0% found this document useful (0 votes)
53 views82 pages

English for Cybersecurity Students

Uploaded by

arurgamer29834
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
53 views82 pages

English for Cybersecurity Students

Uploaded by

arurgamer29834
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

KAZAN FEDERAL UNIVERSITY

INSTITUTE OF INTERNATIONAL RELATIONS, HISTORY AND


ORIENTAL STUDIES

THE DEPARTMENT OF THE ENGLISH LANGUAGE


IN THE SPHERE OF HIGH TECHNOLOGIES

G.F. VALIEVA, D.A. JARULLINA

English for Information Security

Kazan – 2015
УДК 811.11
ББК 81.2 Англ
В 15

Принято на заседании кафедры английского языка


в сфере высоких технологий
Протокол № 1 от 17 сентября 2015 года

Рецензенты:
кандидат филологических наук,
доцент кафедры английского языка в сфере высоких технологий КФУ
Д.Ф. Хакимзянова;
кандидат филологических наук,
начальник управления международных связей КГЭУ,
доцент Г.Т. Нежметдинова

Валиева Г.Ф., Яруллина Д.А.


В15 English for Information Security / Г.Ф. Валиева, Д.А. Яруллина. –
Казань: Казан. ун-т, 2015. – 83с.

Данное пособие предназначено для студентов, обучающихся по


специальности «Информационная безопасность» (10.03.10, 10.03.01), и
содержит задания формата IELTS, что позволяет подготовиться к сдаче
международного экзамена на базе профессионально-ориентированного
материала, отработку четырех аспектов (Чтение, Аудирование, Говорение
и Письмо), аутентичные тексты и аудиоматериалы, направленные на
углубление и расширение профессиональной лексики.

© Валиева Г.Ф., Яруллина Д.А., 2015


© Казанский университет, 2015
Introduction
This textbook is dedicated to students of the Information Security
specialization.

The purpose of the textbook is to form profession-oriented competences


of students, enlarge their professional vocabulary and prepare for IELTS exam.

“English for Information Security” consists of 7 units, each of them


contains all 4 aspects that are Speaking, Reading, Listening and Writing. As
well as these aspects, there is a range of material which can be used according
to students’ needs and time available. One can find useful vocabulary with
definitions and transcriptions to practice pronunciation. Also some useful tips
are presented to help fulfil the IELTS tasks. Students are given useful language
to keep changing the phrases they use to express their opinion, agreement,
disagreement, to hold and take part in a meeting, to make presentations.

All texts are adapted from scientific articles and refer to students’
specialization. All recordings for Listening are taken from interviews with
representatives of such organizations as Kaspersky Lab.

3
Content
Unit 1 Cybersecurity Career 5
Unit 2 Security Threats 15
Unit 3 Computer System Security 29
Unit 4 Network Security 46
Unit 5 Online Banking Security 54
Unit 6 Mobile Devices Security 61
Unit 7 Cloud Security 67
Bibliography 80

4
Unit 1 Cybersecurity Career
Speaking
1. What is cybersecurity? Try to work
out your definition using key words
in the picture.

2. Choose the best definition for


cybersecurity. Which one is similar
to yours?

a. 10 pluses of b. 10 minuses of
working in the working in the
sphere of sphere of
cybersecurity cybersecurity

c. What traces of
character should a d. Would you like to 3. Discuss the following topics:
good specialist work in the field of
have? cyber secuirity?

5
4. Imagine that you are working for the big company as a network security manager. Try to
decribe your simple working day.

to be your to do a job- a good team a heavy


a dead-end job full-time
own boss share player workload

a high- holiday job maternity to meet a


manual work
powered job entitlement satisfaction leave deadline

one of the
a nine-to-five to run your to be self-
perks of the part-time sick leave
job own business employed
job

to be stuck to be/get to take early temporary voluntary


to be well paid
behind a desk stuck in a rut retirement work work

working to work with


conditions your hands

Reading 1 Vocabulary and Pronunciation


1. What are the main principles of How to prepare for a cybersecurity
cybersecurity career?
Cybersecurity breaches affect businesses large and
Note: Words in tasks are small, and the annual cost of computer- and network-
given in initial form! based crimes worldwide is estimated to be more than
$400 billion. As organizations increasingly use data
2. Match the following
networks for business, commerce and the transfer of
transcriptions, A-Q, with the
sensitive information, the risks multiply, as do the needs
highlighted words and pronounce for qualified cybersecurity professionals.
them. (ISC)² Foundation and University of Phoenix set out to
A /ˈækjʊmən/ develop actionable recommendations to prepare
B /ˈmɪtɪɡeɪt/
students for cybersecurity careers-delivering a report on
C /ˈkɒmɜːs/
D /dʌb/ it, dubbed Cybersecurity Workforce Competencies:
E /əˌkrɛdɪˈteɪʃ(ə)n/ Preparing Tomorrow’s Risk-Ready Professionals.
F /kɔp̃ etɑ̃s/ The research identifies three education-to-workforce
G /ˈkruːʃ(ə)l/ gaps that leave employers and organizations particularly
H /ˈwɜːkfɔːs/ vulnerable: competency, professional experience and
I /ˈvʌln(ə)rəb(ə)l/ education speed-to-market.
J /əbˈteɪn/
The report is based on a year of research, including
K /ˈpɑːθweɪ/
L/ˈsteɪkˌhəʊldə/ analysis of industry competency models and labor
M /ˌraʊndˈteɪb(ə)l/ statistics, which led to a national focus group, followed
6
N /ɪnˈtɜːnʃɪp/ by the roundtable with industry leaders.
O /ˌsaɪbəsɪˈkjʊərətɪ/ “The growing frequency, sophistication, and costs of
P /kəˈrɪkjʊləm/ cyberattacks threaten business continuity for
Q /ʃɪft/
organizations of all sizes,” said Julie Peeler, director of
the (ISC)² Foundation, in a statement. “Preparing and
3. Read the article once. Try to
attracting the next generation of cybersecurity
work out the meaning of the
professionals is critical to the health of the economy and
highlighted words. Then match
businesses globally.”
them with their definitions a-q.
Roundtable participants say the following actions by
industry and education leaders can have the most
a._______________ noun ways of
immediate impact on closing the gaps:
protecting computer systems against
1. Encouraging problem-based learning via case studies
threats such as viruses
and labs;
b._______________ noun a track 2. Offering meaningful internships for cybersecurity
that a person can walk along degree completion; and
c._______________ noun the 3. Developing curriculum and career resources that are
activities involved in buying and informed by cybersecurity employers.
selling things “The multi-faceted cybersecurity field demands a strong
d._______________ noun a period of workforce comprised of individuals who can adapt to
time during which someone works constant shifts in the sector,” said Dennis Bonilla,
for a company or organization in executive dean of University of Phoenix College of
order to get experience of a particular Information Systems and Technology, in a statement.
type of work “The industry increasingly needs professionals who
e._______________ noun the act of possess both technical skills and strong business
granting credit or recognition acumen, and curriculum is shifting to reflect these
(especially with respect to dynamics. Relevant education and training aligned to
educational institution that maintains industry requirements are crucial to protecting and
suitable standards); "a commission is growing business infrastructure in the US and globally.”
responsible for the accreditation of “Having qualified cybersecurity professionals is critical
medical schools in all industries,” added Peeler. “Employers must act
f._______________ noun the quickly to close workforce gaps and mitigate the risks
subjects studied in a school, college, that threaten enterprises. The roundtable report by the
etc. and what each subject includes (ISC)² Foundation and University of Phoenix provides
g._______________ verb to give practical recommendations to key stakeholder groups
something or someone a particular that must work together to build the cybersecurity talent
name, especially describing what you pipeline.”
think of it, him, or her The report offers the following tips for students
h._______________ noun an interested in cybersecurity careers, and for employers
important skill that is needed to do a struggling to fill job openings:
job For Students
i._______________ noun a person 1. __________Obtain the relevant certifications that can
such as an employee, customer, or help enhance employability.
citizen who is involved with an 2. ___________Many jobs in this field may require a
organization, society, etc. and security clearance. Be mindful that past actions could
therefore has responsibilities towards
affect your eligibility.
it and an interest in its success
7
j._______________ noun a group of 3. ________Demonstrate interest in the field by
workers who do a job for a period of developing professional relationships. Stay abreast of
time during the day or night, or the industry trends by joining an association.
period of time itself 4. __________Seek opportunities to demonstrate your
k._______________ noun skill in
expertise by co-presenting at industry conferences and
making correct decisions and
judgements in a particular subject, completing relevant projects.
such as business or politics 5. ____________Look for ways to obtain professional
l._______________ adj extremely experience through internships, job shadowing or work-
important or necessary study jobs.
m._______________ noun the group For Employers:
of people who work in a company, 6. ____________Offer internships and participate in
industry, country, etc. higher education curriculum advisory boards.
n._______________ adj able to be
7. _____________Partner with middle schools and high
easily physically, emotionally, or
mentally hurt, influenced, or attacked schools to increase awareness of cybersecurity career
o._______________ noun involving opportunities.
several people who talk about 8. _____________Remove barriers to entry-level jobs
something as equals by decoupling tasks that require a security clearance.
p._______________ verb to make Many applicants, such as non-U.S. citizens, may be
something less harmful, unpleasant, unable to obtain a security clearance readily.
or bad 9. ____________Develop partnerships with higher
q._______________ verb to get
education institutions to support curriculum
something
development, career networking, and internships.
4. Read the article again and 10. ______________Develop and fund programs that
choose the most suitable topic provide industry experience to students. Ensure
sentence, i-xi, for each paragraph, programs meet the National Security Agency’s Centers
1-11, from the list below. of Academic Excellence accreditation requirements, and
seek accreditation approval for such programs.
i Champion cybersecurity careers. 11. ___________Internships are a viable step to
ii Get certified. employment and demonstrate the value of entry-level
iii Hire interns.
experience as a pathway to a career.
iv Understand clearance
requirements. (adapted from [Link]
v Encourage professional experience.
vi Steer clear of clearances.
vii Promote partnerships.
viii Get involved.
ix Build a portfolio.
x Seek opportunities.
xi Engage with educators.

Listening and Speaking


1. What kind of IT professions do you know?

2. You are going to listen to a part of a TV program about cybersecurity.

8
Questions 1-5
Before you listen, try to Complete the notes below.
predict what the answer Write NO MORE THAN THREE WORDS for each
will be answer:
1. Almost any movie today dealing with national security
includes a dramatic __________________ scene.
2. It’s growing importance, because now we are having
The recording will be played _________________.
ONCE only! 3. A lot of our confidential data we ___________, they
wouldn’t be able to_________ it.
4. Students who graduated computer science program are
well prepared to ____________ and
________________.
The words you read will
5. They need to get ___________________, they need to
probably not be the same as
get training, and they even have to get certificates.
the ones you hear, so be
prepared to listen to
Questions 6-10
synonyms or paraphrases. Choose the correct letter A, B, C or D.
6. Why is cybersecurity so important?
A. It’s fashionable
B. It’s interesting for people
Glossary: C. It’s necessary because people use technological
devices
High drama noun high D. It’s necessary for proper office work
drama usually refers to 7. Why is information being decrypted?
acting in an overly A. To gain access to it
dramatic way B. To delete it
Flow through verb to C. Not to be able to read it
affect someone or D. To make its usage easier.
something 8. What did Professor Ming do for cybersecurity?
Encrypt verb to alter A. He opened special courses
(data) using a B. He opened IT university
mathematical algorithm C. He invented new program
so as to make the data D. He invented artificial intelligence
unintelligible to 9. Who usually tends to get higher job offers?
unauthorized users while A. Postgraduates in computer science
allowing a user with a key B. Students of computer science
or password to convert C. People who work in office
the altered data back to D. People who have PhD
its original state 10. How many students choose technical major at
Meet a demand verb to university?
be apparent to (esp. in A. A lot
the phrase meet the eye) B. Not much
C. A half
D. None

9
3. Look at the graph. Do
you agree with it?
Make analysis based
on the graph, try to
answer the following
questions:

A. Why do you think


jobs in Finance are
more demanded?

B. Analyze your country.


Does this graph suit
for it?

4. Divide into groups. Each group is to choose one degree in the chart. You are to decide
why people need your job. Practice using “Useful language”.

Useful language I see your point, but I think…


In our opinion… Yes, I understand, but my opinion is that…
We (don’t) think that… That’s all very interesting, but the problem is
The way we see it… that…
If you want our honest opinion… I’m afraid I can’t quite agree with your
According to the other side/our point…
opponents… I think I’ve got your point, now let me
As far as I'm concerned… respond to it…
Our position is the following… We can see what you’re saying. Here’s my
reply…

Reading and Speaking 2


Do you think there is any Cybersecurity vs. Information Security.
difference between cybersecurity Hollywood exerts influence over many areas of modern life,
and information security? Prove even down to how people think about and refer to different
your point of view. types of work. Movies and television shows often depict the
professionals who deal with computer security as
Questions 1-6 Cybersecurity or information security specialists. These terms
are often used in the entertainment industry in a way that
Do the following statements
implies that they are identical, which can create confusion for
agree with the information given
those who are interested in pursuing a career in one of these
in the text? Write T(true),
F(false), NG(not given) next to exciting and growing fields. Prospective students need to be
the sentences 1-6. able to distinguish between these two professions in order to

10
1. Cybersecurity is a term determine which career path is the best fit.
made by Hollywood Cybersecurity
movies. Cybersecurity is the use of various technologies and processes
2. Cybersecurity and to protect networks, computers, programs and data from
information security are attack, damage or unauthorized access. Since all computer
different things. systems rely on operating systems and networks to function,
3. Cybersecurity implies those areas are often targeted for attack and are the main
searching information in the sources of many security vulnerabilities.
internet. Cybersecurity jobs require strong technical skills and most
4. There is only one job in require a technical degree in Cybersecurity, computer science,
cybersecurity field. information technology or engineering. Cybersecurity degree
5. It’s not important to courses often offer classes in:
distinguish information and Computer forensics
cyber security. Advanced computer security issues and practices
6. There is similarity between General computer topics.
information and cyber Cybersecurity jobs might include information systems
security. security professional, senior system manager and system
administrator.
Questions 7-12 Information Security
Information security involves protecting information from
Choose NO MORE THAN unauthorized access, use, disruption, modification or
THREE WORDS from the destruction, regardless of whether the information is stored
passage for each answer. electronically or physically. Cybersecurity is a subset of the
larger area of information security.
7. Student has to distinguish Similar to Cybersecurity jobs, information security jobs also
information and cyber rely on strong technical skills since most information is stored
security to make a proper digitally. A solid background in networking, system
choice of his ___________. administration, software development and data integrity and
8. Viruses, cyber-attacks, security is an asset to those looking to enter this field.
spies are one of many Prospective students should also consider supplementing
____________ that network technical courses with general communication and business
can face with. courses. Information security jobs include security systems
9. Information security deals administrator, security auditor and security analyst.
with protecting information Understanding technology and security issues is critical for
whether it stored any Cybersecurity or information security professional,
________________. regardless of the specific field of specialization. By
10. Information security understanding the differences between these two related but
students are also trying to distinct fields, individuals choose the most appropriate
take such courses as educational options that will best prepare them for a career
____________________. that matches their goals and interests.
11. By understanding The Bottom Line
differences between When deciding on one of these computer security-related
_____________________ career paths, it is critical to be clear and detailed about exactly
students can choose their what it is you’re looking for in a career. Cybersecurity and
future career path. Information Security are two similar fields which offer a great

11
variety of job options, but they are distinct career choices.
12. If you know differences By fully understanding the differences and similarities
between cybersecurity and between these two fields of study, individuals will better be
information security, you able to select the educational path that best matches their
are able to select profession skills, interests and career goals. By researching potential
that best matches you professions carefully, you’ll be able to discern the differences
____________________. and similarities between several possible programs of study.
Gathering data about your prospective field and evaluating it
Try to find as many pluses and carefully will allow you to make an informed choice about the
minuses of both professions as best career path for you.
possible. Which one would you (adapted from [Link]
like to choose? Explain your
point.

Writing 1. Complete the letter by filling the gaps with a


word from the box below.

Differences between CV and CV post department developer


resume.
A resume is a one or two page interview experience qualified closing
summary of your skills, skills salary
experience, and education.
While a resume is brief and
concise - no more than a page or Dear Sir/Madam,
two - a curriculum vitae is longer I am writing to apply for the .................... of Software
(at least two pages) and provides Development Manager advertised on February 9th on the
a more detailed synopsis. University of Kent vacancy database. I have been
Curriculum vitae includes a working for the past ten years as a senior .................... in
summary of your educational a telecommunication company in the IT ..................... I
and academic backgrounds as think now is the right time to apply for a better position
as I believe I have gained relevant .................... and
well as teaching and research
skills.
experience, publications,
As you can see from my enclosed ...................., I am
presentations, awards, honors,
a .................... engineer and believe I have excellent
affiliations, and other details. In
technical and management ..................... My
Europe, the Middle East, Africa, current .................... is $55,000 a year.
or Asia, employers may expect to I realize that the .................... date for applications was
receive curriculum vitae. In the last Saturday, but I hope you will still consider my
United States curriculum vitae is application. I will be available for .................... at any
used primarily when applying for time, apart from the 12 - 24 March when I arranged a
academic, education, scientific, holiday in Italy.
or research positions. It is also I look forward to hearing from you soon.
applicable when applying for Yours faithfully,
fellowships or grants. John Smith.

