跳到主要内容
学科

AP 网络安全

AP 网络安全是 AP 项目中较新的科目,按"逐层防护"组织:安全导论,随后依次是空间安全、网络 安全、设备安全,以及应用与数据安全。由于课程较新,尚无长期的历年真题存档——课程与考试说明 (CED)中的样题是了解考查方式最可靠的依据。

贯穿全课的核心是 CIA 三要素——机密性、完整性、可用性——大多数题目实质上在问:某项控制措施 保护的是其中哪一项,以及它的代价是什么。能点明威胁、控制措施与权衡取舍的答案,始终优于只 描述某项技术的答案。

这里的术语精确且容易混淆:身份认证不是授权,漏洞不是威胁,加密不是哈希。请记住它们的区别, 而不是大致含义。本站笔记按单元逐一讲解并配有例题;本站 /code 的网络安全课程可在浏览器中 直接完成练习。

训练全部词汇
  • 1

    安全导论

    讲义 词汇表
    1.1

    理解社会工程学

    大纲
    Learning ObjectiveEssential Knowledge

    1.1.A
    Identify common indicators of social engineering tactics.

    • 1.1.A.1 Social engineering attacks employ psychological tactics to manipulate users into revealing sensitive information (elicitation), downloading a malicious file, or clicking on a malicious link. Social engineering can be performed in person but is often done by email, by text message, or through social media messages.
    • 1.1.A.2 Adversaries often use psychological tactics like intimidation and urgency to achieve their goals. Intimidation is when an adversary threatens a target with negative consequences if they don’t comply. Urgency is when an adversary creates reasons why a target should act quickly.

    1.1.B
    Explain how social engineering tactics influence victims to perform a desired action.

    • 1.1.B.1 Social engineering tactics rely on common psychological principles that influence human behavior.
    • 1.1.B.2 Intimidation leverages a natural human aversion to negative consequences. By drawing attention to possible negative consequences, adversaries use fear to incite targets to act.
    • 1.1.B.3 Urgency leverages a natural human response to react quickly to time-sensitive needs. When targets detect a sense of urgency in a message, they feel pressured to respond or act quickly, which can prevent them from taking the time to consider whether an action is reasonable or safe.

    1.1.C
    Describe possible impacts for victims of social engineering attacks.

    • 1.1.C.1 Victims may give an adversary personal information that could lead to impersonation, such as name, phone number, address, workplace, pets’ names, or birthdate. These types of information, and information like them, are often used on websites as challenge questions to verify a user’s identity.
    • 1.1.C.2 Victims may give an adversary secure information like a one-time password (OTP) or authentication login code, which could allow an adversary to log in to a service as the victim.
    • 1.1.C.3 Victims may download malware or click a link that installs malware on their device, steals information from their web browser, or directs them to a website where their login credentials can be captured by an adversary.

    来源:美国大学理事会 AP 课程与考试说明

    钓鱼:假邮件如何窃取密码

    任何计算机系统最弱的部分常常是使用它的社会工程学(social engineering)是诱骗人们破坏安全的艺术——泄露一个密码、打开一个坏文件,或点击一个坏链接。攻击者(我们把他们称为一个对手(adversary))不需要破解代码;他们只需要愚弄一个人。

    大多数社会工程学通过电子邮件、短信或社交媒体发生,尽管它也能亲自或通过电话发生。目标是套取信息(elicitation)——在某人没有意识到的情况下从他们那里获得敏感信息。

    对手依靠两种强大的感觉:

    • 恐吓(intimidation)——对手威胁若你不服从会有一个坏结果。恐惧推动你行动。
    • 紧迫感(urgency)——对手发明一个截止期("在下一个小时内回复否则你的账户关闭")。当我们感到匆忙时,我们停止仔细思考一个行动是否安全。
    社会工程学使用心理压力使一个受害者在思考之前行动
    社会工程学使用心理压力使一个受害者在思考之前行动

    对一个受害者的影响(impact)能是严重的。他们可能透露个人细节(名字、地址、宠物的名字、生日),它们后来被用来回答安全安全问题(challenge questions)并冒充(impersonate)他们。他们可能交出一个一次性密码(OTP)(one-time password),让对手作为他们登录。或他们可能下载从他们浏览器窃取数据的恶意软件(malware)。

    Worked example. 一封钓鱼电子邮件写道:"超过 90% 的员工已经验证了他们的账户——在下一个小时内确认你的,否则失去工资访问。" 两种策略在这里堆叠。"在下一个小时内"是紧迫感(一个催促你的截止期),而"超过 90% 的员工已经"是共识(consensus)(跟随人群的社会压力)。命名每种策略——不只是把这封电子邮件称为"可疑"——正是一个考试答案所需要的。

    探索

    Which social-engineering tactic is it?

    Intimidation threatens harm, urgency invents a deadline, consensus claims everyone else is doing it, and authority pretends to have power over you.

    词汇表 训练
    英文 中文 拼音
    Social engineering 社会工程学 shè huì gōng chéng xué
    adversary 对手 duì shǒu
    elicitation 套取信息 tào qǔ xìn xī
    Intimidation 恐吓 kǒng hè
    Urgency 紧迫感 jǐn pò gǎn
    impact 影响 yǐng xiǎng
    challenge questions 安全问题 ān quán wèn tí
    impersonate 冒充 mào chōng
    one-time password (OTP) 一次性密码 yí cì xìng mì mǎ
    malware 恶意软件 è yì ruǎn jiàn
    phishing 钓鱼 diào yú
    1.2

    可疑的网站登录

    大纲
    Learning ObjectiveEssential Knowledge

    1.2.A
    Identify common signs of a password attack.

    • 1.2.A.1 In an online password attack, adversaries try logging in to a device or service using common passwords, common password patterns, or stolen passwords.
    • 1.2.A.2 Signs of an online password attack include:
      • Many failed attempts to log in over a short duration
      • Login attempts at unusual times
      • Login attempts from unknown devices

    1.2.B
    Explain how adversaries take advantage of weak authentication.

    • 1.2.B.1 Many people use common patterns when creating passwords, such as:
      • Starting a password with one or two words, adding a two-digit number (often signifying a year), and putting a special character at the end
      • Including the names of family or pets in their passwords
      • Including personally significant dates in their passwords
    • 1.2.B.2 Adversaries often construct a dictionary of possible passwords based on personal information gathered about a target (e.g., birthday, anniversary, names of pets and family) and use an automated tool to submit potential passwords.

    1.2.C
    Explain how to make authentication stronger.

    • 1.2.C.1 Users should create passwords that are long, random, and unique. A password manager can be used to generate and store strong passwords, or a user may create long, unique passphrases for their accounts.
    • 1.2.C.2 When creating passwords, users should avoid names, dates, or other personally meaningful words or numbers.
    • 1.2.C.3 When available, users should enable multifactor authentication (MFA), which will require the user to provide extra proof of identity—such as a one-time code—in addition to the password as an extra layer of security.

    来源:美国大学理事会 AP 课程与考试说明

    一个密码攻击(password attack)是任何用猜测或窃取的密码登录的尝试。在一个在线密码攻击中对手对一个真实的登录页面尝试密码。警告迹象在日志里可见:

    • 短时间内许多失败的登录,
    • 在异常时间的登录尝试,
    • 来自未知设备的登录尝试。

    对手成功是因为人们选择(weak)密码。常见的模式包括一个词加一个两位数的年份加一个特殊字符(像 Summer24!),或一个宠物或家庭成员的名字。因为这些模式如此常见,一个对手能从收集到的关于你的信息构建一个可能密码的字典(dictionary)并让一个自动化工具尝试每一个。

    要使身份验证(authentication)更强:

    • 创建长、随机和唯一的密码——一个密码管理器(password manager)能为你生成和存储它们。
    • 避免名字、日期和有意义的词。
    • 打开多因素身份验证(MFA)(multifactor authentication),它在密码之上要求额外的证明(像一个发短信的代码)。
    词汇表 训练
    英文 中文 拼音
    password attack 密码攻击 mì mǎ gōng jī
    weak ruò
    dictionary 字典 zì diǎn
    authentication 身份验证 shēn fèn yàn zhèng
    password manager 密码管理器 mì mǎ guǎn lǐ qì
    multifactor authentication (MFA) 多因素身份验证 duō yīn sù shēn fèn yàn zhèng
    1.3

    公共网络的最佳实践

    大纲
    Learning ObjectiveEssential Knowledge

    1.3.A
    Identify the type of adversary conducting a cyberattack.

    • 1.3.A.1 Adversaries can be classified by their skill levels.
      • Low-skilled adversaries rely on malicious cyber tools created by others that can be purchased online. The tools they use exploit known vulnerabilities.
      • High-skilled adversaries have the capacity to create new malicious cyber tools or modify existing ones to adapt to new defensive techniques and tools. They also have the capacity to discover undocumented vulnerabilities, known as zero days.
    • 1.3.A.2 Adversaries have a variety of motivations, including greed, desire for recognition, dedication to a cause, revenge, politics, or beliefs.

    1.3.B
    Identify types of wireless cyberattacks.

    • 1.3.B.1 In an evil twin attack, an adversary sets up their own wireless access point (WAP) with a service set identifier (SSID) similar or identical to a target network; the adversary’s network is called the evil twin. Victims of this attack could select to unknowingly connect to the evil twin, allowing the adversary to capture their network traffic. The adversary cannot read traffic that uses an encrypted protocol like HTTPS.
    • 1.3.B.2 In a jamming attack, an adversary floods an area with a strong electromagnetic (EM) signal in the same frequency range as the wireless network, which prevents legitimate traffic between the access point (AP) and users. This type of attack that prevents users from accessing resources is called a denial of service (DoS) attack.
    • 1.3.B.3 In a war driving attack, adversaries try to detect wireless network beacons while driving or walking around a target. If a wireless signal is detected, the adversary can gather information about the type of wireless network used and find areas where the wireless signal extends outside the physical building.

    1.3.C
    Describe actions individuals can take to increase protection of sensitive data when using the internet and Wi-Fi.

    • 1.3.C.1 Individuals should verify that the name of any wireless network they join exactly matches the name of the network they intend to join.
    • 1.3.C.2 Most internet protocols are encrypted to protect network traffic. However, individuals may consider the sensitivity of their data in choosing whether to join unencrypted Wi-Fi networks to protect vulnerable data such as DNS queries.
    • 1.3.C.3 Individuals may consider using a virtual private network (VPN), which encrypts all their traffic to the VPN operator’s system. Although this action prevents a service provider from viewing traffic, the VPN provider can view the traffic.

    来源:美国大学理事会 AP 课程与考试说明

    不是所有对手都相同。我们按技能给他们分类:低技能的攻击者在网上购买现成的工具并重用已知的漏洞利用(exploits),而高技能的攻击者写他们自己的工具并能发现全新的洞叫零日漏洞(zero days)。他们的动机(motivation)也不同——贪婪、复仇、政治,或信仰。

    公共 Wi-Fi 是一个最爱的猎场。你必须知道的三种无线攻击:

    • 双胞胎恶意热点(evil twin)——对手设置一个假的接入点(access point),名字(SSID(服务集标识符))从真实的网络复制。受害者连接到假的,而对手读他们的流量(尽管像 HTTPS 这样加密的(encrypted)网站保持安全)。
    • 干扰攻击(jamming)——对手用一个强的无线电信号淹没空中,所以没有人能连接。这是一种拒绝服务(DoS)(denial of service)攻击。
    • 战争驾驶(war driving)——对手四处驾驶,检测无线网络以及它们的信号在哪里泄漏到一栋建筑之外。
    一个双胞胎恶意接入点复制真实网络的名字,所以受害者连接到攻击者
    一个双胞胎恶意接入点复制真实网络的名字,所以受害者连接到攻击者

    要在公共网络上保护你自己:检查网络名字与你打算加入的恰好匹配、偏好加密的网站,并考虑一个虚拟专用网络(VPN)(virtual private network),它把你所有的流量加密给 VPN 运营商。

    词汇表 训练
    英文 中文 拼音
    exploits 漏洞利用 lòu dòng lì yòng
    zero days 零日漏洞 líng rì lòu dòng
    motivation 动机 dòng jī
    Evil twin 双胞胎恶意热点 shuāng bāo tāi è yì rè diǎn
    access point 接入点 jiē rù diǎn
    SSID 服务集标识符 fú wù jí biāo shí fú
    encrypted 加密的 jiā mì de
    Jamming 干扰攻击 gān rǎo gōng jī
    denial of service (DoS) 拒绝服务 jù jué fú wù
    War driving 战争驾驶 zhàn zhēng jià shǐ
    virtual private network (VPN) 虚拟专用网络 xū nǐ zhuān yòng wǎng luò
    1.4

    基于AI的网络安全攻击

    大纲
    Learning ObjectiveEssential Knowledge

    1.4.A
    Explain how adversaries use AI-powered tools to augment cyberattacks.

    • 1.4.A.1 Adversaries can use AI-powered tools that leverage existing voice and image samples of a person to create a digital avatar of that person. The use of these technologies enables adversaries to impersonate someone over the phone or even on a video call, which can lead to financial loss or the sharing of sensitive or private information. As more organizations adopt voice-based authentication, the impact of voice-impersonation has a larger potential impact.
    • 1.4.A.2 Adversaries can use generative AI tools, like large language models (LLMs), to create convincing phishing messages in any target language. Because traditional phishing messages are sometimes written by non-native speakers of the target’s language, unnatural language is a feature that has been used to distinguish phishing messages from legitimate messages. However, with AI tools, adversaries can now craft phishing messages in any language that read as though they were written by a native speaker.
    • 1.4.A.3 Adversaries can craft prompts that extract secure or sensitive information from LLMs. Secure or sensitive information in LLMs can come from user input and the large data sets used to train LLMs.
    • 1.4.A.4 Adversaries can publish websites or modify existing websites to contain false information so that the false information will be included in the training sets for LLMs, causing the LLMs to repeat the false information.
    • 1.4.A.5 Adversaries can perform reconnaissance on a target using AI-powered tools that scan the internet to gather information posted on social media and public websites.
    • 1.4.A.6 Adversaries can use AI-enhanced coding tools to help them write new malware, modify existing application code to perform malicious activities, or to find vulnerabilities in large code bases.

    1.4.B
    Explain how to protect against some AI-augmented cyberattacks.

    • 1.4.B.1 Shared secrets with close friends and relatives that can be used to verify each other’s identities should be established. A secret word or phrase known only to two parties can be used to authenticate identities in high-stakes situations.
    • 1.4.B.2 Multifactor authentication (MFA) should be enabled. If an adversary clones a target’s voice to access a system with voice authentication, requiring a second authentication factor could prevent an adversary from gaining access to accounts.
    • 1.4.B.3 Personal or sensitive data should not be entered into any AI-powered tools, such as chatbots or virtual assistants. Some AI-powered tools feed user input back into the model to provide continuous training. Adversaries could extract data that users have included in prompts.
    • 1.4.B.4 Output from AI-powered tools should be carefully evaluated. Verify information from AI-powered tools using reputable, stable, non-AI-based sources.

    来源:美国大学理事会 AP 课程与考试说明

    人工智能给对手强大的新工具。有足够的语音和图像样本,一个对手能构建一个深度伪造(deepfake)化身在一个通话中冒充某人。大语言模型(LLMs)(large language models)让他们能以完美的、听起来像母语的语言写有说服力的钓鱼(phishing)电子邮件——去除曾经暴露骗局的笨拙措辞。

    AI 也在后端帮助对手:制作从一个 LLM 拉出秘密数据的提示、在网站上植入虚假信息以便它毒害一个 LLM 的训练数据、扫描互联网以收集关于一个目标的事实,甚至写新的恶意软件。

    你能防御许多 AI 增强的攻击:与亲密联系人商定一个共享秘密(shared secret)词以验证身份、启用 MFA(所以一个克隆的声音单独不能登录)、绝不把敏感数据输入一个聊天机器人,并总是对照可靠的、非 AI 的来源仔细检查 AI 输出。

    词汇表 训练
    英文 中文 拼音
    deepfake 深度伪造 shēn dù wěi zào
    Large language models (LLMs) 大语言模型 dà yǔ yán mó xíng
    shared secret 共享秘密 gòng xiǎng mì mì
    1.5

    在网络防御中运用AI

    大纲
    Learning ObjectiveEssential Knowledge

    1.5.A
    Explain how cyber defenders can leverage AI-powered tools to protect networks, applications, and data.

    • 1.5.A.1 AI tools can review current security configurations, like firewall rules and access controls, and recommend more secure options. Recommendations should always be checked by a knowledgeable security technician before being implemented.
    • 1.5.A.2 AI-powered tools can analyze application code to identify vulnerabilities and recommend mitigations. Recommendations should always be reviewed by a knowledgeable programmer before being implemented.
    • 1.5.A.3 AI-powered tools can suggest rules for automated detection systems. Detection rules should always be reviewed by a knowledgeable detection engineer before being added to a system.

    1.5.B
    Explain how AI-powered tools are enabling faster and more accurate threat detection and response.

    • 1.5.B.1 Of the millions of digital events that happen on networks daily, some likely represent an adversary conducting malicious activity. Humans cannot carefully examine all those events to identify the malicious activity.
    • 1.5.B.2 AI-powered tools can be trained to quickly analyze digital events and sort the events that are likely malicious activity from those that are harmless.
    • 1.5.B.3 AI-powered tools can be programmed to alert human cybersecurity personnel when likely malicious activity is detected or to take specific corrective actions based on the type of malicious activity detected.
    • 1.5.B.4 AI-powered tools enable threat-detection and response teams to catch malicious activity and intervene quickly to prevent loss, harm, damage, and destruction to digital infrastructure and data.

