Skip to content · ⁨ข้ามไปยังเนื้อหา⁩

Introduction to Security · ⁨แนะนำความปลอดภัย⁩

AP Cybersecurity · ⁨AP ความปลอดภัยทางไซเบอร์⁩ · Topic 1 · ⁨หัวข้อ 1⁩

Video lesson for this topic · ⁨บทเรียนวิดีโอสำหรับหัวข้อนี้⁩ Open the video page · ⁨เปิดหน้าวิดีโอ⁩
7:55

แนะนำความปลอดภัย

คุณสามารถสร้างกำแพงที่สมบูรณ์แบบ การเข้ารหัสที่ไม่สามารถทำลายได้ ไฟร์วอลล์ทุกพอร์ต และแพตช์ที่ถูกติดตั้งในวันReleased และผู้โจมตีก็ยังคงเดินเข้าไปตรงๆ...

English narration · English + 中文 subtitles burned in · ⁨การบรรยายภาษาอังกฤษ · คำบรรยายภาษาอังกฤษ + 中文 ลอยตัวบนภาพ⁩

1.1

Understanding Social Engineering · ⁨ความเข้าใจเรื่องวิศวกรรมสังคม⁩

Syllabus · ⁨หลักสูตร⁩
English

Learning Objective 1.1.A: Identify common indicators of social engineering tactics.

  • 1.1.A.1 Social engineering attacks employ psychological tactics to manipulate users into revealing sensitive information (elicitation), downloading a malicious file, or clicking on a malicious link. Social engineering can be performed in person but is often done by email, by text message, or through social media messages.
  • 1.1.A.2 Adversaries often use psychological tactics like intimidation and urgency to achieve their goals. Intimidation is when an adversary threatens a target with negative consequences if they don’t comply. Urgency is when an adversary creates reasons why a target should act quickly.

Learning Objective 1.1.B: Explain how social engineering tactics influence victims to perform a desired action.

  • 1.1.B.1 Social engineering tactics rely on common psychological principles that influence human behavior.
  • 1.1.B.2 Intimidation leverages a natural human aversion to negative consequences. By drawing attention to possible negative consequences, adversaries use fear to incite targets to act.
  • 1.1.B.3 Urgency leverages a natural human response to react quickly to time-sensitive needs. When targets detect a sense of urgency in a message, they feel pressured to respond or act quickly, which can prevent them from taking the time to consider whether an action is reasonable or safe.

Learning Objective 1.1.C: Describe possible impacts for victims of social engineering attacks.

  • 1.1.C.1 Victims may give an adversary personal information that could lead to impersonation, such as name, phone number, address, workplace, pets’ names, or birthdate. These types of information, and information like them, are often used on websites as challenge questions to verify a user’s identity.
  • 1.1.C.2 Victims may give an adversary secure information like a one-time password (OTP) or authentication login code, which could allow an adversary to log in to a service as the victim.
  • 1.1.C.3 Victims may download malware or click a link that installs malware on their device, steals information from their web browser, or directs them to a website where their login credentials can be captured by an adversary.
ไทย

จุดประสงค์การเรียนรู้ 1.1.A: ระบุสัญญาณทั่วไปของกลยุทธ์ทางสังคมวิศวกรรม

  • 1.1.A.1 การโจมตีทางสังคมวิศวกรรมใช้กลยุทธ์ทางจิตวิทยาเพื่อหลอกให้ผู้ใช้เปิดเผยข้อมูลสำคัญ (elicitation) ดาวน์โหลดไฟล์ที่เป็นอันตราย หรือคลิกที่ลิงก์ที่เป็นอันตราย การโจมตีทางสังคมวิศวกรรมสามารถทำได้โดยตรงต่อหน้า แต่มักทำผ่านอีเมล ข้อความข้อความ หรือข้อความบนโซเชียลมีเดีย
  • 1.1.A.2 ผู้โจมตีมักใช้กลยุทธ์ทางจิตวิทยาเช่นการขู่และการสร้างความเร่งด่วนเพื่อให้บรรลุเป้าหมาย การขู่คือการที่ผู้โจมตีคุกคามเป้าหมายด้วยผลเสียหากไม่ปฏิบัติตาม ส่วนความเร่งด่วนคือการที่ผู้โจมตีสร้างเหตุผลว่าทำไมเป้าหมายควรกระทำอย่างรวดเร็ว

จุดประสงค์การเรียนรู้ 1.1.B: อธิบายว่ากลยุทธ์ทางสังคมวิศวกรรมมีอิทธิพลต่อเหยื่ออย่างไร使之ดำเนินการตามที่ต้องการ

  • 1.1.B.1 กลยุทธ์ทางสังคมวิศวกรรมพึ่งพาหลักการทางจิตวิทยาทั่วไปที่มีอิทธิพลต่อพฤติกรรมมนุษย์
  • 1.1.B.2 การขู่ใช้ประโยชน์จากความเกลียดชังตามธรรมชาติของมนุษย์ต่อผลเสีย通过将ความสนใจไปที่ผลเสียที่เป็นไปได้ ผู้โจมตีใช้ความกลัวกระตุ้นให้เป้าหมายกระทำการใด动作หนึ่ง
  • 1.1.B.3 ความเร่งด่วนใช้ประโยชน์จากปฏิกิริยาตามธรรมชาติของมนุษย์ที่ต้องการตอบสนองอย่างรวดเร็วต่อความต้องการที่มีกำหนดเวลา เมื่อเป้าหมายตรวจจับความรู้สึกเร่งด่วนในข้อความ พวกเขาจะรู้สึกกดดันที่จะตอบกลับหรือกระทำอย่างรวดเร็ว ซึ่งอาจป้องกันไม่ให้他们有เวลาพิจารณาว่าการกระทำนั้นสมเหตุสมผลหรือปลอดภัยหรือไม่

จุดประสงค์การเรียนรู้ 1.1.C: อธิบายผลกระทบที่เป็นไปได้สำหรับเหยื่อของการโจมตีทางสังคมวิศวกรรม

  • 1.1.C.1 เหยื่ออาจมอบข้อมูลส่วนตัวให้ผู้โจมตีซึ่งนำไปสู่การปลอมแปลงตัวตนได้ เช่น ชื่อ หมายเลขโทรศัพท์ ที่อยู่ สถานที่ทำงาน ชื่อนกหรือสัตว์เลี้ยง หรือวันเกิด ข้อมูลประเภทนี้และข้อมูลอื่น ๆ มักใช้ในเว็บไซต์เป็นคำถามท้าทายเพื่อยืนยันตัวตนผู้ใช้
  • 1.1.C.2 เหยื่ออาจมอบข้อมูลสำคัญ如水รหัสผ่านครั้งเดียว (OTP) หรือรหัสเข้าสู่ระบบให้กับผู้โจมตี ซึ่งอาจช่วยให้ผู้ログインเข้าสู่บริการในฐานะเหยื่อได้
  • 1.1.C.3 เหยื่ออาจดาวน์โหลดมัลแวร์หรือคลิกที่ลิงก์ที่ติดตั้งมัลแวร์บนอุปกรณ์ שלה ดึงข้อมูลออกจากเว็บเบราว์เซอร์ของเธอ หรือนำเธอไปยังเว็บไซต์ที่ข้อมูลเข้าสู่ระบบของเธอถูกจับโดยผู้โจมตีได้

Source: College Board AP Course and Exam Description · ⁨แหล่งที่มา: คำอธิบายหลักสูตรและข้อสอบ College Board AP⁩

English
Phishing: how a fake email steals a password

The weakest part of any computer system is often the human using it. Social engineering 社会工程学 is the art of tricking people into breaking security - giving away a password, opening a bad file, or clicking a bad link. The attacker (we call them an adversary 对手) does not need to break the code; they only need to fool a person.

