<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>专注安管平台</title>
    <link>https://wechat2rss.xlab.app/feed/1a525e06c123c345dae49c4992df35964b8c4d53.xml</link>
    <description>专注安管平台、SIEM、SOC、SOAR、大数据安全分析、态势感知等平台类安全领域。&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (专注安管平台)</managingEditor>
    <image>
      <url>https://wx.qlogo.cn/mmhead/Q3auHgzwzM71RQ1HaxJicSGyATLsDs0ssAr30EsfZbDibWJnMib8kbpuA/0</url>
      <title>专注安管平台</title>
      <link>https://wechat2rss.xlab.app/feed/1a525e06c123c345dae49c4992df35964b8c4d53.xml</link>
    </image>
    <item>
      <title>数据就绪：AI SOC平台隐秘的死穴</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485098&amp;idx=1&amp;sn=13d77822f173455187e755ef46e05d44</link>
      <description>AI SOC的成功钥匙不在AI算法，而在数据平台的重构。</description>
      <content:encoded><![CDATA[<p>原创 <span>Benny Ye</span> <span>2026-02-06 18:08</span> <span style="display: inline-block;">北京</span></p>






  
  <p><img src="https://wechat2rss.xlab.app/img-proxy/?k=08996eb9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FYOptcHklHZIaLqXoUbhCrHy1sB11H0xHICRIFg6PYVjg2SoUq6GJ72YdLfWfyxsAic6hDN7N0oiaEG6g0ENgnDvFTNPr97WlaR1XvWbMYGCCY%2F0%3Fwx_fmt%3Djpeg"/></p>
  <p>AI SOC的成功钥匙不在AI算法，而在数据平台的重构。</p>
  <p data-layout-id="0" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">毫无疑问，我们已经进入了全新的<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485094&amp;idx=1&amp;sn=8a353a198556536e7e3018366f82c0ef&amp;scene=21#wechat_redirect" textvalue="AI SOC时代" data-itemshowtype="0" linktype="text" data-linktype="2">AI SOC时代</a>，这里的AI特指Agentic AI以及其所代表智能体（AI Agents）。智能体正迅速蔓延至网络安全的各种产品中，“几乎每个安全产品都值得用智能体去重构一次”。</span></p><h1 data-layout-id="1" style="font-size: 20px;font-weight: 500;color: rgba(43, 119, 191, 1);line-height: 1.8;margin-bottom: 12px;text-align: center;"><span leaf=""><span textstyle="" style="font-weight: bold;">回归AI SOC的技术本质</span></span></h1><p data-layout-id="2" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">笔者丝毫不怀疑AI对SOC带来的巨大革新，并对AI应用于SOC的未来充满信心，亦就此写过许多文章。但AI SOC平台终究还是SOC平台，作为支撑安全运营的平台，其技术本质并未改变，就是数据驱动。因此，当我们讨论AI SOC平台的时候，不要把所有目光都聚焦到AI上，而更应该关注数据，关注数据就绪度（Data Readiness），<span textstyle="" style="font-weight: bold;">数据和数据平台才是AI SOC平台成功的关键，是AI SOC隐秘的“死穴”</span>。</span></p><p data-layout-id="3" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">对SOC而言，如果说AI是SOC能效的倍增器（“0 / 00 / 000”，十倍/百倍/千倍），那么数据和数据平台就是决定SOC成败的那个“1”。</span></p><p data-layout-id="4" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">而从AI（尤其是智能体）视角来看，<span textstyle="" style="font-weight: bold;">数据问题将成为AI扩展的最大瓶颈，数据不再只是AI的输入，而是企业智能的基石</span>。在智能体时代，问题已不再是“是否拥有数据”，而是：现有的数据架构、治理方式和组织能力，是否足以支撑智能体的实时决策、自主行动与持续智能（参见《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzA5MTc1NzQzOQ==&amp;mid=2651799649&amp;idx=1&amp;sn=3610bdb8117c5fa6e247ea8e44de08de&amp;scene=21#wechat_redirect" textvalue="IDC FutureScape：全球数据与分析2026年预测" linktype="text" data-linktype="2">IDC FutureScape：全球数据与分析2026年预测</a>》）。</span></p><p data-layout-id="5" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">在《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzA5MTc1NzQzOQ==&amp;mid=2651799968&amp;idx=1&amp;sn=de5c2e7f95ffec768e2ae4c731a4ddbd&amp;scene=21#wechat_redirect" textvalue="IDC FutureScape：全球 Agentic AI 2026 年预测——中国启示" linktype="text" data-linktype="2">IDC FutureScape：全球 Agentic AI 2026 年预测——中国启示</a>》（2026年1月）中，IDC 系统地刻画了未来五年中国企业在智能体发展过程中将面临的十个关键转折点。 报告第一个预测就是针对数据就绪度的。</span></p><blockquote style="font-size: 15px;font-weight: 400;color: rgba(0,0,0,0.55);line-height: 1.8;margin-bottom: 24px;"><p style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">“到2027年，如果企业没有优先构建高质量的AI就绪数据，在扩展AI解决方案时将面临幻觉频发、错误率高的问题，导致生产力下降15%。”</span></p><p style="text-align: right;margin-bottom: 24px;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;"><span leaf="">——</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">IDC FutureScape：全球 Agentic AI 2026 年预测——中国启示</span></p></blockquote><p data-layout-id="7" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">业内知名SOC专家Anton Chuvakin表示，判断SOC是否AI就绪的五个支柱中，第一个就是数据，包括数据的可用性（譬如上下文是否充分）、可访问性（是否可以机读，譬如API；是否AI友好，譬如支持MCP等）、可靠性，以及数据质量，等。</span></p><p data-layout-id="7" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">笔者在去年的文章《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484854&amp;idx=1&amp;sn=81ac539adfe55fca334828b7e82002e5&amp;scene=21#wechat_redirect" textvalue="仅靠AI不足以重新定义安全运营平台" linktype="text" data-linktype="2">仅靠AI不足以重新定义安全运营平台</a>》中，就明确指出“<span textstyle="" style="color: rgba(0, 0, 0, 0.9);">GenAI本身就是建立在数据之上的，没有好的数据，GenAI也难以奏效</span>”。</span></p><h1 data-layout-id="8" style="font-size: 20px;font-weight: 500;color: rgba(43, 119, 191, 1);line-height: 1.8;margin-bottom: 12px;text-align: center;"><span leaf=""><span textstyle="" style="font-weight: bold;">为什么数据是AI SOC平台的死穴</span></span></h1><p data-layout-id="9" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">“巧妇难为无米之炊”，AI 的推理能力高度依赖于“语义事实”。再强大的AI，如果面对残缺的、甚至是错误的数据，只会诱发智能体产生严重的“幻觉”，导致AI在错误数据上“加速跑”，让运营陷入“一本正经的胡说八道”中。</span></p><p data-layout-id="10" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">正如IDC《全球 Agentic AI 2026 年预测》报告所述：“<span textstyle="" style="font-weight: bold;">数据质量不再只是IT部门的KPI，而是企业的生存红线。如果投喂给智能体的数据是脏的、乱的、没有经过治理的，那么企业得到的将不是效率提升，而是需要耗费更多人力去修正错误的负生产力</span>”。</span></p><p data-layout-id="11" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">因此，“数据就绪度”（Data Readniess）是AI SOC平台落地最隐秘的“死穴”。数据不仅是燃料，更是约束 AI 行为的边界。</span></p><h1 data-layout-id="12" style="font-size: 20px;font-weight: 500;color: rgba(43, 119, 191, 1);line-height: 1.8;margin-bottom: 12px;text-align: center;"><span leaf=""><span textstyle="" style="font-weight: bold;">数据不就绪的典型智能体“翻车现场”</span></span></h1><p data-layout-id="13" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">下面列举几个典型场景，感受一下数据不就绪造成的危害。</span></p><h2 data-layout-id="14" style="font-size: 17px;font-weight: 500;color: rgba(43, 119, 191, 1);line-height: 1.8;margin-bottom: 12px;"><span leaf=""><span textstyle="" style="font-weight: bold;">典型场景1：语义缺失</span></span></h2><p data-layout-id="15" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">在智能体进行告警研判的时候，由于缺乏实时富化的资产权重和威胁情报上下文，仅凭告警自身的信息，无法快速准确判断攻击者意图和攻击危害，导致研判失准。有的智能体虽然可以通过工具或者技能（skills）调用资产和情报数据库进行碰撞比对，但性能难以保证，且耗费大量Token。</span></p><p data-layout-id="16" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">根因分析：数据质量低，缺少富化，缺乏上下文。</span></p><h2 data-layout-id="17" style="font-size: 17px;font-weight: 500;color: rgba(43, 119, 191, 1);line-height: 1.8;margin-bottom: 12px;"><span leaf=""><span textstyle="" style="font-weight: bold;">典型场景2：格式耗散</span></span></h2><p data-layout-id="18" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">同种异构数据格式不一（如不同厂家的入侵告警描述各异），迫使智能体耗费海量Token进行格式对齐，耗散了宝贵的推理算力，增加了运营成本。</span></p><p data-layout-id="19" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">根因分析：数据质量低，数据格式不统一，缺乏统一语义。</span></p><h2 data-layout-id="20" style="font-size: 17px;font-weight: 500;color: rgba(43, 119, 191, 1);line-height: 1.8;margin-bottom: 12px;"><span leaf=""><span textstyle="" style="font-weight: bold;">典型场景3：冗余耗散</span></span></h2><p data-layout-id="21" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">将存在大量冗余、且可能明显属于误报的告警推给智能体去研判，导致其在重复的噪音中反复研判，造成算力与 Token 的巨大浪费，虚高运营成本。</span></p><p data-layout-id="22" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">根因分析：数据质量低，数据冗余。</span></p><h1 data-layout-id="23" style="font-size: 20px;font-weight: 500;color: rgba(43, 119, 191, 1);line-height: 1.8;margin-bottom: 12px;text-align: center;"><span leaf=""><span textstyle="" style="font-weight: bold;">旧架构的倒塌：为何它无法支撑“数据就绪”？</span></span></h1><p data-layout-id="24" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">通过前面的分析，我们了解到了数据就绪之于智能体发挥效用的重要性。但现在的SOC平台数据架构能担当数据就绪的重任吗？</span></p><p data-layout-id="25" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">当前大部分基于大数据的SOC平台架构都被笔者归入SOC3.0架构（参见文章《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="迈向AI赋能的SOC4.0时代" linktype="text" data-linktype="2">迈向AI赋能的SOC4.0时代</a>》2.4小节）。<span textstyle="" style="font-weight: bold;">这些架构的数据平台底座都是为“存储与检索”设计的，而非为“智能体推理”设计，无法支撑未来面向AI的数据就绪</span>。</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p data-layout-id="26" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><span textstyle="" style="font-weight: bold;">数据引力与时延</span>：数据引力（Data Gravity）引发数据分散，而SOC3.0数据架构强制进行数据的物理集中，大幅提升了数据移动和存储的成本，也可能导致分析时效性变差。</span></p></li><li><p data-layout-id="27" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><span textstyle="" style="font-weight: bold;">建模能力缺失</span>：缺乏安全数据统一建模和灵活调整模型的能力，无法根据 AI 运营需求动态定义安全实体逻辑。</span></p></li><li><p data-layout-id="28" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><span textstyle="" style="font-weight: bold;">质量治理困局</span>：缺少有效的流式清洗管道和实时质量度量，导致“数据沼泽”污染AI的推理空间。</span></p></li></ul><h1 data-layout-id="29" style="font-size: 20px;font-weight: 500;color: rgba(43, 119, 191, 1);line-height: 1.8;margin-bottom: 12px;text-align: center;"><span leaf=""><span textstyle="" style="font-weight: bold;">新架构尝试：“智能体直连”是解药吗？</span></span></h1><p data-layout-id="30" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">既然存在数据引力，数据集中存在诸多弊端，数据平台需要深度数据治理，那么，可否去掉数据平台？</span></p><p data-layout-id="31" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">最近，有不少人提出了“智能体直连数据源”的解决方案：彻底消灭旧的数据平台，用一种纯分布式的、智能编排的机制将分散的数据源连接起来。他们表示，未来的AI SOC平台将是一个纯粹的多智能体系统。</span></p><p data-layout-id="32" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">尤其是随着专项检测能力（譬如EDR、NDR等）不断增强，且其自身能够存储上下文数据和告警，自然容易让人产生这个遐想。而这种故事，其实在Agentic AI出现之前就发生过。笔者作为国内最早的一批SOAR（安全编排自动化响应）从业者，早在2020年就参与过当时兴起的“安全能力中台”、“安全能力原子化”的工作。在那个时候，我们也曾想象过通过编排技术和剧本将分散的安全能力（包括数据查询/比对）协同起来。</span></p><p data-layout-id="33" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">在笔者看来，“智能体直连”方案过于理想化，尽管有很多安全运营场景可以这么做，但最终还是需要一个数据平台。</span></p><p data-layout-id="34" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">必须指出的是，即便是“智能体直连”方案也是建立在数据基础之上的，至少与数据驱动的安全运营是吻合的。分歧在于是否需要一个专门的数据平台，以及这个数据平台长什么样（肯定不是现在这样）。</span></p><p data-layout-id="35" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><span textstyle="" style="font-weight: bold;">“智能体直连”忽视了数据就绪这个命门，无法消除数据平台的必要性。</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p data-layout-id="36" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><span textstyle="" style="font-weight: bold;">连接不等于就绪</span>：直连获得的原始数据缺乏标准化，智能体必须充当低效的“翻译官”，耗费大量Token去理解原始数据。</span></p></li><li><p data-layout-id="37" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><span textstyle="" style="font-weight: bold;">性能与信噪比</span>：若无数据平台在前置环节进行“去重降噪”，智能体将直接暴露在高EPS的冗余洪流中 。不仅算力成本不可接受，智能体分秒级的推理速度也根本无法支撑实时对抗。</span></p></li><li><p data-layout-id="38" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><span textstyle="" style="font-weight: bold;">数据集中有时更高效</span>：数据是否集中并不绝对，关键是看数据就绪，“该搬还得搬”。经典的例子就是多源数据的实时关联分析，这时集中分析所需数据是性价比最高的选择。再比如，如果让智能体直接去多个数据源中获取原始资产信息，然后自己进行复杂的合并去重与纳管，而不借助数据平台，几乎是不可能的。</span></p></li></ul><p data-layout-id="39" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">当然，在某些场景下，直连方案也有其合理性。譬如针对<span textstyle="" style="font-weight: bold;">数量较低</span>的告警和事件进行<span textstyle="" style="font-weight: bold;">深度调查</span>，或者进行对<span textstyle="" style="font-weight: bold;">时效性不高</span>的<span textstyle="" style="font-weight: bold;">威胁猎捕</span>的时候，智能体可以采用直连方式，去相关的检测系统上调取相关的上下文信息，进行推理决策。例如，在事件调查阶段，按需直连 EDR 等数据源获取特定瞬时的端点运行信息（Telemetry）是极具性价比的。</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-layout-id&#34;:&#34;39&#34;,&#34;style&#34;:&#34;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">因此，需要一种全新的数据平台架构思维去兼容这种直连方案。</span></p><p data-layout-id="39" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">【注释：需要厘清的是，很多时候，国外不少人所说的“智能体直连”AI SOC是一个基于数据平台之上的产物（更接近 AI SOAR），而非去掉数据平台。这时候的AI SOC更应该称作AI SOC Agents（<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485094&amp;idx=1&amp;sn=8a353a198556536e7e3018366f82c0ef&amp;scene=21#wechat_redirect" textvalue="参见Garnter定义" data-itemshowtype="0" linktype="text" data-linktype="2">参见Gartner定义</a>）。因为这里的AI SOC并不是完整意义上的SOC平台。】</span></p><p data-layout-id="40" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">我们需要从安全运营的业务视角去判断什么数据需要集中，什么数据不需要集中。</span></p><p data-layout-id="41" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><span textstyle="" style="background-color: rgb(255, 251, 0);color: rgba(0, 0, 0, 0.9);font-weight: bold;">我们不能用 AI 的“可能性”去对抗数据处理的“确定性”</span><span textstyle="" style="color: rgba(0, 0, 0, 0.9);">。</span>那些认为不需要数据平台、仅靠智能体就能闭环的观点，本质上是把数据治理的重担，从廉价高效的<span textstyle="" style="font-weight: bold;">代码层过度</span>转移到了昂贵缓慢的<span textstyle="" style="font-weight: bold;">AI推理层</span>。我们需要做好平衡。</span></p><p data-layout-id="42" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">AI SOC平台的命门在于：只有在“逻辑统一、语义就绪”的数据编织架构之上，智能体才能从繁琐的数据搬砖中解脱出来，成为真正的决策指挥官。</span></p><h1 data-layout-id="43" style="font-size: 20px;font-weight: 500;color: rgba(43, 119, 191, 1);line-height: 1.8;margin-bottom: 12px;text-align: center;"><span leaf=""><span textstyle="" style="font-weight: bold;">破局之道：基于“数据编织”构建新一代数据平台</span></span></h1><p data-layout-id="44" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">新一代数据平台的核心思路是从数据的“物理集中”转向“逻辑统一”，从数据的“硬连接”变为“软编织”。</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p data-layout-id="45" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><span textstyle="" style="font-weight: bold;">元数据驱动</span>：作为神经中枢，统一数据模型与治理规则。</span></p></li><li><p data-layout-id="46" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><span textstyle="" style="font-weight: bold;">智能数据管道</span>：在数据流动中实时完成标准化、富化、关联分析，实现“入库即就绪”。</span></p></li><li><p data-layout-id="47" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><span textstyle="" style="font-weight: bold;">数据虚拟化</span>：支持按需直连分散的数据源，无需搬迁即可实现逻辑融合。</span></p></li></ul><p data-layout-id="48" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">如果说旧SOC平台数据架构是构建一个传统重量级数据中台的话，那么<span textstyle="" style="font-weight: bold;">基于安全数据编织的SOC平台数据架构则旨在建立一个轻量级的数据中台</span>。</span></p><table><tbody><tr><td data-colwidth="576" style="background-color:#d6d6d6;"><p><span leaf="">笔者在《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="迈向AI赋能的SOC4.0时代" data-itemshowtype="11" linktype="text" data-linktype="2">迈向AI赋能的SOC4.0时代</a>》（5.2小节）一文中对基于“数据编织”的新一代数据平台进行了详细描述。而在《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkzMzkzMjI4OQ==&amp;mid=2247483748&amp;idx=1&amp;sn=403a04f2e7ab7b101d5b34378f1853ba&amp;scene=21#wechat_redirect" textvalue="自主化安全运营平台技术解析与实践" data-itemshowtype="0" linktype="text" data-linktype="2">自主化安全运营平台技术解析与实践</a>》一文中也介绍了笔者所在创业公司取得的实际成果。</span></p></td></tr></tbody></table><h1 data-layout-id="50" style="font-size: 20px;font-weight: 500;color: rgb(43, 119, 191);line-height: 1.8;margin-bottom: 12px;text-align: center;margin-top: 24px;"><span leaf=""><span textstyle="" style="font-weight: bold;">总结</span></span></h1><p data-layout-id="51" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">AI SOC的“死穴”在于数据，AI SOC的成功钥匙不在AI算法，而在数据平台的重构。做好数据就绪，构建逻辑统一、按需流转的新一代数据平台底座，是实现自主化安全运营的唯一路径。</span></p><p data-layout-id="52" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="">最后，引用《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzA5MTc1NzQzOQ==&amp;mid=2651799649&amp;idx=1&amp;sn=3610bdb8117c5fa6e247ea8e44de08de&amp;scene=21#wechat_redirect" textvalue="IDC FutureScape：全球数据与分析2026年预测" linktype="text" data-linktype="2">IDC FutureScape：全球数据与分析2026年预测</a>——中国启示》报告中的话结束本文。</span></p><table style="width:577px;"><tbody><tr><td data-colwidth="577" style="background-color:#d6d6d6;"><p data-pm-slice="2 2 []" style="font-size: 17px;font-weight: 400;color: rgba(0, 0, 0, 0.9);line-height: 1.8;margin-bottom: 0px;"><span leaf="">智能体</span><span leaf="">的成功，不取决于模型能力，而取决于数据是否“随时可用、始终可信、持续可控”，</span><span leaf="">只有完成数据架构、治理和访问方式的系统性重构，AI才能真正走向生产。</span></p></td></tr></tbody></table><p data-layout-id="54" style="font-size: 17px;font-weight: 400;color: rgba(0, 0, 0, 0.9);line-height: 1.8;margin-bottom: 24px;margin-top: 24px;"><span leaf="">【参考】</span></p><p data-layout-id="55" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="迈向AI赋能的SOC4.0时代" linktype="text" data-linktype="2">迈向AI赋能的SOC4.0时代</a></span></p><p data-layout-id="56" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484854&amp;idx=1&amp;sn=81ac539adfe55fca334828b7e82002e5&amp;scene=21#wechat_redirect" textvalue="仅靠AI不足以重新定义安全运营平台" linktype="text" data-linktype="2">仅靠AI不足以重新定义安全运营平台</a></span></p><p data-layout-id="57" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484842&amp;idx=1&amp;sn=38dba05e2a0024b71d81d1d9b3e74a6c&amp;scene=21#wechat_redirect" textvalue="2024年安全运营技术趋势回顾" linktype="text" data-linktype="2">2024年安全运营技术趋势回顾</a></span></p><p data-layout-id="58" style="font-size: 17px;font-weight: 400;color: rgba(0, 0, 0, 0.9);line-height: 1.8;margin-bottom: 24px;text-align: left;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkzMzkzMjI4OQ==&amp;mid=2247483748&amp;idx=1&amp;sn=403a04f2e7ab7b101d5b34378f1853ba&amp;scene=21#wechat_redirect" textvalue="自主化安全运营平台技术解析与实践" linktype="text" data-linktype="2">自主化安全运营平台技术解析与实践</a></span></p><div data-layout-id="58" style="font-size: 17px;font-weight: 400;color: rgba(0, 0, 0, 0.9);line-height: 1.8;margin-bottom: 24px;text-align: left;"><p data-layout-id="7" style="font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;data-layout-id&#34;:&#34;7&#34;,&#34;style&#34;:&#34;font-size: 17px;font-weight: 400;color: rgba(0,0,0,0.9);line-height: 1.8;margin-bottom: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">近几年崭露头角的网络安全分析公司SACR在撰写大量AI SOC分析报告的同时，也花了很多精力在支撑SOC的数据之上（重点关注数据管道），国内也一直有跟踪报道。</span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="%27%27">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=58a97efa&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyNzMxOTAwMw%3D%3D%26mid%3D2247485098%26idx%3D1%26sn%3D13d77822f173455187e755ef46e05d44">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 06 Feb 2026 18:08:00 +0800</pubDate>
    </item>
    <item>
      <title>AI SOP市场划分和AI SOC类型划分</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485094&amp;idx=1&amp;sn=8a353a198556536e7e3018366f82c0ef</link>
      <description>三种AI SOP，三类AI SOC，您选择哪一种？</description>
      <content:encoded><![CDATA[<p>
原创 <span>Benny Ye</span> <span>2025-11-18 12:10</span> <span style="display: inline-block;">北京</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=6f6ff9b6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMcMqXjdGgt7eGJPqJmS00pH9a8NStgEnpd2HrnQjJqHCRhwYPQib5cGdhD9ECBz1EB5JUc9C3HJhEA%2F0%3Fwx_fmt%3Djpeg"/></p>

<p>三种AI SOP，三类AI SOC，您选择哪一种？</p>

<p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">AI SOC、AI SOP、AI助理、SOC智能体概念厘清</span></span></p><p><span leaf="">AI SOC是一个很通泛的术语，其实很早就有了。</span></p><p><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;" data-pm-slice="3 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; margin: 0px 0px 24px; padding: 0px; outline: 0px; max-width: 100%; box-sizing: border-box !important; overflow-wrap: break-word !important; clear: both; min-height: 1em; color: rgba(0, 0, 0, 0.9); font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; font-size: 17px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: 0.544px; orphans: 2; text-align: justify; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; line-height: 1.75em;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">广义上的AI SOC泛指AI赋能的SOC，这不是一个技术术语，也不是一个产品类别（<span textstyle="" style="color: rgb(0, 82, 255);">注意：SOC不是产品</span>），而是特指一种安全运营中心。这里的AI也泛指各种AI技术，包括<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485048&amp;idx=1&amp;sn=4bceff5bb6514bacc86b69ce83b0fca1&amp;scene=21#wechat_redirect" textvalue="传统AI" data-itemshowtype="0" linktype="text" data-linktype="2">传统AI</a>和GenAI。可以说，从第一代SOC开始，AI技术就有应用，譬如</span></span></span><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">基于规则推理的关联分析</span></span><span leaf="">引擎。</span></p><p data-pm-slice="4 3 []"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;" data-pm-slice="3 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent; margin: 0px 0px 24px; padding: 0px; outline: 0px; max-width: 100%; box-sizing: border-box !important; overflow-wrap: break-word !important; clear: both; min-height: 1em; color: rgba(0, 0, 0, 0.9); font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; font-size: 17px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: 0.544px; orphans: 2; text-align: justify; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; line-height: 1.75em;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">2015</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">年，</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">Gartner</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">发表了一份</span><span textstyle="" style="font-size: 17px;font-weight: bold;">智能</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;font-weight: bold;">SOC</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">的报告，指出要利用高级安全分析来落地智能化</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">，采用机器学习（</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">ML</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">）算法识别未知威胁的异常检测技术开始盛行。此后，还出现了其它用于提升暴露评估、告警研判、态势评估与预测等关键能力的</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">和</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">ML</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">算法。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;" data-pm-slice="2 2 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;font-style: normal;">安全运营是一个过程，是一系列流程、规程和操作的集合。传统</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;font-style: normal;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;font-style: normal;">虽然解决了安全运营过程中的一些关键难题，但却不能将整个运营过程串起来，对整体运营帮助有限，还需要安全运营人员的大量工作。</span></span></span></p><p><span leaf="">最近两年，GenAI/LLM迅速兴起，已经成为了AI的代名词。</span><span leaf="">GenAI和Agentic AI具备普适性、普惠性、自主性、协作性、知识快速激活等超越传统AI的优秀特性，能够很好地提升安全运营工作过程的效能，正在重塑SOC。</span></p><p><span leaf="">随着GenAI/LLM在安全运营领域的深化应用，<span textstyle="" style="font-weight: bold;">我</span></span><span leaf=""><span textstyle="" style="font-weight: bold;">们现在经常谈及的AI SOC通常是指采用GenAI（尤其是LLM）赋能/增强的SOC</span>。而事实上，AI SOC中的AI必定是传统AI和GenAI兼备的复合式AI（</span><span leaf="">Composite AI</span><span leaf="">）。</span></p><p><span leaf="">GenAI/LLM赋能的AI SOC核心在于有一个GenAI/LLM赋能的安全运营平台（AI Security Operations Platform，简称<span textstyle="" style="font-weight: bold;">AI SOP</span>，有的也叫AI SOC平台）。因此，当下我们讨论AI SOC，核心是要讨论<span textstyle="" style="font-weight: normal;">AI SOP</span>的关键技术。</span></p><p><span leaf="">当前，Gartner定义了两个具体的AI SOP技术概念：早期的“<span textstyle="" style="font-weight: bold;">网络安全AI助理</span>”（Cybersecurity AI Assisants），以及当下最火的“<span textstyle="" style="font-weight: bold;">SOC智能体</span>”（AI SOC Agents，也可以称作“安全运营智能体”）。<span textstyle="" style="font-weight: bold;">目前，几乎所有SOP都应用了“网络安全AI助理”技术，而“SOC智能体”则迅速成为AI SOP的主要技术发展方向</span>。</span></p><blockquote><p><span leaf="">“<span textstyle="" style="font-weight: bold;">网络安全AI助理/助手/副驾</span>”借助GenAI技术，挖掘网络安全工具中的既有知识，生成相关内容或代码，为安全团队的日常工作提供辅助。</span></p></blockquote><blockquote><p><span leaf="">“<span textstyle="" style="font-weight: bold;">SOC智能体</span>”解决方案借助GenAI和智能体技术，增强安全运营中的多项日常活动。它可通过自然语言查询、减少误报、丰富告警信息、明确攻击路径背景、汇总报告、提供下一步操作建议等方式辅助调查。 </span></p></blockquote><p><span leaf="">SOC智能体在业界有时候也称作“<span textstyle="" style="font-weight: bold;">AI SOC分析师</span>”（AI SOC Analyst），显得更加拟人化、具象化，譬如DropZone.AI、</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Gurucul、</span><span leaf="">Prophet Security、Simbian、Torq等公司。</span></p><p><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">AI SOP市场细分</span></span></p><p><span leaf="">从产品角度，AI 安全运营平台（</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">AI SOP</span><span leaf="">）市场可以划分为“自带AI助理的SOP</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">”</span><span leaf="">、“SOC智能体”、“自带SOC智能体的SOP”三个细分市场/产品。</span></p><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">自带AI助理的SOP</span></span></p><p><span leaf="">目前大部分SOP（包括SIEM、XDR等）都扩充了AI助理功能，借助</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">（通用或安全专用）</span><span leaf="">LLM的基本内容生成能力，有的还进一步应用RAG技术，采用嵌入到应用后台或者专门提供聊天对话UI的方式，为安全运营人员提供基本的运营辅助，譬如撰写告警或安全事件摘要、生成查询语句、生成脚本代码、解读威胁情报、安全知识检索、提供安全操作（调查/处置等）建议，等等。</span></p><p><span leaf="">目前来看，AI助理是最基础的LLM应用，帮助安全运营人员打些“零工”，运营的主要工作还是人在干，其自主化程度（L2）还比较低。</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">随着Agentic AI和智能体技术的应用，AI助理逐渐成为AI SOC的普通能力。</span></p><p><span leaf="">尽管比较基础，但自带AI助理的SOP可以称作“AI SOP”或“AI SOC平台”。</span></p><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">SOC智能体</span></span></p><p><span leaf="">这是当前的热门产品赛道，聚集了大量（40+）的初创公司。<span textstyle="" style="font-weight: bold;">SOC智能体并不是一个完整的SOP，而是作为一款独立的产品/组件，通过叠加部署【注1】的方式，跟现有SOP对接，实现现有SOP的安全运营工作的智能化、自动化、自主化。</span>SOC智能体没有去清洗现有巨大的SOP存量市场，受到存量SOP客户的青睐。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;font-style: italic;">【</span><span textstyle="" style="font-weight: normal;font-style: italic;">注1</span><span textstyle="" style="font-style: italic;">：有关叠加部署的更多信息，可以参见《</span><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485080&amp;idx=1&amp;sn=c6c4509a6ce51a7dfbfd0e2219200751&amp;scene=21#wechat_redirect" textvalue="国外Agentic SOC平台落地实践经验" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-style: italic;">国外Agentic SOC平台落地实践经验</span></a><span textstyle="" style="font-style: italic;">》中的“</span></span><span leaf=""><span textstyle="" style="font-style: italic;">智能体的集成部署模式</span></span><span leaf=""><span textstyle="" style="font-style: italic;">”小节】</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;" data-pm-slice="0 0 []"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">当前，</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 17px;">业界经常把这类产品用“AI SOC”来指代，笔者认为是不严谨的。因为首先“AI SOC”不是产品而是系统，其次这类产品也不是完整的安全运营平台。因此，Gartner称呼为“AI SOC Agent&#34;(SOC智能体）是可以的，表示是SOC系统的智能体产品。虽然SOC智能体不是完整的SOP，但可以归属于AI SOP市场之下。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;" data-pm-slice="0 0 []"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 17px;">目前，这个细分市场十分火爆，很多第三方机构都密切追踪这个赛道，不仅Gartner对此进行了专门的定义和研究，其它如</span></span><span leaf=""><span textstyle="" style="font-size: 17px;">Software Analyst Cyber Research也对此做过深入研究，可参见《</span><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkzNjE5NjQ4Mw==&amp;mid=2247545134&amp;idx=2&amp;sn=4a4c77cee8f673090596220bafa23dc7&amp;scene=21#wechat_redirect" textvalue="万字报告｜2025 AI SOC 2025市场格局解读" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 17px;">万字报告｜2025 AI SOC 2025市场格局解读</span></a><span textstyle="" style="font-size: 17px;">》。IDC中国近期也发布了多份该领域的报告。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-size: 12pt;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">SOC智能体最主要的功能集中在给L1安全分析师提供自动告警分诊功能，减轻甚至消除L1安全分析师的工作，有的也提供HITL/HOTL（分析师审核/监督）机制。这里的分诊可不是基于LLM的文本分类【注：有的人用预训练或微调的LLM做这个，还不如用判别式AI】，而是一整个告警分诊流程，包括告警富化、告警分类分级、告警升级/安全事件提交等。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;" data-pm-slice="0 0 []"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">同时，很多SOC智能体开始面向L2/L3级别的安全分析师提供能力，譬如安全事件调查、安全事件响应、安全事件处置报告生成、威胁猎捕、团队协作辅助等。</span></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">除了面向各级分析师，SOC智能体系统还开发出了面向运营经理、安全内容工程师等不同岗位人员的智能体，譬如：</span></span></span></p><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">面向运营经理：风险评估分析智能体、安全运营绩效评估智能体，安全内容有效性评估智能体，等。</span></span></span></p></li><li><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">面向安全内容工程师：安全内容（如关联分析规则、剧本、黑白名单等）生成和优化智能体、威胁情报提取智能体，等。</span></span></span></p></li></ul><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">此外，还有面向漏洞运营、资产运营的SOC智能体系统。</span></span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">需要注意的是，目前SOC智能体系统的整体自主化程度（L3）还不是很高，人的参与还比较多，但比“AI助理”的自主化程度提升了一个等级。</span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;font-weight: bold;">自带SOC智能体的SOP</span></span></span></p><p><span leaf="">现在，部分厂商开始提供自带SOC智能体的SOP，也即笔者称呼的“Agentic SOP”（自主式安全运营平台）。</span></p><blockquote><p><span leaf=""><span textstyle="" style="font-weight: bold;">Agentic SOP</span>是指Agentic AI赋能的SOP，在SOP功能的基础上，以LLM作为思考中枢，具有自主推理、规划和决策能力，能够调用各种工具自动完成预定的安全运营任务，并通过人机协作，共同实现常态化安全运营目标。</span></p></blockquote><p><span leaf="">这些SOP的目标显然是要替代现有的SOP，他们一方面具备完整的SOP功能，另一方面又内置了SOC智能体功能。这些厂商主要包括大型综合性厂商（如Splunk、PANW、CrowdStrike）、综合性技术巨头（如微软、Google等）、创新型公司（如Exaforce、</span><span leaf="">Radiant Security等）【注2】。在《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485064&amp;idx=1&amp;sn=1c65225911fa0875d1e68ab8600a1586&amp;scene=21#wechat_redirect" textvalue="国外Agentic SOC最新进展（2025Q3）" data-itemshowtype="0" linktype="text" data-linktype="2">国外Agentic SOC最新进展（2025Q3）</a>》一文中有对前两类典型公司的最新产品进展介绍。</span></p><p><span leaf=""><span textstyle="" style="font-style: italic;">【注2：就创新型公司而言，主要还是集中在SOC智能体领域，有超过40家，而做完整的Agentic SOP的创新公司并不多，因为这既涉及到智能体技术，又涉及到下一代SOP技术架构，比较复杂】</span></span></p><p><span leaf="">值得注意的是，自带SOC智能体的SOP都具备AI助理功能，覆盖了自带AI助理的SOP，反之则不然。不过，随着SOC智能体技术路线越发清晰，仅具备AI助理功能的SOP正纷纷进军SOC智能体。</span></p><p><span leaf=""><span textstyle="" style="font-style: normal;">自带SOC智能体的SOP开启了</span><span textstyle="" style="font-weight: bold;font-style: normal;">AI原生安全运营平台</span><span textstyle="" style="font-style: normal;">之路。不过当前这些SOP的AI原生程度还较低。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 24px;font-weight: bold;">AI SOC类型划分</span></span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">对使用者（如甲方用户、安全运营服务商等）而言，AI SOC是指他们利用AI SOP搭建的一套AI安全运营体系。根据AI SOC使用的AI SOP产品不同，可以分为三种类型【注3】。