Skip to content · ⁨コンテンツへスキップ⁩

Securing Networks · ⁨ネットワークの保護⁩

AP Cybersecurity · ⁨AP サイバーセキュリティ⁩ · Topic 3 · ⁨トピック 3⁩

View Slides · ⁨查看幻灯片⁩ Train · ⁨練習する⁩
Video lesson for this topic · ⁨このトピックのビデオレッスン⁩ Open the video page · ⁨動画ページを開く⁩
9:26

ネットワークの保護

あなたは銀行にメッセージを送信します。それは到着し、返信が戻ってきます。すべてが正常に見えます。しかし、あなたと银行の間に静かに座っている人がいて、すべてのメッセージを読んでいます…

English narration · English + 中文 subtitles burned in · ⁨英語ナレーション・英語+中文字幕 burning-in⁩

3.1

Network Vulnerabilities and Attacks · ⁨ネットワークの脆弱性と攻撃⁩

Syllabus · ⁨シラバス⁩
English

Learning Objective 3.1.A: Identify common network attacks.

  • 3.1.A.1 The address resolution protocol (ARP) is used by a default gateway on a network to establish a table that pairs internet protocol (IP) addresses with media access control (MAC) addresses. An ARP poisoning attack is when an adversary sends falsified ARP packets to the default gateway to modify the table so that the adversary’s device receives traffic intended for the target by linking the target’s IP address to the adversary’s MAC address. Faking a MAC address is called MAC spoofing. This is an example of an on-path attack (or man-in-the-middle attack), which is when an adversary interrupts a data stream between two parties, captures both parties’ data, and copies or alters the data before sending them on. Both parties think they are communicating directly with each other, but instead they are each communicating with the adversary who is secretly intercepting their messages.
  • 3.1.A.2 A MAC flooding attack is when an adversary sends the target switch many Ethernet frames, each with a different MAC address. This can force the switch into broadcast mode, and the adversary can then collect all of the frames on the network (because they are being broadcast), which could allow the adversary to access sensitive information. This is an example of eavesdropping (or sniffing), which is when an adversary captures data in transit and can record and copy the data.
  • 3.1.A.3 A domain name system (DNS) poisoning attack is when an adversary pretends to be an authoritative name server (NS) and plants a fake DNS record on a DNS server to redirect browser traffic to a malicious website designed to steal credentials. This is an example of credential harvesting, which is when adversaries set up a fake login site that looks like a real one. Unsuspecting users enter their real credentials, which the adversaries capture and use.
  • 3.1.A.4 A smurf attack attempts to overwhelm a network with Internet Control Message Protocol (ICMP) requests. It is a type of denial of service (DoS) attack, which makes a system or resource unavailable to authorized users. During a smurf attack, an adversary sends many ICMP requests with the victim’s address to the network’s broadcast address. The network’s gateway then sends these requests to all devices on the network. Each device on the network replies to the victim’s address, creating a flood of traffic that can block legitimate messages. When multiple devices attack the same target simultaneously, it’s called a distributed denial of service (DDoS) attack.

Learning Objective 3.1.B: Explain how adversaries can exploit network vulnerabilities to steal, disrupt, or destroy network communication.

  • 3.1.B.1 Adversaries can send malicious traffic into a network to flood it creating a DoS, to map the internal structure of the network, or to spoof a legitimate device. Networks without firewalls, or with improperly configured firewalls, are vulnerable to these types of attacks.
  • 3.1.B.2 Adversaries that have compromised a device often attempt to leverage their access to compromise other devices on the local area network (LAN).
  • 3.1.B.3 Adversaries that physically plug into a data port can gain access to a LAN through the switch port unless port security is enabled. This allows adversaries to launch DoS attacks or perform MAC flooding or MAC spoofing attacks.
  • 3.1.B.4 Adversaries standing outside of physically secure spaces can pick up the signals and beacon frames from a wireless access point that is broadcasting outside the physical space. This allows them to gather information about the wireless network and to attempt eavesdropping and cryptographic attacks on it.
  • 3.1.B.5 Adversaries can attempt to join networks to launch attacks from within the networks. Networks that do not authenticate devices and users make it easier for adversaries to join.
  • 3.1.B.6 If there is an open network port, an adversary can plug a wireless access point into the port creating a rogue access point. The adversary could use this rogue access point to access the internal network wirelessly (maybe even from outside the physical space). This allows the adversary direct access to the LAN, bypassing any firewalls.
  • 3.1.B.7 Adversaries can attempt to break wireless encryption and intercept, steal, or compromise data on a network.

Learning Objective 3.1.C: Assess and document risks from network vulnerabilities.

  • 3.1.C.1 Vulnerabilities on a network can lead to adversaries being able to intercept and alter data in transit, launch DoS attacks, or move laterally on a network to gain access to more sensitive or critical systems. Network vulnerabilities can constitute a risk to confidentiality, integrity, and availability.
  • 3.1.C.2 There are automated vulnerability scanners that can check networks, devices, and applications for known vulnerabilities. These scanners produce a report that often includes the vulnerabilities detected, their severity, and mitigation recommendations.
  • 3.1.C.3 Successfully exploiting a network vulnerability often requires advanced technical ability and knowledge. This can impact the likelihood of an exploit.
  • 3.1.C.4 High risks from network vulnerabilities allow an adversary to easily have a significant impact by capturing network traffic, spoofing a legitimate device on the network, or launching a DoS attack.
    • Illustrative examples for 3.1.C.4:
      • An organization has a single unsegmented internal network that is accessible via a wireless network with weak encryption, and on that network it has a server running its proprietary web-application.
  • 3.1.C.5 Moderate risks from network vulnerabilities could include vulnerabilities that might give adversaries the ability to gain information about systems or devices on a network.
    • Illustrative examples for 3.1.C.5:
      • An organization’s external firewall is not configured to block external ICMP traffic.
  • 3.1.C.6 Low risks from network vulnerabilities include vulnerabilities that would be difficult to exploit and would likely have minimal negative impacts on an organization.
    • Illustrative examples for 3.1.C.6:
      • An organization has wireless access points that broadcast a beacon frame, which contains the network service set identifier (SSID) and the wireless encryption protocols.
日本語

学習目標 3.1.A: 一般的なネットワーク攻撃を特定する。

  • 3.1.A.1 アドレス解像プロトコル (ARP) は、ネットワーク上のデフォルトゲートウェイによって使用され、インターネットプロトコル (IP) アドレスとメディアアクセスコントロール (MAC) アドレスをペアにするテーブルを構築するために用いられる。ARP ポイズニング攻撃とは、敵対者が偽造された ARP パケットをデフォルトゲートウェイに送信し、ターゲットの IP アドレスを敵対者の MAC アドレスにリンクすることで、ターゲット宛てのトラフィックを敵対者のデバイスに転送するようにテーブルを変更することである。MAC アダプタを偽装することを MAC スPUフィングという。これはオンパス攻撃(またはミドルマン攻撃)の例であり、敵対者が2者間のデータストリームを遮断し、両者のデータをキャッチし、送信する前にデータをコピーまたは改変する攻撃である。双方は互いに直接通信していると思っているが、実際には各自が敵対者と通信しており、そのメッセージが密かに傍受されている状態となる。
  • 3.1.A.2 MAC フラッディング攻撃とは、敵対者が異なる MAC アダプタを持つ多数のエターネットフレームをターゲットスイッチに送信することである。これによりスイッチがブロードキャストモードに強制され、敵対者はネットワーク上のすべてのフレームを収集できる(これらはブロードキャストされているため)。これにより、敵対者は機密情報へのアクセスが可能になる可能性がある。これはイブスドロップ(またはスニフィング)の例であり、敵対者が進行中のデータをキャッチし、記録・コピーできる攻撃である。
  • 3.1.A.3 DNS ポイズニング攻撃とは、敵対者が権威あるネームサーバー (NS) を装い、DNS サーバーに偽の DNS レコード植入して、認証情報を盗むために設計された悪意のあるウェブサイトへブラウザのトラフィックをリダイレクトすることである。これはクレデンシャルハーベストingの例であり、敵対者が本物のように見える偽のログインサイトを设置し、無邪気なユーザーが本物の認証情報を入力すると、それらを敵対者がキャッチして利用する攻撃である。
  • 3.1.A.4 スマーフ攻撃は、インターネットコントロールメッセージプロトコル (ICMP) リクエストでネットワークを飽和させようとする攻撃である。これは denial of service (DoS) 攻撃の一種であり、システムやリソースを authorized users が利用できないようにする攻撃である。スマーフ攻撃中、敵対者は被害者のアドレスを含む多数の ICMP リクエストをネットワークのブロードキャストアドレスに送信する。ネットワークのゲートウェイはこれらのリクエストをネットワーク上のすべてのデバイスに送信する。各デバイスは被害者のアドレスに返信し、正規のメッセージをブロックする可能性のあるトラフィックの洪水を生み出す。複数のデバイスが同時に同じターゲットを攻撃する場合、これを分散 denial of service (DDoS) 攻撃と呼ぶ。

