Device Vulnerabilities and Attacks · 设备漏洞与攻击
| English | 中文 | Pinyin · 拼音 |
|---|---|---|
| embedded computer/emˈbedɪd kəmˈpjuːtə/ | 嵌入式计算机 | qiàn rù shì jì suàn jī |
| Internet of Things/ˈɪntənet ɒv θɪŋz/ | 物联网 | wù lián wǎng |
| virus/ˈvaɪrəs/ | 病毒 | bìng dú |
| worm/wɜːm/ | 蠕虫 | rú chóng |
| ransomware/ˈrænsəmweə/ | 勒索软件 | lè suǒ ruǎn jiàn |
| remote access trojan/rɪˈməʊt ˈækses ˈtrəʊdʒn/ | 远程访问木马 | yuǎn chéng fǎng wèn mù mǎ |
| unpatched software/ʌnˈpætʃt ˈsɒftweə/ | 未打补丁的软件 | wèi dǎ bǔ dīng de ruǎn jiàn |
Kinds of device
- A device is any computer: server, laptop, phone, or embedded computer 嵌入式计算机.
- Everyday embedded devices are Internet of Things (IoT) 物联网 devices.
- IoT runs everything from water pumps to washing machines.
设备的种类
- 设备是任何计算机:服务器、笔记本电脑、手机或嵌入式计算机(embedded computer)。
- 日常的嵌入式设备是物联网(Internet of Things)设备。
- 物联网运行从水泵到洗衣机的一切。
Types of malware
- A virus 病毒 needs a user to open a file; a worm 蠕虫 spreads by itself.
- Ransomware 勒索软件 encrypts your files for money; a rootkit hides in the OS.
- A remote access trojan (RAT) 远程访问木马 gives remote control.
恶意软件的类型
- 病毒(virus)需要用户打开文件;蠕虫(worm)自己传播。
- 勒索软件(ransomware)加密你的文件以索取钱财;rootkit藏在操作系统里。
- 远程访问木马(remote access trojan)提供远程控制。
Name the malware from its behaviour · 根据其行为命名恶意软件
A worm self-spreads; a virus needs a user; ransomware encrypts for money; a rootkit hides. · 蠕虫自我传播;病毒需要用户;勒索软件加密以索赎金;rootkit隐藏。
Which malware spreads WITHOUT any user action? · 哪种恶意软件无需任何用户操作即可传播?
A worm self-spreads; a virus needs a user. · 蠕虫自我传播;病毒需要用户。
Malware that encrypts your files and demands payment is... · 加密您的文件并要求付款的恶意软件是……
Ransomware encrypts for money. · 勒索软件 加密文件以索赎金。
Software with no recent security update installed is called ____ software. · 未安装近期安全更新的软件被称为____软件。
Unpatched software has open, known holes. · 未打补丁 的软件存在已知的开放性漏洞。
Which malware behaviours match their names? (Choose all) · 哪些恶意软件行为与其名称匹配?(多选)
A worm self-spreads; it does NOT need a user. · 蠕虫自我传播;它不需要用户。
Rating device risk
- Adversaries exploit unpatched software 未打补丁的软件 and weak passwords.
- High: an unpatched server with a critical flaw.
- Low: a laptop with one unused open port.
评定设备风险
- 对手利用未打补丁的软件(unpatched software)和弱密码。
- 高:有严重缺陷的未打补丁服务器。
- 低:有一个未使用的开放端口的笔记本电脑。
Do not confuse a virus with a worm. A virus needs a person to run an infected file; a worm spreads on its own with no human action. The self-spreading is exactly what makes worms so dangerous.
不要混淆病毒和蠕虫。病毒需要人运行受感染的文件;蠕虫自己传播,无需人类行动。这种自我传播正是蠕虫如此危险的原因。
An internet-connected thermostat is an example of an IoT device. · 联网恒温器是物联网设备的示例。
Everyday embedded devices are IoT. · 日常嵌入式设备是IoT。
Ransomware locks a hospital's files and demands payment for the decryption key. Because patient care depends on those files, availability is destroyed — this is why an unpatched hospital server is rated a high risk.
勒索软件锁定一家医院的文件并索要解密密钥的付款。因为病人护理依赖这些文件,可用性被摧毁——这就是为什么未打补丁的医院服务器被评为高风险。
A device is any computer, including IoT. Learn malware by its trait: virus needs a user, worm self-spreads, ransomware encrypts for money, rootkit hides. Rate risk high for an unpatched critical device, low for a low-value one.
设备是任何计算机,包括物联网。按特征学习恶意软件:病毒需要用户,蠕虫自我传播,勒索软件加密索钱,rootkit隐藏。未打补丁的关键设备评为高风险,低价值的评为低。