Most social engineering happens by email, text message, or social media, though it can also happen in person or by phone. The goal is elicitation 套取信息 - getting sensitive information out of someone without them realising.

Adversaries lean on two powerful feelings:

  • Intimidation 恐吓 - the adversary threatens a bad result if you do not obey. Fear pushes you to act.
  • Urgency 紧迫感 - the adversary invents a deadline ("reply in the next hour or your account closes"). When we feel rushed, we stop thinking carefully about whether an action is safe.

The impact 影响 on a victim can be serious. They might reveal personal details (name, address, pet's name, birthday) that are later used to answer security challenge questions 安全问题 and impersonate 冒充 them. They might hand over a one-time password (OTP) 一次性密码, letting the adversary log in as them. Or they might download malware 恶意软件 that steals data from their browser.

Worked example. A phishing email reads: "Over 90% of staff have already verified their account - confirm yours in the next hour or lose payroll access." Two tactics are stacked here. "In the next hour" is urgency (a deadline that rushes you), and "over 90% of staff have already" is consensus (social pressure to follow the crowd). Naming each tactic - not just calling the email "suspicious" - is exactly what an exam answer needs.

ไทย
Phishing: อีเมลปลอมขโมยรหัสผ่านได้อย่างไร

จุดอ่อนที่สุดของระบบคอมพิวเตอร์ใดๆ มักจะเป็น มนุษย์ ผู้ใช้งาน วิศวกรรมสังคม (Social engineering) คือศิลปะของการหลอกลวงคนให้ละเมิดความปลอดภัย - การมอบรหัสผ่าน การเปิดไฟล์ที่ไม่ดี หรือการคลิกลิงก์ที่ไม่ดี ผู้โจมตี (เราเรียก họว่า ผู้รุกราน/adversary) ไม่จำเป็นต้องทำลายโค้ด; พวกเขาเพียงแต่ต้องหลอกคนให้เชื่อ

วิศวกรรมสังคมส่วนใหญ่เกิดขึ้นผ่าน อีเมล ข้อความSMS หรือโซเชียลมีเดีย although它也可能发生面对面或通过电话。เป้าหมายคือ การดึงข้อมูล (elicitation) - การดึงข้อมูลละเอียดอ่อนออกมาจาก某人โดยไม่使他们意识到。

ผู้รุกรานอาศัยอารมณ์ทรงพลังสองอย่าง:

  • การขู่ (Intimidation) - ผู้รุกรานคุกคามผลลัพธ์ที่ไม่ดีหากคุณไม่ปฏิบัติตาม ความกลัวผลักดันให้คุณกระทำ
  • ความเร่งด่วน (Urgency) - ผู้รุกรานสร้างกำหนดเวลา (“ตอบภายในอีกหนึ่งชั่วโมงหรือบัญชีของคุณจะถูกปิด”) เมื่อเรารู้สึกเร่งรัด เราหยุดคิดอย่างรอบคอบว่าการกระทำนั้นปลอดภัยหรือไม่
วิศวกรรมสังคม (Social engineering) ใช้แรงกดดันทางจิตวิทยาเพื่อให้เหยื่อกระทำก่อนคิด
วิศวกรรมสังคมใช้แรงกดดันทางจิตวิทยาเพื่อให้เหยื่อกระทำก่อนที่พวกเขาจะคิด

ผลกระทบ ต่อเหยื่ออาจรุนแรง พวกเขาอาจเปิดเผยรายละเอียดส่วนตัว (ชื่อ, ที่อยู่, ชื่อสัตว์เลี้ยง, วันเกิด) ที่后被用于ตอบคำถามความปลอดภัยและ ปลอมแปลงตัวตน ของพวกเขา พวกเขาอาจมอบ รหัสผ่านครั้งเดียว (OTP) ให้ผู้รุกราน ทำให้ผู้รุกรานเข้าสู่ระบบในฐานะพวกเขา หรือพวกเขาอาจดาวน์โหลด malware ที่ stealingข้อมูลจากเบราว์เซอร์ของพวกเขา

ตัวอย่างวิธีทำ. อีเมล phishing เขียนว่า: “พนักงานกว่า 90% ยืนยันบัญชีของตนแล้ว - ยืนยันบัญชีของคุณภายในอีกหนึ่งชั่วโมงหรือสูญเสียสิทธิ์เข้าถึงเงินเดือน” มีเทคนิคสองอย่างซ้อนกันที่นี่ “ภายในอีกหนึ่งชั่วโมง” คือ ความเร่งด่วน (กำหนดเวลาที่เร่งคุณ) และ “พนักงานกว่า 90% ทำไปแล้ว” คือ ความสอดคล้อง (consensus) (แรงกดดันทางสังคมให้เดินตาม đám人群) การระบุชื่อแต่ละเทคนิค - ไม่ใช่แค่เรียกว่าอีเมลว่า “น่าสงสัย” - คือสิ่งที่คำตอบข้อสอบต้องการเป๊ะๆ

Explore · ⁨สำรวจ⁩

Which social-engineering tactic is it? · ⁨กลยุทธ์การหลอกลวงผ่านสังคมชนิดนี้คืออะไร?⁩

Intimidation threatens harm, urgency invents a deadline, consensus claims everyone else is doing it, and authority pretends to have power over you. · ⁨การข่มขู่ threats ความเสียหาย, ความเร่งด่วน สร้างdeadline, ความเห็นพ้อง声称ทุกคนทำ, และ อำนาจ Pretends มีอำนาจเหนือคุณ⁩

Vocabulary · ⁨คำศัพท์⁩ Train · ⁨ฝึกฝน⁩
English ไทย
Social engineering/ˈsəʊʃl ˌendʒɪˈnɪərɪŋ/ วิศวกรรมสังคม
adversary/ˈædvəsəri/ ศัตรู
elicitation/ɪˌlɪsɪˈteɪʃn/ การดึงข้อมูล
Intimidation/ɪnˌtɪmɪˈdeɪʃn/ การข่มขู่
Urgency/ˈɜːdʒənsi/ ความเร่งด่วน
impact/ˈɪmpækt/ ผลกระทบ
challenge questions/ˈtʃælɪndʒ ˈkwestʃnz/ คำถามท้าทาย
impersonate/ɪmˈpɜːsəneɪt/ ปลอมตัว
one-time password (OTP)/wʌn taɪm ˈpæswɜːd/ รหัสผ่านครั้งเดียว (OTP)
malware/ˈmælweə/ มัลแวร์
phishing/ˈfɪʃɪŋ/ ฟิชชิ่ง (phishing)
shared secret/ʃeəd ˈsiːkrɪt/ รหัสลับร่วมกัน
AI-enhanced coding tools/ˌeɪ ˈaɪ enˈhænst ˈkəʊdɪŋ tuːlz/ เครื่องมือเขียนโค้ดที่เสริมด้วย AI
vulnerabilities/ˌvʌlnərəˈbɪlɪtiz/ ช่องโหว่ความปลอดภัย
threat detection and response/θret dɪˈtekʃn ænd rɪˈspɒns/ การตรวจจับและตอบสนองต่อภัยคุกคาม
1.2

Suspicious Website Logins · ⁨การเข้าสู่ระบบเว็บไซต์ที่น่าสงสัย⁩

Syllabus · ⁨หลักสูตร⁩
English

Learning Objective 1.2.A: Identify common signs of a password attack.

