Английский для студентов, изучающих информационную безопасность. Учебное пособие
.pdf4.What do you need to send an email?
a)An email address and a phone number
b)An email address and an internet connection
c)A physical address and a phone number
d)A physical address and an internet connection
5.Where can you create an email account for free?
a)On various websites such as Gmail, Yahoo, or Outlook
b)At the post office
c)At the library
d)At the bank
6.What are the three parts of an email?
a)Header, body, and footer
b)Header, body, and attachment
c)Attachment, body, and footer
d)Header, attachment, and footer
7.What is one advantage of email when it comes to sharing informa-
tion?
a)You can only share text
b)You can't attach files
c)You can attach files
d)You can only share information with people in your immediate area
8. What should you be careful of when opening attachments from unknown sources?
a)They may contain viruses or malware
b)They may contain important information
c)They may be too large to download
d)They may be irrelevant to the email
2. Say whether thesentences are true or false. Correct the falseones.
1.The internet has not revolutionized the way we communicate, work, and access information.
2.Email is a slow and inconvenient way of communicating with others.
3.You need an email address and a phone number to send an email.
4.You can only create an email account on Gmail.
5.The body of an email is where you write your message.
6.The footer of an email contains the recipient's email address.
7.You cannot attach files to an email.
8.It's safe to open attachments from unknown sources.
9.Email is a fast and convenient way of staying in touch with others.
10.Email is difficult to use even if you understand the basics.
51
3. Here are some communicative situations. Read them and make up situations of your own.
1. Lily: «Did you receive my email about the project?»
Tom: «Yes, I did. I haven't had a chance to read it yet though».
2.Amy: «I can't find the important email from my boss in my inbox». Jack: «Did you check your spam folder? It might be there».
3.Sophie: «I got an email with an attachment, but I can't open it». Mike: «You might need to download the software to open it. I can help
you with that».
4. Ben: «I need to upload some files to send to my professor».
Emily: «You can do that through the school's online portal. It's pretty simple to use».
5. Max: «I'm trying to find information about a topic. Which search engine do you recommend».
Olivia: «Google is the most popular one. Just type in your keywords and hit search».
4. Read the sentences and try to guess whether they are considered as advantages or disadvantages of using the email. What else can you add to the list.
1.It helps you stay connected with people who are far away 2.Cyberbullying and online harassment can happen. 3.Some websites may be inappropriate or unsafe for children 4.You can learn new things online
5.Spending too much time online can be bad for your eyes and health 6.Email is a fast way to communicate with people
7.You can find answers to questions on the internet 8.You can get information quickly and easily 9.People can share false information online 10.Addiction to the internet is possible
III. GRAMMAR IN CONTEXT
1. Complete the following sentences according to the rules of the Sequence of Tenses:
1.By the time I ___ (arrive) at the office, the software ___ (already re-
lease).
2.After the developer ___ (fix) the bug, she ___ (test) it thoroughly.
3.I ___ (start) learning coding last year and I ___ (already master) several programming languages.
4.Oncethesystem___(go) live,we___(monitor) itcloselyforanyissues.
52
5.The project manager ___ (inform) the team that the deadline ___ (be) moved to the following week.
6.If the database ___ (crash), we ___ (lose) all the data.
7.The company ___ (hire) a new IT manager next month to oversee the IT department.
8.Our team ___ (spend) hours debugging the code before we ___ (finally find) the error.
9.By the time the server ___ (restart), all the users ___ (log) out.
10.If the network ___ (fail), we ___ (not be able to) access the internet.
2. Rewrite the sentences using the Reported Speech
1."I will fix the bug later," the IT instructor claimed
2."We have completed the coding for the new software," she stated. 3."They are going to launch the website next week," the manager said. 4."I can't attend the meeting on Friday," the IT manager refused. 5."We are working on improving the user interface," they answered. 6.Peter persuaded, "I am currently updating the server software." 7.IT specialist claimed, "I have just finished debugging the program." 8.Tom said, "We are developing a new mobile application."
9.Anna promised, "I will send you the report by email."
