Security threats · 安全威胁
| English | 中文 | Pinyin · 拼音 |
|---|---|---|
| worm/wɜːm/ | 蠕虫 | rú chóng |
| ransomware/ˈrænsəmweə/ | 勒索软件 | lè suǒ ruǎn jiàn |
| security/sɪˈkjʊərɪti/ | 安全 | ān quán |
| privacy/ˈprɪvəsi/ | 隐私 | yǐn sī |
| integrity/ɪnˈteɡrɪti/ | 完整性 | wán zhěng xìng |
| unauthorised/ʌnˈɔːθəraɪzd/ | 未授权 | wèi shòu quán |
| virus/ˈvaɪrəs/ | 病毒 | bìng dú |
| Trojan/ˈtrəʊdʒn/ | 木马 | mù mǎ |
| spyware/ˈspaɪweə/ | 间谍软件 | jiàn dié ruǎn jiàn |
| adware/ˈædweə/ | 广告软件 | guǎng gào ruǎn jiàn |
| phishing/ˈfɪʃɪŋ/ | 网络钓鱼 | wǎng luò diào yú |
| pharming/ˈfɑːmɪŋ/ | 域名欺骗 | yù míng qī piàn |
| social engineering/ˈsəʊʃl ˌendʒɪˈnɪərɪŋ/ | 社会工程 | shè huì gōng chéng |
| hackers/ˈhækəz/ | 黑客 | hēi kè |
| denial of service/dɪˈnaɪəl ɒv ˈsɜːvɪs/ | 拒绝服务 | jù jué fú wù |
| eavesdropping/ˈiːvzdrɒpɪŋ/ | 窃听 | qiè tīng |
| man-in-the-middle/mæn ɪnðə ˈmɪdl/ | 中间人攻击 | zhōng jiān rén gōng jī |
The Friday the hospitals went dark
- On 12 May 2017 a program called WannaCry spread to more than 200,000 computers in 150 countries in a single day. It needed no one to click anything: it found a flaw in Windows file sharing and copied itself from machine to machine.
- On each one it encrypted every file and demanded $300 in bitcoin. In the UK, a third of hospital trusts were hit; 19,000 appointments were cancelled and ambulances were diverted.
- The patch that closed the flaw had been published two months earlier. The computers that were hit had not installed it.
- Worm, ransomware, missing update: three words from this lesson in one afternoon. This lesson is the threats to data and to the systems that hold it.
医院陷入黑暗的那个星期五
- 2017 年 5 月 12 日,一个叫 WannaCry 的程序在一天之内传播到 150 个国家的 20 多万台计算机。它不需要任何人点击什么:它找到 Windows 文件共享中的一个漏洞,自己从一台机器复制到另一台。
- 在每台机器上它加密所有文件并索要 300 美元的比特币。在英国,三分之一的医院信托机构被击中;19,000 个预约被取消,救护车被改道。
- 封堵这个漏洞的补丁两个月前就已发布。被击中的计算机没有安装它。
- 蠕虫、勒索软件、缺失的更新:这一课的三个词在一个下午同时出现。这一课讲对数据和存放数据的系统的威胁。
Security, privacy, integrity
- Security 安全 is keeping data safe from loss and from unauthorised 未授权 access, change or deletion.
- Privacy 隐私 is keeping data confidential, so that only those with the right to see it can, with consent and for a clear purpose.
- Integrity 完整性 is the data being accurate, consistent and complete.
- A file can be secure but corrupted, or accurate but readable by anyone. The exam asks for the difference in one sentence each.
安全、隐私、完整性
- 安全(security)是保护数据不丢失、不被未授权(unauthorised)访问、更改或删除。
- 隐私(privacy)是让数据保密,只有有权查看的人才能看到,并且经过同意、有明确目的。
- 完整性(integrity)是数据准确、一致、完整。
- 一个文件可以安全却损坏,或准确却任何人都能读。考试要求各用一句话说出区别。
Which best describes data "integrity"? · 哪项最能描述数据“完整性”?
Integrity = accurate and complete. Security = blocking unauthorised access; privacy = control over personal data. · 完整性 = 准确且完整。安全性 = 阻止未授权访问;隐私 = 对个人数据的控制权。
Privacy is about a person controlling who sees their personal data, while security is about stopping unauthorised access. · 隐私是关于个人控制谁可以看到其私人数据,而安全是关于阻止未授权访问。
They overlap but differ: security blocks intruders; privacy is control over personal data; integrity is about accuracy. · 它们有重叠但不同:安全阻止入侵者;隐私是对个人数据的控制;完整性关乎准确性。
Two things to protect
- The data: it is personal and confidential, so it must not be read, changed or deleted by an unauthorised person, and losing it would stop the organisation working.
- The computer system: an intruder who reaches it can install malware, use it to attack other systems, damage hardware or software, or lock it with ransomware.
- A secure system is the first line of defence for the data on it. "Why must a school keep both secure?" wants one reason for each.
