RSA Á¢ÒìɳºÐÅÌ»õ| ForAllSecure£ºÈÚÈëDevSecOpsµÄ¡°ÏÂÒ»´ú¡±Ä£ºý²âÊÔÊÖÒÕ
2020-02-20
2020Äê2ÔÂ24ÈÕ-28ÈÕ£¬ÍøÂçÇå¾²ÐÐҵʢ»áRSA Conference½«ÔھɽðɽÀ¿ªá¡Ä»¡£½ñÌì¾ÅÓÎÀϸç¾ý½«ÏÈÈÝÁ¢ÒìɳºÐʮǿÊ×´´¹«Ë¾Ö®Ò»£ºForAllSecure¡£
Ò»¡¢¹«Ë¾ÏÈÈÝ
ForAllSecureÊÇÓÉÀ´×Ô¿¨ÄÍ»ù÷¡´óѧµÄForAllSecureÇå¾²Ñо¿ÍŶÓÓÚ2012Ä꽨ÉèµÄ¹«Ë¾£¬ÊÂÇéËùÔÚ°üÀ¨±öϦ·¨ÄáÑÇÖÝÆ¥×ȱ¤¡¢¾É½ðɽÍåÇøºÍ¸¥¼ªÄáÑÇÖÝË®¾§³Ç¡£Ê×´´ÈËDavid Brumley¡¢Thanassis AvgerinosºÍAlex Rebert¾ùÀ´×Ô¿¨ÄÍ»ù÷¡´óѧ²¢ÓµÓÐÏà¹Ø×¨ÒµÅä¾°¡£¹«Ë¾ÔÚAÂÖÈÚ×ÊÖлñµÃ1500ÍòÃÀÔª£¬ÓÉNew Enterprise AssociatesÁìͶ¡£ÆäÖ÷´ò“ÏÂÒ»´ú”Ä£ºý²âÊÔÊÖÒÕ£¬²¢»ùÓÚ´ËÊÖÒÕʵÏÖÄ£ºý²âÊÔϵͳMayhem£¬ÒÀ¸½MayhemµÄ¾«²ÊÌåÏÖÒÔ´ó·ùÁìÏÈÓÅÊÆÔÚÃÀ¹ú¹ú·À²¿ÏȽøÏîÄ¿Ñо¿¾Ö£¨DARPA£©ÓÚ2016ÄêÖ÷ÀíµÄÍøÂ糬µÈÌôÕ½Èü£¨CGC£©ÖÐÒ»¾Ù¶á¿ý¡£ForAllSecure»¹ÔÚ2017Äê±»¡¸ÂéÊ¡Àí¹¤¿Æ¼¼Ì¸ÂÛ¡¹Ñ¡Èë“È«Çò×îÖǻ۵Ä50¼Ò¹«Ë¾”°ñµ¥£¨Î»ÁеÚ35Ãû£©¡£

¹«Ë¾ÌṩMayhemÄ£ºý²âÊÔ½â¾ö¼Æ»®£¬½«×Ô¶¯»¯Ò»Á¬ÐÔÇå¾²²âÊÔÈÚÈëDevOpsÁ÷³Ì£¬Á¦ÕùÔÚÔçÆÚ·¢Ã÷Îó²î¡¢ÐÞ¸´Îó²î£¬ÒÔÌá¸ßÈí¼þÇå¾²ÐÔ¡£Óë¹Å°åÄ£ºý²âÊÔÊÖÒÕÏà±È£¬¸Ã“ÏÂÒ»´ú”Ä£ºý²âÊÔÊÖÒÕÍŽáʹÓÓ·ûºÅÖ´ÐДÊÖÒպ͓µ¼ÏòÐÍÄ£ºý²âÊÔ”ÊÖÒÕ£¬Äܹ»Õë¶Ô²âÊÔ·¢Ã÷µÄÇå¾²Îó²î×Ô¶¯»¯ÌìÉú¿´·¨ÐÔÑéÖ¤£¨PoC£©ºÍ²¹¶¡£¬ÔÚÒ»¶¨Ë®Æ½ÉÏ×èÖ¹¹Å°å°×ºÐ²âÊԵĸßÎ󱨺ͺںвâÊÔµÄäĿÐÔ£¬¾ßÓкܸߵÄÁ¢ÒìÐԺͼÛÖµ¡£
