Skip to content · ⁨본문 바로가기⁩

Introduction to Security · ⁨보안 소개⁩

AP Cybersecurity · ⁨AP 사이버보안⁩ · Topic 1 · ⁨주제 1⁩

Video lesson for this topic · ⁨이 주제용 영상 수업⁩ Open the video page · ⁨영상 페이지 열기⁩
7:55

보안 소개

완벽한 벽을 세울 수 있습니다. 깨지지 않는 암호화, 모든 포트에 방화벽, 출하 당일 적용되는 패치. 그러나 적대자가 여전히… 직진할 수 있습니다.

English narration · English + 中文 subtitles burned in · ⁨영어 내레이션 · 영어 + 중국어 자막 burned-in⁩

1.1

Understanding Social Engineering · ⁨사회공학적 기법 이해하기⁩

Syllabus
English

Learning Objective 1.1.A: Identify common indicators of social engineering tactics.

  • 1.1.A.1 Social engineering attacks employ psychological tactics to manipulate users into revealing sensitive information (elicitation), downloading a malicious file, or clicking on a malicious link. Social engineering can be performed in person but is often done by email, by text message, or through social media messages.
  • 1.1.A.2 Adversaries often use psychological tactics like intimidation and urgency to achieve their goals. Intimidation is when an adversary threatens a target with negative consequences if they don’t comply. Urgency is when an adversary creates reasons why a target should act quickly.

Learning Objective 1.1.B: Explain how social engineering tactics influence victims to perform a desired action.

  • 1.1.B.1 Social engineering tactics rely on common psychological principles that influence human behavior.
  • 1.1.B.2 Intimidation leverages a natural human aversion to negative consequences. By drawing attention to possible negative consequences, adversaries use fear to incite targets to act.
  • 1.1.B.3 Urgency leverages a natural human response to react quickly to time-sensitive needs. When targets detect a sense of urgency in a message, they feel pressured to respond or act quickly, which can prevent them from taking the time to consider whether an action is reasonable or safe.

Learning Objective 1.1.C: Describe possible impacts for victims of social engineering attacks.

  • 1.1.C.1 Victims may give an adversary personal information that could lead to impersonation, such as name, phone number, address, workplace, pets’ names, or birthdate. These types of information, and information like them, are often used on websites as challenge questions to verify a user’s identity.
  • 1.1.C.2 Victims may give an adversary secure information like a one-time password (OTP) or authentication login code, which could allow an adversary to log in to a service as the victim.
  • 1.1.C.3 Victims may download malware or click a link that installs malware on their device, steals information from their web browser, or directs them to a website where their login credentials can be captured by an adversary.
한국어

학습 목표 1.1.A: 사회공학적 기법의 일반적인 징후를 식별하시오.

  • 1.1.A.1 사회공학적 공격은 심리적 전략을 사용하여 사용자를 조작하여 민감한 정보(정보 유출)를 공개하게 하거나, 악의적 파일을 다운로드하거나, 악의적 링크를 클릭하게 합니다. 사회공학적 공격은 대면으로 수행되기도 하지만 주로 이메일, 문자 메시지 또는 소셜 미디어 메시지를 통해 이루어집니다.
  • 1.1.A.2 적대자는自己的目标을 달성하기 위해 협박과緊迫감 같은 심리적 전략을 자주 사용합니다. 협박은 표적이 따르지 않을 경우 부정적인 결과를 초래한다고威胁하는 것입니다.緊迫감은 표적이 빠르게 행동해야 하는 이유를 만들어내는 것입니다.

학습 목표 1.1.B: 사회공학적 기법이 피해자를 특정 행동을 취하도록 유도하는 원리를 설명하시오.

  • 1.1.B.1 사회공학적 기법은 인간의 행동을影响하는 일반적인 심리학적 원리에 의존합니다.
  • 1.1.B.2 협박은 인간이 부정적인 결과에 자연적으로 회피하려는 성질을 이용합니다. 가능한 부정적인 결과를 강조함으로써 적대자는 공포를 유발하여 표적이 행동하도록 자극합니다.
  • 1.1.B.3緊迫감은 시간이 제한된 필요에 대해 빠르게 반응하려는 인간의 본능적인 반응을 이용합니다. 표적이 메시지 내에緊迫감을 감지하면, 행동이 타당하거나 안전한지를 고려할 시간을 갖지 못해 빠르게 응답하거나 행동하도록 압박을 느끼게 됩니다.

학습 목표 1.1.C: 사회공학적 공격의 피해자가 겪을 수 있는 영향을 서술하시오.

  • 1.1.C.1 피해자는 적대자에게 성명, 전화번호, 주소, 직장, 반려동물 이름 또는 생일 등 신원 위조(人身冒用)로 이어질 수 있는 개인 정보를 제공할 수 있습니다. 이러한 종류의 정보는 websites에서 사용자 신원을 확인하는Challenge 질문으로 자주 사용됩니다.
  • 1.1.C.2 피해자는 적대자에게 일회용 비밀번호(OTP) 또는 인증 로그인 코드와 같은 보안 정보를 제공할 수 있으며, 이는 적대자가 피해자 명의로 서비스에 로그인할 수 있게 할 수 있습니다.
  • 1.1.C.3 피해자는 악성 소프트웨어를 다운로드하거나, 악의적 링크를 클릭하여 장치에 악성 소프트웨어를 설치되거나, 웹 브라우저에서 정보를 도난당하거나,登录 credentials가 적대자에게 포획되는 웹사이트로 안내받을 수 있습니다.

Source: College Board AP Course and Exam Description · ⁨출처: College Board AP Course and Exam Description⁩

English
Phishing: how a fake email steals a password

The weakest part of any computer system is often the human using it. Social engineering 社会工程学 is the art of tricking people into breaking security - giving away a password, opening a bad file, or clicking a bad link. The attacker (we call them an adversary 对手) does not need to break the code; they only need to fool a person.