12
2. Write your own CV using the following tips. Write at least 150 words.

1. Use a confident tone and positive language.


2. Concentrate on your achievements not your responsibilities. This means listing things you
have done - such as products launched, sales increase, awards won - not rewriting your job
description. Quote figures whenever possible.
3. Make your most relevant experience and skills prominent to encourage the employer to
read on.
4. Keep it to the point and concentrate on the quality of your achievements, not the quantity
5. List other skills that could raise you above the competition such as languages and IT skills
6. Your CV can be far longer than the normal 2 pages of a non-academic CV but your first
page should include all the best bits.
7. Check thoroughly for correct spelling and grammar - spotting errors is a quick and easy
way of weeding out weaker candidates when faced with a mountain of CVs to read.
8. Appeal to your online audience; ensure you have relevant keywords in your CV.
9. Capture immediate attention. Prioritize the content and detail the most relevant information
first.
10. Make sure that you include all Education and prizes awarded, research interest, funding
awarded for research projects, other research experience and your publications.

Notice:

British / American English


There are sometimes differences between British and American English and conventions. Here is a
guide to some of the most important differences for your CV/resume and covering letter. But
remember, this is a guide only - there are no strict rules. For example, some British people like to
use "American" words, and some American people like to use "British" words.

British American
CV/curriculum vitae Resumé
covering letter cover letter
Standard paper size: Standard paper size:
A4 (210 x 297 millimetres) Letter (8 1/2 x 11 inches)
Mrs Ms
Dear Sirs Gentlemen
Yours faithfully Yours truly
Yours sincerely Sincerely
Sincerely yours
Yours truly
Managing Director (MD) Chief Executive Officer (CEO)
General Manager
date format: DD/MM/YY date format: MM/DD/YY
example: 30/12/15 example: 12/30/15
30 December 2015 December 31st, 2015
labour labor
13
Unit 1 Cybersecurity Career Revise and Check

CAN YOU:

…give definition
of
…pronounce and give
definition of: Cybersecurity

commerce

dub

competence

workforce

vulnerable

roundtable …speak about:


internships
Cybersecurity (skills that
curriculum are in demand)

shift Choosing career

acumen Debating about job


(pluses and minuses)
crucial

mitigate

stakeholder

obtain

accreditation

pathway …write:
Curriculum Vitae

14
Unit 2 Security Threats
Speaking
1. What kind of threats can you face? Discuss the threats given in the chart.

2. In pairs write down the description of the chart. Read the following tips first. Practice
using “Useful language”. You should spend about 10 minutes on this task. Present
your description to your groupmates. Discuss and correct all mistakes together.

 Spend one or two minutes studying the chart;


 Explain what the chart is describing in introduction;
 Then identify two or three main features. Don’t describe everything you see.
Look for any interesting features, especially surprising or contrasting
information;
 Start with an overall information and then move on to use details to support
your main points. Remember to use expressions to link your ideas;
 Make conclusion. Just sum up. Do not explain anything and do not give new
information.
 Write at least 150 words.
 Remember to check your work before the end.
15
Useful language It/There is/are twice as…as
The chart shows/illustrates/provides a over … %
clear overview of/gives information… nearly/about/around … %
According to… is nearly the same as… that of…
It can be seen… is a little more than… the amount/
It would appear from the chart… is double… number/
One of the first things to note is… percentage of…
Another thing which stands out in this relatively small percentage…
chart is… much more…than…
However… slightly more…
Although… a great deal…
It should be noted that… The majority of…
A final point to note is… A minority of…
Overall, … compared with…
To conclude… whereas/while…
It is clear from the data above that… As well as…it also shows…
The data clearly indicates… not only…but also…

3. Can you add any other threats that were not mentioned in the chart?

Listening
Vocabulary and Pronunciation

You are going to listen to the speech by David


Emm, Senior Security Researcher, Kaspersky Lab.

Section 1 Different types of Malware


Always read through
the tasks very Questions 1-17
carefully before you Complete the sentences below. Write down NO MORE
listen to get an idea THAN THREE WORDS for each answer.
what you are
1.__________ is a collective term for all kinds of threats.
listening for.
The most popular threat is 2. __________.
Virus infects the object on a disk by 3. __________ and travels
16
4. __________ from computer to computer.
Network Worms require 5. __________ to spread while
You will hear a lot of 6. __________ do not.
information, but you Trojans are masqueraded with some useful function but perform
don’t need to 7. __________ on the computer.
If the code infects the computer when the victim views the
understand it all. You
webpage it is 8. __________.
should always look
Comparing Trojans with Viruses and Worms they don’t
ahead to the next
9. __________.
question so that you
Backdoor Trojans allow 10. __________ of a system where
don’t miss hearing the 11. __________ records every key pressed.
answer to a question. Banking Trojans’ aim is to steal money from a 12. __________.
Trojan downloaders download 13. __________ to the computer.
14.__________ combine the functionality of a virus, worm and
Trojan in one package.
You will only hear As soon as cybercriminals are able to control your computer they
each section ONCE! will connect it with other infected computers – create
15. __________ or botnet.
Now they can do anything from sending out 16. __________ to
loading 17. __________ on organizations.
Be ready to listen for a
paraphrase!
Section 2 How malware evolves
Write down the words Questions 18-33
exactly as you hear
Questions 18-22
them!
Answer the questions below. Write down NO MORE THAN
Remember to write
THREE WORDS for each answer.
down the speaker’s
answer not your own 18. What do damage with no financial gain such as deletion of
one! files, renaming the data, erasing the data storage media refer to?
19. What machine can be unintended side effect of malware?
Check that your 20. What kind of machine is of no value to cybercriminals?
answers are spelt 21. What is an infected machine for cybercriminals?
correctly, 22. The number of what is growing?
grammatically relevant
and make sense in Questions 23-27
relation to the Choose the correct letter A, B or C.
question. 23. Which motive of attacks wasn’t mentioned?
A ruin reputation
B disrupt the work of a company
C steal money
Hyphenated words 24. What gives opportunity to access corporate system?
count as one word! A confidential data
B disclosing information
C sensitive information
17
25. Cybercrime is effectively the use of malware for ________.
Be aware that some of A making money
the answers may come B profit
quickly one after the C stealing data
26. What doesn’t refer to identity theft?
other!
A password
B intellectual property
Use shorthand to C online banking logging
improve the speed at 27. Which way of using victim’s online credentials wasn’t
which you write down mentioned?
your answers (to write A laundering money
B accessing accounts
down the answers more
C selling to criminals
quickly, write only the
first two or three letters
Questions 28-33
of the answer that you
hear) or use your own Do the following statements agree with the speaker?
system of note-taking Write T, F, NG on lines 20-22.
28. Encrypting the data with the password and making pay money
to decrypt it is called ransomware.
29. Ransomware is very profitable.
The questions are 30. Fake Anti-Virus scam indicates the presence of malware on
always in the order the victim’s computer and asks for money to remove it.
answers occur in 31. Criminals can manipulate social networks.
listening 32. When you pay for removal of malware criminals get your
password.
33. Two malware mentioned above refer to extortion of money.

Section 3 Questions 34-47


Make sure you write NO
How malware spreads and how to stay protected
MORE than the
maximum number of Questions 34-38
words given in Complete the summary below. Write down NO MORE
instructions!
THAN THREE WORDS for each answer.
Malware spreads via:
a. 34. __________. Having found the 35. __________ in web
service criminals hide the code there. Computers can be
Don’t forget to listen
infected while victims visit the pages;
for each answer in turn.
b. e-mail 36. __________ or links;
If you miss one go on to
c. social network;
the next question or
d. 37. __________ that is physical media;
you may miss that too. e. 38. __________ known as vulnerabilities or bugs.

18
Kaspersky analyses modifications of existing viruses that are
39. __________. It searches for 40. __________ of none viruses
or signatures. Kaspersky provides a range of 41. __________:
heuristic analysis, sandboxing, 42. __________, behavioral
Always give an answer analysis etc. It has 43. __________ called Kaspersky Security
– you won’t lose marks Network. It provides 44. __________ protection as they can
if it is wrong! 45. __________ even unknown virus without the signature.
Kaspersky can offer 46. __________, accurate and comprehensive
analysis by applying 47. __________ of detection.

Pronounce and give definitions of the following words:

malware /ˈmæ[Link]ər/ cyber vandalism /saɪbər ˈvændəlɪzəm/


virus /ˈvaɪərəs/ sluggish /ˈslʌɡɪʃ/
worm /wɜːm/ disclosing information /dɪsˈkləʊziŋ
e-mail worm /ˈiːmeɪl wɜːm/ ˌɪnfəˈmeɪʃən/
network worm /ˈnetwɜːk wɜːm/ cybercrime /ˈsaɪ.bə.kraɪm/
Trojan /ˌtrəʊ.dʒən/ identity theft /aɪˈdentəti θeft/
homegrown application /ˌhəʊmˈɡrəʊn laundering money /ˈlɔːndəriŋ ˈmʌni/
ˌæplɪˈkeɪʃən/ ransomware /ˈrænsə[Link]ər/
drive-by download /ˈdraɪvbaɪ ˌdaʊnˈləʊd/ lucrative /ˈluːkrətɪv/
self-replicate /self ˈreplɪkeɪt/ fake anti-virus scam /feɪk ˌæntiˈvaɪərəs skæm/
backdoor Trojan /bækdɔːr ˌtrəʊ.dʒən/ extortion /ɪkˈstɔːʃən/
banking Trojan /ˈbæŋkɪŋ ˌtrəʊ.dʒən/ loophole /ˈluːphəʊl/
Trojan downloaders /ˌtrəʊ.dʒən ˌdaʊnˈləʊdez/ vulnerability /ˌvʌlnərəˈbɪləti/
hydrid threat /ˈhaɪbrɪd θret/ bug /bʌɡ/
keylogger /kiːlɑː.ɡɚ/ variants /ˈveəriənts/
botnet /ˈbɒ[Link]/ snippet /ˈsnɪpɪt/
spam /spæm/ signatures /ˈsɪɡnətʃərz/
target attack /ˈtɑːɡɪt əˈtæk/ sandbox /sænd bɒks/

Pronounce the following malware types that were not mentioned by the speaker and
match them with their definitions. What do you know about them?

Malware Definition
1. Bot A will redirect your normal search activity and give you the results
/bɒt/ the developers want you to see. Its intention is to make money off
your web surfing.
2. Rootkit B is one that can transform based on the ability to translate, edit and
/ruːtkɪt/ rewrite its own code.
3. Backdoors C is the name given to legitimate programs that can cause damage if
/ˈbækˌdɔː(r)z/ they are exploited by malicious users – in order to delete, block,
modify or copy data, and disrupt the performance of computers or
networks.
4. Browser D is the name given to programs that are designed to display
Hijacker advertisements on your computer, redirect your search requests to
/ˈbraʊzər advertising websites and collect marketing-type data about you.
ˈhaɪdʒækər/
19
5. A stealth virus E is derived from the word "robot" and is an automated process that
/stelθ ˈvaɪərəs/
interacts with other network services.
6. A metamorphic F is complex malware that hides itself after infecting a computer and
virus copies information from uninfected data onto itself and relays this to
/ˌmet.əˈmɔː.fɪk antivirus software during a scan.
ˈvaɪərəs/
7. A macro virus G provide a network connection for hackers or other Malware to
/mækrəʊ enter or for viruses or SPAM to be sent.
ˈvaɪərəs/
8. Spyware H alters or replaces a macro, which is a set of commands used by
/ˈspaɪ.weər/ programs to perform common actions.
9. Adware I works in a similar way to spyware but does not usually collect
/ˈædweər/ information from the computer. Instead, it just sits there waiting for
commands from a command-and-control server controlled by the
attacker.
10. Riskware J is designed to permit the other information gathering Malware to
/ˈrɪsk weər/ get the identity information from your computer without you
realizing anything is going on.
11. Zombie K is a type of malware that surreptitiously gathers information and
/ˈzɒmbi/ transmits it to interested parties.

Writing
You should spend about 20 min on this task. Write at least 150 words.

The chart shows 5 top malware types over 2012-2014 . Summarize the information by
selecting and reporting the main features, and make comparisons where relevant.

20
 If the chart includes time references (dates, years) you will need a range of past and
present tenses. If it has no past time reference, you will need to use present simple
tense only.
 It is important not to offer your opinion on the chart or to try to give reasons for the
figures mentioned.
 Paraphrase the figures in the chart. Use just under half of, a third…
 You need to compare information as well as describe it. Use phrases from Speaking
of this unit (useful language) and the following ones:
to shoot up
to soar amount of +uncountable noun
to boom number of + countable noun
to jump five (number) per cent of…
to surge the percentage of (noun)…
to skyrocket to

to increase/an increase of 20%, in obesity dramatically/dramatic


to rise/a rise steeply/steep
to go up sharply/sharp
to grow rapidly/rapid
to climb significantly/significant
to double drastically

to reach a peak/a peak clearly


to reach a high/a high undoubtedly
to hit record levels surprisingly
obviously
to hold/remain steady statistically
to remain/be stable/constant/unchanged unbelievably
to flatten out probably
no change luckily
to level off/a levelling off disappointingly

to fluctuate/a fluctuation
to zigzag
to move up and down

to fall/a fall gradually/gradual


to decline/a decline steadily/steady
to decrease/a decrease constantly/constant
to dip/a dip slightly/slight
to go down slowly/slow

to drop/a drop by Time expressions


to plunge in 2015
to plummet by between 2013 and 2015
to dive-take a nosedive for 5 years
for the period
to bottom out since 2013
to fall/hit to a low point/a low point

21
Reading Vocabulary and Pronunciation
Social Engineering: an underestimated danger
What is Social Engineering?
There is always a lot of concern about how we protect IT
Does it really turn out to be
systems against sophisticated attacks by super intelligent
one of the most dangerous
hackers whilst completely neglecting the risks posed by staff
threats?
not adhering to policies and procedures or their vulnerability
to being socially engineered to give away information.
Match the following The poor implementation of data protection rules can pose a
transcriptions, A-L, with the major threat to information security. Vulnerabilities may also
highlighted words and emerge where people are lazy, or do not understand the
pronounce them. potential consequences of failing to meet policy standards.
However, there are also lots of ways people might be
A /daɪər/ manipulated through social engineering into giving away
B /ˌræʃəˈnɑːl/ information that would facilitate an attack, and this risk is
often overlooked.
C /daɪˈvʌldʒ/
Social engineering is the act of manipulating people into
D /ˌpenɪˈtreɪʃən ˈtes.tər/
performing actions that compromise security or divulging
E /nɪˈɡlekt/ confidential information.
F /blæɡiŋ/ Perhaps the most well- known means of social engineering is
G /ədˈhɪər/ phishing – the act of creating a legitimate looking email or
H /səˈseptəbl/ letter from an institution or a person in a position of authority
with the aim of gaining access to personal or confidential
I /ɪkˈsplɔɪtit/
information.
J /ɡeɪn/
Whilst phishing attacks are clumsy and easy to spot, a great
K /tæp/ number of emails sent, combined with the fact we all still
L /fəˈsɪlɪteɪt/ receive them, suggests that the senders are achieving some
level of success. Furthermore, some groups of people are
Read the article once. Try to singled out by social engineers as they are seen as more
work out the meaning of the susceptible to phishing scams. Take for example the pyramid
highlighted words. Then schemes that commonly target elderly people who are
match them with their perceived to have the money to invest and time on their
definitions, a-l. hands, and may be lonely and starving for attention. Another
example is the recent money laundering scam targeting
a._______________ verb to students, unemployed people, and foreign nationals.
use part of a large supply of
The targets effectively launder the criminals’ money through
something for your own
advantage their own bank account and take a percentage as “payment”
for their services. This is, of course, illegal and can have dire
b._______________ verb to consequences for the victims who may end up with a criminal
make something possible or record and/or being denied banking services.
easier There are also examples of individuals working in large firms
being specifically targeted with official looking emails
c._______________ adj very
issuing them with a subpoena and informing them they need
serious or bad
to appear in court (in the USA). These emails, of course, had
22
d._______________ verb to malicious links embedded within them. The targeted nature of
obey a rule or principle such attacks has given rise to the term “spear phishing”.
Although phishing is perhaps the most well-known social
e._______________ noun
engineering tactic, it is not the only one. There are numerous
someone whose job is to attack
computer systems in order to other ways a social engineer can persuade people to part with
find security weaknesses that confidential information or permit them to access places they
can then be fixed shouldn’t be allowed to. For example:
1_________________– This is one of the best tactics when
f._______________ adj easily you are trying to make it appear perfectly normal to everyone
influenced or harmed by that you should be there. For example, pretend to be an
something
employee to gain access – identity cards can be stolen or
g._______________ verb to mimicked and uniforms can be purchased. Combined with
not give enough care or poor access control procedures, this makes it easy to gain the
attention to something or necessary information for the social engineer.
someone 2_________________– the social engineer will create and
use an invented scenario to engage the target in a way that
h._______________ noun a increases their chances of divulging information or acting in a
group of reasons for a decision
different way. This is also known as blagging.
or belief
3_________________– the social engineer persuades the
i._______________ verb to get person responsible for a legitimate delivery that the
something useful consignment is requested elsewhere and steals the contents.
4_________________– the real-world Trojan horse. This
j._______________ noun the relies on the curiosity and greed of the victim by offering
practice of pretending to be
“too-good-to-be-true” investment opportunities. It can be in a
someone else in order to get
personal information about form of music or movie download or a USB flash drive with a
them company logo left out in the open for you to find.
5_________________– this is a common tactic used by social
k._______________ verb to engineers. In emails, they will claim to be a peer/prince, a law
give secret or private enforcement agent, or anyone else that could be perceived as
information to someone an authority figure. In person, an air of confidence and the
ability to lie convincingly can gain a social engineer access to
l._______________ adj be
treated unfairly in order to get all sorts of places.
some benefit from you 6_________________– it is surprisingly easy to follow
people into secure restricted area or system. The polite
Questions 1-8 practice of holding doors open is a social engineer’s dream.
To be honest, most people hate confrontation and are unlikely
Read the article again and to challenge you anyway.
choose the most suitable
7_________________– drawing attention by being very
topic sentence, i-xii, for each
unfriendly. This is because people just want to get rid of
paragraph, 1-8, from the list
below. angry people and they are much more likely to obey your
wishes when you are angry, so it works well when asking
i Vishing
people to open doors for you or provide information on the
ii Tailgating
location of things. A good real-world example of this is to
iii Diversion theft start an argument with someone as you approach a checkpoint
iv Unfriendly behaviour (e.g. if you are trying to sneak alcohol into a festival) and

