RSAÁ¢ÒìɳºÐÅÌ»õ£üAxis Security£ºÈÃÁãÐÅÍиü¼òÆÓ
2021-05-17
RSAConference2021½«Óھɽðɽʱ¼ä5ÔÂ17ÈÕÕÙ¿ª£¬Õ⽫ÊÇRSA´ó»áÓÐÊ·ÒÔÀ´µÚÒ»´Î½ÓÄÉÍøÂçÐéÄâ¾Û»áµÄÐÎʽ¾ÙÐС£´ó»áµÄInnovation Sandbox£¨É³ºÐ£©´óÈü×÷Ϊ“Ç徲ȦµÄ°Â˹¿¨”£¬Ã¿Äê¶¼±¸ÊÜÖõÄ¿£¬³ÉΪȫÇòÍøÂçÇå¾²ÐÐÒµÊÖÒÕÁ¢ÒìºÍͶ×ʵķçÏò±ê¡£
ǰ²»¾Ã£¬RSA¹Ù·½Ðû²¼ÁË×îÖÕÈëÑ¡Á¢ÒìɳºÐµÄʮǿÊ×´´¹«Ë¾£ºWABBI¡¢Satori¡¢Abnormal Security¡¢Apiiro¡¢Axis Security¡¢Cape Privacy¡¢Deduce¡¢Open Raven¡¢STARATA¡¢WIZ¡£
¾ÅÓÎÀϸç¾ý½«Í¨¹ýÅä¾°ÏÈÈÝ¡¢²úÆ·ÌØµã¡¢µãÆÀÆÊÎöµÈ£¬´ø¸÷ÈËÏàʶÈëΧµÄʮǿ³§ÉÌ¡£½ñÌ죬ÎÒÃÇÒªÏÈÈݵÄÊdz§ÉÌÊÇ£ºAxis Security¡£
1 ¹«Ë¾ÏÈÈÝ
Axis SecurityÓÚ2018ÄêÓÉDor KnafoºÍGil Azrielant½¨É裬ÊÇÒ»¼Ò×¢²áÔÚÃÀ¹ú¼ÓÀû¸£ÄáÑÇÖݵÄÁãÐÅÍÐÊ×´´¹«Ë¾£¬ÏÖÔÚÒѾÓÉ4ÂÖÈÚ×Ê£¬ÀۼƻñµÃ½üÒ»ÒÚÃÀԪͶ×Ê¡£Axis SecurityµÄÁ½Î»Ê×´´ÈËÊÇÒÔÉ«ÁкÕ×ÈÀûÑÇ¿çѧ¿ÆÑо¿ÖÐÐÄ£¨IDC Herzliya£©µÄУÓÑ£¬Dor KnafoÔøÔÚÒÔÉ«Áйú·À¾üµ£µ±¸ß¼¶Èí¼þ¹¤³Ìʦ£¬ºó½øÈëÈüÃÅÌú¿ËÈθ߼¶Ñо¿Ô±£»Gil AzrielantÔòÔøÔÚÒÔÉ«Áйú·À¾ü8200²½¶Ó·þÒÛ¡£

Axis SecurityÖÂÁ¦ÓÚÌṩ¼òÆÓ¿ì½ÝµÄÁãÐÅÍнâ¾ö¼Æ»®£¬×ÊÖú¿Í»§¿ìËÙÂ䵨ÁãÐÅÍУ¬×èÖ¹ÐéÄâרÓÃÍøÂ磨VPN£©±£´æµÄÇ徲Σº¦¡£
2 Åä¾°ÏÈÈÝ
ÔÚ¶ÔAxis SecurityµÄ²úÆ·¼°Ïà¹ØÊÖÒÕ¾ÙÐÐÆÊÎö֮ǰ£¬ÎÒÃÇÊ×ÏÈÏÈÈÝһϓÁãÐÅÍДµÄ¿´·¨¡£ÁãÐÅÍÐÊÇÒ»ÖÖеÄÍøÂçÇå¾²·ÀÕչ˻¤Ê¿Ä¶ø·ÇÏêϸµÄij¸öÊÖÒÕ»ò²úÆ·¡£