Most social engineering happens by email, text message, or social media, though it can also happen in person or by phone. The goal is elicitation 套取信息 - getting sensitive information out of someone without them realising.

Adversaries lean on two powerful feelings:

  • Intimidation 恐吓 - the adversary threatens a bad result if you do not obey. Fear pushes you to act.
  • Urgency 紧迫感 - the adversary invents a deadline ("reply in the next hour or your account closes"). When we feel rushed, we stop thinking carefully about whether an action is safe.

The impact 影响 on a victim can be serious. They might reveal personal details (name, address, pet's name, birthday) that are later used to answer security challenge questions 安全问题 and impersonate 冒充 them. They might hand over a one-time password (OTP) 一次性密码, letting the adversary log in as them. Or they might download malware 恶意软件 that steals data from their browser.

Worked example. A phishing email reads: "Over 90% of staff have already verified their account - confirm yours in the next hour or lose payroll access." Two tactics are stacked here. "In the next hour" is urgency (a deadline that rushes you), and "over 90% of staff have already" is consensus (social pressure to follow the crowd). Naming each tactic - not just calling the email "suspicious" - is exactly what an exam answer needs.

한국어
피싱: 가짜 이메일이 비밀번호를 훔치는 과정

어떤 컴퓨터 시스템의 가장 약한 점은 종종 이를 사용하는 사람입니다. **사회공학적 기법(social engineering)**은 사람을 속여 보안 조치를 위반하게 만드는 기술로, 비밀번호를 누설하거나 악성 파일을 열게 하거나 해킹 링크를 클릭하게 만듭니다. 공격자(우리는 이들을 **적(adversary)**이라고 부름)는 코드를 해킹할 필요가 없습니다. 단지 사람을 속이면 됩니다.

대부분의 사회공학적 기법은 이메일, 문자 메시지 또는 소셜 미디어를 통해 이루어지지만, 대면이나 전화로도 발생할 수 있습니다. 목표는 정보 추출(elicitation) - 상대방이気づ지 않고 민감한 정보를 얻어내는 것 - 입니다.

적(adversaries)은 두 가지 강력한 감정을 이용합니다:

  • 협박(intimidation) - 적(adversary)이 불복종할 경우 나쁜 결과가 초래됨을威胁합니다. 두려움이 당신으로 하여금 행동하게 만듭니다.
  • 급박함(urgency) - 적(adversary)이 마감일(예: "다음 시간 내에 응답하지 않으면 계정이 폐쇄됩니다")을 설정합니다. 우리가 서두른다고 느끼면 어떤 행위가 안전한지에 대해 진지하게 생각하는 것을 멈춥니다.
사회공학적 기법은 피해자가 생각하기 전에 행동하게 만들기 위해 심리적 압력을 사용합니다
사회공학적 기법은 피해자가 생각하기 전에 행동하게 만들기 위해 심리적 압력을 사용합니다

피해자에 대한 영향(impact) 은 심각할 수 있습니다. 그들은 나중에 보안 **질문(challenge questions)**에 답하거나 위장(impersonate) 하는 데 사용될 이름, 주소, 애완동물 이름, 생일 같은 개인 정보를 폭로할 수 있습니다. 그들은 일회용 비밀번호(OTP) 를 제공하여 적(adversary)이其名登录하게 할 수도 있습니다. 혹은 브라우저에서 데이터를 도난하는 악성코드(malware) 를 다운로드할 수도 있습니다.

해설 예제. 한 피싱 이메일에는 다음과 같이 적혀 있습니다: "사원의 90% 이상이 이미 계정을 인증했습니다. 다음 시간 이내에 본인의 계정을 확인하지 않으면 급여 지급 접근 권한을 상실합니다." 여기에는 두 가지 전술이 결합되어 있습니다. "다음 시간 이내"는 급박함(urgency) (당신을 서두르게 만드는 마감일)이며, "사원의 90% 이상이 이미"는 동조 효과(consensus) (무리를 따라는 사회적 압력)입니다. 각 전술에 명칭을 부여하고 단순히 이메일을 '의심스러운'이라고 부르는 것만으로는不够합니다. 이것이 바로 시험 답안에 필요한 것입니다.

Explore · ⁨탐색하기⁩

Which social-engineering tactic is it? · ⁨어떤 사회공학적 전술입니까?⁩

Intimidation threatens harm, urgency invents a deadline, consensus claims everyone else is doing it, and authority pretends to have power over you. · ⁨협박(intimidation) 은 해를 가할 것을 위협하고, 긴급성(urgency) 은 마감일을 발명하며, 동조(consensus) 는 남들이 모두这样做 claim하고, 권위(authority) 는 당신에게 권력을 행사한다고 위장합니다.⁩

Vocabulary · ⁨어휘⁩ Train · ⁨연습하기⁩
English 한국어
Social engineering/ˈsəʊʃl ˌendʒɪˈnɪərɪŋ/ 사회 공학(Social engineering)
adversary/ˈædvəsəri/ 적(adversary)
elicitation/ɪˌlɪsɪˈteɪʃn/ 인출(elicitation)
Intimidation/ɪnˌtɪmɪˈdeɪʃn/ 협박(Intimidation)
Urgency/ˈɜːdʒənsi/ Urgency(시급성)
impact/ˈɪmpækt/ 영향
challenge questions/ˈtʃælɪndʒ ˈkwestʃnz/ 도전 질문
impersonate/ɪmˈpɜːsəneɪt/ 위장하기(impersonate)
one-time password (OTP)/wʌn taɪm ˈpæswɜːd/ 일회용 비밀번호 (OTP)
malware/ˈmælweə/ 악성 코드
phishing/ˈfɪʃɪŋ/ 피싱
shared secret/ʃeəd ˈsiːkrɪt/ 공유 비밀(shared secret)
AI-enhanced coding tools/ˌeɪ ˈaɪ enˈhænst ˈkəʊdɪŋ tuːlz/ AI 향상 코딩 도구
1.2

Suspicious Website Logins · ⁨의심스러운 웹사이트 로그인⁩

Syllabus
English

Learning Objective 1.2.A: Identify common signs of a password attack.