10.Mark said, "We are planning to implement a new security measure."
3. Change the Reported speech into Direct
1.The IT specialist said that the software update was ready and the development team had already completed the testing phase.
2.The IT support team mentioned that they had begun troubleshooting the issue immediately when the network outage occurred.
3.The IT security team reported that they had implemented additional security measures after the cybersecurity breach was discovered.
4.The IT infrastructure team stated that they would configure the new server for optimal performance once it was installed.
5.The IT project manager informed that they had already created a detailed plan for the data migration before it started.
4. READING EXERCISES
1.Make a summary of the text
2.Rewrite the highlighted sentences using the reported Speech
Example: Usually the caller will be led to believe that there's a virus on
their computer. – The IT Specialst told me that the caller would be led to believe that there was a virus on their computer.
53
Types of Social Engineering
Social engineering is a term used to describe the various ways that criminals trick people into revealing their personal information, such as passwords and credit card numbers. They can do this by pretending to be someone else or by creating a sense of urgency. Here are some common types of social engineering attacks:
1. Phishing: In a phishing attack, the criminal sends an email that appears to come from a reputable company, such as a bank or an online retailer.
The email usually asks the recipient to click on a link and enter their personal information. However, the link takes them to a fake website, where the criminal collects their information.
2.Spear phishing: This is a more targeted version of phishing. The criminal researches their victim in advance and then sends them a personalized email that appears to come from someone they know, such as a coworker or a friend. The goal is still to trick the recipient into revealing their personal information.
3.Baiting: Baiting attacks involve offering the victim something in exchange for their personal information. For example, the criminal might leave a USB drive somewhere that the victim is likely to find it, such as a coffee shop. If the victim picks up the USB drive and plugs it into their computer, malware is installed that allows the criminal to access their personal information.
To protect yourself from social engineering attacks, it's important to be cautious and skeptical. Never give out your personal information unless
you're absolutely sure who you're dealing with, and never click on links in emails or download files from unknown sources.
3. Use one of the following topics to write an essay.
1.Email is a better way to communicate than talking on the phone. Do you agree?
2.The internet is full of information, but not all of it is true. What do you think?
3.Some people believe that social media is a waste of time. Do you agree or disagree?
4.The internet has changed the way we live our lives. Is this change positive or negative?
5.More and more people today are using the internet for shopping. Is this trend good or bad?
54
UNIT 8
Vishing and Smishing Scams
Vishing and smishing attacks are becoming increasingly sophisticated, and it's important for individuals to stay informed and educated about the latest threats.
Raj Samani
Before you read.
1.Read the quote above and say whether you agree or not with it. Prove your point of view.
2.Discuss the questions. Give reasons for your answers.
1.Have you ever received a phone call from someone claiming to be
from a well-known computer company? What would you do if you received a call like this?
2.Have you ever received a text message asking you to confirm your personal details?
3.Why do scammers use vishing and smishing techniques instead of just sending an email?
4.What are some common tactics used by scammers in vishing and smishing attacks?
5.Can you think of any ways to protect yourself from these types of
scams?
6.How important is it to stay vigilant against these types of scams in today's digital age?
Vocabulary vishing – фишинг по телефону
voice phishing – фишинг, угроза, исходящая от электронных писем social engineering attack ['səuʃ(ə)l ˌenʤɪ'nɪərɪŋ ə'tæk] – атака соци-
альной инженерии
vulnerability [ˌvʌln(ə)rə'bɪlətɪ] – уязвимость victim ['vɪktɪm] – жертва
remote connection – удаленноеподключение script [skrɪpt] – скрипт
сonfuse [kən'fjuːz] – сбивать с толку, смущать baffle ['bæfl] – дефлектор, сбивать с толку keylogger – кейлоггер, клавиатурный шпион username and password – имя пользователя и пароль
55
steal [stiːl] – воровать scam [skæm] – афера
fraud [frɔːd] – мошенничество legitimate [lɪ'ʤɪtəmət] – законный
confirmation [ˌkɔnfə'meɪʃ(ə)n] – подтверждение link – cсылка
keystroke [ki͟ ːstroʊk] – нажатие клавиш delivery [dɪ'lɪv(ə)rɪ] – доставка baiting techniques – приемы травли
remain vigilant [rɪ'meɪn 'vɪʤɪlənt] – сохранять бдительность be savvy ['sævɪ] – быть сообразительным
