Attacks and brute force · 공격 및 브루트 포스
How attackers get in
- Beyond malware, attackers use direct attacks. The exam lists several:
- Brute-force attack — trying every possible password until one works.
- Hacking — gaining access without permission, often through a weakness.
공격자가 진입하는 방법
- 말웨어 외에도 공격자는 직접적인 공격을 사용합니다. 시험에서는 다음과 같은 것을 다룹니다:
- 브루트포스 공격 — 작동하는 비밀번호가 나올 때까지 가능한 모든 비밀번호를 시도합니다.
- 해킹 — 허락 없이 접근을 얻는 것, 보통 약점을 통해 이루어집니다.
Attacks on the network
- Data interception — "listening in" on data as it travels, to steal it (a packet sniffer).
- Denial of Service (DoS) — flooding a server with so many requests that it cannot serve real users.
- A DDoS does this from thousands of machines at once, so it is hard to block.
네트워크에 대한 공격
- 데이터 interception(도청) — 데이터가 전송되는 동안 "들여다보는" 행위로 도난하는 것(패킷 스너퍼).
- 서비스 거부 공격 (DoS) — 서버에 너무 많은 요청을 보내서 실제 사용자에게 서비스를 제공할 수 없게 만듭니다.
- DDoS는 이를 수천 대의 기계에서 동시에 수행하므로 차단하기 어렵습니다.
Why short passwords fail
- A 4-digit PIN has only 10,000 combinations. A computer tries millions per second.
- Below, brute-force a PIN by trying every value — then notice how a longer password would have far more combinations.
짧은 비밀번호가 실패하는 이유
- 4자리 PIN은 오직 10,000 가지 조합만 있습니다. 컴퓨터는 초당 수백만 번을 시도합니다.
- 아래에서 PIN을 모든 값으로 시도하여 브루트포스 해보세요. 그러면 더 긴 비밀번호가 훨씬 더 많은 조합을 가짐을 깨닫게 될 것입니다.
The lesson
- Each extra character multiplies the number of guesses needed.
- That is why length is the single most powerful thing about a password — more on that soon.
Covers: IGCSE 5.3 (brute-force, hacking, interception, DDoS).
교훈
- 문자 하나 추가될 때마다 추측해야 할 횟수가 배가됩니다.
- 이것이 바로 길이가 비밀번호에서 가장 강력한 요소인 이유이며, 이에 대해서는 곧 자세히 설명하겠습니다.
적용: IGCSE 5.3 (브루트 포스, 해킹, intercepted, DDoS).
Common mistakes
- A brute-force attack tries every combination — a longer password makes it far slower.
- Rate-limiting and account lockouts help defend against it.
흔한 실수
- 브루트포스 공격은 모든 조합을 시도합니다. 더 긴 비밀번호는 이를 훨씬 느리게 만듭니다.
- 레이트 리미팅과 계정 잠금功能是 이를 방어하는 데 도움이 됩니다.
A 4-digit PIN has only 10000 possibilities — a computer can try them all in an instant. Loop through range(10000) and print the value that equals the secret, then stop. · 4자리 PIN은 오직 10000가지 가능성만 있습니다 — 컴퓨터는 순식간에 모두 시도할 수 있습니다. range(10000)와 print 사이를 루프하며 값이 secret과 일치하면 멈추십시오.
Click Run to see the output here. · 출력을 보려면 '실행'을 클릭하세요.
See why length wins. A lowercase-letters password has 26 ** length combinations. Print the number of combinations for length 4, then for length 8 — watch it explode. · 길이가 이기는 이유를 확인하십시오. 소문자 알파벳 비밀번호는 26 ** length가지 조합을 가집니다. 길이 4일 때와 길이 8일 때의 조합 수를 출력하십시오 — 급증하는 것을 확인하십시오.
Click Run to see the output here. · 출력을 보려면 '실행'을 클릭하세요.