学習目標 3.1.B: 敵対者がネットワーク脆弱性をどう活用してネットワーク通信を盗聴、妨害、破壊するか説明する。

  • 3.1.B.1 敵対者は、DoS を引き起こすためにネットワークを飽和させる恶意trafficを送信したり、ネットワークの内部構造をマッピングしたり、合法デバイスを偽装したりできる。ファイアウォールがない、または適切に構成されていないファイアウォールを持つネットワークは、これらの攻撃に脆弱である。
  • 3.1.B.2 デバイスを乗っ取った敵対者は、ローカルエリアネットワーク (LAN) 上の他のデバイスも乗っ取るためにそのアクセスを利用しようとする傾向がある。
  • 3.1.B.3 敵対者がデータポートに物理的に接続した場合、ポートセキュリティが有効化されていない限り、スイッチポートを通じて LAN にアクセスできる。これにより、敵対者は DoS 攻撃を実行したり、MAC フラッディングや MAC スPUフィング攻撃を行ったりできる。
  • 3.1.B.4 物理的に安全なスペースの外にいる敵対者は、物理的空間の外にブロードキャストされているワイヤレスアクセスポイントからの信号やビコンフレームをキャッチできる。これにより、ワイヤレスネットワークに関する情報を収集し、それに対するイブスドロップ暗号化攻撃を試みることが可能になる。
  • 3.1.B.5 敵対者はネットワークに参加して、その内部から攻撃を行うことを試みることがある。デバイスやユーザーを認証しないネットワークでは、敵対者が参加することが容易になる。
  • 3.1.B.6 開放されたネットワークポートがある場合、攻撃者はそのポートにワイヤレスアクセスポイントを接続し、不正アクセスポイントを作成できます。攻撃者はこの不正アクセスポイントを利用して、内部ネットワークに無線でアクセスすることが可能であり(物理的な空間の外からでも)、これによりファイアウォールを回避してLANへの直接アクセスが可能になります。
  • 3.1.B.7 攻撃者は、ワイヤレス暗号化の解除を試み、ネットワーク上のデータを傍受、盗取、または侵害しようとする可能性があります。

学習目標 3.1.C: ネットワーク脆弱性からのリスクを評価・文書化する。

  • 3.1.C.1 ネットワーク上の脆弱性は、攻撃者が送信中のデータを傍受・改変したり、DoS攻撃を実行したり、ネットワーク上で横方向に移動してより敏感かつ重要なシステムへのアクセスを得たりする原因となることがあります。ネットワーク脆弱性は、機密性、完全性、可用性に対するリスクとなる可能性があります。
  • 3.1.C.2 既知の脆弱性に対してネットワーク、デバイス、アプリケーションを検査できる自動化された脆弱性スキャナがあります。これらのスキャナは、検出された脆弱性、その深刻度、および軽減策に関する推奨事項を含むレポートを生成します。
  • 3.1.C.3 ネットワーク脆弱性を成功裏に悪用するには、高度な技術的能力及び知識が通常必要です。これはエクスプロイトの可能性に影響を与えます。
  • 3.1.C.4 ネットワーク脆弱性による高リスクは、攻撃者がネットワークトラフィックをキャプチャしたり、ネットワーク上の正規デバイスを偽装したり、DoS攻撃を実行したりすることで、容易に重大な影響を与えることを意味します。
    • 3.1.C.4 の例:
      • 組織が単一の未分割内部ネットワークを持ち、弱体な暗号化を持つワイヤレスネットワークを通じてアクセス可能であり、そのネットワーク上で独自ウェブアプリケーションを実行しているサーバーを運用している場合。
  • 3.1.C.5 ネットワーク脆弱性による中程度のリスクには、攻撃者にネットワーク上のシステムやデバイスに関する情報を取得させる可能性がある脆弱性が含まれます。
    • 3.1.C.5 の例:
      • 組織の外部ファイアウォールが、外部ICMPトラフィックをブロックするように設定されていない場合。
  • 3.1.C.6 ネットワーク脆弱性による低リスクには、悪用が困難であり、組織に与える否定的な影響が最小限である可能性が高い脆弱性が含まれます。
    • 3.1.C.6 の例:
      • 組織が、ネットワークサービスセットID(SSID)およびワイヤレス暗号化プロトコルを含むビーコンフレームをブロードキャストするワイヤレスアクセスポイントを持っている場合。

Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

English
A man-in-the-middle attack
DDoS: a botnet floods a server

A network connects devices so they can share data - and every connection is a possible way in. You must know the classic network attacks and the tricks behind them.

  • ARP poisoning 地址解析投毒 - the address resolution protocol (ARP) 地址解析协议 pairs IP addresses with hardware MAC addresses 物理地址. An adversary sends fake ARP messages so traffic meant for the target flows to the adversary instead. This is an on-path attack 中间人攻击 (also called man-in-the-middle): the adversary secretly sits between two parties, reading and even altering their messages.
  • MAC flooding 物理地址泛洪 - flooding a switch 交换机 with fake MAC addresses forces it into broadcast mode, so the adversary can capture all traffic. This is a form of eavesdropping 窃听.
  • DNS poisoning 域名投毒 - planting a fake record on a domain name system (DNS) 域名系统 server redirects users to a malicious site to steal credentials (credential harvesting 凭据收集).
  • Smurf attack - flooding a network with ICMP requests aimed at the broadcast address, so every device replies to the victim. It is a denial of service (DoS) 拒绝服务 attack; when many machines attack at once it becomes a distributed denial of service (DDoS) 分布式拒绝服务.

Adversaries exploit weak networks to flood, map, or spoof devices. A physical data port with no port security lets an attacker plug in; an open port lets them install a rogue access point 非法接入点 that bypasses the firewall entirely. We rate network risk by impact and by how much skill the exploit needs.

To find weaknesses before an adversary does, organisations run an automated vulnerability scanner 自动漏洞扫描器: a tool that checks networks, devices, and applications against a database of known vulnerabilities, then produces a report listing each one found, how severe it is, and a recommended mitigation 缓解措施. Fixing the highest-severity items first is a core part of managing network risk.

