RSA Á¢ÒìɳºÐÅÌ»õ| Vulcan Cyber£º»¯±»¶¯Îª×Ô¶¯µÄÔÆ¶ËÎó²îÏìÓ¦×Ô¶¯»¯Æ½Ì¨
2020-02-20
2020Äê2ÔÂ24ÈÕ-28ÈÕ£¬ÍøÂçÇå¾²ÐÐҵʢ»áRSA Conference½«ÔھɽðɽÀ¿ªá¡Ä»¡£¾ÅÓÎÀϸç¾ýÏà¼ÌΪ¸÷ÈËÏÈÈÝÁ˽øÈë½ñÄêÁ¢ÒìɳºÐʮǿÊ×´´¹«Ë¾£¬½ñÌìΪ¸÷ÈËÏÈÈݵÄÊÇ£ºVulcan Cyber¡£
Ò»¡¢¹«Ë¾ÏÈÈÝ
Vulcan CyberÊÇÁ¢ÒìɳºÐʮǿÖÐΨһµÄÒ»¼ÒÒÔÉ«Áй«Ë¾£¬ÔÚ2019ÄêÔøÈëÑ¡Gartner ÔÚSecurity and Risk ManagementµÄCool Vendor¡£ÔÚ¹«Ë¾µÄÈýλÍŽáÊ×´´ÈËÖУ¬CEO Yaniv Bar-DayanÓëCPO Tal Morgenstern¶¼ÔøÔÚÒÔÉ«Áоü·½ÈÎÖ°£¬Óи»ºñµÄÍøÂçÇ徲ʵսÂÄÀú¡£¹«Ë¾½¨ÉèÓÚ2018Ä꣬ÏÖÔÚÒѾ»ñµÃÁËÁ½ÂÖ¹²1400ÍòÃÀÔªµÄÈÚ×Ê£¬×î½üÒ»´ÎÊÇÓÉTen Eleven VenturesÁìÍ·µÄ1000ÍòÃÀÔªAÂÖÈÚ×Ê¡£Vulcan CyberΪÆóÒµÌṩÁËÒ»Ì××Ô¶¯»¯Îó²îÍþв»º½â£¨Automated Vulnerability Remediation£©½â¾ö¼Æ»®£¬Í¨¹ý¶ÔÒÑÓпª·¢¡¢ÔËά¹¤¾ßµÄ¼¯³ÉÓëÕûºÏ£¬ÊµÏÖ¶ÔÍ»·¢Çå¾²Îó²îµÄ¿ìËÙÏìÓ¦£¬½«ÆóÒµÊܵ½Çå¾²ÍþвµÄʱ¼ä´°¿Ú´ÓÊýÖÜ¡¢ÊýÔÂËõ¶Ìµ½Ð¡Ê±¼¶¡£
Vulcan Cyber×Ô³ÆÎªÒµ½ç×Ô¶¯»¯Îó²î»º½â¿´·¨µÄÏÈÐÐÕß¡£¾ÅÓÎÀϸç¾ýÒÔΪ£¬½«ÆóÒµ×ʲúÕûºÏ¡¢Õë¶ÔÇå¾²ÊÂÎñ¾ÙÐÐ×Ô¶¯»¯ÏìÓ¦µÄÍ·ÄÔ¿ÉÒÔ×·Ëݵ½2017ÄêGartnerÌá³öµÄÇå¾²±àÅÅ×Ô¶¯»¯ÓëÏìÓ¦SOAR£¨Security Orchestration, Automation and Response£©¡£µ«×÷ΪSOAR¿´·¨µÄʵÏÖÕߣ¬ÇÐʵΪÆóÒµ½â¾öÁËÇ徲ʹµã£¬Î´À´¿ÉÆÚ¡£
