RSAC2020 £¨¶þ£©| ´ÓÁ¢ÒìɳºÐµÄ×ܽáÖР̸Á½¸ö·×ÆçÑùµÄ¿´·¨
Ðû²¼Ê±¼ä 2020-02-28RSAC2020Á¢ÒìɳºÐÆÀÑ¡¿¢Ê£¬£¬¸÷¸öÏà¹Ø´ÓÒµÕß¶¼ÁÄÁ˲»ÉÙ£¬£¬±¾ÆªÍ¨¹ý¶ÔÀúÄêRSACÁ¢ÒìɳºÐµÄÇéÐξÙÐÐÆÊÎö£¬£¬×ܽáÁËÁ½¸ö²î±ðµÄ¿´·¨£ºÍ¬ÊÇ×öÊý¾ÝÇå¾²µÄÆóÒµ£¬£¬½â¾öÎÊÌâµÄÊÖÒÕ˼Ð÷È´ÓÐÖʵIJî±ð£¬£¬»ñʤ²¢²»ÊÇÓÉÓÚAI£»£»Æ½Ì¨Àà²úÆ·ÓÀÔ¶ÊÇÍøÂçÇå¾²½çÈÆ²»¹ýÈ¥µÄ¸ß¼¶Ãż÷£¬£¬¸üÊÇÒµ½çµÄÖÆ¸ßµã¡£¡£
RSAC2020Á¢ÒìɳºÐËäÈ»»¨ÂäSECU RITI.AI£¬£¬Æä½¹µãÓªÒµÓëRSAC2018ÄêµÄ¹Ú¾üBigIDͬÊôÒ»À๫˾¡£¡£ËäÈ»Á½¼Ò¹«Ë¾¾ùÊÇÃæÏòÊý¾ÝÇå¾²£¬£¬µ«Æ¾Ö¤±ÊÕ߯ÊÎö£¬£¬Á½¼ÒÄܹ»»ñ¹ÚÉÐÓÐÆäËûÔµ¹ÊÔÓÉ¡£¡£
ÔÚÉÏÆª¡¶´ÓÓªÒµÊӽǿ´RSAC2020Á¢ÒìɳºÐµÄÇå¾²ÓªÒµ¡·ÎÄÕÂÖУ¬£¬±ÊÕßÒѶÔÈëΧ¹«Ë¾µÄ½¹µãÓªÒµ¡¢½¹µã²úÆ·¡¢½¹µãÌØÉ«ÊÖÒÕ¾ÙÐÐÐðÊö£¬£¬±¾ÆªÍ¨¹ý²¢¶Ô½üÈýÄêÁ¢ÒìɳºÐ¹«Ë¾µÄ½¹µãÊÖÒÕ¾ÙÐйéÀàºÍÕûÀí£¬£¬×ܽá³öÁ½¸ö·×ÆçÑùµÄ¿´·¨¡£¡£
ͬÊÇ×öÊý¾ÝÇå¾²µÄÆóÒµ£¬£¬½â¾öÎÊÌâµÄÊÖÒÕ˼Ð÷È´ÓÐÖʵIJî±ð£¬£¬»ñʤ²¢²»ÊÇÓÉÓÚAI¡£¡£
ƾ֤ÏÖ³¡ÏÈÈÝ£¬£¬ SECURITI.aiµÄPrivacyOpsƽ̨ÊÇÒÔAIÊÖÒÕΪ½¹µã£¬£¬Îª×éÖ¯ÌṩÐ×÷ºÍ×Ô¶¯»¯±àÅŵÄ×ÛºÏÐÔÆ½Ì¨¡£¡£PRIVACI.ai ͨ¹ý AI Çý¶¯µÄ PI £¨Ð¡ÎÒ˽¼ÒÐÅÏ¢£©Êý¾Ý·¢Ã÷¡¢ DSR £¨Êý¾ÝÖ÷ÌåȨ£©×Ô¶¯»¯¡¢ÎĵµÔðÈΡ¢Êý¾Ý´¦Öóͷ£¿É¼ûÐÔºÍ AI ×Ô¶¯»¯´¦Öóͷ££¬£¬À´×ÊÖúÆóÒµÓ¦¶ÔºÏ¹æÐèÇ󡣡£ËüËùÌṩµÄÒþ˽±£»£»¤ºÏ¹æ½â¾ö¼Æ»®µÄÒªº¦½¹µãÊÇ¡°¿ÉÒÔ×ÊÖú¿Í»§ÊµÏÖÒþ˽ºÏ¹æËùÐèµÄËùÓÐÖ÷Òª¹¦Ð§µÄ×Ô¶¯»¯¡£¡£"
