RSAC2020 £¨¶þ£©| ´Ó´´ÐÂɳºÐµÄ×ܽáÖР̸Á½¸ö²»Ò»ÑùµÄ¸ÅÏë

°ä²¼¹¦·ò 2020-02-28

RSAC2020´´ÐÂɳºÐÆÀ±ÈʵÏÖ£¬¸÷¸öÓйشÓÒµÕß¶¼ÁÄÁ˲»ÉÙ£¬±¾ÆªÍ¨¹ý¶Ô»ýÄêRSAC´´ÐÂɳºÐµÄÇé¿ö½øÐзÖÎö£¬×ܽáÁËÁ½¸ö·ÖÆçµÄ¸ÅÏ룺ͬÊÇ×öÊý¾Ý°²È«µÄÆóÒµ£¬½â¾öÎÊÌâµÄ¼¼Êõ˼·ȴÓÐÖ浀ᅮ磬»ñʤ²¢²»ÊÇÓÉÓÚAI£»Æ½Ì¨Àà²úƷʼÖÕÊÇÍøÂ簲ȫ½çÈÆ²»ÍâÈ¥µÄ¸ß¼¼ûż÷£¬¸üÊÇÒµ½çµÄÔì¸ßµã¡£


RSAC2020´´ÐÂɳºÐ¹ÌÈ»»¨ÂäSECU RITI.AI£¬ÆäÖ÷ÌâÒµÎñÓëRSAC2018ÄêµÄ¹Ú¾üBigIDͬÊôÒ»À๫˾¡£¹ÌÈ»Á½¼Ò¹«Ë¾¾ùÊÇÃæÏòÊý¾Ý°²È«£¬µ«Æ¾¾Ý±ÊÕß·ÖÎö£¬Á½¼Ò¿ÉÄÜ»ñ¹Ú»¹ÓÐÆäËûÔ­Òò¡£


ÔÚÉÏÆª¡¶´ÓÒµÎñÊӽǿ´RSAC2020´´ÐÂɳºÐµÄ°²È«ÒµÎñ¡·ÎÄÕÂÖУ¬±ÊÕßÒѶÔÈëΧ¹«Ë¾µÄÖ÷ÌâÒµÎñ¡¢Ö÷Ìâ²úÆ·¡¢Ö÷ÌâÌØÉ«¼¼Êõ½øÐÐÂÛÊö£¬±¾ÆªÍ¨¹ý²¢¶Ô½üÈýÄê´´ÐÂɳºÐ¹«Ë¾µÄÖ÷Ìâ¼¼Êõ½øÐйéÀàºÍÕû¶Ù£¬×ܽá³öÁ½¸ö²»Ò»ÑùµÄ¸ÅÏë¡£


GA»Æ½ð¼×¡¤(ÖйúÇø)¹Ù·½ÍøÕ¾


ͬÊÇ×öÊý¾Ý°²È«µÄÆóÒµ£¬½â¾öÎÊÌâµÄ¼¼Êõ˼·ȴÓÐÖ浀ᅮ磬»ñʤ²¢²»ÊÇÓÉÓÚAI¡£


ƾ¾ÝÏÖ³¡½éÉÜ£¬ SECURITI.aiµÄPrivacyOpsƽ̨ÊÇÒÔAI¼¼ÊõΪÖ÷Ì⣬Ϊ×éÖ¯ÌṩºÏ×÷ºÍ×Ô¶¯»¯±àÅŵÄ×ÛºÏÐÔÆ½Ì¨¡£PRIVACI.ai ͨ¹ý AI Çý¶¯µÄ PI £¨Ó×ÎÒÐÅÏ¢£©Êý¾Ý·¢ÏÖ¡¢ DSR £¨Êý¾ÝÖ÷ÌåȨ£©×Ô¶¯»¯¡¢ÎĵµÔðÈΡ¢Êý¾Ý´¦ÖÿɼûÐÔºÍ AI ×Ô¶¯»¯´¦Öã¬À´Ô®ÊÔìóÒµÓ¦¶ÔºÏ¹æÐèÒª¡£ËüËùÌṩµÄÒþÖÔ±£»¤ºÏ¹æ½â¾ö¹æ»®µÄ¹Ø¼üÖ÷ÌâÊÇ¡°Äܹ»Ô®ÊÖ¿Í»§ÊµÏÖÒþÖԺϹæËùÐèµÄËùÓÐÖØÒªÖ°ÄܵÄ×Ô¶¯»¯¡£"


