RSA Á¢ÒìɳºÐÅÌ»õ| Obsidian¡ª¡ªÄÜΪSaaSÓ¦ÓóÌÐòÌṩÇå¾²·À»¤ÔƼì²âÓëÏìӦƽ̨
2020-02-21
2020Äê2ÔÂ24ÈÕ-28ÈÕ£¬ÍøÂçÇå¾²ÐÐҵʢ»áRSA Conference½«ÔھɽðɽÀ¿ªá¡Ä»¡£½ñÌ죬¾ÅÓÎÀϸç¾ý½«¼ÌÐøÎª¸÷ÈËÏÈÈÝÈëÑ¡½ñÄêRSACÁ¢ÒìɳºÐʮǿµÄÊ×´´¹«Ë¾£ºObsidian¡£
Ò»¡¢¹«Ë¾ÏÈÈÝ
Obsidan Security¹«Ë¾½¨ÉèÓÚ2017Ä꣬ÓÚ2017Äê7ÔÂÍê³ÉAÂÖ950ÍòÃÀÔªÈÚ×Ê£¬ÏÖ×ÜÈÚ×ʶîÒÑ´ï2950ÍòÃÀÔª£¬Ö÷ÒªÓÉGreylock Partners¡¢WingºÍGVͶ×Ê¡£
Obsidian¹«Ë¾ÊÇÒ»¼ÒΪÆóÒµÌá¹©ÔÆ¼ì²âÓëÏìÓ¦µÄ¹«Ë¾£¬×ܲ¿Î»ÓÚ¼ÓÀû¸£ÄáÑÇÖÝŦ²¨Ìغ£Ì²¡£Ê×´´ÍŶÓÀ´×ÔÓÚCylance¡¢Carbon BlackºÍNSA£¬CylanceǰÈÎCTO¸ñÀ¼·ÆæÊ²»ô¶ûµÂ½¨Éè²¢³öÈÎCEO£¬CylanceǰÈÎÊ×ϯÊý¾Ý¿ÆÑ§¼Ò¼æNSAÅÌËã»ú¿ÆÑ§¼ÒÂíÌØ·ÎÖ¶û¸£µ£µ±CTO£¬Carbon Black¹«Ë¾Ç°CTO¼æÍŽáÊ×´´ÈËÒÔ¼°NSAÅÌËã»ú¿ÆÑ§¼Ò±¾·Ô¼º²Ñ·Ôòµ£µ±Ê×ϯÊý¾Ý¿ÆÑ§¼Ò¡£

ObsidianÌá³öÁËÒ»¸öеÄÀíÄî-CDR(Cloud Detection and Response)ÄÜΪSaaSÓ¦ÓóÌÐòÌṩÇå¾²·À»¤£¬²¢ÄÜ×ÊÖúÇå¾²ÔËÓªÍŶӼì²â²¢ÏìÓ¦ÈëÇÖºÍÄÚ²¿Íþв¡£Ö¼ÔÚ¿ìËÙ·¢Ã÷¡¢ÊÓ²ìºÍÏìÓ¦SaaSÓ¦ÓóÌÐòÖеÄÎó²îºÍÄÚ²¿Íþв£¬ÔÚ²»Ó°ÏìÓªÒµµÄÇéÐÎÏÂʵÏÖÒ»Á¬µÄ¼à¿ØÓëÆÊÎö¡£
¶þ¡¢²úÆ·ÏÈÈÝ
01
²úÆ·Åä¾°
ÔÚÒÑÍùµÄÊ®ÄêÖУ¬SaaSºÍ¹«¹²ÔÆ·þÎñµÄʹÓÃÈ¡µÃÁËÖØ´óµÄÔöÌí¡£×éÖ¯ÒѾ»òÕýÔÚ½«ÆäӪҵϵͳ£¨°üÀ¨µç×ÓÓʼþ£¬Ð×÷£¬HR£¬ÏúÊÛ£¬Êг¡ÓªÏúºÍÔËÓª£©Ç¨áãµ½ÔÆÖС£ÔÚ2019ÄêESGÑо¿ÊÓ²ìÖУ¬Èý·ÖÖ®¶þ£¨67£¥£©µÄ¼ÓÈëÕß±¨¸æ£¬ÏÖÔÚÁè¼Ý20£¥µÄÓ¦ÓóÌÐò»ùÓÚSaaS£¬¶øÁè¼Ý58£¥µÄ×éÖ¯ÔÚ2019Ä걨¸æÊ¹ÓÃÁËIaaS¡£

