します。一般的なものとして4つ挙げられます:既知の悪意あるIPアドレスへの接続、未承認のネットワークスキャン(外部からのポート探査)、トラフィックの異常なスパイクや遅延、およびポート-アプリケーション不整合トラフィック(例:非Webトラフィックがポート80を流れる)。これらは、単一デバイスが記録するホスト、ファイル、行動由来の指標を補完します。

    AI、閾値、およびアラート疲労

    中規模のネットワークは一日あたり数百万のイベントを記録しますが、チームで全てを確認することは不可能であるため、組織はAIモデルを訓練して、可能性のある悪意あるパターンを正常なものから選別します。これらのモデルは確率的であり、Yes/Noではなく、各イベントが悪意あるものである確率をパーセンテージで示します

    その後、組織は**閾値(しちち)**を設定します。これは警報が発生する確率の基準であり、この選択には真のトレードオフが含まれます:

    • 閾値を高すぎると、実際の攻撃が検知されずに通過してしまいます;
    • 閾値を低すぎると、チームは過剰な誤警報に圧倒されてしまいます。

    誤警報が多すぎると**警報疲労(アラート・フィガティ)**が生じます。対応担当者は誤警報に慣れ親しみ、調査开始前に「警報は誤りだ」と仮定し始めます。そのため、実際に攻撃が発生した際にも、それは無視されてしまいます。このため、低誤警報率が重要である理由です:シグネチャベース检测はほぼ誤警報がありませんが、異常検知やハイブリッド检测は、新しい攻撃を検出できる能力と引き換えに、より高い誤警報率を受け入れています。

    シグネチャベース检测は既知の攻撃に一致し、異常検知は通常からの逸脱を警告します
    シグネチャベース检测は既知の攻撃に一致し、異常検知は通常からの逸脱を警告します
    3.5

    Exam tips · ⁨試験対策⁩

    English
    • For firewall-ACL questions, read the rules top-to-bottom and stop at the first match - a Deny rule above an Allow blocks the traffic even though the Allow exists lower down.
    • Pair each attack with its tell-tale sign: ARP poisoning = one IP with two MAC addresses; MAC flooding = a surge of new MAC addresses; DNS poisoning = an unexplained drop in web traffic.
    • Read packet captures for network-based IoCs: known-malicious IPs, unauthorized scans, traffic spikes/slowdowns, and mismatched port-application traffic.
    • Run vulnerability scanners to find known weaknesses proactively, and fix the highest-severity findings first.
    • Signature-based = fast, few false positives, misses new attacks (more false negatives); anomaly-based = catches new attacks, costs more, more false positives. Memorise this trade-off.
    • A screened subnet / DMZ holds public-facing servers between the internet and the private network - name it whenever a question separates public services from internal data.
    • WPA3 is the strong wireless encryption; WEP and original WPA are insecure.
    日本語
    • ファイアウォールACLに関する問題では、ルールを上から順に読み、最初に一致したところで停止してください。Allowルールの上方にあるDenyルールが存在する場合、下方にAllowルールがあってもトラフィックはブロックされます。
    • 各攻撃にその特徴的な兆候をペアにします:ARPポイズニング = 1つのIPに2つのMACアドレス;MACフラッディング = 新規MACアドレスの急増;DNSポイズニング = 説明のないWebトラフィックの減少。
    • ネットワークベースのIoCについてはパケットキャプチャを確認します:既知の悪意のあるIP、未許可のスキャン、トラフィックのスパイク/減速、ポートとアプリケーションの不一致。
    • 脆弱性スキャナを実行して、既知の欠陥を能動的に見つけ出し、最も深刻度の高い所見を最初に修正してください。
    • シグネチャベース = 高速、誤警報が少ないが、新しい攻撃を見逃す(誤検知率が高い);異常検知 = 新しい攻撃を検出するが、コストが高く、誤警報が多い。このトレードオフを暗記すること。
    • スクリーンドサブネット / DMZ は、インターネットとプライベートネットワークの間に公開サーバーを保持します。質問で公開サービスと内部データが区別されている場合は、必ずこの用語を使用してください。
    • WPA3 は強力なワイヤレス暗号化です。WEP と初期の WPA は不安全です。
  • 4

    Securing Devices · ⁨デバイスの保護⁩

    Watch lesson · ⁨レッスンを視聴⁩
    4.1

    Device Vulnerabilities and Attacks

    Syllabus · ⁨シラバス⁩
    English

    Learning Objective 4.1.A: Identify types of computing devices.

    • 4.1.A.1 Server computers are devices that provide one or more services to other computers (e.g., DNS, DHCP, FTP). Any computer can be a server, and in an enterprise environment servers typically have more processing power and storage than a personal computer.
    • 4.1.A.2 Personal computers are devices that are designed to be used by one person for work or recreational purposes (e.g., word processing, graphic design, web browsing, and media production or viewing). These include desktop, laptop, and notebook computers.
    • 4.1.A.3 Handheld computers (also called mobile computers or information appliances) are smaller than personal computers and run on battery power. These include tablets, smartphones, and wearable technology like smart watches.
    • 4.1.A.4 Embedded computers are devices that are part of a machine. Embedded devices have specific instruction sets for interfacing with the specialized components of the machine they’re embedded in. Embedded computers tend to be slower and cheaper than other computers and have minimal storage.
    • 4.1.A.5 Everyday devices with embedded computers are often called Internet of Things (IoT) devices. Embedded computers are found in transportation (e.g., cars, trains, and airplanes), devices that operate critical infrastructure (e.g., operating circuit breakers at electrical substations and pumps at water treatment plants), medical equipment (e.g., IV pumps, MRI scanners, pacemakers, and insulin pumps), and everyday devices like washing machines, coffee makers, and thermostats.

    Learning Objective 4.1.B: Identify the type of malware used in a cyberattack.

    • 4.1.B.1 Malware is malicious software that can damage or destroy a device or network, or allow an adversary access to a device and the data on the device.
    • 4.1.B.2 Malware is often used as a tool to accomplish part of an adversary’s plan to achieve their ultimate goal(s). There are many types of malware, such as:
      • Viruses are malware that must be activated by a user executing or opening a file.
      • Worms spread from one computer to another without human interaction.
      • Trojans are malware embedded in other software that seems harmless. Remote access trojans (RATs) provide an adversary with remote access to the target system.
      • Ransomware encrypts a device’s files, preventing the user from accessing files on the device. The ransomware typically presents the user with a screen demanding payment and promising to give the user a decryption key for their files if the user pays within a fixed amount of time.
      • Spyware tracks a user’s actions on a computer and sends information back to an adversary.
      • A keylogger is software or hardware that logs the users keystrokes and sends the information back to the adversary. Adversaries can often extract usernames and passwords from keylogger data.
      • Logic bombs are set to trigger their effect only when a specific set of conditions are met; the conditions can include time and date, specific type or version of the operating system, character set the computer is using, etc.
      • A rootkit is sophisticated malware that gets into the target computer’s operating system and can control nearly every aspect of the system, including making the rootkit itself invisible to detection.
    • 4.1.B.3 While most malware is a file or a collection of files, fileless malware is malicious code that lives in RAM and uses legitimate programs already installed on a device to compromise it.

    Learning Objective 4.1.C: Explain how adversaries can exploit common device vulnerabilities to cause loss, damage, disruption, or destruction.

    • 4.1.C.1 Adversaries can develop exploits for known vulnerabilities in software (including operating systems). Devices with unpatched software are vulnerable to these exploits, which could allow an adversary to crash a system, view user actions, enable or disable various services or components on the device (e.g., turning on a webcam or microphone), or even take control of the device to issue their own commands including commands to steal or destroy information on the device.
    • 4.1.C.2 Adversaries can take advantage of weak authentication requirements by guessing a user’s password or using social engineering to get a user to divulge their password.
    • 4.1.C.3 When systems don’t have a password on the basic input output system (BIOS) or unified extensible firmware interface (UEFI), an adversary can boot a computer into a special mode (e.g., “recovery mode”) that gives them higher-level privileges. Without BIOS or UEFI protection, adversaries can load their own operating system onto a device from an external drive and use specialized tools to alter or create user profiles, including changing user passwords.
    • 4.1.C.4 Adversaries can load malware onto an external drive, and if autorun is enabled, then a device will run the malware when the external drive is inserted.
    • 4.1.C.5 Adversaries can leverage open ports to connect to a device.
    • 4.1.C.6 Adversaries can send malicious data to devices to disrupt them or attempt to take control of them. Devices that have no firewall (or a misconfigured firewall) cannot filter out this malicious data.
    • 4.1.C.7 Adversaries often attempt to install malware on a device to disrupt or control it. Devices lacking anti-malware software are more vulnerable to this type of attack.

    Learning Objective 4.1.D: Assess and document risks from device vulnerabilities.

    • 4.1.D.1 Risk from device vulnerabilities can come from unauthorized access or malware that allow an adversary to impersonate an authorized user, remotely control a device, encrypt a device’s drive to ransom the data, or wipe a device’s memory, destroying data or rendering the device inoperable. The level of risk varies depending on the criticality of the device or the services the device provides or data it stores.
    • 4.1.D.2 High risks from device vulnerabilities involve potentially compromising sensitive data or critical operations.
      • Illustrative examples for 4.1.D.2:
        • An organization has not installed the most recent update for their email server which included a patch for a known critical vulnerability.
    • 4.1.D.3 Moderate risks from device vulnerabilities can arise from weak authentication requirements or from vulnerabilities that would be less likely to be exploited.
      • Illustrative examples for 4.1.D.3:
        • A water treatment plant has embedded systems controlling pumps. The pumps can be remotely accessed via username and password for remote management for the plant, but the devices do not require multi-factor authentication (MFA).
    • 4.1.D.4 Low risks from device vulnerabilities are typically related to vulnerabilities that, if exploited, would have little impact.
      • Illustrative examples for 4.1.D.4:
        • An employee’s laptop has telnet port 23 open.
    日本語

    学習目標 4.1.A: コンピューティングデバイスの種類を特定する。

    • 4.1.A.1 サーバーコンピュータは、他のコンピュータに対して1つ以上のサービス(例:DNS、DHCP、FTP)を提供するデバイスです。すべてのコンピュータがサーバーになることができ、企業環境ではサーバーは通常、パーソナルコンピュータよりも高い処理能力とストレージを持ちます。
    • 4.1.A.2 パーソナルコンピュータは、一人の人が業務や娯楽目的で使用するよう設計されたデバイスです(例:ワード処理、グラフィックデザイン、ウェブブラウジング、メディア制作または視聴)。これにはデスクトップ、ラップトップ、ノートパソコンが含まれます。
    • 4.1.A.3 ハンドヘルドコンピュータ(モバイルコンピュータや情報家電とも呼ばれる)は、パーソナルコンピュータより小さく、バッテリーで動作します。これにはタブレット、スマートフォン、スマートウォッチのようなウェアラブルテクノロジーが含まれます。
    • 4.1.A.4 エンベッドドコンピュータは、機械の一部であるデバイスです。エンベッドドデバイスは、組み込まれている機械の専用コンポーネントとのインターフェース用に特定の命令セットを持っています。エンベッドドコンピュータは他のコンピュータより遅く、安価であり、ストレージ容量も最小限です。
    • 4.1.A.5 エンベッドドコンピュータを搭載した日常的なデバイスは、Often Internet of Things (IoT) デバイスと呼ばれます。エンベッドドコンピュータは、輸送機器(例:自動車、鉄道、航空機)、重要インフラを稼働させるデバイス(例:変電所の遮断器操作、浄水場のポンプ)、医療機器(例:点滴ポンプ、MRIスキャナー、ペースメーカー、インスリンポンプ)、そして洗濯機、コーヒーメーカー、サーモスタットなどの日常品に見られます。

    学習目標 4.1.B: サイバー攻撃で使用されるマルウェアの種類を特定する。

    • 4.1.B.1 マルウェアは、デバイスやネットワークを損傷または破壊したり、攻撃者にデバイスへのアクセスやデバイス上のデータへのアクセスを許容する悪意あるソフトウェアです。
    • 4.1.B.2 マルウェアは、攻撃者の最終的な目標達成のための計画の一部を遂行するためのツールとしてよく使用されます。マルウェアには多くの種類があります。例えば:
      • ユーザーがファイルを実行または開くことで起動されなければならないマルウェアであるウイルス。
      • 人間の介在なく、一台のコンピュータから別のコンピュータへ拡散するワーム。
      • 無害そうに見える他のソフトウェアに埋め込まれたマルウェアであるトロイの木馬。リモートアクセストロイ(RATs)は、攻撃者に対して標的システムへのリモートアクセスを提供します。
      • デバイスのファイルを暗号化し、ユーザーがデバイス上のファイルにアクセスできなくするランサムウェア。通常、ランサムウェアはユーザーに対し、画面を表示して支払いを要求し、一定期間内に支払えばファイルの復号鍵を提供すると約束します。
      • ユーザーのコンピュータ上での行動を追跡し、情報を攻撃者に送信するスパイウェア。
      • ユーザーのキー入力をログ記録し、情報を攻撃者に送信するソフトウェアまたはハードウェアであるキーロガー。攻撃者はキーロガーのデータからユーザー名やパスワードを抽出できることが多いです。
      • 特定の条件が満たされた場合にのみ効果を発動するよう設定されたロジックボム;条件には日付と時間、特定のOSタイプやバージョン、コンピュータが使用している文字集合などが含まれます。
      • ターゲットコンピュータのオペレーティングシステムに侵入し、システムのほぼあらゆる側面を制御できる高度なマルウェアであるルートキット。ルートキット自体を検知不可にすることも可能です。
    • 4.1.B.3 ほとんどのマルウェアはファイルまたはファイルの集まりですが、ファイルレスマルウェアはRAM上に存在し、デバイスに既にインストールされている正規のプログラムを利用してそれを侵害する悪意あるコードです。

    学習目標 4.1.C: 攻撃者が一般的なデバイスの脆弱性をどのように利用して、損失、損傷、妨害、または破壊を引き起こすかを説明する。

    • 4.1.C.1 攻撃者は、ソフトウェア(オペレーティングシステムを含む)の既知の脆弱性に対するエクスプロイトを開発できる。パッチ未適用のソフトウェアを搭載したデバイスはこれらのエクスプロイトに対して脆弱であり、システムをクラッシュさせたり、ユーザーの操作を監視したり、デバイス上のさまざまなサービスやコンポーネントを有効化または無効化したり(例:Webカメラやマイクのオン/オフ)、さらにはデバイスを掌握して自らの命令を発令し、デバイス上の情報を盗取または破壊する命令を含めることができる。
    • 4.1.C.2 攻撃者は、認証要件が緩弱な点を利用し、ユーザーのパスワードを推測したり、ソーシャルエンジニアリングによってユーザーにパスワードを洩れ出させたりすることができる。
    • 4.1.C.3 システムに基本入出力システム(BIOS)または統合拡張ファームウェアインターフェース(UEFI)にパスワードがない場合、攻撃者はより高い権限を与える特別なモード(例:「回復モード」)でコンピューターをブートさせることができる。BIOSやUEFIによる保護がない場合、攻撃者は外部ドライブから独自のオペレーティングシステムをデバイスに読み込み、専門的なツールを使用してユーザープロフィールを変更または作成することができ、ユーザーパスワードの変更も含まれる。
    • 4.1.C.4 攻撃者は外部ドライブにマルウェアを読み込むことができ、 autorun が有効化されている場合、外部ドライブを挿入するとデバイスがそのマルウェアを実行する。
    • 4.1.C.5 攻撃者は開放されたポートを利用してデバイスに接続することができる。
    • 4.1.C.6 攻撃者は悪意のあるデータを送信してデバイスを妨害したり、それらを掌握しようと試みることがある。ファイアウォールがない(または誤設定のファイアウォールを持つ)デバイスは、この悪意のあるデータをフィルタリングできない。
    • 4.1.C.7 攻撃者はoften、デバイスを妨害または制御するためにマルウェアのインストールを試みる。アンチマルウェアソフトウェアー缺失するデバイスは、この種のアタックに対してより脆弱である。

    学習目標 4.1.D: デバイスの脆弱性からのリスクを評価し、記録する。

    • 4.1.D.1 デバイスの脆弱性からのリスクは、不正アクセスやマルウェアにより、攻撃者が authorized user を騙り、デバイスに遠隔でアクセスし、デバイスのドライブを暗号化してデータを拉致したり、デバイスのメモリを消去してデータを破棄したり、デバイスを機能不全に陥らせたりすることを可能にする。リスクの程度は、デバイスの重要性や、デバイスが提供するサービスや保持するデータの重さに応じて異なる。
    • 4.1.D.2 デバイスの脆弱性による高リスクは、機密情報の漏洩や重要な運用への潜在的な侵害を伴う。
      • 4.1.D.2 の例:
        • 組織がメールサーバーの最新アップデート(既知の重大な脆弱性を修正するパッチが含まれている)を未導入の状態にある。
    • 4.1.D.3 デバイスの脆弱性による中程度のリスクは、弱い認証要件や、エクスプロイトされる可能性が低い脆弱性から生じることがある。
      • 4.1.D.3 の例:
        • 水処理プラントにはポンプを制御する組み込みシステムがある。プラントの遠隔管理のために、ユーザー名とパスワードでポンプに遠隔アクセスできるが、デバイスにはマルチファクタ認証(MFA)が要求されていない。
    • 4.1.D.4 デバイスの脆弱性による低リスクは、通常、エクスプロイトされたとしても影響が小さい脆弱性に関連している。
      • 4.1.D.4 の例:
        • 社員のラップトップに telnet ポート 23 が開放されている。

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English

    A device is any computer - a server, a personal laptop, a smartphone, or an embedded computer 嵌入式计算机 built into a machine. Everyday devices with embedded computers are called Internet of Things (IoT) 物联网 devices, and they run everything from water pumps to washing machines.