¶þ¡¢Åä¾°ÏÈÈÝ
ƾ֤Cybersecurity VenturesµÄÓ¦ÓÃÇå¾²±¨¸æÏÔʾ£¬Ó¦ÓóÌÐòµÄ¹¥»÷ÃæÕýÔÚÒÔÿÄê1110ÒÚÐдúÂëµÄËÙÂÊÔöÌí£¬ÁíÍ⣬0dayÎó²îʹÓóÌÐò±»Ðû²¼µÄËÙÂÊÒѾ´Ó2015ÄêµÄ“ÿÖÜÒ»¸ö”ÔöÌíµ½2021ÄêµÄ“ÌìÌìÒ»¸ö”¡£
Óë´Ëͬʱ£¬DevOpsÕýÔÚ±»Ô½À´Ô½¶àµÄÍŶӺÍ×éÖ¯½ÓÊܺͽÓÄÉ¡£È»¶ø£¬¾ø´ó´ó¶¼Ó¦ÓÃÇå¾²¹¤¾ß²¢²»¿É¸úÉÏDevOpsµÄ½Å²½¡£ÀýÈ磬ÓÉÓÚÆä¾Ó¸ß²»ÏµÄÎó±¨ÂÊ£¬“¾²Ì¬´úÂëÆÊÎö”¹¤¾ß´ó´óÏÞÖÆÁËÇå¾²¡¢¿ª·¢ºÍ²âÊÔÖ°Ô±µÄÉú²úÁ¦¡£
ÁíÒ»·½Ã棬ÆóÒµ¼¶Îó²îÖÎÀí¼Æ»®ÔòÊÇÓÐÏÞÓ¦¶ÔÕ½ÂÔ¡£ÀýÈ磬“Èí¼þ×éÉíÆÊÎö”¹¤¾ßÖ»Äܼì²âÄÇЩÒѾ±»¹ûÕæ²¢·ÖÅÉÁËCVE±àºÅµÄÎó²î¡£
ÃæÁÙÕâЩÏÞÖÆºÍÎÊÌ⣬ForAllSecureÌṩ“ÏÂÒ»´úÄ£ºý²âÊÔ”Çå¾²¼Æ»®Mayhem£¬¼æ¾ßµ¼ÏòÐÍÄ£ºý²âÊԵĿɿ¿ÐԺͷûºÅÖ´ÐÐÊÖÒյĴ´Á¢Á¦£¬×ÊÖúÆóÒµÔÚÈí¼þ¿ª±¬·¢ÃüÖÜÆÚÖиüÔçµØ·¢Ã÷Ç徲Σº¦²¢¿ìËÙÏû³ý¡£
Èý¡¢²úÆ·ÏÈÈÝ
MayhemÊÇÒ»¸ö×ÊÖúÆóÒµÒÔ»úе¼¶ËÙÂʺ͹æÄ£²âÊÔÈí¼þµÄ¸¨ÖúÐÍÖÇÄÜÐÐΪ²âÊÔ½â¾ö¼Æ»®¡£ËüÍŽáʹÓ÷ûºÅÖ´Ðк͵¼ÏòÐÍÄ£ºý²âÊÔÊÖÒÕ£¬Í¨¹ý¼à¿ØÄ¿µÄ³ÌÐòµÄÐÐΪÀ´¶¯Ì¬ÌìÉú²âÊÔÓÃÀý¡£
¹Ù·½²¢Î´Ö±½Ó¸ø³öMayhemµÄ¼Ü¹¹×é³É¡£¾ÅÓÎÀϸç¾ýƾ֤¹Ù·½¹ûÕæ×ÊÁÏÕûÀí³öµÄ´óÖ¼ܹ¹ÈçÏ£º

ÆäÖУº
TranslatorÓÃÓÚ½«¶þ½øÖƳÌÐò·ÒëΪÒ×ÓÚÆÊÎöµÄÖÐÐÄÌåÏÖ£»
Offensive ToolsÓÃÓÚѰÕÒÎó²î²¢¹¹½¨PoC»òExP£»