</span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-style: italic;">【</span><span textstyle="" style="font-weight: normal;font-style: italic;">注3</span><span textstyle="" style="font-style: italic;">：需要指出的是，由于SOC智能体技术的迅速发展，几乎所有的AI SOC都采用了该技术，笔者认为研究仅采用AI助理技术构建的AI SOC意义不大，故不纳入分类之中】</span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">基于“自带SOC智能体的SOP”构建的AI SOC</span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">这是最清晰的一种AI SOC，采用全新的技术架构，原生的AI能力和智能体，此时AI的效果发挥最佳。但这种AI SOC对用户的整个运营体系提出了较高的挑战。因为AI SOC还涉及到组织、流程的重新适配。</span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">基于“传统SOP+SOC智能体”构建的AI SOC</span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">这种AI SOC可能更受现有SOC用户青睐，因为它总体上维持了现有的安全运营体系，叠加了一个智能自动化的运营调度层。这种AI SOC对客户的组织、流程影响更加可控，成本也更低。目前，由于国外SOC部署率已经十分高，因而大部分AI SOP产品都集中在SOC智能体这个赛道。</span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">不过，这种模式下，往往由于现有SOC的数据平台存在诸多缺陷，而制约了AI的发挥。可以<span textstyle="" style="font-style: normal;">参见笔者《</span><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485080&amp;idx=1&amp;sn=c6c4509a6ce51a7dfbfd0e2219200751&amp;scene=21#wechat_redirect" textvalue="国外Agentic SOC平台落地实践经验" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-style: normal;">国外Agentic SOC平台落地实践经验</span></a><span textstyle="" style="font-style: normal;">》文中的“</span></span><span leaf=""><span textstyle="" style="font-style: normal;">智能体的集成部署模式</span></span><span leaf=""><span textstyle="" style="font-style: normal;">”小节，了解更多。</span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">基于“传统SOP+通用智能体平台+智能体开发”构建的AI SOC</span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">这种类型的AI SOC往往见于大型的、先进的、具备AI开发能力的企业。他们通过调研，会基于现有SOP，采购（或者部署开源）一套通用智能体平台（譬如n8n、Akira、Beam、Coze、Dify等），基于该通用智能体平台自行开发安全运营所需智能体，并与现有SOP对接，实现安全运营工作的智能化、自动化、自主化。目前，这类通用智能体平台也比较多，也是一个竞争激烈的细分市场。</span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">这种模式对客户自身的开发能力和对安全运营业务理解的能力要求比较高，往往这类企业的现有SOC也是自己搭建的。还有一些安全运营服务商会采用这种模式，但他们的挑战反而不在智能体，而在于SOP整体技术架构的协调性和有效性。</span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 24px;font-weight: bold;">结尾</span></span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">在研究所有AI SOC / AI SOP的时候，还有一个很重要的设施就是LLM。目前，AI SOP跟LLM存在多种组合模式：内嵌或者外接、封闭或者开放。</span></p><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 17px;">内嵌：指LLM嵌入在AI SOP产品中，整体打包提供给客户。</span></span></p></li><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 17px;">外接：指AI SOP自身不带LLM，而是通过接口与外部独立的LLM对接。</span></span></p></li><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 17px;">封闭：是指AI SOP内嵌（或外接）的LLM系统是固定的，用户在选择AI SOP的时候无法自行选择。</span></span></p></li><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 17px;">开放：是指AI SOP外接（或内嵌）的LLM系统是开放的，支持多种第三方商业、开源或用户自有的LLM，用户可以自行选择。</span></span></p></li></ul><p style="margin-top: 24px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 17px;">目前，业界主流的趋势是AI SOP多采用外接LLM模式，并采用开放接口，支持多种LLM。</span></span></p><p><span leaf="">最后，举个实际的例子。笔者所在睿安致远（metasec.com.cn）的<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkzMzkzMjI4OQ==&amp;mid=2247483748&amp;idx=1&amp;sn=403a04f2e7ab7b101d5b34378f1853ba&amp;scene=21#wechat_redirect" textvalue="MetaSec-SOP" data-itemshowtype="0" linktype="text" data-linktype="2">MetaSec-SOP</a>是一款集成了SOC智能体技术的、采用了全新数据架构和流程架构的AI SOP，同时其SOC智能体子系统也可以作为独立组件跟用户现有SOP对接，实现现有SOP的自主化。Metasec-SOP可以外接多种LLM，用户可以自由选择。<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkzMzkzMjI4OQ==&amp;mid=2247483680&amp;idx=1&amp;sn=2cd09d78ab450c2fa40360538f5e9367&amp;scene=21#wechat_redirect" textvalue="欢迎了解" data-itemshowtype="0" linktype="text" data-linktype="2">欢迎了解</a>。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">【附录】AI SOP的自主化水平划分</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001445" data-ratio="0.5935185185185186" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=1fbd4101&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdHobWH3FZeQN3xBBddYswCNq14MkmXHJCMqMcIRdXh0qgoofLdtPVhL4yGCmqCcjNblkVfdeaVrA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;">L0表示非自主化SOP。这时，安全运营工作完全依赖人类，各种安全运营工作都采用人工操作来完成，人类分析师手工配置和操作各种安全运营工具。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;">L1表示具备初步自主性的SOP。这时，安全运营工作实现了对重复性工作的自动化，采用基于规则的专家系统（如SOAR）自动执行，流程和工作步骤都是预先定义好的，各种安全运营工具的调用也是提前编排好的。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;">L2表示引入LLM并具备了一定的自主性的SOP。这时，安全运营工作以人为主，LLM充当人类的辅助工具，安全运营工作的流程和步骤依然是预先定义好的，工具调用也依然是预先编排好的，但运营的部分流程节点调用了LLM，实现了部分工作的自主化。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;">L3表示以LLM为思考中枢的真正具备自主规划和决策的SOP（也称作SOC4.0或Agentic SOP）。这时，LLM成为了人类的伙伴而非简单工具，但人类仍需要参与到运营的各个环节（包括配置、监督、决策、优化等），安全运营工作基于LLM进行规划和决策，自主生成达成任务目标的流程和步骤，并能够自主地调用安全运营工具（包括LLM和基于传统AI的工具），但这些工具需要提前准备好。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;">L4表示高度自主化的SOP。这时，AI将自主开展大部分安全运营工作，人类更多行使监督和指导的角色，主要运营工作的流程和步骤都是自主生成、自主决策、自主优化的，并且能够自主创造新的安全运营工具并按需使用。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 16px;">图中没有绘制L5（完全自主化）级别的SOP，因为在可以预见的未来，这个级别是无法达成的，并且可能永远也无法达成。</span></span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">【参考】</span></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485080&amp;idx=1&amp;sn=c6c4509a6ce51a7dfbfd0e2219200751&amp;scene=21#wechat_redirect" textvalue="国外Agentic SOC平台落地实践经验" data-itemshowtype="0" linktype="text" data-linktype="2">国外Agentic SOC平台落地实践经验</a></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 24px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485048&amp;idx=1&amp;sn=4bceff5bb6514bacc86b69ce83b0fca1&amp;scene=21#wechat_redirect" textvalue="浅析SecOps中的AI Agent和Agentic AI，以及SOC自主化水平模型" data-itemshowtype="0" linktype="text" data-linktype="2">浅析SecOps中的AI Agent和Agentic AI，以及SOC自主化水平模型</a></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 24px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485079&amp;idx=1&amp;sn=86c2df034a23791da7b39aa42cba0fc6&amp;scene=21#wechat_redirect" textvalue="Gartner分析师谈AI Agent和Agentic AI" data-itemshowtype="0" linktype="text" data-linktype="2">Gartner分析师谈AI Agent和Agentic AI</a></span></p><p data-pm-slice="0 0 []" style="-webkit-tap-highlight-color: transparent;margin: 24px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485064&amp;idx=1&amp;sn=1c65225911fa0875d1e68ab8600a1586&amp;scene=21#wechat_redirect" textvalue="国外Agentic SOC最新进展（2025Q3）" data-itemshowtype="0" linktype="text" data-linktype="2">国外Agentic SOC最新进展（2025Q3）</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 24px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="迈向AI赋能的SOC4.0时代" data-itemshowtype="11" linktype="text" data-linktype="2">迈向AI赋能的SOC4.0时代</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 24px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485053&amp;idx=1&amp;sn=e2a7ec77a9a9e7fd7f32ed88e3549b83&amp;scene=21#wechat_redirect" textvalue="从Gartner2025年北美安全峰会看安全运营的发展趋势" data-itemshowtype="0" linktype="text" data-linktype="2">从Gartner2025年北美安全峰会看安全运营的发展趋势</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 24px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484993&amp;idx=1&amp;sn=506b9c0de108b2293d71c15750f0d95c&amp;scene=21#wechat_redirect" textvalue="从RSAC2025看安全运营技术发展趋势" data-itemshowtype="0" linktype="text" data-linktype="2">从RSAC2025看安全运营技术发展趋势</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 24px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484842&amp;idx=1&amp;sn=38dba05e2a0024b71d81d1d9b3e74a6c&amp;scene=21#wechat_redirect" textvalue="2024年安全运营技术趋势回顾" data-itemshowtype="0" linktype="text" data-linktype="2">2024年安全运营技术趋势回顾</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 24px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzkzMzkzMjI4OQ==&amp;mid=2247483748&amp;idx=1&amp;sn=403a04f2e7ab7b101d5b34378f1853ba&amp;scene=21#wechat_redirect" textvalue="自主化安全运营平台技术解析与实践" data-itemshowtype="0" linktype="text" data-linktype="2">自主化安全运营平台技术解析与实践</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247485094">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=c8334793&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyNzMxOTAwMw%3D%3D%26mid%3D2247485094%26idx%3D1%26sn%3D8a353a198556536e7e3018366f82c0ef">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 18 Nov 2025 12:10:00 +0800</pubDate>
    </item>
    <item>
      <title>Gartner：2025年SIEM（安全信息与事态管理）市场分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485087&amp;idx=1&amp;sn=ebfdc5516d2df161f0f1e745bb554691</link>
      <description>深度分析Gartner SIEM魔力象限，掌握未来SIEM/SOC平台发展趋势</description>
      <content:encoded><![CDATA[<p>
原创 <span>Benny Ye</span> <span>2025-11-11 08:01</span> <span style="display: inline-block;">北京</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=6121f35f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMemaicDV0hQPp4aL3qKS2wMfLx25P3zX29jRl71Uu50OKhJndicEibxdjruA1VEoKnoOweiaXZb9lmJhQ%2F0%3Fwx_fmt%3Djpeg"/></p>

<p>深度分析Gartner SIEM魔力象限，掌握未来SIEM/SOC平台发展趋势</p>

<p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;" data-pm-slice="0 0 []"><em style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: italic;color: rgb(2, 30, 170);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);visibility: visible;"><span leaf="">【注：本文不是译文，结合了大量笔者自己的体会和判断，请勿将此文观点等同于Gartner观点】</span></em></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;" data-pm-slice="0 0 []"><em style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: italic;color: rgb(2, 30, 170);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);visibility: visible;"><span leaf=""><span textstyle="" style="font-weight: bold;font-style: normal;">【关键摘要】</span></span></em></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;" data-pm-slice="0 0 []"><em style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: italic;color: rgb(2, 30, 170);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);visibility: visible;"><span leaf=""><span textstyle="" style="font-weight: bold;font-style: normal;">1）SIEM市场已经成熟，2024年规模达68亿美元，年增长率达17%。</span></span></em></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;" data-pm-slice="0 0 []"><em style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-style: italic;color: rgb(2, 30, 170);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);visibility: visible;"><span leaf=""><span textstyle="" style="font-weight: bold;font-style: normal;">2）SIEM市场竞争激烈，17个厂商入选2025年魔力象限，</span></span></em><em style="clear: both;min-height: 1em;font-size: 17px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: italic;color: rgb(2, 30, 170);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: italic;color: rgb(2, 30, 170);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;font-style: normal;">领导者象限两强格局已经形成</span></span></em><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-top: 24px;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="clear: both;min-height: 1em;font-size: 17px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: italic;color: rgb(2, 30, 170);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;font-style: normal;">，综合性大厂纷纷入局，多年的SIEM老牌厂商黯然退场，而纯SIEM玩家也在严峻压力中奋力拼搏，还有很多新兴技术厂商凭借突破性技术正在底下虎视眈眈。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;" data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-top: 24px;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="clear: both;min-height: 1em;font-size: 17px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: italic;color: rgb(2, 30, 170);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;font-style: normal;">3</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-top: 24px;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="clear: both;min-height: 1em;font-size: 17px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: italic;color: rgb(2, 30, 170);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;font-style: normal;">）SIEM产品</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="clear: both;min-height: 1em;font-size: 17px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: italic;color: rgb(2, 30, 170);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;font-style: normal;">更加看重细节——易用性、可定制性和扩展性、安全内容的丰富程度和围绕产品打造的生态系统。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;" data-pm-slice="0 0 []"><span leaf="" style="clear: both;min-height: 1em;font-size: 17px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: italic;color: rgb(2, 30, 170);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;font-style: normal;">4）</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="clear: both;min-height: 1em;font-size: 17px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: italic;color: rgb(2, 30, 170);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;font-style: normal;">Gartner的最终客户调查表明AI能力并非当前采购SIEM的主要考量因素。笔者认为当前AI（特指GenAI和Agentic AI，智能体等）还处于初级阶段，AI赋能的SIEM功能是特色，是未来发展方向，但还不能成为SIEM的关键成功因素。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;" data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="clear: both;min-height: 1em;font-size: 17px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: italic;color: rgb(2, 30, 170);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;font-style: normal;">5）XDR与SIEM的战争已经结束</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="clear: both;min-height: 1em;font-size: 17px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: italic;color: rgb(2, 30, 170);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;font-style: normal;">，</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="clear: both;min-height: 1em;font-size: 17px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: italic;color: rgb(2, 30, 170);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;font-style: normal;">成为SIEM和融入WSP可能是XDR的最终归宿。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;" data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="clear: both;min-height: 1em;font-size: 17px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: italic;color: rgb(2, 30, 170);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;font-style: normal;">6）SOAR已经成为SIEM的一部分，但独立SOAR还将继续存在。笔者认为国内尤其需要SOAR。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;" data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="clear: both;min-height: 1em;font-size: 17px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: italic;color: rgb(2, 30, 170);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;font-style: normal;">7）SIEM需要重新考虑数据管理问题，引入新的技术（如数据管道、数据湖等）。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;" data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="clear: both;min-height: 1em;font-size: 17px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: italic;color: rgb(2, 30, 170);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-weight: bold;font-style: normal;">8）SIEM必须是云原生的，但中国市场已经分叉。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;"><span leaf="">2025年10月8日，Gartner发布了新一期SIEM市场魔力象限（MQ）报告。该报告基于2024年至2025年2月25日期间的调研做出，不能完全反映当前最新的SIEM市场状况，但仍然具有较高的参考价值。本次报告的主笔分析师依然是Andrew Davies。</span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="background-color: rgb(255, 251, 0);font-weight: bold;">注意：严格来说，Event的中文称呼是“事态”，而Incident称作“事件”，这也是所有国标中所定义的。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;" data-pm-slice="0 0 []"><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);visibility: visible;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 20px;visibility: visible;"><span leaf=""><span textstyle="" style="font-size: 24px;">SIEM市场定义</span></span></span></strong></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;"><span leaf="">今年的定义跟去年的定义基本保持一致，但功能组成和要求有所变化，简言之，就是可涵盖功能更多了。 </span></p><blockquote><p><span leaf="">安全信息和事态管理（SIEM）是一种可配置的记录系统，能够收集、聚合并分析来自本地环境和云环境的安全事态数据，用于威胁检测、调查与响应。其原生支持数据标准化，提供用户可配置的检测内容与报告功能，以实现编排威胁缓解工作并满足合规要求。此类解决方案（通常）通过软件即服务（SaaS）平台交付，或由客户在本地环境及私有云中自行部署。</span></p></blockquote><blockquote><p><span leaf="">SIEM is a configurable system of record that collects, aggregates and analyzes security event data from on-premises and cloud environments. SIEM processes security event data for the purposes of threat detection, investigation and response.</span></p></blockquote><blockquote><p><span leaf=""> It natively supports data normalization and offers userconfigurable detection content and reporting to orchestrate threat mitigation and satisfy compliance requirements.  These solutions are delivered via a SaaS platform or clienthosted on-premises or private cloud.</span></p></blockquote><p><span leaf="">注意，从2022年开始，Gartner就认为<span textstyle="" style="font-weight: bold;">云部署和SaaS化已经成为SIEM的主要交付方式</span>，入选的产品必须支持该部署方式，这反映了Gartner对全球SIEM部署形态的客户侧观察。譬如，IBM因为将其QRadar的SIEM SaaS业务出售给了Palo Alto Neteworks（派拓网络）仅保留本地化部署SIEM业务就被Gartner排除在今年分析报告之外。但据笔者观察，</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">在中国本土市场，情况却大不相同。</span></p><p data-pm-slice="0 0 []"><span leaf="">SIEM的“根本、核心、一般”（must, mandatory, common）三种功能要求列举如下。对比最近两年的报告对功能要求的表述，可以看到<span textstyle="" style="font-weight: bold;">对SIEM的品类定义锚定到了OT数据采集、近实时分析和响应功能上，而对SIEM的其它功能要求则弱化了。</span></span></p><table style="width:571px;"><tbody><tr><td data-colwidth="87"></td><td data-colwidth="236"><p><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">2025年</span></span></p></td><td data-colwidth="248"><p><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">2024年</span></span></p></td></tr><tr><td data-colwidth="87"><p><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">根本功能</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">（划定产品品类）</span></span></p></td><td data-colwidth="236"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="font-size:14px;"><p><span leaf=""><span textstyle="" style="font-size: 14px;">聚合并标准化来自各类IT与</span><span textstyle="" style="font-size: 14px;color: rgb(255, 0, 0);font-weight: bold;">OT</span><span textstyle="" style="font-size: 14px;">环境的数据</span></span></p></li><li style="font-size:14px;"><p><span leaf=""><span textstyle="" style="font-size: 14px;">设计并执行</span><span textstyle="" style="font-size: 14px;color: rgb(255, 0, 0);font-weight: bold;">近实时</span><span textstyle="" style="font-size: 14px;font-weight: normal;">监控与告警</span><span textstyle="" style="font-size: 14px;">内容</span></span></p></li><li style="font-size:14px;"><p><span leaf=""><span textstyle="" style="font-size: 14px;color: rgb(255, 0, 0);font-weight: bold;">富化并调查</span><span textstyle="" style="font-size: 14px;">感兴趣之安全事态</span></span></p></li><li style="font-size:14px;"><p><span leaf=""><span textstyle="" style="font-size: 14px;">支持手动与自动化</span><span textstyle="" style="font-size: 14px;color: rgb(255, 0, 0);font-weight: bold;">响应</span><span textstyle="" style="font-size: 14px;">操作</span></span></p></li><li style="font-size:14px;"><p><span leaf=""><span textstyle="" style="font-size: 14px;">维护并报告当前及历史事态数据</span></span></p></li></ul></td><td data-colwidth="248"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf=""><span textstyle="" style="font-size: 14px;">能从位于本地或</span><span textstyle="" style="font-size: 14px;font-weight: bold;">云端</span><span textstyle="" style="font-size: 14px;">的各种资产中采集基础设施的详细数据和安全相关的数据</span></span></p></li><li style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf=""><span textstyle="" style="font-size: 14px;">最终用户可以通过关联的、分析的和签名的方法自助开发、修改和维护</span><span textstyle="" style="font-size: 14px;font-weight: bold;">威胁检测用例</span></span></p></li><li style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf=""><span textstyle="" style="font-size: 14px;">SIEM供应商能够向客户提供</span><span textstyle="" style="font-size: 14px;font-weight: bold;">安全内容</span><span textstyle="" style="font-size: 14px;">及相关设施以帮助客户创建安全内容</span></span></p></li><li style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf=""><span textstyle="" style="font-size: 14px;">提供</span><span textstyle="" style="font-size: 14px;font-weight: bold;">案例管理</span><span textstyle="" style="font-size: 14px;">以支撑事件响应活动</span></span></p></li><li style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf=""><span textstyle="" style="font-size: 14px;">能按照业务、</span><span textstyle="" style="font-size: 14px;font-weight: bold;">合规和审计</span><span textstyle="" style="font-size: 14px;">需求生成报告</span></span></p></li></ul></td></tr><tr><td data-colwidth="87"><p><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">核心功能</span></span></p></td><td data-colwidth="236"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 14px;">从本地和 / 或</span><span textstyle="" style="font-size: 14px;font-weight: bold;">云</span><span textstyle="" style="font-size: 14px;">基础设施中的各类资产收集基础设施详情及安全相关数据</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 14px;">提供灵活的</span><span textstyle="" style="font-size: 14px;font-weight: normal;">数据留存</span><span textstyle="" style="font-size: 14px;">选项，支持关键事件数据的</span><span textstyle="" style="font-size: 14px;font-weight: bold;">长期存储</span><span textstyle="" style="font-size: 14px;">和 / 或长期查询</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 14px;">终端用户能够自主开发、修改和维护</span><span textstyle="" style="font-size: 14px;font-weight: bold;">威胁检测用例</span><span textstyle="" style="font-size: 14px;">，支持基于关联、分析和特征码的检测方法</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 14px;">供应商提供</span><span textstyle="" style="font-size: 14px;font-weight: bold;">安全检测与响应相关内容</span><span textstyle="" style="font-size: 14px;">（分析模型、数据标准化规则、收集关联逻辑、数据丰富化工具及报告模板），同时支持原生与非原生解决方案</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 14px;">具备创建和定制</span><span textstyle="" style="font-size: 14px;font-weight: bold;">检测与响应内容</span><span textstyle="" style="font-size: 14px;">的能力</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 14px;">生成满足业务、</span><span textstyle="" style="font-size: 14px;font-weight: bold;">合规及审计</span><span textstyle="" style="font-size: 14px;">需求的报告</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 14px;">支持客户自定义</span><span textstyle="" style="font-size: 14px;font-weight: bold;">工作流增强</span><span textstyle="" style="font-size: 14px;">功能，以辅助事件响应活动与报告生成</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 14px;">能够对主动检测内容生成的安全告警进行</span><span textstyle="" style="font-size: 14px;font-weight: bold;">调查、取证和报告</span></span></p></li></ul></td><td data-colwidth="248"><ul style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;list-style-type: circle;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf=""><span textstyle="" style="font-size: 14px;">能</span><span textstyle="" style="font-size: 14px;font-weight: bold;">长期存储</span><span textstyle="" style="font-size: 14px;">基本的安全事态数据，并能够方便查询</span></span></p></li><li style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf=""><span textstyle="" style="font-size: 14px;">能够根据威胁检测用例、报告和事件调查等不同意图，通过多种方式（日志流、API、文件）</span><span textstyle="" style="font-size: 14px;background-color: rgb(255, 251, 0);font-weight: bold;">从不同的事态源收集事态数据</span></span></p></li><li style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf=""><span textstyle="" style="font-size: 14px;">具备多种</span><span textstyle="" style="font-size: 14px;font-weight: bold;">部署</span><span textstyle="" style="font-size: 14px;">选项，包括本地部署、云宿主中部署（云寄生）、云原生部署和SaaS</span></span></p></li><li style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf=""><span textstyle="" style="font-size: 14px;">能对来自</span><span textstyle="" style="font-size: 14px;background-color: rgb(255, 251, 0);font-weight: bold;">第三方</span><span textstyle="" style="font-size: 14px;">系统的数据进行范化、富化和风险评分</span></span></p></li><li style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf=""><span textstyle="" style="font-size: 14px;">对任务和</span><span textstyle="" style="font-size: 14px;font-weight: bold;">工作流</span><span textstyle="" style="font-size: 14px;">进行编排和自动化以强化调查从而遏制事件的不利影响</span></span></p></li><li style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf=""><span textstyle="" style="font-size: 14px;">具备完整的</span><span textstyle="" style="font-size: 14px;font-weight: bold;">SOAR</span><span textstyle="" style="font-size: 14px;">功能</span></span></p></li><li style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf=""><span textstyle="" style="font-size: 14px;">具备</span><span textstyle="" style="font-size: 14px;font-weight: bold;">UEBA</span><span textstyle="" style="font-size: 14px;">和基于</span><span textstyle="" style="font-size: 14px;background-color: rgb(255, 251, 0);font-weight: bold;">数据科学</span><span textstyle="" style="font-size: 14px;">（譬如有监督/无监督机器学习、深度学习、递归神经网络）的</span><span textstyle="" style="font-size: 14px;font-weight: normal;">高级分析</span><span textstyle="" style="font-size: 14px;">能力</span></span></p></li><li style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf=""><span textstyle="" style="font-size: 14px;">具备</span><span textstyle="" style="font-size: 14px;background-color: rgb(255, 251, 0);font-weight: bold;">TIP</span><span textstyle="" style="font-size: 14px;">能力，能管理情报，并为威胁信息提供上下文</span></span></p></li></ul></td></tr><tr><td data-colwidth="87"><p><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">一般功能</span></span></p></td><td data-colwidth="236"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 14px;">支持</span><span textstyle="" style="font-size: 14px;background-color: rgb(255, 251, 0);font-weight: bold;">混合数据收集</span><span textstyle="" style="font-size: 14px;">方式，包括流式事件数据与静态遥测数据（如文件处理、API 获取数据或系统配置数据）；</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 14px;">提供多种</span><span textstyle="" style="font-size: 14px;background-color: rgb(255, 251, 0);font-weight: bold;">部署</span><span textstyle="" style="font-size: 14px;">选项，包括本地部署、云托管、云原生部署或 SaaS 部署；</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 14px;">支持从</span><span textstyle="" style="font-size: 14px;background-color: rgb(255, 251, 0);font-weight: bold;">第三方系统</span><span textstyle="" style="font-size: 14px;">（如威胁情报源或配置管理数据库（CMDB））摄入标准化数据、丰富化数据及风险评分数据；</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 14px;">提供</span><span textstyle="" style="font-size: 14px;background-color: rgb(255, 251, 0);font-weight: bold;">案例管理</span><span textstyle="" style="font-size: 14px;">流程并支持事件响应操作；</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 14px;">具备</span><span textstyle="" style="font-size: 14px;background-color: rgb(255, 251, 0);font-weight: bold;">工作流增强</span><span textstyle="" style="font-size: 14px;">功能，如自动化、常见任务编排及</span><span textstyle="" style="font-size: 14px;color: rgb(255, 0, 0);font-weight: bold;">AI应用</span><span textstyle="" style="font-size: 14px;">；</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 14px;">能够运用各类</span><span textstyle="" style="font-size: 14px;background-color: rgb(255, 251, 0);font-weight: bold;">数据科学</span><span textstyle="" style="font-size: 14px;">技术，对用户、网络、应用程序或对象等可能指示攻击行为的广泛行为生成检测结果；</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 14px;">具备</span><span textstyle="" style="font-size: 14px;background-color: rgb(255, 251, 0);font-weight: bold;">TIP</span><span textstyle="" style="font-size: 14px;">功能，可管理情报源并提供威胁相关上下文信息（可能包含原生威胁情报）；</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 14px;">提供</span><span textstyle="" style="font-size: 14px;font-weight: bold;">应用市场</span><span textstyle="" style="font-size: 14px;">(marketplace)，支持客户订阅威胁内容并促进与第三方技术的整合；</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 14px;">支持跨不同供应商 SIEM 环境的</span><span textstyle="" style="font-size: 14px;font-weight: bold;">联邦搜索</span><span textstyle="" style="font-size: 14px;">，可通过集中式界面进行分析与操作；</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 14px;">具备</span><span textstyle="" style="font-size: 14px;font-weight: bold;">去中心化查询</span><span textstyle="" style="font-size: 14px;">功能，可查询供应商数据仓库以外的事件，并在适当时引入额外的丰富化信息；</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 14px;">支持与</span><span textstyle="" style="font-size: 14px;font-weight: bold;">XDR互操作</span><span textstyle="" style="font-size: 14px;">性，包括使用EDR、NDR或其他扩展遥测与响应能力；</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 14px;">支持与</span><span textstyle="" style="font-size: 14px;font-weight: bold;">第三方数据湖平台</span><span textstyle="" style="font-size: 14px;">整合，用于存储与搜索。</span></span></p></li></ul></td><td data-colwidth="248"><ul style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;list-style-type: circle;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 17px;letter-spacing: 0.034em;"><span leaf=""><span textstyle="" style="font-size: 14px;">客户可以从平台订阅威胁内容和与第三方技术集成的设施，包括各种</span><span textstyle="" style="font-size: 14px;font-weight: bold;">应用市场</span></span></span></p></li><li style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 17px;letter-spacing: 0.034em;"><span leaf=""><span textstyle="" style="font-size: 14px;">对分散环境进行</span><span textstyle="" style="font-size: 14px;font-weight: bold;">联邦搜索</span></span></span></p></li><li style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 17px;letter-spacing: 0.034em;"><span leaf=""><span textstyle="" style="font-size: 14px;">能对SIEM存储库之外的事态进行</span><span textstyle="" style="font-size: 14px;font-weight: bold;">去中心化查询</span><span textstyle="" style="font-size: 14px;">，以在必要时提取附加的富化信息</span></span></span></p></li><li style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf=""><span textstyle="" style="font-size: 14px;">具备</span><span textstyle="" style="font-size: 14px;font-weight: bold;">EDR、NDR</span><span textstyle="" style="font-size: 14px;">等附加技术组件</span></span></p></li><li style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;"><span leaf=""><span textstyle="" style="font-size: 14px;">存储能够与</span><span textstyle="" style="font-size: 14px;font-weight: bold;">数据湖平台</span><span textstyle="" style="font-size: 14px;">集成</span></span></p></li></ul></td></tr></tbody></table><p data-pm-slice="0 0 []" style="margin-top: 24px;"><span leaf="">值得注意的是，<span textstyle="" style="font-weight: bold;">Gartner并未将生成式AI和自主式AI（Agentic AI）能力列为SIEM的关键能力，而只是在一般性功能中有所提及</span>。