    The four classes of device, and why the class matters

    Class What it is Security consequence
    servers shared machines running services for many users the highest-value target; one compromise reaches everyone
    personal computers desktops and laptops general purpose, so they run anything the user installs
    handheld computers 手持计算机 (also called mobile computers or information appliances) smaller than a PC and running on battery power — smartphones, tablets, smart watches and other wearable technology easily lost or stolen, and often carried across untrusted networks
    embedded computers a computer that is part of a machine — a car's engine controller, a thermostat, a medical pump has a specialised instruction set for interfacing with its components, and tends to be slower, cheaper and to have minimal storage, so security features are often left out and updates are rare

    That last row is the reason embedded and IoT devices appear so often in attack scenarios: the constraints that make them cheap are the same constraints that make them hard to defend.

    The main threat to a device is malware 恶意软件 - malicious software. Learn the types:

    • Virus 病毒 - must be activated by a user opening a file.
    • Worm 蠕虫 - spreads by itself, with no human action.
    • Trojan 木马 - hides inside software that looks safe; a remote access trojan (RAT) 远程访问木马 gives the adversary remote control.
    • Ransomware 勒索软件 - encrypts your files and demands payment for the key.
    • Spyware 间谍软件 - secretly tracks what you do.
    • Keylogger 键盘记录器 - records every keystroke to steal passwords.
    • Logic bomb 逻辑炸弹 - triggers only when a condition is met (a date, a version).
    • Rootkit - deeply hides in the operating system and can even make itself invisible.

    Most malware is a file, but fileless malware 无文件恶意软件 is different: it lives only in RAM 内存 and abuses legitimate programs already on the device, leaving no file for a scanner to find.

    Adversaries exploit unpatched software 未打补丁的软件, weak passwords, unprotected BIOS/UEFI startup settings, and open ports. We rate device risk by the value and criticality of the device - a hospital's unpatched email server is high risk, while an employee's laptop with one unused open port is low.

    日本語

    A device is any computer - a server, a personal laptop, a smartphone, or an embedded computer 嵌入式计算机 built into a machine. Everyday devices with embedded computers are called Internet of Things (IoT) 物联网 devices, and they run everything from water pumps to washing machines.

    The four classes of device, and why the class matters

    Class What it is Security consequence
    servers shared machines running services for many users the highest-value target; one compromise reaches everyone
    personal computers desktops and laptops general purpose, so they run anything the user installs
    handheld computers 手持计算机 (also called mobile computers or information appliances) smaller than a PC and running on battery power — smartphones, tablets, smart watches and other wearable technology easily lost or stolen, and often carried across untrusted networks
    embedded computers a computer that is part of a machine — a car's engine controller, a thermostat, a medical pump has a specialised instruction set for interfacing with its components, and tends to be slower, cheaper and to have minimal storage, so security features are often left out and updates are rare

    That last row is the reason embedded and IoT devices appear so often in attack scenarios: the constraints that make them cheap are the same constraints that make them hard to defend.

    The main threat to a device is malware 恶意软件 - malicious software. Learn the types:

    • Virus 病毒 - must be activated by a user opening a file.
    • Worm 蠕虫 - spreads by itself, with no human action.
    • Trojan 木马 - hides inside software that looks safe; a remote access trojan (RAT) 远程访问木马 gives the adversary remote control.
    • Ransomware 勒索软件 - encrypts your files and demands payment for the key.
    • Spyware 间谍软件 - secretly tracks what you do.
    • Keylogger 键盘记录器 - records every keystroke to steal passwords.
    • Logic bomb 逻辑炸弹 - triggers only when a condition is met (a date, a version).
    • Rootkit - deeply hides in the operating system and can even make itself invisible.

    Most malware is a file, but fileless malware 无文件恶意软件 is different: it lives only in RAM 内存 and abuses legitimate programs already on the device, leaving no file for a scanner to find.

    Adversaries exploit unpatched software 未打补丁的软件, weak passwords, unprotected BIOS/UEFI startup settings, and open ports. We rate device risk by the value and criticality of the device - a hospital's unpatched email server is high risk, while an employee's laptop with one unused open port is low.

    Explore · ⁨探索⁩

    Name the malware from its behaviour · ⁨挙動からマルウェアの名前を答える⁩

    Each kind of malware has one defining trait: a worm self-spreads, a virus needs a user to run it, ransomware encrypts for money, and a rootkit hides deep in the OS. · ⁨各マルウェアには一つの特徴があります。ワームは自己複製し、ウイルスはユーザーによる実行を必要とし、ランサムウェアは金銭目的で暗号化し、ルートキットはOSの奥深くに隠れます。⁩

    Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
    English 日本語
    embedded computer/emˈbedɪd kəmˈpjuːtə/ 組み込みコンピュータ
    Internet of Things (IoT)/ˈɪntənet ɒv θɪŋz/ インターネット・オブ・シンギング (IoT)
    handheld computers/ˈhændheld kəmˈpjuːtəz/ ハンドヘルドコンピューター
    malware/ˈmælweə/ マルウェア
    Virus/ˈvaɪrəs/ ウイルス
    Worm/wɜːm/ ワーム
    Trojan/ˈtrəʊdʒn/ トロイの木馬
    remote access trojan (RAT)/rɪˈməʊt ˈækses ˈtrəʊdʒn/ リモートアクセストロイジ (RAT)
    Ransomware/ˈrænsəmweə/ ランサムウェア
    Spyware/ˈspaɪweə/ スパイウェア
    Keylogger/ˈkiːlɒɡə/ キーロガー
    Logic bomb/ˈlɒdʒɪk bɒm/ ロジックボム
    fileless malware/ˈfaɪlləs ˈmælweə/ ファイルレスマルウェア
    RAM/ræm/ RAM
    unpatched software/ʌnˈpætʃt ˈsɒftweə/ 未パッチのソフトウェア
    4.2

    Authentication

    Syllabus · ⁨シラバス⁩
    Learning ObjectiveEssential Knowledge

    4.2.A
    Explain why hashes (also called hash outputs, checksums, message digests, or digests) are used to store passwords.

    • 4.2.A.1 A cryptographic hash function (also called a message digest function) is a mathematical algorithm that takes binary data of an arbitrary length, processes it according to a set of instructions, and outputs a fixed-length binary string called the hash (or checksum or message digest). Well known cryptographic hashes include:
      • MD5
      • SHA-1, SHA-256, SHA-512 (SHA stands for Secure Hash Algorithm)
      • NTHash
      • RIPEMD-160
    • 4.2.A.2 An n-bit hash has $2^n$ possible outputs. The number of inputs is infinite, and so inevitably two different inputs will produce the same hash. This is called a collision.
    • 4.2.A.3 Cryptographic hash functions have the following properties:
      • Hashes are collision resistant; it is difficult to find two different inputs to the same hash function that produce the same output.
      • Hashes have pre-image resistance; given a hash, it is infeasible to figure out the input that generated the hash.
      • Hashes are repeatable; the same input will always produce the same hash.
      • Hashes have a fixed length; the length in bits of the hash for a specific hash function is constant regardless of the size of the input.
    • 4.2.A.4 Adversaries try to compromise hashing functions by forcing collisions in their output. If an efficient algorithm exists to force a collision for a specific hash function, then that hash function will be deprecated (no longer used in secure settings). MD5 and SHA1 are examples of deprecated hash functions.
    • 4.2.A.5 Password-based authentication services shouldn’t store passwords in plaintext, so that if an adversary gains access to the user:password directory they won’t immediately know the passwords for all users. Instead, user passwords should be hashed and the hash stored in a database. When a user enters their password, it is hashed, and the hash is compared to the hash stored on file. If the hashes match, then the user is authenticated.
    • 4.2.A.6 If two users had the same password, then their passwords would have identical hashes in the user:password directory. To prevent this, a few random bits (called salt) are hashed with a user’s password to generate the hash. Each user’s salt is unique, so even if two users have the same password they will have a different password hash because they have different salt.

    4.2.B
    Explain how password attacks exploit vulnerabilities.

    • 4.2.B.1 If an adversary can compromise the password of a legitimate user, and that user’s organization has not enabled MFA or other authentication protections, then the adversary can act within that organization with all the access and rights available to the user.
    • 4.2.B.2 Password attacks can be classified as online or offline.
      • Online password attacks attempt user:password combinations in an active authentication portal.
      • Offline password attacks have captured a user:password database and can run password attacks against the database on their own computer. This method bypasses any account lock out protections that may be in place.
    • 4.2.B.3 Many users reuse the same passwords (or variations of the same password) for all the services and accounts they have, despite warnings not to. When an organization’s user database is stolen, the usernames, emails, and passwords are sold to adversaries or posted online. Adversaries often begin an attempt to compromise an account by trying stolen or leaked credentials for a target individual.
    • 4.2.B.4 Many users set passwords that are easy to guess, and adversaries will attempt to guess common passwords for a user’s account. Password spraying is an attack where an adversary attempts a common password against many different user accounts.
    • 4.2.B.5 Some services and devices (e.g., switches, routers, and IoT devices) are preconfigured with a default administrative user and password. Credential stuffing is an attack where an adversary attempts to gain access to these services or devices using common default credentials or account credentials that have been stolen.
    • 4.2.B.6 Offline password attacks use automated hash-cracking tools to hash possible passwords and compare them against a captured hash. Although hashes can’t be reversed, an adversary can use these tools to hash many potential passwords and compare them to the target hash. If an adversary finds a hash that matches, they can use the password that generated the hash to login to the user’s account. Offline attacks include:
      • Brute force attacks, where an adversary uses an automated tool to test all the potential passwords that a user could have
      • Dictionary attacks, where an adversary uses an automated tool to test a list of common passwords
    • 4.2.B.7 A rainbow table attack uses a list of common passwords to generate a rainbow table. A rainbow table is a table that contains each potential password and its hash. The table is then sorted by the hashes, and the adversary uses an automated tool to search the list of hashes for the captured hash. If the hashes match, then the adversary has found a password that generates the same hash, and the password will allow the adversary to login to the user’s account.

    4.2.C
    Determine the type of authentication used to verify the identity of a user.

    • 4.2.C.1 Authentication mechanisms are technical controls that verify the identity of a user to ensure that only authorized users access a system. The proof the user provides to identify themselves is called a factor. Common authentication factors include:
      • Something the user knows (knowledge factor)
      • Something the user has (possession factor)
      • Something the user is (biometric factor)
      • Somewhere the user is (location factor)
    • 4.2.C.2 Knowledge factors can be passwords, PINs, or answers to preselected challenge questions. For a knowledge factor to be effective it needs to be something an adversary can’t easily guess; however, knowledge factors that are difficult for an adversary to figure out can also be harder for a user to remember.
    • 4.2.C.3 A possession factor is an object a user has that is unique to them, such as an access card, a bank card, a cell phone, or an authentication token. The more difficult it is for an adversary to obtain the object (or a copy of it), the more secure the possession factor is.
    • 4.2.C.4 Biometric factors measure features of the human body and can include fingerprints, palm prints, facial recognition, iris or retina scans, or voice identification. Biometric factors are difficult for an adversary to duplicate because they are unique to an individual.
    • 4.2.C.5 Location factors use information about Wi-Fi signals, GPS data, time zone settings, and even IP address information to make determinations about location. Rules can be established for allowing or denying access based on a location factor.
    • 4.2.C.6 Multifactor authentication (MFA) is when a system uses more than one factor to authenticate a user. MFA is more secure than single-factor authentication because it requires the user to provide at least two separate factors of authentication.

    4.2.D
    Configure login settings to make a device more secure.

    • 4.2.D.1 Requiring complexity in passwords is a login setting that can be configured. When enabled, users setting a new password must include at least one character from each character set. Passwords with characters from each character set are significantly harder for an adversary to crack than passwords that use characters from only one or two character sets. The main character sets often required are:
      • Uppercase letters (A–Z)
      • Lowercase letters (a–z)
      • Numeric digits (0–9)
      • Special characters (!”#$%&’()*+,-./:;<=>?@ [ \ ] ^_`{|}~)
    • 4.2.D.2 Requiring a minimum password length is a login setting that can be configured. This means that users must have at least a certain number of characters in their password. The longer and more complex a password is, the longer it will take a digital tool to crack the password.
    • 4.2.D.3 Requiring a maximum password age is a login setting that can be configured. When configured, users will receive a prompt to change their password a certain number of days after their last password change, usually every 90 or 120 days. If a user’s password has been compromised, changing it could prevent an adversary from gaining access to the user’s account. However, some national standards recommend that organizations not require users to change their passwords on predefined intervals to discourage users from developing password patterns (e.g., PasswordFall2028).
    • 4.2.D.4 Requiring the system to store a certain number of previous user passwords is a login setting that can be configured. This prevents a user from reusing a password. Many organizations store users’ previous 5–10 password hashes to prevent reuse.
    • 4.2.D.5 Requiring a lockout period after a certain number of invalid login attempts is a login setting that can be configured. This prevents an adversary from continuously randomly attempting wrong passwords. Many organizations lock a user’s account after 3–5 invalid login attempts. The period of the lockout varies.

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English
    Multi-factor authentication

    To store passwords safely, systems use a cryptographic hash function 密码散列函数 - a one-way maths algorithm that turns any input into a fixed-length string called a hash 散列值 (or digest). Hashes have three vital properties: they are collision resistant 抗碰撞 (hard to find two inputs with the same output), have pre-image resistance 抗原像 (you cannot work backwards to the input), and are repeatable (the same input always gives the same hash).

    Real hash functions have names. The Secure Hash Algorithm (SHA) family – SHA-256 and SHA-512 – is today's standard. Adversaries attack a hash function by trying to force a collision (two different inputs with the same hash); once an efficient collision attack exists, that function is deprecated 弃用 (retired from secure use). MD5 and SHA-1 are the classic deprecated examples – never rely on them to protect data today.

    A service never stores your plaintext password. It stores the hash; when you log in, it hashes what you typed and compares. To stop two identical passwords producing identical hashes, a few random bits called salt 盐值 are added before hashing, so every stored hash is unique.

    Worked example. Two users both choose the password sunshine. Without salt, both stored hashes would be identical, so cracking one instantly cracks the other. Give each user a unique salt - say x7 and q2 - and the service hashes sunshinex7 and sunshineq2 instead. The two stored hashes now look completely different, so the adversary must attack each account separately. This is why a stolen hash database is far less dangerous when the hashes are salted.

    Adversaries fight back with password attacks. Online attacks guess against a live login; offline attacks steal the hash database and crack it on their own machine (which bypasses any account-lockout protection). Techniques include:

    • brute force 暴力破解 - an automated tool tries every possible password in turn; guaranteed to work eventually, but slow, and it grows explosively with password length.
    • a dictionary attack 字典攻击 - the tool tries a list of common words and known passwords first, because most people pick guessable ones.
    • password spraying 密码喷洒 - one common password against many accounts (this dodges lockout, which counts failures per account).
    • credential stuffing 撞库 - reusing stolen or default credentials, exploiting that people reuse passwords across sites.
    • a rainbow table 彩虹表 - a precomputed table of passwords and their hashes, sorted by hash, so a captured hash can be looked up instead of recomputed.