  • 1.2.A.1 In an online password attack, adversaries try logging in to a device or service using common passwords, common password patterns, or stolen passwords.
  • 1.2.A.2 Signs of an online password attack include:
    • Many failed attempts to log in over a short duration
    • Login attempts at unusual times
    • Login attempts from unknown devices

Learning Objective 1.2.B: Explain how adversaries take advantage of weak authentication.

  • 1.2.B.1 Many people use common patterns when creating passwords, such as:
    • Starting a password with one or two words, adding a two-digit number (often signifying a year), and putting a special character at the end
    • Including the names of family or pets in their passwords
    • Including personally significant dates in their passwords
  • 1.2.B.2 Adversaries often construct a dictionary of possible passwords based on personal information gathered about a target (e.g., birthday, anniversary, names of pets and family) and use an automated tool to submit potential passwords.

Learning Objective 1.2.C: Explain how to make authentication stronger.

  • 1.2.C.1 Users should create passwords that are long, random, and unique. A password manager can be used to generate and store strong passwords, or a user may create long, unique passphrases for their accounts.
  • 1.2.C.2 When creating passwords, users should avoid names, dates, or other personally meaningful words or numbers.
  • 1.2.C.3 When available, users should enable multifactor authentication (MFA), which will require the user to provide extra proof of identity—such as a one-time code—in addition to the password as an extra layer of security.
ไทย

จุดประสงค์การเรียนรู้ 1.2.A: ระบุสัญญาณทั่วไปของการโจมตีรหัสผ่าน

  • 1.2.A.1 ในการโจมตีรหัสผ่านออนไลน์ ผู้โจมตีพยายามเข้าสู่ระบบอุปกรณ์หรือบริการโดยใช้รหัสผ่านทั่วไป รูปแบบรหัสผ่านทั่วไป หรือรหัสผ่านที่ถูกขโมย
  • 1.2.A.2 สัญญาณของการโจมตีรหัสผ่านออนไลน์ประกอบด้วย:
    • ความพยายามเข้าสู่ระบบล้มเหลวจำนวนมากในช่วงเวลาสั้น
    • ความพยายามเข้าสู่系统在เวลาที่ไม่ปกติ
    • ความพยายามเข้าสู่ระบบจากอุปกรณ์ที่ไม่รู้จัก

จุดประสงค์การเรียนรู้ 1.2.B: อธิบายว่าผู้โจมตี如何利用การยืนยันตัวตนที่อ่อนแอ

  • 1.2.B.1 หลายคนใช้รูปแบบทั่วไปเมื่อสร้างรหัสผ่าน เช่น:
    • เริ่มรหัสผ่านด้วยคำหนึ่งหรือสองคำ เพิ่มตัวเลขสองหลัก (มักหมายถึงปี) และใส่ตัวอักษรพิเศษที่ท้ายสุด
    • รวมชื่อครอบครัวหรือสัตว์เลี้ยงลงในรหัสผ่าน
    • รวมวันที่มีความหมายส่วนตัวลงในรหัสผ่าน
  • 1.2.B.2 ผู้โจมตีมักสร้างรายการรหัสผ่านที่เป็นไปได้โดยอ้างอิงจากข้อมูลส่วนบุคคลที่รวบรวมเกี่ยวกับเป้าหมาย (เช่น วันเกิด, วันครบรอบ, ชื่อสัตว์เลี้ยงและครอบครัว) และใช้เครื่องมืออัตโนมัติในการส่งรหัสผ่านที่เป็นไปได้นั้น

วัตถุประสงค์การเรียนรู้ 1.2.C: อธิบายวิธีการทำให้การยืนยันตัวตนมีความแข็งแกร่งยิ่งขึ้น

  • 1.2.C.1 ผู้ใช้ควรสร้างรหัสผ่านที่มีความยาว สุ่ม และไม่ซ้ำกับอื่น ๆ สามารถใช้โปรแกรมจัดการรหัสผ่านเพื่อสร้างและจัดเก็บรหัสผ่านที่แข็งแกร่ง หรือผู้ใช้สามารถสร้างรหัสผ่านแบบphrase ที่มีความยาวและไม่ซ้ำกันสำหรับบัญชีของตนได้
  • 1.2.C.2 ในการสร้างรหัสผ่าน ผู้ใช้ควรหลีกเลี่ยงการใช้ชื่อ วันที่ หรือคำหรือตัวเลขอื่น ๆ ที่มีนัยสำคัญต่อตนเอง
  • 1.2.C.3 เมื่อมีบริการให้เลือก ผู้ใช้ควรเปิดใช้งานการยืนยันตัวตนหลายปัจจัย (MFA) ซึ่งจะทำให้ผู้用户提供หลักฐานเพิ่มเติมเพื่อยืนยันตัวตน เช่น รหัสครั้งเดียว (one-time code) นอกจากรหัสผ่าน เพื่อเพิ่มชั้นความปลอดภัย

Source: College Board AP Course and Exam Description · ⁨แหล่งที่มา: คำอธิบายหลักสูตรและข้อสอบ College Board AP⁩

English

A password attack 密码攻击 is any attempt to log in using guessed or stolen passwords. In an online password attack the adversary tries passwords against a real login page. The warning signs are visible in the logs:

  • many failed logins in a short time,
  • login attempts at unusual hours,
  • login attempts from unknown devices.

Adversaries succeed because people choose weak 弱 passwords. Common patterns include a word plus a two-digit year plus a special character (like Summer24!), or a pet's or family member's name. Because these patterns are so common, an adversary can build a dictionary 字典 of likely passwords from information gathered about you and let an automated tool try each one.

To make authentication 身份验证 stronger:

  • Create passwords that are long, random, and unique - a password manager 密码管理器 can generate and store them for you.
  • Avoid names, dates, and meaningful words.
  • Turn on multifactor authentication (MFA) 多因素身份验证, which asks for extra proof (like a texted code) on top of the password.
ไทย
กุญแจความปลอดภัยฮาร์ดแวร์: การยืนยันตัวตนที่เข้มงวดช่วยลดความเสียหายเมื่อรหัสผ่านถูกขโมยด้วย Phishing
คีย์ความปลอดภัยฮาร์ดแวร์: การยืนยันตัวตนที่แข็งแกร่งลดความเสียหายเมื่อรหัสผ่านถูก phished

การโจมตีด้วยรหัสผ่าน (password attack) คือการพยายามเข้าสู่ระบบโดยใช้รหัสผ่านที่เดาหรือถูกขโมย ใน ออนไลน์ การโจมตีด้วยรหัสผ่าน ผู้รุกรานลองรหัสผ่านagainstหน้าเว็บเข้าสู่ระบบจริง สัญญาณเตือนจะปรากฏใน logs:

  • การ尝试เข้าสู่ระบบล้มเหลวจำนวนมากในเวลาสั้น,
  • การ尝试เข้าสู่ระบบในช่วงเวลาที่ไม่ปกติ,
  • การ尝试เข้าสู่ระบบจากอุปกรณ์ที่ไม่รู้จัก

ผู้โจมตีประสบความสำเร็จเพราะผู้คนเลือกใช้ รหัสผ่านที่อ่อนแอ รูปแบบที่พบบ่อยประกอบด้วยคำศัพท์ตามด้วยปีสองหลักและสัญลักษณ์พิเศษ (เช่น Summer24!) หรือชื่อสัตว์เลี้ยงหรือสมาชิกในครอบครัว เนื่องจากรูปแบบเหล่านี้พบบ่อยมาก ผู้โจมตีสามารถสร้าง พจนานุกรม ของรหัสผ่านที่เป็นไปได้จากข้อมูลที่ได้มาเกี่ยวกับคุณ และให้เครื่องมืออัตโนมัติลองใช้แต่ละตัว

เพื่อให้ การยืนยันตัวตน เข้มข้นขึ้น:

  • สร้างรหัสผ่านที่มี ความยาว, สุ่ม, และไม่ซ้ำใคร - โปรแกรมจัดการรหัสผ่าน สามารถสร้างและจัดเก็บให้คุณได้
  • หลีกเลี่ยงชื่อ, วันที่, และคำที่มีความหมาย
  • เปิดใช้งาน การยืนยันตัวตนหลายปัจจัย (MFA) ซึ่งขอหลักฐานเพิ่มเติม (เช่น รหัสที่ส่งทางข้อความ) นอกจากรหัสผ่าน
Vocabulary · ⁨คำศัพท์⁩ Train · ⁨ฝึกฝน⁩
English ไทย
password attack/ˈpæswɜːd əˈtæk/ การโจมตีรหัสผ่าน
weak/wiːk/ อ่อนแอ (Weak)
dictionary/ˈdɪkʃənəri/ dictionary
authentication/ɔːˌθentɪˈkeɪʃn/ authentication
password manager/ˈpæswɜːd ˈmænɪdʒə/ ผู้จัดการรหัสผ่าน
multifactor authentication (MFA)/ˌmʌltɪˈfæktə ɔːˌθentɪˈkeɪʃn/ การยืนยันตัวตนหลายปัจจัย (MFA)
1.3

Best Practices for Public Networks · ⁨แนวปฏิบัติที่ดีสำหรับเครือข่ายสาธารณะ⁩

Syllabus · ⁨หลักสูตร⁩
English

Learning Objective 1.3.A: Identify the type of adversary conducting a cyberattack.

  • 1.3.A.1 Adversaries can be classified by their skill levels.
    • Low-skilled adversaries rely on malicious cyber tools created by others that can be purchased online. The tools they use exploit known vulnerabilities.
    • High-skilled adversaries have the capacity to create new malicious cyber tools or modify existing ones to adapt to new defensive techniques and tools. They also have the capacity to discover undocumented vulnerabilities, known as zero days.
  • 1.3.A.2 Adversaries have a variety of motivations, including greed, desire for recognition, dedication to a cause, revenge, politics, or beliefs.

Learning Objective 1.3.B: Identify types of wireless cyberattacks.

  • 1.3.B.1 In an evil twin attack, an adversary sets up their own wireless access point (WAP) with a service set identifier (SSID) similar or identical to a target network; the adversary’s network is called the evil twin. Victims of this attack could select to unknowingly connect to the evil twin, allowing the adversary to capture their network traffic. The adversary cannot read traffic that uses an encrypted protocol like HTTPS.
  • 1.3.B.2 In a jamming attack, an adversary floods an area with a strong electromagnetic (EM) signal in the same frequency range as the wireless network, which prevents legitimate traffic between the access point (AP) and users. This type of attack that prevents users from accessing resources is called a denial of service (DoS) attack.
  • 1.3.B.3 In a war driving attack, adversaries try to detect wireless network beacons while driving or walking around a target. If a wireless signal is detected, the adversary can gather information about the type of wireless network used and find areas where the wireless signal extends outside the physical building.

Learning Objective 1.3.C: Describe actions individuals can take to increase protection of sensitive data when using the internet and Wi-Fi.

  • 1.3.C.1 Individuals should verify that the name of any wireless network they join exactly matches the name of the network they intend to join.
  • 1.3.C.2 Most internet protocols are encrypted to protect network traffic. However, individuals may consider the sensitivity of their data in choosing whether to join unencrypted Wi-Fi networks to protect vulnerable data such as DNS queries.
  • 1.3.C.3 Individuals may consider using a virtual private network (VPN), which encrypts all their traffic to the VPN operator’s system. Although this action prevents a service provider from viewing traffic, the VPN provider can view the traffic.
ไทย

วัตถุประสงค์การเรียนรู้ 1.3.A: ระบุประเภทของผู้โจมตี正在进行ไซเบอร์แอทแทค

  • 1.3.A.1 ผู้โจมตีสามารถจำแนกตามระดับทักษะได้
    • ผู้โจมตีที่มีทักษะต่ำพึ่งพามัลแวร์หรือเครื่องมือไซเบอร์ร้ายแรงที่其他人สร้างขึ้น ซึ่งสามารถซื้อออนไลน์ได้ เครื่องมือที่ใช้จะ aproveit vulnerabilities ที่รู้จักแล้ว
    • ผู้โจมตีที่มีทักษะสูงมีความสามารถในการสร้างเครื่องมือไซเบอร์ร้ายแรงใหม่หรือดัดแปลงเครื่องมือที่มีอยู่ให้ปรับตัวเข้ากับเทคนิคและเครื่องมือป้องกันใหม่ ๆ พวกเขา还具有 capacity เพื่อค้นพบ vulnerabilities ที่ไม่มีเอกสาร记录下来 ซึ่งเรียกว่า zero days
  • 1.3.A.2 ผู้โจมตีมี动机หลากหลาย รวมถึงความโลภ, ความต้องการได้รับการยอมรับ, การอุทิศตนต่อสาเหตุหนึ่ง, ความ报复, การเมือง, หรือความเชื่อ

วัตถุประสงค์การเรียนรู้ 1.3.B: ระบุประเภทของการโจมตีไซเบอร์ผ่านไร้สาย

  • 1.3.B.1 ในการโจมตี evil twin ผู้โจมตีจะตั้ง access point ไร้สายของตนเอง (WAP) ที่มี service set identifier (SSID) คล้ายหรือเหมือน網絡เป้าหมาย;erior ของผู้โจมตีจะถูกเรียกว่า evil twin ผู้ถูกโจมตีอาจเลือกที่จะเชื่อมต่อไปยัง evil twin โดยไม่รู้ตัว ทำให้ผู้.attack者สามารถ capture network traffic ได้ ผู้.attack者ไม่สามารถอ่าน traffic ที่ใช้ encrypted protocol อย่าง HTTPS ได้
  • 1.3.B.2 ในการโจมตี jamming ผู้.attack者จะ flood พื้นที่ด้วย electromagnetic (EM) signal ที่แรงในช่วง frequency เดียวกับ wireless network ซึ่งจะทำให้ legitimate traffic ระหว่าง access point (AP) กับ users ไม่สามารถดำเนินการได้ การโจมตีประเภทนี้ที่ prevents users จาก accessing resources ถูกเรียกว่า denial of service (DoS) attack
  • 1.3.B.3 ในการโจมตี war driving ผู้.attack者พยายาม detect wireless network beacons ขณะขับรถหรือเดินสำรวจรอบเป้าหมาย หาก detects wireless signal ผู้.attack者สามารถ gather ข้อมูลเกี่ยวกับประเภทของ wireless network ที่ใช้ และ find areas ที่ wireless signal ครอบคลุมภายนอกอาคาร