23
v Impersonating someone in security staff may be more likely to wave you through instead
a position of authority of searching you.
vi Quid pro quo 8_________________– this is where a social engineer will
offer something for something else in return. For example,
vii Familiarity exploit
disgruntled employees may be approached to provide
viii Win-win deal information in exchange for cash.
ix Reading body language There are lots of techniques and approaches that the social
x Baiting engineer can access to facilitate their work. For example:
xi Hostility • Surveillance – identifying the targets' routine helps
xii Pretexting determine the best way to approach them. However, the
approach does not always need to be direct. Take for example
Questions 9-18 a scenario where a group of employees regularly go to the
same pub on a Friday night. Conversations after a few alcohol
Complete the summary beverages can lead to sharing of confidential information.
below with words from the • Maximizing on naivety –for example, when the victim
article. Write NO MORE pays a bill over the phone in public place. By the time she
THAN THREE WORDS for gets through to payment services the social engineer can have
each answer. a pen and notepad ready and will be able to write down all of
It’s quite difficult to keep your her credit card information (including the 3 digit security
system safe from 9. code on the back of the card!).
__________ attacks if your • Using social networks – LinkedIn, Facebook, Twitter and
employees don’t 10. other social networks contain a mountain of information. It is
__________ the rules. The surprising how much personal data you can access about
main purpose of social someone from their social media profiles. Knowing this kind
engineering is to make people of information could allow strangers to strike up a
11. __________ confidential conversation with you under the pretense that they know you.
data. The most popular way is Once your barriers are down, they can start asking more
to send 12. __________ letter. confidential questions to gain the key information that they
For example, social engineers want. Some people also post where they are at a given time
can easily 13. __________ and even information on when they are going on holiday!
money with the help of this • New technology – it is now easier to fake identity cards.
method. But there are some There are also all sorts of tiny cameras and microphones on
other ways to 14. __________ the market which help the social engineer gather information.
access to confidential • Services – any service that involves geotagging will tell a
information. One of them is 15. social engineer where you are if they can tap into it. There are
__________ when social also very unethical telephone call centre services available
engineers go in path with you who will masquerade as someone on your behalf. Picture the
to enter necessary place. scene – you have stolen a credit card from an elderly lady and
Another one is 16. __________ you want to purchase expensive items with it. To achieve this
when they use something you want to change the billing address for the credit card.
victims can be interested in to Problem – you are not an elderly lady, nor you can mimic
attract their attention. Also one, so calling the bank yourself is out of the question. If you
another 17. __________ can be don’t have a friend who can call for you, you can actually
used to 18. __________ the purchase the service. Believe it or not, there are companies
work. out there that will charge you around $7-15 to make the call

24
Questions 19-25 to the bank on your behalf if you provide them with enough
information to pass the security questions.
Complete each of the Everyone is at risk of being targeted by a social engineer.
following sentences, 5-10, Even if social engineers don’t think they can get access to you
with the best ending, A-N, directly, they may try to target you through your friends,
from the list of endings
family, or colleagues. For example, they may hack into your
below.
friends’ email account and send a message inviting you to
19. If you get an e-mail, … click on a link. Because you trust your friend, you are
20. If you are an employee, … more likely to click the link.
21. If you are an employer, … Tips for reducing risk
22. If you use different If you are unsure about the authenticity of an email or a letter,
protection policies, … use contact information you have sourced independently
23. Try to give your employees (rather than that provided) to verify it.
access to … As an employee of a company, you need to ensure that you
24. Try to use special people to are not exploited to give away trade secrets. In this instance,
… increasing your knowledge of how social engineers operate
25. If you employ white hat and adopting a questioning nature will help – i.e. if someone
hackers, … you don’t really know asks you something confidential, don’t
be afraid to challenge them. If in doubt, seek confirmation
that you can share the information with that person from a
A give information to your
trusted source before proceeding. Also, follow the data
staff about accounts.
protection policy – e.g. if you have been told not to access
B keep it in secret.
personal email at work, don’t just assume your employer is
C say the employees about
being unreasonable, because there may be a very good reason
your decision.
for the policy.
D contact the given source.
As an employer or business, remember that it is all good and
E inform your staff about
well to spend money on technical protection systems, but if
them.
you don’t train your staff to avoid social engineering attempts
F be sure in security of
and teach them good data protection practices, your system is
your company.
still vulnerable. It is important to explain to staff why you
G don’t share information
have certain policies in place. For example, if you block
with people you are not
access to personal email accounts to help minimize the risk of
sure about.
malware being downloaded, then inform staff about this
H challenge your
rationale.
colleagues.
You might also want to consider adopting the “least
I give recommendations.
privilege” principle, which means providing users with access
J teach your employees
only to specific places - basically, the need-to-know
how protect the data.
translated into a need-to-access. The bottom line is that if the
K check your company’s
person cannot access the system, they cannot abuse it (either
security.
intentionally or unintentionally).
L you should check its
You might also want to employ penetration testers who can
authenticity.
test the effectiveness of your security procedures by trying to
M information they really
socially engineer their way into your business. They can test
need.
whichever security measures you want and will report back
N necessary accounts. with recommendations for improvement.

25
Penetration tests can be physical (e.g. someone trying to get
Questions 26-28 past building security) or through the IT systems (e.g. white
hat hackers will attempt to breach your IT security systems).
Do the following statements Don’t warn your staff that a penetration tester is coming – it
agree with the article? Write undermines the whole operation!
T, F, NG on lines 26-28. Social engineering will never go away. In fact, the more
technologically advanced we become, the more necessary it is
26. Social engineering will be to use social engineering to gain access to IT systems. The
more popular. methods are unlikely to change – social engineers have been
27. Social engineers will use using the same basic tricks (e.g. familiarity exploits) for years
modern tactics in future. and there is no reason for them to change now.
28. Social engineers will use The only difference is that new technology provides different
social networks. ways of achieving their aim (e.g. allowing them to improve or
automate their attacks). Secondly, social engineering attacks
are likely to continue to become more sophisticated and
Underline the sentence or targeted.
part of the text that gives As people become more aware of social engineering tactics, it
you the answer. is necessary for them to up their game to ensure continued
success (e.g. the development and use of social engineering
services).
Finally, remember the birth of social media has acted as an
enabler to social engineering, so be careful what you post.
(adapted from [Link] issue 37)
Speaking
You are going to have a conference dedicated to Security Threats. Choose any type of
threat and prepare 7 min presentation about it. Be sure to speak about: history of this
threat, how it works, how to avoid it and actions to be taken to remove it. Use the
following plan and phrases or you’ll lose your marks.

Greeting the audience Introducing each section


Good morning (afternoon, evening) So, let’s start with…
ladies and gentlemen (everyone). Now let’s move on to…
It’s a pleasure to be with you here Let’s turn our attention to…
today. Shall we begin? (I think we can This leads me to…
begin now)
Introducing yourself (your Referring backward and forwards
company) I mentioned earlier…
Let me introduce myself first (I’d like I’ll say more about it later.
to introduce myself; Before I begin let We’ll come back to this point later.
me tell you a little about myself).
I’m… I study… I work for…

26
Giving a short introduction Checking understanding
Today (this morning) I’m going to Is that clear?
(I’d like to) talk about (describe)… Are there any questions?
The aim (purpose) of my presentation Referring to visual information
today is… This screen shows…
My talk today will deal with… If you look at this graph you can see…
My presentation today will concern I’d like to draw your attention to…
primarily…
This morning I’d like to cover the
topic of…
The overview -presenting the Concluding. Calling for questions
structure That concludes my talk.
I’ve divided my presentation into (My That brings me to the end of my
talk will be in) … parts. presentation.
First of all (to begin with, to start Thank you for being such an attentive
with, first), I’ll present (give an audience (Thank you for your attention)
overview)… If you have any questions, I’ll be pleased
Second (then, next, later, after that), (do my best, be happy) to answer them.
I’ll discuss (consider, talk about, look I hope that was clear. If there are any
at, explain, analyze, explain, describe, questions, please don’t hesitate to ask
focus on, move on, deal with, them.
compare, review, outline, highlight, This is a complex subject. There are
go over)… probably many things that are still not
Finally (last of all, in the final part), clear. I welcome any questions you may
I’ll try to forecast… have.
If you would like to have some points
clarified, please feel free.
Referring to questions Dealing with questions
Feel free to interrupt me if there’s I’m glad you asked that question.
anything you don’t understand. I’m sorry I’m not sure I understand.
If you don’t mind, we’ll leave Could you repeat your question, please?
questions till the end. If I understand you correctly, what you
want to know is…
Your question leads to an area which
could be the subject of another
presentation.
I’m afraid I’m not the right person to
answer that.

27
Unit 2 Security Threats Revise and Check

CAN YOU… …pronounce and give definition of

malware bot
virus rootkit
worm backdoors
…speak about e-mail worm browser hijacker
network worm a stealth virus
different types of threats Trojan a metamorphic
and malware homegrown virus
application a macro virus
how malware evolves and drive-by download spyware
spreads self-replicate adware
backdoor Trojan riskware
how to stay protected banking Trojan zombie
Trojan downloaders social engineering
social engineering: tactics, hydrid threat phishing
keylogger spear phishing
approaches, tips to avoid neglect
botnet
spam familiarity exploit
target attack adhere to
cyber vandalism pretexting
sluggish facilitate
disclosing blagging
information gain
cybercrime diversion theft
identity theft divulge
laundering money baiting
ransomware penetration tester
lucrative tailgating
…make fake anti-virus scam be exploited
presentations extortion hostility
loophole tap into
vulnerability dire
bug quid pro quo
variants susceptible
snippet rationale
signatures white hat hacker
sandbox sophisticated

…describe bar charts

28
Unit3 Computer System Security
Speaking
What Makes a System Secure?
Discuss the following methods.
Which one is the most important?

Taking advantage of basic


hardware and software security
characteristics; for example, using
a system architecture that’s able
to segment memory, thus isolating
privileges processes from
nonprivileged processes. Performing the offline
procedures that make or break
a secure system - by clearly
delineating system
administrator responsibilities,
by training users appropriately,
and by monitoring users to
Monitoring who can access what data, make sure that security policies
and for what purpose. Your system are observed. Also more global
might support discretionary access security management as
controls; with these, you determine figuring out what security
whether other people can read or threats dace your system and
change your data. Your system might what it will cost to protect
also have support mandatory access against it.
controls; with these, the system
determines access rules based on the
security levels of the people, the files,
and the other objects in your system. Ensuring that unauthorized users don’t
get into the system, and by encouraging
authorized users to be security-
conscious.

What is the difference between identification and authentication?

29
Reading 1 Vocabulary and Pronunciation
What kinds of Authentication is the process to allow users to confirm his or
Authentication do you her identity to a Web application. Human factors are often
know? Can you give any considered the weakest link in a computer security system.
examples? Which ones do Point out that there are three major areas where human-
you use and why? computer interaction is important: authentication, security
operations, and developing secure systems.
Current authentication methods can be divided into three
Pronounce the following
main areas:
words from the text with the
• Token based authentication
help of given transcriptions.
• Biometric based authentication
• Knowledge based authentication
authentication
Token based techniques, such as key cards, bank cards and
noun /ɔːˌθen.tɪˈkeɪ.ʃən/
smart cards are widely used. Many token-based authentication
technique
systems also use knowledge based techniques to enhance
noun /tekˈniːk/
security.
biometric
Biometrics offer automated methods of identity verification
adj /ˌbaɪəʊˈmetrɪk/
or identification on the principle of measurable physiological
measurable
or behavioral characteristics such as a fingerprint or a voice
adj /ˈmeʒərəbl/
sample. The characteristics are measurable and unique. These
identification
characteristics should not be duplicable, but it is unfortunately
noun /aɪˌdentɪfɪˈkeɪʃən/
often possible to create a copy that is accepted by the
enrollment
biometric system as a true sample.
noun /ɪnˈrəʊlment/
The process of the user’s registration with the biometric
geometry
system is called enrollment. Biometric systems can be used in
noun /dʒiˈɒmɪtri/
two different modes. Identity verification occurs when the
iris
user claims to be already enrolled in the system (presents an
noun /ˈaɪərɪs/
ID card or login name); in this case the biometric data
facial
obtained from the user is compared to the user’s data already
adj /ˈfeɪʃəl/
stored in the database. Identification (also called search)
recognition
occurs when the identity of the user is a priori unknown. In
noun /ˌrekəɡˈnɪʃən/
this case the user’s biometric data is matched against all the
signature
records in the database as the user can be anywhere in the
noun /ˈsɪɡnətʃər/
database or he/she actually does not have to be there at all. It
dynamics
is evident that identification is technically more challenging
noun /daɪˈnæmɪks/
and costly.
rhythm
There are lots of biometric techniques available nowadays. A
noun /ˈrɪðəm/
few of them are in the stage of the research only (e.g. the odor
digitalization
analysis), but a significant number of technologies is already
noun /ˈdɪdʒɪtəlizeiʃn/
mature and commercially available (at least ten different
microphone
types of biometrics are commercially available nowadays:
noun /ˈmaɪkrəfəʊn/
fingerprint, finger geometry, hand geometry, palm print, iris
amateur
pattern, retina pattern, facial recognition, voice comparison,
adj /ˈæmətər/
signature dynamics and typing rhythm).
30
Fingerprint identification is perhaps the oldest of all the
Match the following biometric techniques. The live fingerprint readers are most
transcriptions, A-Z, with the commonly based on optical, thermal, silicon or ultrasonic
highlighted words and principles.
pronounce them. The iris is the colored ring of textured tissue that surrounds
the pupil of the eye. Even twins have different iris patterns
and everyone’s left and right iris is different, too. Research
A /kjuː/
shows that the matching accuracy of iris identification is
B /raʊnd/ greater than of the DNA testing. The iris pattern is taken by a
C /ˈvɜːtʃuəli/ special gray-scale camera in the distance of 10–40 cm from
D /ˈaɪɡənˌfeis/ the camera. The camera is hidden behind a mirror, the user
E /əbˈzɔːb/ looks into the mirror so that he/she can see his/her own eye,
then also the camera can “see” the eye. Once the eye is stable
F /ˈretɪnə/ (not moving too fast) and the camera has focused properly,
G /ˈprɒpəli/ the image of the eye is captured.
H /ɪnˈveɪ.sɪv/ Retina scan is based on the blood vessel pattern in the retina
I /ˌsɪməlˈteɪniəsli/ of the eye. Retina scan technology is older than the iris scan
technology that also uses a part of the eye. The main
J /ˌɪnfrəˈred/
drawback of the retina scan is its intrusiveness. The method
K /ɪnˈtruːsɪv/ of obtaining a retina scan is personally invasive. A laser light
L /ˈkaʊn.təˌmeʒ.ər/ must be directed through the cornea of the eye. Also the
M /ˈkæptʃər/ operation of the retina scanner is not easy. A skilled operator
is required and the person being scanned has to follow his/her
N /dɪˈstɪŋɡwɪʃ/
directions.
O /ɪnˈtrenʃt/ Hand geometry is based on the fact that nearly every person’s
P /ɡrɪd/ hand is shaped differently and that the shape of a person’s
Q /ɡliːn/ hand does not change after certain age. Hand geometry
systems produce estimates of certain measurements of the
R /səˈfɪstɪkeɪtɪd/
hand such as the length and the width of fingers. Various
S /ˈækjərəsi/ methods are used to measure the hand. These methods are
T /strəʊk/ most commonly based either on mechanical or optical
U /ˈtɪʃuː/ principle. A few hand geometry scanners produce only the
video signal with the hand shape. Image digitalization and
V /ˈsiːkwəns/
processing is then done in the computer. On the other side
W /ˈkjuːmjələtɪv/ there exist very sophisticated and automated scanners that do
X /ˈvɜːsətaɪl/ everything by themselves including the enrollment, data
Y /ˈdiːkɔɪ/ storage, verification and even simple networking with a
Z /pəˈmjuːtid/ master device and multiple slave scanners.
The signature dynamics recognition is based on the dynamics
of making the signature, rather than a direct comparison of
Read the article once. Try to
the signature itself afterwards. The dynamics is measured as a
work out the meaning of the
means of the pressure, direction, acceleration and the length
highlighted words. Then
of the strokes, number of strokes and their duration. The most
match them with their
obvious and important advantage of this is that a fraudster
definitions, a-z. cannot glean any information on how to write the signature by