    Password policy settings

    An administrator hardens accounts by configuring login settings - and the exam expects you to name them and say what each defends against:

    Setting What it does The attack it slows
    complexity 复杂度 require a character from each set (upper, lower, digit, special) brute force / dictionary
    minimum length 最小长度 require N characters - length matters more than anything brute force (grows exponentially)
    maximum age 最长有效期 force a change every ~90-120 days limits how long a stolen password is useful
    password history 密码历史 store the last 5-10 hashes, block reuse stops recycling an old (possibly leaked) password
    lockout 锁定 lock the account after 3-5 wrong tries brute force / online guessing

    One subtlety worth a mark: some national standards now advise against forced expiry, because regular changes push users into predictable patterns like PasswordFall2028. A password manager 密码管理器 solves the real problem - it generates and stores a long, unique password per site, so none is ever reused or guessable.

    Authentication factors prove who you are, and fall into categories: something you know (a password), something you have (a token or phone), something you are (a biometric 生物特征 like a fingerprint or retina scan), and somewhere you are (a location factor). Using two or more is multifactor authentication (MFA) 多因素身份验证 - far stronger than a password alone.

    Removable media, and the autorun problem

    An adversary can load malware onto an external drive — a USB stick, a portable disc — and leave it where someone will pick it up. If autorun 自动运行 is enabled, the device runs a program from that drive the moment it is inserted, with no click required, so the malware executes before the user has decided to trust anything.

    Two controls answer this, and the exam wants both named:

    • Disable autorun, so inserting a drive never runs anything by itself.
    • Prohibit users from connecting external drives or media at all — enforced by policy and by a technical control that blocks the USB ports — which is why so many secure environments physically or logically disable them.
    日本語
    Multi-factor authentication
    A person pressing a fingertip onto a small optical fingerprint scanner
    A fingerprint scanner: biometric authentication checks something you ARE, which is much harder for an attacker to steal or guess than a password

    To store passwords safely, systems use a cryptographic hash function 密码散列函数 - a one-way maths algorithm that turns any input into a fixed-length string called a hash 散列值 (or digest). Hashes have three vital properties: they are collision resistant 抗碰撞 (hard to find two inputs with the same output), have pre-image resistance 抗原像 (you cannot work backwards to the input), and are repeatable (the same input always gives the same hash).

    A hash function turns any input into a fixed-length digest, and cannot be reversed
    A hash function turns any input into a fixed-length digest, and cannot be reversed

    Real hash functions have names. The Secure Hash Algorithm (SHA) family – SHA-256 and SHA-512 – is today's standard. Adversaries attack a hash function by trying to force a collision (two different inputs with the same hash); once an efficient collision attack exists, that function is deprecated 弃用 (retired from secure use). MD5 and SHA-1 are the classic deprecated examples – never rely on them to protect data today.

    A service never stores your plaintext password. It stores the hash; when you log in, it hashes what you typed and compares. To stop two identical passwords producing identical hashes, a few random bits called salt 盐值 are added before hashing, so every stored hash is unique.

    Worked example. Two users both choose the password sunshine. Without salt, both stored hashes would be identical, so cracking one instantly cracks the other. Give each user a unique salt - say x7 and q2 - and the service hashes sunshinex7 and sunshineq2 instead. The two stored hashes now look completely different, so the adversary must attack each account separately. This is why a stolen hash database is far less dangerous when the hashes are salted.

    Adversaries fight back with password attacks. Online attacks guess against a live login; offline attacks steal the hash database and crack it on their own machine (which bypasses any account-lockout protection). Techniques include:

    • brute force 暴力破解 - an automated tool tries every possible password in turn; guaranteed to work eventually, but slow, and it grows explosively with password length.
    • a dictionary attack 字典攻击 - the tool tries a list of common words and known passwords first, because most people pick guessable ones.
    • password spraying 密码喷洒 - one common password against many accounts (this dodges lockout, which counts failures per account).
    • credential stuffing 撞库 - reusing stolen or default credentials, exploiting that people reuse passwords across sites.
    • a rainbow table 彩虹表 - a precomputed table of passwords and their hashes, sorted by hash, so a captured hash can be looked up instead of recomputed.

    Password policy settings

    An administrator hardens accounts by configuring login settings - and the exam expects you to name them and say what each defends against:

    Setting What it does The attack it slows
    complexity 复杂度 require a character from each set (upper, lower, digit, special) brute force / dictionary
    minimum length 最小长度 require N characters - length matters more than anything brute force (grows exponentially)
    maximum age 最长有效期 force a change every ~90-120 days limits how long a stolen password is useful
    password history 密码历史 store the last 5-10 hashes, block reuse stops recycling an old (possibly leaked) password
    lockout 锁定 lock the account after 3-5 wrong tries brute force / online guessing

    One subtlety worth a mark: some national standards now advise against forced expiry, because regular changes push users into predictable patterns like PasswordFall2028. A password manager 密码管理器 solves the real problem - it generates and stores a long, unique password per site, so none is ever reused or guessable.

    Authentication factors prove who you are, and fall into categories: something you know (a password), something you have (a token or phone), something you are (a biometric 生物特征 like a fingerprint or retina scan), and somewhere you are (a location factor). Using two or more is multifactor authentication (MFA) 多因素身份验证 - far stronger than a password alone.

    Two small USB hardware security keys
    A hardware security key proves who you are with something you physically hold — a strong second factor

    Removable media, and the autorun problem

    An adversary can load malware onto an external drive — a USB stick, a portable disc — and leave it where someone will pick it up. If autorun 自动运行 is enabled, the device runs a program from that drive the moment it is inserted, with no click required, so the malware executes before the user has decided to trust anything.

    Two controls answer this, and the exam wants both named:

    • Disable autorun, so inserting a drive never runs anything by itself.
    • Prohibit users from connecting external drives or media at all — enforced by policy and by a technical control that blocks the USB ports — which is why so many secure environments physically or logically disable them.
    Explore · ⁨探索⁩

    How a hash maps any input to a fixed slot · ⁨ハッシュが任意の入力を固定されたスロットにマッピングする方法⁩

    A hash function sends every input to a fixed-length output. The same input always lands in the same place (repeatable), and you cannot work backwards from the slot to the input. · ⁨ハッシュ関数は、すべての入力を固定長の出力に送ります。同じ入力は常に同じ場所に戻り(再現可能)、スロットから入力への逆演算はできません。⁩

    Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
    English 日本語
    cryptographic hash function/ˌkrɪptəˈɡræfɪk hæʃ ˈfʌŋkʃn/ 暗号ハッシュ関数
    hash/hæʃ/ ハッシュ
    collision resistant/kəˈlɪʒn rɪˈzɪstənt/ 衝突耐性
    pre-image resistance/priː ˈɪmɪdʒ rɪˈzɪstəns/ 逆算耐性
    deprecated/ˈdeprɪkeɪtɪd/ 非推奨
    salt/sɒlt/ 塩
    brute force/bruːt fɔːs/ ブルートフォース
    dictionary attack/ˈdɪkʃənəri əˈtæk/ 辞書攻撃
    password spraying/ˈpæswɜːd ˈspreɪɪŋ/ パスワードスプレーイング
    credential stuffing/krɪˈdenʃl ˈstʌfɪŋ/ クレデンシャルスタッフィング
    rainbow table/ˈreɪnbəʊ ˈteɪbl/ レインボーテーブル
    complexity/kəmˈpleksɪti/ 複雑性
    minimum length/ˈmɪnɪməm leŋθ/ 最小長さ
    maximum age/ˈmæksɪməm eɪdʒ/ 最大有効期間
    password history/ˈpæswɜːd ˈhɪstəri/ パスワード履歴
    lockout/ˈlɒkaʊt/ ロックアウト
    password manager/ˈpæswɜːd ˈmænɪdʒə/ パスワードマネージャー
    biometric/ˌbaɪəʊˈmetrɪk/ 生体認証
    multifactor authentication (MFA)/ˌmʌltɪˈfæktə ɔːˌθentɪˈkeɪʃn/ 多要素認証 (MFA)
    autorun/ˌɔːtəʊˈrʌn/ オートラン
    Watch lesson · ⁨レッスンを視聴⁩
    4.3

    Protecting Devices

    Syllabus · ⁨シラバス⁩
    English

    Learning Objective 4.3.A: Identify managerial controls related to device security.

    • 4.3.A.1 An acceptable use policy will describe the range of activities that are permissible, prohibited, or required by users on devices owned by an organization and may include:
      • Prohibiting users from accessing specific websites or types of websites (e.g., social media or gaming)
      • Requiring users to keep software updated
      • Allowing users to connect peripheral devices
      • Prohibiting users from connecting external drives or media
    • 4.3.A.2 A password policy will detail the requirements for user passwords within an organization and may include:
      • A minimum or maximum password length
      • A minimum or maximum amount of time a user may keep the same password
      • A prohibition of password reuse
      • Rules for password construction (e.g., no dictionary words and character set requirements)
      • A suggestion to use secure password management tools instead of writing passwords down
    • 4.3.A.3 A software installation policy will describe what (if any) software users are allowed to install on their devices and usually also a process for users to request specialized software they may need to perform their role, and it may include:
      • A prohibition against users installing software on their devices
      • A process for users to request new software needed for their role
      • A list of approved software for users

    Learning Objective 4.3.B: Explain how anti-malware software can make a device more secure.

    • 4.3.B.1 Anti-malware software (sometimes called antivirus software) has tools to quarantine and remove malware that can corrupt, spy on, or destroy a system. Malware contains indicators that make it detectable; these indicators are called signatures.
    • 4.3.B.2 Anti-malware software has a database of malware signatures. It periodically scans the files on a device and checks to see if any of the files match any of the signatures in its database. If there is a match, the software quarantines and removes the malicious files.

    Learning Objective 4.3.C: Explain why keeping a device’s operating system and software updated makes it more secure.

    • 4.3.C.1 When vulnerabilities in operating systems and software are found, the vendor or organization that maintains the operating system software will fix it and send an update. A small update is called a patch.
    • 4.3.C.2 Ensuring that a computer’s operating system and software applications are updated to the most recent version prevents adversaries from taking advantage of a known vulnerability.

    Learning Objective 4.3.D: Configure a host-based firewall.

    • 4.3.D.1 Host-based firewalls allow or deny traffic into or out of a single device. This provides an extra layer of security in case a host is connected to a compromised network.
    • 4.3.D.2 A host-based firewall is software that runs on a device and follows a set of rules (an ACL) like a network-based firewall. Firewall rules are implemented in order, applying the first rule that matches.
    • 4.3.D.3 A host-based firewall can also block specified types of outbound traffic. Host-based firewalls should always block ports or services not needed for a given device.
      • Illustrative examples for 4.3.D.3:
        • A host-based firewall is configured to block outbound FTP traffic. This prevents an adversary with remote access to the host from using FTP to exfiltrate a file to the adversary’s server.
    • 4.3.D.4 The rules for a host-based firewall can allow or deny traffic based on source or destination port or IP address, service, protocol, or application.
    日本語

    学習目標 4.3.A: デバイスセキュリティに関連する管理統制を特定する。

    • 4.3.A.1 許容利用ポリシーは、組織所有のデバイスにおいてユーザーが許可される、禁止される、または必須とする活動の範囲を説明し、以下を含む場合があります:
      • ユーザーによる特定のウェブサイトや種類のウェブサイト(例:SNSやゲームサイト)へのアクセスの禁止
      • ソフトウェアの更新状態を維持することの強制
      • 周辺機器の接続の許可
      • 外部ドライブやメディアの接続の禁止
    • 4.3.A.2 パスワードポリシーは、組織内のユーザーのパスワードに関する要件を詳細に示し、以下を含む場合があります:
      • パスワードの最小または最大長さ
      • 同じパスワードを保持できる最小または最大の期間
      • パスワードの再使用の禁止
      • パスワードの作成ルール(例:辞書語の禁止、文字セット要件など)
      • パスワードメモ書きではなく、安全なパスワード管理ツールの使用を推奨
    • 4.3.A.3 ソフトウェアインストールポリシーは、ユーザーが自分のデバイスにインストールできるソフトウェア(あれば)を説明し、一般的にまた、職務遂行に必要な特別ソフトウェアをリクエストするためのプロセスも含まれ、以下を含む場合があります:
      • ユーザーによるデバイスへのソフトウェアインストールの禁止
      • 職務遂行に必要な新ソフトウェアのリクエストプロセス
      • ユーザーのための承認済みソフトウェア一覧

    学習目標 4.3.B: アンチマルウェアソフトウェアがデバイスをより安全にする方法を説明する。

    • 4.3.B.1 アンチマルウェアソフトウェア(アンチウイルスソフトウェアとも呼ばれる)には、システムを損壊させたり、監視したり、破壊したりするマルウェアを隔離・除去するためのツールがあります。マルウェアには検出可能にするインジケーターが含まれており、これらのインジケーターはシグネチャと呼ばれます。
    • 4.3.B.2 アンチマルウェアソフトウェアには、マルウェアのシグネチャデータベースがあります。デバイスのファイルを定期的にスキャンし、ファイルがデータベース内のどのシグネチャと一致するかを確認します。一致がある場合、ソフトウェアは悪質なファイルを隔離・削除します。

    学習目標 4.3.C: デバイスのオペレーティングシステムとソフトウェアを更新することの安全性について説明する。

    • 4.3.C.1 オペレーティングシステムやソフトウェアに脆弱性が見つかった場合、そのOSソフトウェアを保守するベンダーや組織が修正し、アップデートを送信します。小さなアップデートはパッチと呼ばれます。
    • 4.3.C.2 コンピュータのオペレーティングシステムおよびアプリケーションソフトウェアを最新バージョンに更新しておくことで、攻撃者が既知の脆弱性を悪用することを防げます。

    学習目標 4.3.D: ホストベースのファイアウォールを設定する。

    • 4.3.D.1 ホストベースのファイアウォールは、単一デバイスへの入出力トラフィックを許可または拒否します。ホストが侵害されたネットワークに接続されている場合に備えて、追加のセキュリティ層を提供します。
    • 4.3.D.2 ホストベースのファイアウォールは、デバイス上で動作するソフトウェアであり、ネットワークベースのファイアウォールと同様に一連のルール(ACL)に従います。ファイアウォールルールは順序に従って適用され、最初に一致するルールが適用されます。
    • 4.3.D.3 ホストベースのファイアウォールは、指定された種類のアウトバウンドトラフィックをブロックすることもできます。ホストベースのファイアウォールは、特定のデバイスに不要なポートやサービスを常にブロックすべきです。
      • 4.3.D.3 の参考例:
        • ホストベースのファイアウォールがアウトバウンドFTPトラフィックをブロックするように設定されています。これにより、リモートアクセスを持つ攻撃者がFTPを使用してファイルを攻撃者のサーバーへ転送することを防げます。
    • 4.3.D.4 ホストベースのファイアウォールのルールは、ソースまたは dest port、IPアドレス、サービス、プロトコル、またはアプリケーションに基づいて、トラフィックを許可または拒否できます。

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English

    Managerial controls set the rules: an acceptable use policy 可接受使用政策 lists what users may and may not do, a password policy sets length and reuse rules, and a software installation policy controls what can be installed.

    Technical controls do the work. Anti-malware software 反恶意软件 keeps a database of malware signatures and quarantines any file that matches. Keeping the operating system and applications updated - installing each patch 补丁 - closes known holes before adversaries can use them. A host-based firewall 主机防火墙 controls traffic in and out of one single device, blocking ports and services it does not need.

    日本語

    Managerial controls set the rules: an acceptable use policy 可接受使用政策 lists what users may and may not do, a password policy sets length and reuse rules, and a software installation policy controls what can be installed.

    Technical controls do the work. Anti-malware software 反恶意软件 keeps a database of malware signatures and quarantines any file that matches. Keeping the operating system and applications updated - installing each patch 补丁 - closes known holes before adversaries can use them. A host-based firewall 主机防火墙 controls traffic in and out of one single device, blocking ports and services it does not need.