2011-2019ÄêʹÓûù´¡¼Ü¹¹¼´·þÎñ£¨IaaS£©µÄ×éÖ¯°Ù·Ö±È
02
ÔÆ¼ì²âÓëÏìÓ¦£¨CDR£©
ÔÆ¼ì²âÓëÏìÓ¦ÊÇObsidianÌá³öµÄÒ»¸öеÄÀíÄҲÊÇÄ¿½ñÔÆÇ徲ϵͳÖÐȱʧµÄÒ»²¿·Ö¡£
ÔÆ»á¼ûÇå¾²ÊðÀí£¨CASB£©Ö®ÀàµÄ½â¾ö¼Æ»®½ÓÄɵÄÊÇÔ¤·ÀÕ½ÂÔ¡£CASBÔڽṹÉÏÏñÔÆÇéÐεķÀ»ðǽ£¬³äµ±×éÖ¯»ù´¡¼Ü¹¹ÓëÔÆ·þÎñÖ®¼äµÄÖн飬Ö÷ÒªÊÇͨ¹ý×èÖ¹»á¼ûÀ´±ÜÃâÊý¾ÝɥʧºÍй¶ÒÔ¼°¶ñÒâÈí¼þ̻¶¡£
¿ÉÊÇ£¬ÕýÈçGartnerÔÚ×Ô˳ӦÇå¾²µÄÀíÄîÖÐÌá¼°£¬Ô¤·ÀÐÔ£¨Prevention£©¿ØÖƲ¢È±·¦ÒÔ±£»¤ÔÆÇéÐÎÃâÊܹ¥»÷¡£×ÝÈ»ÓÐÁË×îºÃµÄÔ¤·ÀÐÔÇå¾²½â¾ö¼Æ»®£¬¹¥»÷ÕßÈÔ¿ÉÒÔ´©Í¸»òÈÆ¹ý·ÀÓù»ñÈ¡¶ÔÔÆ×ʲúµÄ»á¼ûȨÏÞ¡£ÔÚÔÆÖУ¬Çå¾²ÍŶÓÐèÒª¿ìËÙ¼ì²â£¨Detection£©£¬ÊӲ첢ÏìÓ¦Íþв£¨Response£©£¬Õâ¾ÍÐèÒª¿ÉÊÓ»¯ºÍ¸»ºñµÄÓû§ÉÏÏÂÎÄÐÅÏ¢£¬ÒÔ±ãʵʱµÄ¼ì²âºÍÏìÓ¦¿ÉÒÉÐÐΪ¡£¶øÏÖÔÚ£¬ÕâÕýÊÇSaaSºÍÔÆ·þÎñËùȱ°±ÉĹ¦Ð§¡£
ÓëEDRÏà±È£¬ÔÆÇéÐÎÖеĿÉÊÓ»¯ÎÊÌâÓÐËù²î±ð£¬²¢ÇÒ¸üÎªÖØ´ó¡£ÓÉÓÚÓû§Õë¶Ô²î±ðÓ¦ÓóÌÐòÓвî±ðµÄȨÏÞ£¬Òò´ËSaaSÓ¦ÓóÌÐòÐèÒªÔÚÆ½Ì¨ÄÚ¾ÙÐÐÊÚȨÖÎÀí¡£ºÃ±ÈÇå¾²ÖÎÀíÔ±ÏëÉó²éÓû§¿ÉÒÔÔÚSalesforceÖлá¼ûµÄÄÚÈÝ»òËûÔÚG SuiteÖеIJÙ×÷£¬ÔòÖÎÀíÔ±±ØÐèÏÈ»ñÈ¡ÏìӦȨÏÞºÍÐÐΪÈÕÖ¾£¬²¢Ïàʶÿ¸ö·þÎñµÄÊÚȨģ×ÓºÍÐÐΪÈÕÖ¾ÃûÌã¬È»ºóÔÙÈ·¶¨Æ¾Ö¤ÕâЩÐÅϢȷ¶¨ÊÇ·ñ±¬·¢¿ÉÒɵĹ¥»÷ÊÂÎñ¡£´ó×ڵĻá¼û¼Í¼ºÍÐÐΪÐÅϢʹµÃÍþв¼ì²â±äµÃÒì³£ÖØ´ó£¬Í¨³£Ïà¹ØµÄÉÏÏÂÎÄÊý¾Ý»á±¬·¢TB¼¶Êý¾Ý£¬ÕâʹµÃÕæÕýµÄÍþв»ò¹¥»÷ÊÂÎñ¿Õ¼ä±»ÑÍûÔÚ´ó×ÚµÄÊý¾ÝÁ÷ÖС£
Õë¶ÔÒÔǰµÄÐèÇó£¬Ìá³öÁËÔÆ¼ì²âºÍÏìÓ¦£¨CDR£©½â¾ö¼Æ»®£¬CDRͨ¹ýÒ»Ö±ÍøÂ磬¹æ·¶»¯ºÍÆÊÎöÀ´×ÔSaaSºÍÔÆ·þÎñµÄ´ó×Ú״̬ºÍÐÐΪÊý¾Ý£¬ÎªÇ徲רҵְԱÌṩÁ˼ì²â£¬ÊÓ²ìºÍÏìÓ¦ÔÆÖÐÍþвËùÐèµÄÖÜÈ«µÄ¿ÉÊÓ»¯ÐÅÏ¢¡£
Òò´Ë£¬CDRÐèÒªÌṩÒÔϽ¹µã¹¦Ð§£º
