Skip to content · ⁨Bỏ qua nội dung⁩
Subjects · ⁨Môn học⁩

AP Cybersecurity · ⁨AP An ninh mạng⁩

Tips · ⁨Mẹo⁩

AP Cybersecurity covers the CIA triad, threats and vulnerabilities, access control and authentication, cryptography, network security, secure software, incident response, and security policy, law and ethics. It is a new course, so no released exams exist yet and the Course and Exam Description is the authority on what is examinable.

The reasoning is defensive. A question is usually "here is a system, what could go wrong and what would you do about it" — which needs a named threat, a named control, and a reason the control addresses that threat.

Learn the vocabulary precisely. Authentication is not authorisation; hashing is not encryption; a vulnerability is not a threat. These distinctions are what questions are built on.

Notes follow the CED across threats, cryptography, networking and defence, with practical examples you can try in the browser. Because the course is new, the library carries the sample questions released so far rather than a run of past papers.

  • 1

    Introduction to Security · ⁨Giới thiệu về Bảo mật⁩

    Watch lesson · ⁨Xem bài học⁩
    1.1

    Understanding Social Engineering

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 1.1.A: Identify common indicators of social engineering tactics.

    • 1.1.A.1 Social engineering attacks employ psychological tactics to manipulate users into revealing sensitive information (elicitation), downloading a malicious file, or clicking on a malicious link. Social engineering can be performed in person but is often done by email, by text message, or through social media messages.
    • 1.1.A.2 Adversaries often use psychological tactics like intimidation and urgency to achieve their goals. Intimidation is when an adversary threatens a target with negative consequences if they don’t comply. Urgency is when an adversary creates reasons why a target should act quickly.

    Learning Objective 1.1.B: Explain how social engineering tactics influence victims to perform a desired action.

    • 1.1.B.1 Social engineering tactics rely on common psychological principles that influence human behavior.
    • 1.1.B.2 Intimidation leverages a natural human aversion to negative consequences. By drawing attention to possible negative consequences, adversaries use fear to incite targets to act.
    • 1.1.B.3 Urgency leverages a natural human response to react quickly to time-sensitive needs. When targets detect a sense of urgency in a message, they feel pressured to respond or act quickly, which can prevent them from taking the time to consider whether an action is reasonable or safe.

    Learning Objective 1.1.C: Describe possible impacts for victims of social engineering attacks.

    • 1.1.C.1 Victims may give an adversary personal information that could lead to impersonation, such as name, phone number, address, workplace, pets’ names, or birthdate. These types of information, and information like them, are often used on websites as challenge questions to verify a user’s identity.
    • 1.1.C.2 Victims may give an adversary secure information like a one-time password (OTP) or authentication login code, which could allow an adversary to log in to a service as the victim.
    • 1.1.C.3 Victims may download malware or click a link that installs malware on their device, steals information from their web browser, or directs them to a website where their login credentials can be captured by an adversary.
    Tiếng Việt

    Mục tiêu học tập 1.1.A: Xác định các dấu hiệu phổ biến của các chiến lược kỹ thuật xã hội.

    • 1.1.A.1 Các cuộc tấn công kỹ thuật xã hội sử dụng các thủ đoạn tâm lý để thao túng người dùng tiết lộ thông tin nhạy cảm (lấy thông tin), tải xuống tệp độc hại hoặc nhấp vào liên kết độc hại. Kỹ thuật xã hội có thể được thực hiện trực tiếp nhưng thường diễn ra qua email, tin nhắn văn bản hoặc tin nhắn trên mạng xã hội.
    • 1.1.A.2 Kẻ thù thường sử dụng các thủ đoạn tâm lý như đe dọa và sự cấp bách để đạt được mục tiêu. Đe dọa là khi kẻ thù đe dọa mục tiêu bằng các hậu quả tiêu cực nếu họ không tuân theo. Sự cấp bách là khi kẻ thù tạo ra các lý do tại sao mục tiêu nên hành động nhanh chóng.

    Mục tiêu học tập 1.1.B: Giải thích cách các chiến lược kỹ thuật xã hội ảnh hưởng đến nạn nhân để thực hiện hành động mong muốn.

    • 1.1.B.1 Các chiến lược kỹ thuật xã hội dựa trên các nguyên tắc tâm lý chung ảnh hưởng đến hành vi con người.
    • 1.1.B.2 Đe dọa tận dụng sự e ngại tự nhiên của con người trước các hậu quả tiêu cực. Bằng cách thu hút sự chú ý vào các hậu quả tiêu cực có thể xảy ra, kẻ thù sử dụng nỗi sợ hãi để kích thích mục tiêu hành động.
    • 1.1.B.3 Sự cấp bách tận dụng phản ứng tự nhiên của con người khi cần phản ứng nhanh với các nhu cầu phụ thuộc vào thời gian. Khi mục tiêu nhận thấy cảm giác cấp bách trong tin nhắn, họ cảm thấy áp lực phải trả lời hoặc hành động ngay lập tức, điều này có thể ngăn họ dành thời gian để xem xét liệu hành động đó có hợp lý hay an toàn hay không.

    Mục tiêu học tập 1.1.C: Mô tả các tác động tiềm ẩn đối với nạn nhân của các cuộc tấn công kỹ thuật xã hội.

    • 1.1.C.1 Nạn nhân có thể cung cấp cho kẻ thù thông tin cá nhân dẫn đến việc giả mạo danh tính, chẳng hạn như tên, số điện thoại, địa chỉ, nơi làm việc, tên thú cưng hoặc ngày sinh. Loại thông tin này và các loại thông tin tương tự thường được sử dụng trên các trang web dưới dạng câu hỏi thách thức để xác minh danh tính người dùng.
    • 1.1.C.2 Nạn nhân có thể cung cấp cho kẻ thù thông tin bảo mật như mật khẩu dùng một lần (OTP) hoặc mã đăng nhập xác thực, điều này có thể cho phép kẻ thù đăng nhập vào dịch vụ với danh tính nạn nhân.
    • 1.1.C.3 Nạn nhân có thể tải xuống phần mềm độc hại hoặc nhấp vào liên kết sẽ cài đặt phần mềm độc hại lên thiết bị của họ, đánh cắp thông tin từ trình duyệt web hoặc đưa họ đến một trang web nơi thông tin đăng nhập của họ có thể bị kẻ thù thu thập.

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    Phishing: how a fake email steals a password

    The weakest part of any computer system is often the human using it. Social engineering 社会工程学 is the art of tricking people into breaking security - giving away a password, opening a bad file, or clicking a bad link. The attacker (we call them an adversary 对手) does not need to break the code; they only need to fool a person.

    Most social engineering happens by email, text message, or social media, though it can also happen in person or by phone. The goal is elicitation 套取信息 - getting sensitive information out of someone without them realising.

    Adversaries lean on two powerful feelings:

    • Intimidation 恐吓 - the adversary threatens a bad result if you do not obey. Fear pushes you to act.
    • Urgency 紧迫感 - the adversary invents a deadline ("reply in the next hour or your account closes"). When we feel rushed, we stop thinking carefully about whether an action is safe.
    Social engineering uses psychological pressure to make a victim act before they think
    Social engineering uses psychological pressure to make a victim act before they think

    The impact 影响 on a victim can be serious. They might reveal personal details (name, address, pet's name, birthday) that are later used to answer security challenge questions 安全问题 and impersonate 冒充 them. They might hand over a one-time password (OTP) 一次性密码, letting the adversary log in as them. Or they might download malware 恶意软件 that steals data from their browser.

    Worked example. A phishing email reads: "Over 90% of staff have already verified their account - confirm yours in the next hour or lose payroll access." Two tactics are stacked here. "In the next hour" is urgency (a deadline that rushes you), and "over 90% of staff have already" is consensus (social pressure to follow the crowd). Naming each tactic - not just calling the email "suspicious" - is exactly what an exam answer needs.

    Explore · ⁨Khám phá⁩

    Which social-engineering tactic is it? · ⁨Nó là chiến thuật kỹ thuật xã hội nào?⁩

    Intimidation threatens harm, urgency invents a deadline, consensus claims everyone else is doing it, and authority pretends to have power over you. · ⁨Sợ hãi đe dọa gây hại, khẩn cấp tạo ra một hạn chót, sự đồng thuận claim rằng tất cả mọi người đều đang làm điều đó, và quyền lực giả vờ có quyền kiểm soát bạn.⁩

    Vocabulary · ⁨Từ vựng⁩ Train · ⁨Luyện tập⁩
    English Tiếng Việt
    Social engineering/ˈsəʊʃl ˌendʒɪˈnɪərɪŋ/ Kỹ thuật xã hội
    adversary/ˈædvəsəri/ kẻ thù
    elicitation/ɪˌlɪsɪˈteɪʃn/ lấy thông tin
    Intimidation/ɪnˌtɪmɪˈdeɪʃn/ sự đe dọa
    Urgency/ˈɜːdʒənsi/ Khẩn cấp
    impact/ˈɪmpækt/ tác động
    challenge questions/ˈtʃælɪndʒ ˈkwestʃnz/ câu hỏi thách thức
    impersonate/ɪmˈpɜːsəneɪt/ giả mạo
    one-time password (OTP)/wʌn taɪm ˈpæswɜːd/ mật khẩu một lần (OTP)
    malware/ˈmælweə/ malware (mã độc)
    1.2

    Suspicious Website Logins

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 1.2.A: Identify common signs of a password attack.

    • 1.2.A.1 In an online password attack, adversaries try logging in to a device or service using common passwords, common password patterns, or stolen passwords.
    • 1.2.A.2 Signs of an online password attack include:
      • Many failed attempts to log in over a short duration
      • Login attempts at unusual times
      • Login attempts from unknown devices

    Learning Objective 1.2.B: Explain how adversaries take advantage of weak authentication.

    • 1.2.B.1 Many people use common patterns when creating passwords, such as:
      • Starting a password with one or two words, adding a two-digit number (often signifying a year), and putting a special character at the end
      • Including the names of family or pets in their passwords
      • Including personally significant dates in their passwords
    • 1.2.B.2 Adversaries often construct a dictionary of possible passwords based on personal information gathered about a target (e.g., birthday, anniversary, names of pets and family) and use an automated tool to submit potential passwords.

    Learning Objective 1.2.C: Explain how to make authentication stronger.

    • 1.2.C.1 Users should create passwords that are long, random, and unique. A password manager can be used to generate and store strong passwords, or a user may create long, unique passphrases for their accounts.
    • 1.2.C.2 When creating passwords, users should avoid names, dates, or other personally meaningful words or numbers.
    • 1.2.C.3 When available, users should enable multifactor authentication (MFA), which will require the user to provide extra proof of identity—such as a one-time code—in addition to the password as an extra layer of security.
    Tiếng Việt

    Mục tiêu học tập 1.2.A: Xác định các dấu hiệu phổ biến của cuộc tấn công mật khẩu.

    • 1.2.A.1 Trong cuộc tấn công mật khẩu trực tuyến, kẻ thù cố gắng đăng nhập vào thiết bị hoặc dịch vụ bằng cách sử dụng các mật khẩu phổ biến, các mẫu mật khẩu phổ biến hoặc mật khẩu bị đánh cắp.
    • 1.2.A.2 Các dấu hiệu của cuộc tấn công mật khẩu trực tuyến bao gồm:
      • Nhiều lần thất bại trong việc đăng nhập trong khoảng thời gian ngắn
      • Các lần đăng nhập diễn ra vào những thời điểm bất thường
      • Các lần đăng nhập từ các thiết bị chưa quen thuộc

    Mục tiêu học tập 1.2.B: Giải thích cách kẻ thù lợi dụng xác thực yếu kém.

    • 1.2.B.1 Nhiều người sử dụng các mẫu phổ biến khi tạo mật khẩu, chẳng hạn như:
      • Bắt đầu mật khẩu bằng một hoặc hai từ, thêm một số hai chữ số (thường biểu thị năm), và đặt ký tự đặc biệt ở cuối
      • Bao gồm tên thành viên gia đình hoặc thú cưng trong mật khẩu của họ
      • Bao gồm các ngày tháng có ý nghĩa cá nhân trong mật khẩu của họ
    • 1.2.B.2 Kẻ thù thường xây dựng danh sách các mật khẩu có thể dựa trên thông tin cá nhân thu thập được về mục tiêu (ví dụ: ngày sinh, kỷ niệm, tên thú cưng và thành viên gia đình) và sử dụng công cụ tự động để gửi các mật khẩu tiềm năng.

    Mục tiêu học tập 1.2.C: Giải thích cách làm cho xác thực mạnh hơn.

    • 1.2.C.1 Người dùng nên tạo mật khẩu dài, ngẫu nhiên và duy nhất. Có thể sử dụng trình quản lý mật khẩu để tạo và lưu trữ mật khẩu an toàn, hoặc người dùng có thể tạo các cụm mật khẩu dài, duy nhất cho tài khoản của mình.
    • 1.2.C.2 Khi tạo mật khẩu, người dùng nên tránh sử dụng tên, ngày tháng hoặc các từ ngữ, con số có ý nghĩa cá nhân khác.
    • 1.2.C.3 Khi có sẵn, người dùng nên bật xác thực đa yếu tố (MFA), yêu cầu người dùng cung cấp thêm bằng chứng nhận dạng—như mã một lần—bên cạnh mật khẩu như một lớp bảo vệ bổ sung.

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    A hardware security key: strong authentication reduces damage when a password is phished
    A hardware security key: strong authentication reduces damage when a password is phished

    A password attack 密码攻击 is any attempt to log in using guessed or stolen passwords. In an online password attack the adversary tries passwords against a real login page. The warning signs are visible in the logs:

    • many failed logins in a short time,
    • login attempts at unusual hours,
    • login attempts from unknown devices.

    Adversaries succeed because people choose weak 弱 passwords. Common patterns include a word plus a two-digit year plus a special character (like Summer24!), or a pet's or family member's name. Because these patterns are so common, an adversary can build a dictionary 字典 of likely passwords from information gathered about you and let an automated tool try each one.

    To make authentication 身份验证 stronger:

    • Create passwords that are long, random, and unique - a password manager 密码管理器 can generate and store them for you.
    • Avoid names, dates, and meaningful words.
    • Turn on multifactor authentication (MFA) 多因素身份验证, which asks for extra proof (like a texted code) on top of the password.
    Vocabulary · ⁨Từ vựng⁩ Train · ⁨Luyện tập⁩
    English Tiếng Việt
    password attack/ˈpæswɜːd əˈtæk/ tấn công mật khẩu
    weak/wiːk/ yếu
    dictionary/ˈdɪkʃənəri/ từ điển
    authentication/ɔːˌθentɪˈkeɪʃn/ xác thực
    password manager/ˈpæswɜːd ˈmænɪdʒə/ quản lý mật khẩu
    multifactor authentication (MFA)/ˌmʌltɪˈfæktə ɔːˌθentɪˈkeɪʃn/ xác thực đa yếu tố (MFA)
    1.3

    Best Practices for Public Networks

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 1.3.A: Identify the type of adversary conducting a cyberattack.

    • 1.3.A.1 Adversaries can be classified by their skill levels.
      • Low-skilled adversaries rely on malicious cyber tools created by others that can be purchased online. The tools they use exploit known vulnerabilities.
      • High-skilled adversaries have the capacity to create new malicious cyber tools or modify existing ones to adapt to new defensive techniques and tools. They also have the capacity to discover undocumented vulnerabilities, known as zero days.
    • 1.3.A.2 Adversaries have a variety of motivations, including greed, desire for recognition, dedication to a cause, revenge, politics, or beliefs.

    Learning Objective 1.3.B: Identify types of wireless cyberattacks.

    • 1.3.B.1 In an evil twin attack, an adversary sets up their own wireless access point (WAP) with a service set identifier (SSID) similar or identical to a target network; the adversary’s network is called the evil twin. Victims of this attack could select to unknowingly connect to the evil twin, allowing the adversary to capture their network traffic. The adversary cannot read traffic that uses an encrypted protocol like HTTPS.
    • 1.3.B.2 In a jamming attack, an adversary floods an area with a strong electromagnetic (EM) signal in the same frequency range as the wireless network, which prevents legitimate traffic between the access point (AP) and users. This type of attack that prevents users from accessing resources is called a denial of service (DoS) attack.
    • 1.3.B.3 In a war driving attack, adversaries try to detect wireless network beacons while driving or walking around a target. If a wireless signal is detected, the adversary can gather information about the type of wireless network used and find areas where the wireless signal extends outside the physical building.

    Learning Objective 1.3.C: Describe actions individuals can take to increase protection of sensitive data when using the internet and Wi-Fi.

    • 1.3.C.1 Individuals should verify that the name of any wireless network they join exactly matches the name of the network they intend to join.
    • 1.3.C.2 Most internet protocols are encrypted to protect network traffic. However, individuals may consider the sensitivity of their data in choosing whether to join unencrypted Wi-Fi networks to protect vulnerable data such as DNS queries.
    • 1.3.C.3 Individuals may consider using a virtual private network (VPN), which encrypts all their traffic to the VPN operator’s system. Although this action prevents a service provider from viewing traffic, the VPN provider can view the traffic.
    Tiếng Việt

    Mục tiêu học tập 1.3.A: Xác định loại kẻ thù đang thực hiện cuộc tấn công mạng.

    • 1.3.A.1 Kẻ thù có thể được phân loại theo mức độ kỹ năng của họ.
      • Kẻ thù kém kỹ năng dựa vào các công cụ cyber độc hại do người khác tạo ra mà có thể mua trực tuyến. Các công cụ họ sử dụng khai thác các lỗ hổng đã biết.
      • Kẻ thù có kỹ năng cao có khả năng tạo ra các công cụ cyber độc hại mới hoặc sửa đổi các công cụ hiện có để thích ứng với các kỹ thuật và công cụ phòng thủ mới. Họ cũng có khả năng phát hiện các lỗ hổng chưa được ghi chép, được gọi là zero days.
    • 1.3.A.2 Kẻ thù có nhiều động cơ khác nhau, bao gồm tham vọng, mong muốn được công nhận, cam kết vì một mục đích, lòng căm ghét, chính trị hoặc niềm tin.

    Mục tiêu học tập 1.3.B: Xác định các loại cuộc tấn công mạng không dây.

    • 1.3.B.1 Trong cuộc tấn công Evil Twin, kẻ thù thiết lập điểm truy cập không dây (WAP) riêng với định danh bộ dịch vụ (SSID) tương tự hoặc giống hệt mạng mục tiêu; mạng của kẻ thù được gọi là Evil Twin. nạn nhân của cuộc tấn công này có thể chọn vô tình kết nối vào Evil Twin, cho phép kẻ thù thu thập lưu lượng mạng của họ. Kẻ thù không thể đọc lưu lượng sử dụng giao thức mã hóa như HTTPS.
    • 1.3.B.2 Trong cuộc tấn công gây nhiễu (jamming), kẻ thù tràn ngập một khu vực bằng tín hiệu điện từ (EM) mạnh trong cùng dải tần số với mạng không dây, ngăn chặn lưu lượng hợp lệ giữa điểm truy cập (AP) và người dùng. Loại cuộc tấn công ngăn người dùng truy cập tài nguyên này được gọi là cuộc tấn công từ chối dịch vụ (DoS).
    • 1.3.B.3 Trong cuộc tấn công War Driving, kẻ thù cố gắng phát hiện các tín hiệu beacons mạng không dây khi lái xe hoặc đi bộ quanh khu vực mục tiêu. Nếu phát hiện tín hiệu không dây, kẻ thù có thể thu thập thông tin về loại mạng không dây được sử dụng và tìm thấy các khu vực nơi tín hiệu không wireless lan rộng ra ngoài tòa nhà vật lý.

    Mục tiêu học tập 1.3.C: Mô tả các hành động cá nhân có thể thực hiện để tăng cường bảo vệ dữ liệu nhạy cảm khi sử dụng internet và Wi-Fi.

    • 1.3.C.1 Cá nhân nên xác minh rằng tên của bất kỳ mạng không dây nào họ tham gia khớp chính xác với tên mạng mà họ dự định kết nối.
    • 1.3.C.2 Hầu hết các giao thức internet đều được mã hóa để bảo vệ lưu lượng mạng. Tuy nhiên, cá nhân có thể xem xét mức độ nhạy cảm của dữ liệu của mình khi quyết định có tham gia các mạng Wi-Fi không mã hóa hay không để bảo vệ dữ liệu dễ bị tổn thương như các truy vấn DNS.
    • 1.3.C.3 Cá nhân có thể cân nhắc sử dụng mạng riêng ảo (VPN), mã hóa toàn bộ lưu lượng của họ đến hệ thống của nhà cung cấp VPN. Mặc dù hành động này ngăn nhà cung cấp dịch vụ xem lưu lượng, nhưng nhà cung cấp VPN có thể xem lưu lượng đó.

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    A security token: one-time codes and tokens stop password-only logins from being enough
    A security token: one-time codes and tokens stop password-only logins from being enough

    Not all adversaries are the same. We classify them by skill: low-skilled attackers buy ready-made tools online and reuse known exploits 漏洞利用, while high-skilled attackers write their own tools and can discover brand-new holes called zero days 零日漏洞. Their motivation 动机 varies too - greed, revenge, politics, or belief.

    Public Wi-Fi is a favourite hunting ground. Three wireless attacks you must know:

    • Evil twin 双胞胎恶意热点 - the adversary sets up a fake access point 接入点 with a name (SSID 服务集标识符) copied from the real network. Victims connect to the fake one, and the adversary reads their traffic (though encrypted 加密的 sites like HTTPS stay safe).
    • Jamming 干扰攻击 - the adversary floods the air with a strong radio signal so no one can connect. This is one kind of denial of service (DoS) 拒绝服务 attack.
    • War driving 战争驾驶 - the adversary drives around detecting wireless networks and where their signal leaks outside a building.
    An evil-twin access point copies the real network's name so victims connect to the attacker
    An evil-twin access point copies the real network's name so victims connect to the attacker

    To protect yourself on public networks: check that the network name exactly matches the one you intend to join, prefer encrypted sites, and consider a virtual private network (VPN) 虚拟专用网络, which encrypts all of your traffic to the VPN operator.

    Vocabulary · ⁨Từ vựng⁩ Train · ⁨Luyện tập⁩
    English Tiếng Việt
    exploits/ˈeksplɔɪts/ lợi dụng lỗ hổng
    zero days/ˈzɪərəʊ deɪz/ ngày không vá
    motivation/ˌməʊtɪˈveɪʃn/ động lực
    Evil twin/ˈiːvl twɪn/ Twin xấu
    access point/ˈækses pɔɪnt/ trạm truy cập
    SSID/ˌes es aɪ ˈdiː/ SSID
    encrypted/enˈkrɪptɪd/ được mã hóa
    Jamming/ˈdʒæmɪŋ/ Gây nhiễu
    denial of service (DoS)/dɪˈnaɪəl ɒv ˈsɜːvɪs/ từ chối dịch vụ (DoS)
    War driving/wɔː ˈdraɪvɪŋ/ Lái xe tìm mạng
    virtual private network (VPN)/ˈvɜːtʃuːəl ˈpraɪvət ˈnetwɜːk/ mạng riêng ảo (VPN)
    1.4

    AI-Based Cybersecurity Attacks

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 1.4.A: Explain how adversaries use AI-powered tools to augment cyberattacks.

    • 1.4.A.1 Adversaries can use AI-powered tools that leverage existing voice and image samples of a person to create a digital avatar of that person. The use of these technologies enables adversaries to impersonate someone over the phone or even on a video call, which can lead to financial loss or the sharing of sensitive or private information. As more organizations adopt voice-based authentication, the impact of voice-impersonation has a larger potential impact.
    • 1.4.A.2 Adversaries can use generative AI tools, like large language models (LLMs), to create convincing phishing messages in any target language. Because traditional phishing messages are sometimes written by non-native speakers of the target’s language, unnatural language is a feature that has been used to distinguish phishing messages from legitimate messages. However, with AI tools, adversaries can now craft phishing messages in any language that read as though they were written by a native speaker.
    • 1.4.A.3 Adversaries can craft prompts that extract secure or sensitive information from LLMs. Secure or sensitive information in LLMs can come from user input and the large data sets used to train LLMs.
    • 1.4.A.4 Adversaries can publish websites or modify existing websites to contain false information so that the false information will be included in the training sets for LLMs, causing the LLMs to repeat the false information.
    • 1.4.A.5 Adversaries can perform reconnaissance on a target using AI-powered tools that scan the internet to gather information posted on social media and public websites.
    • 1.4.A.6 Adversaries can use AI-enhanced coding tools to help them write new malware, modify existing application code to perform malicious activities, or to find vulnerabilities in large code bases.

    Learning Objective 1.4.B: Explain how to protect against some AI-augmented cyberattacks.

    • 1.4.B.1 Shared secrets with close friends and relatives that can be used to verify each other’s identities should be established. A secret word or phrase known only to two parties can be used to authenticate identities in high-stakes situations.
    • 1.4.B.2 Multifactor authentication (MFA) should be enabled. If an adversary clones a target’s voice to access a system with voice authentication, requiring a second authentication factor could prevent an adversary from gaining access to accounts.
    • 1.4.B.3 Personal or sensitive data should not be entered into any AI-powered tools, such as chatbots or virtual assistants. Some AI-powered tools feed user input back into the model to provide continuous training. Adversaries could extract data that users have included in prompts.
    • 1.4.B.4 Output from AI-powered tools should be carefully evaluated. Verify information from AI-powered tools using reputable, stable, non-AI-based sources.
    Tiếng Việt

    Mục tiêu học tập 1.4.A: Giải thích cách kẻ thù sử dụng các công cụ hỗ trợ AI để gia tăng cuộc tấn công mạng.

    • 1.4.A.1 Kẻ thù có thể sử dụng các công cụ hỗ trợ AI tận dụng các mẫu giọng nói và hình ảnh hiện có của một người để tạo ra avatar kỹ thuật số của người đó. Việc sử dụng các công nghệ này cho phép kẻ thù giả mạo ai đó qua điện thoại hoặc thậm chí trong cuộc gọi video, dẫn đến thiệt hại tài chính hoặc chia sẻ thông tin nhạy cảm hoặc riêng tư. Khi càng nhiều tổ chức áp dụng xác thực dựa trên giọng nói, tác động của việc giả mạo giọng nói có tiềm năng ảnh hưởng lớn hơn.
    • 1.4.A.2 Kẻ thù có thể sử dụng các công cụ AI tạo sinh, như mô hình ngôn ngữ lớn (LLMs), để tạo ra các tin nhắn lừa đảo đáng tin ở bất kỳ ngôn ngữ mục tiêu nào. Vì các tin nhắn lừa đảo truyền thống đôi khi được viết bởi những người không phải母语 của ngôn ngữ mục tiêu, ngôn ngữ không tự nhiên là đặc điểm đã được sử dụng để phân biệt tin nhắn lừa đảo với tin nhắn hợp lệ. Tuy nhiên, với các công cụ AI, kẻ thù giờ đây có thể tinh chỉnh tin nhắn lừa đảo bằng bất kỳ ngôn ngữ nào sao cho đọc lên như thể chúng được viết bởi một母语 viên.
    • 1.4.A.3 Kẻ thù có thể tinh chỉnh prompt để trích xuất thông tin an toàn hoặc nhạy cảm từ LLMs. Thông tin an toàn hoặc nhạy cảm trong LLMs có thể đến từ đầu vào của người dùng và các bộ dữ liệu lớn được sử dụng để huấn luyện LLMs.
    • 1.4.A.4 Kẻ thù có thể đăng tải các trang web hoặc sửa đổi các trang web hiện có để chứa thông tin sai lệch nhằm mục đích đưa thông tin sai lệch đó vào các bộ dữ liệu huấn luyện cho LLMs, khiến LLMs lặp lại thông tin sai lệch đó.
    • 1.4.A.5 Kẻ thù có thể tiến hành thám thính mục tiêu bằng các công cụ hỗ trợ AI quét internet để thu thập thông tin được đăng trên mạng xã hội và các trang web công khai.
    • 1.4.A.6 Kẻ thù có thể sử dụng các công cụ lập trình được nâng cấp bởi AI để giúp họ viết malware mới, sửa đổi mã ứng dụng hiện có để thực hiện các hoạt động độc hại, hoặc để tìm kiếm các lỗ hổng trong các cơ sở mã lớn.

    Mục tiêu học tập 1.4.B: Giải thích cách bảo vệ chống lại một số cuộc tấn công mạng được hỗ trợ bởi AI.

    • 1.4.B.1 Các bí mật được chia sẻ với bạn bè thân thiết và người nhà, có thể dùng để xác thực danh tính lẫn nhau, nên được thiết lập. Một từ khóa hoặc cụm từ chỉ hai bên biết có thể được sử dụng để xác thực danh tính trong các tình huống có rủi ro cao.
    • 1.4.B.2 Xác thực đa yếu tố (MFA) nên được kích hoạt. Nếu kẻ tấn công sao chép giọng nói của mục tiêu để truy cập hệ thống có xác thực bằng giọng nói, việc yêu cầu thêm một yếu tố xác thực thứ hai có thể ngăn kẻ tấn công chiếm quyền truy cập vào tài khoản.
    • 1.4.B.3 Dữ liệu cá nhân hoặc nhạy cảm không nên nhập vào bất kỳ công cụ nào có khả năng AI, chẳng hạn như chatbot hoặc trợ lý ảo. Một số công cụ có khả năng AI trả lại dữ liệu đầu vào cho mô hình để cung cấp đào tạo liên tục. Kẻ tấn công có thể trích xuất dữ liệu mà người dùng đã đưa vào các câu hỏi.
    • 1.4.B.4 Kết quả đầu ra từ các công cụ có khả năng AI cần được đánh giá kỹ lưỡng. Xác minh thông tin từ các công cụ có khả năng AI bằng các nguồn đáng tin cậy, ổn định, không dựa trên AI.

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    Artificial intelligence gives adversaries powerful new tools. With enough voice and image samples, an adversary can build a deepfake 深度伪造 avatar to impersonate someone on a call. Large language models (LLMs) 大语言模型 let them write convincing phishing 钓鱼 emails in perfect, native-sounding language - removing the clumsy wording that once gave scams away.

    AI also helps adversaries on the back end: crafting prompts that pull secret data out of an LLM, planting false information on websites so it poisons an LLM's training data, scanning the internet to gather facts about a target, and even writing new malware.

    You can defend against many AI-augmented attacks: agree on a shared secret 共享秘密 word with close contacts to verify identity, enable MFA (so a cloned voice alone cannot log in), never type sensitive data into a chatbot, and always double-check AI output against reliable, non-AI sources.

    AI writes code, and that cuts both ways. Adversaries use AI-enhanced coding tools 人工智能辅助编程工具 to write new malware faster than they could by hand, to modify existing application code so that it performs malicious activity, and to scan a codebase for vulnerabilities 漏洞 to attack. The skill barrier falls: someone who could not previously write an exploit can now ask for one, so the number of capable attackers rises even when no new technique is invented.

    Vocabulary · ⁨Từ vựng⁩ Train · ⁨Luyện tập⁩
    English Tiếng Việt
    deepfake/ˈdiːpfeɪk/ deepfake
    Large language models (LLMs)/lɑːdʒ ˈlæŋɡwɪdʒ ˈmɒdlz/ Mô hình ngôn ngữ lớn (LLMs)
    phishing/ˈfɪʃɪŋ/ phishing
    shared secret/ʃeəd ˈsiːkrɪt/ bí mật chia sẻ
    AI-enhanced coding tools/ˌeɪ ˈaɪ enˈhænst ˈkəʊdɪŋ tuːlz/ công cụ lập trình tăng cường AI
    vulnerabilities/ˌvʌlnərəˈbɪlɪtiz/ lỗ hổng bảo mật
    1.5

    Leveraging AI in Cyber Defense

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 1.5.A: Explain how cyber defenders can leverage AI-powered tools to protect networks, applications, and data.

    • 1.5.A.1 AI tools can review current security configurations, like firewall rules and access controls, and recommend more secure options. Recommendations should always be checked by a knowledgeable security technician before being implemented.
    • 1.5.A.2 AI-powered tools can analyze application code to identify vulnerabilities and recommend mitigations. Recommendations should always be reviewed by a knowledgeable programmer before being implemented.
    • 1.5.A.3 AI-powered tools can suggest rules for automated detection systems. Detection rules should always be reviewed by a knowledgeable detection engineer before being added to a system.

    Learning Objective 1.5.B: Explain how AI-powered tools are enabling faster and more accurate threat detection and response.

    • 1.5.B.1 Of the millions of digital events that happen on networks daily, some likely represent an adversary conducting malicious activity. Humans cannot carefully examine all those events to identify the malicious activity.
    • 1.5.B.2 AI-powered tools can be trained to quickly analyze digital events and sort the events that are likely malicious activity from those that are harmless.
    • 1.5.B.3 AI-powered tools can be programmed to alert human cybersecurity personnel when likely malicious activity is detected or to take specific corrective actions based on the type of malicious activity detected.
    • 1.5.B.4 AI-powered tools enable threat-detection and response teams to catch malicious activity and intervene quickly to prevent loss, harm, damage, and destruction to digital infrastructure and data.
    Tiếng Việt

    Mục tiêu học tập 1.5.A: Giải thích cách các chuyên gia phòng thủ an ninh mạng có thể khai thác các công cụ có khả năng AI để bảo vệ mạng, ứng dụng và dữ liệu.

    • 1.5.A.1 Các công cụ AI có thể xem xét cấu hình bảo mật hiện tại, như quy tắc tường lửa và kiểm soát truy cập, và đề xuất các tùy chọn an toàn hơn. Các khuyến nghị luôn phải được kiểm tra bởi kỹ thuật viên an ninh am hiểu trước khi triển khai.
    • 1.5.A.2 Các công cụ có khả năng AI có thể phân tích mã ứng dụng để xác định lỗ hổng và đề xuất biện pháp giảm thiểu. Các khuyến nghị luôn phải được xem xét bởi lập trình viên am hiểu trước khi triển khai.
    • 1.5.A.3 Các công cụ có khả năng AI có thể đề xuất các quy tắc cho hệ thống phát hiện tự động. Các quy tắc phát hiện luôn phải được xem xét bởi kỹ sư phát hiện am hiểu trước khi thêm vào hệ thống.

    Mục tiêu học tập 1.5.B: Giải thích cách các công cụ có khả năng AI đang giúp tăng tốc độ và độ chính xác trong việc phát hiện và phản hồi mối đe dọa.

    • 1.5.B.1 Trong số hàng triệu sự kiện kỹ thuật số xảy ra trên mạng mỗi ngày, một số có khả năng đại diện cho kẻ tấn công đang thực hiện hoạt động độc hại. Con người không thể kiểm tra cẩn thận tất cả những sự kiện đó để xác định hoạt động độc hại.
    • 1.5.B.2 Các công cụ có khả năng AI có thể được huấn luyện để nhanh chóng phân tích các sự kiện kỹ thuật số và phân loại các sự kiện có khả năng là hoạt động độc hại so với những sự kiện vô hại.
    • 1.5.B.3 Các công cụ có khả năng AI có thể được lập trình để cảnh báo nhân viên an ninh mạng con người khi phát hiện hoạt động có khả năng là độc hại hoặc thực hiện các hành động khắc phục cụ thể dựa trên loại hoạt động độc hại được phát hiện.
    • 1.5.B.4 Các công cụ có khả năng AI cho phép các đội phát hiện và phản hồi mối đe dọa bắt kịp hoạt động độc hại và can thiệp nhanh chóng để ngăn chặn thiệt hại, tổn thất, hư hỏng và phá hủy cơ sở hạ tầng kỹ thuật số và dữ liệu.

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    The same technology defends us. AI tools can analyse an application's own source code, identify vulnerabilities in it and recommend mitigations; they can also review firewall rules and access settings and recommend safer options - though a human expert must always check the advice before applying it. AI can scan application code for weaknesses and suggest detection rules.

    ⚠️ A recommendation is not a fix. The CED is explicit that the advice must be reviewed and implemented by a knowledgeable programmer: an AI tool can be confidently wrong about whether a flaw is exploitable, and applying a suggested patch without understanding it can introduce a new fault of its own.

    Its biggest advantage is scale. A medium network produces millions of events every day - far too many for people to read. AI can quickly sort the harmless events from the likely-malicious ones, alert human staff, or take an automatic action. This lets defenders catch an attack and respond in seconds instead of days, preventing loss and damage.

    That scale is what makes threat detection and response 威胁检测与响应 possible in practice: an AI system flags malicious activity as it happens, so the response team can intervene quickly enough to prevent loss, harm, or destruction of digital infrastructure — rather than reading the logs days later and finding out what was taken.

    Vocabulary · ⁨Từ vựng⁩ Train · ⁨Luyện tập⁩
    English Tiếng Việt
    threat detection and response/θret dɪˈtekʃn ænd rɪˈspɒns/ phát hiện và ứng phó với mối đe dọa
    1.5

    Exam tips

    • When a question asks you to rank risks, remember high risk = high impact AND easy to exploit. A parking-lot Wi-Fi leak matters less than an open internal port that lets an adversary spoof a device.
    • Learn the social-engineering tactics by name - intimidation, urgency, pretexting, authority, consensus, scarcity, familiarity - and be ready to spot which one an email is using.
    • Encryption still protects you on an evil twin: the adversary sees your traffic but cannot read HTTPS. Say what is exposed, not just "it's unsafe".
    • For "how to make authentication stronger", MFA is almost always part of the answer, plus long/unique passwords from a manager.
    • AI is dual-use: the same tool (LLMs, code analysis) appears on both the attack and the defense side. Read the question carefully to see which side it asks about.
  • 2

    Securing Spaces · ⁨Bảo vệ Không gian⁩

    Watch lesson · ⁨Xem bài học⁩
    2.1

    Cyber Foundations

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 2.1.A: Identify social engineering attacks.

    • 2.1.A.1 Social engineers use psychological tactics to manipulate targets into taking a desired action.
    • 2.1.A.2 Pretexting is when adversaries create a believable reason to contact a target.
    • 2.1.A.3 Authority is when adversaries impersonate someone with power over a target or pretend to relay instructions from that person.
    • 2.1.A.4 Intimidation is when adversaries state negative consequences if demands aren’t met.
    • 2.1.A.5 Consensus is when adversaries create social pressure by making a target believe everyone else is doing a desired action.
    • 2.1.A.6 Scarcity is when adversaries create a sense of limited availability.
    • 2.1.A.7 Familiarity is when adversaries pretend to be or know someone close to a target to establish trust.
    • 2.1.A.8 Urgency is when adversaries create a deadline that requires quick action by a target to avert negative consequences.

    Learning Objective 2.1.B: Identify types of adversaries.

    • 2.1.B.1 Script kiddies are low-skilled adversaries who use tools developed by others without understanding how the tools work. They are often motivated by greed or a desire for recognition.
    • 2.1.B.2 Hacktivists are motivated by social, political, or personal causes. They compromise computers and networks to support their cause or stop perceived harm, believing their goals justify their illegal methods.
    • 2.1.B.3 Insider adversaries are unique threats because they have legitimate credentials and access to systems and data. They can be recruited by malicious third parties and can be motivated by greed or revenge.
    • 2.1.B.4 Cyberterrorists are motivated by politics or beliefs and seek to disrupt entire communities, regions, or nations through cyberattacks (e.g., attacking a power grid, water treatment plant, or other civil infrastructure). They can act independently or on behalf of governments or criminal organizations.
    • 2.1.B.5 Transnational criminal organizations seek financial gain primarily by deploying ransomware and stealing corporate intellectual property (IP) to sell in illegal markets.

    Learning Objective 2.1.C: Describe the phases of a cyberattack.

    • 2.1.C.1 Cyberattacks aim to disrupt, harm, steal, or destroy devices, networks, or data. Adversaries work in phases, which may not all be used in every attack. The phases are:
      • i. Reconnaissance
      • ii. Initial access
      • iii. Persistence
      • iv. Lateral movement
      • v. Taking action
      • vi. Evading detection
    • 2.1.C.2 In the reconnaissance phase of an attack, adversaries gather as much information as possible about their target, often using open source intelligence (OSINT), which is freely available information.
    • 2.1.C.3 In the initial-access phase of an attack, adversaries establish a foothold on the target’s computer, often through social engineering or compromised or weak credentials.
    • 2.1.C.4 After gaining access during an attack, adversaries establish persistence to maintain access without needing to regain it. They may use a command and control (C2) protocol to send commands to the device and receive output, often through malware like a remote access trojan (RAT) or rootkit.
    • 2.1.C.5 In the lateral-movement phase of an attack, adversaries try to escalate their privileges by accessing computers and user accounts with elevated permissions to services and data.
    • 2.1.C.6 In the taking-action phase of an attack, adversaries act on their objectives by collecting targeted data, exfiltrating it, and disrupting services or destroying data.
    • 2.1.C.7 In the final phase of an attack, many adversaries try to evade detection by removing or editing log files and erasing other files they may have planted on devices (e.g., malware).