日本語
マン・イン・ザ・ミドル攻撃
DDoS:ボットネットがサーバーを氾濫させる

ネットワークはデバイス同士を接続してデータ共有を可能にするものですが、すべての接続は侵入経路となり得ます。古典的なネットワーク攻撃とその背後にある手口を熟知する必要があります。

  • ARPポイズニング - アドレス解決プロトコル(ARP) はIPアドレスとハードウェアMACアドレスをペアリングします。攻撃者は偽のARPメッセージを送信し、ターゲット宛てのトラフィックを攻击者側へ誘導します。これはオンパス攻撃(マン・イン・ザ・ミドルとも呼ばれる)であり、攻撃者は2者の間に隠れて、メッセージを読み取ったり改変したりします。
  • MACフラッディング - スイッチに偽のMACアドレスを大量送信し、广播モードに強制することで、攻撃者が全トラフィックを捕獲できるようにします。これはイブスドロップ(Eavesdropping) の一種です。
  • DNSポイズニング - ドメインネームシステム(DNS) サーバーに偽レコードを植入し、ユーザーを悪意あるサイトへリダイレクトして認証情報窃取(クレデンシャルハーベスティング)を図ります。
  • スマーフ攻撃(Smurf attack) - ブロードキャストアドレス targeted なICMPリクエストを網絡全体に送信し、すべてのデバイスが標的へ応答するようにします。サービス拒否(DoS) 攻撃であり、複数のマシンが同時に攻撃すると分散型サービス拒否(DDoS) となります。

攻撃者は脆弱なネットワークを利用して、デバイスを氾濫させたりマッピングしたり、またはサボタージュしたりします。物理的なデータポートにポートセキュリティがないと、攻撃者が接続できます。開放されたポート则有ローグアクセスポイントを設置でき、ファイアウォールを完全にバイパスします。ネットワークリスクは、影響度と利用に必要なスキル度合いに基づいて評価します。

攻撃者よりも先に脆弱性の弱点を特定するために、組織は自動化された脆弱性スキャナを実装します。これは、ネットワーク、デバイス、アプリケーションが既知の脆弱性のデータベースに照合され、発見された各脆弱性、その深刻度、推奨される対策を含む報告書を作成するツールです。最も深刻度の高い項目から優先的に修復することは、ネットワークリスクを管理する際の重要な手法です。

Explore · ⁨探索⁩

Identify the network attack from its evidence · ⁨証拠に基づいてネットワーク攻撃を特定する⁩

Each network attack leaves a distinct trace: ARP poisoning = one IP with two MACs; MAC flooding = a surge of new MACs; DNS poisoning = misdirected web traffic; smurf/DoS = a flood that blocks legitimate traffic. · ⁨各ネットワーク攻撃には固有の痕跡が残ります:ARPポイズニング=1つのIPに2つのMAC;MACフロッディング=多数の新しいMACの流入;DNSポイズニング=誤ったWebトラフィック;スマーフ/DoS=正当なトラフィックをブロックする洪水。⁩

Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
English 日本語
eavesdropping/ˈiːvzdrɒpɪŋ/ 盗聴
DNS poisoning/ˌdiː en ˈes ˈpɔɪzənɪŋ/ DNSポイズニング
domain name system (DNS)/dəˈmeɪn neɪm ˈsɪstəm/ ドメインネームシステム (DNS)
credential harvesting/krɪˈdenʃl ˈhɑːvɪstɪŋ/ クレデンシャルハーベスト
denial of service (DoS)/dɪˈnaɪəl ɒv ˈsɜːvɪs/ サービス妨害攻撃 (DoS)
distributed denial of service (DDoS)/ˈdɪstrɪbjuːtɪd dɪˈnaɪəl ɒv ˈsɜːvɪs/ 分散型サービス妨害攻撃 (DDoS)
rogue access point/rəʊɡ ˈækses pɔɪnt/ ローグアクセスポイント
automated vulnerability scanner/ˈɔːtəmeɪtɪd ˌvʌlnərəˈbɪlɪti ˈskænə/ 自動脆弱性スキャナ
mitigation/ˌmɪtɪˈɡeɪʃn/ 緩和策
split tunneling/splɪt ˈtʌnəlɪŋ/ スプリット_tunneling(分割_tunneling)
3.2

Protecting Networks: Managerial Controls and Wireless Security · ⁨ネットワーク保護:管理的統制とワイヤレスセキュリティ⁩

Syllabus · ⁨シラバス⁩
English

Learning Objective 3.2.A: Identify managerial controls related to network security.

  • 3.2.A.1 A router security policy will set forth a minimum configuration standard for routers on an organization’s network and may include:
    • Banning local user accounts (All router logins must use an approved authentication server.)
    • Disabling unnecessary services (e.g., Telnet)
    • Requiring a firewall (An organization may opt for a firewall device separate from the router.)
  • 3.2.A.2 A switch security policy will set forth a minimum configuration standard for switches on an organization’s network and may include:
    • Banning local user accounts (All switch logins must use an approved authentication server.)
    • Requiring port security to be enabled.
    • Using MAC filtering
  • 3.2.A.3 A virtual private network (VPN) policy will detail the minimum security requirements for employees using a VPN to access an organization’s internal network, and it may include:
    • A list of roles within the organization that are allowed to use a VPN to access the organization’s internal network
    • Authentication requirements for employees using a VPN (e.g., public/private key system or MFA)
    • A prohibition against split tunneling (also called dual tunneling)
  • 3.2.A.4 A wireless security policy will establish the minimum security requirements for wireless networks within an organization and may include:
    • Requiring users to authenticate to the wireless network through an extensible authentication protocol (EAP) connected to an approved authentication server
    • Requiring all wireless traffic to be encrypted using AES encryption with a minimum key length
    • Disabling beacon frames on wireless access points

Learning Objective 3.2.B: Configure wireless network security features.

  • 3.2.B.1 Organizations can disable beacon frame broadcasting on wireless access points (WAPs) to make it harder for adversaries to find their wireless network and learn its basic properties.
  • 3.2.B.2 Organizations can control the broadcast direction and signal strength of a WAP so the signal does not extend beyond the physical space the access point is meant to cover.
  • 3.2.B.3 Organizations should enable strong wireless encryption protocols to ensure wireless frames are not readable by adversaries who might intercept them.
    • WEP, WPS, and the original WPA wireless encryption protocols have known vulnerabilities and are insecure.
    • WPA3 is currently the strongest wireless encryption algorithm.
  • 3.2.B.4 Organizations can enable MAC filtering to prevent unauthorized devices from accessing the network, and they can require users to authenticate when joining a network.
日本語

学習目標 3.2.A: ネットワークセキュリティに関連する管理統制を特定する。

  • 3.2.A.1 ルーターセキュリティポリシーは、組織のネットワーク上のルーターに対する最低構成基準を定めており、以下を含めることがあります:
    • ローカルユーザーアカウントの使用禁止(すべてのルーターログインは承認された認証サーバーを使用すること。)
    • 不要なサービスの無効化(例:Telnet)
    • ファイアウォールの必須化(組織はルーターとは別のファイアウォールデバイスを選択することもある。)
  • 3.2.A.2 スイッチセキュリティポリシーは、組織のネットワーク上のスイッチに対する最低構成基準を定めており、以下を含めることがあります:
    • ローカルユーザーアカウントの使用禁止(すべてのスイッチログインは承認された認証サーバーを使用すること。)
    • ポートセキュリティの有効化の必須化。
    • MACフィルタリングの使用
  • 3.2.A.3 仮想プライベートネットワーク(VPN)ポリシーは、組織の内部ネットワークにアクセスするためにVPNを使用する従業員に対する最低セキュリティ要件を詳細に示しており、以下を含めることがあります:
    • 組織の内部ネットワークにアクセスするためにVPNの使用が許可されている組織内の役職の一覧
    • VPNを使用する従業員のための認証要件(例:公開鍵/秘密鍵システムまたはMFA)
    • スプリット_tunneling(デュアル_tunnelingとも呼ばれる)の禁止
  • 3.2.A.4 ワイヤレスセキュリティポリシーは、組織内のワイヤレスネットワークに対する最低セキュリティ要件を確立しており、以下を含めることがあります:
    • 承認された認証サーバーに接続された拡張認証プロトコル(EAP)を介してユーザーがワイヤレスネットワークに認証されること
    • AES暗号化を使用して最小キー長で、すべてのワイヤレストラフィックが暗号化されていること
    • ワイヤレスアクセスポイントにおけるビーコンフレームの無効化

