Skip to content · ⁨דלג לתוכן⁩

Securing Networks · ⁨אבטחת רשתות⁩

AP Cybersecurity · ⁨אבטחת מידע והסייבר - AP⁩ · Topic 3 · ⁨נושא 3⁩

Video lesson for this topic · ⁨שיעור וידאו לנושא זה⁩ Open the video page · ⁨פתח את עמוד הוידאו⁩
9:26

אבטחת רשתות

אתה שולח הודעה לבנק שלך. היא מגיעה. התשובה חוזרת. הכל נראה תקין. אבל מישהו יושב בשקט בינך, וקורא כל הודעה…

English narration · English + 中文 subtitles burned in · ⁨קריאת קול באנגלית · תרגום אנגלי + סינית שרוף בתוך הסרטון⁩

3.1

Network Vulnerabilities and Attacks · ⁨חומות נקבעויות והתקפות ברשת⁩

Syllabus · ⁨סיילבוס⁩
English

Learning Objective 3.1.A: Identify common network attacks.

  • 3.1.A.1 The address resolution protocol (ARP) is used by a default gateway on a network to establish a table that pairs internet protocol (IP) addresses with media access control (MAC) addresses. An ARP poisoning attack is when an adversary sends falsified ARP packets to the default gateway to modify the table so that the adversary’s device receives traffic intended for the target by linking the target’s IP address to the adversary’s MAC address. Faking a MAC address is called MAC spoofing. This is an example of an on-path attack (or man-in-the-middle attack), which is when an adversary interrupts a data stream between two parties, captures both parties’ data, and copies or alters the data before sending them on. Both parties think they are communicating directly with each other, but instead they are each communicating with the adversary who is secretly intercepting their messages.
  • 3.1.A.2 A MAC flooding attack is when an adversary sends the target switch many Ethernet frames, each with a different MAC address. This can force the switch into broadcast mode, and the adversary can then collect all of the frames on the network (because they are being broadcast), which could allow the adversary to access sensitive information. This is an example of eavesdropping (or sniffing), which is when an adversary captures data in transit and can record and copy the data.
  • 3.1.A.3 A domain name system (DNS) poisoning attack is when an adversary pretends to be an authoritative name server (NS) and plants a fake DNS record on a DNS server to redirect browser traffic to a malicious website designed to steal credentials. This is an example of credential harvesting, which is when adversaries set up a fake login site that looks like a real one. Unsuspecting users enter their real credentials, which the adversaries capture and use.
  • 3.1.A.4 A smurf attack attempts to overwhelm a network with Internet Control Message Protocol (ICMP) requests. It is a type of denial of service (DoS) attack, which makes a system or resource unavailable to authorized users. During a smurf attack, an adversary sends many ICMP requests with the victim’s address to the network’s broadcast address. The network’s gateway then sends these requests to all devices on the network. Each device on the network replies to the victim’s address, creating a flood of traffic that can block legitimate messages. When multiple devices attack the same target simultaneously, it’s called a distributed denial of service (DDoS) attack.

Learning Objective 3.1.B: Explain how adversaries can exploit network vulnerabilities to steal, disrupt, or destroy network communication.

  • 3.1.B.1 Adversaries can send malicious traffic into a network to flood it creating a DoS, to map the internal structure of the network, or to spoof a legitimate device. Networks without firewalls, or with improperly configured firewalls, are vulnerable to these types of attacks.
  • 3.1.B.2 Adversaries that have compromised a device often attempt to leverage their access to compromise other devices on the local area network (LAN).
  • 3.1.B.3 Adversaries that physically plug into a data port can gain access to a LAN through the switch port unless port security is enabled. This allows adversaries to launch DoS attacks or perform MAC flooding or MAC spoofing attacks.
  • 3.1.B.4 Adversaries standing outside of physically secure spaces can pick up the signals and beacon frames from a wireless access point that is broadcasting outside the physical space. This allows them to gather information about the wireless network and to attempt eavesdropping and cryptographic attacks on it.
  • 3.1.B.5 Adversaries can attempt to join networks to launch attacks from within the networks. Networks that do not authenticate devices and users make it easier for adversaries to join.
  • 3.1.B.6 If there is an open network port, an adversary can plug a wireless access point into the port creating a rogue access point. The adversary could use this rogue access point to access the internal network wirelessly (maybe even from outside the physical space). This allows the adversary direct access to the LAN, bypassing any firewalls.
  • 3.1.B.7 Adversaries can attempt to break wireless encryption and intercept, steal, or compromise data on a network.

Learning Objective 3.1.C: Assess and document risks from network vulnerabilities.

  • 3.1.C.1 Vulnerabilities on a network can lead to adversaries being able to intercept and alter data in transit, launch DoS attacks, or move laterally on a network to gain access to more sensitive or critical systems. Network vulnerabilities can constitute a risk to confidentiality, integrity, and availability.
  • 3.1.C.2 There are automated vulnerability scanners that can check networks, devices, and applications for known vulnerabilities. These scanners produce a report that often includes the vulnerabilities detected, their severity, and mitigation recommendations.
  • 3.1.C.3 Successfully exploiting a network vulnerability often requires advanced technical ability and knowledge. This can impact the likelihood of an exploit.
  • 3.1.C.4 High risks from network vulnerabilities allow an adversary to easily have a significant impact by capturing network traffic, spoofing a legitimate device on the network, or launching a DoS attack.
    • Illustrative examples for 3.1.C.4:
      • An organization has a single unsegmented internal network that is accessible via a wireless network with weak encryption, and on that network it has a server running its proprietary web-application.
  • 3.1.C.5 Moderate risks from network vulnerabilities could include vulnerabilities that might give adversaries the ability to gain information about systems or devices on a network.
    • Illustrative examples for 3.1.C.5:
      • An organization’s external firewall is not configured to block external ICMP traffic.
  • 3.1.C.6 Low risks from network vulnerabilities include vulnerabilities that would be difficult to exploit and would likely have minimal negative impacts on an organization.
    • Illustrative examples for 3.1.C.6:
      • An organization has wireless access points that broadcast a beacon frame, which contains the network service set identifier (SSID) and the wireless encryption protocols.
עברית

מטרות למידה 3.1.A: זיהוי התקפות רשת נפוצות.

  • 3.1.A.1 פרוטוקול פתרון כתובות (ARP) משמש על ידי שערי ברירת מחדל ברשת ליצירת טבלה המקשרת כתובות אינטרנט (IP) לכתובות בקרת גישה מדיה (MAC). התקפת הרשלת ARP היא כאשר אויב שולח חבילות ARP מזויפות לשער ברירת מחדל כדי לשנות את הטבלה כך שמכשיר האויב יקבל תנועה שנועדה ליעד על ידי חיבור כתובת ה-IP של היעד לכתובת ה-MAC של האויב. הזיוף של כתובת MAC נקרא MAC spoofing. זהו דוגמה להתקפה מסלול (או man-in-the-middle), שבה אויב מפריע לזרימת נתונים בין שני צדדים, תופס את הנתונים של שני הצדדים ומעתיק או משנה אותם לפני השליחה. שני הצדדים חושבים שהם תקשורת ישירה אחד עם השני, אך למעשה כל אחד תקשורת עם האויב שחוצץ בסתר בהודעותיהם.
  • 3.1.A.2 התקפת הצפת MAC היא כאשר אויב שולח למתג היעד מספר רב של מסגות אתרנט, כל אחת עם כתובת MAC שונה. זאת יכולה להכריח את המתג לעבור למצב שידור (broadcast), ובכך האויב יכול לאסוף את כל המסגות ברשת (מכיוון שהן משודרות), מה שיכול לאפשר לאויב לגשת למידע רגיש. זהו דוגמה להקשבה (או sniffing), שבה אויב תופס נתונים בזמן מעבר ויכול להקליט ולהעתיק אותם.
  • 3.1.A.3 התקפת הרשלת DNS היא כאשר אויב מתחזה לשירות שם מוסמך (NS) ומוטען רקCORD DNS מזויף על שרת DNS כדי להפנות תנועת דפדפן לאתר רע designed to steal credentials. זהו דוגמה לאיסוף תעודות זיהוי (credential harvesting), שבו אויבים יוצרים אתר התחברות מזויף שנראה כמו אתר אמיתי. משתמשים חסרי ספק מכניסים את תעודות הזיהוי האמיתיות שלהם, שהאויבים תופסים ומשתמשים בהן.
  • 3.1.A.4 התקפת Smurf מנסה לעמוס רשת בבקשות Internet Control Message Protocol (ICMP). זוהי סוג של התקפת סירוב שירות (DoS), שמפחיתה את זמינות מערכת או משאב למשתמשים מורשים. במהלם התקפת Smurf, אויב שולח מספר רב של בקשות ICMP עם כתובת הקורבן לכתובת השידור של הרשת. שערי הרשת שולחים את הבקשות הללו לכל המכשירים ברשת. כל מכשיר ברשת מגיב לכתובת הקורבן, ויוצר גלישת תנועה שיכולה לחסום הודעות חוקיות. כאשר מספר מכשירים תוקפים אותו יעד בו-זמנית, נקראת ההתקפה התקפת סירוב שרות מבוזרת (DDoS).