31
a._______________ verb to simply looking at one that has been previously written.
become part of something Facial recognition is the most natural means of biometric
identification. The method of distinguishing one individual
b._______________ verb to from another is an ability of virtually every human. The better
recognize the differences the image source (i.e. camera or scanner) is the more accurate
between two people, ideas, or
results we get. The facial recognition systems usually use
things
only the grayscale information. Colors (if available) are used
c._______________ adj as a help in locating the face in the image only. The lighting
moving into all areas of conditions required are mainly dependent on the quality of the
something and difficult to stop camera used. Facial recognition technology has recently
developed into two areas: facial metrics and eigenfaces.
d._______________ noun a Facial metrics technology relies on the measurement of the
part at the back of the eye,
specific facial features (the systems usually look for the
which is affected by light and
sends messages to the brain positioning of the eyes, nose and mouth and the distances
between these features). The method is based on categorizing
e._______________ noun a faces according to the degree of fit with a fixed set of 150
movement that you make master eigenfaces. This technique is in fact similar to the
against something with your police method of creating a portrait, but the image processing
hand, a pen, brush, etc. is automated and based on a real picture here. Better results
can be achieved if the operator is able to tell the system
f._______________ adj useful
for doing a lot of different exactly where the eyes are positioned. The systems also have
things problems to distinguish very similar persons like twins and
any significant change in hair or beard style requires re
g._______________ verb to enrollment. Glasses can also cause additional difficulties. The
discover information slowly or face recognition system does not require any contact with the
with difficulty person and can be fooled with a picture if no countermeasures
are active. The liveness detection is based most commonly on
h._______________ noun how
correct or exact something is facial mimics. The user is asked to blink or smile. If the
image changes properly then the person is considered “live”.
i._______________ adverb A few systems can simultaneously process images from two
almost cameras, from two different viewpoints. The use of two
cameras can also avoid fooling the system with a simple
j._______________ noun the
picture.
name given to a set of
eigenvectors when they are The principle of speaker verification is to analyze the voice of
used in the computer vision the user in order to store a voiceprint that is later used for
problem of human face identification/verification. Speaker verification and speech
recognition recognition are two different tasks. The aim of speech
recognition is to find what has been told while the aim of the
k._______________ verb to speaker verification is who told that. Speaker verification
get control of a place with
focuses on the vocal characteristics that produce speech and
force
not on the sound or the pronunciation of the speech itself. The
l._______________ adj so greatest advantage of speaker verification systems is that they
fixed or have existed for so do not require any special and expensive hardware. A
long that they cannot be microphone is a standard accessory of any multimedia
changed computer, speaker verification can also be used remotely via

32
m._______________ noun a phone line. A high sampling rate is not required, but the
series of related events or background (or network) noise causes a significant problem
things that have a particular that decreases the accuracy. The speaker verification is not
order
intrusive for users and is easy to use.
n._______________ adj light Palmprint verification is a slightly different implementation
that feels warm but cannot be of the fingerprint technology. Palmprint scanning uses optical
seen readers that are very similar to those used for fingerprint
scanning, their size is, however, much bigger and this is a
o._______________ noun a limiting factor for the use in workstations or mobile devices.
group of events that is part of a Hand vein geometry is based on the fact that the vein pattern
series
is distinctive for various individuals. The veins under the skin
p._______________ adj very absorb infrared light and thus have a darker pattern on the
advanced and works in a clever image of the hand taken by an infrared camera. The hand vein
way geometry is still in the stage of research and development.
DNA sampling is rather intrusive at present and requires a
q._______________ adverb form of tissue, blood or other bodily sample. This method of
correctly, or in a satisfactory capture still has to be refined. So far the DNA analysis has
way
not been sufficiently automatic to rank the DNA analysis as a
r._______________ noun an biometric technology. The analysis of human DNA is now
action taken against an possible within 10 minutes. At present DNA is very
unwanted action or situation entrenched in crime detection and so will remain in the law
enforcement area for the time being.
s._______________ adj Thermal imaging is similar to the hand vein geometry. It also
reached by gradually adding
uses an infrared source of light and camera to produce an
one thing after another
image of the vein pattern in the face or in the wrist.
t._______________ noun Identifying individuals by the ear shape is used in law
someone or something used to enforcement applications where ear markings are found at
lead a person or animal to a crime scenes. An ear shape verifier (Optophone) is produced
place so that they can be by a French company ART Techniques. It is a telephone-type
caught handset within which is a lighting unit and cameras which
capture two images of the ear.
u._______________ adj
interrupting a peaceful The body odor biometrics is based on the fact that virtually
situation, becoming involved in each human smell is unique. The smell is captured by sensors
something in a way that is not that are capable to obtain the odor from non-intrusive parts of
welcome the body such as the back of the hand.
Keystroke dynamics is a method of verifying the identity of
v._______________ adverb an individual by their typing rhythm which can cope with
happening or existing at the
trained typists as well as the amateur two-finger typist.
same time
Systems can verify the user at the log-on stage or they can
w._______________ noun a continually monitor the typist. These systems should be cheap
pattern or structure made from to install as all that is needed is a software package.
horizontal and vertical lines The US company AIMS is developing a system which scans
crossing each other to form the dermal structure under the fingernail.
squares
Knowledge based techniques are the most widely used
authentication techniques and include both text-based and

33
x._______________ adj picture-based passwords. Although there are different types of
changed sequence of authentication techniques available alphanumeric passwords
are the widely used because they are versatile and it is easy to
y._______________ noun the
implement and use. The text based passwords need to satisfy
material that animals and
plants are made of two contradictory requirements. That is it should be easily
remembered by the user and it should be hard to guess by an
z._______________ verb to attacker. So these text passwords are vulnerable to dictionary
give someone a signal to do attacks and brute force attacks.
something A graphical password is an authentication system that works
by having the user select from images, in a specific order,
Questions 1-10 presented in a graphical user interface (GUI). They can be
classified into three categories according to the task involved
Read the text again and in memorizing and entering passwords: recognition, recall,
match characteristics, 1-10, and cued recall.
with suitable type of A recognition-based scheme requires identifying among
authentication, A-O. decoys the visual objects belonging to a password portfolio. A
typical scheme is Passfaces wherein a user selects a portfolio
1. Based on the process, of faces from a database in creating a password. During
the way you make it authentication, a panel of candidate faces is presented for the
user to select the face belonging to her portfolio. This process
2. Better than the DNA is repeated several rounds, each round with a different panel.
A successful login requires correct selection in each round.
3. Has recently started to The set of images in a panel remains the same between logins,
be used as it took much but their locations are permuted. Story is similar to Passfaces
time before but the images in the portfolio are ordered, and a user must
identify her portfolio images in the correct order. Déjà Vu is
4. Needs no contact with also similar but uses a large set of computer generated
people “random-art” images. Cognitive Authentication requires a
user to generate a path through a panel of images as follows:
5. You need to follow starting from the top-left image, moving down if the image is
instructions in her portfolio, or right otherwise. The user identifies among
decoys the row or column label that the path ends. This
6. You will need to process is repeated, each time with a different panel. A
choose from pictures successful login requires that the cumulative probability that
correct answers were not entered by chance exceeds a
7. Can be used remotely threshold within a given number of rounds.
A recall-based scheme requires a user to regenerate the same
8. Is supposed to be cheap interaction result without cueing. Draw-A-Secret (DAS) was
the first recall-based scheme proposed. A user draws her
9. Based on optical and password on a 2D grid. The system encodes the sequence of
mechanical principle grid cells along the drawing path as a userdrawn password.
Pass-Go improves DAS’s usability by encoding the grid
10. Easy to use and carry intersection points rather than the grid cells. BDAS adds
out background images to DAS to encourage users to create more
complex passwords.

34
In a cued-recall scheme, an external cue is provided to help
memorize and enter a password. PassPoints is a widely
A token based
B fingerprint studied click-based cued-recall scheme wherein a user clicks
C finger geometry a sequence of points anywhere on an image in creating a
D hand geometry password, and re-clicks the same sequence during
E palm print authentication. Cued Click Points (CCP) is similar to
F iris pattern PassPoints but uses one image per click, with the next image
G retina pattern selected by a deterministic function. Persuasive Cued Click
H facial recognition
Points (PCCP) extends CCP by requiring a user to select a
I signature dynamics
J speaker verification point inside a randomly positioned viewport when creating a
K hand vein geometry password, resulting in more randomly distributed click-points
L DNA sampling in a password.
M keystroke dynamics (adapted from [Link] Vol.6 (1),
N text based passwords [Link] ITonIFaS Vol 9, [Link] IJSPTM
O graphical passwords Vol 2, [Link])

Questions 11-25

Complete the chart below with words from the text. Write NO MORE THAN THREE
WORDS for each answer.

text based recognition- recall-based


Token based based (Draw-A-Secret
easy to
(key, smart, 14_______ the (DAS), BDAS)
12_______, need to
bank 13_______ visual objects
from a password 15_______
11_______) to attacks interaction
portfolio
result

Authentication picture-
Knowledge
based
based
fingerprint
identification retina scan
intrusive and
18_______ Biometric cued-recall
iris pattern (PassPoints, Cued
based
the characteristics Click Points (CCP))
are 17_______, have 16_______ to
signature enter and memorize
hand measurable and
dynamics unique password
geometry
is based on the is based on
way of 20_______ measurements of
the signature DNA the body
the 19___ and
___ of fingers facial sampling odor
recognition takes the odor
palmprint (facial metrics, from 23______
verification eyegenfaces)
speaker focuses on the
verification measurements of keystroke
hand vein is based on the 21_______ thermal dynamics
geometry 22_______ imaging focuses on 24____
35
Listening
“A password should be like a
toothbrush. Use it every day; change
it regularly; and DON’T share it with
friends.”

You are going to listen to the interview


with David Emm, a Senior Security
Researcher at Kaspersky, UK Global
Research and Analysis Team.

What are the advantages Questions 1-2


and disadvantages of
Choose the correct 2 letters A, B or C.
passwords?
Can you recommend any 1. What are the most dangerous mistakes people make?
ways to protect A one password for all accounts
passwords? Do you agree B writing password everywhere
with the hints presented C recycling passwords
below?

Hints for protecting [Link] should people do?


A have a key word
passwords:
B have ways to create a unique password
 Don’t allow any C realize that password is your identity
logins without
passwords (every Questions 3-6
account must have
a password). Complete the table below. Write down NO MORE THAN
 Don’t keep THREE WORDS for each answer.
passwords that may
have come with How to create a unique password:
your system.
 Don’t ever let a. use the words that are not in the 3. __________.
anyone use your b. try not to use the words that are 4. __________.
password.
c. mix up letters, numbers and 5. __________ to 6.
 Don’t write your
__________.
password down.
 Don’t type a Question 7
password while
anyone is watching. Choose the correct 2 letters A, B or C.
 Don’t record your
7. What should people do to memorize their passwords?
password online or
A create their own formula
send it via e-mail.
 Don’t keep the B have favourite passphrase
same password C have the same part in all passwords
indefinitely.

36
What is a strong Questions 8-11
password? How to create
Complete the flow chart below. Write down NO MORE
it?
THAN THREE WORDS for each answer.
Step process of creating formula

take 8. __________ of the


word and move it to the end
Glossary:

jumble
verb /ˈdʒʌmbl/ ( also
jumble up) put 9. __________ after the
to mix things together third character
in an untidy way

reverse
verb /rɪˈvɜːs/ 10. __________ the fifth
to change a situation character
or change the order of
things so that it
becomes the opposite take another character and
11. __________ in that string
scramble
verb /ˈskræmbl/
to move or climb Questions 12-17
quickly but with Complete the sentences below. Write down NO MORE
difficulty, often using
THAN THREE WORDS for each answer.
your hands

enterprise 12. If you lose your password there is a __________ to reset it.
noun /ˈentəpraɪz/
13. This __________ feature is a great advantage for potential
a business or
organization attackers to apply to reset the password.
14. You should pick things for questions that are not easy to
vendor
__________ from social networks.
noun /ˈvendɔːr/
someone who sells 15. Kaspersky Lab offers an __________ producing unique
something outside passwords.
16. There is the risk in business that some third party can look
a password over __________.
17. One should be careful and keep the password in a
__________.

37
Speaking
Imagine you are members of the department responsible for security of the company. You
are supposed to present the best ways of protecting the data to the CEO. So you are to have
a meeting to discuss pros and cons of each type of authentication to choose the best one
that can meet the company’s security need. Choose the chairperson first. Practice using
“Useful language”.

Asking for opinions Giving opinions


What are your views? In my opinion…
How do you feel about? From a … point of view…
Do you think…? Personally I think…
Do we all agree? I really do think…
I’m inclined to think… I’m quite sure…
Agreeing Disagreeing
I agree completely. I’m afraid I can’t agree with that idea.
Yes, that’s an important point. I don’t think so.
Yes, definitely. Sorry, but I don’t agree.
Yes, … is right. Expressing reservations
Yes, I’d go along with that. You could be right, but…
Yes, I agree with that. Maybe, but…
The Chair Person:
Opening
Shall we start?
Starting objectives
The aim of the meeting is to…
Beginning of the discussion
…, would you like to start?
Interrupting
Just a minute, … , could I just ask something?
Before you go on could I say something?
Asking for clarification
Sorry, I don’t quite follow you. Could you explain what you mean by…
Checking agreement
Do we all agree then?
Moving on
Let’s move on to the next topic.
Concluding
Well, I think that’s everything. Is there anything else you want to discuss?
Summarizing
So, to sum up, we’ve agreed that…
Closing
Good. Let’s call it a day, then.

