Добавил:
Опубликованный материал нарушает ваши авторские права? Сообщите нам.
Вуз: Предмет: Файл:

ENGLISH FOR IT. Учебное пособие

.pdf
Скачиваний:
0
Добавлен:
07.09.2026
Размер:
2 Мб
Скачать
Unit 10. Information Security
151
This means a cyber criminal can gain unauthorized access to the sensitive data without effort.
Data exfiltration [ˈdeɪ.təˈɛksfɪlˌtreɪʃən] occurs when malware and/or a ma- licious actor carries out an unauthorized data transfer from a computer. It is also commonly called data extrusion or data exportation. Data exfiltration is also con­sidered a form of data theft.
Vulnerability (n) [ˌvʌl.nər.əˈbɪl.ə.ti] a weakness that can be exploited by cybercriminals to gain unauthorized access to a computer system.
Credentials (n) [krɪˈden·ʃəlz] refer to the verification of identity or tools for authentication. They help confirm a user’s identity.
Cyber threat (n) [ˈsaɪ.bɚθret] − an activity intended to compromise the se- curity of an information system by altering the availability, integrity, or confiden­tiality of a system or the information it contains, or to disrupt digital life in general.
Cyberattack (n) [ˈsaɪ.bə.rəˌtæk] an illegal attempt to harm someone's computer system or the information on it, using the internet.
Man-in-the-middle attack a cyberattack where the attacker secretly re- lays and possibly alters the communications between two parties who believe that they are directly communicating with each other, as the attacker has inserted themselves between the two parties.
Malware (n) [ˈmæl.weər ] (short for “malicious software”) − a catch-all term to refer to any software designed to cause damage to a single computer, server, or computer network.
Ransomware (n) [ˈræn.səm.weər] a type of malware that encrypts your hard drive's files and demands a payment, usually in Bitcoin, in exchange for the decryption key.
Adware (n) [ˈæd.weər] malware that forces your browser to redirect to web advertisements, which often themselves seek to download further, even more malicious software.
Worm (n) [wɜːm] − a standalone piece of malicious software that repro- duces itself and spreads from computer to computer.
Virus (n) [ˈvaɪə.rəs] − a piece of computer code that inserts itself within the code of another standalone program, then forces that program to take malicious action and spread itself.
Trojan (n) [ˌtrəʊ.dʒən] a program that cannot reproduce itself but mas- querades as something the user wants and tricks them into activating it so it can do its damage and spread.
Unit 10. Information Security
152
Rootkit (n) [ˈruːtˌkɪt] a program or, more often, a collection of software tools that gives a threat actor remote access to and control over a computer or other system.
Distributed Denial of Service [dɪˈstrɪb.juːtɪd dɪˌnaɪ.əl əv ˈsɜː.vɪs] (DDoS). In a DDoS attack, the attacker sends an overwhelming number of fake requests to a server, preventing it from being used by legitimate end users.
Nonrepudiation (n) [ˌnɒn rɪˌpjuː.diˈeɪ.ʃən] means one party cannot deny receiving a message or a transaction nor can the other party deny sending a mes­sage or a transaction.
Authentication (n) [ɔːˌθen.tɪˈkeɪ.ʃən] means confirming that a user is who they say they are. Authentication is part of a three-step process for gaining access to digital resources:
Identification (n) [aɪˌden.tɪ.fɪˈkeɪ.ʃən] Who are you?
Authentication (n) Prove it.
Authorization (n) [ˌɔː.θər.aɪˈzeɪ.ʃən] Do you have permission?
Multi-factor authentication [ˌmʌl.tiˈfæk.tər] this security mechanism re-
quires users to provide information (a PIN or biometric, for example) in addition
Prevent (v) [prɪˈvent] to stop something from happening.
Relay (v) [ˌrɪˈleɪ] receive and pass on (information or a message).
Intercept (v) [ˌɪn.təˈsept] to stop and catch something or someone before
that thing or person is able to reach a particular place.
Eavesdrop (v) [ˈiːvz.drɒp] to listen to someone's private conversation without them knowing.
Alter (v) [ˈɒl.tər] to change something, usually slightly.
Damage (v) [ˈdæm.ɪdʒ] to harm or spoil something.
Infect (v) [ɪnˈfekt] to damage a computer's software or data with a harmful
program that has been passed from another computer.
Disclose (v) [dɪˈskləʊz] to make something known publicly, or to show something that was hidden.
Compromise (v) [ˈkɒm.prə.maɪz] to risk having a harmful effect on something.
Disrupt (v) [dɪsˈrʌpt] to throw into confusion or disorder.