¶øÔÚ2018Äê´´ÐÂɳºÐÄÃϹھüµÄBigID£¬¹ÌȻҲÊÇÊý¾Ý°²È«µÄ½â¾ö¹æ»®ÌṩÉÌ£¬ÖØÒª×öÒÔÊý¾Ý±£»¤ÎªÖÐÐĵÄÒ»¿îƽ̨·ÖÎöÀà²úÆ·¡£Æä¸ü¶àµÄÒÀ¸½ÊǺϹæÊг¡´øÀ´µÄ²úÆ·»úÓö£¬ÒÔÔ®ÊÖ¿Í»§Ó¦¶ÔGDPR¡¢PI¡¢PIIµÈÅ·ÃÀºÏ¹æÒªÇó£¬Ô®ÊÔìóÒµ¸üºÃ¼òÖ±±£ËûÃÇËùÕ¼ÓÐÃô¸ÐÊý¾ÝµÄ˽ÃÜÐÔ£¬Ï÷¼õÊý¾Ýй¶£¬Ç¿»¯Êý¾ÝµÄºÏ¹æ±£»¤,ÕâµãÓë½ñÄê»ñʤµÄ¼¼Êõ˼·ÆëÈ«·ÖÆç¡£


ÈôÊǽñÄê»ñʤÓÉÓÚAI£¬ÏÔÈ»²»ÊÇ£¬ÓÉÓÚ£¬ÔÚ2018Ä꣬һ·ÈëΧµÄ¾ÍÓÐÒ»¼Ò×öAIµÄ¹«Ë¾£¬Ö»ÊÇÄÇËûÃÇÀûÓÃAI¼¼ÊõÈ¥×öÁËÍþвȷµý±¨ºÍÏÂÒ»´úÈëÇÖ¼ì²â¡£²¢ÇҸù«Ë¾»¹ÓëÃÀ¹úµý±¨ÏµÍ³ºÏ×÷³¤´ï8ÄêÖ®¾Ã£¬³ä·ÖÀûÓÃÁËÃÀ¹úµý±¨ÏµÍ³µÄÍþвÊý¾Ý¡£µ«×îÖÕÓÉÓÚ¼¼ÊõÎüÒýÁ¦²»¹»£¬Î´Äܸж¯µ½ÆÀί¡£


Óɴ˿ɼû£¬±¾½ìÆÀίע³ÁµÄ¿ÉÄܲ¢²»ÊǼ¼Êõ×ÔÉí£¬¶ø¹Ø×¢µÄ³Áµã·ÅÔÚÁ˺ϹæÉÏ£¡ÈçÂú×ãCCPA¡¢GDPR¡¢LGPD¡¢PI¡¢PIIµÈµÄºÏ¹æÒªÇó¡£±ÊÕßÒÔΪ£¬Êý¾Ý°²È«×÷ΪÓû§µÄÖ÷ÌâÐèÒª£¬½«À´¶¨»áµÃµ½·¢×÷ÐÔÔö³¤¡£¶øÈç½ñ£¬ºÃ¶àÈËÖ»¿´µ½Êý¾Ý°²È«µÄÊг¡»úÓö£¬È´Î´¹Ø×¢Õâ¸ö»úÓöÊÇ·ñÇкÏ×Ô¼ºµÄ½»¸¶ÄÜÁ¦¡£±ÊÕßÒÔΪ£¬¹úÄÚ±íÊý¾Ý°²È«Êг¡´æÔÚµ××ÓÐ﵀ᅮ磬¹ú±íÊDZØÒªÒÔ¼±¾ç¼ø±ðÆóÒµÃæ¶ÔµÄÒþÖÔÇé¿ö΢·çÏÕ¡¢¸ßЧÕýÈ·µØÅųý·çÏÕºÍÍÆ¹ã¸÷ÀàÂÉÀý£¨ÈçCCPA¡¢GDPR¡¢LGPD£©µÄºÏ¹æÊ¹Ãü¡£Òò¶ø£¬³ýÁ˼¼Êõ¼¿Á©Äܹ»½è¼øÖ®±í£¬ÖÎÀí»·¾³¡¢ÖÎÀíÖ¸±êÒªÒòµØÔìÒË¡£