38
Reading 2 Vocabulary and Pronunciation
What is Encryption? Encryption
Although there are many ways to protect information from
Can you give definition of undesired access, including various physical security
Cryptography? techniques that prevent any access from unintended receivers,
it is most useful to safeguard data so that it can be transmitted
What kinds of Encryption over insecure networks, such as the Internet, without fear of
do you know?
compromise. Since the time of the ancient Egyptians,
cryptography, or the art of secret writing, has been employed to
What are their positive and
negative sides? What is the keep key information private.
difference between them? Encryption algorithms or ciphers are mathematical formulas or
functions applied to data to transform the unprotected
Read the article once. Find information, or plaintext or cleartext, into an unrecognizable
definitions of the following format commonly referred to as ciphertext. There are generally
words and pronounce two inputs to an encryption algorithm: a key and the plaintext
them: itself.3 In some cases the ciphertext is larger than its associated
plaintext or the same size. The goal is to make the time it
Cryptography
/krɪpˈtɒɡ.rə.fi/
would take to recover or decipher the plaintext, having only the
Cipher /ˈsaɪ.fər/ ciphertext and not the key, so long as to greatly exceed the
Plaintext /ˈpleɪnˌtɛkst/ time-value of the plaintext. Ideally, a strong algorithm and key
combination should take at least millions of years to break,
Ciphertext
based on mathematical predictions. Naturally, if an interloper
A key /kiː/
manages to somehow obtain the ciphertext and the key,
Decipher /dɪˈsaɪfər/
deciphering the information is as straightforward as it is for the
Brute-force methods /bruːt-
intended receiver, and therefore all security is lost.
fɔːs ˈmeθəd/
Much of security is predicated on strong methods of keeping
Symmetric encryption
encryption keys sacrosanct, in order to force attackers to use
/sɪˈmetrɪk ɪnˈkrɪpʃən/
brute-force methods, such as trying every possible key
A one-time pad /ˈwʌntaɪm
pæd/
combination with the use of fast computers. The ideal
algorithm is strong, meaning that the algorithm itself is
Substitution ciphers
/ˌsʌbstɪˈtjuːʃən/ relatively impervious to direct attack, leaving attempts to
Transposition ciphers derive or guess the key as the only practical avenue to breaking
/ˌtræ[Link]əˈzɪʃ.ən/ the encryption. The ideal encryption algorithm creates unique
Diffusion ciphers /dɪˈfju·ʒən/ ciphertext from the same plaintext for each key permutation,
The Avalanche effect among other traits.
/ˈævəlɑːnʃ ɪˈfekt/ So what exactly is a key? A key is simply a number with a
Block ciphers /blɒk/ predetermined length. Keys can be created or generated in
Stream ciphers /striːm/ many ways, but computers commonly generate them. Ideally,
Public key encryption each key is truly random, meaning that any possible key
Sender non-repudiation combination is equally likely and that keys are not generated in
/rɪˈpjuːdieɪʃən/ a predictable fashion. A random number generator (RNG) or a
A digital signature /ˈdɪdʒɪtəl pseudo-random number generator (PRNG) is frequently used
ˈsɪɡnətʃər/ for this purpose. The difference between an RNG and a PRNG
is that the RNG autonomously generates random numbers,
39
Match the following whereas a PRNG is computer-based and creates a somewhat
transcriptions, A-I, with random number based on seed values that are readily available
the highlighted words and within the computer. A significant threat to any PRNG is the
pronounce them. feasibility of regenerating the key if one can determine the seed
values.
A /siːd/ Encryption algorithms are divided into two families based on
B /ɪnˈvaɪə.lə.bl̩ / the key type: symmetric or secret key, and asymmetric or
C /beər/ public key encryption. In symmetric key encryption both the
D /ˈsækrəʊsæŋkt/ sender (encrypter) and receiver (decrypter) use the same secret
E /bʌlk/ key, so named because the strength of the system relies on the
F /daɪˈvʌldʒ/ key being known only to the sender and receiver. In
G /ˌfiːzəˈbɪləti/ asymmetric key encryption, the sender and receiver each have
distinct but mathematically related keys.
H /sjuːdəʊ-/
Symmetric encryption is the oldest form of encryption and
I /ˈbʌndl/
has been used to safeguard communications for over three
Read the article again. Try thousand years. All secret key algorithms or systems require
to work out the meaning of that the party generating the key share or transfer it to the other
the highlighted words. party in a secure manner. If the key is not transferred by some
means that prevents its interception by unintended receivers
Then match them with
and attackers, whatever strength is inherent in the algorithm is
their definitions, a-i.
compromised and the confidentiality of data encrypted with the
key cannot be guaranteed. Thus, when considering a symmetric
a._______________ verb to
key encryption scheme, it is equally important to evaluate the
give secret or private
key transfer mechanism.
information to someone
Figure 1 illustrates the encryption process using a symmetric
key cipher. Sometimes other values are provided to the
b._______________ verb to
encryption algorithm for initialization purposes. The resulting
carry something
ciphertext will bear no relation to the plaintext. Figure 2 shows
how decryption is accomplished by reversing the process. If
c._______________ adj too
values other than the key were used to initialize the encryption
important to be changed or
operation, they are required inputs to the decryption algorithm.
destroyed
The resulting plaintext will be a faithful reproduction of the
original plaintext. Using the wrong key in the decryption
d._______________ noun a
process, even if different from the correct key by just one bit,
number of things that are tied
results in meaningless output.
together

e._______________ noun
possibility to do

f._______________ adj the


source, beginning, random

g._______________ noun the


large size of something or
someone
40
h._______________ false

i._______________ adj that


must be respected and not
removed or ignored

Can you read the following


acronyms: RNG, PRNG,
RSA? Along the way, it was also determined that if the key was only
used once then destroyed, the resulting system, called a one-
The following are the secret
key algorithms listed in time pad, is mathematically proven to be unbreakable through
chronological order of their cryptanalysis. Naturally, a lot more keys have to be transferred
inception.
when using a one-time pad and the keys still need to be
Data Encryption Standard distributed in a secure manner, so this is not commercially
(DES) feasible.
DES is a standardized and Symmetric encryption algorithms are primarily used for bulk
published encryption
algorithm, approved by the encryption of data, such as an entire file, document, or bundle
U.S. Government in 1977 of transaction data. The two fundamental symmetric encryption
after considerable analysis.
The genesis of DES is traced
techniques are substitution and transposition. Substitution
back to a cipher termed ciphers are simple and operate by replacing each character with
Lucifer, invented by Horst another character, for example, the letter 'a' would be
Feistel of IBM. It uses a 56-bit
key, which is sometimes substituted for the letter 'g' every place it occurs. Substitution
7
stored with additional parity ciphers are rarely used today due to the ease in breaking them
bits, extending its length to 64 with frequency cryptanalysis, in which the frequency of
bits. DES is a block cipher
and encrypts and decrypts encrypted characters in the ciphertext is used to derive the
64-bit data blocks. Although plaintext. Figure 3 is an example of a substitution cipher.
at the time of its inception, the
effort to crack a 56-bit key
was considered so enormous
as to prevent brute-force
attacks, it is now considered
insecure, and all government
agencies must use algorithms
with longer keys, as
discussed below. Despite the
obsolescence of DES due to
its key length, it is quite
In contrast, transposition ciphers operate by moving plaintext
elegant and the most characters to new locations in the ciphertext, rather than by
cryptanalyzed algorithm in the substituting individual characters. An example of a simple
world, withstanding all attacks
on the algorithm itself. transposition cipher is the word jumble or cryptogram in a
newspaper. All the characters found in the plaintext are in the
RC4 ciphertext, but in different relative positions. Unlike a word
RC4 is a stream cipher, also
created in 1987, and its only
jumble, which is a random transposition, transposition-based
complexity is in the encryption works by moving characters around in a definite
generation of the keystream, pattern that is reversed to decrypt the ciphertext. Pure
which is potentially an
infinitely long sequence of key transposition ciphers are not used in modern cryptography
values, which start with a 40- because of the ease of computer-based cryptanalysis. Figure 4
or 128-bit key, and a 24-bit
is an example of a transposition cipher. The key for such a
initialization vector (IV).
cipher is a representation for the character replacement scheme.
41
The actual encryption step is
very simple; the keystream is
combined with the plaintext in
an XOR (XOR stands for
‘exclusive OR’ and is a
standard logical operation
performed on two values on a
bit-wise basis. If one value is
‘0’ and the other ‘1,’ the XOR
output is ‘1,’ whereas the XOR The principles of substitution and transposition are, however,
output is ‘0’ if either both
combined into diffusion ciphers, which are used for all modern
inputs are ‘0’ or ‘1.’ The XOR
operation is not only extremely symmetric key ciphers. Diffusion algorithms not only
fast, but has the useful substitute differing values for the plaintext characters, but also
property of being symmetric.
For example, if the first four spread the characters throughout the ciphertext. A significant
bits of the keystream and strength of many diffusion-based algorithms is that the same
plaintext are, respectively, character will actually be encrypted into a different symbol
‘1011’ and ‘0010,’ the result of
XORing them is ‘1001,’ the based on its location in the plaintext and the data that precedes
ciphertext. Notice how it.
decryption works: the
keystream is identical, so
The best secret key algorithms possess a property known as the
‘1011’ and ‘1001’ are XORed, Avalanche effect, in which even a one-bit change in the
resulting in ‘0010,’ the original plaintext results in changes in approximately one-half of all the
plaintext) operation. Using the
same key and IV, the ciphertext bits. Symmetric ciphers are fast and typically
keystream is totally compact in terms of their computer code size and memory
reproducible, so in practice requirements, which is important as encryption capabilities are
the sender and receiver using
this algorithm will each be extended to devices like PDAs and smart phones that have
generating an identical power, processor, and memory limitations.
keystream. RC4 is ten times
faster than DES.
Symmetric algorithms can be further divided into block and
RC5 stream ciphers. Block algorithms encrypt and decrypt a fixed-
RC5 is a fast, parameterized size block of cleartext and ciphertext, respectively, usually a
block cipher, with a variable
block size (32, 64 and 128 multiple of 64 bits. Stream ciphers, on the other hand,
bits), variable key size (0 to continuously encrypt any amount of data as it is presented,
2040 bits), and a variable
usually by mathematically combining the data with a
number of rounds (0 to 255),
or individual encryption keystream, an infinitely long key sequence that is generated
steps.RC5 is patented by based on a finite key starting value.
RSA. It can be used as a
drop-in replacement for DES, Public Key Encryption
with the block size set to 64 It was made by Ronald Rivest, Ari Shamir and Leonard
bits and the key size set to 56 Adleman, all researchers at MIT and inventors of the public
bits.
Triple DES (3DES) key encryption algorithm called RSA. RSA not only eliminated
Triple DES is simply three the need to transfer secret keys, but also facilitated convenient
successive encryptions with
[Link] is possible to use
and efficient encryption by removing the Diffie-Hellman
either 2 or 3 distinct keys with requirement of exchanging values back and forth.
3DES. Thus, for the three-key Figure 5a demonstrates how RSA works. Note that the public
case, one obtains the benefit
of a 168-bit key space with the and private keys referenced in the figure are part of the
known strength of the DES receiver's key pair. When the sender wishes to encrypt
algorithm. Performed information that only the receiver can decrypt, she uses the
correctly, 3DES is as
unbreakable a secret-key receiver's public key to encrypt. The public key, as the name
algorithm as any known, but it suggests, can be freely distributed in the clear. It can be sent
is slow. 3DES is defined as
ANSI standard X9.52.
42
via electronic or postal mail, posted on a billboard, or spoken
Advanced Encryption over the telephone without sacrificing any security. It is
Standard (AES) essential, however, that the private key be kept inviolable and
The National Institute of never shared or divulged to anyone.
Standards and Technology
(NIST) selected an algorithm
called "Rjindael" on October 2,
2000 as the AES in a multi-
year competition. AES
replaced DES. AES is
projected to provide secure
encryption of sensitive but
unclassified government
information until 2020. Rjindael
is a fast block cipher, with Note the fundamental differences between asymmetric and
variable key length and block symmetric key encryption. When using secret key ciphers,
sizes (each can be
independently set to 128, 192 there is a different secret key for each pair of parties
or 256 bits). AES became an communicating. In the public key case, there is just one key
official U.S. Government pair for each receiver, because the public key can be distributed
standard in 2002. Like DES
before it, AES is now widely to everyone who wants to send encrypted data to the receiver.
used for commercial and Having the public key allows senders to encrypt data, but
private encryption purposes.
One significant benefit of AES without the private key, they are unable to use the public key to
is that the algorithm is public, decrypt communications from anyone else using the same key
and its use is unrestricted, with pair.
no royalties or license fees
owed to the inventors or the Equally important as the advantages inherent in public key
government. encryption is the support for the properties of authentication
RSA is the undisputed leader
(identification of the sender) and sender non-repudiation (the
in public key encryption. The
algorithm's one-way function is inability of a sender to refute that they signed something
based on the intractability, or encrypted with their private key). Since anyone with the
mathematical difficulty, of
factoring the product of two sender's public key can decrypt a message encrypted by the
prime numbers. In RSA, the sender's private key, this type of encryption, called a digital
product of the prime numbers signature, does not protect the confidentiality of the message.
is the public key, and the two
prime numbers make up the The sender is prevented, however, from denying that he was
private key. If an attacker can the originator of the information thus signed, unless the private
factor the public key, the
private key is thus
key was compromised.
compromised, and it is (adapted from [Link]
possible to decrypt information
encrypted with the public key.

Writing
 Make a plan;
 Make sure you have an introduction, 2-3 paragraphs giving reasons and examples,
and a conclusion;
 Check for errors – spelling, grammar, punctuation and appropriate (formal) language;
 Make sure you answered all parts of the question;
 Check you have written enough (not more than about 290).

43
You should spend about 40 minutes on this task. Write at least 250 words.

Write about the following topic:

The importance of computers and networks and the information they store and communicate to
society today are equaled only by the threats to them. The recent departure of Google from
mainland China over a widely-publicized attack there on its e-mail system is an ominous reminder
of the growing attacks on data and communication networks. The encryption algorithms are in
many instances the only protection between our critical information and those who seek to
compromise and exploit it.
To what extend do you agree or disagree with this statement. Give reasons for your answer
and include any relevant examples from your own knowledge or experience.

 Don’t repeat the question in your introduction. Try to


paraphrase it;
 avoid repeating the same words, keep changing phrases to
show flexibility. Improve your written work by using a variety
of connecting words: though, unfortunately, consequently, in
addition (to), therefore, in fact, despite (the fact that),
however, although, also, what is more, more over, as a result
(of)…
 try to vary the sentence structures you use, different
grammar constructions like gerund, conditional sentences,
passive voice:
Many people believe that… – It is commonly believed that…,
Some people think that…- It is often thought that…,
It is considered by many that…
It is argued by some that…
Some people support the opinion that…;
 write complex sentences joining some sentences using
sequencing words and relative pronounce (which, that,
where, when). Be careful with punctuation (defining, non-
defining clauses);
 include opinions, reasons and examples to extend your
answer: for example/instance…; to illustrate…; as an
illustration,…; to give a clear example,…; this can be seen by..;
 conclusion is a short paragraph which summarises your
arguments. Don’t introduce new ideas!

44
Unit 3 Computer System Security
Revise and Check
CAN YOU…
…pronounce and give
definition of
…speak about authentication cryptography
Authentication and its biometric cipher
identification plaintext
types: token based, enrollment ciphertext
biometrics, iris a key
knowledge based retina decipher
accuracy brute-force
Passwords: cons and properly methods
pros, hints to protect capture symmetric
and create intrusiveness encryption
invasive a one-time pad
Cryptography sophisticated substitution
strokes ciphers
Encryption and its glean transposition
distinguishing ciphers
types (symmetric,
eigenfaces diffusion
public), their positive countermeasures ciphers
and negative sides simultaneously the Avalanche
and difference distinctive effect
between them absorb block ciphers
infrared stream ciphers
tissue public key
entrenched encryption
virtually sender non-
versatile repudiation
decoys a digital
…hold and rounds signature
permuted sacrosanct
take part in cumulative pseudo
a meeting cue seed
grid feasibility
sequence bear
jumble bulk
reverse bundle
scramble inviolable
enterprise divulge
…write an essay vendor

45
Unit 4 Network Security
Speaking and Vocabulary
1. Choose the most relevant definition of Network Security. Prove your choice.

Network security is protection of the access to files and


directories in a computer network against hacking,
misuse and unauthorized changes to the system

The authorization of access to data in a


network, which is controlled by the network
administrator. Users are assigned an ID
and password that allows them access to
information and programs within their
authority.

Network security is an over-arching term that describes


that the policies and procedures implemented by a
network administrator to avoid and keep track of
unauthorized access, exploitation, modification, or denial
of the network and network resources.
This means that a well-implemented network security
blocks viruses, malware, hackers, etc. from accessing or
altering secure information.

2. Study the following words. Work out definition for each.

Adware Back up Denial of Service Bot


Compromised Configure Validation Botnet
computer Extended Flash drives Drive-by download
Encryption Firewall Mobile device Instant messaging
Firmware Malware Spyware Peer-to-peer (P2P)
Key logger Software patches Vulnerability Trojan
Phishing Virus Payment Worm
URL Credit Card Data stewards Processing

46
3. Now work out definition for network security. Try to use words from exercise 2.
Explain how each of the word is connected with network security.