  • 1.2.A.1 In an online password attack, adversaries try logging in to a device or service using common passwords, common password patterns, or stolen passwords.
  • 1.2.A.2 Signs of an online password attack include:
    • Many failed attempts to log in over a short duration
    • Login attempts at unusual times
    • Login attempts from unknown devices

Learning Objective 1.2.B: Explain how adversaries take advantage of weak authentication.

  • 1.2.B.1 Many people use common patterns when creating passwords, such as:
    • Starting a password with one or two words, adding a two-digit number (often signifying a year), and putting a special character at the end
    • Including the names of family or pets in their passwords
    • Including personally significant dates in their passwords
  • 1.2.B.2 Adversaries often construct a dictionary of possible passwords based on personal information gathered about a target (e.g., birthday, anniversary, names of pets and family) and use an automated tool to submit potential passwords.

Learning Objective 1.2.C: Explain how to make authentication stronger.

  • 1.2.C.1 Users should create passwords that are long, random, and unique. A password manager can be used to generate and store strong passwords, or a user may create long, unique passphrases for their accounts.
  • 1.2.C.2 When creating passwords, users should avoid names, dates, or other personally meaningful words or numbers.
  • 1.2.C.3 When available, users should enable multifactor authentication (MFA), which will require the user to provide extra proof of identity—such as a one-time code—in addition to the password as an extra layer of security.
한국어

학습 목표 1.2.A: 비밀번호 공격의 일반적인 징후를 식별하시오.

  • 1.2.A.1 온라인 비밀번호 공격에서 적대자는 일반 비밀번호, 일반적인 비밀번호 패턴 또는 도난당한 비밀번호를 사용하여 장치 또는 서비스에 로그인하려 시도합니다.
  • 1.2.A.2 온라인 비밀번호 공격의 징후로는 다음이 포함됩니다:
    • 짧은 기간 동안 여러 번의 로그인 실패 시도
    • 비정상적인 시간에进行的登录尝试
    • 미지의 장치에서의 로그인 시도

학습 목표 1.2.B: 적대자가 약한 인증 방식을如何利用하는지 설명하시오.

  • 1.2.B.1 많은 사람들은 비밀번호 생성 시 일반적인 패턴을 사용합니다. 예를 들면:
    • 비밀번호를 한두 단어로 시작하고, 두 자리 숫자(보통 연도를 의미)를 추가하며,末尾에 특수문자를 넣는 것
    • 비밀번호에 가족이나 반려동물 이름을 포함하는 것
    • 비밀번호에 개인적으로 의미 있는 날짜를 포함하는 것
  • 1.2.B.2 공격자는 표적에 대한 개인 정보(예: 생일, 기념일, 애완동물 및 가족의 이름)를 수집하여 가능한 비밀번호 목록을 구성하고 자동화 도구를 사용하여 잠재적인 비밀번호를 제출합니다.

학습 목표 1.2.C: 인증을 강화하는 방법을 설명하십시오.

  • 1.2.C.1 사용자는 길고 무작위이며 고유한 비밀번호를 생성해야 합니다. 강력한 비밀번호를 생성하고 저장하기 위해 비밀번호 관리자를 사용할 수 있으며, 사용자는 계정별로 길고 고유한 패스프레이스를 만들 수도 있습니다.
  • 1.2.C.2 비밀번호를 생성할 때 사용자는 이름, 날짜 또는 개인적으로 의미 있는 단어나 숫자를 피해야 합니다.
  • 1.2.C.3 제공되는 경우 사용자들은 추가 보안 계층으로 비밀번호 외에 일회용 코드와 같은 추가 신원 증명 정보를 요구하는 다중 요인 인증(MFA)을 활성화해야 합니다.

Source: College Board AP Course and Exam Description · ⁨출처: College Board AP Course and Exam Description⁩

English

A password attack 密码攻击 is any attempt to log in using guessed or stolen passwords. In an online password attack the adversary tries passwords against a real login page. The warning signs are visible in the logs:

  • many failed logins in a short time,
  • login attempts at unusual hours,
  • login attempts from unknown devices.

Adversaries succeed because people choose weak 弱 passwords. Common patterns include a word plus a two-digit year plus a special character (like Summer24!), or a pet's or family member's name. Because these patterns are so common, an adversary can build a dictionary 字典 of likely passwords from information gathered about you and let an automated tool try each one.

To make authentication 身份验证 stronger:

  • Create passwords that are long, random, and unique - a password manager 密码管理器 can generate and store them for you.
  • Avoid names, dates, and meaningful words.
  • Turn on multifactor authentication (MFA) 多因素身份验证, which asks for extra proof (like a texted code) on top of the password.
한국어
하드웨어 보안 키: 비밀번호가 피싱 당했을 때 강력한 인증은 피해를 줄입니다
하드웨어 보안 키: 비밀번호가 피싱 당했을 때 강력한 인증은 피해를 줄입니다

비밀번호 공격(password attack) 은 추측하거나 도난당한 비밀번호를 사용하여 로그인하려는 시도의 모든 것을 의미합니다. 온라인 비밀번호 공격에서 적(adversary)은 실제 로그인 페이지에 대해 비밀번호를 시도합니다. 경고 신호는 로그에서 확인할 수 있습니다:

  • 짧은 시간에 많은 실패한 로그인,
  • 비정상적인 시간대의 로그인 시도,
  • 미확인 기기에서의 로그인 시도.

공격자가 성공하는 이유는 사람들이 약한 비밀번호를 선택하기 때문입니다. 일반적인 패턴에는 단어에 두 자리 연도를 더하고 특수 문자(Summer24! 등)를 추가하거나, 반려동물이나 가족의 이름을 사용하는 것이 포함됩니다. 이러한 패턴이 매우 흔하기 때문에 공격자는 당신에 대해 수집된 정보를 바탕으로 유력한 비밀번호 목록을 구성하고 자동화 도구를 사용하여 하나씩 시도할 수 있습니다.