4. Think about the Russian equivalents of the terms given above.
5. Match the following definitions with the terms.
Unit 10. Information Security
153
DEFINITIONS
TERMS
1
A security incident that involves the exposure, loss, theft, destruction, or alteration of personal information either intentional or accidental.
rootkit
2
The act of stealing digital information stored on comput­ers, servers, or electronic devices to obtain confidential in­formation or compromise privacy.
cyber threat
3
When malware and/or a malicious actor carries out an un­authorized data transfer from a computer.
vulnerability
4
A weakness that can be exploited by cybercriminals to gain unauthorized access to a computer system.
data breach
5
Verification of identity or tools for authentication, they help confirm a user’s identity.
authentication
6
An activity intended to compromise the security of an in­formation system by altering the availability, integrity, or confidentiality of a system or the information it contains, or to disrupt digital life in general.
data exfiltration
7
An illegal attempt to harm someone's computer system or the information on it, using the internet.
cyberattack
8
A catch-all term to refer to any software designed to cause damage to a single computer, server, or computer net­work.
malware
9
Program or, more often, a collection of software tools that gives a threat actor remote access to and control over a computer or other system.
credentials
10
Means one party cannot deny receiving a message or a transaction nor can the other party deny sending a mes­sage or a transaction.
disrupt
11
Confirming that a user is who they say they are
nonrepudiation
12
To stop and catch something or someone before that thing or person is able to reach a particular place.
intercept
13
To listen to someone's private conversation without them knowing.
damage 14
To harm or spoil something.
infect
15
To damage a computer's software or data with a harmful program that has been passed from another computer.
relay 16
To throw into confusion or disorder.
eavesdrop
17
Receive and pass on (information or a message).
data theft
Unit 10. Information Security
154
6. Match the words in A with their synonyms in B.
A B
1
weakness
a
harm
2
alter b exportation
3
damage
c
protect
4
exfiltration
d
permission
5
authentication
e
reveal
6
reproduce
f
stop
7
prevent
g
fraud
8
disclose
h
modify
9
authorization
i
replicate
10
secure
j
endanger
11
jeopardize
k
legal
12
legitimate
l
vulnerability
13
scam
m
confirmation
7. Read the definition and write the term.
DEFINITIONS
TERMS
1
A catch-all term to refer to any software designed to cause damage to a single computer, server, or computer network (7 letters).
_ _ _ _ _ _ _
2
A standalone piece of malicious software that reproduces itself and spreads from computer to computer (4).
_ _ _ _
3
A piece of computer code that inserts itself within the code of another standalone program, then forces that pro­gram to take malicious action and spread itself (5).
_ _ _ _ _
4
A program that cannot reproduce itself but masquerades as something the user wants and tricks them into activat­ing it so it can do its damage and spread (6).
_ _ _ _ _ _
5
To harm or spoil something (6).
_ _ _ _ _ _
6
To damage a computer's software or data with a harmful program that has been passed from another computer (6).
_ _ _ _ _ _
7
To make something known publicly, or to show some­thing that was hidden (8).
_ _ _ _ _ _ _ _
8
To risk having a harmful effect on something (10).
_ _ _ _ _ _ _ _ _ _
9
An incident where data is destroyed, deleted, or made un­readable by users and software applications (4, 4).
_ _ _ _ _ _ _ _
Unit 10. Information Security
155
DEFINITIONS
TERMS
10
When sensitive data is accidentally exposed physically, on the Internet or any other form including lost hard drives or laptops (4, 4).
_ _ _ _ _ _ _ _ 11
It means information is not disclosed to unauthorized indi­viduals (15).
_ _ _ _ _ _ _ _ _ _ _ _ _ _ _
12
It means maintaining accuracy and completeness of data (9).
_ _ _ _ _ _ _ _ _
13
It means information must be available when needed (12).
_ _ _ _ _ _ _ _ _
14
Information that needs protecting against unauthorized ac­cess to minimize possible harm to individuals and busi­nesses (9, 4).
_ _ _ _ _ _ _ _ _ _ _ _ _
15
Translating data into another form, or code, so that only people with access to a decryption key or password can read it (4, 10).
_ _ _ _ _ _ _ _ _ _ _ _ _
USEFUL GRAMMAR
Grammar to study: Adjectives. Adverbs. Comparatives and Superlatives.