¶þ¡¢Åä¾°ÏÈÈÝ
Ëæ×ÅÍøÂçÇå¾²¹¥·À¶Ô¿¹µÄÈÕÇ÷Ç¿ÁÒ£¬ÆóÒµµÄÇå¾²ÍŶÓÓëÔËάÍŶÓÃæÁÙ×ÅÈÕÒæÑÏËàµÄÄ¥Á·¡£Çå¾²ÊÂÎñ¡¢Çå¾²Îó²îÈÕÒæÔö¶à£¬Ô½À´Ô½ÖØ´óÇÒÓÐÕë¶ÔÐÔ¡£ÆóÒµÕë¶Ô²î±ðÓªÒµµÄ¿ªÕ¹£¬°²ÅÅ¡¢Î¬»¤À´×Ô²î±ð¹©Ó¦É̵Ä×ʲú×°±¸£¬Ò»Á¬Ôö¶àµÄÇå¾²¸æ¾¯ÓëÎó±¨ÔöÌíÁËÓ¦¼±ÏìÓ¦ÍŶӵÄÊÂÇ鸺ºÉ¡£
ÕâЩÄêÀ´£¬¼ì²âÓëÏìÓ¦ÀàµÄ²úÆ·Êܵ½Á˼«´óµÄ¹Ø×¢£¬ÓÈÆäÊǶÔδ֪¶ñÒâÐÐΪµÄ¼ì²â¹¦Ð§ÒѾ³ÉΪ½üÄêÖÕ¶Ë·À»¤²úÆ·µÄ±êÅä¡£ÕâЩ²úÆ·ºÍÊÖÒÕʹÓû§»ñµÃÁ˸üµÍµÄMTTD£¨Æ½¾ù¼ì²âʱ¼äMean Time to Detect£©£¬Äܹ»¸ü¿ì¡¢¸ü׼ȷµÄ¼ì²âÈëÇֺ͹¥»÷£¬µ«¶ÔÓû§¶øÑÔ£¬½â¾öÎÊÌâÓë·¢Ã÷ÎÊÌâÒ»ÑùÖ÷Òª¡£Ò»¸öÏÖ×´ÊÇ£¬ÆóÒµµÄÇå¾²ÍŶÓÓëÔËάÍŶӲ»¿É°ü¹ÜÔÚÈκÎʱ¼ä¶¼ÄÜÕÒµ½»º½âÎó²îµÄ²½·¥£¬Í¬Ê±Ò²·×Æç¶¨Äܹ»×¼È·ÆÀ¹À»º½â²½·¥¶ÔÓªÒµÔì³ÉµÄÓ°Ïì¡£Vulcan CyberÌṩµÄ½â¾ö¼Æ»®Ö¼ÔÚÌî²¹ÆóÒµµÄÕâÒ»ÄÜÁ¦¿Õȱ¡£
Èý¡¢²úÆ·ÏÈÈÝ
Vulcan CyberµÄ½â¾ö¼Æ»®Ó빫˾ͬÃû£¬ÏÂÃæÎÒÃǽ«¼ò³ÆÆäΪVulcan¡£VulcanÊÇÒ»Ì×°²ÅÅÔÚÔÆ¶ËµÄÎó²îÏìÓ¦×Ô¶¯»¯Æ½Ì¨£¨Vulnerability Response Automation Platform£©£¬ËüµÄÉè¼ÆÄ¿µÄÊǽ«Ó¦ÓÃÎó²î¡¢¹ýʧÉèÖõÈһϵÁÐÇå¾²ÎÊÌâת»¯Îª¿ÉÖ´ÐеĽâ¾ö¼Æ»®£¬´Ó¶øÊ¹ÆóÒµµÄÇå¾²ÍŶÓÄܹ»×¨×¢ÓÚ½â¾ö×îÓÐÍþвµÄÇå¾²ÎÊÌ⣬»¯±»¶¯ÓÚ×Ô¶¯¡£Vulcan½«Îó²îÐÅÏ¢µÄÍøÂ硢Σº¦ÆÀ¹ÀÀú³Ì¾ÙÐÐ×Ô¶¯»¯£¬×îÖÕÒÔÒ»¸ö²¹¶¡¡¢ÉèÖÃÎļþ¸Ä¶¯»òÆäËûÐÎʽÌṩһ¸ö¶ÔÉú²úÇéÐÎÓ°Ïì×îµÍµÄ×î¼Ñ½â¾ö¼Æ»®¡£