ƽ̨Àà²úƷʼÖÕÊÇÍøÂ簲ȫ½çÈÆ²»ÍâÈ¥µÄ¸ß¼¼ûż÷£¬¸üÊÇÒµ½çµÄÔì¸ßµã¡£


ÎÒÃÇÔÚÂ½ÐøÈýÄêµÄ´´ÐÂɳºÐÈëΧÃûµ¥ÖУ¬¶¼·¢ÏÖÁ˸÷ÀàÆ½Ì¨µÄÉíÓ°¡£ÎÞÂÛÕâЩƽ̨ÊÇÒÔ·ÖÎöƽ̨¡¢·ì϶ÖÎÀíÆ½Ì¨¡¢Íþвá÷ÁÔÆ½Ì¨¡¢ÔÆ·À»¤ºÍ¼ì²âƽ̨״̬µÄ´æÔÚ£¬»¹ÊÇÒÔ×Ô¶¯»¯ÔËά¡¢µ÷²éµÈ״̬µÄ´æÔÚ£¬ÉõÖÁÔ̺¬ÖªÊ¶ÖÎÀíÓëÅàѵµÄƽ̨¡£ÈôÊÇÎÒÃǰѹ¦·ò³ß¶È·ÅµÄ¸ü³¤£¬ÊÓÒ°ÁìÓò¿´µÃ¸ü¹ã£¬»á·¢ÏÔì½Ì¨»¯µÄ¼ùÐÐÒ»ÏòÔÚÅ¹ú¶ÈÓÐ׿«¶È³ÁÒªµÄְ룬ÓëÆ½Ì¨Óйصĸ÷¸öÁìÓòµÄ´´ÐÂÕߺÍÌôÕ½ÕßÒàÊÇ×î¶à¡£


RSAC2020ÓÐÆ½Ì¨Àà²úÆ·£º


1¡¢Obsidian£º¾ß±¸Íþвá÷ÁÔÄÜÁ¦£¬²¢ÄÜΪSaaSÀûÓ÷¨Ê½Ìṩ°²È«·À»¤ÔƼì²âÓëÏìӦƽ̨¡£ËüµÄÀíÏëÊÇCDR(Cloud Detection and Response)ÄÜΪSaaSÀûÓ÷¨Ê½Ìṩ°²È«·À»¤£¬Ô®ÊÖ°²È«ÔËÓªÍŶӼì²â²¢ÏìÓ¦ÈëÇÖºÍÄÚ²¿Íþв£¬×öµ½¼±¾ç·¢ÏÖ¡¢µ÷²éºÍÏìÓ¦SaaSÀûÓ÷¨Ê½Öеķì϶ºÍÄÚ²¿Íþв£¬ÔÚ²»Ó°ÏìÒµÎñµÄÇé¿öÏÂʵÏÖ³ÖÐøµÄ¼à¿ØÓë·ÖÎö¡£


2¡¢Elevate Security£ºÌṩµÄƽ̨ÊÇͨ¹ýͳһµÄ¿ÉÊÓ»¯¼¿Á©£¬¼à²âºÍÖÎÀíÔ±¹¤µÄ°²È«ÐÐΪ£¬²¢ÓÐÖúÓÚÌáÉýÆóÒµ°²È«ÎÄ»¯µÄÓʼþ·´À¡ºÍ°²È«½ÌÓý×ÊÔ´¡£ElevateÆ½Ì¨ÖØÒªÌṩÒÔÏÂËĸöÖ°ÄÜÄ£¿é£¬ReflexÌá¹©ÍøÂç´¹µöÓʼþ¹¥»÷·ÂÕÕ¼°ÓйØÁË¾ÖÆÀ¹À£»VisionÌṩÒDZíÅÌ£¬½«´¹µöÓʼþ¹¥»÷·ÂÕÕÁ˾Ö£¬ÒÔAPI¼¯³É·½Ê½£¬°Ñ±¨´ð³É·ÖÓйذ²È«Êý¾ÝͳһÕûºÏ¼°·ÖÎö£»PulseÌṩ¿ÉÅäÖõġ¢»ùÓÚÓʼþµÄÔ±¹¤ÆÀ¼¶·´À¡ÏµÍ³ºÍ°²È«ÐÐΪÆÀ¼¶£»Hacker¡¯s MindÌṩ¹¥»÷ÕßÊӽǵݲȫÅàѵ£¬½µµÍÔ±¹¤±¨´ð³É·Ö¹ØÁªµÄ°²È«·çÏÕ£¬Ìá¸ßÔ±¹¤°²È«Òâʶ¡¢¸ÄÉÆ°²È«ÐÐΪºÍ·À»¤ÄÜÁ¦¡£