    Learning Objective 2.1.D: Describe the risk assessment process.

    • 2.1.D.1 Risk occurs when a threat can exploit a vulnerability to compromise an asset.
    • 2.1.D.2 An asset is anything valuable. Assets include financial resources, intellectual property, data, digital infrastructure, physical property, and reputation.
    • 2.1.D.3 Risk assessment considers two factors:
      • The likelihood of an attack against a specific vulnerability
      • The severity of the projected damage from an attack against a specific vulnerability
    • 2.1.D.4 The likelihood of a vulnerability being exploited depends on many factors, including:
      • The value of the target: Adversaries are more likely to attack targets they perceive as valuable.
      • The level of skill required to exploit the vulnerability (i.e., the difficulty): Vulnerabilities with well-documented exploits often require less skill and can be carried out by more adversaries.
      • The motivation and capabilities of likely adversaries: Highly motivated and skilled adversaries are more likely to be able to perform more complex exploits.
    • 2.1.D.5 The severity of an attack is often measured by financial cost, which can also include reputational and operational impacts.
      • Illustrative examples for 2.1.D.5:
        • A hacktivist is passionate about illegal fishing practices supported by a local food production company. The main webpage of this food production company would be a high-value target for this hacktivist; defacing the webpage to expose the company’s support of illegal fishing would provide no financial gain to the adversary, but would allow them to raise awareness about an issue that motivates them.
    • 2.1.D.6 The result of a risk assessment can be quantitative or qualitative.
      • Quantitative risk assessment assigns a numeric value to a vulnerability based on a numeric scale (e.g., 1–10) or quantifiable impact, which could be financial (e.g., a $10,000 annual risk).
      • Illustrative examples for 2.1.D.6:
        • Low, medium, high, severe
        • Unlikely low impact, likely low impact, unlikely high impact, likely high impact
    • 2.1.D.7 Risk assessment documentation should include:
      • Vulnerable assets and their value
      • Descriptions of likely threats to the assets
      • Details of specific vulnerabilities for specific assets and how they would be exploited
      • An explanation of the severity of damage (financial, operational, reputational, etc.) if a specific asset were compromised, and the likelihood of that compromise occurring
      • A final rating, quantitative or qualitative, for each risk identified
      • Illustrative examples for 2.1.D.7:
        • Scaled score (e.g., 1–10)
        • Monetary value (e.g., a $10,000 risk vs. a$100,000 risk)

    Learning Objective 2.1.E: Identify strategies for managing risk.

    • 2.1.E.1 Once a risk has been identified and assessed, an organization has four options for managing that risk:
      • i. Avoid
      • ii. Transfer
      • iii. Mitigate
      • iv. Accept
    • 2.1.E.2 Risk avoidance stops the activity that is generating the risk. If the activity is a critical part of an organization’s mission or purpose, then avoidance is not possible.
    • 2.1.E.3 Risk transference places the burden of the risk on another entity, such as an insurance company, a government, or consumers.
    • 2.1.E.4 Risk mitigation implements security controls to reduce the likelihood or impact of a risk.
    • 2.1.E.5 Residual risk is the risk that remains after an organization has gone through avoidance, transference, and mitigation. The residual risk is the level of risk that an organization is willing to accept. Risk acceptance acknowledges the fact that absolute security is unattainable.
    • 2.1.E.6 To conserve financial resources and employee capacity, an organization will often favor solutions that are cost effective and easy to implement and maintain. Cost-effective solutions cost less to install and maintain than the expected loss from an attack.

    Learning Objective 2.1.F: Identify types of security controls.

    • 2.1.F.1 Security controls address at least one of the following principles:
      • Confidentiality ensures that only authorized individuals, systems, or processes can access data. Systems lacking confidentiality are vulnerable to data theft or destruction.
      • Integrity ensures data are accurate and trustworthy. Systems lacking integrity are vulnerable to data manipulation.
      • Availability ensures data and services are accessible to authorized individuals when needed. Systems lacking availability may experience unexpected downtime.
    • 2.1.F.2 Security controls can be classified by type.
      • Physical controls provide security in the physical space and include locks, fences, and cameras, bollards, and security guards.
      • Technical controls provide security in the digital space and include firewalls, anti-malware software, and encryption.
      • Managerial controls provide rules, guidelines, policies, and procedures that specify what security should be in place and include password policies, regular access reviews, and incident response plans (IRPs).
    • 2.1.F.3 Security controls can be classified by function.
      • Preventative controls address potential vulnerabilities with the goal of stopping an adversary from attacking and include locks and encryption.
      • Detective controls help identify attacks when they occur and include intrusion detection systems (IDSs), cameras, and security incident and event management (SIEM) systems.
      • Corrective controls fix problems and help restore systems to an operational state and include vulnerability patching, repairing a broken card reader, and intrusion prevention systems (IPSs).

    Learning Objective 2.1.G: Explain why a defense-in-depth security strategy is necessary to optimally protect an organization.

    • 2.1.G.1 A defense-in-depth strategy, or layered defense, uses multiple types of security controls to protect sensitive data and systems.
    • 2.1.G.2 A defense-in-depth strategy allows an organization to address different types of threats, each with a security control most suited to mitigate it.
    • 2.1.G.3 A defense-in-depth strategy allows for resilience in data protection so when one security control is bypassed by an adversary, another security control may still prevent access to the data or system or limit the damage done to the data or system.
    • 2.1.G.4 Layers in a defense-in-depth strategy can include human, physical, network, device, application, and data.
    Tiếng Việt

    Mục tiêu học tập 2.1.A: Xác định các cuộc tấn công kỹ thuật xã hội.

    • 2.1.A.1 Những kẻ thao túng tâm lý sử dụng các chiến thuật tâm lý để thao túng mục tiêu thực hiện một hành động mong muốn.
    • 2.1.A.2 Tạo tiền cảnh là khi kẻ tấn công tạo ra một lý do thuyết phục để liên lạc với mục tiêu.
    • 2.1.A.3 Uy quyền là khi kẻ tấn công giả mạo một người có quyền lực đối với mục tiêu hoặc giả vờ truyền đạt chỉ thị từ người đó.
    • 2.1.A.4 Lừa đỗi là khi kẻ tấn công nêu rõ các hậu quả tiêu cực nếu các yêu cầu không được đáp ứng.
    • 2.1.A.5 Đồng thuận là khi kẻ tấn công tạo áp lực xã hội bằng cách khiến mục tiêu tin rằng mọi người khác đều đang thực hiện một hành động mong muốn.
    • 2.1.A.6 khan hiếm là khi kẻ tấn công tạo cảm giác về sự sẵn có có hạn.
    • 2.1.A.7 quen thuộc là khi kẻ tấn công giả vờ là hoặc biết ai đó gần gũi với mục tiêu để thiết lập niềm tin.
    • 2.1.A.8 Khẩn cấp là khi kẻ tấn công tạo ra một thời hạn yêu cầu mục tiêu phải hành động nhanh chóng để ngăn ngừa các hậu quả tiêu cực.

    Mục tiêu học tập 2.1.B: Xác định các loại kẻ tấn công.

    • 2.1.B.1 Script kiddies là những kẻ tấn công ít kỹ năng sử dụng các công cụ do người khác phát triển mà không hiểu cách chúng hoạt động. Họ thường bị thúc đẩy bởi tham vọng hoặc mong muốn được công nhận.
    • 2.1.B.2 Hacktivists bị thúc đẩy bởi các nguyên nhân xã hội, chính trị hoặc cá nhân. Họ xâm phạm máy tính và mạng lưới để hỗ trợ nguyên nhân của mình hoặc ngăn chặn thiệt hại được cho là đang xảy ra, tin rằng mục tiêu của họ biện minh cho phương pháp trái luật của họ.
    • 2.1.B.3 Kẻ tấn công nội bộ là mối đe dọa đặc biệt vì họ có giấy chứng nhận hợp lệ và quyền truy cập vào hệ thống và dữ liệu. Họ có thể bị tuyển dụng bởi các bên thứ ba độc hại và có thể bị thúc đẩy bởi tham vọng hoặc lòng thù địch.
    • 2.1.B.4 khủng bố mạng bị thúc đẩy bởi chính trị hoặc niềm tin và tìm cách gây gián đoạn cho toàn bộ cộng đồng, khu vực hoặc quốc gia thông qua các cuộc tấn công mạng (ví dụ: tấn công lưới điện, nhà máy xử lý nước hoặc cơ sở hạ tầng dân sự khác). Họ có thể hành động độc lập hoặc thay mặt cho chính phủ hoặc tổ chức tội phạm.
    • 2.1.B.5 Tổ chức tội phạm xuyên quốc gia tìm kiếm lợi nhuận tài chính chủ yếu bằng cách triển khai ransomware và đánh cắp tài sản trí tuệ doanh nghiệp (IP) để bán trong các thị trường bất hợp pháp.

    Mục tiêu học tập 2.1.C: Mô tả các giai đoạn của một cuộc tấn công mạng.

    • 2.1.C.1 Các cuộc tấn công mạng nhằm mục đích gây gián đoạn, làm tổn hại, đánh cắp hoặc phá hủy thiết bị, mạng hoặc dữ liệu. Kẻ tấn công làm việc theo từng giai đoạn, có thể không phải tất cả các giai đoạn nào cũng được sử dụng trong mỗi cuộc tấn công. Các giai đoạn bao gồm:
      • i. Tái kiến
      • ii. Truy cập ban đầu
      • iii. Duy trì
      • iv. Di chuyển ngang
      • v. Thực hiện hành động
      • vi. Tránh phát hiện
    • 2.1.C.2 Trong giai đoạn tái kiến của một cuộc tấn công, kẻ tấn công thu thập càng nhiều thông tin càng tốt về mục tiêu của mình, thường sử dụng tình báo nguồn mở (OSINT), là thông tin miễn phí.
    • 2.1.C.3 Trong giai đoạn truy cập ban đầu của một cuộc tấn công, kẻ thù thiết lập vị thế trên máy tính mục tiêu, thường thông qua kỹ thuật xã hội hóa hoặc sử dụng mật khẩu bị xâm phạm hoặc yếu.
    • 2.1.C.4 Sau khi có quyền truy cập trong một cuộc tấn công, kẻ thù thiết lập khả năng tồn tại (persistence) để duy trì quyền truy cập mà không cần phải chiếm lại nó. Chúng có thể sử dụng giao thức điều khiển và chỉ huy (C2) để gửi lệnh đến thiết bị và nhận dữ liệu phản hồi, thường thông qua phần mềm độc hại như trojan truy cập từ xa (RAT) hoặc rootkit.
    • 2.1.C.5 Trong giai đoạn di chuyển ngang của một cuộc tấn công, kẻ thù cố gắng nâng cao quyền hạn bằng cách truy cập vào các máy tính và tài khoản người dùng có quyền truy cập cao hơn đối với các dịch vụ và dữ liệu.
    • 2.1.C.6 Trong giai đoạn hành động của một cuộc tấn công, kẻ thù thực hiện các mục tiêu của mình bằng cách thu thập dữ liệu được nhắm mục tiêu, tẩu thoát dữ liệu đó, và phá hủy dịch vụ hoặc xóa dữ liệu.
    • 2.1.C.7 Trong giai đoạn cuối cùng của một cuộc tấn công, nhiều kẻ thù cố gắng né tránh việc phát hiện bằng cách xóa hoặc chỉnh sửa nhật ký và xóa bỏ các tệp khác mà chúng có thể đã cài đặt trên các thiết bị (ví dụ: phần mềm độc hại).

    Mục tiêu học tập 2.1.D: Mô tả quy trình đánh giá rủi ro.

    • 2.1.D.1 Rủi ro xảy ra khi một mối đe dọa có thể khai thác điểm yếu để làm tổn hại đến một tài sản.
    • 2.1.D.2 Một tài sản là bất cứ thứ gì có giá trị. Tài sản bao gồm nguồn lực tài chính, sở hữu trí tuệ, dữ liệu, hạ tầng kỹ thuật số, tài sản vật lý và danh tiếng.
    • 2.1.D.3 Đánh giá rủi ro xem xét hai yếu tố:
      • Khả năng xảy ra một cuộc tấn công vào một điểm yếu cụ thể
      • Mức độ nghiêm trọng của thiệt hại dự kiến từ một cuộc tấn công vào một điểm yếu cụ thể
    • 2.1.D.4 Khả năng một điểm yếu bị khai thác phụ thuộc vào nhiều yếu tố, bao gồm:
      • Giá trị của mục tiêu: Kẻ thù có xu hướng tấn công các mục tiêu mà chúng cảm thấy có giá trị.
      • Trình độ kỹ năng yêu cầu để khai thác điểm yếu (tức là mức độ khó): Các điểm yếu có phương thức khai thác được mô tả rõ ràng thường đòi hỏi ít kỹ năng hơn và có thể được thực hiện bởi nhiều kẻ thù hơn.
      • Động lực và năng lực của những kẻ thù tiềm năng: Những kẻ thù có động lực mạnh và kỹ năng cao có khả năng thực hiện các cuộc khai thác phức tạp hơn.
    • 2.1.D.5 Mức độ nghiêm trọng của một cuộc tấn công thường được đo lường bằng chi phí tài chính, cũng có thể bao gồm các tác động về danh tiếng và vận hành.
      • Ví dụ minh họa cho 2.1.D.5:
        • Một hacker chủ nghĩa hoạt động rất nhiệt tình với vấn đề đánh bắt cá trái phép được hỗ trợ bởi một công ty sản xuất thực phẩm địa phương. Trang web chính của công ty sản xuất thực phẩm này sẽ là một mục tiêu có giá trị cao đối với hacker này; làm hỏng trang web để tiết lộ sự hỗ trợ của công ty đối với việc đánh bắt cá trái phép sẽ không mang lại lợi ích tài chính nào cho kẻ thù, nhưng sẽ giúp họraising nhận thức về một vấn đề thúc đẩy động cơ của họ.
    • 2.1.D.6 Kết quả của một cuộc đánh giá rủi ro có thể định lượng hoặc định tính.
      • Đánh giá rủi ro định lượng gán một giá trị số cho một điểm yếu dựa trên thang đo số (ví dụ: 1–10) hoặc tác động có thể định lượng, chẳng hạn như tài chính (ví dụ: rủi ro $10,000 mỗi năm).
      • Ví dụ minh họa cho 2.1.D.6:
        • Thấp, Trung bình, Cao, Nghiêm trọng
        • Không khả thi ảnh hưởng thấp, Khả thi ảnh hưởng thấp, Không khả thi ảnh hưởng cao, Khả thi ảnh hưởng cao
    • 2.1.D.7 Tài liệu đánh giá rủi ro nên bao gồm:
      • Các tài sản dễ bị tổn thương và giá trị của chúng
      • Mô tả các mối đe dọa tiềm năng đối với các tài sản
      • Chi tiết về các điểm yếu cụ thể đối với các tài sản cụ thể và cách chúng sẽ bị khai thác
      • Giải thích về mức độ nghiêm trọng của thiệt hại (tài chính, vận hành, danh tiếng, v.v.) nếu một tài sản cụ thể bị tổn hại, và khả năng xảy ra sự tổn hại đó
      • Xếp hạng cuối cùng, định lượng hoặc định tính, cho từng rủi ro được xác định
      • Ví dụ minh họa cho 2.1.D.7:
        • Điểm số theo thang đo (ví dụ: 1–10)
        • Giá trị tiền tệ (ví dụ: rủi ro $10,000 risk vs. a$100,000)

    Mục tiêu học tập 2.1.E: Xác định các chiến lược quản lý rủi ro.

    • 2.1.E.1 Khi một rủi ro đã được xác định và đánh giá, một tổ chức có bốn tùy chọn để quản lý rủi ro đó:
      • i. Tránh
      • ii. Chuyển giao
      • iii. Giảm thiểu
      • iv. Chấp nhận
    • 2.1.E.2 Việc tránh rủi ro dừng lại hoạt động đang tạo ra rủi ro. Nếu hoạt động đó là một phần quan trọng trong sứ mệnh hoặc mục đích của tổ chức, thì việc tránh rủi ro là không thể.
    • 2.1.E.3 Việc chuyển giao rủi ro đặt gánh nặng của rủi ro lên một thực thể khác, chẳng hạn như công ty bảo hiểm, chính phủ hoặc người tiêu dùng.
    • 2.1.E.4 Việc giảm thiểu rủi ro triển khai các biện pháp kiểm soát an ninh để giảm khả năng xảy ra hoặc tác động của một rủi ro.
    • 2.1.E.5 Rủi ro dư thừa là rủi ro còn lại sau khi một tổ chức đã trải qua quá trình tránh, chuyển giao và giảm thiểu. Mức độ rủi ro dư thừa là mức độ rủi ro mà tổ chức sẵn sàng chấp nhận. Việc chấp nhận rủi ro thừa nhận thực tế rằng bảo mật tuyệt đối là không thể đạt được.
    • 2.1.E.6 Để tiết kiệm nguồn lực tài chính và năng lực nhân viên, một tổ chức thường ưu tiên các giải pháp có hiệu quả về chi phí và dễ dàng triển khai cũng như bảo trì. Các giải pháp có hiệu quả về chi phí tốn kém hơn để lắp đặt và bảo trì so với tổn thất dự kiến từ một cuộc tấn công.

    Mục tiêu học tập 2.1.F: Xác định các loại biện pháp kiểm soát an ninh.

    • 2.1.F.1 Các biện pháp kiểm soát an ninh giải quyết ít nhất một trong các nguyên tắc sau:
      • Tính bí mật đảm bảo rằng chỉ những cá nhân, hệ thống hoặc quy trình được ủy quyền mới có thể truy cập dữ liệu. Các hệ thống thiếu tính bí mật dễ bị tổn thương trước việc trộm cắp hoặc phá hủy dữ liệu.
      • Tính toàn vẹn đảm bảo dữ liệu chính xác và đáng tin cậy. Các hệ thống thiếu tính toàn vẹn dễ bị tổn thương trước việc thao túng dữ liệu.
      • Tính khả dụng đảm bảo dữ liệu và dịch vụ có thể truy cập được bởi các cá nhân được ủy quyền khi cần thiết. Các hệ thống thiếu tính khả dụng có thể gặp phải thời gian ngừng hoạt động bất ngờ.
    • 2.1.F.2 Các biện pháp kiểm soát an ninh có thể được phân loại theo loại hình.
      • Biện pháp kiểm soát vật lý cung cấp sự an toàn trong không gian vật lý và bao gồm khóa, hàng rào, camera, cọc chắn và nhân viên bảo vệ.
      • Biện pháp kiểm soát kỹ thuật cung cấp sự an toàn trong không gian số và bao gồm tường lửa, phần mềm chống mã độc và mã hóa.
      • Biện pháp kiểm soát quản trị cung cấp các quy tắc, hướng dẫn, chính sách và quy trình quy định những gì cần được đặt để đảm bảo an ninh và bao gồm chính sách mật khẩu, xem xét quyền truy cập định kỳ và kế hoạch ứng phó với sự cố (IRP).
    • 2.1.F.3 Các biện pháp kiểm soát an ninh có thể được phân loại theo chức năng.
      • Biện pháp kiểm soát phòng ngừa giải quyết các lỗ hổng tiềm ẩn với mục tiêu ngăn chặn kẻ thù tấn công và bao gồm khóa và mã hóa.
      • Biện pháp kiểm tra phát hiện giúp xác định các cuộc tấn công khi chúng xảy ra và bao gồm hệ thống phát hiện xâm nhập (IDS), camera và hệ thống quản lý sự kiện và sự cố an ninh (SIEM).
      • Biện pháp kiểm soát khắc phục sửa chữa các vấn đề và giúp khôi phục hệ thống về trạng thái hoạt động và bao gồm vá lỗi lỗ hổng, sửa chữa đầu đọc thẻ hỏng và hệ thống ngăn chặn xâm nhập (IPS).

    Mục tiêu học tập 2.1.G: Giải thích tại sao chiến lược an ninh đa lớp là cần thiết để bảo vệ tổ chức một cách tối ưu.

    • 2.1.G.1 Chiến lược an ninh đa lớp, hay phòng thủ nhiều tầng, sử dụng nhiều loại biện pháp kiểm soát an ninh khác nhau để bảo vệ dữ liệu và hệ thống nhạy cảm.
    • 2.1.G.2 Chiến lược an ninh đa lớp cho phép tổ chức giải quyết các loại mối đe dọa khác nhau, mỗi loại đều có biện pháp kiểm soát an ninh phù hợp nhất để giảm thiểu.
    • 2.1.G.3 Chiến lược an ninh đa lớp cho phép khả năng phục hồi trong bảo vệ dữ liệu, do đó khi một biện pháp kiểm soát an ninh bị kẻ thù vượt qua, một biện pháp kiểm soát an ninh khác vẫn có thể ngăn chặn việc truy cập vào dữ liệu hoặc hệ thống hoặc hạn chế thiệt hại gây ra cho dữ liệu hoặc hệ thống.
    • 2.1.G.4 Các lớp trong chiến lược an ninh đa lớp có thể bao gồm con người, vật lý, mạng, thiết bị, ứng dụng và dữ liệu.

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    A monitor wall: network monitoring and logging help detect intrusions
    A monitor wall: network monitoring and logging help detect intrusions

    Before defending a system, you need a shared language. This section builds it.

    Every security control protects at least one part of the CIA triad 信息安全三要素 - the three goals of security:

    • Confidentiality 保密性 - only authorised people can read the data.
    • Integrity 完整性 - the data is accurate and unaltered.
    • Availability 可用性 - the data and services are there when needed.
    The CIA triad: the three goals every security control supports
    The CIA triad: the three goals every security control supports

    Attacks come from different adversaries, classified by their goals. A script kiddie 脚本小子 reuses tools built by others for greed or recognition; a hacktivist 黑客活动分子 acts for a political, social, or personal cause; an insider 内部人员 already holds legitimate access and may act from revenge or greed; a cyberterrorist 网络恐怖分子 disrupts critical infrastructure like a power grid or water plant; and transnational criminal organisations 跨国犯罪组织 chase money through ransomware and stolen data.

    Most attacks unfold in phases 阶段: reconnaissance 侦察 (gathering information, often from public OSINT 公开来源情报 sources), initial access, persistence, lateral movement 横向移动 (spreading to more systems by escalating privileges), taking action on the goal, and evading detection. Naming the phase an attacker has reached helps a defender choose the right response.

    Social engineering: the seven tactics

    Most attacks begin not with code but with social engineering 社会工程学 - psychological tricks that manipulate a person into doing what the adversary wants. The exam names seven tactics, and expects you to identify which one a scenario shows:

    Tactic The trick
    Pretexting 借口 inventing a believable reason to make contact ("I'm from IT, verifying your account")
    Authority 权威 posing as someone powerful, or relaying "the boss's" instructions
    Intimidation 恐吓 threatening negative consequences if a demand is not met
    Consensus 从众 claiming everyone else is already doing it, to create social pressure
    Scarcity 稀缺 inventing limited availability ("only 2 left")
    Familiarity 熟悉 pretending to be, or to know, someone close to the target
    Urgency 紧迫感 imposing a tight deadline so the target acts before thinking

    the common thread is that all seven bypass a target's judgement by triggering an automatic emotional response - fear, trust, haste, or the wish to fit in. The defence is the same each time: verify through a separate, trusted channel before acting.

    A risk 风险 appears when a threat 威胁 can exploit a vulnerability 漏洞 to compromise an asset 资产 (anything valuable - data, money, hardware, reputation). We assess risk by weighing two things: the likelihood 可能性 of an attack and the severity 严重性 of the damage.

    Likelihood itself depends on the value of the target (adversaries chase what looks worth stealing), the skill needed to exploit the vulnerability (a well-documented exploit needs little skill, so more adversaries can use it), and the motivation and capability of likely adversaries. Severity is usually measured in financial cost, but includes reputational and operational damage too.

    The final rating can be written two ways, and the exam wants you to tell them apart:

    • quantitative 定量 - a number: a score on a scale (e.g. 1-10), or a money value (e.g. "a $10,000 annual risk").
    • qualitative 定性 - a label: low / medium / high / severe, or a grid such as likely-high-impact vs unlikely-low-impact.

    A written risk assessment 风险评估 should record, for each risk: the vulnerable asset and its value, the likely threats, how the specific vulnerability would be exploited, the severity if it were compromised, and a final quantitative or qualitative rating.

    Once a risk is measured, an organisation has four ways to manage it:

    • Avoid 规避 - stop the risky activity (only possible if it isn't essential).
    • Transfer 转移 - shift the burden to someone else, such as an insurer.
    • Mitigate 缓解 - add controls to lower the likelihood or impact.
    • Accept 接受 - live with the leftover residual risk 剩余风险, because perfect security is impossible.

    Security controls are grouped two ways. By type: physical 物理 (locks, fences, guards), technical 技术 (firewalls, anti-malware, encryption), and managerial 管理 (policies and procedures). By function: preventative 预防性 (stop an attack, like a lock), detective 检测性 (spot an attack, like a camera), and corrective 纠正性 (fix and restore, like patching).

    Worked example. A hospital stores patient records on an unencrypted server in an unlocked room. Rate the risk: the asset is highly sensitive (patient data, protected by law) and the vulnerability is easy to exploit (no encryption, no access control), so this is a high risk. Now classify one fix - a door lock: by type it is a physical control, and by function it is preventative (it stops entry before an attack even begins).

    The best strategy layers many controls - a defense-in-depth 纵深防御 approach. If an adversary bypasses one layer, another still stands. Layers include human, physical, network, device, application, and data.

    Defense in depth: many layers so one breach does not expose the asset
    Defense in depth: many layers so one breach does not expose the asset
    Explore · ⁨Khám phá⁩

    Classify each security control by function · ⁨Phân loại từng biện pháp an ninh theo chức năng⁩

    A preventative control stops an attack, a detective control spots one in progress, and a corrective control fixes the damage and restores the system. · ⁨Biện pháp phòng ngừa ngăn chặn cuộc tấn công, biện pháp kiểm tra phát hiện cuộc tấn công đang diễn ra, và biện pháp sửa chữa khắc phục thiệt hại và khôi phục hệ thống.⁩

    Explore · ⁨Khám phá⁩

    Classify each security control by type · ⁨Phân loại từng biện pháp an ninh theo loại⁩

    A physical control guards the physical space, a technical control works in the digital space, and a managerial control is a rule, policy, or procedure. · ⁨Biện pháp vật lý bảo vệ không gian vật lý, biện pháp kỹ thuật hoạt động trong không gian kỹ thuật số, và biện pháp quản lý là một quy tắc, chính sách hoặc quy trình.⁩

    Vocabulary · ⁨Từ vựng⁩ Train · ⁨Luyện tập⁩
    English Tiếng Việt
    CIA triad/ˌsiː aɪ ˈeɪ ˈtraɪæd/ tam giác CIA
    Confidentiality/ˌkɒnfɪˌdenʃiˈæləti/ Bảo mật
    Integrity/ɪnˈteɡrɪti/ Đạo đức
    Availability/əˌveɪləˈbɪlɪti/ Khả năng sẵn sàng
    script kiddie/skrɪpt ˈkɪdi/ tên hacker trẻ tuổi (script kiddie)
    hacktivist/ˈhæktɪvɪst/ kẻ hoạt động chính trị mạng
    insider/ɪnˈsaɪdə/ người bên trong
    cyberterrorist/ˈsaɪbəterərɪst/ kẻ khủng bố mạng
    transnational criminal organisations/trænˈsnæʃənl ˈkrɪmɪnl ˌɔːɡənaɪˈzeɪʃnz/ tổ chức tội phạm xuyên quốc gia
    phases/ˈfeɪzɪz/ pha của mặt trăng
    reconnaissance/rɪˈkɒnɪsəns/ trinh sát
    OSINT/ˈəʊsɪnt/ OSINT
    lateral movement/ˈlætərəl ˈmuːvmənt/ di chuyển ngang
    social engineering/ˈsəʊʃl ˌendʒɪˈnɪərɪŋ/ kỹ thuật xã hội
    Pretexting/ˈpriːtekstɪŋ/ Giả tạo tình huống
    Authority/əˈθɒrɪti/ Quyền lực
    Intimidation/ɪnˌtɪmɪˈdeɪʃn/ sự đe dọa
    Consensus/kənˈsensəs/ thống nhất
    Scarcity/ˈskeəsɪti/ sự khan hiếm
    Familiarity/fəˌmɪliˈærɪti/ sự quen thuộc
    Urgency/ˈɜːdʒənsi/ Khẩn cấp
    risk/rɪsk/ rủi ro
    threat/θret/ nguy cơ
    vulnerability/ˌvʌlnərəˈbɪlɪti/ lỗ hổng
    asset/ˈæset/ tài sản
    likelihood/ˈlaɪklihʊd/ khả năng xảy ra
    severity/səˈverɪti/ mức độ nghiêm trọng
    quantitative/ˈkwɒntɪteɪtɪv/ định lượng
    qualitative/ˈkwɒlɪteɪtɪv/ định tính
    risk assessment/rɪsk əˈsesmənt/ đánh giá rủi ro
    Avoid/əˈvɔɪd/ Tránh né
    Transfer/ˈtrænsfɜː/ Chuyển giao
    Mitigate/ˈmɪtɪɡeɪt/ Giảm thiểu
    Accept/əkˈsept/ Chấp nhận
    residual risk/rɪˈsɪdʒuːəl rɪsk/ rủi ro dư thừa
    physical/ˈfɪzɪkl/ vật lý
    technical/ˈteknɪkl/ kỹ thuật
    managerial/ˌmænəˈdʒɪərɪəl/ quản lý
    preventative/prɪˈventətɪv/ phòng ngừa
    detective/dɪˈtektɪv/ phát hiện
    corrective/kəˈrektɪv/ sửa chữa
    defense-in-depth/dɪˈfens ɪn depθ/ phòng thủ theo chiều sâu
    2.2

    Physical Vulnerabilities and Attacks

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 2.2.A: Identify common physical attacks.

    • 2.2.A.1 Adversaries often use social engineering when conducting a physical attack.
    • 2.2.A.2 Piggybacking is the name for an attack where an adversary uses social engineering to manipulate an authorized individual to grant the adversary access to a restricted area. Common piggybacking tactics include carrying something large to entice an authorized person to hold the door open, pretending to be an authorized person who has forgotten their access token, or pretending to be a maintenance person who needs to get into a certain area to perform an inspection or repair.
    • 2.2.A.3 Tailgating is the name for an attack where an adversary gains unauthorized access to a restricted area by following close behind an authorized individual without that individual’s awareness or knowledge.
    • 2.2.A.4 Shoulder surfing is the name for an attack where an adversary watches as a user accesses sensitive information so the adversary can use it later. Sometimes adversaries use a camera to record the target accessing the sensitive information for later analysis.
    • 2.2.A.5 Dumpster diving is the name for an attack where an adversary goes through a target’s physical trash to look for information that could be used to help the adversary reach their goal.
    • 2.2.A.6 Card cloning is the name for an attack where an adversary makes a copy of an authorized user’s access card so they can gain access to all the resources the user is authorized to access.

    Learning Objective 2.2.B: Explain how threats can exploit common physical vulnerabilities to cause loss, damage, disruption, or destruction to assets.

    • 2.2.B.1 Threats include human adversaries seeking to cause harm or disruption as well as natural disasters. Natural disasters can cause physical damage or destruction to computers and data as well as disruption of digital services provided by computers.
    • 2.2.B.2 Vulnerabilities are weaknesses or flaws that could allow an asset to be compromised. Common compromises include:
      • Unauthorized access to sensitive data or restricted physical spaces
      • Disruption of services
      • Theft or destruction of digital or physical resources
      • Unauthorized modification of data
    • 2.2.B.3 When adversaries disrupt power to a device, the device and any services it provides become unavailable. To disrupt power, adversaries may damage fuses or breakers in an electrical box, unplug or cut electrical wiring, or damage power distribution systems like substations and transformers.
    • 2.2.B.4 When adversaries gain access to an area with sensitive information, they can steal or copy sensitive information.
    • 2.2.B.5 When adversaries gain physical access to a device and its ports, they can plug in a keylogger or external drive containing malware, which could allow them to collect data from a user or possibly even to gain control of the device. With direct physical access adversaries can also physically destroy a device, making the device itself, any data stored on it, and any services it provides unavailable.

    Learning Objective 2.2.C: Assess and document risks from physical vulnerabilities.

    • 2.2.C.1 Physical access to devices can allow adversaries to bypass many technical controls and layers of security.
    • 2.2.C.2 High risks from physical vulnerabilities arise when sensitive information or systems are exposed in physical spaces without sufficiently restricted and controlled access.
      • Illustrative examples for 2.2.C.2:
        • A server that stores customer data is in a room with no lock which is accessed via an unmonitored hallway.
    • 2.2.C.3 Moderate risks from physical vulnerabilities arise when a noncritical or nonsensitive part of an organization is left unprotected in a way that it could act as a foothold for an adversary to gain initial access to other resources.
      • Illustrative examples for 2.2.C.3:
        • An office has a reception area beyond which access is controlled; the receptionist has a computer that connects to the office’s internal wireless network and the computer has exposed USB ports.
    • 2.2.C.4 Low risks from physical vulnerabilities arise when a vulnerable asset is of low value and the vulnerability is unlikely to be exploited.
      • Illustrative examples for 2.2.C.4:
        • Employees in an office that requires badge access have laptop computers that they leave on their desks unattended when they all go to lunch together. The computers do not contain any sensitive information, but there are no cables securing the devices to the desks.
    Tiếng Việt

    Mục tiêu học tập 2.2.A: Xác định các cuộc tấn công vật lý phổ biến.

    • 2.2.A.1 Kẻ thù thường sử dụng kỹ thuật xã hội khi thực hiện cuộc tấn công vật lý.
    • 2.2.A.2 Piggybacking là tên gọi của cuộc tấn công mà kẻ thù sử dụng kỹ thuật xã hội để thao túng một cá nhân được ủy quyền cấp quyền truy cập cho kẻ thù vào khu vực hạn chế. Các chiến thuật piggybacking phổ biến bao gồm mang theo vật lớn để thu hút người được ủy quyền giữ cửa mở, giả vờ là người được ủy quyền đã quên thẻ truy cập, hoặc giả vờ là nhân viên bảo trì cần vào một khu vực cụ thể để thực hiện kiểm tra hoặc sửa chữa.
    • 2.2.A.3 Tailgating là tên gọi của cuộc tấn công mà kẻ thù gaining quyền truy cập trái phép vào khu vực hạn chế bằng cách đi sát ngay sau lưng một cá nhân được ủy quyền mà không biết hay nhận thức được điều đó.
    • 2.2.A.4 Shoulder surfing là tên gọi của cuộc tấn công mà kẻ thù quan sát khi người dùng truy cập thông tin nhạy cảm để kẻ thù có thể sử dụng nó sau này. Đôi khi kẻ thù sử dụng camera để ghi lại quá trình mục tiêu truy cập thông tin nhạy cảm phục vụ cho việc phân tích sau này.
    • 2.2.A.5 Dumpster diving là tên gọi của cuộc tấn công mà kẻ thù tìm kiếm trong rác thải vật lý của mục tiêu để tìm thông tin có thể được sử dụng để giúp kẻ thù đạt được mục tiêu của mình.
    • 2.2.A.6 Card cloning là tên gọi của cuộc tấn công mà kẻ thù tạo ra bản sao của thẻ truy cập người dùng được ủy quyền để họ có thể truy cập tất cả các tài nguyên mà người dùng được ủy quyền truy cập.

    Mục tiêu học tập 2.2.B: Giải thích làm thế nào các mối đe dọa có thể khai thác các lỗ hổng vật lý phổ biến để gây mất mát, hư hỏng, gián đoạn hoặc phá hủy tài sản.

    • 2.2.B.1 Các mối đe dọa bao gồm cả kẻ thù con người tìm cách gây harm hoặc disruption cũng như thiên tai. Thiên tai có thể gây hư hỏng vật lý hoặc phá hủy máy tính và dữ liệu cũng như gián đoạn các dịch vụ kỹ thuật số do máy tính cung cấp.
    • 2.2.B.2 Lỗ hổng là điểm yếu hoặc khuyết tật có thể cho phép một tài sản bị compromise. Các hình thức compromise phổ biến bao gồm:
      • Truy cập trái phép vào dữ liệu nhạy cảm hoặc không gian vật lý hạn chế
      • Gián đoạn dịch vụ
      • Trộm cắp hoặc phá hủy tài nguyên kỹ thuật số hoặc vật lý
      • Sửa đổi dữ liệu trái phép
    • 2.2.B.3 Khi kẻ thù切断 nguồn điện của một thiết bị, thiết bị đó và bất kỳ dịch vụ nào do nó cung cấp sẽ trở nên không khả dụng. Để切断 nguồn điện, kẻ thù có thể làm hỏng cầu chì hoặc rơ-le trong hộp điện, rút phích cắm hoặc cắt dây điện, hoặc làm hỏng hệ thống phân phối điện như trạm biến áp và máy biến áp.
    • 2.2.B.4 Khi kẻ thù gain quyền truy cập vào khu vực chứa thông tin nhạy cảm, họ có thể trộm cắp hoặc sao chép thông tin nhạy cảm.
    • 2.2.B.5 Khi kẻ thù gain quyền truy cập vật lý vào thiết bị và các cổng của nó, họ có thể cắm keylogger hoặc ổ đĩa ngoài chứa mã độc, điều này có thể cho phép họ thu thập dữ liệu từ người dùng hoặc thậm chí có thể gain quyền kiểm soát thiết bị. Với quyền truy cập vật lý trực tiếp, kẻ thù cũng có thể phá hủy vật lý một thiết bị, khiến thiết bị đó, bất kỳ dữ liệu nào lưu trữ trên đó và bất kỳ dịch vụ nào do nó cung cấp trở nên không khả dụng.

    Mục tiêu học tập 2.2.C: Đánh giá và ghi nhận rủi ro từ các lỗ hổng vật lý.

    • 2.2.C.1 Quyền truy cập vật lý vào thiết bị có thể cho phép kẻ thù vượt qua nhiều biện pháp kiểm soát kỹ thuật và các lớp an ninh.
    • 2.2.C.2 Rủi ro cao từ các lỗ hổng vật lý arises khi thông tin hoặc hệ thống nhạy cảm bị exposure trong không gian vật lý mà không có quyền truy cập được restricted và controlled đủ.
      • Ví dụ minh họa cho 2.2.C.2:
        • Một máy chủ lưu trữ dữ liệu khách hàng nằm trong phòng không có khóa và tiếp cận qua hành lang không được giám sát.
    • 2.2.C.3 Rủi ro trung bình từ các điểm yếu vật lý phát sinh khi một phần phi trọng yếu hoặc không nhạy cảm của tổ chức bị bỏ trống bảo vệ theo cách mà nó có thể trở thành điểm tựa để kẻ tấn công đạt được quyền truy cập ban đầu vào các tài nguyên khác.
      • Ví dụ minh họa cho 2.2.C.3:
        • Văn phòng có khu vực lễ tân nơi việc truy cập được kiểm soát; nhân viên lễ tân có máy tính kết nối với mạng không dây nội bộ của văn phòng và máy tính này có các cổng USB bị mở.
    • 2.2.C.4 Rủi ro thấp từ các điểm yếu vật lý phát sinh khi tài sản dễ bị tổn thương có giá trị thấp và khả năng bị khai thác là khó xảy ra.
      • Ví dụ minh họa cho 2.2.C.4:
        • Nhân viên trong văn phòng yêu cầu thẻ truy cập có laptop để trên bàn làm việc khi họ rời đi ăn trưa cùng nhau. Các máy tính này không chứa thông tin nhạy cảm, nhưng không có cáp nào khóa thiết bị vào bàn.

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    Digital security means nothing if an adversary can simply walk in. Common physical attacks 物理攻击 often begin with social engineering:

    • Piggybacking 尾随(获许可) - tricking an authorised person into holding a door open (for example, by carrying a heavy box).
    • Tailgating 尾随(未察觉) - slipping through a secured door behind someone without their knowledge.
    • Shoulder surfing 肩窥 - watching someone type a password or read sensitive information.
    • Dumpster diving 翻垃圾搜集情报 - searching a target's trash for useful information.
    • Card cloning 门禁卡复制 - copying an access card to enter restricted areas.

    With physical access, an adversary can cut power, steal or copy data, or plug in a keylogger 键盘记录器. We rate physical risk as high when sensitive systems sit in a space without controlled access, moderate when an unimportant area could act as a foothold 立足点 to reach other resources, and low when the asset is worthless and unlikely to be attacked.