วัตถุประสงค์การเรียนรู้ 1.3.C: อธิบายการกระทำที่บุคคลสามารถทำได้เพื่อเพิ่มการปกป้องข้อมูลสำคัญเมื่อใช้อินเทอร์เน็ตและ Wi-Fi

  • 1.3.C.1 บุคคลควรตรวจสอบว่าชื่อของ wireless network ที่เข้าร่วมตรงกับชื่อของ networks ที่ตั้งใจจะเชื่อมต่อกันอย่างแท้จริง
  • 1.3.C.2 โปรโตคอลอินเทอร์เน็ตส่วนใหญ่มีการ encrypt เพื่อปกป้อง network traffic อย่างไรก็ตาม บุคคลอาจพิจารณาความสำคัญของข้อมูลของตนในการเลือก whether จะเชื่อมต่อกับ unencrypted Wi-Fi networks เพื่อปกป้องข้อมูลที่เสี่ยงต่อการถูกเข้าถึง เช่น DNS queries
  • 1.3.C.3 บุคคลอาจพิจารณาการใช้ virtual private network (VPN) ซึ่ง will encrypt ทั้งหมด traffic ไปยังระบบของ VPN operator Although การกระทำนี้จะ prevents service provider จาก viewing traffic แต่ VPN provider สามารถ viewing traffic ได้

Source: College Board AP Course and Exam Description · ⁨แหล่งที่มา: คำอธิบายหลักสูตรและข้อสอบ College Board AP⁩

English

Not all adversaries are the same. We classify them by skill: low-skilled attackers buy ready-made tools online and reuse known exploits 漏洞利用, while high-skilled attackers write their own tools and can discover brand-new holes called zero days 零日漏洞. Their motivation 动机 varies too - greed, revenge, politics, or belief.

Public Wi-Fi is a favourite hunting ground. Three wireless attacks you must know:

  • Evil twin 双胞胎恶意热点 - the adversary sets up a fake access point 接入点 with a name (SSID 服务集标识符) copied from the real network. Victims connect to the fake one, and the adversary reads their traffic (though encrypted 加密的 sites like HTTPS stay safe).
  • Jamming 干扰攻击 - the adversary floods the air with a strong radio signal so no one can connect. This is one kind of denial of service (DoS) 拒绝服务 attack.
  • War driving 战争驾驶 - the adversary drives around detecting wireless networks and where their signal leaks outside a building.

To protect yourself on public networks: check that the network name exactly matches the one you intend to join, prefer encrypted sites, and consider a virtual private network (VPN) 虚拟专用网络, which encrypts all of your traffic to the VPN operator.

ไทย
โทكنความปลอดภัย: โค้ดครั้งเดียวและโทكنช่วยป้องกันไม่ให้การใช้เพียงรหัสผ่านในการเข้าสู่ระบบเพียงพอ
โทkenความปลอดภัย: โค้ดครั้งเดียวและโทkenช่วยป้องกันไม่ให้การใช้เพียงรหัสผ่านในการเข้าสู่ระบบเพียงพอ

ผู้โจมตีไม่เหมือนกันทั้งหมด เราจำแนกพวกเขาตาม ทักษะ: ผู้โจมตีระดับต่ำซื้อเครื่องมือสำเร็จรูปออนไลน์และนำ ช่องโหว่ Known exploits มาใช้ซ้ำ ในขณะที่ผู้โจมตีระดับสูงเขียนเครื่องมือของตนเองและสามารถค้นพบช่องโหว่ใหม่ทั้งหมดที่เรียกว่า วันศูนย์ (zero days) แรงจูงใจ ของพวกเขาก็แตกต่างกันไป - ความโลภ, การเอาคืน, การเมือง, หรือความเชื่อ

Wi-Fi สาธารณะเป็นพื้นที่ล่าเหยื่อที่นิยมที่สุด การโจมตีไร้สายสามประเภทที่คุณต้องรู้:

  • Evil twin - ผู้โจมตีตั้งจุดเข้าถึง (access point) ปลอมที่มีชื่อ (SSID) คัดลอกมาจากเครือข่ายจริง ผู้ถูกหลอกลวงเชื่อมต่อกับปลอม และผู้โจมตีอ่านการจราจรของพวกเขา (แม้ว่า เว็บไซต์ที่เข้ารหัส เช่น HTTPS จะยังคงปลอดภัย)
  • Jamming - ผู้โจมตีล้นอากาศด้วยสัญญาณวิทยุที่แข็งแกร่งเพื่อให้ไม่มีใครเชื่อมต่อได้นี้เป็นการโจมตีแบบ ปฏิเสธการให้บริการ (DoS) หนึ่งชนิด
  • War driving - ผู้ขับรถสำรวจเพื่อตรวจจับเครือข่ายไร้สายและตำแหน่งที่สัญญาณรั่วไหลออกจากอาคาร
จุดเข้าถึง evil-twin คัดลอกชื่อเครือข่ายจริงเพื่อให้ผู้ถูกหลอกลวงเชื่อมต่อกับผู้โจมตี
จุดเข้าถึง evil-twin คัดลอกชื่อเครือข่ายจริงเพื่อให้ผู้ถูกหลอกลวงเชื่อมต่อกับผู้โจมตี

เพื่อปกป้องตนเองบนเครือข่ายสาธารณะ: ตรวจสอบให้แน่ใจว่าชื่อเครือข่าย ตรงกัน กับที่ intends จะเชื่อมต่ออย่างสมบูรณ์, เลือกใช้เว็บไซต์ที่มีระบบเข้ารหัส, และพิจารณาใช้ เครือข่ายส่วนตัวเสมือน (VPN) ซึ่งจะเข้ารหัสทุกการรับส่งข้อมูลไปยังผู้ให้บริการ VPN

Vocabulary · ⁨คำศัพท์⁩ Train · ⁨ฝึกฝน⁩
English ไทย
exploits/ˈeksplɔɪts/ การ利用了
zero days/ˈzɪərəʊ deɪz/ วันศูนย์
motivation/ˌməʊtɪˈveɪʃn/ แรงจูงใจ
Evil twin/ˈiːvl twɪn/ Evil twin
access point/ˈækses pɔɪnt/ จุดเข้าถึง
SSID/ˌes es aɪ ˈdiː/ ชื่อเครือข่ายไร้สาย
encrypted/enˈkrɪptɪd/ encrypted
Jamming/ˈdʒæmɪŋ/ Jamming
denial of service (DoS)/dɪˈnaɪəl ɒv ˈsɜːvɪs/ การปฏิเสธการให้บริการ (DoS)
War driving/wɔː ˈdraɪvɪŋ/ War driving
virtual private network (VPN)/ˈvɜːtʃuːəl ˈpraɪvət ˈnetwɜːk/ เครือข่ายส่วนตัวเสมือน (VPN)
1.4

AI-Based Cybersecurity Attacks · ⁨การโจมตีทางไซเบอร์ด้วย AI⁩

Syllabus · ⁨หลักสูตร⁩
English

Learning Objective 1.4.A: Explain how adversaries use AI-powered tools to augment cyberattacks.