4. Fill in the gaps. Use words given in exercise 2.


a. ___________ a portable, wireless computing device that is small enough to be used
while held in the hand
b. ___________ widespread or extensive
c. ___________ software that is installed surreptitiously and gathers information about an
Internet user's browsing habits, intercepts the user's personal data, etc., transmitting this
information to a third party
d. ___________ a person responsible for the management of data elements
e. ___________ to try to obtain financial or other confidential information from Internet
users, typically by sending an email that looks as if it is from a legitimate organization,
usually a financial institution, but contains a link to a fake website that replicates the real
one
f. __________ to put together by supplying, arranging, or connecting a specific set of
internal or external components
g. __________ the process of converting data to an unrecognizable form
h. __________ a network security system, either hardware- or software-based, that controls
incoming and outgoing network traffic based on a set of rules
i. __________ to give official sanction, confirmation, or approval to, as elected officials,
election procedures, documents
j. __________ a continuous action, operation, or series of changes taking place in a
definite manner
k. ___________ any malicious computer program which misrepresents itself as useful,
routine, or interesting in order to persuade a victim to install it
l. ___________ capable of or susceptible to being wounded or hurt, as by a weapon
m. ___________ software that displays advertisements and is integrated into another
program offered at no charge or at low cost

5. Write 10 different sentences using words from exercise 2.

Reading

What are the main principles of WHAT IS NETWORK SECURITY?


network security? Try to work
them out without reading the Network Security is an organization’s strategy and
text. provisions for ensuring the security of its assets and of all
network traffic. Network security is manifested in an
Now read the text. Are those implementation of security policy, hardware, and software.
principles the same with yours? For the purposes of this discussion, the following approach
is adopted in an effort to view network security in its
entirety:
47
Policy
Note: The order of
Enforcement
question might differ
Auditing
from the text order.
The IT Security Policy is the principle document for
network security. Its goal is to outline the rules for
Questions 1-7 ensuring the security of organizational assets. Employees
Do the following statements today utilize several tools and applications to conduct
agree with the information business productively. Policy that is driven from the
given in the text? Write
organization’s culture supports these routines and focuses
T(true), F(false), NG(not given)
on the safe enablement of these tools to its employees. The
next to the sentences 1-7.
enforcement and auditing procedures for any regulatory
1. To understand what compliance an organization is required to meet must be
network security is we mapped out in the policy as well.
must take into account Enforcement
such things as: policy, Most definitions of network security are narrowed to the
enforcement, auditing. enforcement mechanism. Enforcement concerns analyzing
2. The main goal of network all network traffic flows and should aim to preserve the
security is to save confidentiality, integrity, and availability of all systems
information. and information on the network. These three principles
3. Network security is high- compose the CIA triad:
cost service. Confidentiality - involves the protection of assets from
4. Firewall is not important unauthorized entities
in the process of network Integrity - ensuring the modification of assets is handled in
security. a specified and authorized manner
5. Policy management can be Availability - a state of the system in which authorized
simplified by CIA. users have continuous access to said assets.
6. CIA is complexity, Strong enforcement strives to provide CIA to network
identity and availability. traffic flows. This begins with a classification of traffic
7. Additional services for flows by application, user, and content. As the vehicle for
network security are now content, all applications must first be identified by the
available as add-ons. firewall regardless of port, protocol, evasive tactic, or SSL.
Proper application identification allows for full visibility of
Questions 8-11 the content it carries. Policy management can be simplified
Choose the correct letter, A, B, by identifying applications and mapping their use to a user
C or D. identity while inspecting the content at all times for the
8. One of following terms is preservation of CIA.
not used in terms of The concept of defense in depth is observed as a best
network security: practice in network security, prescribing for the network to
A. Enforcement be secured in layers. These layers apply an assortment of
B. Policy security controls to sift out threats trying to enter the
C. Detection network:
D. Protection Access control
9. Which of those is the layer Identification
for controlling network: Authentication
A. Authentication Malware detection

48
B. Decryption Encryption
C. Adware File type filtering
D. Confidentiality URL filtering
10. Auditing gives company: These layers are built through the deployment of firewalls,
A. opportunity to fire intrusion prevention systems (IPS), and antivirus
people components. Among the components for enforcement, the
B. a chance to work out firewall (an access control mechanism) is the foundation of
new criteria for network network security.
security Providing CIA of network traffic flows was difficult to
C. opportunity to save accomplish with previous technologies. Traditional
time and money firewalls were plagued by controls that relied on
D. opportunity to start a port/protocol to identify applications—which have since
new project developed evasive characteristics to bypass the controls—
11. Next generation firewall and the assumption that IP address equates to a user’s
gives opportunity to: identity.
A. download content The next generation firewall retains an access control
easily mission, but reengineers the technology; it observes all
B. surf the internet traffic across all ports, can classify applications and their
C. observe the traffic content, and identifies employees as users. This enables
coming from all ports access controls nuanced enough to enforce the IT security
D. build up our own policy as it applies to each employee of the organization,
computer with no compromise to security.
Additional services for layering network security to
Glossary: implement a defense in depth strategy have been
incorporated to the traditional model as add-on
Enforcement the act of components. Intrusion prevention systems (IPS) and
compelling observance of antivirus, for example, are effective tools for scanning
or compliance with a law, content and preventing malware attacks. However,
rule, or obligation. organizations must be cautious of the complexity and cost
that additional components may add to its network
Integrity the condition of
security, and more importantly, not depend on these
being unified or sound in
additional components to do the core job of the firewall.
construction.
Auditing
Authentication the process The auditing process of network security requires checking
or action of proving or back on enforcement measures to determine how well they
showing something to be have aligned with the security policy. Auditing encourages
true, genuine, or valid. continuous improvement by requiring organizations to
reflect on the implementation of their policy on a
Malware software which is consistent basis. This gives organizations the opportunity
specifically designed to to adjust their policy and enforcement strategy in areas of
disrupt or damage a evolving need.
computer system. (adapted from [Link]

49
Listening and Speaking
1. Do you know what social Listen to a security expert James Lyne. How
engineering is? Try to guess and can you safe yourself from social engineering?
work out the meaning of it.
Questions 1-6
2. Now read the definition of social
engineering. Were you right? Complete the notes below.
Write down 5 main principles of Write NO MORE THAN THREE WORDS for
social engineering. each answer:

1. It is getting harder to crack the program


because programmers learn lessons about
Social engineering, in the context of how _________________________.
information security, refers to
2. Criminals have to move to new way that is
psychological manipulation of
called as ______________________.
people into performing actions or
3. This way is based on _____________ the
divulging confidential information.
things they shouldn’t or ____________ the
A type of confidence trick for the
information away.
purpose of information gathering,
4. First way of social engineering is
fraud, or system access, it differs
_____________________.
from a traditional "con" in that it is
5. __________________ is one of the main
often one of many steps in a more
principles of avoiding social engineering
complex fraud scheme.
attacks.
The term "social engineering" as an
act of psychological manipulation is 6. Create _________________. The more
also associated with the social controls your implement much more luck
sciences, but its usage has caught you can avoid attacks on your computer.
on among computer and
information security professionals. Questions 7-11
Choose the correct letter A, B, C or D.

7. New ways of cheating are emerging


because:
A. people are getting more stupid
Before you listen, try to
B. people learn their mistakes
predict what the answer
C. people are trying something new
will be
D. just for fun
8. The main principle of social engineering is:
A. to push person to press link and give
The recording will be played information away
ONCE only! B. to steal information
C. to get information by asking people he
or she knows
D. to guess the password
50
9. One of the methods based on tricking
Glossary: person on sending him e-mail. It’s called:
A. Fishing
Phishing is the attempt to acquire B. Phishing
sensitive information such as C. Cheating
usernames, passwords, and credit card D. Validating
details, often for malicious reasons, by 10. James shows how to:
masquerading as a trustworthy entity A. steal passwords
in an electronic communication. B. play game
Gmail- short for google mail. C. make up e-mail
D. buy a product
Intercept - to gain possession of (an 11. E-mail’s home page was looking:
opponent's pass), as in football or A. pretty normal
basketball. B. unusual
C. like new one
Awareness- the state or condition of
D. strange
being aware; having knowledge;
consciousness

3. You can see the graph below. It shows typical


social engineering scheme. Try to think over
different scenarios that can be connected with this
graph.

51
Writing
You should spend about 20 min on this task. Write at least 150 words.

This chart shows the distribution of malicious traffic sources detected inside healthcare
networks. Notice that the fourth largest source is “radiology imaging software.”

How many healthcare providers even realize that medical devices and radiology software
can be hacked? HIPAA network security requirements suggest these systems should be
locked-down. Write our own way of solving this problem by discribing a chart.

Useful vocabulary

Increases: a slight / notable / significant decrease in ...


a slight/constant/marked/substantial/increase in the downturn began in (month)
sales the situation began to deteriorate in (month)
an increase of about/roughly/approximately/in the number has continued to fall
the region of ... % Fluctuations:
a little over/above what we predicted a slow start developed into steady progress in
the recovery/upturn began in sales
an overall increase in . an initial upward trend was followed by ...
an upward trend in the demand for ... we note slight fluctuations through the year
sales reached record levels / reached a peak in normal seasonal variations are the cause of
a strong surge in the sales of .. occasional downward trend
by (month), the figure had risen to ... sales have been (rather) irregular
Decreases: the level / the rate has been unstable since ...
just under our target you will note a certain instability in the rate of

52
Unit 4 Network Security Revise and Check

CAN YOU… …give


definition of
…pronounce and give
Network
definition of:
security
adware

compromised computer

encryption

firmware

key logger
…speak about:
phishing
Network security
URL

back up Phishing

configure Social engineering


extended

firewall

malware

software patches

virus

Credit Card
…describe:
Denial of Service
Bar charts
validation

flash drives

mobile device

Spyware

Vulnerability 53

Payment
Unit 5 Online Banking Security
Speaking
1. Give the definition of online banking.

2. Study the main threats while using the internet. Give example of each when using
online banking systems.

3. Study the given graph. Give brief analysis of it. Use tips from the previous units.

54
Reading Vocabulary and Pronunciation
Do you use online banking Concerns About Electronic Banking
Since Electronic Banking is a new technology that has many
systems in everyday life? Write
pluses and minuses of it. capabilities and also many potential problems, users are
hesitant to use the system. The use of Electronic Banking has
Questions 1- 5 brought many concerns from different perspectives:
government, businesses, banks, individuals and technology.
Complete the sentences below. Government
Write down NO MORE THAN From a government point of view, the Electronic Banking
THREE WORDS for each system poses a threat to the Antitrust laws. Electronic
answer. Banking also arouse concerns about the reserve requirements
of banks, deposit insurance and the consumer protection laws
associated with electronic transfer of money. The US
1. US government
government is concerned with the use of high quality of
concerned with the use
encryption algorithms because encryption algorithms are a
of ___________ controlled military technology.
because they are to be Businesses
controlled by military Businesses also raise concerns about this new media of
technology. interaction. Since most large transfer of money is done by
businesses, these businesses are concern about the security of
their money. At the same time, these businesses also consider
2. Businesses concerns are
the potential savings in time and financial charges (making
usually connected with cash deposits and withdrawals which some banks charge
_______________. money for these processes) associated with this system.
Another businesses concern is connected to the customer.
3. Investing between time Businesses ponder the thought that there are enough potential
of deposit and the time customers who would not make a purchase because the
of withdrawal is called business did not offer a particular payment system (e.g.
electronic cash and electronic check). This would result in a
_______________.
loss of sales. On the other side of the coin, if this system
becomes wide spread, this would allow more buying power to
4. Individuals are the consumer which puts pressure on businesses to allow
concerned about consumers to use electronic transfer of money.
__________ access to Banks
Banks are pressured from other financial institutions to
their account and
provide a wide range of financial services to their customers.
_________ of their
Banks also profit from handling financial transactions, both
personal information. by charging fees to one or more participants in a transaction
and by investing the funds they hold between the time of
5. Keys areas in deposit and the time of withdrawal, also known as the
technology accepts are: “spread”. With more financial transactions being processed
by their central computer systems, banks are also concern
Security,
about the security of their system.
__________________. Individuals
55
Individuals are mainly concern with the security of the
system, in particular with the unwarranted access to their
Questions 6-10 accounts. In addition, individuals are also concern with the
secrecy of their personal information. 82% of American poled
Do the following statements expressed concern over privacy of computerized data. As
agree with the information given more and more people are exposed to the information
in the text? Write T(true), superhighway, privacy of information and the security that
F(false), NG(not given) next to goes hand and hand with this information is crucial to the
the sentences 6-10. growth of electronic transactions. Some privacy technologies
related to the electronic banking industry are electronic cash
6. Privacy section is not and electronic checks which will be discussed in the software
solution section.
so important in aspect
Technology
of security. In order to provide effective and secure banking transactions,
7. Authentication is one of there are four technology issues needed to be resolved. The
the ways to cheat on key areas are:
person. 1. Security
8. Online banking is one Security of the transactions is the primary concern of the
of the most safest ways Internet-based industries. The lack of security may result in
serious damages such as the example of Citibank illustrated in
to safe money. the earlier section.
9. Main concern of people The security issue will be further discussed in the next section
is privacy of their along with the possible attacks due to the insufficient
personal information. protections. The examples of potential hazards of the
[Link] lack of security can electronic banking system are during on-line transactions,
transferring funds, and minting electric currency, etc.
seriosly damage
2. Anonymity (Privacy)
banking system. Generally speaking, the privacy issue is a subset of the
security issue and thus will be discussed in the Privacy
Match the following Technology section later. By strengthening the privacy
transcriptions, A-P, with the technology, this will ensure the secrecy of sender’s personal
highlighted words and information and further enhance the security of the
pronounce them. transactions. The examples of the private information relating
to the banking industry are: the amount of the transaction, the
date and time of the transaction, and the name of the merchant
A. [ɪkˈspəʊz]
where the transaction is taking place.
B. [ˈhɛzɪt(ə)nt]
3. Authentication
C. [ˈmɜːtʃ(ə)nt] Encryption may help make the transactions more secure, but
D. [ˌvɛrɪfɪˈkeɪʃ(ə)n] there is also a need to guarantee that no one alters the data at
E. [ʌnˈwɒrəntɪd] either end of the transaction. There are two possible ways to
F. [kənˈsɜːn] verify the integrity of the message. One form of verification is
the secure Hash algorithm which is “a check that protects data
G. [trænˈzækʃ(ə)n]
against most modification.” The sender transmits the Hash
H. [θrɛt]
algorithm generated data. The recipient performs the same
I. [dɪˌvɪzɪˈbɪlɪtɪ] calculation and compares the two to make sure everything

56
J. [ɪnˈʃʊ(ə)rəns] arrived correctly.
K. [ˌɪnsəˈfɪʃ(ə)nt] If the two results are different, a change has occurred in the
message. The other form of verification is through a third
L. [ɔːˌθɛntɪˈkeɪʃ(ə)n]
party called Certification Authority (CA) with the trust of
M. [ˈs(j)uːpəˌhaɪweɪ] both the sender and the receiver to verify that the electronic
N. [ˌɪntəˈrækʃ(ə)n] currency or the digital signature that they received is real.
O. [wɪðˈdrɔːəl] 4. Divisibility
P. [ˈpɒndə] Electronic money may be divisible into different units of
currency, similar to real money. For example, electronic
money needs to account for pennies and nickels.
(adapted from [Link]

Try to work out the meaning of the highlighted words. Then match them with their
definitions, a-p.

a. _________________ noun a statement saying you will be harmed if you do not


do what someone wants you to do
b. _________________ verb to relate to (something or someone): to be about
(something or someone)
c. _________________ noun the capacity
of being divided
d. _________________ verb think about
or consider (something) carefully
e. _________________ noun evidence
that establishes or confirms the accuracy or
truth of something
f. _________________ noun the process
of determining whether someone or something
is, in fact, who or what it is declared to be
g. _________________ noun an agreement between a buyer and a seller to
exchange goods, services or financial instruments
h. _________________ noun a person who buys and sells commodities for profit;
dealer; trader
i. _________________ adj. slow to act or speak especially because you are
nervous or unsure about what to do
j. _________________ noun mutual or reciprocal action or influence
k. _________________ adj. lacking in what is necessary or required
l. _________________ noun any very fast route or course
m. _________________ verb to lay open to danger, attack, harm, etc.
n. _________________ adj. having no justification; groundless

57
o. _________________ noun an
agreement in which a person
makes regular payments to a
company and the company
promises to pay money if the
person is injured or dies, or to
pay money equal to the value of
something (such as a house or
car) if it is damaged, lost, or
stolen
p. _________________ noun the
act of taking money out of a bank account

Writing and Speaking

You should spend about 20 min on this task. Write at least 150 words.

Think over main principles of online banking. Do you agree with them?
The annual survey of 1,000 consumers was conducted for the ABA by Ipsos-Reid, an
independent market research firm, Aug. 14 to 16. A list of questions asked was designed to
take a snapshot of current consumer trends. You can see this graph below. Make an analysis.
What is your preferred banking method? Discuss pros and cons of them. Practice using
“Useful language”.

Useful language On the other hand, we can


Many people think… observe/notice/see that …
Let us consider what are the advantages and The other side of the coin is that …
disadvantages of … Another way of looking at this question is to
Let us start by considering the facts. …
It is generally agreed today that… One should, nevertheless, consider the
The first thing that needs to be said is … problem from another angle.
First of all, let us try to understand … One should, however, not forget that …
In conclusion, I can say that although .. On the other hand, …
To draw the conclusion, one can say that … Although …
The arguments we have presented … suggest Perhaps, we should also point out the fact
that … / prove that … / would indicate that … that …
From these arguments one must … / could… One must admit that …
/ might … conclude that … We cannot ignore the fact that …
Thus, … / Therefore,…
58
Listening

Write down minuses and pluses of You are going to listen to a financial expert Barbara
online banking. Check up your Shaw who explains how online banking can save
opinion with Barbara’s. you both time and money.

Questions 1- 7
You will only hear Complete the sentences below. Write down NO
each section ONCE! MORE THAN THREE WORDS for each answer.