    A padlock on a chain: physical security is the first layer — locks, doors and barriers matter
    A padlock on a chain: physical security is the first layer — locks, doors and barriers matter
    Vocabulary · ⁨Từ vựng⁩ Train · ⁨Luyện tập⁩
    English Tiếng Việt
    physical attacks/ˈfɪzɪkl əˈtæks/ tấn công vật lý
    Piggybacking/ˈpɪɡɪbækɪŋ/ Piggybacking
    Tailgating/ˈteɪlɡeɪtɪŋ/ Tailgating
    Shoulder surfing/ˈʃəʊldə ˈsɜːfɪŋ/ Shoulder surfing
    Dumpster diving/ˈdʌmpstə ˈdaɪvɪŋ/ Dumpster diving
    Card cloning/kɑːd ˈkləʊnɪŋ/ Sao chép thẻ
    keylogger/ˈkiːlɒɡə/ keylogger
    foothold/ˈfʊthəʊld/ nơi立足点 (điểm neo giữ)
    2.3

    Protecting Physical Spaces

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 2.3.A: Identify managerial controls related to physical security.

    • 2.3.A.1 Organizations should conduct employee security awareness training to educate employees about how they can contribute to the organization’s security by:
      • Detecting social engineering attempts like phishing
      • Not badging other people into restricted areas
      • Preventing device theft
    • 2.3.A.2 Organizations should have a workstation security policy that outlines the measures necessary to protect a physical workplace. The policy may have tiers of workstation security based on the type of data handled at a workstation. Workstation policies often require:
      • Locking devices before leaving workstations unattended to prevent unauthorized access
      • Clearing sensitive documents off workstations before leaving them unattended (sometimes called a clean desk policy)
      • Using a privacy screen filter or other physical barrier to prevent others from viewing information on the screen
      • Connecting devices to surge protectors or uninterruptible power supplies (UPS)

    Learning Objective 2.3.B: Determine mitigation strategies for risks from physical vulnerabilities.

    • 2.3.B.1 To determine a relevant control, a cyber defender considers how an adversary could take advantage of a vulnerability to attack a system and how to prevent, detect, or correct the attack.
    • 2.3.B.2 Installing physical controls like fencing, gates, and bollards around a building can deter adversaries from trying to physically access an organization’s buildings.
    • 2.3.B.3 Locks on doors, server cabinets, and computers can prevent devices from being accessed or stolen.
    • 2.3.B.4 Card readers can record which employee badges are being used to access different entries at specific times and deny access to unauthorized badges.
    • 2.3.B.5 Access control vestibules and turnstiles can prevent an authorized person from intentionally or accidentally admitting an unauthorized person into a restricted area.
    • 2.3.B.6 Organizations can disable USB ports to prevent external drives from loading malware onto a computer.
    • 2.3.B.7 An uninterruptible power supply (UPS) provides a backup power source for a device in the event of a power outage. Organizations can also use power generators to provide power at a larger scale to a building or set of critical devices.
    • 2.3.B.8 Organizations prioritize risk mitigations based on the severity of the risks and the cost of the recommended mitigations.
    Tiếng Việt

    Mục tiêu học tập 2.3.A: Xác định các kiểm soát quản lý liên quan đến an ninh vật lý.

    • 2.3.A.1 Tổ chức nên tiến hành đào tạo nhận thức an ninh cho nhân viên nhằm giáo dục họ về cách đóng góp vào an ninh tổ chức bằng cách:
      • Phát hiện các nỗ lực kỹ thuật xã hội như phishing
      • Không đưa người khác vào các khu vực hạn chế bằng thẻ của mình
      • Ngăn ngừa trộm cắp thiết bị
    • 2.3.A.2 Tổ chức nên có chính sách an ninh trạm làm việc nêu rõ các biện pháp cần thiết để bảo vệ môi trường làm việc vật lý. Chính sách này có thể có các cấp độ an ninh trạm làm việc dựa trên loại dữ liệu được xử lý tại đó. Chính sách trạm làm việc thường yêu cầu:
      • Khóa thiết bị trước khi rời khỏi trạm làm việc không có người trông coi để ngăn truy cập trái phép
      • Dọn dẹp tài liệu nhạy cảm khỏi trạm làm việc trước khi rời đi (đôi khi gọi là chính sách bàn làm việc sạch)
      • Sử dụng màn hình chống nhìn lén hoặc rào cản vật lý khác để ngăn người khác xem thông tin trên màn hình
      • Kết nối thiết bị với bộ ổn áp điện hoặc nguồn điện không ngắt (UPS)

    Mục tiêu học tập 2.3.B: Xác định các chiến lược giảm thiểu rủi ro từ các điểm yếu vật lý.

    • 2.3.B.1 Để xác định kiểm soát phù hợp, nhà phòng thủ cyber xem xét cách kẻ tấn công có thể lợi dụng điểm yếu để tấn công hệ thống và làm thế nào để ngăn chặn, phát hiện hoặc khắc phục cuộc tấn công.
    • 2.3.B.2 Lắp đặt các kiểm soát vật lý như hàng rào, cửa gates và cọc chắn xung quanh tòa nhà có thể răn đe kẻ tấn công không thử tiếp cận vật lý các tòa nhà của tổ chức.
    • 2.3.B.3 Khóa trên cửa, tủ server và máy tính có thể ngăn thiết bị bị truy cập hoặc đánh cắp.
    • 2.3.B.4 Đầu đọc thẻ có thể ghi lại thẻ nhân viên nào đang được sử dụng để truy cập các lối vào khác nhau ở những thời điểm cụ thể và từ chối truy cập đối với các thẻ không được ủy quyền.
    • 2.3.B.5 Khu vực kiểm soát truy cập (vestibule) và cửa xoay có thể ngăn một người được ủy quyền cố ý hoặc vô tình cho một người không được ủy quyền vào khu vực hạn chế.
    • 2.3.B.6 Tổ chức có thể tắt các cổng USB để ngăn ổ đĩa ngoài tải mã độc vào máy tính.
    • 2.3.B.7 Nguồn điện không ngắt (UPS) cung cấp nguồn dự phòng cho thiết bị trong trường hợp mất điện. Tổ chức cũng có thể sử dụng máy phát điện để cung cấp điện quy mô lớn hơn cho một tòa nhà hoặc nhóm thiết bị quan trọng.
    • 2.3.B.8 Tổ chức ưu tiên các biện pháp giảm thiểu rủi ro dựa trên mức độ nghiêm trọng của rủi ro và chi phí của các biện pháp đề xuất.

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    Managerial controls come first: security-awareness training teaches staff not to badge strangers in, and a workstation security policy requires locking devices, clearing desks (a clean desk policy 清桌政策), and using privacy screens.

    Physical controls then harden the building: fences, gates, and bollards 防撞柱 deter access; locks protect doors and cabinets; card readers 读卡器 log and restrict entry; an access control vestibule 门禁前室 (a two-door airlock) stops piggybacking; disabling USB ports blocks malware drives; and an uninterruptible power supply (UPS) 不间断电源 keeps devices running through an outage. Organisations prioritise these by matching the cost of a control to the severity of the risk.

    A dome security camera: physical controls and monitoring protect spaces as well as networks
    A dome security camera: physical controls and monitoring protect spaces as well as networks
    Vocabulary · ⁨Từ vựng⁩ Train · ⁨Luyện tập⁩
    English Tiếng Việt
    clean desk policy/kliːn desk ˈpɒlɪsi/ chính sách bàn làm việc sạch
    bollards/ˈbɒlɑːdz/ cột chắn
    card readers/kɑːd ˈriːdəz/ đầu đọc thẻ
    access control vestibule/ˈækses kənˈtrəʊl ˈvestɪbjuːl/ cửa kiểm soát truy cập (access control vestibule)
    uninterruptible power supply (UPS)/ˌʌˌnɪntəˈrʌptɪbl ˈpaʊə səˈplaɪ/ nguồn điện không间断 (UPS)
    2.4

    Detecting Physical Attacks

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 2.4.A: Identify ways security controls can detect physical attacks.

    • 2.4.A.1 Cameras can capture a visual record of an adversary’s malicious activity. The feed from a camera should be recorded and monitored for maximum effect. Recordings can be especially helpful in after-incident investigations.
    • 2.4.A.2 Security guards can monitor activity in an area and respond to suspicious activity once detected.
    • 2.4.A.3 Motion sensors can alert security to movement in an area.
    • 2.4.A.4 Employees that work in a physical space are often the first to notice the presence of an unauthorized person and can alert security.

    Learning Objective 2.4.B: Determine effective placement of security controls for detecting physical attacks.

    • 2.4.B.1 When placing cameras, consideration should be given to visual coverage, angle, and the ability to be tampered with by an adversary. Consideration should also be given to what a camera in a specific area could capture an adversary doing and how that information would be helpful. Points of ingress and egress are often monitored by camera.
    • 2.4.B.2 Motion sensors should be placed in areas where traffic is unexpected, like server rooms, or areas where sensitive materials are stored and few people have access. Motion sensors in high-traffic areas create many false alarms, making the alarms less likely to be taken seriously when there is a real security event.
    • 2.4.B.3 Locks should be placed on all entries to areas containing sensitive information or systems. For areas with particularly sensitive information or systems, an organization could use an access control vestibule at the entry point to prevent piggybacking or tailgating.
    • 2.4.B.4 Security guards can be stationary or patrolling. Stationary guards can provide constant protection for a specific area, entrance, or high-value item. Patrolling guards are more difficult for an adversary to plan around and can create time pressure for an adversary. Placing stationary guards at places that funnel traffic (e.g., entry gates, main entrances or lobbies, and entrances to more secure access areas) can be highly effective, while patrolling guards are better suited for perimeters and exterior areas.

    Learning Objective 2.4.C: Apply detection techniques to identify physical attacks.

    • 2.4.C.1 Cameras provide visual monitoring and a visual record of activity within a designated space. Cameras can be paired with facial recognition software that can provide alerts when unauthorized individuals enter controlled areas. Once a physical breach has been detected, defenders can use live and recorded camera footage to track an adversary’s path and actions.
    • 2.4.C.2 Motion detectors work best when paired with cameras. When a security alert is raised because a motion detector has been activated, defenders can use cameras to check the space visually and verify a physical security breach.
    • 2.4.C.3 When employees are required to use an electronic badge to unlock a door to a restricted area, a sensor can record how long the door was open. In reviewing entry logs for the door, potential piggybacking or tailgating can be detected by doors being open for longer than normal lengths of time.
    Tiếng Việt

    Mục tiêu học tập 2.4.A: Xác định cách các kiểm soát an ninh có thể phát hiện các cuộc tấn công vật lý.

    • 2.4.A.1 Camera có thể ghi lại hình ảnh trực quan các hoạt động độc hại của kẻ tấn công. Dòng truyền từ camera nên được ghi lại và giám sát để đạt hiệu quả tối đa. Bản ghi đặc biệt hữu ích trong các cuộc điều tra sau sự cố.
    • 2.4.A.2 Cảnh vệ có thể giám sát hoạt động trong khu vực và phản ứng với các hoạt động đáng ngờ khi được phát hiện.
    • 2.4.A.3 Cảm biến chuyển động có thể cảnh báo an ninh về sự di chuyển trong khu vực.
    • 2.4.A.4 Nhân viên làm việc trong không gian vật lý thường là người đầu tiên nhận thấy sự hiện diện của người không được ủy quyền và có thể cảnh báo an ninh.

    Mục tiêu học tập 2.4.B: Xác định vị trí đặt an ninh hiệu quả để phát hiện các cuộc tấn công vật lý.

    • 2.4.B.1 Khi lắp đặt camera, cần cân nhắc đến phạm vi bao phủ, góc nhìn và khả năng bị can thiệp bởi kẻ tấn công. Cần cân nhắc cả những gì mà camera tại một khu vực cụ thể có thể ghi lại hành động của kẻ tấn công và thông tin đó sẽ hữu ích như thế nào. Các điểm vào và ra thường được giám sát bằng camera.
    • 2.4.B.2 Cảm biến chuyển động nên được đặt ở những khu vực có lưu lượng bất ngờ, như phòng server, hoặc khu vực lưu trữ tài liệu nhạy cảm và ít người truy cập. Cảm biến chuyển động ở khu vực đông người đi lại tạo ra nhiều báo động giả, khiến các báo động ít được coi trọng khi có sự kiện an ninh thực sự xảy ra.
    • 2.4.B.3 Khóa nên được lắp đặt ở tất cả các lối vào các khu vực chứa thông tin nhạy cảm hoặc hệ thống. Đối với các khu vực có thông tin hoặc hệ thống đặc biệt nhạy cảm, tổ chức có thể sử dụng khu vực kiểm soát truy cập (vestibule) tại điểm vào để ngăn chặn việc đi theo người khác (piggybacking/tailgating).
    • 2.4.B.4Guard an ninh có thể đứng cố định hoặc tuần tra. Guard đứng cố định có thể cung cấp bảo vệ liên tục cho một khu vực, lối vào hoặc tài sản có giá trị cao cụ thể. Guard tuần tra khó hơn để đối thủ lên kế hoạch chống lại và có thể tạo áp lực thời gian cho đối thủ. Việc bố trí guard đứng cố định tại các điểm tập trung lưu lượng (ví dụ: cổng vào, lối đi chính hoặc sảnh, và lối vào các khu vực truy cập an toàn hơn) có thể rất hiệu quả, trong khi guard tuần tra phù hợp hơn cho các vùng biên giới và khu vực bên ngoài.

    Mục tiêu học tập 2.4.C: Áp dụng các kỹ thuật phát hiện để xác định các cuộc tấn công vật lý.

    • 2.4.C.1 Camera cung cấp giám sát trực quan và bản ghi hình ảnh về hoạt động trong không gian được chỉ định. Camera có thể kết hợp với phần mềm nhận diện khuôn mặt để gửi cảnh báo khi cá nhân không được phép vào các khu vực kiểm soát. Khi một vụ xâm phạm vật lý đã được phát hiện, các bên phòng thủ có thể sử dụng video camera trực tiếp và đã quay để theo dõi đường đi và hành động của đối thủ.
    • 2.4.C.2Cảm biến chuyển động hoạt động tốt nhất khi kết hợp với camera. Khi một cảnh báo an ninh được kích hoạt do cảm biến chuyển động được kích hoạt, các bên phòng thủ có thể sử dụng camera để kiểm tra không gian bằng mắt thường và xác minh việc xâm phạm an ninh vật lý.
    • 2.4.C.3Khi nhân viên bắt buộc phải sử dụng thẻ điện tử để mở cửa ra khu vực hạn chế, một cảm biến có thể ghi lại thời gian cửa mở. Trong quá trình xem xét nhật ký truy cập cửa, việc lén lút đi theo (piggybacking hoặc tailgating) có thể bị phát hiện thông qua việc cửa mở lâu hơn bình thường.

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    Some controls detect attacks rather than prevent them. Cameras record activity and help after-incident investigations; security guards respond to what they see; motion sensors 运动传感器 alert staff to movement; and employees themselves often notice an intruder first.

    Placement matters. Cameras belong at points of ingress and egress 出入口 (entrances and exits). Motion sensors work best in low-traffic areas like server rooms - put them in a busy hallway and constant false alarms make everyone ignore them. Stationary guards protect a fixed high-value point, while patrolling guards are harder for an adversary to plan around. Reviewing door-open times in entry logs can even reveal piggybacking, because a door held open too long is suspicious.

    Vocabulary · ⁨Từ vựng⁩ Train · ⁨Luyện tập⁩
    English Tiếng Việt
    motion sensors/ˈməʊʃn ˈsensəz/ cảm biến chuyển động
    points of ingress and egress/pɔɪnts ɒv ˈɪŋɡres ænd iːˈɡres/ điểm vào và ra
    2.4

    Exam tips

    • Memorise the CIA triad and be ready to say which goal a control protects - encryption serves confidentiality, a hash checks integrity, a backup restores availability.
    • Know the four risk responses (avoid, transfer, mitigate, accept) and the two ways to classify controls (by type: physical/technical/managerial; by function: preventative/detective/corrective).
    • Distinguish piggybacking (with consent, tricked) from tailgating (without the person's knowledge) - exam questions test this exact pair.
    • For risk-rating questions, high risk needs both high value AND easy exploitation; a "foothold to other systems" is the classic moderate risk.
    • Defense in depth is the model answer whenever a question asks why one control is not enough.
  • 3

    Securing Networks · ⁨Bảo vệ Mạng⁩

    Watch lesson · ⁨Xem bài học⁩
    3.1

    Network Vulnerabilities and Attacks

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 3.1.A: Identify common network attacks.

    • 3.1.A.1 The address resolution protocol (ARP) is used by a default gateway on a network to establish a table that pairs internet protocol (IP) addresses with media access control (MAC) addresses. An ARP poisoning attack is when an adversary sends falsified ARP packets to the default gateway to modify the table so that the adversary’s device receives traffic intended for the target by linking the target’s IP address to the adversary’s MAC address. Faking a MAC address is called MAC spoofing. This is an example of an on-path attack (or man-in-the-middle attack), which is when an adversary interrupts a data stream between two parties, captures both parties’ data, and copies or alters the data before sending them on. Both parties think they are communicating directly with each other, but instead they are each communicating with the adversary who is secretly intercepting their messages.
    • 3.1.A.2 A MAC flooding attack is when an adversary sends the target switch many Ethernet frames, each with a different MAC address. This can force the switch into broadcast mode, and the adversary can then collect all of the frames on the network (because they are being broadcast), which could allow the adversary to access sensitive information. This is an example of eavesdropping (or sniffing), which is when an adversary captures data in transit and can record and copy the data.
    • 3.1.A.3 A domain name system (DNS) poisoning attack is when an adversary pretends to be an authoritative name server (NS) and plants a fake DNS record on a DNS server to redirect browser traffic to a malicious website designed to steal credentials. This is an example of credential harvesting, which is when adversaries set up a fake login site that looks like a real one. Unsuspecting users enter their real credentials, which the adversaries capture and use.
    • 3.1.A.4 A smurf attack attempts to overwhelm a network with Internet Control Message Protocol (ICMP) requests. It is a type of denial of service (DoS) attack, which makes a system or resource unavailable to authorized users. During a smurf attack, an adversary sends many ICMP requests with the victim’s address to the network’s broadcast address. The network’s gateway then sends these requests to all devices on the network. Each device on the network replies to the victim’s address, creating a flood of traffic that can block legitimate messages. When multiple devices attack the same target simultaneously, it’s called a distributed denial of service (DDoS) attack.

    Learning Objective 3.1.B: Explain how adversaries can exploit network vulnerabilities to steal, disrupt, or destroy network communication.

    • 3.1.B.1 Adversaries can send malicious traffic into a network to flood it creating a DoS, to map the internal structure of the network, or to spoof a legitimate device. Networks without firewalls, or with improperly configured firewalls, are vulnerable to these types of attacks.
    • 3.1.B.2 Adversaries that have compromised a device often attempt to leverage their access to compromise other devices on the local area network (LAN).
    • 3.1.B.3 Adversaries that physically plug into a data port can gain access to a LAN through the switch port unless port security is enabled. This allows adversaries to launch DoS attacks or perform MAC flooding or MAC spoofing attacks.
    • 3.1.B.4 Adversaries standing outside of physically secure spaces can pick up the signals and beacon frames from a wireless access point that is broadcasting outside the physical space. This allows them to gather information about the wireless network and to attempt eavesdropping and cryptographic attacks on it.
    • 3.1.B.5 Adversaries can attempt to join networks to launch attacks from within the networks. Networks that do not authenticate devices and users make it easier for adversaries to join.
    • 3.1.B.6 If there is an open network port, an adversary can plug a wireless access point into the port creating a rogue access point. The adversary could use this rogue access point to access the internal network wirelessly (maybe even from outside the physical space). This allows the adversary direct access to the LAN, bypassing any firewalls.
    • 3.1.B.7 Adversaries can attempt to break wireless encryption and intercept, steal, or compromise data on a network.

    Learning Objective 3.1.C: Assess and document risks from network vulnerabilities.

    • 3.1.C.1 Vulnerabilities on a network can lead to adversaries being able to intercept and alter data in transit, launch DoS attacks, or move laterally on a network to gain access to more sensitive or critical systems. Network vulnerabilities can constitute a risk to confidentiality, integrity, and availability.
    • 3.1.C.2 There are automated vulnerability scanners that can check networks, devices, and applications for known vulnerabilities. These scanners produce a report that often includes the vulnerabilities detected, their severity, and mitigation recommendations.
    • 3.1.C.3 Successfully exploiting a network vulnerability often requires advanced technical ability and knowledge. This can impact the likelihood of an exploit.
    • 3.1.C.4 High risks from network vulnerabilities allow an adversary to easily have a significant impact by capturing network traffic, spoofing a legitimate device on the network, or launching a DoS attack.
      • Illustrative examples for 3.1.C.4:
        • An organization has a single unsegmented internal network that is accessible via a wireless network with weak encryption, and on that network it has a server running its proprietary web-application.
    • 3.1.C.5 Moderate risks from network vulnerabilities could include vulnerabilities that might give adversaries the ability to gain information about systems or devices on a network.
      • Illustrative examples for 3.1.C.5:
        • An organization’s external firewall is not configured to block external ICMP traffic.
    • 3.1.C.6 Low risks from network vulnerabilities include vulnerabilities that would be difficult to exploit and would likely have minimal negative impacts on an organization.
      • Illustrative examples for 3.1.C.6:
        • An organization has wireless access points that broadcast a beacon frame, which contains the network service set identifier (SSID) and the wireless encryption protocols.
    Tiếng Việt

    Mục tiêu học tập 3.1.A: Xác định các cuộc tấn công mạng phổ biến.

    • 3.1.A.1Giao thức giải địa chỉ ARP được sử dụng bởi cổng mặc định trên mạng để thiết lập bảng ghép nối địa chỉ giao thức Internet (IP) với địa chỉ kiểm soát truy cập phương tiện (MAC). Một cuộc tấn công毒 ARP là khi đối thủ gửi các gói tin ARP giả mạo đến cổng mặc định để sửa đổi bảng đó sao cho thiết bị của đối thủ nhận được lưu lượng dự kiến dành cho mục tiêu bằng cách liên kết địa chỉ IP của mục tiêu với địa chỉ MAC của đối thủ. Giả mạo địa chỉ MAC được gọi là giả mạo MAC. Đây là ví dụ về cuộc tấn công trên đường truyền (hoặc tấn công người giữa), là khi đối thủ gián đoạn luồng dữ liệu giữa hai bên, thu thập dữ liệu của cả hai bên và sao chép hoặc thay đổi dữ liệu trước khi gửi tiếp. Cả hai bên đều nghĩ rằng họ đang giao tiếp trực tiếp với nhau, nhưng thực tế họ đang giao tiếp với đối thủ, người đang âm thầm chặn lấy tin nhắn của họ.
    • 3.1.A.2Một cuộc tấn công làm tràn MAC là khi đối thủ gửi nhiều khung Ethernet đến bộ chuyển đổi mục tiêu, mỗi khung có một địa chỉ MAC khác nhau. Điều này có thể buộc bộ chuyển đổi vào chế độ phát sóng, và sau đó đối thủ có thể thu thập tất cả các khung trên mạng (vì chúng đang được phát sóng), điều này có thể cho phép đối thủ truy cập thông tin nhạy cảm. Đây là ví dụ về nghe trộm (hoặc sniffing), là khi đối thủ thu thập dữ liệu đang truyền và có thể ghi lại và sao chép dữ liệu đó.
    • 3.1.A.3Một cuộc tấn công毒 DNS là khi đối thủ giả vờ là máy chủ tên có thẩm quyền (NS) và cài đặt bản ghi DNS giả trên máy chủ DNS để định hướng lưu lượng trình duyệt sang một trang web độc hại được thiết kế để đánh cắp thông tin đăng nhập. Đây là ví dụ về thu thập thông tin đăng nhập, là khi đối thủ thiết lập một trang đăng nhập giả trông giống thật. Người dùng vô tội rơi vào bẫy nhập thông tin đăng nhập thật của họ, mà đối thủ thu thập và sử dụng.
    • 3.1.A.4Một cuộc tấn công Smurf cố gắng làm quá tải mạng bằng các yêu cầu Giao thức tin nhắn Internet (ICMP). Đây là một loại cuộc tấn công từ chối dịch vụ (DoS), khiến hệ thống hoặc tài nguyên không khả dụng đối với người dùng được ủy quyền. Trong một cuộc tấn công Smurf, đối thủ gửi nhiều yêu cầu ICMP với địa chỉ nạn nhân đến địa chỉ phát sóng của mạng. Cổng mạng sau đó gửi các yêu cầu này đến tất cả các thiết bị trên mạng. Mỗi thiết bị trên mạng phản hồi về địa chỉ nạn nhân, tạo ra một cơn bão lưu lượng có thể chặn các tin nhắn hợp lệ. Khi nhiều thiết bị tấn cùng một mục tiêu đồng thời, nó được gọi là cuộc tấn công từ chối dịch vụ phân tán (DDoS).

    Mục tiêu học tập 3.1.B: Giải thích cách đối thủ khai thác lỗ hổng mạng để đánh cắp, phá hoại hoặc hủy bỏ giao tiếp mạng.

    • 3.1.B.1Đối thủ có thể gửi lưu lượng độc hại vào mạng để làm ngập nó tạo ra DoS, để lập sơ đồ cấu trúc nội bộ của mạng, hoặc để giả mạo một thiết bị hợp lệ. Các mạng không có tường lửa, hoặc có tường lửa được cấu hình không đúng cách, dễ bị tổn thương trước các loại cuộc tấn công này.
    • 3.1.B.2Đối thủ đã xâm chiếm một thiết bị thường cố gắng tận dụng quyền truy cập của mình để xâm chiếm các thiết bị khác trên mạng cục bộ (LAN).
    • 3.1.B.3Đối thủ cắm vật lý vào cổng dữ liệu có thể truy cập LAN thông qua cổng bộ chuyển đổi trừ khi bảo mật cổng được bật. Điều này cho phép đối thủ triển khai các cuộc tấn công DoS hoặc thực hiện các cuộc tấn công làm tràn MAC hoặc giả mạo MAC.
    • 3.1.B.4Đối thủ đứng bên ngoài các không gian an toàn vật lý có thể thu nhận tín hiệu và khung beacon từ một điểm truy cập không dây đang phát sóng ra ngoài không gian vật lý. Điều này cho phép họ thu thập thông tin về mạng không dây và cố gắng nghe trộm cũng như thực hiện các cuộc tấn công mã hóa lên nó.
    • 3.1.B.5Đối thủ có thể cố gắng tham gia vào các mạng để triển khai cuộc tấn công từ bên trong các mạng đó. Các mạng không xác thực thiết bị và người dùng giúp đối thủ dễ dàng tham gia hơn.
    • 3.1.B.6 Nếu có một cổng mạng mở, kẻ tấn công có thể cắm một điểm truy cập không dây vào cổng đó để tạo ra một điểm truy cập bất hợp pháp. Kẻ tấn công có thể sử dụng điểm truy cập bất hợp pháp này để truy cập mạng nội bộ qua kết nối không dây (có thể thậm chí từ bên ngoài không gian vật lý). Điều này cho phép kẻ tấn công truy cập trực tiếp vào LAN, vượt qua mọi tường lửa.
    • 3.1.B.7 Kẻ tấn công có thể cố gắng phá mã bảo mật không dây và đánh cắp, chiếm đoạt hoặc làm giả dữ liệu trên mạng.

    Mục tiêu học tập 3.1.C: Đánh giá và ghi chép các rủi ro từ lỗ hổng bảo mật mạng.

    • 3.1.C.1 Lỗ hổng trên mạng có thể dẫn đến việc kẻ tấn công có thể chặn và thay đổi dữ liệu đang truyền tải, phát triển cuộc tấn công DoS, hoặc di chuyển ngang trong mạng để truy cập vào các hệ thống nhạy cảm hoặc quan trọng hơn. Lỗ hổng mạng có thể cấu thành rủi ro đối với tính bí mật, tính toàn vẹn và tính sẵn sàng.
    • 3.1.C.2 Có các trình quét lỗ hổng tự động có thể kiểm tra mạng, thiết bị và ứng dụng xem có lỗ hổng đã biết hay không. Các trình quét này tạo ra báo cáo thường bao gồm các lỗ hổng được phát hiện, mức độ nghiêm trọng và các khuyến nghị giảm thiểu.
    • 3.1.C.3 Khai thác thành công một lỗ hổng mạng thường yêu cầu kỹ năng và kiến thức kỹ thuật nâng cao. Điều này có thể ảnh hưởng đến khả năng xảy ra việc khai thác.
    • 3.1.C.4 Rủi ro cao từ lỗ hổng mạng cho phép kẻ tấn công dễ dàng gây tác động đáng kể bằng cách bắt giữ lưu lượng mạng, giả mạo một thiết bị hợp lệ trên mạng, hoặc phát triển cuộc tấn công DoS.
      • Ví dụ minh họa cho 3.1.C.4:
        • Một tổ chức có một mạng nội bộ duy nhất không phân vùng và có thể truy cập qua mạng không dây với mã hóa yếu, và trên mạng đó có một máy chủ đang chạy ứng dụng web độc quyền của họ.
    • 3.1.C.5 Rủi ro trung bình từ lỗ hổng mạng có thể bao gồm các lỗ hổng có thể giúp kẻ tấn công thu thập thông tin về các hệ thống hoặc thiết bị trên mạng.
      • Ví dụ minh họa cho 3.1.C.5:
        • Tường lửa bên ngoài của một tổ chức không được cấu hình để chặn lưu lượng ICMP từ bên ngoài.
    • 3.1.C.6 Rủi ro thấp từ lỗ hổng mạng bao gồm các lỗ hổng sẽ khó khai thác và có khả năng sẽ gây ra ít tác động tiêu cực nhất định đến tổ chức.
      • Ví dụ minh họa cho 3.1.C.6:
        • Một tổ chức có các điểm truy cập không dây phát tín hiệu beacon, chứa định danh dịch vụ tập hợp mạng (SSID) và các giao thức mã hóa không dây.

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    A man-in-the-middle attack
    DDoS: a botnet floods a server

    A network connects devices so they can share data - and every connection is a possible way in. You must know the classic network attacks and the tricks behind them.

    • ARP poisoning 地址解析投毒 - the address resolution protocol (ARP) 地址解析协议 pairs IP addresses with hardware MAC addresses 物理地址. An adversary sends fake ARP messages so traffic meant for the target flows to the adversary instead. This is an on-path attack 中间人攻击 (also called man-in-the-middle): the adversary secretly sits between two parties, reading and even altering their messages.
    • MAC flooding 物理地址泛洪 - flooding a switch 交换机 with fake MAC addresses forces it into broadcast mode, so the adversary can capture all traffic. This is a form of eavesdropping 窃听.
    • DNS poisoning 域名投毒 - planting a fake record on a domain name system (DNS) 域名系统 server redirects users to a malicious site to steal credentials (credential harvesting 凭据收集).
    • Smurf attack - flooding a network with ICMP requests aimed at the broadcast address, so every device replies to the victim. It is a denial of service (DoS) 拒绝服务 attack; when many machines attack at once it becomes a distributed denial of service (DDoS) 分布式拒绝服务.

    Adversaries exploit weak networks to flood, map, or spoof devices. A physical data port with no port security lets an attacker plug in; an open port lets them install a rogue access point 非法接入点 that bypasses the firewall entirely. We rate network risk by impact and by how much skill the exploit needs.

    To find weaknesses before an adversary does, organisations run an automated vulnerability scanner 自动漏洞扫描器: a tool that checks networks, devices, and applications against a database of known vulnerabilities, then produces a report listing each one found, how severe it is, and a recommended mitigation 缓解措施. Fixing the highest-severity items first is a core part of managing network risk.

    Explore · ⁨Khám phá⁩

    Identify the network attack from its evidence · ⁨Xác định cuộc tấn công mạng dựa trên bằng chứng⁩

    Each network attack leaves a distinct trace: ARP poisoning = one IP with two MACs; MAC flooding = a surge of new MACs; DNS poisoning = misdirected web traffic; smurf/DoS = a flood that blocks legitimate traffic. · ⁨Mỗi cuộc tấn công mạng để lại dấu vết đặc trưng: lừa ARP = một IP có hai MAC; tràn ngập MAC = một đợt tăng đột biến các MAC mới; lừa DNS = lưu lượng web bị định hướng sai; smurf/DoS = một đợt tràn ngập chặn lưu lượng hợp lệ.⁩

    Vocabulary · ⁨Từ vựng⁩ Train · ⁨Luyện tập⁩
    English Tiếng Việt
    ARP poisoning/ɑːp ˈpɔɪzənɪŋ/ ARP poisoning
    address resolution protocol (ARP)/əˈdres ˌrezəˈluːʃn ˈprəʊtəkɒl/ giao thức giải quyết địa chỉ (ARP)
    MAC addresses/mæk əˈdresɪz/ địa chỉ MAC
    on-path attack/ɒn pæθ əˈtæk/ tấn công trên đường truyền
    MAC flooding/mæk ˈflʌdɪŋ/ MAC flooding
    switch/swɪtʃ/ công tắc
    eavesdropping/ˈiːvzdrɒpɪŋ/ nghe lén
    DNS poisoning/ˌdiː en ˈes ˈpɔɪzənɪŋ/ DNS poisoning
    domain name system (DNS)/dəˈmeɪn neɪm ˈsɪstəm/ hệ thống tên miền (DNS)
    credential harvesting/krɪˈdenʃl ˈhɑːvɪstɪŋ/ thu thập thông tin đăng nhập
    denial of service (DoS)/dɪˈnaɪəl ɒv ˈsɜːvɪs/ từ chối dịch vụ (DoS)
    distributed denial of service (DDoS)/ˈdɪstrɪbjuːtɪd dɪˈnaɪəl ɒv ˈsɜːvɪs/ tấn công từ chối dịch vụ phân tán (DDoS)
    rogue access point/rəʊɡ ˈækses pɔɪnt/ trạm truy cập bất hợp pháp
    automated vulnerability scanner/ˈɔːtəmeɪtɪd ˌvʌlnərəˈbɪlɪti ˈskænə/ máy quét lỗ hổng tự động
    mitigation/ˌmɪtɪˈɡeɪʃn/ giảm thiểu
    3.2

    Protecting Networks: Managerial Controls and Wireless Security

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 3.2.A: Identify managerial controls related to network security.

    • 3.2.A.1 A router security policy will set forth a minimum configuration standard for routers on an organization’s network and may include:
      • Banning local user accounts (All router logins must use an approved authentication server.)
      • Disabling unnecessary services (e.g., Telnet)
      • Requiring a firewall (An organization may opt for a firewall device separate from the router.)
    • 3.2.A.2 A switch security policy will set forth a minimum configuration standard for switches on an organization’s network and may include:
      • Banning local user accounts (All switch logins must use an approved authentication server.)
      • Requiring port security to be enabled.
      • Using MAC filtering
    • 3.2.A.3 A virtual private network (VPN) policy will detail the minimum security requirements for employees using a VPN to access an organization’s internal network, and it may include:
      • A list of roles within the organization that are allowed to use a VPN to access the organization’s internal network
      • Authentication requirements for employees using a VPN (e.g., public/private key system or MFA)
      • A prohibition against split tunneling (also called dual tunneling)
    • 3.2.A.4 A wireless security policy will establish the minimum security requirements for wireless networks within an organization and may include:
      • Requiring users to authenticate to the wireless network through an extensible authentication protocol (EAP) connected to an approved authentication server
      • Requiring all wireless traffic to be encrypted using AES encryption with a minimum key length
      • Disabling beacon frames on wireless access points

    Learning Objective 3.2.B: Configure wireless network security features.

    • 3.2.B.1 Organizations can disable beacon frame broadcasting on wireless access points (WAPs) to make it harder for adversaries to find their wireless network and learn its basic properties.
    • 3.2.B.2 Organizations can control the broadcast direction and signal strength of a WAP so the signal does not extend beyond the physical space the access point is meant to cover.
    • 3.2.B.3 Organizations should enable strong wireless encryption protocols to ensure wireless frames are not readable by adversaries who might intercept them.
      • WEP, WPS, and the original WPA wireless encryption protocols have known vulnerabilities and are insecure.
      • WPA3 is currently the strongest wireless encryption algorithm.
    • 3.2.B.4 Organizations can enable MAC filtering to prevent unauthorized devices from accessing the network, and they can require users to authenticate when joining a network.
    Tiếng Việt

    Mục tiêu học tập 3.2.A: Xác định các kiểm soát quản trị liên quan đến an ninh mạng.

    • 3.2.A.1 Chính sách an ninh bộ định tuyến sẽ thiết lập tiêu chuẩn cấu hình tối thiểu cho các bộ định tuyến trong mạng của tổ chức và có thể bao gồm:
      • Cấm tài khoản người dùng cục bộ (Tất cả đăng nhập bộ định tuyến phải sử dụng máy chủ xác thực được phê duyệt.)
      • Tắt các dịch vụ không cần thiết (ví dụ: Telnet)
      • Yêu cầu có tường lửa (Một tổ chức có thể chọn thiết bị tường lửa riêng biệt với bộ định tuyến.)
    • 3.2.A.2 Chính sách an ninh bộ chuyển mạch sẽ thiết lập tiêu chuẩn cấu hình tối thiểu cho các bộ chuyển mạch trong mạng của tổ chức và có thể bao gồm:
      • Cấm tài khoản người dùng cục bộ (Tất cả đăng nhập bộ chuyển mạch phải sử dụng máy chủ xác thực được phê duyệt.)
      • Yêu cầu bật bảo mật cổng.
      • Sử dụng lọc MAC
    • 3.2.A.3 Chính sách mạng riêng ảo (VPN) sẽ chi tiết hóa các yêu cầu an ninh tối thiểu cho nhân viên sử dụng VPN để truy cập mạng nội bộ của tổ chức, và có thể bao gồm:
      • Danh sách các vai trò trong tổ chức được phép sử dụng VPN để truy cập mạng nội bộ của tổ chức
      • Yêu cầu xác thực cho nhân viên sử dụng VPN (ví dụ: hệ thống khóa công/khóa riêng tư hoặc MFA)
      • Cấm phân luồng (cũng gọi là song luồng)
    • 3.2.A.4 Chính sách an ninh không dây sẽ thiết lập các yêu cầu an ninh tối thiểu cho các mạng không dây trong tổ chức và có thể bao gồm:
      • Yêu cầu người dùng xác thực vào mạng không dây thông qua giao thức xác thực mở rộng (EAP) kết nối với máy chủ xác thực được phê duyệt
      • Yêu cầu tất cả lưu lượng không dây phải được mã hóa bằng mã hóa AES với độ dài khóa tối thiểu
      • Tắt tín hiệu beacon trên các điểm truy cập không dây

    Mục tiêu học tập 3.2.B: Cấu hình các tính năng an ninh mạng không dây.

    • 3.2.B.1 Các tổ chức có thể tắt phát sóng tín hiệu beacon trên các điểm truy cập không dây (WAP) để khiến kẻ tấn công khó tìm thấy mạng không dây của họ và hiểu rõ các thuộc tính cơ bản.
    • 3.2.B.2 Các tổ chức có thể điều khiển hướng phát sóng và cường độ tín hiệu của WAP để tín hiệu không lan rộng vượt quá không gian vật lý mà điểm truy cập dự định bao phủ.
    • 3.2.B.3 Các tổ chức nên bật các giao thức mã hóa không dây mạnh mẽ để đảm bảo các khung không dây không thể đọc được bởi những kẻ tấn công có thể chặn chúng.
      • Các giao thức mã hóa không dây WEP, WPS và WPA ban đầu có lỗ hổng đã biết và không an toàn.
      • WPA3 hiện là thuật toán mã hóa không dây mạnh nhất.
    • 3.2.B.4 Các tổ chức có thể bật lọc MAC để ngăn các thiết bị không được cấp phép truy cập mạng, và có thể yêu cầu người dùng xác thực khi tham gia mạng.

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    Good network security starts with written policies that set a minimum standard: a router security policy and switch security policy ban local accounts and require port security; a VPN policy sets authentication rules and forbids split tunneling 分离隧道; and a wireless security policy requires strong encryption and authenticated access.

    For wireless networks specifically, organisations disable beacon frames so the network is harder to find, control signal strength so it does not leak outside the building, enable strong encryption - WPA3 Wi-Fi 保护接入第三代 is the current strongest, while old WEP and the original WPA are broken - and use MAC filtering to allow only known devices.

    Vocabulary · ⁨Từ vựng⁩ Train · ⁨Luyện tập⁩
    English Tiếng Việt
    split tunneling/splɪt ˈtʌnəlɪŋ/ chia đường truyền
    WPA3/ˌdʌbljuː piː eɪ ˈθriː/ WPA3
    3.3

    Protecting Networks: Segmentation

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 3.3.A: Identify techniques for segmenting a network.

    • 3.3.A.1 Firewall zones and rules can be used to create a screened subnet (also known as a demilitarized zone, or DMZ)—a network segment that sits between public, external networks like the internet and internal, private networks. A screened subnet is typically a lower security zone than the internal, private networks, and it typically holds an organization’s publicly facing resources, separating them from the internal network.
    • 3.3.A.2 Subnetting can be used to create different subnets based on IP addressing. If a device is compromised by an adversary, subnets can contain a security breach to reduce the number of exposed devices.
    • 3.3.A.3 Switches can be used to create VLANs, which logically separate devices physically connected to central switches.