  • 1.4.A.1 Adversaries can use AI-powered tools that leverage existing voice and image samples of a person to create a digital avatar of that person. The use of these technologies enables adversaries to impersonate someone over the phone or even on a video call, which can lead to financial loss or the sharing of sensitive or private information. As more organizations adopt voice-based authentication, the impact of voice-impersonation has a larger potential impact.
  • 1.4.A.2 Adversaries can use generative AI tools, like large language models (LLMs), to create convincing phishing messages in any target language. Because traditional phishing messages are sometimes written by non-native speakers of the target’s language, unnatural language is a feature that has been used to distinguish phishing messages from legitimate messages. However, with AI tools, adversaries can now craft phishing messages in any language that read as though they were written by a native speaker.
  • 1.4.A.3 Adversaries can craft prompts that extract secure or sensitive information from LLMs. Secure or sensitive information in LLMs can come from user input and the large data sets used to train LLMs.
  • 1.4.A.4 Adversaries can publish websites or modify existing websites to contain false information so that the false information will be included in the training sets for LLMs, causing the LLMs to repeat the false information.
  • 1.4.A.5 Adversaries can perform reconnaissance on a target using AI-powered tools that scan the internet to gather information posted on social media and public websites.
  • 1.4.A.6 Adversaries can use AI-enhanced coding tools to help them write new malware, modify existing application code to perform malicious activities, or to find vulnerabilities in large code bases.

Learning Objective 1.4.B: Explain how to protect against some AI-augmented cyberattacks.

  • 1.4.B.1 Shared secrets with close friends and relatives that can be used to verify each other’s identities should be established. A secret word or phrase known only to two parties can be used to authenticate identities in high-stakes situations.
  • 1.4.B.2 Multifactor authentication (MFA) should be enabled. If an adversary clones a target’s voice to access a system with voice authentication, requiring a second authentication factor could prevent an adversary from gaining access to accounts.
  • 1.4.B.3 Personal or sensitive data should not be entered into any AI-powered tools, such as chatbots or virtual assistants. Some AI-powered tools feed user input back into the model to provide continuous training. Adversaries could extract data that users have included in prompts.
  • 1.4.B.4 Output from AI-powered tools should be carefully evaluated. Verify information from AI-powered tools using reputable, stable, non-AI-based sources.
ไทย

วัตถุประสงค์การเรียนรู้ 1.4.A: อธิบายว่าผู้.attack者如何利用 AI-powered tools เพื่อเสริมการโจมตีไซเบอร์

  • 1.4.A.1 ผู้.attack者สามารถใช้ AI-powered tools ที่ leverage voice และ image samples ของบุคคลเพื่อสร้าง digital avatar ของบุคคลนั้น การใช้เทคโนโลยีเหล่านี้ช่วยให้ผู้.attack者 impersonate คนอื่นทางโทรศัพท์หรือแม้กระทั่งใน video call ซึ่ง可能导致 financial loss หรือการ sharing sensitive/private information เมื่อ organizations越多采用 voice-based authentication则 voice-impersonation impact越大
  • 1.4.A.2 ผู้.attack者สามารถใช้ generative AI tools เช่น large language models (LLMs) เพื่อสร้าง phishing messages ที่น่าเชื่อถือ在任何目标语言中。因为传统的phishing messages有时由非目标语言的母语者编写,不自然的语言特征曾被用于区分phishing消息与合法消息。然而,借助AI工具,攻击者现在可以编写任何语言的钓鱼信息,使其读起来像是由母语者撰写的。
  • 1.4.A.3 ผู้.attack者สามารถ crafting prompts เพื่อ extract secure หรือ sensitive information จาก LLMs Secure หรือ sensitive information ใน LLMs สามารถมาจาก user input และ large datasets ที่ใช้ train LLMs
  • 1.4.A.4 ผู้.attack者สามารถ publish Websites หรือ modify existing websites ให้ contain false information เพื่อให้ false information นั้น被 included ใน training sets สำหรับ LLMs ซึ่ง会导致 LLMs重复 false information
  • 1.4.A.5 ผู้.attack者สามารถ perform reconnaissance บนเป้าหมายโดยใช้ AI-powered tools ที่ scan internet เพื่อ gather information posted ใน social media และ public websites
  • 1.4.A.6 ผู้.attack者สามารถใช้ AI-enhanced coding tools เพื่อช่วย write malware ใหม่, modify existing application code เพื่อทำ malicious activities, หรือหา vulnerabilities ใน large code bases

วัตถุประสงค์การเรียนรู้ 1.4.B: อธิบายวิธีการปกป้องจากการโจมตีไซเบอร์ที่ถูกเสริมด้วย AI บางประเภท

  • 1.4.B.1 ควรกำหนดรหัสลับที่แบ่งปันกันกับเพื่อนสนิทและครอบครัว ซึ่งสามารถใช้ยืนยันตัวตนซึ่งและซึ่งได้ รหัสลับหรือวลีที่只知道โดยสองฝ่ายเท่านั้นสามารถใช้ในการยืนยันตัวตนในสถานการณ์ที่มีความเสี่ยงสูง
  • 1.4.B.2 ควรเปิดใช้งานการยืนยันตัวตนหลายปัจจัย (MFA) หากผู้โจมตีจำลองเสียงเป้าหมายเพื่อเข้าสู่ระบบที่มีการยืนยันตัวตนด้วยเสียง การขอปัจจัยยืนยันตัวตนเพิ่มเติมอาจป้องกันไม่ให้ผู้.attack者的เข้าถึงบัญชีได้
  • 1.4.B.3 ไม่ควรป้อนข้อมูลส่วนบุคคลหรือข้อมูลที่ละเอียดอ่อนลงในเครื่องมือanything powered by AI เช่น แชทบอทหรือผู้ช่วยเสมือน เครื่องมือบางtool that powered by AI นำข้อมูลผู้ใช้กลับเข้าไปในโมเดลเพื่อใช้สำหรับการฝึกฝนอย่างต่อเนื่อง ผู้.attackers could extract data that users have included in prompts.
  • 1.4.B.4 ควรประเมินผลลัพธ์จากเครื่องมือpowered by AI อย่างระมัดระวัง ตรวจสอบข้อมูลจากเครื่องมือpowered by AI โดยใช้แหล่งข้อมูลที่มีชื่อเสียง มั่นคง และไม่ใช้AI-based sources.

Source: College Board AP Course and Exam Description · ⁨แหล่งที่มา: คำอธิบายหลักสูตรและข้อสอบ College Board AP⁩

English

Artificial intelligence gives adversaries powerful new tools. With enough voice and image samples, an adversary can build a deepfake 深度伪造 avatar to impersonate someone on a call. Large language models (LLMs) 大语言模型 let them write convincing phishing 钓鱼 emails in perfect, native-sounding language - removing the clumsy wording that once gave scams away.

AI also helps adversaries on the back end: crafting prompts that pull secret data out of an LLM, planting false information on websites so it poisons an LLM's training data, scanning the internet to gather facts about a target, and even writing new malware.

You can defend against many AI-augmented attacks: agree on a shared secret 共享秘密 word with close contacts to verify identity, enable MFA (so a cloned voice alone cannot log in), never type sensitive data into a chatbot, and always double-check AI output against reliable, non-AI sources.