¶øÔÚ2018ÄêÁ¢ÒìɳºÐÄÃϹھüµÄBigID£¬£¬ËäȻҲÊÇÊý¾ÝÇå¾²µÄ½â¾ö¼Æ»®ÌṩÉÌ£¬£¬Ö÷Òª×öÒÔÊý¾Ý±£»£»¤ÎªÖÐÐĵÄÒ»¿îƽ̨ÆÊÎöÀà²úÆ·¡£¡£Æä¸ü¶àµÄÒÀÍÐÊǺϹæÊг¡´øÀ´µÄ²úƷʱ»ú£¬£¬ÒÔ×ÊÖú¿Í»§Ó¦¶ÔGDPR¡¢PI¡¢PIIµÈÎ÷Å·ºÏ¹æÒªÇ󣬣¬×ÊÖúÆóÒµ¸üºÃ¼òÖ±±£ËûÃÇËùÓµÓÐÃô¸ÐÊý¾ÝµÄ˽ÃÜÐÔ£¬£¬ïÔÌÊý¾Ýй¶£¬£¬Ç¿»¯Êý¾ÝµÄºÏ¹æ±£»£»¤,ÕâµãÓë½ñÄê»ñʤµÄÊÖÒÕ˼Ð÷ÍêÈ«²î±ð¡£¡£
ÈôÊǽñÄê»ñʤÓÉÓÚAI£¬£¬ÏÔÈ»²»ÊÇ£¬£¬ÓÉÓÚ£¬£¬ÔÚ2018Ä꣬£¬Ò»ÆðÈëΧµÄ¾ÍÓÐÒ»¼Ò×öAIµÄ¹«Ë¾£¬£¬Ö»ÊÇÄÇËûÃÇʹÓÃAIÊÖÒÕÈ¥×öÁËÍþвȷÇ鱨ºÍÏÂÒ»´úÈëÇÖ¼ì²â¡£¡£²¢ÇҸù«Ë¾»¹ÓëÃÀ¹úÇ鱨ϵͳÏàÖú³¤´ï8ÄêÖ®¾Ã£¬£¬³ä·ÖʹÓÃÁËÃÀ¹úÇ鱨ϵͳµÄÍþвÊý¾Ý¡£¡£µ«×îÖÕÓÉÓÚÊÖÒÕÎüÒýÁ¦²»·ó£¬£¬Î´Äܸж¯µ½ÆÀί¡£¡£
Óɴ˿ɼû£¬£¬±¾½ìÆÀÎ¯×¢ÖØµÄ¿ÉÄܲ¢²»ÊÇÊÖÒÕ×Ô¼º£¬£¬¶ø¹Ø×¢µÄÖØµã·ÅÔÚÁ˺ϹæÉÏ£¡ÈçÖª×ãCCPA¡¢GDPR¡¢LGPD¡¢PI¡¢PIIµÈµÄºÏ¹æÒªÇ󡣡£±ÊÕßÒÔΪ£¬£¬Êý¾ÝÇå¾²×÷ΪÓû§µÄ½¹µãÐèÇ󣬣¬Î´À´¶¨»á»ñµÃ±¬·¢ÐÔÔöÌí¡£¡£¶øÏÖÔÚ£¬£¬Ðí¶àÈËÖ»¿´µ½Êý¾ÝÇå¾²µÄÊг¡Ê±»ú£¬£¬È´Î´¹Ø×¢Õâ¸öʱ»úÊÇ·ñÇкÏ×Ô¼ºµÄ½»¸¶ÄÜÁ¦¡£¡£±ÊÕßÒÔΪ£¬£¬º£ÄÚÍâÊý¾ÝÇå¾²Êг¡±£´æ¸ùÌìÐԵIJî±ð£¬£¬ÍâÑóÊÇÐèÒªÒÔ¿ìËÙʶ±ðÆóÒµÃæÁÙµÄÒþ˽״̬ºÍΣº¦¡¢¸ßЧ׼ȷµØÉ¨³ýΣº¦ºÍÍÆÐÐÖÖÖÖ¹æÔò£¨ÈçCCPA¡¢GDPR¡¢LGPD£©µÄºÏ¹æÒåÎñ¡£¡£Òò´Ë£¬£¬³ýÁËÊÖÒÕÊֶοÉÒÔ½è¼øÖ®Í⣬£¬ÖÎÀíÇéÐΡ¢ÖÎÀíÄ¿µÄÒªÒòµØÖÆÒË¡£¡£