    来源:美国大学理事会 AP 课程与考试说明

    同样的技术保护我们。AI 工具能审查防火墙规则和访问设置并推荐更安全的选项——尽管一个人类专家必须总是在应用之前检查建议。AI 能扫描应用代码的弱点并建议检测规则。

    它最大的优势是规模。一个中型网络每天产生数百万个事件——远太多人无法阅读。AI 能快速地把无害的事件从可能恶意的中分类、警报人类员工,或采取一个自动的行动。这让防御者能在几秒而不是几天内捕捉一个攻击并响应,防止损失和损害。

    1.5

    考试技巧

    • 当一个问题要求你给风险排名时,记住高风险 = 高影响并且容易利用。一个停车场 Wi-Fi 泄漏比一个让对手能伪造一个设备的开放内部端口重要性更低。
    • 按名字学社会工程学策略——恐吓、紧迫感、伪装借口(pretexting)、权威(authority)、共识、稀缺(scarcity)、熟悉(familiarity)——并准备好发现一封电子邮件在使用哪一个。
    • 加密在一个双胞胎恶意热点上仍然保护你:对手看到你的流量但不能读 HTTPS。说什么被暴露,不只是"它不安全"。
    • 对于"如何使身份验证更强",MFA 几乎总是答案的一部分,加上来自一个管理器的长/唯一密码。
    • AI 是双重用途的:同样的工具(LLM、代码分析)出现在攻击和防御两侧。仔细读问题以看它问哪一侧。
  • 2

    保护物理空间

    讲义 词汇表
    2.1

    网络安全基础

    大纲
    Learning ObjectiveEssential Knowledge

    2.1.A
    Identify social engineering attacks.

    • 2.1.A.1 Social engineers use psychological tactics to manipulate targets into taking a desired action.
    • 2.1.A.2 Pretexting is when adversaries create a believable reason to contact a target.
    • 2.1.A.3 Authority is when adversaries impersonate someone with power over a target or pretend to relay instructions from that person.
    • 2.1.A.4 Intimidation is when adversaries state negative consequences if demands aren’t met.
    • 2.1.A.5 Consensus is when adversaries create social pressure by making a target believe everyone else is doing a desired action.
    • 2.1.A.6 Scarcity is when adversaries create a sense of limited availability.
    • 2.1.A.7 Familiarity is when adversaries pretend to be or know someone close to a target to establish trust.
    • 2.1.A.8 Urgency is when adversaries create a deadline that requires quick action by a target to avert negative consequences.

    2.1.B
    Identify types of adversaries.

    • 2.1.B.1 Script kiddies are low-skilled adversaries who use tools developed by others without understanding how the tools work. They are often motivated by greed or a desire for recognition.
    • 2.1.B.2 Hacktivists are motivated by social, political, or personal causes. They compromise computers and networks to support their cause or stop perceived harm, believing their goals justify their illegal methods.
    • 2.1.B.3 Insider adversaries are unique threats because they have legitimate credentials and access to systems and data. They can be recruited by malicious third parties and can be motivated by greed or revenge.
    • 2.1.B.4 Cyberterrorists are motivated by politics or beliefs and seek to disrupt entire communities, regions, or nations through cyberattacks (e.g., attacking a power grid, water treatment plant, or other civil infrastructure). They can act independently or on behalf of governments or criminal organizations.
    • 2.1.B.5 Transnational criminal organizations seek financial gain primarily by deploying ransomware and stealing corporate intellectual property (IP) to sell in illegal markets.

    2.1.C
    Describe the phases of a cyberattack.

    • 2.1.C.1 Cyberattacks aim to disrupt, harm, steal, or destroy devices, networks, or data. Adversaries work in phases, which may not all be used in every attack. The phases are:
      • i. Reconnaissance
      • ii. Initial access
      • iii. Persistence
      • iv. Lateral movement
      • v. Taking action
      • vi. Evading detection
    • 2.1.C.2 In the reconnaissance phase of an attack, adversaries gather as much information as possible about their target, often using open source intelligence (OSINT), which is freely available information.
    • 2.1.C.3 In the initial-access phase of an attack, adversaries establish a foothold on the target’s computer, often through social engineering or compromised or weak credentials.
    • 2.1.C.4 After gaining access during an attack, adversaries establish persistence to maintain access without needing to regain it. They may use a command and control (C2) protocol to send commands to the device and receive output, often through malware like a remote access trojan (RAT) or rootkit.
    • 2.1.C.5 In the lateral-movement phase of an attack, adversaries try to escalate their privileges by accessing computers and user accounts with elevated permissions to services and data.
    • 2.1.C.6 In the taking-action phase of an attack, adversaries act on their objectives by collecting targeted data, exfiltrating it, and disrupting services or destroying data.
    • 2.1.C.7 In the final phase of an attack, many adversaries try to evade detection by removing or editing log files and erasing other files they may have planted on devices (e.g., malware).

    2.1.D
    Describe the risk assessment process.

    • 2.1.D.1 Risk occurs when a threat can exploit a vulnerability to compromise an asset.
    • 2.1.D.2 An asset is anything valuable. Assets include financial resources, intellectual property, data, digital infrastructure, physical property, and reputation.
    • 2.1.D.3 Risk assessment considers two factors:
      • The likelihood of an attack against a specific vulnerability
      • The severity of the projected damage from an attack against a specific vulnerability
    • 2.1.D.4 The likelihood of a vulnerability being exploited depends on many factors, including:
      • The value of the target: Adversaries are more likely to attack targets they perceive as valuable.
      • The level of skill required to exploit the vulnerability (i.e., the difficulty): Vulnerabilities with well-documented exploits often require less skill and can be carried out by more adversaries.
      • The motivation and capabilities of likely adversaries: Highly motivated and skilled adversaries are more likely to be able to perform more complex exploits.
    • 2.1.D.5 The severity of an attack is often measured by financial cost, which can also include reputational and operational impacts.
      • Illustrative examples for 2.1.D.5:
        • A hacktivist is passionate about illegal fishing practices supported by a local food production company. The main webpage of this food production company would be a high-value target for this hacktivist; defacing the webpage to expose the company’s support of illegal fishing would provide no financial gain to the adversary, but would allow them to raise awareness about an issue that motivates them.
    • 2.1.D.6 The result of a risk assessment can be quantitative or qualitative.
      • Quantitative risk assessment assigns a numeric value to a vulnerability based on a numeric scale (e.g., 1–10) or quantifiable impact, which could be financial (e.g., a $10,000 annual risk).
      • Illustrative examples for 2.1.D.6:
        • Low, medium, high, severe
        • Unlikely low impact, likely low impact, unlikely high impact, likely high impact
    • 2.1.D.7 Risk assessment documentation should include:
      • Vulnerable assets and their value
      • Descriptions of likely threats to the assets
      • Details of specific vulnerabilities for specific assets and how they would be exploited
      • An explanation of the severity of damage (financial, operational, reputational, etc.) if a specific asset were compromised, and the likelihood of that compromise occurring
      • A final rating, quantitative or qualitative, for each risk identified
      • Illustrative examples for 2.1.D.7:
        • Scaled score (e.g., 1–10)
        • Monetary value (e.g., a $10,000 risk vs. a$100,000 risk)

    2.1.E
    Identify strategies for managing risk.

    • 2.1.E.1 Once a risk has been identified and assessed, an organization has four options for managing that risk:
      • i. Avoid
      • ii. Transfer
      • iii. Mitigate
      • iv. Accept
    • 2.1.E.2 Risk avoidance stops the activity that is generating the risk. If the activity is a critical part of an organization’s mission or purpose, then avoidance is not possible.
    • 2.1.E.3 Risk transference places the burden of the risk on another entity, such as an insurance company, a government, or consumers.
    • 2.1.E.4 Risk mitigation implements security controls to reduce the likelihood or impact of a risk.
    • 2.1.E.5 Residual risk is the risk that remains after an organization has gone through avoidance, transference, and mitigation. The residual risk is the level of risk that an organization is willing to accept. Risk acceptance acknowledges the fact that absolute security is unattainable.
    • 2.1.E.6 To conserve financial resources and employee capacity, an organization will often favor solutions that are cost effective and easy to implement and maintain. Cost-effective solutions cost less to install and maintain than the expected loss from an attack.

    2.1.F
    Identify types of security controls.

    • 2.1.F.1 Security controls address at least one of the following principles:
      • Confidentiality ensures that only authorized individuals, systems, or processes can access data. Systems lacking confidentiality are vulnerable to data theft or destruction.
      • Integrity ensures data are accurate and trustworthy. Systems lacking integrity are vulnerable to data manipulation.
      • Availability ensures data and services are accessible to authorized individuals when needed. Systems lacking availability may experience unexpected downtime.
    • 2.1.F.2 Security controls can be classified by type.
      • Physical controls provide security in the physical space and include locks, fences, and cameras, bollards, and security guards.
      • Technical controls provide security in the digital space and include firewalls, anti-malware software, and encryption.
      • Managerial controls provide rules, guidelines, policies, and procedures that specify what security should be in place and include password policies, regular access reviews, and incident response plans (IRPs).
    • 2.1.F.3 Security controls can be classified by function.
      • Preventative controls address potential vulnerabilities with the goal of stopping an adversary from attacking and include locks and encryption.
      • Detective controls help identify attacks when they occur and include intrusion detection systems (IDSs), cameras, and security incident and event management (SIEM) systems.
      • Corrective controls fix problems and help restore systems to an operational state and include vulnerability patching, repairing a broken card reader, and intrusion prevention systems (IPSs).

    2.1.G
    Explain why a defense-in-depth security strategy is necessary to optimally protect an organization.

    • 2.1.G.1 A defense-in-depth strategy, or layered defense, uses multiple types of security controls to protect sensitive data and systems.
    • 2.1.G.2 A defense-in-depth strategy allows an organization to address different types of threats, each with a security control most suited to mitigate it.
    • 2.1.G.3 A defense-in-depth strategy allows for resilience in data protection so when one security control is bypassed by an adversary, another security control may still prevent access to the data or system or limit the damage done to the data or system.
    • 2.1.G.4 Layers in a defense-in-depth strategy can include human, physical, network, device, application, and data.

    来源:美国大学理事会 AP 课程与考试说明

    在防御一个系统之前,你需要一门共同的语言。这个部分构建它。

    每个安全控制都保护 CIA 三要素(CIA triad)的至少一部分——安全的三个目标:

    • 保密性(confidentiality)——只有授权的人能读数据。
    • 完整性(integrity)——数据是准确的和未被更改的。
    • 可用性(availability)——数据和服务在需要时在那里。
    CIA 三要素:每个安全控制支持的三个目标
    CIA 三要素:每个安全控制支持的三个目标

    攻击来自不同的对手,按他们的目标分类。一个脚本小子(script kiddie)为贪婪或认可重用其他人构建的工具;一个黑客活动分子(hacktivist)为一个政治的、社会的或个人的事业行动;一个内部人员(insider)已经持有合法的访问并可能出于复仇或贪婪行动;一个网络恐怖分子(cyberterrorist)破坏像一个电网或水厂这样的关键基础设施;而跨国犯罪组织(transnational criminal organisations)通过勒索软件和窃取的数据追逐金钱。

    大多数攻击以阶段(phases)展开:侦察(reconnaissance)(收集信息,常常从公开的 公开来源情报(OSINT) 来源)、初始访问、持久化、横向移动(lateral movement)(通过提升权限扩散到更多系统)、对目标采取行动,和逃避检测。命名一个攻击者已经到达的阶段帮助一个防御者选择正确的响应。

    Social engineering: the seven tactics

    大多数攻击不是从代码开始的,而是从社会工程(social engineering)开始 —— 用心理伎俩操纵一个人去做攻击者想让他做的事。考试会点名这七种伎俩,并要求你判断一个情景展示的是哪一种:

    伎俩 手法
    借口(pretexting) 编造一个可信的理由来接触目标("我是 IT 部门的,来核实你的账户")
    权威(authority) 冒充有权势的人,或转达"老板"的指示
    恐吓(intimidation) 威胁说不满足要求就会有负面后果
    从众(consensus) 声称别人都已经在做了,以制造社会压力
    稀缺(scarcity) 编造有限供应("只剩 2 个了")
    熟悉(familiarity) 假装自己是、或认识与目标亲近的人
    紧迫(urgency) 强加一个紧迫的截止时间,让目标不假思索就行动

    它们共同的核心是:这七种全都通过触发一种自动的情绪反应 —— 恐惧、信任、匆忙,或想要合群 —— 来绕过目标的判断力。防御方法每次都一样:在行动前通过另一条可信的渠道去核实

    一个风险(risk)在一个威胁(threat)能利用一个漏洞(vulnerability)来危害一个资产(asset)(任何有价值的东西——数据、金钱、硬件、声誉)时出现。我们通过权衡两样东西评估风险:一个攻击的可能性(likelihood)和损害的严重性(severity)。

    可能性本身取决于目标的价值(攻击者追逐看起来值得偷的东西)、利用该漏洞所需的技能(有完备公开利用方法的漏洞几乎不需要技能,所以更多攻击者用得了它),以及可能的攻击者的动机与能力。严重性通常用财务成本来衡量,但也包括声誉运营上的损害。

    最终的评级可以用两种方式表述,考试要你能把它们区分开:

    • 定量(quantitative)—— 一个数字:某个标度上的分数(例如 1-10),或一个金额(例如"每年 $10,000 的风险")。
    • 定性(qualitative)—— 一个标签:低 / 中 / 高 / 严重,或者一张网格,例如很可能-高影响不太可能-低影响

    一份书面的风险评估(risk assessment)对每一项风险都应记录:易受攻击的资产及其价值、可能的威胁、该具体漏洞会如何被利用、一旦被攻破的严重性,以及一个最终的定量或定性评级。

    一旦一个风险被衡量,一个组织有四种方式来管理它:

    • 规避(avoid)——停止有风险的活动(只在它不是必需的时候可能)。
    • 转移(transfer)——把负担转移给别人,例如一个保险公司。
    • 缓解(mitigate)——添加控制以降低可能性或影响。
    • 接受(accept)——忍受剩下的剩余风险(residual risk),因为完美的安全不可能。

    安全控制以两种方式分组。按类型:物理(physical)(锁、栅栏、警卫)、技术(technical)(防火墙、反恶意软件、加密),和管理(managerial)(政策和程序)。按功能:预防性(preventative)(阻止一个攻击,像一把锁)、检测性(detective)(发现一个攻击,像一个摄像头),和纠正性(corrective)(修复和恢复,像打补丁)。

    Worked example. 一家医院把患者记录存储在一个未上锁房间里的一个未加密的服务器上。给风险评级:资产高度敏感(患者数据,受法律保护)漏洞容易利用(没有加密、没有访问控制),所以这是一个风险。现在分类一个修复——一个门锁:按类型它是一个物理控制,而按功能它是预防性的(它在一个攻击甚至开始之前就阻止进入)。

    最好的策略层叠许多控制——一个纵深防御(defense-in-depth)方法。若一个对手绕过一层,另一层仍然屹立。层包括人、物理、网络、设备、应用和数据。

    纵深防御:许多层,以便一次入侵不暴露资产
    纵深防御:许多层,以便一次入侵不暴露资产
    探索

    Classify each security control by function

    A preventative control stops an attack, a detective control spots one in progress, and a corrective control fixes the damage and restores the system.

    探索

    Classify each security control by type

    A physical control guards the physical space, a technical control works in the digital space, and a managerial control is a rule, policy, or procedure.

    词汇表 训练
    英文 中文 拼音
    CIA triad 信息安全三要素 xìn xī ān quán sān yào sù
    Confidentiality 保密性 bǎo mì xìng
    Integrity 完整性 wán zhěng xìng
    Availability 可用性 kě yòng xìng
    script kiddie 脚本小子 jiǎo běn xiǎo zi
    hacktivist 黑客活动分子 hēi kè huó dòng fèn zǐ
    insider 内部人员 nèi bù rén yuán
    cyberterrorist 网络恐怖分子 wǎng luò kǒng bù fèn zi
    transnational criminal organisations 跨国犯罪组织 kuà guó fàn zuì zǔ zhī
    phases 阶段 jiē duàn
    reconnaissance 侦察 zhēn chá
    OSINT 公开来源情报 gōng kāi lái yuán qíng bào
    lateral movement 横向移动 héng xiàng yí dòng
    social engineering 社会工程学 shè huì gōng chéng xué
    Pretexting 借口 jiè kǒu
    Authority 权威 quán wēi
    Intimidation 恐吓 kǒng hè
    Consensus 从众 cóng zhòng
    Scarcity 稀缺 xī quē
    Familiarity 熟悉 shú xī
    Urgency 紧迫感 jǐn pò gǎn
    risk 风险 fēng xiǎn
    threat 威胁 wēi xié
    vulnerability 漏洞 lòu dòng
    asset 资产 zī chǎn
    likelihood 可能性 kě néng xìng
    severity 严重性 yán zhòng xìng
    quantitative 定量 dìng liàng
    qualitative 定性 dìng xìng
    risk assessment 风险评估 fēng xiǎn píng gū
    Avoid 规避 guī bì
    Transfer 转移 zhuǎn yí
    Mitigate 缓解 huǎn jiě
    Accept 接受 jiē shòu
    residual risk 剩余风险 shèng yú fēng xiǎn
    physical 物理 wù lǐ
    technical 技术 jì shù
    managerial 管理 guǎn lǐ
    preventative 预防性 yù fáng xìng
    detective 检测性 jiǎn cè xìng
    corrective 纠正性 jiū zhèng xìng
    defense-in-depth 纵深防御 zòng shēn fáng yù
    2.2

    物理漏洞与攻击

    大纲
    Learning ObjectiveEssential Knowledge

    2.2.A
    Identify common physical attacks.

    • 2.2.A.1 Adversaries often use social engineering when conducting a physical attack.
    • 2.2.A.2 Piggybacking is the name for an attack where an adversary uses social engineering to manipulate an authorized individual to grant the adversary access to a restricted area. Common piggybacking tactics include carrying something large to entice an authorized person to hold the door open, pretending to be an authorized person who has forgotten their access token, or pretending to be a maintenance person who needs to get into a certain area to perform an inspection or repair.
    • 2.2.A.3 Tailgating is the name for an attack where an adversary gains unauthorized access to a restricted area by following close behind an authorized individual without that individual’s awareness or knowledge.
    • 2.2.A.4 Shoulder surfing is the name for an attack where an adversary watches as a user accesses sensitive information so the adversary can use it later. Sometimes adversaries use a camera to record the target accessing the sensitive information for later analysis.
    • 2.2.A.5 Dumpster diving is the name for an attack where an adversary goes through a target’s physical trash to look for information that could be used to help the adversary reach their goal.
    • 2.2.A.6 Card cloning is the name for an attack where an adversary makes a copy of an authorized user’s access card so they can gain access to all the resources the user is authorized to access.