מטרות למידה 3.1.B: הסבר כיצד אויבים יכולים לנצל חולשות רשת לגניבה, הפרעה או הרס תקשורת רשת.

  • 3.1.B.1 מתקיפים יכולים לשלוח תנועה זדונית לתוך רשת כדי לטבול אותה ולגרום להפסקת שירות (DoS), לעצב את המבנה הפנימי של הרשת, או לגרסת התחברות של התקן חוקי. רשתות שאין בהן אשונות גדר, או שהאשונות הגדר שלהן מוגדרות באופן לא תקין, הן רגישות לסוגי התקפות אלו.
  • 3.1.B.2 מתקיפים שפרצו התקן מסוים נטים לנצל את גישה זו כדי לפרץ התקנים אחרים ברשת מקומית (LAN).
  • 3.1.B.3 התוקפים שמחברים פיזית לתא נתונים יכולים להשיג גישה לרשת LAN דרך יציאת הסוויץ' כל עוד ביטחון יציאה אינו מופעל. הדבר מאפשר להתוקפים להפעיל תקיפת DoS או לבצע תקיפות MAC flooding או MAC spoofing.
  • 3.1.B.4 מתקיפים הנמצאים מחוץ לחללים בטוחים פיזית יכולים לקלוט אותות ומסגרות ביקור (beacon frames) מאחת נגישות אלחוטית שמשידרת מחוץ לחלל הפיזי. זה מאפשר להם לאסוף מידע על הרשת האלחוטית ולנסות לבצע ציתת דיבור והתקפות קריפטוגרפיות עליה.
  • 3.1.B.5 מתקיפים יכולים לנסות להתחבר לרשתות כדי לבצע התקבות מתוכן הרשתות. רשתות שאינן מאמתות התקנים ומשתמשים מקלות על מתקיפים להתחבר אליהן.
  • 3.1.B.6 אם יש פורט רשת פתוח, מתקין יכול לחבר אחת נגישות אלחוטית לפורט ליצירת אחת נגישות זדונית. המתקין יכול להשתמש באחת הנגישות הזו כדי לגשת לרשת הפנימית אלחוטית (ואולי גם מחוץ לחלל הפיזי). זה מאפשר למתקין גישה ישירה ל-LAN, סביב כל אשון גדר.
  • 3.1.B.7 מתקיפים יכולים לנסות לשבור את ההצפנה של רשתות אלחוטיות ולהצית, לגנוב או לפגוע במידע ברשת.

מטרות למידה 3.1.C: הערכה ותיעוד סיכונים ממעורעוריות ברשתות.

  • 3.1.C.1 מעורעוריות ברשת עשויות להוביל לכך שמתקיפים יוכלו להצית ולשנות מידע במעבר, לבצע התקבות DoS, או לנוע בצדדים ברשת כדי לגשת למערכות רגישות או קריטיות יותר. מעורעוריות ברשת יכולות להוות סיכון לנאמנות, שלמות וזמינות.
  • 3.1.C.2 קיימים סורקי מעורעוריות אוטומטיים שיכולים לבדוק רשתות, התקנים ואפליקציות למעורעוריות ידועות. סורקים אלו מייצרים דוח המכלל לעיתים קרובות את המעורעוריות שזוהו, את חומרתן, והמלצות לטיפול.
  • 3.1.C.3 ניצול מוצלח של מעורעוריות ברשת דורש לעיתים קרובות יכולת טכנית ומידע מתקדמים. הדבר יכול להשפיע על הסבירות לניצול.
  • 3.1.C.4 סיכונים גבוהים ממעורעוריות ברשת מאפשרים למתקין להשיג השפעה משמעותית בקלות על ידי לכידת תנועת רשת, גרסת התחברות של התקן חוקי ברשת, או ביצוע התקבת DoS.
    • דוגמאות מדגמיות ל-3.1.C.4:
      • ארגון בעל רשת פנימית אחת שאינה מחולקת, הנגישה דרך רשת אלחוטית עם הצפנה חלשה, ועל הרשת הזו יש שרת המופעלת בו אפליקציית אינטרנט פרופריטארית.
  • 3.1.C.5 סיכונים בינוניים ממעורעוריות ברשת יכולים לכלול מעורעוריות שיכולות לתת למתקינים יכולת לקבל מידע על מערכות או התקנים ברשת.
    • דוגמאות מדגמיות ל-3.1.C.5:
      • אשון גדר חיצוני של ארגון אינו מוגדר כדי לחסום תנועת ICMP חיצונית.
  • 3.1.C.6 סיכונים נמוכים ממעורעוריות ברשת כוללים מעורעוריות שייהיו קשות לניצול ושמסביר שיהיו להן השפעות שליליות מינימליות על ארגון.
    • דוגמאות מדגמיות ל-3.1.C.6:
      • לארגון יש אחת נגישות אלחוטית שמשידרת מסגרת ביקור, המכילה את מזהה שרת השירות של הרשת (SSID) ואת פרוטוקולי ההצפנה האלחוטיים.

Source: College Board AP Course and Exam Description · ⁨מקור: תיאור הקורס והמבחן של College Board AP⁩

English
A man-in-the-middle attack
DDoS: a botnet floods a server

A network connects devices so they can share data - and every connection is a possible way in. You must know the classic network attacks and the tricks behind them.

  • ARP poisoning 地址解析投毒 - the address resolution protocol (ARP) 地址解析协议 pairs IP addresses with hardware MAC addresses 物理地址. An adversary sends fake ARP messages so traffic meant for the target flows to the adversary instead. This is an on-path attack 中间人攻击 (also called man-in-the-middle): the adversary secretly sits between two parties, reading and even altering their messages.
  • MAC flooding 物理地址泛洪 - flooding a switch 交换机 with fake MAC addresses forces it into broadcast mode, so the adversary can capture all traffic. This is a form of eavesdropping 窃听.
  • DNS poisoning 域名投毒 - planting a fake record on a domain name system (DNS) 域名系统 server redirects users to a malicious site to steal credentials (credential harvesting 凭据收集).
  • Smurf attack - flooding a network with ICMP requests aimed at the broadcast address, so every device replies to the victim. It is a denial of service (DoS) 拒绝服务 attack; when many machines attack at once it becomes a distributed denial of service (DDoS) 分布式拒绝服务.

Adversaries exploit weak networks to flood, map, or spoof devices. A physical data port with no port security lets an attacker plug in; an open port lets them install a rogue access point 非法接入点 that bypasses the firewall entirely. We rate network risk by impact and by how much skill the exploit needs.

To find weaknesses before an adversary does, organisations run an automated vulnerability scanner 自动漏洞扫描器: a tool that checks networks, devices, and applications against a database of known vulnerabilities, then produces a report listing each one found, how severe it is, and a recommended mitigation 缓解措施. Fixing the highest-severity items first is a core part of managing network risk.

עברית
התקפת אדם באמצע רשת
DDoS: בוטנט מציף שרת

רשת מחברת מכשירים כדי שיכלו לשתף נתונים - וכל חיבור הוא דרך אפשרית לתוקפים. עליך לדעת את ההתקפות הקלאסיות על רשת ואת הטריקים מאחוריהן.

  • הרעלת ARP - פרוטוקול פתרון הכתובות (ARP) זוגי כתובות IP עם כתובות MAC של ציוד. תקוף שולח הודעות ARP מזויפות כך שתנועה שהייתה אמורה להגיע למטרה תזרום אליו במקום זאת. זוהי התקפת on-path (שנקראת גם אדם באמצע רשת): התוקף יושב בסתר בין שתי הצדדים, קורא ואפילו משנה את ההודעות שלהם.
  • הצפה MAC - הצפת מתג בכתובות MAC מזויפות גורמת לו לעבור למצב שידור קבוצתי, כך שהתוקף יכול לתפוס את כל התנועה. זהו סוג של הקשבה סמויה.
  • הרעלת DNS - השתלת רישום מזויף על שרת מערכת שמות הדומיין (DNS) מפנה משתמשים לאתר זדוני כדי לגנוב פרטי כניסה (איסוף פרטים).
  • התקפת Smurf - הצפת רשת עם בקשות ICMP המכוונות לכתובת השידור הקבוצתית, כך שכל מכשיר מגיב לקורban. זוהי התקפת סירוב שירות (DoS); כאשר מכונות רבות תוקפות בו-זמנית, היא הופכת לסירוב שירות מפוזר (DDoS).

תוקפים מנצלים רשתות חלשות כדי להצפיף, למפות או להתחזות למכשירים. פורט נתונים פיזי ללא ביטחון פורט מאפשר לתוקף לחבר מכשיר; פורט פתוח מאפשר להם להתקין נקודת גישה פוגעת שעוברת מעל הגופרית לחלוטין. אנו דורגים סיכון רשת לפי ההשפעה ולפי כמה מיומנות הפעולה מתקיף דורשת.

כדי למצוא חולשות לפני שבתוקף עושה זאת, ארגונים מבצעים סורק נקבעויות אוטומטי: כלי בודק רשתות, מכשירים ואפליקציות מול מסד נתונים של נקבעויות ידועות, ומייצר דוח המפרט כל אחת מהן שנמצאה, כמה חמורה היא, והמלצה להקלה. תיקון האובייקטים בעלי החמורה הגבוהה ביותר קודם כל הוא חלק ליבה בניהול סיכון רשת.