ÔڹŰåµÄÍøÂçÇå¾²¿´·¨ÖУ¬ÆóÒµÍøÂçÓÐÄÚÍâÍøÖ®·Ö£¬Á½ÕßÖ®¼äÓÐÒ»ÌõÇåÎúµÄ½çÏߣ¬½çÏßÄÚͨ³£±»ÒÔΪÊǸüÇå¾²µÄ£¬½çÏßÍâÔòÊÇδ֪¡¢³äÂúΣº¦µÄ¡£È»¶ø£¬Ëæ×ſƼ¼µÄÉú³¤ºÍÍøÂç¼Ü¹¹µÄÑݽø£¬ÈËÃÇ·¢Ã÷ÕâÑùµÄ“½çÏßÐÅÍмÙÉè”±£´æÈ±ÏÝ——ÍâÍøËäÈ»ÊdzäÂúΣº¦µÄ£¬µ«ÄÚÍøÈ´·×Æç¶¨¾ÍÊÇÇå¾²µÄ£¬Í¬Ñù»áÓÐÍþв¡£Ì«¹ýÐÅÍС¢ÒÀÀµÕâÑùµÄ½çÏß»®·Ö¿ÉÄܵ¼ÖÂÑÏÖØÐ§¹û£¬ÀýÈ磬ÍⲿµÄ¹¥»÷ÕßÍ»ÆÆÄÚÍøºó¿ÉÒÔÈÝÒ׵ؾÙÐкáÏòÒÆ¶¯¡¢ÄÚÍøÖÜÓΣ»ÄÚ²¿µÄ¹¥»÷ÕßÔòÄܹ»ÈÝÒ×µØÌᳫ¹¥»÷¡£
ÃæÁÙÕâЩÎÊÌ⣬ÔÚ2010Ä꣬ʱÈÎForresterÆÊÎöʦµÄJohn KindervagÌá³öÁËÁãÐÅÍУ¨Zero Trust£©µÄ¿´·¨¡£ÁãÐÅÍÐÇ¿µ÷ĬÈϵÄÐÅÍÐÊDz»±£´æµÄ£¬ÍøÂçλÖò»ÔÙ¾öÒé»á¼ûȨÏÞ£¬Ã¿Ò»¸öÇëÇó£¬ÎÞÂÛÀ´×ÔÄÇÀ¶¼Òª¾Óɼì²é£¬È·ÈÏÓµÓÐÕýµ±ÊÚȨ¡£
ØÊºó£¬GoogleÓÚ2011ÄêÂÊÏÈ×îÏÈʵÑé»ùÓÚÁãÐÅÍÐÄ£×Ó½¨ÉèÍøÂçÇå¾²¼Ü¹¹µÄÏîÄ¿BeyondCrop[2]£¬²¢ÓÚ2017¶ÔÍâÐû²¼Íê³É£¬BeyondCropÆÕ±éÓ¦ÓÃÓÚGoogleÔ±¹¤µÄÒ»Ñùƽ³£°ì¹«¡£
2014Ä꣬¹ú¼ÊÔÆÇ徲ͬÃË£¨Cloud Security Alliance£¬¼ò³ÆCSA£©Ðû²¼ÁË¡¶Èí¼þ½ç˵½çÏߣ¨Software Defined Perimeter£¬¼ò³Æ SDP£©±ê×¼¹æ·¶ 1.0¡·£¬SDPÓëÁãÐÅÍÐÍøÂçµÄÀíÄîÊÇÒ»Öµģº
1. ÎÞÂÛÓû§ºÍ·þÎñÆ÷×ÊÔ´ÔÚʲôλÖã¬È·±£ËùÓÐ×ÊÔ´»á¼ûÊÇÇå¾²µÄ¡£
2. ¼Í¼ºÍ¼ì²éËùÓеÄÁ÷Á¿¡£
3. ¹ØÓÚËùÓÐÊÚȨִÐÐ×îСȨÏÞÔÔò¡£
2019Ä꣬ÃÀ¹ú¹ú¼Ò±ê×¼ÓëÊÖÒÕÑо¿Ôº£¨NIST£©Ðû²¼ÁË¡¶ÁãÐÅÍмܹ¹¡·²Ý°¸£¬ÓÚ2020ÄêÔÙ´ÎÐÞ¶©£¬²¢ÓÚͬÄêÕýʽÐû²¼£¨NIST.SP.800-207£©¡£
