RSA Á¢ÒìɳºÐÅÌ»õ | WABBI ¡ª¡ªÃæÏòÓ¦ÓÃÈ«ÉúÃüÖÜÆÚµÄÇå¾²·À»¤¼Æ»®
2021-05-12
RSAConference2021 ½«Óھɽðɽʱ¼ä 5 Ô 17 ÈÕÕÙ¿ª£¬Õ⽫ÊÇ RSA ´ó»áÓÐÊ·ÒÔÀ´µÚÒ»´Î ½ÓÄÉÍøÂçÐéÄâ¾Û»áµÄÐÎʽ¾ÙÐС£´ó»áµÄ Innovation Sandbox(ɳºÐ)´óÈü×÷Ϊ“Ç徲ȦµÄ °Â˹¿¨”£¬Ã¿Äê¶¼±¸ÊÜÖõÄ¿£¬³ÉΪȫÇòÍøÂçÇå¾²ÐÐÒµÊÖÒÕÁ¢ÒìºÍͶ×ʵķçÏò±ê¡£
ǰ²»¾Ã£¬RSA ¹Ù·½Ðû²¼ÁË×îÖÕÈëÑ¡Á¢ÒìɳºÐµÄʮǿÊ×´´¹«Ë¾:WABBI¡¢Satori¡¢Abnormal Security¡¢Apiiro¡¢Axis Security¡¢Cape Privacy¡¢Deduce¡¢Open Raven¡¢STARATA¡¢ WIZ¡£
¾ÅÓÎÀϸç¾ý½«Í¨¹ýÅä¾°ÏÈÈÝ¡¢²úÆ·ÌØµã¡¢µãÆÀÆÊÎöµÈ£¬´ø¸÷ÈËÏàʶÈëΧµÄʮǿ³§ÉÌ¡£½ñÌ죬ÎÒÃÇ ÒªÏÈÈݵÄÊdz§ÉÌÊÇ:WABBI¡£
Ò»¡¢¹«Ë¾ÏÈÈÝ
WABBI ½¨ÉèÓÚ 2018 Ä꣬×ܲ¿Î»ÓÚÃÀ¹ú²¨Ê¿¶ÙÖÝ£¬¸Ã¹«Ë¾×¨×¢ÓÚ SecDevOps ÁìÓò£¬Í¨¹ý ÆìÏ嵀 SecDevOps ²úÆ·¿ÉʹÆóÒµÄܹ»¸ü¿ì¡¢¸üÇå¾²µÄ½«Èí¼þ¾ÙÐн»¸¶£¬ÏÖÔÚ¹«Ë¾ÈËÊýԼĪ 20-30 ÈË×óÓÒ£¬¹«Ë¾µÄÊ×ϯִÐйټæÊ×´´ÈËΪ BrittanyGreenfield[1]£¬½áÒµÓڶſ˴óѧ£¬ ²¢ÔÚÂéÊ¡Àí¹¤Ñ§Ôº¶ÁÈ¡ÁË MBA£¬µ¥´ÓÆäÊÂÇéÂÄÏòÀ´¿´£¬¸ÃÊ×´´ÈË´ÓʵĶàΪÊг¡ÓªÏúÏà¹Ø ÁìÓò£¬ÓëÐÅÏ¢Çå¾²ÁìÓò²¢ÎÞÌ«¶à½»¼¯£¬µ«ÓÅÊÆÔÚÓÚ¶ÔÏÖÓÐÈí¼þÊг¡ÓÐ׎ÏÉîÃ÷È·£¬²¢ÔÚ DevOps Æ«ÏòÓÐ×ÅǰհÐÔµÄÑо¿£¬2019 Äê 5 Ô·ݣ¬¸Ã¹«Ë¾ÒѾ³ï¼¯ÁË 33 ÍòÃÀÔªµÄµÚÒ»ÂÖ ÈÚ×Ê£¬Í¶×ÊÕßÒÔ Underscore VC[2]¹«Ë¾Ç£Í·£¬Douglas Levin[3]¡¢Ashley Smith[4]µÈÈË Ò²¼ÓÈëÁË´ËÂÖÈÚ×Ê¡£
¶þ¡¢Åä¾°ÏÈÈÝ
Ëæ×ÅÊÖÒյIJ»¶ÏÉú³¤£¬Îª´Ù½ø¿ª·¢ÔËάһÌ廯£¬DevOps Ó¦Ô˶øÉú£¬Æä´ú±íµÄ²¢·ÇÒ»ÖÖÏêϸ µÄʵÏÖÊÖÒÕ£¬¶øÊÇÒ»ÖÖ·½·¨ÂÛ£¬²¢ÔÚ 2009 Äê±»Ìá³ö[1]¡£DevOps µÄ·ºÆð×îÖÕÄ¿µÄÊÇΪÁË Í»ÆÆ¿ª·¢ÈËÔ±ÓëÔËάÈËÔ±Ö®¼äµÄ±ÚÀݺͺ蹵£¬¸ßЧµÄ×éÖ¯ÍŶÓͨ¹ý×Ô¶¯»¯¹¤¾ßÏ໥Ð×÷ÒÔÍê ³ÉÈí¼þÉúÃüÖÜÆÚ¹ÜÀí£¬´Ó¶ø¸ü¿ìÇÒÆµÈԵؽ»¸¶¸ßÖÊÁ¿Îȹ̵ÄÈí¼þ¡£
ÈçÎÒÃÇËùÖª£¬DevOps Ó°ÏìµÄ²»½ö°üÀ¨¿ª·¢ÍŶÓ(Dev)ºÍÔËάÍŶÓ(Ops)£¬»¹Ó¦°üÀ¨Çå¾² ÍŶÓ(Sec)£¬ÔÚϵͳÉúÃüÖÜÆÚ(SDLC Systems DevelopmentLife Cycle)ÖУ¬Çå¾²ÍÅ¶Ó Òò³£¾Û½¹ÓÚÔËÓª½×¶Î£¬Òò¶øÍùÍùºöÊÓÁË¿ª·¢½×¶ÎµÄÇå¾²£¬ËùÒÔ“Çå¾²×óÒÆ”µÄÀíÄîÔÚ½üЩÄê ºÜÊÇµÄ»ð£¬ÆäÇ¿µ÷Çå¾²ÒòËØÓ¦ÄÉÈëÓ¦Óÿª·¢µÄÔçÆÚ½×¶Î£¬³£¼ûµÄ£¬ÎÒÃÇÔÚ¿ª·¢(Dev)ÓëÔË Î¬(Ops)Ö®¼ä¼ÓÈëÇå¾²(Sec)£¬Ò²¾ÍÊÇ DevSecOps ÀíÄÆä×ÅÖØµãÊǽ«Çå¾²¹¤¾ß×ÔÉí ÕûºÏÖÁ CI/CD ÊÂÇéÁ÷ÖУ¬ÇÒÇå¾²¹¤¾ßÖ÷ÒªÄÉÈëÓ¦ÓõIJâÊÔ¡¢·¢²¼ºÍÔËά½×¶Î£¬ÈçÏÂͼËùʾ:

ͼ 1 DevSecOps ʾÒâͼ[6]
½üЩÄêÀ´£¬Ëæ×Å DevOps ¹¤¾ßÁ´¼¤Ôö£¬Èç Aqua¡¢Twistlock µÈÈÝÆ÷Çå¾²¹«Ë¾¾ùÖ§³ÖÁË DevSecOps µÄ½â¾ö·½°¸[7][8]¡£
È»¶ø£¬´ÓÇå¾²µÄ½Ç¶ÈÉÏ˼Á¿£¬DevSecOps ËäÈ»ÔÚÒ»¶¨Ë®Æ½Éϰü¹ÜÁË DevOps µÄÇå¾²£¬µ«ÓÉ ÓÚÆä²¢Î´º¸Ç DevOps µÄÕû¸ö±Õ»·Á÷³Ì£¬Òò¶øÈ±·¦ÏîÄ¿ÇéÐÎ(Ó¦ÓõÄÉÏÏÂÎÄÇéÐÎ)£¬½ø¶ø£¬ DevSecOps ÎÞ·¨½â¾öÓ¦ÓÃÇå¾²µÄÓÅÏȼ¶ÎÊÌâ¡£±ðµÄ£¬ÏîÄ¿ÇéÐεÄȱʧ»¹»á½µµÍÕûÌåµÄ¿ª·¢ ÔËάЧÂÊ¡£¼øÓÚ´Ë£¬ÈËÃÇÐìÐìÌá³öÁË SecDevOps µÄÀíÄ¼´½«Çå¾²²¿·Ö(Sec)ÒÆÖÁ×î×ó ±ß£¬SecDevOps ×ñÕÕ½«Çå¾²²¿ÊðÖÁϵͳÉúÃüÖÜÆÚµÄÿһ¸ö½×¶Î£¬¶ø²»½ö½öÊDzâÊÔ¡¢²¿Êð¡¢ ÔËά½×¶Î£¬ÈçÏÂͼËùʾ:

ͼ 2 SecDevOps ʾÒâͼ[9]
ͨ¹ýÇå¾²Á÷³ÌÓ뿪·¢Á÷³ÌµÄÒ»ÖÂÐÔ£¬ÎÒÃÇ¿ÉÒÔÔ¤½ç˵Á÷³ÌÒÔÈ·±£ÔÚ׼ȷ
ÄúµÄÁªÏµ·½·¨
? 2025 NSFOCUS ¾ÅÓÎÀÏ¸ç¿Æ¼¼ www.nsfocus.com All Rights Reserved . ¾©¹«Íø°²±¸ 11010802021605ºÅ ¾©ICP±¸14004349ºÅ ¾©ICPÖ¤110355ºÅ

¾ÅÓÎÀϸçÔÆ