学習目標 3.2.B: ワイヤレスネットワークセキュリティ機能を設定する。

  • 3.2.B.1 組織は、ワイヤレスアクセスポイント(WAP)でのビーコンフレームのブロードキャストを無効化して、攻撃者がワイヤレスネットワークを見つけやすくせず、その基本的な属性を学ぶのを難しくすることができます。
  • 3.2.B.2 組織は、WAPのブロードキャスト方向と信号強度を制御して、信号がアクセスポイントが本来カバーすべき物理的な空間を超えて広がらないようにできます。
  • 3.2.B.3 組織は、強固なワイヤレス暗号化プロトコルを有効化して、ワイヤレスフレームが傍受される可能性がある攻撃者によって読み解かれないようにする必要があります。
    • WEP、WPS、および最初のWPAワイヤレス暗号化プロトコルには既知の脆弱性があり、安全ではありません。
    • WPA3は現在、最も強力なワイヤレス暗号アルゴリズムです。
  • 3.2.B.4 組織は、MACフィルタリングを有効化して、未授权デバイスがネットワークにアクセスできないようにし、ネットワークに接続する際にユーザーの認証を求めることができます。

Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

English

Good network security starts with written policies that set a minimum standard: a router security policy and switch security policy ban local accounts and require port security; a VPN policy sets authentication rules and forbids split tunneling 分离隧道; and a wireless security policy requires strong encryption and authenticated access.

For wireless networks specifically, organisations disable beacon frames so the network is harder to find, control signal strength so it does not leak outside the building, enable strong encryption - WPA3 Wi-Fi 保护接入第三代 is the current strongest, while old WEP and the original WPA are broken - and use MAC filtering to allow only known devices.

日本語

適切なネットワークセキュリティは、最低基準を定めた文書化されたポリシーから始まります。ルーターセキュリティポリシーおよびスイッチセキュリティポリシーはローカルアカウントの使用を禁止し、ポートセキュリティの実施を義務付けます。VPNポリシーは認証ルールを設定し、スプリット_tunneling(分割トネリング)を禁止します。また、ワイヤレスセキュリティポリシーでは強力な暗号化と認証済みアクセスの実施を要件としています。

ワイヤレスネットワークに関しては、組織はネットワークが検出されにくくなるようビーコンフレームを無効にし、建物の外へ信号が漏れないように信号強度を制御し、強力な暗号化を有効化します(現在の最強化はWPA3 Wi-Fiであり、古いWEPや初期のWPAは破綻しています)。さらに、MACフィルタリングを使用して、事前に登録されたデバイスのみを許可します。

Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
English 日本語
WPA3/ˌdʌbljuː piː eɪ ˈθriː/ WPA3
Network segmentation/ˈnetwɜːk ˌseɡmənˈteɪʃn/ ネットワークセグメンテーション
subnets/ˈsʌbnets/ サブネット
screened subnet/skriːnd ˈsʌbnet/ スクリーンedサブネット
3.3

Protecting Networks: Segmentation · ⁨ネットワーク保護:セグメンテーション⁩

Syllabus · ⁨シラバス⁩
English

Learning Objective 3.3.A: Identify techniques for segmenting a network.

  • 3.3.A.1 Firewall zones and rules can be used to create a screened subnet (also known as a demilitarized zone, or DMZ)—a network segment that sits between public, external networks like the internet and internal, private networks. A screened subnet is typically a lower security zone than the internal, private networks, and it typically holds an organization’s publicly facing resources, separating them from the internal network.
  • 3.3.A.2 Subnetting can be used to create different subnets based on IP addressing. If a device is compromised by an adversary, subnets can contain a security breach to reduce the number of exposed devices.
  • 3.3.A.3 Switches can be used to create VLANs, which logically separate devices physically connected to central switches.

Learning Objective 3.3.B: Explain why network segmentation can increase network security.

  • 3.3.B.1 Network segmentation refers to the process of dividing a network into smaller, isolated segments or subnetworks (subnets).
  • 3.3.B.2 Dividing a network into smaller subnets isolates network traffic, which can prevent attacks on one subnet from impacting devices on other subnets.
  • 3.3.B.3 Network segmentation can allow for different security policies and controls to be applied to different segments of the network, allowing for higher security zones and lower security zones.
  • 3.3.B.4 Port security on a switch can prevent MAC flooding by limiting the number of addresses assignable to any single switch port.
日本語

学習目標 3.3.A: ネットワークをセグメント化する手法を特定する。

  • 3.3.A.1 フォアウォール・ゾーンおよびルールを使用して、スクリーンド・サブネット(ディミリタライズド・ゾーン、DMZとも呼ばれる)を作成できます。これは、インターネットなどの公開外部ネットワークと、内部のプライベートネットワークとの間に位置するネットワークセグメントです。スクリーンド・サブネットは通常、内部のプライベートネットワークよりもセキュリティレベルが低く、組織の公网資源を保持し、それらを内部ネットワークから分離します。
  • 3.3.A.2 サブネット分割は、IPアドレスに基づいて異なるサブネットを作成するために使用できます。あるデバイスが攻撃者に侵害された場合、サブネットはセキュリティ違反を限定することで、露出するデバイスの数を減らすことができます。
  • 3.3.A.3 スイッチを使用してVLANを作成することができ、これにより中央スイッチに物理的に接続されているデバイスを論理的に分離できます。

学習目標 3.3.B: ネットワーク分割がネットワークセキュリティを向上させる理由を説明すること。

  • 3.3.B.1 ネットワーク分割とは、ネットワークをより小さく、隔離されたセグメントやサブネットワーク(サブネット)に分割するプロセスを指します。
  • 3.3.B.2 ネットワークを小さなサブネットに分割すると、ネットワークトラフィックが隔离され、あるサブネットに対する攻撃が他のサブネット上のデバイスに影響を与えるのを防ぐことができます。
  • 3.3.B.3 ネットワーク分割により、ネットワークの異なるセグメントに対して異なるセキュリティポリシーや制御を適用することが可能になり、高いセキュリティゾーンと低いセキュリティゾーンを設定できます。
  • 3.3.B.4 スイッチのポートセキュリティは、単一のスイッチ・ポートに割り当て可能なMACアドレスの数を制限することで、MACフラッディングを防ぐことができます。

Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

English

Network segmentation 网络分段 divides one network into smaller, isolated pieces (subnets 子网). If one subnet is breached, the damage is contained and cannot spread.

A key pattern is the screened subnet 屏蔽子网 (also called a DMZ 隔离区). It sits between the public internet and the private internal network, holding an organisation's public-facing servers in a lower-security zone - separated from the sensitive internal systems.

Segments can also be built with subnetting (by IP address) or VLANs 虚拟局域网 (logically separating devices on the same switch). Each segment can then get its own security policy - higher-security and lower-security zones.

日本語

ネットワークセグメンテーションは、単一のネットワークをより小さく隔離された部分(サブネット)に分割します。1つのサブネットが侵害されても、被害は限定され、拡大することはありません。

重要な設計パターンとしてスクリーンドサブネット(DMZとも呼ばれる)があります。これは、公的インターネットと private な内部ネットワークの間に位置し、組織のパブリックFacingサーバーを安全性の低いゾーンに保持します。これにより、敏感な内部システムとは分離されます。

スクリーンドサブネット(DMZ)は、パブリックサーバーを2つのファイアウォールの間に配置し、プライベートネットワークから遠ざけます
スクリーンドサブネット(DMZ)は、パブリックサーバーを2つのファイアウォールの間に配置し、プライベートネットワークから遠ざけます

セグメントは、IPアドレスによるサブネットティングや、同じスイッチ上のデバイスを論理的に分離するVLANsによって構築することもできます。各セグメントには独自のセキュリティポリシー(高セキュリティゾーンと低セキュリティゾーン)を適用することが可能です。

サーバーラック: ネットワークセグメンテーションによりシステムが隔離され、1つの侵害で全てが暴露されるのを防ぎます
サーバーラック: ネットワークセグメンテーションによりシステムが隔離され、1つの侵害で全てが暴露されるのを防ぎます
Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
English 日本語
DMZ/ˌdiː em ˈzed/ DMZ
VLANs/ˈviːlænz/ VLANs
3.4

Protecting Networks: Firewalls · ⁨ネットワーク保護:ファイアウォール⁩

Syllabus · ⁨シラバス⁩
Learning ObjectiveEssential Knowledge

3.4.A
Identify types of network-based firewalls.