笔者认为，一方面是因为该报告考察的时间是2024年，彼时GenAI（尤其是Agentic AI）刚刚开始炒作；另一方面则是即便时至今日GenAI和Agentic AI在SIEM乃至安全运营中的实战化应用还处于探索和试点阶段，尚未真正形成规模。<span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">Gartner的最终客户调查表明这些AI能力并非当前采购SIEM的主要考量因素</span>。</span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">厂商产品分析</span></span></p><p data-pm-slice="0 0 []"><span leaf="">今年入围的厂商有17家，比去年减少了5家。如笔者去年所言，今年派拓网络（PANW）和CrowdStrike果然上榜。而由于更多大厂参加打榜，Gartner进一步提升了业绩要求和国际化要求。</span></p><ol style="list-style-type: decimal;" class="list-paddingleft-1"><li><p data-pm-slice="0 0 []"><span leaf="">业绩要求：</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">2024年全年，要么有8500万美元产品及订阅但不含托管服务的收入，或者直签500个独立SaaS客户。</span></p></li><li><p data-pm-slice="0 0 []"><span leaf="">国际化要求：必须在全球7个大区（</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">欧、北美、</span><span leaf="">亚、非、拉美、中东、日本）中至少3个开展实质性业务。</span></p></li></ol><p data-pm-slice="0 0 []" style="margin-top: 24px;"><span leaf="">很多公司由于上述限制未能上榜或者下榜。</span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;"><span leaf="">先看今年的魔力象限：</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001434" class="rich_pages wxw-img" data-ratio="1.040586245772266" data-s="300,640" data-type="png" data-w="887" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=75998469&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMceu2ehIX5Pgme7Q5w9ou8uPwfuChPzKNIEeu801gEyEbOKNaicxicXMfrz6tKibv67DebKb90icBBQYA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-pm-slice="0 0 []" style="margin-top: 24px;"><span leaf="">对照去年的：</span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: center;"><span leaf=""><img style="width:525px;height:538px;" alt="图片" class="rich_pages wxw-img" data-ratio="1.0256410256410255" data-w="975" src="https://wechat2rss.xlab.app/img-proxy/?k=c1bb7083&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMftfrmibPvKKCsicFwusHkZ46ZfuY7HErJqtMVxhhvWBc3gh3Fua1bgUoO3ibhOcJ1s0y7rAcC97ts5A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%23imgIndex%3D0"/></span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">可以发现，领导者象限</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">两强格局已经形成</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-top: 24px;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 82, 255);">（微软和Splunk）</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">综合性大厂纷纷入局</span><span textstyle="" style="color: rgb(0, 82, 255);">（PANW、CS、DataDog）重塑市场格局，多年的SIEM</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">老牌厂商黯然退场</span><span textstyle="" style="color: rgb(0, 82, 255);">（IBM、ArcSight / MicroFocus / </span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-top: 24px;text-align: justify;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 82, 255);">OpenText、</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">LogRhythm</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">），而</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">纯SIEM玩家也在严峻压力中奋力拼搏</span><span textstyle="" style="color: rgb(0, 82, 255);">（如</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Securonix、Exabeam、Gurucul</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">），还有很多</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">新兴技术厂商</span><span textstyle="" style="color: rgb(0, 82, 255);">凭借突破性技术正在底下虎视眈眈。</span></span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">头部两强格局形成：微软和Splunk</span></span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf="">微软已经连续多年成为领导者阵营中的强中强，其聚焦纯SaaS模式，持续技术创新。微软在2025年9月份</span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []">发布了全新的基于Agentic AI赋能的</span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">Sentinel 和 Security Copilot版本。但微软成为魔力象限强中强的关键原因并非AI，而是出色的<span textstyle="" style="font-weight: bold;">易用性和灵活定制能力</span>。此外，微软紧密围绕自身生态打造SIEM的战略既是优势也是劣势。</span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;">Splunk虽然在2024年被思科收购，但似乎并未出现波动，持续保持强中强地位。Splunk成功的秘诀在于<span textstyle="" style="font-weight: bold;">强大的定制化能力，以及多年来形成的良好生态和丰富的安全内容/应用市场</span>。尽管Gartner认为Splunk近来的AI赋能战略和执行明显落后竞争对手，但尚不影响其强中强位置。笔者在《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485064&amp;idx=1&amp;sn=1c65225911fa0875d1e68ab8600a1586&amp;scene=21#wechat_redirect" textvalue="国外Agentic SOC最新进展（2025Q3）" data-itemshowtype="0" linktype="text" data-linktype="2">国外Agentic SOC最新进展（2025Q3）</a>》一文中分析过微软和Splunk在Agentic SOC方面的最新进展，二者进度差距可见一斑。</span></p><p data-pm-slice="0 0 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 20px;font-weight: bold;">综合性大厂密集入局，SIEM市场渐成“大玩家俱乐部”</span></span></p><p data-pm-slice="0 0 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">继去年Google首次上榜后，大张旗鼓进入SIEM领域的PANW和CrowdStrike（简称CS）也顺理成章进入MQ。尽管第一次未能登陆领导者象限，但仅是时间问题。譬如Google今年就已经跃居领导者象限。</span></p><p data-pm-slice="0 0 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">PANW早在2022年就高调进入SOP（安全运营平台）市场，推出融合式安全运营平台XSIAM，但在2024年的Gartner SIEM MQ入围时被判定为不符合评选技术功能要求。当时Gartner要求SIEM必须具备“混合数据收集”和“第三方数据收集”等关键功能，而XSIAM则更像是一个PANW全家桶。</span></p><p data-pm-slice="0 0 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">不过，接下来PANW强势收购了IBM的QRadar SIEM SaaS业务，并凭借其<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485053&amp;idx=1&amp;sn=e2a7ec77a9a9e7fd7f32ed88e3549b83&amp;scene=21#wechat_redirect" textvalue="“融合式平台”战略" data-itemshowtype="0" linktype="text" data-linktype="2">“融合式平台”战略</a>在安全运营领域大杀四方，业绩突飞猛进，成为SIEM领域不可忽视的一股力量。尽管Garnter并不认同XSIAM模式就是SIEM的未来，但已然成为一个流派，尤其适合中型客户。笔者在《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485053&amp;idx=1&amp;sn=e2a7ec77a9a9e7fd7f32ed88e3549b83&amp;scene=21#wechat_redirect" textvalue="从Gartner2025年北美安全峰会看安全运营的发展趋势" data-itemshowtype="0" linktype="text" data-linktype="2">从Gartner2025年北美安全峰会看安全运营的发展趋势</a>》一文中的“</span><span leaf="">最佳单品与生态（平台）之争</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">”小节对此有详细介绍。</span></p><p data-pm-slice="0 0 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">为此，Gartner也修订了今年SIEM的核心功能描述，去掉了</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">“混合数据收集”和“第三方数据收集”，转而放到“一般功能”（可选功能）要求中去了，为XSIAM的入选铺平了道路。</span></p><p data-pm-slice="0 0 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Gartner报告认为PANW XSIAM的亮点包括：整合XSOAR后带来的强大<span textstyle="" style="font-weight: bold;">自动化编排、案例管理和作战室功能</span>。另一方面，XSIAM的易用性还有待提升，且支持第三方设备的成本明显偏高。</span></p><p data-pm-slice="0 0 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">CrowdStrike也是一样的问题，其</span><span leaf="">Next-Gen SIEM俨然就是围绕其EDR为核心打造的融合型平台。Gartner认为CS的</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Next-Gen SIEM</span><span leaf=""><span textstyle="" style="font-weight: bold;">易用性强、事件管理功能强，并且产品路线图清晰、AI能力出色</span>。而问题同样在于仅在使用CS全家桶时才能获得较好价值。</span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf="">进一步分析，可以发现，包括PANW和CS在内，此次上榜的17家厂商有9家都是大型综合性厂商，占比过半。<span textstyle="" style="font-weight: bold;">SIEM主要市场正逐步被大型厂商占据</span>。笔者认为，这表明<span textstyle="" style="font-weight: bold;">SIEM市场已经趋于成熟，且市场规模和未来增量都足够大</span>。</span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">老牌SIEM厂商黯然退场，一个时代结束</span></span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf="">与一些综合性大厂大张旗鼓挺进SIEM市场相对的，是老牌SIEM厂商们纷纷下线。</span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf="">首当其冲就是<span textstyle="" style="font-weight: bold;">ArcSight终于离榜，一个时代终于结束</span>。而著名SIEM专家Anton Chuvakin则说，ArcSight时代早在2017-2018年就结束了，只是因为惯性拖到了现在而已。</span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf="">从2004年Garnter首次推出SIEM（当时叫TI安全管理）MQ开始到2024年，不论是叫ArcSight，还是HPE、MicroFocus，或者OpenText【笔者注：ArcSight从被HP收购后沾上了HP的霉运开始了颠沛流离】，<span textstyle="" style="font-weight: bold;">ArcSight每年的MQ都没有落下过，并且</span><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247483705&amp;idx=2&amp;sn=893002cafd46ae55c1f932435ac81fbb&amp;scene=21#wechat_redirect" textvalue="直到2016年" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-weight: bold;">直到2016年</span></a><span textstyle="" style="font-weight: bold;">都一直位居领导者象限</span>。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001435" class="rich_pages wxw-img" data-ratio="0.8924418604651163" data-s="300,640" data-type="png" data-w="1032" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=7834bf6c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMceea88Q3xGF497RAMtPVWw8jP8uJNlVM4lNMASZwBCNCWCY3k6MRqRU3ABWqK2z7fAaHNgW7ToicQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf="">上图是2004年的SIEM MQ，如今已经完全更迭完毕。</span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf=""><span textstyle="" style="font-weight: bold;">ArcSight堪称SIEM领域的一个传奇</span>。笔者所在团队也有幸将其引入中国。从引进，到吸收，到自研，笔者从ArcSight受益匪浅，其花费数年时间所做的调研和业务模型设计奠定了此后的辉煌，至今其《101》文档依然堪称经典。此外，ArcSight也可称得上是SIEM领域的“黄埔军校”，从Splunk研发负责人、Sumo Logic创始人，到Abstract Security、Amonali、AirMDR等创新SIEM/SecOps厂商的创始人，都打上了ArcSight的烙印。</span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf="">不过，ArcSight的现任东家OpenText还在继续SIEM产品，只是不再满足Gartner的SIEM MQ入选的功能与商业条件了。笔者估计，应该是SaaS功能的缺失，以及市场业绩不达标。ArcSight还有东山再起的机会吗？不得而知。</span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf=""><span textstyle="" style="font-weight: bold;">同样悲催的还有IBM和</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-top: 24px;text-align: justify;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">LogRhythm</span></span><span leaf="">。</span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf=""><span textstyle="" style="font-weight: bold;">IBM在2024年将自己的</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484774&amp;idx=1&amp;sn=987126678b5166e4149e90aca01e2d78&amp;scene=21#wechat_redirect" textvalue="QRadar SIEM SaaS业务卖给了PANW" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-weight: bold;">QRadar SIEM SaaS业务卖给了PANW</span></a>，仅象征性保留本地化部署的SIEM业务。可以预见，这么做就是为了让本地部署的客户有时间稳妥迁移到其它SIEM平台。现在可以说，IBM还有SIEM业务，但估计仅限于本地化部署的留存客户（还会有新增客户吗？够呛）。如此，自然也无法达到Gartner SIEM MQ的评估标准而无法继续上榜了。</span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf=""><span textstyle="" style="font-weight: bold;">IBM的SIEM业务也是一个传奇</span>。从2004年第一次SIEM MQ开始就有IBM，但那时的IBM拿出来的是Tivoli产品系列。笔者当时还安装过，仅光盘就有十几张，Tivoli的Framework就装了一天，太费劲了。<span textstyle="" style="font-weight: bold;">如果说ArcSight是一个产品不停的换牌子，那么IBM就是一块牌子不停的换产品。</span><span textstyle="" style="font-weight: normal;">IBM的SIEM业务特点是“收购”战略。</span>Tivoli不行，那就买。为了争夺SIEM的领导者地位，IBM在2006年一口气收购了两个SIEM厂商——Micromuse（GuardedNet）和Consul，同年还收购了ISS获得了其MSS运营平台。未见起色后，又在2011年买入了Q1 Labs，获得了QRadar SIEM，</span><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">并成立了专门的IBM Security部，由此将IBM SIEM带入了一个黄金时代。也是在2011年，HP收购了ArcSight，Splunk首次登陆MQ，笔者所在团队加盟了启明星辰。从2004年到2024年，IBM的霸榜时间跟ArcSight一样长。</span></span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">LogRhythm也在2024年将自己与Exabeam合并了</span>。并入Exabeam之后，其主打的SaaS SIEM业务由Exabeam </span><span leaf="">NewScale担纲，而LogRhythm 的SIEM系列产品则变身为本地化部署版本。可以预见，在欧美SIEM业务SaaS化的大势之下，LogRhythm未来不可能获得太大投入，砍掉是迟早的事儿。</span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf="">作为中生代SIEM产品的代表，LogRhythm于2007年首次登陆SIEM MQ，期间一度替代ArcSight成为领导者阵营的三强之一。</span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">纯SIEM玩家面临严峻挑战</span></span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf="">在综合性大厂的混战中，纯SIEM玩家也面临越来越大的压力。</span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf="">好基友Securonix和Exabeam逆水行舟不进则退，Gurucul虽将将踏入领导者阵营，但也压力山大。Gartner认为，Exabeam整合LogRhythm进行时，结果仍待观察；Securonix和Gurucul的客户增长速度慢于头部厂商，AI能力不足。</span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf="">前Gartner分析师</span><span leaf="">Augusto Barros表示，上述三家公司在抢占市场方面表现乏力，面对激烈竞争，他们都更多将自己的产品定位为微软和Splunk产品的补充（附加组件），以避免正面硬杠。</span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-top: 24px;text-align: justify;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">不过，笔者认为，<span textstyle="" style="color: rgb(0, 82, 255);">他们也并非没有机会，三家都都在重构其SIEM的底层数据架构，纷纷引入数据管道/编织和联邦搜索技术。</span></span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">新兴技术厂商虎视眈眈</span></span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf="">除了17家上榜的厂商，Gartner还在报告中荣誉提及了几家创新型公司（AnviLogic、Panther、Hunters），以及SentinelOne。他们虽然现在达不到报告的业绩要求门槛，但凭借创新的技术，正在悄然突破表面成熟的SIEM市场。无一例外的，他们（包括还有其它一些<span textstyle="" style="font-weight: bold;">新兴SIEM厂商）都正在用新一代数据架构（数据湖、数据编织等）重塑SIEM平台</span>。</span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">厂商小结</span></span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf="">如下表所示，笔者利用AI技术生成了一份各厂商的主要能力对比分析报告，并进行了核对和修订【<span textstyle="" style="color: rgb(0, 82, 255);">注：不能完全相信AI，需要评审</span><img style="display:inline-block;width:20px;vertical-align:middle;background-size:cover;" class="rich_pages wxw-img" data-ratio="1" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=68d02745&amp;u=https%3A%2F%2Fres.wx.qq.com%2Ft%2Fwx_fed%2Fwe-emoji%2Fres%2Fassets%2FExpression%2FExpression_14%402x.png"/><img style="display:inline-block;width:20px;vertical-align:middle;background-size:cover;" class="rich_pages wxw-img" data-ratio="1" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=68d02745&amp;u=https%3A%2F%2Fres.wx.qq.com%2Ft%2Fwx_fed%2Fwe-emoji%2Fres%2Fassets%2FExpression%2FExpression_14%402x.png"/>】。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001436" class="rich_pages wxw-img" data-ratio="3.191666666666667" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=13e31d2f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMceea88Q3xGF497RAMtPVWwIwVObwic8VgsK3Q6iaJUBpvKWtzsOibb9GHAW7Ku6d4hFbSI0cOv5QUrQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">看似平稳的SIEM市场之下，暗流涌动。</span></span></p><p data-pm-slice="0 0 []" style="margin-top: 24px;text-align: justify;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">市场和技术分析</span></span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">概述</span></span></p><p data-pm-slice="0 0 []"><span leaf="">Gartner报告指出，<span textstyle="" style="background-color: rgb(255, 251, 0);font-weight: bold;">SIEM 技术是安全运营的核心支柱</span>，已处于 “生产力成熟期”，“<span textstyle="" style="background-color: rgb(255, 251, 0);">2023-2024年，SIEM市场增长17%，规模达68亿美元</span>。SIEM 市场不仅在增长，还在不断演进：采购方选择 SIEM 的核心原因仍为执行 TDIR 操作及满足合规与报告需求，而次要选择因素正是 SIEM 的演进方向 —— 采购方寻求<span textstyle="" style="font-weight: bold;">操作更简便、数据管理更优、云环境支持更好的 SIEM 平台</span>。这些次要因素推动 SIEM 供应商创新——<span textstyle="" style="font-weight: bold;">AI 驱动的工作流程增强【笔者注：即‘Agentic SOP’】、TDIR 生态系统【笔者注：即‘融合型SOP’】解决方案、改进的数据管理选项【笔者注：即‘新一代安全数据架构’】及更完善的云环境支持</span>等功能”。</span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="background-color: rgb(255, 251, 0);">Gartner认为当今的SIEM面临两大挑战：第</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="background-color: rgb(255, 251, 0);">一个是产品使用太复杂，第二个是数据处理和存储成本高企</span>【注：国内客户似乎还没有感受到】。</span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">关于AI赋能</span></span></p><p data-pm-slice="2 3 []"><span leaf="">针对上述第一个挑战，国外厂商采取两条路径：1）采用“融合型安全运营”解决方案，其</span><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">最大特点就是将自家的SIEM、EDR、NDR、TIP、SOAR甚至ASM融合到一个平台之下，提供一体化的功能和统一的用户界面，大幅降低平台部署实施和运营的复杂度，提升运营体验。</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">笔者在《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485053&amp;idx=1&amp;sn=e2a7ec77a9a9e7fd7f32ed88e3549b83&amp;scene=21#wechat_redirect" textvalue="从Gartner2025年北美安全峰会看安全运营的发展趋势" data-itemshowtype="0" linktype="text" data-linktype="2">从Gartner2025年北美安全峰会看安全运营的发展趋势</a>》一文中有详细介绍。2）借助安全自动化和自主化（Agentic）技术，让AI增强现有的工作流程，</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">从而“</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">降低运营复杂度，引导用户获得更可预测的成果”。</span></span></p><p data-pm-slice="0 0 []"><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(0, 82, 255);">在笔者看来，两种方式需要综合使用，并且要适应中国国情，进而提出了“生态型安全运营平台”的思路和Agentic SOP</span>（<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="SOC4.0" data-itemshowtype="11" linktype="text" data-linktype="2">SOC4.0</a>）<span textstyle="" style="color: rgb(0, 82, 255);">的理念。</span></span></span></p><p><span leaf="">简言之，</span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;" data-pm-slice="0 0 []"><span textstyle="" style="font-weight: bold;">Agentic SOP是指Agentic AI赋能的SOP，在SOP功能的基础上，以</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;"><span textstyle="" style="font-weight: bold;">LLM作为思考中枢，具有自主推理、规划和决策能力，能够调用各种工具自动完成预定的安全运营任务，并通过人机协作，共同实现常态化安全运营目标</span>。</span></p><p><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">此前，笔者已经梳理过SOC从手工化到自动化再到自主化的<a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485048&amp;idx=1&amp;sn=4bceff5bb6514bacc86b69ce83b0fca1&amp;scene=21#wechat_redirect" textvalue="演进过程和Agentic SOC的自主化水平划分" data-itemshowtype="0" linktype="text" data-linktype="2">演进过程和SOC的自主化水平划分</a></span></span><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">，也详细阐述了</span></span><span leaf=""><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="Agentic SOP的五大关键技术特征" data-itemshowtype="11" linktype="text" data-linktype="2">Agentic SOP的五大关键技术特征</a></span><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">，并介绍过</span></span><span leaf=""><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485079&amp;idx=1&amp;sn=86c2df034a23791da7b39aa42cba0fc6&amp;scene=21#wechat_redirect" textvalue="Gartner对Agentic AI的释义" data-itemshowtype="0" linktype="text" data-linktype="2">Gartner对Agentic AI的释义</a></span><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">，还分析过</span></span><span leaf=""><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485064&amp;idx=1&amp;sn=1c65225911fa0875d1e68ab8600a1586&amp;scene=21#wechat_redirect" textvalue="国外主要Agentic SOC平台厂商最新的发展动态" data-itemshowtype="0" linktype="text" data-linktype="2">国外主要Agentic SOC平台厂商最新的发展动态</a>，以及<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485080&amp;idx=1&amp;sn=c6c4509a6ce51a7dfbfd0e2219200751&amp;scene=21#wechat_redirect" textvalue="国外Agentic SOC的落地经验剖析" data-itemshowtype="0" linktype="text" data-linktype="2">国外Agentic SOC的落地经验剖析</a>。简言之，<span textstyle="" style="color: rgb(0, 82, 255);">Agentic SOP的建设不是一蹴而就的，需要循序渐进，</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">当前Agentic AI和智能体赋能安全运营还处于早期和试点阶段</span>。</span></p><p><span leaf="">回到报告，Gartner将AI赋能的安全运营称作“AI增强的工作流程”。</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Gartner表示，“AI技术正逐步应用于 SIEM 中的日志收集、检测、数据丰富化与工作流增强等领域。采购方期望 SIEM 解决方案提供可靠的自然语言查询、建议的修复措施与高级趋势识别功能，实现数据上下文关联、解答特定问题，并在所有这些领域提供建议的自动化操作。”</span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Gartner进一步警告称：“</span><span leaf="">这一变革并不意味着 SOC 团队的工作量会减少或复杂度会降低。实际上，随着自动化处理简单问题并降低部分攻击类型的可行性，SOC 将能专注于应对更复杂的威胁。</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">”</span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Gartner建议采购者“</span><span leaf="">评估 AI 能力时，需将其影响与手动流程对比，并跟踪性能变化；准确性与透明度至关重要 —— 若 AI 出现故障或 SOC 对其失去信任，团队必须能在不依赖 AI 的情况下有效运营。</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">”</span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">如前所述，报告还隐含了一个细节，就是Garnter修改了SIEM功能要求，将AI能力从核心能力将为了可选的一般能力。也就是说，当前AI不是SIEM好坏的关键因素，因为</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;,&#34;style&#34;:&#34;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">Gartner的最终客户调查表明这些AI能力并非当前采购SIEM的主要考量因素</span>。笔者认为，<span textstyle="" style="background-color: rgb(255, 251, 0);font-weight: bold;">当前AI（特指GenAI和Agentic AI，智能体等）还处于初级阶段，AI赋能的SIEM功能是特色，是未来发展方向，但还不能成为SIEM的关键成功因素</span><span textstyle="" style="background-color: rgb(255, 251, 0);">。而为了迎接AI时代的到来，首先需要练好SIEM/SOC平台的架构，做好平台的数据架构和流程架构</span>。</span></p><p data-pm-slice="2 3 []"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">关于数据架构</span></span></p><p data-pm-slice="0 0 []"><span leaf="">针对上述第二个挑战，Gartner观察到厂商纷纷提供更优的数据管理功能，从数据湖到数据管道，以及更优的大规模数据摄取方案。但<span textstyle="" style="color: rgb(0, 82, 255);">笔者认为，数据架构的变革不仅是为了应对数据成本，也是为了提升数据质量，并给后续的AI应用提供AI就绪的数据</span>。</span></p><p><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">笔者认为，现有SIEM/SOC平台的数据技术架构已经完全基于大数据技术，但随着安全建设的不断深入，尤其是数据驱动的GenAI的引入，现有的安全数据技术架构再次遇到瓶颈，数据驱动正在变成垃圾驱动。新一代的SIEM/SOC平台</span></span><b style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">必须基于</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">“安全数据编织”</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">的思想，采用现代数据栈的最佳实践，摒弃旧的大数据架构，构建新一代安全数据架构</span></span></span></b><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-size: 12pt;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">。新一代安全数据架构应包括数据治理、数据编排、数据集成、数据存算、数据分析、数据呈现、数据分发</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">7</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">个构件。基于新一代安全数据架构，实现按需集成数据，简化数据管理，释放数据价值，</span></span><b style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">为安全运营平台的</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">化和自动化提供坚实的数据底座</span></span></b><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">，以实现高效的数据驱动的安全运营。</span></span></span></p><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">关于XDR</span></span></p><p data-pm-slice="0 0 []"><span leaf="">从<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484351&amp;idx=1&amp;sn=ff83fa4e2b4286a301a541ccc971c3cf&amp;scene=21#wechat_redirect" textvalue="2021年" data-itemshowtype="0" linktype="text" data-linktype="2">2021年</a>开始，有关XDR与SIEM关系的争论就一直不断，笔者在《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484634&amp;idx=1&amp;sn=4bf253ef025528fc75493ba8df4444fd&amp;scene=21#wechat_redirect" textvalue="2022年Gartner SIEM市场分析" data-itemshowtype="0" linktype="text" data-linktype="2">2022年Gartner SIEM市场分析</a>》和《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484500&amp;idx=1&amp;sn=91a3a818e697213a9b46ac7b5559944e&amp;scene=21#wechat_redirect" textvalue="SIEM的未来（2022版）" data-itemshowtype="0" linktype="text" data-linktype="2">SIEM的未来（2022版）</a>》等文章中持续分析过这个问题。</span></p><p data-pm-slice="0 0 []"><span leaf="">时至今日，<span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">XDR与SIEM的争论可以结束了。XDR无法取代SIEM，XDR自身面临终结</span>。摆在XDR面前有四条路：1）继续做好中低位能力，为SIEM或其它高位平台供数；2）升级为SIEM，成为SIEM的一个用例，因为SIEM才是SecOps的核心支柱（好吧，也许XDR们会说他们以另一种方式替代了SIEM <img style="display:inline-block;width:20px;vertical-align:middle;background-size:cover;" class="rich_pages wxw-img" data-ratio="1" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=68d02745&amp;u=https%3A%2F%2Fres.wx.qq.com%2Ft%2Fwx_fed%2Fwe-emoji%2Fres%2Fassets%2FExpression%2FExpression_14%402x.png"/>）；3）回归EDR的初心，成为一个更强大的EDR，最终还是给SIEM供数；4）成为工作空间安全平台（Workspace Security Platform）的一部分，去打造新的应用场景。Gartner表示，<span textstyle="" style="background-color: rgb(255, 251, 0);color: rgb(0, 0, 0);font-weight: bold;">成为SIEM和融入WSP可能是XDR的最终归宿</span><span textstyle="" style="background-color: rgb(255, 251, 0);color: rgb(0, 0, 0);">。</span></span></p><blockquote><p><span leaf="">Gartner将工作空间安全平台（WSP）定义为一款旨在识别和阻止针对数字员工终端、身份、应用和数据的威胁的产品。其功能包括攻击面缩减、行为分析、威胁防护和数据防泄漏。工作空间安全平台还支持受保护终端和认证基础设施的威胁检测、调查与响应（TDIR）。该平台基于云原生服务架构构建，提供统一终端代理和集中化安全管理，支持工作空间安全平台设置与策略配置、报告和事件响应的全生命周期管理。</span></p></blockquote><p data-pm-slice="0 0 []"><span leaf="">事实上，PANW为了进入安全运营平台市场推出了XSIAM，而不是用它的XDR产品，而EDR/XDR厂商SentinelOne也推出了SIEM产品，再比如CrowdStrike也把XDR放一边而推出了专门SIEM产品。这表明，XDR不是SIEM，取代不了SIEM，安全运营的核心支柱还是SIEM（或者说是安全运营平台SOP）。在《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484500&amp;idx=1&amp;sn=91a3a818e697213a9b46ac7b5559944e&amp;scene=21#wechat_redirect" textvalue="SIEM的未来" data-itemshowtype="0" linktype="text" data-linktype="2">SIEM的未来</a>》（2022版）一文中，笔者画过一幅SIEM厂商纷纷推出XDR的图画。如今，包括Exabeam，Securonix，Sumo Logic，Rapid7等在内的公司已经不再提XDR了。</span></p><p data-pm-slice="0 0 []"><span leaf="">回到MQ本身，Gartner修改SIEM功能要求，显然是为了将升级版XDR纳入到SIEM体系之下，犹如将PANW和</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">CrowdStrike</span><span leaf="">纳入MQ。而PANW和</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">CrowdStrike</span><span leaf="">也通过大张旗鼓的发布融合型SIEM产品，以跟其原来的XDR产品进行切割。简言之，<span textstyle="" style="font-weight: bold;">在SecOps领域，SIEM吃掉了XDR</span>。</span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">关于SOAR</span></span></p><p data-pm-slice="0 0 []"><span leaf="">2024年Garnter Hype Cycle报告将SOAR标记为“过时”，引发轩然大波。笔者当时在《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484818&amp;idx=1&amp;sn=1966e121ac2e4f4dacda712854534d0c&amp;scene=21#wechat_redirect" textvalue="SOAR的未来" data-itemshowtype="0" linktype="text" data-linktype="2">SOAR的未来</a>》一文中进行了详细探讨。对于“SOAR成为SIEM的一部分”这个结论毋庸置疑，但“独立SIEM就此消亡”却不见得。当前，独立的SOAR产品甚至厂商依然存在，一些AI SOC / Agentic SOC厂做的其实就是下一代SOAR，而Gartner最新发布的“AI SOC Agents”（SOC智能体）也可以看作是SOAR的一个升级，因为从Agentic AI的自主化程度谱系来看，<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485048&amp;idx=1&amp;sn=4bceff5bb6514bacc86b69ce83b0fca1&amp;scene=21#wechat_redirect" textvalue="SOAR是一种初级的智能体" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="background-color: rgb(255, 251, 0);">SOAR是一种初级的智能体</span></a>。</span></p><p data-pm-slice="0 0 []"><span leaf="">有趣的是，可能是“独立SOAR消亡”的争议太大，在2025年的Gartner</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"> Hype Cycle报告中，再次出现了SOAR。尽管依然被标记为“过时”，但还是对SOAR技术进行了专门的阐述，供读者参考。正常情况下，一种技术在某年“过时”后，就不会出现在次年的Hype Cycle中了（没有意义啊）。Gartner如此操作，说明还有必要给大家介绍一下SOAR<img style="display:inline-block;width:20px;vertical-align:middle;background-size:cover;" class="rich_pages wxw-img" data-ratio="1" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=f0062110&amp;u=https%3A%2F%2Fres.wx.qq.com%2Ft%2Fwx_fed%2Fwe-emoji%2Fres%2Fassets%2FExpression%2FExpression_21%402x.png"/>，里面还列举了多个独立SOAR厂商/产品（包括Splunk SOAR和PANW的XSOAR，以及一些Agentic SOAR公司）。<span textstyle="" style="color: rgb(0, 82, 255);">笔者可否这样理解：SOAR过时需要一段较长的时间</span>。</span></p><p data-pm-slice="0 0 []"><span leaf="">此外，笔者认为，对于中国市场而言，用户将存量SIEM/SOP全部升级到内置SOAR功能的下一代版本还有较长的一个时期，<span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">独立（或者模块化的）SOAR在中国依然大有可为</span>。</span></p><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">关于云原生</span></span></p><p><span leaf="">在欧美，“SIEM是云原生的”已经成为共识。一方面是他们的IT基础设施大都上云了，应用也都云原生了；其次，云技术可以较好地解决分布式计算和大规模数据存储的问题。</span></p><blockquote><p><span leaf="">Gartner 将 “云原生” 定义为 “为利用云特性而设计的技术”。这些云特性属于云计算的原始定义范畴，核心是服务化交付能力，具备可扩展性、弹性、按使用计量、服务化、基于互联网技术的泛在访问及共享特性。</span></p></blockquote><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">深入分析，欧美用户认为“把数据存到云上”比存放到本地更安全。而国内却不是这样看的。这不仅是技术问题，也是体制问题。从这里开始，国内外的应用发展出现了分叉。诚然国内肯定还是存在SaaS SIEM（如阿里云的Agentic SOC）市场，但更多的还是本地部署的SIEM/SOC平台，此外就是专有云环境中的SIEM/SOC平台（这个类别很可能最终还是会分解到SaaS和本地两种技术架构中去）。</span></p><p><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">总结</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;"><span leaf="">纵览Gartner SIEM MQ及相关报告，可以发现，SIEM整体而言属于成熟市场，更加看重细节——易用性、可定制性和扩展性、安全内容的丰富程度和围绕产品打造的生态系统。但SIEM的背面也暗潮涌动，新的技术和业务模式正在悄然兴起，成为搅动市场的关键力量。</span></p><p><span leaf="">我们不能被动等待，要主动求变，迎接AI时代的到来。</span></p><p><span leaf="">笔者目前也在这个大潮中拼搏，无论技术还是商务领域，都<a class="normal_text_link" target="_blank" style="color: rgb(255, 0, 0);" href="https://mp.weixin.qq.com/s?__biz=MzkzMzkzMjI4OQ==&amp;mid=2247483680&amp;idx=1&amp;sn=2cd09d78ab450c2fa40360538f5e9367&amp;scene=21#wechat_redirect" textvalue="欢迎与我们联系" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="background-color: rgb(255, 251, 0);color: rgb(255, 0, 0);">欢迎与我们联系</span></a>。