1¡¢È«¾Ö¿ÉÊÓ»¯
CDRÐèÒªÌṩһ¸öÈ«¾Ö¿ÉÊÓ»¯ÊÓͼÀ´ÏÔʾÓû§¿çÔÆ·þÎñµÄ»á¼ûºÍÐÐΪÐÅÏ¢¡£ÕâÖÖÈ«¾Ö¿ÉÊÓ»¯ÊÓͼÈÚºÏÁË״̬ºÍÓû§ÐÐΪÊý¾Ý£¬²¢¼¯³ÉÁËÍþвÇ鱨ºÍÏà¹ØÉÏÏÂÎÄÐÅÏ¢£¨Î»Öá¢×°±¸¡¢ä¯ÀÀÆ÷µÈ£©¡£»ùÓÚÕâÖÖ¿ÉÊÓ»¯ÊÓͼ£¬Çå¾²ÍŶӿÉÒÔÓÐÓõÄʵÏÖ²î±ð½×¶ÎµÄÍþв¼ì²â£¬²¢¿ìËÙʵÏÖÊÂÎñÊÓ²ìºÍÏìÓ¦¡£
2¡¢×Ô¶¯¼ì²â
CDRËùÒªÆÊÎöµÄÊý¾Ýͨ³£½ÏÁ¿´ó£¬Òò´Ë£¬Ä¿½ñÔÆÇéÐεÄÎÊÌâÊÇÍþв»òÊǹ¥»÷ÐÐΪͨ³£»á±»ÑÍûÔÚ´ó×ÚµÄÊý¾ÝÓë¸æ¾¯ÖС£Òò´Ë£¬CDRʹÓûúеѧϰºÍ¹æÔòÆÊÎö¿ÉÒÔ×ÊÖúSOC´Ó´ó×ÚµÄÔëÉùÊý¾ÝÖÐÌáÈ¡ÓмÛÖµµÄÐÅÏ¢¡£
3¡¢ÍþвչÍû
CDR³ýÁ˾ßÓжÔÒѾÍþвºÍ¹¥»÷µÄ¼ì²âÄÜÁ¦Í⣬»¹¿ÉÒÔÕ¹ÍûÔÆÇéÐÎÖÐÏÂÒ»²½¿ÉÄܱ¬·¢µÄÒì³£»òÍþвÐÐΪ¡£Õâ¿ÉʹÇå¾²ÖÎÀíÕßÄÜÌáǰÕë¶ÔÒª±¬·¢µÄÍþвÐÐΪ×öÔ¤·À¡£
03
Obsidianƽ̨
ObsidianÔÆ¼ì²âºÍÏìӦΪSaaSÌṩÁËÎÞ·ìµÄÇå¾²ÐÔ¡£Ê¹ÓÃÒ»ÖÖÆæÒìµÄÒÔÉí·ÝΪÖÐÐĵÄÒªÁìºÍ»úеѧϰ£¬×èÖ¹ÔÆÖеĸ߼¶¹¥»÷¡£Æ½Ì¨ÄÜΪSaaSÓ¦ÓóÌÐòÌṩÇå¾²·À»¤£¬²¢ÄÜ×ÊÖúÇå¾²ÔËÓªÍŶӼì²â²¢ÏìÓ¦ÈëÇÖºÍÄÚ²¿Íþв¡£Ö¼ÔÚ¿ìËÙ·¢Ã÷¡¢ÊÓ²ìºÍÏìÓ¦SaaSÓ¦ÓóÌÐòÖеÄÎó²îºÍÄÚ²¿Íþв£¬ÔÚ²»Ó°ÏìÓªÒµµÄÇéÐÎÏÂʵÏÖÒ»Á¬µÄ¼à¿ØÓëÆÊÎö¡£
ObsidianÊÇͨ¹ýAPI¼¯³É×÷ΪSaaS·þÎñµÄ£¬ÓÉÓÚ²»ÐèÒª°²ÅÅÈκι¤¾ß£¬½â¾ö¼Æ»®¿ÉÒÔÔÚ¼¸·ÖÖÓÄÚÆô¶¯£¬ÔÚ¼¸Ð¡Ê±ÄھͿÉÒÔ±¬·¢Ð§¹û¡£
Obsidian×Ô¶¯µÄÍøÂç²¢±ê×¼»¯ÔÆÓ¦ÓõÄÏà¹ØÊý¾Ý£¬²¢»ùÓÚÍþвÇ鱨ºÍÉÏÏÂÎÄÀ´¸»ºñÕâЩÊý¾Ý¡£Obsidian»á»ùÓÚ»úеѧϰºÍ¹æÔòÕë¶ÔÎ¥¹æºÍÄÚÍøÍþвÐÐΪÌìÉú¸æ¾¯£¬²¢Ò»Ö±µÄ´ÓСÎÒ˽¼ÒºÍȺÌåÐÐΪģʽÖÐѧϰÔõÑùÀ´»á¼ûÊý¾Ý×ʲú¡£
»ùÓÚÓû§È¨ÏÞºÍÐÐΪµÄͳһÊÓͼ£¬Obsidianƽ̨¿ÉÒÔʵÏÖÊÂÎñÏìÓ¦¡¢ÊÓ²ìºÍÍþвá÷ÁÔ¡£Æ½Ì¨»á½¨Òéͨ¹ýɾ³ýÓâÆÚµÄÕ˺źÍÐÞ¸´¹ýʧÉèÖôӶøÔöÇ¿ÔÆÇå¾²Ó¦ÓõÄÇå¾²ÐÔ¡£