ƽ̨Àà²úÆ·ÓÀÔ¶ÊÇÍøÂçÇå¾²½çÈÆ²»¹ýÈ¥µÄ¸ß¼¶Ãż÷£¬£¬¸üÊÇÒµ½çµÄÖÆ¸ßµã¡£¡£
ÎÒÃÇÔÚÒ»Á¬ÈýÄêµÄÁ¢ÒìɳºÐÈëΧÃûµ¥ÖУ¬£¬¶¼·¢Ã÷ÁËÖÖÖÖÆ½Ì¨µÄÉíÓ°¡£¡£ÎÞÂÛÕâЩƽ̨ÊÇÒÔÆÊÎöƽ̨¡¢Îó²îÖÎÀíÆ½Ì¨¡¢Íþвá÷ÁÔÆ½Ì¨¡¢ÔÆ·À»¤ºÍ¼ì²âƽ̨ÐÎ̬µÄ±£´æ£¬£¬ÕÕ¾ÉÒÔ×Ô¶¯»¯ÔËά¡¢ÊÓ²ìµÈÐÎ̬µÄ±£´æ£¬£¬ÉõÖÁ°üÀ¨ÖªÊ¶ÖÎÀíÓëÅàѵµÄƽ̨¡£¡£ÈôÊÇÎÒÃǰÑʱ¼ä±ê×¼·ÅµÄ¸ü³¤£¬£¬ÊÓÒ°¹æÄ£¿´µÃ¸ü¹ã£¬£¬»á·¢Ã÷ƽ̨»¯µÄ¼ùÐÐÒ»Ö±ÔÚÅ¹ú¼ÒÓÐןÜÊÇÖ÷ÒªµÄְ룬£¬ÓëÆ½Ì¨Ïà¹ØµÄ¸÷¸öÁìÓòµÄÁ¢ÒìÕߺÍÌôÕ½ÕßÒàÊÇ×î¶à¡£¡£
RSAC2020ÓÐÆ½Ì¨Àà²úÆ·£º
1¡¢Obsidian£º¾ß±¸Íþвá÷ÁÔÄÜÁ¦£¬£¬²¢ÄÜΪSaaSÓ¦ÓóÌÐòÌṩÇå¾²·À»¤ÔƼì²âÓëÏìӦƽ̨¡£¡£ËüµÄÀíÄîÊÇCDR(Cloud Detection and Response)ÄÜΪSaaSÓ¦ÓóÌÐòÌṩÇå¾²·À»¤£¬£¬×ÊÖúÇå¾²ÔËÓªÍŶӼì²â²¢ÏìÓ¦ÈëÇÖºÍÄÚ²¿Íþв£¬£¬×öµ½¿ìËÙ·¢Ã÷¡¢ÊÓ²ìºÍÏìÓ¦SaaSÓ¦ÓóÌÐòÖеÄÎó²îºÍÄÚ²¿Íþв£¬£¬ÔÚ²»Ó°ÏìÓªÒµµÄÇéÐÎÏÂʵÏÖÒ»Á¬µÄ¼à¿ØÓëÆÊÎö¡£¡£
2¡¢Elevate Security£ºÌṩµÄƽ̨ÊÇͨ¹ýͳһµÄ¿ÉÊÓ»¯ÊֶΣ¬£¬¼à²âºÍÖÎÀíÔ±¹¤µÄÇå¾²ÐÐΪ£¬£¬²¢ÓÐÖúÓÚÌáÉýÆóÒµÇå¾²ÎÄ»¯µÄÓʼþ·´ÏìºÍÇå¾²½ÌÓý×ÊÔ´¡£¡£Elevateƽ̨Ö÷ÒªÌṩÒÔÏÂËĸö¹¦Ð§Ä£¿£¿£¿£¿é£¬£¬ReflexÌá¹©ÍøÂç´¹ÂÚÓʼþ¹¥»÷Ä£Äâ¼°Ïà¹ØÐ§¹ûÆÀ¹À£»£»VisionÌṩÒDZíÅÌ£¬£¬½«´¹ÂÚÓʼþ¹¥»÷Ä£ÄâЧ¹û£¬£¬ÒÔAPI¼¯³É·½·¨£¬£¬°ÑÈËΪÒòËØÏà¹ØÇå¾²Êý¾ÝͳһÕûºÏ¼°ÆÊÎö£»£»PulseÌṩ¿ÉÉèÖõġ¢»ùÓÚÓʼþµÄÔ±¹¤ÆÀ¼¶·´ÏìϵͳºÍÇå¾²ÐÐΪÆÀ¼¶£»£»Hacker¡¯s MindÌṩ¹¥»÷ÕßÊӽǵÄÇå¾²Åàѵ£¬£¬½µµÍÔ±¹¤ÈËΪÒòËØ¹ØÁªµÄÇ徲Σº¦£¬£¬Ìá¸ßÔ±¹¤Çå¾²Òâʶ¡¢¸ÄÉÆÇå¾²ÐÐΪºÍ·À»¤ÄÜÁ¦¡£¡£