Participial adjectives
8. Choose the correct option.
1. Threats are _____ delivered by email.
a) most common b) most commonly c) more common
2. Malware is an ever-evolving threat and cybercriminals are getting _____
creative to breach your business.
a) more and more b) the most c) much less
3. By combining the likelihood with impact, you can identify threats that
are _____ to your organization and ensure you are protected.
a) significantly b) significant c) more significantly
4. These types of cyber risks continue to grow in complexity, but under-
standing them is _____ way to _____ defend your networks and systems.
a) better, the best b) the best, well c) the best, better
5. Spear phishing threats are often _____ than random phishing threats due
to the victim(s) being specifically targeted by the cybercriminal.
a) more successful b) more successfully c) less successfully
6. The delivery of ransomware via email is one of _____ of all current phish-
ing threats.
a) the most seriously b) more serious c) the most serious
Unit 10. Information Security
156
7. Being able to _____ identify which reports are more reliable than others
is critical to lessening the chance of a breach from a phishing email.
a) quickly b) quick c) quicker
8. Hackers can also modify or misuse legitimate software to _____ access a
device.
a) remote b) remotely
9. Malware short for "malicious software" − is any software code or com-
puter program written _____ to harm a computer system or its users.
a) intentionally b) intentional
10. The most basic ransomware attacks render assets unusable until the ran­som is paid, but cybercriminals may use _____ tactics to increase the pressure on victims.
a) additional b) additionally
11. Mirai, one of _____ botnets, was responsible for a massive 2016 attack against the Domain Name System provider Dyn.
a) more well-known b) the most well-known c) much more well-known
12. While some worms do nothing _____ than spread, many have _____ consequences.
a) more, more severe b) much, more severe c) more, as severe as
13. Cryptojacking is a type of cybercrime where a criminal _____ uses a victim’s computing power to generate cryptocurrency.
a) secret b) secretly
14. One of _____, and therefore one of _____, types of malware amongst cybercriminals is ransomware.
a) the more profitable, the more popular b) the most profitable,
the most popular c) much more profitable, much more popular
15. _____ of these common symptoms you see, _____ the likelihood your computer has a malware infection.
a) The most, the highest b) More, than higher c) The more, the higher
9. Choose the correct adverb to complete the sentence.
Increasingly, intentionally, usually, interchangeably, necessarily,
automatically, easily, widely, theoretically, mostly, just, unintentionally,
always, ideally, negatively, exactly, constantly, accidentally
1. As a result, authentication has become an _____ important mitigation strategy to reduce risk and protect sensitive data.
Unit 10. Information Security
157
2. Hacking does not _____ count as a cybercrime; as such, not all hackers
are cybercriminals.
3. Much of the evidence in cybercrime cases is digital, which is intangible,
fragile, and _____ destroyed.
4. Phishing, ransomware and data breaches are _____ a few examples of
current cyberthreats, while new types of cybercrime are emerging all the time.
5. Malware is _____ distributed through malicious websites, emails, and
software.
6. Users can _____ install malware when they click on a link in a phi-
shing email.
7. Hackers and cybercriminals aren’t the same. Pop culture and media have
popularized using the terms _____, which has led to many people _____ using the wrong word.
8. There’s not a strong consensus on how _____ to refer to the good hackers,
and it varies from company to company, but one thing is clear: a hacker isn’t _____ a malicious person, so we shouldn’t use the term _____.
9. _____, organizations should have complete control over all applications
used by employees to conduct business.
10. Cybercriminals are _____ available in what is called the “Dark Web”
where they _____ provide their illegal services or products.
11. The world is _____ developing new technologies, so now, it has a big
reliance on technology.
12. Malware is software code written _____ to harm a computer system or its
users.
13. Worms are self-replicating programs that _____ spread to apps and de-
vices without human interaction.
14. Many password attacks use social engineering to trick victims into unwit-
tingly sharing this sensitive data.
15. Knowledge factors are pieces of information that, _____, only the user
would know, such as passwords, PINs and answers to security questions.
10. Choose the correct participial adjective to complete the sentence.
1. While similar to spear-phishing, whale phishing or executive phishing is
much more personalized / personalizing to the target and damaged / damaging to the company.
2. Smishing is a form of cyber-attack that involves sending malicious dis-
guised / disguising messages.
Unit 10. Information Security
158
3. A remote access Trojan or "RAT" creates a secret backdoor on the in- fected / infecting device.
4. Just as fighter pilots train in flight simulators, users can learn by expe- riencing a simulated / simulating phishing threat in a controlled /controlling environment.
5. Using a tactic called "baiting," hackers may place infected / infecting USB drives adorned with attention-grabbing labels in public places like coworking spaces or coffee shops. Enticed by these drives, unsuspected / unsuspecting users may plug them into their devices to see what they contain and the malware infects their system.