    2.2.B
    Explain how threats can exploit common physical vulnerabilities to cause loss, damage, disruption, or destruction to assets.

    • 2.2.B.1 Threats include human adversaries seeking to cause harm or disruption as well as natural disasters. Natural disasters can cause physical damage or destruction to computers and data as well as disruption of digital services provided by computers.
    • 2.2.B.2 Vulnerabilities are weaknesses or flaws that could allow an asset to be compromised. Common compromises include:
      • Unauthorized access to sensitive data or restricted physical spaces
      • Disruption of services
      • Theft or destruction of digital or physical resources
      • Unauthorized modification of data
    • 2.2.B.3 When adversaries disrupt power to a device, the device and any services it provides become unavailable. To disrupt power, adversaries may damage fuses or breakers in an electrical box, unplug or cut electrical wiring, or damage power distribution systems like substations and transformers.
    • 2.2.B.4 When adversaries gain access to an area with sensitive information, they can steal or copy sensitive information.
    • 2.2.B.5 When adversaries gain physical access to a device and its ports, they can plug in a keylogger or external drive containing malware, which could allow them to collect data from a user or possibly even to gain control of the device. With direct physical access adversaries can also physically destroy a device, making the device itself, any data stored on it, and any services it provides unavailable.

    2.2.C
    Assess and document risks from physical vulnerabilities.

    • 2.2.C.1 Physical access to devices can allow adversaries to bypass many technical controls and layers of security.
    • 2.2.C.2 High risks from physical vulnerabilities arise when sensitive information or systems are exposed in physical spaces without sufficiently restricted and controlled access.
      • Illustrative examples for 2.2.C.2:
        • A server that stores customer data is in a room with no lock which is accessed via an unmonitored hallway.
    • 2.2.C.3 Moderate risks from physical vulnerabilities arise when a noncritical or nonsensitive part of an organization is left unprotected in a way that it could act as a foothold for an adversary to gain initial access to other resources.
      • Illustrative examples for 2.2.C.3:
        • An office has a reception area beyond which access is controlled; the receptionist has a computer that connects to the office’s internal wireless network and the computer has exposed USB ports.
    • 2.2.C.4 Low risks from physical vulnerabilities arise when a vulnerable asset is of low value and the vulnerability is unlikely to be exploited.
      • Illustrative examples for 2.2.C.4:
        • Employees in an office that requires badge access have laptop computers that they leave on their desks unattended when they all go to lunch together. The computers do not contain any sensitive information, but there are no cables securing the devices to the desks.

    来源:美国大学理事会 AP 课程与考试说明

    若一个对手能简单地走进来,数字安全就毫无意义。常见的物理攻击(physical attacks)常常以社会工程学开始:

    • 尾随(获许可)(piggybacking)——诱骗一个授权的人为你把门开着(例如,通过搬一个重箱子)。
    • 尾随(未察觉)(tailgating)——在某人不知情的情况下跟在他们后面溜过一扇安全的门。
    • 肩窥(shoulder surfing)——观看某人打一个密码或读敏感信息。
    • 翻垃圾搜集情报(dumpster diving)——搜索一个目标的垃圾以找有用的信息。
    • 门禁卡复制(card cloning)——复制一张访问卡以进入受限区域。

    有了物理访问,一个对手能切断电源、窃取或复制数据,或插入一个键盘记录器(keylogger)。当敏感系统坐落在一个没有受控访问的空间时我们把物理风险评为,当一个不重要的区域能作为一个立足点(foothold)去到达其他资源时评为中等,而当资产没有价值且不太可能被攻击时评为

    A padlock on a chain: physical security is the first layer — locks, doors and barriers matter
    A padlock on a chain: physical security is the first layer — locks, doors and barriers matter
    词汇表 训练
    英文 中文 拼音
    physical attacks 物理攻击 wù lǐ gōng jī
    Piggybacking 尾随(获许可) wěi suí ( huò xǔ kě )
    Tailgating 尾随(未察觉) wěi suí ( wèi chá jué )
    Shoulder surfing 肩窥 jiān kuī
    Dumpster diving 翻垃圾搜集情报 fān lā jī sōu jí qíng bào
    Card cloning 门禁卡复制 mén jìn kǎ fù zhì
    keylogger 键盘记录器 jiàn pán jì lù qì
    foothold 立足点 lì zú diǎn
    2.3

    保护物理场所

    大纲
    Learning ObjectiveEssential Knowledge

    2.3.A
    Identify managerial controls related to physical security.

    • 2.3.A.1 Organizations should conduct employee security awareness training to educate employees about how they can contribute to the organization’s security by:
      • Detecting social engineering attempts like phishing
      • Not badging other people into restricted areas
      • Preventing device theft
    • 2.3.A.2 Organizations should have a workstation security policy that outlines the measures necessary to protect a physical workplace. The policy may have tiers of workstation security based on the type of data handled at a workstation. Workstation policies often require:
      • Locking devices before leaving workstations unattended to prevent unauthorized access
      • Clearing sensitive documents off workstations before leaving them unattended (sometimes called a clean desk policy)
      • Using a privacy screen filter or other physical barrier to prevent others from viewing information on the screen
      • Connecting devices to surge protectors or uninterruptible power supplies (UPS)

    2.3.B
    Determine mitigation strategies for risks from physical vulnerabilities.

    • 2.3.B.1 To determine a relevant control, a cyber defender considers how an adversary could take advantage of a vulnerability to attack a system and how to prevent, detect, or correct the attack.
    • 2.3.B.2 Installing physical controls like fencing, gates, and bollards around a building can deter adversaries from trying to physically access an organization’s buildings.
    • 2.3.B.3 Locks on doors, server cabinets, and computers can prevent devices from being accessed or stolen.
    • 2.3.B.4 Card readers can record which employee badges are being used to access different entries at specific times and deny access to unauthorized badges.
    • 2.3.B.5 Access control vestibules and turnstiles can prevent an authorized person from intentionally or accidentally admitting an unauthorized person into a restricted area.
    • 2.3.B.6 Organizations can disable USB ports to prevent external drives from loading malware onto a computer.
    • 2.3.B.7 An uninterruptible power supply (UPS) provides a backup power source for a device in the event of a power outage. Organizations can also use power generators to provide power at a larger scale to a building or set of critical devices.
    • 2.3.B.8 Organizations prioritize risk mitigations based on the severity of the risks and the cost of the recommended mitigations.

    来源:美国大学理事会 AP 课程与考试说明

    管理控制先来:安全意识培训教员工不要给陌生人刷卡进入,而一个工作站安全政策要求锁定设备、清理桌面(一个清桌政策(clean desk policy)),和使用隐私屏。

    物理控制然后加固建筑:栅栏、大门和防撞柱(bollards)阻止访问;锁保护门和柜子;读卡器(card readers)记录和限制进入;一个门禁前室(access control vestibule)(一个两门的气闸)阻止尾随;禁用 USB 端口阻止恶意软件驱动器;而一个不间断电源(UPS)(uninterruptible power supply)在一次断电中保持设备运行。组织通过把一个控制的成本匹配到风险的严重性来给这些排优先级。

    A dome security camera: physical controls and monitoring protect spaces as well as networks
    A dome security camera: physical controls and monitoring protect spaces as well as networks
    词汇表 训练
    英文 中文 拼音
    clean desk policy 清桌政策 qīng zhuō zhèng cè
    bollards 防撞柱 fáng zhuàng zhù
    card readers 读卡器 dú kǎ qì
    access control vestibule 门禁前室 mén jìn qián shì
    uninterruptible power supply (UPS) 不间断电源 bù jiàn duàn diàn yuán
    2.4

    检测物理攻击

    大纲
    Learning ObjectiveEssential Knowledge

    2.4.A
    Identify ways security controls can detect physical attacks.

    • 2.4.A.1 Cameras can capture a visual record of an adversary’s malicious activity. The feed from a camera should be recorded and monitored for maximum effect. Recordings can be especially helpful in after-incident investigations.
    • 2.4.A.2 Security guards can monitor activity in an area and respond to suspicious activity once detected.
    • 2.4.A.3 Motion sensors can alert security to movement in an area.
    • 2.4.A.4 Employees that work in a physical space are often the first to notice the presence of an unauthorized person and can alert security.

    2.4.B
    Determine effective placement of security controls for detecting physical attacks.

    • 2.4.B.1 When placing cameras, consideration should be given to visual coverage, angle, and the ability to be tampered with by an adversary. Consideration should also be given to what a camera in a specific area could capture an adversary doing and how that information would be helpful. Points of ingress and egress are often monitored by camera.
    • 2.4.B.2 Motion sensors should be placed in areas where traffic is unexpected, like server rooms, or areas where sensitive materials are stored and few people have access. Motion sensors in high-traffic areas create many false alarms, making the alarms less likely to be taken seriously when there is a real security event.
    • 2.4.B.3 Locks should be placed on all entries to areas containing sensitive information or systems. For areas with particularly sensitive information or systems, an organization could use an access control vestibule at the entry point to prevent piggybacking or tailgating.
    • 2.4.B.4 Security guards can be stationary or patrolling. Stationary guards can provide constant protection for a specific area, entrance, or high-value item. Patrolling guards are more difficult for an adversary to plan around and can create time pressure for an adversary. Placing stationary guards at places that funnel traffic (e.g., entry gates, main entrances or lobbies, and entrances to more secure access areas) can be highly effective, while patrolling guards are better suited for perimeters and exterior areas.

    2.4.C
    Apply detection techniques to identify physical attacks.

    • 2.4.C.1 Cameras provide visual monitoring and a visual record of activity within a designated space. Cameras can be paired with facial recognition software that can provide alerts when unauthorized individuals enter controlled areas. Once a physical breach has been detected, defenders can use live and recorded camera footage to track an adversary’s path and actions.
    • 2.4.C.2 Motion detectors work best when paired with cameras. When a security alert is raised because a motion detector has been activated, defenders can use cameras to check the space visually and verify a physical security breach.
    • 2.4.C.3 When employees are required to use an electronic badge to unlock a door to a restricted area, a sensor can record how long the door was open. In reviewing entry logs for the door, potential piggybacking or tailgating can be detected by doors being open for longer than normal lengths of time.

    来源:美国大学理事会 AP 课程与考试说明

    一些控制检测攻击而不是预防它们。摄像头记录活动并帮助事后调查;保安对他们看到的响应;运动传感器(motion sensors)向员工警报移动;而员工自己常常最先注意到一个入侵者。

    放置重要。摄像头属于出入口(points of ingress and egress)(入口和出口)。运动传感器在像服务器机房这样的低流量区域工作最好——把它们放在一条繁忙的走廊里,持续的误报会使每个人忽略它们。固定的警卫保护一个固定的高价值点,而巡逻的警卫对一个对手来说更难围绕计划。审查进入日志里的开门时间甚至能揭示尾随,因为一扇被开着太久的门是可疑的。

    词汇表 训练
    英文 中文 拼音
    motion sensors 运动传感器 yùn dòng chuán gǎn qì
    points of ingress and egress 出入口 chū rù kǒu
    2.4

    考试技巧

    • 记住 CIA 三要素并准备好说一个控制保护哪个目标——加密服务于保密性、一个哈希检查完整性、一个备份恢复可用性
    • 知道四种风险响应(规避、转移、缓解、接受)和分类控制的两种方式(按类型:物理/技术/管理;按功能:预防性/检测性/纠正性)。
    • 尾随(获许可)(带同意、被诱骗)与尾随(未察觉)(在那人不知情的情况下)区分开——考试问题考查这个确切的一对。
    • 对于风险评级问题,高风险需要既高价值又容易利用;一个"到其他系统的立足点"是经典的中等风险。
    • 每当一个问题问为什么一个控制不够时,纵深防御是标准答案。
  • 3

    保护网络

    讲义 词汇表
    3.1

    网络漏洞与攻击

    大纲
    Learning ObjectiveEssential Knowledge

    3.1.A
    Identify common network attacks.

    • 3.1.A.1 The address resolution protocol (ARP) is used by a default gateway on a network to establish a table that pairs internet protocol (IP) addresses with media access control (MAC) addresses. An ARP poisoning attack is when an adversary sends falsified ARP packets to the default gateway to modify the table so that the adversary’s device receives traffic intended for the target by linking the target’s IP address to the adversary’s MAC address. Faking a MAC address is called MAC spoofing. This is an example of an on-path attack (or man-in-the-middle attack), which is when an adversary interrupts a data stream between two parties, captures both parties’ data, and copies or alters the data before sending them on. Both parties think they are communicating directly with each other, but instead they are each communicating with the adversary who is secretly intercepting their messages.
    • 3.1.A.2 A MAC flooding attack is when an adversary sends the target switch many Ethernet frames, each with a different MAC address. This can force the switch into broadcast mode, and the adversary can then collect all of the frames on the network (because they are being broadcast), which could allow the adversary to access sensitive information. This is an example of eavesdropping (or sniffing), which is when an adversary captures data in transit and can record and copy the data.
    • 3.1.A.3 A domain name system (DNS) poisoning attack is when an adversary pretends to be an authoritative name server (NS) and plants a fake DNS record on a DNS server to redirect browser traffic to a malicious website designed to steal credentials. This is an example of credential harvesting, which is when adversaries set up a fake login site that looks like a real one. Unsuspecting users enter their real credentials, which the adversaries capture and use.
    • 3.1.A.4 A smurf attack attempts to overwhelm a network with Internet Control Message Protocol (ICMP) requests. It is a type of denial of service (DoS) attack, which makes a system or resource unavailable to authorized users. During a smurf attack, an adversary sends many ICMP requests with the victim’s address to the network’s broadcast address. The network’s gateway then sends these requests to all devices on the network. Each device on the network replies to the victim’s address, creating a flood of traffic that can block legitimate messages. When multiple devices attack the same target simultaneously, it’s called a distributed denial of service (DDoS) attack.

    3.1.B
    Explain how adversaries can exploit network vulnerabilities to steal, disrupt, or destroy network communication.

    • 3.1.B.1 Adversaries can send malicious traffic into a network to flood it creating a DoS, to map the internal structure of the network, or to spoof a legitimate device. Networks without firewalls, or with improperly configured firewalls, are vulnerable to these types of attacks.
    • 3.1.B.2 Adversaries that have compromised a device often attempt to leverage their access to compromise other devices on the local area network (LAN).
    • 3.1.B.3 Adversaries that physically plug into a data port can gain access to a LAN through the switch port unless port security is enabled. This allows adversaries to launch DoS attacks or perform MAC flooding or MAC spoofing attacks.
    • 3.1.B.4 Adversaries standing outside of physically secure spaces can pick up the signals and beacon frames from a wireless access point that is broadcasting outside the physical space. This allows them to gather information about the wireless network and to attempt eavesdropping and cryptographic attacks on it.
    • 3.1.B.5 Adversaries can attempt to join networks to launch attacks from within the networks. Networks that do not authenticate devices and users make it easier for adversaries to join.
    • 3.1.B.6 If there is an open network port, an adversary can plug a wireless access point into the port creating a rogue access point. The adversary could use this rogue access point to access the internal network wirelessly (maybe even from outside the physical space). This allows the adversary direct access to the LAN, bypassing any firewalls.
    • 3.1.B.7 Adversaries can attempt to break wireless encryption and intercept, steal, or compromise data on a network.

    3.1.C
    Assess and document risks from network vulnerabilities.

    • 3.1.C.1 Vulnerabilities on a network can lead to adversaries being able to intercept and alter data in transit, launch DoS attacks, or move laterally on a network to gain access to more sensitive or critical systems. Network vulnerabilities can constitute a risk to confidentiality, integrity, and availability.
    • 3.1.C.2 There are automated vulnerability scanners that can check networks, devices, and applications for known vulnerabilities. These scanners produce a report that often includes the vulnerabilities detected, their severity, and mitigation recommendations.
    • 3.1.C.3 Successfully exploiting a network vulnerability often requires advanced technical ability and knowledge. This can impact the likelihood of an exploit.
    • 3.1.C.4 High risks from network vulnerabilities allow an adversary to easily have a significant impact by capturing network traffic, spoofing a legitimate device on the network, or launching a DoS attack.
      • Illustrative examples for 3.1.C.4:
        • An organization has a single unsegmented internal network that is accessible via a wireless network with weak encryption, and on that network it has a server running its proprietary web-application.
    • 3.1.C.5 Moderate risks from network vulnerabilities could include vulnerabilities that might give adversaries the ability to gain information about systems or devices on a network.
      • Illustrative examples for 3.1.C.5:
        • An organization’s external firewall is not configured to block external ICMP traffic.
    • 3.1.C.6 Low risks from network vulnerabilities include vulnerabilities that would be difficult to exploit and would likely have minimal negative impacts on an organization.
      • Illustrative examples for 3.1.C.6:
        • An organization has wireless access points that broadcast a beacon frame, which contains the network service set identifier (SSID) and the wireless encryption protocols.

    来源:美国大学理事会 AP 课程与考试说明

    中间人攻击
    DDoS:僵尸网络淹没服务器

    一个网络连接设备,以便它们能共享数据——而每个连接都是一个可能的入口。你必须知道经典的网络攻击和它们背后的诡计。

    • 地址解析投毒(ARP poisoning)——地址解析协议(ARP)(address resolution protocol)把 IP 地址与硬件 物理地址(MAC 地址)(MAC addresses)配对。一个对手发送假的 ARP 消息,以便本该发给目标的流量转而流向对手。这是一个中间人攻击(on-path attack)(也叫 man-in-the-middle):对手秘密地坐在两方之间,读甚至更改他们的消息。
    • 物理地址泛洪(MAC flooding)——用假的 MAC 地址淹没一个交换机(switch)迫使它进入广播模式,所以对手能捕获所有流量。这是窃听(eavesdropping)的一种形式。
    • 域名投毒(DNS poisoning)——在一个域名系统(DNS)(domain name system)服务器上植入一个假记录,把用户重定向到一个恶意网站以窃取凭据(凭据收集(credential harvesting))。
    • Smurf 攻击(Smurf attack)——用瞄准广播地址的 ICMP 请求淹没一个网络,所以每个设备都回复受害者。它是一个拒绝服务(DoS)(denial of service)攻击;当许多机器同时攻击时它变成一个分布式拒绝服务(DDoS)(distributed denial of service)。

    对手利用弱的网络来淹没、映射或伪造设备。一个没有端口安全的物理数据端口让一个攻击者能插入;一个开放的端口让他们能安装一个完全绕过防火墙的非法接入点(rogue access point)。我们按影响和漏洞利用需要多少技能给网络风险评级。

    为了在对手之前找到弱点,组织运行一个自动漏洞扫描器(automated vulnerability scanner):一个把网络、设备和应用对照一个已知漏洞数据库检查的工具,然后生成一份报告,列出找到的每一个漏洞、它有多严重,以及一个推荐的缓解措施(mitigation)。优先修复最严重的项目是管理网络风险的核心部分。

    探索

    Identify the network attack from its evidence

    Each network attack leaves a distinct trace: ARP poisoning = one IP with two MACs; MAC flooding = a surge of new MACs; DNS poisoning = misdirected web traffic; smurf/DoS = a flood that blocks legitimate traffic.