Defensive ToolsÓÃÓÚÌìÉú²¹¶¡£»
ControllerÓÃÓÚͳ³ïÕû¸öÁ÷³Ì£»
MayhemµÄÊÂÇéÁ÷³ÌÈçÏ£º

ÎÒÃÇ¿ÉÒÔ¿´µ½£¬ÉÏÊöÁ÷³ÌÕýÊÇDevOpsµÄÒ»²¿·Ö£º
1¡¢Óû§ÏòSCM£¨´úÂë¿ÍÕ»£©Ìá½»Ó¦ÓôúÂ룻
2¡¢ÏµÍ³×Ô¶¯»ùÓÚSCM×îдúÂë¹¹½¨Ó¦Óã»
3¡¢ÏµÍ³×Ô¶¯½«¹¹½¨µÄÓ¦ÓÃÌá½»¸øMayhem¾ÙÐвâÊÔ£¬¶øMayhemµÄ²âÊÔÓÖ¿É·ÖΪÈý¸öÏศÏà³ÉµÄÂ߼ģ¿é£º
·¢ËͲâÊÔÊý¾Ý
¼àÊÓÄ¿µÄÐÐΪ
ÍøÂç¡¢·ÖÀಢÖü´æÐ§¹û
4¡¢ Óû§ÓëMayhem½»»¥£¬ÅÌÎÊÓ¦ÓõÄΣº¦ÇéÐβ¢¾ÙÐÐÏÂÒ»²½´¦Öóͷ£¡£
ÁíÍ⣬MayhemÖ§³Ö¶àÖÖÓïÑÔ¡¢Æ½Ì¨ºÍDevOpsÇéÐΣ¬Äܹ»Öª×ã²î±ðÓû§µÄÐèÇó£º

½ÓÏÂÀ´£¬ÎÒÃÇչʾһ¸öÏêϸµÄÓ¦Óð¸Àý¡£½èÖúÕâ¸ö°¸Àý£¬ÎÒÃÇÄܹ»ÕæÕý´¥Ãþµ½Mayhem£¬¶ÔÆäÊÂÇéÁ÷³ÌÓÐÉîÌõÀíµÄÃ÷È·£»ÁíÒ»·½Ã棬ҲÄܹ»ÔÚÒ»¶¨Ë®Æ½ÉÏÌå»áµ½ËüµÄʵÁ¦ºÍ¼ÛÖµËùÔÚ¡£
×îÏȲâÊÔ
MayhemÌṩÁËÓѺõÄÓû§½»»¥½çÃæ¡£³õʼ»¯Íê³Éºó£¬Õýʽ½øÈë²âÊԽ׶Σ¬¿ÉÒÔ¿´µ½²âÊÔÕýÔÚ¾ÙÐУº

Éó²é»ù±¾²âÊÔЧ¹û
²âÊÔ¿¢Êº󣬿ÉÒÔÉó²é²âÊÔЧ¹û£¬ÏàʶӦÓõÄųÈõµã£º

ÖµµÃ×¢ÖØµÄÊÇ£¬Mayhemƾ֤CWE¶ÔųÈõµã¾ÙÐÐÁË·ÖÀࣺ


Éó²éÏêϸ²âÊÔЧ¹û
ÎÒÃÇ»¹¿ÉÒÔÉó²éÏêϸ²âÊÔÓÃÀýµÄÊäÈëÊä³ö£¬´Ó¶ø×¼È·¶¨Î»ÎÊÌ⣨ÉõÖÁ¿ÉÒÔ¿´µ½·´»ã±àºóµÄ´úÂ룩£º