Obsidianƽ̨¹¦Ð§
1¡¢¿É¼ûÐÔ
ObsidianÊ×´ÎÌá³öÔÆÖеÄÓû§¡¢Êý¾ÝºÍÓ¦ÓóÌÐòµÄͳһÊÓͼ£¬²¢¿ÉÒÔÒ»Á¬¼àÊÓÓû§ºÍ·þÎñÕÊ»§µÄÐÐΪ£¬¶ÔÍþвºÍÎÀÉúÎÊÌâ·¢³ö¸æ¾¯¡£¿É¼ûÐÔÖ÷ÒªµÄ¹¦Ð§ÈçÏ£º
a) ÿ¸ö·þÎñµÄ»á¼ûȨÏÞºÍÌØÈ¨Çåµ¥
b) ÌØÈ¨Óû§Ô˶¯
c) ¿çSaaSÓ¦ÓóÌÐòµÄÔ˶¯¼àÊÓ
d)¿Éͨ¹ýAPIÏÂÔØµÄ¹æ·¶»¯Êý¾ÝÄ£×Ó
2¡¢¸æ¾¯
ƾ֤»ùÓÚ¹æÔòµÄ´¥·¢Æ÷ºÍ»úеѧϰ£¬¿ÉÒÔ»ñµÃ¹ØÓÚÎ¥¹æ¡¢Î£ÏÕÐÐΪºÍÕ½ÂÔÎ¥¹æµÄÖÒÑÔ¡£Obsidianƽ̨¿ÉÒÔ·¢Ã÷SaaS³¤ÆÚÐÔ¡¢OAuthÁîÅÆÀÄÓÃºÍÆäËûÏà¹ØÒì³£ÐÅÏ¢¡£¸Ã¹¦Ð§Ä£¿é°üÀ¨£º
a) ÄÚÖùæÔòʵÏÖ¶ÔÕ½ÂÔ³åÍ»ºÍÒì³£ÐÐΪ·¢³ö¾¯±¨µÄÄÚÖùæÔò
b) ʹÓûúеѧϰʵÏÖÒì³£ÐÐΪ¼ì²â
c) ÓÅÏÈ´¦Öóͷ£¾¯±¨£¬ÒÔïÔ̳¬¸ººÉµÄÇå¾²ÍŶӵľ¯±¨Æ£ÀÍ
d) ÓëSOARºÍ·þÎñÖÎÀíµÄ¿É¼¯³ÉÐÔ