    词汇表 训练
    英文 中文 拼音
    ARP poisoning 地址解析投毒 dì zhǐ jiě xī tóu dú
    address resolution protocol (ARP) 地址解析协议 dì zhǐ jiě xī xié yì
    MAC addresses 物理地址 wù lǐ dì zhǐ
    on-path attack 中间人攻击 zhōng jiān rén gōng jī
    MAC flooding 物理地址泛洪 wù lǐ dì zhǐ fàn hóng
    switch 交换机 jiāo huàn jī
    eavesdropping 窃听 qiè tīng
    DNS poisoning 域名投毒 yù míng tóu dú
    domain name system (DNS) 域名系统 yù míng xì tǒng
    credential harvesting 凭据收集 píng jù shōu jí
    denial of service (DoS) 拒绝服务 jù jué fú wù
    distributed denial of service (DDoS) 分布式拒绝服务 fēn bù shì jù jué fú wù
    rogue access point 非法接入点 fēi fǎ jiē rù diǎn
    automated vulnerability scanner 自动漏洞扫描器 zì dòng lòu dòng sǎo miáo qì
    mitigation 缓解措施 huǎn jiě cuò shī
    3.2

    保护网络:管理性控制与无线安全

    大纲
    Learning ObjectiveEssential Knowledge

    3.2.A
    Identify managerial controls related to network security.

    • 3.2.A.1 A router security policy will set forth a minimum configuration standard for routers on an organization’s network and may include:
      • Banning local user accounts (All router logins must use an approved authentication server.)
      • Disabling unnecessary services (e.g., Telnet)
      • Requiring a firewall (An organization may opt for a firewall device separate from the router.)
    • 3.2.A.2 A switch security policy will set forth a minimum configuration standard for switches on an organization’s network and may include:
      • Banning local user accounts (All switch logins must use an approved authentication server.)
      • Requiring port security to be enabled.
      • Using MAC filtering
    • 3.2.A.3 A virtual private network (VPN) policy will detail the minimum security requirements for employees using a VPN to access an organization’s internal network, and it may include:
      • A list of roles within the organization that are allowed to use a VPN to access the organization’s internal network
      • Authentication requirements for employees using a VPN (e.g., public/private key system or MFA)
      • A prohibition against split tunneling (also called dual tunneling)
    • 3.2.A.4 A wireless security policy will establish the minimum security requirements for wireless networks within an organization and may include:
      • Requiring users to authenticate to the wireless network through an extensible authentication protocol (EAP) connected to an approved authentication server
      • Requiring all wireless traffic to be encrypted using AES encryption with a minimum key length
      • Disabling beacon frames on wireless access points

    3.2.B
    Configure wireless network security features.

    • 3.2.B.1 Organizations can disable beacon frame broadcasting on wireless access points (WAPs) to make it harder for adversaries to find their wireless network and learn its basic properties.
    • 3.2.B.2 Organizations can control the broadcast direction and signal strength of a WAP so the signal does not extend beyond the physical space the access point is meant to cover.
    • 3.2.B.3 Organizations should enable strong wireless encryption protocols to ensure wireless frames are not readable by adversaries who might intercept them.
      • WEP, WPS, and the original WPA wireless encryption protocols have known vulnerabilities and are insecure.
      • WPA3 is currently the strongest wireless encryption algorithm.
    • 3.2.B.4 Organizations can enable MAC filtering to prevent unauthorized devices from accessing the network, and they can require users to authenticate when joining a network.

    来源:美国大学理事会 AP 课程与考试说明

    好的网络安全以设定一个最低标准的书面政策开始:一个路由器安全政策交换机安全政策禁止本地账户并要求端口安全;一个 VPN 政策设定身份验证规则并禁止分离隧道(split tunneling);而一个无线安全政策要求强的加密和经过认证的访问。

    具体对于无线网络,组织禁用信标帧以便网络更难被找到、控制信号强度以便它不泄漏到建筑之外、启用强的加密——WPA3(无线加密协议)是当前最强的,而旧的 WEP 和原始的 WPA 被破解——并使用 MAC 过滤以只允许已知的设备。

    词汇表 训练
    英文 中文 拼音
    split tunneling 分离隧道 fēn lí suì dào
    3.3

    保护网络:网络分段

    大纲
    Learning ObjectiveEssential Knowledge

    3.3.A
    Identify techniques for segmenting a network.

    • 3.3.A.1 Firewall zones and rules can be used to create a screened subnet (also known as a demilitarized zone, or DMZ)—a network segment that sits between public, external networks like the internet and internal, private networks. A screened subnet is typically a lower security zone than the internal, private networks, and it typically holds an organization’s publicly facing resources, separating them from the internal network.
    • 3.3.A.2 Subnetting can be used to create different subnets based on IP addressing. If a device is compromised by an adversary, subnets can contain a security breach to reduce the number of exposed devices.
    • 3.3.A.3 Switches can be used to create VLANs, which logically separate devices physically connected to central switches.

    3.3.B
    Explain why network segmentation can increase network security.

    • 3.3.B.1 Network segmentation refers to the process of dividing a network into smaller, isolated segments or subnetworks (subnets).
    • 3.3.B.2 Dividing a network into smaller subnets isolates network traffic, which can prevent attacks on one subnet from impacting devices on other subnets.
    • 3.3.B.3 Network segmentation can allow for different security policies and controls to be applied to different segments of the network, allowing for higher security zones and lower security zones.
    • 3.3.B.4 Port security on a switch can prevent MAC flooding by limiting the number of addresses assignable to any single switch port.

    来源:美国大学理事会 AP 课程与考试说明

    网络分段(network segmentation)把一个网络分成更小的、隔离的片段(子网(subnets))。若一个子网被入侵,损害被遏制并不能扩散。

    一个关键的模式是屏蔽子网(screened subnet)(也叫一个 DMZ(隔离区))。它坐在公共互联网和私有内部网络之间,把一个组织面向公众的服务器放在一个较低安全的区域——与敏感的内部系统分开。

    一个屏蔽子网(DMZ)把公共服务器放在两个防火墙之间,远离私有网络
    一个屏蔽子网(DMZ)把公共服务器放在两个防火墙之间,远离私有网络

    分段也能用子网划分(subnetting)(按 IP 地址)或 VLAN(虚拟局域网)(在逻辑上分开同一交换机上的设备)构建。每个分段然后能得到它自己的安全政策——较高安全和较低安全的区域。

    Server racks: network segmentation isolates systems so one breach does not open everything
    Server racks: network segmentation isolates systems so one breach does not open everything
    词汇表 训练
    英文 中文 拼音
    Network segmentation 网络分段 wǎng luò fēn duàn
    subnets 子网 zi wǎng
    screened subnet 屏蔽子网 píng bì zi wǎng
    3.4

    保护网络:防火墙

    大纲
    Learning ObjectiveEssential Knowledge

    3.4.A
    Identify types of network-based firewalls.

    • 3.4.A.1 A firewall is used to allow or deny network traffic in or out of a network. The firewall itself is software that can be hosted on a standalone device or integrated into another network device, such as a router.
    • 3.4.A.2 A stateless firewall filters traffic based on information in packet headers, such as IP addresses, ports, and protocols.
    • 3.4.A.3 A stateful firewall (also known as dynamic packet filtering) tracks the state of network connections passing through the firewall and can filter according to connection-related rules in addition to the filtering done by a stateless firewall. This allows for more control over content allowed in and out of a network.
    • 3.4.A.4 A next-generation firewall (NGFW) has both the capabilities of typical stateless and stateful firewalls and additional advanced features, such as intrusion prevention, deep packet inspection, and filtering by application type.

    3.4.B
    Explain how a firewall uses an access control list to allow or deny traffic entering or leaving a network.

    • 3.4.B.1 Network administrators create a set of rules, called an access control list (ACL), that a firewall uses to permit or deny inbound and outbound network traffic.
    • 3.4.B.2 ACL rules are checked in order and the first rule that matches the criteria will be executed for the specified data.
    • 3.4.B.3 A typical ACL will specify the direction of traffic (inbound or outbound), the criterion to filter by (IP addresses, logical port, service, or application), and the action to take (permit or deny).

    3.4.C
    Determine the effective placement of firewalls in a network.

    • 3.4.C.1 Each segment of a network should have a firewall to control the flow of data in and out of that segment.
    • 3.4.C.2 Network segments may have different security needs based on the data and services within them. The level of security for each firewall can be set independently.
    • 3.4.C.3 Each point of data ingress and egress between the internal network and the public internet should have a firewall.

    3.4.D
    Configure a firewall to manage the flow of network traffic.

    • 3.4.D.1 The requirements for a firewall will specify what type of traffic from which sources or to which destinations should be allowed or denied.
    • 3.4.D.2 Specific rules for a firewall can allow or deny inbound or outbound traffic based on source or destination port or IP address, service, protocol, or application.
      • Illustrative examples for 3.4.D.2:
        • Allow inbound TCP port 22 from ALL; (this rule will allow all inbound TCP traffic with destination port 22, which is the designated port for the SSH protocol)
        • Deny inbound TCP port 80 from 192.168.1.0/24; (this rule will deny inbound TCP traffic with destination port 80 from IP addresses in the 192.168.1.0-192.168.1.255 range)
    • 3.4.D.3 Rules are implemented in order, and changing the order of a set of rules can change which traffic is allowed or denied. Consideration must be given to the precedence of filtering priorities when establishing the order of rules.
      • Illustrative examples for 3.4.D.3:
        • This set of rules would allow SSH traffic and deny other inbound TCP traffic
        • Rule 1: ALLOW inbound TCP port 22 from ALL;
        • Rule 2: DENY inbound TCP ALL from ALL;
        • Reversing the order of those rules would deny all inbound TCP traffic including SSH traffic.

    来源:美国大学理事会 AP 课程与考试说明

    防火墙如何判断

    一个防火墙(firewall)允许或拒绝进入或离开一个网络的流量。有几种:

    • 无状态(stateless)——只在数据包头(IP、端口、协议)上过滤。
    • 有状态(stateful)——也追踪每个连接的状态(state)以进行更细的控制。
    • 下一代(NGFW)(next-generation)——添加像入侵防御和深度包检测这样的高级功能。

    一个防火墙遵循一个访问控制列表(ACL)(access control list)——一组有序的规则。规则按顺序检查,而第一个匹配获胜,所以规则的顺序改变哪些流量通过。每条规则指定一个方向、一个过滤依据(IP、端口、服务),和一个动作(允许或拒绝)。

    一个防火墙从上到下检查它的 ACL;第一个匹配的规则决定
    一个防火墙从上到下检查它的 ACL;第一个匹配的规则决定

    Worked example. 一个防火墙有规则 3:DENY TCP 443 from 192.168.*,而更下面规则 7:ALLOW TCP 443 from ALL。一个在 192.168.45.37 的用户不能到达端口 443——即使规则 7 会允许他们——因为规则 3 先匹配,而第一个匹配获胜。修复是把 ALLOW 规则移到 DENY 之上。这就是为什么规则顺序、不只是规则内容,决定哪些流量通过。

    防火墙属于数据在区域之间跨越的每个点——在每个网络分段和在到公共互联网的每个网关。

    词汇表 训练
    英文 中文 拼音
    firewall 防火墙 fáng huǒ qiáng
    Stateless 无状态 wú zhuàng tài
    Stateful 有状态 yǒu zhuàng tài
    access control list (ACL) 访问控制列表 fǎng wèn kòng zhì liè biǎo
    3.5

    检测网络攻击

    大纲
    Learning ObjectiveEssential Knowledge

    3.5.A
    Identify types of automated security tools used to detect network attacks.

    • 3.5.A.1 Automated detection tools analyze data collected from an organization’s network and devices, such as switches and routers, servers, firewalls, and user computers. These data are often collected in a log file.
    • 3.5.A.2 A network intrusion detection system (NIDS) is an automated tool that analyzes data to determine if malicious activity is taking place on a network. When an attack is detected, it generates an alert.
    • 3.5.A.3 A network intrusion prevention system (NIPS) is an automated tool that, like an IDS, analyzes data to determine if malicious activity is taking place on a network. A NIPS can also mitigate or halt an attack by closing ports, blocking specific IP or MAC addresses, or rejecting specific protocols.
    • 3.5.A.4 A security information and event management (SIEM) system collects and analyzes data from multiple sources (including firewalls, NIDS/NIPS, device logs, and application logs) to detect patterns that may indicate a cyberattack and raises an alert if a potential attack is detected. Security analysts investigate the alert to determine whether it represents a true threat and follow standard operating procedures to resolve or escalate the alert.

    3.5.B
    Explain how organizations can leverage artificial intelligence (AI) to enhance threat detection and response.

    • 3.5.B.1 Computers log every action that users take. Firewalls, IDS, IPS, and other network sensors log all the traffic passing through various points in a network. A medium-sized organization’s network is logging millions (or even tens of millions) of data points per day. Even a large team of humans is incapable of analyzing so much data.
    • 3.5.B.2 Threat detection teams are creating AI algorithms to analyze large amounts of data and classify the data patterns as malicious or normal.
    • 3.5.B.3 AI models for threat detection are based on probabilistic calculations; they report a percentage to indicate the likelihood that something is malicious.
    • 3.5.B.4 Organizations determine their own thresholds for what percentage of likelihood of a threat results in an alert. If the threshold is set too high, real attacks may go undetected; if the threshold is too low, the security team will be overwhelmed with false alerts.

    3.5.C
    Determine a network detection method.

    • 3.5.C.1 Volume of network traffic is a criterion for determining a detection method. Signature-based detection is more efficient for networks with high traffic volume. Signature-based detection compares detection data to a database of known indicators of compromise (IoCs), called signatures. Signature databases must be updated with IoCs for the latest attacks. Signature-based detection runs more quickly than anomaly-based detection.
    • 3.5.C.2 Consistency of network traffic patterns is a criterion for determining a detection method. Anomaly-based detection is most effective on networks with consistent traffic patterns. Anomaly-based detection compares detection data to a baseline of recorded activity. Baselines must be recorded on uncompromised systems to establish expected data types and volumes. Anomaly-based detection triggers an alert or action when data types or volumes outside of a specified tolerance range are recorded. Anomaly-based detection relies on consistent patterns in network traffic to detect anomalous traffic patterns.
    • 3.5.C.3 Degree of sensitivity or criticality of a network is a criterion for determining a detection method. Networks with more sensitive or critical data or services will likely consider a hybrid approach. Hybrid detection combines signature-based and anomaly-based detection. Hybrid detection is more expensive than using either signature- or anomaly-based detection alone, and hybrid-detection models generate more alerts.
    • 3.5.C.4 Likelihood of novel attacks on a network is a criterion for determining a detection method. Signature-based detection cannot detect a new attack. When an organization suspects that adversaries are likely to attempt a new attack on a network, anomaly-based detection is the preferred method when the cost of hybrid detection is prohibitively high.

    3.5.D
    Evaluate the impact of a network detection method.

    • 3.5.D.1 Speed of detection is a factor in evaluating the impact of a network detection method. Faster detection enables faster response. Signature-based detection methods are faster than anomaly-based detection methods, especially on networks with high traffic volume.
    • 3.5.D.2 Cost is a factor in evaluating the impact of a network detection method. Detection tools and ongoing costs need to be within a budget. Anomaly-based detection systems require more expensive hardware to operate than signature based. Hybrid detection is the most expensive option because it combines both anomaly- and signature-based methods.
    • 3.5.D.3 False positive rate is a factor in evaluating the impact of a network detection method. Signature-based detection has almost no false positives. Anomaly-based or hybrid detection will have higher false positive rates. Impacts of high false positive rates include:
      • Time and resources are put toward investigating alerts for nonmalicious activity.
      • Alert fatigue is a condition that occurs when responders get accustomed to false positives and take alerts less seriously because they assume alerts are false positives before investigating them.
    • 3.5.D.4 False negative rate is a factor in evaluating the impact of a network detection method. A false negative occurs when an adversary can bypass a detection system. Signature-based detection systems are easier to bypass than anomaly-based or hybrid systems. False negatives can result in adversaries causing loss, harm, disruption, or destruction to data and systems.

    3.5.E
    Apply detection techniques to identify indicators of network attacks by analyzing log files.