    An anti-malware scanner window: 3106 files scanned, two threats found, with quarantine and update controls
    Anti-malware software scans files against a signature database and quarantines any matches — this scan has flagged two threats
    Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
    English 日本語
    acceptable use policy/əkˈseptəbl juːs ˈpɒlɪsi/ 許容利用ポリシー
    Anti-malware software/ˈænti ˈmælweə ˈsɒftweə/ アンチマルウェアソフトウェア
    patch/pætʃ/ パッチ
    host-based firewall/həʊst beɪst ˈfaɪəwɔːl/ ホストベースドファイアウォール
    4.4

    Detecting Attacks on Devices

    Syllabus · ⁨シラバス⁩
    English

    Learning Objective 4.4.A: Explain how to detect attacks against devices.

    • 4.4.A.1 System processes and settings, login attempts, file download attempts, and user actions are logged by computing systems. These logs can be used to reconstruct circumstances leading up to and during a cyber incident.
    • 4.4.A.2 An indicator of compromise (IoC) is evidence that an adversary has compromised a device or network.
    • 4.4.A.3 Authentication logs (or auth logs) record every attempted login on a system. Analysis of authentication logs can reveal attempted attacks.
    • 4.4.A.4 Host-based IoCs are discovered when analyzing logs and configuration settings. Indicators, such as the following, can be found in authentication logs, user activity logs, and system configuration files:
      • Unusual files being created or modified
      • Unexpected processes or services
      • Unauthorized changes to system configuration settings
      • Unauthorized software installation or update
    • 4.4.A.5 File-based IoCs are discovered when analyzing files on a device. Indicators are usually found in executable files and can include:
      • Files whose hash matches known malware
      • File names that are known to be created by a certain piece of malware
      • File paths that are associated with malicious activity
    • 4.4.A.6 Behavior-based IoCs are discovered when analyzing logs. Indicators can be found in authentication logs and access logs and can include:
      • Multiple failed login attempts
      • Unusual login times or locations
      • Unauthorized attempts to access sensitive data
      • Attempts to elevate user privileges on a system

    Learning Objective 4.4.B: Determine controls for detecting attacks against a device.

    • 4.4.B.1 Performance is a criterion for determining a detection method. Detection tools use system memory and processing power and can impact the performance of a device. Anomaly-based detection tools use more system resources than signature-based tools. Signature-based detection is a better option for devices with less powerful system resources. Many embedded devices do not have enough system resources to run any detection tools on the device.
    • 4.4.B.2 Cost is a criterion for determining a detection method. Organizations that purchase detection software need to consider the cost of purchasing enough software licenses for the number of devices they need to monitor. Some organizations purchase an endpoint detection and response (EDR) service from a third-party vendor. Although these services are expensive, they provide a holistic, unified approach to threat detection for an organization’s devices; they typically include a centralized alert platform for monitoring possible attacks on devices.
    • 4.4.B.3 Sensitivity or criticality of the device is a criterion for determining a detection method. Devices that store or process sensitive information or provide critical services are more likely to be targeted by adversaries and benefit from a hybrid-detection model to offer maximum protection, when possible.

    Learning Objective 4.4.C: Evaluate the impact of a device detection method.

    • 4.4.C.1 Speed and performance are factors in evaluating the impact of a detection method. Signature-based detection is faster than anomaly-based detection in general, and that effect is compounded on devices, which often lack the processing power to effectively run anomaly-based detection tools. Implementing resource-intensive detection tools on devices can degrade device performance.
    • 4.4.C.2 Phase of the attack is a factor in evaluating the impact of a detection method. To carry out actions on a device, adversaries must first bypass a combination of physical- or network-layer protective, deterrent, and detective security controls. Detecting and stopping an attack at the device level can prevent adversaries from accessing sensitive data or disrupting critical services.
    • 4.4.C.3 False positives versus ease of bypassing detection is a factor in evaluating the impact of a detection method. Most device-level detection tools are signature-based, and signature-based detection has a low rate of false positives. However, signature-based detection is easier for adversaries to bypass.

    Learning Objective 4.4.D: Apply detection techniques to identify indicators of password attacks by analyzing log files.

    • 4.4.D.1 Online password attacks can be detected in authentication logs. A single user attempting many wrong passwords is an indicator of an online password attack. If a user:password hash database has been compromised, all the user passwords in the database should be considered insecure and all users should be forced to reset their passwords.
    • 4.4.D.2 If an authorized user is logging in from a different location or IP address than expected, or at a different time than normal, this can be an indicator that the user’s password has been compromised.
    • 4.4.D.3 An indicator of password spraying is many users trying to log in within seconds of each other from one IP address or from unusual IP addresses.
    • 4.4.D.4 An indicator of credential stuffing is a series of default user:password combinations being attempted on a device in quick succession, often from the same IP address.
    • 4.4.D.5 Offline password attacks can’t be detected, because the attack takes place on the adversary’s computer.
    日本語

    学習目標 4.4.A: デバイスに対する攻撃を検知する方法を説明する。

    • 4.4.A.1 システムプロセスと設定、ログイン試行、ファイルダウンロード試行、およびユーザー操作は、コンピューティングシステムによってログとして記録されます。これらのログは、サイバー事件に至る前および発生時の状況を復元するために使用できます。
    • 4.4.A.2 侵害の指標(IoC)とは、攻撃者がデバイスやネットワークを乗っ取ったことを示す証拠である。
    • 4.4.A.3 認証ログ(auth logs)は、システムへのログイン試行をすべて記録する。認証ログの分析により、試みられた攻撃が判明することがある。
    • 4.4.A.4 ホストベースのIoCは、ログと設定の分析によって発見される。以下の指標などは、認証ログ、ユーザー活動ログ、およびシステム設定ファイルに存在する可能性がある:
      • 不審なファイルの作成または修改
      • 予期せぬプロセスやサービス
      • システム設定に対する無断の変更
      • 無断のソフトウェアインストールまたはアップデート
    • 4.4.A.5 ファイルベースのIoCは、デバイス上のファイルの分析によって発見される。指標は通常、実行可能ファイルに含まれ、以下を含むことがある:
      • 既知のマルウェアとハッシュ値が一致するファイル
      • 特定のマルウェアによって生成されることが知られているファイル名
      • 悪意のある活動に関連付けられているファイルパス
    • 4.4.A.6 ベースド・イン・-behavior IoCは、ログの分析によって発見される。指標は認証ログおよびアクセスログに含まれることができ、以下を含むことがある:
      • 複数のログイン失敗試行
      • 不審なログイン時間や場所
      • 機密データへの無断アクセス試行
      • システム上でのユーザー権限の昇格試行

    学習目標 4.4.B: デバイスに対する攻撃を検出するための統制策を決定する。

    • 4.4.B.1 パフォーマンスは検出方法を選択するための基準となる。検出ツールはシステムメモリと処理能力を使用し、デバイスのパフォーマンスに影響を与えることがある。異常ベースの検出ツールは、シグネチャベースのツールよりも多くのシステムリソースを消費する。リソースが少ないデバイスには、シグネチャベースの検出の方が適している。多くの組み込みデバイスは、デバイス上で検出ツールを実行するのに十分なシステムリソースを持っていない。
    • 4.4.B.2 コストは検出方法を選択するための基準となる。検出ソフトウェアを購入する組織は、監視が必要なデバイス数分のライセンスを取得するコストを考慮しなければならない。一部の組織は、サードパーティベンダーからエンドポイント検出およびレスポンス(EDR)サービスを購入する。これらのサービスは高価ではあるが、組織のデバイスに対する脅威検出に対して包括的かつ統合されたアプローチを提供します。通常、デバイスに対する攻撃を監視するための集中型アラートプラットフォームが含まれている。
    • 4.4.B.3 デバイスの感度または重要度は、検出方法を選択するための基準となる。機密情報を保持または処理するデバイスや重要なサービスを提供するデバイスは、攻撃者の標的となりやすく、最大限の保護を提供するために、可能な限りハイブリッド検出モデルを利用するメリットがある。

    学習目標 4.4.C: デバイス検出方法の影響を評価する。

    • 4.4.C.1 スピードとパフォーマンスは、検出方法の影響を評価する要因となる。一般的に、シグネチャベースの検出は異常ベースの検出より高速であり、その効果は、異常ベースの検出ツールを効果的に実行する処理能力を欠いていることが多いデバイスにおいてさらに増幅される。リソースを大量に消費する検出ツールをデバイスに実装すると、デバイスのパフォーマンスが低下する可能性がある。
    • 4.4.C.2 攻撃フェーズは、検出方法の影響を評価する要因となる。デバイス上で操作を行うために、攻撃者はまず、物理層またはネットワーク層の防御、抑止、および探知セキュリティ統制の組み合わせを回避しなければならない。デバイスレベルで攻撃を検知して停止することは、攻撃者が機密データにアクセスしたり、重要なサービスを妨害したりすることを防ぐことができる。
    • 4.4.C.3 フォルスポットと検出回避の容易さは、検出方法の影響を評価する要因となる。ほとんどのデバイスレベルの検出ツールはシグネチャベースであり、シグネチャベースの検出はフォールスポットの率が低い。しかし、シグネチャベースの検出は攻撃者にとって回避しやすい。

    学習目標 4.4.D: ログファイルを分析してパスワード攻撃の指標を特定する検出手法を適用する。

    • 4.4.D.1 オンラインパスワード攻撃は、認証ログで検出できる。単一のユーザーが多数の誤ったパスワードを試行することは、オンラインパスワード攻撃の指標である。ユーザー:パスワードハッシュデータベースが乗っ取られた場合、データベース内のすべてのユーザーパスワードは不secureと見なされ、すべてのユーザーにパスワードのリセットを強制すべきである。
    • 4.4.D.2 正規ユーザーが予想される場所やIPアドレス、または通常の時間とは異なる場所や時間にログインしている場合、これはユーザーのパスワードが乗っ取られたことを示す指標になることがある。
    • 4.4.D.3 パスワードスプレーの指標は、1つのIPアドレスまたは不審なIPアドレスから、数秒間隔で多数のユーザーがログインしようとしていることである。
    • 4.4.D.4 クレデンシャルスタッフィングの指標は、同じIPアドレスなどから、一度に多数のデフォルトユーザー:パスワード組み合わせがデバイス上で試行されていることである。
    • 4.4.D.5 オフラインパスワード攻撃は、攻撃が攻撃者のコンピュータ上で行われるため、検出できない。

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English

    Devices log logins, file changes, and processes, and these logs reveal an indicator of compromise (IoC) 入侵指标 - evidence that an adversary got in. Host-based IoCs show up as unexpected processes or changed settings; file-based IoCs are files whose hash matches known malware; behaviour-based IoCs are things like many failed logins or unusual login times.

    Choosing a detection method means weighing performance (signature-based is lighter, better for weak devices), cost (an endpoint detection and response (EDR) 端点检测与响应 service is powerful but expensive), and how sensitive the device is. Reading authentication logs exposes password attacks: many wrong passwords for one user signals a guessing attack; many users failing from one IP signals password spraying; a burst of default credentials signals credential stuffing. Offline attacks, though, cannot be detected - they happen on the adversary's own computer.

    Speed is itself a security factor. Signature-based detection compares what it sees against a list of known-bad patterns, so it is faster than anomaly-based detection, which must first learn what normal looks like and then measure every event against that model. Anomaly-based detection catches attacks that have no signature yet, but it costs far more processing power — and on a device that lacks it, the effect compounds: the detection runs slowly, the device degrades, and the method ends up not being implemented effectively at all.

    日本語

    Devices log logins, file changes, and processes, and these logs reveal an indicator of compromise (IoC) 入侵指标 - evidence that an adversary got in. Host-based IoCs show up as unexpected processes or changed settings; file-based IoCs are files whose hash matches known malware; behaviour-based IoCs are things like many failed logins or unusual login times.

    Choosing a detection method means weighing performance (signature-based is lighter, better for weak devices), cost (an endpoint detection and response (EDR) 端点检测与响应 service is powerful but expensive), and how sensitive the device is. Reading authentication logs exposes password attacks: many wrong passwords for one user signals a guessing attack; many users failing from one IP signals password spraying; a burst of default credentials signals credential stuffing. Offline attacks, though, cannot be detected - they happen on the adversary's own computer.

    Speed is itself a security factor. Signature-based detection compares what it sees against a list of known-bad patterns, so it is faster than anomaly-based detection, which must first learn what normal looks like and then measure every event against that model. Anomaly-based detection catches attacks that have no signature yet, but it costs far more processing power — and on a device that lacks it, the effect compounds: the detection runs slowly, the device degrades, and the method ends up not being implemented effectively at all.

    Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
    English 日本語
    indicator of compromise (IoC)/ˈɪndɪkeɪtə ɒv ˈkɒmprəmaɪz/ 侵害指標 (IoC)
    endpoint detection and response (EDR)/endˈpɔɪnt dɪˈtekʃn ænd rɪˈspɒns/ エンドポイント検知と応答 (EDR)
    4.4

    Exam tips

    • Know each malware type by its defining trait: a worm self-spreads, a virus needs a user, ransomware encrypts for money, a RAT gives remote control, a rootkit hides.
    • A hash is one-way and fixed-length; salt makes identical passwords hash differently. Never say a service "stores the password" - it stores the salted hash.
    • Name real algorithms: SHA-256/SHA-512 are current; MD5 and SHA-1 are deprecated because efficient collision attacks exist.
    • Match the password attack to its log signature: one user + many wrong passwords = guessing; many users + one IP = spraying; default credentials = stuffing.
    • Sort authentication factors into know / have / are / where, and remember MFA combines two or more - a fingerprint plus a password, not two passwords.
    • Offline password attacks cannot be detected because the cracking happens on the adversary's machine - a favourite exam "gotcha".
  • 5

    Securing Applications and Data · ⁨アプリケーションとデータの保護⁩

    Watch lesson · ⁨レッスンを視聴⁩
    5.1

    Application and Data Vulnerabilities and Attacks · ⁨アプリケーションおよびデータ脆弱性と攻撃⁩

    Syllabus · ⁨シラバス⁩
    English

    Learning Objective 5.1.A: Explain how adversaries can exploit application and file vulnerabilities to cause loss, damage, disruption, or destruction.

    • 5.1.A.1 An adversary can read any unencrypted files if they have access to the device or drive storing the files.
    • 5.1.A.2 Computers have standard users and administrative users. Administrative users have access to control system settings and can typically access any files or applications on a system. If regular users are given administrative privileges on a computer, and an adversary can compromise a user’s account, then the adversary will have elevated privileges on the system.
    • 5.1.A.3 When access control settings are weakly configured, many users often have permission to view and sometimes even edit files on a system. Adversaries can take advantage of weak access control settings to steal or destroy files or disrupt an application.

    Learning Objective 5.1.B: Explain how application attacks exploit vulnerabilities.

    • 5.1.B.1 Applications are programs that run instructions on computers; they are executable data. Some applications run locally on a user’s computer, while other applications, like web applications, run on a server and are accessed by users through a network.
    • 5.1.B.2 Many applications take user input through open-ended input fields where users can type characters (e.g., letters, numbers, punctuation). Developers should include user input checks in their application, such as numeric input when asked for a number of items, to ensure that the user input matches what is expected; the application should reject input outside of the expected parameters. This process of verifying that user input meets expected criteria before processing it is called data validation. Applications that fail to validate user input are vulnerable to injection-type attacks, where adversaries insert unexpected character strings in input fields to alter the behavior of a program.
    • 5.1.B.3 Structured query language (SQL) is a computer language used to request information from databases and make changes to databases or entries in databases. Applications that query a database using unvalidated or unsanitized input from users are vulnerable.
    • 5.1.B.4 An SQL-injection attack places SQL commands and control characters into a user-input field in an application, which can lead to a breach of confidentiality by causing the application to return more information than it should, or a breach of integrity by modifying or deleting data in the database.
    • 5.1.B.5 Websites are written using hypertext markup language (HTML), and many websites use Javascript to create dynamic content on websites or web applications. Because Javascript commands run in the browser of the user visiting the website, those commands can access sensitive data stored in the browser like usernames, passwords, and cryptographic keys.
    • 5.1.B.6 A cross site scripting (XSS) attack injects malicious code into a website that a user’s browser then executes. The malicious code can be embedded in a link the user clicks (a Type I or Reflected XSS attack) or it can be inserted onto a website through a comment field, forum post, or visitor log, which would affect any user visiting that website (a Type II or Stored XSS attack).
    • 5.1.B.7 When applications take user input, that input is written to a buffer. A buffer is a designated section of computer memory with a fixed size. If the amount of data the user enters exceeds the size of the buffer, it can overflow into adjacent memory locations and overwrite other parts of the computer’s memory.
    • 5.1.B.8 A buffer overflow attack feeds more data into memory than was allotted, which can cause a system to crash or to execute code outside the scope of a program’s security policy, effectively allowing the adversary to perform unauthorized actions on a computer, such as accessing, modifying, or deleting files.
    • 5.1.B.9 The files that run web applications are stored in directories on servers. When users access web applications, their browsers send GET requests using hypertext transfer protocol (HTTP). A GET request accesses a file somewhere in the filesystem of the server.
    • 5.1.B.10 In a directory traversal attack, adversaries modify URLs and GET requests to attempt to access sensitive data (e.g., usernames and passwords) on a server’s file system.
      • Illustrative examples for 5.1.B.10:
        • A web server stores images for a website it hosts in the /var/www/images/ directory. An adversary modifies a URL requesting an image to ../../../etc/passwd. The .. moves one directory up in the file system; so the three consecutive .. returns the path to the root, and from there the adversary is attempting to access the passwd file that would return a list of all the authorized usernames on the device.