RSAC2019ÓÐÆ½Ì¨Àà²úÆ·£º


1¡¢Capsule8£º·À»¤Æ½Ì¨£¬½â¾öÈκÎLinux³ö²ú»·¾³µÄ·À»¤ÎÊÌ⣬ÓÈÆäÊǶÔ0-dayµÄ·À»¤£¬Ô̺¬ÈÝÆ÷¡¢ÔÆ·þÎñÆ÷¡¢ÎïÀí»úµÄ·À»¤£¬²¢ÔÚÌáÉý·À»¤ÄÜÁ¦µÄͬʱ£¬±ØÒª½µµÍ°²È«ÔËάÈËÔ±¾Þ´ó¹¤×÷Á¿¡£


2¡¢DisruptOps£ºÔư²È«¼°×Ô¶¯»¯ÔËάÖÎÀí £¬½â¾öÔÆ»ù´¡ÉèÊ©µÄÖÎÀíÎÊÌ⣬ÔÚ½µµÍ¹¥»÷ÃæµÄͬʱ£¬Ò²±ØÒª¼õÇᰲȫÔËÓªÍŶӵŤ×÷¸ººÉ¡£ ƽ̨ͨ¹ýÒ»¸öSaaS»¯µÄÔÆÖÎÀíÆ½Ì¨GuardrailÀ´ÊµÏÖ¶ÔÓÚÔÆ×ÊÔ´µÄ×Ô¶¯»¯½ÚÔ졣ͨ¹ý³ÉÁ¢³ÖÐøµÄ°²È«ÆÀ¹À£¬´Ó°²È«¡¢ÔËά¡¢¾­¼ÃÈý¸öά¶ÈÀ´Ê©¼ÓÕ½Êõ£¬ÊµÏÖIAM¡¢³ÖÐø¼à¿Ø¡¢ºÏÀí×éÍø¡¢Êý¾Ý°²È«´æ´¢½Ó¼ûµÈÖ°ÄÜ¡£


RSAC2018ÓÐÆ½Ì¨Àà²úÆ·£º


1¡¢Vulcan Cyber£º»¯±»¶¯Îª×Ô¶¯µÄÔÆ¶Ë·ì϶ÏìÓ¦×Ô¶¯»¯Æ½Ì¨£¬ÎªÆóÒµÌṩÁËÒ»Ì××Ô¶¯»¯·ì϶Íþв»º½â£¨Auto mated Vulnerability Remediation£©½â¾ö¹æ»®£¬Í¨¹ý¶ÔÒÑÓпª·¢¡¢ÔËά¹¤¾ßµÄ¼¯³ÉÓëÕûºÏ£¬ÊµÏÖ¶ÔÍ»·¢°²È«·ì϶µÄ¼±¾çÏìÓ¦£¬½«ÆóÒµÊܵ½°²È«ÍþвµÄ¹¦·ò´°¿Ú´ÓÊýÖÜ¡¢ÊýÔÂËõ¶Ìµ½Ó×ʱ¼¶¡£Vulcan CyberÊÇÒµ½ç×Ô¶¯»¯·ì϶»º½â¸ÅÏëµÄÏÈÐÐÕߣ¬Ò²ÊÇÔçÆÚ°²È«±àÅÅ×Ô¶¯»¯ÓëÏìÓ¦SOAR£¨Security Orchestration,  Automation and Res ponse£©µÄ»ý¼«ÏìÓ¦ÕßÖ®Ò»¡£