3. Read the text thoroughly and find the appropriate title to it.
***
Vishing is voice phishing, using a telephone call to commit some form of social engineering attack. The victim will, as we've explained previously, receive a call from a legitimate sounding call centre with the person on the line claiming to be from a well-known computer related comparty. Usually the caller will be led to believe that there's a virus on their computer or that some form of security vulnerability has been detected. The victim will then be guided to a website where the caller can make a remote connection to their computer. Once on the victim's computer, the caller will then run a script that will display reams of data on the screen designed to confuse and baffle the victim, in the meantime, they're secretly running a keylogger in the background.
In some circumstances they can then claim to have fixed the so called issue but ask you to log into your bank to double-check all is well. With a keylogger in place, they can then see your username and password on their screen; after which they log in and steal from your account
Alteratively an automated call can ask you to enter your credit card number into the phone's keypad, as it's been reported as being used elsewhere. Of course it hasn't but as soon as you enter the details they're recorded and your card can be used by the scammers,
Smishing is an SMS form of phishing In these cases you receive a text from a seemingly legitimate source, usually your bank or credit card company but also in the form of a competition winner or something free, asking you to confirm your details. There's often a link for you to follow, which leads to a false website that logs your keystrokes and records your data.
56
Some smishing attacks will ask you to send a retum SMS to approve an action, such as a delivery of some goods. The return message is designed to cost significantly more than the usual SMS rate, with the money going straight to the scammers.
One way or another, each of these scams are designed to bait the victim, hence the phishing element, a homophone of the word fishing. The best defence is to ignore, delete or hang up on anything that's even remotely suspicious. Microsoft doesn't know if you have a virus, and nor will it telephone you. Your bank won't email you for your account details and don't be tempted to fill in any Facebook games with personal information. In short, be savvy about baiting techniques and remain vigilant.
4. Choose the appropriate title to the text:
1.Vishing and Smishing Scams: How to Recognize and Avoid Them
2.The Benefits of Keyloggers for Remote Computer Support
3.Understanding the Phonetics of Social Engineering
I. ELICITING THE VOCABULARY
1.Fill in the gaps using the words from the box.
legitimate source, voice phishing, smishing, |
security vulnerability, |
keylogger, remote connection, baiting techniques, |
username and pass- |
word |
|
Vishing is _____(1), using a telephone call to commit some form of social engineering attack. Usually the caller will be led to believe that there's a virus on their computer or that some form of _____(2) has been detected. The victim will then be guided to a website where the caller can make a
_____(3) to their computer. With a _____(4) in place, they can then see your _____(5) on their screen; after which they log in and steal from your account
_____(6) is an SMS form of phishing In these cases you receive a text from a seemingly _____(7), usually your bank or credit card company but also in the form of a competition winner or something free, asking you to confirm your details.
In short, be savvy about _____(8) and remain vigilant.
57
2.Match the words and expressions with their definitions.