    Learning Objective 3.3.B: Explain why network segmentation can increase network security.

    • 3.3.B.1 Network segmentation refers to the process of dividing a network into smaller, isolated segments or subnetworks (subnets).
    • 3.3.B.2 Dividing a network into smaller subnets isolates network traffic, which can prevent attacks on one subnet from impacting devices on other subnets.
    • 3.3.B.3 Network segmentation can allow for different security policies and controls to be applied to different segments of the network, allowing for higher security zones and lower security zones.
    • 3.3.B.4 Port security on a switch can prevent MAC flooding by limiting the number of addresses assignable to any single switch port.
    Tiếng Việt

    Mục tiêu học tập 3.3.A: Xác định các kỹ thuật phân vùng mạng.

    • 3.3.A.1 Các vùng và quy tắc tường lửa có thể được sử dụng để tạo ra một mạng con được bảo vệ (còn gọi là khu vực phi quân sự, hay DMZ)—một phân đoạn mạng nằm giữa các mạng công cộng, bên ngoài như internet và các mạng nội bộ, riêng tư. Mạng con được bảo vệ thường là vùng an toàn thấp hơn so với các mạng nội bộ, riêng tư, và thường chứa các tài nguyên hướng tới công chúng của tổ chức, tách biệt chúng khỏi mạng nội bộ.
    • 3.3.A.2 Chia nhỏ mạng (subnetting) có thể được sử dụng để tạo ra các subnet khác nhau dựa trên địa chỉ IP. Nếu một thiết bị bị kẻ thù xâm phạm, các subnet có thể giới hạn vi phạm bảo mật vào một phạm vi cụ thể để giảm số lượng thiết bị bị lộ.
    • 3.3.A.3 Switches có thể được sử dụng để tạo VLANs, giúp tách biệt về mặt logic các thiết bị được kết nối vật lý với các switch trung tâm.

    Mục tiêu học tập 3.3.B: Giải thích tại sao việc phân chia mạng có thể tăng cường bảo mật mạng.

    • 3.3.B.1 Phân chia mạng đề cập đến quá trình chia một mạng thành các phân đoạn hoặc mạng con nhỏ hơn, cách ly lẫn nhau (subnets).
    • 3.3.B.2 Việc chia mạng thành các subnet nhỏ hơn sẽ cách ly lưu lượng mạng, có thể ngăn chặn các cuộc tấn công vào một subnet không ảnh hưởng đến các thiết bị trên các subnet khác.
    • 3.3.B.3 Phân chia mạng cho phép áp dụng các chính sách và biện pháp kiểm soát bảo mật khác nhau cho các phân đoạn mạng khác nhau, tạo điều kiện cho các vùng an toàn cao và vùng an toàn thấp.
    • 3.3.B.4 Bảo mật cổng trên switch có thể ngăn chặn hiện tượng tràn MAC bằng cách giới hạn số lượng địa chỉ có thể gán cho bất kỳ cổng switch đơn lẻ nào.

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    Network segmentation 网络分段 divides one network into smaller, isolated pieces (subnets 子网). If one subnet is breached, the damage is contained and cannot spread.

    A key pattern is the screened subnet 屏蔽子网 (also called a DMZ 隔离区). It sits between the public internet and the private internal network, holding an organisation's public-facing servers in a lower-security zone - separated from the sensitive internal systems.

    A screened subnet (DMZ) puts public servers between two firewalls, away from the private network
    A screened subnet (DMZ) puts public servers between two firewalls, away from the private network

    Segments can also be built with subnetting (by IP address) or VLANs 虚拟局域网 (logically separating devices on the same switch). Each segment can then get its own security policy - higher-security and lower-security zones.

    Server racks: network segmentation isolates systems so one breach does not open everything
    Server racks: network segmentation isolates systems so one breach does not open everything
    Vocabulary · ⁨Từ vựng⁩ Train · ⁨Luyện tập⁩
    English Tiếng Việt
    Network segmentation/ˈnetwɜːk ˌseɡmənˈteɪʃn/ Phân đoạn mạng
    subnets/ˈsʌbnets/ subnets
    screened subnet/skriːnd ˈsʌbnet/ phân khu màn hình
    DMZ/ˌdiː em ˈzed/ DMZ
    VLANs/ˈviːlænz/ VLANs
    3.4

    Protecting Networks: Firewalls

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 3.4.A: Identify types of network-based firewalls.

    • 3.4.A.1 A firewall is used to allow or deny network traffic in or out of a network. The firewall itself is software that can be hosted on a standalone device or integrated into another network device, such as a router.
    • 3.4.A.2 A stateless firewall filters traffic based on information in packet headers, such as IP addresses, ports, and protocols.
    • 3.4.A.3 A stateful firewall (also known as dynamic packet filtering) tracks the state of network connections passing through the firewall and can filter according to connection-related rules in addition to the filtering done by a stateless firewall. This allows for more control over content allowed in and out of a network.
    • 3.4.A.4 A next-generation firewall (NGFW) has both the capabilities of typical stateless and stateful firewalls and additional advanced features, such as intrusion prevention, deep packet inspection, and filtering by application type.

    Learning Objective 3.4.B: Explain how a firewall uses an access control list to allow or deny traffic entering or leaving a network.

    • 3.4.B.1 Network administrators create a set of rules, called an access control list (ACL), that a firewall uses to permit or deny inbound and outbound network traffic.
    • 3.4.B.2 ACL rules are checked in order and the first rule that matches the criteria will be executed for the specified data.
    • 3.4.B.3 A typical ACL will specify the direction of traffic (inbound or outbound), the criterion to filter by (IP addresses, logical port, service, or application), and the action to take (permit or deny).

    Learning Objective 3.4.C: Determine the effective placement of firewalls in a network.

    • 3.4.C.1 Each segment of a network should have a firewall to control the flow of data in and out of that segment.
    • 3.4.C.2 Network segments may have different security needs based on the data and services within them. The level of security for each firewall can be set independently.
    • 3.4.C.3 Each point of data ingress and egress between the internal network and the public internet should have a firewall.

    Learning Objective 3.4.D: Configure a firewall to manage the flow of network traffic.

    • 3.4.D.1 The requirements for a firewall will specify what type of traffic from which sources or to which destinations should be allowed or denied.
    • 3.4.D.2 Specific rules for a firewall can allow or deny inbound or outbound traffic based on source or destination port or IP address, service, protocol, or application.
      • Illustrative examples for 3.4.D.2:
        • Allow inbound TCP port 22 from ALL; (this rule will allow all inbound TCP traffic with destination port 22, which is the designated port for the SSH protocol)
        • Deny inbound TCP port 80 from 192.168.1.0/24; (this rule will deny inbound TCP traffic with destination port 80 from IP addresses in the 192.168.1.0-192.168.1.255 range)
    • 3.4.D.3 Rules are implemented in order, and changing the order of a set of rules can change which traffic is allowed or denied. Consideration must be given to the precedence of filtering priorities when establishing the order of rules.
      • Illustrative examples for 3.4.D.3:
        • This set of rules would allow SSH traffic and deny other inbound TCP traffic
        • Rule 1: ALLOW inbound TCP port 22 from ALL;
        • Rule 2: DENY inbound TCP ALL from ALL;
        • Reversing the order of those rules would deny all inbound TCP traffic including SSH traffic.
    Tiếng Việt

    Mục tiêu học tập 3.4.A: Xác định các loại tường lửa dựa trên mạng.

    • 3.4.A.1 Tường lửa được sử dụng để cho phép hoặc từ chối lưu lượng mạng đi vào hoặc ra khỏi mạng. Bản thân tường lửa là phần mềm có thể chạy trên một thiết bị độc lập hoặc tích hợp vào một thiết bị mạng khác, chẳng hạn như router.
    • 3.4.A.2 Tường lửa không trạng thái lọc lưu lượng dựa trên thông tin trong đầu gói tin, chẳng hạn như địa chỉ IP, cổng và giao thức.
    • 3.4.A.3 Tường lửa có trạng thái (còn gọi là lọc gói tin động) theo dõi trạng thái của các kết nối mạng đi qua tường lửa và có thể lọc theo các quy tắc liên quan đến kết nối ngoài việc lọc do tường lửa không trạng thái thực hiện. Điều này cho phép kiểm soát chặt chẽ hơn đối với nội dung được phép đi vào và ra khỏi mạng.
    • 3.4.A.4 Tường lửa thế hệ mới (NGFW) có cả khả năng của các tường lửa không trạng thái và có trạng thái thông thường cùng với các tính năng nâng cao bổ sung, chẳng hạn như ngăn chặn xâm nhập, kiểm tra gói tin sâu và lọc theo loại ứng dụng.

    Mục tiêu học tập 3.4.B: Giải thích cách tường lửa sử dụng danh sách kiểm soát truy cập để cho phép hoặc từ chối lưu lượng đi vào hoặc rời khỏi mạng.

    • 3.4.B.1 Quản trị viên mạng tạo ra một bộ quy tắc, được gọi là danh sách kiểm soát truy cập (ACL), mà tường lửa sử dụng để cho phép hoặc từ chối lưu lượng mạng đi vào và đi ra.
    • 3.4.B.2 Các quy tắc ACL được kiểm tra theo thứ tự và quy tắc đầu tiên khớp với tiêu chí sẽ được thực thi cho dữ liệu đã chỉ định.
    • 3.4.B.3 Một ACL điển hình sẽ chỉ định hướng lưu lượng (vào hoặc ra), tiêu chí để lọc theo (địa chỉ IP, cổng logic, dịch vụ hoặc ứng dụng), và hành động cần thực hiện (cho phép hoặc từ chối).

    Mục tiêu học tập 3.4.C: Xác định vị trí đặt hiệu quả của tường lửa trong mạng.

    • 3.4.C.1 Mỗi phân đoạn của mạng nên có một tường lửa để kiểm soát dòng chảy dữ liệu đi vào và ra khỏi phân đoạn đó.
    • 3.4.C.2 Các phân đoạn mạng có thể có nhu cầu bảo mật khác nhau dựa trên dữ liệu và dịch vụ bên trong chúng. Mức độ bảo mật cho từng tường lửa có thể được thiết lập độc lập.
    • 3.4.C.3 Mỗi điểm tiếp nhận và xuất dữ liệu giữa mạng nội bộ và internet công khai nên có một tường lửa.

    Mục tiêu học tập 3.4.D: Cấu hình tường lửa để quản lý dòng chảy lưu lượng mạng.

    • 3.4.D.1 Các yêu cầu cho tường lửa sẽ xác định loại lưu lượng nào từ nguồn nào hoặc đến đích nào nên được cho phép hoặc từ chối.
    • 3.4.D.2 Các quy tắc cụ thể cho tường lửa có thể cho phép hoặc từ chối lưu lượng đi vào hoặc đi ra dựa trên cổng nguồn hoặc đích, địa chỉ IP, dịch vụ, giao thức hoặc ứng dụng.
      • Ví dụ minh họa cho 3.4.D.2:
        • Cho phép TCP cổng 22 đi vào từ TẤT CẢ; (quy tắc này sẽ cho phép tất cả lưu lượng TCP đi vào với cổng đích là 22, đây là cổng được chỉ định cho giao thức SSH)
        • Từ chối TCP cổng 80 đi vào từ 192.168.1.0/24; (quy tắc này sẽ từ chối lưu lượng TCP đi vào với cổng đích là 80 từ các địa chỉ IP trong phạm vi 192.168.1.0-192.168.1.255)
    • 3.4.D.3 Các quy tắc được triển khai theo thứ tự, và thay đổi thứ tự của một bộ quy tắc có thể làm thay đổi lưu lượng nào được cho phép hoặc từ chối. Cần cân nhắc đến mức độ ưu tiên của các ưu tiên lọc khi thiết lập thứ tự các quy tắc.
      • Ví dụ minh họa cho 3.4.D.3:
        • Bộ quy tắc này sẽ cho phép lưu lượng SSH và từ chối các lưu lượng TCP đi vào khác
        • Quy tắc 1: CHO PHÉP TCP port 22 đi vào từ TẤT CẢ;
        • Quy tắc 2: TỪ CHỐI TCP ALL đi vào từ TẤT CẢ;
        • Đảo ngược thứ tự của các quy tắc đó sẽ từ chối tất cả lưu lượng TCP đi vào, bao gồm cả lưu lượng SSH.

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    How a firewall decides

    A firewall 防火墙 allows or denies traffic entering or leaving a network. There are several kinds:

    • Stateless 无状态 - filters on packet headers alone (IP, port, protocol).
    • Stateful 有状态 - also tracks the state of each connection for finer control.
    • Next-generation (NGFW) - adds advanced features like intrusion prevention and deep packet inspection.

    A firewall follows an access control list (ACL) 访问控制列表 - an ordered set of rules. Rules are checked in order, and the first match wins, so the order of rules changes which traffic gets through. Each rule specifies a direction, a thing to filter by (IP, port, service), and an action (permit or deny).

    A firewall checks its ACL top to bottom; the first matching rule decides
    A firewall checks its ACL top to bottom; the first matching rule decides

    Worked example. A firewall has Rule 3: DENY TCP 443 from 192.168.*, and lower down Rule 7: ALLOW TCP 443 from ALL. A user at 192.168.45.37 cannot reach port 443 - even though Rule 7 would allow them - because Rule 3 matches first, and the first match wins. The fix is to move the ALLOW rule above the DENY. This is why rule order, not just rule content, decides what traffic gets through.

    Firewalls belong at every point where data crosses between zones - at each network segment and at every gateway to the public internet.

    Rack-mounted network switches with many ethernet cables
    Real network hardware: a firewall is a device (or software) sitting where these cables meet the outside world
    Vocabulary · ⁨Từ vựng⁩ Train · ⁨Luyện tập⁩
    English Tiếng Việt
    firewall/ˈfaɪəwɔːl/ tường lửa
    Stateless/ˈsteɪtləs/ Không trạng thái
    Stateful/ˈsteɪtfl/ Có trạng thái
    access control list (ACL)/ˈækses kənˈtrəʊl lɪst/ danh sách kiểm soát truy cập (ACL)
    3.5

    Detecting Network Attacks

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 3.5.A: Identify types of automated security tools used to detect network attacks.

    • 3.5.A.1 Automated detection tools analyze data collected from an organization’s network and devices, such as switches and routers, servers, firewalls, and user computers. These data are often collected in a log file.
    • 3.5.A.2 A network intrusion detection system (NIDS) is an automated tool that analyzes data to determine if malicious activity is taking place on a network. When an attack is detected, it generates an alert.
    • 3.5.A.3 A network intrusion prevention system (NIPS) is an automated tool that, like an IDS, analyzes data to determine if malicious activity is taking place on a network. A NIPS can also mitigate or halt an attack by closing ports, blocking specific IP or MAC addresses, or rejecting specific protocols.
    • 3.5.A.4 A security information and event management (SIEM) system collects and analyzes data from multiple sources (including firewalls, NIDS/NIPS, device logs, and application logs) to detect patterns that may indicate a cyberattack and raises an alert if a potential attack is detected. Security analysts investigate the alert to determine whether it represents a true threat and follow standard operating procedures to resolve or escalate the alert.

    Learning Objective 3.5.B: Explain how organizations can leverage artificial intelligence (AI) to enhance threat detection and response.

    • 3.5.B.1 Computers log every action that users take. Firewalls, IDS, IPS, and other network sensors log all the traffic passing through various points in a network. A medium-sized organization’s network is logging millions (or even tens of millions) of data points per day. Even a large team of humans is incapable of analyzing so much data.
    • 3.5.B.2 Threat detection teams are creating AI algorithms to analyze large amounts of data and classify the data patterns as malicious or normal.
    • 3.5.B.3 AI models for threat detection are based on probabilistic calculations; they report a percentage to indicate the likelihood that something is malicious.
    • 3.5.B.4 Organizations determine their own thresholds for what percentage of likelihood of a threat results in an alert. If the threshold is set too high, real attacks may go undetected; if the threshold is too low, the security team will be overwhelmed with false alerts.

    Learning Objective 3.5.C: Determine a network detection method.

    • 3.5.C.1 Volume of network traffic is a criterion for determining a detection method. Signature-based detection is more efficient for networks with high traffic volume. Signature-based detection compares detection data to a database of known indicators of compromise (IoCs), called signatures. Signature databases must be updated with IoCs for the latest attacks. Signature-based detection runs more quickly than anomaly-based detection.
    • 3.5.C.2 Consistency of network traffic patterns is a criterion for determining a detection method. Anomaly-based detection is most effective on networks with consistent traffic patterns. Anomaly-based detection compares detection data to a baseline of recorded activity. Baselines must be recorded on uncompromised systems to establish expected data types and volumes. Anomaly-based detection triggers an alert or action when data types or volumes outside of a specified tolerance range are recorded. Anomaly-based detection relies on consistent patterns in network traffic to detect anomalous traffic patterns.
    • 3.5.C.3 Degree of sensitivity or criticality of a network is a criterion for determining a detection method. Networks with more sensitive or critical data or services will likely consider a hybrid approach. Hybrid detection combines signature-based and anomaly-based detection. Hybrid detection is more expensive than using either signature- or anomaly-based detection alone, and hybrid-detection models generate more alerts.
    • 3.5.C.4 Likelihood of novel attacks on a network is a criterion for determining a detection method. Signature-based detection cannot detect a new attack. When an organization suspects that adversaries are likely to attempt a new attack on a network, anomaly-based detection is the preferred method when the cost of hybrid detection is prohibitively high.

    Learning Objective 3.5.D: Evaluate the impact of a network detection method.

    • 3.5.D.1 Speed of detection is a factor in evaluating the impact of a network detection method. Faster detection enables faster response. Signature-based detection methods are faster than anomaly-based detection methods, especially on networks with high traffic volume.
    • 3.5.D.2 Cost is a factor in evaluating the impact of a network detection method. Detection tools and ongoing costs need to be within a budget. Anomaly-based detection systems require more expensive hardware to operate than signature based. Hybrid detection is the most expensive option because it combines both anomaly- and signature-based methods.
    • 3.5.D.3 False positive rate is a factor in evaluating the impact of a network detection method. Signature-based detection has almost no false positives. Anomaly-based or hybrid detection will have higher false positive rates. Impacts of high false positive rates include:
      • Time and resources are put toward investigating alerts for nonmalicious activity.
      • Alert fatigue is a condition that occurs when responders get accustomed to false positives and take alerts less seriously because they assume alerts are false positives before investigating them.
    • 3.5.D.4 False negative rate is a factor in evaluating the impact of a network detection method. A false negative occurs when an adversary can bypass a detection system. Signature-based detection systems are easier to bypass than anomaly-based or hybrid systems. False negatives can result in adversaries causing loss, harm, disruption, or destruction to data and systems.

    Learning Objective 3.5.E: Apply detection techniques to identify indicators of network attacks by analyzing log files.

    • 3.5.E.1 Evil-twin attacks can be detected by regularly scanning for service set identifiers (SSIDs) that look suspicious or similar to local legitimate SSIDs. Signal triangulation can be used to locate and disable an access point broadcasting an evil-twin network.
    • 3.5.E.2 Jamming attacks can be detected by recognizing that no wireless devices in a specific physical space are able to connect to a wireless network and by scanning for electromagnetic (EM) noise in the wireless range.
    • 3.5.E.3 ARP poisoning attacks can be detected by monitoring network traffic for unusual ARP messages (particularly duplicate MAC address ARP packets) and checking the ARP table on the default gateway.
    • 3.5.E.4 MAC flooding attacks can be detected by monitoring network traffic for an unexpected surge of Ethernet frames with different MAC addresses and checking the MAC address table on a switch.
    • 3.5.E.5 DNS poisoning attacks are difficult to detect. However, if an organization’s website experiences an abrupt and otherwise inexplicable drop in traffic, DNS records should be examined as a potential cause.
    • 3.5.E.6 Smurf attacks can be detected by watching network traffic for a sudden increase in ICMP requests sent to the network’s broadcast address.
    • 3.5.E.7 Network-based IoCs are discovered when analyzing network traffic, often in the form of packet capture files. Indicators can be found in source and destination IP addresses, ports, and protocols. These can include:
      • Connections to known malicious IP addresses
      • Unauthorized network scans
      • Unusual spikes or slow downs in network traffic
      • Mismatched port-application traffic
    Tiếng Việt

    Mục tiêu học tập 3.5.A: Xác định các loại công cụ bảo mật tự động được sử dụng để phát hiện cuộc tấn công mạng.

    • 3.5.A.1 Các công cụ phát hiện tự động phân tích dữ liệu thu thập được từ mạng và thiết bị của tổ chức, chẳng hạn như switch và router, máy chủ, tường lửa và máy tính người dùng. Dữ liệu này thường được thu thập trong một tệp nhật ký.
    • 3.5.A.2 Hệ thống phát hiện xâm nhập mạng (NIDS) là một công cụ tự động phân tích dữ liệu để xác định xem hoạt động độc hại đang diễn ra trên mạng hay không. Khi phát hiện cuộc tấn công, nó sẽ tạo ra cảnh báo.
    • 3.5.A.3 Hệ thống ngăn chặn xâm nhập mạng (NIPS) là công cụ tự động, tương tự như IDS, phân tích dữ liệu để xác định xem có hoạt động độc hại nào đang diễn ra trên mạng hay không. NIPS cũng có thể giảm thiểu hoặc dừng cuộc tấn công bằng cách đóng các cổng, chặn địa chỉ IP hoặc MAC cụ thể, hoặc từ chối các giao thức nhất định.
    • 3.5.A.4 Hệ thống quản lý thông tin và sự kiện bảo mật (SIEM) thu thập và phân tích dữ liệu từ nhiều nguồn (bao gồm tường lửa, NIDS/NIPS, nhật ký thiết bị và nhật ký ứng dụng) để phát hiện các mẫu hình có thể chỉ ra cuộc tấn công mạng và cảnh báo nếu phát hiện cuộc tấn công tiềm ẩn. Các nhà phân tích bảo mật điều tra cảnh báo để xác định xem đó có phải là mối đe dọa thực sự hay không và tuân theo quy trình vận hành tiêu chuẩn để giải quyết hoặc chuyển cấp cảnh báo.

    Mục tiêu học tập 3.5.B: Giải thích cách các tổ chức có thể tận dụng trí tuệ nhân tạo (AI) để nâng cao khả năng phát hiện và phản ứng với mối đe dọa.

    • 3.5.B.1 Máy tính ghi lại mọi hành động mà người dùng thực hiện. Tường lửa, IDS, IPS và các cảm biến mạng khác ghi lại toàn bộ lưu lượng đi qua các điểm khác nhau trong mạng. Mạng của một tổ chức vừa ghi lại hàng triệu (hoặc thậm chí hàng chục triệu) điểm dữ liệu mỗi ngày. Ngay cả một đội ngũ nhân viên lớn cũng không đủ sức phân tích khối lượng dữ liệu khổng lồ như vậy.
    • 3.5.B.2 Các nhóm phát hiện mối đe dọa đang xây dựng các thuật toán AI để phân tích số lượng lớn dữ liệu và phân loại các mẫu dữ liệu là độc hại hoặc bình thường.
    • 3.5.B.3 Mô hình AI cho phát hiện mối đe dọa dựa trên các phép tính xác suất; chúng báo cáo tỷ lệ phần trăm để chỉ mức độ khả năng một hành vi là độc hại.
    • 3.5.B.4 Các tổ chức tự xác định ngưỡng của mình đối với tỷ lệ phần trăm khả năng tồn tại mối đe dọa sẽ kích hoạt cảnh báo. Nếu ngưỡng được đặt quá cao, các cuộc tấn công thực tế có thể bị bỏ sót; nếu ngưỡng quá thấp, đội ngũ an ninh sẽ bị quá tải bởi các cảnh báo giả.

    Mục tiêu học tập 3.5.C: Xác định phương pháp phát hiện mạng.

    • 3.5.C.1 Lưu lượng mạng là tiêu chí để xác định phương pháp phát hiện. Phát hiện dựa trên chữ ký hiệu quả hơn đối với các mạng có lưu lượng cao. Phát hiện dựa trên chữ ký so sánh dữ liệu phát hiện với cơ sở dữ liệu các dấu hiệu đã biết về sự xâm phạm (IoCs), được gọi là chữ ký. Cơ sở dữ liệu chữ ký phải được cập nhật với IoCs cho các cuộc tấn công mới nhất. Phát hiện dựa trên chữ ký chạy nhanh hơn phát hiện dựa trên bất thường.
    • 3.5.C.2 Tính nhất quán của các mẫu lưu lượng mạng là tiêu chí để xác định phương pháp phát hiện. Phát hiện dựa trên bất thường hiệu quả nhất trên các mạng có lưu lượng ổn định. Phát hiện dựa trên bất thường so sánh dữ liệu phát hiện với đường nền của các hoạt động đã được ghi lại. Đường nền phải được ghi lại trên các hệ thống chưa bị xâm phạm để xác định các loại và khối lượng dữ liệu mong đợi. Phát hiện dựa trên bất thường kích hoạt cảnh báo hoặc hành động khi ghi nhận các loại hoặc khối lượng dữ liệu nằm ngoài phạm vi dung sai quy định. Phát hiện dựa trên bất thường dựa vào các mẫu ổn định trong lưu lượng mạng để phát hiện các mẫu lưu lượng bất thường.
    • 3.5.C.3 Mức độ nhạy cảm hoặc tính quan trọng của mạng là tiêu chí để xác định phương pháp phát hiện. Các mạng chứa dữ liệu hoặc dịch vụ nhạy cảm hoặc quan trọng hơn có khả năng sẽ áp dụng phương pháp lai. Phát hiện lai kết hợp phát hiện dựa trên chữ ký và phát hiện dựa trên bất thường. Phát hiện lai tốn kém hơn so với việc sử dụng riêng lẻ phát hiện dựa trên chữ ký hoặc bất thường, và mô hình phát hiện lai tạo ra nhiều cảnh báo hơn.
    • 3.5.C.4 Khả năng xảy ra các cuộc tấn công mới lạ trên mạng là tiêu chí để xác định phương pháp phát hiện. Phát hiện dựa trên chữ ký không thể phát hiện một cuộc tấn công mới. Khi một tổ chức nghi ngờ rằng kẻ thù có khả năng sẽ thử nghiệm một cuộc tấn công mới lên mạng, phát hiện dựa trên bất thường là phương pháp được ưu tiên khi chi phí của phát hiện lai là quá cao.

    Mục tiêu học tập 3.5.D: Đánh giá tác động của phương pháp phát hiện mạng.

    • 3.5.D.1 Tốc độ phát hiện là yếu tố trong việc đánh giá tác động của phương pháp phát hiện mạng. Phát hiện nhanh hơn giúp phản ứng nhanh hơn. Các phương pháp phát hiện dựa trên chữ ký nhanh hơn các phương pháp phát hiện dựa trên bất thường, đặc biệt là trên các mạng có lưu lượng cao.
    • 3.5.D.2 Chi phí là yếu tố trong việc đánh giá tác động của phương pháp phát hiện mạng. Công cụ phát hiện và chi phí duy trì cần nằm trong ngân sách. Hệ thống phát hiện dựa trên bất thường yêu cầu phần cứng đắt đỏ hơn để vận hành so với phát hiện dựa trên chữ ký. Phát hiện lai là tùy chọn tốn kém nhất vì nó kết hợp cả hai phương pháp dựa trên bất thường và chữ ký.
    • 3.5.D.3 Tỷ lệ cảnh báo giả là yếu tố trong việc đánh giá tác động của phương pháp phát hiện mạng. Phát hiện dựa trên chữ ký gần như không có cảnh báo giả. Phát hiện dựa trên bất thường hoặc phát hiện lai sẽ có tỷ lệ cảnh báo giả cao hơn. Tác động của tỷ lệ cảnh báo giả cao bao gồm:
      • Thời gian và nguồn lực bị dành để điều tra các cảnh báo do hoạt động không độc hại gây ra.
      • Mệt mỏi cảnh báo là tình trạng xảy ra khi những người phản ứng quen với các cảnh báo giả và coi nhẹ cảnh báo hơn vì họ cho rằng cảnh báo là cảnh báo giả trước khi điều tra.
    • 3.5.D.4 Tỷ lệ cảnh báo âm là yếu tố trong việc đánh giá tác động của phương pháp phát hiện mạng. Cảnh báo âm xảy ra khi kẻ thù có thể vượt qua hệ thống phát hiện. Hệ thống phát hiện dựa trên chữ ký dễ bị vượt qua hơn so với các hệ thống dựa trên bất thường hoặc lai. Cảnh báo âm có thể dẫn đến việc kẻ thù gây ra thiệt hại, tổn thất, gián đoạn hoặc phá hủy dữ liệu và hệ thống.

    Mục tiêu học tập 3.5.E: Áp dụng các kỹ thuật phát hiện để xác định các chỉ số của cuộc tấn công mạng bằng cách phân tích tệp nhật ký.

    • 3.5.E.1 Các cuộc tấn công Evil-twin có thể được phát hiện bằng cách quét thường xuyên các định danh dịch vụ (SSIDs) trông đáng ngờ hoặc tương tự với SSIDs hợp lệ địa phương. Tam giác hóa tín hiệu có thể được sử dụng để xác định vị trí và vô hiệu hóa một điểm truy cập đang phát sóng mạng Evil-twin.
    • 3.5.E.2 Các cuộc tấn công gây nhiễu (Jamming) có thể được phát hiện bằng cách nhận ra rằng không có thiết bị không dây nào trong một không gian vật lý cụ thể nào đó có thể kết nối đến mạng không dây và bằng cách quét tiếng ồn điện từ (EM) trong phạm vi không dây.
    • 3.5.E.3 Các cuộc tấn công đầu độc ARP có thể được phát hiện bằng cách theo dõi lưu lượng mạng để tìm các tin nhắn ARP bất thường (đặc biệt là gói ARP có địa chỉ MAC trùng lặp) và kiểm tra bảng ARP trên bộ định tuyến mặc định.
    • 3.5.E.4 Các cuộc tấn công tràn ngập MAC (MAC flooding) có thể được phát hiện bằng cách theo dõi lưu lượng mạng để tìm sự gia tăng đột biến của các khung Ethernet với các địa chỉ MAC khác nhau và kiểm tra bảng địa chỉ MAC trên một bộ chuyển mạch (switch).
    • 3.5.E.5 Các cuộc tấn công đầu độc DNS rất khó phát hiện. Tuy nhiên, nếu trang web của một tổ chức gặp phải sự sụt giảm lưu lượng đột ngột và không giải thích được, các bản ghi DNS nên được xem xét như một nguyên nhân tiềm ẩn.
    • 3.5.E.6 Các cuộc tấn công Smurf có thể được phát hiện bằng cách theo dõi lưu lượng mạng để tìm sự gia tăng đột biến của các yêu cầu ICMP được gửi đến địa chỉ broadcast của mạng.
    • 3.5.E.7 Các IoC dựa trên mạng được khám phá khi phân tích lưu lượng mạng, thường dưới dạng tệp bắt gói (packet capture files). Chỉ báo có thể được tìm thấy trong địa chỉ IP nguồn và đích, cổng và giao thức. Những thứ này có thể bao gồm:
      • Kết nối đến các địa chỉ IP độc hại đã biết
      • Quét mạng trái phép
      • Sự gia tăng đột biến hoặc suy giảm bất thường trong lưu lượng mạng
      • Lưu lượng không khớp giữa cổng và ứng dụng

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    When prevention fails, detection takes over. Automated tools read the log files 日志文件 that record network activity:

    • a network intrusion detection system (NIDS) 网络入侵检测系统 analyses traffic and raises an alert, but does not block;
    • a network intrusion prevention system (NIPS) 网络入侵防御系统 can also stop an attack by closing ports or blocking addresses;
    • a security information and event management (SIEM) 安全信息与事件管理 system gathers data from many sources to spot patterns.

    There are two detection methods. Signature-based 基于特征 detection compares traffic to a database of known attack signatures - fast and low on false alarms, but blind to brand-new attacks. Anomaly-based 基于异常 detection compares traffic to a normal baseline 基线 and flags anything unusual - it can catch novel attacks but needs more resources and raises more false alarms. A hybrid approach combines both.

    Examining captured traffic (packet-capture files), analysts hunt for network-based indicators of compromise 网络入侵指标 in the source and destination IP addresses, ports, and protocols. Four common ones: connections to known-malicious IP addresses, unauthorized network scans (an outsider probing your ports), unusual spikes or slowdowns in traffic, and mismatched port-application traffic (for example, non-web traffic flowing over port 80). These complete the host-, file-, and behaviour-based indicators a single device logs.

    AI, thresholds, and alert fatigue

    A medium network logs millions of events a day - far more than any team can read - so organisations train AI models to sort likely-malicious patterns from normal ones. These models are probabilistic 概率的: rather than a yes/no, each event gets a percentage likelihood of being malicious.

    The organisation then sets a threshold 阈值 - the likelihood at which an alert fires - and that choice is a genuine trade-off:

    • set the threshold too high and real attacks slip through undetected;
    • set it too low and the team is overwhelmed with false alerts.

    Too many false alerts cause alert fatigue 警报疲劳: responders get so used to false positives that they start assuming an alert is false before investigating it - so a real attack, when it finally comes, is waved away. This is exactly why a low false-positive rate matters: signature-based detection has almost none, while anomaly-based and hybrid detection trade a higher false-positive rate for the ability to catch novel attacks.

    Signature-based detection matches known attacks; anomaly-based detection flags deviations from normal
    Signature-based detection matches known attacks; anomaly-based detection flags deviations from normal
    Vocabulary · ⁨Từ vựng⁩ Train · ⁨Luyện tập⁩
    English Tiếng Việt
    log files/lɒɡ faɪlz/ tập tin nhật ký
    network intrusion detection system (NIDS)/ˈnetwɜːk ɪnˈtruːʒn dɪˈtekʃn ˈsɪstəm/ hệ thống phát hiện xâm nhập mạng (NIDS)
    network intrusion prevention system (NIPS)/ˈnetwɜːk ɪnˈtruːʒn prɪˈvenʃn ˈsɪstəm/ hệ thống ngăn chặn xâm nhập mạng (NIPS)
    security information and event management (SIEM)/sɪˈkjʊərɪti ˌɪnfəˈmeɪʃn ænd ɪˈvent ˈmænɪdʒmənt/ quản lý thông tin và sự kiện an ninh (SIEM)
    Signature-based/ˈsɪɡnɪtʃə beɪst/ Dựa trên chữ ký
    Anomaly-based/əˈnɒməli beɪst/ Dựa trên bất thường
    baseline/ˈbeɪslaɪn/ baseline
    network-based indicators of compromise/ˈnetwɜːk beɪst ˈɪndɪkeɪtəz ɒv ˈkɒmprəmaɪz/ chỉ báo xâm nhập dựa trên mạng
    probabilistic/ˌprɒbəbɪˈlɪstɪk/ xác suất
    threshold/ˈθreʃəʊld/ ngưỡng
    alert fatigue/əˈlɜːt fəˈtiːɡ/ kiệt sức cảnh báo
    3.5

    Exam tips

    • For firewall-ACL questions, read the rules top-to-bottom and stop at the first match - a Deny rule above an Allow blocks the traffic even though the Allow exists lower down.
    • Pair each attack with its tell-tale sign: ARP poisoning = one IP with two MAC addresses; MAC flooding = a surge of new MAC addresses; DNS poisoning = an unexplained drop in web traffic.
    • Read packet captures for network-based IoCs: known-malicious IPs, unauthorized scans, traffic spikes/slowdowns, and mismatched port-application traffic.
    • Run vulnerability scanners to find known weaknesses proactively, and fix the highest-severity findings first.
    • Signature-based = fast, few false positives, misses new attacks (more false negatives); anomaly-based = catches new attacks, costs more, more false positives. Memorise this trade-off.
    • A screened subnet / DMZ holds public-facing servers between the internet and the private network - name it whenever a question separates public services from internal data.
    • WPA3 is the strong wireless encryption; WEP and original WPA are insecure.
  • 4

    Securing Devices · ⁨Bảo vệ Thiết bị⁩

    Watch lesson · ⁨Xem bài học⁩
    4.1

    Device Vulnerabilities and Attacks

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 4.1.A: Identify types of computing devices.

    • 4.1.A.1 Server computers are devices that provide one or more services to other computers (e.g., DNS, DHCP, FTP). Any computer can be a server, and in an enterprise environment servers typically have more processing power and storage than a personal computer.
    • 4.1.A.2 Personal computers are devices that are designed to be used by one person for work or recreational purposes (e.g., word processing, graphic design, web browsing, and media production or viewing). These include desktop, laptop, and notebook computers.
    • 4.1.A.3 Handheld computers (also called mobile computers or information appliances) are smaller than personal computers and run on battery power. These include tablets, smartphones, and wearable technology like smart watches.
    • 4.1.A.4 Embedded computers are devices that are part of a machine. Embedded devices have specific instruction sets for interfacing with the specialized components of the machine they’re embedded in. Embedded computers tend to be slower and cheaper than other computers and have minimal storage.
    • 4.1.A.5 Everyday devices with embedded computers are often called Internet of Things (IoT) devices. Embedded computers are found in transportation (e.g., cars, trains, and airplanes), devices that operate critical infrastructure (e.g., operating circuit breakers at electrical substations and pumps at water treatment plants), medical equipment (e.g., IV pumps, MRI scanners, pacemakers, and insulin pumps), and everyday devices like washing machines, coffee makers, and thermostats.

    Learning Objective 4.1.B: Identify the type of malware used in a cyberattack.

    • 4.1.B.1 Malware is malicious software that can damage or destroy a device or network, or allow an adversary access to a device and the data on the device.
    • 4.1.B.2 Malware is often used as a tool to accomplish part of an adversary’s plan to achieve their ultimate goal(s). There are many types of malware, such as:
      • Viruses are malware that must be activated by a user executing or opening a file.
      • Worms spread from one computer to another without human interaction.
      • Trojans are malware embedded in other software that seems harmless. Remote access trojans (RATs) provide an adversary with remote access to the target system.
      • Ransomware encrypts a device’s files, preventing the user from accessing files on the device. The ransomware typically presents the user with a screen demanding payment and promising to give the user a decryption key for their files if the user pays within a fixed amount of time.
      • Spyware tracks a user’s actions on a computer and sends information back to an adversary.
      • A keylogger is software or hardware that logs the users keystrokes and sends the information back to the adversary. Adversaries can often extract usernames and passwords from keylogger data.
      • Logic bombs are set to trigger their effect only when a specific set of conditions are met; the conditions can include time and date, specific type or version of the operating system, character set the computer is using, etc.
      • A rootkit is sophisticated malware that gets into the target computer’s operating system and can control nearly every aspect of the system, including making the rootkit itself invisible to detection.
    • 4.1.B.3 While most malware is a file or a collection of files, fileless malware is malicious code that lives in RAM and uses legitimate programs already installed on a device to compromise it.

    Learning Objective 4.1.C: Explain how adversaries can exploit common device vulnerabilities to cause loss, damage, disruption, or destruction.

    • 4.1.C.1 Adversaries can develop exploits for known vulnerabilities in software (including operating systems). Devices with unpatched software are vulnerable to these exploits, which could allow an adversary to crash a system, view user actions, enable or disable various services or components on the device (e.g., turning on a webcam or microphone), or even take control of the device to issue their own commands including commands to steal or destroy information on the device.
    • 4.1.C.2 Adversaries can take advantage of weak authentication requirements by guessing a user’s password or using social engineering to get a user to divulge their password.
    • 4.1.C.3 When systems don’t have a password on the basic input output system (BIOS) or unified extensible firmware interface (UEFI), an adversary can boot a computer into a special mode (e.g., “recovery mode”) that gives them higher-level privileges. Without BIOS or UEFI protection, adversaries can load their own operating system onto a device from an external drive and use specialized tools to alter or create user profiles, including changing user passwords.
    • 4.1.C.4 Adversaries can load malware onto an external drive, and if autorun is enabled, then a device will run the malware when the external drive is inserted.
    • 4.1.C.5 Adversaries can leverage open ports to connect to a device.
    • 4.1.C.6 Adversaries can send malicious data to devices to disrupt them or attempt to take control of them. Devices that have no firewall (or a misconfigured firewall) cannot filter out this malicious data.
    • 4.1.C.7 Adversaries often attempt to install malware on a device to disrupt or control it. Devices lacking anti-malware software are more vulnerable to this type of attack.

    Learning Objective 4.1.D: Assess and document risks from device vulnerabilities.

