Материал: English_for_IT_I-II_years

Внимание! Если размещение файла нарушает Ваши авторские права, то обязательно сообщите нам

WRITING

Imagine that you are to make a report on the following topics. While preparing it use the main information from the text.

1. How to become a computer graphics developer.

2. Advantages and disadvantages of 3D computer graphics.

3. 3D computer graphics in game industry.

UNIT 19

DATA PROTECTION

Vocabulary Bank Unit 19

Task 1. Read, write the translation and learn the basic vocabulary terms:

  1. black-hat hacker

  2. breaking open

  3. cash-dispensing systems

  4. computer extortion

  5. console operator

  6. cracker

  7. dark filters

  8. decryption

  9. distortion

  10. duplicate

  11. embedded

  12. encryption

  1. envisage

  1. fingerprints

  2. firewall

  3. firmware

  4. for abusing

  5. fraud

  6. fraudulent use

  7. freeware program

  8. harassment

  9. ill-intentioned use

  10. impose

  11. industrial espionage

  12. innocent-looking file

  13. intruder

  14. IP spoofing

  15. juristically fixed rules

  16. leak

  17. malicious software

  18. massifs

  19. personal enrichment

  20. personal privacy

  21. positive identification

  22. predator

  23. public cryptosystem

  24. ransom

  25. restrictions

  26. safeguarding

  27. security matrix

  28. shareware applications

  29. sneakernet crowd

  30. sniffer program

  31. spyware

  32. surge protector

  33. theft of data

  34. throughput

  35. to confine

  36. to forge

  37. to protect

  38. unsanctioned

  39. unscrupulous

  40. violators

  41. voiceprints

  42. white-collar crime

  43. worms

  44. write-protect measures

Text 18A. DATA PROTECTION

The computer industry has been extremely vulnerable in the mat­ter of security. Computer security once meant the physical securi­ty of the computer itself — guarded and locked doors. Computer screens were given dark filters so others could not easily see the data on the screen. But filters and locks by no means prevented access. More sophisticated security means safeguarding the computer sys­tem against such threats as burglary, vandalism, fire, natural di­sasters, theft of data for ransom, industrial espionage, and various forms of white-collar crime.

Rapid development of automation processes and the penetration of the computers in all fields of life have lead to appearance of a range of peculiar problems. One of these problems is the necessity of providing effective protection to information and means of its processing.

A lot of ways to access information, considerable quantity of qualified specialists, vast use of special technical equipment in social production make it possible for violators practically at any moment and in any place carry out the actions, which represent a threat to information safety.

Particular role in this process has been played by appearance of personal computer (PC), which has made computers, software and other informational technologies available to general public. Wide distribution of PC and impossibility of conducting effective control of their use have resulted in the decreasing security level of information systems.

The problem of information security is relatively new. Not all problems, connected with it have been figured out and solved up to now. The fact of great number of computer systems users means the definite risk to security because not all clients will carry out the requirements of its providing.

The order of storage mediums should be clearly defined in legal acts and envisage the complete safety of mediums, control over the work with information, responsibility for unsanctioned access to medium with a purpose of copying, changing or destroying them and so on.

There are some legal aspects of information protection, which can appear due to not carefully thought or ill-intentioned use of computer techniques:

  • Legal questions of informational massifs form distortions;

  • Security of stored information from the unsanctioned access;

  • Setting juristically fixed rules and methods of copyrights protection and priorities of software producers;

  • Development of measures for providing the juridical power to the documents, which are given to the machines;

  • Legal protection of the experts’ interests, who pass their knowledge to the databases;

  • Setting of legal norms and juridical responsibility for using electronic computer means in personal interests, which hurt other people and social interests and can harm them;

  • The lack of appropriate registration and control, low level of work and production personnel discipline, the access of an unauthorized persons to the computing sources create conditions for abusing and cause difficulties to their detection. In every computing canter it is usual to set and strictly follow the regulations of the access to different official rooms for employees of any categories.

The main purpose of information protection is preventing from the leak, theft, distortion, counterfeit of information; preventing the threat to person’s life and social safety, protection of the constitution and so on. The information is subjected to protection, when it may cause the harm for its owner, user or other person.

The development of computer technology and its wide use have lead to appearance and spread of computer crimes. Such situation causes alarm among those organizations and legislative institution that use computer technologies and, of course, people, who use new informational services at home.

The term “computer crime” was first used in the early 70s. However, the discussions concerning it are still actual. The top question of these discussions is “What unlawful actions are implied by computer crime”.

A rank of definitions of the computer crime has been composed. It often refers to crimes directly or indirectly connected to electronic computing machines and which includes a number of illegal acts, committed by means of electronic data processing system or against it. Others consider that computer crime is any action, which goes together with interfering with property rights and fulfilled by means of computers. The thirds think that computer crime can be defined as all intentional and unlawful actions, which lead to causing harm to possessions, with help of computers too.

There are following forms of computers criminality: computer manipulations, economic espionage, sabotage, computer extortion, “hacker” activity. The main character of committing computer crimes in the business field becomes highly qualified “white collars” from the suffered organization’s employees.

There are many causes, when “hackers” get a job with a goal of personal enrichment. But the most danger can represent such specialists, who are in collusion with managers of commercial structures and organized criminal groups; in these situations causing damage and weight of consequences considerably increases.

There are two types of unsanctioned access:

  • internal “breaking open” – the criminal has access to the terminal, with information he interested in and can work with it for some time without somebody’s control;

  • external “breaking open” – the criminal doesn’t have indirect access to the computer system, but has an opportunity of penetration to the protected system by means of remote access;

Analysis of such actions shows that single crimes from own or neighbor work places gradually develop into network computer crimes, which are carried out by means of breaking of organizations’ protecting systems.

