Cyber security · 网络安全
| English | 中文 | Pinyin · 拼音 |
|---|---|---|
| cyber security/ˈsaɪbə sɪˈkjʊərɪti/ | 网络安全 | wǎng luò ān quán |
| malware/ˈmælweə/ | 恶意软件 | è yì ruǎn jiàn |
| brute force/bruːt fɔːs/ | 暴力破解 | bào lì pò jiě |
| DDoS/diː duː es/ | 分布式拒绝服务 | fēn bù shì jù jué fú wù |
| phishing/ˈfɪʃɪŋ/ | 网络钓鱼 | wǎng luò diào yú |
| pharming/ˈfɑːmɪŋ/ | 域名欺骗 | yù míng qī piàn |
| social engineering/ˈsəʊʃl ˌendʒɪˈnɪərɪŋ/ | 社会工程 | shè huì gōng chéng |
| virus/ˈvaɪrəs/ | 病毒 | bìng dú |
| worm/wɜːm/ | 蠕虫 | rú chóng |
| Trojan horse/ˈtrəʊdʒn hɔːs/ | 特洛伊木马 | tè luò yī mù mǎ |
| spyware/ˈspaɪweə/ | 间谍软件 | jiàn dié ruǎn jiàn |
| ransomware/ˈrænsəmweə/ | 勒索软件 | lè suǒ ruǎn jiàn |
| firewall/ˈfaɪəwɔːl/ | 防火墙 | fáng huǒ qiáng |
| authentication/ɔːˌθentɪˈkeɪʃn/ | 身份验证 | shēn fèn yàn zhèng |
Defending against attack
- Cyber security 网络安全 keeps computers, networks and data safe from attack.
- You must know the main threats, the types of malware 恶意软件, and how to protect data.
- Many attacks trick people, not just computers.
防御攻击
- 网络安全(cyber security)使计算机、网络和数据免受攻击。
- 你必须知道主要的威胁、恶意软件(malware)的类型,以及如何保护数据。
- 许多攻击欺骗人,不只是计算机。
Threats
- Brute force 暴力破解 — trying many passwords quickly until one works.
- Data interception — "listening in" to steal data as it travels.
- DDoS 分布式拒绝服务 — flooding a server with requests so it can't respond (the site goes down).
- Hacking — gaining access without permission.
- Phishing 网络钓鱼 — fake messages that trick you into giving details; pharming 域名欺骗 — secret code sends you to a fake site even when you type the right address.
- Social engineering 社会工程 — tricking a person (e.g. pretending to be the boss).
The browser asks a DNS for the site's IP address, then requests the page from the web server, which returns the HTML.
威胁
- 暴力破解(brute force)——快速尝试许多密码直到一个有效。
- 数据拦截(data interception)——"窃听"以在数据传播时窃取它。
- DDoS——用请求淹没一个服务器使它无法响应(网站宕机)。
- 黑客攻击(hacking)——未经许可获得访问。
- 网络钓鱼(phishing)——欺骗你给出细节的假消息;域名欺骗(pharming)——秘密代码即使你键入正确的地址也把你送到一个假网站。
- 社会工程(social engineering)——欺骗一个人(例如假装是老板)。