Vulcan¾ßÓÐÈý´ó½¹µã¹¦Ð§£ºÎ£º¦ÐÅÏ¢¾ÛºÏ¡¢ÍþвÆÊÎö¡¢×Ô¶¯»¯Îó²î»º½â¡£
Σº¦ÐÅÏ¢¾ÛºÏ£ºÌṩÍêÕûµÄ×ʲúÊÓͼ

Ò»¸öÏÖ´úµÄÎó²îÖÎÀíÆ½Ì¨Äܹ»ÍêÕûµÄ·ºÆðÆóÒµµÄ×ʲúÓëÕâЩ×ʲúÖ®¼äµÄ¹ØÁª¹ØÏµ£¬Ö»Óе±ÆóÒµ¶ÔÆäÍøÂçÖÐËùÓеÄ×é¼þÓÐÍêÕûµÄÈÏÖª£¬Ó¦¶ÔÎó²îµÄ»º½â²½·¥²Å»ªÍêÉÆµÄ½â¾öÎÊÌâ¡£Vulcan»á¶ÔÍøÂç¾ÙÐÐɨÃè²¢¶ÔЧ¹û¾ÙÐÐÍøÂç»ã×Ü£¬ÕÒ³öÆäÖпÉÄܱ£´æµÄ̻¶µã¡¢ÉèÖÃȱÏÝ¡£
³ý´ËÖ®Í⣬µ±ÎÒÃÇÆÀ¹ÀÒ»¸öÎó²î»º½â²½·¥µÄDZÔÚΣº¦Ê±£¬ÎÒÃÇÒ²ÐèÒªÖªµÀ×ʲúÖ®¼äµÄÁª¶¯¹ØÏµ£¬´Ó¶øÈ·±£¶ÔÎó²îÐÞ¸´Àú³ÌËùµ¼Öµĸ±×÷Óã¨ÈçÒâÍâÍ£»ú£©¾ÙÐÐÍêÕûµÄÔ¤ÅС£
ÔÚÕû¸öÐÞ¸´Àú³ÌÖУ¬Vulcan»á¸ú×ÙºÎʱ¡¢ºÎµØ¡¢ÄÄЩ°ì·¨Ê¹ÓÃÁËÄÄЩά»¤¹¤¾ß£¬ÒÔ¼°ÕâЩ¹¤¾ßÓÉËʹÓá£Í¨³£²î±ðµÄ¹¤¾ßÓëӪҵϵͳÊèÉ¢ÔÚ²î±ðµÄƽ̨ÉÏ£¬VulcanÌṩ¶Ô¶àÖÖÔÆÆ½Ì¨Óëά»¤¹¤¾ßµÄÖ§³Ö£¬°üÀ¨AWS Inspector¡¢Microsoft Intune¡¢Tenable Nessus¡¢AnsibleµÈ£¬Ò²Ö§³Öͨ¹ýVulcan Gateway½«Óû§Ë½ÓÐÔÆµÄ¼à¿ØÊý¾ÝÉÏ´«µ½VulcanÔÆ¶Ë¡£
ÍþвÆÊÎö£º»ùÓÚΣº¦µÄÍþвÓÅÏȼ¶ÅÅÐò

¹Å°åµÄTVM³§ÉÌÇãÏòÓÚÒÀÀµ¿Í¹ÛÆÀ·Ö£¬ÈçCVSS·ÖÊý£¬¶ÔÎó²îµÄΣº¦Ë®Æ½¾ÙÐж¨¼¶£¬µ«ÏÖʵÉÏ£¬²î±ðÎó²î¶ÔÏÖʵӪҵµÄΣº¦Ë®Æ½£¬ÕÕ¾ÉÒÀÀµÇå¾²ÍŶӵÄÖ÷¹ÛÅжϡ£Òò´Ë£¬VulcanÒýÈëÁ˶àÖÖÒªÏòÀ´ÆÀ¶¨Ò»¸öÇå¾²ÊÂÎñµÄÏÖʵΣº¦¡£