2¡¢Awake Security£ºÌṩ»ùÓÚ»úе½ø½¨µÄ°²È«·ÖÎöƽ̨£¬½áºÏÍøÂçÁ÷Á¿µÈÊý¾Ý£¬Îª°²È«·ÖÎöÈËÔ±ÌṩÁËÒ»¸ö¸ßµÍÎÄ·á˶¡¢Äܹ»³ÖÐø½øÐÐ×·×ٵĸ߼¶·ÖÎöÖ°ÄÜϵͳ£¬ÊÇÒ»¸ö°²È«µ÷²éƽ̨£¨Security Investigation Platform £©£¬Æ½Ì¨Ê¹ÓÃÍøÂçÊý¾ÝÀ´¼ø±ð»·¾³ÖеÄËùÓÐÏÖʵʵÌ壨ÈçÉ豸£¬Óû§ºÍÓòÃû£©£¬¶øºó¹¹½¨Ò»¸ö¹ÖÒìµÄ°²È«ÖªÊ¶Í¼Æ×£¨Security Knowledge Graph£©Êý¾ÝÄ£ÐÍ£¬ÀïÃæÔ̺¬ÁËʵÌå¼ä¾ßÌåµÄÓ³Éä¹ØÏµ£¬ÒÔ¼°Ã¿¸öʵÌåÖîÈçÉ豸ÀàÐÍ£¬²Ù×÷ϵͳ¡¢ÀûÓÃÈí¼þ°æ±¾ºÍÐÐΪ»î¶¯µÈÐÅÏ¢¡£


ƽ̨ÊÇÒ»ÖÖÄÜÁ¦½»¸¶£¬¸üÊÇÒ»ÖÖ¼¼Êõ±ÚÀÝ¡£¹ú±íÊÇÕâÑù£¬¹úÄÚ¸üÊÇ¡£¹úÄںöàµÄSOC¡¢CSA¡¢CDR¡¢MSSP¡¢MDRµÈϸ·ÖÁìÓòƽ̨ºÍ°²È«ÔËÓª¡¢³ÇÊÐÔËÓª£¬¶¼ÊÇÆ½Ì¨´´ÐÂÕßÃÇ×îºÃµÄ´ð°¸¡£µ«Ë¼¿¼µ½Æ½Ì¨¸ÅÏë¼°ÄÚº­±íÑÓ¼«¶È·á˶£¬Òò¶øÖ»ÓаÑ×ÔÉíÊÓÒ°·Åµ½×ã¹»ºëÔ¶£¬Â·²Å»áÔ½×ßÔ½¿í£¡


¿´µ½Òµ½ç¸÷λ´ó¿§¸ø±¾´Î´ó»áÖ÷ÌâHuman ElementµÄÖ÷Ìâ·­Ò룬±ÊÕ߸üÆ«²î·­Òë³É¡°È˵ÄÔªËØ¡±¡£Õâ¸ö·­Òë¸ù»ùÉÏÊÇÇкÏÓµÓÐÕ½Êõ˼ÏëµÄ¹ú¶È¼ÛÖµ¹ÛÊöÇó¡£Human Element±»Ìá³öÒ²ÊÇÓµÓÐʱÆÚ²¼¾°µÄ£¬¼´»úеºÍËã·¨µÄÁ÷ÐС£µ±ÈË»úÆ¥µÓ×¢ÈËΪÖÇÄÜ¡¢»úеÂòÂô¡¢»úе¾¯Ô±µÈÉøÈëµ½ÎÒÃÇÉúÑĵķ½·½ÃæÃæÊ±£¬È˺ͻúеÊÇ·ñÄÜºÍÆ½¹²´¦£¬Ò²ÐíÊÇÒ»¸ö²©ÞĵĹý³Ì¡£¶øÕâ¸ö²©ÞĹý³Ì£¬¹úÄÚÁÙʱ»¹²»»á¾­Àú£¬ÓÉÓÚ»úе»¹Î´×ã¹»Å¡¢×ã¹»ÖÇÄÜ£¬Õâ¾ÍÊÇ¡°¼¼Êõ²î¾à¡±¡£Òò¶øÌ¸¡°ÈË¡¹Øâ¸öÔªËØ£¬±ØÒªÓÐÕâÑùµÄ¼¼Êõ²¼¾°È¥Àí½â¡£