Security, Privacy & Integrity
A-Level Computer Science Topic 6 16:27 English narration · English + 中文 subtitles burned in
Chapters
Transcript
Right now, this very second, your devices are under attack.
就在此刻,就在这一秒,你的设备正在遭受攻击。
Not by a person hunched over a keyboard — by armies of automated bots, endlessly scanning the internet, knocking on billions of doors, looking for one that is unlocked.
不是一个弓着背趴在键盘上的人—— 而是一支支自动化的机器人大军,不停地扫描整个互联网,敲遍数十亿扇门, 只为找到一扇没锁的。
A weak password.
一个弱密码。
An out-of-date app.
一个过时的应用。
One careless click on a fake email.
对一封假邮件的一次不经意的点击。
Between all your data — your photos, your money, your identity — and the whole world, stands only what you put in their way.
在你所有的数据——你的照片、你的钱、你的身份——和整个世界之间, 挡着的只有你亲手设下的那些防线。
Keeping data safe is three ideas, many threats, and a toolbox of defences.
让数据安全,是三个概念、许多威胁,和一整箱防御工具。
Today: security, privacy and integrity; the threats out there; the measures that stop them; encryption; and how we check that data is correct.
今天:安全、隐私与完整性; 外面的种种威胁;阻止它们的措施;加密;以及我们如何核查数据是否正确。
Let's begin.
让我们开始吧。
First, three words that sound alike but mean different things.
首先,三个听起来很像、意思却不同的词。
Security is keeping data safe from anyone unauthorised — locked away.
安全,是让数据免受任何未授权者的侵害——被锁起来。
Privacy is your right to control who sees your personal data — even people allowed in.
隐私,是你控制谁能看到你个人数据的权利——哪怕是被允许进来的人。
And integrity is the data being accurate and complete — not corrupted or accidentally changed.
而完整性, 是数据准确而完整——没有被损坏,也没有被意外改动。
A file can be perfectly secure, yet ruined by a single typo.
一个文件可以非常安全, 却因一个小小的笔误而毁掉。
You need all three.
这三样,你都需要。
The threats come in three flavours.
威胁分成三种。
Malware — malicious software: a virus that hides in other programs, a worm that spreads across networks by itself, a Trojan disguised as something useful, ransomware that locks your files for money.
恶意软件:藏在别的程序里的病毒,自己在网络上扩散的蠕虫, 伪装成有用东西的木马,把你文件锁住来勒索钱财的勒索软件。
Social attacks that trick the person, not the machine — phishing emails, fake websites.
社会攻击, 骗的是人而不是机器——钓鱼邮件、假冒网站。
And network attacks — hacking weak passwords, denial of service that floods a server, and a man-in-the-middle secretly reading your messages.
还有网络攻击——入侵弱密码、 把服务器淹没的拒绝服务攻击,以及偷偷读你消息的中间人攻击。
Six kinds of malware, and the way to remember them is by behaviour rather than as a list.
恶意软件有六类,而记住它们的办法是按行为分组,而不是死记一张清单。
Two of them copy themselves.
其中两类会自我复制。
A virus attaches itself to another program and spreads when someone runs that program — it needs a host and it needs a user.
病毒把自己附着在别的程序上,当有人运行那个程序时就传播开—— 它既需要宿主,也需要用户。
A worm needs neither: it spreads over networks by itself, with no user action at all.
蠕虫两样都不需要:它自己就能在网络上传播, 完全不用用户做任何事。
That single distinction is the one exams ask for most.
这一个区别正是考试问得最多的。
The other four hide rather than spread.
另外四类是隐藏,而不是传播。
A Trojan horse looks useful but conceals malicious code.
木马看起来有用,却藏着恶意代码。
Spyware secretly collects information such as keystrokes and passwords.
间谍软件偷偷收集信息,比如击键记录和密码。
Ransomware encrypts your files and demands payment to give them back.
勒索软件把你的文件加密,然后索要赎金才还给你。
And adware pushes unwanted adverts at you.
而广告软件则不停地向你推送垃圾广告。
The second group does not attack the computer at all.