RSAC2019ÓÐÆ½Ì¨Àà²úÆ·£º
1¡¢Capsule8£º·À»¤Æ½Ì¨£¬£¬½â¾öÈκÎLinuxÉú²úÇéÐεķÀ»¤ÎÊÌ⣬£¬ÓÈÆäÊǶÔ0-dayµÄ·À»¤£¬£¬°üÀ¨ÈÝÆ÷¡¢ÔÆÐ§ÀÍÆ÷¡¢ÎïÀí»úµÄ·À»¤£¬£¬²¢ÔÚÌáÉý·À»¤ÄÜÁ¦µÄͬʱ£¬£¬ÐèÒª½µµÍÇå¾²ÔËÎ¬Ö°Ô±ÖØ´óÊÂÇéÁ¿¡£¡£
2¡¢DisruptOps£ºÔÆÇå¾²¼°×Ô¶¯»¯ÔËάÖÎÀí £¬£¬½â¾öÔÆ»ù´¡ÉèÊ©µÄÖÎÀíÎÊÌ⣬£¬ÔÚ½µµÍ¹¥»÷ÃæµÄͬʱ£¬£¬Ò²ÐèÒª¼õÇáÇå¾²ÔËÓªÍŶӵÄÊÂÇ鸺ºÉ¡£¡£ ƽ̨ͨ¹ýÒ»¸öSaaS»¯µÄÔÆÖÎÀíÆ½Ì¨GuardrailÀ´ÊµÏÖ¹ØÓÚÔÆ×ÊÔ´µÄ×Ô¶¯»¯¿ØÖÆ¡£¡£Í¨¹ý½¨ÉèÒ»Á¬µÄÇå¾²ÆÀ¹À£¬£¬´ÓÇå¾²¡¢ÔËά¡¢¾¼ÃÈý¸öά¶ÈÀ´Ê©¼ÓÕ½ÂÔ£¬£¬ÊµÏÖIAM¡¢Ò»Á¬¼à¿Ø¡¢ºÏÀí×éÍø¡¢Êý¾ÝÇå¾²´æ´¢»á¼ûµÈ¹¦Ð§¡£¡£
RSAC2018ÓÐÆ½Ì¨Àà²úÆ·£º
1¡¢Vulcan Cyber£º»¯±»¶¯Îª×Ô¶¯µÄÔÆ¶ËÎó²îÏìÓ¦×Ô¶¯»¯Æ½Ì¨£¬£¬ÎªÆóÒµÌṩÁËÒ»Ì××Ô¶¯»¯Îó²îÍþв»º½â£¨Auto mated Vulnerability Remediation£©½â¾ö¼Æ»®£¬£¬Í¨¹ý¶ÔÒÑÓпª·¢¡¢ÔËά¹¤¾ßµÄ¼¯³ÉÓëÕûºÏ£¬£¬ÊµÏÖ¶ÔÍ»·¢Çå¾²Îó²îµÄ¿ìËÙÏìÓ¦£¬£¬½«ÆóÒµÊܵ½Çå¾²ÍþвµÄʱ¼ä´°¿Ú´ÓÊýÖÜ¡¢ÊýÔÂËõ¶Ìµ½Ð¡Ê±¼¶¡£¡£Vulcan CyberÊÇÒµ½ç×Ô¶¯»¯Îó²î»º½â¿´·¨µÄÏÈÐÐÕߣ¬£¬Ò²ÊÇÔçÆÚÇå¾²±àÅÅ×Ô¶¯»¯ÓëÏìÓ¦SOAR£¨Security Orchestration, Automation and Res ponse£©µÄÆð¾¢ÏìÓ¦ÕßÖ®Ò»¡£¡£