    • 4.1.D.1 Risk from device vulnerabilities can come from unauthorized access or malware that allow an adversary to impersonate an authorized user, remotely control a device, encrypt a device’s drive to ransom the data, or wipe a device’s memory, destroying data or rendering the device inoperable. The level of risk varies depending on the criticality of the device or the services the device provides or data it stores.
    • 4.1.D.2 High risks from device vulnerabilities involve potentially compromising sensitive data or critical operations.
      • Illustrative examples for 4.1.D.2:
        • An organization has not installed the most recent update for their email server which included a patch for a known critical vulnerability.
    • 4.1.D.3 Moderate risks from device vulnerabilities can arise from weak authentication requirements or from vulnerabilities that would be less likely to be exploited.
      • Illustrative examples for 4.1.D.3:
        • A water treatment plant has embedded systems controlling pumps. The pumps can be remotely accessed via username and password for remote management for the plant, but the devices do not require multi-factor authentication (MFA).
    • 4.1.D.4 Low risks from device vulnerabilities are typically related to vulnerabilities that, if exploited, would have little impact.
      • Illustrative examples for 4.1.D.4:
        • An employee’s laptop has telnet port 23 open.
    Tiếng Việt

    Mục tiêu Học tập 4.1.A: Xác định các loại thiết bị tính toán.

    • 4.1.A.1 Máy chủ máy tính là các thiết bị cung cấp một hoặc nhiều dịch vụ cho các máy tính khác (ví dụ: DNS, DHCP, FTP). Bất kỳ máy tính nào cũng có thể là máy chủ, và trong môi trường doanh nghiệp, máy chủ thường có sức mạnh xử lý và dung lượng lưu trữ lớn hơn so với máy tính cá nhân.
    • 4.1.A.2 Máy tính cá nhân là các thiết bị được thiết kế để một người sử dụng cho mục đích làm việc hoặc giải trí (ví dụ: xử lý văn bản, thiết kế đồ họa, duyệt web, và sản xuất hoặc xem phương tiện). Bao gồm máy tính bàn, laptop và notebook.
    • 4.1.A.3 Máy tính cầm tay (còn gọi là máy tính di động hoặc thiết bị thông tin) nhỏ hơn máy tính cá nhân và chạy bằng pin. Bao gồm máy tính bảng, điện thoại thông minh và công nghệ đeo như đồng hồ thông minh.
    • 4.1.A.4 Máy tính nhúng là các thiết bị là một phần của một cỗ máy. Các thiết bị nhúng có các bộ lệnh đặc biệt để giao tiếp với các thành phần chuyên dụng của cỗ máy mà chúng được nhúng vào. Máy tính nhúng thường chậm hơn và rẻ hơn so với các máy tính khác và có dung lượng lưu trữ tối thiểu.
    • 4.1.A.5 Các thiết bị hàng ngày có máy tính nhúng thường được gọi là thiết bị Internet of Things (IoT). Máy tính nhúng được tìm thấy trong giao thông vận tải (ví dụ: ô tô, tàu hỏa và máy bay), các thiết bị vận hành cơ sở hạ tầng quan trọng (ví dụ: vận hành cầu dao tại trạm biến áp và bơm tại nhà máy xử lý nước), thiết bị y tế (ví dụ: bơm truyền dịch, máy cộng hưởng từ MRI, máy tạo nhịp tim và bơm insulin), và các thiết bị hàng ngày như máy giặt, máy pha cà phê và bộ điều nhiệt.

    Mục tiêu Học tập 4.1.B: Xác định loại mã độc được sử dụng trong cuộc tấn công an ninh mạng.

    • 4.1.B.1 Mã độc (Malware) là phần mềm độc hại có thể gây hư hỏng hoặc phá hủy thiết bị hoặc mạng, hoặc cho phép kẻ thù truy cập vào thiết bị và dữ liệu trên thiết bị đó.
    • 4.1.B.2 Mã độc thường được sử dụng như một công cụ để thực hiện một phần kế hoạch của kẻ thù nhằm đạt được mục tiêu cuối cùng của chúng. Có nhiều loại mã độc, chẳng hạn như:
      • Virus là mã độc phải được kích hoạt bởi người dùng thực thi hoặc mở một tệp.
      • Sâu (Worms) lây lan từ máy tính này sang máy tính khác mà không cần tương tác của con người.
      • Trojan là mã độc được nhúng trong phần mềm khác trông có vẻ vô hại. Trojan truy cập từ xa (RATs) cung cấp quyền truy cập từ xa cho kẻ thù vào hệ thống mục tiêu.
      • Ransomware mã hóa các tệp của thiết bị, ngăn người dùng truy cập vào các tệp trên thiết bị. Ransomware thường hiển thị màn hình yêu cầu tiền chuộc và hứa sẽ cung cấp khóa giải mã cho các tệp của người dùng nếu người dùng thanh toán trong một khoảng thời gian cố định.
      • Spyware theo dõi các hành động của người dùng trên máy tính và gửi thông tin trở lại cho kẻ thù.
      • Keylogger là phần mềm hoặc phần cứng ghi lại các phím bấm của người dùng và gửi thông tin trở lại cho kẻ thù. Kẻ thù thường có thể trích xuất tên đăng nhập và mật khẩu từ dữ liệu keylogger.
      • Bomb logic (Logic bombs) được cài đặt để kích hoạt tác dụng chỉ khi một tập hợp các điều kiện cụ thể được đáp ứng; các điều kiện có thể bao gồm thời gian và ngày tháng, loại hoặc phiên bản hệ điều hành cụ thể, bộ ký tự mà máy tính đang sử dụng, v.v.
      • Rootkit là mã độc tinh vi xâm nhập vào hệ điều hành của máy tính mục tiêu và có thể kiểm soát hầu hết mọi khía cạnh của hệ thống, bao gồm cả việc làm cho chính rootkit trở nên vô hình đối với việc phát hiện.
    • 4.1.B.3 Mặc dù hầu hết mã độc là một tệp hoặc một tập hợp các tệp, nhưng mã độc không có tệp (fileless malware) là mã độc hại tồn tại trong RAM và sử dụng các chương trình hợp lệ đã được cài đặt sẵn trên thiết bị để làm giả mạo nó.

    Mục tiêu Học tập 4.1.C: Giải thích cách kẻ thù có thể khai thác các lỗ hổng thiết bị phổ biến để gây ra thiệt hại, tổn thất, gián đoạn hoặc phá hủy.

    • 4.1.C.1 Kẻ thù có thể phát triển các công cụ khai thác cho các lỗ hổng đã biết trong phần mềm (bao gồm cả hệ điều hành). Các thiết bị có phần mềm chưa được vá lỗi sẽ dễ bị tổn thương trước các công cụ này, cho phép kẻ thù làm sập hệ thống, xem xét hành vi của người dùng, bật hoặc tắt các dịch vụ hoặc thành phần khác nhau trên thiết bị (ví dụ: bật webcam hoặc micro), hoặc thậm chí chiếm quyền kiểm soát thiết bị để ra lệnh trộm cắp hoặc phá hủy thông tin trên thiết bị.
    • 4.1.C.2 Kẻ thù có thể lợi dụng yêu cầu xác thực yếu bằng cách đoán mật khẩu của người dùng hoặc sử dụng kỹ thuật xã hội học để khiến người dùng tiết lộ mật khẩu của họ.
    • 4.1.C.3 Khi hệ thống không có mật khẩu ở hệ thống nhập xuất cơ bản (BIOS) hoặc giao diện firmware mở rộng nhất quán (UEFI), kẻ thù có thể khởi động máy tính vào chế độ đặc biệt (ví dụ: "chế độ phục hồi") mang lại cho chúng quyền hạn cao hơn. Không có bảo vệ BIOS hay UEFI, kẻ thù có thể tải hệ điều hành riêng lên thiết bị từ ổ đĩa ngoài và sử dụng các công cụ chuyên dụng để thay đổi hoặc tạo hồ sơ người dùng, bao gồm thay đổi mật khẩu người dùng.
    • 4.1.C.4 Kẻ thù có thể tải mã độc lên ổ đĩa ngoài, và nếu chức năng chạy tự động được bật, thì thiết bị sẽ chạy mã độc khi ổ đĩa ngoài được cắm vào.
    • 4.1.C.5 Kẻ thù có thể tận dụng các cổng mở để kết nối với thiết bị.
    • 4.1.C.6 Kẻ thù có thể gửi dữ liệu độc hại đến các thiết bị để làm gián đoạn chúng hoặc cố gắng chiếm quyền kiểm soát. Các thiết bị không có tường lửa (hoặc tường lửa được cấu hình sai) không thể lọc bỏ dữ liệu độc hại này.
    • 4.1.C.7 Kẻ thù thường cố gắng cài đặt mã độc lên thiết bị để làm gián đoạn hoặc kiểm soát nó. Các thiết bị thiếu phần mềm chống mã độc sẽ dễ bị tổn thương hơn trước loại tấn công này.

    Mục tiêu Học tập 4.1.D: Đánh giá và ghi chép các rủi ro từ các lỗ hổng thiết bị.

    • 4.1.D.1 Rủi ro từ các lỗ hổng thiết bị có thể đến từ truy cập trái phép hoặc mã độc cho phép kẻ thù giả mạo một người dùng được ủy quyền, điều khiển từ xa một thiết bị, mã hóa ổ đĩa của thiết bị để đòi tiền chuộc dữ liệu, hoặc xóa bộ nhớ thiết bị, phá hủy dữ liệu hoặc khiến thiết bị không hoạt động. Mức độ rủi ro thay đổi tùy thuộc vào mức độ quan trọng của thiết bị, các dịch vụ mà thiết bị cung cấp hoặc dữ liệu mà nó lưu trữ.
    • 4.1.D.2 Rủi ro cao từ các lỗ hổng thiết bị liên quan đến khả năng bị đánh cắp dữ liệu nhạy cảm hoặc các hoạt động then chốt.
      • Ví dụ minh họa cho 4.1.D.2:
        • Một tổ chức chưa cập nhật phiên bản mới nhất cho máy chủ email của mình, phiên bản đó bao gồm bản vá cho một lỗ hổng nghiêm trọng đã được biết đến.
    • 4.1.D.3 Rủi ro trung bình từ các lỗ hổng thiết bị có thể nảy sinh từ các yêu cầu xác thực yếu hoặc từ các lỗ hổng ít có khả năng bị khai thác hơn.
      • Ví dụ minh họa cho 4.1.D.3:
        • Một nhà máy xử lý nước có các hệ thống nhúng điều khiển bơm. Các bơm có thể được truy cập từ xa qua tên người dùng và mật khẩu để quản lý từ xa cho nhà máy, nhưng các thiết bị không yêu cầu xác thực đa yếu tố (MFA).
    • 4.1.D.4 Rủi ro thấp từ các lỗ hổng thiết bị thường liên quan đến các lỗ hổng mà nếu bị khai thác sẽ có ít tác động.
      • Ví dụ minh họa cho 4.1.D.4:
        • Laptop của nhân viên có cổng telnet 23 đang mở.

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    A device is any computer - a server, a personal laptop, a smartphone, or an embedded computer 嵌入式计算机 built into a machine. Everyday devices with embedded computers are called Internet of Things (IoT) 物联网 devices, and they run everything from water pumps to washing machines.

    The four classes of device, and why the class matters

    Class What it is Security consequence
    servers shared machines running services for many users the highest-value target; one compromise reaches everyone
    personal computers desktops and laptops general purpose, so they run anything the user installs
    handheld computers 手持计算机 (also called mobile computers or information appliances) smaller than a PC and running on battery power — smartphones, tablets, smart watches and other wearable technology easily lost or stolen, and often carried across untrusted networks
    embedded computers a computer that is part of a machine — a car's engine controller, a thermostat, a medical pump has a specialised instruction set for interfacing with its components, and tends to be slower, cheaper and to have minimal storage, so security features are often left out and updates are rare

    That last row is the reason embedded and IoT devices appear so often in attack scenarios: the constraints that make them cheap are the same constraints that make them hard to defend.

    The main threat to a device is malware 恶意软件 - malicious software. Learn the types:

    • Virus 病毒 - must be activated by a user opening a file.
    • Worm 蠕虫 - spreads by itself, with no human action.
    • Trojan 木马 - hides inside software that looks safe; a remote access trojan (RAT) 远程访问木马 gives the adversary remote control.
    • Ransomware 勒索软件 - encrypts your files and demands payment for the key.
    • Spyware 间谍软件 - secretly tracks what you do.
    • Keylogger 键盘记录器 - records every keystroke to steal passwords.
    • Logic bomb 逻辑炸弹 - triggers only when a condition is met (a date, a version).
    • Rootkit - deeply hides in the operating system and can even make itself invisible.

    Most malware is a file, but fileless malware 无文件恶意软件 is different: it lives only in RAM 内存 and abuses legitimate programs already on the device, leaving no file for a scanner to find.

    Adversaries exploit unpatched software 未打补丁的软件, weak passwords, unprotected BIOS/UEFI startup settings, and open ports. We rate device risk by the value and criticality of the device - a hospital's unpatched email server is high risk, while an employee's laptop with one unused open port is low.

    Explore · ⁨Khám phá⁩

    Name the malware from its behaviour · ⁨Gọi tên mã độc dựa vào hành vi của nó⁩

    Each kind of malware has one defining trait: a worm self-spreads, a virus needs a user to run it, ransomware encrypts for money, and a rootkit hides deep in the OS. · ⁨Mỗi loại malware có một đặc điểm xác định: worm tự nhân bản, virus cần người dùng chạy nó, ransomware mã hóa để tống tiền, và rootkit ẩn sâu trong hệ điều hành.⁩

    Vocabulary · ⁨Từ vựng⁩ Train · ⁨Luyện tập⁩
    English Tiếng Việt
    embedded computer/emˈbedɪd kəmˈpjuːtə/ máy tính nhúng
    Internet of Things (IoT)/ˈɪntənet ɒv θɪŋz/ Internet vạn vật (IoT)
    handheld computers/ˈhændheld kəmˈpjuːtəz/ máy tính cầm tay
    malware/ˈmælweə/ malware (mã độc)
    Virus/ˈvaɪrəs/ Virus
    Worm/wɜːm/ Worm (sâu máy tính)
    Trojan/ˈtrəʊdʒn/ Trojan (ngựa thành Troia)
    remote access trojan (RAT)/rɪˈməʊt ˈækses ˈtrəʊdʒn/ trojan truy cập từ xa (RAT)
    Ransomware/ˈrænsəmweə/ Ransomware
    Spyware/ˈspaɪweə/ Spyware (phần mềm gián điệp)
    Keylogger/ˈkiːlɒɡə/ Machine ghi phím
    Logic bomb/ˈlɒdʒɪk bɒm/ Bom logic
    fileless malware/ˈfaɪlləs ˈmælweə/ mã độc không tập tin
    RAM/ræm/ RAM
    unpatched software/ʌnˈpætʃt ˈsɒftweə/ phần mềm chưa vá
    4.2

    Authentication

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 4.2.A: Explain why hashes (also called hash outputs, checksums, message digests, or digests) are used to store passwords.

    • 4.2.A.1 A cryptographic hash function (also called a message digest function) is a mathematical algorithm that takes binary data of an arbitrary length, processes it according to a set of instructions, and outputs a fixed-length binary string called the hash (or checksum or message digest). Well known cryptographic hashes include:
      • MD5
      • SHA-1, SHA-256, SHA-512 (SHA stands for Secure Hash Algorithm)
      • NTHash
      • RIPEMD-160
    • 4.2.A.2 An n-bit hash has $2^n$ possible outputs. The number of inputs is infinite, and so inevitably two different inputs will produce the same hash. This is called a collision.
    • 4.2.A.3 Cryptographic hash functions have the following properties:
      • Hashes are collision resistant; it is difficult to find two different inputs to the same hash function that produce the same output.
      • Hashes have pre-image resistance; given a hash, it is infeasible to figure out the input that generated the hash.
      • Hashes are repeatable; the same input will always produce the same hash.
      • Hashes have a fixed length; the length in bits of the hash for a specific hash function is constant regardless of the size of the input.
    • 4.2.A.4 Adversaries try to compromise hashing functions by forcing collisions in their output. If an efficient algorithm exists to force a collision for a specific hash function, then that hash function will be deprecated (no longer used in secure settings). MD5 and SHA1 are examples of deprecated hash functions.
    • 4.2.A.5 Password-based authentication services shouldn’t store passwords in plaintext, so that if an adversary gains access to the user:password directory they won’t immediately know the passwords for all users. Instead, user passwords should be hashed and the hash stored in a database. When a user enters their password, it is hashed, and the hash is compared to the hash stored on file. If the hashes match, then the user is authenticated.
    • 4.2.A.6 If two users had the same password, then their passwords would have identical hashes in the user:password directory. To prevent this, a few random bits (called salt) are hashed with a user’s password to generate the hash. Each user’s salt is unique, so even if two users have the same password they will have a different password hash because they have different salt.

    Learning Objective 4.2.B: Explain how password attacks exploit vulnerabilities.

    • 4.2.B.1 If an adversary can compromise the password of a legitimate user, and that user’s organization has not enabled MFA or other authentication protections, then the adversary can act within that organization with all the access and rights available to the user.
    • 4.2.B.2 Password attacks can be classified as online or offline.
      • Online password attacks attempt user:password combinations in an active authentication portal.
      • Offline password attacks have captured a user:password database and can run password attacks against the database on their own computer. This method bypasses any account lock out protections that may be in place.
    • 4.2.B.3 Many users reuse the same passwords (or variations of the same password) for all the services and accounts they have, despite warnings not to. When an organization’s user database is stolen, the usernames, emails, and passwords are sold to adversaries or posted online. Adversaries often begin an attempt to compromise an account by trying stolen or leaked credentials for a target individual.
    • 4.2.B.4 Many users set passwords that are easy to guess, and adversaries will attempt to guess common passwords for a user’s account. Password spraying is an attack where an adversary attempts a common password against many different user accounts.
    • 4.2.B.5 Some services and devices (e.g., switches, routers, and IoT devices) are preconfigured with a default administrative user and password. Credential stuffing is an attack where an adversary attempts to gain access to these services or devices using common default credentials or account credentials that have been stolen.
    • 4.2.B.6 Offline password attacks use automated hash-cracking tools to hash possible passwords and compare them against a captured hash. Although hashes can’t be reversed, an adversary can use these tools to hash many potential passwords and compare them to the target hash. If an adversary finds a hash that matches, they can use the password that generated the hash to login to the user’s account. Offline attacks include:
      • Brute force attacks, where an adversary uses an automated tool to test all the potential passwords that a user could have
      • Dictionary attacks, where an adversary uses an automated tool to test a list of common passwords
    • 4.2.B.7 A rainbow table attack uses a list of common passwords to generate a rainbow table. A rainbow table is a table that contains each potential password and its hash. The table is then sorted by the hashes, and the adversary uses an automated tool to search the list of hashes for the captured hash. If the hashes match, then the adversary has found a password that generates the same hash, and the password will allow the adversary to login to the user’s account.

    Learning Objective 4.2.C: Determine the type of authentication used to verify the identity of a user.

    • 4.2.C.1 Authentication mechanisms are technical controls that verify the identity of a user to ensure that only authorized users access a system. The proof the user provides to identify themselves is called a factor. Common authentication factors include:
      • Something the user knows (knowledge factor)
      • Something the user has (possession factor)
      • Something the user is (biometric factor)
      • Somewhere the user is (location factor)
    • 4.2.C.2 Knowledge factors can be passwords, PINs, or answers to preselected challenge questions. For a knowledge factor to be effective it needs to be something an adversary can’t easily guess; however, knowledge factors that are difficult for an adversary to figure out can also be harder for a user to remember.
    • 4.2.C.3 A possession factor is an object a user has that is unique to them, such as an access card, a bank card, a cell phone, or an authentication token. The more difficult it is for an adversary to obtain the object (or a copy of it), the more secure the possession factor is.
    • 4.2.C.4 Biometric factors measure features of the human body and can include fingerprints, palm prints, facial recognition, iris or retina scans, or voice identification. Biometric factors are difficult for an adversary to duplicate because they are unique to an individual.
    • 4.2.C.5 Location factors use information about Wi-Fi signals, GPS data, time zone settings, and even IP address information to make determinations about location. Rules can be established for allowing or denying access based on a location factor.
    • 4.2.C.6 Multifactor authentication (MFA) is when a system uses more than one factor to authenticate a user. MFA is more secure than single-factor authentication because it requires the user to provide at least two separate factors of authentication.

    Learning Objective 4.2.D: Configure login settings to make a device more secure.

    • 4.2.D.1 Requiring complexity in passwords is a login setting that can be configured. When enabled, users setting a new password must include at least one character from each character set. Passwords with characters from each character set are significantly harder for an adversary to crack than passwords that use characters from only one or two character sets. The main character sets often required are:
      • Uppercase letters (A–Z)
      • Lowercase letters (a–z)
      • Numeric digits (0–9)
      • Special characters (!”#$%&’()*+,-./:;<=>?@ [ \ ] ^_`{|}~)
    • 4.2.D.2 Requiring a minimum password length is a login setting that can be configured. This means that users must have at least a certain number of characters in their password. The longer and more complex a password is, the longer it will take a digital tool to crack the password.
    • 4.2.D.3 Requiring a maximum password age is a login setting that can be configured. When configured, users will receive a prompt to change their password a certain number of days after their last password change, usually every 90 or 120 days. If a user’s password has been compromised, changing it could prevent an adversary from gaining access to the user’s account. However, some national standards recommend that organizations not require users to change their passwords on predefined intervals to discourage users from developing password patterns (e.g., PasswordFall2028).
    • 4.2.D.4 Requiring the system to store a certain number of previous user passwords is a login setting that can be configured. This prevents a user from reusing a password. Many organizations store users’ previous 5–10 password hashes to prevent reuse.
    • 4.2.D.5 Requiring a lockout period after a certain number of invalid login attempts is a login setting that can be configured. This prevents an adversary from continuously randomly attempting wrong passwords. Many organizations lock a user’s account after 3–5 invalid login attempts. The period of the lockout varies.
    Tiếng Việt

    Mục tiêu Học tập 4.2.A: Giải thích tại sao các hàm băm (còn gọi là đầu ra hash, tổng kiểm tra, digest tin nhắn hoặc digest) được sử dụng để lưu mật khẩu.

    • 4.2.A.1 Một hàm băm mã hóa (còn gọi là hàm digest tin nhắn) là một thuật toán toán học nhận dữ liệu nhị phân có độ dài tùy ý, xử lý theo một bộ chỉ thị và trả về một chuỗi nhị phân có độ dài cố định gọi là hash (hoặc tổng kiểm tra hoặc digest tin nhắn). Các hàm băm mã hóa nổi tiếng bao gồm:
      • MD5
      • SHA-1, SHA-256, SHA-512 (SHA viết tắt của Secure Hash Algorithm)
      • NTHash
      • RIPEMD-160
    • 4.2.A.2 Một hash n-bit có $2^n$ đầu ra có thể. Số lượng đầu vào là vô hạn, vì vậy tất nhiên hai đầu vào khác nhau sẽ tạo ra cùng một hash. Điều này được gọi là va chạm.
    • 4.2.A.3 Các hàm băm mã hóa có các tính chất sau đây:
      • Hashs kháng va chạm; khó để tìm thấy hai đầu vào khác nhau của cùng một hàm hash tạo ra cùng một đầu ra.
      • Hashs có tính kháng ảnh tượng trước; cho trước một hash, việc suy ra đầu vào đã tạo ra hash đó là không khả thi.
      • Hashs có tính lặp lại; cùng một đầu vào sẽ luôn tạo ra cùng một hash.
      • Hashs có độ dài cố định; độ dài bit của hash cho một hàm hash cụ thể là không đổi bất kể kích thước của đầu vào.
    • 4.2.A.4 Kẻ thù cố gắng xâm phạm các hàm hash bằng cách ép buộc va chạm trong đầu ra của chúng. Nếu tồn tại một thuật toán hiệu quả để ép buộc va chạm cho một hàm hash cụ thể, thì hàm hash đó sẽ bị bãi bỏ (không còn được sử dụng trong các môi trường an toàn). MD5 và SHA1 là ví dụ về các hàm hash bị bãi bỏ.
    • 4.2.A.5 Các dịch vụ xác thực dựa trên mật khẩu không nên lưu mật khẩu dưới dạng văn bản rõ, do đó nếu kẻ thù truy cập vào thư mục người dùng:mật khẩu, chúng sẽ không ngay lập tức biết mật khẩu của tất cả người dùng. Thay vào đó, mật khẩu người dùng nên được băm và hash được lưu trong cơ sở dữ liệu. Khi người dùng nhập mật khẩu của họ, nó được băm, và hash được so sánh với hash được lưu trên tập tin. Nếu các hash khớp nhau, thì người dùng được xác thực.
    • 4.2.A.6 Nếu hai người dùng có cùng mật khẩu, thì các giá trị băm (hash) của mật khẩu sẽ giống nhau trong thư mục user:password. Để ngăn chặn điều này, một vài bit ngẫu nhiên (được gọi là muối/salt) được băm cùng với mật khẩu của người dùng để tạo ra giá trị băm. Muỗi của mỗi người dùng là duy nhất, vì vậy ngay cả khi hai người dùng có cùng mật khẩu, họ vẫn sẽ có giá trị băm mật khẩu khác nhau do có muối khác nhau.

    Mục tiêu học tập 4.2.B: Giải thích cách các cuộc tấn công mật khẩu khai thác điểm yếu bảo mật.

    • 4.2.B.1 Nếu kẻ thù có thể đánh cắp mật khẩu của một người dùng hợp lệ, và tổ chức của người dùng đó chưa bật xác thực đa yếu tố (MFA) hoặc các biện pháp bảo vệ xác thực khác, thì kẻ thù có thể hành động trong tổ chức đó với tất cả quyền truy cập và đặc quyền mà người dùng đó sở hữu.
    • 4.2.B.2 Các cuộc tấn công mật khẩu có thể được phân loại thành trực tuyến (online) và ngoại tuyến (offline).
      • Các cuộc tấn công mật khẩu trực tuyến cố gắng thử nghiệm các kết hợp user:password trên giao diện xác thực đang hoạt động.
      • Các cuộc tấn công mật khẩu ngoại tuyến đã thu thập được cơ sở dữ liệu user:password và có thể chạy các cuộc tấn công mật khẩu đối với cơ sở dữ liệu này trên máy tính riêng của chúng. Phương pháp này bỏ qua bất kỳ biện pháp khóa tài khoản nào có thể đang được áp đặt.
    • 4.2.B.3 Nhiều người dùng tái sử dụng cùng một mật khẩu (hoặc các biến thể của cùng một mật khẩu) cho tất cả các dịch vụ và tài khoản của mình, mặc dù có cảnh báo không nên làm như vậy. Khi cơ sở dữ liệu người dùng của một tổ chức bị trộm, tên đăng nhập, email và mật khẩu sẽ bị bán cho kẻ thù hoặc đăng lên mạng. Kẻ thù thường bắt đầu cố gắng xâm nhập vào tài khoản bằng cách thử các thông tin xác thực bị trộm hoặc bị rò rỉ cho một cá nhân cụ thể.
    • 4.2.B.4 Nhiều người dùng đặt mật khẩu dễ bị đoán, và kẻ thù sẽ cố gắng đoán các mật khẩu phổ biến cho tài khoản của người dùng. Phun mật khẩu (Password spraying) là một cuộc tấn công trong đó kẻ thù thử một mật khẩu phổ biếnagainst nhiều tài khoản người dùng khác nhau.
    • 4.2.B.5 Một số dịch vụ và thiết bị (ví dụ: bộ chuyển đổi, bộ định tuyến và thiết bị IoT) được cấu hình sẵn với người dùng quản trị và mật khẩu mặc định. Đổ độn thông tin xác thực (Credential stuffing) là một cuộc tấn công trong đó kẻ thù cố gắng truy cập các dịch vụ hoặc thiết bị này bằng cách sử dụng các thông tin xác thực mặc định phổ biến hoặc thông tin xác thực tài khoản đã bị trộm.
    • 4.2.B.6 Các cuộc tấn công mật khẩu ngoại tuyến sử dụng các công cụ phá mã băm tự động để băm các mật khẩu khả dĩ và so sánh chúng với giá trị băm đã thu thập được. Mặc dù không thể đảo ngược giá trị băm, nhưng kẻ thù có thể sử dụng các công cụ này để băm nhiều mật khẩu tiềm năng và so sánh chúng với giá trị băm mục tiêu. Nếu kẻ thù tìm thấy một giá trị băm trùng khớp, họ có thể sử dụng mật khẩu tạo ra giá trị băm đó để đăng nhập vào tài khoản người dùng. Các cuộc tấn công ngoại tuyến bao gồm:
      • Các cuộc tấn công brute force, nơi kẻ thù sử dụng công cụ tự động để thử tất cả các mật khẩu tiềm năng mà người dùng có thể có
      • Các cuộc tấn công từ điển, nơi kẻ thù sử dụng công cụ tự động để thử một danh sách các mật khẩu phổ biến
    • 4.2.B.7 Cuộc tấn công bảng cầu vồng (Rainbow table attack) sử dụng một danh sách các mật khẩu phổ biến để tạo ra một bảng cầu vồng. Bảng cầu vồng là một bảng chứa mỗi mật khẩu tiềm năng và giá trị băm tương ứng của nó. Bảng sau đó được sắp xếp theo các giá trị băm, và kẻ thù sử dụng công cụ tự động để tìm kiếm trong danh sách các giá trị băm để tìm giá trị băm đã thu thập được. Nếu các giá trị băm trùng khớp, thì kẻ thù đã tìm thấy một mật khẩu tạo ra cùng một giá trị băm, và mật khẩu đó sẽ cho phép kẻ thù đăng nhập vào tài khoản người dùng.

    Mục tiêu học tập 4.2.C: Xác định loại xác thực được sử dụng để xác minh danh tính của người dùng.

    • 4.2.C.1 Các cơ chế xác thực là các kiểm soát kỹ thuật nhằm xác minh danh tính của người dùng để đảm bảo chỉ những người dùng được ủy quyền mới truy cập hệ thống. Bằng chứng mà người dùng cung cấp để tự xác định danh tính được gọi là một yếu tố. Các yếu tố xác thực phổ biến bao gồm:
      • Những gì người dùng biết (yếu tố kiến thức)
      • Những gì người dùng có (yếu tố sở hữu)
      • Những gì người dùng là (yếu tố sinh trắc học)
      • Nơi người dùng ở (yếu tố vị trí)
    • 4.2.C.2 Các yếu tố kiến thức có thể là mật khẩu, mã PIN hoặc câu trả lời cho các câu hỏi thách thức được chọn trước. Đối với một yếu tố kiến thức có hiệu quả, nó cần phải là thứ mà kẻ thù không thể dễ dàng đoán; tuy nhiên, các yếu tố kiến thức khó đoán đối với kẻ thù cũng có thể khó nhớ hơn đối với người dùng.
    • 4.2.C.3 Một yếu tố sở hữu là một vật thể mà người dùng có và là duy nhất đối với họ, chẳng hạn như thẻ truy cập, thẻ ngân hàng, điện thoại di động hoặc token xác thực. Càng khó để kẻ thù lấy được vật thể (hoặc bản sao của nó), yếu tố sở hữu càng an toàn.
    • 4.2.C.4 Các yếu tố sinh trắc học đo lường các đặc điểm của cơ thể con người và có thể bao gồm vân tay, dấu lòng bàn tay, nhận diện khuôn mặt, quét mống mắt hoặc võng mạc, hoặc nhận diện giọng nói. Các yếu tố sinh trắc học khó để kẻ thù sao chép vì chúng là duy nhất đối với từng cá nhân.
    • 4.2.C.5 Các yếu tố vị trí sử dụng thông tin về tín hiệu Wi-Fi, dữ liệu GPS, cài đặt múi giờ, và thậm chí thông tin địa chỉ IP để đưa ra quyết định về vị trí. Các quy tắc có thể được thiết lập để cho phép hoặc từ chối truy cập dựa trên yếu tố vị trí.
    • 4.2.C.6 Xác thực đa yếu tố (MFA) là khi một hệ thống sử dụng hơn một yếu tố để xác thực người dùng. MFA an toàn hơn xác thực đơn yếu tố vì nó yêu cầu người dùng cung cấp ít nhất hai yếu tố xác thực riêng biệt.

    Mục tiêu học tập 4.2.D: Cấu hình cài đặt đăng nhập để làm cho thiết bị an toàn hơn.

    • 4.2.D.1 Yêu cầu độ phức tạp trong mật khẩu là một cài đặt đăng nhập có thể được cấu hình. Khi được bật, người dùng đặt mật khẩu mới phải bao gồm ít nhất một ký tự từ mỗi tập ký tự. Mật khẩu có ký tự từ mỗi tập ký tự khó bị bẻ mã hơn đáng kể so với mật khẩu sử dụng ký tự từ chỉ một hoặc hai tập ký tự. Các tập ký tự chính thường được yêu cầu là:
      • Chữ cái in hoa (A–Z)
      • Chữ cái thường (a–z)
      • Digit số (0–9)
      • Ký tự đặc biệt (!"#$%&'()*+,-./:;<=>?@ [ \ ] ^_`{|}~)
    • 4.2.D.2 Yêu cầu độ dài mật mã tối thiểu là một cài đặt đăng nhập có thể được cấu hình. Điều này có nghĩa là người dùng phải có ít nhất một số lượng ký tự nhất định trong mật mã của họ. Mật mã càng dài và phức tạp thì công cụ kỹ thuật số càng mất nhiều thời gian để phá mật mã đó.
    • 4.2.D.3 Yêu cầu tuổi đời mật mã tối đa là một cài đặt đăng nhập có thể được cấu hình. Khi được cấu hình, người dùng sẽ nhận được yêu cầu thay đổi mật mã sau một số ngày nhất định kể từ lần thay đổi mật mã cuối cùng, thường là mỗi 90 hoặc 120 ngày. Nếu mật mã của người dùng bị lộ, việc thay đổi nó có thể ngăn chặn kẻ tấn công truy cập vào tài khoản của người dùng. Tuy nhiên, một số tiêu chuẩn quốc gia khuyến nghị các tổ chức không bắt buộc người dùng thay đổi mật mã theo khoảng thời gian cố định để ngăn người dùng tạo ra các quy luật mật mã (ví dụ: PasswordFall2028).
    • 4.2.D.4 Yêu cầu hệ thống lưu trữ một số lượng mật mã trước đó của người dùng là một cài đặt đăng nhập có thể được cấu hình. Điều này ngăn người dùng sử dụng lại mật mã. Nhiều tổ chức lưu trữ hash của 5–10 mật mã trước đó của người dùng để ngăn việc tái sử dụng.
    • 4.2.D.5 Yêu cầu thời gian khóa sau một số lần thử đăng nhập không thành công là một cài đặt đăng nhập có thể được cấu hình. Điều này ngăn kẻ tấn công liên tục thử ngẫu nhiên các mật mã sai. Nhiều tổ chức khóa tài khoản người dùng sau 3–5 lần thử đăng nhập không thành công. Thời gian khóa có sự khác nhau tùy theo từng trường hợp.

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    Multi-factor authentication
    A person pressing a fingertip onto a small optical fingerprint scanner
    A fingerprint scanner: biometric authentication checks something you ARE, which is much harder for an attacker to steal or guess than a password

    To store passwords safely, systems use a cryptographic hash function 密码散列函数 - a one-way maths algorithm that turns any input into a fixed-length string called a hash 散列值 (or digest). Hashes have three vital properties: they are collision resistant 抗碰撞 (hard to find two inputs with the same output), have pre-image resistance 抗原像 (you cannot work backwards to the input), and are repeatable (the same input always gives the same hash).

    A hash function turns any input into a fixed-length digest, and cannot be reversed
    A hash function turns any input into a fixed-length digest, and cannot be reversed

    Real hash functions have names. The Secure Hash Algorithm (SHA) family – SHA-256 and SHA-512 – is today's standard. Adversaries attack a hash function by trying to force a collision (two different inputs with the same hash); once an efficient collision attack exists, that function is deprecated 弃用 (retired from secure use). MD5 and SHA-1 are the classic deprecated examples – never rely on them to protect data today.

    A service never stores your plaintext password. It stores the hash; when you log in, it hashes what you typed and compares. To stop two identical passwords producing identical hashes, a few random bits called salt 盐值 are added before hashing, so every stored hash is unique.

    Worked example. Two users both choose the password sunshine. Without salt, both stored hashes would be identical, so cracking one instantly cracks the other. Give each user a unique salt - say x7 and q2 - and the service hashes sunshinex7 and sunshineq2 instead. The two stored hashes now look completely different, so the adversary must attack each account separately. This is why a stolen hash database is far less dangerous when the hashes are salted.

    Adversaries fight back with password attacks. Online attacks guess against a live login; offline attacks steal the hash database and crack it on their own machine (which bypasses any account-lockout protection). Techniques include:

    • brute force 暴力破解 - an automated tool tries every possible password in turn; guaranteed to work eventually, but slow, and it grows explosively with password length.
    • a dictionary attack 字典攻击 - the tool tries a list of common words and known passwords first, because most people pick guessable ones.
    • password spraying 密码喷洒 - one common password against many accounts (this dodges lockout, which counts failures per account).
    • credential stuffing 撞库 - reusing stolen or default credentials, exploiting that people reuse passwords across sites.
    • a rainbow table 彩虹表 - a precomputed table of passwords and their hashes, sorted by hash, so a captured hash can be looked up instead of recomputed.

    Password policy settings

    An administrator hardens accounts by configuring login settings - and the exam expects you to name them and say what each defends against:

    Setting What it does The attack it slows
    complexity 复杂度 require a character from each set (upper, lower, digit, special) brute force / dictionary
    minimum length 最小长度 require N characters - length matters more than anything brute force (grows exponentially)
    maximum age 最长有效期 force a change every ~90-120 days limits how long a stolen password is useful
    password history 密码历史 store the last 5-10 hashes, block reuse stops recycling an old (possibly leaked) password
    lockout 锁定 lock the account after 3-5 wrong tries brute force / online guessing

    One subtlety worth a mark: some national standards now advise against forced expiry, because regular changes push users into predictable patterns like PasswordFall2028. A password manager 密码管理器 solves the real problem - it generates and stores a long, unique password per site, so none is ever reused or guessable.

    Authentication factors prove who you are, and fall into categories: something you know (a password), something you have (a token or phone), something you are (a biometric 生物特征 like a fingerprint or retina scan), and somewhere you are (a location factor). Using two or more is multifactor authentication (MFA) 多因素身份验证 - far stronger than a password alone.

    Two small USB hardware security keys
    A hardware security key proves who you are with something you physically hold — a strong second factor

    Removable media, and the autorun problem

    An adversary can load malware onto an external drive — a USB stick, a portable disc — and leave it where someone will pick it up. If autorun 自动运行 is enabled, the device runs a program from that drive the moment it is inserted, with no click required, so the malware executes before the user has decided to trust anything.

    Two controls answer this, and the exam wants both named:

    • Disable autorun, so inserting a drive never runs anything by itself.
    • Prohibit users from connecting external drives or media at all — enforced by policy and by a technical control that blocks the USB ports — which is why so many secure environments physically or logically disable them.
    Explore · ⁨Khám phá⁩

    How a hash maps any input to a fixed slot · ⁨Cách hash ánh xạ mọi đầu vào vào một vị trí cố định⁩

    A hash function sends every input to a fixed-length output. The same input always lands in the same place (repeatable), and you cannot work backwards from the slot to the input. · ⁨Hàm hash gửi mọi đầu vào đến đầu ra có độ dài cố định. Đầu vào giống nhau luôn nằm ở cùng một nơi (lặp lại được), và bạn không thể suy ngược từ vị trí đó về đầu vào ban đầu.⁩

    Vocabulary · ⁨Từ vựng⁩ Train · ⁨Luyện tập⁩
    English Tiếng Việt
    cryptographic hash function/ˌkrɪptəˈɡræfɪk hæʃ ˈfʌŋkʃn/ hàm băm mã hóa
    hash/hæʃ/ hàm hash
    collision resistant/kəˈlɪʒn rɪˈzɪstənt/ kháng va chạm
    pre-image resistance/priː ˈɪmɪdʒ rɪˈzɪstəns/ kháng ảnh gốc
    deprecated/ˈdeprɪkeɪtɪd/ đã bị loại bỏ
    salt/sɒlt/ muối
    brute force/bruːt fɔːs/ brute force
    dictionary attack/ˈdɪkʃənəri əˈtæk/ tấn công bảng từ điển
    password spraying/ˈpæswɜːd ˈspreɪɪŋ/ phun mật khẩu (password spraying)
    credential stuffing/krɪˈdenʃl ˈstʌfɪŋ/ nhồi credentia (credential stuffing)
    rainbow table/ˈreɪnbəʊ ˈteɪbl/ bảng cầu vồng
    complexity/kəmˈpleksɪti/ độ phức tạp
    minimum length/ˈmɪnɪməm leŋθ/ chiều dài tối thiểu
    maximum age/ˈmæksɪməm eɪdʒ/ tuổi đời tối đa
    password history/ˈpæswɜːd ˈhɪstəri/ lịch sử mật khẩu
    lockout/ˈlɒkaʊt/ khóa tài khoản
    password manager/ˈpæswɜːd ˈmænɪdʒə/ quản lý mật khẩu
    biometric/ˌbaɪəʊˈmetrɪk/ sinh trắc học
    multifactor authentication (MFA)/ˌmʌltɪˈfæktə ɔːˌθentɪˈkeɪʃn/ xác thực đa yếu tố (MFA)
    autorun/ˌɔːtəʊˈrʌn/ tự chạy
    Watch lesson · ⁨Xem bài học⁩
    4.3

    Protecting Devices

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 4.3.A: Identify managerial controls related to device security.