3¡¢±¨¸æ
¿ÉÒÔÆ¾Ö¤²î±ð½ÇÉ«£¬»ñµÃ¹ØÓÚÓ¦ÓóÌÐòʹÓá¢Ð·ºÆðµÄÍþвºÍΣº¦ÐÐΪµÄÆæÒì¿´·¨µÄ±¨¸æ¡£Òò´Ë£¬Æ½Ì¨¾ßÓÐÈçϹ¦Ð§£º
a) ƾ֤×éÖ¯Öвî±ð½ÇÉ«µÄÐèÒª¶¨ÖƱ¨¸æºÍÒDZí°å
ƾ֤ÐèÇóµ¼³ö²î±ðÃûÌõÄÊý¾Ý
4¡¢ÏìÓ¦ÐÐΪ
ƽ̨»ùÓÚÓû§ºÍÆäÐÐÒµµÄͳһÊÓͼ£¬ÊµÏÖ¿ìËÙÓÐÓõÄÒì³£¼ì²âºÍÄÚ²¿Íþвʶ±ð£¬²¢Í¨¹ý×·×ÙÕ˺ʲÏíºÍÎļþÉÏ´«Óë»á¼ûµÄÀúÊ·ÐÐΪÀ´Ê¶±ðÓû§µÄºáÏòÒÆ¶¯¡£²¢ÄÜͨ¹ýƽ̨ÄÚÖù¦Ð§£¬×è¶ÏÊý¾Ýй¶ºÍեȡÕË»§ÀÄÓá£Òò´Ë£¬Æ½Ì¨ÐèÒªÈçϹ¦Ð§£º
a) »ùÓÚʱ¼ä¹ØÁªÓû§ÐÐΪºÍÆäÉÏÏÂÎÄÐÅϢʵÏÖÒì³£¼ì²âºÍÍþвʶ±ð£»
b) Ìá¹©ÍÆ¼öÐÐΪÒÔÖ¸µ¼´¦Öóͷ£¡£