1. For many people __________ and


____________ provided by online banking are
the best part.
Before you listen, try
to predict what the
2. By online banking system you can make a
answer will be
____________ and check_____________.
3. Many people spend much time sitting in front of
the kitchen table going over __________,
writing up___________ and putting them into
___________.
4. _______________ reduces the time you spend
Questions can be given on banking.
in paraphrased forms! 5. Online banking is easy way to____________.
6. Online banking can help us save __________
and _____________.
7. With bill service you can _____________ to
your bills.
59
Unit 5 Online Banking Security
Revise and Check
CAN YOU…

…pronounce and give


definition of

hesitant
…describe
concern
Graphs
threat

insurance

interaction

withdrawal

ponder

transactions

unwarranted

exposed

superhighway
…speak about:
insufficient
Online banking
authentication

merchant

verification

divisibility

60
Unit 6 Mobile Devices Security
Speaking
1. Study the graph. Give short analysis for it. Do you think that this graph is right for
nowadays?

2. Now work in pairs. Take a look at your partner’s cell phone. Explain what type of
phone is that. Use the chart below to help you.

61
Reading Vocabulary and Pronunciation
1. Do you think that mobile Cybercriminals developing complex hacks of mobile
security is important in devices
nowadays? Why? Prove What’s the future of cybercrime? In short, it’s mobile devices.
your point. That’s the new target for cybercriminals, and their attacks are
getting more sophisticated. One of the biggest innovations in
2. Match the following mobile technology is mobile banking, and cybercriminals are
transcriptions, A-K, with right on top of it with new ways to get into your account and
the highlighted words hack other vital information, says a new report from McAfee
and pronounce them. Labs.

A. [səˈfɪstɪkeɪtɪd]
B. [ˈluːkrətɪv]
C. [kənˈviːnɪənt]
D. [ʌn liːʃ]
E. [ˈmʊltɪtjuːd]
F. [prɒkˈsɪmɪtɪ]
G. [dɪˈsɛmɪneɪt]
H. [skæm]
I. [prəˈlɪfəreɪt]
J. [frɔːd]
K. [ˈvaɪtl]
“In today’s digital world, we use our smartphones for just
3. Read the article once. Try about everything, so the idea of paying with your mobile
to work out the meaning device sounds fun and convenient. That is until a
of the highlighted words. cybercriminal unleashes a near field communication (NFC)
Then match them with hack while you’re sitting on the bus on the way to work or
their definitions, a-k. standing in line at an amusement park,” says Lianne Caetano,
a. __________ adj. of or director of mobility product marketing at McAfee, in a post
relating to life about the report. “An NFC attack deploys viruses that
b. ___________ verb to
disseminate through proximity to quickly spread malware
abandon control of
c. ___________ adj. through a crowd, a process the McAfee Labs team calls
altered by education, ‘bump and infect.’ Once the malware infects a device, the
experience, etc., so as to scammer collects the details associated with your digital
be worldly-wise wallet account and secretly reuses these credentials to steal
d. __________adj. your money.”
suitable or agreeable to Caetano said NFC attacks are just one of several types of
the needs or purpose;
mobile scams that are expected to proliferate in 2013. As the
well-suited with respect
to facility or ease in use; smartphone market explodes, and the devices become capable
favorable, easy for use of more important transactions, the hacks are becoming more
e. ___________ verb to sophisticated, destructive and difficult to spot.
scatter or spread widely, In its newly released Mobile Security: McAfee Consumer
as though sowing seed; Trends Report, McAfee Labs identified and analyzed a
promulgate extensively; variety of mobile security threats. Here are two of the most
broadcast; disperse
common.
62
f. __________ noun a Bad Apps. Cybercriminals are going to great lengths to insert
great number of people bad apps into trusted sources such as Google Play, and using
gathered together; them as the gateway to a multitude of mobile hacks. McAfee
crowd; throng
Labs found that 75 percent of the malware-infected apps
g. ___________ noun
nearness in place, time, downloaded by McAfee Mobile Security users were housed in
order, occurrence, or the Google Play store, and the average consumer has a one-in-
relation. six chance of downloading a risky app. About a quarter of
h. ____________ adj. these risky apps contain both malware and a suspicious URL
profitable capable of generating click fraud or phishing schemes for
i. __________ noun a personal information.
confidence game or
Complex malware. McAfee Labs found that 40 percent of
other fraudulent
scheme, especially for malware misbehaves in more than one way. A complex attack
making a quick profit; helps criminals achieve success because they are hard to
swindle detect and they often take advantage of the specific
j. ___________ verb to technologies or vulnerabilities of a mobile device. Malware
increase in number or poses a real threat to consumers and can be very lucrative for
spread rapidly and often criminals.
excessively
The chart above shows a broad range of malicious or
k. __________ noun
deceit, trickery, sharp potentially undesirable attack methods associated with
practice, or breach of Android malware families from 2007 through 2012. About
confidence, perpetrated half of all malicious behaviors are related to either spying,
for profit or to gain which could mean a criminal is browsing your text message
some unfair or history, or sending handset information, said Caetano.
dishonest advantage
Caetano said it makes sense to pay attention to the
permissions requested by an app and keep an eye on monthly
4. Explain the graph
given in the text. Try bills to catch premium content fraud quickly. Also, look
to combine it with the carefully at the URL or address bar of all websites and apps,
information given in as attackers will lure users in by building a web page or link
the text. Use the with the common misspelling of a popular page or app. For
following tips to make example, if you’re searching for “[Link]” a criminal
a good speech. might build an attack around “[Link].”
“The moral of this mobile security story is that it’s time that
we all take mobile protection a little bit more seriously,” said
Caetano. (adapted from [Link]

Does the report have a suitable structure?


Does it have an introduction, body and conclusion?
Does it include connective words to make the writing cohesive within sentences and
paragraphs?
Does the report use suitable grammar and vocabulary?
Does it include a variety of sentence structures?
Does it include a range of appropriate vocabulary?
Does the report meet the requirements of the task?
Does it meet the word limit requirements?
Does it describe the whole graph adequately?
Does it focus on the important trends presented in the graphic information?

63
Listening
You are going to listen to a part of a program “How it
works”.

Questions 1- 7
Complete the sentences below. Write down NO
MORE THAN THREE WORDS for each answer.

1. Today our life is full of mobile devices, some of


the people check their phones __________ times a
day.
2. As mobile technology becomes more ___________
so do the security attacks.
3. _____________ is masquerading information as a
trusted source.
4. He downloads the version that already is bounded
with ______________.
5. Malware is short for ____________________.
You will only hear 6. Tapping into personal network is called
_____________.
each section ONCE!
7. The maker of real app is also unaware how their
app is being ______________.

Questions 8-10
Answer the questions below. Write down NO MORE
Before you listen, try THAN THREE WORDS for each answer.
to predict what the
answer will be 8. What is SDK?
9. What kind of processes does mobile security have?
10. What is the most important thing we carry about?

Questions 11-15
Do the following statements agree with the
information given in the recording? Write T(true),
Questions can be given F(false), NG(not given) next to the sentences 11-15.
in paraphrased forms!

11. It’s not important to check up mobile app before


using it.
12. Personal data is usually stored in safest place on the
phone.
Tasks are not always given
13. Phising is one of the hacking ways to get your
in the same order as the personal data.
text 14. Malware is always to hurt a device.
15. Social engineering is tapping into your own
network.

64
Writing
You should spend about 20 min on this task. Write at least 150 words. Analyze this graph
and work out how life changed during this period?
The green line on this chart represents mobile devices.
The orange line is viewing on desktop and notebook screens.

Read these sentences. Use the words you have learned to help you choose the correct
answers. Use new words in your writing task.

1. Please choose a username/security code/house number. It can be the same as your email address.
2. The receipt / address / password you entered is incorrect. Please try again.
3. You can find the security code / password / payment on the back of your card.
4. Please enter your name / security code / card number carefully, without any spaces.
5. Select your card's expiry date / account / receipt by using the drop down menu.
6. Please print your expiry date / postcode / receipt and keep it for your records.
7. To make online payments you need to set up a card number / account / computer.
8. You can add to or empty your account / payment / basket at any time.
9. When you are ready to pay you should proceed to the checkout / password /security code.
10. Please select a date from the expiry date / account / drop down menu.

65
Unit 6 Mobile Devices Security
Revise and Check
CAN YOU…

…describe
…pronounce and give
definition of line charts

sophisticated pie charts

vital

unleash

convenient

disseminate

proximity

scammer
…speak about:
proliferate
Smartphones
multitude
Online payments
fraud
Hacks of mobile
lucrative devices

66
Unit 7 Cloud Security
Speaking
1. Choose the most relevant definition of Cloud
Computing. Prove your choice.

Cloud computing is the latest


approach to provide computing
infrastructure, with the purpose to
shift the location of the computing
infrastructure to the network in order
Cloud computing is defined
to reduce the cost of management and
as a type of computing that
maintenance of hardware and
relies on sharing computing
software resources. resources rather than having
local servers or personal
devices to handle
applications.

“Cloud computing is a model for enabling


convenient, on-demand network access to a
shared pool of configurable computing resources
(e.g., networks, servers, storage, applications,
and services) that can be rapidly provisioned and
released with minimal management effort or
service provider interaction”

2. Give your own definition of Cloud Computing using information from the previous
ones.

67
3. In small groups talk about…

a. Service Models. Can you give any examples?

b. Three Deployment Models of Cloud. What is the difference between


them?

4. In pairs write down as many benefits of Cloud Computing as you can. Discuss them
with your groupmates to find out who has written more. Prove your ideas. Practice
using “Useful language”.

Useful language Another good thing about it is that…


It is true that / clear that / noticeable that… One argument in support of…
One should note here that… Firstly / Secondly / Finally…
It is undeniable that… What is more…
It is a well-known fact that… Besides /because it is…
Doubtless… Moreover…
One cannot deny that… In addition to…
Nevertheless, one should accept that… Furthermore, one should not forget that…

Reading Part 1 Vocabulary and Pronunciation

1. What kind of The Security, Privacy and Trust


challenges can you Challenges of Cloud Computing
face dealing with Security, Privacy and Trust are the three major
Cloud Computing? concerns about cloud computing. In the cloud computing
world the virtual environment lets user access computing
2. Match the following power. To enter this virtual environment a user is required to
transfer data throughout the cloud. Consequently several
transcriptions, A-O,
security concerns arise. Before assessing Security concerns of
with the highlighted
Cloud Computing let’s define the Security, Privacy and Trust.
words and pronounce
• Security is all about the maintenance of the confidentiality,
them.
availability and integrity of data or information. Security may
also include authentication, reliability, non-repudiation and
A /ˌʌndəˈlaɪɪŋ/ accountability. The fundamental property of security is the
B /kəmˈplaɪəns/ information or data must be closed to any unauthorized
68
C /ɪnˈteɡrəti/ person.
D /ˈæset/ • Privacy is a fundamental human right which concerns the
expression of various legal and non-legal norms regarding the
E /kənˈsent/
right to private life. Privacy also talks about the protection
F /ɪnˈhɑːns/ and appropriate use of the personal data. Organizations
G /nɒn- manage the privacy using application of laws, polices,
rɪˌpjuːdiˈeɪʃən/ standards and processes. The globally accepted privacy
H /əˌkaʊntəˈbɪləti/ principles: consent, purpose restriction, legitimacy,
I /əˌveɪləˈbɪləti/ transparency, data security and data subject participation.
• Trust can be defined as “ a psychological state comprising
J /trænˈspærənsi/
the intention to accept vulnerability based upon positive
K/ˌɪmplɪmenˈteɪʃən/ expectations of the intentions or behavior of another”. It
L /ˈliː.kɪdʒ/ revolves around ‘assurance’ and confidence that people, data,
M /kəˈmɪtmənt/ entities, information or processes will function or behave in
N /ˈkɒnsɪkwəns/ expected ways. Trust may be human to human, machine to
O /ˈækses/ machine, human to machine, or machine to human. Trust can
be regarded as a consequence of progress towards security or
privacy objectives.
3. Read the article once.
Challenges of Cloud Computing due its Underlying
Try to work out the
Technologies
meaning of the By the definition of cloud computing (by NIST), a
highlighted words. number of challenges for security, privacy and trust from the
Then match them underlying technologies (virtualization technology, grid
with their definitions, computing, web services, service-orientated architectures,
a-o. web application frameworks and encryption) of cloud
computing are:
a._______________ noun Area/ Security Privacy Trust
something that you must do Technology
that takes your time, obligation Segregation of Compromised
Virtualization Integrity personal virtual
b._______________ noun data on shared machines/
infrastructure hypervisors
making known secret
permit loss of
information
trust
Grid technology Availability Interoperability
c._______________ noun an
Web services Integrity and Security and Interoperability
obligation or willingness to confidentiality confidentiality
accept responsibility and The reliance of
perform periodic checks to be Service- Integrity distributed
certain that the policy is being orientated systems on
followed architectures different
security
d._______________ noun a credentials
realization of a technical Web application Integrity and Trust across
specification or algorithm as a frameworks availability distributed
program, software component, environments
or other computer system Encryption in Security and
through computer the Confidentiality Confidentiality
programming and deployment cloud context
69
e._______________ noun not Security challenges of Cloud computing:
being able to refuse, the Cloud computing is not secure by nature. The Security
verification of the identities of risks depend on the cloud services and deployment model.
individuals or companies
The security challenges related to Cloud computing are:
Users control over Cloud resources - Cloud users typically
f._______________ verb to
raise to a higher degree have no control over the Cloud resources. There is a risk of
data exposure to third parties on the Cloud or the Cloud
g._______________ noun provider itself. From a security perspective, data keepers of
clarity the Cloud computing have to ensure that each user can control
over his data or information.
h._______________ noun the Data secrecy & confidentiality - Encrypting data is a
result of an action or situation
common practice to protect secrecy and confidentiality of
data. End-users may hold the decryption keys that still leads
i._______________ noun the
component of information to some technical challenges.
assurance that focuses upon Access control and use of the data - The cloud computing
providing immediate access to requires the identity and access control management
mission critical data when it is measures. When data are trusted to a third party for handling
needed for decision making or storage within a common user environment, precaution
must be taken to ensure uninterrupted and full control of the
j._______________ noun ways
data.
of controlling who can see or
enter information on a Application & Platform Security - The application, which
computer system, to obtain or was developed for internal use, is now being used in cloud
retrieve (information) from a computing environment without addressing the risks of new
storage device technology. Migration to Cloud computing (the secure
development lifecycle of the organization) needs to be
k._______________ noun the changed to accommodate the Cloud computing risk context.
state of being whole and not
Privacy challenges of Cloud computing:
divided, the assurance that
information can only be In the Cloud-computing environment Cloud providers
accessed or modified by those can host or store important data, files and records of Cloud
authorized to do so users. It is difficult for companies and private users to control
the information or data all times they entrust to Cloud
l._______________ noun an suppliers. Some key privacy challenges particular to the
item of value owned; any data, Cloud-computing are:
device, or other component of
A_________________________ - Any type of information
the environment that supports
information-related activities can be hosted or managed by the Cloud providers. The
information may be highly confidential or extremely valuable
m._______________ noun as company asset. Then entrusting this information to a Cloud
permission, approval, or increases the risk because there is a possibility of cloud
agreement platform sharing by the competitors.
n._______________ noun the B_________________________ - The users of the same
practice of obeying rules or
Cloud share the server of data processing and the data storage
requests made by people in
authority procedures that must facilities, they are exposed to the risk of data or information
be followed leakage, either by accident or intentionally.
o._______________ adj basic, Data transfers to different locations - If the data on the
fundamental Cloud change the location regularly or reside on multiple

70
4. Read the article again locations, it becomes complicated to watch the data flows.
and choose the most Data transfers to other countries require arrangements to be
suitable topic placed. It will be complicated to fulfill these arrangements if
sentence, I-X, for each data locations are not stable.
paragraph, A-E, from C_________________________ - Companies engaging in
the list below. Cloud computing expect that the privacy commitments they
have made towards their customers, employees or other third
I. Management parties will continue to be carried out by the Cloud computer
problems provider. Trust challenges of Cloud computing:
II. Sensitivity of Trust is critical barrier that must be passed. Cloud
information customers must trust the cloud providers. Providers must trust
III. Users’ customers with access to the services which may lead to
security issue. If Cloud providers succeed in providing the
possibility to
solutions to Security and Privacy, they achieve success in the
access the data trustworthy services in cloud computing. They can enhance
IV. Trust in Cloud user’s confidence in the application of Cloud computing and
Providers would build the trust in the market of Cloud services.
V. Confidentiality Joining the Cloud by users/resources dynamically – In
of information cloud computing environment many users or resources join
and leave cloud dynamically. Users, resources and the cloud
VI. Data privacy
should establish the trustful relationships with each other and
VII. Leak of the data they should take into account the change which is happening
VIII. Trust dynamically.
enhancement Different Security policies – The cloud environment consists
through of distributed users and resources from different local systems
assurance that may have different security policies. This situation brings
up the question how to build a suitable relationship between
mechanisms
them?
IX. Continuity and D_________________________ - The complexity of Cloud
Provider architectures and the lack of transparency will increase the
Dependency security risk. In many Cloud implementations, the centralized
X. Privacy management and control introduces several single points of
preservation failure. These could threaten the availability of Cloud users’
data or computing capabilities indirectly.
Compliance with applicable regulations and good
practices - Once the applicable law to a Cloud service is
Do not expect the determined, the provider will need to comply with other
topic sentence or heading regulations such as privacy, General civil law and contract
to use the same words as law, Consumer protection law, etc.,
the text. They will E_________________________ - The Cloud-computing
probably be paraphrased. concept cannot guarantee full, continuous and complete
control of the Cloud users over their assets. For these reasons,
the establishment of appropriate “checks and controls” to
ascertain that Cloud providers meet their obligations becomes
very relevant for Cloud users.