浏览器向一个 DNS 询问网站的 IP 地址,然后从网页服务器请求页面,服务器返回 HTML。
Encryption with a key · 用密钥加密
Change the shift — that is the key. Each letter slides that many places to make ciphertext, and the same key slides it back. That is symmetric encryption. · 改变偏移量——那就是密钥。每个字母滑动那么多位生成密文,同样的密钥把它滑回来。这就是对称加密。
A brute force attack works by: · 一个暴力破解攻击通过以下工作:
Brute force tries password after password until it gets in. · 暴力破解一个接一个地尝试密码,直到进入。
A DDoS attack: · 一个 DDoS 攻击:
A distributed denial-of-service overwhelms a server so genuine users can't reach the site. · 一个分布式拒绝服务压垮一个服务器,使真正的用户无法到达网站。
Phishing tricks you with fake messages into giving away details, while pharming silently redirects you to a fake site even when you type the correct address. · 网络钓鱼用假消息欺骗你交出细节,而域名欺骗即使你键入正确的地址也悄悄把你重定向到一个假网站。
Both aim to steal credentials, but phishing needs you to click; pharming poisons the address lookup itself. · 两者都旨在窃取凭据,但网络钓鱼需要你点击;域名欺骗毒化地址查找本身。
Malware
- Virus 病毒 — attaches to a file and copies itself when the file is opened.
- Worm 蠕虫 — copies itself across a network on its own, with no file needed.
- Trojan horse 特洛伊木马 — pretends to be useful, but harms once installed.
- Spyware 间谍软件 — secretly records what you do (e.g. keystrokes); adware — floods you with adverts; ransomware 勒索软件 — locks your files and demands payment.
A URL has three parts: the protocol, the domain name, and the path to the page on the server.
恶意软件
- 病毒(virus)——附着到一个文件,并在文件被打开时复制自己。
- 蠕虫(worm)——自己跨一个网络复制自己,不需要文件。
- 特洛伊木马(Trojan horse)——假装有用,但一旦安装就造成伤害。
- 间谍软件(spyware)——秘密记录你做什么(例如击键);广告软件(adware)——用广告淹没你;勒索软件(ransomware)——锁住你的文件并要求付款。

一个 URL 有三部分:协议、域名,和到服务器上页面的路径。
How does a worm differ from a virus? · 一个蠕虫与一个病毒有何不同?
A worm self-spreads over networks; a virus needs an infected file to be opened. · 一个蠕虫在网络上自我传播;一个病毒需要一个被感染的文件被打开。
Match each item to what it is. · 把每个项目匹配到它是什么。
Ransomware extorts; spyware spies; DDoS overwhelms a server. · 勒索软件勒索;间谍软件监视;DDoS 压垮一个服务器。
Keeping data safe
- Access levels (each user sees only what they need), anti-malware, and a firewall 防火墙 (checks and blocks network traffic).
- Authentication 身份验证 — proving who you are: a password, biometrics, or two-step verification.
- Automatic software updates (fix weak points), checking a message's spelling/tone and a link's URL, privacy settings, and a proxy server (hides your IP, filters content).
A firewall sits between the outside internet and your network, checking each connection and blocking any traffic that is not allowed
保持数据安全
- 访问级别(access levels,每个用户只看到他们需要的)、反恶意软件(anti-malware),和一个防火墙(firewall,检查并阻止网络流量)。
- 身份验证(authentication)——证明你是谁:一个密码、生物识别(biometrics),或两步验证(two-step verification)。
- 自动软件更新(修复弱点)、检查一条消息的拼写/语气和一个链接的 URL、隐私设置,和一个代理服务器(proxy server,隐藏你的 IP、过滤内容)。

一个防火墙位于外部互联网和你的网络之间,检查每个连接并阻止任何不被允许的流量
Two-step verification improves security by: · 两步验证通过以下提高安全:
Adding a second factor (a phone code or biometric) means a stolen password alone is not enough. · 添加第二个因素(一个手机验证码或生物识别)意味着单单一个被窃取的密码不够。
You've got it
- threats: brute force, interception, DDoS, hacking, phishing/pharming, social engineering
- malware: virus (file), worm (network), Trojan, spyware, adware, ransomware
- protect with access levels, anti-malware, firewall, authentication/2FA, updates, proxy server
- many attacks target people — check spelling, tone and the URL
你掌握了
- 威胁:暴力破解、拦截、DDoS、黑客攻击、网络钓鱼/域名欺骗、社会工程
- 恶意软件:病毒(文件)、蠕虫(网络)、特洛伊木马、间谍软件、广告软件、勒索软件
- 用访问级别、反恶意软件、防火墙、身份验证/2FA、更新、代理服务器保护
- 许多攻击针对人——检查拼写、语气和 URL