日韩中文字幕在线一区二区三区,亚洲热视频在线观看,久久精品午夜一区二区福利,精品一区二区三区在线观看l,麻花传媒剧电影,亚洲香蕉伊综合在人在线,免费av一区二区三区在线,亚洲成在线人视频观看
          首頁 500強 活動 榜單 商業 科技 商潮 專題 品牌中心
          雜志訂閱

          軟件漏洞令專家難以招架,人工智能或許能夠提供幫助

          Christian Vasquez
          2025-03-28

          更廣泛地應用人工智能或將助力企業確定修復軟件漏洞的優先順序。

          文本設置
          小號
          默認
          大號
          Plus(0條)

          圖片來源:Jakub Porzycki/NurPhoto via Getty Images

          在網絡安全領域工作20多年后,大衛·林德納(David Lindner)已做好準備迎接行業變革。

          作為網絡安全公司Contrast Security的首席信息安全官,他正在推動同行們從傳統的安全從業者轉型為人工智能的早期采納者。他在安全領域工作了很長時間,他認為該行業需要借助人工智能實現變革,以免在遭受重大網絡攻擊后才被迫采取行動。

          林德納表示:“安全領域在適應變化方面,有時表現得極為遲緩。我認為我們正處在變革的邊緣。我確實認為人們將不得不開始采取不同的做法。”

          多年來,軟件生態系統一直飽受漏洞困擾,為惡意黑客提供了大量可乘之機。與此同時,軟件的產出速度不斷加快,已知缺陷也層出不窮。

          林德納警告稱,開發人員利用人工智能加速軟件開發,這不僅會擴大黑客的攻擊目標范圍,還會催生更多漏洞。他認為,應對策略在于更廣泛地應用人工智能,以抵消其可能帶來的負面影響,并助力企業確定網絡安全工作的優先事項。

          確定優先事項在一定程度上取決于每家公司所獨有的基礎設施以及所運營的產品特性。林德納指出,這是一項艱巨的任務,需要耗費大量資源。

          美國國家計算機通用漏洞數據庫(National Vulnerability Database)是一個由聯邦政府運營的軟件漏洞數據庫,每天追蹤并發布上百個嚴重程度不一的漏洞。部分漏洞可忽略不計,而另一些則應立即修復或采取降低風險措施。

          等開發人員著手修復漏洞時,往往又有新的漏洞加入到本就積壓已久的漏洞列表中。軟件安全公司Veracode的一份報告顯示,在近一半的機構中,關鍵漏洞在軟件中的滯留時間超過一年,局面幾乎失控。

          林德納用應用安全領域的行業術語解釋道:“確定優先順序始終是應用安全工作的核心所在,因為在關鍵環節,信息匱乏的問題長期存在。”

          林德納的技術生涯始于開發人員,隨后迅速對安全領域產生了興趣。他最初在一家中型保險公司從事安全領域的工作,彼時該公司正初步探索應用網絡安全之道。

          林德納剛加入安全團隊時,就接觸到了滲透測試領域,即企業委托專業黑客嘗試找出其產品中的漏洞和安全隱患。

          林德納表示:“我們聘請了第三方開展(滲透)測試,我當時眼前一亮。我心想,哇,這太棒了。太酷了,于是我決定去攻讀碩士學位。”

          2006年獲得碩士學位后,他在應用安全領域工作了約15年。之后,林德納先是進入IBM工作,然后在同一領域從事咨詢工作約8年。2008年,他加入了一家安全公司,該公司的部分業務后來剝離出來,最終成為Contrast Security。

          如今,他認為無論人們是否做好準備,生態系統已準備好迎接重大變革。軟件開發人員和網絡安全從業人員就如同置身于一艘滿是漏洞的船上,而他們手中用以應對危機的水桶同樣滿是漏洞。林德納說:“諸多表象已然改變,但本質上卻又仿佛一切如舊。”

          修復漏洞對林德納而言,往往是一個令人沮喪的話題,這很大程度上源于他多年來目睹的情況始終未見好轉。例如,專注于軟件安全的非營利機構開放式Web應用程序安全項目(OWASP)每年都會發布十大web應用安全風險,而據林德納所言,這些年度風險榜單中的條目總是大同小異。