|
|
|
|
1) |
remain vigilant |
a) |
A dishonest scheme or fraud, often involv- |
|
|
ing the theft of money or personal information |
|
2) |
details |
b) |
wrongful or criminal deception intended to |
|
|
result in financial or personal gain |
|
3) |
delivery |
c) |
The fraudulent practice of sending emails or |
|
|
messages purporting to be from reputable com- |
|
|
|
panies in order to induce individuals to reveal |
|
|
|
personal information, such as passwords and |
|
|
|
credit card numbers |
|
4) |
baiting techniques |
d) |
Conforming to the law or rules; genuine or |
|
|
valid |
|
5) |
phishing |
e) |
The action of verifying or validating some- |
|
|
thing, often by receiving official approval or |
|
|
|
proof |
|
6) |
return sms |
f) |
Specific pieces of information about a par- |
|
|
ticular subject or situation |
|
7) |
confirmation |
g) |
A clickable connection between two web |
|
|
pages or documents that takes you from one to |
|
|
|
the other |
|
8) |
be savvy |
h) |
A text message sent back to the original |
|
|
sender in response to an initial message or re- |
|
|
|
quest |
|
9) |
legitimate |
i) |
The process of transporting goods or items |
|
|
from one place to another |
|
10)link |
j) |
To stay alert and watchful, especially in sit- |
|
|
|
uations where there may be potential danger or |
|
|
|
risk |
|
11)fraud |
k) |
To have practical knowledge and under- |
|
|
|
standing of a particular subject or situation, of- |
|
|
|
ten used in reference to technology or business |
|
|
|
practices |
|
II. COMPREHENSION
1. Read the text again and choose the right answers to the questions.
1. What is vishing?
a)A form of phishing through SMS
b)A form of phishing through voice calls
c)A form of phishing through email
58
d) A form of phishing through social media
2. What is the purpose of a vishing call? a) To ask for personal information
b) To sell a product
c) To fix a computer virus
d) To commit a social engineering attack
3. How does a vishing call work?
a) The caller will ask for personal information b) The caller will guide the victim to a website
c) The caller will fix a virus on the victim's computer d) The caller will sell a product
4. What is a keylogger?
a) A tool to fix computer viruses
b) A tool to display data on the screen c) A tool to record keystrokes
d) A tool to confuse and baffle the victim
5. What is smishing?
a) A form of phishing through voice calls b) A form of phishing through email
c) A form of phishing through social media d) A form of phishing through SMS
6. How do smishing attacks work?
a) By asking you to send a return SMS to approve an action b) By sending you a text from a seemingly legitimate source c) By asking you to confirm your details on a false website d) All of the above
7. What is the purpose of a smishing attack? a) To bait the victim
b) To sell a product
c) To fix a computer virus
d) To commit a social engineering attack
8. What is the best defense against phishing attacks?
a) Ignoring, deleting, or hanging up on anything that's remotely suspicious
b) Entering personal information into Facebook games
c) Responding to automated calls asking for credit card information d) Logging into your bank account when asked to do so by a caller
9. What is the meaning of the word «phishing»? a) A homophone of the word fishing
b) A tool to fix computerviruses
59
c)A tool to display data on the screen
d)A tool to record keystrokes
2. Discuss the situation and give your advice how to keep your personal information safe.
Detective Jones: Ma'am, can you tell me what happened?
Ms. Smith: Yes, I received a call from someone claiming to be from my bank, saying there was some suspicious activity on my account.
Detective Jones: And did they ask for any personal information or passwords?
Ms. Smith: Yes, they asked for my account number and password…and foolishly, I gave it to them.
Detective Jones: Okay. Did they do anything else during the call?
Ms. Smith: Yes, they asked me to verify some recent transactions and directed me to a website where they could remotely access my computer.
Detective Jones: And did you let them?
Ms. Smith: Unfortunately, yes. They said they were fixing the problem, but then later I found out that £1000 had been taken from my account.
Detective Jones: I see. Do you have any idea who these scammers might be?
Ms. Smith: No, not really. It sounded like an official call centre. Detective Jones: These criminals are becoming more sophisticated by
the day. Have you heard of vishing or smishing before? It sounds like one of these scams.
Ms. Smith: No, I haven't. What are those?
Detective Jones: Vishing is when scammers use voice calls to commit social engineering attacks, while smishing uses text messages to trick people into giving away their personal information.
Ms. Smith: Oh, that's terrible. How can we protect ourselves from these scams?
Detective Jones: The best defence is to ignore any unsolicited calls or messages, especially if they're asking for personal details. Don't click on links or download files from unknown sources either.
Ms. Smith: Thank you for your advice, Detective.
Detective Jones: You're welcome. We'll investigate this matter further and try to catch those responsible. In the meantime, please be extra vigilant with your bank transactions and report any suspicious activity to them immediately.
60