    • 4.3.A.1 An acceptable use policy will describe the range of activities that are permissible, prohibited, or required by users on devices owned by an organization and may include:
      • Prohibiting users from accessing specific websites or types of websites (e.g., social media or gaming)
      • Requiring users to keep software updated
      • Allowing users to connect peripheral devices
      • Prohibiting users from connecting external drives or media
    • 4.3.A.2 A password policy will detail the requirements for user passwords within an organization and may include:
      • A minimum or maximum password length
      • A minimum or maximum amount of time a user may keep the same password
      • A prohibition of password reuse
      • Rules for password construction (e.g., no dictionary words and character set requirements)
      • A suggestion to use secure password management tools instead of writing passwords down
    • 4.3.A.3 A software installation policy will describe what (if any) software users are allowed to install on their devices and usually also a process for users to request specialized software they may need to perform their role, and it may include:
      • A prohibition against users installing software on their devices
      • A process for users to request new software needed for their role
      • A list of approved software for users

    Learning Objective 4.3.B: Explain how anti-malware software can make a device more secure.

    • 4.3.B.1 Anti-malware software (sometimes called antivirus software) has tools to quarantine and remove malware that can corrupt, spy on, or destroy a system. Malware contains indicators that make it detectable; these indicators are called signatures.
    • 4.3.B.2 Anti-malware software has a database of malware signatures. It periodically scans the files on a device and checks to see if any of the files match any of the signatures in its database. If there is a match, the software quarantines and removes the malicious files.

    Learning Objective 4.3.C: Explain why keeping a device’s operating system and software updated makes it more secure.

    • 4.3.C.1 When vulnerabilities in operating systems and software are found, the vendor or organization that maintains the operating system software will fix it and send an update. A small update is called a patch.
    • 4.3.C.2 Ensuring that a computer’s operating system and software applications are updated to the most recent version prevents adversaries from taking advantage of a known vulnerability.

    Learning Objective 4.3.D: Configure a host-based firewall.

    • 4.3.D.1 Host-based firewalls allow or deny traffic into or out of a single device. This provides an extra layer of security in case a host is connected to a compromised network.
    • 4.3.D.2 A host-based firewall is software that runs on a device and follows a set of rules (an ACL) like a network-based firewall. Firewall rules are implemented in order, applying the first rule that matches.
    • 4.3.D.3 A host-based firewall can also block specified types of outbound traffic. Host-based firewalls should always block ports or services not needed for a given device.
      • Illustrative examples for 4.3.D.3:
        • A host-based firewall is configured to block outbound FTP traffic. This prevents an adversary with remote access to the host from using FTP to exfiltrate a file to the adversary’s server.
    • 4.3.D.4 The rules for a host-based firewall can allow or deny traffic based on source or destination port or IP address, service, protocol, or application.
    Tiếng Việt

    Mục tiêu học tập 4.3.A: Xác định các kiểm soát quản lý liên quan đến bảo mật thiết bị.

    • 4.3.A.1 Chính sách sử dụng chấp nhận sẽ mô tả phạm vi các hoạt động được phép, bị cấm hoặc bắt buộc đối với người dùng trên các thiết bị do tổ chức sở hữu, và có thể bao gồm:
      • Cấm người dùng truy cập vào các trang web cụ thể hoặc loại trang web nhất định (ví dụ: mạng xã hội hoặc game)
      • Yêu cầu người dùng giữ cho phần mềm luôn được cập nhật
      • Cho phép người dùng kết nối các thiết bị ngoại vi
      • Cấm người dùng kết nối ổ đĩa ngoài hoặc phương tiện lưu trữ
    • 4.3.A.2 Chính sách mật mã sẽ chi tiết hóa các yêu cầu về mật mã người dùng trong tổ chức và có thể bao gồm:
      • Độ dài mật mã tối thiểu hoặc tối đa
      • Khoảng thời gian tối thiểu hoặc tối đa mà người dùng có thể giữ nguyên mật mã cũ
      • Việc cấm tái sử dụng mật mã
      • Các quy tắc xây dựng mật mã (ví dụ: không dùng từ điển và yêu cầu bộ ký tự)
      • Khuyến nghị sử dụng công cụ quản lý mật mã an toàn thay vì ghi chép mật mã
    • 4.3.A.3 Chính sách cài đặt phần mềm sẽ mô tả những gì (nếu có) phần mềm mà người dùng được phép cài đặt trên thiết bị của mình và thường cũng bao gồm quy trình để người dùng yêu cầu phần mềm chuyên biệt mà họ cần để thực hiện nhiệm vụ, và có thể bao gồm:
      • Việc cấm người dùng cài đặt phần mềm lên thiết bị của họ
      • Quy trình để người dùng yêu cầu phần mềm mới cần thiết cho vai trò của họ
      • Danh sách phần mềm đã được phê duyệt dành cho người dùng

    Mục tiêu học tập 4.3.B: Giải thích cách phần mềm chống mã độc có thể làm cho thiết bị an toàn hơn.

    • 4.3.B.1 Phần mềm chống mã độc (đôi khi được gọi là phần mềm diệt virus) có các công cụ để cô lập và loại bỏ mã độc có thể làm hỏng, gián điệp hoặc phá hủy hệ thống. Mã độc chứa các chỉ báo khiến nó có thể bị phát hiện; các chỉ báo này được gọi là chữ ký.
    • 4.3.B.2 Phần mềm chống mã độc có cơ sở dữ liệu chứa các chữ ký mã độc. Nó định kỳ quét các tệp trên thiết bị và kiểm tra xem có tệp nào khớp với bất kỳ chữ ký nào trong cơ sở dữ liệu của nó hay không. Nếu có sự trùng khớp, phần mềm sẽ cô lập và xóa các tệp độc hại.

    Mục tiêu học tập 4.3.C: Giải thích tại sao việc duy trì hệ điều hành và phần mềm của thiết bị ở phiên bản mới nhất giúp tăng cường bảo mật.

    • 4.3.C.1 Khi các lỗ hổng trong hệ điều hành và phần mềm được phát hiện, nhà cung cấp hoặc tổ chức duy trì phần mềm hệ điều hành sẽ sửa chữa và gửi bản cập nhật. Một bản cập nhật nhỏ được gọi là bản vá.
    • 4.3.C.2 Đảm bảo rằng hệ điều hành và các ứng dụng phần mềm của máy tính được cập nhật lên phiên bản mới nhất sẽ ngăn các kẻ tấn công lợi dụng các lỗ hổng đã biết.

    Mục tiêu học tập 4.3.D: Cấu hình tường lửa dựa trên máy chủ.

    • 4.3.D.1 Tường lửa dựa trên máy chủ cho phép hoặc từ chối lưu lượng đi vào hoặc ra khỏi một thiết bị đơn lẻ. Điều này cung cấp thêm một lớp bảo vệ trong trường hợp máy chủ được kết nối với mạng bị xâm nhập.
    • 4.3.D.2 Tường lửa dựa trên máy chủ là phần mềm chạy trên thiết bị và tuân theo một bộ quy tắc (một danh sách kiểm soát truy cập - ACL) giống như tường lửa dựa trên mạng. Các quy tắc tường lửa được triển khai theo thứ tự, áp dụng quy tắc đầu tiên khớp.
    • 4.3.D.3 Tường lửa dựa trên máy chủ cũng có thể chặn các loại lưu lượng đi ra được chỉ định. Tường lửa dựa trên máy chủ luôn nên chặn các cổng hoặc dịch vụ không cần thiết cho một thiết bị cụ thể.
      • Ví dụ minh họa cho 4.3.D.3:
        • Một tường lửa dựa trên máy chủ được cấu hình để chặn lưu lượng FTP đi ra. Điều này ngăn một kẻ tấn công có quyền truy cập từ xa vào máy chủ sử dụng FTP để đánh cắp một tệp dữ liệu sang máy chủ của kẻ tấn công.
    • 4.3.D.4 Các quy tắc cho tường lửa dựa trên máy chủ có thể cho phép hoặc từ chối lưu lượng dựa trên cổng nguồn hoặc đích, địa chỉ IP, dịch vụ, giao thức hoặc ứng dụng.

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    Managerial controls set the rules: an acceptable use policy 可接受使用政策 lists what users may and may not do, a password policy sets length and reuse rules, and a software installation policy controls what can be installed.

    Technical controls do the work. Anti-malware software 反恶意软件 keeps a database of malware signatures and quarantines any file that matches. Keeping the operating system and applications updated - installing each patch 补丁 - closes known holes before adversaries can use them. A host-based firewall 主机防火墙 controls traffic in and out of one single device, blocking ports and services it does not need.

    An anti-malware scanner window: 3106 files scanned, two threats found, with quarantine and update controls
    Anti-malware software scans files against a signature database and quarantines any matches — this scan has flagged two threats
    Vocabulary · ⁨Từ vựng⁩ Train · ⁨Luyện tập⁩
    English Tiếng Việt
    acceptable use policy/əkˈseptəbl juːs ˈpɒlɪsi/ quy định sử dụng chấp nhận được
    Anti-malware software/ˈænti ˈmælweə ˈsɒftweə/ Phần mềm chống mã độc
    patch/pætʃ/ bản vá
    host-based firewall/həʊst beɪst ˈfaɪəwɔːl/ tường lửa dựa trên máy chủ
    4.4

    Detecting Attacks on Devices

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 4.4.A: Explain how to detect attacks against devices.

    • 4.4.A.1 System processes and settings, login attempts, file download attempts, and user actions are logged by computing systems. These logs can be used to reconstruct circumstances leading up to and during a cyber incident.
    • 4.4.A.2 An indicator of compromise (IoC) is evidence that an adversary has compromised a device or network.
    • 4.4.A.3 Authentication logs (or auth logs) record every attempted login on a system. Analysis of authentication logs can reveal attempted attacks.
    • 4.4.A.4 Host-based IoCs are discovered when analyzing logs and configuration settings. Indicators, such as the following, can be found in authentication logs, user activity logs, and system configuration files:
      • Unusual files being created or modified
      • Unexpected processes or services
      • Unauthorized changes to system configuration settings
      • Unauthorized software installation or update
    • 4.4.A.5 File-based IoCs are discovered when analyzing files on a device. Indicators are usually found in executable files and can include:
      • Files whose hash matches known malware
      • File names that are known to be created by a certain piece of malware
      • File paths that are associated with malicious activity
    • 4.4.A.6 Behavior-based IoCs are discovered when analyzing logs. Indicators can be found in authentication logs and access logs and can include:
      • Multiple failed login attempts
      • Unusual login times or locations
      • Unauthorized attempts to access sensitive data
      • Attempts to elevate user privileges on a system

    Learning Objective 4.4.B: Determine controls for detecting attacks against a device.

    • 4.4.B.1 Performance is a criterion for determining a detection method. Detection tools use system memory and processing power and can impact the performance of a device. Anomaly-based detection tools use more system resources than signature-based tools. Signature-based detection is a better option for devices with less powerful system resources. Many embedded devices do not have enough system resources to run any detection tools on the device.
    • 4.4.B.2 Cost is a criterion for determining a detection method. Organizations that purchase detection software need to consider the cost of purchasing enough software licenses for the number of devices they need to monitor. Some organizations purchase an endpoint detection and response (EDR) service from a third-party vendor. Although these services are expensive, they provide a holistic, unified approach to threat detection for an organization’s devices; they typically include a centralized alert platform for monitoring possible attacks on devices.
    • 4.4.B.3 Sensitivity or criticality of the device is a criterion for determining a detection method. Devices that store or process sensitive information or provide critical services are more likely to be targeted by adversaries and benefit from a hybrid-detection model to offer maximum protection, when possible.

    Learning Objective 4.4.C: Evaluate the impact of a device detection method.

    • 4.4.C.1 Speed and performance are factors in evaluating the impact of a detection method. Signature-based detection is faster than anomaly-based detection in general, and that effect is compounded on devices, which often lack the processing power to effectively run anomaly-based detection tools. Implementing resource-intensive detection tools on devices can degrade device performance.
    • 4.4.C.2 Phase of the attack is a factor in evaluating the impact of a detection method. To carry out actions on a device, adversaries must first bypass a combination of physical- or network-layer protective, deterrent, and detective security controls. Detecting and stopping an attack at the device level can prevent adversaries from accessing sensitive data or disrupting critical services.
    • 4.4.C.3 False positives versus ease of bypassing detection is a factor in evaluating the impact of a detection method. Most device-level detection tools are signature-based, and signature-based detection has a low rate of false positives. However, signature-based detection is easier for adversaries to bypass.

    Learning Objective 4.4.D: Apply detection techniques to identify indicators of password attacks by analyzing log files.

    • 4.4.D.1 Online password attacks can be detected in authentication logs. A single user attempting many wrong passwords is an indicator of an online password attack. If a user:password hash database has been compromised, all the user passwords in the database should be considered insecure and all users should be forced to reset their passwords.
    • 4.4.D.2 If an authorized user is logging in from a different location or IP address than expected, or at a different time than normal, this can be an indicator that the user’s password has been compromised.
    • 4.4.D.3 An indicator of password spraying is many users trying to log in within seconds of each other from one IP address or from unusual IP addresses.
    • 4.4.D.4 An indicator of credential stuffing is a series of default user:password combinations being attempted on a device in quick succession, often from the same IP address.
    • 4.4.D.5 Offline password attacks can’t be detected, because the attack takes place on the adversary’s computer.
    Tiếng Việt

    Mục tiêu học tập 4.4.A: Giải thích cách phát hiện các cuộc tấn công vào thiết bị.

    • 4.4.A.1 Các quá trình và cài đặt hệ thống, các lần thử đăng nhập, các lần thử tải xuống tệp, và các hành động của người dùng đều được ghi lại bởi các hệ thống máy tính. Các nhật ký này có thể được sử dụng để tái tạo lại bối cảnh dẫn đến và diễn ra trong một sự cố an ninh mạng.
    • 4.4.A.2 Chỉ báo vi phạm (IoC) là bằng chứng cho thấy một đối thủ đã xâm nhập vào thiết bị hoặc mạng.
    • 4.4.A.3 Nhật ký xác thực (hoặc auth logs) ghi lại mọi lần đăng nhập được thử trên hệ thống. Phân tích nhật ký xác thực có thể tiết lộ các cuộc tấn công đang diễn ra.
    • 4.4.A.4 Các IoC dựa trên máy chủ được phát hiện khi phân tích nhật ký và cài đặt cấu hình. Các chỉ báo, như những ví dụ sau đây, có thể được tìm thấy trong nhật ký xác thực, nhật ký hoạt động của người dùng và tệp cấu hình hệ thống:
      • Tệp bất thường được tạo ra hoặc thay đổi
      • Quy trình hoặc dịch vụ không mong đợi
      • Thay đổi cấu hình hệ thống trái phép
      • Cài đặt hoặc cập nhật phần mềm trái phép
    • 4.4.A.5 Các IoC dựa trên tệp được phát hiện khi phân tích các tệp trên thiết bị. Các chỉ báo thường được tìm thấy trong tệp thực thi và có thể bao gồm:
      • Tệp có giá trị hash khớp với mã độc đã biết
      • Tên tệp được biết đến là do một loại mã độc cụ thể tạo ra
      • Đường dẫn tệp liên quan đến hoạt động độc hại
    • 4.4.A.6 Các IoC dựa trên hành vi được phát hiện khi phân tích nhật ký. Các chỉ báo có thể được tìm thấy trong nhật ký xác thực và nhật truy cập và có thể bao gồm:
      • Nhiều lần thử đăng nhập thất bại
      • Thời gian hoặc vị trí đăng nhập bất thường
      • Cố gắng truy cập dữ liệu nhạy cảm trái phép
      • Cố gắng nâng cao quyền hạn người dùng trên hệ thống

    Mục tiêu học tập 4.4.B: Xác định các biện pháp kiểm soát để phát hiện các cuộc tấn công vào thiết bị.

    • 4.4.B.1 Hiệu suất là tiêu chí để xác định phương pháp phát hiện. Các công cụ phát hiện sử dụng bộ nhớ và sức mạnh xử lý của hệ thống và có thể ảnh hưởng đến hiệu suất của thiết bị. Các công cụ phát hiện dựa trên bất thường sử dụng nhiều tài nguyên hệ thống hơn so với các công cụ dựa trên chữ ký. Phát hiện dựa trên chữ ký là lựa chọn tốt hơn cho các thiết bị có tài nguyên hệ thống yếu hơn. Nhiều thiết bị nhúng không có đủ tài nguyên hệ thống để chạy bất kỳ công cụ phát hiện nào trên thiết bị.
    • 4.4.B.2 Chi phí là tiêu chí để xác định phương pháp phát hiện. Các tổ chức mua phần mềm phát hiện cần xem xét chi phí mua đủ giấy phép phần mềm cho số lượng thiết bị cần giám sát. Một số tổ chức mua dịch vụ phát hiện và phản ứng đầu cuối (EDR) từ nhà cung cấp bên thứ ba. Mặc dù các dịch vụ này đắt đỏ, nhưng chúng cung cấp cách tiếp cận toàn diện, thống nhất để phát hiện mối đe dọa cho các thiết bị của tổ chức; chúng thường bao gồm nền tảng cảnh báo tập trung để giám sát các cuộc tấn công có thể xảy ra trên thiết bị.
    • 4.4.B.3 Độ nhạy cảm hoặc tính quan trọng của thiết bị là tiêu chí để xác định phương pháp phát hiện. Các thiết bị lưu trữ hoặc xử lý thông tin nhạy cảm hoặc cung cấp các dịch vụ quan trọng dễ bị nhắm mục tiêu bởi đối thủ hơn và được hưởng lợi từ mô hình phát hiện lai để cung cấp khả năng bảo vệ tối đa, nếu có thể.

    Mục tiêu học tập 4.4.C: Đánh giá tác động của phương pháp phát hiện thiết bị.

    • 4.4.C.1 Tốc độ và hiệu suất là các yếu tố trong việc đánh giá tác động của phương pháp phát hiện. Phát hiện dựa trên chữ ký nói chung nhanh hơn phát hiện dựa trên bất thường, và hiệu ứng này càng rõ rệt trên các thiết bị, vốn thường thiếu sức mạnh xử lý để chạy hiệu quả các công cụ phát hiện dựa trên bất thường. Triển khai các công cụ phát tốn tài nguyên trên thiết bị có thể làm giảm hiệu suất thiết bị.
    • 4.4.C.2 Giai đoạn của cuộc tấn công là một yếu tố trong việc đánh giá tác động của phương pháp phát hiện. Để thực hiện các hành động trên thiết bị, đối thủ phải vượt qua sự kết hợp giữa các biện pháp kiểm soát an ninh vật lý- hoặc lớp mạng mang tính bảo vệ, răn đe và phát hiện. Việc phát hiện và ngăn chặn cuộc tấn công ở cấp thiết bị có thể ngăn đối thủ truy cập dữ liệu nhạy cảm hoặc phá vỡ các dịch vụ quan trọng.
    • 4.4.C.3 False positives so với khả năng dễ dàng vượt qua phát hiện là một yếu tố trong việc đánh giá tác động của phương pháp phát hiện. Hầu hết các công cụ phát hiện cấp thiết bị đều dựa trên chữ ký, và phát hiện dựa trên chữ ký có tỷ lệ false positives thấp. Tuy nhiên, phát hiện dựa trên chữ ký dễ bị đối thủ vượt qua hơn.

    Mục tiêu học tập 4.4.D: Áp dụng các kỹ thuật phát hiện để xác định các chỉ báo của cuộc tấn mật khẩu bằng cách phân tích tệp nhật ký.

    • 4.4.D.1 Các cuộc tấn mật khẩu trực tuyến có thể được phát hiện trong nhật ký xác thực. Một người dùng duy nhất cố gắng nhập nhiều mật khẩu sai là chỉ báo của cuộc tấn mật khẩu trực tuyến. Nếu cơ sở dữ liệu hash mật khẩu: người dùng đã bị xâm phạm, tất cả mật khẩu người dùng trong cơ sở dữ liệu nên được coi là không an toàn và tất cả người dùng nên bị buộc phải đặt lại mật khẩu của họ.
    • 4.4.D.2 Nếu một người dùng được ủy quyền đang đăng nhập từ một vị trí hoặc địa chỉ IP khác với dự kiến, hoặc vào thời điểm khác so với bình thường, điều này có thể là chỉ báo cho thấy mật khẩu của người dùng đã bị xâm phạm.
    • 4.4.D.3 Một chỉ báo của việc phun mật khẩu là nhiều người dùng cố gắng đăng nhập trong vài giây liên tiếp từ cùng một địa chỉ IP hoặc từ các địa chỉ IP bất thường.
    • 4.4.D.4 Một chỉ báo của việc nhồi credentia (credential stuffing) là một loạt các kết hợp user:password mặc định đang được thử nghiệm trên một thiết bị trong thời gian ngắn, thường từ cùng một địa chỉ IP.
    • 4.4.D.5 Các cuộc tấn mật khẩu ngoại tuyến không thể được phát hiện, vì cuộc tấn công diễn ra trên máy tính của đối thủ.

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    Devices log logins, file changes, and processes, and these logs reveal an indicator of compromise (IoC) 入侵指标 - evidence that an adversary got in. Host-based IoCs show up as unexpected processes or changed settings; file-based IoCs are files whose hash matches known malware; behaviour-based IoCs are things like many failed logins or unusual login times.

    Choosing a detection method means weighing performance (signature-based is lighter, better for weak devices), cost (an endpoint detection and response (EDR) 端点检测与响应 service is powerful but expensive), and how sensitive the device is. Reading authentication logs exposes password attacks: many wrong passwords for one user signals a guessing attack; many users failing from one IP signals password spraying; a burst of default credentials signals credential stuffing. Offline attacks, though, cannot be detected - they happen on the adversary's own computer.

    Speed is itself a security factor. Signature-based detection compares what it sees against a list of known-bad patterns, so it is faster than anomaly-based detection, which must first learn what normal looks like and then measure every event against that model. Anomaly-based detection catches attacks that have no signature yet, but it costs far more processing power — and on a device that lacks it, the effect compounds: the detection runs slowly, the device degrades, and the method ends up not being implemented effectively at all.

    Vocabulary · ⁨Từ vựng⁩ Train · ⁨Luyện tập⁩
    English Tiếng Việt
    indicator of compromise (IoC)/ˈɪndɪkeɪtə ɒv ˈkɒmprəmaɪz/ chỉ báo xâm nhập (IoC)
    endpoint detection and response (EDR)/endˈpɔɪnt dɪˈtekʃn ænd rɪˈspɒns/ phát hiện và ứng phó điểm cuối (EDR)
    4.4

    Exam tips

    • Know each malware type by its defining trait: a worm self-spreads, a virus needs a user, ransomware encrypts for money, a RAT gives remote control, a rootkit hides.
    • A hash is one-way and fixed-length; salt makes identical passwords hash differently. Never say a service "stores the password" - it stores the salted hash.
    • Name real algorithms: SHA-256/SHA-512 are current; MD5 and SHA-1 are deprecated because efficient collision attacks exist.
    • Match the password attack to its log signature: one user + many wrong passwords = guessing; many users + one IP = spraying; default credentials = stuffing.
    • Sort authentication factors into know / have / are / where, and remember MFA combines two or more - a fingerprint plus a password, not two passwords.
    • Offline password attacks cannot be detected because the cracking happens on the adversary's machine - a favourite exam "gotcha".
  • 5

    Securing Applications and Data · ⁨Bảo vệ Ứng dụng và Dữ liệu⁩

    Watch lesson · ⁨Xem bài học⁩
    5.1

    Application and Data Vulnerabilities and Attacks · ⁨Lỗ hổng và Cuộc tấn Công vào Ứng dụng và Dữ liệu⁩

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 5.1.A: Explain how adversaries can exploit application and file vulnerabilities to cause loss, damage, disruption, or destruction.

    • 5.1.A.1 An adversary can read any unencrypted files if they have access to the device or drive storing the files.
    • 5.1.A.2 Computers have standard users and administrative users. Administrative users have access to control system settings and can typically access any files or applications on a system. If regular users are given administrative privileges on a computer, and an adversary can compromise a user’s account, then the adversary will have elevated privileges on the system.
    • 5.1.A.3 When access control settings are weakly configured, many users often have permission to view and sometimes even edit files on a system. Adversaries can take advantage of weak access control settings to steal or destroy files or disrupt an application.

    Learning Objective 5.1.B: Explain how application attacks exploit vulnerabilities.

    • 5.1.B.1 Applications are programs that run instructions on computers; they are executable data. Some applications run locally on a user’s computer, while other applications, like web applications, run on a server and are accessed by users through a network.
    • 5.1.B.2 Many applications take user input through open-ended input fields where users can type characters (e.g., letters, numbers, punctuation). Developers should include user input checks in their application, such as numeric input when asked for a number of items, to ensure that the user input matches what is expected; the application should reject input outside of the expected parameters. This process of verifying that user input meets expected criteria before processing it is called data validation. Applications that fail to validate user input are vulnerable to injection-type attacks, where adversaries insert unexpected character strings in input fields to alter the behavior of a program.
    • 5.1.B.3 Structured query language (SQL) is a computer language used to request information from databases and make changes to databases or entries in databases. Applications that query a database using unvalidated or unsanitized input from users are vulnerable.
    • 5.1.B.4 An SQL-injection attack places SQL commands and control characters into a user-input field in an application, which can lead to a breach of confidentiality by causing the application to return more information than it should, or a breach of integrity by modifying or deleting data in the database.
    • 5.1.B.5 Websites are written using hypertext markup language (HTML), and many websites use Javascript to create dynamic content on websites or web applications. Because Javascript commands run in the browser of the user visiting the website, those commands can access sensitive data stored in the browser like usernames, passwords, and cryptographic keys.
    • 5.1.B.6 A cross site scripting (XSS) attack injects malicious code into a website that a user’s browser then executes. The malicious code can be embedded in a link the user clicks (a Type I or Reflected XSS attack) or it can be inserted onto a website through a comment field, forum post, or visitor log, which would affect any user visiting that website (a Type II or Stored XSS attack).
    • 5.1.B.7 When applications take user input, that input is written to a buffer. A buffer is a designated section of computer memory with a fixed size. If the amount of data the user enters exceeds the size of the buffer, it can overflow into adjacent memory locations and overwrite other parts of the computer’s memory.
    • 5.1.B.8 A buffer overflow attack feeds more data into memory than was allotted, which can cause a system to crash or to execute code outside the scope of a program’s security policy, effectively allowing the adversary to perform unauthorized actions on a computer, such as accessing, modifying, or deleting files.
    • 5.1.B.9 The files that run web applications are stored in directories on servers. When users access web applications, their browsers send GET requests using hypertext transfer protocol (HTTP). A GET request accesses a file somewhere in the filesystem of the server.
    • 5.1.B.10 In a directory traversal attack, adversaries modify URLs and GET requests to attempt to access sensitive data (e.g., usernames and passwords) on a server’s file system.
      • Illustrative examples for 5.1.B.10:
        • A web server stores images for a website it hosts in the /var/www/images/ directory. An adversary modifies a URL requesting an image to ../../../etc/passwd. The .. moves one directory up in the file system; so the three consecutive .. returns the path to the root, and from there the adversary is attempting to access the passwd file that would return a list of all the authorized usernames on the device.

    Learning Objective 5.1.C: Assess and document risks from application and data vulnerabilities.

    • 5.1.C.1 Data security risks can involve a compromise of confidentiality when unauthorized persons can access sensitive data, integrity when data can be manipulated or altered from its intended state, and availability when data can be destroyed or encrypted to prevent others from accessing it.
    • 5.1.C.2 High risks from data vulnerabilities often involve highly sensitive data (e.g., data that is governed by laws or regulations) that could be compromised through a highly likely exploit.
      • Illustrative examples for 5.1.C.2:
        • The company developing the next jet engine that will be used by the Air Force in its planes is storing the technical specifications for the engine on an unencrypted drive.
    • 5.1.C.3 Moderate risks from data vulnerabilities often involve sensitive data not having strong enough encryption or strict enough access controls.
      • Illustrative examples for 5.1.C.3:
        • A company stores its customers’ PII in a spreadsheet, and the spreadsheet is encrypted using a small key.
    • 5.1.C.4 Low risks from data vulnerabilities often involve less sensitive information being encrypted with shorter keys or having access controls that are not strict enough.
      • Illustrative examples for 5.1.C.4:
        • An organization’s CEO stores his private memos to his executive staff on a company share drive that is unencrypted and has no access controls.
    Tiếng Việt

    Mục tiêu học tập 5.1.A: Giải thích cách đối thủ có thể khai thác lỗ hổng ứng dụng và tệp để gây mất mát, hư hỏng, gián đoạn hoặc phá hủy.

    • 5.1.A.1 Đối thủ có thể đọc bất kỳ tệp không được mã hóa nào nếu họ có quyền truy cập vào thiết bị hoặc ổ đĩa lưu trữ các tệp đó.
    • 5.1.A.2 Máy tính có người dùng tiêu chuẩn và người dùng quản trị. Người dùng quản trị có quyền truy cập để điều khiển các cài đặt hệ thống và thường có thể truy cập bất kỳ tệp tin hoặc ứng dụng nào trên hệ thống. Nếu người dùng thông thường được cấp quyền quản trị trên máy tính, và một kẻ tấn công có thể chiếm đoạt tài khoản của người dùng đó, thì kẻ tấn công sẽ có quyền hạn nâng cao trên hệ thống.
    • 5.1.A.3 Khi các cài đặt kiểm soát truy cập được cấu hình yếu, nhiều người dùng thường có quyền xem và đôi khi cả chỉnh sửa các tệp tin trên hệ thống. Kẻ tấn công có thể lợi dụng các cài đặt kiểm soát truy cập yếu để đánh cắp, phá hủy tệp tin hoặc làm gián đoạn một ứng dụng.

    Mục tiêu học tập 5.1.B: Giải thích cách các cuộc tấn công vào ứng dụng khai thác lỗ hổng bảo mật.

    • 5.1.B.1 Ứng dụng là các chương trình chạy các lệnh trên máy tính; chúng là dữ liệu có thể thực thi. Một số ứng dụng chạy cục bộ trên máy tính của người dùng, trong khi các ứng dụng khác, như ứng dụng web, chạy trên máy chủ và được người dùng truy cập thông qua mạng lưới.
    • 5.1.B.2 Nhiều ứng dụng nhận đầu vào từ người dùng thông qua các trường nhập liệu mở rộng, nơi người dùng có thể gõ ký tự (ví dụ: chữ cái, số, dấu câu). Các nhà phát triển nên bao gồm các kiểm tra đầu vào người dùng trong ứng dụng của họ, chẳng hạn như yêu cầu đầu vào số khi cần số lượng mặt hàng, để đảm bảo đầu vào người dùng khớp với những gì mong đợi; ứng dụng nên từ chối đầu vào nằm ngoài tham số mong đợi. Quá trình xác minh rằng đầu vào người dùng đáp ứng các tiêu chí mong đợi trước khi xử lý nó được gọi là xác thực dữ liệu. Các ứng dụng không xác thực được đầu vào người dùng sẽ dễ bị các cuộc tấn công kiểu chèn, nơi kẻ tấn công chèn chuỗi ký tự không mong muốn vào các trường nhập liệu để thay đổi hành vi của chương trình.
    • 5.1.B.3 Ngôn ngữ truy vấn có cấu trúc (SQL) là ngôn ngữ máy tính được sử dụng để yêu cầu thông tin từ cơ sở dữ liệu và thực hiện các thay đổi đối với cơ sở dữ liệu hoặc các mục trong cơ sở dữ liệu. Các ứng dụng truy vấn cơ sở dữ liệu bằng cách sử dụng đầu vào không được xác thực hoặc không được loại bỏ đặc biệt an toàn từ người dùng sẽ dễ bị tổn thương.
    • 5.1.B.4 Một cuộc tấn công chèn SQL đưa các lệnh SQL và ký tự điều khiển vào một trường nhập liệu của người dùng trong ứng dụng, điều này có thể dẫn đến vi phạm tính bảo mật bằng cách khiến ứng dụng trả về nhiều thông tin hơn mức cho phép, hoặc vi phạm tính toàn vẹn bằng cách sửa đổi hoặc xóa dữ liệu trong cơ sở dữ liệu.
    • 5.1.B.5 Các trang web được viết bằng ngôn ngữ đánh dấu siêu văn bản (HTML), và nhiều trang web sử dụng Javascript để tạo nội dung động trên trang web hoặc ứng dụng web. Vì các lệnh Javascript chạy trong trình duyệt của người dùng đang truy cập trang web, các lệnh đó có thể truy cập dữ liệu nhạy cảm được lưu trữ trong trình duyệt như tên người dùng, mật khẩu và khóa mã hóa.
    • 5.1.B.6 Một cuộc tấn công chèn mã xuyên trang (XSS) chèn mã độc hại vào một trang web mà sau đó trình duyệt của người dùng sẽ thực thi. Mã độc hại có thể được nhúng vào liên kết mà người dùng nhấp vào (cuộc tấn công XSS phản xạ Type I hoặc Reflected XSS) hoặc nó có thể được chèn vào trang web thông qua trường bình luận, bài đăng diễn đàn hoặc nhật ký khách访问, điều này sẽ ảnh hưởng đến bất kỳ người dùng nào truy cập trang web đó (cuộc tấn công XSS lưu trữ Type II hoặc Stored XSS).
    • 5.1.B.7 Khi các ứng dụng nhận đầu vào từ người dùng, đầu vào đó được ghi vào bộ đệm. Bộ đệm là một phần bộ nhớ máy tính được chỉ định với kích thước cố định. Nếu lượng dữ liệu người dùng nhập vào vượt quá kích thước của bộ đệm, nó có thể tràn sang các vị trí bộ nhớ liền kề và ghi đè lên các phần khác của bộ nhớ máy tính.
    • 5.1.B.8 Một cuộc tấn công tràn bộ đệm cung cấp nhiều dữ liệu vào bộ nhớ hơn mức được phân bổ, điều này có thể khiến hệ thống bị treo hoặc thực thi mã nằm ngoài phạm vi chính sách bảo mật của chương trình, về cơ bản cho phép kẻ tấn công thực hiện các hành vi trái phép trên máy tính, chẳng hạn như truy cập, sửa đổi hoặc xóa tệp tin.
    • 5.1.B.9 Các tệp chạy ứng dụng web được lưu trữ trong các thư mục trên máy chủ. Khi người dùng truy cập ứng dụng web, trình duyệt của họ gửi yêu cầu GET bằng giao thức truyền tải siêu văn bản (HTTP). Yêu cầu GET truy cập vào một tệp ở đâu đó trong hệ thống tệp của máy chủ.
    • 5.1.B.10 Trong cuộc tấn công duyệt thư mục, kẻ tấn công sửa đổi URL và yêu cầu GET để cố gắng truy cập dữ liệu nhạy cảm (ví dụ: tên người dùng và mật khẩu) trên hệ thống tệp của máy chủ.
      • Ví dụ minh họa cho 5.1.B.10:
        • Một máy chủ web lưu trữ hình ảnh cho một trang web mà nó托管 trong thư mục /var/www/images/. Một kẻ tấn công sửa đổi URL yêu cầu một hình ảnh thành ../../../etc/passwd. Hai chấm .. di chuyển lên một thư mục trong hệ thống tệp; vì vậy, ba dấu .. liên tiếp trả về đường dẫn đến gốc, và từ đó kẻ tấn công đang cố truy cập tệp passwd sẽ trả về danh sách tất cả các tên người dùng được ủy quyền trên thiết bị.

    Mục tiêu học tập 5.1.C: Đánh giá và ghi lại rủi ro từ các lỗ hổng bảo mật ứng dụng và dữ liệu.

    • 5.1.C.1 Rủi ro bảo mật dữ liệu có thể bao gồm sự xâm phạm tính bảo mật khi những người không có thẩm quyền truy cập dữ liệu nhạy cảm, tính toàn vẹn khi dữ liệu có thể bị thao túng hoặc thay đổi so với trạng thái ban đầu, và khả năng sẵn có khi dữ liệu có thể bị phá hủy hoặc mã hóa để ngăn người khác truy cập vào nó.
    • 5.1.C.2 Rủi ro cao từ các lỗ hổng dữ liệu thường liên quan đến dữ liệu cực kỳ nhạy cảm (ví dụ: dữ liệu chịu sự điều tiết bởi luật pháp hoặc quy định) có thể bị xâm phạm thông qua việc khai thác rất có khả năng xảy ra.
      • Ví dụ minh họa cho 5.1.C.2:
        • Công ty đang phát triển động cơ phản lực tiếp theo sẽ được Không quân sử dụng trong máy bay của họ đang lưu trữ các thông số kỹ thuật của động cơ trên ổ đĩa chưa được mã hóa.
    • 5.1.C.3 Rủi ro trung bình từ các lỗ hổng dữ liệu thường liên quan đến dữ liệu nhạy cảm không có độ mã hóa đủ mạnh hoặc kiểm soát truy cập đủ nghiêm ngặt.
      • Ví dụ minh họa cho 5.1.C.3:
        • Một công ty lưu trữ PII của khách hàng trong một bảng tính, và bảng tính đó được mã hóa bằng một khóa nhỏ.
    • 5.1.C.4 Rủi ro thấp từ các lỗ hổng dữ liệu thường liên quan đến việc mã hóa thông tin ít nhạy cảm hơn bằng khóa ngắn hoặc có kiểm soát truy cập không đủ nghiêm ngặt.
      • Ví dụ minh họa cho 5.1.C.4:
        • CEO của một tổ chức lưu trữ các bản ghi nhớ riêng tư gửi nhân viên điều hành trên ổ chia sẻ công ty không được mã hóa và không có kiểm soát truy cập nào.

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    English
    SQL injection

    Applications 应用程序 are the programs that run on computers, and data is what they process - both are prime targets. If files are stored unencrypted, anyone with access to the drive can read them. If a normal user is given administrative 管理性 privileges, an adversary who steals that account gains sweeping power.

    The biggest application danger is bad user input. When a program does not check what a user types, an adversary can slip in commands - an injection attack 注入攻击. Data validation 数据验证 (checking input meets expected rules) is the defense. Key attacks:

    • SQL injection SQL注入 - inserting SQL commands into an input field to read or change a database.
    • Cross-site scripting (XSS) 跨站脚本 - injecting malicious script into a website that runs in another user's browser.

    What a SQL injection actually looks like

    SQL is a language for querying a database, and its control words are always written in capital letters — SELECT, FROM, WHERE, IN, OR, AND. A login form usually builds a query by pasting what you typed into one:

    An attacker types SQL into the field instead of a name. Two tricks do most of the damage:

    • A condition that is always true. Entering ' OR '1'='1 makes the WHERE clause true for every row, so the database returns every user.
    • A double dash, which begins a comment in SQL. Entering admin' -- ends the name string and comments out the whole rest of the line, including the password check, so the query becomes … WHERE name = 'admin' and the attacker is logged in as the administrator without a password.

    The defence is not to filter for the word SELECT. It is to stop the input being treated as code at all: use parameterised queries 参数化查询 (also called prepared statements), where the database is given the query and the values separately and never mixes them, and add input validation to reject characters the field has no reason to contain.

    • Buffer overflow 缓冲区溢出 - sending more data than a memory buffer 缓冲区 can hold, so it overflows into nearby memory and may run the adversary's code.
    • Directory traversal 目录遍历 - using ../ sequences in a URL to reach files outside the intended folder, such as /etc/passwd.

    We rate data risk by sensitivity: unencrypted military plans are high risk; customer data with a weak key is moderate; low-value data with short keys is low.

    Tiếng Việt
    Xâm nhập SQL

    Ứng dụng là các chương trình chạy trên máy tính, và dữ liệu là thứ chúng xử lý - cả hai đều là mục tiêu hàng đầu. Nếu tệp được lưu trữ không được mã hóa, bất kỳ ai có quyền truy cập ổ đĩa cũng có thể đọc chúng. Nếu một người dùng thường được cấp quyền quản trị viên, kẻ tấn công đánh cắp tài khoản đó sẽ có quyền kiểm soát toàn diện.

    Nguy hiểm lớn nhất đối với ứng dụng là dữ liệu đầu vào của người dùng kém an toàn. Khi chương trình không kiểm tra những gì người dùng nhập, kẻ tấn công có thể chèn lệnh - một cuộc tấn công nhúng. Xác thực dữ liệu (kiểm tra đầu vào tuân thủ các quy tắc mong đợi) là biện pháp phòng vệ. Các cuộc tấn công chính:

    • Xâm nhập SQL: Chèn các lệnh SQL vào trường nhập liệu để đọc hoặc thay đổi cơ sở dữ liệu.
    • Tấn công script xuyên trang (XSS): Nhúng mã độc vào website chạy trên trình duyệt của người dùng khác.