          林德納推動更廣泛地采用人工智能,部分原因是他聽到一些首席信息安全官以安全和隱私問題為由抵制人工智能工具。然而,他指出,在生成式軟件風靡之前,多年來,該行業就已經以各種形式使用人工智能了。比如,電子郵件垃圾郵件過濾器就是機器學習的早期應用實例,很快便成為處理大量垃圾郵件的常規解決方案。

          林德納說:“我希望看到人們接受并利用新技術。人工智能并不可怕。它很強大,會對我們有所幫助。”(財富中文網)

          譯者:中慧言-王芳

          在網絡安全領域工作20多年后,大衛·林德納(David Lindner)已做好準備迎接行業變革。

          作為網絡安全公司Contrast Security的首席信息安全官,他正在推動同行們從傳統的安全從業者轉型為人工智能的早期采納者。他在安全領域工作了很長時間,他認為該行業需要借助人工智能實現變革,以免在遭受重大網絡攻擊后才被迫采取行動。

          林德納表示:“安全領域在適應變化方面,有時表現得極為遲緩。我認為我們正處在變革的邊緣。我確實認為人們將不得不開始采取不同的做法。”

          多年來,軟件生態系統一直飽受漏洞困擾,為惡意黑客提供了大量可乘之機。與此同時,軟件的產出速度不斷加快,已知缺陷也層出不窮。

          林德納警告稱,開發人員利用人工智能加速軟件開發,這不僅會擴大黑客的攻擊目標范圍,還會催生更多漏洞。他認為,應對策略在于更廣泛地應用人工智能,以抵消其可能帶來的負面影響,并助力企業確定網絡安全工作的優先事項。

          確定優先事項在一定程度上取決于每家公司所獨有的基礎設施以及所運營的產品特性。林德納指出,這是一項艱巨的任務,需要耗費大量資源。

          美國國家計算機通用漏洞數據庫(National Vulnerability Database)是一個由聯邦政府運營的軟件漏洞數據庫,每天追蹤并發布上百個嚴重程度不一的漏洞。部分漏洞可忽略不計,而另一些則應立即修復或采取降低風險措施。

          等開發人員著手修復漏洞時,往往又有新的漏洞加入到本就積壓已久的漏洞列表中。軟件安全公司Veracode的一份報告顯示,在近一半的機構中,關鍵漏洞在軟件中的滯留時間超過一年,局面幾乎失控。

          林德納用應用安全領域的行業術語解釋道:“確定優先順序始終是應用安全工作的核心所在,因為在關鍵環節,信息匱乏的問題長期存在。”

          林德納的技術生涯始于開發人員,隨后迅速對安全領域產生了興趣。他最初在一家中型保險公司從事安全領域的工作,彼時該公司正初步探索應用網絡安全之道。

          林德納剛加入安全團隊時,就接觸到了滲透測試領域,即企業委托專業黑客嘗試找出其產品中的漏洞和安全隱患。

          林德納表示:“我們聘請了第三方開展(滲透)測試,我當時眼前一亮。我心想,哇,這太棒了。太酷了,于是我決定去攻讀碩士學位。”

          2006年獲得碩士學位后,他在應用安全領域工作了約15年。之后,林德納先是進入IBM工作,然后在同一領域從事咨詢工作約8年。2008年,他加入了一家安全公司,該公司的部分業務后來剝離出來,最終成為Contrast Security。

          如今,他認為無論人們是否做好準備,生態系統已準備好迎接重大變革。軟件開發人員和網絡安全從業人員就如同置身于一艘滿是漏洞的船上,而他們手中用以應對危機的水桶同樣滿是漏洞。林德納說:“諸多表象已然改變,但本質上卻又仿佛一切如舊。”

          修復漏洞對林德納而言,往往是一個令人沮喪的話題,這很大程度上源于他多年來目睹的情況始終未見好轉。例如,專注于軟件安全的非營利機構開放式Web應用程序安全項目(OWASP)每年都會發布十大web應用安全風險,而據林德納所言,這些年度風險榜單中的條目總是大同小異。

          林德納推動更廣泛地采用人工智能,部分原因是他聽到一些首席信息安全官以安全和隱私問題為由抵制人工智能工具。然而,他指出,在生成式軟件風靡之前,多年來,該行業就已經以各種形式使用人工智能了。比如,電子郵件垃圾郵件過濾器就是機器學習的早期應用實例,很快便成為處理大量垃圾郵件的常規解決方案。

          林德納說:“我希望看到人們接受并利用新技術。人工智能并不可怕。它很強大,會對我們有所幫助。”(財富中文網)

          譯者:中慧言-王芳

          After spending more than 20 years in the cybersecurity field, David Lindner is ready for the industry to change.