71
Listening and Speaking

What kind of risks can you take dealing with Cloud Computing?
You are going to listen to the interview with Kristin Lovejoy, Vice President IBM Security
Strategy, Richard Cocchiara, CTO/IBM Business Continuity and Resiliency Services, and
RicTelford, Vice President IBM Cloud Services.

The recording will be


Section 1 Questions 1-10
played ONCE only!
Questions 1-3
What do responders worry about?
Before you listen, try to Write the correct letter, A-F, next to question 1-3.
predict what the answer
A Uptime/business continuity
will be.
B The data leakage
C Inability to customize applications
D Reducing the strength of corporate
The words you read will network security
E Data privacy
probably not be the
F Keeping safe your privacy
same as the ones you
hear, so be prepared to 1. 77% _______________
listen to synonyms or 2. 50% _______________
3. 23% _______________
paraphrases.
Questions 4- 9
Choose 6 great security threats in Cloud Computing, A-K.
Glossary:
breach noun the act or
A Handling over sensitive data to a 3rd person
a result of breaking;
tenant noun a group of
B Complying with the law
users who share a
C Loss of governance
D Lock in
common access with
E Accessibility of the data
specific privileges to
F Insider full of malice
the software instance; G Failure of isolation
back up verb to make a
H Insecure Interfaces
copy of information on
I Deletion of the data
your computer;
J Infrastructure failure
SLA Service level
K Management Interfaces
agreement

Question 10
Which threat does Richard Cocchiara agree with?
Choose 1 letter, A-K.

72
Which threats are the most and least dangerous from your point of view? Prove your
ideas. Practice using “Useful language”.

Useful language It seems to me…


I strongly believe that … As far as I'm concerned…

In my opinion… I'd like to point out that…

Personally, I think… I consider…

I'd say that… To my mind…

I'd suggest that… I’m inclined to think that…

Section 2 Questions 11-14


Choose the correct letter A, B, C or D.
Try to give an answer
for all the questions. 11. What does centrally managed mean?
Multiple Choice A apply the policy equally
questions in particular B push the policy down
are worth trying to
C well managed Cloud environment
answer, as you have a
chance of guessing the D apply a policy from the top and push it down
correct one. 12. Why can’t enterprises perform logging and auditing
themselves?
A too expensive
Skip any questions you
are not sure about, B hard to combine
rather than wasting too C impossible to combine
much time on a D difficult to implement
particular question. You
13. What is compelling statement about Cloud?
can come back to these
questions later. A updating
B patching
C delivering immediate control to all assets
D the ability to deliver security control
Some of the answers
14. What wasn’t mentioned by Kristin Lovejoy? Cloud can offer
you hear may be very
close in recording. better benefit with:
Always be ready to A right SLA
listen for the answer! B understanding of security architecture
C being centrally managed
D right provider

73
Section 3 Questions 15-23
Questions 15-19
Complete the flow chart below. Write down NO MORE
The information you THAN THREE WORDS for each answer.
need to answer the
How to get started in developing and executing
questions is in the
same order as it is on Cloud Security Strategy
the recording. Look at workload and 15____________:
the data, the sensitivity of the data,
16_____________, compliance
requirements

17_____________ to help build secure


cloud strategy
You may know the
answers due to your
knowledge, but your Negotiate your SLA. Make sure the SLA
answers cannot depend defines your responsibility, the provider’s
on that: you will need to responsibility, what you’re implementing
listen for to what the gives you some 18_____________ and
speakers say to identify looks at the standards.
the answer.

Assess your 19_____________,


management interface as well.

Questions 20-22
Do the following statements agree with the interviewers?
If you have to
complete the chart, Write T, F, NG on lines 20-22.
always write the words 20. Creating an architecture make sure yours combines with the
you hear on the cloud provider’s.
recording; do not use
21. The Cloud Provider should manage all your risks.
your own words.
22. Your strategy must be entire and cover all aspects.

Question 23
Which aspects weren’t mentioned? Choose 3 letters, A-K.

74
A physical security
B platform security
C application security
D data security
E network policy
F compliance requirements
G network
H access control
I data privacy
J identity management
K centralized policy

Reading Part 2 and Speaking

Questions 1-4 PROPOSED SOLUTIONS TO CLOUD COMPUTING


Choose the most suitable SECURITY, PRIVACY AND TRUST CHALLENGES
threat, A-H, for each For the above specified Cloud Computing Security,
paragraph, 1-4, from the Privacy and Trust Challenges, the following measures need to be
list below. considered.
The steps to be considered when moving to Cloud
A Shared Technology
environment
issues
Adapting a few guidelines will help protect users on the
B Isolation Failure
cloud environment. Cloud security mechanisms can be of two
C Data loss or leakage different categories: Partner-based (Security for SaaS, PaaS, IaaS)
D Protecting data or Userbased (client based).
policy
 Strategically plan your cloud security – Considering
E Compliance risk
security during the initial planning phase creates solid
F Account or Service foundation. Careful considerations must be taken how
Hijacking corporate workloads should be delivered to end users.
G Abuse and illegal
 Select the Cloud provider – It is crucial to choose a
use of cloud computing cloud provider who can protect your sensitive information
H Management or data. Before selecting cloud provider check whether
Interfaces they have experience in both IT and security services for
their strategic service performance assurances.
Questions 5-10
 Find the written document about security measures
Complete each of the provided by the cloud provider – This means getting
following sentences, 5-10, assurances from the cloud provider written into the
with the best ending, A- contract. The document must include applications,
L, from the list of infrastructure, configurations, policies, rules and
endings below. regulations.
75
 Find out who will monitor your data – Find out who
will access to data and why and when they are accessing
Try to predict how
it.
each sentence will end
 Have a plan for Security issues – What responsibility
before looking at the
the cloud provider is promising, and what actions he will
list of endings.
take during and after the security issue must be checked.
 Verify the access controls being used – Verify the
5. Before choosing access controls imposed on the data to ensure that the
cloud provider… third parties cannot access the data. It is important to
6. Determine
clearly define roles and responsibilities to ensure that even
responsibilities and
privileged users cannot skip auditing, monitoring and
roles…
testing, unless authorized.
7. Implement strong
 Monitoring system – Cloud provider must continuously
access control and
monitor data in the cloud. Establish cloud performance
authentification…
objectives and test regularly.
8. Implement strong
Measures to be taken for the top threats identified in the
API access control..
Cloud Computing
9. Security policy
For 1________________________
refers to …
 Care must be taken in Initial registration and Validation
10. Integrity and
process.
confidentiality of
 To use credit card in Cloud computing an Enhanced fraud
the data are
monitoring system must be implemented.
maintained by …
 Monitoring public blacklists for one’s own network
blocks.
A to prevent account For Insecure Interfaces and APIs
hijacking.  Cloud providers interfaces security model must be
B authentication. analyzed properly.
C to be sure that no one  Strong authentication and access controls must be
can access the data. implemented.
D encryption.  Understand the dependency chain associated with the
E to prevent isolation APIs.
failure. For Malicious Insiders
F identification.  Identify the human resources requirements as a part of
G to prevent insecure legal contracts.
interfaces.  Information security, management practices require
H find out what transparency.
experience he has.  Decide Security breaches.
I to ensure that others  Conduct survey on comprehensive supplier assessment
can monitor data. and implement strict supply chain management.
J check what In case of 2________________________
documents he has.  Best Security practices must be implemented for
K to prevent data installation or System configuration.
breach.  Unauthorized activities must be monitored.
L authorization.  Service level agreements must be enforced.
 Configuration audits and vulnerability scanning must be
76
Questions 11-16 conducted.
 Strong authentication and access control administrative
Complete the abstract access.
below with words from For 3________________________
the text. Write NO  Implement strong API access control.
MORE THAN ONE
 Specify backup and retention mechanisms
WORD for each answer.
 Analyze data protection at both design and run time.
Try to predict what  Necessary measures must be taken for strong key
generation, storage, and destruction practices.
kinds of words may be
With respect to 4________________________
missing by using your
 Implement strong monitory system to detect unauthorized
knowledge of
activity.
grammar. Your
 Sharing of account details between users and services must
answers need to be be avoided.
grammatically correct.  Read and understand properly cloud security policies.
Security requirements need to be considered with respect to
Cloud Computing has service models and cloud deployment models
emerged as a new A cloud customer needs to check the security state of the
paradigm of computing, cloud model before selecting cloud provider. For this an
that is built on the assessment must be performed in terms of security requirements.
foundations of Distributed The following table gives six security requirements with respect to
Computing, Grid Cloud Service Models and Cloud Deployment Models.
Computing, and
Virtualization.

Cloud computing has (A Check mark (√) indicates requirement in the Cloud Service
grown to provide a Models and Deployment models, while the asterisk (‫ )٭‬indicates
promising business optional)
concept for computing Identification and authentication methods include
infrastructure, where passwords, smartcards and biometrics. Authorization or access
11____________ are control refers to a set of security policies which defines users’
beginning to grow about permissions to access the resources in the cloud. Depending on the
how safe an environment way that the security policies are specified, access control can be
is. Security is one of the categorized into different models. Encryption is a core mechanism
major 12____________ in for maintaining the confidentiality of all data, whether it consists
cloud computing of business, personal or sensitive information, and it can also be
77
13____________. The aim used to establish the integrity of various transactions, code and
of this article is to address data. Encryption is considered as a security control on maintaining
the security, privacy and confidentiality and integrity. The uses of encryption in accessing
trust 14____________ of services in the cloud are similar to data protection as conventional
cloud computing and we technologies. Many public offered services are provided via an
15____________ some HTTPS-protocol connection to a web service, which works on the
solutions by analyzing the concept of Secure Socket Layer (SSL) protection.
technological, operational (adapted from International Journal of Computer Science and
and legal 16____________ Information Technologies [Link])
of cloud computing taking
into consideration cloud
customers.

Do you agree with solutions proposed by the authors of this article? Practice using
“Useful language”.

Useful language I don't agree with…


I agree with… I'm sorry to disagree with…
That's true that… I'm afraid I have to disagree…
I'd go along with… I'm not so sure about…

Writing
You should spend about 20 min on this task. Write at least 150 words.

The table from Reading Part 2 gives six security requirements with respect to Cloud
Service Models and Cloud Deployment Models.

Summarize the information by selecting and reporting the main features, and make
comparisons where relevant.

When you write about a chart or table you will receive marks for organizing and describing
all the information. You will not receive marks for giving reasons for the information or
giving your opinion about the information (but you will not lose marks if you do this). As
you have limited time and number of words, write about the information only.
Always use the present tense to describe a table, unless it contains information about a
time in the past or past dates, e.g. years, are used as categories.
Use the following structure for the introduction:
1) One or two sentences to explain what the table shows (Use different words from the
words used in the heading for the table wherever possible.)
2) One or two sentences summarizing the information shown in the table.
3) Do not include details in the introduction.

78
Unit 6 Cloud Security Revise and Check

…give definition of

CAN YOU… Cloud computing

…pronounce and give definition of


availability
integrity
non-repudiation
accountability
consent
transparency
consequence
underlying
access
asset
leakage
commitments
implementations
compliance
enhance
tenant

…speak about
Enhance
Service models
Deployment models
Cloud Computing challenges
Security threats in CC
Benefits of CC
…describe tables
Security strategy steps
Proposed solutions and measures to be
taken

79
Bibliography

[Link] Williams Writing for IELTS. – Collins, 2011.

[Link] - [Link]

[Link] - [Link]

[Link] - [Link]

[Link] About Electronic Banking - [Link]

[Link] developing complex hacks of mobile devices -


[Link]

[Link] vs. Information Security - [Link]

[Link] Russell, G.T. Gangemi Computer Security Basics

[Link] Van Geyte Reading for IELTS. - Collins, 2011.

[Link] Adams and Terry Peck 101 helpful hints for IELTS Academic Module

[Link] to prepare for a cybersecurity [Link]

[Link] to Cryptography [Link]

[Link] Grand A short guide to oral presentation in English. - ENSIEG

[Link] Black, Wendy Sharp Cambridge Objective IELTS

[Link] Cullen Cambridge Vocabulary for IELTS Advanced

[Link] Security [Link]

80
[Link] Hallows, Martin Lisboa, Mark Unwin IELTS Express Intermediate
Course book. - Thomson tm, 2006.

[Link] Engineering: an underestimated danger [Link]

[Link] Security, Privacy and Trust Challenges of Cloud Computing


[Link]

[Link] is Network Security [Link]

[Link]://[Link]

[Link]://[Link]

[Link]://[Link]

[Link]://[Link]

[Link]://[Link]/

[Link]://[Link]

81
Учебное издание

Валиева Гульнара Фирдусовна

Яруллина Диляра Алмазовна

English for Information Security

Подписано в печать 20.09.2015

Бумага офсетная. Печать цифровая.

Формат 60х84 1/16. Гарнитура «Times New Roman». Усл. печ. л. 4,77.

Уч.-изд. л. 4,46. Тираж 100 экз. Заказ 169/9

Отпечатано с готового оригинал-макета

в типографии Издательства Казанского университета

420008, г. Казань, ул. Профессора Нужина, 1/37

тел. (843) 233-73-59, 233-73-28

82

Common questions

Powered by AI

Different security policies in a cloud computing environment can introduce compatibility and integration challenges, potentially hindering smooth functionality. Variations in local system security measures require careful negotiation and alignment of policies to establish trust and avoid potential vulnerabilities. Such complexities necessitate robust relationship management between distributed users and cloud resources .

Cloud computing users face significant privacy and security challenges such as data leaks, lack of continuous control over their data, and complicated data transfers across international boundaries. These issues can significantly erode user trust, as users expect privacy commitments to be maintained even when data is hosted by third parties. The lack of transparency and centralized management increases security risks, leading to user dependency on cloud providers to meet privacy and security obligations .

Social engineers use a variety of tactics such as impersonating authority figures, baiting with too-good-to-be-true offers, exploiting familiarity, and using pretexting. These methods often involve psychological manipulation, leveraging the victim's naivety, or exploiting professional courtesies like holding doors open, to gain unauthorized access to secure areas or confidential information .

Hollywood often misrepresents cybersecurity professionals as the same as information security specialists, creating a public misconception that these two fields are identical. This portrayal oversimplifies the complexity and specialization within the fields and may lead prospective students to misunderstand what each discipline entails, thereby affecting their career decisions and expectations .

The lack of transparency in cloud architectures can obscure potential vulnerabilities and complicate risk management. Centralized control without clear oversight may present single points of failure, threatening data availability and security capabilities. This opacity can prevent users from effectively assessing provider compliance and implementing necessary security measures, increasing reliance on providers' assurances .

Cybersecurity focuses specifically on the protection of computer systems, networks, and data from unauthorized access, attacks, and damages. It's a subset of information security that primarily deals with internet threats, digital attacks, and securing digital information. Conversely, information security refers to a broader concept of protecting information in all its forms, which includes not only digital but also physical forms of data security, and addresses issues such as access control and confidentiality .

Handing over sensitive data to cloud providers can lead to a loss of direct data governance, as control shifts to third-party entities. This affects users' ability to enforce data management policies and ensures privacy compliance. Trusting providers with critical data necessitates reliance on their integrity and capabilities to fulfill privacy commitments, potentially risking exposure to breaches and introducing governance challenges .

Social engineers exploit social networks by accessing extensive personal data shared by users on platforms like LinkedIn and Facebook. By impersonating familiar contacts or using gained personal details, they breach social defenses, fostering trust to extract confidential information. This tactic is facilitated by users inadvertently sharing sensitive information, such as locations or behavioral patterns, on their profiles .

Encryption is essential in cloud computing as it helps protect the confidentiality and integrity of data by making it unintelligible to unauthorized users. This is critical for maintaining data privacy. However, encryption poses challenges, such as the requirement for users to manage decryption keys securely, potentially complicating data accessibility and usability while ensuring compliance with data protection regulations .

Trust in cloud environments can be established through transparency, comprehensive security policies, and regular audits. Standards and certifications ensure compliance, while service level agreements (SLAs) clearly define responsibilities. Adapting security strategies as users and resources dynamically interact helps maintain trust. Continuous education and updates on security practices also bolster trust in such a rapidly evolving environment .

You might also like