    Một cuộc xâm nhập SQL thực tế trông như thế nào

    SQL là ngôn ngữ truy vấn cơ sở dữ liệu, và các từ khóa điều khiển luôn được viết hoa — SELECT, FROM, WHERE, IN, OR, AND. Một biểu mẫu đăng nhập thường xây dựng truy vấn bằng cách dán nội dung bạn nhập vào một:

    SELECT * FROM users WHERE name = 'alice' AND password = 'secret'
    

    Kẻ tấn công nhập SQL vào trường thay vì tên. Hai thủ thuật gây ra hầu hết thiệt hại:

    • Một điều kiện luôn đúng. Nhập ' OR '1'='1 khiến mệnh đề WHERE đúng cho mọi dòng, do đó cơ sở dữ liệu trả về tất cả người dùng.
    • Hai dấu gạch ngang, bắt đầu một chú thích trong SQL. Nhập admin' -- kết thúc chuỗi tên và comment cả phần còn lại của dòng, bao gồm cả kiểm tra mật khẩu, nên truy vấn trở thành … WHERE name = 'admin' và kẻ tấn công đăng nhập với tư cách quản trị viên mà không cần mật khẩu.

    Biện pháp phòng vệ không phải là lọc từ SELECT. Đó là ngăn chặn đầu vào được coi là mã: sử dụng truy vấn tham số (còn gọi là câu lệnh chuẩn bị sẵn), nơi cơ sở dữ liệu nhận được truy vấn và các giá trị riêng biệt và không bao giờ trộn lẫn chúng, và thêm xác thực đầu vào để từ chối các ký tự mà trường không có lý do gì để chứa đựng.

    • Vượt bộ nhớ đệm: Gửi nhiều dữ liệu hơn bộ nhớ đệm có thể chứa, khiến nó tràn sang bộ nhớ lân cận và có thể chạy mã của kẻ tấn công.
    • Duyệt thư mục: Sử dụng ../ trong URL để truy cập các tệp ngoài thư mục dự định, chẳng hạn như /etc/passwd.

    Chúng tôi đánh giá rủi ro dữ liệu theo mức độ nhạy cảm: kế hoạch quân sự không được mã hóa là rủi ro cao; dữ liệu khách hàng có khóa yếu là vừa phải; dữ liệu ít giá trị với khóa ngắn là thấp.

    Vocabulary · ⁨Từ vựng⁩ Train · ⁨Luyện tập⁩
    English Tiếng Việt
    SQL injection/ˌes kjuː ˈel ɪnˈdʒekʃn/ Inject SQL
    Watch lesson · ⁨Xem bài học⁩
    5.2

    Protecting Applications and Data: Managerial Controls and Access Controls · ⁨Bảo vệ Ứng dụng và Dữ liệu: Kiểm soát Quản trị và Kiểm soát Truy cập⁩

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 5.2.A: Explain how the state or classification of data impacts the type and degree of security applied to that data.

    • 5.2.A.1 Organizations implement specific security controls to comply with legal requirements based on the types of data they collect, store, process, and transmit.
    • 5.2.A.2 Data can be classified by their state.
      • Data at rest are stored on a drive. It is important to protect the physical drive storing the data from destruction or theft. Data at rest can also be encrypted so that if an adversary steals it, they can’t immediately read the data.
      • Data in transit are being sent from one device to another. If the data are being transferred over physical media (e.g., cables) it is important to protect the media. Data in transit can also be encrypted so that if an adversary intercepts it, they can’t immediately read the data.
      • Data in use are being processed by software or a person. Access controls can be used to limit who or what has the ability to use data in different ways (e.g., view or edit). Data must be unencrypted to be used.
    • 5.2.A.3 Organizations often categorize data according to their sensitivity and prioritize a higher degree of security for more sensitive information.
    • 5.2.A.4 Laws and regulations can require certain types of data to be stored, transmitted, and handled according to specific rules.
      • Personally identifiable information (PII) is any data that allows someone to be identified and includes (but is not limited to): name, signature, phone number, address, biometric data (e.g., fingerprints), social security number, date of birth, and email address. The protection of this data is covered by many laws but most notably The Privacy Act of 1974 and for children under the age of 13 the Children’s Online Privacy Protection Act of 1998.
      • Protected health information (PHI) is any data related to an individual’s health, treatment, payment for healthcare at any time and includes (but is not limited to): test results, treatment records, hospital records, doctor visit notes, and health provider payment records. The protection of PHI is included in the Health Insurance Portability and Accountability Act of 1996.
      • Payment card information (PCI) is the data collected by organizations to process payments via cards (e.g., credit cards) and includes the following: name, account number, expiration date, address, and CVV code. The protection of this data is regulated by the Payment Card Industry Data Security Standard (PCI-DSS).
    • 5.2.A.5 Organizations that collect regulated data will label them and have policies that comply with the legal or regulatory requirements for the safe storage, transmission, and handling of these data.

    Learning Objective 5.2.B: Identify managerial controls related to application and data security.

    • 5.2.B.1 A cryptography policy will describe the acceptable encryption protocols and key parameters for an organization and may include:
      • A list of encryption algorithms approved for specific uses
      • Minimum or maximum key lengths
      • Cryptographic key-generation requirements and parameters
      • Cryptographic key-storage requirements
    • 5.2.B.2 A web application security policy will outline the requirements and parameters for testing and mitigating web application vulnerabilities in an organization, and it may include:
      • Parameters for when an application is subject to a security assessment
      • Timelines for remediating vulnerabilities based on level of risk
      • Parameters for how an application security assessment is to be carried out (e.g., using specific tools or according to specific frameworks)

    Learning Objective 5.2.C: Determine an appropriate access control model to protect applications and data.

    • 5.2.C.1 Access control enforces which users or applications (called subjects) can access, modify, add, or remove (called operations) which files or applications (called objects). Access control models describe how to determine which subjects have what type of access to which objects.
    • 5.2.C.2 Role-based access control (RBAC) assigns every subject to a role and defines which roles have which types of access to which objects.
      • Illustrative examples for 5.2.C.2:
        • An example of a role at a company might be “accountant,” and one type of object could be the payroll software. Role-based access could be used to ensure that only subjects who are assigned to the role of “accountant” have access to the payroll software object.
    • 5.2.C.3 Rule-based access control (RuBAC) checks a set of rules to determine what type of access a subject should have for a specific object and then allows or denies types of access based on the rules. This access control model is typically layered on top of another access control model.
      • Illustrative examples for 5.2.C.3:
        • There is a rule that prohibits subjects (even those who would normally have access) from accessing a certain database (the object) outside of local working hours. When a subject attempts to access the database, even if they are authorized to access it, they will be denied access if it is outside the time designated by the rule.
    • 5.2.C.4 Discretionary access control (DAC) gives individual subjects the ability to set the type of access that other subjects have on objects they own. In DAC models some subjects are designated as administrators or super users, and they have the ability to override the access controls established by other subjects.
      • Illustrative examples for 5.2.C.4:
        • Bob creates a file (an object) and decides to give Alice permission to edit the file, to give Frank permission to view the file only, and to deny everyone else access to the file altogether.
    • 5.2.C.5 Mandatory access control (MAC) follows strict rules for which types of access each subject level has for objects that are above their level, at their level, or below their level. Subject and object levels are assigned by an external administrator.
    • 5.2.C.6 The Bell-LaPadula model is a MAC model that is often used by governments and military organizations to control the security of information. This model has the following two important properties:
      • i. The Simple Security Property states that subjects may not read objects that are above their level.
      • ii. The * (Star) Security Property states that subjects may not write to objects below their level.
      • These rules taken together are often summarized as “write up, read down” (WURD).
    • 5.2.C.7 The principle of least privilege is the idea that entities should be given exactly as much access as they need to perform their function and no more.

    Learning Objective 5.2.D: Configure access control settings on a Linux-based system.

    • 5.2.D.1 Authorization is when an entity is granted permission to have a certain type of access to a resource. Access controls are put in place to control which users have what types of access to which data.
    • 5.2.D.2 There are three types of access to a file in Linux that can be set, and they always come in the following order:
      • i. Read access allows a user to view the contents of a file.
      • ii. Write access allows a user to make changes to a file.
      • iii. Execute access allows a user to run a binary file such as a program.
      • These are abbreviated rwx, respectively. If a user only has read and execute permissions (not write), then it would display as r-x. The - symbol indicates the absence of that permission.
    • 5.2.D.3 There are three default entities for which permissions are set and always in this order: (1) the file owner, (2) the file group, and (3) all other users. The three sets are displayed with no spaces (e.g., rwxrwxrwx).
    • 5.2.D.4 To view the current permission settings for a file, use the command ls -l, which will show the current settings for the default entities. If there is a + symbol at the end of the permissions, this means that other permissions have been set for that file and it can be viewed with the getfacl command.
    • 5.2.D.5 To modify the permission settings for a file, use the chmod command. This command can be used with the numeric method or the symbolic method.
    • 5.2.D.6 To use chmod in the numeric method the syntax is chmod ### filename. Each of the three ### represents one of the three entities mentioned above (the owner, the group, other nongroup users).
      • The first # = the owner
      • The second # = the group
      • The third # = other nongroup users
      • The permission for each entity is determined by adding up the values for the types of access to be granted:
      • 0 = no permissions
      • 1 = execute
      • 2 = write
      • 4 = read
      • Therefore 3 sets permission to write and execute, 5 sets permission to read and execute, 6 sets permission to read and write, and 7 sets permission to read, write, and execute.
      • Illustrative examples for 5.2.D.6:
        • The command chmod 750 test would set the permissions for the owner to read, write, and execute, for the group to read and execute, and for everyone else to no access at all.
        • The command chmod 543 test would set the permissions for the owner to read and execute, for the group to read only, and for everyone else to write and execute.
        • The command chmod 777 test would set the permissions for all three entities to read, write, and execute for the file test.
    • 5.2.D.7 To use chmod in the symbolic method the syntax is chmod entity +(or –) permission filename. The entities are the user owner, the group, and other nongroup users. Each entity is represented with a single letter.
      • u = user owner
      • g = group
      • o = others
      • a = all
      • Permission can be either added or removed to any combination of entities.
        • = add the permission
      • – = remove the permission
      • The permissions that can be set are read, write, and execute.
      • r = read
      • w = write
      • x = execute
      • Entities and permissions can be combined in a single command. To add the read and execute permissions for the group and user owner for a file called testfile, the command would be chmod ug+rx testfile.
    Tiếng Việt

    Mục tiêu Học tập 5.2.A: Giải thích cách trạng thái hoặc phân loại dữ liệu ảnh hưởng đến loại và mức độ bảo mật áp dụng cho dữ liệu đó.

    • 5.2.A.1 Các tổ chức triển khai các kiểm soát bảo mật cụ thể để tuân thủ yêu cầu pháp lý dựa trên các loại dữ liệu họ thu thập, lưu trữ, xử lý và truyền tải.
    • 5.2.A.2 Dữ liệu có thể được phân loại theo trạng thái của chúng.
      • Dữ liệu khi nghỉ (at rest) được lưu trữ trên ổ đĩa. Việc bảo vệ vật lý ổ đĩa chứa dữ liệu khỏi bị phá hủy hoặc đánh cắp là rất quan trọng. Dữ liệu khi nghỉ cũng có thể được mã hóa để nếu kẻ tấn công lấy trộm nó, họ sẽ không thể đọc ngay lập tức dữ liệu đó.
      • Dữ liệu khi truyền (in transit) đang được gửi từ thiết bị này sang thiết bị khác. Nếu dữ liệu được chuyển qua phương tiện vật lý (ví dụ: cáp), việc bảo vệ phương tiện đó là rất quan trọng. Dữ liệu khi truyền cũng có thể được mã hóa để nếu kẻ tấn công chặn đứng nó, họ sẽ không thể đọc ngay lập tức dữ liệu đó.
      • Dữ liệu khi sử dụng (in use) đang được phần mềm hoặc con người xử lý. Kiểm soát truy cập có thể được sử dụng để hạn chế ai hoặc cái gì có khả năng sử dụng dữ liệu theo các cách khác nhau (ví dụ: xem hoặc chỉnh sửa). Dữ liệu phải được giải mã để có thể sử dụng.
    • 5.2.A.3 Các tổ chức thường phân loại dữ liệu theo mức độ nhạy cảm và ưu tiên mức độ bảo mật cao hơn đối với thông tin nhạy cảm hơn.
    • 5.2.A.4 Luật và quy định có thể yêu cầu một số loại dữ liệu được lưu trữ, truyền tải và xử lý theo các quy tắc cụ thể.
      • Thông tin nhận dạng cá nhân (PII) là bất kỳ dữ liệu nào cho phép xác định một người và bao gồm (nhưng không giới hạn ở): tên, chữ ký, số điện thoại, địa chỉ, dữ liệu sinh trắc học (ví dụ: dấu vân tay), số an sinh xã hội, ngày sinh và địa chỉ email. Việc bảo vệ dữ liệu này được che chở bởi nhiều luật pháp nhưng nổi bật nhất là Đạo luật Bảo mật năm 1974 và đối với trẻ em dưới 13 tuổi là Đạo luật Bảo vệ Quyền riêng tư trực tuyến của Trẻ em năm 1998.
      • Thông tin sức khỏe được bảo vệ (PHI) là bất kỳ dữ liệu nào liên quan đến sức khỏe, điều trị, thanh toán dịch vụ chăm sóc sức khỏe của một cá nhân tại bất kỳ thời điểm nào và bao gồm (nhưng không giới hạn ở): kết quả xét nghiệm, hồ sơ điều trị, hồ sơ bệnh viện, ghi chú thăm khám bác sĩ và hồ sơ thanh toán nhà cung cấp dịch vụ y tế. Việc bảo vệ PHI được bao gồm trong Đạo luật Di chuyển và Trách nhiệm Bảo hiểm Y tế năm 1996.
      • Thông tin thẻ thanh toán (PCI) là dữ liệu được tổ chức thu thập để xử lý thanh toán qua thẻ (ví dụ: thẻ tín dụng) và bao gồm các thông tin sau: tên, số tài khoản, ngày hết hạn, địa chỉ và mã CVV. Việc bảo vệ dữ liệu này được quản lý bởi Tiêu chuẩn Bảo mật Dữ liệu Ngành Thanh toán Thẻ (PCI-DSS).
    • 5.2.A.5 Các tổ chức thu thập dữ liệu được quản lý sẽ gán nhãn cho chúng và có các chính sách tuân thủ các yêu cầu pháp lý hoặc quy định về việc lưu trữ, truyền tải và xử lý an toàn những dữ liệu này.

    Mục tiêu Học tập 5.2.B: Xác định các kiểm soát quản trị liên quan đến bảo mật ứng dụng và dữ liệu.

    • 5.2.B.1 Chính sách mã hóa sẽ mô tả các giao thức mã hóa và tham số khóa được chấp nhận cho một tổ chức và có thể bao gồm:
      • Danh sách các thuật toán mã hóa được phê duyệt cho các mục đích cụ thể
      • Độ dài khóa tối thiểu hoặc tối đa
      • Yêu cầu và tham số tạo khóa mã hóa
      • Yêu cầu lưu trữ khóa mã hóa
    • 5.2.B.2 Chính sách bảo mật ứng dụng web sẽ nêu rõ các yêu cầu và tham số cho việc kiểm tra và khắc phục các lỗ hổng ứng dụng web trong một tổ chức, và có thể bao gồm:
      • Tham số về thời điểm một ứng dụng chịu trách nhiệm đánh giá bảo mật
      • Thời hạn khắc phục lỗ hổng dựa trên mức độ rủi ro
      • Tham số về cách thức tiến hành đánh giá bảo mật ứng dụng (ví dụ: sử dụng các công cụ cụ thể hoặc theo các khung làm việc cụ thể)

    Mục tiêu Học tập 5.2.C: Xác định mô hình kiểm soát truy cập phù hợp để bảo vệ ứng dụng và dữ liệu.

    • 5.2.C.1 Kiểm soát truy cập enforce (thực thi) những người dùng hoặc ứng dụng nào (được gọi là chủ thể) có thể truy cập, sửa đổi, thêm vào hoặc xóa bỏ (được gọi là thao tác) những tệp hoặc ứng dụng nào (được gọi là đối tượng). Các mô hình kiểm soát truy cập mô tả cách xác định những chủ thể nào có loại truy cập gì vào những đối tượng nào.
    • 5.2.C.2 Kiểm soát truy cập theo vai trò (RBAC) gán mỗi chủ thể vào một vai trò và xác định các vai trò nào có loại truy cập nào vào các đối tượng nào.
      • Ví dụ minh họa cho 5.2.C.2:
        • Một ví dụ về vai trò trong công ty có thể là "kế toán viên", và một loại đối tượng có thể là phần mềm trả lương. Kiểm soát truy cập theo vai trò có thể được sử dụng để đảm bảo rằng chỉ những chủ thể được gán vào vai trò "kế toán viên" mới có quyền truy cập vào đối tượng phần mềm trả lương.
    • 5.2.C.3 Kiểm soát truy cập theo quy tắc (RuBAC) kiểm tra một bộ quy tắc để xác định loại truy cập mà một chủ thể nên có cho một đối tượng cụ thể, sau đó cho phép hoặc từ chối các loại truy cập dựa trên các quy tắc này. Mô hình kiểm soát truy cập này thường được lớp phủ lên trên một mô hình kiểm soát truy cập khác.
      • Ví dụ minh họa cho 5.2.C.3:
        • Có một quy tắc cấm các chủ thể (ngay cả những người thường có quyền truy cập) truy cập một cơ sở dữ liệu nhất định (đối tượng) ngoài giờ làm việc tại văn phòng. Khi một chủ thể cố gắng truy cập cơ sở dữ liệu, ngay cả khi họ được ủy quyền truy cập, họ sẽ bị từ chối truy cập nếu đó là ngoài thời gian do quy tắc chỉ định.
    • 5.2.C.4 Điều khiển truy cập tùy chọn (DAC) cho phép các chủ thể cá nhân xác định loại truy cập mà các chủ thể khác có đối với các đối tượng mà họ sở hữu. Trong các mô hình DAC, một số chủ thể được chỉ định là quản trị viên hoặc siêu người dùng, và họ có khả năng bỏ qua các điều khiển truy cập do các chủ thể khác thiết lập.
      • Ví dụ minh họa cho 5.2.C.4:
        • Bob tạo một tệp (một đối tượng) và quyết định cấp cho Alice quyền chỉnh sửa tệp, cấp cho Frank quyền xem tệp duy nhất, và từ chối truy cập vào tệp hoàn toàn cho tất cả những người còn lại.
    • 5.2.C.5 Điều khiển truy cập bắt buộc (MAC) tuân theo các quy tắc nghiêm ngặt về các loại truy cập mà mỗi cấp độ chủ thể có đối với các đối tượng ở trên cấp độ của họ, ở cùng cấp độ hoặc dưới cấp độ của họ. Cấp độ chủ thể và đối tượng được phân bổ bởi một quản trị viên bên ngoài.
    • 5.2.C.6 Mô hình Bell-LaPadula là một mô hình MAC thường được chính phủ và các tổ chức quân đội sử dụng để kiểm soát an ninh thông tin. Mô hình này có hai thuộc tính quan trọng sau:
      • i. Thuộc tính An toàn Đơn giản quy định rằng các chủ thể không được đọc các đối tượng nằm trên cấp độ của họ.
      • ii. Thuộc tính An toàn * (Star) quy định rằng các chủ thể không được ghi vào các đối tượng nằm dưới cấp độ của họ.
      • Các quy tắc này khi kết hợp lại thường được tóm tắt là “ghi lên, đọc xuống” (WURD).
    • 5.2.C.7 Nguyên tắc tối thiểu hóa đặc quyền là ý tưởng rằng các thực thể chỉ nên được cấp đúng lượng truy cập cần thiết để thực hiện chức năng của chúng và không nhiều hơn.

    Mục tiêu học tập 5.2.D: Cấu hình cài đặt điều khiển truy cập trên hệ thống dựa trên Linux.

    • 5.2.D.1 Cấp quyền (Authorization) là khi một thực thể được cấp quyền truy cập vào một tài nguyên theo một loại cụ thể. Các điều khiển truy cập được thiết lập để kiểm soát người dùng nào có loại truy cập gì vào dữ liệu nào.
    • 5.2.D.2 Có ba loại truy cập vào một tệp trong Linux có thể được thiết lập, và chúng luôn xuất hiện theo thứ tự sau:
      • i. Truy cập Đọc cho phép người dùng xem nội dung của tệp.
      • ii. Truy cập Ghi cho phép người dùng thay đổi nội dung của tệp.
      • iii. Truy cập Thực thi cho phép người dùng chạy một tệp nhị phân như một chương trình.
      • Những loại này được viết tắt là rwx tương ứng. Nếu người dùng chỉ có quyền Đọc và Thực thi (không có quyền Ghi), thì nó sẽ hiển thị là r-x. Ký hiệu - biểu thị sự vắng mặt của quyền đó.
    • 5.2.D.3 Có ba thực thể mặc định mà quyền được thiết lập và luôn theo thứ tự này: (1) chủ sở hữu tệp, (2) nhóm tệp, và (3) tất cả người dùng khác. Ba bộ này được hiển thị không có khoảng trắng (ví dụ: rwxrwxrwx).
    • 5.2.D.4 Để xem cài đặt quyền hiện tại của một tệp, hãy sử dụng lệnh ls -l, lệnh này sẽ hiển thị các cài đặt hiện tại cho các thực thể mặc định. Nếu có ký hiệu + ở cuối phần quyền, điều này có nghĩa là các quyền khác đã được thiết lập cho tệp đó và có thể xem bằng lệnh getfacl.
    • 5.2.D.5 Để thay đổi cài đặt quyền của một tệp, hãy sử dụng lệnh chmod. Lệnh này có thể được sử dụng với phương pháp số hoặc phương pháp ký hiệu.
    • 5.2.D.6 Để sử dụng chmod theo phương pháp số, cú pháp là chmod ### filename. Mỗi trong số ba ### đại diện cho một trong ba thực thể được đề cập ở trên (chủ sở hữu, nhóm, người dùng phi nhóm khác).
      • đầu tiên = chủ sở hữu

      • thứ hai = nhóm

      • thứ ba = người dùng phi nhóm khác

      • Quyền của mỗi thực thể được xác định bằng cách cộng giá trị của các loại truy cập được cấp:
      • 0 = không có quyền nào
      • 1 = thực thi
      • 2 = ghi
      • 4 = đọc
      • Do đó, 3 thiết lập quyền ghi và thực thi, 5 thiết lập quyền đọc và thực thi, 6 thiết lập quyền đọc và ghi, và 7 thiết lập quyền đọc, ghi và thực thi.
      • Ví dụ minh họa cho 5.2.D.6:
        • Lệnh chmod 750 test sẽ thiết lập quyền cho chủ sở hữu là đọc, ghi và thực thi, cho nhóm là đọc và thực thi, và cho tất cả mọi người khác là không có quyền truy cập nào.
        • Lệnh chmod 543 test sẽ thiết lập quyền cho chủ sở hữu là đọc và thực thi, cho nhóm là đọc duy nhất, và cho tất cả mọi người khác là ghi và thực thi.
        • Lệnh chmod 777 test sẽ thiết lập quyền cho cả ba thực thể là đọc, ghi và thực thi cho tệp test.
    • 5.2.D.7 Để sử dụng chmod theo phương pháp ký hiệu, cú pháp là chmod entity +(or –) permission filename. Các thực thể là chủ sở hữu người dùng, nhóm, và người dùng phi nhóm khác. Mỗi thực thể được đại diện bằng một chữ cái.
      • u = chủ sở hữu người dùng
      • g = nhóm
      • o = người khác
      • a = tất cả
      • Quyền có thể được thêm hoặc xóa khỏi bất kỳ tổ hợp thực thể nào.
        • = thêm quyền
      • – = xóa quyền
      • Các quyền có thể được thiết lập là đọc, ghi và thực thi.
      • r = đọc
      • w = ghi
      • x = thực thi
      • Thực thể và quyền có thể được kết hợp trong một lệnh duy nhất. Để thêm quyền đọc và thực thi cho nhóm và chủ sở hữu người dùng của một tệp tên là testfile, lệnh sẽ là chmod ug+rx testfile.

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    English

    Data is classified by its state - at rest 静态数据 (stored on a drive), in transit 传输中数据 (moving between devices), and in use 使用中数据 (being processed). Data at rest and in transit can be encrypted so a thief cannot read it; data in use must be decrypted, so access controls guard it instead.

    Some data types are regulated 受监管 - the law dictates how they must be stored, transmitted and handled - so an organisation must achieve compliance 合规 by matching its controls to the rules. The exam expects you to pair each data type with its governing law:

    Regulated data What it is Governing law
    personally identifiable information (PII) 个人身份信息 anything identifying a person: name, address, SSN, biometrics, date of birth The Privacy Act (1974); COPPA for under-13s
    protected health information (PHI) 受保护健康信息 health, treatment and healthcare-payment records HIPAA (1996)
    payment card information (PCI) 支付卡信息 card number, expiry, CVV, cardholder name PCI-DSS

    An organisation that collects regulated data must label it and hold policies that keep its storage, transmission and handling compliant - the higher the sensitivity, the higher the required degree of security.

    Access control decides which subjects (users) may perform which operations on which objects (files). Four models:

    • Role-based (RBAC) 基于角色的访问控制 - access follows your role (all "accountants" reach the payroll software).
    • Rule-based (RuBAC) 基于规则的访问控制 - access follows conditions (only during business hours), layered on another model.
    • Discretionary (DAC) 自主访问控制 - the owner of a file decides who else may use it.
    • Mandatory (MAC) 强制访问控制 - a central administrator sets strict levels; the Bell-LaPadula model summarises it as "write up, read down".

    A guiding idea across all models is the principle of least privilege 最小权限原则 - give each entity exactly the access it needs and no more.

    On a Linux system, each file has three permissions - read (r), write (w), execute (x) - for three groups: the owner, the group, and others. The chmod command sets them with numbers, adding 4 (read) + 2 (write) + 1 (execute). So chmod 640 means owner read+write (6), group read (4), others nothing (0).

    Worked example. A principal wants only herself to read and edit a file, her staff group to read it, and no one else to touch it. Read+write = 4+2 = 6 for the owner, read = 4 for the group, nothing = 0 for others, giving chmod 640 file. The listing then shows -rw-r-----. To also let the owner run the file as a program you would add execute (7 = 4+2+1), giving chmod 740.

    Tiếng Việt

    Dữ liệu được phân loại theo trạng thái của nó - khi lưu trữ (được lưu trên ổ đĩa), khi di chuyển (di chuyển giữa các thiết bị), và khi sử dụng (đang được xử lý). Dữ liệu khi lưu trữ và khi di chuyển có thể được mã hóa để kẻ trộm không thể đọc được; dữ liệu khi sử dụng phải được giải mã, nên kiểm soát truy cập sẽ bảo vệ nó thay thế.

    Một số loại dữ liệu bị giám sát bởi luật pháp - luật quy định cách chúng phải được lưu trữ, truyền tải và xử lý - vì vậy tổ chức phải đạt được sự tuân thủ bằng cách điều chỉnh các biện pháp kiểm soát của mình tương ứng với các quy tắc. Kỳ thi yêu cầu bạn ghép mỗi loại dữ liệu với luật điều chỉnh:

    Dữ liệu bị giám sát Nội dung Luật điều chỉnh
    thông tin nhận dạng cá nhân (PII) mọi thứ có thể xác định một người: tên, địa chỉ, số an sinh xã hội, dữ liệu sinh trắc học, ngày sinh Đạo luật Bảo mật (1974); COPPA cho trẻ dưới 13 tuổi
    thông tin sức khỏe được bảo vệ (PHI) hồ sơ về sức khỏe, điều trị và thanh toán dịch vụ y tế HIPAA (1996)
    thông tin thẻ thanh toán (PCI) số thẻ, ngày hết hạn, CVV, tên chủ thẻ PCI-DSS

    Một tổ chức thu thập dữ liệu quy định bắt buộc phải đánh dấu nó và duy trì các chính sách để đảm bảo việc lưu trữ, truyền tải và xử lý tuân thủ - mức độ nhạy cảm càng cao thì yêu cầu về cấp độ bảo mật càng lớn.

    Kiểm soát truy cập quyết định những chủ thể (người dùng) nào được phép thực hiện những thao tác nào trên những đối tượng (tệp tin). Bốn mô hình:

    • Dựa trên vai trò (RBAC) - quyền truy cập dựa vào vai trò của bạn (tất cả "kế toán viên" đều có thể truy cập phần mềm lương).
    • Dựa trên quy tắc (RuBAC) - quyền truy cập tuân theo điều kiện (chỉ trong giờ làm việc), được áp đặt lên trên một mô hình khác.
    • Tự do (DAC) - chủ sở hữu của một tệp tin quyết định ai khác cũng có thể sử dụng nó.
    • Bắt buộc (MAC) - một quản trị viên trung tâm thiết lập các mức độ nghiêm ngặt; mô hình Bell-LaPadula tóm tắt là "ghi lên, đọc xuống".
    Bốn mô hình kiểm soát truy cập quyết định ai tiếp cận đối tượng nào và như thế nào
    Bốn mô hình kiểm soát truy cập quyết định ai tiếp cận đối tượng nào và như thế nào

    Một ý tưởng hướng dẫn xuyên suốt tất cả các mô hình là nguyên tắc tối thiểu đặc quyền - cấp cho mỗi thực thể đúng chính quyền truy cập cần thiết và không nhiều hơn.

    Trên hệ thống Linux, mỗi tệp tin có ba quyền - đọc (r), ghi (w), thực thi (x) - cho ba nhóm: chủ sở hữu, nhóm và khác. Lệnh chmod thiết lập chúng bằng số, cộng 4 (đọc) + 2 (ghi) + 1 (thực thi). Vì vậy, chmod 640 có nghĩa là chủ sở hữu đọc+ghi (6), nhóm đọc (4), không gì cả (0).

    Quyền hạn tệp Linux: đọc/ghi/thực thi cho chủ sở hữu, nhóm và người khác
    Quyền tệp tin Linux: đọc/ghi/thực thi cho chủ sở hữu, nhóm, và khác

    Ví dụ minh họa. Một giáo viên muốn chỉ mình cô ấy mới được đọc và chỉnh sửa một tệp tin, nhóm nhân viên của cô ấy được đọc tệp đó, và không ai khác được chạm vào. Đọc+ghi = 4+2 = 6 cho chủ sở hữu, đọc = 4 cho nhóm, không gì = 0 cho người khác, tạo thành chmod 640 file. Danh sách sau đó sẽ hiển thị -rw-r-----. Để cho phép chủ sở hữu chạy tệp tin như một chương trình, bạn cần thêm quyền thực thi (7 = 4+2+1), tạo ra chmod 740.

    Explore · ⁨Khám phá⁩

    Which access-control model fits the rule? · ⁨Mô hình kiểm soát truy cập nào phù hợp với quy tắc?⁩

    Each access-control model has a different decider: RBAC by your role, RuBAC by a condition, DAC by the file's owner, and MAC by a central administrator's levels. · ⁨Mỗi mô hình kiểm soát truy cập có một người quyết định khác nhau: RBAC dựa trên vai trò của bạn, RuBAC dựa trên một điều kiện, DAC dựa trên chủ sở hữu tệp, và MAC dựa trên cấp độ của quản trị viên trung tâm.⁩

    5.3

    Protecting Stored Data with Cryptography · ⁨Bảo vệ Dữ liệu Lưu trữ bằng Mật mã học⁩

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 5.3.A: Explain how encryption can be used to protect files.

    • 5.3.A.1 The purpose of cryptography is to hide information. A cryptographic algorithm defines a process for encrypting and decrypting information. Encryption is the process of hiding the information, and decryption is the process of reversing the encryption to retrieve the original information.
    • 5.3.A.2 An encryption algorithm defines a process for combining the information to be encrypted with a predefined key. The information to be encrypted is called the plaintext. The output of the encryption algorithm is called the ciphertext.
    • 5.3.A.3 The number of possible keys that can be used in an encryption algorithm is called the keyspace. The larger the keyspace, the longer it will take an adversary to discover the correct key by random chance.
    • 5.3.A.4 Cryptographic algorithms are classified by whether they use one key or two keys.
      • Symmetric encryption algorithms use the same key to encrypt and decrypt information.
      • Asymmetric encryption algorithms use two different keys—one to encrypt information and the other to decrypt information.
    • 5.3.A.5 Cryptographic algorithms are also classified by whether they process information one bit at a time or in fixed-size chunks of bits.
      • Block encryption handles information in fixed-size chunks called blocks, producing an output block for each input block.
      • Stream encryption handles input information continuously, producing output one element at a time.

    Learning Objective 5.3.B: Apply symmetric encryption algorithms to encrypt and decrypt data.

    • 5.3.B.1 Computer-based encryption algorithms operate on binary data. The most common symmetric encryption algorithm is the Advanced Encryption Standard (AES). AES encryption is used to secure Wi-Fi transmissions, internet browsing, file encryption on disks, and hardware-level encryption on processors.
    • 5.3.B.2 AES is a symmetric key block cipher that encrypts data in 128-bit blocks (16 bytes). AES can operate with keys of varying lengths. Longer keys produce more secure encryption but require more time to encrypt and decrypt.
    • 5.3.B.3 Symmetric encryption and decryption can be performed using the command line, specialized software, or web-based tools.
      • On a command line interface, users can encrypt or decrypt with OpenSSL.
      • Specialized software like AES Crypt is an open source tool that can encrypt and decrypt files.
      • There are many web-based tools for encrypting and decrypting files.
    • 5.3.B.4 Using OpenSSL in a CLI, a user can encrypt and decrypt a file using the following commands (note that the encryption key is derived from the password provided):
      • To encrypt a file named test with AES using a 128-bit key, use the command: openssl enc -aes-128-cbc -e -in test -k password -out test.enc
      • To decrypt the encrypted file using the same key, use the command: openssl enc -aes-128-cbc -d -in test.enc -k password -out text
    Tiếng Việt

    Mục tiêu học tập 5.3.A: Giải thích cách mã hóa có thể được sử dụng để bảo vệ tệp.

    • 5.3.A.1 Mục đích của mật mã học là ẩn thông tin. Một thuật toán mật mã học xác định một quy trình để mã hóa và giải mã thông tin. Mã hóa là quá trình ẩn thông tin, và giải mã là quá trình đảo ngược việc mã hóa để lấy lại thông tin gốc.
    • 5.3.A.2 Một thuật toán mã hóa xác định quy trình kết hợp thông tin cần mã hóa với một khóa được định nghĩa trước. Thông tin cần mã hóa được gọi là văn bản rõ (plaintext). Kết quả của thuật toán mã hóa được gọi là văn bản mã hóa (ciphertext).
    • 5.3.A.3 Số lượng khóa có thể sử dụng trong một thuật toán mã hóa được gọi là không gian khóa (keyspace). Không gian khóa càng lớn, thời gian mà kẻ tấn công mất để phát hiện ra khóa chính xác bằng cách ngẫu nhiên sẽ càng dài.
    • 5.3.A.4 Các thuật toán mật mã được phân loại dựa trên việc chúng sử dụng một khóa hay hai khóa.
      • Thuật toán mã hóa đối xứng sử dụng cùng một khóa để mã hóa và giải mã thông tin.
      • Thuật toán mã hóa bất đối xứng sử dụng hai khóa khác nhau—one để mã hóa thông tin và một để giải mã thông tin.
    • 5.3.A.5 Các thuật toán mật mã cũng được phân loại dựa trên việc chúng xử lý thông tin từng bit một hay theo các khối bit có kích thước cố định.
      • Mã hóa khối xử lý thông tin theo các khối có kích thước cố định được gọi là khối, tạo ra một khối đầu ra cho mỗi khối đầu vào.
      • Mã hóa dòng xử lý thông tin đầu vào liên tục, tạo ra đầu ra từng phần tử một.

    Mục tiêu học tập 5.3.B: Áp dụng các thuật toán mã hóa đối xứng để mã hóa và giải mã dữ liệu.

    • 5.3.B.1 Các thuật toán mã hóa dựa trên máy tính hoạt động trên dữ liệu nhị phân. Thuật toán mã hóa đối xứng phổ biến nhất là Tiêu chuẩn Mã hóa Nâng cao (AES). Mã hóa AES được sử dụng để bảo vệ truyền dẫn Wi-Fi, duyệt web, mã hóa tệp trên đĩa và mã hóa ở cấp phần cứng trên bộ xử lý.
    • 5.3.B.2 AES là một mã khối khóa đối xứng mã hóa dữ liệu theo khối 128-bit (16 byte). AES có thể hoạt động với các khóa có độ dài khác nhau. Khóa càng dài thì tạo ra mã hóa an toàn hơn nhưng đòi hỏi nhiều thời gian hơn để mã hóa và giải mã.
    • 5.3.B.3 Mã hóa và giải mã đối xứng có thể thực hiện qua dòng lệnh, phần mềm chuyên dụng hoặc công cụ dựa trên web.
      • Trên giao diện dòng lệnh, người dùng có thể mã hóa hoặc giải mã với OpenSSL.
      • Phần mềm chuyên dụng như AES Crypt là một công cụ mã nguồn mở có thể mã hóa và giải mã tệp.
      • Có rất nhiều công cụ dựa trên web để mã hóa và giải mã tệp.
    • 5.3.B.4 Sử dụng OpenSSL trong CLI, người dùng có thể mã hóa và giải mã một tệp bằng các lệnh sau (lưu ý rằng khóa mã hóa được suy ra từ mật khẩu được cung cấp):
      • Để mã hóa một tệp tên là test với AES sử dụng khóa 128-bit, sử dụng lệnh: openssl enc -aes-128-cbc -e -in test -k password -out test.enc
      • Để giải mã tệp đã mã hóa sử dụng cùng khóa, sử dụng lệnh: openssl enc -aes-128-cbc -d -in test.enc -k password -out text

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    English
    Symmetric vs asymmetric encryption
    Hashing and the avalanche effect

    Cryptography 密码学 hides information. An encryption algorithm combines the plaintext 明文 with a key 密钥 to produce ciphertext 密文; decryption reverses it. The keyspace 密钥空间 is the number of possible keys - the bigger it is, the longer an adversary needs to guess. An n-bit key has a keyspace of $2^n$.

    Symmetric encryption 对称加密 uses the same key to encrypt and decrypt. The standard is AES 高级加密标准, a block cipher 分组密码 that works on 128-bit blocks and secures Wi-Fi, browsing, and stored files. Because both sides need the same secret key, sharing that key safely is the challenge.

    Tiếng Việt
    Máy Enigma: mã hóa bảo vệ dữ liệu được lưu trữ và truyền tải khỏi kẻ nghe lén
    Một máy Enigma: mật mã học bảo vệ dữ liệu lưu trữ và truyền tải khỏi kẻ nghe lén
    Mật mã hóa đối xứng và bất đối xứng
    Hashing và hiệu ứng tuyết lở

    Mật mã học ẩn đi thông tin. Một thuật toán mật mã hóa kết hợp bản rõ với một khóa để tạo ra bản mã; giải mã đảo ngược lại quá trình này. Không gian khóa là số lượng khóa có thể có - càng lớn thì thời gian kẻ thù cần để đoán càng lâu. Một khóa n-bit có không gian khóa là $2^n$.

    Mật mã hóa đối xứng sử dụng cùng một khóa để mã hóa và giải mã. Tiêu chuẩn là AES, một mã khối hoạt động trên các khối 128-bit và bảo vệ Wi-Fi, duyệt web, và tệp tin lưu trữ. Vì cả hai bên đều cần cùng một khóa bí mật, việc chia sẻ khóa đó an toàn là thách thức.