Explore · ⁨חקור⁩

Identify the network attack from its evidence · ⁨זהה את התקיפה ברשת מתוך העדויות שלה⁩

Each network attack leaves a distinct trace: ARP poisoning = one IP with two MACs; MAC flooding = a surge of new MACs; DNS poisoning = misdirected web traffic; smurf/DoS = a flood that blocks legitimate traffic. · ⁨כל תקיפה ברשת משאירה עקבות ייחודיים: ריעול ARP = כתובת IP אחת עם שני MACs; הצפת MAC = גלישה חד של MACs; ריעול DNS = תנועת אינטרנט מופנת לשגוי; Smurf/DoS = הצפה החוסמת תנועה חוקית.⁩

3.2

Protecting Networks: Managerial Controls and Wireless Security · ⁨הגנה על רשתות: בקרות מנהליות ובטיחות אלחוטית⁩

Syllabus · ⁨סיילבוס⁩
English

Learning Objective 3.2.A: Identify managerial controls related to network security.

  • 3.2.A.1 A router security policy will set forth a minimum configuration standard for routers on an organization’s network and may include:
    • Banning local user accounts (All router logins must use an approved authentication server.)
    • Disabling unnecessary services (e.g., Telnet)
    • Requiring a firewall (An organization may opt for a firewall device separate from the router.)
  • 3.2.A.2 A switch security policy will set forth a minimum configuration standard for switches on an organization’s network and may include:
    • Banning local user accounts (All switch logins must use an approved authentication server.)
    • Requiring port security to be enabled.
    • Using MAC filtering
  • 3.2.A.3 A virtual private network (VPN) policy will detail the minimum security requirements for employees using a VPN to access an organization’s internal network, and it may include:
    • A list of roles within the organization that are allowed to use a VPN to access the organization’s internal network
    • Authentication requirements for employees using a VPN (e.g., public/private key system or MFA)
    • A prohibition against split tunneling (also called dual tunneling)
  • 3.2.A.4 A wireless security policy will establish the minimum security requirements for wireless networks within an organization and may include:
    • Requiring users to authenticate to the wireless network through an extensible authentication protocol (EAP) connected to an approved authentication server
    • Requiring all wireless traffic to be encrypted using AES encryption with a minimum key length
    • Disabling beacon frames on wireless access points

Learning Objective 3.2.B: Configure wireless network security features.

  • 3.2.B.1 Organizations can disable beacon frame broadcasting on wireless access points (WAPs) to make it harder for adversaries to find their wireless network and learn its basic properties.
  • 3.2.B.2 Organizations can control the broadcast direction and signal strength of a WAP so the signal does not extend beyond the physical space the access point is meant to cover.
  • 3.2.B.3 Organizations should enable strong wireless encryption protocols to ensure wireless frames are not readable by adversaries who might intercept them.
    • WEP, WPS, and the original WPA wireless encryption protocols have known vulnerabilities and are insecure.
    • WPA3 is currently the strongest wireless encryption algorithm.
  • 3.2.B.4 Organizations can enable MAC filtering to prevent unauthorized devices from accessing the network, and they can require users to authenticate when joining a network.
עברית

מטרות למידה 3.2.A: זיהוי בקרות מנהליות הקשורות לאבטחת רשת.

  • 3.2.A.1 מדיניות אבטחת נתב תגדיר תקן תצורה מינימלי לנתבים ברשת הארגון, ויכלול עשויה להכיל:
    • איסור על חשבנות משתמש מקומיים (כל כניסות הנתב חייבות להשתמש בשרת אימות מאושר.)
    • השבתת שירותים שאינם נדרשים (למשל Telnet)
    • דרישה לגודל חומרה (An organization may opt for a firewall device separate from the router.)
  • 3.2.A.2 מדיניות אבטחת סוויץ' תגדיר תקן תצורה מינימלי לסוויצים ברשת הארגון, ויכלול עשויה להכיל:
    • איסור על חשבנות משתמש מקומיים (כל כניסות הסוויץ' חייבות להשתמש בשרת אימות מאושר.)
    • דרישה להפעלת אבטחת יציאה.
    • שימוש במסנן MAC
  • 3.2.A.3 מדיניות רשת פרטית וירטואלית (VPN) תפרט את הדרישות המינימליות לאבטחה עבור עובדים המשתמשים ב-VPN כדי לגשת לרשת הפנימית של הארגון, ויכלול עשויה להכיל:
    • רשימת תפקידים בארגון המאושרים להשתמש ב-VPN כדי לגשת לרשת הפנימית של הארגון
    • דרישות אימות לעובדים המשתמשים ב-VPN (למשל מערכת מפתחות ציבורית/פרטית או MFA)
    • איסור על טונל פיצול (split tunneling, גם קרוי dual tunneling)
  • 3.2.A.4 מדיניות אבטחה אלחוטית תקבע את הדרישות המינימליות לאבטחה ברשתות אלחוטיות בתוך הארגון ויכלול עשויה להכיל:
    • דרישה מהמשתמשים לבצע אימות לרשת האלחוטית באמצעות פרוטוקול אימות הרחבה (EAP) מחובר לשרת אימות מאושר
    • דרישה שכל התנועה האלחוטית תוצפן באמצעות הצפנת AES עם אורך מפתח מינימלי
    • השבתת מסגרות ביקה (beacon frames) על נקודות גישה אלחוטיות

מטרות למידה 3.2.B: תצורת מאפייני אבטחה לרשת אלחוטית.

  • 3.2.B.1 ארגונים יכולים להשבת את שידור מסגרות הביקה בנקודות גישה אלחוטיות (WAPs) כדי להקשות על מתקיפי רשת למצוא את הרשת האלחוטית וללמוד את המאפיינים הבסיסיים שלה.
  • 3.2.B.2 ארגונים יכולים לשלוט בכיוון השידור ובעוצמת האות של נקודת גישה אלחוטית (WAP) כך שהאות לא יתפשט מעבר למרחב הפיזי שנקודת הגישה אמורה לכסות.
  • 3.2.B.3 ארגונים צריכים להפעיל פרוטוקולי הצפנה אלחוטית חזקים כדי להבטיח שהמסגרות האלחוטיות לא יהיו קריאות עבור אויבים שייתכן שמצליחים לחצוץ אותן.
    • פרוטוקולי ההצפנה האלחוטית WEP, WPS ו-WPA המקורי בעלי תכונות חולשה ידועות ואינם מאובטחים.
    • כעת, WPA3 הוא האלגוריתם ההצפנה האלחוטית החזק ביותר.
  • 3.2.B.4 ארגונים יכולים להפעיל סינון MAC כדי למנוע מכשירים בלתי מורשים מגישה לרשת, ויכולים לדורש מהמשתמשים לעבור אימות כאשר הם מצטרפים לרשת.

Source: College Board AP Course and Exam Description · ⁨מקור: תיאור הקורס והמבחן של College Board AP⁩

English

Good network security starts with written policies that set a minimum standard: a router security policy and switch security policy ban local accounts and require port security; a VPN policy sets authentication rules and forbids split tunneling 分离隧道; and a wireless security policy requires strong encryption and authenticated access.

For wireless networks specifically, organisations disable beacon frames so the network is harder to find, control signal strength so it does not leak outside the building, enable strong encryption - WPA3 Wi-Fi 保护接入第三代 is the current strongest, while old WEP and the original WPA are broken - and use MAC filtering to allow only known devices.

עברית

ביטחון רשת טוב מתחיל במדיניות כתובה שקובעת סטנדרט מינימלי: מדיניות ביטחון נתב ומדיניות ביטחון מתג אוסמות חשבונות מקומיים ודורשות ביטחון פורט; מדיניות VPN קובעת כללי אימות ואוסמת חלוקת מנהרות; ומדיניות בטיחות אלחוטית דורשת הצפנה חזקה וגישה מאומתת.

לרשתות אלחוטיות ספציפית, ארגונים מנטרלים פריימים Beacon כך שהרשת קשה יותר למצוא, שולטים בעוצמת אות כך שלא תדלף מחוץ לבניין, מפעילים הצפנה חזקה - WPA3 Wi-Fi הוא החזק כיום, בעוד WEP ישן ו-WPA המקורי הם שבורים - ומשתמשים בסינון MAC כדי לאפשר רק מכשירים ידועים.

Vocabulary · ⁨מילון מונחים⁩ Train · ⁨אימון⁩
English עברית
WPA3/ˌdʌbljuː piː eɪ ˈθriː/ WPA3
Network segmentation/ˈnetwɜːk ˌseɡmənˈteɪʃn/ חלוקת רשת
subnets/ˈsʌbnets/ רשתות משנה
screened subnet/skriːnd ˈsʌbnet/ רשת משנה מבודדת
3.3

Protecting Networks: Segmentation · ⁨הגנה על רשתות: ניתוק רשתות⁩

Syllabus · ⁨סיילבוס⁩
English

Learning Objective 3.3.A: Identify techniques for segmenting a network.