    Learning Objective 5.1.C: Assess and document risks from application and data vulnerabilities.

    • 5.1.C.1 Data security risks can involve a compromise of confidentiality when unauthorized persons can access sensitive data, integrity when data can be manipulated or altered from its intended state, and availability when data can be destroyed or encrypted to prevent others from accessing it.
    • 5.1.C.2 High risks from data vulnerabilities often involve highly sensitive data (e.g., data that is governed by laws or regulations) that could be compromised through a highly likely exploit.
      • Illustrative examples for 5.1.C.2:
        • The company developing the next jet engine that will be used by the Air Force in its planes is storing the technical specifications for the engine on an unencrypted drive.
    • 5.1.C.3 Moderate risks from data vulnerabilities often involve sensitive data not having strong enough encryption or strict enough access controls.
      • Illustrative examples for 5.1.C.3:
        • A company stores its customers’ PII in a spreadsheet, and the spreadsheet is encrypted using a small key.
    • 5.1.C.4 Low risks from data vulnerabilities often involve less sensitive information being encrypted with shorter keys or having access controls that are not strict enough.
      • Illustrative examples for 5.1.C.4:
        • An organization’s CEO stores his private memos to his executive staff on a company share drive that is unencrypted and has no access controls.
    日本語

    学習目標 5.1.A: 攻撃者がアプリケーションおよびファイルの脆弱性をどのように利用して、損失、損傷、妨害、または破壊を引き起こすかを説明する。

    • 5.1.A.1 攻撃者がファイルが格納されているデバイスまたはドライブにアクセスできる場合、暗号化されていないファイルはすべて読み取られることができる。
    • 5.1.A.2 コンピュータには標準ユーザーと管理者ユーザーがあります。管理者ユーザーはシステム設定の制御にアクセスでき、通常、システム上のすべてのファイルやアプリケーションにアクセスできます。標準ユーザーに管理者権限が与えられており、攻撃者がユーザーのアカウントを乗っ取った場合、攻撃者はシステム上で elevated privileges( comented privileges )を獲得することになります。
    • 5.1.A.3 アクセス制御設定が緩く設定されている場合、多くのユーザーがシステム上のファイルの表示、さらには編集へのアクセス権限を持つことがあります。攻撃者はこれらの弱いアクセス制御設定を利用し、ファイルを盗み出したり破棄したり、アプリケーションを妨害したりすることがあります。

    学習目標 5.1.B: アプリケーション攻撃が脆弱性をどのように利用するかを説明する。

    • 5.1.B.1 アプリケーションはコンピューターで命令を実行するプログラムであり、実行可能なデータです。一部のアプリケーションはユーザーのコンピューター上でローカルに動作しますが、Webアプリケーションなどの他のアプリケーションはサーバー上で動作し、ユーザーがネットワークを通じてアクセスします。
    • 5.1.B.2 多くのアプリケーションは、ユーザーが文字(例:アルファベット、数字、記号)を入力できるオープンエンドの入力フィールドを通じてユーザー入力を取得します。開発者は、アイテム数を問われた際に数値入力を行うようにするなどの、ユーザー入力の検証をアプリケーションに含めるべきです。これにより、ユーザー入力が期待される内容と一致していることを確認でき、期待されるパラメータ外の入力は拒否されます。このように、処理前にユーザー入力が期待される基準を満たしているかを検証するプロセスは「データバリデーション」と呼ばれます。ユーザー入力を検証しないアプリケーションは、攻撃者が入力フィールドに予期せぬ文字列を挿入してプログラムの動作を変更する注入型攻撃に対して脆弱となります。
    • 5.1.B.3 スtructured query language (SQL) は、データベースから情報を要求したり、データベースやそのエントリの変更を行ったりするために使用されるコンピューター言語です。ユーザーからの検証されていないまたは清浄化されていない入力でデータベースを照会するアプリケーションは脆弱性があります。
    • 5.1.B.4 SQLインジェクション攻撃では、SQLコマンドや制御文字がアプリケーションの入力フィールドに配置され、これが機密性の侵害(アプリケーションが返すべき以上の情報を返すこと)、または整合性の侵害(データベース内のデータの修改や削除)を引き起こすことがあります。
    • 5.1.B.5 ウェブサイトはhypertext markup language (HTML) で記述されており、多くのウェブサイトではdynamic content(動的コンテンツ)を作成するためにJavascriptを使用しています。 Javascriptコマンドは訪問者のブラウザ内で実行されるため、それらのコマンドはブラウザ内に格納されたユーザー名、パスワード、暗号鍵などの敏感なデータにアクセスできます。
    • 5.1.B.6 A cross site scripting (XSS) attack(クロスサイトスクリプティング攻撃)では、悪意のあるコードがウェブサイトへ注入され、ユーザーのブラウザによって実行されます。悪意のあるコードは、ユーザーがクリックするリンクに埋め込まれている場合(Type I または Reflected XSS 攻撃)や、コメント欄、フォーラム投稿、访客日志(visitor log)を介してサイトに挿入され、そのサイトを訪問するすべてのユーザーに影響を与える場合(Type II または Stored XSS 攻撃)があります。
    • 5.1.B.7 アプリケーションがユーザー入力を取得すると、その入力はバッファに書き込まれます。バッファとは、固定サイズを持つコンピューターメモリの指定された領域です。ユーザーが入力したデータ量がバッファのサイズを超えると、隣接するメモリ領域にオーバーフローし、コンピューターのメモリの他の部分を上書きすることがあります。
    • 5.1.B.8 バッファオーバーフロー攻撃では、割り当てられた量よりも多くのデータをメモリに供給することで、システムがクラッシュしたり、プログラムのセキュリティポリシーの範囲外でコードを実行したりすることがあり、結果として攻撃者にファイルのアクセス、修改、または削除など、コンピューター上での不正操作を許可することになります。
    • 5.1.B.9 Webアプリケーションを実行するファイルは、サーバー上のディレクトリに保存されています。ユーザーがWebアプリケーションにアクセスすると、そのブラウザはhypertext transfer protocol (HTTP) を用いてGETリクエストを送信します。GETリクエストはサーバーのファイルシステム内のどこかのファイルにアクセスします。
    • 5.1.B.10 ディレクトリトラバーサル攻撃では、攻撃者はURLやGETリクエストを改変し、サーバーのファイルシステム上の敏感なデータ(例:ユーザー名とパスワード)にアクセスしようと試みます。
      • 5.1.B.10 の具体例:
        • 某ウェブサーバーがホストするサイトの画像を /var/www/images/ デレクトリに格納しています。攻撃者は画像を要求するURLを ../../../etc/passwd に変更します。 .. はファイルシステム内で1つ上のディレクトリを示すため、3つの連続する .. はルートパスを指し示し、そこから攻撃者は passwd ファイルにアクセスしようとし、これはデバイス上のすべての承認済みユーザー名のリストを返します。

    学習目標 5.1.C: アプリケーションおよびデータの脆弱性からのリスクを評価・文書化する。

    • 5.1.C.1 データセキュリティリスクには、未授权者(unauthorized persons )が敏感なデータにアクセスできることで機密性が侵害されること、データが意図した状態から操作・修改されることで整合性が侵害されること、データが破壊または暗号化されて他者がアクセスできなくなることで可用性が侵害されることが含まれます。
    • 5.1.C.2 データ脆弱性による高リスクは、法律や規制で管理されるような非常に敏感なデータ(例:法的保護対象データ)が、発生可能性の高いエプロイトによって侵害される場合に該当します。
      • 5.1.C.2 の具体例:
        • 空軍の飛行機で使用される次世代ジェットエンジンを開発している企業は、技術仕様書を非暗号化ドライブ上に格納しています。
    • 5.1.C.3 データ脆弱性による中程度リスクは、敏感なデータの暗号化が十分でない、またはアクセス制御が厳しくない場合に該当します。
      • 5.1.C.3 の具体例:
        • 某企業が顧客のPIIをスプレッドシートに格納しており、そのスプレッドシートは小さなキーを用いて暗号化されています。
    • 5.1.C.4 データの脆弱性による低リスクは、通常、より機密性の低い情報が短い暗号鍵で暗号化されたり、アクセス制御が十分でない状態であったりすることに関連しています。
      • 5.1.C.4 の例:
        • 組織のCEOが、暗号化されておらずアクセス制御も設定されていない会社共用ドライブに、役員への私人メモを保管している。

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English
    SQL injection

    Applications 应用程序 are the programs that run on computers, and data is what they process - both are prime targets. If files are stored unencrypted, anyone with access to the drive can read them. If a normal user is given administrative 管理性 privileges, an adversary who steals that account gains sweeping power.

    The biggest application danger is bad user input. When a program does not check what a user types, an adversary can slip in commands - an injection attack 注入攻击. Data validation 数据验证 (checking input meets expected rules) is the defense. Key attacks:

    • SQL injection SQL注入 - inserting SQL commands into an input field to read or change a database.
    • Cross-site scripting (XSS) 跨站脚本 - injecting malicious script into a website that runs in another user's browser.

    What a SQL injection actually looks like

    SQL is a language for querying a database, and its control words are always written in capital letters — SELECT, FROM, WHERE, IN, OR, AND. A login form usually builds a query by pasting what you typed into one:

    An attacker types SQL into the field instead of a name. Two tricks do most of the damage:

    • A condition that is always true. Entering ' OR '1'='1 makes the WHERE clause true for every row, so the database returns every user.
    • A double dash, which begins a comment in SQL. Entering admin' -- ends the name string and comments out the whole rest of the line, including the password check, so the query becomes … WHERE name = 'admin' and the attacker is logged in as the administrator without a password.

    The defence is not to filter for the word SELECT. It is to stop the input being treated as code at all: use parameterised queries 参数化查询 (also called prepared statements), where the database is given the query and the values separately and never mixes them, and add input validation to reject characters the field has no reason to contain.

    • Buffer overflow 缓冲区溢出 - sending more data than a memory buffer 缓冲区 can hold, so it overflows into nearby memory and may run the adversary's code.
    • Directory traversal 目录遍历 - using ../ sequences in a URL to reach files outside the intended folder, such as /etc/passwd.

    We rate data risk by sensitivity: unencrypted military plans are high risk; customer data with a weak key is moderate; low-value data with short keys is low.

    日本語
    SQLインジェクション

    アプリケーションはコンピュータ上で動作するプログラムであり、データはその処理対象 - どちらも主要な標的となる。ファイルが暗号化されていない状態で保存されている場合、ドライブへのアクセス権限を持つ誰しもがそれらを読むことができる。通常のユーザーに管理者権限が与えられ、攻撃者がそのアカウントを盗まれた場合、広範な権限を握られることになる。

    最大のアプリケーション危険性は不適切なユーザー入力にある。プログラムがユーザーの入力を検証しない場合、攻撃者はコマンドを仕込むことができ、これがインジェクション攻撃となる。データ検証(入力が期待されるルールに従っているかを確認すること)が防御手段となる。主要な攻撃:

    • SQLインジェクション:入力フィールドにSQLコマンドを挿入してデータベースの読み出しや変更を行うこと。
    • クロスサイトスクリプティング(XSS):別のユーザーのブラウザ内で実行されるウェブサイトへ悪意のあるスクリプトを注入すること。

    SQLインジェクションの実際の外観

    SQLはデータベースを照会するための言語であり、その制御語はすべて大文字で書かれる - SELECT, FROM, WHERE, IN, OR, AND。ログインフォームは通常、あなたが入力したものを貼り付けてクエリを構築する。

    SELECT * FROM users WHERE name = 'alice' AND password = 'secret'
    

    攻撃者は名前ではなくSQLを入力する。2つのテクニックが大部分の被害をもたらす:

    • 常に真となる条件。' OR '1'='1を入力すると、WHERE節が各行について真となり、データベースはすべてのユーザーを返す。
    • ダブルダッシュ(--)、これはSQLにおいてコメントの開始を表す。admin' --を入力すると名前文字列が終了し、残りの行全体(パスワードチェックを含む)がコメントアウトされる。そのためクエリは… WHERE name = 'admin'となり、攻撃者はパスワードなしで管理者としてログインする。

    防御はSELECTという単語をフィルタリングすることではない。入力をコードとして扱わないようにすることだ:パラメータ化クエリ(プレステートメントとも呼ばれる)を使用し、データベースにクエリと値を別々に提供して混在させず、フィールドに存在する理由のない文字を拒否するために入力検証を追加する。

    • バッファオーバーフロー:メモリバッファが保持できる以上のデータを送信し、近傍のメモリに溢れて攻撃者のコードを実行させる可能性があること。
    • ディレクトリトラバース:URL内で../シーケンスを使用して、意図されたフォルダ外のファイル(例:/etc/passwdなど)にアクセスすること。

    データのリスクを感度に基づいて評価する:暗号化されていない軍事計画は高リスク、弱い鍵を持つ顧客データは中リスク、短い鍵を持つ低価値データは低リスクである。

    Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
    English 日本語
    SQL injection/ˌes kjuː ˈel ɪnˈdʒekʃn/ SQLインジェクション
    Watch lesson · ⁨レッスンを視聴⁩
    5.2

    Protecting Applications and Data: Managerial Controls and Access Controls · ⁨アプリケーションおよびデータの保護:管理統制およびアクセス統制⁩

    Syllabus · ⁨シラバス⁩
    Learning ObjectiveEssential Knowledge

    5.2.A
    Explain how the state or classification of data impacts the type and degree of security applied to that data.

    • 5.2.A.1 Organizations implement specific security controls to comply with legal requirements based on the types of data they collect, store, process, and transmit.
    • 5.2.A.2 Data can be classified by their state.
      • Data at rest are stored on a drive. It is important to protect the physical drive storing the data from destruction or theft. Data at rest can also be encrypted so that if an adversary steals it, they can’t immediately read the data.
      • Data in transit are being sent from one device to another. If the data are being transferred over physical media (e.g., cables) it is important to protect the media. Data in transit can also be encrypted so that if an adversary intercepts it, they can’t immediately read the data.
      • Data in use are being processed by software or a person. Access controls can be used to limit who or what has the ability to use data in different ways (e.g., view or edit). Data must be unencrypted to be used.
    • 5.2.A.3 Organizations often categorize data according to their sensitivity and prioritize a higher degree of security for more sensitive information.
    • 5.2.A.4 Laws and regulations can require certain types of data to be stored, transmitted, and handled according to specific rules.
      • Personally identifiable information (PII) is any data that allows someone to be identified and includes (but is not limited to): name, signature, phone number, address, biometric data (e.g., fingerprints), social security number, date of birth, and email address. The protection of this data is covered by many laws but most notably The Privacy Act of 1974 and for children under the age of 13 the Children’s Online Privacy Protection Act of 1998.
      • Protected health information (PHI) is any data related to an individual’s health, treatment, payment for healthcare at any time and includes (but is not limited to): test results, treatment records, hospital records, doctor visit notes, and health provider payment records. The protection of PHI is included in the Health Insurance Portability and Accountability Act of 1996.
      • Payment card information (PCI) is the data collected by organizations to process payments via cards (e.g., credit cards) and includes the following: name, account number, expiration date, address, and CVV code. The protection of this data is regulated by the Payment Card Industry Data Security Standard (PCI-DSS).
    • 5.2.A.5 Organizations that collect regulated data will label them and have policies that comply with the legal or regulatory requirements for the safe storage, transmission, and handling of these data.