  • 3.4.A.1 A firewall is used to allow or deny network traffic in or out of a network. The firewall itself is software that can be hosted on a standalone device or integrated into another network device, such as a router.
  • 3.4.A.2 A stateless firewall filters traffic based on information in packet headers, such as IP addresses, ports, and protocols.
  • 3.4.A.3 A stateful firewall (also known as dynamic packet filtering) tracks the state of network connections passing through the firewall and can filter according to connection-related rules in addition to the filtering done by a stateless firewall. This allows for more control over content allowed in and out of a network.
  • 3.4.A.4 A next-generation firewall (NGFW) has both the capabilities of typical stateless and stateful firewalls and additional advanced features, such as intrusion prevention, deep packet inspection, and filtering by application type.

3.4.B
Explain how a firewall uses an access control list to allow or deny traffic entering or leaving a network.

  • 3.4.B.1 Network administrators create a set of rules, called an access control list (ACL), that a firewall uses to permit or deny inbound and outbound network traffic.
  • 3.4.B.2 ACL rules are checked in order and the first rule that matches the criteria will be executed for the specified data.
  • 3.4.B.3 A typical ACL will specify the direction of traffic (inbound or outbound), the criterion to filter by (IP addresses, logical port, service, or application), and the action to take (permit or deny).

3.4.C
Determine the effective placement of firewalls in a network.

  • 3.4.C.1 Each segment of a network should have a firewall to control the flow of data in and out of that segment.
  • 3.4.C.2 Network segments may have different security needs based on the data and services within them. The level of security for each firewall can be set independently.
  • 3.4.C.3 Each point of data ingress and egress between the internal network and the public internet should have a firewall.

3.4.D
Configure a firewall to manage the flow of network traffic.

  • 3.4.D.1 The requirements for a firewall will specify what type of traffic from which sources or to which destinations should be allowed or denied.
  • 3.4.D.2 Specific rules for a firewall can allow or deny inbound or outbound traffic based on source or destination port or IP address, service, protocol, or application.
    • Illustrative examples for 3.4.D.2:
      • Allow inbound TCP port 22 from ALL; (this rule will allow all inbound TCP traffic with destination port 22, which is the designated port for the SSH protocol)
      • Deny inbound TCP port 80 from 192.168.1.0/24; (this rule will deny inbound TCP traffic with destination port 80 from IP addresses in the 192.168.1.0-192.168.1.255 range)
  • 3.4.D.3 Rules are implemented in order, and changing the order of a set of rules can change which traffic is allowed or denied. Consideration must be given to the precedence of filtering priorities when establishing the order of rules.
    • Illustrative examples for 3.4.D.3:
      • This set of rules would allow SSH traffic and deny other inbound TCP traffic
      • Rule 1: ALLOW inbound TCP port 22 from ALL;
      • Rule 2: DENY inbound TCP ALL from ALL;
      • Reversing the order of those rules would deny all inbound TCP traffic including SSH traffic.

Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

English
How a firewall decides

A firewall 防火墙 allows or denies traffic entering or leaving a network. There are several kinds:

  • Stateless 无状态 - filters on packet headers alone (IP, port, protocol).
  • Stateful 有状态 - also tracks the state of each connection for finer control.
  • Next-generation (NGFW) - adds advanced features like intrusion prevention and deep packet inspection.

A firewall follows an access control list (ACL) 访问控制列表 - an ordered set of rules. Rules are checked in order, and the first match wins, so the order of rules changes which traffic gets through. Each rule specifies a direction, a thing to filter by (IP, port, service), and an action (permit or deny).

Worked example. A firewall has Rule 3: DENY TCP 443 from 192.168.*, and lower down Rule 7: ALLOW TCP 443 from ALL. A user at 192.168.45.37 cannot reach port 443 - even though Rule 7 would allow them - because Rule 3 matches first, and the first match wins. The fix is to move the ALLOW rule above the DENY. This is why rule order, not just rule content, decides what traffic gets through.

Firewalls belong at every point where data crosses between zones - at each network segment and at every gateway to the public internet.

日本語
How a firewall decides

ファイアウォールは、ネットワークへの入出力トラフィックを許可または拒否します。主な種類は以下の通りです:

  • ステートレス - パケットヘッダーのみ(IP、ポート、プロトコル)に基づいてフィルタリングを行います。
  • ステートフル - 各接続の状態も追跡し、より細かい制御が可能です。
  • 次世代(NGFW) - 侵入防止機能やディープパケットインスペクションなどの高度な機能を追加します。

ファイアウォールはアクセスコントロールリスト(ACL)に従って動作します。これは順序付けられたルールのセットであり、ルールは順にチェックされ、最初の一致したルールが優先されます。したがって、ルールの順序が変更されると、通過するトラフィックも変化します。各ルールは方向、フィルタリング対象(IP、ポート、サービス)、アクション(許可または拒否)を指定します。

ファイアウォールはACLを最上段から順に確認し、最初に一致したルールが決定します
ファイアウォールはACLを最上段から順に確認し、最初に一致したルールが決定します

計算例。 ファイアウォールにルール 3: DENY TCP 443 from 192.168.* と、その下にあるルール 7: ALLOW TCP 443 from ALL があります。ユーザー 192.168.45.37 はポート 443 にアクセスできません。ルール 7 が許可しているにもかかわらずです。これは、ルール 3 が先に一致するためであり、最初の一致が勝つからです。修正方法は、ALLOWルールをDENYルールの上に移動することです。これが、通過するトラフィックを決定するのはルールの内容だけでなく、ルールの順序である理由です。

データがゾーン間を交差するすべてのポイントにファイアウォールを設置します。各ネットワークセグメントおよび公的インターネットへのゲートウェイに配置します。

Rack-mounted network switches with many ethernet cables
実際のネットワークハードウェア: ファイアウォールとは、これらのケーブルが外部世界と接続する場所に設置されたデバイス(またはソフトウェア)です
Vocabulary · ⁨語彙⁩ Train · ⁨練習する⁩
English 日本語
ARP poisoning/ɑːp ˈpɔɪzənɪŋ/ ARPポイズニング
address resolution protocol (ARP)/əˈdres ˌrezəˈluːʃn ˈprəʊtəkɒl/ アドレス解決プロトコル (ARP)
MAC addresses/mæk əˈdresɪz/ MACアドレス
on-path attack/ɒn pæθ əˈtæk/ on-path attack(中継攻撃)
MAC flooding/mæk ˈflʌdɪŋ/ MACフロッディング
switch/swɪtʃ/ スイッチ
firewall/ˈfaɪəwɔːl/ ファイアウォール
Stateless/ˈsteɪtləs/ ステートレス
Stateful/ˈsteɪtfl/ ステートフル
access control list (ACL)/ˈækses kənˈtrəʊl lɪst/ アクセスコントロールリスト (ACL)
log files/lɒɡ faɪlz/ ログファイル
network intrusion detection system (NIDS)/ˈnetwɜːk ɪnˈtruːʒn dɪˈtekʃn ˈsɪstəm/ ネットワーク侵入検知システム (NIDS)
network intrusion prevention system (NIPS)/ˈnetwɜːk ɪnˈtruːʒn prɪˈvenʃn ˈsɪstəm/ ネットワーク侵入防止システム (NIPS)
security information and event management (SIEM)/sɪˈkjʊərɪti ˌɪnfəˈmeɪʃn ænd ɪˈvent ˈmænɪdʒmənt/ セキュリティ情報およびイベント管理 (SIEM)
Signature-based/ˈsɪɡnɪtʃə beɪst/ シグネチャベース
Anomaly-based/əˈnɒməli beɪst/ アナモリー(異常値)ベース
baseline/ˈbeɪslaɪn/ ベースライン
network-based indicators of compromise/ˈnetwɜːk beɪst ˈɪndɪkeɪtəz ɒv ˈkɒmprəmaɪz/ ネットワークベースの侵害指標
probabilistic/ˌprɒbəbɪˈlɪstɪk/ 確率的
threshold/ˈθreʃəʊld/ 閾値(しちじ)
alert fatigue/əˈlɜːt fəˈtiːɡ/ アラート疲労
3.5

Detecting Network Attacks · ⁨ネットワーク攻撃の検知⁩

Syllabus · ⁨シラバス⁩
English

Learning Objective 3.5.A: Identify types of automated security tools used to detect network attacks.