ƾ֤¡¶ÁãÐÅÍмܹ¹¡·[4]£¬ÁãÐÅÍÐÊÇÒ»ÖÖÒÔ×ÊÔ´±£»¤Îª½¹µãµÄÍøÂçÇå¾²·¶Ê½£¬ÆäÌõ¼þÊÇÐÅÍÐÀúÀ´²»ÊÇÒþʽÊÚÓèµÄ£¬¶øÊDZØÐè¾ÙÐÐÒ»Á¬ÆÀ¹À¡£ÁãÐÅÍÐϵͳ¼Ü¹¹ÊÇÒ»Öֶ˵½¶ËµÄÆóÒµ×ÊÔ´ºÍÊý¾ÝÇå¾²ÒªÁ죬°üÀ¨Éí·Ý(È˺ͷÇÈ˵ÄʵÌå)¡¢Æ¾Ö¤¡¢»á¼ûÖÎÀí¡¢²Ù×÷¡¢¶Ëµã¡¢ËÞÖ÷ÇéÐκͻ¥Áª»ù´¡ÉèÊ©¡£ÁãÐÅÍÐÒª½â¾öµÄÒªº¦ÎÊÌâÊDZÜÃâδ¾ÊÚȨ»á¼ûÊý¾ÝºÍ·þÎñÒÔ¼°Ê¹»á¼û¿ØÖƵÄʵÑ龡¿ÉÄÜϸÄå¡£
ÁãÐÅÍмܹ¹µÄ½¹µãÂß¼×é¼þÈçÏÂͼËùʾ£º

ÈçÓûÏàʶ¸ü¶à¹ØÓÚÁãÐÅÍеÄÐÅÏ¢£¬¿ÉÒԲο¼NIST.SP.800-207¡¶ÁãÐÅÍмܹ¹¡·±ê×¼ÎÄÏס£
×÷Ϊһ¼ÒÁãÐÅÍнâ¾ö¼Æ»®ÌṩÉÌ£¬Axis SecurityÏÖÔÚµÄÖ÷´ò²úÆ·£¨Ò²ÊÇΨһ²úÆ·£©ÃûΪApplication Access Cloud£¬Ö±Òë¹ýÀ´¾ÍÊǓӦÓûá¼ûÔÆ”¡£´ÓÕâ¸öÃû×ÖËÆºõ»¹²»¿É¹»×¼È·µÃÉú²úÆ·µÄ¹¦Ð§£¬ÎÒÃÇÍŽá¹ÙÍøµÄʾÒâͼÀ´ÆÊÎöһϣº

ÉÏͼ×ó²àÃè»æµÄÊǹŰåVPNµÄʹÓó¡¾°£¬ÖÖÖÖÖÕ¶Ëͨ¹ýVPN½ÓÈëÆóÒµµÄÔÆºÍÍøÂ磻ÓÒ²àÔòÃè»æÁËÖÕ¶Ëͨ¹ýAxis Cloud½ÓÈëÆóÒµµÄÔÆºÍÍøÂç¡£
ƾ֤¹Ù·½µÄ˵·¨£¬Application Access CloudÊÇÒ»¸öÓ¦ÓòãÁãÐÅÍÐÇå¾²»á¿´·¨¾ö¼Æ»®£¬°²ÅżòÆÓ£¬¹¦Ð§Ç¿Ê¢¡£¸Ã¼Æ»®²»ÒªÇó¸Ä¶¯ÔÓеÄÓ¦ÓᢷþÎñÆ÷»òÍøÂ磬Ҳ²»ÐèÒª¸Ä¶¯Óû§²àÖÕ¶Ë»òÔÚÖն˲లÅÅagent£¬Ö»ÐèÒªÔÚ×ÊÔ´²à°²ÅÅÒ»¸öConnectorÓëAxis Cloud¼´¿É¡£¸ÃConnectorʵÖÊÉÏÊÇÒ»¸ö·´ÏòÊðÀí[5]¡£ËùÓÐÁãÐÅÍлá¼û¹¦Ð§¾ùÓÉAxis CloudºÍConnectorÍê³É£¬ÖÕ¶Ëͨ¹ýAxis Cloud»á¼ûµ½ÓªÒµ×ÊÔ´¡£ÖµµÃ×¢ÖØµÄÊÇ£¬ConnectorÊÇÈÝÆ÷»¯µÄ[5]£¬±ãÓÚÔÚDocker»òKubernetesµÈÔÆÔÉúÇéÐÎÖа²ÅÅ¡£