    5.2.B
    Identify managerial controls related to application and data security.

    • 5.2.B.1 A cryptography policy will describe the acceptable encryption protocols and key parameters for an organization and may include:
      • A list of encryption algorithms approved for specific uses
      • Minimum or maximum key lengths
      • Cryptographic key-generation requirements and parameters
      • Cryptographic key-storage requirements
    • 5.2.B.2 A web application security policy will outline the requirements and parameters for testing and mitigating web application vulnerabilities in an organization, and it may include:
      • Parameters for when an application is subject to a security assessment
      • Timelines for remediating vulnerabilities based on level of risk
      • Parameters for how an application security assessment is to be carried out (e.g., using specific tools or according to specific frameworks)

    5.2.C
    Determine an appropriate access control model to protect applications and data.

    • 5.2.C.1 Access control enforces which users or applications (called subjects) can access, modify, add, or remove (called operations) which files or applications (called objects). Access control models describe how to determine which subjects have what type of access to which objects.
    • 5.2.C.2 Role-based access control (RBAC) assigns every subject to a role and defines which roles have which types of access to which objects.
      • Illustrative examples for 5.2.C.2:
        • An example of a role at a company might be “accountant,” and one type of object could be the payroll software. Role-based access could be used to ensure that only subjects who are assigned to the role of “accountant” have access to the payroll software object.
    • 5.2.C.3 Rule-based access control (RuBAC) checks a set of rules to determine what type of access a subject should have for a specific object and then allows or denies types of access based on the rules. This access control model is typically layered on top of another access control model.
      • Illustrative examples for 5.2.C.3:
        • There is a rule that prohibits subjects (even those who would normally have access) from accessing a certain database (the object) outside of local working hours. When a subject attempts to access the database, even if they are authorized to access it, they will be denied access if it is outside the time designated by the rule.
    • 5.2.C.4 Discretionary access control (DAC) gives individual subjects the ability to set the type of access that other subjects have on objects they own. In DAC models some subjects are designated as administrators or super users, and they have the ability to override the access controls established by other subjects.
      • Illustrative examples for 5.2.C.4:
        • Bob creates a file (an object) and decides to give Alice permission to edit the file, to give Frank permission to view the file only, and to deny everyone else access to the file altogether.
    • 5.2.C.5 Mandatory access control (MAC) follows strict rules for which types of access each subject level has for objects that are above their level, at their level, or below their level. Subject and object levels are assigned by an external administrator.
    • 5.2.C.6 The Bell-LaPadula model is a MAC model that is often used by governments and military organizations to control the security of information. This model has the following two important properties:
      • i. The Simple Security Property states that subjects may not read objects that are above their level.
      • ii. The * (Star) Security Property states that subjects may not write to objects below their level.
      • These rules taken together are often summarized as “write up, read down” (WURD).
    • 5.2.C.7 The principle of least privilege is the idea that entities should be given exactly as much access as they need to perform their function and no more.

    5.2.D
    Configure access control settings on a Linux-based system.

    • 5.2.D.1 Authorization is when an entity is granted permission to have a certain type of access to a resource. Access controls are put in place to control which users have what types of access to which data.
    • 5.2.D.2 There are three types of access to a file in Linux that can be set, and they always come in the following order:
      • i. Read access allows a user to view the contents of a file.
      • ii. Write access allows a user to make changes to a file.
      • iii. Execute access allows a user to run a binary file such as a program.
      • These are abbreviated rwx, respectively. If a user only has read and execute permissions (not write), then it would display as r-x. The - symbol indicates the absence of that permission.
    • 5.2.D.3 There are three default entities for which permissions are set and always in this order: (1) the file owner, (2) the file group, and (3) all other users. The three sets are displayed with no spaces (e.g., rwxrwxrwx).
    • 5.2.D.4 To view the current permission settings for a file, use the command ls -l, which will show the current settings for the default entities. If there is a + symbol at the end of the permissions, this means that other permissions have been set for that file and it can be viewed with the getfacl command.
    • 5.2.D.5 To modify the permission settings for a file, use the chmod command. This command can be used with the numeric method or the symbolic method.
    • 5.2.D.6 To use chmod in the numeric method the syntax is chmod ### filename. Each of the three ### represents one of the three entities mentioned above (the owner, the group, other nongroup users).
      • The first # = the owner
      • The second # = the group
      • The third # = other nongroup users
      • The permission for each entity is determined by adding up the values for the types of access to be granted:
      • 0 = no permissions
      • 1 = execute
      • 2 = write
      • 4 = read
      • Therefore 3 sets permission to write and execute, 5 sets permission to read and execute, 6 sets permission to read and write, and 7 sets permission to read, write, and execute.
      • Illustrative examples for 5.2.D.6:
        • The command chmod 750 test would set the permissions for the owner to read, write, and execute, for the group to read and execute, and for everyone else to no access at all.
        • The command chmod 543 test would set the permissions for the owner to read and execute, for the group to read only, and for everyone else to write and execute.
        • The command chmod 777 test would set the permissions for all three entities to read, write, and execute for the file test.
    • 5.2.D.7 To use chmod in the symbolic method the syntax is chmod entity +(or –) permission filename. The entities are the user owner, the group, and other nongroup users. Each entity is represented with a single letter.
      • u = user owner
      • g = group
      • o = others
      • a = all
      • Permission can be either added or removed to any combination of entities.
        • = add the permission
      • – = remove the permission
      • The permissions that can be set are read, write, and execute.
      • r = read
      • w = write
      • x = execute
      • Entities and permissions can be combined in a single command. To add the read and execute permissions for the group and user owner for a file called testfile, the command would be chmod ug+rx testfile.

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English

    Data is classified by its state - at rest 静态数据 (stored on a drive), in transit 传输中数据 (moving between devices), and in use 使用中数据 (being processed). Data at rest and in transit can be encrypted so a thief cannot read it; data in use must be decrypted, so access controls guard it instead.

    Some data types are regulated 受监管 - the law dictates how they must be stored, transmitted and handled - so an organisation must achieve compliance 合规 by matching its controls to the rules. The exam expects you to pair each data type with its governing law:

    Regulated data What it is Governing law
    personally identifiable information (PII) 个人身份信息 anything identifying a person: name, address, SSN, biometrics, date of birth The Privacy Act (1974); COPPA for under-13s
    protected health information (PHI) 受保护健康信息 health, treatment and healthcare-payment records HIPAA (1996)
    payment card information (PCI) 支付卡信息 card number, expiry, CVV, cardholder name PCI-DSS

    An organisation that collects regulated data must label it and hold policies that keep its storage, transmission and handling compliant - the higher the sensitivity, the higher the required degree of security.

    Access control decides which subjects (users) may perform which operations on which objects (files). Four models:

    • Role-based (RBAC) 基于角色的访问控制 - access follows your role (all "accountants" reach the payroll software).
    • Rule-based (RuBAC) 基于规则的访问控制 - access follows conditions (only during business hours), layered on another model.
    • Discretionary (DAC) 自主访问控制 - the owner of a file decides who else may use it.
    • Mandatory (MAC) 强制访问控制 - a central administrator sets strict levels; the Bell-LaPadula model summarises it as "write up, read down".

    A guiding idea across all models is the principle of least privilege 最小权限原则 - give each entity exactly the access it needs and no more.

    On a Linux system, each file has three permissions - read (r), write (w), execute (x) - for three groups: the owner, the group, and others. The chmod command sets them with numbers, adding 4 (read) + 2 (write) + 1 (execute). So chmod 640 means owner read+write (6), group read (4), others nothing (0).

    Worked example. A principal wants only herself to read and edit a file, her staff group to read it, and no one else to touch it. Read+write = 4+2 = 6 for the owner, read = 4 for the group, nothing = 0 for others, giving chmod 640 file. The listing then shows -rw-r-----. To also let the owner run the file as a program you would add execute (7 = 4+2+1), giving chmod 740.

    日本語

    データは状態によって分類される - 静止中(ドライブに保存中)、転送中(デバイス間で移動中)、使用中(処理中)。静止中および転送中のデータは暗号化されており、泥棒が読むことができないようにし、使用中のデータは復号化される必要があるため、代わりにアクセス統制がそれを守る。

    一部のデータ種別は規制対象である - 法律がその保管、送信、取扱い方法を規定している - 因此組織は统制をルールに合わせることでコンプライアンスを達成しなければならない。試験では各データ種別を管轄する法律とペアにすることを期待している:

    規制対象データ 内容 管轄法
    PII(個人識別情報) 個人を特定できる情報:氏名、住所、SSN、生体情報、生年月日 プライバシー法(1974年);COPPA(13歳未満向け)
    PHI(保護医療情報) 健康、治療、医療費請求の記録 HIPAA(1996年)
    PCI(決済カード情報) カード番号、有効期限、CVV、カードホルダー名 PCI-DSS

    規制対象データを収集する組織は、それをラベル付けし、保存、送信、処理がコンプライアンスに準拠するためのポリシーを保持する必要があります。敏感性の高いデータほど、必要なセキュリティレベルも高くなります。

    アクセス制御は、どの主体(ユーザー)がどのオブジェクト(ファイル)に対してどの操作を行うかを決定します。主なモデルは4つあります:

    • ロールベース(RBAC) - アクセス権限は役割に基づきます(「会計担当者」全員が給与計算ソフトにアクセス可能)。
    • ルールベース(RuBAC) - アクセス権限は条件(営業時間中のみなど)に従い、他のモデルの上に重ねて適用されます。
    • 裁量式(DAC) - ファイルの所有者が、誰がそのファイルを使用できるかを決めます。
    • 強制式(MAC) - 中央管理者が厳格なレベルを設定します。Bell-LaPadulaモデルではこれを「書き上げ、読み下」(write up, read down)と要約できます。
    4つのアクセス制御モデルが、どの主体がどのオブジェクトにアクセスできるか、およびその方法を示しています
    4つのアクセス制御モデルが、どの主体がどのオブジェクトにアクセスできるか、およびその方法を示しています

    すべてのモデル共通の指導原則として最小特権の原則があります。各エンティティには、必要以上のアクセス権限を与えず、必要な分だけ付与します。

    Linuxシステムでは、各ファイルに対して3つのグループ(所有者、グループ、その他)に対し、3つの権限(読取 (r)、書込み (w)、実行 (x))が設定されます。chmod コマンドは数字を使ってこれらの権限を設定し、数値は読取(4)+書込み(2)+実行(1)で計算されます。したがって、chmod 640 は所有者が読取+書込み(6)、グループが読取(4)、その他がなし(0)を意味します。

    Linuxファイル権限:所有者、グループ、その他に対する読取・書込み・実行の表示
    Linuxファイル権限:所有者、グループ、その他に対する読取・書込み・実行の表示

    ** worked example(実例解説)。ある校長が、自身だけがファイルを読取して編集でき、所属スタッフグループが読取でき、他者は一切アクセスできないようにしたいとします。読取+書込み=4+2=6(所有者)、読取=4(グループ)、なし=0(その他)なので、chmod 640 file となります。リスト表示では -rw-r----- が表示されます。さらに所有者にファイルをプログラムとして実行させる場合、実行権限を追加して7 = 4+2+1 とし、chmod 740 となります。

    Explore · ⁨探索⁩

    Which access-control model fits the rule?

    Each access-control model has a different decider: RBAC by your role, RuBAC by a condition, DAC by the file's owner, and MAC by a central administrator's levels.

    5.3

    Protecting Stored Data with Cryptography · ⁨暗号学による保存データの保護⁩

    Syllabus · ⁨シラバス⁩
    English

    Learning Objective 5.3.A: Explain how encryption can be used to protect files.

    • 5.3.A.1 The purpose of cryptography is to hide information. A cryptographic algorithm defines a process for encrypting and decrypting information. Encryption is the process of hiding the information, and decryption is the process of reversing the encryption to retrieve the original information.
    • 5.3.A.2 An encryption algorithm defines a process for combining the information to be encrypted with a predefined key. The information to be encrypted is called the plaintext. The output of the encryption algorithm is called the ciphertext.
    • 5.3.A.3 The number of possible keys that can be used in an encryption algorithm is called the keyspace. The larger the keyspace, the longer it will take an adversary to discover the correct key by random chance.
    • 5.3.A.4 Cryptographic algorithms are classified by whether they use one key or two keys.
      • Symmetric encryption algorithms use the same key to encrypt and decrypt information.
      • Asymmetric encryption algorithms use two different keys—one to encrypt information and the other to decrypt information.
    • 5.3.A.5 Cryptographic algorithms are also classified by whether they process information one bit at a time or in fixed-size chunks of bits.
      • Block encryption handles information in fixed-size chunks called blocks, producing an output block for each input block.
      • Stream encryption handles input information continuously, producing output one element at a time.

    Learning Objective 5.3.B: Apply symmetric encryption algorithms to encrypt and decrypt data.

    • 5.3.B.1 Computer-based encryption algorithms operate on binary data. The most common symmetric encryption algorithm is the Advanced Encryption Standard (AES). AES encryption is used to secure Wi-Fi transmissions, internet browsing, file encryption on disks, and hardware-level encryption on processors.
    • 5.3.B.2 AES is a symmetric key block cipher that encrypts data in 128-bit blocks (16 bytes). AES can operate with keys of varying lengths. Longer keys produce more secure encryption but require more time to encrypt and decrypt.
    • 5.3.B.3 Symmetric encryption and decryption can be performed using the command line, specialized software, or web-based tools.
      • On a command line interface, users can encrypt or decrypt with OpenSSL.
      • Specialized software like AES Crypt is an open source tool that can encrypt and decrypt files.
      • There are many web-based tools for encrypting and decrypting files.
    • 5.3.B.4 Using OpenSSL in a CLI, a user can encrypt and decrypt a file using the following commands (note that the encryption key is derived from the password provided):
      • To encrypt a file named test with AES using a 128-bit key, use the command: openssl enc -aes-128-cbc -e -in test -k password -out test.enc
      • To decrypt the encrypted file using the same key, use the command: openssl enc -aes-128-cbc -d -in test.enc -k password -out text
    日本語

    学習目標 5.3.A: 暗号化を用いてファイルを保護する方法を説明する。

    • 5.3.A.1 暗号学の目的は情報を隠すことです。暗号アルゴリズムは、情報を暗号化および復号化するプロセスを定義します。暗号化は情報を隠すプロセスであり、復号化は暗号化を逆転させて元の情報を取得するプロセスです。
    • 5.3.A.2 暗号化アルゴリズムは、暗号化する情報と事前に定義された鍵を組み合わせるプロセスを定義する。暗号化する情報は平文(plaintext)と呼ばれる。暗号化アルゴリズムの出力は暗号文(ciphertext)と呼ばれる。
    • 5.3.A.3 暗号化アルゴリズムで使用可能な鍵の数のことをキー空間(keyspace)という。キー空間が大きいほど、攻撃者が偶然に正しい鍵を見つけるのにより長い時間がかかる。
    • 5.3.A.4 暗号アルゴリズムは、単一鍵を使用するか、二重鍵を使用するかによって分類される。
      • 対称暗号アルゴリズムは、情報の暗号化と復号に同じ鍵を使用する。
      • 非対称暗号アルゴリズムは、異なる2つの鍵を使用する—oneは情報の暗号化に使用し、もう一方は復号に使用する。
    • 5.3.A.5 暗号アルゴリズムは、情報を1ビットずつ処理するか、固定サイズのビット塊として処理するかによって分類される。
      • ブロック暗号は、ブロックと呼ばれる固定サイズの塊で情報を処理し、各入力ブロックに対して出力ブロックを生成する。
      • ストリーム暗号は、入力情報を連続的に処理し、出力を1要素ずつ生成する。

    学習目標 5.3.B: 対称暗号アルゴリズムを用いてデータを暗号化および復号する。

    • 5.3.B.1 コンピュータベースの暗号化アルゴリズムはバイナリデータに対して動作します。最も一般的な対称暗号化アルゴリズムは高度暗号標準 (AES) です。AES暗号化は、Wi-Fi通信の保護、インターネット閲覧、ディスク上のファイル暗号化、プロセッサレベルでのハードウェア暗号化に使用されています。
    • 5.3.B.2 AESは対称鍵ブロック暗号であり、128ビットブロック(16バイト)単位でデータを暗号化する。AESは多様な長さの鍵で動作できる。長い鍵はより安全な暗号化を実現するが、暗号化および復号に要する時間も増える。
    • 5.3.B.3 対称暗号化と復号は、コマンドライン、専用ソフトウェア、またはWebベースのツールを使用して実行できる。
      • コマンドラインインターフェースでは、OpenSSLを使用して暗号化や復号を行うことができる。
      • AES Cryptのような専用ソフトウェアは、ファイルを暗号化・復号できるオープンソースツールである。
      • ファイルの暗号化および復号化には、多くのWebツールが存在します。
    • 5.3.B.4 CLIでOpenSSLを使用する場合、以下のコマンドを使用してファイルの暗号化・復号を行うことができる(注:暗号鍵は提供されたパスワードから導出される)。
      • 128ビット鍵を使用してAESで「test」という名前のファイルを暗号化する場合、以下のコマンドを使用する:openssl enc -aes-128-cbc -e -in test -k password -out test.enc
      • 同じ鍵を使用して暗号化ファイルを復号する場合、以下のコマンドを使用する:openssl enc -aes-128-cbc -d -in test.enc -k password -out text

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English
    Symmetric vs asymmetric encryption
    Hashing and the avalanche effect

    Cryptography 密码学 hides information. An encryption algorithm combines the plaintext 明文 with a key 密钥 to produce ciphertext 密文; decryption reverses it. The keyspace 密钥空间 is the number of possible keys - the bigger it is, the longer an adversary needs to guess. An n-bit key has a keyspace of $2^n$.