    Máy mã hóa Enigma Thế chiến II kèm khóa và rotor
    Máy Enigma đã xáo trộn tin nhắn bằng các rotor — một ví dụ sớm, có thể bị phá vỡ, của mã hóa
    Explore · ⁨Khám phá⁩

    Encrypt a message by shifting letters · ⁨Mã hóa một thông điệp bằng cách dịch chuyển các chữ cái⁩

    Encryption combines plaintext with a key to make ciphertext. In this simple cipher the key is the shift amount; only someone who knows the shift can decrypt the message back. · ⁨Mã hóa kết hợp văn bản rõ với khóa để tạo thành văn bản mã hóa. Trong thuật ngữ đơn giản này, khóa chính là lượng dịch chuyển; chỉ những ai biết lượng dịch chuyển mới giải mã được thông điệp trở lại.⁩

    Vocabulary · ⁨Từ vựng⁩ Train · ⁨Luyện tập⁩
    English Tiếng Việt
    Applications/ˌæplɪˈkeɪʃnz/ Ứng dụng
    administrative/ədˈmɪnɪstrətɪv/ về hành chính
    injection attack/ɪnˈdʒekʃn əˈtæk/ tấn công nhúng
    Data validation/ˈdeɪtə ˌvælɪˈdeɪʃn/ Xác minh dữ liệu
    Cross-site scripting (XSS)/krɒs saɪt ˈskrɪptɪŋ/ tấn công chèn trang web (XSS)
    parameterised queries/ˌpærəˈmetəraɪzd ˈkwɪərɪz/ truy vấn tham số hóa
    Buffer overflow/ˈbʌfə ˌəʊvəˈfləʊ/ Tràn bộ đệm
    buffer/ˈbʌfə/ dung dịch đệm
    Directory traversal/daɪˈrektəri træˈvɜːsl/ Duyệt thư mục
    at rest/æt rest/ đứng yên
    in transit/ɪn ˈtrænsɪt/ trong quá trình truyền
    in use/ɪn juːs/ đang sử dụng
    regulated/ˈreɡjʊleɪtɪd/ được quy định
    compliance/kəmˈplaɪəns/ tuân thủ
    personally identifiable information (PII)/ˈpɜːsənəli aɪˈdentɪfaɪəbl ˌɪnfəˈmeɪʃn/ thông tin cá nhân có thể xác định được (PII)
    protected health information (PHI)/prəˈtektɪd helθ ˌɪnfəˈmeɪʃn/ thông tin y tế được bảo vệ (PHI)
    payment card information (PCI)/ˈpeɪmənt kɑːd ˌɪnfəˈmeɪʃn/ thông tin thẻ thanh toán (PCI)
    Role-based (RBAC)/rəʊl beɪst/ Dựa trên vai trò (RBAC)
    Rule-based (RuBAC)/ruːl beɪst/ Dựa trên quy tắc (RuBAC)
    Discretionary (DAC)/dɪˈskreʃənəri/ Tùy ý (DAC)
    Mandatory (MAC)/ˈmændətəri/ Bắt buộc (MAC)
    principle of least privilege/ˈprɪnsɪpl ɒv liːst ˈprɪvɪlɪdʒ/ nguyên tắc quyền tối thiểu
    Cryptography/krɪpˈtɒɡrəfi/ Mã hóa
    plaintext/ˈpleɪntekst/ văn bản rõ
    key/kiː/ key
    ciphertext/ˈsaɪfətekst/ văn bản mã hóa
    keyspace/ˈkiːspeɪs/ không gian khóa
    Symmetric encryption/sɪˈmetrɪk enˈkrɪpʃn/ Mã hóa đối xứng
    AES/ˌeɪ iː ˈes/ AES
    block cipher/blɒk ˈsaɪfə/ bảo mã khối
    Asymmetric encryption/ˌeɪsɪˈmetrɪk enˈkrɪpʃn/ Mã hóa bất đối xứng
    key pair/kiː peə/ cặp khóa
    public key/ˈpʌblɪk kiː/ khóa công khai
    private key/ˈpraɪvət kiː/ khóa riêng tư
    elliptic curve cryptography (ECC)/ɪˈlɪptɪk kɜːv krɪpˈtɒɡrəfi/ mã hóa đường cong elip (ECC)
    Secure by design/sɪˈkjʊə baɪ dɪˈzaɪn/ An toàn trong thiết kế
    Secure by default/sɪˈkjʊə baɪ dɪˈfɒlt/ An toàn theo mặc định
    input sanitization/ˈɪnpʊt ˌsænɪtaɪˈzeɪʃn/ chuẩn hóa đầu vào
    special characters/ˈspeʃl ˈkærɪktəz/ ký tự đặc biệt
    accounting/əˈkaʊntɪŋ/ kế toán
    Watch lesson · ⁨Xem bài học⁩
    5.4

    Asymmetric Cryptography · ⁨Mật mã học Bất đối xứng⁩

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 5.4.A: Determine the appropriate asymmetric key to use when sending or receiving encrypted data.

    • 5.4.A.1 Asymmetric encryption allows users to communicate securely without prearranging a shared secret key.
    • 5.4.A.2 When using asymmetric encryption, each entity that will be receiving data must first generate a key pair. Key pairs are binary strings of equal length that are generated at the same time through a mathematical process. One key is designated as the public key and the other as the private key. The keys are mathematical inverses of each other— each key reverses its partner. Either key can be used to encrypt information, but only the other key in the key pair will then be able to decrypt it.
    • 5.4.A.3 Once the receiver generates the key pair, the private key must be stored securely. If the private key is exposed, shared, stolen, corrupted, or compromised the key pair must be deleted and a new key pair must be generated, because the security of the encryption algorithm rests on the security of the private key. The public key is published for anyone to view and use.
    • 5.4.A.4 To send information securely to someone, the sender will use the receiver’s public key to encrypt the data and send it. Only the receiver who has the private key will be able to decrypt and read the information.

    Learning Objective 5.4.B: Explain why the length of a key impacts the security of encrypted data.

    • 5.4.B.1 Longer keys result in larger keyspaces. For binary keys, an n-bit length key has a keyspace of $2^n$.
    • 5.4.B.2 Using an application to randomly guess an n-bit length encryption key means that on average an adversary will be able to guess the correct key in $2^n \div 2$ (or $2^{n-1}$) guesses.
    • 5.4.B.3 Although longer keys are more secure, they also require more time to encrypt and decrypt messages.
    • 5.4.B.4 Computational processing power and efficiency continue to improve, allowing software to guess keys faster. Key-length recommendations for both symmetric and asymmetric encryption algorithms are periodically increased to account for increased processing power.
    • 5.4.B.5 Key-length comparison is only valid when comparing keys for the same cryptographic algorithm.
      • Illustrative examples for 5.4.B.5:
        • An AES 256-bit key is more secure than an AES 128-bit key.
        • An RSA 4096-bit key is more secure than an RSA 2048-bit key.
        • RSA and AES keys cannot be directly compared to one another in determining the level of security.

    Learning Objective 5.4.C: Apply asymmetric encryption algorithms to encrypt and decrypt data.

    • 5.4.C.1 Common asymmetric encryption algorithms include RSA and elliptic curve cryptography (ECC). Asymmetric algorithms are used in many applications, including digital signatures and digital certificates.
    • 5.4.C.2 As with symmetric encryption, asymmetric encryption and decryption can be performed using the command line, specialized software, or web-based tools.
      • On a command line interface, users can encrypt or decrypt with OpenSSL.
      • Specialized software like RSA Encryption Tool is an open source tool that can encrypt and decrypt files.
      • There are many web-based tools for encrypting and decrypting files.
    • 5.4.C.3 In a CLI, a user can generate an asymmetric key pair and encrypt or decrypt files as necessary.
      • To generate a 2048-bit RSA key pair and save the key to a file named rsa.pem use the command: openssl genrsa -out rsa.pem 2048
      • To extract the public key from rsa.pem into a file named public.pem, use the command: openssl rsa -pubout -in rsa.pem -outform PEM -out public.pem
      • To encrypt the file test using RSA encryption and the key file public.pem, use the command: openssl pkeyutl -encrypt -pubin -inkey public.pem -in test -out test.enc
      • To decrypt the test.enc file using the rsa.pem file, run the command: openssl pkeyutl -decrypt -inkey rsa.pem -in test.enc -out test
    Tiếng Việt

    Mục tiêu học tập 5.4.A: Xác định khóa bất đối xứng phù hợp khi gửi hoặc nhận dữ liệu đã mã hóa.

    • 5.4.A.1 Mã hóa bất đối xứng cho phép người dùng giao tiếp an toàn mà không cần thiết lập trước một khóa bí mật chung.
    • 5.4.A.2 Khi sử dụng mã hóa bất đối xứng, mỗi thực thể nhận dữ liệu cần phải tạo trước một cặp khóa. Cặp khóa là các chuỗi nhị phân có độ dài bằng nhau, được sinh ra đồng thời thông qua một quy trình toán học. Một khóa được chỉ định làm khóa công khai và khóa còn lại là khóa riêng tư. Các khóa này là nghịch đảo toán học của nhau—mỗi khóa sẽ đảo ngược hoạt động của khóa kia. Có thể dùng bất kỳ khóa nào để mã hóa thông tin, nhưng sau đó chỉ có khóa còn lại trong cặp khóa mới giải mã được nó.
    • 5.4.A.3 Sau khi người nhận sinh cặp khóa, khóa riêng tư phải được lưu trữ an toàn. Nếu khóa riêng tư bị lộ, chia sẻ, đánh cắp, hư hỏng hoặc bị xâm phạm, cặp khóa phải bị xóa và một cặp khóa mới phải được tạo ra, vì tính an toàn của thuật toán mã hóa dựa vào tính an toàn của khóa riêng tư. Khóa công khai được xuất bản để mọi người có thể xem và sử dụng.
    • 5.4.A.4 Để gửi thông tin an toàn đến ai đó, người gửi sẽ sử dụng khóa công khai của người nhận để mã hóa dữ liệu và gửi đi. Chỉ có người nhận có khóa riêng tư mới có thể giải mã và đọc thông tin.

    Mục tiêu học tập 5.4.B: Giải thích tại sao độ dài của khóa ảnh hưởng đến tính an toàn của dữ liệu đã mã hóa.

    • 5.4.B.1 Khóa càng dài dẫn đến không gian khóa càng lớn. Đối với khóa nhị phân, khóa có độ dài n-bit có không gian khóa là $2^n$.
    • 5.4.B.2 Sử dụng ứng dụng để đoán ngẫu nhiên một khóa mã hóa có độ dài n-bit có nghĩa là trung bình kẻ tấn công sẽ có thể đoán đúng khóa trong $2^n \div 2$ (hoặc $2^{n-1}$) lần đoán.
    • 5.4.B.3 Mặc dù khóa dài hơn an toàn hơn, nhưng chúng cũng đòi hỏi nhiều thời gian hơn để mã hóa và giải mã tin nhắn.
    • 5.4.B.4 Sức mạnh tính toán và hiệu suất liên tục được cải thiện, cho phép phần mềm đoán khóa nhanh hơn. Các khuyến nghị về độ dài khóa cho cả thuật toán mã hóa đối xứng và bất đối xứng định kỳ được tăng lên để tính đến sức mạnh tính toán gia tăng.
    • 5.4.B.5 So sánh độ dài khóa chỉ có giá trị khi so sánh các khóa cho cùng một thuật toán mật mã.
      • Ví dụ minh họa cho 5.4.B.5:
        • Khóa AES 256-bit an toàn hơn khóa AES 128-bit.
        • Khóa RSA 4096-bit an toàn hơn khóa RSA 2048-bit.
        • Khóa RSA và AES không thể so sánh trực tiếp với nhau để xác định mức độ an toàn.

    Mục tiêu học tập 5.4.C: Áp dụng các thuật toán mã hóa bất đối xứng để mã hóa và giải mã dữ liệu.

    • 5.4.C.1 Các thuật toán mã hóa bất đối xứng phổ biến bao gồm RSA và mật mã đường cong elip (ECC). Các thuật toán bất đối xứng được sử dụng trong nhiều ứng dụng, bao gồm chữ ký số và chứng chỉ số.
    • 5.4.C.2 Tương tự như mã hóa đối xứng, mã hóa và giải mã bất đối xứng có thể thực hiện qua dòng lệnh, phần mềm chuyên dụng hoặc công cụ dựa trên web.
      • Trên giao diện dòng lệnh, người dùng có thể mã hóa hoặc giải mã với OpenSSL.
      • Phần mềm chuyên dụng như RSA Encryption Tool là một công cụ mã nguồn mở có khả năng mã hóa và giải mã tập tin.
      • Có rất nhiều công cụ dựa trên web để mã hóa và giải mã tệp.
    • 5.4.C.3 Trong CLI, người dùng có thể tạo cặp khóa bất đối xứng và mã hóa hoặc giải mã tệp khi cần thiết.
      • Để tạo cặp khóa RSA 2048-bit và lưu khóa vào tệp có tên rsa.pem, hãy sử dụng lệnh: openssl genrsa -out rsa.pem 2048
      • Để trích xuất khóa công khai từ rsa.pem ra tệp có tên public.pem, hãy sử dụng lệnh: openssl rsa -pubout -in rsa.pem -outform PEM -out public.pem
      • Để mã hóa tệp test bằng mã hóa RSA và tệp khóa public.pem, hãy sử dụng lệnh: openssl pkeyutl -encrypt -pubin -inkey public.pem -in test -out test.enc
      • Để giải mã tệp test.enc sử dụng tệp rsa.pem, chạy lệnh: openssl pkeyutl -decrypt -inkey rsa.pem -in test.enc -out test

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    English

    Asymmetric encryption 非对称加密 solves the key-sharing problem with a key pair 密钥对 - a public key 公钥 anyone may see and a private key 私钥 kept secret. The keys are mathematical inverses: whatever one locks, only the other unlocks. To send you a secret, I encrypt with your public key, and only your private key can decrypt it - so we never had to share a secret in advance.

    Longer keys mean larger keyspaces and more security, but slower encryption. Common asymmetric algorithms are RSA and elliptic curve cryptography (ECC) 椭圆曲线密码学, used in digital signatures and certificates. Remember: you can only compare key lengths within the same algorithm - an RSA 4096-bit key is not directly comparable to an AES 256-bit key.

    Tiếng Việt

    Mật mã hóa bất đối xứng giải quyết vấn đề chia sẻ khóa bằng một cặp khóa - một khóa công khai mà bất kỳ ai cũng có thể xem và một khóa riêng tư được giữ bí mật. Các khóa là nghịch đảo toán học: cái gì một khóa khóa, thì chỉ khóa kia mới mở được. Để gửi cho bạn một tin bí mật, tôi mã hóa bằng khóa công khai của bạn, và chỉ có khóa riêng tư của bạn mới giải mã được nó - vì vậy chúng ta chưa bao giờ cần chia sẻ một khóa bí mật trước đó.

    Mã hóa bất đối xứng: mã hóa bằng khóa công khai, giải mã bằng khóa riêng tư
    Mật mã hóa bất đối xứng: mã hóa bằng khóa công khai, giải mã bằng khóa riêng tư

    Khóa dài hơn có nghĩa là không gian khóa lớn hơn và bảo mật tốt hơn, nhưng tốc độ mã hóa chậm hơn. Các thuật toán bất đối xứng phổ biến là RSA và mật mã đường cong elip (ECC), được sử dụng trong chữ ký số và chứng chỉ. Hãy nhớ: bạn chỉ có thể so sánh độ dài khóa trong cùng một thuật toán - một khóa RSA 4096-bit không thể so sánh trực tiếp với khóa AES 256-bit.

    Một chiếc ổ khóa: mã hóa khóa dữ liệu lại để chỉ người có khóa tương ứng mới mở được
    Một ổ khóa: mật mã học khóa dữ liệu lại sao cho chỉ người có khóa phù hợp mới mở được
    Watch lesson · ⁨Xem bài học⁩
    5.5

    Protecting Applications · ⁨Bảo vệ Ứng dụng⁩

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 5.5.A: Identify the application security principles of secure by design and security by default.

    • 5.5.A.1 Secure by design is an initiative that encourages companies to include security in all phases of product development including design. When organizations implement secure by design, security is a design principle not just a technical feature.
    • 5.5.A.2 Secure by design includes three design principles:
      • i. Companies should take ownership of customer security outcomes. Companies should build products that meet the security needs of their customers.
      • ii. Companies should embrace radical transparency and accountability. Sharing relevant security-related product news and updates quickly increases security for everyone.
      • iii. Companies should build organizational structure and leadership to implement secure by design. Companies need leaders who are focused on security and have a security-first posture.
    • 5.5.A.3 Secure by design includes the concept of secure by default, which is the idea that security features for software and devices should be enabled by default. Devices and software should be secure to use out of the box, with security features already enabled.

    Learning Objective 5.5.B: Explain how user input sanitization protects applications.

    • 5.5.B.1 When users enter input into an application, the application typically encases that input in special characters to process it. The characters that encase the user input are called control characters and include the single quote, the double quote, and the semicolon.
    • 5.5.B.2 When creating a program that takes user input, programmers should use a function to verify that user input meets their expected criteria and does not include any control characters that could be used to manipulate the system. This verification function can sanitize user input by removing potentially malicious characters, or it can give the user an error and force the user to provide different input. This can protect against many application attacks, including:
      • SQL injection attacks
      • XSS attacks
      • Directory traversal attacks
    Tiếng Việt

    Mục tiêu Học tập 5.5.A: Xác định các nguyên tắc bảo mật ứng dụng dựa trên thiết kế an toàn và bảo mật mặc định.

    • 5.5.A.1 Thiết kế an toàn (Secure by design) là một sáng kiến khuyến khích các công ty tích hợp bảo mật vào tất cả các giai đoạn của quá trình phát triển sản phẩm, bao gồm cả thiết kế. Khi các tổ chức áp dụng thiết kế an toàn, bảo mật là một nguyên tắc thiết kế chứ không chỉ là một tính năng kỹ thuật.
    • 5.5.A.2 Thiết kế an toàn bao gồm ba nguyên tắc thiết kế:
      • i. Các công ty nên chủ động chịu trách nhiệm về kết quả bảo mật của khách hàng. Các công ty nên xây dựng các sản phẩm đáp ứng nhu cầu bảo mật của khách hàng.
      • ii. Các công ty nên chấp nhận sự minh bạch cực đoan và trách nhiệm giải trình. Chia sẻ tin tức và cập nhật liên quan đến bảo mật sản phẩm nhanh chóng sẽ tăng cường bảo mật cho tất cả mọi người.
      • iii. Các công ty nên xây dựng cấu trúc tổ chức và lãnh đạo để triển khai thiết kế an toàn. Các công ty cần những nhà lãnh đạo tập trung vào bảo mật và có tư duy ưu tiên bảo mật.
    • 5.5.A.3 Thiết kế an toàn bao gồm khái niệm bảo mật mặc định (secure by default), đó là ý tưởng rằng các tính năng bảo mật cho phần mềm và thiết bị nên được bật sẵn mặc định. Thiết bị và phần mềm phải an toàn khi sử dụng ngay từ khi mở hộp, với các tính năng bảo mật đã được kích hoạt sẵn.

    Mục tiêu Học tập 5.5.B: Giải thích cách việc làm sạch dữ liệu đầu vào của người dùng giúp bảo vệ ứng dụng.

    • 5.5.B.1 Khi người dùng nhập dữ liệu vào ứng dụng, ứng dụng thường bao bọc dữ liệu đầu vào đó trong các ký tự đặc biệt để xử lý. Các ký tự bao bọc dữ liệu đầu vào của người dùng được gọi là ký tự điều khiển và bao gồm dấu ngoặc đơn, dấu ngoặc kép, và dấu chấm phẩy.
    • 5.5.B.2 Khi tạo chương trình chấp nhận dữ liệu đầu vào từ người dùng, lập trình viên nên sử dụng hàm để xác minh rằng dữ liệu đầu vào đáp ứng các tiêu chí mong muốn và không chứa bất kỳ ký tự điều khiển nào có thể bị lợi dụng để thao túng hệ thống. Hàm xác minh này có thể làm sạch dữ liệu đầu vào của người dùng bằng cách loại bỏ các ký tự tiềm ẩn nguy hiểm, hoặc nó có thể trả về lỗi cho người dùng và buộc họ cung cấp dữ liệu đầu vào khác. Điều này có thể bảo vệ khỏi nhiều cuộc tấn công vào ứng dụng, bao gồm:
      • Cuộc tấn công chèn SQL
      • Cuộc tấn công XSS
      • Cuộc tấn công duyệt thư mục

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    English

    Two design principles keep applications safe from the start. Secure by design 安全设计 builds security into every phase of development, not as an afterthought. Secure by default 默认安全 means the product ships with its security features already enabled - safe straight out of the box.

    Secure by design rests on three principles a company must adopt: (1) take ownership of its customers' security outcomes rather than shifting blame onto users, (2) embrace radical transparency and accountability – sharing security-relevant news and updates quickly so everyone becomes safer, and (3) build the organisational structure and leadership that makes security a first-class goal.

    The key defense against injection attacks is input sanitization 输入清理. Certain special characters 特殊字符 - the single quote, double quote, and semicolon - can be used to manipulate a system, so a good program removes or rejects them before processing. Sanitization protects against SQL injection, XSS, and directory-traversal attacks alike.

    Tiếng Việt

    Hai nguyên tắc thiết kế giúp ứng dụng an toàn ngay từ đầu. An toàn ngay từ thiết kế tích hợp bảo mật vào mọi giai đoạn phát triển, chứ không phải như một suy nghĩ phụ sau này. An toàn theo mặc định có nghĩa là sản phẩm được giao với các tính năng bảo mật đã được bật sẵn - an toàn ngay khi mới mở hộp.

    An toàn ngay từ thiết kế dựa trên ba nguyên tắc mà một công ty phải áp dụng: (1) chấp nhận trách nhiệm cho kết quả bảo mật của khách hàng thay vì đổ lỗi cho người dùng, (2) đón nhận sự minh bạch tuyệt đối và trách nhiệm giải trình – chia sẻ tin tức và bản cập nhật liên quan đến bảo mật nhanh chóng để mọi người trở nên an toàn hơn, và (3) xây dựng cấu trúc tổ chức và lãnh đạo khiến bảo mật trở thành mục tiêu ưu tiên hàng đầu.

    Phòng thủ chính chống lại các cuộc tấn công nhúng (injection) là làm sạch đầu vào. Certain ký tự đặc biệt - dấu ngoặc đơn đơn, dấu ngoặc đôi và dấu chấm phẩy - có thể được sử dụng để thao túng hệ thống, vì vậy một chương trình tốt sẽ loại bỏ hoặc từ chối chúng trước khi xử lý. Việc làm sạch bảo vệ chống lại các cuộc tấn công nhúng SQL, XSS và traversing thư mục.

    5.6

    Detecting Attacks on Data and Applications · ⁨Phát hiện các cuộc tấn công vào dữ liệu và ứng dụng⁩

    Syllabus · ⁨Chương trình⁩
    English

    Learning Objective 5.6.A: Explain how to detect attacks on data.

    • 5.6.A.1 Devices track and log when data are accessed and by whom. The process of recording and monitoring user activities is called accounting. Analysis of these logs can reveal malicious activity when an adversary attempts to access, copy, move, or delete data. Suspicious activity can include:
      • Accessing files that aren’t typically accessed
      • Accessing files or applications outside of a user’s normal patterns (including time of day, location, and device type)
      • Attempts to delete or copy sensitive files
    • 5.6.A.2 A honeypot is a file that appears as if it contains valuable data (e.g., credit card information, PII, passwords), but the data in the file are fake. A system can alert defenders if someone attempts to access the honeypot. Since the honeypot is a fake file, there is no legitimate reason to be accessing it, and any attempted access would be an indicator of malicious activity.
    • 5.6.A.3 Cryptographic hash functions can generate a digest for data and can reveal if data have been altered. If a file has changed unexpectedly, this can be a sign of malicious activity.

    Learning Objective 5.6.B: Determine controls for detecting attacks against applications or data.

    • 5.6.B.1 Cost is a criterion in determining detective controls. Detective controls like honeypots and using hash values to check data integrity are inexpensive. Some organizations invest in third-party data loss prevention (DLP) services, which monitor data access, usage, and transmission by users throughout the organization to detect suspicious activity; DLP services provide strong detection capabilities at a higher cost.
    • 5.6.B.2 Sensitivity or criticality of data or applications is a criterion in determining detective controls. More sensitive or critical data or applications are more likely targets of an adversary and should be monitored more closely.
    • 5.6.B.3 Classification of data is a criterion in determining detective controls. Data that have been classified as private, educational, healthcare, or financial often have legal or regulatory detection and monitoring requirements.

    Learning Objective 5.6.C: Evaluate the impact of a method for detecting attacks against an application or data.

    • 5.6.C.1 To operate at an effective speed, log analysis needs to be augmented with some automation. Honeypots offer near instantaneous detection capabilities.
    • 5.6.C.2 Some DLP tools, honeypots, and realtime automated log analysis provide alerts as an attack is happening. These tools allow for a prompt response that can stop an attack before it does more harm. Retrospective log analysis and the use of cryptographic hashes to verify data integrity identify attacks after they have occurred.
    • 5.6.C.3 False negatives can occur in applications and data attack detection. Cryptographic hash functions only detect if data have been altered. An adversary could view and steal data without altering it, and a cryptographic hash function would not detect this. Honeypots cannot detect adversaries that do not attempt to access them.

    Learning Objective 5.6.D: Identify whether a file has been altered by verifying its hash.

    • 5.6.D.1 Cryptographic hash functions can help identify changes in a file because they are repeatable: the same input always produces the same output for a given hash function.
    • 5.6.D.2 Hashes can be calculated using the command line on a computer, a website, or specialized software.
      • In Windows Powershell, if a user wanted to generate the SHA256 hash for a file named testfile, they would use the command: Get-FileHash testfile -Algorithm SHA256
      • In BASH the same could be accomplished with the command: sha256sum testfile
      • In zsh, the common command line terminal on Apple computers, this could be accomplished with the command: shasum -a 256 testfile
    • 5.6.D.3 A file can be hashed and its hash output recorded. Then it can be hashed again later, and the second hash output can be compared to the previous hash output for the same file. If a file’s hash changes, then the file was altered between when the first and second hashes were generated.

    Learning Objective 5.6.E: Apply detection techniques to identify and report indicators of application attacks by analyzing log files.

    • 5.6.E.1 SQL injection attacks can be detected by reviewing application and server logs of user input for SQL control words and symbols such as:
      • A single (') or double (") quote character
      • Boolean conditions like OR 1=1
      • A double dash (which indicates a comment in SQL): --
      • SQL control words (always in capital letters) like WHERE, IN, FROM
    • 5.6.E.2 XSS attacks can be detected by reviewing user input for suspicious tags, particularly the tag.
    • 5.6.E.3 For web applications, buffer overflows can be detected by checking the amount of data the user is sending to the web application in their request. The fields commonly checked are the URL length, cookie length, query string length, and total request length. Long strings in any of these fields can be an indicator of an attempted buffer overflow attack.
    • 5.6.E.4 Directory traversal attacks can be detected by reviewing application and server logs. HTTP GET requests that include paths with sequences of ../ are indicators of an adversary attempting a directory traversal.
    Tiếng Việt

    Mục tiêu Học tập 5.6.A: Giải thích cách phát hiện các cuộc tấn công vào dữ liệu.

    • 5.6.A.1 Thiết bị theo dõi và ghi lại thời điểm dữ liệu được truy cập và bởi ai. Quá trình ghi chép và giám sát hoạt động của người dùng được gọi là kế toán. Phân tích các nhật ký này có thể tiết lộ hoạt động độc hại khi kẻ thù cố gắng truy cập, sao chép, di chuyển hoặc xóa dữ liệu. Hoạt động đáng ngờ có thể bao gồm:
      • Truy cập các tệp không thường xuyên được truy cập
      • Truy cập tệp hoặc ứng dụng bên ngoài các mẫu hành vi bình thường của người dùng (bao gồm thời gian trong ngày, vị trí và loại thiết bị)
      • Các nỗ lực xóa hoặc sao chép tệp nhạy cảm
    • 5.6.A.2 Một honeypot (răng cưa) là một tệp trông giống như chứa dữ liệu có giá trị (ví dụ: thông tin thẻ tín dụng, PII, mật khẩu), nhưng dữ liệu trong tệp lại giả. Hệ thống có thể cảnh báo cho đội phòng thủ nếu có ai đó cố truy cập vào honeypot. Vì honeypot là một tệp giả, không có lý do chính đáng nào để truy cập vào nó, và mọi nỗ lực truy cập đều là dấu hiệu của hoạt động độc hại.
    • 5.6.A.3 Các hàm băm mã hóa có thể tạo ra digest (bản tóm tắt) cho dữ liệu và có thể tiết lộ xem dữ liệu đã bị thay đổi hay chưa. Nếu một tệp thay đổi không mong muốn, đây có thể là dấu hiệu của hoạt động độc hại.

    Mục tiêu Học tập 5.6.B: Xác định các biện pháp kiểm soát để phát hiện các cuộc tấn công vào ứng dụng hoặc dữ liệu.

    • 5.6.B.1 Chi phí là một tiêu chí trong việc xác định các biện pháp kiểm soát phát hiện. Các biện pháp kiểm soát phát hiện như honeypots và sử dụng giá trị hash để kiểm tra tính toàn vẹn của dữ liệu khá tốn kém thấp. Một số tổ chức đầu tư vào các dịch vụ ngăn chặn thất thoát dữ liệu bên thứ ba (DLP), dịch vụ này giám sát việc truy cập, sử dụng và truyền tải dữ liệu của người dùng trong suốt tổ chức để phát hiện hoạt động đáng ngờ; các dịch vụ DLP cung cấp khả năng phát hiện mạnh mẽ nhưng với chi phí cao hơn.
    • 5.6.B.2 Mức độ nhạy cảm hoặc tính quan trọng của dữ liệu hoặc ứng dụng là một tiêu chí trong việc xác định các biện pháp kiểm soát phát hiện. Dữ liệu hoặc ứng dụng càng nhạy cảm hoặc quan trọng thì càng dễ trở thành mục tiêu của kẻ thù và cần được giám sát chặt chẽ hơn.
    • 5.6.B.3 Phân loại dữ liệu là một tiêu chí trong việc xác định các biện pháp kiểm soát phát hiện. Dữ liệu được phân loại là riêng tư, giáo dục, chăm sóc sức khỏe hoặc tài chính thường có các yêu cầu về phát hiện và giám sát theo quy định pháp luật.

    Mục tiêu Học tập 5.6.C: Đánh giá tác động của một phương pháp phát hiện các cuộc tấn công vào ứng dụng hoặc dữ liệu.

    • 5.6.C.1 Để vận hành ở tốc độ hiệu quả, phân tích nhật ký cần được bổ sung bằng một số tự động hóa. Honeypots cung cấp khả năng phát hiện gần như tức thì.
    • 5.6.C.2 Một số công cụ DLP, honeypots và phân tích nhật ký tự động thời gian thực cung cấp cảnh báo khi cuộc tấn công đang diễn ra. Những công cụ này cho phép phản ứng nhanh chóng nhằm ngăn chặn cuộc tấn công trước khi gây thêm thiệt hại. Phân tích nhật ký mang tính hồi tưởng và sử dụng hàm băm mã hóa để xác minh tính toàn vẹn của dữ liệu giúp phát hiện các cuộc tấn công sau khi chúng đã xảy ra.
    • 5.6.C.3 Lỗi âm giả có thể xảy ra trong việc phát hiện ứng dụng và tấn công dữ liệu. Các hàm băm mã hóa chỉ phát hiện xem dữ liệu có bị thay đổi hay không. Kẻ tấn công có thể xem và đánh cắp dữ liệu mà không làm thay đổi nó, và một hàm băm mã hóa sẽ không phát hiện được điều này. Honeypots không thể phát hiện những kẻ tấn công không cố gắng truy cập vào chúng.

    Mục tiêu học tập 5.6.D: Xác định xem một tệp tin đã bị thay đổi bằng cách kiểm tra giá trị hash của nó.

    • 5.6.D.1 Các hàm băm mã hóa có thể giúp xác định sự thay đổi trong một tệp tin vì chúng có tính lặp lại: cùng một đầu vào luôn tạo ra cùng một đầu ra đối với một hàm hash nhất định.
    • 5.6.D.2 Hashes có thể được tính toán thông qua dòng lệnh trên máy tính, trang web hoặc phần mềm chuyên dụng.
      • Trong Windows Powershell, nếu người dùng muốn tạo hash SHA256 cho một tệp tên là testfile, họ sẽ sử dụng lệnh: Get-FileHash testfile -Algorithm SHA256
      • Trong BASH, điều tương tự có thể thực hiện được với lệnh: sha256sum testfile
      • Trong zsh, dòng lệnh terminal phổ biến trên các máy tính Apple, điều này có thể thực hiện được với lệnh: shasum -a 256 testfile
    • 5.6.D.3 Một tệp có thể được tạo hash và kết quả hash của nó được ghi lại. Sau đó, nó có thể được tạo hash lại ở một thời điểm khác, và kết quả hash thứ hai có thể so sánh với kết quả hash trước đó của cùng một tệp. Nếu hash của một tệp thay đổi, thì tệp đó đã bị thay đổi giữa lúc tạo hash lần đầu và lần thứ hai.

    Mục tiêu học tập 5.6.E: Áp dụng các kỹ thuật phát hiện để xác định và báo cáo các chỉ báo của cuộc tấn ứng dụng bằng cách phân tích các tệp nhật ký.

    • 5.6.E.1 Các cuộc tấn công SQL injection có thể được phát hiện bằng cách xem xét nhật ký ứng dụng và server từ đầu vào của người dùng tìm kiếm các từ khóa và ký hiệu điều khiển SQL như:
      • Ký tự dấu ngoặc đơn đơn (') hoặc dấu ngoặc đơn kép (")
      • Điều kiện logic như OR 1=1
      • Dấu gạch ngang đôi (chỉ ra một comment trong SQL): --
      • Các từ khóa điều khiển SQL (luôn viết hoa) như WHERE, IN, FROM
    • 5.6.E.2 Các cuộc tấn công XSS có thể được phát hiện bằng cách xem xét đầu vào của người dùng tìm kiếm các thẻ đáng ngờ, đặc biệt là thẻ .
    • 5.6.E.3 Đối với các ứng dụng web, tràn bộ đệm (buffer overflows) có thể được phát hiện bằng cách kiểm tra lượng dữ liệu người dùng gửi đến ứng dụng web trong yêu cầu của họ. Các trường thường được kiểm tra là độ dài URL, độ dài cookie, độ dài chuỗi truy vấn và tổng độ dài yêu cầu. Các chuỗi dài trong bất kỳ trường nào trong số này có thể là chỉ báo của một cuộc attempted buffer overflow attack.
    • 5.6.E.4 Các cuộc tấn công duyệt thư mục (directory traversal) có thể được phát hiện bằng cách xem xét nhật ký ứng dụng và server. Các yêu cầu HTTP GET bao gồm đường dẫn có chứa chuỗi ../ là chỉ báo của kẻ tấn công đang cố gắng thực hiện duyệt thư mục.

    Source: College Board AP Course and Exam Description · ⁨Nguồn: Mô tả Khóa học và Bài thi College Board AP⁩

    English

    To detect data attacks, systems perform accounting 审计记录 - logging who accessed what and when. But logs are huge, so log analysis must be automated to run at a useful speed; a human reading raw logs is far too slow. A clever complement is a honeypot 蜜罐 - a fake file that looks valuable; since no one has a real reason to open it, any access is a clear, near-instantaneous sign of an attack. Watch especially for attempts to delete or copy sensitive files. Cryptographic hashes also help: re-hash a file and compare - if the digest changed, the file was altered.

    Choosing detective controls means weighing cost (honeypots are cheap; a data loss prevention (DLP) 数据泄露防护 service is powerful but pricey) against the sensitivity of the data. To read a specific attack from logs, look for its signature: SQL injection shows OR 1=1 and --; XSS shows <script> tags; directory traversal shows ../ sequences; a buffer overflow shows unusually long input strings.

    Checking that a file has not been altered

    A cryptographic hash turns a file of any size into a short fixed-length value. Change one byte of the file and the hash changes completely, so comparing a downloaded file's hash with the one the publisher lists proves the file arrived intact. You do this at the command line:

    Shell Command
    BASH (Linux, and most servers) sha256sum testfile
    zsh, the usual terminal on Apple computers shasum -a 256 testfile

    Both print the SHA-256 hash of testfile. If it differs from the published value by even one character, the file has been altered — by corruption in transit, or by an attacker who replaced it.

    ⚠️ A hash proves integrity, not authenticity. An attacker who can replace the file on a web page can usually replace the published hash beside it too; that is why a signed hash, or one fetched over a separate trusted channel, is stronger evidence.

    Tiếng Việt

    Để phát hiện các cuộc tấn công vào dữ liệu, hệ thống thực hiện giao dịch kế toán - ghi lại ai đã truy cập cái gì và khi nào. Nhưng nhật ký rất lớn, nên phân tích nhật ký phải được tự động hóa để chạy ở tốc độ hữu ích; một người đọc nhật ký thô chậm hơn nhiều. Một giải pháp bổ sung thông minh là bẫy mật mã (honeypot) - một tệp giả tưởng như thể nó có giá trị; vì không ai có lý do chính đáng để mở nó, mọi lần truy cập đều là dấu hiệu rõ ràng, gần như tức thì của một cuộc tấn công. Hãy đặc biệt chú ý đến các nỗ lực xóa hoặc sao chép các tệp nhạy cảm. Bảng băm mã hóa cũng giúp ích: tạo lại bảng băm của một tệp và so sánh - nếu digest thay đổi, tệp đã bị chỉnh sửa.

    Việc chọn các biện pháp kiểm tra phát hiện đòi hỏi cân nhắc giữa chi phí (honeypot rẻ; một dịch vụ ngăn chặn thất thoát dữ liệu (DLP) mạnh mẽ nhưng đắt tiền) với mức độ nhạy cảm của dữ liệu. Để đọc được một cuộc tấn công cụ thể từ nhật ký, hãy tìm dấu ấn của nó: SQL injection hiển thị OR 1=1 và --; XSS hiển thị thẻ <script>; duyệt thư mục hiển thị chuỗi ../; tràn bộ đệm hiển thị chuỗi đầu vào dài bất thường.

    Kiểm tra xem một tệp có bị chỉnh sửa hay không

    Một bảng băm mã hóa biến một tệp có kích thước bất kỳ thành một giá trị cố định độ dài ngắn. Thay đổi một byte của tệp và bảng băm sẽ thay đổi hoàn toàn, do đó so sánh bảng băm của tệp đã tải về với bảng băm mà nhà xuất bản liệt kê chứng minh rằng tệp đã đến nguyên vẹn. Bạn làm điều này ở dòng lệnh:

    Shell Lệnh
    BASH (Linux, và hầu hết các máy chủ) sha256sum testfile
    zsh, terminal tiêu chuẩn trên máy tính Apple shasum -a 256 testfile

    Cả hai đều in bảng băm SHA-256 của testfile. Nếu nó khác với giá trị được công bố dù chỉ một ký tự, tệp đã bị chỉnh sửa — do lỗi trong quá trình truyền tải, hoặc bởi kẻ tấn công đã thay thế nó.

    ⚠️ Bảng băm chứng minh tính toàn vẹn, chứ không phải tính xác thực. Một kẻ tấn công có thể thay thế tệp trên trang web thường cũng có thể thay thế bảng băm được công bố bên cạnh nó; đó là lý do tại sao bảng băm được ký, hoặc bảng băm được lấy qua một kênh tin cậy riêng biệt, là bằng chứng mạnh hơn.

    Vocabulary · ⁨Từ vựng⁩ Train · ⁨Luyện tập⁩
    English Tiếng Việt
    honeypot/ˈhʌnɪpɒt/ honeypot
    data loss prevention (DLP)/ˈdeɪtə lɒs prɪˈvenʃn/ ngăn ngừa mất mát dữ liệu (DLP)
    5.6

    Exam tips · ⁨Mẹo làm bài thi⁩

    English
    • Match each application attack to its evidence in a log: OR 1=1 / -- = SQL injection; <script> = XSS; ../ = directory traversal; very long input = buffer overflow.
    • Learn the four access-control models by their decider: RBAC = your role, RuBAC = a condition, DAC = the file's owner, MAC = a central admin. Least privilege underlies them all.
    • Read Linux permissions by adding 4+2+1 per group - chmod 750 = owner rwx (7), group r-x (5), others none (0). Practice converting both ways.
    • Symmetric = one shared key (fast, AES); asymmetric = a public/private key pair (solves key sharing, RSA/ECC). Encrypt with the recipient's public key.
    • Input sanitization is the single best answer for preventing injection attacks; a honeypot is the classic cheap detective control.
    Tiếng Việt
    • Khớp mỗi cuộc tấn công ứng dụng với bằng chứng trong nhật ký: OR 1=1 / -- = SQL injection; <script> = XSS; ../ = duyệt thư mục; đầu vào rất dài = tràn bộ đệm.
    • Học bốn mô hình kiểm soát truy cập theo người quyết định của chúng: RBAC = vai trò của bạn, RuBAC = điều kiện, DAC = chủ sở hữu tệp, MAC = quản trị viên trung tâm. Quyền tối thiểu nằm ở nền tảng của tất cả chúng.
    • Đọc quyền Linux bằng cách cộng 4+2+1 cho mỗi nhóm - chmod 750 = chủ sở hữu rwx (7), nhóm r-x (5), những người khác không có (0). Thực hành chuyển đổi theo cả hai chiều.
    • Đối xứng = một khóa chung (nhanh, AES); bất đối xứng = cặp khóa công khai/riêng tư (giải quyết vấn đề chia sẻ khóa, RSA/ECC). Mã hóa bằng khóa công khai của người nhận.
    • Vệ sinh đầu vào là câu trả lời tốt nhất để ngăn chặn các cuộc tấn công xâm nhập; một honeypot là biện pháp kiểm tra phát hiện điển hình và rẻ tiền.

Log in or create account · ⁨Đăng nhập hoặc tạo tài khoản⁩

IGCSE, A-Level & AP