인증을 강화하려면:

  • 길고, 무작위이며 고유한 비밀번호를 생성하십시오. 비밀번호 관리자가 이를 생성하고 저장해 줄 수 있습니다.
  • 이름, 날짜 및 의미 있는 단어는 피하십시오.
  • 다중 인증(MFA) 을 활성화하십시오. 이는 비밀번호 외에codes(예: 문자 메시지 코드의 경우)와 같은 추가 증명 요구사항을 asking합니다.
Vocabulary · ⁨어휘⁩ Train · ⁨연습하기⁩
English 한국어
password attack/ˈpæswɜːd əˈtæk/ 비밀번호 공격(password attack)
weak/wiːk/ 약함
dictionary/ˈdɪkʃənəri/ dictionary(字典)
authentication/ɔːˌθentɪˈkeɪʃn/ 인증
password manager/ˈpæswɜːd ˈmænɪdʒə/ 비밀번호 관리자(password manager)
multifactor authentication (MFA)/ˌmʌltɪˈfæktə ɔːˌθentɪˈkeɪʃn/ 다중 요인 인증 (MFA)
1.3

Best Practices for Public Networks · ⁨공공 네트워크를 위한 최우선 원칙⁩

Syllabus
English

Learning Objective 1.3.A: Identify the type of adversary conducting a cyberattack.

  • 1.3.A.1 Adversaries can be classified by their skill levels.
    • Low-skilled adversaries rely on malicious cyber tools created by others that can be purchased online. The tools they use exploit known vulnerabilities.
    • High-skilled adversaries have the capacity to create new malicious cyber tools or modify existing ones to adapt to new defensive techniques and tools. They also have the capacity to discover undocumented vulnerabilities, known as zero days.
  • 1.3.A.2 Adversaries have a variety of motivations, including greed, desire for recognition, dedication to a cause, revenge, politics, or beliefs.

Learning Objective 1.3.B: Identify types of wireless cyberattacks.

  • 1.3.B.1 In an evil twin attack, an adversary sets up their own wireless access point (WAP) with a service set identifier (SSID) similar or identical to a target network; the adversary’s network is called the evil twin. Victims of this attack could select to unknowingly connect to the evil twin, allowing the adversary to capture their network traffic. The adversary cannot read traffic that uses an encrypted protocol like HTTPS.
  • 1.3.B.2 In a jamming attack, an adversary floods an area with a strong electromagnetic (EM) signal in the same frequency range as the wireless network, which prevents legitimate traffic between the access point (AP) and users. This type of attack that prevents users from accessing resources is called a denial of service (DoS) attack.
  • 1.3.B.3 In a war driving attack, adversaries try to detect wireless network beacons while driving or walking around a target. If a wireless signal is detected, the adversary can gather information about the type of wireless network used and find areas where the wireless signal extends outside the physical building.

Learning Objective 1.3.C: Describe actions individuals can take to increase protection of sensitive data when using the internet and Wi-Fi.

  • 1.3.C.1 Individuals should verify that the name of any wireless network they join exactly matches the name of the network they intend to join.
  • 1.3.C.2 Most internet protocols are encrypted to protect network traffic. However, individuals may consider the sensitivity of their data in choosing whether to join unencrypted Wi-Fi networks to protect vulnerable data such as DNS queries.
  • 1.3.C.3 Individuals may consider using a virtual private network (VPN), which encrypts all their traffic to the VPN operator’s system. Although this action prevents a service provider from viewing traffic, the VPN provider can view the traffic.
한국어

학습 목표 1.3.A: 사이버 공격을 수행하는 공격자의 유형을 식별하십시오.

  • 1.3.A.1 공격자는 기술 수준에 따라 분류될 수 있습니다.
    • 저기술 공격자는 온라인에서 구매할 수 있는 타인이 만든 악성 사이버 도구에 의존하며, 그들이 사용하는 도구들은 알려진 취약점을 이용합니다.
    • 고기술 공격자는 새로운 악성 사이버 도구를 생성하거나 기존 도구를 수정하여 새로운 방어 기법과 도구들에 적응할 수 있는 능력을 가지고 있습니다. 또한 문서화되지 않은 취약점, 즉 제로데이를 발견할 수 있는 능력도 가지고 있습니다.
  • 1.3.A.2 공격자는 탐욕, 명성 추구, 특정 이념에 대한 헌신, 복수, 정치적 목적 또는 신앙 등 다양한 동기를 가질 수 있습니다.

학습 목표 1.3.B: 무선 사이버 공격의 유형을 식별하십시오.

  • 1.3.B.1 악의적 쌍(Evil Twin) 공격에서 공격자는 표적 네트워크와 유사하거나 동일한 서비스 세트 식별자(SSID)를 가진 자체 무선 액세스 포인트(WAP)를 설정합니다.攻击者的网络被称为恶之双。此攻击的受害者可能会在不知情的情况下选择连接到恶之双,从而使攻击者能够捕获其网络流量。攻击者无法读取使用HTTPS等加密协议的网络流量。
  • 1.3.B.2 재밍(Jamming) 공격에서 공격자는 무선 네트워크와 동일한 주파수 대역에 강력한 전자기(EM) 신호를 범람시켜 액세스 포인트(AP)와 사용자 간의 정당한 트래픽을 차단합니다. 사용자가 리소스에 접근하지 못하게 하는此类攻击称为拒绝服务(DoS)攻击。
  • 1.3.B.3 워드라이딩(War Driving) 공격에서 공격자는 표적을 driving或walking around时尝试检测无线信标。如果检测到无线信号,攻击者可以收集所用无线网络类型的信息,并找到无线信号延伸到物理建筑外部的区域。