  • 3.3.A.1 Firewall zones and rules can be used to create a screened subnet (also known as a demilitarized zone, or DMZ)—a network segment that sits between public, external networks like the internet and internal, private networks. A screened subnet is typically a lower security zone than the internal, private networks, and it typically holds an organization’s publicly facing resources, separating them from the internal network.
  • 3.3.A.2 Subnetting can be used to create different subnets based on IP addressing. If a device is compromised by an adversary, subnets can contain a security breach to reduce the number of exposed devices.
  • 3.3.A.3 Switches can be used to create VLANs, which logically separate devices physically connected to central switches.

Learning Objective 3.3.B: Explain why network segmentation can increase network security.

  • 3.3.B.1 Network segmentation refers to the process of dividing a network into smaller, isolated segments or subnetworks (subnets).
  • 3.3.B.2 Dividing a network into smaller subnets isolates network traffic, which can prevent attacks on one subnet from impacting devices on other subnets.
  • 3.3.B.3 Network segmentation can allow for different security policies and controls to be applied to different segments of the network, allowing for higher security zones and lower security zones.
  • 3.3.B.4 Port security on a switch can prevent MAC flooding by limiting the number of addresses assignable to any single switch port.
עברית

מטרות למידה 3.3.A: זיהוי טכניקות לחלוקת רשת לקטעים.

  • 3.3.A.1 אזורי חומות מגן וכלליהן יכולים לשמש ליצירת סבנט מסונן (ידוע גם כאזור דמי-ליטרי, DMZ) – קטע רשת השוכן בין רשתות ציבוריות חיצוניות כמו האינטרנט לבין רשתות פנימיות פרטיות. סבנט מסונן הוא בדרך כלל אזור עם רמת אבטחה נמוכה יותר מאשר הרשתות הפנימיות הפרטיות, והוא משמש בדרך כלל לאחסון המשאבים הציבוריים של הארגון, ובכך מפריד אותם מהרשת הפנימית.
  • 3.3.A.2 חלוקה לסבנטים (Subnetting) יכולה לשמש ליצירת סבנטים שונים על בסיס כתובות IP. אם מכשיר מושפג על ידי התוקף, הסבנטים יכולים לכבוש את ההפרה ולצמצם את מספר המכשירים החשופים.
  • 3.3.A.3 סוויצים יכולים לשמש ליצירת VLANs, המפרידים לוגית מכשירים מחוברים פיזית לסוויצים מרכזיים.

מטרות למידה 3.3.B: הסבר מדוע חלוקת רשת לקטעים יכולה להגביר את הביטחון ברשת.

  • 3.3.B.1 חלוקת רשת לקטעים מתייחסת לתהליך חלוקת רשת לקטעים קטנים יותר ומבודדים או לתת-רשתות (subnets).
  • 3.3.B.2 חלוקת רשת לתת-רשתות קטנות יותר מבודדת תנועת רשת, מה שעלול למנוע תקיפות בסבנט אחד מלהשפיע על מכשירים בסבנטים אחרים.
  • 3.3.B.3 חלוקת רשת לקטעים מאפשרת היישום של מדיניות אבטחה ושליטה שונות על קטעים שונים ברשת, כך ניתן ליצור אזורי אבטחה גבוהים ואזורי אבטחה נמוכים.
  • 3.3.B.4 ביטחון יציאה בסוויץ' יכול למנוע MAC flooding על ידי הגבלת מספר הכתובות הניתנות ליישוב לכל יציאת סוויץ' בודדת.

Source: College Board AP Course and Exam Description · ⁨מקור: תיאור הקורס והמבחן של College Board AP⁩

English

Network segmentation 网络分段 divides one network into smaller, isolated pieces (subnets 子网). If one subnet is breached, the damage is contained and cannot spread.

A key pattern is the screened subnet 屏蔽子网 (also called a DMZ 隔离区). It sits between the public internet and the private internal network, holding an organisation's public-facing servers in a lower-security zone - separated from the sensitive internal systems.

Segments can also be built with subnetting (by IP address) or VLANs 虚拟局域网 (logically separating devices on the same switch). Each segment can then get its own security policy - higher-security and lower-security zones.

עברית

ניתוק רשתות מחלק רשת אחת לחלקים קטנים יותר, מבודדים (תת-רשתות). אם תת-רשת נפרצה, הנזק מוגבל ולא יכול להתפשט.

דפוס מרכזי הוא תת-רשת מוגנת (שנקראת גם DMZ). היא נמצאת בין האינטרנט הציבורי לרשת הפנימית הפרטית, ומכילה את השרתים המיועדים לציבור של הארגון באזור בטחון נמוך יותר - מבודד מהמערכות הפנימיות הרגישות.

סובנט עם מסך (DMZ) מציב שרתים ציבוריים בין שני חומות אש, הרחק מהרשת הפרטית
רשת תת-מסוננת (DMZ) מניחה שרתים ציבוריים בין שתי מצפנים, הרחוק מהרשת הפרטית

ניתן לבנות חלוקות גם באמצעות חלוקת רשת תת-מסוננת (על בסיס כתובת IP) או VLANs (הפרדה לוגית של התקנים על אותו מתג). כל חלוקה יכולה לקבל מדיניות אבטחה משלה - אזורים עם ביטחון גבוה ואזורים עם ביטחון נמוך.

מארזי שרתים: חלוקת רשת מבודדת מערכים כך שפרצת אבטחה אחת לא פותחת את הכל *מארזי שרתים: חלוקת רשת מבודדת מערכים כך שפרצת אבטחה אחת לא פותחת את הכל

Vocabulary · ⁨מילון מונחים⁩ Train · ⁨אימון⁩
English עברית
DMZ/ˌdiː em ˈzed/ אזור ביניים (DMZ)
VLANs/ˈviːlænz/ רשתות לוגיות (VLANs)
3.4

Protecting Networks: Firewalls · ⁨הגנה על רשתות: מצפנים⁩

Syllabus · ⁨סיילבוס⁩
English

Learning Objective 3.4.A: Identify types of network-based firewalls.

  • 3.4.A.1 A firewall is used to allow or deny network traffic in or out of a network. The firewall itself is software that can be hosted on a standalone device or integrated into another network device, such as a router.
  • 3.4.A.2 A stateless firewall filters traffic based on information in packet headers, such as IP addresses, ports, and protocols.
  • 3.4.A.3 A stateful firewall (also known as dynamic packet filtering) tracks the state of network connections passing through the firewall and can filter according to connection-related rules in addition to the filtering done by a stateless firewall. This allows for more control over content allowed in and out of a network.
  • 3.4.A.4 A next-generation firewall (NGFW) has both the capabilities of typical stateless and stateful firewalls and additional advanced features, such as intrusion prevention, deep packet inspection, and filtering by application type.

Learning Objective 3.4.B: Explain how a firewall uses an access control list to allow or deny traffic entering or leaving a network.

  • 3.4.B.1 Network administrators create a set of rules, called an access control list (ACL), that a firewall uses to permit or deny inbound and outbound network traffic.
  • 3.4.B.2 ACL rules are checked in order and the first rule that matches the criteria will be executed for the specified data.
  • 3.4.B.3 A typical ACL will specify the direction of traffic (inbound or outbound), the criterion to filter by (IP addresses, logical port, service, or application), and the action to take (permit or deny).

Learning Objective 3.4.C: Determine the effective placement of firewalls in a network.

  • 3.4.C.1 Each segment of a network should have a firewall to control the flow of data in and out of that segment.
  • 3.4.C.2 Network segments may have different security needs based on the data and services within them. The level of security for each firewall can be set independently.
  • 3.4.C.3 Each point of data ingress and egress between the internal network and the public internet should have a firewall.

Learning Objective 3.4.D: Configure a firewall to manage the flow of network traffic.

  • 3.4.D.1 The requirements for a firewall will specify what type of traffic from which sources or to which destinations should be allowed or denied.
  • 3.4.D.2 Specific rules for a firewall can allow or deny inbound or outbound traffic based on source or destination port or IP address, service, protocol, or application.
    • Illustrative examples for 3.4.D.2:
      • Allow inbound TCP port 22 from ALL; (this rule will allow all inbound TCP traffic with destination port 22, which is the designated port for the SSH protocol)
      • Deny inbound TCP port 80 from 192.168.1.0/24; (this rule will deny inbound TCP traffic with destination port 80 from IP addresses in the 192.168.1.0-192.168.1.255 range)
  • 3.4.D.3 Rules are implemented in order, and changing the order of a set of rules can change which traffic is allowed or denied. Consideration must be given to the precedence of filtering priorities when establishing the order of rules.
    • Illustrative examples for 3.4.D.3:
      • This set of rules would allow SSH traffic and deny other inbound TCP traffic
      • Rule 1: ALLOW inbound TCP port 22 from ALL;
      • Rule 2: DENY inbound TCP ALL from ALL;
      • Reversing the order of those rules would deny all inbound TCP traffic including SSH traffic.
עברית

מטרות למידה 3.4.A: זיהוי סוגי חומות מגן מבוססות רשת.