第二类根本不攻击计算机。
Phishing sends fake emails or builds fake sites that trick a user into typing their credentials in.
网络钓鱼发送伪造的邮件,或者搭建伪造的网站, 诱骗用户把自己的凭据输进去。
Pharming is nastier and worth distinguishing carefully: it redirects you to a fake site even when you typed the correct address yourself, by poisoning the name lookup — so checking the address bar does not save you.
域名欺骗更阴险,值得仔细区分: 即使你自己输入的是正确的网址,它也会通过污染域名解析把你重定向到假网站—— 所以光看地址栏救不了你。
And social engineering is the general case: simply persuading a person to hand over information, often by pretending to be IT support.
而社会工程是最一般的情形:直接说服一个人交出信息, 常见的手法是冒充技术支持。
What links all three is that the target is the person, not the machine, which is why the defence is training rather than software.
三者的共同点是:目标是人,不是机器, 这正是为什么防御手段是培训而不是软件。
The third group attacks the network itself.
第三类攻击网络本身。
Hacking by hackers is unauthorised access, usually through a weak password or an unpatched software flaw.
黑客入侵是未经授权的访问,通常靠一个弱口令, 或者一个没打补丁的软件漏洞。
A denial of service attack floods a server with so much traffic that real users cannot get through — note that it steals nothing, it just makes the service unavailable, and a distributed version uses thousands of machines at once.
拒绝服务攻击用海量流量淹没服务器, 让真正的用户挤不进去——注意它什么也没偷,只是让服务变得不可用, 而分布式的版本会同时动用成千上万台机器。
Eavesdropping is capturing data while it is in transit, which is why open Wi-Fi is risky.
窃听是在数据传输途中把它截获下来, 这正是开放无线网络危险的原因。
And a man-in-the-middle attacker sits between two parties, secretly relaying messages and able to read or alter them, while both ends believe they are talking directly to each other.
而中间人攻击者坐在双方中间, 偷偷转发消息,并且能够读取或篡改它们,可两端都以为自己在直接对话。
For every threat, a defence.
每一种威胁,都有一种防御。
Interception?
有人拦截数据?
Encrypt the data, so a thief steals only gibberish.
就加密,让小偷偷走的只是一堆乱码。
Unauthorised access?
有人未经授权访问?
Strong authentication — a long password, plus a second factor like a phone code, or a fingerprint.
就用强身份验证——一个长密码,再加上第二重因素,比如手机验证码, 或一个指纹。
Malware?
恶意软件?
Antivirus and prompt updates.
杀毒软件加上及时更新。
The careless insider?
粗心的内部人员?
The least-privilege principle: give each person only what they need.
最小权限原则: 每个人只给他需要的那点权限。
And a firewall filters the traffic, while backups let you recover from the worst.
而防火墙过滤流量,备份则让你能从最坏的情况里恢复过来。
Measures come in layers, and exams often specify which layer.
防护措施是分层的,而考题常常指定是哪一层。
For a standalone PC: a strong password, antivirus kept up to date, prompt software updates, backups onto separate media, full-disk encryption, and a locked screen.
对一台独立的个人电脑: 强密码、及时更新的杀毒软件、尽快安装软件更新、备份到独立介质、全盘加密,以及锁屏。
Put that PC on a network and you keep all of those and add more.
把这台电脑接入网络,上面这些全都保留,再往上加。
A firewall to filter what crosses the boundary.
防火墙,过滤跨越边界的流量。
Per-user permissions, so administrator rights belong only to administrators.
按用户分配权限,让管理员权限只属于管理员。
Central management of user accounts.
集中管理用户账户。
And audit logs recording who logged in and what they touched.
还有审计日志,记录谁登录过、动过什么。
Across the internet you add another layer again: a VPN encrypting traffic to the corporate gateway, HTTPS and TLS encrypting web traffic, digital signatures proving who sent a message and that nobody altered it, and intrusion detection watching for known attack patterns.