°¸Àý
1¡¢Õ˺ű£»¤
a) ±£»¤SaaSÕÊ»§²»±»ÆÆËðºÍÀÄÓÃ
ÔÆÇéÐÎϵÄÒªº¦ÊÇÔõÑùÔÚ²»Ó°ÏìÕýµ±Óû§ÌåÑéµÄÇéÐÎϰü¹ÜÔÆ×ʲúµÄÇå¾²¡£Í¨¹ýÈ«¾Ö¿É¼ûÐÔ£¬Obsidian¿ÉÒÔչʾÄÄЩÓû§¿ÉÒÔ»á¼ûSaaSÓ¦ÓóÌÐò£¬ÒÔ¼°»á¼ûµÄ¼¶±ð¡£Æ½Ì¨»¹¿ÉÒÔÒ»Á¬¼à¿ØÓû§ÔÚÕâЩӦÓóÌÐòÖÐ×öÁËʲô£¬²¢É¾³ý²»»îÔ¾µÄÕÊ»§£¬ÒÔËõС¹¥»÷ÃæºÍ½µµÍ±¾Ç®¡£

ÉÏͼ¿ÉÒÔ¿´µ½Ã¿¸ö·þÎñÉÏËÓµÓÐÊ²Ã´ÌØÈ¨£¬ËüÃÇÊÇ·ñ´¦ÓÚÔ˶¯×´Ì¬£¬ÒÔ¼°ËüÃÇÔõÑùʹÓÃÕâÐ©ÌØÈ¨¡£
b) »á¼ûÌØÈ¨ÕÊ»§µÄĿ¼
»ñȡÿ¸ö·þÎñÖоßÓÐÌØÈ¨µÄÕÊ»§Çåµ¥¡£

c) »îÔ¾ÕË»§Óë·Ç»îÔ¾Õ˺Å
ObsidianÄÜͨ¹ý·þÎñ»ñµÃÔ˶¯ÕÊ»§ºÍ·ÇÔ˶¯ÕÊ»§µÄ¼òªÊÓͼ£¬ÆäÖаüÀ¨Ô˶¯ÇéÐεÄÀúʷת±ä¡£²¢ÇÒ»ùÓÚÕâЩÕË»§µÄÔ˶¯ÐÅÏ¢£¬ÕûÀí²»»îÔ¾µÄÕÊ»§£¬ÒÔ¸ÄÉÆÉí·ÝÒ»Ñùƽ³£ÕûÀíºÍ½µµÍ±¾Ç®¡£

d) ¾ßÓжàÖÖÌØÈ¨½ÇÉ«µÄÓû§
Ò»¸öÓû§¾ßÓжàÖÖÌØÈ¨£¬¿ÉÄÜ»á¶Ô×éÖ¯×é³É¸ü¸ßµÄΣº¦¡£
e) ²»Ô˶¯ÕÊ»§µÄ³Â¸¯Óû§¼à¿Ø
Obsidian¿ÉÄÜ¼à¿ØÕË»§µÄ»îÔ¾ÇéÐΣ¬ÒÔ±ã²éÓû§ÊÇ·ñÒÑÇл»½ÇÉ«»òÍÑÀ빫˾¡£

2¡¢Íþвá÷ÁÔ
a) ¾ÀÕýÎ¥¹æºÍÍþвʶ±ð
SaaSÇéÐÎÖеÄÍþв¼ì²âºÜÊÇÄÑÌ⣬SaaSÓ¦ÓóÌÐòʵÖÊÉÏÊǶàÔÆÇéÐΡ£Salesforce¡¢G Suite¡¢SlackºÍÆäËûÓ¦ÓóÌÐò¶¼ÓÐÆæÒìµÄÉí·ÝºÍ»á¼ûģʽ£¬²¢½«ÓйØÈ¨ÏÞºÍÔ˶¯µÄÐÅÏ¢ÉúÑÄÔÚsilosÖС£ObsidianÌṩÁËÍþв¼ì²â¡¢Î¥Ô¼ÐÞ¸´ºÍÇå¾²¼Ó¹ÌµÄͳһ¿ÉÊÓ»¯,¿ÉÒÔ¿ìËÙ¼ì²âÒì³£µÇ¼¡¢SaaS³¤ÆÚÐÔ¡¢Êý¾Ý¹ýÂË¡¢ºáÏòÒÆ¶¯¡¢OAuthÁîÅÆÀÄÓÃºÍÆäËûÍþвµÄÖ¸±ê£¬²¢Ñ¸ËÙ¾ÀÕýÎ¥¹æ¡¢Ê¶±ðÍþв¡£

b) ÖÒÑÔ
ObsidianÔÚ²»ÐèÒª¾ÙÐÐÈκÎÉèÖõÄÇéÐÎÏ£¬Äܹ»»ñµÃÖÖÖÖÍþвµÄ¸æ¾¯¡£ObidianµÄ¸æ¾¯º¸ÇÁËÖÚËùÖÜÖªµÄ¶ñÒâ¹¥»÷£¬²¢ÊµÏÖÁ˸澯ÑÏÖØ¶ÈÅÅÐò¡£

c) λÖüͼ
Obsidian¿ÉÒÔ¼àÊÓÓû§´ÓÄÇÀïµÇ¼¡£¼ì²âÒì³£µÇ¼ºÍÔ˶¯¼£ÏóµÈ¡£

d) Íþвá÷ÁÔµÄÔ˶¯ÊÓͼ
Obsidianͨ¹ýλÖá¢ÊÂÎñÀàÐÍ¡¢ISP¡¢×°±¸¡¢ÌØÈ¨¡¢»á¼ûÀúÊ·µÈ·½ÃæµÄÌØÈ¨¡¢Ô˶¯ºÍÉÏÏÂÎĵÄͳһÊÓͼ£¬Æð¾¢×Ô¶¯µØ¼ì²âSaaSÇéÐÎÖеÄδ֪Íþв¡£