  • 3.4.A.1 חומת מגן משמשת לאישור או לדחיית תנועת רשת הנכנסת או היוצאת מרשת. חומת המגן עצמה היא תוכנה שתוכל להיות מארחת על מכשיר עצמאי או משולבת בתוך מכשיר רשת אחר, כגון נתב.
  • 3.4.A.2 חומת מגן ללא מצב (stateless firewall) מסננת תנועה על בסיס מידע בשלופי החבילה, כגון כתובות IP, יציאות ופרוטוקולים.
  • 3.4.A.3 חומת אש מדידה (הידועה גם כסינון חבילות דינמי) מעקבת אחרי מצב החיבורים הרשת עוברים דרכה ויכולה לסנן לפי כללים הקשורים לחיבור, בנוסף לסינון הנעשה על ידי חומת אש ללא מצבה. הדבר מאפשר שליטה רבה יותר על התוכן המותר נכנס ויוצא מהרשת.
  • 3.4.A.4 חומת אש מדור חדש (NGFW) כוללת את יכולותיהן של חומות אש ללא מצב ולמצב רגילות, בנוסף לתכונות מתקדמות נוספות, כמו מניעת פלישות, בדיקת עמוקה של חבילות וסינון לפי סוג יישום.

מטרות למידה 3.4.B: הסבר כיצד חומת אש משתמשת ברשימת בקרת גישה כדי לאפשר או לסרב תנועה הנכנסת או יוצאת מרשתה.

  • 3.4.B.1 מנהלי רשתות יוצרים סט של כללים, הנקרא רשימת בקרת גישה (ACL), שחומת האש משתמשת בו כדי לאפשר או לסרב תנועת רשת נכנסת ויוצאת.
  • 3.4.B.2 כללי ה-ACL נבדקים בסדר, והכלל הראשון התואם לקריטריונים יושרת עבור הנתונים המסופקים.
  • 3.4.B.3 כלל ACL רגיל יפרט את כיוון התנועה (נכנסת או יוצאת), הקריטריון לסנון לפיו (כתובות IP, יציאה לוגית, שירות או יישום), והפעולה לבצע (אישור או סירוב).

מטרות למידה 3.4.C: קביעת המקום היעיל לחומות אש ברשת.

  • 3.4.C.1 לכל מקטע ברשת צריכה להיות חומת אש כדי לשלוט בזרימת הנתונים לתוך זה ובחוץ ממנו.
  • 3.4.C.2 מקטעי רשת עשויים להצריך רמות אבטחה שונות בהתבסס על הנתונים והשירותים הפועלים בתוכם. רמת האבטחה לכל חומת אש ניתן לקבוע באופן עצמאי.
  • 3.4.C.3 לכל נקודת כניסה ויציאת נתונים בין הרשת הפנימית לאינטרנט הציבורי צריכה להיות חומת אש.

מטרות למידה 3.4.D: הגדרת חומת אש כדי לנהל את זרימת התנועה ברשת.

  • 3.4.D.1 הדרישות לחומת האש יפרטו איזה סוג של תנועה מאיזו מקור או ליעד כלשהו צריך להיות מותר או מוסרב.
  • 3.4.D.2 כללים ספציפיים לחומת האש יכולים לאפשר או לסרב תנועה נכנסת או יוצאת בהתבסס על יציאה או כתובת IP של מקור, שירות, פרוטוקול או יישום.
    • דוגמאות מסבריות ל-3.4.D.2:
      • האישור תנועה נכנסת TCP יציאה 22 מכל; (כלל זה יאפשר את כל תנועת ה-TCP הנכנסת עם יציאת יעד 22, שהיא היציאה המיועדת לפרוטוקול SSH)
      • הסרת תנועה נכנסת TCP יציאה 80 מ-192.168.1.0/24; (כלל זה יסיר תנועת TCP נכנסת עם יציאת יעד 80 מכתובות IP בטווח 192.168.1.0 עד 192.168.1.255)
  • 3.4.D.3 כללים מיושמים בסדר, ושליפה בסדר של קבוצת כללים יכולה לשנות את התנועה המותרת או המוסרבת. יש לקחת בחשבון את עדיפויות הסנון בעת קביעת סדר הכללים.
    • דוגמאות מסבריות ל-3.4.D.3:
      • קבוצה זו של כללים תאפשר תנועת SSH ותסיר שאר תנועות TCP נכנסות
      • כלל 1: אישור תנועה נכנסת TCP יציאה 22 מכל;
      • כלל 2: הסרת תנועה נכנסת TCP מכל מכל;
      • הפיכת סדר הכללים האלה תסיר גישה לכל תנועת TCP נכנסת, כולל תנועת SSH.

Source: College Board AP Course and Exam Description · ⁨מקור: תיאור הקורס והמבחן של College Board AP⁩

English
How a firewall decides

A firewall 防火墙 allows or denies traffic entering or leaving a network. There are several kinds:

  • Stateless 无状态 - filters on packet headers alone (IP, port, protocol).
  • Stateful 有状态 - also tracks the state of each connection for finer control.
  • Next-generation (NGFW) - adds advanced features like intrusion prevention and deep packet inspection.

A firewall follows an access control list (ACL) 访问控制列表 - an ordered set of rules. Rules are checked in order, and the first match wins, so the order of rules changes which traffic gets through. Each rule specifies a direction, a thing to filter by (IP, port, service), and an action (permit or deny).

Worked example. A firewall has Rule 3: DENY TCP 443 from 192.168.*, and lower down Rule 7: ALLOW TCP 443 from ALL. A user at 192.168.45.37 cannot reach port 443 - even though Rule 7 would allow them - because Rule 3 matches first, and the first match wins. The fix is to move the ALLOW rule above the DENY. This is why rule order, not just rule content, decides what traffic gets through.

Firewalls belong at every point where data crosses between zones - at each network segment and at every gateway to the public internet.

עברית

*איך מצפן מקבל החלטות

מצפן מאפשר או דוחה תנועה הנכנסת או יוצאת מרשת. קיימים סוגים שונים:

  • ללא מצב - מסנן לפי כותרות החבילה בלבד (IP, יציאה, פרוטוקול).
  • עם מצב - עוקבת גם אחר המצב של כל חיבור לשליטה מדויקת יותר.
  • דור חדש (NGFW) - מוסיף תכונות מתקדמות כמו מניעת תקיפות וסקירת חבילות מעמיקה.

מצפן פועל לפי רשימת בקרת גישה (ACL) - סדרה מסודרת של כללים. כללים נבדקים בסדר, וההתאמה הראשונה היא הקובעת, ולכן סדר הכללים משנה איזה תנועה תעבור. כל כלל מפרט כיוון, קריטריון לסננון (IP, יציאה, שירות), ופעולה (התרצה או איסור).

חומת אש בודקת את רשימת ההגדרות שלה מלמעלה למטה; הכלל הראשון המתאים הוא הקובע *מצפן בודק את ה-ACL שלו מלמעלה למטה; הכלל המתאים הראשון הוא הקובע

דוגמה מפורטת. למצפן יש הכלל 3: DENY TCP 443 from 192.168.*, ומטה יותר הכלל 7: ALLOW TCP 443 from ALL. משתמש ב192.168.45.37 אינו מגיע ליציאה 443 - גם אם הכלל 7 היה אמור להרשות לו - כי הכלל 3 מתאים קודם, וההתאמה הראשונה היא הקובעת. הפתרון הוא להעביר את הכלל ALLOW מעל ה-DENY. זוהי הסיבה לכך שמסדר הכללים, ולא רק תוכן הכללים, קובע איזה תנועה תעבור.

מצפנים צריכים להיות בכל נקודה שבה נתונים חוצים בין אזורי אבטחה - בכל חלוקת רשת ובכל שערי הגישה לאינטרנט הציבורי.

מתגי רשת מותקנים בארון עם מגוון כבלי אתרנט *ציוד רשת אמיתי: מצפן הוא מכשיר (או תוכנה) הממוקם במקום שבו כבלים אלו נפגשים עם העולם החיצוני