1¡¢Ó¦ÓÃÇå¾²ÐÔ¡£°üÀ¨Qualys¡¢SourceClearµÈDevSecOps¹¤¾ß²ú³öµÄ´úÂë¹æ·¶ÐÔ¡¢ÁýÕÖÂʵÈÊý¾Ý¡£
2¡¢ÓªÒµÓ°ÏìÁ¦¡£ÓëÆóÒµµÄCMDBÁª¶¯£¬½«Ó¦Ó÷þÎñµÄÉÌÒµ¼ÛÖµÄÉÈ뵽Σº¦ÆÀ¼ÛÖ¸±êÖС£ÀýÈçÖü´æÓû§ÐÅÏ¢¡¢ÉúÒâ¼Í¼µÄÊý¾Ý¿â¶Ô¹«Ë¾ÖÁ¹ØÖ÷Òª£¬ÕâЩ×ʲú¹ØÁªµÄÎó²îÓëÇå¾²ÊÂÎñµÄ´¦Öóͷ£ÓÅÏȼ¶¾ÍÊÇ×î¸ßµÄ¡£
3¡¢×ʲúÂþÑÜÇéÐΡ£Í¨¹ýÓëÓ¦Óð²Åʤ¾ß¡¢×ʲúÖÎÀíϵͳµÄ¼¯³É£¬¶ÔÎó²îËù²¨¼°µÄ×ʲúÊýÄ¿¾ÙÐж¨Î»Óëͳ¼Æ¡£
4¡¢ÍþвÇ鱨¡£Vulcan½ÓÈëÁËÁè¼Ý50¸öÍþвÇ鱨Դ£¬ÅÌÎÊ·¢Ã÷µÄÎó²îÊÇ·ñ±£´æÒÑÖªµÄIOC¡£
ËäÈ»£¬ÕâЩά¶ÈµÄ±£´æ£¬³ýÁËÄÉÈëVulcanµÄËã·¨£¬Êä³öÍþв¶¨¼¶Ö®Í⣬ҲÄܹ»ÎªÇå¾²ÍŶӴ¦Öóͷ£Çå¾²ÊÂÎñÌṩ¸ü¶àµÄ²Î¿¼¡£
×Ô¶¯»¯Îó²î»º½â£º¶ÔÓ¦ÓÃ×é¼þ¾ÙÐÐÅúÁ¿ÐÞ¸´

Vulcanͨ¹ý×Ô¶¯»¯µÄ·½·¨À´ïÔÌÊÂÎñÏìÓ¦ËùÐèµÄÈËÁ¦Óëʱ¼ä£¬É¨³ýÎó²Ù×÷µÄΣº¦£¬Ìṩ¸ü¸ßµÄ¿É¿¿ÐÔ¡£Óû§¿ÉÒÔÔ¤ÏȽç˵һЩPlaybook£¬´Ó¶ø½«Öª×ãÌØ¶¨Ìõ¼þµÄÊÂÎñ´¦Öóͷ£°ë×Ô¶¯»òÈ«×Ô¶¯»¯£¬ÔÚ¹Ù·½µÄ°¸ÀýÆÊÎöÖУ¬Vulcan¿ÉÒÔ½«Ä³Ð©×é¼þµÄÎó²îÐÅÏ¢ÍÆË͵½SlackµÄ̸ÌìÆµµÀÖУ¬²¢ÔÚJiraÖн¨ÉèÒ»¸öIssue£¬´Ó¶øµ÷¶¯Ïà¹ØÖ°Ô±¾ÙÐд¦Öóͷ£¡£³ý´ËÖ®Í⣬Vulcan»¹Î¬»¤ÁËһЩ³£¼ûµÄ×Ô¶¯»¯Ö¸ÁºÃ±ÈʹÓÃAnsible»òChefµÈ¹¤¾ß¶ÔLinux·þÎñÆ÷×°Öò¹¶¡£¬»ò²Ù×÷WAF¡¢ÖÕ¶Ë·À»¤Èí¼þÉèÖùæÔò×è¶Ï¶ñÒâÈí¼þÈö²¥µÈµÈ¡£
ËÄ¡¢ÓÅÊÆÓëÌôÕ½