2¡¢Awake Security£ºÌṩ»ùÓÚ»úеѧϰµÄÇå¾²ÆÊÎöƽ̨£¬£¬Á¬ÏµÍøÂçÁ÷Á¿µÈÊý¾Ý£¬£¬ÎªÇå¾²ÆÊÎöÖ°Ô±ÌṩÁËÒ»¸öÉÏÏÂÎĸ»ºñ¡¢¿ÉÒÔÒ»Á¬¾ÙÐÐ×·×ٵĸ߼¶ÆÊÎö¹¦Ð§ÏµÍ³£¬£¬ÊÇÒ»¸öÇå¾²ÊÓ²ìÆ½Ì¨£¨Security Investigation Platform £©£¬£¬Æ½Ì¨Ê¹ÓÃÍøÂçÊý¾ÝÀ´Ê¶±ðÇéÐÎÖеÄËùÓÐÏÖʵʵÌ壨Èç×°±¸£¬£¬Óû§ºÍÓòÃû£©£¬£¬È»ºó¹¹½¨Ò»¸öÆæÒìµÄÇ徲֪ʶͼÆ×£¨Security Knowledge Graph£©Êý¾ÝÄ£×Ó£¬£¬ÄÚÀï°üÀ¨ÁËʵÌå¼äÏêϸµÄÓ³Éä¹ØÏµ£¬£¬ÒÔ¼°Ã¿¸öʵÌåÖîÈç×°±¸ÀàÐÍ£¬£¬²Ù×÷ϵͳ¡¢Ó¦ÓÃÈí¼þ°æ±¾ºÍÐÐΪ»î¶¯µÈÐÅÏ¢¡£¡£
ƽ̨ÊÇÒ»ÖÖÄÜÁ¦½»¸¶£¬£¬¸üÊÇÒ»ÖÖÊÖÒÕ±ÚÀÝ¡£¡£ÍâÑóÊÇÕâÑù£¬£¬º£ÄÚ¸üÊÇ¡£¡£º£ÄÚÐí¶àµÄSOC¡¢CSA¡¢CDR¡¢MSSP¡¢MDRµÈϸ·ÖÁìÓòƽ̨ºÍÇå¾²ÔËÓª¡¢¶¼»áÔËÓª£¬£¬¶¼ÊÇÆ½Ì¨Á¢ÒìÕßÃÇ×îºÃµÄÃյס£¡£µ«Ë¼Á¿µ½Æ½Ì¨¿´·¨¼°ÄÚÔÚÍâÑÓºÜÊǸ»ºñ£¬£¬Òò´ËÖ»ÓаÑ×ÔÉíÊÓÒ°·Åµ½×ã¹»Ô¶´ó£¬£¬Â·²Å»áÔ½×ßÔ½¿í£¡
¿´µ½Òµ½çÁÐλ´ó¿§¸ø±¾´Î´ó»áÖ÷ÌâHuman ElementµÄÖ÷Ìâ·Ò룬£¬±ÊÕ߸üÇãÏò·Òë³É¡°È˵ÄÔªËØ¡±¡£¡£Õâ¸ö·Òë»ù±¾ÉÏÊÇÇкϾßÓÐÕ½ÂÔÍ·ÄԵĹú¼Ò¼ÛÖµ¹ÛÊöÇ󡣡£Human Element±»Ìá³öÒ²ÊǾßÓÐʱ´úÅä¾°µÄ£¬£¬¼´»úеºÍËã·¨µÄÊ¢ÐС£¡£µ±ÈË»ú¶Ô¿¹¡¢È˹¤ÖÇÄÜ¡¢»úеÉúÒâ¡¢»úе¾¯Ô±µÈÉøÍ¸µ½ÎÒÃÇÉúÑĵķ½·½ÃæÃæÊ±£¬£¬È˺ͻúеÊÇ·ñÄÜÇå¾²¹²´¦£¬£¬Ò²ÐíÊÇÒ»¸ö²©ÞĵÄÀú³Ì¡£¡£¶øÕâ¸ö²©ÞÄÀú³Ì£¬£¬º£ÄÚÔÝʱ»¹²»»áÂÄÀú£¬£¬ÓÉÓÚ»úе»¹Î´×ã¹»Å¡¢×ã¹»ÖÇÄÜ£¬£¬Õâ¾ÍÊÇ¡°ÊÖÒÕ²î±ð¡±¡£¡£Òò´Ë̸¡°ÈË¡±Õâ¸öÔªËØ£¬£¬ÐèÒªÓÐÕâÑùµÄÊÖÒÕÅä¾°È¥Ã÷È·¡£¡£


¾©¹«Íø°²±¸11010802024551ºÅ