Cyber Foundations · 网络安全基础
| English | 中文 | Pinyin · 拼音 |
|---|---|---|
| confidentiality/ˌkɒnfɪˌdenʃiˈæləti/ | 保密性 | bǎo mì xìng |
| integrity/ɪnˈteɡrɪti/ | 完整性 | wán zhěng xìng |
| availability/əˌveɪləˈbɪlɪti/ | 可用性 | kě yòng xìng |
| risk/rɪsk/ | 风险 | fēng xiǎn |
| threat/θret/ | 威胁 | wēi xié |
| vulnerability/ˌvʌlnərəˈbɪlɪti/ | 漏洞 | lòu dòng |
| asset/ˈæset/ | 资产 | zī chǎn |
| likelihood/ˈlaɪklihʊd/ | 可能性 | kě néng xìng |
| severity/səˈverɪti/ | 严重性 | yán zhòng xìng |
| script kiddie/skrɪpt ˈkɪdi/ | 脚本小子 | jiǎo běn xiǎo zi |
| hacktivist/ˈhæktɪvɪst/ | 黑客活动分子 | hēi kè huó dòng fèn zǐ |
| insider/ɪnˈsaɪdə/ | 内部人员 | nèi bù rén yuán |
| cyberterrorist/ˈsaɪbəterərɪst/ | 网络恐怖分子 | wǎng luò kǒng bù fèn zi |
| reconnaissance/rɪˈkɒnɪsəns/ | 侦察 | zhēn chá |
| lateral movement/ˈlætərəl ˈmuːvmənt/ | 横向移动 | héng xiàng yí dòng |
| physical/ˈfɪzɪkl/ | 物理 | wù lǐ |
| technical/ˈteknɪkl/ | 技术 | jì shù |
| managerial/ˌmænəˈdʒɪərɪəl/ | 管理 | guǎn lǐ |
| preventative/prɪˈventətɪv/ | 预防性 | yù fáng xìng |
| detective/dɪˈtektɪv/ | 检测性 | jiǎn cè xìng |
| corrective/kəˈrektɪv/ | 纠正性 | jiū zhèng xìng |
| defense in depth/dɪˈfens ɪn depθ/ | 纵深防御 | zòng shēn fáng yù |
The CIA triad
- Confidentiality 保密性: only authorised people can read the data.
- Integrity 完整性: the data is accurate and unaltered.
- Availability 可用性: it is there when needed.
CIA三要素
- 保密性(confidentiality):只有授权的人能读取数据。
- 完整性(integrity):数据准确且未被更改。
- 可用性(availability):需要时它就在那里。
What risk is
- A risk 风险 appears when a threat 威胁 exploits a vulnerability 漏洞 to harm an asset 资产.
- We assess it by likelihood 可能性 and severity 严重性.
- Four responses: avoid, transfer, mitigate, or accept the residual risk.
什么是风险
- 当威胁(threat)利用漏洞(vulnerability)危害资产(asset)时,就出现风险(risk)。
- 我们用可能性(likelihood)和严重性(severity)来评估它。
- 四种应对:规避、转移、缓解或接受剩余风险。
Which CIA goal does the control protect? · 该控制措施保护哪个 CIA 目标?
Encryption protects confidentiality; a hash checks integrity; a backup restores availability. · 加密保护机密性;哈希校验完整性;备份恢复可用性。
Encrypting data mainly protects which CIA goal? · 加密数据主要保护哪个 CIA 目标?
Encryption hides data = confidentiality. · 隐藏数据 = 机密性。
A risk exists when a threat exploits a ____ to harm an asset. · 当威胁利用____损害资产时,就存在风险。
A vulnerability is the weakness a threat uses. · 漏洞是威胁利用的弱点。
Who attacks, and how
- A script kiddie 脚本小子 reuses others' tools; a hacktivist 黑客活动分子 acts for a cause.
- An insider 内部人员 already has access; a cyberterrorist 网络恐怖分子 hits infrastructure.
- Attacks move in phases: reconnaissance 侦察, access, persistence, lateral movement 横向移动, action.
谁在攻击,如何攻击
- 脚本小子(script kiddie)重用他人的工具;黑客活动分子(hacktivist)为某种事业行动。
- 内部人员(insider)已经拥有访问权;网络恐怖分子(cyberterrorist)攻击基础设施。
- 攻击分阶段进行:侦察(reconnaissance)、获取访问、维持、横向移动(lateral movement)、采取行动。
An attacker who copies code from online tutorials and reuses others' tools is a... · 一个从在线教程复制代码并重复使用他人工具的攻击者是……
Low skill + reused tools = a script kiddie. · 低技能 + 重复使用的工具 = 脚本小子。
Types and layers of control
- By type: physical 物理, technical 技术, managerial 管理.
- By function: preventative 预防性, detective 检测性, corrective 纠正性.
- Defense in depth 纵深防御 layers many controls so one breach is not enough.
控制的类型与分层
- 按类型:物理(physical)、技术(technical)、管理(managerial)。
- 按功能:预防性(preventative)、检测性(detective)、纠正性(corrective)。
- 纵深防御(defense in depth)分层部署多个控制,使单次突破不足以得手。
Defense in depth means using a single very strong control. · 纵深防御意味着使用单一非常强大的控制措施。
It means layering many controls, not one. · 这意味着分层部署多个控制措施,而非单一措施。
The leftover risk an organisation lives with after mitigation is ____ risk. · 组织在缓解后仍承担遗留的风险是____风险。
Residual risk remains after avoid/transfer/mitigate. · 剩余风险是在规避/转移/缓解之后残留的。
Match each control to its function. · 将每个控制措施与其功能匹配。
Function = what the control does. · 功能 = 控制措施所起的作用。
Do not confuse the two ways of grouping controls. Type answers "where does it work?" (physical/technical/managerial). Function answers "what does it do?" (prevent/detect/correct). A camera is a physical control by type and a detective control by function.
不要混淆两种给控制分组的方式。类型回答"它在哪里起作用?"(物理/技术/管理)。功能回答"它做什么?"(预防/检测/纠正)。摄像头按类型是物理控制,按功能是检测控制。
A hospital encrypts patient records (confidentiality), uses file hashes to catch tampering (integrity), and keeps backups so care continues after an outage (availability). One system, all three CIA goals.
一家医院加密病历(保密性),用文件散列捕捉篡改(完整性),并保留备份使停机后护理得以继续(可用性)。一个系统,三个CIA目标全都覆盖。
The CIA triad (confidentiality, integrity, availability) names security's goals. A risk = threat × vulnerability × asset, assessed by likelihood and severity. Controls are grouped by type and function, and layered as defense in depth.
CIA三要素(保密性、完整性、可用性)命名了安全的目标。风险=威胁×漏洞×资产,用可能性和严重性评估。控制按类型和功能分组,并以纵深防御分层。