  • 3.5.A.1 Automated detection tools analyze data collected from an organization’s network and devices, such as switches and routers, servers, firewalls, and user computers. These data are often collected in a log file.
  • 3.5.A.2 A network intrusion detection system (NIDS) is an automated tool that analyzes data to determine if malicious activity is taking place on a network. When an attack is detected, it generates an alert.
  • 3.5.A.3 A network intrusion prevention system (NIPS) is an automated tool that, like an IDS, analyzes data to determine if malicious activity is taking place on a network. A NIPS can also mitigate or halt an attack by closing ports, blocking specific IP or MAC addresses, or rejecting specific protocols.
  • 3.5.A.4 A security information and event management (SIEM) system collects and analyzes data from multiple sources (including firewalls, NIDS/NIPS, device logs, and application logs) to detect patterns that may indicate a cyberattack and raises an alert if a potential attack is detected. Security analysts investigate the alert to determine whether it represents a true threat and follow standard operating procedures to resolve or escalate the alert.

Learning Objective 3.5.B: Explain how organizations can leverage artificial intelligence (AI) to enhance threat detection and response.

  • 3.5.B.1 Computers log every action that users take. Firewalls, IDS, IPS, and other network sensors log all the traffic passing through various points in a network. A medium-sized organization’s network is logging millions (or even tens of millions) of data points per day. Even a large team of humans is incapable of analyzing so much data.
  • 3.5.B.2 Threat detection teams are creating AI algorithms to analyze large amounts of data and classify the data patterns as malicious or normal.
  • 3.5.B.3 AI models for threat detection are based on probabilistic calculations; they report a percentage to indicate the likelihood that something is malicious.
  • 3.5.B.4 Organizations determine their own thresholds for what percentage of likelihood of a threat results in an alert. If the threshold is set too high, real attacks may go undetected; if the threshold is too low, the security team will be overwhelmed with false alerts.

Learning Objective 3.5.C: Determine a network detection method.

  • 3.5.C.1 Volume of network traffic is a criterion for determining a detection method. Signature-based detection is more efficient for networks with high traffic volume. Signature-based detection compares detection data to a database of known indicators of compromise (IoCs), called signatures. Signature databases must be updated with IoCs for the latest attacks. Signature-based detection runs more quickly than anomaly-based detection.
  • 3.5.C.2 Consistency of network traffic patterns is a criterion for determining a detection method. Anomaly-based detection is most effective on networks with consistent traffic patterns. Anomaly-based detection compares detection data to a baseline of recorded activity. Baselines must be recorded on uncompromised systems to establish expected data types and volumes. Anomaly-based detection triggers an alert or action when data types or volumes outside of a specified tolerance range are recorded. Anomaly-based detection relies on consistent patterns in network traffic to detect anomalous traffic patterns.
  • 3.5.C.3 Degree of sensitivity or criticality of a network is a criterion for determining a detection method. Networks with more sensitive or critical data or services will likely consider a hybrid approach. Hybrid detection combines signature-based and anomaly-based detection. Hybrid detection is more expensive than using either signature- or anomaly-based detection alone, and hybrid-detection models generate more alerts.
  • 3.5.C.4 Likelihood of novel attacks on a network is a criterion for determining a detection method. Signature-based detection cannot detect a new attack. When an organization suspects that adversaries are likely to attempt a new attack on a network, anomaly-based detection is the preferred method when the cost of hybrid detection is prohibitively high.

Learning Objective 3.5.D: Evaluate the impact of a network detection method.

  • 3.5.D.1 Speed of detection is a factor in evaluating the impact of a network detection method. Faster detection enables faster response. Signature-based detection methods are faster than anomaly-based detection methods, especially on networks with high traffic volume.
  • 3.5.D.2 Cost is a factor in evaluating the impact of a network detection method. Detection tools and ongoing costs need to be within a budget. Anomaly-based detection systems require more expensive hardware to operate than signature based. Hybrid detection is the most expensive option because it combines both anomaly- and signature-based methods.
  • 3.5.D.3 False positive rate is a factor in evaluating the impact of a network detection method. Signature-based detection has almost no false positives. Anomaly-based or hybrid detection will have higher false positive rates. Impacts of high false positive rates include:
    • Time and resources are put toward investigating alerts for nonmalicious activity.
    • Alert fatigue is a condition that occurs when responders get accustomed to false positives and take alerts less seriously because they assume alerts are false positives before investigating them.
  • 3.5.D.4 False negative rate is a factor in evaluating the impact of a network detection method. A false negative occurs when an adversary can bypass a detection system. Signature-based detection systems are easier to bypass than anomaly-based or hybrid systems. False negatives can result in adversaries causing loss, harm, disruption, or destruction to data and systems.

Learning Objective 3.5.E: Apply detection techniques to identify indicators of network attacks by analyzing log files.

  • 3.5.E.1 Evil-twin attacks can be detected by regularly scanning for service set identifiers (SSIDs) that look suspicious or similar to local legitimate SSIDs. Signal triangulation can be used to locate and disable an access point broadcasting an evil-twin network.
  • 3.5.E.2 Jamming attacks can be detected by recognizing that no wireless devices in a specific physical space are able to connect to a wireless network and by scanning for electromagnetic (EM) noise in the wireless range.
  • 3.5.E.3 ARP poisoning attacks can be detected by monitoring network traffic for unusual ARP messages (particularly duplicate MAC address ARP packets) and checking the ARP table on the default gateway.
  • 3.5.E.4 MAC flooding attacks can be detected by monitoring network traffic for an unexpected surge of Ethernet frames with different MAC addresses and checking the MAC address table on a switch.
  • 3.5.E.5 DNS poisoning attacks are difficult to detect. However, if an organization’s website experiences an abrupt and otherwise inexplicable drop in traffic, DNS records should be examined as a potential cause.
  • 3.5.E.6 Smurf attacks can be detected by watching network traffic for a sudden increase in ICMP requests sent to the network’s broadcast address.
  • 3.5.E.7 Network-based IoCs are discovered when analyzing network traffic, often in the form of packet capture files. Indicators can be found in source and destination IP addresses, ports, and protocols. These can include:
    • Connections to known malicious IP addresses
    • Unauthorized network scans
    • Unusual spikes or slow downs in network traffic
    • Mismatched port-application traffic
日本語