학습 목표 1.3.C: 인터넷과 Wi-Fi 사용 시 민감한 데이터를 보호하기 위해 개인이 취할 수 있는 조치를 설명하십시오。

  • 1.3.C.1 개인은 참여하는 모든 무선 네트워크의 이름이 의도하는 네트워크의 이름과 정확히 일치하는지 확인해야 합니다。
  • 1.3.C.2 대부분의 인터넷 프로토콜은 네트워크 트래픽을 보호하기 위해 암호화됩니다。然而,个人在选择是否加入未加密的Wi-Fi网络以保护DNS查询等易受攻击的数据时,应考虑数据的敏感性。
  • 1.3.C.3 개인은 모든 트래픽을VPN运营商的系统加密的虚拟专用网络(VPN)을 사용할지 고려할 수 있습니다。虽然这一操作可以防止服务提供商查看流量,但VPN提供商可以查看流量。

Source: College Board AP Course and Exam Description · ⁨출처: College Board AP Course and Exam Description⁩

English

Not all adversaries are the same. We classify them by skill: low-skilled attackers buy ready-made tools online and reuse known exploits 漏洞利用, while high-skilled attackers write their own tools and can discover brand-new holes called zero days 零日漏洞. Their motivation 动机 varies too - greed, revenge, politics, or belief.

Public Wi-Fi is a favourite hunting ground. Three wireless attacks you must know:

  • Evil twin 双胞胎恶意热点 - the adversary sets up a fake access point 接入点 with a name (SSID 服务集标识符) copied from the real network. Victims connect to the fake one, and the adversary reads their traffic (though encrypted 加密的 sites like HTTPS stay safe).
  • Jamming 干扰攻击 - the adversary floods the air with a strong radio signal so no one can connect. This is one kind of denial of service (DoS) 拒绝服务 attack.
  • War driving 战争驾驶 - the adversary drives around detecting wireless networks and where their signal leaks outside a building.

To protect yourself on public networks: check that the network name exactly matches the one you intend to join, prefer encrypted sites, and consider a virtual private network (VPN) 虚拟专用网络, which encrypts all of your traffic to the VPN operator.

한국어
보안 토큰: 일회용 코드와 토은 비밀번호만으로는 로그인이 충분하지 않음을 방지합니다
보안 토큰: 일회용 코드와 토큰은 비밀번호만으로는 로그인이 충분하지 않음을 방지합니다

모든 공격자가 동일하지는 않습니다. 우리는 그들을 기술 수준으로 분류합니다. 저수준 공격자는 온라인에서 완성된 도구를 구매하여 알려진 취점(exploits) 을 재사용하지만, 고수준 공격자는 자체적으로 도구を作成하며 제로데이(zero days) 라는 새로운 취약점을 발견할 수 있습니다. 또한 그들의 동기도 다양합니다. 이득, 복수, 정치, 혹은 신념 등입니다.

공공 Wi-Fi는 가장 선호되는 사냥터입니다. 반드시 알아야 할 세 가지 무선 공격 유형:

  • 악성 쌍(Evil twin) - 공격자가 실제 네트워크의 이름(SSID)을 복사한 가짜 접속 포인트(access point) 를 설치합니다. 피해자들이 가짜 접속 포인트에 연결하면, 공격자는 해당 트래픽을 읽을 수 있습니다(다만 HTTPS와 같은 암호화된 사이트는 안전합니다).
  • 저밍(Jamming) - 공격자가 강력한 라디오 신호로 공기를 폭주시켜 아무도 연결할 수 없게 만듭니다. 이는 서비스 거부 공격(denial of service, DoS) 의 한 종류입니다.
  • 워 드라이빙(War driving) - 공격자가 차량을 타고 이동하면서 무선 네트워크를 탐지하고, 신호가 건물 외부로 누출되는 위치를 파악합니다.
악성 쌍 접속 포인트가 실제 네트워크의 이름을 복사하여 피해자들이 공격자에게 연결되도록 합니다
악성 쌍 접속 포인트가 실제 네트워크의 이름을 복사하여 피해자들이 공격자에게 연결되도록 합니다

공공 네트워크에서 자신을 보호하려면, 네트워크 이름이接続하려는 것정확히 일치하는지 확인하고, 암호화된 사이트를 우선 사용하며, 모든 트래픽을 VPN 운영자에게 암호화하는 가상 사설 네트워크(VPN) 사용을 고려하십시오.

Vocabulary · ⁨어휘⁩ Train · ⁨연습하기⁩
English 한국어
exploits/ˈeksplɔɪts/ 공격(explaits)
zero days/ˈzɪərəʊ deɪz/ 제로 데이즈(zero days)
motivation/ˌməʊtɪˈveɪʃn/ 동기부여
Evil twin/ˈiːvl twɪn/ 악의적 쌍
access point/ˈækses pɔɪnt/ access point
SSID/ˌes es aɪ ˈdiː/ SSID
encrypted/enˈkrɪptɪd/ 암호화된
Jamming/ˈdʒæmɪŋ/ 저머링
denial of service (DoS)/dɪˈnaɪəl ɒv ˈsɜːvɪs/ 서비스 거절 (DoS)
War driving/wɔː ˈdraɪvɪŋ/ 워드라이빙
virtual private network (VPN)/ˈvɜːtʃuːəl ˈpraɪvət ˈnetwɜːk/ 가상 사설망 (VPN)
1.4

AI-Based Cybersecurity Attacks · ⁨AI 기반 사이버 보안 공격⁩

Syllabus
English

Learning Objective 1.4.A: Explain how adversaries use AI-powered tools to augment cyberattacks.