Vocabulary · ⁨מילון מונחים⁩ Train · ⁨אימון⁩
English עברית
ARP poisoning/ɑːp ˈpɔɪzənɪŋ/ התעללות ARP
address resolution protocol (ARP)/əˈdres ˌrezəˈluːʃn ˈprəʊtəkɒl/ פרוטוקול פתרון כתובות (ARP)
MAC addresses/mæk əˈdresɪz/ כתובות MAC
on-path attack/ɒn pæθ əˈtæk/ תקיפה מסלולית (On-path attack)
MAC flooding/mæk ˈflʌdɪŋ/ שיפוש MAC
switch/swɪtʃ/ מתג
eavesdropping/ˈiːvzdrɒpɪŋ/ הקשבה
DNS poisoning/ˌdiː en ˈes ˈpɔɪzənɪŋ/ התעללות DNS
domain name system (DNS)/dəˈmeɪn neɪm ˈsɪstəm/ מערכת שם התחום (DNS)
credential harvesting/krɪˈdenʃl ˈhɑːvɪstɪŋ/ איסוף נתוני הזדהות (credential harvesting)
denial of service (DoS)/dɪˈnaɪəl ɒv ˈsɜːvɪs/ מניעת שירות (DoS)
distributed denial of service (DDoS)/ˈdɪstrɪbjuːtɪd dɪˈnaɪəl ɒv ˈsɜːvɪs/ תקיפת סירוב לשירות מפוזרת (DDoS)
rogue access point/rəʊɡ ˈækses pɔɪnt/ נקודת גישה זדונית
automated vulnerability scanner/ˈɔːtəmeɪtɪd ˌvʌlnərəˈbɪlɪti ˈskænə/ סורק תשתיות אוטומטי
mitigation/ˌmɪtɪˈɡeɪʃn/ צמצום
split tunneling/splɪt ˈtʌnəlɪŋ/ חיבור טונל מפורק (Split tunneling)
firewall/ˈfaɪəwɔːl/ חומת אש
Stateless/ˈsteɪtləs/ ללא מצב
Stateful/ˈsteɪtfl/ עם מצב
access control list (ACL)/ˈækses kənˈtrəʊl lɪst/ רשימת בקרת גישה (ACL)
log files/lɒɡ faɪlz/ קובצי יומן
network intrusion detection system (NIDS)/ˈnetwɜːk ɪnˈtruːʒn dɪˈtekʃn ˈsɪstəm/ מערכת זיהוי התפרצויות רשת (NIDS)
network intrusion prevention system (NIPS)/ˈnetwɜːk ɪnˈtruːʒn prɪˈvenʃn ˈsɪstəm/ מערכת מניעת התפרצויות רשת (NIPS)
security information and event management (SIEM)/sɪˈkjʊərɪti ˌɪnfəˈmeɪʃn ænd ɪˈvent ˈmænɪdʒmənt/ ניהול מידע ואירועי אבטחה (SIEM)
Signature-based/ˈsɪɡnɪtʃə beɪst/ מבוסס חתימות
Anomaly-based/əˈnɒməli beɪst/ מבוסס חריגות
baseline/ˈbeɪslaɪn/ בסיס
network-based indicators of compromise/ˈnetwɜːk beɪst ˈɪndɪkeɪtəz ɒv ˈkɒmprəmaɪz/ אינדיקטורים מבוססי רשת להתפרצויות
probabilistic/ˌprɒbəbɪˈlɪstɪk/ פרובליסטי
threshold/ˈθreʃəʊld/ סף
alert fatigue/əˈlɜːt fəˈtiːɡ/ דיוש התראות
3.5

Detecting Network Attacks · ⁨זיהוי התקפות ברשת⁩

Syllabus · ⁨סיילבוס⁩
English

Learning Objective 3.5.A: Identify types of automated security tools used to detect network attacks.

  • 3.5.A.1 Automated detection tools analyze data collected from an organization’s network and devices, such as switches and routers, servers, firewalls, and user computers. These data are often collected in a log file.
  • 3.5.A.2 A network intrusion detection system (NIDS) is an automated tool that analyzes data to determine if malicious activity is taking place on a network. When an attack is detected, it generates an alert.
  • 3.5.A.3 A network intrusion prevention system (NIPS) is an automated tool that, like an IDS, analyzes data to determine if malicious activity is taking place on a network. A NIPS can also mitigate or halt an attack by closing ports, blocking specific IP or MAC addresses, or rejecting specific protocols.
  • 3.5.A.4 A security information and event management (SIEM) system collects and analyzes data from multiple sources (including firewalls, NIDS/NIPS, device logs, and application logs) to detect patterns that may indicate a cyberattack and raises an alert if a potential attack is detected. Security analysts investigate the alert to determine whether it represents a true threat and follow standard operating procedures to resolve or escalate the alert.

Learning Objective 3.5.B: Explain how organizations can leverage artificial intelligence (AI) to enhance threat detection and response.

  • 3.5.B.1 Computers log every action that users take. Firewalls, IDS, IPS, and other network sensors log all the traffic passing through various points in a network. A medium-sized organization’s network is logging millions (or even tens of millions) of data points per day. Even a large team of humans is incapable of analyzing so much data.
  • 3.5.B.2 Threat detection teams are creating AI algorithms to analyze large amounts of data and classify the data patterns as malicious or normal.
  • 3.5.B.3 AI models for threat detection are based on probabilistic calculations; they report a percentage to indicate the likelihood that something is malicious.
  • 3.5.B.4 Organizations determine their own thresholds for what percentage of likelihood of a threat results in an alert. If the threshold is set too high, real attacks may go undetected; if the threshold is too low, the security team will be overwhelmed with false alerts.

Learning Objective 3.5.C: Determine a network detection method.

  • 3.5.C.1 Volume of network traffic is a criterion for determining a detection method. Signature-based detection is more efficient for networks with high traffic volume. Signature-based detection compares detection data to a database of known indicators of compromise (IoCs), called signatures. Signature databases must be updated with IoCs for the latest attacks. Signature-based detection runs more quickly than anomaly-based detection.
  • 3.5.C.2 Consistency of network traffic patterns is a criterion for determining a detection method. Anomaly-based detection is most effective on networks with consistent traffic patterns. Anomaly-based detection compares detection data to a baseline of recorded activity. Baselines must be recorded on uncompromised systems to establish expected data types and volumes. Anomaly-based detection triggers an alert or action when data types or volumes outside of a specified tolerance range are recorded. Anomaly-based detection relies on consistent patterns in network traffic to detect anomalous traffic patterns.
  • 3.5.C.3 Degree of sensitivity or criticality of a network is a criterion for determining a detection method. Networks with more sensitive or critical data or services will likely consider a hybrid approach. Hybrid detection combines signature-based and anomaly-based detection. Hybrid detection is more expensive than using either signature- or anomaly-based detection alone, and hybrid-detection models generate more alerts.
  • 3.5.C.4 Likelihood of novel attacks on a network is a criterion for determining a detection method. Signature-based detection cannot detect a new attack. When an organization suspects that adversaries are likely to attempt a new attack on a network, anomaly-based detection is the preferred method when the cost of hybrid detection is prohibitively high.

Learning Objective 3.5.D: Evaluate the impact of a network detection method.

  • 3.5.D.1 Speed of detection is a factor in evaluating the impact of a network detection method. Faster detection enables faster response. Signature-based detection methods are faster than anomaly-based detection methods, especially on networks with high traffic volume.
  • 3.5.D.2 Cost is a factor in evaluating the impact of a network detection method. Detection tools and ongoing costs need to be within a budget. Anomaly-based detection systems require more expensive hardware to operate than signature based. Hybrid detection is the most expensive option because it combines both anomaly- and signature-based methods.
  • 3.5.D.3 False positive rate is a factor in evaluating the impact of a network detection method. Signature-based detection has almost no false positives. Anomaly-based or hybrid detection will have higher false positive rates. Impacts of high false positive rates include:
    • Time and resources are put toward investigating alerts for nonmalicious activity.
    • Alert fatigue is a condition that occurs when responders get accustomed to false positives and take alerts less seriously because they assume alerts are false positives before investigating them.
  • 3.5.D.4 False negative rate is a factor in evaluating the impact of a network detection method. A false negative occurs when an adversary can bypass a detection system. Signature-based detection systems are easier to bypass than anomaly-based or hybrid systems. False negatives can result in adversaries causing loss, harm, disruption, or destruction to data and systems.

Learning Objective 3.5.E: Apply detection techniques to identify indicators of network attacks by analyzing log files.

  • 3.5.E.1 Evil-twin attacks can be detected by regularly scanning for service set identifiers (SSIDs) that look suspicious or similar to local legitimate SSIDs. Signal triangulation can be used to locate and disable an access point broadcasting an evil-twin network.
  • 3.5.E.2 Jamming attacks can be detected by recognizing that no wireless devices in a specific physical space are able to connect to a wireless network and by scanning for electromagnetic (EM) noise in the wireless range.
  • 3.5.E.3 ARP poisoning attacks can be detected by monitoring network traffic for unusual ARP messages (particularly duplicate MAC address ARP packets) and checking the ARP table on the default gateway.
  • 3.5.E.4 MAC flooding attacks can be detected by monitoring network traffic for an unexpected surge of Ethernet frames with different MAC addresses and checking the MAC address table on a switch.
  • 3.5.E.5 DNS poisoning attacks are difficult to detect. However, if an organization’s website experiences an abrupt and otherwise inexplicable drop in traffic, DNS records should be examined as a potential cause.
  • 3.5.E.6 Smurf attacks can be detected by watching network traffic for a sudden increase in ICMP requests sent to the network’s broadcast address.
  • 3.5.E.7 Network-based IoCs are discovered when analyzing network traffic, often in the form of packet capture files. Indicators can be found in source and destination IP addresses, ports, and protocols. These can include:
    • Connections to known malicious IP addresses
    • Unauthorized network scans
    • Unusual spikes or slow downs in network traffic
    • Mismatched port-application traffic
עברית

מטרת ההלימוד 3.5.A: לזהות סוגים של כלי אבטחה אוטומטיים המשמשים לזיהוי התקפות רשת.