ForAllSecureÇ¿µ÷MayhemµÄÓÅÊÆÖ®Ò»ÊÇÁãÎ󱨡£ÄÇôÔõÑù×öµ½ÁãÎó±¨ÄØ£¿´ÓÉÏÃæµÄ²âÊÔЧ¹ûÎÒÃÇ¿ÉÒÔÂÔÖªÒ»¶þ¡£Mayhem×Ô¶¯¹¹½¨µÄ²âÊÔÓÃÀýµÈЧÓÚÑо¿Ö°Ô±ÊÖ¹¤ÑéÖ¤Îó²îʱ±àдµÄPoC¡£Ò»Ñùƽ³£À´Ëµ£¬ÈôÊÇÄܹ»µ¼Ö³ÌÐò·ºÆð±ÀÀ£»òÆäËûÒì³££¨´úÂëÂß¼Ô¤ÆÚÖ®ÍâµÄÐÐΪ£©£¬ÎÒÃDZãÒÔΪPoCÊÇÓÐÓõģ¬Í¬Ê±ÒÔΪÎó²î±£´æ¡£
ËÄ¡¢²úÆ·ÌØµã
Ò»Á¬ÐÔÉî¶ÈÆÊÎö£ºËæ×ÅÄ¿µÄ³ÌÐò֪ʶµÄ»ýÀÛ£¬MayhemµÄÆÊÎö½«Öð½¥ÉîÈ룬´úÂëÁýÕÖÂʽ«Öð½¥ÌáÉý¡£
ÁãÎ󱨣ºMayhem±¨¸æµÄËùÓÐȱÏݾùÊÇ׼ȷµÄ£¨ÓÉÓÚËü»á×Ô¶¯ÌìÉúPoCÈ¥²âÊÔ£©¡£
×Ô¶¯»¯ÌìÉú²âÊÔÓÃÀý£º»ùÓÚÍŶÓÔÚ¿¨ÄÍ»ù÷¡´óѧµÄרÀûÊÖÒÕ£¬MayhemÄܹ»Ê¹ÓÃÄ¿µÄ·´ÏìÔÚÔËÐÐʱ×Ô¶¯»¯ÌìÉú²âÊÔÓÃÀý¡£
Çå¾²×óÒÆ£ºÔÚÇå¾²¿ª·¢Á÷³ÌÖУ¬Mayhem½«¶¯Ì¬ÆÊÎö¡¢Ä£ºý²âÊÔ¼°Íþв½¨Ä£µÈ²âÊÔÓëÑéÖ¤°ì·¨×óÒÆ£¬×ÊÖúÆóÒµ¿ØÖÆÐÞ¸´±¾Ç®¡£ËüÄܹ»Ö±½Ó²åÈëµ½CIÁ÷Ë®ÏßÖУ¬½«Ò»Á¬ÐÔ²âÊÔ×÷ΪDevOpsÊÂÇéÁ÷µÄÒ»²¿·Ö¡£
Èí¼þ¹©Ó¦Á´ÖÎÀí£ºMayhemÄܹ»¶ÔÓ¦ÓÃÒÀÀµµÄ¿ªÔ´»òµÚÈý·½´úÂë¾ÙÐÐÍþвÆÀ¹À£¬ÒÔïÔÌÈí¼þ¹©Ó¦Á´Öб£´æµÄΣº¦¡£
Îå¡¢×ܽá
ÔÚÕû¸öµ÷ÑÐÀú³ÌÖУ¬¾ÅÓÎÀϸç¾ýÄܹ»´Ó¸÷·ýÌ屨µÀºÍForAllSecure¹Ù·½¶ÔMayhemÊÖÒÕÔÀíµÄ¹éÄÉ×ÛºÏÐÔÐÎòÖиÐÊܵ½ÆäÍŶÓÓµÓеÄÉîÖ¿ÊÖÒÕ»ýµí¡£Å׿ªÌ¬¶È·×ÆçµÄýÌ壬Èý¸öÊÂʵ×㹻֤ʵËûÃǵÄÐÛºñʵÁ¦£º
1¡¢ ¹«Ë¾Î´Á¢£¬ÊÖÒÕÏÈÐУº×÷Ϊһ֧À´×Ô¿¨ÄÍ»ù÷¡´óѧµÄ¿ÆÑÐÍŶӣ¬ÆäÊÖÒյĽµÉúʱ¼ä±È¹«Ë¾½¨Éèʱ¼äÔçÐí¶àÄꣻ
2¡¢ÒÔ¾ø¶ÔÓÅÊÆ»ñµÃDARPA CGC¾öÈüµÚÒ»Ãû£ºÌôÕ½ÈüÜöÝÍÁËÈ«ÇòÇå¾²ÁìÓòµÄ¶¥¼âÍŶӣ¬ForAllSecure´Ó104Ö§²½¶ÓÖÐÍÑÓ±¶ø³ö½øÈëÆßǿɱÈë¾öÈü¡¢²¢»ñµÃ¹Ú¾ü£¬ÕâÊÇӲʵÁ¦µÄÌåÏÖ£»