要保护的两样东西
- 数据:它是个人的、保密的,所以不能被未授权者读取、更改或删除,丢失它会让机构停摆。
- 计算机系统:入侵者一旦进入,就能安装恶意软件、用它攻击其他系统、损坏硬件或软件,或用勒索软件把它锁住。
- 安全的系统是其上数据的第一道防线。"学校为什么必须两者都保护?"要每样一个理由。
Risk and responsibility lab · 风险与责任实验室
Sort examples by the rule, risk or protection involved. · 根据所涉及的规则、风险或保护措施对示例进行排序。
Why must a school keep its computer system secure, not only its data? Select all · 所有 that apply. · 为什么学校必须保持其计算机系统的安全,而不仅仅是数据?选择所有适用项。
System security is the first line of defence: a compromised machine attacks, steals and can be held to ransom. Accuracy is integrity, a different property. · 系统安全是第一道防线:被攻陷的机器会发起攻击、窃取数据并可能被勒索。准确性是完整性,这是不同的属性。
Malware
| Type | What it does |
|---|---|
| virus 病毒 | self-copying code that attaches to other programs and spreads when they run |
| worm 蠕虫 | self-copying code that spreads over networks with no user action |
| Trojan 木马 | looks useful but hides malicious code |
| spyware 间谍软件 | secretly records key presses and actions and sends them to a third party |
| ransomware 勒索软件 | encrypts your files and demands payment |
| adware 广告软件 | pushes unwanted adverts |
Two families: the ones that spread themselves and the ones that hide
恶意软件
| 类型 | 它做什么 |
|---|---|
| 病毒(virus) | 自我复制的代码,附着在其他程序上,在程序运行时传播 |
| 蠕虫(worm) | 自我复制的代码,无需用户操作即通过网络传播 |
| 木马(Trojan) | 看起来有用,却隐藏恶意代码 |
| 间谍软件(spyware) | 秘密记录按键和操作并发送给第三方 |
| 勒索软件(ransomware) | 加密你的文件并索要赎金 |
| 广告软件(adware) | 推送不想要的广告 |

两个家族:自己传播的,和藏起来的
How does a worm differ from a virus? · 蠕虫与病毒有何区别?
A worm self-propagates across networks without user action; a virus needs an infected program to be run. · 蠕虫无需用户操作即可在网络中自我传播;病毒需要运行受感染的程序。
Malware that encrypts your files and demands payment for the key is called . · 加密您的文件并要求支付费用以获取密钥的恶意软件被称为。
Ransomware encrypts the victim's files and demands a ransom for the decryption key. · 勒索软件加密受害者的文件并要求支付赎金以换取解密密钥。
Match each type of malware to its behaviour. · 将每种类型的恶意软件与其行为匹配。
Spyware spies, a Trojan disguises itself, and a worm self-spreads across networks. · 间谍软件窃听,特洛伊木马伪装自己,蠕虫在网络中自我传播。
Worked example: describe a virus and spyware
- Describe what is meant by a virus and by spyware. [4]
- A virus is malicious software that replicates, copying itself and attaching to other files, and deletes or corrupts data.
- Spyware is malicious software that records the user's key presses and actions and sends them to a third party, to obtain passwords and personal data.
- Two facts each: how it behaves, and what it does to the victim. Swapping "replicates" and "records" loses both marks.
例题:描述病毒和间谍软件
- 描述病毒和间谍软件分别指什么。[4]
- 病毒是会复制的恶意软件——复制自己并附着到其他文件上——并删除或损坏数据。
- 间谍软件是记录用户按键和操作并发送给第三方的恶意软件,目的是获取密码和个人数据。
- 各两个事实:它怎样行为,以及对受害者做了什么。把"复制"和"记录"互换会丢掉两分。
Tricking people
- Phishing 网络钓鱼: an email pretending to come from a legitimate organisation leads the user to a fake website that collects their credentials or personal data.
- Pharming 域名欺骗: malicious code redirects the user to a fake website even when they type the correct address.
- Social engineering 社会工程: tricking a person into giving up information, by phone, by email or in person.
- The difference the exam marks: phishing needs the user to follow a link; pharming works on a correct address.
欺骗人
- 网络钓鱼(phishing):一封假装来自合法机构的电子邮件把用户引到收集其凭据或个人数据的假网站。
- 域名欺骗(pharming):恶意代码把用户重定向到假网站,即使他们输入了正确的地址。
- 社会工程(social engineering):通过电话、电子邮件或当面欺骗一个人交出信息。
- 考试评分的区别:网络钓鱼需要用户点击链接;域名欺骗在正确地址上也起作用。
Phishing is: · 网络钓鱼是:
Phishing deceives users into revealing passwords or details via fake messages/sites. · 网络钓鱼通过伪造的消息/网站欺骗用户泄露密码或详细信息。
A user types their bank's correct web address and still arrives at a fake site. This is: · 用户输入了银行正确的网址但仍到达了一个假网站。这是:
Pharming redirects a correct address; phishing needs the user to follow a link in a fake email. · 域名劫持重定向正确地址;网络钓鱼需要用户在伪造的邮件中点击链接。
Attacks on the network
- Hacking by hackers 黑客: unauthorised access, often through a weak password or a software flaw.