Öն˲àÎÞagent£¨agentless£©È·ÊµïÔÌÁËÐí¶àƶÀ§ºÍ¿ªÏú¡£ÊÂʵÉÏ£¬agentlessÊÇÏà¶Ô¶øÑԵġ£Æ¾Ö¤Ê×´´ÈËGil AzrielantµÄ˵·¨£¬agentlessÁýÕÖÁËÖ÷Á÷·þÎñ£¬ÈçWeb·þÎñ¡¢RDP·þÎñ¡¢SSH·þÎñ¡¢Git·þÎñºÍÊý¾Ý¿â·þÎñµÈ¡£ÈôÊÇÖÕ¶ËÖ»ÐèÒª»á¼ûÕâЩ·þÎñ£¬¾Í²»±Ø×°ÖÃagent¡£×°ÖÃagentÔòÔÊÐíÖÕ¶Ë»á¼ûÏÕЩÈκÎÐÎʽµÄÍøÂç·þÎñ¡£ÕâÁ½ÖÖ·½·¨£¨×°ÖÃagentÓë·ñ£©ÌṩµÄ·þÎñÊÇ»¥²¹µÄ¡£

Axis Cloud×ÔÉí°²ÅÅÔÚ°üÀ¨Google Cloud¡¢AWSµÈÔÚÄڵĶà¼Ò¹«ÓÐÔÆÉÏ£¬ÕâÖÖ°²ÅÅ·½·¨Ìá¸ßÁËÕû¸öϵͳµÄÎȹÌÐÔ£¬×èÖ¹µ¥¸öÔÆ·þÎñÉ̹ÊÕϵ¼ÖµÄÓªÒµÖÐÖ¹£¬Í¬Ê±Ò²Ìá¸ßÁ˲î±ðÇøÓòÓû§µÄ»á¼ûËÙÂÊ¡£
Application Access CloudÌṩÁË¿ØÖÆÌ¨½çÃæ£¬´Ó¸Ã½çÃæÖпÉÒÔÇåÎúµØ¿´µ½¸÷¸öÖն˶ÔÓ¦ÓõĻá¼ûÇéÐΣº

³ý´ËÖ®Í⣬»¹Äܹ»Õë¶ÔÌØ¶¨Óû§¶ÔÌØ¶¨Ó¦ÓõÄÏêϸ²Ù×÷——ÏÂÁîÐС¢ÆÁÄ»½ØÍ¼µÈ——¾ÙÐÐÉó²é£º

Application Access CloudÌṩÁËÒ×ÓÚÃ÷È·µÄÕ½ÂÔºÍÇå¾²Õ½ÂÔ½ç˵·½·¨£¬±ãÓÚÓû§×Ô½ç˵Çå¾²Õ½ÂÔ£º

4 ²úÆ·ÌØµã
×÷ΪһÖÖ»ùÓÚÔÆµÄÁãÐÅÍнâ¾ö¼Æ»®£¬Application Access CloudÄܹ»È·±£ÆóÒµÔ±¹¤´ÓÈκεط½Çå¾²»á¼û£¬²¢¾ßÓмòÆÓµÄÔÆÇ¨áãÁ÷³Ì¡£

4.1 È·±£Ô±¹¤ÄÜ´ÓÈκεط½Çå¾²»á¼û