3¡¢»ñµÃNew Enterprise AssociatesÁìͶµÄ1500ÍòÃÀÔªÈÚ×Ê£ºÕâÊÇ×ÊÔ´µÄÆÀ¹ÀºÍÈϿɡ£
ÁíÒ»·½Ã棬ForAllSecure¶ÔÄ¿½ñÇå¾²²âÊÔÊÖÒÕµÄÍ´µãÕÆÎÕµÃÊ®·Öµ½Î»¡£Çå¾²´ÓÒµÕßÍùÍù»áÓÐÕâÑùµÄ¸ÐÊÜ£º×Ô¶¯»¯°×ºÐ²âÊÔ£¨È羲̬´úÂëÆÊÎöµÈ£©¾ßÓв»Ð¡µÄÎó±¨ÂÊ£»×Ô¶¯»¯ºÚºÐ²âÊÔ£¨ÈçÎó²îɨÃèµÈ£©¼ÈÓÐÒ»¶¨µÄÎó±¨ÂÊ£¬Í¬Ê±Ò²ÓÐ×ÔÉíµÄ¾ÖÏÞÐÔ——ÊÜÏÞÓÚÎó²î֪ʶ¿â£»È˹¤ÉøÍ¸²âÊÔËäȻЧ¹ûÏÔÖø£¬µ«×Ô¶¯»¯µÄȱʧµ¼ÖÂÆäÎÞ·¨ÈÚÈëDevOpsÁ÷³Ì£»¶ø¹Å°åÄ£ºý²âÊÔÊÖÒÕµÄÖ÷ÒªÍæ¼Òͨ³£ÊÇÖ°Òµ»ò°ëÖ°ÒµµÄÎó²îÁÔÈË¡£
ÔÚ´ËÐÎÊÆÏ£¬ForAllSecure¸ø³öÁËÒ»¸öÖ§³ÖDevOpsµÄÆóÒµ¼¶Ä£ºý²âÊԼƻ®£¬²¢ÔÚÒ»¶¨Ë®Æ½ÉÏ֤ʵÎú¸Ã¼Æ»®µÄÓÐÓÃÐÔ£¨DARPA CGC£©£¬ÕâÎÞÒÉÊÇÁîÈËÕñ·ÜµÄ¡£
È»¶ø£¬ÎÒÃÇÒ²ÒªÌá³öÎÊÌ⣺MayhemÊÇ·ñÕæÈçForAllSecureÐÎòµÄÄÇôÓÅÒ죿ËûÃÇÊÇ·ñÔÚÕÆÎÕסʹµãµÄͬʱ½ÏºÃµØ½â¾öÁËÄѵ㣿

·ûºÅÖ´ÐкÍÄ£ºý²âÊÔ×Ô¼º²¢²»ÊÇÐÂÊÖÒÕ£¬ÈËÃǶÔÁ½ÕßµÄÓÅÊÆºÍȱÏÝÒ²¶¼ÔçÓÐÑо¿¡£·ûºÅÖ´ÐÐÊÖÒÕ¸ü¶àµØ¾ßÓÐÀíÂÛÉϵÄÏȽøÐÔ£¬¿ÉÊÇÔÚÓ¦Óõ½ÖØ´ó³ÌÐòʱÍùÍù»áÓöµ½Â·¾¶±¬Õ¨µÈÎÊÌ⣻ģºý²âÊÔµÄЧ¹ûÔòÓëÊäÈ뼯µÄÊýÄ¿ºÍÖÊÁ¿ÓÐ×ÅÇ×½üµÄ¹ØÏµ¡£