</span></p><p style="-webkit-tap-highlight-color: transparent;margin: 24px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="">【参考】</span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484777&amp;idx=1&amp;sn=dd216426fc6cf09be507e2d8d83b3695&amp;scene=21#wechat_redirect" textvalue="Gartner：2024年SIEM（安全信息与事件管理）市场分析" data-itemshowtype="0" linktype="text" data-linktype="2">Gartner：2024年SIEM（安全信息与事件管理）市场分析</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484530&amp;idx=1&amp;sn=af1537ab8fe4503a0b10fb133d507096&amp;chksm=fa002ec6cd77a7d01239618b95446d54a2fd0b83c1e6b16c22a1bbb2718df271fc94a6fb3abe&amp;scene=21#wechat_redirect" textvalue="Gartner：2022年SIEM（安全信息与事件管理）市场分析" data-itemshowtype="0" linktype="text" data-linktype="2">Gartner：2022年SIEM（安全信息与事件管理）市场分析</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);text-align: left;line-height: 1.6em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf=""><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484351&amp;idx=1&amp;sn=ff83fa4e2b4286a301a541ccc971c3cf&amp;chksm=fa00290bcd77a01d7b917fd6c9041ef12b5f2300916212d0dd74fe836c78bcffc1887ed11520&amp;scene=21#wechat_redirect" textvalue="Gartner：2021年SIEM（安全信息与事件管理）市场分析" data-itemshowtype="0" linktype="text" data-linktype="2">Gartner：2021年SIEM（安全信息与事件管理）市场分析</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);line-height: 1.6em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf=""><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484022&amp;idx=1&amp;sn=e39ec5ac122c698f201e94df81d6d7f3&amp;chksm=fa0028c2cd77a1d442b08e857f98863b9be1894f56ef98615d4d588cbdb90e5ae3270fc4eb78&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">Gartner：2019年SIEM（安全信息与事件管理）市场分析</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);line-height: 1.6em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf=""><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247483705&amp;idx=1&amp;sn=575fd73452bccf2dbfd4612f93aabf1c&amp;chksm=fa002b8dcd77a29bdabd04ba1e2819b3cf710bd98412c45e6b036433b24b3605bfbc1060843e&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">Gartner：2018年SIEM（安全信息与事件管理）市场分析</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);line-height: 1.6em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf=""><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247483705&amp;idx=2&amp;sn=893002cafd46ae55c1f932435ac81fbb&amp;chksm=fa002b8dcd77a29bdef3b56239692999329f32a80eb6ad6ab98ad901e7e1b54460297293c211&amp;scene=21#wechat_redirect" textvalue="" data-itemshowtype="0" linktype="text" data-linktype="2">Gartner：2017年SIEM（安全信息与事件管理）市场分析</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="迈向AI赋能的SOC4.0时代" data-itemshowtype="11" linktype="text" data-linktype="2">迈向AI赋能的SOC4.0时代</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485053&amp;idx=1&amp;sn=e2a7ec77a9a9e7fd7f32ed88e3549b83&amp;scene=21#wechat_redirect" textvalue="从Gartner2025年北美安全峰会看安全运营的发展趋势" data-itemshowtype="0" linktype="text" data-linktype="2">从Gartner2025年北美安全峰会看安全运营的发展趋势</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484993&amp;idx=1&amp;sn=506b9c0de108b2293d71c15750f0d95c&amp;scene=21#wechat_redirect" textvalue="从RSAC2025看安全运营技术发展趋势" data-itemshowtype="0" linktype="text" data-linktype="2">从RSAC2025看安全运营技术发展趋势</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484842&amp;idx=1&amp;sn=38dba05e2a0024b71d81d1d9b3e74a6c&amp;scene=21#wechat_redirect" textvalue="2024年安全运营技术趋势回顾" data-itemshowtype="0" linktype="text" data-linktype="2">2024年安全运营技术趋势回顾</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484795&amp;idx=1&amp;sn=8f835c0699be66f615e7b713f67e26dc&amp;scene=21#wechat_redirect" textvalue="从Gartner2024年北美安全峰会看安全运营的技术趋势" data-itemshowtype="0" linktype="text" data-linktype="2">从Gartner2024年北美安全峰会看安全运营的技术趋势</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin-right: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484766&amp;idx=1&amp;sn=5b66715c108908d39eb92ecdc964c9f6&amp;chksm=fa002feacd77a6fcdc78bff2275afb83ea403c19d547584bd02669f68550e26c5d27b7303c8b&amp;scene=21#wechat_redirect" textvalue="从RSAC2024看SOC发展趋势" data-itemshowtype="0" linktype="text" data-linktype="2">从RSAC2024看SOC发展趋势</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);"><span leaf=""><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484730&amp;idx=1&amp;sn=a4dfcb4c250f3128b59cab19c6a393f2&amp;chksm=fa002f8ecd77a698a4d47c17f463eaa132656a7fdfecef6f280c698759af43704b1210b1ae1e&amp;scene=21#wechat_redirect" textvalue="再见！爱因斯坦计划，网安态势感知迎来转型" data-itemshowtype="0" linktype="text" data-linktype="2">再见！爱因斯坦计划，网安态势感知迎来转型</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);"><span leaf=""><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484657&amp;idx=1&amp;sn=97ef202f80d16243bc1212bedf759458&amp;chksm=fa002e45cd77a75364e60ca7227c60618c930f3f54eb514f850630b26bd60fa359e9ee03894d&amp;scene=21#wechat_redirect" textvalue="从Garnter2023年北美安全与风险管理峰会看SIEM和SOC的发展趋势" data-itemshowtype="0" linktype="text" data-linktype="2">从Gartner2023年北美安全与风险管理峰会看SIEM和SOC的发展趋势</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);"><span leaf=""><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484640&amp;idx=1&amp;sn=6ff1f407b3ad35c01efbf35d5a0ded0d&amp;chksm=fa002e54cd77a7425235ca39c42acb32187bd913d3b3ab9ec75c9d2c504fab0f49d75efada57&amp;scene=21#wechat_redirect" textvalue="从RSAC2023看安全运营的技术发展趋势" data-itemshowtype="0" linktype="text" data-linktype="2">从RSAC2023看安全运营的技术发展趋势</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);"><span leaf=""><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: pointer;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484634&amp;idx=1&amp;sn=4bf253ef025528fc75493ba8df4444fd&amp;chksm=fa002e6ecd77a77823156257953359d03278eb1ac2543c0fbd244181f918a81206869ff90b83&amp;scene=21#wechat_redirect" textvalue="从Gartner2022年魔力象限看SIEM未来发展" data-itemshowtype="0" linktype="text" data-linktype="2">从Gartner2022年魔力象限看SIEM未来发展</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 8px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;background-color: rgb(255, 255, 255);"><span leaf=""><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: pointer;max-width: 100%;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);box-sizing: border-box !important;overflow-wrap: break-word !important;" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484500&amp;idx=1&amp;sn=91a3a818e697213a9b46ac7b5559944e&amp;chksm=fa002ee0cd77a7f6503c923d308c43d53b0cdd2e6725326b24fd49915c33e9f3b1ba9a42af05&amp;scene=21#wechat_redirect" textvalue="SIEM的未来" data-itemshowtype="0" linktype="text" data-linktype="2">SIEM的未来</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247485087">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=71afc526&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyNzMxOTAwMw%3D%3D%26mid%3D2247485087%26idx%3D1%26sn%3Debfdc5516d2df161f0f1e745bb554691">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 11 Nov 2025 08:01:00 +0800</pubDate>
    </item>
    <item>
      <title>国外Agentic SOC平台落地实践经验</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485080&amp;idx=1&amp;sn=c6c4509a6ce51a7dfbfd0e2219200751</link>
      <description>探讨自主式SOC平台的优势、局限、部署模式、治理变革、风险、价值评估。</description>
      <content:encoded><![CDATA[<p>
原创 <span>Benny Ye</span> <span>2025-11-06 12:02</span> <span style="display: inline-block;">北京</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=994236ec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMfvsj8NibPia0GaGjmlHJMlr3no7Kb0gIIkGDahic64HicXOakyXGd6keAaaGo8SgFZhcdEiacsqNV5ZWA%2F0%3Fwx_fmt%3Djpeg"/></p>

<p>探讨自主式SOC平台的优势、局限、部署模式、治理变革、风险、价值评估。</p>

<p><span leaf=""><span textstyle="" style="font-style: italic;">【引言】就在2025年10月28日，新修订的《网络安全法》颁布。新增的第20条明确指出“</span><span textstyle="" style="font-weight: bold;font-style: italic;">国家支持创新网络安全管理方式，运用人工智能等新技术，提升网络安全保护水平</span><span textstyle="" style="font-style: italic;">”。以Agentic AI为代表的最新型AI赋能安全运营，顺应了《网络安全法》的要求。</span></span></p><p><span leaf="">当前，Agentic AI赋能的Agentic SOC（自主式SOC）平台（即Agentic SOP）正发展得如火如荼，不断攀上炒作的高峰。<span textstyle="" style="font-weight: bold;">Agentic SOC平台以</span></span><span leaf=""><span textstyle="" style="font-weight: bold;">LLM作为思考中枢，具有自主推理、规划和决策能力，能够调用各种工具自动完成预定的安全运营任务，并通过人机协作，共同实现常态化安全运营目标</span>。</span></p><p><span leaf="">此前，笔者已经梳理过SOC从手工化到自动化再到自主化的<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485048&amp;idx=1&amp;sn=4bceff5bb6514bacc86b69ce83b0fca1&amp;scene=21#wechat_redirect" textvalue="演进过程和Agentic SOC的自主化水平划分" data-itemshowtype="0" linktype="text" data-linktype="2">演进过程和SOC的自主化水平划分</a>，也详细阐述了<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="Agentic SOP的五大关键技术特征" data-itemshowtype="11" linktype="text" data-linktype="2">Agentic SOP的五大关键技术特征</a>，并介绍过<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485079&amp;idx=1&amp;sn=86c2df034a23791da7b39aa42cba0fc6&amp;scene=21#wechat_redirect" textvalue="Gartner对Agentic AI的释义" data-itemshowtype="0" linktype="text" data-linktype="2">Gartner对Agentic AI的释义</a>，还分析过<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485064&amp;idx=1&amp;sn=1c65225911fa0875d1e68ab8600a1586&amp;scene=21#wechat_redirect" textvalue="国外主要Agentic SOC平台厂商最新的发展动态" data-itemshowtype="0" linktype="text" data-linktype="2">国外主要Agentic SOC平台厂商最新的发展动态</a>。</span></p><p><span leaf="">本文将分享一篇发表于CSO在线网站的讨论Agentic SOC平台落地实践的文章【注1】。通过对正在试点和部署Agentic AI赋能的安全运营项目，或为相关项目提供咨询的安全高管、产品负责人和研究人员进行调研访谈，让我我们更清晰的认识Agentic SOC的现状。<span textstyle="" style="color: rgb(0, 82, 255);">同时，本文也包括笔者对该访谈信息的评论</span>。</span></p><p><span leaf="">访谈内容涉及6个议题。</span></p><p><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">自主式 AI 的优势与局限</span></span></p><table style="width:576px;"><tbody><tr><td data-colwidth="576" style="background-color:#d6d6d6;"><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-weight: bold;">优势</span></span></p></td></tr><tr><td data-colwidth="576"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">与仅标记待审查行为的传统工具不同，基于智能体的系统 “能够</span><span textstyle="" style="font-size: 14px;font-weight: bold;">处理L1任务</span><span textstyle="" style="font-size: 14px;">，例如警报分类、跨工具关联信号，在部分场景下甚至能采取威胁遏制措施（如隔离终端），让分析师专注于更具战略性的重要工作”。</span></span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">自主式 AI 的核心价值在于将人类分析师</span><span textstyle="" style="font-size: 14px;font-weight: bold;">从“重复性苦差” 中解放出来，让他们专注于更高层次的探索与威胁狩猎工作</span><span textstyle="" style="font-size: 14px;">。</span></span></p><p data-pm-slice="0 0 []" style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——FifthElement 首席执行官兼企业 AI 战略师 Jonathan Garini</span></span></p></td></tr><tr><td data-colwidth="576"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">在安全运营中心环境中，AI 智能体的运作 “酷似数字L1分析师 —— 筛选数据、收集情境信息，甚至能生成关于自身活动的详细报告”。他还提到了 AI 智能体在恶意软件检测、脚本反混淆、工具协同等场景的实际应用。</span></span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">引入智能体的团队还能实现 “更快的响应速度、更精简的团队架构，以及在海量警报处理中的更强韧性”。</span></span></p><p data-pm-slice="0 0 []" style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——美国银行数据驱动解决方案与应用 AI 专家 Vinod Goje</span></span></p></td></tr><tr><td data-colwidth="576"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">自主式 AI 擅长 “</span><span textstyle="" style="font-size: 14px;font-weight: bold;">应对‘最初 15 分钟’的紧急场景 </span><span textstyle="" style="font-size: 14px;">—— 获取情境信息、核查威胁情报、汇总日志、提出待审核行动建议”。此外，它还能通过优先级排序助力漏洞暴露管理，并处理诸如识别失效账户等基础安全维护任务。</span></span></p><p style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——OPSWAT 公司产品副总裁 Itay Glick</span></span></p></td></tr><tr><td data-colwidth="576"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">AI 智能体通过聚合警报模式，并将其与威胁情报源关联，</span><span textstyle="" style="font-size: 14px;font-weight: bold;">有效缓解了 “警报疲劳”</span><span textstyle="" style="font-size: 14px;">；同时，基于自然语言处理（NLP）的工具能够实现</span><span textstyle="" style="font-size: 14px;font-weight: bold;">大规模警报汇总</span><span textstyle="" style="font-size: 14px;">。</span></span></p><p style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——Black Duck 首席产品与技术官 Dipto Chakravarty</span></span></p></td></tr></tbody></table><table style="width:577px;"><tfoot><tr><td data-colwidth="577" style="background-color:#d6d6d6;"><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-weight: bold;">局限</span></span></p></td></tr><tr><td data-colwidth="577"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">若缺乏清洁数据或清晰的剧本（工作流），智能体可能会</span><span textstyle="" style="font-size: 14px;font-weight: bold;">陷入无效信息干扰，甚至自主 “创造” 流程步骤</span></span></p><p style="text-align: right;"><span leaf="" data-pm-slice="1 1 [&#34;table&#34;,{&#34;interlaced&#34;:null,&#34;align&#34;:null,&#34;class&#34;:null,&#34;style&#34;:null},&#34;table_body&#34;,{},&#34;table_row&#34;,{&#34;class&#34;:null,&#34;style&#34;:null},&#34;table_cell&#34;,{&#34;colspan&#34;:1,&#34;rowspan&#34;:1,&#34;colwidth&#34;:[287],&#34;width&#34;:null,&#34;valign&#34;:null,&#34;align&#34;:null,&#34;style&#34;:null},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: right;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]"><span textstyle="" style="font-size: 14px;">——OPSWAT 公司产品副总裁 Itay Glick</span></span></p></td></tr><tr><td data-colwidth="577"><p><span leaf=""><span textstyle="" style="font-size: 14px;">Agentic AI存在</span><span textstyle="" style="font-size: 14px;font-weight: bold;">误报与过拟合问题</span><span textstyle="" style="font-size: 14px;">。</span></span></p><p style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——Black Duck 首席产品与技术官 Dipto Chakravarty</span></span></p></td></tr><tr><td data-colwidth="577"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">即便训练最充分的智能体，也可能</span><span textstyle="" style="font-size: 14px;font-weight: bold;">被模糊信号或多层级情境难住</span><span textstyle="" style="font-size: 14px;">。</span></span></p><p style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——Mphasis 公司高级副总裁兼全球网络安全服务主管 Prashant Jagwani</span></span></p></td></tr></tfoot></table><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">通过专家的表述，可以发现，尽管Agentic AI有N个优势，但在当前的具体实践上，主要还是针对L1分析师的告警研判过程有显著的效果。当前的实战应用程度表明，</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">大多数企业仍将Agentic AI作为人类分析师的辅助工具，而非替代品。</span></span></p><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">正如Gartner所言，</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">生成式AI在安全运营中的价值依然严重依赖SOC分析师的先验技能水平</span><span textstyle="" style="color: rgb(0, 82, 255);">。要么，在预训练和微调的时候，该LLM灌输大量的高质量先验安全运营知识，得到所谓的安全垂域模型（Gartner将此类模型称作DSLM），并应用于Agentic AI；要么，在使用LLM思考的时候给智能体丰富的先验安全运营知识，并结合上下文工程让LLM思考得更加像一名老练的分析师。</span></span></p><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">与此同时，当前Agentic AI还存在诸多局限，但也正在快速发展演进。Gartner警告，</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">到 2027 年，30% 的 SOC 领导者将因输出不准确和幻觉而无法将生成式AI整合到生产流程中</span><span textstyle="" style="color: rgb(0, 82, 255);">。</span></span></p><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">智能体的集成部署模式：附加式VS独立式（叠加型VS替代型）</span></span></p><ul class="list-paddingleft-1"><li style="text-align:left;"><p><strong><span leaf="">附加模式</span></strong><span leaf="">：将智能体视为SOP、SIEM、SOAR或其他安全工具的扩展，能以最小干扰实现快速见效。</span></p></li><li style="text-align:left;"><p style="margin-bottom: 24px;"><strong><span leaf="">独立模式</span></strong><span leaf="">：此时智能体位于一个独立的编排层，虽具备更高灵活性，但需更严格的治理、更复杂的集成工作与更全面的变革管理。</span></p></li></ul><table style="width:574px;"><tbody><tr><td data-colwidth="574"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">直接构建在 SIEM 或 SOAR 平台之上的现成</span><span textstyle="" style="font-size: 14px;font-weight: bold;">附加模式通常效果最佳</span><span textstyle="" style="font-size: 14px;">，而独立框架 “往往需要投入更多精力进行编排与治理”</span></span></p><p style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——FifthElement 首席执行官兼企业 AI 战略师 Jonathan Garini</span></span></p></td></tr><tr><td data-colwidth="574"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">“Microsoft’s Security Copilot 帮助分析师自动分类警报、过滤无效信息；CrowdStrike 也在开展类似工作；Google 则推出了基于 Gemini 的智能体，能够完成端到端的警报调查。</span><span textstyle="" style="font-size: 14px;font-weight: bold;">目前行业主流仍停留在‘附加与扩展’阶段</span><span textstyle="" style="font-size: 14px;">。”</span></span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">附加组件受欢迎的原因之一在于：替换或深度集成新的安全运营平台是一项艰巨任务 ——“部署、人员再培训、流程调整可能需要数月时间，而在此期间，团队仍需应对实时威胁。”</span></span></p><p style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——Checkpoint 公司网络安全与 AI 专家 Amit Weigman</span></span></p></td></tr><tr><td data-colwidth="574"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">两种模式的选择在于“速度与灵活性的权衡”。“附加式便于快速采用，但动态性较弱；独立系统控制力更强，却需要更多部署与维护工作。”</span></span></p><p style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——Mindgard 公司首席营销官兼 AI 安全倡导者 Fergal Glynn</span></span></p></td></tr><tr><td data-colwidth="574"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">提出了一个 “经验法则”：若大部分数据存在于现有 SIEM/SOAR 流程中，附加模式是更优选择；</span><span textstyle="" style="font-size: 14px;font-weight: bold;">若需处理分散在 IT、运营技术（OT）、云及软件即服务（SaaS）中的数据，独立智能体层则更有效</span><span textstyle="" style="font-size: 14px;">，且 “能减少‘频繁切换系统’的麻烦”。</span></span></p><p style="text-align: right;"><span leaf="" data-pm-slice="1 1 [&#34;table&#34;,{&#34;interlaced&#34;:null,&#34;align&#34;:null,&#34;class&#34;:null,&#34;style&#34;:null},&#34;table_body&#34;,{},&#34;table_row&#34;,{&#34;class&#34;:null,&#34;style&#34;:null},&#34;table_cell&#34;,{&#34;colspan&#34;:1,&#34;rowspan&#34;:1,&#34;colwidth&#34;:[287],&#34;width&#34;:null,&#34;valign&#34;:null,&#34;align&#34;:null,&#34;style&#34;:null},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: right;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]"><span textstyle="" style="font-size: 14px;">——OPSWAT 公司产品副总裁 Itay Glick</span></span></p></td></tr><tr><td data-colwidth="574"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">大多数企业从附加模式起步</span><span textstyle="" style="font-size: 14px;"> —— 既能依托现有投资，又能在可控环境中测试效果。而独立框架通常是后续步骤，仅当企业准备好跨混合云或多云环境实现集中化管理时才会部署。</span></span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">“从客户项目中我们总结出一个经验，许多SOC低估了集成的复杂性。这不仅是 API 连接系统的问题，更需要让智能体的决策逻辑与现有剧本、风险容忍度对齐。附加组件模式为这种对齐提供了更平缓的路径，而独立编排往往是成熟度提升后的第二阶段工作。”</span></span></p><p data-pm-slice="0 0 []" style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——Mphasis 公司高级副总裁兼全球网络安全服务主管 Prashant Jagwani</span></span></p></td></tr></tbody></table><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">SOC平台是一个复杂的、迭代演进的平台，对于已有SOC平台的用户而言，如何逐步演进到新的Agentic SOP阶段，需要根据自身目标和具体情况做好路径规划。因此，当前Agentic SOP可以分为两种部署模式：叠加型部署和替代型部署。</span></span></p><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">叠加型部署相当于上文提到的“附加模式”</span><span textstyle="" style="color: rgb(0, 82, 255);">，也就是在现有SOP基础之上部署一个</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">叠加型Agentic SOP</span><span textstyle="" style="color: rgb(0, 82, 255);">，获取现有SOP的告警、事件等信息，结合可以得到的上下文信息，基于Agentic AI进行分析、研判、调查、响应、报告，再将结果返回给现有SOP。</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">此时，用户的安全运营组织和流程基本维持不变，Agentic AI就是在现有SOP基础上进行赋能</span><span textstyle="" style="color: rgb(0, 82, 255);">。</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 82, 255);">叠加型Agentic SOP可以认为是一个裁剪版的SOP，聚焦于安全运营任务的自主化，其技术架构更接近于一个智能体管理与运行平台。</span></span></p><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">叠加型Agentic SOP可以分为两类。一类是专门的产品，在国外经常被称作“AI SOC分析师”（</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">Gartner称之为“AI SOC Agent”</span><span textstyle="" style="color: rgb(0, 82, 255);">，即“SOC智能体”），主要用于实现L1分析师（有的也针对L2/L3分析师）的工作自动化和自主化，多采用SaaS模式交付。另一类则是作为完整的Agentic SOP产品的一个可拆分功能组件（子系统）。</span></span></p><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">替代型部署相当于上文提到的“独立模式”</span><span textstyle="" style="color: rgb(0, 82, 255);">。</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">替代型Agentic SOP</span><span textstyle="" style="color: rgb(0, 82, 255);">架构和功能更加完整，具有跨域多源数据采集、归一、存储、分析等能力，具备较为完善的安全数据中心和较为完整的原生AI安全运营功能，并将多智能体管理与运行子系统内置于平台中。采用替代型部署时，Agentic SOP通常完全或者部分替代现有的SOP。</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">此时，用户的安全运营平台面临较大的升级</span><span textstyle="" style="color: rgb(0, 82, 255);">，可能涉及组织结构和流程的调整，数据的迁移，等等。</span></span></p><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">两种模式各有利弊。如果用户对自身现有SOP比较满意，可以优先采用叠加型Agentic SOP，如果对现有SOP的某些部分（甚至全部）不满意，则可以考虑采用替代型Agentic SOP。当然，如果用户要新建SOP，则应该优先考虑替代型Agentic SOP。</span></span></p><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">目前来看，</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">国内外很多用户都对现有SOP的安全数据中心部分存在不满</span><span textstyle="" style="color: rgb(0, 82, 255);">，这也是导致告警疲劳的根源。这个问题仅靠Agentic AI不足以消除（在低质量数据之上加载AI依然难以得到理想效果），需要对安全数据中心的技术架构进行调整。也就是说，</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">如果不调整现有SOP数据架构，Agentic AI赋能作用有限</span><span textstyle="" style="color: rgb(0, 82, 255);">。</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">现在主流的Agentic SOP都采用了新一代数据驱动架构</span><span textstyle="" style="color: rgb(0, 82, 255);">。因此，</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">现在越来越多的用户优先采用替代型Agentic SOP去优化现有的安全运营数据中心架构，并在此基础上扩展Agentic AI能力</span><span textstyle="" style="color: rgb(0, 82, 255);">。</span></span></p><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">治理与组织变革</span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">实践表明，用户更倾向于在不影响现有运营的前提下，逐步叠加新功能，因此试点成为常见的第一步。</span></p><table><tbody><tr><td data-colwidth="576"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">自主式 AI 的落地很少一蹴而就</span><span textstyle="" style="font-size: 14px;">，“大多数安全团队不会用全新的 AI 系统彻底替换现有安全运营中心 —— 这不仅成本高昂，还需要大量时间与人力投入，最终可能因破坏性过大、成本过高而难以推进。”</span></span></p><p style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——Checkpoint 公司网络安全与 AI 专家 Amit Weigman</span></span></p></td></tr><tr><td data-colwidth="576"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">“对于有意部署自主式 AI 的组织，我的首要建议是：先以试点形式开展小型用例，例如钓鱼攻击响应或凭证滥用检测，再逐步扩展到更广泛的检测与响应场景”。</span><span textstyle="" style="font-size: 14px;font-weight: bold;">聚焦特定场景有助于团队在大规模变革前验证技术价值与可靠性</span><span textstyle="" style="font-size: 14px;">。</span></span></p><p style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——FifthElement 首席执行官兼企业 AI 战略师 Jonathan Garini</span></span></p></td></tr><tr><td data-colwidth="576"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">一旦智能体投入使用，治理体系也需随之升级</span><span textstyle="" style="font-size: 14px;">。团队不会摒弃现有框架，而是对其进行适配：“将现有的变更控制、职责分离规则融入智能体工作流程 —— 例如，破坏性操作需双人签字确认，根据风险等级决定‘自动执行’‘咨询后执行’或‘升级处理’，并在正式部署前通过沙盒环境测试。” 此外，如今智能体也被纳入红队测试，通过提示注入、“越狱” 尝试等方式检验安全性。“核心框架并未改变，只是在智能体场景中变得更加明确。”</span></span></p><p style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——OPSWAT 公司产品副总裁 Itay Glick</span></span></p></td></tr><tr><td data-colwidth="576"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">治理与风险控制通过 “</span><span textstyle="" style="font-size: 14px;font-weight: bold;">人机协同”（Human-in-the-Loop）</span><span textstyle="" style="font-size: 14px;">审批得以扩展，而非彻底重构。除非 AI 达到更高水平的通用智能，否则完全替代现有监管框架并不现实。</span></span></p><p style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——Mphasis 公司高级副总裁兼全球网络安全服务主管 Prashant Jagwani</span></span></p></td></tr></tbody></table><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI在SecOps的应用，不是一个简单的工具或者功能的应用，而是一个体系的应用，必然涉及到安全运营体系的变革，以及相应带来的运营组织变革。正如笔者在《</span><a class="normal_text_link" target="_blank" style="color: rgb(0, 82, 255);" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="迈向AI赋能的SOC4.0时代" data-itemshowtype="11" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 82, 255);text-decoration: underline;">迈向AI赋能的SOC4.0时代</span></a><span textstyle="" style="color: rgb(0, 82, 255);">》一文的5.4小节所述，未来的安全运营一定是自动化和智能化优先的，这就必然引发</span></span><b style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">安全运营过程中人与机器之间协作关系的重新适配</span></span></b><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(0, 82, 255);">，进而需要我们重塑运营的治理体系、组织结构、流程规范。</span></span></p><p><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">在《</span><a class="normal_text_link" target="_blank" style="color: rgb(0, 82, 255);" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485053&amp;idx=1&amp;sn=e2a7ec77a9a9e7fd7f32ed88e3549b83&amp;scene=21#wechat_redirect" textvalue="从Gartner2025年北美安全峰会看安全运营的发展趋势" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 82, 255);text-decoration: underline;">从Gartner2025年北美安全峰会看安全运营的发展趋势</span></a><span textstyle="" style="color: rgb(0, 82, 255);">》一文中，笔者介绍过一幅Gartner的分析师运营工作迁移图，也体现了运营组织的变化。</span></span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">一些旧的岗位消失或者弱化了，一些新的岗位职责产生了</span><span textstyle="" style="color: rgb(0, 82, 255);">。当然，这个过程不是一蹴而就的，而应该是渐进式的，随着Agentic AI应用深入而持续深化。</span></span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">信任、监督与人机协作</span></span></p><p data-pm-slice="0 0 []"><span leaf="">自主式 AI 的核心优势在于自主性，但这也成为其落地的主要障碍：许多组织不愿让智能体在生产环境中自主运行。</span></p><table><tbody><tr><td data-colwidth="576"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">“若智能体在威胁响应中被误用或部署不当，其执行的一系列操作</span><span textstyle="" style="font-size: 14px;font-weight: bold;">可能会引发新风险</span><span textstyle="" style="font-size: 14px;">。例如，可能出现未受监管的脚本执行，或暴露新发现的漏洞。” 因此，大多数组织在缺乏强有力保障措施的情况下，不会允许智能体完全自主运行。</span></span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">建议将智能体视为</span><span textstyle="" style="font-size: 14px;font-weight: bold;"> “协作式数字伙伴”</span><span textstyle="" style="font-size: 14px;">，通过人机协作提升AI的透明度。</span></span></p><p data-pm-slice="0 0 []" style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——美国银行数据驱动解决方案与应用 AI 专家 Vinod Goje</span></span></p></td></tr><tr><td data-colwidth="576"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">“</span><span textstyle="" style="font-size: 14px;font-weight: bold;">AI 仍像是一个‘黑箱’</span><span textstyle="" style="font-size: 14px;">，” 他说，“人类分析师虽也会犯错，但管理者清楚其失误范围，能量化相关损失；而对于 AI，我们往往‘不知道自己不知道什么’，这种不确定性自然会引发担忧。”</span></span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">大多数使用者会 “在高风险操作中坚持</span><span textstyle="" style="font-size: 14px;font-weight: bold;">人机协同</span><span textstyle="" style="font-size: 14px;"> ——AI 可提供建议或分类信息，但最终决策权仍归属分析师”。</span></span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">部署</span><span textstyle="" style="font-size: 14px;font-weight: bold;">专注特定领域的 “狭义智能体（Narrow Agent）” </span><span textstyle="" style="font-size: 14px;">有助于提升可见性。“无需构建一个庞大的‘黑箱式 AI 大脑’，而是打造一组专业化智能体 —— 每个智能体的职责范围明确，便于监控与解释。”</span></span></p><p data-pm-slice="0 0 []" style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——Checkpoint 公司网络安全与 AI 专家 Amit Weigman</span></span></p></td></tr><tr><td data-colwidth="576"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">“</span><span textstyle="" style="font-size: 14px;font-weight: bold;">所有操作都需有审计跟踪</span><span textstyle="" style="font-size: 14px;"> —— 从提示输入、工具调用，到输出结果与审批流程，无一例外。”</span></span></p><p style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——OPSWAT 公司产品副总裁 Itay Glick</span></span></p></td></tr><tr><td data-colwidth="576"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">文档记录至关重要</span><span textstyle="" style="font-size: 14px;">：“所有受监管操作都需记录、验证，并最终可审计。我们不仅要知道 AI‘做了什么’，还必须阐明它‘为何采取这些特定行动’。”</span></span></p><p style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——BigID 公司安全副总裁 Kyle Kurdziolek</span></span></p></td></tr><tr><td data-colwidth="576"><p><span leaf=""><span textstyle="" style="font-size: 14px;">金融服务领域的监管机构尤其看重 “可审计中的</span><span textstyle="" style="font-size: 14px;font-weight: bold;">可解释性</span><span textstyle="" style="font-size: 14px;">”。“这意味着 AI 输出不能仅是‘黑箱式建议’”。当前，</span></span><span style="letter-spacing: 0.034em;background-color: transparent;"><span leaf=""><span textstyle="" style="font-size: 14px;">“</span></span></span><span style="letter-spacing: 0.034em;background-color: transparent;"><span leaf=""><span textstyle="" style="font-size: 14px;">团队正开始部署分层审计跟踪系统，将智能体的决策拆解为输入数据、置信度评分与升级逻辑。”</span></span></span></p><p data-pm-slice="0 0 []" style="text-align: right;"><span leaf="" data-pm-slice="1 1 [&#34;table&#34;,{&#34;interlaced&#34;:null,&#34;align&#34;:null,&#34;class&#34;:null,&#34;style&#34;:null},&#34;table_body&#34;,{},&#34;table_row&#34;,{&#34;class&#34;:null,&#34;style&#34;:null},&#34;table_cell&#34;,{&#34;colspan&#34;:1,&#34;rowspan&#34;:1,&#34;colwidth&#34;:[576],&#34;width&#34;:null,&#34;valign&#34;:null,&#34;align&#34;:null,&#34;style&#34;:null},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: right;&#34;},&#34;namespaceURI&#34;:&#34;&#34;}]"><span textstyle="" style="font-size: 14px;">——Mphasis 公司高级副总裁兼全球网络安全服务主管 Prashant Jagwani</span></span><span style="letter-spacing: 0.034em;background-color: transparent;"><span leaf=""><br/></span></span></p></td></tr></tbody></table><p style="margin-top: 24px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(0, 82, 255);">文章认为，当前Agentic AI的问题在于“透明度”不够，需在 AI 工作流程中建立 “可见性” 与 “责任制”，以提升“透明度”。与此同时，人在运营回路之中（Human in the operations loop，即“人机协作”）也十分关键，这既是当下AI能力不足的体现，也是未来人类维持主导的必然。此外，笔者认为，需</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">要建立AI失效的机制和预案，关键的运营工作能够在AI失效后维持运转</span><span textstyle="" style="color: rgb(0, 82, 255);">。</span></span></p><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">显然，为了建立AI的“透明度”，需要针对AI进行额外的投资。</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">在考虑Agentic SOP的投入时，还应该考虑到围绕Agentic AI建立“可见性”与“责任制”的附带投入</span><span textstyle="" style="color: rgb(0, 82, 255);">。而这不能仅靠Agentic SOP自身的安全与可靠性（Security &amp; Saftey）机制，也不能仅依靠第三方的AI安全与可靠性产品或解决方案，还需要组织自身的治理结构的调整。这也是当前阻碍Agentic AI在客户侧落地的重要阻碍之一。从这个意义上而言，建立Agentic SOP，投资不小，可以将Agentic SOP的安全与可靠性投资与企业整体的AI投资进行统筹考虑。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">新一代人才培养</span></span></p><p data-pm-slice="0 0 []"><span leaf="">若智能体接管了一级分析师的工作，安全运营中心的新成员该如何成长？</span></p><table><tbody><tr><td data-colwidth="576"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">传统上，一级分析师的工作是安全领域的 “入门训练场”。自主式 AI 带来了一个悖论：它虽将人类从重复性分类任务中解放出来，却也可能削弱新分析师通过处理警报积累的 “肌肉记忆”。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;">但实际上，许多机械性分类工作（如过滤明显误报、清理重复警报、升级常规钓鱼案件）仅能锻炼分析师的耐心，无法带来实质性能力提升。AI 擅长处理这类琐碎任务，而人类分析师可专注于更复杂的挑战。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;">这一转变</span><span textstyle="" style="font-size: 14px;font-weight: bold;">让一级岗位从 “苦差事” 变为 “指导性训练场”</span><span textstyle="" style="font-size: 14px;">：新分析师无需淹没在无效信息中，而是通过研究 AI 整理并记录的案例，通过探究智能体的决策逻辑学习知识。因此，若缺乏合理规划，自主式 AI 确实可能导致人才培养断层；但只要善加利用，它完全能加速技能提升。</span></span></p><p style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——美国银行数据驱动解决方案与应用 AI 专家 Vinod Goje</span></span></p></td></tr></tbody></table><p><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">笔者认为，Vinod Goje是比较乐观的，反观Gartner，则预测</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span textstyle="" style="color: rgb(0, 82, 255);">“</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">到2030年，</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">由于过度依赖自动化和AI，</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">75%的SOC团队的</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">基础安全分析技能将会退化</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);">”【注：该条目入选Gartner2025年8大网络安全预测】</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 82, 255);">。</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="color: rgb(0, 82, 255);">如何不退化？这就需要重新考虑人才培养的方式。如</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 82, 255);">Vinod Goje所言，初级安全分析师的成长路径在AI时代发生了变化，需要保持学习能力，从AI中去学习，从可解释性AI研判的结果和过程中去学习。此外，要明确哪些运营工作应保持人类主导，哪些工作需要人机协作（HITL）以及如何人机分工。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">定价、价值与方案设计</span></span></p><p data-pm-slice="0 0 []"><span leaf="">自主式 AI 的能力与治理固然重要，但推动其在安全领域落地的核心动力之一仍是 “经济性”。安全负责人最关心的问题是：它能为我们节省多少时间与成本？而答案往往并不简单。</span></p><p data-pm-slice="0 0 []"><span leaf="">文章认为，这个问题可能将决定自主式 AI 在网络安全领域的未来。