VulcanµÄÒ»´óÁÁµãÊÇ£¬Í¨¹ýÎó²îÆÀ¼¶Ö®ÍâµÄ¸ü¶àά¶È£¬È¨ºâÎó²îµÄΣº¦Ë®Æ½£¬×ÊÖúÇå¾²ÍŶÓÔÚº£Á¿¸æ¾¯ÓëÇå¾²ÊÂÎñÖж¨Î»×îÖ÷ÒªµÄÇå¾²ÎÊÌ⣻¸üÖ÷ÒªµÄÊǹŰåTVM²úÆ·Ö»¾ß±¸ÖÎÀíÎó²îÉúÃüÖÜÆÚ¹¦Ð§£¬´ó²¿·ÖµÄÎó²î»º½â¡¢ÏµÍ³Éý¼¶¶¼ÊÇÈ˹¤´¦Öóͷ££¬ºÄʱºÄÁ¦£¬ÔÚ´ó¹æÄ£µÄϵͳÖв»¿ÉÀ©Õ¹£¬¶øVulcanʹÓÃÁË×Ô¶¯»¯±àÅŵķ½·¨£¬¸ßЧ½â¾öÎÊÌ⣬ÕâÒ»µãÊÇÐí¶àTVM²úÆ·Ëù²»¾ß±¸µÄ£¬½â¾öÁËÓû§Ò»´óÍ´µã¡£
µ«Í¬Ê±£¬VulcanÒ²±£´æÒ»Ð©²»ÍêÉÆµÄµØ·½¡£×÷Ϊһ¸öÎó²îÖÎÀíµÄ¼¯ÖÐÆ½Ì¨£¬ËüÐèÒªÄܸøÓû§Ìṩ×ã¹»µÄÎÞаÐÔÒÔ½«¸ü¶àÖÖÀàµÄ×ʲúÄÉÈëÆ½Ì¨ÖС£VulcanÖ»Ìáµ½ÁËÖ§³ÖÓëijЩӦÓõɣ¬µ«²»Ö§³Öʲô£¬ÎÒÃDz¢²»ÖªµÀ¡£Æä´Î£¬Ó¦¶ÔÖØ´ó¶à±äµÄÆóÒµÇéÐΣ¬ÔÚÊý¾ÝµÄչʾÉϸøÓû§¶¨ÖƵĿռäÒ²ÊǺÜÊÇÐëÒªµÄ¡£ÈçRapid7 InsightVMÓëFireEye HelixÌṩÁ˶àÖֿɶ¨ÖƵĽçÃæÔªËØ£¬²î±ðµÄÍŶӿÉÒÔ´Ó²î±ðµÄÊӽǾÙÐÐ¼à¿Ø¡£VulcanÏÖÔÚ¿´À´»¹È±ÉÙÕâÑùµÄ¹¦Ð§¡£
Îå¡¢×ܽá
Gartner ÔøÕ¹Íû£¬µ½ 2020 Äêµ×£¬ÓµÓÐ 5 ÈËÒÔÉϹæÄ£Çå¾²ÍŶӵĹ«Ë¾ÆóÒµÖУ¬15% ¶¼½«½ÓÄÉ SOAR£¬¶øÏÖÔÚ SOAR µÄ½ÓÄÉÂÊÖ»ÓÐ 1%¡£Vulcan Cyber½«SOARµÄ¿´·¨½øÒ»²½ÍÆÏòÂ䵨£¬²¢Õ¹Ê¾ÁËÒ»¸öÇÐʵ¿ÉÐеĽâ¾ö¼Æ»®£¬ïÔÌÁËÊÂÎñÏìÓ¦Àú³ÌÖÐÖØ¸´ÐÔʹÃüµÄÈ˹¤¸ÉÔ¤£¬×ÊÖú¼ÓËÙÎÊÌâµÄ½â¾ö¡£ÕýÈçÈ¥ÄêÁ¢ÒìɳºÐ»ñʤÕßAxoniusÔÚÍøÂçÇå¾²×î»ù´¡µÄ×ʲúÖÎÀí·½ÃæÓÐËùÁ¢Òì»ñµÃÆÀί¿´ÖØ£¬½ñÄêVulcanÊÇ·ñ»áÔÚͬÑù»ù´¡µÄÎó²îÖÎÀí·½Ãæ×Ô¶¯»¯ÌáÉýÇå¾²ÔËάЧÂʶø»ñµÃÐÐÒµµÄÈϿɣ¿ÎÒÃÇÊÃÄ¿ÒÔ´ý¡£

¾ÅÓÎÀϸçÔÆ