3¡¢ÊÂÎñÏìÓ¦
a) »ùÓÚÈ«¾Ö¿ÉÊÓ»¯µÄ¿ìËÙÏìÓ¦
ʹÊÏìӦС×éÄÜÔÚ²»Ó°ÏìϵͳÔËÐеÄÇéÐξÙÐмì²â£¬Ê¶±ð¸ùÒò²¢¿ìËÙÆÀ¹ÀÓ°Ïì¡£Obsidianͨ¹ýÍøÂç¡¢¹æ·¶»¯ºÍ´æ´¢À´×ÔSaaSÓ¦ÓóÌÐòµÄ´ó×Ú״̬ºÍÔ˶¯Êý¾Ý£¬´Ó¶øÊµÏÖ¿ìËÙµÄÔÆÊÂÎñÏìÓ¦¡£

ͨ¹ýʹÓùØÓÚÓû§¡¢ÌØÈ¨ºÍÔ˶¯µÄͳһÊý¾Ý£¬ObsidianÄÜÓÐÓõؾÙÐÐÐÅÏ¢¼ìË÷ÊÂÇ顣ƽ̨½«Óû§¡¢»á¼ûºÍÌØÈ¨ÓëÔ˶¯ÁªÏµÆðÀ´£¬²¢Í¨¹ýλÖá¢ÊÂÎñÀàÐÍ¡¢IPµØµãºÍ×°±¸¸»ºñÁËÕâÒ»¹¦Ð§¡£
b) ͨ¹ýIPËÑË÷
ËÑË÷ÒÑÖªµÄ¶ñÒâIPºÍ¸ÐÐËȤµÄIPµØµã£¬ÒÔ²éÕÒÓë¸ÃµØµãÏà¹ØµÄÆäËûÔ˶¯¡£

c) ƾ֤Óû§»òÎĵµËÑË÷Ô˶¯ÈÕÖ¾
ËÑË÷ÓëÌØ¶¨Óû§Ïà¹ØµÄËùÓÐÔ˶¯£¬»òÔÚÏà¹ØÎĵµ»ò×ʲúÉÏÖ´ÐеÄËùÓÐÔ˶¯¡£