  • 3.5.A.1 כלי זיהוי אוטומטיים מנתחים נתונים שנאספו מהרשת והמכשירים של הארגון, כגון מתגי רשת (switches) ונתבים (routers), שירותים, חומות אש ומחשבי משתמשים. נתונים אלו נאספים לעיתים קרובות בקובץ יומן (log file).
  • 3.5.A.2 מערכת זיהוי פריצות רשת (NIDS) היא כלי אוטומטי המנתח נתונים כדי לקבוע האם מתרחשת פעילות מזיקה ברשת. כאשר נזרקת התקפה, המערכת מייצרת איתור.
  • 3.5.A.3 מערכת מניעת פריצות רשת (NIPS) היא כלי אוטומטי שמדמה ל-IDS ומנתח נתונים כדי לקבוע האם מתרחשת פעילות מזיקה ברשת. NIPS יכול גם למנוע או להפסיק התקפה על ידי סגירת פורטים, חסימת כתובות IP או MAC ספציפיות, או דחיית פרוטוקולים מסוימים.
  • 3.5.A.4 מערכת ניהול מידע ואירועי אבטחה (SIEM) אוספת ומנתחת נתונים ממקורות מרובים (כולל חומות אש, NIDS/NIPS, יומני מכשירים ויומני אפליקציות) כדי לזהות דפוסים שעשויים להעיד על התקפת سایبر ולעורר איתור במקרה של גילוי התקנה אפשרית. אנליסטי אבטחה בודקים את האיתור כדי לקבוע האם הוא מייצג איום אמיתי ועוברים לפי הprotocols תקין כדי לפתור או להעלות את האיתור.

מטרת ההלימוד 3.5.B: להסביר כיצד ארגונים יכולים להיעזר באינטליגנציה מלאכותית (AI) לשיפור זיהוי איומים ותגובה אליהם.

  • 3.5.B.1 מחשבים מקלטים כל פעולה שמשתמשים מבצעים. חומות אש, IDS, IPS וחיישני רשת אחרים מקלטים את כל התנועה העוברת דרך נקודות שונות ברשת. ברשת של ארגון בגודל בינוני נאספים מיליונים (או אף עשרות מיליונים) נקודות נתונים ביום. גם צוות אנשים גדול אינו מסוגל לנתח כמות כזו של נתונים.
  • 3.5.B.2 צוותי זיהוי איומים יוצרים אלגוריתמי AI לניתוח כמות גדולה של נתונים ולסיווג דפוסי הנתונים כמזיקים או נורמליים.
  • 3.5.B.3 מודלי AI לזיהוי איומים מבוססים על חישובים פרובabilitistic; הם מדווחים אחוז כדי להצביע על הסיכון שהדבר הוא מזיק.
  • 3.5.B.4 ארגונים קובעים את הסף שלהם עבור אחוז הסיכון שגורם לאיתור. אם הסף גבוה מדי, התקפות אמיתיות עשויות להישאר בלתי מזוהות; אם הסף נמוך מדי, צוות האבטחה יהיה מוצף באיתורי שווא.

מטרת ההלימוד 3.5.C: לקבוע שיטת זיהוי רשת.

  • 3.5.C.1 נפח תנועת הרשת הוא קריטריון לקביעת שיטת זיהוי. זיהוי מבוסס סיגנונים (Signature-based) יעיל יותר ברשתות עם נפח תנועה גבוה. זיהוי מבוסס סיגנונים משווה נתוני זיהוי לבנק נתונים של אינדיקטורים ידועים לפגיעה (IoCs), המכונים סיגנונים. בנקי הסיגנונים צריכים להתעדכן עם IoCs עבור ההתקפות האחרונות. זיהוי מבוסס סיגנונים פועל מהר יותר מאשר זיהוי מבוסס אנומליה.
  • 3.5.C.2 יציבות דפוסים של תנועת הרשת היא קריטריון לקביעת שיטת זיהוי. זיהוי מבוסס אנומליה (Anomaly-based) יעיל ביותר ברשתות עם דפוסים תנועה יציבים. זיהוי מבוסס אנומליה משווה נתוני זיהוי לבסיס של פעילות מצולמת. בסיסים חייבים להיות מצולמים במערכות שאינן מופקות כדי לקבוע סוגי נתונים ונפחים צפויים. זיהוי מבוסס אנומליה מעורר איתור או פעולה כאשר נרשמים סוגי נתונים או נפחים מחוץ לטווח סטייה מוגדר.
  • 3.5.C.3 רמת הרגישות או הקריטיות של הרשת היא קריטריון לקביעת שיטת זיהוי. רשתות עם נתונים או שירותים רגישים או קריטיים יותר יכללו ככל הנראה גישה היברידית. זיהוי היברידי משלב זיהוי מבוסס סיגנונים וזיהוי מבוסס אנומליה. זיהוי היברידי יקר יותר משימוש בכל שיטה בנפרד, ומודלי זיהוי היברידיים מייצרים יותר איתורים.
  • 3.5.C.4 הסיכון להתקנות חדשות ברשת הוא קריטריון לקביעת שיטת זיהוי. זיהוי מבוסס סיגנונים אינו יכול לזהות התקנה חדשה. כאשר ארגון חושד שהתוקפים יסתמכו על ניסיון התקנה חדשה ברשת, זיהוי מבוסס אנומליה הוא השיטה המועדפת כאשר העלות של זיהוי היברידי היא גבוהה מדי.

מטרת ההלימוד 3.5.D: להעריך את השפעת שיטת זיהוי רשת.

  • 3.5.D.1 מהירות הזיהוי היא גורם בהערכת השפעת שיטת זיהוי רשת. זיהוי מהיר מאפשר תגובה מהירה. שיטות זיהוי מבוסס סיגנונים מהירות מאשר שיטות זיהוי מבוסס אנומליה, במיוחד ברשתות עם נפח תנועה גבוה.
  • 3.5.D.2 העלות היא גורם בהערכת השפעת שיטת זיהוי רשת. כלי זיהוי ועלויות מתמשכות צריכים להיות בתוך התקציב. מערכות זיהוי מבוסס אנומליה דורשות ציוד קשה יקר יותר לתפעול מאשר זיהוי מבוסס סיגנונים. זיהוי היברידי הוא האפשרות היקרה ביותר מכיוון שהוא משלב גם שיטות מבוסס אנומליה וגם מבוסס סיגנונים.
  • 3.5.D.3 שיעור חיובים שקריים הוא גורם בהערכת ההשפעה של שיטת זיהוי ברשת. זיהוי מבוסס חתימה (signature) כמעט ואינו מייצר חיובים שקריים. זיהוי מבוסס אנומליה או היברידי יכיל שיעורי חיובים שקריים גבוהים יותר. השפעות של שיעורי חיובים שקריים גבוהים כוללות:
    • זמן ומשאבים מושקעים בבדיקת התראות הקשורות לפעילות שאינה מזיקה.
    • עייפות התראה היא מצב שנוצר כאשר מטפלים מתרגלים לחיובים שקריים ופחות רגישים להתראות, משום שהם מניחים שהן שקריות לפני בדיקתן.
  • 3.5.D.4 שיעור שליליים שקריים הוא גורם בהערכת ההשפעה של שיטת זיהוי ברשת. שלילי שקרי מתרחש כאשר אדוורסרי יכול לעקוף מערכת זיהוי. מערכות זיהוי מבוסס חתימה קל יותר לעקוף מאשר מערכות מבוסס אנומליה או היברידיות. שליליים שקריים עלולים לגרום לאדוורסרים לגרום לנזק, הרס, הפרעה או הרסנתה של נתונים ומערכות.

מטרות למידה 3.5.E: יישום טכניקות זיהוי כדי לזהות אינדיקטורים לתקיפות ברשת באמצעות ניתוח קובצי יומן.

  • 3.5.E.1 תקיפות "אח תמך" (Evil-twin) ניתן לזהות על ידי סריקה שוטפת של מזהאי שירות (SSIDs) שנראים חשודים או דומים ל-SSIDs מקומיים חוקיים. טריאנגולציה של אותות יכולה לשמש למיקום וכיבוי נקודת גישה המשידרת רשת "אח תמך".
  • 3.5.E.2 תקיפות הפרעה (Jamming) ניתן לזהות על ידי הבחנה שאין מכשירים אלחוטיים במרחב פיזי מסוים יכולים להתחבר לרשת אלחוטית, ועל ידי סריקה לנוכחות רעש אלקטרומגנטי (EM) בטווח האלחוטי.
  • 3.5.E.3 תקיפות רעל ARP ניתן לזהות על ידי ניטור תנועת רשת להודעות ARP חריגות (במיוחד חבילות ARP עם כתובות MAC כפולות) ובדיקת טבלת ה-ARP בגייטווי הרצף.
  • 3.5.E.4 תקיפות הצפה MAC (MAC flooding) ניתן לזהות על ידי ניטור תנועת רשת לעלייה בלתי צפונית במסגרות אתרנט עם כתובות MAC שונות ובדיקת טבלת כתובות ה-MAC במתג (switch).
  • 3.5.E.5 תקיפות רעל DNS קשות לזיהוי. עם זאת, אם אתר האינטרנט של ארגון חווה ירידה פתאומית ובבלתי מוסברת בתנועת הגולשים, יש לבדוק את רשומות ה-DNS כגורם אפשרי.
  • 3.5.E.6 תקיפות Smurf ניתן לזהות על ידי צפייה בתנועת רשת לעלייה פתאומית בבקשות ICMP שנשלחות לכתובת השידור (broadcast) של הרשת.
  • 3.5.E.7 אינדיקטורים מבוססי רשת (IoCs) נמצאים בעת ניתוח תנועת רשת, לעיתים קרובות בצורת קובצי לכידת חבילות. אינדיקטורים יכולים להופיע בכתובות IP מקור ויעד, פורטים ופרוטוקולים. הם יכולים לכלול:
    • חיבורים לכתובות IP מזוהות כמזוהמות
    • סריקות רשת לא מורשות
    • עלייה או ירידה חריגות בתנועת רשת
    • תנועת פורט-יישום שאינה תואמת

Source: College Board AP Course and Exam Description · ⁨מקור: תיאור הקורס והמבחן של College Board AP⁩

English

When prevention fails, detection takes over. Automated tools read the log files 日志文件 that record network activity:

  • a network intrusion detection system (NIDS) 网络入侵检测系统 analyses traffic and raises an alert, but does not block;
  • a network intrusion prevention system (NIPS) 网络入侵防御系统 can also stop an attack by closing ports or blocking addresses;
  • a security information and event management (SIEM) 安全信息与事件管理 system gathers data from many sources to spot patterns.