跨越互联网时还要再加一层: 虚拟专用网加密到公司网关的流量,HTTPS 和 TLS 加密网页流量, 数字签名证明消息是谁发的、并且没有被人改动,以及入侵检测监视已知的攻击模式。
The commonest question type gives you a threat and asks for the measure, so learn them as pairs.
最常见的题型是给你一种威胁,要你说出对应的措施,所以要成对地记。
Interception in transit is answered by encryption — intercepted ciphertext is useless without the key.
传输途中被截获,答案是加密——截获到的密文没有密钥就毫无用处。
Unauthorised access is answered by strong authentication: long passwords, two-factor authentication using a phone code or a key, authorisation controlling what each user may do, and lock-out after repeated failed logins.
未经授权的访问,答案是强身份验证:长密码、用手机验证码或密钥的双因素认证、 用授权控制每个用户能做什么,以及多次登录失败后锁定账户。
Malware is answered by anti-virus and anti-spyware with real-time scanning, plus patching.
恶意软件,答案是带实时扫描的杀毒和反间谍软件,再加上打补丁。
Phishing is answered by user training and email filtering, because the target was a person.
网络钓鱼,答案是用户培训和邮件过滤,因为目标本来就是人。
Internal threats are answered by the least-privilege principle — give each user only what their job needs — plus auditing.
内部威胁,答案是最小权限原则——只给每个用户工作所需的那些权限——再加上审计。
And DDoS is answered by rate limiting and traffic filtering.
而分布式拒绝服务,答案是限流和流量过滤。
Encryption itself comes in two forms.
加密本身有两种形式。
Symmetric: one shared secret key both locks and unlocks the message — fast, but both sides must somehow share that key safely.
对称加密:一把共享的密钥,既上锁又解锁——速度快, 但双方必须设法安全地共享那把密钥。
Asymmetric solves that: everyone has two keys, a public one and a private one.
非对称加密解决了这个问题:每个人都有两把钥匙, 一把公钥,一把私钥。
Anything locked with your public key — which you can hand out freely — can only be opened by your matching private key, which you never share.
任何用你的公钥锁上的东西——公钥你可以随便分发—— 都只能用与之配对的私钥打开,而私钥你从不外传。
This is what secures the web.
这,就是保护整个网络的东西。
How a digital signature authenticates a document is a five-mark answer with five steps.
「数字签名如何验证一份文件」是一道五分题,有五个步骤。
The sender puts the message through a hash function to produce a digest.
发送方把消息通过哈希函数,产生一个摘要。
The sender encrypts that digest with their private key, and the encrypted digest is the digital signature.
发送方用自己的私钥加密这个摘要,加密后的摘要就是数字签名。
The message and the signature are sent together.
消息和签名一起发送。
The receiver decrypts the signature with the sender's public key to recover the digest, then hashes the received message and compares the two.
接收方用发送方的公钥解密签名,还原出摘要, 再对收到的消息做哈希,把两个摘要作比较。
If they match, the message came from that sender — only they hold the private key — and it was not altered on the way.
如果一致,说明消息确实来自那个发送方——只有他持有私钥——而且在传输中没有被改动。
Note what it does not do: a signature does not hide the contents.
注意它做不到的事:签名并不隐藏内容。
Encrypting the message is what does that.
隐藏内容是靠加密消息本身。
Encryption turns plaintext into ciphertext using a key, and there are two families.
加密用一把密钥把明文变成密文,而它分成两大类。
Symmetric encryption, such as AES, uses one shared key for both encrypting and decrypting — fast, but it leaves you a problem: how do you get that key to the other person safely in the first place?
对称加密,比如 AES, 加密和解密用的是同一把共享密钥——速度快,但留下一个难题: 你一开始要怎么把这把密钥安全地交到对方手里?
Asymmetric encryption, such as RSA, solves exactly that with a pair of keys.
非对称加密,比如 RSA, 正是用一对密钥解决了这个问题。
You encrypt with the receiver's public key, which anyone may know, and only their private key can decrypt it — so no secret ever has to be sent.
你用接收方的公钥加密,那把钥匙人人可知, 而只有他们的私钥能解开——于是任何秘密都不必被传送出去。
Both protect data at rest and data in transit.