尽管技术正快速成熟，但其能否长期立足，最终取决于企业是否将其视为 “重塑安全运营中心运作模式的可持续方案”。</span></p><table><tbody><tr><td data-colwidth="576"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">“</span><span textstyle="" style="font-size: 14px;font-weight: bold;">定价仍是一个摩擦点</span><span textstyle="" style="font-size: 14px;">”，“供应商正尝试基于使用量的定价模式，但企业更倾向于将支出与‘节省的分析师工时’挂钩，而非‘原始计算资源或 API 调用量’。”</span></span></p><p style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——FifthElement 首席执行官兼企业 AI 战略师 Jonathan Garini</span></span></p></td></tr><tr><td data-colwidth="576"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">当前 AI 定价模式差异显著：“收费方式可能是订阅制、按席位收费、按警报数量收费，部分供应商还提供基于使用量的方案。先进智能体系统通常价格较高，因其影响范围更广，能为分析师节省更多工作量。”</span></span></p><p style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——Mindgard 公司首席营销官兼 AI 安全倡导者 Fergal Glynn</span></span></p></td></tr><tr><td data-colwidth="576"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">部分团队正在尝试 “按席位、按任务或混合模式” 定价，但是：“存储、API 费用、长提示处理、剧本维护等隐性成本会迅速累积”。“</span><span textstyle="" style="font-size: 14px;font-weight: bold;">投资回报率（ROI）最终应体现在具体指标上</span><span textstyle="" style="font-size: 14px;">，例如更快的检测与响应速度、每位分析师处理更多案件、更少的无效警报”。</span></span></p><p style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——OPSWAT 公司产品副总裁 Itay Glick</span></span></p></td></tr><tr><td data-colwidth="576"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">各团队正 “全面探索定价模式”，基于使用量的模式与混合模式仍在不断演进。企业预算不仅要覆盖软件成本，还需包含在本地与云端运行大型模型的混合基础设施成本。</span></span></p><p style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——Black Duck 首席产品与技术官 Dipto Chakravarty</span></span></p></td></tr><tr><td data-colwidth="576"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">简单的定价指标往往会忽略关键问题：“隐性成本通常出现在特定领域数据模型再训练、清洁结构化遥测数据管道搭建等环节。” 最佳投资回报来自于将智能体视为 “长期流程重构的一部分”，而非 “又一个插件”。</span></span></p><p style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——Mphasis 公司高级副总裁兼全球网络安全服务主管 Prashant Jagwani</span></span></p></td></tr><tr><td data-colwidth="576"><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">投资回报率的衡量</span><span textstyle="" style="font-size: 14px;font-weight: bold;">没有 “统一标准”</span><span textstyle="" style="font-size: 14px;">。“每个组织都有差异” 。“部分组织从效率角度评估：智能体识别的真阳性 / 假阳性事件数量有多少？它发起了多少起事件调查？另一些组织则从资源角度考量：节省了多少警报分类时间？需要多少次复核智能体输出？实际时间节省是否达标？”</span></span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">核心问题其实很简单：智能体能否在分类与调查工作中节省足够时间，让安全团队有更多精力提升企业整体安全能力？</span></span></p><p style="text-align: right;"><span leaf=""><span textstyle="" style="font-size: 14px;">——BigID 公司安全副总裁 Kyle Kurdziolek</span></span></p></td></tr></tbody></table><p><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">安全运营平台的定价越来越需要跟价值挂钩</span><span textstyle="" style="color: rgb(0, 82, 255);">，但这并非易事。Agentic SOP具体发挥多大的价值，不是厂商标称的，也跟各个用户具体环境和应用水平相关。</span></span></p><p><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">在评估投资回报率的时候，一方面在计算投资时，要涵盖“冰山水面之下的部分”，不仅包括Agentic SOP软件系统的投资，还包括LLM（软硬件和算力消耗）的投资，AI安全与可靠性方面的投资，以及配套的安全运营组织人员（包括自有和外包）方面的投资。另一方面在计算回报（价值）的时候，可以采用指标体系去评估。而指标体系跟项目建设的目标密切相关，并没有统一标准，不能简单的采取“拿来主义”。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">总结</span></span></p><p><span leaf="">这里，笔者想借用另一篇文章【注2】的结尾作为本文的总结。</span></p><p><span leaf="">Agentic AI从根本上改变了我们对安全自动化的认知 —— 从僵化的 “规则驱动系统”，转向具备适应能力与推理能力的 “合作伙伴”。但与所有强大工具一样，其价值完全取决于部署方式的审慎性与责任感。</span></p><p><span leaf="">那些能在 SOC 中成功应用</span><span style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: none;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.578px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: break-spaces;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">Agentic AI</span></span><span leaf="">的企业，往往能抵制 “将其视为解决所有安全问题的万能方案” 的诱惑。相反，它们会将其视为 “需要精心集成、持续监督与不断优化的复杂能力”。</span></p><p><span leaf="">未来的发展路径并非 “在人类分析师与智能体之间二选一”，而是 “构建人机混合团队”—— 让两者发挥各自独特优势。智能体带来速度、稳定性与海量信息并行处理能力；人类分析师则贡献创造力、上下文理解、伦理判断，以及应对 “无法被预定义” 的模糊场景的能力。</span></p><p><span leaf="">SOC运营的未来在于这种协作 —— 但前提是，我们能构建必要的治理、安全与监控框架，确保其可靠、安全地运行。</span><span style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: none;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.578px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: break-spaces;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">Agentic AI</span></span><span leaf="">并非解决网络安全挑战的 “银弹”，但如果部署得当，它将成为构建 “更具韧性、响应更快、效率更高的安全运营” 的强大工具。</span></p><p><span leaf="">如今，问题已不再是 “</span><span style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: none;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.578px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: break-spaces;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">Agentic AI</span></span><span leaf="">是否会改变SOC运营”—— 它已然在改变。真正的问题是：企业能否足够快地调整 AI 部署策略，在抓住机遇的同时规避风险？那些平衡好这一点的企业，将在持续的网络威胁对抗中获得显著竞争优势；而那些急于拥抱安全自动化未来、却忽视风险的企业，则可能为自身埋下新的漏洞。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">【注1】</span>文中涉及的受访信息源自文章：</span><span leaf="">Agentic AI in IT security: Where expectations meet reality，链接：</span></p><blockquote><p><span leaf=""><a href="https://www.csoonline.com/article/4064158/agentic-ai-in-it-security-where-expectations-meet-reality.html" target="_blank">https://www.csoonline.com/article/4064158/agentic-ai-in-it-security-where-expectations-meet-reality.html</a></span></p></blockquote><div style="-webkit-tap-highlight-color: transparent;margin: 24px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">【注2】</span><span textstyle="" style="font-weight: normal;">结尾引用的</span>博客文章：</span><span leaf="">The Agentic AI Revolution in SOC: Promise, Peril, and the Path Forward，链接：</span></p><blockquote><p><span leaf=""><a href="https://www.sisainfosec.com/blogs/the-agentic-ai-revolution-in-soc/" target="_blank">https://www.sisainfosec.com/blogs/the-agentic-ai-revolution-in-soc/</a></span></p></blockquote><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">【参考】</span></span></p></div><p style="-webkit-tap-highlight-color: transparent;margin: 24px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485048&amp;idx=1&amp;sn=4bceff5bb6514bacc86b69ce83b0fca1&amp;scene=21#wechat_redirect" textvalue="浅析SecOps中的AI Agent和Agentic AI，以及SOC自主化水平模型" data-itemshowtype="0" linktype="text" data-linktype="2">浅析SecOps中的AI Agent和Agentic AI，以及SOC自主化水平模型</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 24px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485079&amp;idx=1&amp;sn=86c2df034a23791da7b39aa42cba0fc6&amp;scene=21#wechat_redirect" textvalue="Gartner分析师谈AI Agent和Agentic AI" data-itemshowtype="0" linktype="text" data-linktype="2">Gartner分析师谈AI Agent和Agentic AI</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 24px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485064&amp;idx=1&amp;sn=1c65225911fa0875d1e68ab8600a1586&amp;scene=21#wechat_redirect" textvalue="国外Agentic SOC最新进展（2025Q3）" data-itemshowtype="0" linktype="text" data-linktype="2">国外Agentic SOC最新进展（2025Q3）</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 24px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="迈向AI赋能的SOC4.0时代" data-itemshowtype="11" linktype="text" data-linktype="2">迈向AI赋能的SOC4.0时代</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 24px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485053&amp;idx=1&amp;sn=e2a7ec77a9a9e7fd7f32ed88e3549b83&amp;scene=21#wechat_redirect" textvalue="从Gartner2025年北美安全峰会看安全运营的发展趋势" data-itemshowtype="0" linktype="text" data-linktype="2">从Gartner2025年北美安全峰会看安全运营的发展趋势</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 24px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484993&amp;idx=1&amp;sn=506b9c0de108b2293d71c15750f0d95c&amp;scene=21#wechat_redirect" textvalue="从RSAC2025看安全运营技术发展趋势" data-itemshowtype="0" linktype="text" data-linktype="2">从RSAC2025看安全运营技术发展趋势</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 24px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484842&amp;idx=1&amp;sn=38dba05e2a0024b71d81d1d9b3e74a6c&amp;scene=21#wechat_redirect" textvalue="2024年安全运营技术趋势回顾" data-itemshowtype="0" linktype="text" data-linktype="2">2024年安全运营技术趋势回顾</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 24px 0px 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzkzMzkzMjI4OQ==&amp;mid=2247483748&amp;idx=1&amp;sn=403a04f2e7ab7b101d5b34378f1853ba&amp;scene=21#wechat_redirect" textvalue="自主化安全运营平台技术解析与实践" data-itemshowtype="0" linktype="text" data-linktype="2">自主化安全运营平台技术解析与实践</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247485080">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=73b6876f&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyNzMxOTAwMw%3D%3D%26mid%3D2247485080%26idx%3D1%26sn%3Dc6c4509a6ce51a7dfbfd0e2219200751">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 06 Nov 2025 12:02:00 +0800</pubDate>
    </item>
    <item>
      <title>Gartner分析师谈AI Agent和Agentic AI</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485079&amp;idx=1&amp;sn=86c2df034a23791da7b39aa42cba0fc6</link>
      <description>Agentic AI和AI Agent的关系，智能体开发原则和应用风险</description>
      <content:encoded><![CDATA[<p>
<span></span> <span>2025-11-03 12:00</span> <span style="display: inline-block;">北京</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=994236ec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMfvsj8NibPia0GaGjmlHJMlr3no7Kb0gIIkGDahic64HicXOakyXGd6keAaaGo8SgFZhcdEiacsqNV5ZWA%2F0%3Fwx_fmt%3Djpeg"/></p>

<p>Agentic AI和AI Agent的关系，智能体开发原则和应用风险</p>

<p><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">此前笔者在《<a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485048&amp;idx=1&amp;sn=4bceff5bb6514bacc86b69ce83b0fca1&amp;scene=21#wechat_redirect" textvalue="浅析SecOps中的AI Agent和Agentic AI，以及SOC自主化水平模型" data-itemshowtype="0" linktype="text" data-linktype="2">浅析SecOps中的AI Agent和Agentic AI，以及SOC自主化水平模型</a></span></span><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">》一文中对相关概念进行了梳理，并给出了Agentic SOP/SOC的定义，以及SOP/SOC的自主化水平划分，并在《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="迈向AI赋能的SOC4.0时代" data-itemshowtype="11" linktype="text" data-linktype="2">迈向AI赋能的SOC4.0时代</a>》一文中讨论了Agentic SOP的五大关键技术特征。</span></span></p><p><span leaf="">本文主要整理自一篇对Gartner负责Agentic AI研究的分析师Tom Coshow的访谈【注1】，并结合Gartner的一份Agentic AI概览报告【注2】，帮助大家<span textstyle="" style="font-weight: bold;">进一步厘清AI Agent和Agentic AI的关系</span>，以及<span textstyle="" style="font-weight: bold;">开发Agentic AI应用系统的基本原则</span>。此外，本文最后还转载了另一份Gartner报告【注3】中对<span textstyle="" style="font-weight: bold;">Agentic AI带来的风险</span>方面的说明。</span></p><p><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">AI Agent和Agentic AI关系</span></span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-weight: bold;">智能体（AI Agents）是具备自主或半自主能力的软件实体，它们运用人工智能技术感知环境、制定决策、采取行动，并在数字或物理环境中实现目标</span>。这类智能体拥有自主决策权，能规划如何推进目标达成，还具备在数字环境中实际采取行动的工具支持。</span></p><p><span leaf="">而Agentic AI（笔者翻译为“</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">自主式AI”）</span><span leaf="">的定义则稍显复杂 —— 市面上很多定义会让它看起来与智能体截然不同，但在高德纳看来，<span textstyle="" style="background-color: rgb(255, 251, 0);font-weight: bold;">自主</span></span><span style="background-color:rgba(255,246,122,0.8);"><strong><span leaf=""><span textstyle="" style="background-color: rgb(255, 251, 0);">式AI是一个包含智能体（AI Agent）的 “umbrella term”</span></span></strong></span><span style="background-color:rgba(255,246,122,0.8);"><span leaf=""><span textstyle="" style="background-color: rgb(255, 251, 0);font-weight: bold;">（即“涵盖性术语”）</span></span></span><span leaf="">。</span></p><p><span leaf=""><span textstyle="" style="font-style: italic;">【笔者注】Gartner在Agentic AI概述报告中指出：“</span></span><span leaf=""><span textstyle="" style="font-weight: bold;font-style: italic;">自主式 AI（Agentic AI）</span><span textstyle="" style="font-style: italic;">是一种构建 AI 解决方案的方法，其核心是使用一个或多个软件实体 —— 这些实体全部或至少部分符合（Gartner定义的）AI 智能体（AI Agent）特征，且这些实体还可能与其他非 AI 元素相结合。”</span></span></p><blockquote><p><span leaf=""><span textstyle="" style="font-style: italic;">“Agentic AI is an approach to building AI solutions that are based on the use of one or multiple software entities that classify completely or at least partially as an AI agent (as defined by Gartner), possibly combined with other non-AI elements.”</span></span></p></blockquote><p><span leaf=""><span textstyle="" style="font-style: italic;">下图展示了Agentic AI和AI Agent之间的关系：</span></span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001430" data-ratio="0.4083333333333333" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=cd881b08&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMd7XXEyoiaSdJb8DLiaibRcykjgHdVO6HcAJETgFCS7oiau95GMCumnJ8xjK68qy8ibTibjMty5u2EkZLCw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span leaf=""><span textstyle="" style="font-style: italic;">其中，</span><span textstyle="" style="font-weight: bold;font-style: italic;">AI</span></span><span leaf=""><span textstyle="" style="font-weight: bold;font-style: italic;">助手（AI assistants）</span><span textstyle="" style="font-style: italic;">是一类专用应用程序，或大型系统中的模块组件。这类工具会整合人工智能技术，通过（对话式）交互界面，按照外部（人类）操作者的要求、指令和引导，提供任务支持或直接执行任务。并不是所有的AI助手都属于Agentic AI。</span></span></p><p><span leaf=""><span textstyle="" style="font-style: italic;">此外，笔者在《</span><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485048&amp;idx=1&amp;sn=4bceff5bb6514bacc86b69ce83b0fca1&amp;scene=21#wechat_redirect" textvalue="浅析SecOps中的AI Agent和Agentic AI，以及SOC自主化水平模型" data-itemshowtype="0" linktype="text" data-linktype="2">浅析SecOps中的AI Agent和Agentic AI，以及SOC自主化水平模型</a><span textstyle="" style="font-style: italic;">》一文中，也系统性的阐述了Agentic AI和AI Agent的关系。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">构建智能体的关键组件</span></span></p><p><span leaf="">如下图所示，单个智能体拥有自身的 “记忆”，具备规划、执行任务和使用工具的能力，同时包含 “系统提示（system prompt）”，并借助大语言模型（LLM）在环境中推进目标实现。</span></p><p style="text-align: center;"><span leaf=""><img alt="Gartner: Key Components for Building AI Agents" class="rich_pages wxw-img" data-imgfileid="100001421" data-ratio="0.7462962962962963" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=b8ca1093&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMfvsj8NibPia0GaGjmlHJMlr3eiaZuoZzJxwBIjHC79miaNIw3jImVVBooJBIc5ZRnR3iaM0CY5vVVicRjA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p data-pm-slice="0 0 []" style="text-align: center;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 14px;">智能体（AI Agents）的核心构建要素</span></span></p><p><byte-sheet-html-origin data-id="" data-version="4" data-is-embed="true" data-grid-line-hidden="false" data-copy-type="col"></byte-sheet-html-origin></p><table style="border-collapse:collapse;min-width:153px;"><tbody><tr><td data-colwidth="128" style="color:rgb(0, 0, 0);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">要素分类</span></span></p></td><td style="color:rgb(0, 0, 0);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;"><p><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">具体内容</span></span></p></td></tr><tr><td data-colwidth="128" style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 14px;">人工智能技术</span></span></p></td><td style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;"><p><span leaf=""><span textstyle="" style="font-size: 14px;">大型模型、小型模型或其他人工智能技术实践</span></span></p></td></tr><tr><td data-colwidth="128" style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 14px;">智能体组件</span></span></p></td><td style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;"><p><span leaf=""><span textstyle="" style="font-size: 14px;">1. 记忆（Memory）：智能体的短期与长期记忆</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;">2. 规划（Planning）：将目标拆解为更小任务</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;">3. 任务（Tasks）：待执行的当前任务清单</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;">4. 工具集成（Tool integration）：智能体与各类环境的交互能力</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 14px;">5. 感知（Sensing）：感知周围环境的能力</span></span></p></td></tr><tr><td data-colwidth="128" style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 14px;">环境</span></span></p></td><td style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;"><p><span leaf=""><span textstyle="" style="font-size: 14px;">智能体将采取行动的物理或数字场景</span></span></p></td></tr><tr><td data-colwidth="128" style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 14px;">目标</span></span></p></td><td style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;"><p><span leaf=""><span textstyle="" style="font-size: 14px;">需完成的整体任务</span></span></p></td></tr></tbody></table><p style="margin-top: 24px;"><span leaf="">当前已投入实际应用的智能体大多 “限制严格”，原因在于构建 “系统提示” 时必须追求极致精准。每个智能体中都包含 “系统提示”，它需要向大型语言模型明确指令 —— 例如，告知智能体需在四个 API 中选择调用哪一个。我们不能让 “系统提示” 过于开放，否则大语言模型可能会产生混淆。</span></p><p><span leaf="">在多智能体系统（MAS）中，智能体需 “为特定目的定制”—— 比如专门负责撰写内容的智能体、专门负责调研的智能体等。譬如有一个 “药房智能体”，它的唯一功能就是查询用户的用药历史。将任务拆分给专门的智能体来完成，操作会更简便。再举个例子：假设我开发了一个功能完善的 “信用卡智能体”，它可以被嵌入多个工作流程中；但我绝不会开发一个 “全能智能体”—— 既要回答物流问题、产品问题、政策问题，同时还要承担 “协调智能体（orchestrator agent）” 的角色。更合理的方案是单独设置一个 “协调智能体”，由它判断 “你需要的服务是什么”（无论需求来自人类还是其他智能体），然后引导你对接 “信用卡智能体”。</span></p><p data-pm-slice="0 0 []"><span leaf="">此外，</span><strong><span leaf=""><span textstyle="" style="background-color: rgb(255, 251, 0);">数据质量直接决定智能体的性能</span></span></strong><span leaf="">。我们发现，一些原本专注于帮助企业提升数据质量的小型公司，如今也进入了智能体领域 —— 因为它们对数据有深入理解。这一点在生成式人工智能早期应用中就有体现：有人曾基于 20 年前的、存在矛盾的客服文档开发客服聊天机器人，最终效果自然很差。未来，“数据质量提升” 以及 “通过数据预推理驱动智能体行为”，有望成为显著趋势。</span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">“效率” 在 “GenAI助手领域” 与 “主动式AI领域” 中的含义不同</span></span></p><p data-pm-slice="0 0 []"><span style="background-color:rgba(255,246,122,0.8);"><span leaf="">在智能体领域，“效率” 意味着</span></span><span style="background-color:rgba(255,246,122,0.8);"><strong><span leaf="">直接执行人类原本需要完成的任务</span></strong></span><span style="background-color:rgba(255,246,122,0.8);"><span leaf="">；而人工智能助手的作用，仅仅是建议人类该做什么。</span></span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">智能体的成本与人类完成相同工作的成本进行对比</span></span></p><p data-pm-slice="0 0 []"><span leaf="">智能体与人类的成本对比，很大程度上取决于智能体调用大型语言模型的次数，以及涉及的 “tokens”（即语言模型处理的基本语义单位）数量，因此很难直接与人类活动成本对标。</span></p><p><span leaf="">智能体的成本还与它使用的模型相关：如果使用的是最新、最先进但成本高昂的模型，其成本可能会显著高于 “针对特定领域微调后的小型语言模型”—— 使用后者的成本会大幅降低。</span></p><p><span leaf="">预计今年（2025 年）会出现更多 “小型微调语言模型” 的应用案例。若智能体设计合理，“系统提示” 会明确告知语言模型需要返回什么结果；如果有一个性能足够的小型语言模型，且智能体能为其提供清晰的指令和优质数据，那么这个小型语言模型就足以驱动智能体的运行。</span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">企业构建主动式AI平台需要哪些条件</span></span></p><p data-pm-slice="0 0 []"><span leaf="">多数企业都在寻求某种形式的 “平台”—— 无论是小型独立平台，还是与超大规模云计算厂商（hyperscaler）相关的平台，但最终可能会采用 “混合模式”。</span></p><p><span leaf="">大型企业担心最终会陷入 “拥有 30 个不同智能体平台” 的困境，但同时也不愿被单一平台绑定。因此，目前他们对 “同时使用 3-4 个平台” 的方案接受度较高。</span></p><p><span leaf="">智能体平台的创业领域非常活跃，市场对这类创业公司的关注度也很高。<span textstyle="" style="font-weight: bold;">当前的平台主要分为两类</span>：一类是 “横向平台”，可用于开发任何类型的智能体；另一类是 “垂直平台”，专注于特定行业，甚至聚焦于某一特定软件平台。</span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">如何设置约束机制，确保智能体在特定规则内运行</span></span></p><p data-pm-slice="0 0 []"><span leaf="">关键在于通过 “系统提示” 向智能体传递准确指令，且</span><strong><span leaf="">不要给智能体过多选择</span></strong><span leaf="">。这也是多智能体系统越来越受欢迎的原因之一。</span></p><p><span leaf="">举个例子：有一家大型跨国公司，他们为北美市场开发了一款生成式人工智能助手，反响很好；随后将其推广到日本和欧洲市场时，智能体却开始给出混乱答案。原因是他们让大型语言模型从 “5 个选项中做决策” 变成了 “1000 个选项中做决策”—— 这是典型的设计失误。</span><strong><span leaf=""><span textstyle="" style="background-color: rgb(255, 251, 0);">智能体必须 “为特定目的而生”</span></span></strong><span leaf="">。</span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">构建和部署智能体解决方案时，存在哪些风险或挑战</span></span></p><p data-pm-slice="0 0 []"><span leaf="">很多人在开发第一个智能体时，会惊讶地发现它很容易 “失控”；当开发包含两个智能体的系统时，问题会更严重。智能体的开发难度，远低于市场宣传的 “轻松实现”。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">在多智能体系统中，智能体之间需要相互通信，且这种通信必须绝对精准</span> —— 否则工作流程中会出现信息损耗，导致整体效率下降。</span></p><p data-pm-slice="0 0 []"><span leaf="">智能体之间的通信方式可能不同，以 “通过 API 相互发送提示” 为例：必须确保 “提示内容” 能完美适配工作流程的下一步，就像小时候玩过的 “电话游戏”（多人依次传递信息，最终信息失真）—— 多智能体系统中绝对要避免这种 “信息失真问题”。</span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">智能体中的“记忆”概念解析</span></span></p><p data-pm-slice="0 0 []"><span leaf="">通常来说，“记忆” 指的是 “短期记忆”，它能帮助智能体按顺序执行任务 —— 相当于智能体的 “实时状态记忆”，让智能体清楚自己当前所处的流程节点和正在执行的操作。</span></p><p><span leaf="">但市场对 “记忆” 的定义存在一些混淆：</span></p><ul class="list-paddingleft-1"><li style="text-align:left;"><p><span leaf="">有人认为 “记忆” 是存储在客户关系管理系统（CRM）或知识图谱中的信息，这些信息会驱动智能体行为，可称之为 “长期记忆”；</span></p></li><li style="text-align:left;"><p><span leaf="">还有一种 “记忆” 概念：将智能体的所有活动记录 “单独存储”，通过分析这些记录来优化智能体 —— 目前已有团队在研发 “自动化优化方案”，目标是让智能体具备 “学习能力”。</span></p></li></ul><p><span leaf="">不过这一话题比较复杂：比如在机器人领域（如波士顿动力的步行机器人）或视频游戏领域，会通过 “强化学习” 提升系统性能，但在商业领域，目前尚未看到类似应用。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">当前商业场景中的 “记忆”，要么是指从数据中提取的特定信息，要么是支持智能体按顺序执行任务的 “短期记忆”，也可能是用于后续优化智能体的 “活动记录”。</span></span></p><p><span leaf="">此外，还有一种思路：若能构建 “智能体记忆”，或许可以利用这些信息微调模型，让智能体更 “聪明”；也可以通过分析这些信息调整智能体的 “系统提示”—— 比如观察智能体的执行结果后，发现 “系统提示” 需要优化。但目前这些思路仍处于 “概念讨论阶段”，尚未大规模落地。</span></p><p><span leaf="">目前，即使是创业公司提供的平台，大多也会配备 “操作面板”，能清晰展示智能体的所有行为；如果是多智能体系统，还能查看智能体之间的通信记录 —— 通过这些记录，通常能精准定位 “哪里出了问题” 或 “哪里运行正常”。</span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">“系统提示” 可否由智能体自主编写</span></span></p><p data-pm-slice="0 0 []"><span leaf="">每个智能体的 “系统提示” 都由人类编写，要求精准且明确 —— 既要告知智能体 “该做什么”，也要在发现智能体出现 “异常行为” 时，约束其不要再犯。</span></p><p><span leaf="">需要注意的是，这里存在一个区别。如下图所示，“代理智能体”</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">（proxy agent</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">）</span><span leaf="">中的 “系统提示”与向 “协调智能体” （</span><span leaf="">orchestrator agent</span><span leaf="">）发送的 “提示”是不同的。</span></p><p><span leaf="">为 “协调智能体” 编写的 “提示” 至关重要，因为它会决定诸多关键参数 —— 比如大语言模型的 “温度值（temperature）”（用于控制输出内容的创造性与事实性平衡）、可调用的 CRM 系统、可访问的功能或其他工具。事实上，“系统提示” 存在于每个智能体中，其重要性与 “协调智能体的提示” 相当。</span></p><p><span leaf="">至于 “智能体自行编写提示”，最初有人认为 “系统提示只能由人类编写”，但现在观点已发生变化 —— 目前主流方案是 “人类编写 1.0 版本提示”，之后由智能体借助大语言模型生成后续版本，且智能体编写的 “系统提示” 质量，往往优于人类编写的版本。</span></p><p style="text-align: center;"><span leaf=""><img alt="Gartner AI Agent Example Architecture" class="rich_pages wxw-img" data-imgfileid="100001422" data-ratio="0.81796875" data-w="1280" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=3a5acd86&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMfvsj8NibPia0GaGjmlHJMlr3zv3PxzFwxRwicfCqMallWcJW9X03FxGTYoibp8estAYKIiaKIjNEHOkFw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><table><tbody><tr><td data-colwidth="576"><h3 style="-webkit-font-smoothing: antialiased;box-sizing: border-box;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: none;border: 0px solid;margin: 12px 0px 0px;padding: 0px;font-size: 16px;font-weight: 600;line-height: 24px;color: rgb(0, 0, 0);overflow-anchor: auto;font-family: Inter, -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, sans-serif;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 14px;">上图中“博客写作多智能体系统”的工作步骤说明</span></span></h3><ol style="-webkit-font-smoothing: antialiased;box-sizing: border-box;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: none;border: 0px solid;margin: 0px 0px 8px;padding: 0px 0px 0px 24px;list-style: none;overflow-anchor: auto;color: rgb(0, 0, 0);font-family: Inter, -apple-system, BlinkMacSystemFont, &#34;Segoe UI&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei&#34;, &#34;Helvetica Neue&#34;, Helvetica, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: normal;orphans: 2;text-align: start;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" class="list-paddingleft-1"><li style="-webkit-font-smoothing: antialiased;box-sizing: border-box;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: none;border: 0px solid;margin: 8px 0px;padding: 0px;font-size: 16px;font-weight: 400;line-height: 24px;color: rgb(0, 0, 0);list-style-type: decimal;overflow-anchor: auto;"><p><span leaf=""><span textstyle="" style="font-size: 14px;">用户请求撰写一篇博客</span></span></p></li><li style="-webkit-font-smoothing: antialiased;box-sizing: border-box;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: none;border: 0px solid;margin: 8px 0px;padding: 0px;font-size: 16px;font-weight: 400;line-height: 24px;color: rgb(0, 0, 0);list-style-type: decimal;overflow-anchor: auto;"><p><span leaf=""><span textstyle="" style="font-size: 14px;">代理智能体与人类进行沟通</span></span></p></li><li style="-webkit-font-smoothing: antialiased;box-sizing: border-box;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: none;border: 0px solid;margin: 8px 0px;padding: 0px;font-size: 16px;font-weight: 400;line-height: 24px;color: rgb(0, 0, 0);list-style-type: decimal;overflow-anchor: auto;"><p><span leaf=""><span textstyle="" style="font-size: 14px;">协调智能体协调其他智能体的能力</span></span></p></li><li style="-webkit-font-smoothing: antialiased;box-sizing: border-box;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: none;border: 0px solid;margin: 8px 0px;padding: 0px;font-size: 16px;font-weight: 400;line-height: 24px;color: rgb(0, 0, 0);list-style-type: decimal;overflow-anchor: auto;"><p><span leaf=""><span textstyle="" style="font-size: 14px;">子目标以提示词形式传递给下一个智能体</span></span></p></li><li style="-webkit-font-smoothing: antialiased;box-sizing: border-box;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: none;border: 0px solid;margin: 8px 0px;padding: 0px;font-size: 16px;font-weight: 400;line-height: 24px;color: rgb(0, 0, 0);list-style-type: decimal;overflow-anchor: auto;"><p><span leaf=""><span textstyle="" style="font-size: 14px;">子智能体返回各自的输出结果</span></span></p></li><li style="-webkit-font-smoothing: antialiased;box-sizing: border-box;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: none;border: 0px solid;margin: 8px 0px;padding: 0px;font-size: 16px;font-weight: 400;line-height: 24px;color: rgb(0, 0, 0);list-style-type: decimal;overflow-anchor: auto;"><p><span leaf=""><span textstyle="" style="font-size: 14px;">多智能体系统（MAS）中的智能体可使用不同的大型语言模型（LLM）</span></span></p></li><li style="-webkit-font-smoothing: antialiased;box-sizing: border-box;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: none;border: 0px solid;margin: 8px 0px;padding: 0px;font-size: 16px;font-weight: 400;line-height: 24px;color: rgb(0, 0, 0);list-style-type: decimal;overflow-anchor: auto;"><p><span leaf=""><span textstyle="" style="font-size: 14px;">具备自我反思或自我批判能力</span></span></p></li><li style="-webkit-font-smoothing: antialiased;box-sizing: border-box;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: none;border: 0px solid;margin: 8px 0px;padding: 0px;font-size: 16px;font-weight: 400;line-height: 24px;color: rgb(0, 0, 0);list-style-type: decimal;overflow-anchor: auto;"><p><span leaf=""><span textstyle="" style="font-size: 14px;">构建人类与人工智能智能体的协作关系</span></span></p></li></ol></td></tr></tbody></table><p style="text-align: left;margin-top: 24px;"><span leaf="">上图中，“代理智能体（proxy agent</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">）”</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">负责协助用户或其他智能体通信。</span><span leaf=""> “协调智能体（orchestrator agent）” 定义为 “控制工作流程的智能体”—— 它了解工作流程中其他智能体的能力，负责协调各智能体的工作，还可能对其他智能体的成果进行检查。此外，上图展示了一个多智能体系统，其中可使用多个大型语言模型。</span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">多智能体系统目前是否已落地应用</span></span></p><p data-pm-slice="0 0 []"><span leaf="">多智能体系统目前已落地，但 2025 年它会变得更普及、更常见。预计2025年还会出现 “测试中心”—— 通过在智能体流程中运行 5000 个示例，快速判断流程是否 “通过” 或 “失败”。此外，“自我反思（self-reflection）” 功能的应用也会增多。</span></p><p data-pm-slice="0 0 []"><span leaf="">根据Garnter的定义，“自我反思” 或 “自我批判” 是智能体的常见要素。在前面的例子中，“批判智能体（critic agent）” 会对成果提供反馈，帮助人类查看其他内容建议。</span></p><p data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">“自我反思” 是否意味着智能体具备 “自学能力”</span></span></p><p data-pm-slice="0 0 []"><span leaf="">目前还不能这么说。更准确的描述是：工作流程中会加入 “自我反思环节”—— 该环节会检查已完成的工作，判断是否存在问题。若发现问题，会将工作成果与 “优缺点记录” 一同反馈给协调智能体，由协调智能体重新分配任务；若再次返回的结果仍不达标，任务会转交给人类处理。</span></p><p><span leaf="">预计2025 年，“自我反思” 会被广泛应用于多智能体工作流程，用于跟踪、双重检查和改进智能体的工作成果。</span></p><p><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">Agentic AI带来的风险</span></span></p><p data-pm-slice="0 0 []"><span leaf="">Gartner在 2025年7 月发布的报告《新兴技术：企业应用中自主式 AI 的未来》（</span><em><span leaf="">Emerging Tech: The Future of Agentic AI in Enterprise Applications</span></em><span leaf="">）中指出，Agentic AI 虽为自动化带来新可能，但也存在固有风险。</span></p><ol class="list-paddingleft-1" start="1"><li style="font-weight:bold;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">安全与合规</span></span></p></li></ol><p><span leaf="">在未充分理解Agentic AI 的情况下盲目采用，可能导致项目失败，并威胁安全与合规。由于智能体具备自主性，<span textstyle="" style="font-weight: bold;">其设计必须遵循 “安全优先” 原则 </span>—— 从初始阶段就将安全纳入考量。若缺乏保障措施，智能体系统可能采取违反法律法规的行动。</span></p><ol class="list-paddingleft-1" start="2"><li style="font-weight:bold;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">集成复杂性</span></span></p></li></ol><p><span leaf="">除 API 连接外，</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Agentic </span><span leaf="">AI 集成的核心挑战在于 “让决策逻辑与企业战略、风险容忍度对齐”。由于缺乏标准化与互操作性协议，这一过程可能尤为复杂。</span></p><ol class="list-paddingleft-1" start="3"><li style="font-weight:bold;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">信任与治理</span></span></p></li></ol><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Agentic  AI 的 “黑箱” 特性是主要障碍。若<span textstyle="" style="font-weight: bold;">缺乏透明度与可解释性</span>，其决策难以审计。</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Gartner</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">建议部署 “人机协同控制” 与 “审计跟踪系统”，确保智能体在安全、合规的边界内运行，同时让人类对高风险决策承担最终责任。</span></p><ol class="list-paddingleft-1" start="4"><li style="font-weight:bold;"><p><span leaf=""><span textstyle="" style="font-weight: bold;">技能迭代</span></span></p></li></ol><p><span leaf="">Agentic AI 接管低价值任务后，传统 “通过基础工作培养新员工” 的模式被打破，企业可能面临人才断层风险。Gartner建议，应调整培训方向 —— 教会新员工如何治理、协作智能体，而非重复机械任务。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">【注1】</span>原文链接：</span></p><blockquote><p><span leaf=""><a href="https://www.nojitter.com/ai-automation/conversations-in-collaboration-gartner-tom-coshow-on-ai-agents-and-agentic-ai" target="_blank">https://www.nojitter.com/ai-automation/conversations-in-collaboration-gartner-tom-coshow-on-ai-agents-and-agentic-ai</a></span></p></blockquote><p><span leaf=""><span textstyle="" style="font-weight: bold;">【注2】</span>Gartner报告：《</span><span leaf="">Executive Briefing on Emerging Technology: Agentic AI》</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">【注3】</span>Gartner报告：《</span><span leaf="">Emerging Tech: The Future of Agentic AI in Enterprise Applications</span><span leaf="">》</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">【参考】</span></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485048&amp;idx=1&amp;sn=4bceff5bb6514bacc86b69ce83b0fca1&amp;scene=21#wechat_redirect" textvalue="浅析SecOps中的AI Agent和Agentic AI，以及SOC自主化水平模型" data-itemshowtype="0" linktype="text" data-linktype="2">浅析SecOps中的AI Agent和Agentic AI，以及SOC自主化水平模型</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485064&amp;idx=1&amp;sn=1c65225911fa0875d1e68ab8600a1586&amp;scene=21#wechat_redirect" textvalue="国外Agentic SOC最新进展（2025Q3）" data-itemshowtype="0" linktype="text" data-linktype="2">国外Agentic SOC最新进展（2025Q3）</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247485079">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2a31573d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyNzMxOTAwMw%3D%3D%26mid%3D2247485079%26idx%3D1%26sn%3D86c2df034a23791da7b39aa42cba0fc6">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 03 Nov 2025 12:00:00 +0800</pubDate>