There are two detection methods. Signature-based 基于特征 detection compares traffic to a database of known attack signatures - fast and low on false alarms, but blind to brand-new attacks. Anomaly-based 基于异常 detection compares traffic to a normal baseline 基线 and flags anything unusual - it can catch novel attacks but needs more resources and raises more false alarms. A hybrid approach combines both.

Examining captured traffic (packet-capture files), analysts hunt for network-based indicators of compromise 网络入侵指标 in the source and destination IP addresses, ports, and protocols. Four common ones: connections to known-malicious IP addresses, unauthorized network scans (an outsider probing your ports), unusual spikes or slowdowns in traffic, and mismatched port-application traffic (for example, non-web traffic flowing over port 80). These complete the host-, file-, and behaviour-based indicators a single device logs.

AI, thresholds, and alert fatigue

A medium network logs millions of events a day - far more than any team can read - so organisations train AI models to sort likely-malicious patterns from normal ones. These models are probabilistic 概率的: rather than a yes/no, each event gets a percentage likelihood of being malicious.

The organisation then sets a threshold 阈值 - the likelihood at which an alert fires - and that choice is a genuine trade-off:

  • set the threshold too high and real attacks slip through undetected;
  • set it too low and the team is overwhelmed with false alerts.

Too many false alerts cause alert fatigue 警报疲劳: responders get so used to false positives that they start assuming an alert is false before investigating it - so a real attack, when it finally comes, is waved away. This is exactly why a low false-positive rate matters: signature-based detection has almost none, while anomaly-based and hybrid detection trade a higher false-positive rate for the ability to catch novel attacks.

עברית

כשמניעה נכשלת, זיהוי לוקח את הפיקוד. כלים אוטומטיים קוראים את קובצי הלוג שמקליטים פעילות ברשת:

  • מערכת זיהוי התקנות רשת (NIDS) מנתחת תנועה ומפעילה התראה, אך אינה חוסמת;
  • מערכת מניעת התקנות רשת (NIPS) יכולה גם כן לעצור התקפה על ידי סגירת יציאות או חסימת כתובות;
  • מערכת ניהול מידע ואירועי אבטחה (SIEM) אוספת נתונים ממקורות מרובים כדי לזהות דפוסים.

ישנן שתי שיטות זיהוי. זיהוי מבוסס סימנים משווה תנועה לבסיס נתונים של סימנים של התקנות ידועות - מהירה ופחות התרעות שווא, אך עיוורת להתקנות חדשות לחלוטין. זיהוי מבוסס חריגות משווה תנועה לבסיס תקין ומסמן כל חריגה - הוא יכול לתפוס התקנות חדשות אך דורש משאבים רבים יותר וגורם להרבה יותר התראות שווא. גישה מעורבת משלבת את שניהם.

בעת בדיקת תנועה שנלקחה (קבצי פלט-לכידה), אנליסטים מחפשים מדדי חשיפה מבוססי רשת בכתובות IP מקור ויעד, יציאות ופרוטוקולים. ארבעה מדדים נפוצים: חיבורים לכתובות IP מזיקות ידועות, סריקות רשת לא מורשות (מישהו מחוץ לרשת שחוקר את היציאות שלך), פיצוצים או האטות חריגות בתנועה, ותנועה יציאה-יישום לא תואמת (למשל, תנועה שאינה דפדפנית העוברת דרך יציאה 80). אלו משלים את המדדים המבוססי מארח, קובץ והתנהגות שמכשיר יחיד מקליט.

בינה מלאכותית, ספים והתייזות התראות

ברשת בינונית נלכדים מיליונים של אירועים ביום - הרבה יותר ממה שכל צוות יכול לקרוא - ולכן ארגונים מאמנים דגמי בינה מלאכותית לסנן דפוסים סבירים להונאה מתוך תקינים. דגמים אלו הם פרובאבליסטיים: במקום כן/לא, לכל אירוע מיועד אחוז סבירות להיות מזיק.

לאחר מכן הארגון קובע סף - הסבירות שבה ההתרה נשלחת - ובחירה זו היא תמורה אמיתית:

  • אם הסף גבוה מדי, התקנות אמיתיות נשמרות בלתי מודעות;
  • אם הסף נמוך מדי, הצוות מוטבח בהתראות שווא.

הרבה מדי התראות שווא גורמות להתייזות התראות: המגיבים הופכים כל כך למרגילים לפוזיטיבים שווא עד שהם מתחילים להניח שהתרה היא שווא לפני שחוקרים אותה - ולכן, כשהתקפה אמיתית מגיעה בסוף, היא נדחית. זה בדיוק הסיבה ששיעור פוזיטיבים שווא נמוך חשוב: זיהוי מבוסס סימנים כמעט אין לו, בעוד שזיהוי מבוסס חריגות ומעורב מתחלפים שיעור פוזיטיבים שווא גבוה יותר תמורת יכולת לתפוס התקנות חדשות.

זיהוי מבוסס סימנים תואם התקנות ידועות; זיהוי מבוסס חריגות מסמן סטיות מתקין
זיהוי מבוסס סימנים תואם התקנות ידועות; זיהוי מבוסס חריגות מסמן סטיות מתקין
3.5

Exam tips · ⁨טיפים לבחינות⁩

English
  • For firewall-ACL questions, read the rules top-to-bottom and stop at the first match - a Deny rule above an Allow blocks the traffic even though the Allow exists lower down.
  • Pair each attack with its tell-tale sign: ARP poisoning = one IP with two MAC addresses; MAC flooding = a surge of new MAC addresses; DNS poisoning = an unexplained drop in web traffic.
  • Read packet captures for network-based IoCs: known-malicious IPs, unauthorized scans, traffic spikes/slowdowns, and mismatched port-application traffic.
  • Run vulnerability scanners to find known weaknesses proactively, and fix the highest-severity findings first.
  • Signature-based = fast, few false positives, misses new attacks (more false negatives); anomaly-based = catches new attacks, costs more, more false positives. Memorise this trade-off.
  • A screened subnet / DMZ holds public-facing servers between the internet and the private network - name it whenever a question separates public services from internal data.
  • WPA3 is the strong wireless encryption; WEP and original WPA are insecure.
עברית
  • בשאלות אודות ACLs של פיראוול, קראו את הכללים מלמעלה למטה ועצרו בהתאמה הראשונה - כלל Deny (איסור) למעלה מכלל Allow (אישור) חוסם את התנועה גם אם קיים Allw (אישור) במיקום נמוך יותר.
  • שויו כל התקנה עם הסימן המאפיין שלה: הונאת ARP = כתובת IP אחת עם שני MACs; הצפת MAC = גל של כתובות MAC חדשות; הונאת DNS = ירידה בלתי מוסברת בתנועת אתרים.
  • קראו פלט-לכידות למציאת IoCs מבוססי רשת: כתובות IP מזיקות ידועות, סריקות לא מורשות, פיצוצים/האטות בתנועה, ותנועה יציאה-יישום לא תואמת.
  • הפעילו סורקי נקודות תורפה כדי למצוא חולשות ידועות באופן proactively, ותיקנו את הממצאים בעלי חומרה הגבוהה ביותר תחילה.
  • מבוסס סימנים = מהיר, פוזיטיבים שווא מעטים, מפספס התקנות חדשות (יותר פוזיטיבים שווא); מבוסס חריגות = תופס התקנות חדשות, עולה יותר, יותר פוזיטיבים שווא. שימו לב לתמורה זו.
  • DMZ / רשת תת-מבודדת מכילה שרתים המוצגים לציבור בין האינטרנט לרשת הפרטית - הזכירו זאת בכל שאלה המבדילה בין שירותים ציבוריים למידע פנימי.
  • WPA3 היא ההצפנה אלחוטית החזקה; WEP ו-WPA המקורי הם לא בטוחים.

Interactive lessons on this topic · ⁨שיעורים אינטראקטיביים בנושא זה⁩

Work through it step by step, with instant-check exercises. · ⁨לעבור על הדברים צעד אחר צעד, עם תרגילים לבדיקה מיידית.⁩

Past Papers · ⁨מבחני עבר⁩

More topics in AP Cybersecurity · ⁨אבטחת מידע והסייבר - AP⁩ · ⁨נושאים נוספים בAP Cybersecurity · ⁨אבטחת מידע והסייבר - AP⁩⁩

Log in or create account · ⁨היכנס או צור חשבון⁩

IGCSE, A-Level & AP