两者都既保护静止的数据,也保护传输中的数据。
Authentication techniques verify that you are who you claim to be, and every method falls into one of three categories.
身份验证是要确认你确实是你所声称的那个人,而所有方法都落入三类之一。
Something you know — a password or a PIN; cheap, but it can be guessed, stolen or shared.
你知道的东西——密码或个人识别码;便宜,但可能被猜到、被偷走,或者被人分享出去。
Something you have — a token like this one, showing a code that changes every minute, or a phone receiving a message.
你拥有的东西——像这样的令牌,显示每分钟变化一次的验证码,或者一部接收短信的手机。
Something you are — biometrics: a fingerprint, a face, an iris.
你本身的特征——生物识别:指纹、人脸、虹膜。
Each alone can be defeated.
任何一种单独使用都可能被攻破。
Combining two of the three is two-factor authentication, and it is far stronger than either, because an attacker must now beat two different kinds of thing at once.
把三者中的两种结合起来,就是双因素认证,它比其中任何一种都强得多, 因为攻击者现在必须同时攻破两种不同性质的东西。
Encryption and authentication are not the whole story.
加密和身份验证并不是全部。
Access control means file permissions — read, write, execute — and access rights, all enforced by the operating system, so that even a legitimate user can only reach what they are entitled to.
访问控制指的是文件权限——读、写、执行—— 以及访问权限,全部由操作系统强制执行,这样即使是合法用户,也只能接触到他有权接触的东西。
Backups are copies kept so that loss or corruption is recoverable, and the crucial detail is that some must be off-site: a backup in the same building burns in the same fire and is encrypted by the same ransomware.
备份是保留下来的副本,使得丢失或损坏可以恢复,而关键的细节是必须有一部分放在异地: 放在同一栋楼里的备份,会在同一场火里烧掉,也会被同一个勒索软件加密。
And physical security is the layer people forget — locked server rooms and cable locks — because none of the software matters if somebody can simply pick the machine up and walk out with it.
而物理安全是人们最容易忘掉的一层——上锁的机房和机箱锁—— 因为要是有人干脆把机器抱起来走出去,前面所有的软件都白搭。
Access rights in a database, for three marks: each user is given an account with a username and password; the database administrator assigns each account permissions per table — read-only, read and write, or no access; and users see only the tables and fields they are allowed to, so a customer cannot open the staff table and a clerk can read the prices but not change them.
数据库中的访问权限,三分的答法是: 每个用户有一个带用户名和密码的账户; 数据库管理员为每个账户逐表分配权限——只读、读写,或者不可访问; 用户只能看到允许他看的表和字段, 所以顾客打不开员工表,而店员能看价格却改不了价格。
The D B M S enforces this through those access rights and through views, and it can encrypt the stored data as well.
数据库管理系统通过这些访问权限和视图来执行这一点,而且它还可以加密存储的数据。
Finally, integrity.
最后,是完整性。
Two very different checks.
有两种非常不同的检查。
Validation asks: is this data sensible?
验证问的是:这数据合理吗?
A range check rejects a thirteenth month; a format check demands an at-sign in an email.
范围检查会拒绝第十三个月; 格式检查要求电子邮件里必须有一个@符号。
But validation cannot tell right from merely possible.
但验证分不清"正确"和"仅仅有可能"。
Verification asks: was this data copied correctly?
核对问的是:这数据被正确地复制过来了吗?
Type a password twice and compare — double entry.
把密码打两遍再比较——双重录入。
Or add a parity bit that flips if a single bit does.
或者加一个奇偶校验位,只要有一位翻转它就跟着翻。
Validation: is it sensible?
验证:合不合理?
Verification: was it copied faithfully?
核对:抄得对不对?
Validation checks data against sensible rules, automatically, before it is stored.
验证在数据被存储之前,自动地拿它去对照一些合理的规则。
Learn the list, because questions ask for a named check.
要把这份清单记住, 因为题目会要求你说出某一种检查的名称。
A range check confirms a value sits within limits — a month must be one to twelve.