- Denial of service 拒绝服务 (DoS/DDoS): a server is flooded with requests until real users cannot reach it.
- Eavesdropping 窃听: capturing data in transit, a risk on open Wi-Fi. Man-in-the-middle 中间人攻击: an attacker secretly relays or alters the messages between two parties.
Both parties believe they are talking to each other
对网络的攻击
- 黑客(hackers)的入侵:未授权访问,常通过弱密码或软件漏洞。
- 拒绝服务(denial of service,DoS/DDoS):服务器被请求淹没,直到真实用户无法访问。
- 窃听(eavesdropping):截获传输中的数据,在开放 Wi-Fi 上是风险。中间人攻击(man-in-the-middle):攻击者秘密转发或篡改双方之间的消息。

双方都以为在和对方对话
A denial-of-service (DoS/DDoS) attack: · 拒绝服务 (DoS/DDoS) 攻击:
DoS/DDoS overwhelms a server with traffic so legitimate requests can't get through. · DoS/DDoS 通过流量淹没服务器使合法请求无法通过。
Worked example: two threats to a school network
- Identify and describe two threats to the data on a school network, and give a different prevention method for each. [6]
- Malware: a virus copied onto a computer from an email attachment or a download replicates and corrupts or deletes files. Prevention: anti-virus software that scans files and is kept up to date.
- Hacking: an unauthorised person gains access to the network, for example by guessing a weak password, and reads or changes the data. Prevention: a firewall that blocks unauthorised traffic, and strong passwords.
- Threat, what it does, a prevention that actually stops it. Two threats with the same prevention lose a mark.
例题:校园网的两种威胁
- 指出并描述校园网上数据面临的两种威胁,并为每种给出不同的预防方法。[6]
- 恶意软件:从邮件附件或下载复制到计算机上的病毒自我复制,并损坏或删除文件。预防:扫描文件并保持更新的杀毒软件。
- 黑客入侵:未授权者进入网络——例如猜出弱密码——并读取或更改数据。预防:阻止未授权流量的防火墙,以及强密码。
- 威胁、它做什么、一个真正能阻止它的预防措施。两种威胁用同一个预防措施会丢一分。
Match each threat to a prevention that actually stops it. · 将每种威胁与其能实际阻止它的预防措施匹配。
Each prevention fits its threat. The exam deducts for reusing one measure or for a measure that would not stop the threat named. · 每种预防措施都对应其威胁。考试会对重复使用同一措施或措施无法阻止指定威胁的情况扣分。
Restricting the risk of malware
- Install anti-malware software and keep it updated, so that new malware is recognised.
- Use a firewall. Keep the operating system and applications patched, which is exactly what WannaCry's victims had not done.
- Do not open attachments or download files from unknown sources, and train users to recognise phishing.
降低恶意软件的风险
- 安装反恶意软件并保持更新,让新的恶意软件能被识别。
- 使用防火墙。给操作系统和应用程序打补丁——这正是 WannaCry 的受害者没做的。
- 不打开来源不明的附件或下载文件,并培训用户识别网络钓鱼。
Marks that slip away
- The replicating one is the virus; the recording one is spyware. Do not swap the verbs.
- Phishing arrives by email and needs a click; pharming redirects a correct address.
- Give a different prevention for each threat, and one that fits it. "Antivirus" does not stop hacking.
- A measure earns marks with how it works: "a firewall that compares traffic with set criteria and blocks what fails".
容易丢掉的分
- 会复制的是病毒;会记录的是间谍软件。不要互换动词。
- 网络钓鱼通过邮件到达,需要点击;域名欺骗重定向一个正确的地址。
- 为每种威胁给出不同且匹配的预防措施。"杀毒软件"阻止不了黑客入侵。
- 措施要连同它怎样工作才得分:"防火墙把流量与设定的标准比较,阻止不合格的"。
You've got it
- security keeps data safe from loss and unauthorised access · privacy keeps it seen only by those with the right · integrity keeps it accurate, consistent and complete
- protect both the data and the computer system: a compromised system attacks others, steals credentials and can be held to ransom
- virus replicates and attaches · worm spreads over networks by itself · Trojan hides in something useful · spyware records and sends · ransomware encrypts for payment
- phishing by email link · pharming on a correct address · hacking, DoS, eavesdropping, man-in-the-middle on the network
你掌握了
- 安全保护数据不丢失、不被未授权访问 · 隐私让数据只被有权的人看到 · 完整性让数据准确、一致、完整
- 既保护数据也保护计算机系统:被攻陷的系统会攻击别人、窃取凭据,还可能被勒索
- 病毒复制并附着 · 蠕虫自己通过网络传播 · 木马藏在有用的东西里 · 间谍软件记录并发送 · 勒索软件加密索要赎金
- 网络钓鱼靠邮件链接 · 域名欺骗在正确地址上 · 网络上的黑客入侵、拒绝服务、窃听、中间人攻击