AI writes code, and that cuts both ways. Adversaries use AI-enhanced coding tools 人工智能辅助编程工具 to write new malware faster than they could by hand, to modify existing application code so that it performs malicious activity, and to scan a codebase for vulnerabilities 漏洞 to attack. The skill barrier falls: someone who could not previously write an exploit can now ask for one, so the number of capable attackers rises even when no new technique is invented.

ไทย

ปัญญาประดิษฐ์มอบเครื่องมือใหม่ที่มีประสิทธิภาพให้ฝ่ายตรงข้าม เมื่อมีตัวอย่างเสียงและภาพเพียงพอ ฝ่ายตรงข้ามสามารถสร้าง ดีฟייก (deepfake) เพื่อปลอมตัวเป็นบุคคลอื่นในการโทรเข้าได้ โมเดลภาษาขนาดใหญ่ (LLMs) ช่วยให้อาจเขียนอีเมล หลอกลวง (phishing) ที่น่าเชื่อถือได้ด้วยภาษาที่ถูกต้องตามธรรมชาติ - กำจัดคำพูดที่ผิดเพี้ยนซึ่งเคยเป็นจุดบ่งชี้ของมิจฉาชีพ

AI ยังช่วยให้ฝ่ายตรงข้าม ทำงานเบื้องหลัง: สร้างคำสั่งดึงข้อมูลลับออกจาก LLM, ฝังข้อมูลเท็จในเว็บเพื่อทำลายคุณภาพข้อมูลฝึกสอนของ LLM, สแกนอินเทอร์เน็ตเพื่อรวบรวมข้อมูลเป้าหมาย และแม้กระทั่งเขียนมัลแวร์ใหม่

คุณสามารถป้องกัน MANY การโจมตีที่เสริมด้วย AI: ตั้งคำรหัสลับร่วมกันกับคนใกล้ชิดเพื่อยืนยันตัวตน, เปิดใช้งาน MFA (เพื่อให้เสียงที่ถูกเลียนแบบเพียงอย่างเดียวไม่สามารถล็อกอินได้), ห้ามกรอกข้อมูลสำคัญลงในแชทบอท, และตรวจสอบผลลัพธ์ของ AI เสมอเทียบกับแหล่งข้อมูลที่เชื่อถือได้ที่ไม่ใช่ AI

AI เขียนโค้ดได้ และสิ่งนี้เกิดขึ้นได้ทั้งสองด้าน ฝ่ายตรงข้ามใช้ เครื่องมือเขียนโค้ดที่เสริมด้วย AI เพื่อสร้าง มัลแวร์ ใหม่ได้เร็วกว่าทำเอง, แก้ไขโค้ดแอปพลิเคชันเดิมให้ดำเนินการที่ชั่วร้าย, และสแกนฐานโค้ดเพื่อหา ช่องโหว่ เพื่อโจมตี มาตรฐานความยากลดลง: คนที่เคยเขียน exploit ไม่ได้ ตอนนี้สามารถขอได้ ดังนั้นจำนวนผู้โจมตีที่มีความสามารถจึงเพิ่มขึ้นแม้จะไม่มีการเทคนิคใหม่ใดถูกคิดขึ้นเลย

Vocabulary · ⁨คำศัพท์⁩ Train · ⁨ฝึกฝน⁩
English ไทย
deepfake/ˈdiːpfeɪk/ deepfake
Large language models (LLMs)/lɑːdʒ ˈlæŋɡwɪdʒ ˈmɒdlz/ โมเดลภาษาขนาดใหญ่ (LLMs)
1.5

Leveraging AI in Cyber Defense · ⁨การใช้ AI ในการป้องกันภัยไซเบอร์⁩

Syllabus · ⁨หลักสูตร⁩
English

Learning Objective 1.5.A: Explain how cyber defenders can leverage AI-powered tools to protect networks, applications, and data.

  • 1.5.A.1 AI tools can review current security configurations, like firewall rules and access controls, and recommend more secure options. Recommendations should always be checked by a knowledgeable security technician before being implemented.
  • 1.5.A.2 AI-powered tools can analyze application code to identify vulnerabilities and recommend mitigations. Recommendations should always be reviewed by a knowledgeable programmer before being implemented.
  • 1.5.A.3 AI-powered tools can suggest rules for automated detection systems. Detection rules should always be reviewed by a knowledgeable detection engineer before being added to a system.

Learning Objective 1.5.B: Explain how AI-powered tools are enabling faster and more accurate threat detection and response.

  • 1.5.B.1 Of the millions of digital events that happen on networks daily, some likely represent an adversary conducting malicious activity. Humans cannot carefully examine all those events to identify the malicious activity.
  • 1.5.B.2 AI-powered tools can be trained to quickly analyze digital events and sort the events that are likely malicious activity from those that are harmless.
  • 1.5.B.3 AI-powered tools can be programmed to alert human cybersecurity personnel when likely malicious activity is detected or to take specific corrective actions based on the type of malicious activity detected.
  • 1.5.B.4 AI-powered tools enable threat-detection and response teams to catch malicious activity and intervene quickly to prevent loss, harm, damage, and destruction to digital infrastructure and data.
ไทย

วัตถุประสงค์การเรียนรู้ 1.5.A: อธิบายว่านักป้องกันไซเบอร์如何利用AI-powered tools to protect networks, applications, and data.

  • 1.5.A.1 AI-powered tools สามารถตรวจสอบการตั้งค่าความปลอดภัยปัจจุบัน เช่น กฎของไฟร์วอลล์และการควบคุมการเข้าถึง และเสนอตัวเลือกที่ปลอดภัยยิ่งขึ้น คำแนะนำควรได้รับการตรวจสอบโดยเทคนิคด้านความปลอดภัยที่มีความรู้ก่อนนำไปใช้
  • 1.5.A.2 AI-powered tools สามารถวิเคราะห์โค้ดแอปพลิเคชันเพื่อระบุช่องโหว่และเสนอมาตรการบรรเทา คำแนะนำควรได้รับการทบทวนโดยโปรแกรมเมอร์ที่มีความรู้ก่อนนำไปใช้
  • 1.5.A.3 AI-powered tools สามารถเสนอกฎสำหรับระบบตรวจจับอัตโนมัติ กฎการตรวจจับควรได้รับการทบทวนโดยวิศวกรตรวจจับที่มีความรู้ก่อนเพิ่ม vào hệ thống

วัตถุประสงค์การเรียนรู้ 1.5.B: อธิบายว่าAI-powered tools如何 enabling faster and more accurate threat detection and response.

  • 1.5.B.1 จากเหตุการณ์ดิจิทัลนับล้านที่เกิดขึ้นบนเครือข่ายทุกวัน บางเหตุการณ์อาจเป็นสัญญาณของผู้.attackers who are conducting malicious activity Humans cannot carefully examine all those events to identify the malicious activity.
  • 1.5.B.2 AI-powered tools can be trained to quickly analyze digital events and sort the events that are likely malicious activity from those that are harmless.
  • 1.5.B.3 AI-powered tools can be programmed to alert human cybersecurity personnel when likely malicious activity is detected or to take specific corrective actions based on the type of malicious activity detected.
  • 1.5.B.4 AI-powered tools enable threat-detection and response teams to catch malicious activity and intervene quickly to prevent loss, harm, damage, and destruction to digital infrastructure and data.