  • 1.4.A.1 Adversaries can use AI-powered tools that leverage existing voice and image samples of a person to create a digital avatar of that person. The use of these technologies enables adversaries to impersonate someone over the phone or even on a video call, which can lead to financial loss or the sharing of sensitive or private information. As more organizations adopt voice-based authentication, the impact of voice-impersonation has a larger potential impact.
  • 1.4.A.2 Adversaries can use generative AI tools, like large language models (LLMs), to create convincing phishing messages in any target language. Because traditional phishing messages are sometimes written by non-native speakers of the target’s language, unnatural language is a feature that has been used to distinguish phishing messages from legitimate messages. However, with AI tools, adversaries can now craft phishing messages in any language that read as though they were written by a native speaker.
  • 1.4.A.3 Adversaries can craft prompts that extract secure or sensitive information from LLMs. Secure or sensitive information in LLMs can come from user input and the large data sets used to train LLMs.
  • 1.4.A.4 Adversaries can publish websites or modify existing websites to contain false information so that the false information will be included in the training sets for LLMs, causing the LLMs to repeat the false information.
  • 1.4.A.5 Adversaries can perform reconnaissance on a target using AI-powered tools that scan the internet to gather information posted on social media and public websites.
  • 1.4.A.6 Adversaries can use AI-enhanced coding tools to help them write new malware, modify existing application code to perform malicious activities, or to find vulnerabilities in large code bases.

Learning Objective 1.4.B: Explain how to protect against some AI-augmented cyberattacks.

  • 1.4.B.1 Shared secrets with close friends and relatives that can be used to verify each other’s identities should be established. A secret word or phrase known only to two parties can be used to authenticate identities in high-stakes situations.
  • 1.4.B.2 Multifactor authentication (MFA) should be enabled. If an adversary clones a target’s voice to access a system with voice authentication, requiring a second authentication factor could prevent an adversary from gaining access to accounts.
  • 1.4.B.3 Personal or sensitive data should not be entered into any AI-powered tools, such as chatbots or virtual assistants. Some AI-powered tools feed user input back into the model to provide continuous training. Adversaries could extract data that users have included in prompts.
  • 1.4.B.4 Output from AI-powered tools should be carefully evaluated. Verify information from AI-powered tools using reputable, stable, non-AI-based sources.
한국어

학습 목표 1.4.A: 공격자가 AI 구동 도구를 사용하여 사이버 공격을 어떻게 강화하는지 설명하십시오。

  • 1.4.A.1 공격자는某人现有的语音和图像样本利用AI工具创建该人的数字化身。这些技术的使用使攻击者能够在电话甚至视频通话中冒充他人,从而导致财务损失或敏感/私人信息的泄露。随着越来越多组织采用基于语音的身份验证,语音冒充的影响具有更大的潜在影响。
  • 1.4.A.2攻击者可以使用生成式AI工具(如大型语言模型LLM)用任何目标语言创建令人信服的钓鱼邮件。由于传统钓鱼邮件有时由非目标语言母语者编写,不自然的语言是区分钓鱼邮件与合法邮件的一个特征。然而,借助AI工具,攻击者现在可以用任何语言编写出读起来像母语者撰写的钓鱼邮件。
  • 1.4.A.3攻击者可以设计提示词从LLM中提取安全或敏感信息。LLM中的安全或敏感信息可能来自用户输入和用于训练LLM的大规模数据集。
  • 1.4.A.4攻击者可以发布网站或修改现有网站以包含虚假信息,从而使这些信息被纳入LLM的训练集,导致LLM重复虚假信息。
  • 1.4.A.5攻击者可以使用AI驱动的工具对目标进行侦察,扫描互联网以收集社交媒体和公共网站上发布的信息。
  • 1.4.A.6攻击者可以使用AI增强的编码工具帮助他们编写新恶意软件、修改现有应用程序代码以执行恶意活动,或在大型代码库中发现漏洞。

学习目標 1.4.B: 解释如何防范部分经AI增强的网络攻击。

  • 1.4.B.1 신원 확인에 사용할 수 있는 친한 친구 및 가족과의 비밀을 설정해야 합니다. 두 당사자만이 아는 비밀 단어나 구절은 고위험 상황에서 신원을 인증하는 데 사용할 수 있습니다.
  • 1.4.B.2 다중 인증(MFA)을 활성화해야 합니다. 적대자가 음성 인증 시스템에 접근하기 위해 표적의 목소리를 복제할 경우, 두 번째 인증 요소를 요구하면 적대자의 계정 접근을 방지할 수 있습니다.
  • 1.4.B.3 개인 또는 민감한 데이터는 채팅봇이나 가상 비서와 같은 AI 기반 도구에는 입력해서는 안 됩니다. 일부 AI 기반 도구는 사용자 입력을 모델로 다시 피딩하여 지속적인 훈련에 사용합니다. 적대자는 사용자가 프롬프트에 포함한 데이터를 추출할 수 있습니다.
  • 1.4.B.4 AI 기반 도구의 출력물을 주의 깊게 평가해야 합니다. 신뢰할 수 있는 안정된 비(AI) 기반 출처를 통해 AI 기반 도구로부터 정보를 검증하십시오.

Source: College Board AP Course and Exam Description · ⁨출처: College Board AP Course and Exam Description⁩

English

Artificial intelligence gives adversaries powerful new tools. With enough voice and image samples, an adversary can build a deepfake 深度伪造 avatar to impersonate someone on a call. Large language models (LLMs) 大语言模型 let them write convincing phishing 钓鱼 emails in perfect, native-sounding language - removing the clumsy wording that once gave scams away.

AI also helps adversaries on the back end: crafting prompts that pull secret data out of an LLM, planting false information on websites so it poisons an LLM's training data, scanning the internet to gather facts about a target, and even writing new malware.

You can defend against many AI-augmented attacks: agree on a shared secret 共享秘密 word with close contacts to verify identity, enable MFA (so a cloned voice alone cannot log in), never type sensitive data into a chatbot, and always double-check AI output against reliable, non-AI sources.

AI writes code, and that cuts both ways. Adversaries use AI-enhanced coding tools 人工智能辅助编程工具 to write new malware faster than they could by hand, to modify existing application code so that it performs malicious activity, and to scan a codebase for vulnerabilities 漏洞 to attack. The skill barrier falls: someone who could not previously write an exploit can now ask for one, so the number of capable attackers rises even when no new technique is invented.