Therefore the importance of information protection cannot be doubted. However, not only companies and state institutions need information protection system but also general home users need information protection system and should maintain the security of their computers.

Emphasis on Access and Throughput. For the last decade or so, computer programmers have concentrated on making it easy for people to use computer systems. Unfortunately, in some situations the systems are all too easy to use; they don’t impose nearly enough restrictions to safeguard confidential information or to prevent un­authorized persons from changing the information in a file.

It’s as if a bank concentrated all its efforts on handing out money as fast is it could and did very little to see that the persons who requested the money were entitled to it. Of course, a real bank works just the opposite way, checking very carefully before handing out any money. Computer systems that handle sensitive personal and financial data should be designed with the same philosophy in mind.

Positive Identification of Users. A computer system needs a sure way of identifying the people who are authorized to use it.

The identifi­cation procedure has to be quick, simple, and convenient. It should be so thorough that there is little chance of the computer being fooled by a clever imposter. At the same time, the computer must not reject legitimate users. Unfortunately, no identification system currently in use meets all these requirements.

At present, signatures are widely used to identify credit-card hold­ers, but it takes an expert to detect a good forgery. Sometimes even a human expert is fooled, and there is no reason to believe that a computer could do any better.

A variation is to have the computer analyze a person’s hand move­ments as he signs his name instead of analyzing the signature itself. Advocates of this method claim that different persons’ hand move­ments are sufficiently distinct to identify them. And while a forger might learn to duplicate another person’s signature, he probably would not move his hand exactly the way the person whose signa­ture he was forging did.

Photographs are also sometimes used for identification. But, peo­ple find it inconvenient to stop by a bank or credit card company and be photographed. Companies might lose business if they made the pictures an absolute requirement. Also, photographs are less useful these days, when people frequently change their appear­ance by changing the way they wear their hair. Finally, computer programs for analyzing photographs are still highly experimental.

Cash-dispensing systems often use two identification numbers: one is recorded on a magnetic stripe on the identification card, and the other is given to the cardholder. When the user inserts his card into the cash-dispensing terminal, he keys in the identification number he has been given. The computer checks to see that the number recorded on the card and the one keyed in by the user both refer to the same person. Someone who stole the card would not know what number had to be keyed in to use it. This method currently is the one most widely used for identifying computer users.

For a long time, fingerprints have provided a method of positive identification. But they suffer from two problems, one technical and one psychological.

The technical problem is that there is no simple system for com­paring fingerprints electronically. Also, most methods of taking fin­gerprints are messy. The psychological problem is that fingerprints are strongly associated in the public mind with police procedures. Because most people associate being fingerprinted with being ar­rested, they almost surely would resist being fingerprinted for rou­tine identification.

Voiceprints may be more promising. With these, the user has only to speak a few words into a microphone for the computer to analyze his voice. There are no psychological problems here. And technically it’s easier to take and analyze voiceprints than finger­prints. Also, for remote computer users, the identifying words could be transmitted over the telephone.

However, voiceprints still require more research. It has yet to be proved that the computer cannot be fooled by mimics. Also, tech­nical difficulties arise when the voice is subjected to the noise and distortion of a telephone line.

Even lip prints have been suggested. But it’s doubtful that kissing computers will ever catch on.

To date, the most reliable method of positive identification is the card with the magnetic stripe. If the technical problems can be worked out, however, voiceprints may prove to be even better.

Data Encryption. When sensitive data is transmitted to and from remote terminals, it must be encrypted (translated into a secret code) at one end and decrypted (translated back into plain text) at the other. Files also can be protected by encrypting the data before storing it and decrypting it after it has been retrieved.

Since it is impractical to keep secret the algorithms that are used to encrypt and decrypt data, these algorithms are designed so that their operation depends on a certain data item called the key. It is the key that is kept secret.

Even if you know all the details of the encrypting and decrypting algorithms, you cannot decrypt any mes­sages unless you know the key that was used when they were en­crypted.

For instance, the National Bureau of Standards has adopted an algorithm for encrypting and decrypting the data processed by fede­ral agencies. The details of the algorithm have been published in the Federal Register. Plans are under way to incorporate the algorithm in special purpose microprocessors, which anyone can purchase and install in his computer.

So the algorithm is available to anyone who bothers to look it up or buy one of the special purpose microprocessors. But the opera­tion of the algorithm is governed by a sixty-four-bit key. Since there are about 1022 possible sixty-four-bit keys, no one is likely to dis­cover the correct one by chance. And, without the correct key, knowing the algorithm is useless.

A recent important development involves what are called public- key cryptosystems.

In a public-key cryptosystem, each person using the system has two keys, a public key and a private key. Each person’s public key is published in a directory for all to see; each person’s private key is kept secret. Messages encrypted with a person’s public key can be decrypted with that person’s (but no one else’s) private key. Mes­sages encrypted with a person’s private key can be decrypted with that person’s (but no one else’s) public key.

Protection through Software. The software of a computer system, particularly the operating system, can be designed to prevent un­authorized access to the files stored on the system. The protection scheme uses a special table called a security matrix.

Each row of the security matrix corresponds to a data item stored in the system. Each entry in the table lies at the intersection of a particular row and a particular column. The entry tells what kind of access the person corresponding to the row in which the entry lies has to the data item corresponding to the column in which the entry lies.

Источник: https://studfile.net/preview/16433455/