    </item>
    <item>
      <title>国外Agentic SOC最新进展（2025Q3）</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485064&amp;idx=1&amp;sn=1c65225911fa0875d1e68ab8600a1586</link>
      <description>分析微软、CrowdStrike、Splunk、Google等15个Agentic SOC最新发展动态</description>
      <content:encoded><![CDATA[<p>
原创 <span>Benny Ye</span> <span>2025-10-28 12:00</span> <span style="display: inline-block;">北京</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=2800a6ff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMeePH73WeAIL7FDGibXcUa45xSj88kZo1CypgaTHclNUJiaBQsTM7aoFjZ3OvibnsxWramhLahicB25aw%2F0%3Fwx_fmt%3Djpeg"/></p>

<p>分析微软、CrowdStrike、Splunk、Google等15个Agentic SOC最新发展动态</p>

<p><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">从笔者提出<a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484848&amp;idx=1&amp;sn=0f7f582e241603ec68bc85be3926998c&amp;scene=21#wechat_redirect" textvalue="用Agentic AI重塑SOC平台" data-itemshowtype="0" linktype="text" data-linktype="2">用Agentic AI重塑SOC平台</a></span></span><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">，并在5月21日正式发布了</span></span><span leaf=""><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="AI赋能+数据与流程双轮驱动的SOC4.0理念" data-itemshowtype="11" linktype="text" data-linktype="2">AI赋能+数据与流程双轮驱动的SOC4.0理念</a></span><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">和</span></span><span leaf=""><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzkzMzkzMjI4OQ==&amp;mid=2247483748&amp;idx=1&amp;sn=403a04f2e7ab7b101d5b34378f1853ba&amp;scene=21#wechat_redirect" textvalue="国内首个Agentic SOP" data-itemshowtype="0" linktype="text" data-linktype="2">国内首个Agentic SOP</a></span><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">产品，已经过去了半年。Agentic SOC或者Agentic SOP的概念正在盛行，今年以来，全球范围内Agentic SOP / SOC如雨后春笋般不断涌现。无论是<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484993&amp;idx=1&amp;sn=506b9c0de108b2293d71c15750f0d95c&amp;scene=21#wechat_redirect" textvalue="5月份的RSAC大会" data-itemshowtype="0" linktype="text" data-linktype="2">5月份的RSAC大会</a>上，还是<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485053&amp;idx=1&amp;sn=e2a7ec77a9a9e7fd7f32ed88e3549b83&amp;scene=21#wechat_redirect" textvalue="6月份的Gartner安全峰会" data-itemshowtype="0" linktype="text" data-linktype="2">6月份的Gartner安全峰会</a>上，AI赋能下的自主化安全运营（Agentic SecOps）都是热点议题。</span></span></p><p><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">笔者在《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485048&amp;idx=1&amp;sn=4bceff5bb6514bacc86b69ce83b0fca1&amp;scene=21#wechat_redirect" textvalue="浅析SecOps中的AI Agent和Agentic AI，以及SOC自主化水平模型" data-itemshowtype="0" linktype="text" data-linktype="2">浅析SecOps中的AI Agent和Agentic AI，以及SOC自主化水平模型</a>》一文中对相关概念进行了梳理，并给出了Agentic SOP/SOC的定义，以及SOP/SOC的自主化水平划分。</span></span></p><p><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">简单来说，<span textstyle="" style="font-weight: bold;">Agentic SOP/SOC就是指Agentic AI赋能的SOP/SOC，而这里的Agentic AI又主要指采用LLM作为思考中枢的，具有自主推理、规划和决策能力，能够调用各种工具自动完成预定目标的中高级智能体及多智能体协作集群</span>。但深入研究，Agentic SOP/SOC的关键特点还不止于此。让我们看看国际同行都是如何做的。</span></span></p><p><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">概览</span></span></span></p><p><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">下图展示了今年以来主要的一些Agentic SOC厂商的进展情况（截至10月初）。</span></span></p><p><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf=""><img data-imgfileid="100001415" class="rich_pages wxw-img" data-ratio="2.050749711649366" data-type="png" data-w="867" src="https://wechat2rss.xlab.app/img-proxy/?k=2d449475&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMeePH73WeAIL7FDGibXcUa45Dlr40kbF2gm7YGhBud9k8547A76LI85yibicgLKMDxS2uuhniayIZ1u8w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><p><span leaf="">上图对应表格如下：</span></p><table style="border-collapse:collapse;width:759px;"><tbody><tr style="height:28.0pt;"><td data-colwidth="48" width="64" style="height: 28pt;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">类别</span></span></p></td><td data-colwidth="95" width="95" style="border-left: none;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">厂商名称</span></span></p></td><td data-colwidth="111" width="111" style="border-left: none;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">关键 Agentic AI   产品/能力</span></span></p></td><td data-colwidth="112" width="119" style="border-left: none;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">发布时间 (最新或重大发布)</span></span></p></td><td data-colwidth="187" width="187" style="border-left: none;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">描述</span></span></p></td><td data-colwidth="206" width="206" style="border-left: none;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">发布链接</span></span></p></td></tr><tr style="height:70.0pt;"><td rowspan="5" data-colwidth="48" width="64" style="height: 420pt;border-top: none;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">大型综合性安全厂商</span></span></p></td><td data-colwidth="95" width="95" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">CrowdStrike</span></span></span></td><td data-colwidth="111" width="111" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Charlotte AI / Falcon agentic security platform</span></span></span></td><td data-colwidth="112" width="119" align="right" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">2025年9月16日</span></span></span></td><td data-colwidth="187" width="187" style="border-top: none;border-left: none;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">利用智能体自动对威胁告警进行分类、优先级排序和初步调查，并推出了用于构建自定义智能体的   AgentWorks 平台。</span></span></p></td><td data-colwidth="206" width="206" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;"><a href="https://ir.crowdstrike.com/news-releases/news-release-details/crowdstrike-unleashes-agentic-security-workforce-transform" target="_blank">https://ir.crowdstrike.com/news-releases/news-release-details/crowdstrike-unleashes-agentic-security-workforce-transform</a></span></span></span></td></tr><tr style="height:84.0pt;"><td data-colwidth="95" width="95" style="height: 84pt;border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Fortinet</span></span></span></td><td data-colwidth="111" width="111" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">FortiAI / FortiAnalyzer</span></span></span></td><td data-colwidth="112" width="119" align="right" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">2025年4月8日</span></span></span></td><td data-colwidth="187" width="187" style="border-top: none;border-left: none;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">将   Agentic 能力整合到 Fortinet Security Fabric 中，通过 AI 引擎增强威胁检测和自动化操作。</span></span></p></td><td data-colwidth="206" width="206" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;"><a href="https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2025/fortinet-expands-fortiai-across-its-security-fabric-platform" target="_blank">https://www.fortinet.com/corporate/about-us/newsroom/press-releases/2025/fortinet-expands-fortiai-across-its-security-fabric-platform</a></span></span></span></td></tr><tr style="height:98.0pt;"><td data-colwidth="95" width="95" style="height: 98pt;border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Palo Alto Networks</span></span></span></td><td data-colwidth="111" width="111" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Cortex XSIAM (Precision AI)</span></span></span></td><td data-colwidth="112" width="119" align="right" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">2025年4月28日</span></span></span></td><td data-colwidth="187" width="187" style="border-top: none;border-left: none;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">融合   Precision AI 技术驱动 Cortex XSIAM 平台，通过自主安全操作实现类似 Agentic 的自动化调查和响应能力。</span></span></p></td><td data-colwidth="206" width="206" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;"><a href="https://www.paloaltonetworks.com/company/press/2024/palo-alto-networks-launches-new-security-solutions-infused-with-precision-ai-to-defend-against-advanced-threats-and-safeguard-ai-adoption" target="_blank">https://www.paloaltonetworks.com/company/press/2024/palo-alto-networks-launches-new-security-solutions-infused-with-precision-ai-to-defend-against-advanced-threats-and-safeguard-ai-adoption</a></span></span></span></td></tr><tr style="height:84.0pt;"><td data-colwidth="95" width="95" style="height: 84pt;border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">SentinelOne</span></span></span></td><td data-colwidth="111" width="111" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Purple AI (雅典娜 - Athena)</span></span></span></td><td data-colwidth="112" width="119" align="right" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">2025年9月11日</span></span></span></td><td data-colwidth="187" width="187" style="border-top: none;border-left: none;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">内建于   Singularity 平台的 Agentic AI 分析师，能够像经验丰富的防御者一样进行深度推理和自主响应。</span></span></p></td><td data-colwidth="206" width="206" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;"><a href="https://status.n-able.com/2025/09/17/sentinelone-purple-ai-is-now-generally-available-conversational-threat-hunting-for-every-soc/" target="_blank">https://status.n-able.com/2025/09/17/sentinelone-purple-ai-is-now-generally-available-conversational-threat-hunting-for-every-soc/</a></span></span></span></td></tr><tr style="height:84.0pt;"><td data-colwidth="95" width="95" style="height: 84pt;border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Splunk (思科旗下)</span></span></span></td><td data-colwidth="111" width="111" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Agentic AI powered Splunk ES</span></span></span></td><td data-colwidth="112" width="119" align="right" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">2025年9月9日</span></span></span></td><td data-colwidth="187" width="187" style="border-top: none;border-left: none;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">推出基于   Agentic AI 的 Splunk Enterprise Security 新版本，旨在统一 TDIR 工作流程，集成在 Splunk 平台中。</span></span></p></td><td data-colwidth="206" width="206" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;"><a href="https://www.splunk.com/en_us/newsroom/press-releases/2025/cisco-elevates-the-soc-with-agentic-ai-for-faster-threat-response-and-reduced-complexity.html" target="_blank">https://www.splunk.com/en_us/newsroom/press-releases/2025/cisco-elevates-the-soc-with-agentic-ai-for-faster-threat-response-and-reduced-complexity.html</a></span></span></span></td></tr><tr style="height:70.0pt;"><td rowspan="7" data-colwidth="48" width="64" style="height: 546pt;border-top: none;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">创新型/AI原生安全公司</span></span></p></td><td data-colwidth="95" width="95" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Darktrace</span></span></span></td><td data-colwidth="111" width="111" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Cyber AI Analyst</span></span></span></td><td data-colwidth="112" width="119" align="right" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">2025年4月16日</span></span></span></td><td data-colwidth="187" width="187" style="border-top: none;border-left: none;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">作为   Darktrace 平台（SIEM/NDR）的附加组件，能够自主调查安全警报。</span></span></p></td><td data-colwidth="206" width="206" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;"><a href="https://www.darktrace.com/news/darktrace-unveils-new-ai-models-in-cyber-ai-analyst-tm-to-enhance-proactive-security-operations" target="_blank">https://www.darktrace.com/news/darktrace-unveils-new-ai-models-in-cyber-ai-analyst-tm-to-enhance-proactive-security-operations</a></span></span></span></td></tr><tr style="height:56.0pt;"><td data-colwidth="95" width="95" style="height: 56pt;border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Dropzone AI</span></span></span></td><td data-colwidth="111" width="111" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Autonomous SOC Triage Agent</span></span></span></td><td data-colwidth="112" width="119" align="right" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">2025年10月7日</span></span></span></td><td data-colwidth="187" width="187" style="border-top: none;border-left: none;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">专注于利用智能体自动执行   Tier-1 告警分类、调查和响应，作为一个独立的云原生平台运行。</span></span></p></td><td data-colwidth="206" width="206" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;"><a href="https://www.dropzone.ai/blog/what-is-agentic-ai-exploring-its-role-in-security-operations" target="_blank">https://www.dropzone.ai/blog/what-is-agentic-ai-exploring-its-role-in-security-operations</a></span></span></span></td></tr><tr style="height:98.0pt;"><td data-colwidth="95" width="95" style="height: 98pt;border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Exaforce</span></span></span></td><td data-colwidth="111" width="111" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Agentic SOC Platform</span></span></span></td><td data-colwidth="112" width="119" align="right" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">2025年8月26日</span></span></span></td><td data-colwidth="187" width="187" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">AI 原生的 SOC 平台。利用智能体“Exabots”，专注于自主执行 SOC 全生命周期任务。</span></span></span></td><td data-colwidth="206" width="206" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;"><a href="https://www.prnewswire.com/news-releases/exaforce-brings-ai-to-the-entire-security-operations-lifecycle--elevating-the-ai-soc-beyond-just-tier-1-analysts-302538074.html" target="_blank">https://www.prnewswire.com/news-releases/exaforce-brings-ai-to-the-entire-security-operations-lifecycle--elevating-the-ai-soc-beyond-just-tier-1-analysts-302538074.html</a></span></span></span></td></tr><tr style="height:112.0pt;"><td data-colwidth="95" width="95" style="height: 112pt;border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Prophet Security</span></span></span></td><td data-colwidth="111" width="111" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">AI SOC Analyst / Platform</span></span></span></td><td data-colwidth="112" width="119" align="right" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">2025年7月29日</span></span></span></td><td data-colwidth="187" width="187" style="border-top: none;border-left: none;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">专注于   AI 原生的 SOC 平台，作为一个独立的解决方案部署自主 AI 智能体。</span></span></p></td><td data-colwidth="206" width="206" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;"><a href="https://www.businesswire.com/news/home/20250729681026/en/Prophet-Security-Raises-%2430M-Series-A-Announces-Industrys-Most-Comprehensive-Agentic-AI-SOC-Platform-to-Transform-Security-Operations" target="_blank">https://www.businesswire.com/news/home/20250729681026/en/Prophet-Security-Raises-%2430M-Series-A-Announces-Industrys-Most-Comprehensive-Agentic-AI-SOC-Platform-to-Transform-Security-Operations</a></span></span></span></td></tr><tr style="height:70.0pt;"><td data-colwidth="95" width="95" style="height: 70pt;border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Radiant Security</span></span></span></td><td data-colwidth="111" width="111" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Adaptive AI SOC Platform</span></span></span></td><td data-colwidth="112" width="119" align="right" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">2025年4月10日</span></span></span></td><td data-colwidth="187" width="187" style="border-top: none;border-left: none;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">提供能够自主执行   TDIR 任务的 智能体，专注于作为一个独立的自适应平台。</span></span></p></td><td data-colwidth="206" width="206" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;"><a href="https://www.cybersecuritytribe.com/cyber-security-announcements/radiant-security-unveils-the-first-adaptive-ai-soc-platform" target="_blank">https://www.cybersecuritytribe.com/cyber-security-announcements/radiant-security-unveils-the-first-adaptive-ai-soc-platform</a></span></span></span></td></tr><tr style="height:56.0pt;"><td data-colwidth="95" width="95" style="height: 56pt;border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">ReliaQuest</span></span></span></td><td data-colwidth="111" width="111" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">GreyMatter (Agentic Teammates)</span></span></span></td><td data-colwidth="112" width="119" align="right" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">2025年7月29日</span></span></span></td><td data-colwidth="187" width="187" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">GreyMatter 平台本身作为一个独立的编排层，连接不同的安全工具并提供 Agentic 能力。</span></span></span></td><td data-colwidth="206" width="206" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;"><a href="https://reliaquest.com/news-and-press/reliaquest-announces-industrys-first-role-based-agentic-ai-teammates/" target="_blank">https://reliaquest.com/news-and-press/reliaquest-announces-industrys-first-role-based-agentic-ai-teammates/</a></span></span></span></td></tr><tr style="height:84.0pt;"><td data-colwidth="95" width="95" style="height: 84pt;border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Sumo Logic</span></span></span></td><td data-colwidth="111" width="111" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Dojo AI</span></span></span></td><td data-colwidth="112" width="119" align="right" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">2025年9月22日</span></span></span></td><td data-colwidth="187" width="187" style="border-top: none;border-left: none;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">云原生   SIEM 平台的最新 Agentic AI 能力，提供专门的智能体来自动化分析师工作流并加速调查。</span></span></p></td><td data-colwidth="206" width="206" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;"><a href="https://www.sumologic.com/newsroom/sumo-logic-brings-agentic-ai-into-enterprise-security-stack-with-launch-of-dojo-ai-on-amazon-web-services" target="_blank">https://www.sumologic.com/newsroom/sumo-logic-brings-agentic-ai-into-enterprise-security-stack-with-launch-of-dojo-ai-on-amazon-web-services</a></span></span></span></td></tr><tr style="height:70.0pt;"><td rowspan="5" data-colwidth="48" width="64" style="height: 294pt;border-top: none;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">综合性技术巨头 (平台提供商)</span></span></p></td><td data-colwidth="95" width="95" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">AWS</span></span></span></td><td data-colwidth="111" width="111" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Amazon Bedrock Agents / AgentCore</span></span></span></td><td data-colwidth="112" width="119" align="right" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">2025年7月16日</span></span></span></td><td data-colwidth="187" width="187" style="border-top: none;border-left: none;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">提供构建   Agentic AI 应用的底层服务和开发框架，需要客户自主构建。</span></span></p></td><td data-colwidth="206" width="206" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;"><a href="https://aws.amazon.com/blogs/aws/introducing-amazon-bedrock-agentcore-securely-deploy-and-operate-ai-agents-at-any-scale/" target="_blank">https://aws.amazon.com/blogs/aws/introducing-amazon-bedrock-agentcore-securely-deploy-and-operate-ai-agents-at-any-scale/</a></span></span></span></td></tr><tr style="height:70.0pt;"><td rowspan="3" data-colwidth="95" width="95" style="height: 154pt;border-top: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Google</span></span></span></td><td rowspan="3" data-colwidth="111" width="111" style="border-top: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Google Security Operations (AI features)</span></span></span></td><td rowspan="3" data-colwidth="112" width="119" align="right" style="border-top: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">2025年8月</span></span></span></td><td rowspan="3" data-colwidth="187" width="187" style="border-top: none;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">在其安全运营平台中引入由   Agentic AI 驱动的系统，旨在实时检测和应对威胁。</span></span></p></td><td rowspan="3" data-colwidth="206" width="206" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;"><a href="https://cloud.google.com/blog/products/identity-security/security-summit-2025-enabling-defenders-and-securing-ai-innovation" target="_blank">https://cloud.google.com/blog/products/identity-security/security-summit-2025-enabling-defenders-and-securing-ai-innovation</a></span></span></span></td></tr><tr style="height:14.0pt;"></tr><tr style="height:70.0pt;"></tr><tr style="height:70.0pt;"><td data-colwidth="95" width="95" style="height: 70pt;border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Microsoft</span></span></span></td><td data-colwidth="111" width="111" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">Sentinel / Security Copilot (Agentic Features)</span></span></span></td><td data-colwidth="112" width="119" align="right" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;">2025年9月30日</span></span></span></td><td data-colwidth="187" width="187" style="border-top: none;border-left: none;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">作为微软安全生态系统（Defender/Sentinel）的附加组件，提供具备   Agentic 能力的安全助手。</span></span></p></td><td data-colwidth="206" width="206" style="border-top: none;border-left: none;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 12px;"><a href="https://www.microsoft.com/en-us/security/blog/2025/09/30/empowering-defenders-in-the-era-of-agentic-ai-with-microsoft-sentinel/" target="_blank">https://www.microsoft.com/en-us/security/blog/2025/09/30/empowering-defenders-in-the-era-of-agentic-ai-with-microsoft-sentinel/</a></span></span></span></td></tr></tbody></table><p style="margin-top: 24px;"><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span leaf="">笔者将Agentic SOC领域的玩家分为三类：大型综合性安全厂商、创新型中小安全公司、综合性技术巨头（云厂商）。</span></span></p><p style="margin-top: 24px;"><span leaf="">以下针对几个代表性的Agentic SOC产品和服务的最新动态进行介绍<span textstyle="" style="color: rgb(0, 82, 255);">【注：以下厂商都明确提出了Agentic SOC这个术语，对应笔者的Agentic SOP（安全运营平台），笔者认为SOP比SOC更加贴切，平台不是中心】</span>。</span></p><p><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">微软</span></span></span></p><p><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">2025年9月底，微软发布了全新的基于Agentic AI赋能的</span><span leaf="">Sentinel 和 Security Copilot版本。</span></span></p><p style="text-align: center;"><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span leaf=""><img data-imgfileid="100001412" class="rich_pages wxw-img" data-ratio="0.7268351383874849" data-type="png" data-w="831" src="https://wechat2rss.xlab.app/img-proxy/?k=aadb004d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMeePH73WeAIL7FDGibXcUa45FDcLYPNEHE0ztyuQibl6NxicQxLDrYY2EbhcsiackVFTGQH6d8VNDMF2Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span></p><div><p style="margin-top: 24px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgba(0, 0, 0, 0.9);font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">上图展示了最新的Sentinel的功能架构。底层是新发布的数据湖解决方案，并在上面新增了图数据存储与分析能力。再往上是新增的MCP Server层，是微软最新发布的功能，</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">允许智能体使用开放标准访问和推理统一数据，从而实现更快、更智能的威胁检测和响应。</span></p><div style="margin-top: 24px;"><p style="margin-top: 24px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:null},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">基于上述架构，微软表示，“Sentinel扩展成为一个自主化平台（Agentic Platform），凭借基于图形的上下文、语义访问和智能体编排，为防御者提供了一个单一平台来提取信号、跨域关联，并通过MCP Server调用各种智能体实现自主化安全运营”。</span></p></div><p style="margin-top: 24px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">除了对Sentinel的升级，微软还升级了Security Copilot，变成了一个智能体管理和运行平台，并被Sentinel的MCP Server调用，赋能Sentinel。</span></p><p style="margin-top: 24px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">Security Copilot一方面充当了智能体的运行平台，另一方面也管理着所有的智能体，并支持从微软最新发布的Security Store中下载各种微软自己的和第三方的智能体（目前有7个智能体可选）。与此同时，Security Copilot还新增了</span><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">一个无代码智能体构建器，允许客户使用自然语言命令创建、优化和发布智能体。最后，Security Copilot不仅可以赋能Sentinel，还可以赋能微软其它安全产品（譬如Defender、Entra、Intune、Purview）。</span></p><p style="margin-top: 24px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">简单小结一下，微软此次对其安全运营平台的升级不仅体现在将其核心GenAI组件Security Copilot系统变成了一个智能体运行、管理和开发平台，还升级了安全运营平台的底座，通过为Sentinel平台<span textstyle="" style="font-weight: bold;">新增数据湖能力、图存储与分析能力</span>、MCP服务器，实现了安全运营平台的数据架构升级，从而更好地发挥智能体的作用。这充分印证了笔者一直以来的一个重要观点：<span textstyle="" style="color: rgb(0, 82, 255);font-weight: normal;">要实现自主化（Agentic）安全运营平台，不仅要要利用Agentic AI和智能体技术，还需要重构平台的数据架构和流程架构</span>！</span></p><p style="margin-top: 24px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;"><span textstyle="" style="font-size: 24px;font-weight: bold;">谷歌</span></span></p><p style="margin-top: 24px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">Google最初是在<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484993&amp;idx=1&amp;sn=506b9c0de108b2293d71c15750f0d95c&amp;scene=21#wechat_redirect" textvalue="RSAC2025" data-itemshowtype="0" linktype="text" data-linktype="2">RSAC2025</a>上发布了他们的Agentic SOC愿景，</span><span leaf="">以期通过互联互通的多智能体技术，代表防御者自主或半自主地执行安全运营工作流程。Google表示，“</span><span leaf="">通过提供<span textstyle="" style="font-weight: bold;">基于优化数据管道</span>、自动化警报分类、调查和响应而构建的主动式、智能体支持的防御能力，Agentic SOC可以简化检测工程工作流程，以解决覆盖漏洞并创建新的以威胁为导向的检测。</span><span leaf="">”可见，<span textstyle="" style="color: rgb(0, 82, 255);">Google同样认为要实现Agentic SOC，不仅是要应用智能体技术，还需要优化底层的数据架构（数据管道）</span>。</span></p><p style="margin-top: 24px;text-align: center;"><span leaf=""><img data-imgfileid="100001413" alt="https://storage.googleapis.com/gweb-cloudblog-publish/images/3_Agentic_SOC.max-1100x1100.png" class="rich_pages wxw-img" data-ratio="0.512962962962963" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=3476b854&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMeePH73WeAIL7FDGibXcUa45nPjiabgSNOhynz8LPssvmj7IRCV1iamDS2WjD0ZM4nYXxR54H5R9BcFQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="margin-top: 24px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;">2025年8月份，Google对外发布了告警调查智能体的预览版。该智能体</span><span leaf="">对告警的判定结果会附带人工干预的下一步建议，可大幅减少人工工作量，同时缩短响应时间。</span></p><p style="margin-top: 24px;"><span leaf="">此外，Google还升级了其统一安全运营平台，由Gemini作为LLM支撑，深化了其与收购来的SOAR平台（Siemplify）的融合（推出新的仪表板），发布了新的SecOps实验室功能，便于早期用户实验新的安全运营功能。</span></p><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">CrowdStrike</span></span></p><p style="margin-top: 24px;"><span leaf="">CrowdStrike在Agentic SOC方面投入很大，在2025年9月下旬的秋季发布版本中，正式将Falcon平台升级为Falcon Agentic Security Platform，并将以此打造Agentic SOC，称其“专为Agentic时代而设计”。</span></p><p style="margin-top: 24px;"><span leaf="">CrowdStrike表示：“</span><span leaf="">在此平台中，分析师从操作员提升为协调者，他们指挥着一群能够推理、决策、行动并持续学习的智能代理，</span><span leaf="">人类和 AI 代理将并肩工作”。</span></p><p style="margin-top: 24px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">这一版Falcon Agentic Security Platform的三个关键是：新的数据架构、智能体开发工具、预置7个智能体。</span></p><p style="margin-top: 24px;"><span leaf="">全新的CrowdStrike Enterprise Graph提供业内最丰富的 AI 就绪数据层，将跨终端、身份、云、SaaS、XIoT 和第三方工具的遥测数据统一到一个动态互联的企业模型中。</span></p><p style="margin-top: 24px;"><span leaf="">全新的智能提开发工具Charlotte AI AgentWorks 赋能每个安全团队成为 AI 构建者。分析师可以使用简单的语言创建和自定义符合其工作流程和策略的智能体，无需任何代码。智能体在 Falcon 平台内设计、测试并即时部署，内置企业级安全和治理功能。这些特定于任务的智能体可以自动化调查，减少人工工作，并加快响应速度。