    Symmetric encryption 对称加密 uses the same key to encrypt and decrypt. The standard is AES 高级加密标准, a block cipher 分组密码 that works on 128-bit blocks and secures Wi-Fi, browsing, and stored files. Because both sides need the same secret key, sharing that key safely is the challenge.

    日本語
    エニグマ機械:暗号学は保存中および通信中のデータを盗聴者から守ります
    エニグマ機械:暗号学は保存中および通信中のデータを盗聴者から守ります
    対称鍵暗号化と非対称鍵暗号化
    ハッシュ関数と雪崩効果

    暗号学は情報を隠蔽します。暗号化アルゴリズムは平文と鍵を組み合わせて密文を生成し、復号はその逆を行います。キー空間は利用可能な鍵の総数を指し、大きいほど攻撃者が推測するのに時間がかかります。nビット鍵のキー空間は $2^n$ です。

    対称鍵暗号化は、暗号化と復号に同じ鍵を使用します。標準規格はAESであり、ブロック暗号の一種で128ビットブロックで動作し、Wi-Fi、ブラウザ、保存ファイルなどを保護します。両側が同じ秘密鍵を共有するため、その鍵を安全に共有することが課題となります。

    第二次世界大戦時代のエニグ暗号機:鍵とローター
    エニグマ機械はローターでメッセージを乱すことで暗号化しましたが、これは早期の脆弱な暗号化の例です
    Explore · ⁨探索⁩

    Encrypt a message by shifting letters

    Encryption combines plaintext with a key to make ciphertext. In this simple cipher the key is the shift amount; only someone who knows the shift can decrypt the message back.

    Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
    English 日本語
    Applications/ˌæplɪˈkeɪʃnz/ 応用
    administrative/ədˈmɪnɪstrətɪv/ 行政的
    injection attack/ɪnˈdʒekʃn əˈtæk/ インジェクション攻撃
    Data validation/ˈdeɪtə ˌvælɪˈdeɪʃn/ データ検証
    Cross-site scripting (XSS)/krɒs saɪt ˈskrɪptɪŋ/ 跨サイトスクリプト (XSS)
    parameterised queries/ˌpærəˈmetəraɪzd ˈkwɪərɪz/ パラメータ化クエリ
    Buffer overflow/ˈbʌfə ˌəʊvəˈfləʊ/ バッファオーバーフロー
    buffer/ˈbʌfə/ バッファー
    Directory traversal/daɪˈrektəri træˈvɜːsl/ ディレクトリトラバーサル
    at rest/æt rest/ 静止している
    in transit/ɪn ˈtrænsɪt/ 移行中
    in use/ɪn juːs/ 使用中
    regulated/ˈreɡjʊleɪtɪd/ 規制対象
    compliance/kəmˈplaɪəns/ コンプライアンス
    personally identifiable information (PII)/ˈpɜːsənəli aɪˈdentɪfaɪəbl ˌɪnfəˈmeɪʃn/ 個人識別情報 (PII)
    protected health information (PHI)/prəˈtektɪd helθ ˌɪnfəˈmeɪʃn/ 保護医療情報 (PHI)
    payment card information (PCI)/ˈpeɪmənt kɑːd ˌɪnfəˈmeɪʃn/ 決済カード情報 (PCI)
    Role-based (RBAC)/rəʊl beɪst/ ロールベース (RBAC)
    Rule-based (RuBAC)/ruːl beɪst/ ルールベース (RuBAC)
    Discretionary (DAC)/dɪˈskreʃənəri/ 裁量制 (DAC)
    Mandatory (MAC)/ˈmændətəri/ 強制制 (MAC)
    principle of least privilege/ˈprɪnsɪpl ɒv liːst ˈprɪvɪlɪdʒ/ principle of least privilege(最小特権の原則)
    Cryptography/krɪpˈtɒɡrəfi/ 暗号学
    plaintext/ˈpleɪntekst/ 平明文
    key/kiː/ キー
    ciphertext/ˈsaɪfətekst/ 暗号文
    keyspace/ˈkiːspeɪs/ キースペース
    Symmetric encryption/sɪˈmetrɪk enˈkrɪpʃn/ 対称暗号化
    AES/ˌeɪ iː ˈes/ AES
    block cipher/blɒk ˈsaɪfə/ ブロック暗号
    Asymmetric encryption/ˌeɪsɪˈmetrɪk enˈkrɪpʃn/ 非対称暗号化
    key pair/kiː peə/ 鍵ペア
    public key/ˈpʌblɪk kiː/ 公開鍵
    private key/ˈpraɪvət kiː/ 秘密鍵
    elliptic curve cryptography (ECC)/ɪˈlɪptɪk kɜːv krɪpˈtɒɡrəfi/ 楕円曲線暗号 (ECC)
    Watch lesson · ⁨レッスンを視聴⁩
    5.4

    Asymmetric Cryptography · ⁨非対称暗号学⁩

    Syllabus · ⁨シラバス⁩
    English

    Learning Objective 5.4.A: Determine the appropriate asymmetric key to use when sending or receiving encrypted data.

    • 5.4.A.1 Asymmetric encryption allows users to communicate securely without prearranging a shared secret key.
    • 5.4.A.2 When using asymmetric encryption, each entity that will be receiving data must first generate a key pair. Key pairs are binary strings of equal length that are generated at the same time through a mathematical process. One key is designated as the public key and the other as the private key. The keys are mathematical inverses of each other— each key reverses its partner. Either key can be used to encrypt information, but only the other key in the key pair will then be able to decrypt it.
    • 5.4.A.3 Once the receiver generates the key pair, the private key must be stored securely. If the private key is exposed, shared, stolen, corrupted, or compromised the key pair must be deleted and a new key pair must be generated, because the security of the encryption algorithm rests on the security of the private key. The public key is published for anyone to view and use.
    • 5.4.A.4 To send information securely to someone, the sender will use the receiver’s public key to encrypt the data and send it. Only the receiver who has the private key will be able to decrypt and read the information.

    Learning Objective 5.4.B: Explain why the length of a key impacts the security of encrypted data.

    • 5.4.B.1 Longer keys result in larger keyspaces. For binary keys, an n-bit length key has a keyspace of $2^n$.
    • 5.4.B.2 Using an application to randomly guess an n-bit length encryption key means that on average an adversary will be able to guess the correct key in $2^n \div 2$ (or $2^{n-1}$) guesses.
    • 5.4.B.3 Although longer keys are more secure, they also require more time to encrypt and decrypt messages.
    • 5.4.B.4 Computational processing power and efficiency continue to improve, allowing software to guess keys faster. Key-length recommendations for both symmetric and asymmetric encryption algorithms are periodically increased to account for increased processing power.
    • 5.4.B.5 Key-length comparison is only valid when comparing keys for the same cryptographic algorithm.
      • Illustrative examples for 5.4.B.5:
        • An AES 256-bit key is more secure than an AES 128-bit key.
        • An RSA 4096-bit key is more secure than an RSA 2048-bit key.
        • RSA and AES keys cannot be directly compared to one another in determining the level of security.

    Learning Objective 5.4.C: Apply asymmetric encryption algorithms to encrypt and decrypt data.

    • 5.4.C.1 Common asymmetric encryption algorithms include RSA and elliptic curve cryptography (ECC). Asymmetric algorithms are used in many applications, including digital signatures and digital certificates.
    • 5.4.C.2 As with symmetric encryption, asymmetric encryption and decryption can be performed using the command line, specialized software, or web-based tools.
      • On a command line interface, users can encrypt or decrypt with OpenSSL.
      • Specialized software like RSA Encryption Tool is an open source tool that can encrypt and decrypt files.
      • There are many web-based tools for encrypting and decrypting files.
    • 5.4.C.3 In a CLI, a user can generate an asymmetric key pair and encrypt or decrypt files as necessary.
      • To generate a 2048-bit RSA key pair and save the key to a file named rsa.pem use the command: openssl genrsa -out rsa.pem 2048
      • To extract the public key from rsa.pem into a file named public.pem, use the command: openssl rsa -pubout -in rsa.pem -outform PEM -out public.pem
      • To encrypt the file test using RSA encryption and the key file public.pem, use the command: openssl pkeyutl -encrypt -pubin -inkey public.pem -in test -out test.enc
      • To decrypt the test.enc file using the rsa.pem file, run the command: openssl pkeyutl -decrypt -inkey rsa.pem -in test.enc -out test
    日本語

    学習目標 5.4.A: 暗号化データの送信または受信時に適切な非対称鍵を選択する。

    • 5.4.A.1 非対称暗号化は、事前の合意による共有秘密鍵なしにユーザーが安全に通信することを可能にする。
    • 5.4.A.2 非対称暗号化を使用する場合、データを受信する各エンティティはまず鍵ペアを生成する必要があります。鍵ペアは同じ数学的プロセスによって同時に生成される等長のバイナリ文字列です。一方の鍵は公開鍵として、もう一方は秘密鍵として指定されます。これらの鍵は互いに数学的に逆の性質を持ち—oneの鍵が相手の鍵を逆転させます。どちらの鍵でも情報を暗号化できますが、暗号化した後には鍵ペアのもう片方の鍵のみで復号できます。
    • 5.4.A.3 受信者が鍵ペアを生成した後、秘密鍵は安全に保管されなければならない。もし秘密鍵が漏洩、共有、盗難、破損、または侵害された場合、暗号アルゴリズムの安全性は秘密鍵の安全性に依存するため、その鍵ペアは削除され、新しい鍵ペアが生成されなければならない。公開鍵は誰でも表示して使用できるように公開される。
    • 5.4.A.4 情報を安全に誰かに送る場合、送信者は受信者の公開鍵を使用してデータを暗号化して送信する。秘密鍵を持つ受信者だけが、その情報を復号して読み取ることができる。

    学習目標 5.4.B: 鍵の長さが暗号化データのセキュリティに影響を与える理由を説明する。

    • 5.4.B.1 長い鍵ほど大きな鍵空間となります。バイナリ鍵の場合、nビット長键の鍵空間は $2^n$ となります。
    • 5.4.B.2 アプリケーションを使用してnビット長の暗号鍵をランダムに推測する場合、平均して攻撃者が正しい鍵を $2^n \div 2$ (または $2^{n-1}$ )回の試行で当てることになる。
    • 5.4.B.3 長い鍵はより安全だが、メッセージの暗号化・復号にもより時間がかかる。
    • 5.4.B.4 計算処理能力と効率性は向上を続けており、ソフトウェアがより速く鍵を推測できるようになっている。対称暗号および非対称暗号アルゴリズムの鍵長推奨値は、処理能力の向上を考慮して定期的に引き上げられている。
    • 5.4.B.5 鍵長の比較は、同じ暗号アルゴリズムの鍵同士を比較する場合にのみ有効である。
      • 5.4.B.5 の例示:
        • AES 256ビット鍵は、AES 128ビット鍵よりも安全である。
        • RSA 4096ビット鍵は、RSA 2048ビット鍵よりも安全である。
        • RSA鍵とAES鍵は、セキュリティレベルを決定するために直接比較することはできない。

    学習目標 5.4.C: 非対称暗号アルゴリズムを用いてデータを暗号化および復号する。

    • 5.4.C.1 一般的な非対称暗号アルゴリズムには、RSAと楕円曲線暗号(ECC)が含まれる。非対称アルゴリズムは、デジタル署名やデジタル証明書など、多くのアプリケーションで使用される。
    • 5.4.C.2 対称暗号と同様に、非対称暗号化と復号は、コマンドライン、専用ソフトウェア、またはWebベースのツールを使用して実行できる。
      • コマンドラインインターフェースでは、OpenSSLを使用して暗号化や復号を行うことができる。
      • RSA暗号化ツールなどの専用ソフトウェアはオープンソースツールであり、ファイルの暗号化と復号が可能です。
      • ファイルの暗号化および復号化には、多くのWebツールが存在します。
    • 5.4.C.3 コマンドラインインターフェース(CLI)では、ユーザーは必要に応じて非対称鍵ペアを生成し、ファイルを暗号化または復号化できます。
      • 2048ビットのRSA鍵ペアを生成し、rsa.pemという名前のファイルに保存するには、以下のコマンドを使用します:openssl genrsa -out rsa.pem 2048
      • rsa.pemから公開鍵を抽出してpublic.pemという名前のファイルに保存するには、以下のコマンドを使用します:openssl rsa -pubout -in rsa.pem -outform PEM -out public.pem
      • testファイルにRSA暗号化を用いて暗号化し、公開鍵ファイルpublic.pemを使用するには、以下のコマンドを使用します:openssl pkeyutl -encrypt -pubin -inkey public.pem -in test -out test.enc
      • test.encファイルをrsa.pemファイルを使用して復号化するには、以下のコマンドを実行します:openssl pkeyutl -decrypt -inkey rsa.pem -in test.enc -out test

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English

    Asymmetric encryption 非对称加密 solves the key-sharing problem with a key pair 密钥对 - a public key 公钥 anyone may see and a private key 私钥 kept secret. The keys are mathematical inverses: whatever one locks, only the other unlocks. To send you a secret, I encrypt with your public key, and only your private key can decrypt it - so we never had to share a secret in advance.

    Longer keys mean larger keyspaces and more security, but slower encryption. Common asymmetric algorithms are RSA and elliptic curve cryptography (ECC) 椭圆曲线密码学, used in digital signatures and certificates. Remember: you can only compare key lengths within the same algorithm - an RSA 4096-bit key is not directly comparable to an AES 256-bit key.

    日本語

    非対称暗号化は、鍵ペアを用いて鍵の共有問題を解決する。これは、誰が見てもよい公開鍵と、秘密に kept される秘密鍵の組み合わせである。これらの鍵は数学的な逆数関係にあるため、片方の鍵でロックした情報は、もう片方の鍵しか開けられない。あなたに秘密を送る際、私はあなたの公開鍵で暗号化を行うため、あなたの秘密鍵のみで復号可能となり、事前に秘密を共有する必要がない。

    非対称暗号化:公開鍵で暗号化し、秘密鍵で復号する様子
    非対称暗号化:公開鍵で暗号化し、秘密鍵で復号する様子

    長い鍵は大きなキー空間と高いセキュリティを提供しますが、暗号化速度は遅くなります。一般的な非対称アルゴリズムには、デジタルサインや証明書に使用されるRSAと楕円曲線暗号(ECC) があります。なお、鍵の長さの比較は同じアルゴリズム内でのみ可能です。RSA 4096ビット鍵とAES 256ビット鍵を直接比較することはできません。

    パッドロック:暗号化によりデータがロックされ、対応する鍵を持つ者のみが開くことができます
    パッドロック:暗号化によりデータがロックされ、対応する鍵を持つ者のみが開くことができます
    Watch lesson · ⁨レッスンを視聴⁩
    5.5

    Protecting Applications · ⁨アプリケーションの保護⁩

    Syllabus · ⁨シラバス⁩
    English

    Learning Objective 5.5.A: Identify the application security principles of secure by design and security by default.