    • 3.5.E.1 Evil-twin attacks can be detected by regularly scanning for service set identifiers (SSIDs) that look suspicious or similar to local legitimate SSIDs. Signal triangulation can be used to locate and disable an access point broadcasting an evil-twin network.
    • 3.5.E.2 Jamming attacks can be detected by recognizing that no wireless devices in a specific physical space are able to connect to a wireless network and by scanning for electromagnetic (EM) noise in the wireless range.
    • 3.5.E.3 ARP poisoning attacks can be detected by monitoring network traffic for unusual ARP messages (particularly duplicate MAC address ARP packets) and checking the ARP table on the default gateway.
    • 3.5.E.4 MAC flooding attacks can be detected by monitoring network traffic for an unexpected surge of Ethernet frames with different MAC addresses and checking the MAC address table on a switch.
    • 3.5.E.5 DNS poisoning attacks are difficult to detect. However, if an organization’s website experiences an abrupt and otherwise inexplicable drop in traffic, DNS records should be examined as a potential cause.
    • 3.5.E.6 Smurf attacks can be detected by watching network traffic for a sudden increase in ICMP requests sent to the network’s broadcast address.
    • 3.5.E.7 Network-based IoCs are discovered when analyzing network traffic, often in the form of packet capture files. Indicators can be found in source and destination IP addresses, ports, and protocols. These can include:
      • Connections to known malicious IP addresses
      • Unauthorized network scans
      • Unusual spikes or slow downs in network traffic
      • Mismatched port-application traffic

    来源:美国大学理事会 AP 课程与考试说明

    当预防失败时,检测接管。自动化工具读记录网络活动的日志文件(log files):

    • 一个网络入侵检测系统(NIDS)(network intrusion detection system)分析流量并发出警报,但不阻止;
    • 一个网络入侵防御系统(NIPS)(network intrusion prevention system)也能通过关闭端口或阻止地址来停止一个攻击;
    • 一个安全信息与事件管理(SIEM)(security information and event management)系统从许多来源收集数据以发现模式。

    有两种检测方法。基于特征(signature-based)检测把流量与一个已知攻击特征(signatures)的数据库比较——快而误报少,但对全新的攻击视而不见。基于异常(anomaly-based)检测把流量与一个正常的基线(baseline)比较并标记任何不寻常的——它能捕捉新颖的攻击但需要更多资源并引发更多误报。一个混合方法结合两者。

    检查捕获的流量(数据包捕获文件)时,分析师在源和目的 IP 地址、端口和协议里搜寻网络入侵指标(network-based indicators of compromise)。四种常见的:与已知恶意 IP 地址的连接、未授权的网络扫描(一个外部人探测你的端口)、流量中不寻常的激增或减缓,以及端口与应用不匹配的流量(例如,非网页流量经端口 80 流动)。这些补全了单个设备记录的基于主机、文件和行为的指标。

    AI, thresholds, and alert fatigue

    一个中型网络每天记录数百万条事件 —— 远超任何团队能读的量 —— 所以组织训练 AI 模型,把很可能是恶意的模式从正常的当中分拣出来。这些模型是概率的(probabilistic):它给出的不是是/否,而是给每条事件一个是恶意的百分比可能性。

    组织随后设定一个阈值(threshold)—— 达到这个可能性就触发警报 —— 而这个选择是一个实实在在的权衡:

    • 阈值设得太高,真正的攻击就会未被检测地溜过去;
    • 设得太低,团队就会被误报淹没

    太多误报会造成警报疲劳(alert fatigue):响应人员对误报习以为常,以至于在调查之前就先假定一条警报是假的 —— 于是当真正的攻击终于到来时,它被挥手放过了。这正是低误报率之所以重要的原因:基于特征的检测几乎没有误报,而基于异常和混合检测则用更高的误报率换取捕捉新颖攻击的能力。

    基于特征的检测匹配已知攻击;基于异常的检测标记与正常的偏离
    基于特征的检测匹配已知攻击;基于异常的检测标记与正常的偏离
    词汇表 训练
    英文 中文 拼音
    log files 日志文件 rì zhì wén jiàn
    network intrusion detection system (NIDS) 网络入侵检测系统 wǎng luò rù qīn jiǎn cè xì tǒng
    network intrusion prevention system (NIPS) 网络入侵防御系统 wǎng luò rù qīn fáng yù xì tǒng
    security information and event management (SIEM) 安全信息与事件管理 ān quán xìn xī yǔ shì jiàn guǎn lǐ
    Signature-based 基于特征 jī yú tè zhēng
    Anomaly-based 基于异常 jī yú yì cháng
    baseline 基线 jī xiàn
    network-based indicators of compromise 网络入侵指标 wǎng luò rù qīn zhǐ biāo
    probabilistic 概率的 gài lǜ de
    threshold 阈值 yù zhí
    alert fatigue 警报疲劳 jǐng bào pí láo
    3.5

    考试技巧

    • 对于防火墙-ACL 问题,从上到下读规则并在第一个匹配处停止——一个在 Allow 之上的 Deny 规则阻止流量,即使 Allow 在更下面存在。
    • 把每个攻击与它的明显迹象配对:ARP 投毒 = 一个 IP 带两个 MAC 地址;MAC 泛洪 = 新 MAC 地址的一次激增;DNS 投毒 = 网络流量的一次无法解释的下降。
    • 基于特征 = 快、少误报、漏掉新攻击(更多漏报);基于异常 = 捕捉新攻击、花费更多、更多误报。记住这个权衡。
    • 数据包捕获寻找基于网络的入侵指标:已知恶意 IP、未授权扫描、流量激增/减缓,以及端口与应用不匹配的流量。
    • 运行漏洞扫描器主动找出已知的弱点,并优先修复最严重的发现。
    • 一个屏蔽子网 / DMZ 把面向公众的服务器放在互联网和私有网络之间——每当一个问题把公共服务与内部数据分开时命名它。
    • WPA3 是强的无线加密;WEP 和原始的 WPA 不安全。
    词汇表 训练
    英文 中文 拼音
    WPA3 Wi-Fi 保护接入第三代 bǎo hù jiē rù dì sān dài
    DMZ 隔离区 gé lí qū
    VLANs 虚拟局域网 xū nǐ jú yù wǎng
  • 4

    保护设备

    讲义 词汇表
    4.1

    设备漏洞与攻击

    大纲
    Learning ObjectiveEssential Knowledge

    4.1.A
    Identify types of computing devices.

    • 4.1.A.1 Server computers are devices that provide one or more services to other computers (e.g., DNS, DHCP, FTP). Any computer can be a server, and in an enterprise environment servers typically have more processing power and storage than a personal computer.
    • 4.1.A.2 Personal computers are devices that are designed to be used by one person for work or recreational purposes (e.g., word processing, graphic design, web browsing, and media production or viewing). These include desktop, laptop, and notebook computers.
    • 4.1.A.3 Handheld computers (also called mobile computers or information appliances) are smaller than personal computers and run on battery power. These include tablets, smartphones, and wearable technology like smart watches.
    • 4.1.A.4 Embedded computers are devices that are part of a machine. Embedded devices have specific instruction sets for interfacing with the specialized components of the machine they’re embedded in. Embedded computers tend to be slower and cheaper than other computers and have minimal storage.
    • 4.1.A.5 Everyday devices with embedded computers are often called Internet of Things (IoT) devices. Embedded computers are found in transportation (e.g., cars, trains, and airplanes), devices that operate critical infrastructure (e.g., operating circuit breakers at electrical substations and pumps at water treatment plants), medical equipment (e.g., IV pumps, MRI scanners, pacemakers, and insulin pumps), and everyday devices like washing machines, coffee makers, and thermostats.

    4.1.B
    Identify the type of malware used in a cyberattack.

    • 4.1.B.1 Malware is malicious software that can damage or destroy a device or network, or allow an adversary access to a device and the data on the device.
    • 4.1.B.2 Malware is often used as a tool to accomplish part of an adversary’s plan to achieve their ultimate goal(s). There are many types of malware, such as:
      • Viruses are malware that must be activated by a user executing or opening a file.
      • Worms spread from one computer to another without human interaction.
      • Trojans are malware embedded in other software that seems harmless. Remote access trojans (RATs) provide an adversary with remote access to the target system.
      • Ransomware encrypts a device’s files, preventing the user from accessing files on the device. The ransomware typically presents the user with a screen demanding payment and promising to give the user a decryption key for their files if the user pays within a fixed amount of time.
      • Spyware tracks a user’s actions on a computer and sends information back to an adversary.
      • A keylogger is software or hardware that logs the users keystrokes and sends the information back to the adversary. Adversaries can often extract usernames and passwords from keylogger data.
      • Logic bombs are set to trigger their effect only when a specific set of conditions are met; the conditions can include time and date, specific type or version of the operating system, character set the computer is using, etc.
      • A rootkit is sophisticated malware that gets into the target computer’s operating system and can control nearly every aspect of the system, including making the rootkit itself invisible to detection.
    • 4.1.B.3 While most malware is a file or a collection of files, fileless malware is malicious code that lives in RAM and uses legitimate programs already installed on a device to compromise it.

    4.1.C
    Explain how adversaries can exploit common device vulnerabilities to cause loss, damage, disruption, or destruction.

    • 4.1.C.1 Adversaries can develop exploits for known vulnerabilities in software (including operating systems). Devices with unpatched software are vulnerable to these exploits, which could allow an adversary to crash a system, view user actions, enable or disable various services or components on the device (e.g., turning on a webcam or microphone), or even take control of the device to issue their own commands including commands to steal or destroy information on the device.
    • 4.1.C.2 Adversaries can take advantage of weak authentication requirements by guessing a user’s password or using social engineering to get a user to divulge their password.
    • 4.1.C.3 When systems don’t have a password on the basic input output system (BIOS) or unified extensible firmware interface (UEFI), an adversary can boot a computer into a special mode (e.g., “recovery mode”) that gives them higher-level privileges. Without BIOS or UEFI protection, adversaries can load their own operating system onto a device from an external drive and use specialized tools to alter or create user profiles, including changing user passwords.
    • 4.1.C.4 Adversaries can load malware onto an external drive, and if autorun is enabled, then a device will run the malware when the external drive is inserted.
    • 4.1.C.5 Adversaries can leverage open ports to connect to a device.
    • 4.1.C.6 Adversaries can send malicious data to devices to disrupt them or attempt to take control of them. Devices that have no firewall (or a misconfigured firewall) cannot filter out this malicious data.
    • 4.1.C.7 Adversaries often attempt to install malware on a device to disrupt or control it. Devices lacking anti-malware software are more vulnerable to this type of attack.

    4.1.D
    Assess and document risks from device vulnerabilities.

    • 4.1.D.1 Risk from device vulnerabilities can come from unauthorized access or malware that allow an adversary to impersonate an authorized user, remotely control a device, encrypt a device’s drive to ransom the data, or wipe a device’s memory, destroying data or rendering the device inoperable. The level of risk varies depending on the criticality of the device or the services the device provides or data it stores.
    • 4.1.D.2 High risks from device vulnerabilities involve potentially compromising sensitive data or critical operations.
      • Illustrative examples for 4.1.D.2:
        • An organization has not installed the most recent update for their email server which included a patch for a known critical vulnerability.
    • 4.1.D.3 Moderate risks from device vulnerabilities can arise from weak authentication requirements or from vulnerabilities that would be less likely to be exploited.
      • Illustrative examples for 4.1.D.3:
        • A water treatment plant has embedded systems controlling pumps. The pumps can be remotely accessed via username and password for remote management for the plant, but the devices do not require multi-factor authentication (MFA).
    • 4.1.D.4 Low risks from device vulnerabilities are typically related to vulnerabilities that, if exploited, would have little impact.
      • Illustrative examples for 4.1.D.4:
        • An employee’s laptop has telnet port 23 open.

    来源:美国大学理事会 AP 课程与考试说明

    一个设备是任何计算机——一台服务器、一台个人笔记本电脑、一部智能手机,或一台建入一台机器里的嵌入式计算机(embedded computer)。带嵌入式计算机的日常设备被称为物联网(IoT)(Internet of Things)设备,而它们运行从水泵到洗衣机的一切。

    对一个设备的主要威胁是恶意软件(malware)——恶意的软件。学这些类型:

    • 病毒(virus)——必须由一个用户打开一个文件来激活。
    • 蠕虫(worm)——自己扩散,没有人的动作。
    • 木马(Trojan)——藏在看起来安全的软件里面;一个远程访问木马(RAT)(remote access trojan)给对手远程控制。
    • 勒索软件(ransomware)——加密你的文件并要求为密钥付款。
    • 间谍软件(spyware)——秘密地追踪你做什么。
    • 键盘记录器(keylogger)——记录每个击键以窃取密码。
    • 逻辑炸弹(logic bomb)——只在一个条件被满足时触发(一个日期、一个版本)。
    • Rootkit——深深地藏在操作系统里,甚至能使自己不可见。

    大多数恶意软件是一个文件,但无文件恶意软件(fileless malware)不同:它只存在于 内存(RAM)里并滥用设备上已经有的合法程序,不留下文件给一个扫描器找到。

    对手利用未打补丁的软件(unpatched software)、弱密码、无保护的 BIOS/UEFI 启动设置,和开放的端口。我们按设备的价值和关键性给设备风险评级——一家医院未打补丁的电子邮件服务器是风险,而一个员工带一个未使用的开放端口的笔记本电脑是

    探索

    Name the malware from its behaviour

    Each kind of malware has one defining trait: a worm self-spreads, a virus needs a user to run it, ransomware encrypts for money, and a rootkit hides deep in the OS.

    词汇表 训练
    英文 中文 拼音
    embedded computer 嵌入式计算机 qiàn rù shì jì suàn jī
    Internet of Things (IoT) 物联网 wù lián wǎng
    malware 恶意软件 è yì ruǎn jiàn
    Virus 病毒 bìng dú
    Worm 蠕虫 rú chóng
    Trojan 木马 mù mǎ
    remote access trojan (RAT) 远程访问木马 yuǎn chéng fǎng wèn mù mǎ
    Ransomware 勒索软件 lè suǒ ruǎn jiàn
    Spyware 间谍软件 jiàn dié ruǎn jiàn
    Keylogger 键盘记录器 jiàn pán jì lù qì
    Logic bomb 逻辑炸弹 luó jí zhà dàn
    fileless malware 无文件恶意软件 wú wén jiàn è yì ruǎn jiàn
    RAM 内存 nèi cún
    unpatched software 未打补丁的软件 wèi dǎ bǔ dīng de ruǎn jiàn
    patch 补丁 bǔ dīng
    4.2

    身份验证

    大纲
    Learning ObjectiveEssential Knowledge

    4.2.A
    Explain why hashes (also called hash outputs, checksums, message digests, or digests) are used to store passwords.

    • 4.2.A.1 A cryptographic hash function (also called a message digest function) is a mathematical algorithm that takes binary data of an arbitrary length, processes it according to a set of instructions, and outputs a fixed-length binary string called the hash (or checksum or message digest). Well known cryptographic hashes include:
      • MD5
      • SHA-1, SHA-256, SHA-512 (SHA stands for Secure Hash Algorithm)
      • NTHash
      • RIPEMD-160
    • 4.2.A.2 An n-bit hash has $2^n$ possible outputs. The number of inputs is infinite, and so inevitably two different inputs will produce the same hash. This is called a collision.
    • 4.2.A.3 Cryptographic hash functions have the following properties:
      • Hashes are collision resistant; it is difficult to find two different inputs to the same hash function that produce the same output.
      • Hashes have pre-image resistance; given a hash, it is infeasible to figure out the input that generated the hash.
      • Hashes are repeatable; the same input will always produce the same hash.
      • Hashes have a fixed length; the length in bits of the hash for a specific hash function is constant regardless of the size of the input.
    • 4.2.A.4 Adversaries try to compromise hashing functions by forcing collisions in their output. If an efficient algorithm exists to force a collision for a specific hash function, then that hash function will be deprecated (no longer used in secure settings). MD5 and SHA1 are examples of deprecated hash functions.
    • 4.2.A.5 Password-based authentication services shouldn’t store passwords in plaintext, so that if an adversary gains access to the user:password directory they won’t immediately know the passwords for all users. Instead, user passwords should be hashed and the hash stored in a database. When a user enters their password, it is hashed, and the hash is compared to the hash stored on file. If the hashes match, then the user is authenticated.
    • 4.2.A.6 If two users had the same password, then their passwords would have identical hashes in the user:password directory. To prevent this, a few random bits (called salt) are hashed with a user’s password to generate the hash. Each user’s salt is unique, so even if two users have the same password they will have a different password hash because they have different salt.

    4.2.B
    Explain how password attacks exploit vulnerabilities.

    • 4.2.B.1 If an adversary can compromise the password of a legitimate user, and that user’s organization has not enabled MFA or other authentication protections, then the adversary can act within that organization with all the access and rights available to the user.
    • 4.2.B.2 Password attacks can be classified as online or offline.
      • Online password attacks attempt user:password combinations in an active authentication portal.
      • Offline password attacks have captured a user:password database and can run password attacks against the database on their own computer. This method bypasses any account lock out protections that may be in place.
    • 4.2.B.3 Many users reuse the same passwords (or variations of the same password) for all the services and accounts they have, despite warnings not to. When an organization’s user database is stolen, the usernames, emails, and passwords are sold to adversaries or posted online. Adversaries often begin an attempt to compromise an account by trying stolen or leaked credentials for a target individual.
    • 4.2.B.4 Many users set passwords that are easy to guess, and adversaries will attempt to guess common passwords for a user’s account. Password spraying is an attack where an adversary attempts a common password against many different user accounts.
    • 4.2.B.5 Some services and devices (e.g., switches, routers, and IoT devices) are preconfigured with a default administrative user and password. Credential stuffing is an attack where an adversary attempts to gain access to these services or devices using common default credentials or account credentials that have been stolen.
    • 4.2.B.6 Offline password attacks use automated hash-cracking tools to hash possible passwords and compare them against a captured hash. Although hashes can’t be reversed, an adversary can use these tools to hash many potential passwords and compare them to the target hash. If an adversary finds a hash that matches, they can use the password that generated the hash to login to the user’s account. Offline attacks include:
      • Brute force attacks, where an adversary uses an automated tool to test all the potential passwords that a user could have
      • Dictionary attacks, where an adversary uses an automated tool to test a list of common passwords
    • 4.2.B.7 A rainbow table attack uses a list of common passwords to generate a rainbow table. A rainbow table is a table that contains each potential password and its hash. The table is then sorted by the hashes, and the adversary uses an automated tool to search the list of hashes for the captured hash. If the hashes match, then the adversary has found a password that generates the same hash, and the password will allow the adversary to login to the user’s account.

    4.2.C
    Determine the type of authentication used to verify the identity of a user.