学習目標 3.5.A: ネットワーク攻撃を検知するために使用される自動化されたセキュリティツールの種類を特定すること。

  • 3.5.A.1 自動化された検知ツールは、組織のネットワークおよびデバイス(スイッチ、ルーター、サーバー、フォアウォール、ユーザーのコンピューターなど)から収集されたデータを分析します。これらのデータは通常、ログファイルとして収集されます。
  • 3.5.A.2 ネットワーク侵入検知システム(NIDS)は、ネットワーク上で悪意のある活動が発生しているかどうかを判定するためにデータを分析する自動化されたツールです。攻撃が検知されると、アラートを生成します。
  • 3.5.A.3 ネットワーク侵入防止システム(NIPS)は、IDSと同様にデータを分析してネットワーク上で悪意のある活動が行われているかどうかを判定する自動化されたツールである。NIPSは、ポートの閉鎖、特定のIPまたはMACアドレスのブロック、特定のプロトコルの拒否などにより、攻撃を軽減または停止することもできる。
  • 3.5.A.4 セキュリティ情報およびイベント管理(SIEM)システムは、ファイアウォール、NIDS/NIPS、デバイスログ、アプリケーションログなど複数のソースからのデータを収集・分析し、サイバー攻撃を示唆するパターンを検出し、潜在的な攻撃が検出されれば警告を発する。セキュリティアナリストは警告を調査し、それが真の脅威に該当するかを決定し、標準的な運用手順に従って警告を解決またはエスカレートさせる。

学習目標 3.5.B: 組織が人工知能(AI)を活用して脅威の検知と対応をどのように強化するか説明する。

  • 3.5.B.1 コンピュータはユーザーが行うすべてのアクションをログに記録する。ファイアウォール、IDS、IPS、その他のネットワークセンサーは、ネットワーク内の様々なポイントを通じて通過するすべてのトラフィックをログに記録する。中規模組織のネットワークでは、毎日数百万、あるいは数千万ものデータポイントがログに蓄積されている。人間によるチームであっても、この膨大なデータを分析することは不可能である。
  • 3.5.B.2 脅威検知チームは、大量のデータを解析し、データのパターンが悪意のあるものか正常なものを分類するためのAIアルゴリズムを作成している。
  • 3.5.B.3 脅威検知のためのAIモデルは確率的計算に基づいており、何かが悪意のあるものである可能性を示すためにパーセンテージを報告する。
  • 3.5.B.4 組織は、どの程度の可能性で警告が発令されるべきかを独自の閾値として決定する。閾値が高すぎると、実際の攻撃が検知されない可能性がある。一方、閾値が低すぎると、セキュリティチームは誤警告に圧倒されてしまう。

学習目標 3.5.C: ネットワーク検知方法を特定する。

  • 3.5.C.1 ネットワークトラフィックの量は、検知方法を選択する基準となる。高トラフィック量のネットワークでは、シグネチャベースの検知の方が効率的である。シグネチャベースの検知は、検知データを既知の侵害指標(IoCs)のデータベースである「シグネチャ」と比較する。シグネチャデータベースには、最新の攻撃に対応したIoCsで更新が必要である。シグネチャベースの検知は、異常検知ベースの検知よりも高速に動作する。
  • 3.5.C.2 ネットワークトラフィックパターンの一貫性は、検知方法を選択する基準となる。一貫性のあるトラフィックパターンを持つネットワークでは、異常検知ベースの検知が最も効果的である。異常検知ベースの検知は、記録された活動のベースラインと比較する。ベースラインは、期待される数据类型と量を設定するために、侵害されていないシステム上で記録される必要がある。指定された許容範囲外の数据类型や量が記録されると、異常検知ベースの検知は警告または行動をトリガーする。異常検知ベースの検知は、ネットワークトラフィックの一貫したパターンを利用して、異常なトラフィックパターンを検知する。
  • 3.5.C.3 ネットワークの敏感さや重要度の程度は、検知方法を選択する基準となる。より敏感または重要なデータやサービスを持つネットワークでは、ハイブリッドアプローチを検討することが多い。ハイブリッド検知は、シグネチャベースと異常検知ベースの両方を組み合わせる。ハイブリッド検知は、どちらか片方の手法 alone を使用する場合よりもコストが高く、また、より多くの警告を生成する。
  • 3.5.C.4 ネットワークにおける新規攻撃の可能性は、検知方法を選択する基準となる。シグネチャベースの検知では、新しい攻撃を検知できない。組織が敵対者がネットワークに対して新たな攻撃を試みる可能性が高いと懸念している場合、ハイブリッド検知のコストが高額すぎる場合は、異常検知ベースの検知が好まれる方法となる。

学習目標 3.5.D: ネットワーク検知方法の影響を評価する。

  • 3.5.D.1 検知速度は、ネットワーク検知方法の影響を評価する要因である。検知速度が速ければ、対応も迅速に行える。シグネチャベースの検知手法は、異常検知ベースの検知手法よりも速い。特に高トラフィック量のネットワークではその差が顕著である。
  • 3.5.D.2 コストは、ネットワーク検知方法の影響を評価する要因である。検知ツールおよび継続的なコストは予算内に収まる必要がある。異常検知ベースのシステムは、シグネチャベースのものよりも高いハードウェアを必要とする。ハイブリッド検知は、異常検知とシグネチャの両方の手法を組み合わせるため、最も高額な選択肢である。
  • 3.5.D.3 偽陽性率(FP rate)は、ネットワーク検知方法の影響を評価する要因である。シグネチャベースの検知にはほぼ偽陽性がない。異常検知ベースまたはハイブリッド検知は、より高い偽陽性率を示す。高い偽陽性率の影響には以下が含まれる:
    • 非悪意の活動に関する警告の調査に時間とリソースが割かれる。
    • アラート疲労とは、対応者が偽陽性に慣れ、警告を真面目に受け付けなくなる状態のことである。これは、調査前に警告が偽陽性であると仮定してしまうためである。
  • 3.5.D.4 偽陰性率(FN rate)は、ネットワーク検知方法の影響を評価する要因である。敵対者が検知システムを回避できた場合に偽陰性が発生する。シグネチャベースの検知システムは、異常検知ベースやハイブリッドシステムよりも容易に回避される。偽陰性は、敵対者によるデータやシステムへの損失、損害、妨害、破壊をもたらす可能性がある。

学習目標 3.5.E: ログファイルを解析することで、ネットワーク攻撃の兆候(IOCs)を特定するために検知技術を適用する。

  • 3.5.E.1 イビル・ツイン攻撃は、局所内の正規のSSIDと似ているか不審なサービスセットID(SSID)を定期的にスキャンすることで検出できます。信号三角測量を用いて、イビル・ツインネットワークをブロードキャストするアクセスポイントの位置を特定し無効化することが可能です。
  • 3.5.E.2 ジャミング攻撃は、特定の物理空間内の無線デバイスが無線ネットワークに接続できないことを認識し、無線範囲内の電磁(EM)ノイズをスキャンすることで検出できます。
  • 3.5.E.3 ARPポイゾニング攻撃は、ネットワークトラフィックを監視して異常なARPメッセージ(特に重複したMACアドレスを持つARPパケット)を検出し、デフォルトゲートウェイのARPテーブルを確認することで検出できます。
  • 3.5.E.4 MACフラッディング攻撃は、ネットワークトラフィックを監視して異なるMACアドレスを持つEthernetフレームの予期せぬ急増を検出し、スイッチ上のMACアドレステーブルを確認することで検出できます。
  • 3.5.E.5 DNSポイゾニング攻撃は検出するのが困難です。しかし、組織のウェブサイトが急激かつ説明のつかないトラフィック減少を経験した場合、DNSレコードを潜在的な原因として確認すべきです。
  • 3.5.E.6 スマーフ攻撃は、ネットワークトラフィックを監視して、ネットワークの广播アドレス宛てに送られたICMPリクエストの急増を観察することで検出できます。
  • 3.5.E.7 ネットワークベースのIoCは、ネットワークトラフィックを分析する際に発見されます。一般的にはパケットキャプチャファイルの形式をとります。インジケーターは、送信元および宛先IPアドレス、ポート、プロトコルに含まれます。これらには以下が含まれます:
    • 既知の悪意のあるIPアドレスへの接続
    • 承認されていないネットワークスキャン
    • ネットワークトラフィックにおける異常なピークや減速
    • ポートとアプリケーションのトラフィックの不一致

Source: College Board AP Course and Exam Description · ⁨出典: College Board AP コースおよび試験説明書⁩

English

When prevention fails, detection takes over. Automated tools read the log files 日志文件 that record network activity:

  • a network intrusion detection system (NIDS) 网络入侵检测系统 analyses traffic and raises an alert, but does not block;
  • a network intrusion prevention system (NIPS) 网络入侵防御系统 can also stop an attack by closing ports or blocking addresses;
  • a security information and event management (SIEM) 安全信息与事件管理 system gathers data from many sources to spot patterns.