范围检查确认数值落在上下限之内—— 月份必须在一到十二之间。
A limit check tests one side only, such as age at least eighteen.
极限检查只检查一侧,比如年龄至少十八岁。
An existence check confirms the thing referred to actually exists.
存在性检查确认被引用的东西确实存在。
A length check counts characters.
长度检查数字符个数。
A type or character check confirms the kind of data — a phone field takes only digits.
类型或字符检查确认数据的种类——电话号码字段只接受数字。
A format check matches a pattern, so an email must contain an at sign.
格式检查匹配一个模式,所以电子邮件地址里必须有一个 at 符号。
A presence check confirms a required field is not empty.
存在检查确认必填字段不为空。
And a check digit is an extra digit computed from the others, as on an ISBN or a card number, which catches transcription errors. A lookup check and a consistency check catch linked fields — for example a delivery date that must not precede the order date.
而校验位是一位由其余各位算出来的额外数字, 就像书号或者银行卡号上那样,它能发现抄写错误。
But note the limit: validation catches data that is wrongly formatted, but not data that is correctly formatted and still factually wrong.
但要注意它的界限: 验证能抓出格式不对的数据,却抓不出格式正确、事实上却是错的数据。
Verification is a different question: was the data changed while moving from one place to another?
核对问的是另一个问题:数据在从一处搬到另一处的过程中有没有被改变?
During entry, double entry means typing it twice and comparing, which is why you confirm a new password; a visual check is simply reading what is on the screen carefully.
在录入时,双重输入的意思是输两遍再比对,这正是你设置新密码时要确认一遍的原因。
During transfer, bits can flip, and three checks catch that.
在传输时,比特可能翻转,有三种检查能发现它。
A parity check adds one extra bit so that the total number of ones is even, for even parity, or odd; the receiver re-counts, and a mismatch means an error.
奇偶校验多加一位, 使得"一"的总个数为偶数,这叫偶校验,或者为奇数;接收方重新数一遍, 对不上就说明出错了。
It catches a single flipped bit.
它能查出单个比特的翻转。
A checksum sends a summary value of the whole block, which the receiver recomputes and compares.
校验和把整块数据的一个汇总值发过去, 接收方重新算一遍再比对。
And a cyclic redundancy check, CRC, is a stronger checksum using polynomial division that catches far more error patterns.
而循环冗余校验,简称 CRC,是更强的校验和, 用多项式除法,能查出多得多的错误模式。
An ordinary parity check tells you that something broke, but not what.
普通的奇偶校验只告诉你出了错,却说不出错在哪里。
A parity block check goes further and pinpoints it.
奇偶块校验更进一步,能把它精确定位。
Arrange the bytes in a grid, one byte per row.
把这些字节排成一个网格,一行一个字节。
Give each byte a row parity bit as usual.
照常给每个字节一位行校验位。
Then compute one extra parity byte at the bottom, whose bits are the column parity of all the bytes above.
然后在底部再算出一个额外的校验字节,它的每一位是上面所有字节对应列的列校验。
Now flip a single bit anywhere in the block.
现在让块中任意一位发生翻转。
That bit belongs to one row and one column, so exactly one row parity fails and exactly one column parity fails — and their intersection is the bit that changed.
这一位既属于某一行,又属于某一列, 于是恰好有一行的校验对不上,也恰好有一列的校验对不上—— 而它们的交点就是发生变化的那一位。
Because you know precisely which bit is wrong, and a bit has only two possible values, you can not only detect the error but correct it.
因为你确切知道是哪一位错了, 而一个比特只有两种可能取值,所以你不仅能检测出错误,还能把它改正过来。
Here is the classic question.
下面是那道经典的题。
A user types their date of birth as thirty-one, oh-two, two-thousand-and-nine, and types their email address twice.
一位用户把出生日期输成三十一、零二、二零零九, 并且把电子邮件地址输了两遍。
Which check catches which, and what is the difference?
哪一种检查抓住哪一个错误,两者的区别又是什么?