    • 4.2.C.1 Authentication mechanisms are technical controls that verify the identity of a user to ensure that only authorized users access a system. The proof the user provides to identify themselves is called a factor. Common authentication factors include:
      • Something the user knows (knowledge factor)
      • Something the user has (possession factor)
      • Something the user is (biometric factor)
      • Somewhere the user is (location factor)
    • 4.2.C.2 Knowledge factors can be passwords, PINs, or answers to preselected challenge questions. For a knowledge factor to be effective it needs to be something an adversary can’t easily guess; however, knowledge factors that are difficult for an adversary to figure out can also be harder for a user to remember.
    • 4.2.C.3 A possession factor is an object a user has that is unique to them, such as an access card, a bank card, a cell phone, or an authentication token. The more difficult it is for an adversary to obtain the object (or a copy of it), the more secure the possession factor is.
    • 4.2.C.4 Biometric factors measure features of the human body and can include fingerprints, palm prints, facial recognition, iris or retina scans, or voice identification. Biometric factors are difficult for an adversary to duplicate because they are unique to an individual.
    • 4.2.C.5 Location factors use information about Wi-Fi signals, GPS data, time zone settings, and even IP address information to make determinations about location. Rules can be established for allowing or denying access based on a location factor.
    • 4.2.C.6 Multifactor authentication (MFA) is when a system uses more than one factor to authenticate a user. MFA is more secure than single-factor authentication because it requires the user to provide at least two separate factors of authentication.

    4.2.D
    Configure login settings to make a device more secure.

    • 4.2.D.1 Requiring complexity in passwords is a login setting that can be configured. When enabled, users setting a new password must include at least one character from each character set. Passwords with characters from each character set are significantly harder for an adversary to crack than passwords that use characters from only one or two character sets. The main character sets often required are:
      • Uppercase letters (A–Z)
      • Lowercase letters (a–z)
      • Numeric digits (0–9)
      • Special characters (!”#$%&’()*+,-./:;<=>?@ [ \ ] ^_`{|}~)
    • 4.2.D.2 Requiring a minimum password length is a login setting that can be configured. This means that users must have at least a certain number of characters in their password. The longer and more complex a password is, the longer it will take a digital tool to crack the password.
    • 4.2.D.3 Requiring a maximum password age is a login setting that can be configured. When configured, users will receive a prompt to change their password a certain number of days after their last password change, usually every 90 or 120 days. If a user’s password has been compromised, changing it could prevent an adversary from gaining access to the user’s account. However, some national standards recommend that organizations not require users to change their passwords on predefined intervals to discourage users from developing password patterns (e.g., PasswordFall2028).
    • 4.2.D.4 Requiring the system to store a certain number of previous user passwords is a login setting that can be configured. This prevents a user from reusing a password. Many organizations store users’ previous 5–10 password hashes to prevent reuse.
    • 4.2.D.5 Requiring a lockout period after a certain number of invalid login attempts is a login setting that can be configured. This prevents an adversary from continuously randomly attempting wrong passwords. Many organizations lock a user’s account after 3–5 invalid login attempts. The period of the lockout varies.

    来源:美国大学理事会 AP 课程与考试说明

    多因素认证
    一个人把手指按在一个小型光学指纹扫描仪上
    指纹扫描仪:生物特征认证检查你"是"什么,这比密码更难被攻击者窃取或猜到

    要安全地存储密码,系统使用一个密码散列函数(cryptographic hash function)——一个把任何输入变成一个固定长度字符串叫散列值(hash)(或摘要)的单向数学算法。散列有三个关键的性质:它们是抗碰撞(collision resistant)的(难以找到两个有相同输出的输入)、有抗原像(pre-image resistance)(你不能反推到输入),和可重复(相同的输入总是给出相同的散列)。

    一个散列函数把任何输入变成一个固定长度的摘要,而且不能被逆转
    一个散列函数把任何输入变成一个固定长度的摘要,而且不能被逆转

    真实的散列函数有名字。安全散列算法(SHA)(Secure Hash Algorithm)家族——SHA-256 和 SHA-512——是今天的标准。对手通过尝试强制一次碰撞(两个不同的输入有相同的散列)来攻击一个散列函数;一旦存在一种高效的碰撞攻击,那个函数就被弃用(deprecated)(从安全用途中退役)。MD5SHA-1 是经典的被弃用的例子——今天绝不要依赖它们来保护数据。

    一个服务从不存储你的明文密码。它存储散列值;当你登录时,它把你打的散列并比较。要阻止两个相同的密码产生相同的散列,几个叫盐值(salt)的随机位在散列之前被添加,所以每个存储的散列都是唯一的。

    Worked example. 两个用户都选择密码 sunshine。没有盐值,两个存储的散列会相同,所以破解一个立即破解另一个。给每个用户一个唯一的盐值——比如说 x7q2 ——而服务转而散列 sunshinex7sunshineq2。这两个存储的散列现在看起来完全不同,所以对手必须分别攻击每个账户。这就是为什么一个被窃取的散列数据库在散列被加盐时危险得多。

    对手用密码攻击回击。在线攻击对一个实时登录猜测;离线攻击窃取散列数据库并在他们自己的机器上破解它(这样就绕过了任何账户锁定保护)。技术包括:

    • 暴力破解(brute force)—— 自动化工具逐一尝试每一个可能的密码;最终一定能成功,但很慢,而且随密码长度爆炸式增长。
    • 字典攻击(dictionary attack)—— 工具先尝试一份常用词和已知密码的清单,因为大多数人选的密码都容易猜。
    • 密码喷洒(password spraying)—— 一个常见密码对许多账户(这样能躲开锁定,因为锁定是按每个账户计失败次数的)。
    • 撞库(credential stuffing)—— 重用窃取或默认的凭据,利用人们跨网站重复用密码这一点。
    • 彩虹表(rainbow table)—— 一张密码及其散列的预计算表,按散列排序,这样一个捕获的散列可以直接查表,而不必重新计算。

    Password policy settings

    管理员通过配置登录设置来加固账户 —— 考试要你能说出它们的名称,并说明每一项防的是什么:

    设置 作用 它减慢的攻击
    复杂度(complexity) 要求每个字符集(大写、小写、数字、特殊字符)各出现一个 暴力破解 / 字典攻击
    最小长度(minimum length) 要求至少 N 个字符 —— 长度比什么都重要 暴力破解(呈指数增长)
    最长有效期(maximum age) 每约 90-120 天强制更换一次 限制一个被窃密码还能用多久
    密码历史(password history) 保存最近 5-10 个散列,禁止重用 阻止重新用回一个旧的(可能已泄露的)密码
    锁定(lockout) 在 3-5 次错误尝试后锁定账户 暴力破解 / 在线猜测

    有一个值得得分的细节:一些国家标准现在反对强制到期更换,因为定期更换会把用户逼成可预测的模式,比如 PasswordFall2028密码管理器(password manager)才真正解决了根本问题 —— 它为每个网站生成并保存一个又长又独特的密码,这样就没有一个密码会被重用或被猜到。

    身份验证因素(authentication factors)证明你是谁,并落入几类:你知道的东西(一个密码)、你拥有的东西(一个令牌或手机)、你的东西(一个像指纹或视网膜扫描的生物特征(biometric)),和你的某处(一个位置因素)。使用两个或更多是多因素身份验证(MFA)(multifactor authentication)——远强于单独一个密码。

    探索

    How a hash maps any input to a fixed slot

    A hash function sends every input to a fixed-length output. The same input always lands in the same place (repeatable), and you cannot work backwards from the slot to the input.

    词汇表 训练
    英文 中文 拼音
    cryptographic hash function 密码散列函数 mì mǎ sàn liè hán shù
    hash 散列值 sàn liè zhí
    collision resistant 抗碰撞 kàng pèng zhuàng
    pre-image resistance 抗原像 kàng yuán xiàng
    deprecated 弃用 qì yòng
    salt 盐值 yán zhí
    brute force 暴力破解 bào lì pò jiě
    dictionary attack 字典攻击 zì diǎn gōng jī
    password spraying 密码喷洒 mì mǎ pēn sǎ
    credential stuffing 撞库 zhuàng kù
    rainbow table 彩虹表 cǎi hóng biǎo
    complexity 复杂度 fù zá dù
    minimum length 最小长度 zuì xiǎo cháng dù
    maximum age 最长有效期 zuì zhǎng yǒu xiào qī
    password history 密码历史 mì mǎ lì shǐ
    lockout 锁定 suǒ dìng
    password manager 密码管理器 mì mǎ guǎn lǐ qì
    biometric 生物特征 shēng wù tè zhēng
    multifactor authentication (MFA) 多因素身份验证 duō yīn sù shēn fèn yàn zhèng
    4.3

    设备防护

    大纲
    Learning ObjectiveEssential Knowledge

    4.3.A
    Identify managerial controls related to device security.

    • 4.3.A.1 An acceptable use policy will describe the range of activities that are permissible, prohibited, or required by users on devices owned by an organization and may include:
      • Prohibiting users from accessing specific websites or types of websites (e.g., social media or gaming)
      • Requiring users to keep software updated
      • Allowing users to connect peripheral devices
      • Prohibiting users from connecting external drives or media
    • 4.3.A.2 A password policy will detail the requirements for user passwords within an organization and may include:
      • A minimum or maximum password length
      • A minimum or maximum amount of time a user may keep the same password
      • A prohibition of password reuse
      • Rules for password construction (e.g., no dictionary words and character set requirements)
      • A suggestion to use secure password management tools instead of writing passwords down
    • 4.3.A.3 A software installation policy will describe what (if any) software users are allowed to install on their devices and usually also a process for users to request specialized software they may need to perform their role, and it may include:
      • A prohibition against users installing software on their devices
      • A process for users to request new software needed for their role
      • A list of approved software for users

    4.3.B
    Explain how anti-malware software can make a device more secure.

    • 4.3.B.1 Anti-malware software (sometimes called antivirus software) has tools to quarantine and remove malware that can corrupt, spy on, or destroy a system. Malware contains indicators that make it detectable; these indicators are called signatures.
    • 4.3.B.2 Anti-malware software has a database of malware signatures. It periodically scans the files on a device and checks to see if any of the files match any of the signatures in its database. If there is a match, the software quarantines and removes the malicious files.

    4.3.C
    Explain why keeping a device’s operating system and software updated makes it more secure.

    • 4.3.C.1 When vulnerabilities in operating systems and software are found, the vendor or organization that maintains the operating system software will fix it and send an update. A small update is called a patch.
    • 4.3.C.2 Ensuring that a computer’s operating system and software applications are updated to the most recent version prevents adversaries from taking advantage of a known vulnerability.

    4.3.D
    Configure a host-based firewall.

    • 4.3.D.1 Host-based firewalls allow or deny traffic into or out of a single device. This provides an extra layer of security in case a host is connected to a compromised network.
    • 4.3.D.2 A host-based firewall is software that runs on a device and follows a set of rules (an ACL) like a network-based firewall. Firewall rules are implemented in order, applying the first rule that matches.
    • 4.3.D.3 A host-based firewall can also block specified types of outbound traffic. Host-based firewalls should always block ports or services not needed for a given device.
      • Illustrative examples for 4.3.D.3:
        • A host-based firewall is configured to block outbound FTP traffic. This prevents an adversary with remote access to the host from using FTP to exfiltrate a file to the adversary’s server.
    • 4.3.D.4 The rules for a host-based firewall can allow or deny traffic based on source or destination port or IP address, service, protocol, or application.

    来源:美国大学理事会 AP 课程与考试说明

    管理控制设定规则:一个可接受使用政策(acceptable use policy)列出用户可以和不可以做什么、一个密码政策设定长度和重用规则,而一个软件安装政策控制什么能被安装。

    技术控制做工作。反恶意软件(anti-malware software)保持一个恶意软件特征的数据库并隔离任何匹配的文件。保持操作系统和应用更新——安装每个补丁(patch)——在对手能使用它们之前关闭已知的洞。一个主机防火墙(host-based firewall)控制进出一个单一设备的流量,阻止它不需要的端口和服务。

    一个反恶意软件扫描器窗口:已扫描 3106 个文件,发现两个威胁,带有隔离和更新控件
    反恶意软件根据一个特征数据库扫描文件并隔离任何匹配项——这次扫描标记了两个威胁
    词汇表 训练
    英文 中文 拼音
    acceptable use policy 可接受使用政策 kě jiē shòu shǐ yòng zhèng cè
    Anti-malware software 反恶意软件 fǎn è yì ruǎn jiàn
    host-based firewall 主机防火墙 zhǔ jī fáng huǒ qiáng
    4.4

    检测设备攻击

    大纲
    Learning ObjectiveEssential Knowledge

    4.4.A
    Explain how to detect attacks against devices.

    • 4.4.A.1 System processes and settings, login attempts, file download attempts, and user actions are logged by computing systems. These logs can be used to reconstruct circumstances leading up to and during a cyber incident.
    • 4.4.A.2 An indicator of compromise (IoC) is evidence that an adversary has compromised a device or network.
    • 4.4.A.3 Authentication logs (or auth logs) record every attempted login on a system. Analysis of authentication logs can reveal attempted attacks.
    • 4.4.A.4 Host-based IoCs are discovered when analyzing logs and configuration settings. Indicators, such as the following, can be found in authentication logs, user activity logs, and system configuration files:
      • Unusual files being created or modified
      • Unexpected processes or services
      • Unauthorized changes to system configuration settings
      • Unauthorized software installation or update
    • 4.4.A.5 File-based IoCs are discovered when analyzing files on a device. Indicators are usually found in executable files and can include:
      • Files whose hash matches known malware
      • File names that are known to be created by a certain piece of malware
      • File paths that are associated with malicious activity
    • 4.4.A.6 Behavior-based IoCs are discovered when analyzing logs. Indicators can be found in authentication logs and access logs and can include:
      • Multiple failed login attempts
      • Unusual login times or locations
      • Unauthorized attempts to access sensitive data
      • Attempts to elevate user privileges on a system

    4.4.B
    Determine controls for detecting attacks against a device.

    • 4.4.B.1 Performance is a criterion for determining a detection method. Detection tools use system memory and processing power and can impact the performance of a device. Anomaly-based detection tools use more system resources than signature-based tools. Signature-based detection is a better option for devices with less powerful system resources. Many embedded devices do not have enough system resources to run any detection tools on the device.
    • 4.4.B.2 Cost is a criterion for determining a detection method. Organizations that purchase detection software need to consider the cost of purchasing enough software licenses for the number of devices they need to monitor. Some organizations purchase an endpoint detection and response (EDR) service from a third-party vendor. Although these services are expensive, they provide a holistic, unified approach to threat detection for an organization’s devices; they typically include a centralized alert platform for monitoring possible attacks on devices.
    • 4.4.B.3 Sensitivity or criticality of the device is a criterion for determining a detection method. Devices that store or process sensitive information or provide critical services are more likely to be targeted by adversaries and benefit from a hybrid-detection model to offer maximum protection, when possible.

    4.4.C
    Evaluate the impact of a device detection method.

    • 4.4.C.1 Speed and performance are factors in evaluating the impact of a detection method. Signature-based detection is faster than anomaly-based detection in general, and that effect is compounded on devices, which often lack the processing power to effectively run anomaly-based detection tools. Implementing resource-intensive detection tools on devices can degrade device performance.
    • 4.4.C.2 Phase of the attack is a factor in evaluating the impact of a detection method. To carry out actions on a device, adversaries must first bypass a combination of physical- or network-layer protective, deterrent, and detective security controls. Detecting and stopping an attack at the device level can prevent adversaries from accessing sensitive data or disrupting critical services.
    • 4.4.C.3 False positives versus ease of bypassing detection is a factor in evaluating the impact of a detection method. Most device-level detection tools are signature-based, and signature-based detection has a low rate of false positives. However, signature-based detection is easier for adversaries to bypass.

    4.4.D
    Apply detection techniques to identify indicators of password attacks by analyzing log files.

    • 4.4.D.1 Online password attacks can be detected in authentication logs. A single user attempting many wrong passwords is an indicator of an online password attack. If a user:password hash database has been compromised, all the user passwords in the database should be considered insecure and all users should be forced to reset their passwords.
    • 4.4.D.2 If an authorized user is logging in from a different location or IP address than expected, or at a different time than normal, this can be an indicator that the user’s password has been compromised.
    • 4.4.D.3 An indicator of password spraying is many users trying to log in within seconds of each other from one IP address or from unusual IP addresses.
    • 4.4.D.4 An indicator of credential stuffing is a series of default user:password combinations being attempted on a device in quick succession, often from the same IP address.
    • 4.4.D.5 Offline password attacks can’t be detected, because the attack takes place on the adversary’s computer.

    来源:美国大学理事会 AP 课程与考试说明

    设备记录登录、文件变化和进程,而这些日志揭示一个入侵指标(IoC)(indicator of compromise)——一个对手进入的证据。基于主机的 IoC 显示为意想不到的进程或改变的设置;基于文件的 IoC 是散列匹配已知恶意软件的文件;基于行为的 IoC 是像许多失败的登录或不寻常的登录时间这样的东西。

    选择一个检测方法意味着权衡性能(基于特征更轻,对弱设备更好)、成本(一个端点检测与响应(EDR)(endpoint detection and response)服务强大但昂贵),和设备有多敏感。读身份验证日志暴露密码攻击:一个用户的许多错误密码标志一个猜测攻击;许多用户从一个 IP 失败标志密码喷洒;一阵默认凭据标志撞库。不过,离线攻击不能被检测——它们在对手自己的计算机上发生。

    词汇表 训练
    英文 中文 拼音
    indicator of compromise (IoC) 入侵指标 rù qīn zhǐ biāo
    endpoint detection and response (EDR) 端点检测与响应 duān diǎn jiǎn cè yǔ xiǎng yìng
    4.4

    考试技巧

    • 知道每个恶意软件类型的定义特征:蠕虫自我扩散、病毒需要一个用户、勒索软件为钱加密、RAT 给远程控制、rootkit 隐藏。
    • 一个散列是单向和固定长度的;盐值使相同的密码散列不同。绝不说一个服务"存储密码"——它存储加盐的散列
    • 说出真实的算法:SHA-256/SHA-512 是现行的;MD5SHA-1 因为存在高效的碰撞攻击而被弃用
    • 把密码攻击匹配到它的日志特征:一个用户 + 许多错误密码 = 猜测;许多用户 + 一个 IP = 喷洒;默认凭据 = 撞库
    • 把身份验证因素分成知道 / 拥有 / 是 / 在哪里,并记住 MFA 结合两个或更多——一个指纹加一个密码,不是两个密码。
    • 离线密码攻击不能被检测,因为破解在对手的机器上发生——一个最爱的考试"陷阱"。
  • 5

    保护应用与数据

    讲义 词汇表
    5.1

    应用与数据的漏洞与攻击

    大纲
    Learning ObjectiveEssential Knowledge

    5.1.A
    Explain how adversaries can exploit application and file vulnerabilities to cause loss, damage, disruption, or destruction.