Source: College Board AP Course and Exam Description · ⁨แหล่งที่มา: คำอธิบายหลักสูตรและข้อสอบ College Board AP⁩

English

The same technology defends us. AI tools can analyse an application's own source code, identify vulnerabilities in it and recommend mitigations; they can also review firewall rules and access settings and recommend safer options - though a human expert must always check the advice before applying it. AI can scan application code for weaknesses and suggest detection rules.

⚠️ A recommendation is not a fix. The CED is explicit that the advice must be reviewed and implemented by a knowledgeable programmer: an AI tool can be confidently wrong about whether a flaw is exploitable, and applying a suggested patch without understanding it can introduce a new fault of its own.

Its biggest advantage is scale. A medium network produces millions of events every day - far too many for people to read. AI can quickly sort the harmless events from the likely-malicious ones, alert human staff, or take an automatic action. This lets defenders catch an attack and respond in seconds instead of days, preventing loss and damage.

That scale is what makes threat detection and response 威胁检测与响应 possible in practice: an AI system flags malicious activity as it happens, so the response team can intervene quickly enough to prevent loss, harm, or destruction of digital infrastructure — rather than reading the logs days later and finding out what was taken.

ไทย

เทคโนโลยีเดียวกันนี้ยังช่วยปกป้องเราอยู่ AI สามารถวิเคราะห์ซอร์สโค้ดของแอปพลิเคชัน, ระบุ ช่องโหว่, และ เสนอแนวทางแก้ไข; รวมถึงตรวจสอบกฎไฟวอลล์และการตั้งค่าการเข้าถึงและ เสนอทางเลือกที่ปลอดภัยกว่า - แม้แต่ผู้เชี่ยวชาญด้านมนุษย์ต้องตรวจสอบคำแนะนำก่อนนำไปใช้เสมอ AI สามารถสแกนโค้ดแอปฯ เพื่อหาจุดอ่อนและแนะนำกฎการตรวจจับ

⚠️ คำแนะนำไม่ใช่การแก้ปัญหา CED ชี้ชัดว่าคำแนะนำต้องได้รับการตรวจสอบและดำเนินการโดย นักพัฒนาที่มีความรู้: AI อาจผิดพลาดอย่างมั่นใจเกี่ยวกับความเป็นไปได้ที่จะถูกเจาะจง และการนำแพตช์ที่แนะนำไปใช้โดยไม่เข้าใจอาจทำให้เกิดข้อผิดพลาดใหม่ได้เอง

ข้อได้เปรียบที่ใหญ่ที่สุดคือ ปริมาณ เครือข่ายขนาดกลางสร้างเหตุการณ์นับล้านต่อวัน - มากเกินกว่าคนจะอ่านได้ AI สามารถคัดกรองเหตุการณ์ที่ปลอดภัยจาก事件的ที่อาจเป็นอันตรายได้อย่างรวดเร็ว, แจ้งเตือน พนักงานมนุษย์, หรือดำเนินการอัตโนมัติ สิ่งนี้ช่วยให้ทีมป้องกันจับการโจมตีและตอบสนองภายในไม่กี่วินาทีแทนที่จะเป็นหลายวัน ป้องกันความเสียหายและสูญเสีย

ปริมาณมหาศาล inilahที่ทำให้ การตรวจจับภัยคุกคามและการตอบสนอง เป็นไปได้ในทางปฏิบัติ: ระบบ AI จะระบุกิจกรรมที่ชั่วร้ายทันทีที่มันเกิดขึ้น ทำให้ทีมตอบสนองสามารถ แทรกแซงได้อย่างรวดเร็ว เพียงพอเพื่อป้องกันความสูญเสีย ความเสียหาย หรือการทำลายโครงสร้างพื้นฐานดิจิทัล - แทนที่จะมาอ่านบันทึกหลังเกิดเหตุหลายวันแล้ว才知道สิ่งที่หายไป

1.5

Exam tips · ⁨ข้อแนะนำสำหรับการสอบ⁩

English
  • When a question asks you to rank risks, remember high risk = high impact AND easy to exploit. A parking-lot Wi-Fi leak matters less than an open internal port that lets an adversary spoof a device.
  • Learn the social-engineering tactics by name - intimidation, urgency, pretexting, authority, consensus, scarcity, familiarity - and be ready to spot which one an email is using.
  • Encryption still protects you on an evil twin: the adversary sees your traffic but cannot read HTTPS. Say what is exposed, not just "it's unsafe".
  • For "how to make authentication stronger", MFA is almost always part of the answer, plus long/unique passwords from a manager.
  • AI is dual-use: the same tool (LLMs, code analysis) appears on both the attack and the defense side. Read the question carefully to see which side it asks about.
ไทย
  • เมื่อโจทย์ถามให้ลำดับความเสี่ยง จำไว้ว่า ความเสี่ยงสูง = ผลกระทบสูง AND ง่ายต่อการถูกเจาะ การรั่วไหล Wi-Fi ในที่จอดรถมีความสำคัญน้อยกว่า พอร์ตภายในที่เปิดออกที่ทำให้ฝ่ายตรงปลอมแปลงอุปกรณ์ได้
  • เรียนรู้เทคนิคทางสังคมวิทยาตามชื่อ - การข่มขู่, ความเร่งด่วน, การสร้างเรื่องเล่า, อำนาจ, ความเห็นพ้องต้องกัน, ความ khanit, ความคุ้นเคย - และเตรียมพร้อมที่จะระบุได้ว่าอีเมลนั้นใช้เทคนิคใด
  • การเข้ารหัสยังคงปกป้องคุณจาก Evil Twin: ฝ่ายตรงเห็นการรับส่งข้อมูลของคุณแต่ไม่สามารถอ่าน HTTPS ได้ บอก สิ่ง gì ที่ถูกเปิดเผย ไม่ใช่แค่บอกว่า "ไม่ปลอดภัย"
  • สำหรับคำถามว่า "ทำให้การยืนยันตัวตนแข็งแรงขึ้นอย่างไร" MFA มักจะเป็นคำตอบเสมอ พร้อมด้วยรหัสผ่านยาว/เฉพาะบุคคลจากโปรแกรมจัดการรหัสผ่าน
  • AI เป็น dual-use: เครื่องมือเดียวกัน (LLMs, การวิเคราะห์โค้ด) ปรากฏทั้งในฝั่งโจมตีและฝั่งป้องกัน อ่านคำถามให้ละเอียดเพื่อดูว่าโจทย์ถามถึงด้านใด

Interactive lessons on this topic · ⁨บทเรียนเชิงโต้ตอบสำหรับหัวข้อนี้⁩

Work through it step by step, with instant-check exercises. · ⁨ทำทีละขั้นตอน พร้อมแบบฝึกหัดตรวจสอบผลทันที⁩

Past Papers · ⁨ข้อสอบย้อนหลัง⁩

More topics in AP Cybersecurity · ⁨AP ความปลอดภัยทางไซเบอร์⁩ · ⁨หัวข้อเพิ่มเติมใน AP Cybersecurity · ⁨AP ความปลอดภัยทางไซเบอร์⁩⁩

Log in or create account · ⁨เข้าสู่ระบบหรือสร้างบัญชี⁩

IGCSE, A-Level & AP