ÎÞÂÛÔ±¹¤ÔÚÄÄ£¬Axis Application Access Cloud¶¼ÄÜÏòÆäÌṩÆóÒµÓ¦ÓúÍ×ÊÔ´µÄ»á¼û·þÎñ¡£Ô±¹¤Ö»Ð輸·ÖÖÓ¼´¿ÉÍê³ÉÉèÖ㬲»ÐèÒªÐÞ¸ÄÖն˲àµÄÍøÂç»ò×°Öÿͻ§¶ËÈí¼þ¡£ÆóÒµ¿ÉÒÔͨ¹ýÖÐÐÄ»¯µÄÔÆ¿ØÖÆÌ¨ÖÎÀíËùÓеÄÓû§¡¢Ó¦ÓúÍÕ½ÂÔ¡£ÓëÍøÂç²ãµÄ½â¾ö¼Æ»®²î±ð£¬AxisÌṩÍêÈ«µÄ¿ÉÊÓ²ìÄÜÁ¦ºÍÓ¦Óò㼶±ðµÄϸÁ£¶ÈÓû§Ô˶¯¿ØÖÆ¡£Axisͨ¹ý½«Ó¦ÓÃÓëÓû§¡¢Öն˺ͻ¥ÁªÍø¸ôÀ룬×èÖ¹Ó¦ÓÃÔâÊܹ¥»÷¡£
4.2 ¼òÆÓµÄǨáãÁ÷³Ì
ÔÚÁãÐÅÍн¨ÉèÀú³ÌÖУ¬Æóҵͨ³£ºÜÊÇÌåÌùÓªÒµÒ»Á¬ÐÔ¡£Axis Application Access CloudÌṩ¿ÉÀ©Õ¹µÄÆóÒµ¼¶·þÎñ£¬¼õÇáÆóÒµÒÑÓÐÍøÂç×ÊÔ´µÄÊÂÇé¸ºÔØ¡£Ê¹ÓÃAxisÄܹ»¼õСÖ÷Òª×ÊÔ´±»ËæÒâ»á¼ûµÄΣº¦£»¼¯Öлá¼ûÖÎÀí¼Æ»®×èÖ¹ÁËÆóÒµ»ù´¡ÉèÊ©µÄÖØÐÂÉèÖá£
5 ×ܽá
Axis SecurityÌṩµÄApplication Access Cloud½â¾ö¼Æ»®ÒÀÍÐÓÚÔÆÅÌË㣬Öն˲àʵÏÖagentless£¬Ó¦Ó÷þÎñ²àÖ»Ðè°²ÅÅconnector£¬´ó´óïÔÌÁËÆóÒµ´Ó¹Å°åVPN½ÓÈë·½·¨ÏòÁãÐÅÍÐÍøÂçǨáãµÄÊÖÒÕ×è°¡£ÕâЩÊÖÒÕתÐÍÀú³ÌÖеÄ×è°Ò²ÕýÊÇÐí¶àÆóÒµ³Ù³ÙûÓÐתÏòÁãÐÅÍеÄÖ÷ÒªÔµ¹ÊÔÓÉ¡£Axis SecurityµÄ¹Ù·½ÍøÕ¾ÉÏÌáµ½£¬Áè¼Ý54%µÄ×éÖ¯²»ÖªµÀÔõÑù×îÏÈÂ䵨ÁãÐÅÍС£Òò´Ë£¬´ÓÊÖÒսǶȶøÑÔ£¬Axis SecurityÌṩµÄ¼Æ»®½µµÍÁËÁãÐÅÍеÄÓ¦ÓÃÃż÷£¬¹ØÓÚÏëÒªÓÃÁãÐÅÍнâ¾öVPN´øÀ´µÄ±×²¡µÄÆóÒµÀ´ËµÊ®·Ö¾ßÓÐÎüÒýÁ¦¡£
È»¶ø£¬±ÊÕß×¢ÖØµ½Axis SecurityµÄÁãÐÅÍмƻ®ÓëÀÏÅÆCDN·þÎñÉÌAkamaiÐû²¼µÄEnterprise Application AccessÁãÐÅÍнâ¾ö¼Æ»®[6]Ôڼܹ¹ºÍ¹¦Ð§ÉϾßÓÐÒ»¶¨ÏàËÆ¶È¡£ÔõÑùÕÒµ½²¢È·¶¨×Ô¼ºµÄÁ¢ÒìÐÔ¼°ÊÖÒÕÉϵÄÁìÏÈÓÅÊÆ£¬¼Ì¶ø½«ÓÅÊÆ¼á³ÖÏÂÈ¥£¬¹ØÓÚAxis SecurityÕâÑùµÄÊ×´´¹«Ë¾À´ËµÊ®·ÖÖ÷Òª¡£