Validation asks "is this data sensible?" — a format or range check rejects it, because February never has thirty-one days.
验证问的是"这个数据合理吗"——格式检查或范围检查会拒绝它, 因为二月从来没有三十一号。
Verification asks "was this entered correctly?" — typing the email twice is double entry, and comparing the two copies catches a typing slip.
核对问的是"这个数据输对了吗"—— 把邮箱输两遍就是双重输入,比对两份副本就能抓出打字失误。
And now the part that decides the marks.
接下来这一点决定得分。
Validation can never tell you the data is right, only that it is possible: the first of February two-thousand-and-nine passes every validation rule there is, even if the user was actually born on a different day entirely.
验证永远无法告诉你数据是正确的,只能告诉你它是可能的: 二零零九年二月一日能通过所有的验证规则,哪怕这位用户实际上出生在完全不同的一天。
Say what each check can and cannot catch.
要说清每一种检查能抓住什么、抓不住什么。
Three marks to secure.
三个要拿稳的分。
First, keep the three ideas apart: security is safety, privacy is who may see, integrity is correctness.
第一,把这三个概念分清楚:安全是保护、隐私是谁能看、完整性是正确。
Second, match each threat to a measure — encryption for interception, authentication for access, antivirus for malware.
第二,把每一种威胁配上一种措施——加密对拦截,身份验证对访问,杀毒软件对恶意软件。
Third, encryption protects confidentiality, not integrity; use a checksum or parity for that.
第三,加密保护的是机密性,不是完整性;完整性要用校验和或奇偶校验。
Master these, and security is yours.
掌握这些,安全就是你的了。
A definition question here is marked against fixed wording, so learn these exactly.
这一部分的定义题是按固定措辞给分的,所以要背准。
Data security is keeping data safe from loss and from unauthorised access, change or deletion.
数据安全,是保护数据不丢失,也不被未经授权地访问、修改或删除。
Data privacy is keeping it confidential, so it is seen only by those with the right to see it.
数据隐私,是保持数据的机密性,只有有权查看的人才能看到。
Data integrity is the data being accurate, consistent and complete.
数据完整性,是数据准确、一致、完整。
Malware is malicious software installed without the user's knowledge to damage a system or steal data.
恶意软件,是在用户不知情的情况下被安装、用来破坏系统或窃取数据的软件。
A virus replicates itself and attaches to other files; spyware records key presses or actions and sends them to a third party — the replicating one is the virus, the recording one is spyware, and swapping them is a common lost mark.
病毒会自我复制并附着到其他文件上;间谍软件记录按键或操作并发送给第三方—— 会复制的是病毒,会记录的是间谍软件,把两者说反是常见的失分。
Phishing is an email pretending to be from a legitimate organisation that leads the user to a fake website; pharming is malicious code that redirects the user to a fake site even when the correct address is typed.
钓鱼,是伪装成合法机构的邮件,把用户引到假网站; 域名劫持,是即使输入了正确的网址也把用户重定向到假网站的恶意代码。
A firewall examines all traffic entering or leaving a system against set criteria and blocks what does not meet them.
防火墙按设定的标准检查所有进出系统的流量,拦下不符合标准的。
Four more traps.
还有四个陷阱。
Do not give the same measure for two different threats — each needs a prevention that actually stops it.
不要给两种不同的威胁写同一种措施——每一种都需要真正能挡住它的防护。
Do not name a measure without saying how it works: firewall scores only when it is followed by compares traffic with set criteria and blocks what fails.
不要只报出措施的名字而不说它怎么工作: 写「防火墙」只有在后面接上「按设定标准比对流量并拦截不符合的」时才得分。
Do not call validation a check that data is correct — validation checks it is reasonable, verification checks it matches the source, and neither proves it is true.
不要把验证说成「检查数据是否正确」—— 验证检查数据是否合理,核对检查数据是否与来源一致,两者都不能证明数据是真的。
And a digital signature does not encrypt the message: it encrypts a hash of the message with the private key.
另外,数字签名并不加密消息本身:它用私钥加密消息的哈希值。