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001414" class="rich_pages wxw-img" data-ratio="0.7444444444444445" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=a595f493&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMeePH73WeAIL7FDGibXcUa45C80QImxsnQycsPqXYx3bgKUqEcmLX4nbkuVfAKP1YviaA7ib8YliayNCw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-top: 24px;margin-bottom: 0px;"><span leaf="">同时，CrowdStrike发布了第一批7个安全运营智能体：</span></p><ol style="list-style-type: decimal;" class="list-paddingleft-1" start="1"></ol><ol style="list-style-type: decimal;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">暴露优先级排序智能体</span>（Exposure Prioritization Agent）：基于真实世界漏洞被利用的可能性自动分类，大幅缩减漏洞处理积压清单；</span></p></li><li><p><span leaf="">恶意软件分析智能体（Malware Analysis Agent）：自动分析可疑文件，关联已知威胁信息，并能随着威胁情报的更新，回溯检索历史数据以发现新风险；</span></p></li><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">威胁狩猎智能体</span>（Hunt Agent）：持续监测环境，主动搜寻 CrowdStrike 威胁情报已识别的隐藏威胁，同时提供后续行动步骤，助力团队快速根据检测结果采取措施；</span></p></li><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">关联规则生成智能体</span>（Correlation Rule Generation Agent）：针对高级威胁与内部风险，推荐并优化检测规则；</span></p></li><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">搜索分析智能体</span>（Search Analysis Agent）：在几秒内汇总并解读查询结果，将原本需数小时的人工分析工作大幅简化；</span></p></li><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">SOAR剧本生成智能体</span>（Workflow Generation Agent）：无需代码开发，即可将自然语言指令转化为 CrowdStrike Falcon® Fusion SOAR平台中的自动化工作流；</span></p></li><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">数据转换智能体</span>（Data Transformation Agent）：对跨工具数据进行标准化处理与格式转换，消除阻碍自动化效率的各类数据错误。</span></p></li></ol><p style="margin-top: 24px;"><span leaf="">此外，就在2025年8月27日，CrowdStrike宣布收购独立的数据管道（数据编织）厂商Onum，以进一步夯实未来Agentic SOC的数据底座。笔者认为，</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: normal;">CrowdStrike收购Onum</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: normal;">充分体现了以数据编织为基础的新一代数据架构在Agentic SOC中的重要作用</span>。</span></p><p style="margin-top: 24px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">在发布会上，CrowdStrike为大家畅想了一番未来的Agentic SOC：</span></p><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">速度</span>：自动化耗时任务，缩短调查和响应时间</span></p></li><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">规模</span>：无需增加员工数量，AI 队友即可增加分析师能力</span></p></li><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">信心</span>：受管控、可解释的人工智能，并具有企业级监督</span></p></li><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">整合</span>：一个传感器、一个控制台和一个平台，消除复杂性和工具疲劳</span></p></li></ul><p style="margin-top: 24px;"><span leaf="">小结一下，可以看出<span textstyle="" style="color: rgb(0, 82, 255);">CrowdStrike跟微软在Agentic SOC落地上有多相似之处，比如都强调底层数据架构，都发布了图分析能力，都发布了智能体开发功能，支持自定义智能体，都发布了一系列智能体</span>。</span></p><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">Splunk</span></span></p><p style="margin-top: 24px;"><span leaf="">2025年9月份，已经纳入思科旗下的Splunk也发布了Agentic SOC产品——新版的Splunk </span><span leaf="">Enterprise Security系列套件。新版本以Agentic AI为核心，</span><span leaf="">简化了产品组合，为客户提供更快的威胁响应和更简化的安全解决方案。此次发布的</span><span leaf="">一系列AI功能，“旨在为未来的Agentic SOC提供支持，使分析师能够专注于战略决策，而AI则负责日常任务”。</span></p><p style="margin-top: 24px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">同时，</span><span leaf="">Splunk发布了6个智能体（预计2026年GA）：</span></p><ol style="list-style-type: decimal;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">分诊智能体</span>（Triage Agent）：基于AI的分诊功能可对警报进行评估、优先级排序并提供解释（即便针对低频次、长尾场景的警报），减轻分析师工作量，同时突出显示最关键的信息。</span></p></li><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">恶意软件逆向智能体</span>（Malware Reversal Agent）：基于AI的逆向分析功能可逐行解析恶意脚本、提取入侵指标（IOC）、标记规避行为，并对重复出现的恶意行为进行归类。</span></p></li><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">AI剧本编写智能体</span>（AI Playbook Authoring）：将自然语言描述的需求转化为可运行、已测试的 SOAR 剧本，AI在整个编写过程中提供全程辅助。</span></p></li><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">响应导入器</span>（Response Importer）：智能体可遵循 SOC 定义的标准操作程序（SOP），并利用多模态大型语言模型（LLMs）将 SOP 导入企业安全响应计划中。</span></p></li><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">人工智能增强型检测库</span>（AI-Enhanced Detection Library）：帮助检测规则从假设阶段快速落地到生产环境，整个过程仅需数分钟。</span></p></li><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">个性化检测 SPL 生成器</span>（Personalized Detection SPL Generator）：根据 SOC 独特的环境特征，对检测库中的规则进行个性化调整，实现 “开箱即用”。</span></p></li></ol><p style="margin-top: 24px;"><span leaf="">此外，为了应对日趋激烈的竞争，此次发布的Splunk ES高级版将原本独立的SIEM、SOAR、UEBA和AI助理打包到一起，整合成一个具有统一用户体验的融合型安全运营平台。</span></p><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">总结</span></span></p><p style="margin-top: 24px;"><span leaf="">毫无疑问，Agentic SOC/SOP（<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="自主化安全运营中心/安全运营平台" data-itemshowtype="11" linktype="text" data-linktype="2">自主化安全运营中心/安全运营平台</a>）已经成为安全运营未来发展的大势所趋。而Agentic SOC/SOP要成功落地，<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484848&amp;idx=1&amp;sn=0f7f582e241603ec68bc85be3926998c&amp;scene=21#wechat_redirect" textvalue="不仅需要Agentic AI（自主式AI）赋能" data-itemshowtype="0" linktype="text" data-linktype="2">不仅需要Agentic AI（自主式AI）赋能</a>，还需要<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484854&amp;idx=1&amp;sn=81ac539adfe55fca334828b7e82002e5&amp;scene=21#wechat_redirect" textvalue="重塑SOP的底层架构" data-itemshowtype="0" linktype="text" data-linktype="2">重塑SOP的底层架构</a>，包括数据架构和流程架构。笔者作为<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkzMzkzMjI4OQ==&amp;mid=2247483748&amp;idx=1&amp;sn=403a04f2e7ab7b101d5b34378f1853ba&amp;scene=21#wechat_redirect" textvalue="这个大潮中的一员" data-itemshowtype="0" linktype="text" data-linktype="2">这个大潮中的一员</a>，也在奋力拼搏。<img style="display:inline-block;width:20px;vertical-align:middle;background-size:cover;" class="rich_pages wxw-img" data-ratio="1" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=f4b1d93b&amp;u=https%3A%2F%2Fres.wx.qq.com%2Ft%2Fwx_fed%2Fwe-emoji%2Fres%2Fassets%2Fnewemoji%2FAddoil.png"/><img style="display:inline-block;width:20px;vertical-align:middle;background-size:cover;" class="rich_pages wxw-img" data-ratio="1" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=f4b1d93b&amp;u=https%3A%2F%2Fres.wx.qq.com%2Ft%2Fwx_fed%2Fwe-emoji%2Fres%2Fassets%2Fnewemoji%2FAddoil.png"/><img style="display:inline-block;width:20px;vertical-align:middle;background-size:cover;" class="rich_pages wxw-img" data-ratio="1" data-w="20" src="https://wechat2rss.xlab.app/img-proxy/?k=f4b1d93b&amp;u=https%3A%2F%2Fres.wx.qq.com%2Ft%2Fwx_fed%2Fwe-emoji%2Fres%2Fassets%2Fnewemoji%2FAddoil.png"/></span></p><p style="margin-top: 24px;"><span leaf="">后续，笔者将陆续分享从用户和集成商视角对Agentic SOC的感受，国内Agentic SOC的最新发展动态，以及国内外第三方咨询机构对Agentic SOC的不同观点。敬请期待。</span></p><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="font-weight: bold;">【参考】</span></span></p><p style="margin-top: 24px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485048&amp;idx=1&amp;sn=4bceff5bb6514bacc86b69ce83b0fca1&amp;scene=21#wechat_redirect" textvalue="浅析SecOps中的AI Agent和Agentic AI，以及SOC自主化水平模型" data-itemshowtype="0" linktype="text" data-linktype="2">浅析SecOps中的AI Agent和Agentic AI，以及SOC自主化水平模型</a></span></p><p style="margin-top: 24px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="迈向AI赋能的SOC4.0时代" data-itemshowtype="11" linktype="text" data-linktype="2">迈向AI赋能的SOC4.0时代</a></span></p><p style="margin-top: 24px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485053&amp;idx=1&amp;sn=e2a7ec77a9a9e7fd7f32ed88e3549b83&amp;scene=21#wechat_redirect" textvalue="从Gartner2025年北美安全峰会看安全运营的发展趋势" data-itemshowtype="0" linktype="text" data-linktype="2">从Gartner2025年北美安全峰会看安全运营的发展趋势</a></span></p><p style="margin-top: 24px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484993&amp;idx=1&amp;sn=506b9c0de108b2293d71c15750f0d95c&amp;scene=21#wechat_redirect" textvalue="从RSAC2025看安全运营技术发展趋势" data-itemshowtype="0" linktype="text" data-linktype="2">从RSAC2025看安全运营技术发展趋势</a></span></p><p style="margin-top: 24px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484842&amp;idx=1&amp;sn=38dba05e2a0024b71d81d1d9b3e74a6c&amp;scene=21#wechat_redirect" textvalue="2024年安全运营技术趋势回顾" data-itemshowtype="0" linktype="text" data-linktype="2">2024年安全运营技术趋势回顾</a></span></p><p style="margin-top: 24px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkzMzkzMjI4OQ==&amp;mid=2247483748&amp;idx=1&amp;sn=403a04f2e7ab7b101d5b34378f1853ba&amp;scene=21#wechat_redirect" textvalue="自主化安全运营平台技术解析与实践" data-itemshowtype="0" linktype="text" data-linktype="2">自主化安全运营平台技术解析与实践</a></span></p></div><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247485064">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a8d56aab&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyNzMxOTAwMw%3D%3D%26mid%3D2247485064%26idx%3D1%26sn%3D1c65225911fa0875d1e68ab8600a1586">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 28 Oct 2025 12:00:00 +0800</pubDate>
    </item>
    <item>
      <title>从Gartner2025年北美安全峰会看安全运营的发展趋势</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485053&amp;idx=1&amp;sn=e2a7ec77a9a9e7fd7f32ed88e3549b83</link>
      <description>未来的安全运营：依托生态型平台，采用AI增强的流程，构建主被动结合的能力，采用混合式团队进行运营。</description>
      <content:encoded><![CDATA[<p>
原创 <span>Benny Ye</span> <span>2025-10-23 12:02</span> <span style="display: inline-block;">北京</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=dd216a36&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMcW5IG0ib1OcibgHc97NqwYicgOVfYmlQomkrCvfeIV8OXdbg3amrBLYLicPw6fc3D3ySq8FeMNC2kHPg%2F0%3Fwx_fmt%3Djpeg"/></p>

<p>未来的安全运营：依托生态型平台，采用AI增强的流程，构建主被动结合的能力，采用混合式团队进行运营。</p>

<p><span leaf=""><span textstyle="" style="font-style: italic;">【摘要】本文首先介绍了2025年Gartner北美安全峰会上提出的2025年3个重要网络安全技术，然后详细分析了2025年安全运营4个展望，并据此给出了笔者对未来安全运营发展的4个研判：依托生态型平台，构建主被动结合的能力，组建</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-style: italic;">混合式团队，采用AI增强的流程。</span></span></p><p><span leaf="">2025年6月初，一年一度的Gartner最大规模的安全与风险峰会在美国举行。本次大会上，AI、尤其是GenAI和AI Agent无疑成为了焦点，除了如何将AI赋能安全的各个领域，更多则是聚焦AI自身的安全。</span></p><p><span leaf="">本文结合此次峰会的材料，以及Gartner相关的报告，着重分析2025年的网络安全运营（SecOps）技术发展趋势。</span></p><p><span leaf=""><span textstyle="" style="font-size: 24px;color: rgb(0, 82, 255);font-weight: bold;">关键要点</span></span></p><ol style="list-style-type: decimal;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">2025年重要的网络安全技术包括：LLM防火墙、xSPM、安全平台。</span></span></p></li><li><p><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">2025年安全运营领域的四个展望是：最佳单品与生态（平台）之争日趋激烈、混合式安全运营团队已成定局、暴露管理成为安全运营必备、AI增强而非取代安全运营人员。</span></span></p></li><li><p><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">结合Gartner对当前安全运营的展望，笔者给出未来安全运营的发展趋势：</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">安全运营的平台架构是生态型的，安全运营的组织结构是混合式的，安全运营的关键能力是主被动结合的，安全运营的工作过程是自主化的。</span></span></p></li></ol><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">2025年重要的网络安全技术</span></span></p><p><span leaf="">在《2025年重要网络安全技术》议程中，Neil </span><span leaf="">MacDonald从保障GenAI使用安全、新兴的主动与预防性安全技术、平台融合三个方面给出了三类需要重点关注的网络安全技术。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">1）用LLM防火墙保障GenAI使用安全</span></span></p><p><span leaf="">根据Gartner的一项调查，GenAI位居2025年安全投资之首。因此如何保障GenAI的安全成为关键，AI TRiSM（AI信任、风险与安全管理）技术框架，尤其是这个框架中的AI运行检查与执行技术（</span><span leaf="">指在AI系统运行过程中，对其进行实时监测、分析和控制，以确保系统的安全性、可靠性和合规性的一系列技术和措施</span><span leaf="">）十分重要。而这个技术的一个具体表现形式就是<span textstyle="" style="font-weight: bold;">LLM防火墙</span><span textstyle="" style="font-weight: normal;">（如下图所示）</span>。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001373" class="rich_pages wxw-img" data-ratio="0.41759259259259257" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=05df1f23&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdVNzO2cVnA4Oy5KtDf7BvZHv6LPPoU921yrhbdfvtAzFC5K0gdDibF2GSP1jlbE174NjFaxOP70xQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">2）以xSPM为代表的主动与预防性安全技术</span></span></p><p><span leaf="">Neil将自己的CARTA架构（前身是自适应安全架构）与NIST的CSF做了一个整合，并将整个闭环划分为主动安全和被动安全两个维度（如下图所示）。</span></p><p><span leaf=""><img data-imgfileid="100001376" class="rich_pages wxw-img" data-ratio="0.5074074074074074" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=ea9e88a2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdVNzO2cVnA4Oy5KtDf7BvZg665n9icG7rTSfWf7F8rvJ9EO8ZrDgJ1NRp0s0E1FJJiadZkvmeOQtmw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p data-pm-slice="2 2 []"><span leaf="">Gartner认为，未来的安全一定是主动和被动相结合，而随着DR类被动安全领域近些年的长足发展，焦点将逐步转移到主动安全领域。在2025年，主动安全领域的关键技术是xSPM，即面向特定领域的安全姿态管理<span textstyle="" style="color: rgb(0, 82, 255);">【笔者注：这里Posture应翻译为“姿态”，而不是“态势”，以跟“态势感知”（</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 82, 255);">Situational Awareness</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">）中的“态势”保持区别，二者有很大区别】</span>，譬如ASPM（应用安全姿态管理）、SSPM（SaaS安全姿态管理）、DSPM（数据安全姿态管理）。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001375" class="rich_pages wxw-img" data-ratio="0.5166666666666667" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=04084f83&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdVNzO2cVnA4Oy5KtDf7BvZxJ0lLfU2wFX08lN3tS294B7WE0R8YL1qibPNdRJINWGlz0okfQ62Hew%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p data-pm-slice="2 2 []"><span leaf=""><span textstyle="" style="font-weight: bold;">3）各种安全平台技术盛行</span></span></p><p data-pm-slice="2 2 []"><span leaf="">Garnter的调研显示，大型组织使用的安全工具数量的平均值在43个，引入的安全供应商平均值在20个，而其中有</span><span leaf="">62% 的组织目前正在推进安全供应商整合。正如笔者在《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484842&amp;idx=1&amp;sn=38dba05e2a0024b71d81d1d9b3e74a6c&amp;scene=21#wechat_redirect" textvalue="2024年安全运营技术趋势回顾" data-itemshowtype="0" linktype="text" data-linktype="2">2024年安全运营技术趋势回顾</a>》一文所分析的那样，未来几年，包括安全运营在内的各种安全能力整合化将成为一个重要趋势。而整合化的主要表现形式就是各种安全平台。下图展示了一个安全平台的概念框架。</span></p><p data-pm-slice="2 2 []"><span leaf=""><img data-imgfileid="100001377" class="rich_pages wxw-img" data-ratio="0.5043640897755611" data-type="png" data-w="1604" src="https://wechat2rss.xlab.app/img-proxy/?k=f856984b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMeKMiawpUIC10dyicpicPPA9YkI44jXaZ1G88pZrkgPFBE6UuqxZ7WE2EoDoajt5aAIw3PkAkK3YSNxg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p data-pm-slice="2 2 []"><span leaf="">Gartner表示，<span textstyle="" style="background-color: rgb(255, 251, 0);color: rgb(0, 0, 0);font-weight: bold;">工具和供应商整合的根本目的不是为了省钱，而是为了降低安全的复杂度。复杂是安全最大的敌人。</span></span><span leaf="">CISO 希望安全平台整合能够帮助提高员工的工作效率和效益。</span><span leaf="">Gartner认为，大一统的安全平台目前看还很遥远，更多是将某个领域内的多种工具和供应商进行整合，譬如数据安全平台、AI安全平台、CPS（如工控、车联网等）保护平台，又譬如工作空间安全平台、工作负载安全平台、SASE平台等。显然，安全运营平台也是一类安全平台，本文后面将详述。</span></p><p><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">2025年安全运营展望</span></span></p><p><span leaf="">在本届峰会上，Gartner分析师Eric Ahlm提出了<span textstyle="" style="font-weight: bold;">安全运营的四大展望，分别是：最佳单品与生态（平台）之争、混合式SOC、暴露管理、增强型运营</span>。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001379" class="rich_pages wxw-img" data-ratio="0.5078328981723238" data-s="300,640" data-type="png" data-w="1532" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=c5901873&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMeKMiawpUIC10dyicpicPPA9YkLIg1bNT7j7AhicDCbnlmohaZ3hbh78PA31TNuNiblnpymibh7DMibKX4Vw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="">首先，最佳单品与生态之争反映了当下盛行的安全平台化战略背景下“融合型安全运营平台”对过去以SIEM为核心、集成各种单项安全工具的“集成型安全运营平台”带来的冲击。</span></p><p><span leaf="">其次，当前企业和组织的安全运营人力不足，技能短缺，而面临的安全威胁日益严峻，因此，仅靠企业和组织自身团队力量难以做好安全运营。Gartner近几年一直强调未来的安全运营一定是混合式的，必须将战术性运营工作和通用型安全技能进行外包，构建自营和外包相结合的混合式安全运营模式。</span></p><p><span leaf="">第三，暴露管理（CTEM）一直是Gartner主推的安全项目，代表了主动安全的一个发展方向。暴露管理对于安全运营最大的价值在于让安全运营的工作更加主动，能够在威胁实际发生之前对安全隐患进行消除或规避，而在安全检测与响应环节也能提供大量的上下文（情境）信息，提升检测与响应的精准度和效率。</span></p><p><span leaf="">最后，随着GenAI在安全运营领域的应用模式逐步从早期的AI助理向更高阶的自主智能体演进，GenAI的应用更多体现为智能体，但Gartner认为在可预见的未来，不会出现完全自主的SOC，AI（尤其是智能体）更多还是用于增强SOC，赋能分析师，而不会成为真正独立的“机器人分析师”（队友）。</span></p><p><span leaf="">以下针对上述四个方面，笔者结合自身的实践体会进行详细解读<span textstyle="" style="color: rgb(0, 82, 255);">【注：以下4个方面的标题为笔者所取】</span>。</span></p><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">最佳单品与生态（平台）之争：构建生态型安全运营平台</span></span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">基于SIEM集成各种单品构建安全运营平台面临挑战</span></span></p><p><span leaf="">Gartner分析师Eric Ahlm表示，长久以来，安全运营平台（SOP）的构建都是采用基于单项最佳产品进行集成的方式，譬如通过采购优秀的SIEM产品、威胁情报服务、CWPP、EDR、NDR、漏扫、ASM、SOAR等，然后以SIEM为纽带进行集成，并整合其他安全设备日志和告警，形成安全运营平台<span textstyle="" style="color: rgb(0, 82, 255);">【注：笔者将这种方式定义为“集成型安全运营平台”】</span>。但是这种方式暴露的问题日益突出，最关键的就在于SIEM集成成本、运营成本居高不下，且运营效果不佳。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">融合型安全运营平台更好交付安全成果</span></span></p><p><span leaf="">近几年，出现了一种新的构建安全运营平台构建模式，以Palo Alto Networks（PAN）为先锋，CrowdStrike，SentienlOne，微软等紧随其后的一众大厂纷纷通过提供所谓“原生集成”的安全运营平台和SaaS化服务模式入局SOC市场。这类“原生集成”的安全运营平台最大特点就是将自家的SIEM、EDR、NDR、TIP、SOAR甚至ASM融合到一个平台之下，提供一体化的功能和统一的用户界面，大幅降低平台部署实施和运营的复杂度，提升运营体验，并敢于承诺运营效果</span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">【注：笔者将这种方式称之为“融合</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 82, 255);">型</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">安全运营平台”】</span><span textstyle="" style="color: rgb(0, 0, 0);">。以PAN为例，其XSIAM平台一经推出，取得了巨大的业绩突破和飞速的增长，足见其在客户侧的认可程度。Eric表示，这种新的构建模式，迎合了</span><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">构建安全运营平台的评估标准正在从</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">“该平台具备哪些功能” 转向 “该平台是否真能降低运营复杂度，并交付我们所需的安全成果”</span><span textstyle="" style="color: rgb(0, 0, 0);">的趋势。</span></span></p><p><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">笔者认为，融合</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 82, 255);">型</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">安全运营平台之所以能够降低运营复杂度并敢于承诺运营效果，就在于首先将用户侧的集成工作前置到厂商侧，在出厂前就做好了；其次则是在产品设计时仅考虑有限的自有产品间的集成和整合，具有更好的可控性，更容易嵌入预设的场景，开发成本也更低（不用支持五花八门的设备）。而传统的集成型安全运营平台难就难在一方面无法预先确定集成对象，需要保持最大程度的开放性，增加了平台设计开发难度和成本；另一方面平台所能取得的效果依赖于各种集成的第三方设备，有的设备如果接口不完备，或者产生的告警太差，都会影响效果的达成，需要更多的优化时间（和成本），因而不如融合</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 82, 255);">型</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">安全运营平台“容易出效果”。</span></span></p><p><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">显然，融合</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">型</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">安全运营平台的这种“提前集成”和“简化融合”策略恰恰使得平台更加易于使用，用户体验更好，更容易出效果，运营成本也更低（协调沟通工作明显减少，平台有问题找一个厂家就好），迎合了用户的期待。</span></span></p><p><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">应该说，集成</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">型</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">安全运营平台的设计之初也是结果导向的，但受限于用户现有条件（例如需要被集成的设备各不相同，接口开放性和标准化程度参差不齐），很难提前设定较高预期。</span></span></p><p><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">构建融合型安全运营平台并非简单加法</span></span></p><p data-pm-slice="2 3 []"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">需要特别指出的是，融合型安全运营平台尽管在提前整合的单点产品数量上做了精简，但整合的深度却大大提升，绝不是将几个自家的产品整到一起再包个外壳了事（可以看作“</span><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">全家桶1.0</span><span textstyle="" style="color: rgb(0, 0, 0);">”</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">）</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">，是一种深度的产品融合，可以看作是“</span><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">全家桶2.0</span><span textstyle="" style="color: rgb(0, 0, 0);">”。这种融合平台</span></span><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">通常具有统一的管理控制台，统一的策略管理，统一的数据存储，高度一致的用户体验（如用户界面），等等。以Palo Alto Networks为例，尽管其EDR、SOAR、ASM等产品都收购自不同的公司，但是他们将这些产品融合的时候进行了重构，最终做出来的XSIAM在使用SIEM、EDR、SOAR、ASM等功能时界面完全一致，后台的数据也完全融合。这其实体现了安全平台厂商在产品整合、架构设计、研发管理方面的深厚功底。反观国内，很多大厂一直难以将自身的各种安全产品进行融合，更不用说收购进来的产品融合了，何况还有不少OEM的东西。这不仅是技术问题，也是管理问题。</span></span></p><p><span data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">此外，要做出优秀的融合型平台，其单项产品能力也基本上要属于一流水平之列，否则综合能力也难优秀。譬如，PAN</span></span><span data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;color: rgba(0, 0, 0, 0.9); font-family: \&#34;PingFang SC\&#34;, system-ui, -apple-system, BlinkMacSystemFont, \&#34;Helvetica Neue\&#34;, \&#34;Hiragino Sans GB\&#34;, \&#34;Microsoft YaHei UI\&#34;, \&#34;Microsoft YaHei\&#34;, Arial, sans-serif; font-size: 17px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: 0.544px; orphans: 2; text-align: justify; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px;  background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial; display: inline !important; float: none;&#34;,&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">在2023年的</span><a class="normal_text_link" target="_blank" style="color: rgb(0, 0, 0);" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484640&amp;idx=1&amp;sn=6ff1f407b3ad35c01efbf35d5a0ded0d&amp;scene=21#wechat_redirect" textvalue="RSAC大会上就表示" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 0, 0);">RSAC大会上就表示</span></a><span textstyle="" style="color: rgb(0, 0, 0);">平台的各种能力不仅是“原生集成”的，各单项能力也都必须是同类最佳的。</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">这对平台厂商提出了很高的要求，国外也没有几个大厂能够有这种实力。放眼国内，当前即便是主流的单项能力尚有较大提升空间，此时大谈融合自身多个单项能力的平台可以做到优秀实在有些牵强。因此，国内即便有融合安全运营平台的需求，供给侧也比较勉强。</span></span></span></p><p><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">选择集成型SOP还是融合型SOP？</span></span></p><p><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">那么，</span><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">未来属于融合</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">型</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">安全运营平台吗？情况没那么简单</span><span textstyle="" style="color: rgb(0, 0, 0);">。</span></span></p><p><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">对于很多用户而言，引入安全运营平台并不是从安全建设之初就发生的，他们大都会首先进行基础设施的安全建设，采购和部署边界安全设备，然后是主机和端点安全，应用安全，等等。这个过程基本都会采用选择同类最佳/最优产品的策略，部署很多最佳/最优单品。等到他们考虑部署安全运营平台的时候，只能基于现有条件采购集成</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">型</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">安全运营平台，将他们现有的最佳单品进行集成，捎带补充一些单点能力。如果这个时候采用融合</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">型</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">安全运营平台，势必要废弃现有的部分（甚至所有）单点产品。因此，单看平台本身，可能融合</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">型</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">安全运营平台成本低，但从整个安全体系建设来看，反而可能更高。</span></span></p><p><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">如果用户改变上述那种阶段性安全建设的方法，转而在一开始总体安全规划的时候就把安全运营考虑进去并在一开始就部署安全运营平台，则的确更值得考虑融合</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">型</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">安全运营平台策略。但这时用户可能又需要考虑其他的问题：将安全体系的大部分甚至全部托付给一个厂商是否可行？风险多大？厂商能否提供全局最佳/最优的解决方案？安全威胁总是不断变化，这个厂商以后能够持续提供应对新威胁的新能力，或者是否会有意排斥更好的产品和技术，是否会被厂商“锁定”？如果以后要切换供应商，成本有多高？Garnter认为，</span><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">融合</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">型</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">安全运营平台的困境在于不可避免的产生“供应商锁定”担忧</span><span textstyle="" style="color: rgb(0, 0, 0);">。</span></span></p><p><span leaf="">进一步分析，融合型安全运营平台能够满足客户的所有运营需求吗？显然不可能。即便客户部署了融合型平台，依然可能需要或多或少地引入第三方安全遥测设备或者工具，即便现在不需要引入，未来也可能需要引入。这就导致了一个悖论。融合型平台可以减少供应商，但不可能归为一个供应商。8月份，在LinkedIn上有人发出一个题为“</span><span leaf=""><a class="normal_text_link" target="_blank" style="color: rgb(0, 82, 255);" href="https://mp.weixin.qq.com/s?__biz=MzkzNjE5NjQ4Mw==&amp;mid=2247545496&amp;idx=1&amp;sn=a44f9bf1d30e0e232dc7354435c86b4b&amp;scene=21#wechat_redirect" textvalue="安全整合将在2026年消亡" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 82, 255);">安全整合将在2026年消亡</span></a></span><span leaf="">”的帖子，表示“</span><span leaf="">平均而言，整合的企业运行着1个主要供应商的平台，外加12-18个平台无法完全处理的专用工具</span><span leaf="">”，进而引发热烈的讨论【注：上述LinkedIn帖子建议看下面的讨论，则更加精彩】。</span></p><p><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">因此，哪种方式更好不能一概而论，必须根据用户实际情况和自身规划而定。事实上，正如Garnter的SIEM市场报告所言，SIEM市场增长率在17%以上，足见以SIEM为核心的集成</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">型</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">安全运营平台的重要市场地位。当然，以SIEM为核心的集成</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">型</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">安全运营平台将不再是唯一选择。而即便是集成</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">型</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">安全运营平台自身也需要重构，譬如《</span></span><span leaf=""><a class="normal_text_link" target="_blank" style="color: rgb(0, 0, 0);" href="https://mp.weixin.qq.com/s?__biz=MzkzNjE5NjQ4Mw==&amp;mid=2247539966&amp;idx=1&amp;sn=607c2e212578fb1c0c3ebcf7987cb854&amp;scene=21#wechat_redirect" textvalue="SOC不相信厂商整合" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 0, 0);">SOC不相信厂商整合</span></a></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">》一文介绍了一种新型的集成型安全运营平台架构。</span></span></p><p><span leaf=""><img data-imgfileid="100001380" class="rich_pages wxw-img" data-ratio="0.4759259259259259" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=1123afeb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMfZjX9EZYfTe91Go5W6extItMGETMQFALRwpbrMR9hS7BOkFFeSiaKh2TfcWbrZqnpvEpCXn5iauL7w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">根据Gartner的分析，大型和SecOps成熟度更高的客户更倾向于集成</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">型</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">安全运营平台，而中型客户则可能更倾向于融合</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">型</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">安全运营平台，对于中小型客户则建议优先考虑MSS/MDR而非自建平台。</span></span></p><p><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">笔者认为，</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">选择哪种模式的平台，取决于客户构建安全体系的技术路线</span><span textstyle="" style="color: rgb(0, 0, 0);">。</span></span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">生态型安全运营平台或可占据一席之地</span></span></p><p><span data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">在峰会上，Gartner分析师Eric将融合</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">型</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">安全运营平台的出现看作SOC建设从</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">“功能导向”到“结果导向”的一种转变，并将这种新的模式称作“生态化方法（Ecosystems Approach）”。笔者十分欣赏“生态”这个词，并且认为生态这个概念可以扩大一下，不仅指代狭义的“全家桶2.0”式的融合</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">型</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">安全运营平台所代表的某个厂商的内部生态，更可以指代某种</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">相关单点产品和平台厂商之间建立生态联盟条件下为客户提供的“生态型安全运营平台”</span><span textstyle="" style="color: rgb(0, 0, 0);">。而这种模式可能更适合当前的中国市场。</span></span></span></p><p><span data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">进一步分析，笔者认为，正是在“结果导向”的带动下，传统的集成型安全运营平台存在的顽疾已经很难保证结果的有效性，而国外出现的融合</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">型</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">安全运营平台在国内暂时还不具备大规模落地的可行性，因此需要一种折衷的方案，即“生态型安全运营平台”。该方案需要将平台所需能力的整合尽可能放到提供给客户之前，但整合的产品不需要完全来自同一个厂商，而是来自一个生态联盟。这个联盟成员之间开放标准化的、能够深度整合的接口，并提前进行整合，形成一个统一的多体架构和具有较高一致性的平台操作界面。同时，该方案保留在客户侧进一步按需集成的能力。</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">生态型安全运营平台介于融合型和集成型之间，既能一定程度上简化平台的复杂度和运营成本，又不至于落入“供应商锁定”的困境</span><span textstyle="" style="color: rgb(0, 0, 0);">。</span></span></span></p><table><tbody><tr><td data-colwidth="576" style="background-color:#d6d6d6;"><p><span data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">目前，笔者所在的</span><a class="normal_text_link" target="_blank" style="color: rgb(0, 0, 0);" href="https://mp.weixin.qq.com/s?__biz=MzkzMzkzMjI4OQ==&amp;mid=2247483680&amp;idx=1&amp;sn=2cd09d78ab450c2fa40360538f5e9367&amp;scene=21#wechat_redirect" textvalue="睿安致远团队" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 0, 0);">睿安致远团队</span></a><span textstyle="" style="color: rgb(0, 0, 0);">发布的MetaSec-SOP自主化安全运营平台就是一款生态型安全运营平台底座。该平台采用当前最先进的技术架构，以及低代码开发技术，能够快速实现与生态合作伙伴的运营类产品和工具深度对接，形成统一的前端用户界面，让用户获得一致的使用体验。如果您是安全运营类产品提供商（如情报、EDR、NDR、CWPP、ASM、VM等），或有意共同打造生态型安全运营平台，欢迎与我们取得联系。</span></span></span></p></td></tr></tbody></table><p style="margin-top: 24px;"><span data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 20px;font-weight: bold;">自建还是外包：构建混合式安全运营团队</span></span></span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">安全运营工作仅靠自身力量难以为继</span></span></p><p><span leaf="">多年来，Gartner一直有一个统计数据——<span textstyle="" style="font-weight: bold;">对于大部分客户而言，一个安全运营中心要真正运营起来，至少需要12个人的团队</span>。这就意味着，大部分用户的安全运营中心靠自身团队是运营不起来的，其结果就是顾此失彼，或者挑重要的干，遗留大量安全隐患。那么AI和自动化呢？对不起，Gartner已经把这些因素考虑进去了。为什么？后面会讲，这里暂不展开。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">安全运营结合内外部力量是大势所趋</span></span></p><p><span leaf="">安全以人为本，安全运营更是无人不可。当前企业和组织的安全运营团队人手明显不足，并且由于预算和技能等原因，基本没法补齐。这时候，<span textstyle="" style="font-weight: bold;">安全运营团队必须聚焦关键工作，而将一般性常规工作尽可能的进行外包，建立起一个混合式安全运营团队，实现混合安全运营</span>（自己运营+委托运营）。这里的外包可以是人员驻场外包，也可以是远程运营服务外包。同时，外包比重或大或小，视不同客户而定。</span></p><p><span leaf="">在美国，混合安全运营已经成为主流，并且以远程服务为主。笔者相信，<span textstyle="" style="color: rgb(0, 82, 255);">混合安全运营未来在中国市场也将成为主流</span>，但短期内以驻场外包/托管为主。</span><span leaf="">IDC数据显示，2024年中国托管安全服务市场规模为43.6亿元人民币。</span></p><p><span leaf="">如何构建成功的混合式 SOC？Gartner建议从 “战略性资源分配” 的角度思考。首先，所有的安全运营目标（工作）都要分配到角色，然后所有角色都要落实到人，不论是内部成员还是外包人员【笔者注：如果购买的是远程外包服务，则应落实到服务接口人】。其次，识别战略性工作，对于那些需要深度理解业务背景、需要单位特定知识或特定决策的战略性工作及其对应的角色，应该落实到单位内部团队成员上。第三，识别战术性工作，对于那些非本单位独有的常规性的任务和可以通过专业安全能力完成的任务</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">（技术与战术层面工作）</span><span leaf="">，则可以委托给外包团队（安全运营服务提供商）。下图提供了一个分工示意，并展示了不同类型的服务提供商可以承担的角色<span textstyle="" style="color: rgb(0, 82, 255);">【笔者注：Gartner提供的这个分工示意图是针对“狭义SOC”】</span>。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001381" class="rich_pages wxw-img" data-ratio="0.7703703703703704" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f93b08a4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMeGLmy7DIzia0BC3XDDOGH8IkjLA6SXBav0FGia8bbhd5on7rpdHx4OQR4D9SibcOUkR12ibV3n1I8jDg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="">Gartner指出，<span textstyle="" style="font-weight: bold;">未来所有SOC都将采用混合模式</span>。即便企业拥有足够人力独立运营 SOC，也不应排斥外包或托管服务，而应主动接纳这一模式，将其作为内部能力的重要补充。