6. Large botnets can include millions of devices and can launch attacks at devastated / devastating scale.
7. To establish an integrated / integrating risk management program within your organization, you must first conduct a risk assessment.
8. Risk evaluation determines the significance of the identified / identifying risks by comparing the level of risk to the organization’s risk tolerance.
9. Occurring after the discovery of a “zero-day vulnerability,” an exploit is a targeted / targeting attack against a system, network, or software.
10. Cryptojacking is an attempt to install malware which forces the infected /
infecting system to perform “crypto-mining,” a popular form of gaining cry- pto-currency.
11. Cybercriminals are known to access the cybercriminal underground mar-
kets found in the deep web to trade malicious goods and services, such as hacked / hacking tools and stolen / stealing data.
SPECIALIST READING
11. Read the text and fill the gaps with one of the following phrases:
1. … including inspection, modification, recording, and any disruption or destruction
2. … to implement one or more of these principles
3. … who own it or need it to perform their organizational functions
4. … whether accidentally or maliciously
5. … when they are needed for an organizational process or for an organi- zation’s customers
6. … they mainly differ in the way they spread and infect systems
Unit 10. Information Security
159
7. … that a virus requires a human action (such as running an infected pro-
gram) for it to be spread
8. … which are used to overwhelm a target website with fake traffic
9. … the attacker intercepts communications between two parties and eaves-
drops on or alters the data
10. … that will give them control of your computer
11. … to reduce risk and protect sensitive data
12. … further increasing your identity security
INFORMATION SECURITY
Information security (sometimes referred to as InfoSec) covers the tools and processes that organizations use to protect information. Information security pro­tects sensitive information from unauthorized activities, (1) _____. The goal is to ensure the safety and privacy of critical data such as customer account details, financial data or intellectual property.
The basic tenets of information security are confidentiality, integrity and availability. Every element of the information security program must be designed (2) _____. Together they are called the CIA Triad.
Confidentiality
Confidentiality measures are designed to prevent unauthorized disclosure of information. The purpose of the confidentiality principle is to keep personal in­formation private and to ensure that it is visible and accessible only to those in­dividuals (3) _____.
Integrity
Consistency includes protection against unauthorized changes (additions, deletions, alterations, etc.) to data. The principle of integrity ensures that data is accurate and reliable and is not modified incorrectly, (4) _____.
Availability
Availability is the protection of a system’s ability to make software systems
and data fully available when a user needs it (or at a specified time). The purpose of availability is to make the technology infrastructure, the applications and the data available (5) _____.
It’s easy to confuse information security and cybersecurity, as the two areas
overlap in many ways. Information security is an overarching term for creating
Unit 10. Information Security
160
and maintaining systems and policies to protect any information – digital, physi­cal or intellectual, not just data in cyberspace. Cybersecurity, on the other hand, focuses on protecting information from cyberattacks such as ransomware and spyware. Cybersecurity is a type of information security.
Many cybersecurity threats and attacks can jeopardize the security of indi-
viduals, businesses, and governments. Some of the most common include:
Phishing scams are emails or other communications that appear to be from a legitimate source. Still, they are actually from attackers trying to trick you into revealing personal information or infecting your computer with malware.
Malware is short for “malicious software” and refers to programs designed
to damage or disable computers. Common types of malware include viruses, worms, and trojan horses. The symptoms caused by these different types of mal­ware may sometimes be similar. However, (6) _____.
A Trojan (Trojan Horse) is a type of malware that disguises itself as a legit­imate piece of software in order to convince a victim to install it. Once installed, the malware is able to perform its malicious activity in the background. Trojan horses have no way to replicate automatically.
A virus is a type of malware that attaches itself to a program, file or docu­ment enabling it to spread from one computer to another. It is important to note (7) _______.
A worm is similar to a virus. Just like a virus, a worm spreads from computer to computer. However, what mainly distinguishes a worm from a virus is that a worm has the capability of spreading without any human action. A worm will usually exploit weaknesses such as OS vulnerabilities or weak passwords in order to spread over computer networks.
A rootkit is software used by cybercriminals to gain control over a target computer or network. Once they gain unauthorized access to computers, rootkits enable cybercriminals to steal personal data and financial information, install malware or use computers as part of a botnet to circulate spam and participate in DDoS (distributed denial of service) attacks.
Denial of service (DoS) attacks are attempts to make a computer or network resource unavailable to its intended users by overwhelming the target with traffic or requests for data.
Distributed denial of service (DDoS) attacks are a subclass of denial of ser­vice (DoS) attacks. A DDoS attack involves multiple connected online devices,