Defending a system · 防御一个系统
This page needs a recent browser (with SharedArrayBuffer support). Please update Chrome, Edge, Firefox or Safari to the latest version. · 此页面需较新浏览器(支持 SharedArrayBuffer)。请升级 Chrome、Edge、Firefox 或 Safari 至最新版本。
English
Walls at the edge
- A firewall sits between your network and the internet, blocking traffic that breaks the rules.
- A proxy server stands in front of your servers, hiding them and filtering requests.
- Together they keep unwanted visitors out before they reach anything important.
中文
边界上的城墙
- **防火墙(firewall)**位于你的网络和互联网之间,拦截违反规则的流量。
- **代理服务器(proxy server)**挡在你的服务器前面,把它们隐藏起来并过滤请求。
- 二者合力,在不速之客触及任何重要内容之前就把他们挡在门外。
English
Software defences
- Anti-malware (anti-virus / anti-spyware) scans for and removes known malware.
- Automatic updates patch weaknesses as soon as fixes are released — most attacks use old, known holes.
中文
软件层面的防御
- 反恶意软件(杀毒 / 反间谍)扫描并清除已知的恶意软件。
- 自动更新会在修复一发布就立即修补漏洞 —— 大多数攻击利用的都是旧的、已知的漏洞。
English
Limiting the damage
- Access levels give each person only the rights they need — a student cannot change a teacher's grades.
- Privacy settings control who can see your data on a service.
- If one account is broken into, good access levels stop the attacker reaching everything.
中文
控制损失范围
- **访问级别(access levels)**只给每个人他所需要的权限 —— 学生改不了老师录入的成绩。
- 隐私设置控制在某项服务上谁可以看到你的数据。
- 一旦某个账户被攻破,良好的访问级别能阻止攻击者触及一切。
English
Smart habits
- Check the URL of a link before clicking, and the spelling and tone of messages.
- Look for HTTPS (the padlock) before entering a password — that is encryption at work, which we'll cover soon.
Covers: IGCSE 5.3 (solutions), A-Level 6.1 (security measures).
中文
聪明的习惯
- 点击前检查链接的网址,并留意消息的拼写和语气。
- 在输入密码前,确认有 HTTPS(那把小锁) —— 那正是加密在起作用,我们很快会讲到。
涵盖:IGCSE 5.3(解决方案)、A-Level 6.1(安全措施)。
English
Now you try
- First act as a firewall: let the allowed ports through and collect everything else in a blocked list.
- Then match each threat to the defence that stops it.
中文
现在你来试
- 先扮演防火墙:放行允许的端口,把其余的都收进被拦截列表。
- 然后把每个威胁和能阻止它的防御措施配对。
English
Common mistakes
- Use layers: firewall, updates, anti-malware and backups.
- No single measure is enough — this is defence in depth.
中文
常见错误
- 使用多层防御:防火墙、更新、反恶意软件和备份。
- 单一措施不够——这叫纵深防御。
Act as a firewall. Only ports in allowed may pass. Build a list blocked of every requested port that is not · 不 allowed, and print it. · 扮演防火墙。只有 allowed 里的端口可以通过。把所有不被允许的请求端口收进列表 blocked,然后打印它。
Click Run to see the output here. · 点击“运行”查看此处输出。
Match each problem to the defence that stops it: anti-malware, updates or · 或 access levels. · 把每个问题和能阻止它的防御配对:anti-malware、updates 或 access levels。
Click Run to see the output here. · 点击“运行”查看此处输出。