    • 5.1.A.1 An adversary can read any unencrypted files if they have access to the device or drive storing the files.
    • 5.1.A.2 Computers have standard users and administrative users. Administrative users have access to control system settings and can typically access any files or applications on a system. If regular users are given administrative privileges on a computer, and an adversary can compromise a user’s account, then the adversary will have elevated privileges on the system.
    • 5.1.A.3 When access control settings are weakly configured, many users often have permission to view and sometimes even edit files on a system. Adversaries can take advantage of weak access control settings to steal or destroy files or disrupt an application.

    5.1.B
    Explain how application attacks exploit vulnerabilities.

    • 5.1.B.1 Applications are programs that run instructions on computers; they are executable data. Some applications run locally on a user’s computer, while other applications, like web applications, run on a server and are accessed by users through a network.
    • 5.1.B.2 Many applications take user input through open-ended input fields where users can type characters (e.g., letters, numbers, punctuation). Developers should include user input checks in their application, such as numeric input when asked for a number of items, to ensure that the user input matches what is expected; the application should reject input outside of the expected parameters. This process of verifying that user input meets expected criteria before processing it is called data validation. Applications that fail to validate user input are vulnerable to injection-type attacks, where adversaries insert unexpected character strings in input fields to alter the behavior of a program.
    • 5.1.B.3 Structured query language (SQL) is a computer language used to request information from databases and make changes to databases or entries in databases. Applications that query a database using unvalidated or unsanitized input from users are vulnerable.
    • 5.1.B.4 An SQL-injection attack places SQL commands and control characters into a user-input field in an application, which can lead to a breach of confidentiality by causing the application to return more information than it should, or a breach of integrity by modifying or deleting data in the database.
    • 5.1.B.5 Websites are written using hypertext markup language (HTML), and many websites use Javascript to create dynamic content on websites or web applications. Because Javascript commands run in the browser of the user visiting the website, those commands can access sensitive data stored in the browser like usernames, passwords, and cryptographic keys.
    • 5.1.B.6 A cross site scripting (XSS) attack injects malicious code into a website that a user’s browser then executes. The malicious code can be embedded in a link the user clicks (a Type I or Reflected XSS attack) or it can be inserted onto a website through a comment field, forum post, or visitor log, which would affect any user visiting that website (a Type II or Stored XSS attack).
    • 5.1.B.7 When applications take user input, that input is written to a buffer. A buffer is a designated section of computer memory with a fixed size. If the amount of data the user enters exceeds the size of the buffer, it can overflow into adjacent memory locations and overwrite other parts of the computer’s memory.
    • 5.1.B.8 A buffer overflow attack feeds more data into memory than was allotted, which can cause a system to crash or to execute code outside the scope of a program’s security policy, effectively allowing the adversary to perform unauthorized actions on a computer, such as accessing, modifying, or deleting files.
    • 5.1.B.9 The files that run web applications are stored in directories on servers. When users access web applications, their browsers send GET requests using hypertext transfer protocol (HTTP). A GET request accesses a file somewhere in the filesystem of the server.
    • 5.1.B.10 In a directory traversal attack, adversaries modify URLs and GET requests to attempt to access sensitive data (e.g., usernames and passwords) on a server’s file system.
      • Illustrative examples for 5.1.B.10:
        • A web server stores images for a website it hosts in the /var/www/images/ directory. An adversary modifies a URL requesting an image to ../../../etc/passwd. The .. moves one directory up in the file system; so the three consecutive .. returns the path to the root, and from there the adversary is attempting to access the passwd file that would return a list of all the authorized usernames on the device.

    5.1.C
    Assess and document risks from application and data vulnerabilities.

    • 5.1.C.1 Data security risks can involve a compromise of confidentiality when unauthorized persons can access sensitive data, integrity when data can be manipulated or altered from its intended state, and availability when data can be destroyed or encrypted to prevent others from accessing it.
    • 5.1.C.2 High risks from data vulnerabilities often involve highly sensitive data (e.g., data that is governed by laws or regulations) that could be compromised through a highly likely exploit.
      • Illustrative examples for 5.1.C.2:
        • The company developing the next jet engine that will be used by the Air Force in its planes is storing the technical specifications for the engine on an unencrypted drive.
    • 5.1.C.3 Moderate risks from data vulnerabilities often involve sensitive data not having strong enough encryption or strict enough access controls.
      • Illustrative examples for 5.1.C.3:
        • A company stores its customers’ PII in a spreadsheet, and the spreadsheet is encrypted using a small key.
    • 5.1.C.4 Low risks from data vulnerabilities often involve less sensitive information being encrypted with shorter keys or having access controls that are not strict enough.
      • Illustrative examples for 5.1.C.4:
        • An organization’s CEO stores his private memos to his executive staff on a company share drive that is unencrypted and has no access controls.

    来源:美国大学理事会 AP 课程与考试说明

    SQL 注入

    应用程序(applications)是在计算机上运行的程序,而数据是它们处理的——两者都是首要目标。若文件被未加密地存储,任何有访问驱动器权限的人都能读它们。若一个普通用户被给予管理性(administrative)权限,一个窃取那个账户的对手获得广泛的权力。

    最大的应用危险是坏的用户输入。当一个程序不检查一个用户打什么时,一个对手能溜入命令——一个注入攻击(injection attack)。数据验证(data validation)(检查输入符合预期的规则)是防御。关键的攻击:

    • SQL注入(SQL injection)——把 SQL 命令插入一个输入字段以读或改变一个数据库。
    • 跨站脚本(XSS)(cross-site scripting)——把恶意脚本注入一个网站,它在另一个用户的浏览器里运行。
    • 缓冲区溢出(buffer overflow)——发送比一个内存缓冲区(buffer)能容纳的更多数据,所以它溢出到附近的内存并可能运行对手的代码。
    • 目录遍历(directory traversal)——在一个 URL 里用 ../ 序列以到达打算的文件夹之外的文件,例如 /etc/passwd

    我们按敏感性给数据风险评级:未加密的军事计划是风险;带一个弱密钥的客户数据是中等;带短密钥的低价值数据是

    词汇表 训练
    英文 中文 拼音
    Applications 应用程序 yìng yòng chéng xù
    administrative 管理性 guǎn lǐ xìng
    injection attack 注入攻击 zhù rù gōng jī
    Data validation 数据验证 shù jù yàn zhèng
    SQL injection SQL注入 zhù rù
    Cross-site scripting (XSS) 跨站脚本 kuà zhàn jiǎo běn
    Buffer overflow 缓冲区溢出 huǎn chōng qū yì chū
    buffer 缓冲区 huǎn chōng qū
    Directory traversal 目录遍历 mù lù biàn lì
    5.2

    保护应用与数据:管理性控制与访问控制

    大纲
    Learning ObjectiveEssential Knowledge

    5.2.A
    Explain how the state or classification of data impacts the type and degree of security applied to that data.

    • 5.2.A.1 Organizations implement specific security controls to comply with legal requirements based on the types of data they collect, store, process, and transmit.
    • 5.2.A.2 Data can be classified by their state.
      • Data at rest are stored on a drive. It is important to protect the physical drive storing the data from destruction or theft. Data at rest can also be encrypted so that if an adversary steals it, they can’t immediately read the data.
      • Data in transit are being sent from one device to another. If the data are being transferred over physical media (e.g., cables) it is important to protect the media. Data in transit can also be encrypted so that if an adversary intercepts it, they can’t immediately read the data.
      • Data in use are being processed by software or a person. Access controls can be used to limit who or what has the ability to use data in different ways (e.g., view or edit). Data must be unencrypted to be used.
    • 5.2.A.3 Organizations often categorize data according to their sensitivity and prioritize a higher degree of security for more sensitive information.
    • 5.2.A.4 Laws and regulations can require certain types of data to be stored, transmitted, and handled according to specific rules.
      • Personally identifiable information (PII) is any data that allows someone to be identified and includes (but is not limited to): name, signature, phone number, address, biometric data (e.g., fingerprints), social security number, date of birth, and email address. The protection of this data is covered by many laws but most notably The Privacy Act of 1974 and for children under the age of 13 the Children’s Online Privacy Protection Act of 1998.
      • Protected health information (PHI) is any data related to an individual’s health, treatment, payment for healthcare at any time and includes (but is not limited to): test results, treatment records, hospital records, doctor visit notes, and health provider payment records. The protection of PHI is included in the Health Insurance Portability and Accountability Act of 1996.
      • Payment card information (PCI) is the data collected by organizations to process payments via cards (e.g., credit cards) and includes the following: name, account number, expiration date, address, and CVV code. The protection of this data is regulated by the Payment Card Industry Data Security Standard (PCI-DSS).
    • 5.2.A.5 Organizations that collect regulated data will label them and have policies that comply with the legal or regulatory requirements for the safe storage, transmission, and handling of these data.

    5.2.B
    Identify managerial controls related to application and data security.

    • 5.2.B.1 A cryptography policy will describe the acceptable encryption protocols and key parameters for an organization and may include:
      • A list of encryption algorithms approved for specific uses
      • Minimum or maximum key lengths
      • Cryptographic key-generation requirements and parameters
      • Cryptographic key-storage requirements
    • 5.2.B.2 A web application security policy will outline the requirements and parameters for testing and mitigating web application vulnerabilities in an organization, and it may include:
      • Parameters for when an application is subject to a security assessment
      • Timelines for remediating vulnerabilities based on level of risk
      • Parameters for how an application security assessment is to be carried out (e.g., using specific tools or according to specific frameworks)

    5.2.C
    Determine an appropriate access control model to protect applications and data.

    • 5.2.C.1 Access control enforces which users or applications (called subjects) can access, modify, add, or remove (called operations) which files or applications (called objects). Access control models describe how to determine which subjects have what type of access to which objects.
    • 5.2.C.2 Role-based access control (RBAC) assigns every subject to a role and defines which roles have which types of access to which objects.
      • Illustrative examples for 5.2.C.2:
        • An example of a role at a company might be “accountant,” and one type of object could be the payroll software. Role-based access could be used to ensure that only subjects who are assigned to the role of “accountant” have access to the payroll software object.
    • 5.2.C.3 Rule-based access control (RuBAC) checks a set of rules to determine what type of access a subject should have for a specific object and then allows or denies types of access based on the rules. This access control model is typically layered on top of another access control model.
      • Illustrative examples for 5.2.C.3:
        • There is a rule that prohibits subjects (even those who would normally have access) from accessing a certain database (the object) outside of local working hours. When a subject attempts to access the database, even if they are authorized to access it, they will be denied access if it is outside the time designated by the rule.
    • 5.2.C.4 Discretionary access control (DAC) gives individual subjects the ability to set the type of access that other subjects have on objects they own. In DAC models some subjects are designated as administrators or super users, and they have the ability to override the access controls established by other subjects.
      • Illustrative examples for 5.2.C.4:
        • Bob creates a file (an object) and decides to give Alice permission to edit the file, to give Frank permission to view the file only, and to deny everyone else access to the file altogether.
    • 5.2.C.5 Mandatory access control (MAC) follows strict rules for which types of access each subject level has for objects that are above their level, at their level, or below their level. Subject and object levels are assigned by an external administrator.
    • 5.2.C.6 The Bell-LaPadula model is a MAC model that is often used by governments and military organizations to control the security of information. This model has the following two important properties:
      • i. The Simple Security Property states that subjects may not read objects that are above their level.
      • ii. The * (Star) Security Property states that subjects may not write to objects below their level.
      • These rules taken together are often summarized as “write up, read down” (WURD).
    • 5.2.C.7 The principle of least privilege is the idea that entities should be given exactly as much access as they need to perform their function and no more.

    5.2.D
    Configure access control settings on a Linux-based system.

    • 5.2.D.1 Authorization is when an entity is granted permission to have a certain type of access to a resource. Access controls are put in place to control which users have what types of access to which data.
    • 5.2.D.2 There are three types of access to a file in Linux that can be set, and they always come in the following order:
      • i. Read access allows a user to view the contents of a file.
      • ii. Write access allows a user to make changes to a file.
      • iii. Execute access allows a user to run a binary file such as a program.
      • These are abbreviated rwx, respectively. If a user only has read and execute permissions (not write), then it would display as r-x. The - symbol indicates the absence of that permission.
    • 5.2.D.3 There are three default entities for which permissions are set and always in this order: (1) the file owner, (2) the file group, and (3) all other users. The three sets are displayed with no spaces (e.g., rwxrwxrwx).
    • 5.2.D.4 To view the current permission settings for a file, use the command ls -l, which will show the current settings for the default entities. If there is a + symbol at the end of the permissions, this means that other permissions have been set for that file and it can be viewed with the getfacl command.
    • 5.2.D.5 To modify the permission settings for a file, use the chmod command. This command can be used with the numeric method or the symbolic method.
    • 5.2.D.6 To use chmod in the numeric method the syntax is chmod ### filename. Each of the three ### represents one of the three entities mentioned above (the owner, the group, other nongroup users).
      • The first # = the owner
      • The second # = the group
      • The third # = other nongroup users
      • The permission for each entity is determined by adding up the values for the types of access to be granted:
      • 0 = no permissions
      • 1 = execute
      • 2 = write
      • 4 = read
      • Therefore 3 sets permission to write and execute, 5 sets permission to read and execute, 6 sets permission to read and write, and 7 sets permission to read, write, and execute.
      • Illustrative examples for 5.2.D.6:
        • The command chmod 750 test would set the permissions for the owner to read, write, and execute, for the group to read and execute, and for everyone else to no access at all.
        • The command chmod 543 test would set the permissions for the owner to read and execute, for the group to read only, and for everyone else to write and execute.
        • The command chmod 777 test would set the permissions for all three entities to read, write, and execute for the file test.
    • 5.2.D.7 To use chmod in the symbolic method the syntax is chmod entity +(or –) permission filename. The entities are the user owner, the group, and other nongroup users. Each entity is represented with a single letter.
      • u = user owner
      • g = group
      • o = others
      • a = all
      • Permission can be either added or removed to any combination of entities.
        • = add the permission
      • – = remove the permission
      • The permissions that can be set are read, write, and execute.
      • r = read
      • w = write
      • x = execute
      • Entities and permissions can be combined in a single command. To add the read and execute permissions for the group and user owner for a file called testfile, the command would be chmod ug+rx testfile.

    来源:美国大学理事会 AP 课程与考试说明

    数据按它的状态分类——静态数据(at rest)(存储在一个驱动器上)、传输中数据(in transit)(在设备之间移动),和使用中数据(in use)(正在被处理)。静态数据和传输中数据可以加密,这样窃取者也读不了;使用中数据必须解密,所以改由访问控制来守护它。

    有些数据类型是受监管(regulated)的 —— 法律规定了它们必须如何存储、传输和处理 —— 所以组织必须让自己的控制措施匹配这些规则,以达到合规(compliance)。考试要你能把每种数据类型与管辖它的法律配对:

    受监管数据 它是什么 管辖法律
    个人身份信息(PII)(personally identifiable information) 任何能识别一个人的信息:姓名、地址、社保号、生物特征、出生日期 《隐私法》(1974);针对 13 岁以下儿童的 COPPA
    受保护健康信息(PHI)(protected health information) 健康、治疗和医疗付款记录 HIPAA(1996)
    支付卡信息(PCI)(payment card information) 卡号、有效期、CVV、持卡人姓名 PCI-DSS

    收集受监管数据的组织必须给它贴标签,并制定政策,使其存储、传输和处理保持合规 —— 敏感度越高,所需的安全程度就越高。

    访问控制(access control)决定哪些主体(subjects)(用户)可以对哪些对象(objects)(文件)执行哪些操作(operations)。四个模型:

    • 基于角色的访问控制(RBAC)(role-based)——访问遵循你的角色(所有"会计"都能到达工资软件)。
    • 基于规则的访问控制(RuBAC)(rule-based)——访问遵循条件(只在营业时间),层叠在另一个模型上。
    • 自主访问控制(DAC)(discretionary)——一个文件的所有者(owner)决定谁还可以使用它。
    • 强制访问控制(MAC)(mandatory)——一个中央管理员设定严格的级别;Bell-LaPadula 模型把它总结为"向上写、向下读"。
    四个访问控制模型决定谁到达哪个对象,以及如何到达
    四个访问控制模型决定谁到达哪个对象,以及如何到达

    跨所有模型的一个指导思想是最小权限原则(principle of least privilege)——给每个实体恰好它需要的访问,不多。

    在一个 Linux 系统上,每个文件有三个权限——读(r)、写(w)、执行(x)——对三个组:所有者(owner)、(group),和其他人(others)。chmod 命令用数字设定它们,加 4(读)+ 2(写)+ 1(执行)。所以 chmod 640 意味着所有者读+写(6)、组读(4)、其他人什么都没有(0)。

    Linux 文件权限:所有者、组和其他人的读/写/执行
    Linux 文件权限:所有者、组和其他人的读/写/执行

    Worked example. 一个主体想要只有她自己能读编辑一个文件、她的员工组能读它,而没有其他人能碰它。读+写 = 4+2 = 所有者的 6、读 = 组的 4、什么都没有 = 其他人的 0,给出 chmod 640 file。列表然后显示 -rw-r-----。要也让所有者能作为一个程序运行这个文件,你会加执行(7 = 4+2+1),给出 chmod 740

    探索

    Which access-control model fits the rule?

    Each access-control model has a different decider: RBAC by your role, RuBAC by a condition, DAC by the file's owner, and MAC by a central administrator's levels.

    词汇表 训练
    英文 中文 拼音
    at rest 静态数据 jìng tài shù jù
    in transit 传输中数据 chuán shū zhōng shù jù
    in use 使用中数据 shǐ yòng zhōng shù jù
    regulated 受监管 shòu jiān guǎn
    compliance 合规 hé guī
    personally identifiable information (PII) 个人身份信息 gè rén shēn fèn xìn xī
    protected health information (PHI) 受保护健康信息 shòu bǎo hù jiàn kāng xìn xī
    payment card information (PCI) 支付卡信息 zhī fù kǎ xìn xī
    Role-based (RBAC) 基于角色的访问控制 jī yú jué sè de fǎng wèn kòng zhì
    Rule-based (RuBAC) 基于规则的访问控制 jī yú guī zé de fǎng wèn kòng zhì
    Discretionary (DAC) 自主访问控制 zì zhǔ fǎng wèn kòng zhì
    Mandatory (MAC) 强制访问控制 qiáng zhì fǎng wèn kòng zhì
    principle of least privilege 最小权限原则 zuì xiǎo quán xiàn yuán zé
    5.3

    用密码学保护存储的数据

    大纲
    Learning ObjectiveEssential Knowledge

    5.3.A
    Explain how encryption can be used to protect files.