    • 5.5.A.1 Secure by design is an initiative that encourages companies to include security in all phases of product development including design. When organizations implement secure by design, security is a design principle not just a technical feature.
    • 5.5.A.2 Secure by design includes three design principles:
      • i. Companies should take ownership of customer security outcomes. Companies should build products that meet the security needs of their customers.
      • ii. Companies should embrace radical transparency and accountability. Sharing relevant security-related product news and updates quickly increases security for everyone.
      • iii. Companies should build organizational structure and leadership to implement secure by design. Companies need leaders who are focused on security and have a security-first posture.
    • 5.5.A.3 Secure by design includes the concept of secure by default, which is the idea that security features for software and devices should be enabled by default. Devices and software should be secure to use out of the box, with security features already enabled.

    Learning Objective 5.5.B: Explain how user input sanitization protects applications.

    • 5.5.B.1 When users enter input into an application, the application typically encases that input in special characters to process it. The characters that encase the user input are called control characters and include the single quote, the double quote, and the semicolon.
    • 5.5.B.2 When creating a program that takes user input, programmers should use a function to verify that user input meets their expected criteria and does not include any control characters that could be used to manipulate the system. This verification function can sanitize user input by removing potentially malicious characters, or it can give the user an error and force the user to provide different input. This can protect against many application attacks, including:
      • SQL injection attacks
      • XSS attacks
      • Directory traversal attacks
    日本語

    学習目標 5.5.A: デザイン時のセキュリティとデフォルトでのセキュリティというアプリケーションセキュリティの原則を特定する。

    • 5.5.A.1 デザイン時のセキュリティとは、設計を含む製品開発のすべてのフェーズでセキュリティを組み込むことを推奨するイニシアチブです。組織がデザイン時のセキュリティを導入する場合、セキュリティは単なる技術的機能ではなく、設計原則となります。
    • 5.5.A.2 デザイン時のセキュリティには3つの設計原則が含まれます:
      • i. 企業は顧客のセキュリティ成果に対して責任を持つべきです。企業は顧客のセキュリティニーズを満たす製品を構築すべきです。
      • ii. 企業は過激な透明性と説明責任を受け入れるべきです。関連するセキュリティに関する製品ニュースやアップデートを迅速に共有することで、すべての人のセキュリティ向上につながります。
      • iii. 企業は、デザイン時のセキュリティを実現するための組織体制とリーダーシップを構築すべきです。企業には、セキュリティに注力し、セキュリティファーストの姿勢を持つリーダーが必要です。
    • 5.5.A.3 デザイン時のセキュリティには、デフォルトでのセキュリティという概念も含まれており、これはソフトウェアやデバイスのセキュリティ機能がデフォルトで有効になっているべきであるという考えです。デバイスやソフトウェアは、箱を開けた状態ですぐに使用でき、セキュリティ機能がすでに有効化された状態で安全に使えるべきです。

    学習目標 5.5.B: ユーザー入力サンitizedization(正則化)がアプリケーションをどのように保護するかを説明する。

    • 5.5.B.1 ユーザーが入力をアプリケーションに入力すると、アプリケーションはその入力を処理するために通常、特殊文字で囲みます。ユーザー入力を囲むこれらの文字を制御文字と呼び、単一引用符、二重引用符、セミコロンが含まれます。
    • 5.5.B.2 ーザー入力を扱うプログラムを作成する際、プログラマーは関数を使用して、ユーザー入力が期待される基準を満たしており、システムを操作するために使用される可能性のある制御文字が含まれていないことを確認する必要があります。この検証関数は、潜在的に悪質な文字を除去してユーザー入力を正則化できるか、あるいはエラーを返してユーザーに別の入力を強制することができます。これにより、次のような多くのアプリケーション攻撃から守ることができます:
      • SQLインジェクション攻撃
      • XSS攻撃
      • ディレクトリトラバーサル攻撃

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English

    Two design principles keep applications safe from the start. Secure by design 安全设计 builds security into every phase of development, not as an afterthought. Secure by default 默认安全 means the product ships with its security features already enabled - safe straight out of the box.

    Secure by design rests on three principles a company must adopt: (1) take ownership of its customers' security outcomes rather than shifting blame onto users, (2) embrace radical transparency and accountability – sharing security-relevant news and updates quickly so everyone becomes safer, and (3) build the organisational structure and leadership that makes security a first-class goal.

    The key defense against injection attacks is input sanitization 输入清理. Certain special characters 特殊字符 - the single quote, double quote, and semicolon - can be used to manipulate a system, so a good program removes or rejects them before processing. Sanitization protects against SQL injection, XSS, and directory-traversal attacks alike.

    日本語

    アプリケーションを最初から安全にするための2つの設計原則があります。Secure by design(設計段階からのセキュリティ) は、セキュリティを後付けではなく開発の各フェーズに組み込むことです。Secure by default(デフォルトでのセキュリティ有効化) は、製品出荷時にすでにセキュリティ機能が有効化されており、箱を開けた瞬間から安全であることを意味します。

    Secure by design は企業が採用すべき3つの原則に基づいています。(1) ユーザーへの責任転嫁ではなく、顧客のセキュリティ成果に対する自身の所有権を担うこと、(2) 極端な透明性と説明責任を擁護し、セキュリティ関連のニュースやアップデートを迅速に共有することで皆をより安全にすること、(3) セキュリティを最優先事項とするための組織体制とリーダーシップを構築すること。

    インジェクション攻撃に対する最大の防御手段は入力サンプリザイゼーションです。単引号、二重引用符、セミコロンなどの特定の特殊文字はシステムを操作するために利用される可能性があるため、適切なプログラムは処理前にそれらを除去または拒否します。サンプリザイゼーションはSQLインジェクション、XSS、ディレクトリトラバーサル攻撃などから保護します。

    Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
    English 日本語
    Secure by design/sɪˈkjʊə baɪ dɪˈzaɪn/ 設計による安全性
    Secure by default/sɪˈkjʊə baɪ dɪˈfɒlt/ デフォルトでの安全性
    input sanitization/ˈɪnpʊt ˌsænɪtaɪˈzeɪʃn/ 入力Sanitization
    special characters/ˈspeʃl ˈkærɪktəz/ 特殊文字
    accounting/əˈkaʊntɪŋ/ 会計
    honeypot/ˈhʌnɪpɒt/ ハニーポット
    data loss prevention (DLP)/ˈdeɪtə lɒs prɪˈvenʃn/ データ紛失防止 (DLP)
    5.6

    Detecting Attacks on Data and Applications · ⁨データおよびアプリケーションに対する攻撃の検出⁩

    Syllabus · ⁨シラバス⁩
    Learning ObjectiveEssential Knowledge

    5.6.A
    Explain how to detect attacks on data.

    • 5.6.A.1 Devices track and log when data are accessed and by whom. The process of recording and monitoring user activities is called accounting. Analysis of these logs can reveal malicious activity when an adversary attempts to access, copy, move, or delete data. Suspicious activity can include:
      • Accessing files that aren’t typically accessed
      • Accessing files or applications outside of a user’s normal patterns (including time of day, location, and device type)
      • Attempts to delete or copy sensitive files
    • 5.6.A.2 A honeypot is a file that appears as if it contains valuable data (e.g., credit card information, PII, passwords), but the data in the file are fake. A system can alert defenders if someone attempts to access the honeypot. Since the honeypot is a fake file, there is no legitimate reason to be accessing it, and any attempted access would be an indicator of malicious activity.
    • 5.6.A.3 Cryptographic hash functions can generate a digest for data and can reveal if data have been altered. If a file has changed unexpectedly, this can be a sign of malicious activity.

    5.6.B
    Determine controls for detecting attacks against applications or data.

    • 5.6.B.1 Cost is a criterion in determining detective controls. Detective controls like honeypots and using hash values to check data integrity are inexpensive. Some organizations invest in third-party data loss prevention (DLP) services, which monitor data access, usage, and transmission by users throughout the organization to detect suspicious activity; DLP services provide strong detection capabilities at a higher cost.
    • 5.6.B.2 Sensitivity or criticality of data or applications is a criterion in determining detective controls. More sensitive or critical data or applications are more likely targets of an adversary and should be monitored more closely.
    • 5.6.B.3 Classification of data is a criterion in determining detective controls. Data that have been classified as private, educational, healthcare, or financial often have legal or regulatory detection and monitoring requirements.

    5.6.C
    Evaluate the impact of a method for detecting attacks against an application or data.

    • 5.6.C.1 To operate at an effective speed, log analysis needs to be augmented with some automation. Honeypots offer near instantaneous detection capabilities.
    • 5.6.C.2 Some DLP tools, honeypots, and realtime automated log analysis provide alerts as an attack is happening. These tools allow for a prompt response that can stop an attack before it does more harm. Retrospective log analysis and the use of cryptographic hashes to verify data integrity identify attacks after they have occurred.
    • 5.6.C.3 False negatives can occur in applications and data attack detection. Cryptographic hash functions only detect if data have been altered. An adversary could view and steal data without altering it, and a cryptographic hash function would not detect this. Honeypots cannot detect adversaries that do not attempt to access them.

    5.6.D
    Identify whether a file has been altered by verifying its hash.

    • 5.6.D.1 Cryptographic hash functions can help identify changes in a file because they are repeatable: the same input always produces the same output for a given hash function.
    • 5.6.D.2 Hashes can be calculated using the command line on a computer, a website, or specialized software.
      • In Windows Powershell, if a user wanted to generate the SHA256 hash for a file named testfile, they would use the command: Get-FileHash testfile -Algorithm SHA256
      • In BASH the same could be accomplished with the command: sha256sum testfile
      • In zsh, the common command line terminal on Apple computers, this could be accomplished with the command: shasum -a 256 testfile
    • 5.6.D.3 A file can be hashed and its hash output recorded. Then it can be hashed again later, and the second hash output can be compared to the previous hash output for the same file. If a file’s hash changes, then the file was altered between when the first and second hashes were generated.

    5.6.E
    Apply detection techniques to identify and report indicators of application attacks by analyzing log files.

    • 5.6.E.1 SQL injection attacks can be detected by reviewing application and server logs of user input for SQL control words and symbols such as:
      • A single (') or double (") quote character
      • Boolean conditions like OR 1=1
      • A double dash (which indicates a comment in SQL): --
      • SQL control words (always in capital letters) like WHERE, IN, FROM
    • 5.6.E.2 XSS attacks can be detected by reviewing user input for suspicious tags, particularly the tag.
    • 5.6.E.3 For web applications, buffer overflows can be detected by checking the amount of data the user is sending to the web application in their request. The fields commonly checked are the URL length, cookie length, query string length, and total request length. Long strings in any of these fields can be an indicator of an attempted buffer overflow attack.
    • 5.6.E.4 Directory traversal attacks can be detected by reviewing application and server logs. HTTP GET requests that include paths with sequences of ../ are indicators of an adversary attempting a directory traversal.

    Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

    English

    To detect data attacks, systems perform accounting 审计记录 - logging who accessed what and when. But logs are huge, so log analysis must be automated to run at a useful speed; a human reading raw logs is far too slow. A clever complement is a honeypot 蜜罐 - a fake file that looks valuable; since no one has a real reason to open it, any access is a clear, near-instantaneous sign of an attack. Watch especially for attempts to delete or copy sensitive files. Cryptographic hashes also help: re-hash a file and compare - if the digest changed, the file was altered.

    Choosing detective controls means weighing cost (honeypots are cheap; a data loss prevention (DLP) 数据泄露防护 service is powerful but pricey) against the sensitivity of the data. To read a specific attack from logs, look for its signature: SQL injection shows OR 1=1 and --; XSS shows <script> tags; directory traversal shows ../ sequences; a buffer overflow shows unusually long input strings.

    Checking that a file has not been altered

    A cryptographic hash turns a file of any size into a short fixed-length value. Change one byte of the file and the hash changes completely, so comparing a downloaded file's hash with the one the publisher lists proves the file arrived intact. You do this at the command line:

    Shell Command
    BASH (Linux, and most servers) sha256sum testfile
    zsh, the usual terminal on Apple computers shasum -a 256 testfile

    Both print the SHA-256 hash of testfile. If it differs from the published value by even one character, the file has been altered — by corruption in transit, or by an attacker who replaced it.

    ⚠️ A hash proves integrity, not authenticity. An attacker who can replace the file on a web page can usually replace the published hash beside it too; that is why a signed hash, or one fetched over a separate trusted channel, is stronger evidence.

    日本語

    データ攻撃を検出するため、システムは会計処理(ログ記録)を実行し、誰が・何を・いつアクセスしたかを記録します。しかしログは膨大な量であるため、実用的な速度で実行するためにログ分析を自動化する必要があります。人間が生ログを直接読み解くのは非常に時間がかかります。賢明な補完手段としてハニーポットがあります。これは価値があるように見える架空のファイルであり、実際に開く理由がないため、アクセスがあればそれは明確でほぼ瞬時に攻撃の兆候となります。特に機密ファイルの削除またはコピーを試みる行為に注意してください。暗号化ハッシュも役立ちます。ファイルを再ハッシュして比較すると、ダイジェストが変わっていればファイルが改ざんされたことを示します。

    探偵的統制手段を選ぶ際は、コスト(ハニーポットは安価ですが、データ漏洩防止(DLP)サービスは強力だが高価)とデータの感度のバランスを考えます。特定の攻撃をログから読み取るには、そのシグネチャを探します。SQLインジェクションはOR 1=1と--を示し、XSSは<script>タグを示し、ディレクトリトラバーサルは../シーケンスを示し、バッファオーバーフローは異常に長い入力文字列を示します。

    ファイルが改ざんされていないことの確認

    暗号化ハッシュは、いかなるサイズのファイルも短い固定長の値に変換します。ファイルの1バイトを変更するとハッシュも完全に変わります。したがって、ダウンロードしたファイルのハッシュと出版者が記載しているものを比較することで、ファイルが損傷なく到着したことを証明できます。これはコマンドラインで行います:

    シェル コマンド
    BASH (Linux、およびほとんどのサーバー) sha256sum testfile
    zsh (Appleコンピュータの標準ターミナル) shasum -a 256 testfile

    両方ともtestfileのSHA-256ハッシュを表示します。公開された値と1文字でも異なれば、ファイルは改ざんされています——転送中の破損によるものか、攻撃者が置き換えたものかです。

    ⚠️ ハッシュは完全性を証明しますが、真正性を証明するものではありません。Webページ上のファイルを置き換えられる攻撃者は、隣にある公開ハッシュも通常置き換えられます。そのため、署名付きハッシュや、信頼できる別チャネル経由で取得したハッシュの方が、より強力な証拠となります。

    5.6

    Exam tips · ⁨試験対策⁩

    English
    • Match each application attack to its evidence in a log: OR 1=1 / -- = SQL injection; <script> = XSS; ../ = directory traversal; very long input = buffer overflow.
    • Learn the four access-control models by their decider: RBAC = your role, RuBAC = a condition, DAC = the file's owner, MAC = a central admin. Least privilege underlies them all.
    • Read Linux permissions by adding 4+2+1 per group - chmod 750 = owner rwx (7), group r-x (5), others none (0). Practice converting both ways.
    • Symmetric = one shared key (fast, AES); asymmetric = a public/private key pair (solves key sharing, RSA/ECC). Encrypt with the recipient's public key.
    • Input sanitization is the single best answer for preventing injection attacks; a honeypot is the classic cheap detective control.
    日本語
    • 各アプリケーション攻撃をログ内の証拠と一致させます:OR 1=1 / -- = SQLインジェクション;<script> = XSS;../ = ディレクトリトラバーサル;非常に長い入力 = バッファオーバーフロー。
    • 4つのアクセス制御モデルを決定者に基づいて学びます:RBAC = ユーザの役割、RuBAC = 条件、DAC = ファイル所有者、MAC = 中央管理者。最小権限がそのすべてreadcrumbにあります。
    • Linuxの権限はグループごとに4+2+1を加算して読み取ります——chmod 750 = owner rwx (7)、group r-x (5)、others none (0)。両方向への変換を練習してください。
    • 対称鍵暗号 = 共通鍵1つ(高速、AES);非対称鍵暗号 = パブリック/プライベート鍵ペア(鍵共有問題を解決、RSA/ECC)。受信者のパブリックキーで暗号化します。
    • 入力サンプリティゼーションは注入攻撃を防ぐための最良の回答です。ハニーポットは古典的な安価な探偵的統制手段です。

Log in or create account · ⁨ログインまたはアカウント作成⁩

IGCSE, A-Level & AP