´ÓÁíÒ»¸ö½Ç¶ÈÀ´¿´£¬Axis SecurityÌṩµÄÊÇ»ùÓÚ¹«ÓÐÔÆÔÆÅÌËãµÄÁãÐÅÍлá¼û·þÎñ£¬ÕâÊÇ·ñ»á¸øÇ±ÔÚ¿Í»§´øÀ´ÆäËû¼Ç¹Ò£¿¹«ÓÐÔÆµÄÒýÈ룬Òâζ×ÅÆóÒµ±ØÐ轫ËùÓлá¼ûÁ÷Á¿×ªÒƵ½µÚÈý·½£¬¶ø·Ç×Ô¼º²É¹º¡¢°²ÅŵÄÁãÐÅÍÐÈíÓ²¼þ×°±¸¡£ÆóÒµ±ØÐè×ÐϸÏàʶÔÚÔÆÅÌËã“ÔðÈι²µ£Ä£×Ó”[7]ÖÐ×ÔÉí¡¢Axis SecurityºÍ¹«ÓÐÔÆ³§É̸÷×ÔµÄȨÁ¦ºÍÔðÈΣ¬³ä·ÖÆÀ¹ÀDZÔÚΣº¦¼°Î£º¦´¥·¢ºóµÄËðʧ¼°Ç󳥿ÉÄÜÐÔ¡£
³ý´ËÖ®Í⣬Axis SecurityµÄ¶àÔÆ°²ÅÅÐÎ̬¿ÉÄÜ»áʹÇéÐαäµÃÔ½·¢ÖØ´ó——¶àÔÆ°²ÅųÏÈ»Ìá¸ßÁËϵͳµÄ³°ôÐÔ£¬¿ÉÊDzî±ðµÄ¹«ÓÐÔÆ³§ÉÌÌṩµÄÇå¾²·À»¤ÄÜÁ¦¼°·À»¤Ë®Æ½¿ÉÄܲî±ð£¬ÔðÈÎÄ£×ÓÒ²»áÓÐЩÐí²î±ð¡£ÆóÒµÖ»ÐèÒªÓëAxis Security¶Ô½Ó£¿ÕÕ¾ÉÒª³ä·Ö¿¼²ìAxis SecurityÒÀÀµµÄÿһ¸ö¹«ÓÐÔÆ³§ÉÌ£¬È·±£ÆäÌṩµÄ·þÎñÖª×ã×Ô¼ºµÄÇ徲Ʒ¼¶ÐèÇó£¿
×îºó£¬Ììϸ÷¹úºÍ×éÖ¯¶¼ÔÚÏà¼Ì³ǫ̈»òÍêÉÆÊý¾ÝÇå¾²±ê×¼¼°¹æÔò£¬ÕâЩ±ê×¼¹æÔòϸÔò²»¾¡Ïàͬ£¬ÈçÅ·ÖÞͨÓÃÊý¾Ý±£»¤ÌõÀý£¨GDPR£©¡¢Öйú¡¶Êý¾ÝÇå¾²·¨£¨²Ý°¸£©¡·µÈ¡£Axis SecurityÄÜ·ñÖª×ã¸÷µØÇøµÄÊý¾ÝÇå¾²¹æÔòÒªÇó£¿ÕâÒ²ÊÇÆóÒµÐèҪ˼Á¿µÄÎÊÌâ¡£
×ܵÄÀ´¿´£¬“ÁãÐÅÍДµÄ¿´·¨ÒѾ±£´æÁËÊ®Ä꣬µ«ÕâÒ»ÊÖÒÕÀíÄîÔÚÏÖʵÖеÄÂäµØÈ´ÊÇ»ºÂýµÄ¡£Axis SecurityÒÔ¾«Á·ÓÅÑŵķ½·¨½â¾öÁËÆóÒµµÄÊÖÒÕÍ´µã£¬¾ßÓкܴóÁ¢ÒìÐԺͼÛÖµ¡£ÈôÊÇÄÜ×÷·ÏÆóÒµÔÚÆäËû·½ÃæµÄ¼Ç¹Ò£¬Ò²ÐíÄܽ«Ðí¶à¹Å°åÐÐÒµ±äΪËûÃǵĿͻ§£¬´ó´óÍÆ¶¯ÁãÐÅÍеÄÂ䵨Àú³Ì¡£

¾ÅÓÎÀϸçÔÆ