ͨ¹ýDARPA CGC£¬ÎÒÃÇ¿´µ½ÁËMayhemÔÚÎó²î¼ì²âºÍÑéÖ¤ÉϵÄÓÐÓÃʵÁ¦£¬¿ÉÊÇÎÒÃÇÒ²×¢ÖØµ½£¬ÔÚ½ÇÖðÖÐMayhemÐèÒª´ó×ÚµÄË®À´¾ÙÐÐÀäÈ´£¨CGC¾öÈüΪÆßÖ§²½¶ÓÅ䱸ÁË180¶ÖË®¾ÙÐÐË®À䣩ºÍ´ó¹æÄ£µÄËãÁ¦¡¢ÄÜÔ´Ö§³Ö£¬ÕâЩ¶¼ÊÇǰÊöÊÖÒÕ¾ÖÏÞÐÔÔÚÏêϸʵÏÖÉϵĿ͹۷´Ó¦¡£ÓÐʱ¼ä£¬²úÆ·ºÍ¼Æ»®µÄÓÅÒì²¢²»ÍêÈ«ÓÉÊÖÒÕÉϵÄÓÅÊÆ¾öÒé¡£Çå¾²ÐÐÒµµÄÌØµã¾öÒéÁ˱¾Ç®ÓëЧ¹û——Ò²¾ÍÊÇÐÔ¼Û±ÈÍùÍù²ÅÊÇ×îÖ÷ÒªµÄ¡£Òò´Ë£¬MayhemµÄ±¾Ç®ºÍÊг¡¶¨Î»Ò²ÐíÊÇÐèÒªÊ×´´ÍŶÓ˼Á¿µÄÎÊÌ⣬ҲÊǿͻ§ÌåÌùµÄÎÊÌâ¡£
ÌÏÌϳ¤½¶«ÊÅË®£¬ÀË»¨ÌÔ¾¡Ó¢ÐÛ¡£ForAllSecureÕæµÄÄܹ»Íƶ¯DevSecOpsÉú³¤£¬Õվɽö½öê¼»¨Ò»ÏÖ£¿Mayhem¾¿¾¹ÊÇѧÊõ½çµÄÍæÎÕÕ¾ÉÕæµÄÄܹ»³ÉΪҵ½çÒ»´óɱÆ÷£¿ÕâЩ¶¼ÐèҪʱ¼äµÄÄ¥Á·¡£È»¶ø£¬¾Í±¾´ÎÁ¢ÒìɳºÐ¾ºÈü¶øÑÔ£¬×ÛºÏ˼Á¿ÊÖÒÕʵÁ¦ÓëÍŶÓÅä¾°£¬¾ÅÓÎÀϸç¾ýÒÔΪForAllSecure¾ßÓм«Ç¿µÄ¾ºÕùÁ¦£¬Í¬Ê±¿´ºÃËûÃǵĺóÐøÉú³¤¡£ÈÃÎÒÃÇÊÃÄ¿ÒÔ´ý¡£
· ²Î¿¼ÎÄÏ× ·
[1] Mayhem, the Machine That Finds Software Vulnerabilities, Then Patches Them
[2] MIT Technology Review Reveals 50 Smartest Companies List in Annual Business Issue
[3] ForAllSecure
[4] ForAllSecure: About us
[5] DARPAÍøÂ糬µÈÌôÕ½ÈüÇéÐμ°Ë¼Ë÷
[6] ·ûºÅÖ´ÐÐÊÖÒÕ×ܽᣨA Brief Summary of Symbol Execution£©- wcventure
×¢£ºµÚ3½ÚÒýÓÃÁËÀ´×ÔVDA LabsµÄ×ÊÁÏUsing-Next-Generation-Fuzzing-Tools.pdf£»µÚ4½Ú²Î¿¼ÁËForAllSecure¹Ù·½×ÊÁÏFY19 DS Mayhem General v3.7.pdf¡£

¾ÅÓÎÀϸçÔÆ