한국어

인공지능은 공격자에게 강력한 새로운 도구를 제공합니다. 충분한 음성 및 이미지 샘플을 확보하면, 공격자는 통화 중某人을 위장하는 딥페이크(deepfake) 아바타를 만들 수 있습니다. 대형 언어 모델(LLM) 은 완벽한 모국어 스타일의 설득력 있는 피싱(phishing) 메일 작성에 활용되어, 예전에 사기임을 드러내던 어색한 문구를 제거합니다.

AI는 또한 백엔드에서 공격자를 지원합니다: LLM으로부터 기밀 데이터를 끌어내는 프롬프트를 제작하거나,网站上虚假信息进行植入以毒化LLM的训练数据,扫描互联网收集目标信息,甚至编写新的恶意软件。

많은 AI 증강 공격에 대비할 수 있습니다: 신뢰할 수 있는 연락처와 공유 비밀(guess secret) 단어를 정하여 신원을 검증하고, MFA를 활성화하여 클론된 음성이 단독으로 로그인하는 것을 방지하며,Sensitive data를 채팅봇에 입력하지 말고, 항상 AI 출력을 신뢰할 수 있는 비-AI 소스와 대조하여 이중 확인하십시오.

AI는 코드를 작성하며, 그 영향은 양면적입니다. 공격자는 AI 증강 코딩 도구를 사용하여 손으로 작성하는 것보다 빠르게 새로운 악성 소프트웨어(malware) 를 작성하고, 기존 애플리케이션 코드를 수정하여 악의적 활동을 수행하게 하며, 취약점(vulnerabilities) 을 찾아서 공략할 수 있도록 코드베이스를 스캔합니다. 기술 장벽이 낮아졌습니다: 예전에는 취약점을 발췌할 수 없었던 사람도 이제 요청할 수 있으므로, 새로운 기법이 발명되지 않아도 가능한 공격자의 수는 증가합니다.

Vocabulary · ⁨어휘⁩ Train · ⁨연습하기⁩
English 한국어
deepfake/ˈdiːpfeɪk/ 딥페이크 (deepfake)
Large language models (LLMs)/lɑːdʒ ˈlæŋɡwɪdʒ ˈmɒdlz/ 거대 언어 모델 (LLMs)
vulnerabilities/ˌvʌlnərəˈbɪlɪtiz/ 취약점
1.5

Leveraging AI in Cyber Defense · ⁨사이버 방어에서의 AI 활용⁩

Syllabus
English

Learning Objective 1.5.A: Explain how cyber defenders can leverage AI-powered tools to protect networks, applications, and data.

  • 1.5.A.1 AI tools can review current security configurations, like firewall rules and access controls, and recommend more secure options. Recommendations should always be checked by a knowledgeable security technician before being implemented.
  • 1.5.A.2 AI-powered tools can analyze application code to identify vulnerabilities and recommend mitigations. Recommendations should always be reviewed by a knowledgeable programmer before being implemented.
  • 1.5.A.3 AI-powered tools can suggest rules for automated detection systems. Detection rules should always be reviewed by a knowledgeable detection engineer before being added to a system.

Learning Objective 1.5.B: Explain how AI-powered tools are enabling faster and more accurate threat detection and response.

  • 1.5.B.1 Of the millions of digital events that happen on networks daily, some likely represent an adversary conducting malicious activity. Humans cannot carefully examine all those events to identify the malicious activity.
  • 1.5.B.2 AI-powered tools can be trained to quickly analyze digital events and sort the events that are likely malicious activity from those that are harmless.
  • 1.5.B.3 AI-powered tools can be programmed to alert human cybersecurity personnel when likely malicious activity is detected or to take specific corrective actions based on the type of malicious activity detected.
  • 1.5.B.4 AI-powered tools enable threat-detection and response teams to catch malicious activity and intervene quickly to prevent loss, harm, damage, and destruction to digital infrastructure and data.
한국어

학습 목표 1.5.A: 사이버 방어자가 AI 기반 도구를 사용하여 네트워크, 애플리케이션 및 데이터를 보호하는 방법을 설명하십시오.

  • 1.5.A.1 AI 도구는 방화벽 규칙 및 접근 제어와 같은 현재 보안 구성을 검토하고 더 안전한 옵션을 제안할 수 있습니다. 제안은 항상 실행 전에 유능한 보안 기술자에 의해 확인되어야 합니다.
  • 1.5.A.2 AI 기반 도구는 애플리케이션 코드를 분석하여 취약점을 식별하고 완화 방안을 제안할 수 있습니다. 제안은 항상 행 전에 유능한 프로그래머에 의해 검토되어야 합니다.
  • 1.5.A.3 AI 기반 도구는 자동 감지 시스템의 규칙을 제안할 수 있습니다. 감지 규칙은 항상 시스템에 추가되기 전에 유능한 감지 엔지니어에 의해 검토되어야 합니다.

학습 목표 1.5.B: AI 기반 도구가 더 빠르고 정확한 위협 탐지 및 대응을 가능하게 하는 방법을 설명하십시오.

  • 1.5.B.1 매일 네트워크에서 발생하는 수백만 개의 디지털 이벤트 중 일부는 적대자가 악성 활동을 수행하는 것일 가능성이 있습니다. 인간이 모든 이벤트를 면밀히 검토하여 악성 활동을 식별할 수는 없습니다.
  • 1.5.B.2 AI 기반 도구는 빠르게 디지털 이벤트를 분석하고 악성 활동일 가능성이 높은 이벤트와 무해한 이벤트를 분류하도록 훈련될 수 있습니다.
  • 1.5.B.3 AI 기반 도구는 악성 활동이 감지되면 사이버 보안 담당자에게 경보를 알리거나, 감지된 악성 활동 유형에 따라 특정 시정 조치를 취하도록 프로그래밍될 수 있습니다.
  • 1.5.B.4 AI 기반 도구는 위협 탐지 및 대응 팀이 악성 활동을 포착하고 신속하게 개입하여 디지털 인프라 및 데이터의 손실, 피해, 손상 및 파괴를 예방하도록 지원합니다.