Èý¡¢Á¢ÒìµãºÍÌôÕ½
ÔÆ»á¼ûÇå¾²ÊðÀí£¨CASB£©Ö®ÀàµÄ½â¾ö¼Æ»®À´½ÓÄÉÔ¤·ÀÕ½ÂÔ£¬µ«²¢È±·¦ÒÔ±£»¤ÔÆÇéÐÎÃâÊܹ¥»÷¡£×ÝÈ»ÓÐÁË×îºÃµÄÔ¤·ÀÐÔÇå¾²½â¾ö¼Æ»®£¬¹¥»÷ÕßÈÔ¿ÉÒÔ´©Í¸»òÈÆ¹ý·ÀÓù»ñÈ¡¶ÔÔÆ×ʲúµÄ»á¼ûȨÏÞ¡£ÔƼì²âÓëÏìÓ¦ÊÇObsidianÌá³öµÄÒ»¸öеÄÀíÄ½«xDRµÄÀíÄîÓ¦ÓÃÔÚÔÆ¶Ë£¬ÔÆÇå¾²ÍŶÓÐèÒª¿ìËÙ¼ì²â£¬ÊӲ첢ÏìÓ¦Íþв¡£Õâ¾ÍÐèÒª¿ÉÊÓ»¯ºÍ¸»ºñµÄÓû§ÉÏÏÂÎÄÐÅÏ¢£¬ÒÔ±ãʵʱµÄ¼ì²âºÍÏìÓ¦¿ÉÒÉÐÐΪ¡£¶øÏÖÔÚ£¬ÕâÕýÊÇSaaSºÍÔÆ·þÎñËùȱ°±ÉĹ¦Ð§¡£ÔƼì²âºÍÏìÓ¦£¨CDR£©½â¾ö¼Æ»®Í¨¹ýÒ»Ö±ÍøÂ磬¹æ·¶»¯ºÍÆÊÎöÀ´×ÔSaaSºÍÔÆ·þÎñµÄ´ó×Ú״̬ºÍÐÐΪÊý¾Ý£¬ÎªÇ徲רҵְԱÌṩÁ˼ì²â£¬ÊÓ²ìºÍÏìÓ¦ÔÆÖÐÍþвËùÐèµÄÖÜÈ«µÄ¿ÉÊÓ»¯ÐÅÏ¢¡£ObsidianµÄÁ¢Ò죬Ö÷Òª°üÀ¨ÔÆÇéÐεĿɼûÐÔ¡¢×Ô¶¯»¯¼ì²âºÍÇ徲Σº¦¼à¿Ø£¬¶¼ÊÇSaaSµÄ½¹µãÐèÇ󣬽â¾öÁËÔÆÇå¾²µÄÍ´µã¡£
ËäȻҲÐèÒª¿´µ½ÆäÉÌÒµ»¯ÓкܴóµÄÌôÕ½£¬xDR²úÆ·µÄÀÖ³ÉÓ¦ÓÃÐèÒªÓû§Çå¾²ÍŶÓÓнϸߵÄÇå¾²ÔËÓªÄÜÁ¦£¬²»È»ÎÞ·¨Ê©Õ¹ÆäÓ¦ÓеÄ×÷Óá£ÈôÊÇÉÏÔÆµÄÆóÒµ£¨ÌØÊâÊÇÖÐСÆóÒµ£©Ã»ÓÐÏà¹ØµÄÔËÓªÄÜÁ¦£¬ÄÇÓ¦¸ÃҪ˼Á¿Ö§³ÖÔÆ¶ËÓ¦ÓõÄMDR·þÎñ£¬ÀýÈçÈ¥ÄêRSA»á³¡Í⣬Google×éÖ¯µÄÉú̬Ȧ»áÕ¹ÖÐÓÐÒ»¼ÒBlueVoyant¹«Ë¾£¬Äܹ»Ìá¹©ÃæÏò¹«ÓÐÔÆµÄMDR·þÎñ£¬Í¨¹ý¾ø´ó²¿·ÖÄܹ»×Ô¶¯»¯µÄTier 1·þÎñºÍ»ùÓÚÊý¾Ý¿ÆÑ§µÄTier 2ºǫ́·þÎñ£¬¿ÉÒÔΪ´ó×ÚµÄÔÆ¿Í»§Ìṩ¿ÉÀ©Õ¹µÄÇå¾²ÔËÓª·þÎñ¡£

ËÄ¡¢×ܽá
ObsidianµÄÊ×´´ÈËÀ´×ÔCylanceºÍCarbon Black£¬»®·ÖÓÐÔÆ¶ËÁãÐÅÍкÍÖÕ¶ËEDRµÄÀÖ³ÉÂÄÀú£¬ÐÅÍÐÄܹ»½«¸Ã²úÆ·Äܹ»Ã÷È·ÔÆ¶ËSaaSÓ¦ÓõÄÕæÊµÎ£º¦£¬»ùÓÚ¼ì²âºÍÏìÓ¦ÊÖÒÕ½â¾ö¿Í»§ÉÏÔÆµÄÍ´µã£¬Ò²ÐíCDR»áÊÇ“ºóCASB”µÄÐÂÐͲúÆ·£¬×ÊÖú¿Í»§ÊµÊ±·¢Ã÷²¢»º½âÍþв¡£
· ²Î¿¼Á´½Ó ·
[1] CLOUD DETECTION AND RESPONSE IS THE MISSING ELEMENT OF CLOUD SECURITY£¬https://www.obsidiansecurity.com/cloud-detection-and-response-missing-element/
[2] Obsidian¹Ù·½ÍøÕ¾£¬https://www.obsidiansecurity.com/

¾ÅÓÎÀϸçÔÆ