    • 5.3.A.1 The purpose of cryptography is to hide information. A cryptographic algorithm defines a process for encrypting and decrypting information. Encryption is the process of hiding the information, and decryption is the process of reversing the encryption to retrieve the original information.
    • 5.3.A.2 An encryption algorithm defines a process for combining the information to be encrypted with a predefined key. The information to be encrypted is called the plaintext. The output of the encryption algorithm is called the ciphertext.
    • 5.3.A.3 The number of possible keys that can be used in an encryption algorithm is called the keyspace. The larger the keyspace, the longer it will take an adversary to discover the correct key by random chance.
    • 5.3.A.4 Cryptographic algorithms are classified by whether they use one key or two keys.
      • Symmetric encryption algorithms use the same key to encrypt and decrypt information.
      • Asymmetric encryption algorithms use two different keys—one to encrypt information and the other to decrypt information.
    • 5.3.A.5 Cryptographic algorithms are also classified by whether they process information one bit at a time or in fixed-size chunks of bits.
      • Block encryption handles information in fixed-size chunks called blocks, producing an output block for each input block.
      • Stream encryption handles input information continuously, producing output one element at a time.

    5.3.B
    Apply symmetric encryption algorithms to encrypt and decrypt data.

    • 5.3.B.1 Computer-based encryption algorithms operate on binary data. The most common symmetric encryption algorithm is the Advanced Encryption Standard (AES). AES encryption is used to secure Wi-Fi transmissions, internet browsing, file encryption on disks, and hardware-level encryption on processors.
    • 5.3.B.2 AES is a symmetric key block cipher that encrypts data in 128-bit blocks (16 bytes). AES can operate with keys of varying lengths. Longer keys produce more secure encryption but require more time to encrypt and decrypt.
    • 5.3.B.3 Symmetric encryption and decryption can be performed using the command line, specialized software, or web-based tools.
      • On a command line interface, users can encrypt or decrypt with OpenSSL.
      • Specialized software like AES Crypt is an open source tool that can encrypt and decrypt files.
      • There are many web-based tools for encrypting and decrypting files.
    • 5.3.B.4 Using OpenSSL in a CLI, a user can encrypt and decrypt a file using the following commands (note that the encryption key is derived from the password provided):
      • To encrypt a file named test with AES using a 128-bit key, use the command: openssl enc -aes-128-cbc -e -in test -k password -out test.enc
      • To decrypt the encrypted file using the same key, use the command: openssl enc -aes-128-cbc -d -in test.enc -k password -out text

    来源:美国大学理事会 AP 课程与考试说明

    对称与非对称加密
    哈希与雪崩效应

    密码学(cryptography)隐藏信息。一个加密(encryption)算法把明文(plaintext)与一个密钥(key)结合以产生密文(ciphertext);解密(decryption)逆转它。密钥空间(keyspace)是可能的密钥的数量——它越大,一个对手需要越长时间猜测。一个 n 位密钥有一个 $2^n$ 的密钥空间。

    对称加密(symmetric encryption)使用相同的密钥来加密和解密。标准是 AES(高级加密标准),一个在 128 位块上工作的分组密码(block cipher),保护 Wi-Fi、浏览和存储的文件。因为两侧都需要相同的秘密密钥,安全地共享那个密钥是挑战。

    探索

    Encrypt a message by shifting letters

    Encryption combines plaintext with a key to make ciphertext. In this simple cipher the key is the shift amount; only someone who knows the shift can decrypt the message back.

    词汇表 训练
    英文 中文 拼音
    Cryptography 密码学 mì mǎ xué
    plaintext 明文 míng wén
    key 密钥 mì yào
    ciphertext 密文 mì wén
    keyspace 密钥空间 mì yào kōng jiān
    Symmetric encryption 对称加密 duì chèn jiā mì
    AES 高级加密标准 gāo jí jiā mì biāo zhǔn
    block cipher 分组密码 fēn zǔ mì mǎ
    5.4

    非对称密码学

    大纲
    Learning ObjectiveEssential Knowledge

    5.4.A
    Determine the appropriate asymmetric key to use when sending or receiving encrypted data.

    • 5.4.A.1 Asymmetric encryption allows users to communicate securely without prearranging a shared secret key.
    • 5.4.A.2 When using asymmetric encryption, each entity that will be receiving data must first generate a key pair. Key pairs are binary strings of equal length that are generated at the same time through a mathematical process. One key is designated as the public key and the other as the private key. The keys are mathematical inverses of each other— each key reverses its partner. Either key can be used to encrypt information, but only the other key in the key pair will then be able to decrypt it.
    • 5.4.A.3 Once the receiver generates the key pair, the private key must be stored securely. If the private key is exposed, shared, stolen, corrupted, or compromised the key pair must be deleted and a new key pair must be generated, because the security of the encryption algorithm rests on the security of the private key. The public key is published for anyone to view and use.
    • 5.4.A.4 To send information securely to someone, the sender will use the receiver’s public key to encrypt the data and send it. Only the receiver who has the private key will be able to decrypt and read the information.

    5.4.B
    Explain why the length of a key impacts the security of encrypted data.

    • 5.4.B.1 Longer keys result in larger keyspaces. For binary keys, an n-bit length key has a keyspace of $2^n$.
    • 5.4.B.2 Using an application to randomly guess an n-bit length encryption key means that on average an adversary will be able to guess the correct key in $2^n \div 2$ (or $2^{n-1}$) guesses.
    • 5.4.B.3 Although longer keys are more secure, they also require more time to encrypt and decrypt messages.
    • 5.4.B.4 Computational processing power and efficiency continue to improve, allowing software to guess keys faster. Key-length recommendations for both symmetric and asymmetric encryption algorithms are periodically increased to account for increased processing power.
    • 5.4.B.5 Key-length comparison is only valid when comparing keys for the same cryptographic algorithm.
      • Illustrative examples for 5.4.B.5:
        • An AES 256-bit key is more secure than an AES 128-bit key.
        • An RSA 4096-bit key is more secure than an RSA 2048-bit key.
        • RSA and AES keys cannot be directly compared to one another in determining the level of security.

    5.4.C
    Apply asymmetric encryption algorithms to encrypt and decrypt data.

    • 5.4.C.1 Common asymmetric encryption algorithms include RSA and elliptic curve cryptography (ECC). Asymmetric algorithms are used in many applications, including digital signatures and digital certificates.
    • 5.4.C.2 As with symmetric encryption, asymmetric encryption and decryption can be performed using the command line, specialized software, or web-based tools.
      • On a command line interface, users can encrypt or decrypt with OpenSSL.
      • Specialized software like RSA Encryption Tool is an open source tool that can encrypt and decrypt files.
      • There are many web-based tools for encrypting and decrypting files.
    • 5.4.C.3 In a CLI, a user can generate an asymmetric key pair and encrypt or decrypt files as necessary.
      • To generate a 2048-bit RSA key pair and save the key to a file named rsa.pem use the command: openssl genrsa -out rsa.pem 2048
      • To extract the public key from rsa.pem into a file named public.pem, use the command: openssl rsa -pubout -in rsa.pem -outform PEM -out public.pem
      • To encrypt the file test using RSA encryption and the key file public.pem, use the command: openssl pkeyutl -encrypt -pubin -inkey public.pem -in test -out test.enc
      • To decrypt the test.enc file using the rsa.pem file, run the command: openssl pkeyutl -decrypt -inkey rsa.pem -in test.enc -out test

    来源:美国大学理事会 AP 课程与考试说明

    非对称加密(asymmetric encryption)用一个密钥对(key pair)解决密钥共享问题——一个任何人都可以看的公钥(public key)和一个保持秘密的私钥(private key)。这些密钥是数学的逆:无论一个锁上什么,只有另一个解锁。要给你发一个秘密,我用你的公钥加密,而只有你的私钥能解密它——所以我们从不必提前共享一个秘密。

    非对称加密:用公钥加密,用私钥解密
    非对称加密:用公钥加密,用私钥解密

    更长的密钥意味着更大的密钥空间和更多的安全,但更慢的加密。常见的非对称算法是 RSA椭圆曲线密码学(ECC)(elliptic curve cryptography),用于数字签名和证书。记住:你只能在同一算法内比较密钥长度——一个 RSA 4096 位密钥不直接与一个 AES 256 位密钥可比。

    A padlock: cryptography locks data so only someone with the matching key can open it
    A padlock: cryptography locks data so only someone with the matching key can open it
    词汇表 训练
    英文 中文 拼音
    Asymmetric encryption 非对称加密 fēi duì chèn jiā mì
    key pair 密钥对 mì yào duì
    public key 公钥 gōng yào
    private key 私钥 sī yào
    elliptic curve cryptography (ECC) 椭圆曲线密码学 tuǒ yuán qū xiàn mì mǎ xué
    5.5

    保护应用

    大纲
    Learning ObjectiveEssential Knowledge

    5.5.A
    Identify the application security principles of secure by design and security by default.

    • 5.5.A.1 Secure by design is an initiative that encourages companies to include security in all phases of product development including design. When organizations implement secure by design, security is a design principle not just a technical feature.
    • 5.5.A.2 Secure by design includes three design principles:
      • i. Companies should take ownership of customer security outcomes. Companies should build products that meet the security needs of their customers.
      • ii. Companies should embrace radical transparency and accountability. Sharing relevant security-related product news and updates quickly increases security for everyone.
      • iii. Companies should build organizational structure and leadership to implement secure by design. Companies need leaders who are focused on security and have a security-first posture.
    • 5.5.A.3 Secure by design includes the concept of secure by default, which is the idea that security features for software and devices should be enabled by default. Devices and software should be secure to use out of the box, with security features already enabled.

    5.5.B
    Explain how user input sanitization protects applications.

    • 5.5.B.1 When users enter input into an application, the application typically encases that input in special characters to process it. The characters that encase the user input are called control characters and include the single quote, the double quote, and the semicolon.
    • 5.5.B.2 When creating a program that takes user input, programmers should use a function to verify that user input meets their expected criteria and does not include any control characters that could be used to manipulate the system. This verification function can sanitize user input by removing potentially malicious characters, or it can give the user an error and force the user to provide different input. This can protect against many application attacks, including:
      • SQL injection attacks
      • XSS attacks
      • Directory traversal attacks

    来源:美国大学理事会 AP 课程与考试说明

    两个设计原则从一开始就保持应用安全。安全设计(secure by design)把安全建入开发的每个阶段,而不是作为一个事后的想法。默认安全(secure by default)意味着产品出厂时它的安全功能已经启用——开箱即安全。

    安全设计建立在一家公司必须采纳的三个原则上:(1)为它的客户的安全结果负责,而不是把责任推给用户,(2)拥抱彻底的透明和问责——快速分享与安全相关的消息和更新,让每个人都更安全,以及(3)建立把安全作为头等目标的组织结构和领导力

    对抗注入攻击的关键防御是输入清理(input sanitization)。某些特殊字符(special characters)——单引号、双引号和分号——能被用来操纵一个系统,所以一个好的程序在处理之前移除或拒绝它们。清理同样地防御 SQL 注入、XSS 和目录遍历攻击。

    词汇表 训练
    英文 中文 拼音
    Secure by design 安全设计 ān quán shè jì
    Secure by default 默认安全 mò rèn ān quán
    input sanitization 输入清理 shū rù qīng lǐ
    special characters 特殊字符 tè shū zì fú
    5.6

    检测应用与数据攻击

    大纲
    Learning ObjectiveEssential Knowledge

    5.6.A
    Explain how to detect attacks on data.

    • 5.6.A.1 Devices track and log when data are accessed and by whom. The process of recording and monitoring user activities is called accounting. Analysis of these logs can reveal malicious activity when an adversary attempts to access, copy, move, or delete data. Suspicious activity can include:
      • Accessing files that aren’t typically accessed
      • Accessing files or applications outside of a user’s normal patterns (including time of day, location, and device type)
      • Attempts to delete or copy sensitive files
    • 5.6.A.2 A honeypot is a file that appears as if it contains valuable data (e.g., credit card information, PII, passwords), but the data in the file are fake. A system can alert defenders if someone attempts to access the honeypot. Since the honeypot is a fake file, there is no legitimate reason to be accessing it, and any attempted access would be an indicator of malicious activity.
    • 5.6.A.3 Cryptographic hash functions can generate a digest for data and can reveal if data have been altered. If a file has changed unexpectedly, this can be a sign of malicious activity.

    5.6.B
    Determine controls for detecting attacks against applications or data.

    • 5.6.B.1 Cost is a criterion in determining detective controls. Detective controls like honeypots and using hash values to check data integrity are inexpensive. Some organizations invest in third-party data loss prevention (DLP) services, which monitor data access, usage, and transmission by users throughout the organization to detect suspicious activity; DLP services provide strong detection capabilities at a higher cost.
    • 5.6.B.2 Sensitivity or criticality of data or applications is a criterion in determining detective controls. More sensitive or critical data or applications are more likely targets of an adversary and should be monitored more closely.
    • 5.6.B.3 Classification of data is a criterion in determining detective controls. Data that have been classified as private, educational, healthcare, or financial often have legal or regulatory detection and monitoring requirements.

    5.6.C
    Evaluate the impact of a method for detecting attacks against an application or data.

    • 5.6.C.1 To operate at an effective speed, log analysis needs to be augmented with some automation. Honeypots offer near instantaneous detection capabilities.
    • 5.6.C.2 Some DLP tools, honeypots, and realtime automated log analysis provide alerts as an attack is happening. These tools allow for a prompt response that can stop an attack before it does more harm. Retrospective log analysis and the use of cryptographic hashes to verify data integrity identify attacks after they have occurred.
    • 5.6.C.3 False negatives can occur in applications and data attack detection. Cryptographic hash functions only detect if data have been altered. An adversary could view and steal data without altering it, and a cryptographic hash function would not detect this. Honeypots cannot detect adversaries that do not attempt to access them.

    5.6.D
    Identify whether a file has been altered by verifying its hash.

    • 5.6.D.1 Cryptographic hash functions can help identify changes in a file because they are repeatable: the same input always produces the same output for a given hash function.
    • 5.6.D.2 Hashes can be calculated using the command line on a computer, a website, or specialized software.
      • In Windows Powershell, if a user wanted to generate the SHA256 hash for a file named testfile, they would use the command: Get-FileHash testfile -Algorithm SHA256
      • In BASH the same could be accomplished with the command: sha256sum testfile
      • In zsh, the common command line terminal on Apple computers, this could be accomplished with the command: shasum -a 256 testfile
    • 5.6.D.3 A file can be hashed and its hash output recorded. Then it can be hashed again later, and the second hash output can be compared to the previous hash output for the same file. If a file’s hash changes, then the file was altered between when the first and second hashes were generated.

    5.6.E
    Apply detection techniques to identify and report indicators of application attacks by analyzing log files.

    • 5.6.E.1 SQL injection attacks can be detected by reviewing application and server logs of user input for SQL control words and symbols such as:
      • A single (') or double (") quote character
      • Boolean conditions like OR 1=1
      • A double dash (which indicates a comment in SQL): --
      • SQL control words (always in capital letters) like WHERE, IN, FROM
    • 5.6.E.2 XSS attacks can be detected by reviewing user input for suspicious tags, particularly the tag.
    • 5.6.E.3 For web applications, buffer overflows can be detected by checking the amount of data the user is sending to the web application in their request. The fields commonly checked are the URL length, cookie length, query string length, and total request length. Long strings in any of these fields can be an indicator of an attempted buffer overflow attack.
    • 5.6.E.4 Directory traversal attacks can be detected by reviewing application and server logs. HTTP GET requests that include paths with sequences of ../ are indicators of an adversary attempting a directory traversal.

    来源:美国大学理事会 AP 课程与考试说明

    要检测数据攻击,系统执行审计记录(accounting)——记录谁在何时访问了什么。但日志非常庞大,所以日志分析必须自动化才能以有用的速度运行;靠人读原始日志太慢了。一个巧妙的补充是一个蜜罐(honeypot)——一个看起来有价值的假文件;因为没有人有真正的理由打开它,任何访问都是一个近乎即时的、清晰的攻击迹象。尤其要留意删除或复制敏感文件的企图。密码散列也帮助:重新散列一个文件并比较——若摘要改变了,文件被更改了。

    选择检测控制意味着权衡成本(蜜罐便宜;一个数据泄露防护(DLP)(data loss prevention)服务强大但昂贵)与数据的敏感性。要从日志读一个具体的攻击,寻找它的特征:SQL 注入显示 OR 1=1--;XSS 显示 <script> 标签;目录遍历显示 ../ 序列;一个缓冲区溢出显示异常长的输入字符串。

    词汇表 训练
    英文 中文 拼音
    accounting 审计记录 shěn jì jì lù
    honeypot 蜜罐 mì guàn
    data loss prevention (DLP) 数据泄露防护 shù jù xiè lòu fáng hù
    5.6

    考试技巧

    • 把每个应用攻击匹配到它在一个日志里的证据:OR 1=1 / -- = SQL 注入;<script> = XSS;../ = 目录遍历;非常长的输入 = 缓冲区溢出
    • 按它们的决定者学四个访问控制模型:RBAC = 你的角色、RuBAC = 一个条件、DAC = 文件的所有者、MAC = 一个中央管理员。最小权限是它们全部的基础。
    • 通过每组加 4+2+1 读 Linux 权限——chmod 750 = 所有者 rwx(7)、组 r-x(5)、其他人 none(0)。练习双向转换。
    • 对称 = 一个共享密钥(快,AES);非对称 = 一个公钥/私钥对(解决密钥共享,RSA/ECC)。用接收者的公钥加密。
    • 输入清理是防止注入攻击的单个最佳答案;一个蜜罐是经典的便宜的检测控制。

登录或创建账号

IGCSE, A-Level & AP