          As chief information security officer at cybersecurity firm Contrast Security, he’s pushing for fellow CISOs to be more early-adopter enthusiasts than old school security practitioners. Having spent a good portion of his career in security, he thinks the industry needs to change by using artificial intelligence before a major cyberattack forces its hand.

          “Security is just slow to adapt sometimes,” Lindner said. “I think we’re on the precipice of something different. I really think people are going to have to start doing things differently.”

          For years, the software ecosystem has been infested with bugs, leaving malicious hackers with a buffet of options to exploit. Meanwhile, software continues to be churned out at an ever increasing pace and rife with known defects.

          Lindner warns that developers using artificial intelligence to speed up software production will increase the amount of options that hackers can attack as well as increase the number of vulnerabilities. The answer is to fight the consequences of artificial intelligence with more artificial intelligence, Lindner said, to help organizations determine what their cybersecurity priorities should be.

          Deciding priorities depends partly on the unique infrastructure and products each company owns and operates. It’s a monumental task that takes up huge resources, argues Lindner.

          The National Vulnerability Database, a federally-run repository of software vulnerabilities, tracks and releases over a hundred bugs daily that vary in severity. Some bugs can be safely ignored, but others should be immediately patched or the risk mitigated.

          By the time developers can get around to fixing bugs, there are often new ones to join the already long backlog of vulnerabilities. The situation is so unmanageable that nearly half of all organizations have had a critical vulnerability remain in their software for longer than a year, a report by the software security firm Veracode found.

          “Prioritization has been forever the vein of AppSec’s existence, because we just don’t ever have enough information where it matters,” Lindner said, using industry jargon for application security.

          Lindner began his technology career as a developer before quickly finding an interest in security. He started in the security field at a medium-sized insurance company that was just beginning to explore application cybersecurity.

          Lindner had just joined the security team when he discovered the world of penetration testing, or when professional hackers are paid by companies to try to find bugs and vulnerabilities in their products.

          “We hired a third party to come in and run a [penetration] test and my eyes just kind of lit up,” Lindner said. “I was like holy s***, this is awesome. This is so cool and I decided to go get my master’s.”

          He spent the better part of 15 years in application security after finishing his master’s in 2006. Lindner next went to IBM before consulting in the same space for around eight years. In 2008 he went to a security firm, of which a portion would spin out to eventually become Contrast Security.

          Now, he believes the ecosystem is ready for major change—whether people are ready for it or not. Software developers and cybersecurity practitioners are essentially in a boat filled with holes, armed with a bucket that is also filled with holes. “A lot has changed, but nothing has changed,” Lindner said.

          Fixing vulnerabilities is often a frustrating topic for Lindner, largely because he’s been seeing the same thing for years. For example, the Open Worldwide Application Security Project (OWASP), a nonprofit organization that focuses on software security, releases the top 10 web application security risks every year. And every year, the top 10 risks are largely the same, Lindner said.

          Lindner’s push for more AI is partly driven by CISO’s he has heard from who oppose using AI tools, citing security and privacy issues. However, he says the industry has been using AI in one form or another for years before generative software became popular. For example, email spam filters is an early use of machine learning that quickly became a norm to deal with the deluge of unwanted emails.

          “I want to see people embrace it and take advantage of newer things,” Lindner said. “AI is not scary. It’s powerful and it’s going to help us.”

          財富中文網所刊載內容之知識產權為財富媒體知識產權有限公司及/或相關權利人專屬所有或持有。未經許可,禁止進行轉載、摘編、復制及建立鏡像等任何使用。
          0條Plus
          精彩評論
          評論

          撰寫或查看更多評論

          請打開財富Plus APP

          前往打開