There are two detection methods. Signature-based 基于特征 detection compares traffic to a database of known attack signatures - fast and low on false alarms, but blind to brand-new attacks. Anomaly-based 基于异常 detection compares traffic to a normal baseline 基线 and flags anything unusual - it can catch novel attacks but needs more resources and raises more false alarms. A hybrid approach combines both.

Examining captured traffic (packet-capture files), analysts hunt for network-based indicators of compromise 网络入侵指标 in the source and destination IP addresses, ports, and protocols. Four common ones: connections to known-malicious IP addresses, unauthorized network scans (an outsider probing your ports), unusual spikes or slowdowns in traffic, and mismatched port-application traffic (for example, non-web traffic flowing over port 80). These complete the host-, file-, and behaviour-based indicators a single device logs.

AI, thresholds, and alert fatigue

A medium network logs millions of events a day - far more than any team can read - so organisations train AI models to sort likely-malicious patterns from normal ones. These models are probabilistic 概率的: rather than a yes/no, each event gets a percentage likelihood of being malicious.

The organisation then sets a threshold 阈值 - the likelihood at which an alert fires - and that choice is a genuine trade-off:

  • set the threshold too high and real attacks slip through undetected;
  • set it too low and the team is overwhelmed with false alerts.

Too many false alerts cause alert fatigue 警报疲劳: responders get so used to false positives that they start assuming an alert is false before investigating it - so a real attack, when it finally comes, is waved away. This is exactly why a low false-positive rate matters: signature-based detection has almost none, while anomaly-based and hybrid detection trade a higher false-positive rate for the ability to catch novel attacks.

日本語

予防策が機能しない場合、検知が主導権を握ります。自動化されたツールは、ネットワーク活動记录するログファイルを読み取ります:

  • ネットワーク侵入検知システム(NIDS)はトラフィックを分析してアラートを発生させますが、ブロックはしません;
  • ネットワーク侵入防止システム(NIPS)は、ポートを閉じるかアドレスをブロックすることで攻撃を停止できる場合があります;
  • **セキュリティ情報およびイベント管理(SIEM)**システムは、多数のソースからデータを収集してパターンを検出します。

検知には2つの方法があります。シグネチャベースの検知は、トラフィックを既知の攻撃シグネチャのデータベースと比較します。高速で誤警報が少ないですが、全く新しい攻撃には対応できません。アナモロジーベースの検知は、トラフィックを通常ベースラインと比較し、異常なものをフラグ付けします。新たな攻撃を捕捉できますが、リソースが必要で、誤警報が多発します。ハイブリッドアプローチは両方を組み合わせたものです。

捕獲されたトラフィック(パケットキャプチャファイル)を検討する際、分析者は、送信元および宛先IPアドレス、ポート、プロトコルにおけるネットワーク由来の侵害指標を探します。一般的なものとして4つ挙げられます:既知の悪意あるIPアドレスへの接続、未承認のネットワークスキャン(外部からのポート探査)、トラフィックの異常なスパイクや遅延、およびポート-アプリケーション不整合トラフィック(例:非Webトラフィックがポート80を流れる)。これらは、単一デバイスが記録するホスト、ファイル、行動由来の指標を補完します。

AI、閾値、およびアラート疲労

中規模のネットワークは一日あたり数百万のイベントを記録しますが、チームで全てを確認することは不可能であるため、組織はAIモデルを訓練して、可能性のある悪意あるパターンを正常なものから選別します。これらのモデルは確率的であり、Yes/Noではなく、各イベントが悪意あるものである確率をパーセンテージで示します

その後、組織は**閾値(しちち)**を設定します。これは警報が発生する確率の基準であり、この選択には真のトレードオフが含まれます:

  • 閾値を高すぎると、実際の攻撃が検知されずに通過してしまいます;
  • 閾値を低すぎると、チームは過剰な誤警報に圧倒されてしまいます。

誤警報が多すぎると**警報疲労(アラート・フィガティ)**が生じます。対応担当者は誤警報に慣れ親しみ、調査开始前に「警報は誤りだ」と仮定し始めます。そのため、実際に攻撃が発生した際にも、それは無視されてしまいます。このため、低誤警報率が重要である理由です:シグネチャベース检测はほぼ誤警報がありませんが、異常検知やハイブリッド检测は、新しい攻撃を検出できる能力と引き換えに、より高い誤警報率を受け入れています。

シグネチャベース检测は既知の攻撃に一致し、異常検知は通常からの逸脱を警告します
シグネチャベース检测は既知の攻撃に一致し、異常検知は通常からの逸脱を警告します
3.5

Exam tips · ⁨試験対策⁩

English
  • For firewall-ACL questions, read the rules top-to-bottom and stop at the first match - a Deny rule above an Allow blocks the traffic even though the Allow exists lower down.
  • Pair each attack with its tell-tale sign: ARP poisoning = one IP with two MAC addresses; MAC flooding = a surge of new MAC addresses; DNS poisoning = an unexplained drop in web traffic.
  • Read packet captures for network-based IoCs: known-malicious IPs, unauthorized scans, traffic spikes/slowdowns, and mismatched port-application traffic.
  • Run vulnerability scanners to find known weaknesses proactively, and fix the highest-severity findings first.
  • Signature-based = fast, few false positives, misses new attacks (more false negatives); anomaly-based = catches new attacks, costs more, more false positives. Memorise this trade-off.
  • A screened subnet / DMZ holds public-facing servers between the internet and the private network - name it whenever a question separates public services from internal data.
  • WPA3 is the strong wireless encryption; WEP and original WPA are insecure.
日本語
  • ファイアウォールACLに関する問題では、ルールを上から順に読み、最初に一致したところで停止してください。Allowルールの上方にあるDenyルールが存在する場合、下方にAllowルールがあってもトラフィックはブロックされます。
  • 各攻撃にその特徴的な兆候をペアにします:ARPポイズニング = 1つのIPに2つのMACアドレス;MACフラッディング = 新規MACアドレスの急増;DNSポイズニング = 説明のないWebトラフィックの減少。
  • ネットワークベースのIoCについてはパケットキャプチャを確認します:既知の悪意のあるIP、未許可のスキャン、トラフィックのスパイク/減速、ポートとアプリケーションの不一致。
  • 脆弱性スキャナを実行して、既知の欠陥を能動的に見つけ出し、最も深刻度の高い所見を最初に修正してください。
  • シグネチャベース = 高速、誤警報が少ないが、新しい攻撃を見逃す(誤検知率が高い);異常検知 = 新しい攻撃を検出するが、コストが高く、誤警報が多い。このトレードオフを暗記すること。
  • スクリーンドサブネット / DMZ は、インターネットとプライベートネットワークの間に公開サーバーを保持します。質問で公開サービスと内部データが区別されている場合は、必ずこの用語を使用してください。
  • WPA3 は強力なワイヤレス暗号化です。WEP と初期の WPA は不安全です。

Interactive lessons on this topic · ⁨このトピックのインタラクティブ授業⁩

Work through it step by step, with instant-check exercises. · ⁨一歩ずつ進め、即時チェック付きの問題で学習します。⁩

Past Papers · ⁨過去問⁩

More topics in AP Cybersecurity · ⁨AP サイバーセキュリティ⁩ · ⁨AP Cybersecurity · ⁨AP サイバーセキュリティ⁩ の他のトピック⁩

Log in or create account · ⁨ログインまたはアカウント作成⁩

IGCSE, A-Level & AP