Source: College Board AP Course and Exam Description · ⁨출처: College Board AP Course and Exam Description⁩

English

The same technology defends us. AI tools can analyse an application's own source code, identify vulnerabilities in it and recommend mitigations; they can also review firewall rules and access settings and recommend safer options - though a human expert must always check the advice before applying it. AI can scan application code for weaknesses and suggest detection rules.

⚠️ A recommendation is not a fix. The CED is explicit that the advice must be reviewed and implemented by a knowledgeable programmer: an AI tool can be confidently wrong about whether a flaw is exploitable, and applying a suggested patch without understanding it can introduce a new fault of its own.

Its biggest advantage is scale. A medium network produces millions of events every day - far too many for people to read. AI can quickly sort the harmless events from the likely-malicious ones, alert human staff, or take an automatic action. This lets defenders catch an attack and respond in seconds instead of days, preventing loss and damage.

That scale is what makes threat detection and response 威胁检测与响应 possible in practice: an AI system flags malicious activity as it happens, so the response team can intervene quickly enough to prevent loss, harm, or destruction of digital infrastructure — rather than reading the logs days later and finding out what was taken.

한국어

같은 기술이 우리를 보호합니다. AI 도구는 애플리케이션의 자체 소스 코드를 분석하여 취약점을 식별하고 완화策을 제안할 수 있으며, 방화벽 규칙과 접근 설정을 검토하여 더 안전한 옵션을 제안할 수도 있습니다. 다만, 전문가가 always 적용 전에 조언을 검토해야 합니다. AI는 애플리케이션 코드의 약점을 스캔하고 탐지 규칙을 제언할 수 있습니다.

️ 제안은 해결책이 아닙니다. CED는 조언이 전문적인 프로그래머에 의해 검토되고 구현되어야 함을 명시합니다. AI 도구가 결함이 실제로可利用인지에 대해 확신 있게 틀린 판단을 내릴 수 있으며, 이해하지 않은 채로 제안된 패치를 적용하면 새로운 결함을 유발할 수 있습니다.

그의 가장 큰 강점은 규모(scale) 입니다. 중간 규모의 네트워크는 매일 수백만 개의 이벤트를 생성하는데, 이는 인간이 읽기에 너무 많습니다. AI는 무해한 이벤트와 유해할 가능성이 높은 이벤트를 빠르게 구분하여, 경보(alert) 를 발사하거나 자동 조치를 취할 수 있습니다. 이는 방어자가 공격을 포착하고 수일 후가 아닌 수초 내에 대응하여 손실과 피해를 예방하도록 해줍니다.

이러한 규모가 위험 탐지 및 대응(threat detection and response) 을 현실적으로 가능하게 합니다: AI 시스템이 악의적 활동이 발생하자마자 경고를 하므로, 대응 팀이 손실, 피해, 또는 디지털 인프라 파괴를 막을 만큼 빠르게 개입(intervene) 할 수 있습니다. 대신 며칠 후에 로그를 읽고 무엇을 빼앗겼는지 알게 되는 상황을 방지합니다.

Vocabulary · ⁨어휘⁩ Train · ⁨연습하기⁩
English 한국어
threat detection and response/θret dɪˈtekʃn ænd rɪˈspɒns/ 위협 탐지 및 대응
1.5

Exam tips · ⁨시험 팁⁩

English
  • When a question asks you to rank risks, remember high risk = high impact AND easy to exploit. A parking-lot Wi-Fi leak matters less than an open internal port that lets an adversary spoof a device.
  • Learn the social-engineering tactics by name - intimidation, urgency, pretexting, authority, consensus, scarcity, familiarity - and be ready to spot which one an email is using.
  • Encryption still protects you on an evil twin: the adversary sees your traffic but cannot read HTTPS. Say what is exposed, not just "it's unsafe".
  • For "how to make authentication stronger", MFA is almost always part of the answer, plus long/unique passwords from a manager.
  • AI is dual-use: the same tool (LLMs, code analysis) appears on both the attack and the defense side. Read the question carefully to see which side it asks about.
한국어
  • 질문이 위험도를 순서대로 매기도록 요구할 때, high risk = high impact AND easy to exploit임을 기억하십시오. 주차장 Wi-Fi 누출보다 개방된 내부 포트가的攻击者에게 장치 spoofing을 허용하는 경우가 더 중요합니다.
  • 협박, 급박함, 가전(pretexting), 권위(authority), 동조 효과(consensus), 희소성(scarcity), 친숙함(familiarity) 등 사회공학적 기법의 명칭을 숙지하고 이메일이 어떤 기법을 사용하는지 식별할 준비를 하십시오.
  • 악성 쌍에서도 암호화는 여전히的保护您: 공격자는 트래픽을 보지만 HTTPS를 읽을 수 없습니다. 단순히 "안전하지 않다"가 아니라 무엇이 노출되었는지를 말하십시오.
  • "인증을 어떻게 강화하느냐"에 대한 질문에서는 MFA가 거의 항상 답변의 일부이며, 관리자의 길고 고유한 비밀번호가 함께 필요합니다.
  • AI는 이중 용도입니다. 동일한 도구(LLM, 코드 분석 등)가 공격과 방어 양측에 모두 사용됩니다. 질문을 주의 깊게 읽어 어떤 쪽을 묻고 있는지 확인하십시오.

Interactive lessons on this topic · ⁨이 주제에 대한 인터랙티브 수업⁩

Work through it step by step, with instant-check exercises. · ⁨즉시 체크 기능 exercises를 통해 단계별로 진행하세요.⁩

Past Papers · ⁨과거 시험지⁩

More topics in AP Cybersecurity · ⁨AP 사이버보안⁩ · ⁨AP Cybersecurity · ⁨AP 사이버보안⁩ 내 추가 주제⁩

Log in or create account · ⁨로그인 또는 계정 만들기⁩

IGCSE, A-Level & AP