Protecting Devices · 保护设备
| English | 中文 | Pinyin · 拼音 |
|---|---|---|
| acceptable use policy/əkˈseptəbl juːs ˈpɒlɪsi/ | 可接受使用政策 | kě jiē shòu shǐ yòng zhèng cè |
| anti-malware software/ˈænti ˈmælweə ˈsɒftweə/ | 反恶意软件 | fǎn è yì ruǎn jiàn |
| patch/pætʃ/ | 补丁 | bǔ dīng |
| host-based firewall/həʊst beɪst ˈfaɪəwɔːl/ | 主机防火墙 | zhǔ jī fáng huǒ qiáng |
Policies for devices
- An acceptable use policy 可接受使用政策 lists what users may and may not do.
- A password policy sets length and reuse rules.
- A software installation policy controls what can be installed.
设备政策
- 可接受使用政策(acceptable use policy)列出用户可做和不可做的事。
- 密码政策设定长度和重用规则。
- 软件安装政策控制可以安装什么。
Anti-malware and updates
- Anti-malware software 反恶意软件 quarantines files matching known signatures.
- Keeping the OS and apps updated installs each patch 补丁.
- Patches close known holes before adversaries use them.
反恶意软件与更新
- 反恶意软件(anti-malware software)隔离匹配已知特征的文件。
- 保持操作系统和应用更新会安装每个补丁(patch)。
- 补丁在对手利用前关闭已知漏洞。
Which control protects the device here? · 哪项控制在此保护了设备?
Anti-malware catches known malware; patching closes known holes; a host firewall blocks unneeded ports; a policy sets rules. · 反恶意软件捕获已知恶意软件;补丁修复已知漏洞;主机防火墙阻止不必要的端口;策略设定规则。
Why does keeping software updated make a device safer? · 为什么保持软件更新能使设备更安全?
A patch closes a known hole. · 补丁 关闭已知漏洞。
A firewall that controls traffic for just one device is a... · 仅控制单个设备流量的防火墙是……
A host-based firewall guards one device. · 主机防火墙 保护单个设备。
The policy listing what users may and may not do on a device is the ____ use policy. · 列出用户在设备上可做什么和不可做什么的策略是____使用策略。
The acceptable use policy sets the rules. · 可接受使用策略 设定了规则。
Which protect a device? (Choose all) · 哪些能保护设备?(多选)
Leaving all ports open increases risk. · 开放所有端口会增加风险。
Host-based firewall
- A host-based firewall 主机防火墙 controls traffic for one single device.
- It blocks ports and services the device does not need.
- This adds a layer even on a compromised network.
主机防火墙
- 主机防火墙(host-based firewall)控制单一设备的流量。
- 它阻止设备不需要的端口和服务。
- 即使在被攻破的网络上,这也增加了一层保护。
An unpatched device is an open door. When vendors release a patch, they publicly reveal the hole it fixes — so adversaries immediately target anyone who has not updated. Patch promptly.
未打补丁的设备是一扇敞开的门。当厂商发布补丁时,他们公开揭示了它修复的漏洞——所以对手立即瞄准任何尚未更新的人。及时打补丁。
Anti-malware software uses a database of signatures to spot malicious files. · 反恶意软件使用签名数据库来识别恶意文件。
It quarantines files matching a signature. · 它将匹配签名的文件隔离。
A host-based firewall on a laptop blocks all outbound FTP traffic. If malware later infects the laptop and tries to send stolen files out over FTP, the host firewall stops it — even though the network firewall allowed FTP.
笔记本电脑上的主机防火墙阻止所有出站FTP流量。如果恶意软件后来感染了笔记本并试图通过FTP把偷来的文件发出去,主机防火墙会阻止它——即使网络防火墙允许了FTP。
Protect devices with policies (acceptable use, password, software installation), anti-malware that matches signatures, prompt patching of the OS and apps, and a host-based firewall that guards one device by blocking unneeded ports.
用政策(可接受使用、密码、软件安装)、匹配特征的反恶意软件、及时打补丁操作系统和应用,以及通过阻止不需要的端口来守护单一设备的主机防火墙来保护设备。