</span></p><p><span leaf="">当然，</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">一个单位选择哪些战术性工作进行外包要视情况而定，并非所有的战术性工作都必须外包。</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">安全运营服务是大势所趋，但缺乏有效的平台支撑</span></span></p><p><span leaf="">可以预见，随着混合安全运营模式的持续发展与成熟，<span textstyle="" style="color: rgb(0, 82, 255);">安全运营服务将成为网络安全领域的重要细分市场</span>，一批专业的安全运营服务提供商也将随之崛起。对于这类服务商而言，<span textstyle="" style="color: rgb(0, 82, 255);">单纯依靠人力外包（即 “卖人头”）的模式必定难以为继，要实现可持续发展，必须构建专属的安全运营服务平台，并配套标准化的服务流程与专业化的运营团队</span>。其中，<span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">安全运营服务平台是服务成败的核心支柱</span>，整个团队的协作效率、服务流程的落地质量，都需依托该平台才能有效运转，最终实现服务能力的稳定输出。</span></p><p><span leaf="">然而，当前国内安全运营服务市场仍面临显著短板，<span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">绝大部分服务商缺乏真正自主可控的安全运营服务平台</span>，导致运营团队管理与服务流程推进难以实现规范化、规模化，进而引发两大核心问题：一是运营效果无法量化评估，服务价值难以直观呈现；二是运营质量缺乏稳定保障，难以满足企业对安全服务的持续性需求。具体来看，当前服务商的平台建设主要存在两种困境：部分服务商基于开源平台与工具进行定制开发，虽能搭建基础服务框架，但后续维护成本高、系统适应性差，难以扩大业务规模；另一部分服务商采购市场上的商业化通用平台，但这类平台多面向企业自建 SOC 设计，缺乏针对服务商场景的运营管理功能（如团队协作、流程管控、服务计费等），导致服务商难以充分发挥平台价值，不仅运营效率未获提升，更造成前期投入的投资回报率（ROI）极低。</span></p><p><span leaf="">因此，国内的安全运营服务提供商急需一个自主可控的安全运营服务平台。</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">相比之下，国外已经出现了不少专门面向安全运营服务提供商的运营平台，为他们提供了更好的选择。</span></p><table><tbody><tr><td data-colwidth="576" style="background-color:#d6d6d6;"><p><span data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">目前，笔者所在的</span><a class="normal_text_link" target="_blank" style="color: rgb(0, 0, 0);" href="https://mp.weixin.qq.com/s?__biz=MzkzMzkzMjI4OQ==&amp;mid=2247483680&amp;idx=1&amp;sn=2cd09d78ab450c2fa40360538f5e9367&amp;scene=21#wechat_redirect" textvalue="睿安致远团队" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 0, 0);">睿安致远团队</span></a><span textstyle="" style="color: rgb(0, 0, 0);">发布的MetaSec-SOP自主化安全运营平台可以成为安全运营服务提供商的平台底座。该平台采用当前最先进的技术架构，以及低代码开发技术，充分考虑了如何利用平台管理服务团队和流程，借助双流程引擎实现安全运营服务流程的可定制化，借助指标引擎实现运营服务效果的即时量化。如果您是安全运营服务商或者有意进入这个领域，欢迎与我们取得联系。</span></span></span></p></td></tr></tbody></table><p style="margin-top: 24px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 20px;font-weight: bold;">重视CTEM：构建主被动结合的安全运营能力</span></span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">安全运营需要暴露（资产和弱点）运营</span></span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">随着近些年在TDIR（威胁检测、调查与响应）领域的大力投入，业内在被动安全运营这方面已经取得了长足的进步，人们又开始将目光放到了主动安全运营领域。毫无疑问，<span textstyle="" style="font-weight: bold;">安全运营需要主被动结合的能力</span>。</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Gartner认为，暴露管理将成为未来主动安全运营的重点技术，并能提升被动安全的效能。如下图所示，暴露管理包括暴露评估和暴露验证两个部分，对安全运营而言，能够实现更全面的感知资产态势，更好的优化安全措施，更高效的进行调查，及早减少误报，等等。</span></p><p><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001382" data-ratio="0.5046296296296297" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=8a9b1b1f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMeGLmy7DIzia0BC3XDDOGH8ITYHfUF778rQKKQqOlwRjWVAATxEFZwykHYsrIBU6fWRSfOO5IlltEw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Gartner一直强调，<span textstyle="" style="font-weight: bold;">基于暴露管理的持续威胁暴露管理（CTEM）体系将成为安全运营体系中的重要组成部分</span>。</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">在Gartner宇宙中，</span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 0.034em;" data-pm-slice="0 0 []"><span leaf="">持续威胁暴露</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 0.034em;"><span leaf="">管理(Continuous Threat Exposure </span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 0.034em;"><span leaf="">Management，简称CTEM</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 0.034em;"><span leaf="">)是一套包含技术、流程和人员在内的系统性、集成化、迭代性的方法和体系，让企业和组织有意识地持续并</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 0.034em;"><span leaf="">一</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;letter-spacing: 0.034em;"><span leaf="">致地评估其数字资产和物理资产的可见性、脆弱性和可访问性，以持续优化提升安全姿态。Gartner将CTEM看作是一个过程和方法，而将暴露管理（Exposure Management，简称EM）看作是支撑CTEM的技术集合。</span></span></p><p><span leaf="">Gartner在<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484795&amp;idx=1&amp;sn=8f835c0699be66f615e7b713f67e26dc&amp;scene=21#wechat_redirect" textvalue="2024年的安全运营展望" data-itemshowtype="0" linktype="text" data-linktype="2">2024年的安全运营展望</a>中就包含了CTEM，今年则再次强调了这个趋势。笔者在Gartner 2024年安全运营展望中提到了<span textstyle="" style="font-weight: bold;">CTEM的价值在于为SOC提供上下文，以及提升SOC自身的弹性/韧性</span>，现在依然如此。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">Gartner对暴露管理领域的概念进行整合</span></span></p><p><span leaf="">值得一提的是，在2025年，Gartner对EM技术集合进行了重新梳理，将诸多细分技术进行了大刀阔斧的整合，以顺应其对未来安全技术整合趋势的判断，也符合国际市场上相关厂商的实际动向。</span></p><p><span leaf="">首先，<span textstyle="" style="font-weight: bold;">EM（也叫TEM）以后就只有两大细分，分别是暴露评估平台（EAP）和对抗性暴露验证（AEV），即EM = EAP + AEV</span>。其它技术统统被整合。</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">其次，将原来独立存在的攻击面管理（ASM）技术族中的网络资产攻击面管理（CAASM）和外部攻击面管理（EASM）统统标记为“过时”，不再称作独立技术，被整合到EM，或者EAP和AEV中，成为它们的一组组功能点。而原ASM中的数字风险保护服务（DRPS）则被整合到威胁情报平台与服务（TIPS）中去了。</span></p><p><span leaf="">此外，原来的漏洞评估（VA）、漏洞优先级技术（VPT）都已经被整合到EAP中。而原来的突破与攻击模拟（BAS）、自动化渗透测试服务（PTaaS）都已经被整合到AEV中。</span></p><p style="text-align: center;"><span leaf=""><img data-imgfileid="100001391" class="rich_pages wxw-img" data-ratio="0.5027777777777778" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=7af8a1e1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMd2YKsEUSISiajjQ0wjHyjW4dEVo1YJmv5EfBp1iap1bLaeEL23jFgojMNmbGlP0dN4bBboPZicSzCRw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span leaf="">以后，Gartner将针对EAP和AEV出具研究报告，而不再单独研究ASM了。<span textstyle="" style="font-weight: bold;">Gartner在2025年中国网络安全成熟度曲线报告中表示</span>：</span></p><table><tbody><tr><td data-colwidth="576" style="background-color:#ffffff;"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="">对抗性暴露⾯验证（AEV）取代了传统的⼊侵和攻击模拟（BAS），反映出安全测试范围已发⽣根本性变化。中国企业如今需要⾃动化、持续性的验证机制，以应对国家级攻防演练等关键合规要求。AEV不仅能够模拟攻击，还能确认暴露⾯并识别通往关键资产的漏洞路径，从⽽满⾜这⼀需求。这种从简单模拟向可⾏验证的转变，标志着⼀个全新技术类别的出现，推动AEV进⼊技术萌芽期。</span></p></li><li><p><span leaf="">暴露⾯评估平台（EAP）取代了攻击⾯管理（ASM），因为中国企业机构意识到需要从被动发现转向主动暴露⾯管理。EAP可在统⼀平台中，提供优先级明确、可操作的有关漏洞和错误配置的视图。市场对EAP的⾼度关注，源于其提升运营效率和简化修复流程的潜⼒，这推动了该技术快速进⼊期望膨胀期。</span></p></li></ul></td></tr></tbody></table><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="font-weight: bold;">暴露管理正在向预防性安全（Preemptive Cybersecurity）方向发展</span></span></p><p style="margin-top: 24px;"><span leaf="">峰会上，分析师Peter Firstbrook深入分析了GenAI对网络安全带来的影响，包括推动安全运营技术进步，以及对手利用GenAI带来的挑战。而为了应对这些挑战，<span textstyle="" style="font-weight: bold;">Gartner认为，未来不能单纯等待对手的攻击，在攻击中（甚至攻击后）去防护、检测与响应，而应该更进一步，在对手攻击之前就采取迷惑（Deceive）、阻断（Disrupt）、拒止（Deny）等预防性（preemptive）手段，进行网络威慑（Cyber Deterrence），并将相关技术归为“预防性安全（Preemptive Cybersecurity）</span>”。</span></p><p style="margin-top: 24px;text-align: center;"><span leaf=""><img data-imgfileid="100001403" class="rich_pages wxw-img" data-ratio="0.4537037037037037" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b2cf29a9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMfzZx8gWCiaZNclcX2ibVwBYicBa2M4GJDL7LaiaicCN4BBCHuMN313AMlTXMpEU2NNjYJDAXWsWjUVic6w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="margin-top: 24px;"><span leaf="">预防性安全技术中就包含自动化暴露管理。</span></p><p style="text-align: center;"><span leaf=""><img data-imgfileid="100001404" class="rich_pages wxw-img" data-ratio="0.6148148148148148" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=6f60bb31&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMfzZx8gWCiaZNclcX2ibVwBYicVcRmxj2QjsVypFQbJHYzMYR7VHDGqyPmfOLJWKMcOFUKiaw4DetQWyQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="margin-top: 24px;"><span leaf="">作为当前暴露管理技术的升级版，Gartner认为自动化暴露管理</span><span leaf="">解决方案具备持续评估攻击面、优先排序漏洞与暴露点以进行修复的能力。在当前多云、混合基础设施与 AI 驱动新兴技术交织的复杂技术环境中，手动及时管理漏洞已无可能。自动化暴露管理工具可对全环境进行可扩展的持续监控，通过自动化技术提供有关组织暴露态势的实时、情境化洞察，进而支持更精准的威胁狩猎、更合理的风险优先级排序，以及更及时、可落地的修复指导。</span></p><p style="margin-top: 24px;"><span leaf="">简言之，<span textstyle="" style="font-weight: bold;">自动化暴露管理聚焦于</span></span><span leaf=""><span textstyle="" style="font-weight: bold;">持续验证真正可被利用的风险，模拟攻击者在当前环境中的行动路径，并在这些路径被实际利用前将其阻断</span>。而这<span textstyle="" style="font-weight: normal;">有赖于安全数据编织、智能模拟和智能体技术</span>的应用。</span></p><p style="margin-top: 24px;"><span leaf="">顺便提一下，就在10月20日，<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzA5NjQyNjMxNA==&amp;mid=2651420834&amp;idx=1&amp;sn=51ef086c1c0e3c494430452b2c9fdb01&amp;scene=21#wechat_redirect" textvalue="Gartner宣布了2026年十大战略技术" data-itemshowtype="0" linktype="text" data-linktype="2">Gartner宣布了2026年十大战略技术</a>，Preemptive Cybersecurity位列其中。</span></p><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="font-weight: bold;">暴露运营需要全新的底层架构支撑</span></span></p><p style="margin-top: 0px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">放眼国内，CTEM所代表的正是安全运营中的“资配漏补”工作，对应了国内安全运营中心6大运营职能中的资产运营和漏洞/弱点运营。长期以来，国内的安全运营平台在支撑资产运营和漏洞运营方面显得十分薄弱，基本也就只做到了资产维护和漏洞维护，还远远到不了运营的程度。</span></span></p><table><tbody><tr><td data-colwidth="576" style="background-color:#d6d6d6;"><p><span data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">目前，笔者所在的</span><a class="normal_text_link" target="_blank" style="color: rgb(0, 0, 0);" href="https://mp.weixin.qq.com/s?__biz=MzkzMzkzMjI4OQ==&amp;mid=2247483680&amp;idx=1&amp;sn=2cd09d78ab450c2fa40360538f5e9367&amp;scene=21#wechat_redirect" textvalue="睿安致远团队" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 0, 0);">睿安致远团队</span></a><span textstyle="" style="color: rgb(0, 0, 0);">发布的MetaSec-SOP自主化安全运营平台采用了基于安全数据编织的全新数据架构，能够更好地将资产、漏洞和威胁数据整合到一起，支撑起真正的资产运营和漏洞运营。</span></span></span></p></td></tr></tbody></table><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">取代还是增强：构建AI赋能的安全运营流程</span></span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Gartner在<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484795&amp;idx=1&amp;sn=8f835c0699be66f615e7b713f67e26dc&amp;scene=21#wechat_redirect" textvalue="2024年的安全运营展望" data-itemshowtype="0" linktype="text" data-linktype="2">2024年的安全运营展望</a>中就深入分析了GenAI技术对安全运营带来的变革，包括GenAI的应用部署模式、应用类型、安全运营用例、存在的缺陷，GenAI和自动化的关系及如何共同构建超大规模安全运营体系。</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">GenAI已经成为安全领域的投资重点</span></span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Gartner的调研显示，用户侧的GenAI部署率已经达到37%。</span></p><p style="text-align: center;"><span leaf=""><img data-imgfileid="100001396" class="rich_pages wxw-img" data-ratio="0.55" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=49eb1e8b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcW5IG0ib1OcibgHc97NqwYicgGcRiasOYVmr77KDUZuC2Yibgtiac67ajOjoWJialDjnnZic65yjYMT98kUQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: left;"><span leaf="">在网络安全预算中，GenAI位列所有投资项目的综合第二，单项第一。</span></p><p style="text-align: center;"><span leaf=""><img data-imgfileid="100001397" class="rich_pages wxw-img" data-ratio="0.5564814814814815" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=aa924032&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcW5IG0ib1OcibgHc97NqwYicgKHe98OeRILqibib0l6Sic3KUrIGgGw6ge3SqFFUjYtkcNloGmJqOJy27A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: left;"><span leaf="">目前GenAI在安全中的应用场景分布如下：</span></p><p style="text-align: left;"><span leaf=""><img data-imgfileid="100001398" class="rich_pages wxw-img" data-ratio="0.5555555555555556" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=68e1ee3f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcW5IG0ib1OcibgHc97NqwYicg3EJs4fH9viajDI5ueP40Y0Vc9DZTzKDDOoVWVObnLsQXNAE7K17GlXg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-weight: bold;">AI增强而非取代安全运营人员，但运营团队将重构</span></span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Gartner</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">在2024年就表示</span><span leaf="">AI主要还是增强而非替代员工，今年依然持这个观点。</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Eric Ahlm在大会上引述《永远不会有（完全）自主化SOC》报告的结论：<span textstyle="" style="font-weight: bold;">AI在真正成为“队友”之前将在很长一段时间内充当安全运营工具</span>。Gartner给AI使用者的审慎建议是：<span textstyle="" style="font-weight: bold;">将AI用于增强而非取代安全运营人员</span>。</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: normal;">但是，</span><span textstyle="" style="font-weight: bold;">安全运营人员的某些工作的确将被逐步替代</span>。真相就在于随着GenAI的深入赋能，</span><span leaf="">安全运营的组织、职能和流程将发生变化，安全运营人员的工作将不断从低级重复性岗位转向更高级的岗位，而那些高级岗位长期空缺。在笔者《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="迈向AI赋能的SOC4.0时代" data-itemshowtype="11" linktype="text" data-linktype="2">迈向AI赋能的SOC4.0时代</a>》一文的5.4小节对此有深入分析。</span></p><p><span leaf="">Gartner展示了一张安全运营工作分布图，形象地阐释了上述观点。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001393" class="rich_pages wxw-img" data-ratio="0.42962962962962964" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=6558174a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMd2YKsEUSISiajjQ0wjHyjW4oZbFuZlul0OdRBuQaE8dCHiaAuKvgnZAicO86JB7YtcO3FtiaIc7f2nQg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="">上图表明，在没有AI单纯依赖人工的情况下，100个人工时将完全消耗在告警分诊、调查和响应等环节，但是威胁猎捕、防御优化等工作无暇顾及。而在AI赋能之后，同样100个人工时则大幅降低了在告警分诊、调查和响应方面的投入（共计50个人工时），而将高达50个人工时分配到了威胁猎捕和防御优化上，让安全运营工作更加完备。与此同时，AI为安全运营团队贡献了额外的70个人工时，并主要集中在告警分诊和调查等重复性、战术性工作环节。综合来看，<span textstyle="" style="font-weight: bold;">在AI赋能下，安全运营团队在维持总人工时不变的情况下，获得了170%人工时的产能，还使得安全运营工作更加完备</span>。</span></p><p><span leaf="">笔者认为，对于国内客户而言，在安全运营投入长期不足的情况下，引入AI能力，可以在同样规模的投资下进一步缩小上述差距。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">AI和自动化共同增强安全运营</span></span></p><p><span leaf="">Gartner表示，AI不等于自动化。AI和自动化将各有发挥之处，二者需要结合使用。</span></p><p><span leaf="">对于AI（特指智能体）而言，典型的赋能场景包括：</span></p><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="">减少误报：实现告警自动富化，为每条告警收集并汇总相关背景信息，绘制攻击路径，在分析师查看前就过滤掉明显的误报。</span></p></li><li><p><span leaf="">支持调查：在分析师着手调查事件前，AI 会获取威胁情报、构建攻击时间线，并提供丰富的初始背景信息。</span></p></li><li><p><span leaf="">生成检测规则：AI 摄入威胁情报（CTI）报告，提取指标（IoCs），自动生成 SIEM 或终端检测与响应（EDR）规则，省去手动编写规则的繁琐工作。</span></p></li><li><p><span leaf="">辅助报告撰写：利用 AI 对海量数据进行汇总与结构化处理，用于常规状态报告或详细的事件调查结果报告。</span></p></li></ul><p style="margin-top: 24px;"><span leaf="">与此同时，</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">（以SOAR为代表的）</span><span leaf="">自动化技术仍然有重要价值，并可以在很多场景中继续发挥作用：</span></p><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="">工作流程编码化：譬如自动执行标准操作程序（SOP），流程化的沟通与审批。</span></p></li><li><p><span leaf="">常见任务执行：譬如钓鱼调查、执行遏制行动、调用应用API等。</span></p></li></ul><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">而当AI和自动化紧密结合后，就得到了</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="color: rgb(0, 82, 255);" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485048&amp;idx=1&amp;sn=4bceff5bb6514bacc86b69ce83b0fca1&amp;scene=21#wechat_redirect" textvalue="Agentic AI（自主式AI）" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI（自主式AI）</span></a><span textstyle="" style="color: rgb(0, 82, 255);">，并表现为中高级自主智能体，推动安全运营迈入自主化时代。</span></span></p><p style="margin-top: 24px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">2025年7月份，Gartner发布了一份题为《Agentic AI集成将区分TDIR平台的赢家和输家</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">》的报告，认为“Agentic AI代表了AI能力的重大飞跃，从简单的自动化迈向自主决策和目标导向的执行。在威胁检测和事件响应（TDIR）平台的背景下，这一转变意义深远，改变了安全运营中心（SOC）的运作方式，使其更加注重Premetive（暂译为“预防性”）网络安全方法”。显然，Gartner认为</span><span textstyle="" style="color: rgb(0, 0, 0);font-weight: bold;">Agentic AI将决定未来安全运营平台的成败</span><span textstyle="" style="color: rgb(0, 0, 0);">。</span></span></p><p style="margin-top: 24px;" data-pm-slice="2 2 []"><span leaf=""><span textstyle="" style="font-weight: bold;">过度使用自动化和AI的隐忧</span></span></p><p style="margin-top: 24px;"><span leaf="">Gartner分析师</span><span leaf="">Craig Porter</span><span leaf="">在题为《2025年网络安全顶级预测》的主题演讲中表示：“<span textstyle="" style="font-weight: bold;">到2030年，</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">由于过度依赖自动化和AI，</span></span><span leaf=""><span textstyle="" style="font-weight: bold;">75%的SOC团队的</span></span><span leaf=""><span textstyle="" style="font-weight: bold;">基础安全分析技能将会退化</span>。</span><span leaf="">”</span></p><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Gartner认为，当SOC团队越来越依赖AI（尤其是LLM和Agentic AI）后，接触</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">分析流程的机会变得有限，从而降低隐性知识的积累。同时，</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">自然语言功能会削弱对新技能的需求以及对现有技能的维持，而且</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">批判性思维和创新技术将受到影响。</span></p><p style="text-align: left;"><span leaf="">为此，Gartner建议SOC团队要明确哪些SOC职能应持续保持人工主导，清晰定义人在回路之中（HITL）的要求。同时，应</span><span leaf="">制定预案，以应对AI失效的风险。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">自动化+智能化，推动SOC的自主化</span></span></p><p><span leaf="">Garnter分析师</span><span leaf="">Kevin Schmidt在另一个题为的《</span><span leaf="">AI-Enhanced SOC: Bridging the Gap to Advanced Automation in 2025</span><span leaf="">》的主题演讲中表示，<span textstyle="" style="font-weight: bold;">在自动化和超大规模化战略的牵引下，到2027年将有25%的常规SOC任务的成本效益提升50%以上</span>。自动化和AI智能化将共同推动SOC迈向自主化阶段，直至实现高度自主化，但不会有完全的自主化。<span textstyle="" style="color: rgb(0, 82, 255);">某种意义上而言，自主化等于自动化+智能化，自主化是智能自动化</span>。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001394" class="rich_pages wxw-img" data-ratio="0.5212962962962963" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3eaa660e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMd2YKsEUSISiajjQ0wjHyjW4r0PPuovq1QFRpiaaE4yYcuDx30WJIfvX1nIP6xSEJbmk2UFMPZPe7Pw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="">下表是对Gartner的SOC自主化演进各阶段的说明。</span></p><byte-sheet-html-origin data-id="1760965441215" data-version="4" data-is-embed="true" data-grid-line-hidden="false" data-copy-type="col" data-pm-slice="0 0 []"><table style="border-collapse:collapse;min-width:345px;"><tbody><tr><td data-colwidth="50" style="color:rgb(0, 0, 0);font-size:12pt;font-weight:600;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;">对比维度</span></span></p></td><td data-colwidth="107" style="color:rgb(0, 0, 0);font-size:12pt;font-weight:600;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;">手动 SOC</span></span></p></td><td style="color:rgb(0, 0, 0);font-size:12pt;font-weight:600;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;">半自动化 SOC</span></span></p></td><td data-colwidth="138"><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">AI增强型 SOC</span></span></p></td><td><p style="text-align: center;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">自主化SOC</span></span></p></td></tr><tr><td data-colwidth="50"><p><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">关键特点</span></span></p></td><td data-colwidth="107" style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">自动化程度无或极低</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">速度慢</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">容易出错</span></span></p></li></ul></td><td style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">基于用例自动化手动步骤</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">无法自动化所有环节</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">准确性、速度提升</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">分析师可与自动化流程交互</span></span></p></li></ul></td><td data-colwidth="138" style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">自动化 + 人工智能（如LLM）</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">可展示步骤</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">结果可能需要验证</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">分析师审核所有 AI 评估</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">向 AI 反馈</span></span></p></li></ul></td><td style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">更自主地开展分析，而非取代人员</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">可基于智能体实现</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">仅在边缘 / 例外情况时咨询分析师</span></span></p></li></ul></td></tr><tr><td data-colwidth="50"><p><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">自动化程度</span></span></p></td><td data-colwidth="107" style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 12px;">全手动，无自动化</span></span></p></td><td style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 12px;">自动化重复任务</span></span></p></td><td data-colwidth="138" style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 12px;">AI 辅助分析环节（分诊、总结等）</span></span></p></td><td style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">智能体自主处理核心流程（分诊、响应等）</span></span></p></td></tr><tr><td data-colwidth="50"><p><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">人员角色</span></span></p></td><td data-colwidth="107" style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 12px;">分析师手动完成全流程</span></span></p></td><td style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 12px;">分析师审核自动化输出</span></span></p></td><td data-colwidth="138" style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 12px;">分析师用 AI 助手 + 反馈优化</span></span></p></td><td style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">分析师监督 AI智能体</span></span></p></td></tr><tr><td data-colwidth="50"><p><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">工作流特点</span></span></p></td><td data-colwidth="107" style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 12px;">随机性、不一致</span></span></p></td><td style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 12px;">标准化剧本</span></span></p></td><td data-colwidth="138" style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 12px;">人在回路之中（HITL）+AI 洞察</span></span></p></td><td style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">全流程 AI 协调决策，人在回路之上（HOTL）</span></span></p></td></tr><tr><td data-colwidth="50"><p><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">数据利用</span></span></p></td><td data-colwidth="107" style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 12px;">手动查询、关联</span></span></p></td><td style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 12px;">结构化数据馈送</span></span></p></td><td data-colwidth="138" style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 12px;">整合多源数据（告警、情报、上下文等）</span></span></p></td><td style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">高级数据利用（增强数据、共享内存、遥测）</span></span></p></td></tr><tr><td data-colwidth="50"><p><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">治理方式</span></span></p></td><td data-colwidth="107" style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 12px;">同行评审，无自动化支持</span></span></p></td><td style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 12px;">自动化需手动审批</span></span></p></td><td data-colwidth="138" style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 12px;">可解释的 AI 建议 + 审计日志</span></span></p></td><td style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">自治策略 + 终止开关 + 审计日志</span></span></p></td></tr><tr><td data-colwidth="50" style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">可扩展性</span></span></p></td><td data-colwidth="107" style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 12px;">依赖人员，扩展性有限</span></span></p></td><td style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 12px;">随自动化线性增长</span></span></p></td><td data-colwidth="138" style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p><span leaf=""><span textstyle="" style="font-size: 12px;">提升分析师个人效率</span></span></p></td><td style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;"><p><span leaf=""><span textstyle="" style="font-size: 12px;">提升分析师整体产能</span></span></p></td></tr><tr><td data-colwidth="50" style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-size: 14px;font-weight: bold;">度量指标</span></span></p></td><td data-colwidth="107" style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">平均告警分诊 / 调查 / 响应时间</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">每位分析师每天处理的告警数量</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">升级率</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">手动任务中的错误率</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">分析师工作量 / 疲劳程度</span></span></p></li></ul></td><td style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">通过自动化处理的安全告警百分比</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">因自动化节省的时间</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">告警分诊时间和手动错误的减少量</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">随时间变化的平均响应时间（MTTR）差值</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">分析师用于更高优先级任务的时间。</span></span></p></li></ul></td><td data-colwidth="138" style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;border-right:0.5pt solid rgba(0, 0, 0, 0.08);"><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">AI 驱动的告警富集和总结的准确性</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">由 AI 助手处理的事件分析的目标完成率</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">提供给 AI 系统的反馈</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">精确率和召回率指标</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">开展的 AI 辅助调查数量</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">分析师对 AI 工具的满意度</span></span></p></li></ul></td><td style="color:rgba(0, 0, 0, 0.85);font-size:12pt;text-align:left;word-wrap:break-word;word-break:break-word;white-space:pre-wrap;"><p><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">AI 驱动的告警富集和总结的准确性</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">由 AI 助手处理的事件分析的目标完成率</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">提供给 AI 系统的反馈</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">精确率和召回率指标</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">开展的 AI 辅助调查数量</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-size: 12px;">分析师对 AI 工具的满意度</span></span></p></li></ul></p></td></tr></tbody></table></byte-sheet-html-origin><p><span leaf="">总之，SOC运营模式的演进是自动化深度提升 + AI辅助人机协作迭代 + 智能自动化升级的过程：</span></p><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="">手动SOC是基础建设期，核心靠人工落地流程，这一阶段的流程沉淀很重要；</span></p></li><li><p><span leaf="">半自动化SOC进入工具化阶段，通过自动化解放重复劳动；</span></p></li><li><p><span leaf="">LLM增强型SOC聚焦人机协作，AI成为分析师的 “智能助手”；</span></p></li><li><p><span leaf="">自主化SOC探索AI 主导 + 人类监督的高级形态，AI承担更核心的决策与执行工作。</span></p></li></ul><p style="margin-top: 24px;"><span leaf="">作为对照，<span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">笔者也绘制过一个</span><a class="normal_text_link" target="_blank" style="color: rgb(0, 82, 255);" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485048&amp;idx=1&amp;sn=4bceff5bb6514bacc86b69ce83b0fca1&amp;scene=21#wechat_redirect" textvalue="SOC自主化迭代模型" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">SOC自主化迭代模型</span></a><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">。当前我们正处于从SOC3.0到SOC4.0的过渡阶段</span>（SOC3.X是个中间状态）。</span></p><p style="margin-top: 24px;text-align: center;"><span leaf=""><img data-imgfileid="100001395" class="rich_pages wxw-img" data-ratio="0.5925925925925926" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=7cf36bba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcW5IG0ib1OcibgHc97NqwYicgicKjF0adjxgm4TBiah4BPae0JxzJLoqiaADbtssmuQn27rxtEraicDF4pg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="margin-top: 24px;"><span leaf="">其中，SOC3.0是指以大数据架构为支撑的、数据驱动的、应用传统AI技术和SOAR技术的安全运营平台。SOC3.X指在SOC3.0基础上，初步应用了LLM的安全运营平台。<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="SOC4.0" data-itemshowtype="11" linktype="text" data-linktype="2">SOC4.0</a>则指基于安全数据编织架构的、数据与流程双轮驱动的、应用Agentic AI技术的自主化安全运营平台（Agentic SecOps Platform，简称ASOP）。</span></p><table><tbody><tr><td data-colwidth="576" style="background-color:#d6d6d6;"><p><span data-pm-slice="0 0 []"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;data-pm-slice&#34;:&#34;0 0 []&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 0, 0);">笔者所在的</span><a class="normal_text_link" target="_blank" style="color: rgb(0, 0, 0);" href="https://mp.weixin.qq.com/s?__biz=MzkzMzkzMjI4OQ==&amp;mid=2247483680&amp;idx=1&amp;sn=2cd09d78ab450c2fa40360538f5e9367&amp;scene=21#wechat_redirect" textvalue="睿安致远团队" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 0, 0);">睿安致远团队</span></a><span textstyle="" style="color: rgb(0, 0, 0);">提出了</span><a class="normal_text_link" target="_blank" style="color: rgb(0, 0, 0);" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="SOC4.0理念" data-itemshowtype="11" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 0, 0);">SOC4.0理念</span></a><span textstyle="" style="color: rgb(0, 0, 0);">，并国内率先发布了自主化安全运营平台（ASOP）——MetaSec-SOP，成为</span><a class="normal_text_link" target="_blank" style="color: rgb(0, 0, 0);" href="https://mp.weixin.qq.com/s?__biz=MzkzMzkzMjI4OQ==&amp;mid=2247483767&amp;idx=1&amp;sn=587388786eed849eafe27139fbbc84ef&amp;scene=21#wechat_redirect" textvalue="自主化安全运营平台创新赛道领航者" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 0, 0);">自主化安全运营平台创新赛道领航者</span></a><span textstyle="" style="color: rgb(0, 0, 0);">。</span><a class="normal_text_link" target="_blank" style="color: rgb(0, 0, 0);" href="https://mp.weixin.qq.com/s?__biz=MzkzMzkzMjI4OQ==&amp;mid=2247483748&amp;idx=1&amp;sn=403a04f2e7ab7b101d5b34378f1853ba&amp;scene=21#wechat_redirect" textvalue="该平台" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 0, 0);">该平台</span></a></span><span leaf="" data-pm-slice="0 0 []">以基于大语言模型的自主智能体为核心，将生成式</span><span leaf="">AI</span><span leaf="">与传统</span><span leaf="">AI</span><span leaf="">相结合，以基于数据编织的新一代安全数据架构和基于安全编排的新一代运营流程架构为底座，依托低代码开发技术，为用户提供一个自主化、实战化、定制化的安全运营平台，帮助他们真正释放数据价值、缩短定制周期、扩大运营规模、提升运营效率。</span></span></p></td></tr></tbody></table><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">总结</span></span></p><p><span leaf="">展望未来，安全运营的平台架构是生态型的，安全运营的组织结构是混合式的，安全运营的关键能力是主被动结合的，安全运营的工作过程是自主化（Agentic AI赋能）的。笔者所在的睿安致远团队将致力于为合作伙伴搭建生态型安全运营平台，提供主被动结合的安运营能力，打造AI赋能的增强型安全运营流程，</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">支撑起最终用户的混合式安全运营组织。</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">【参考】</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484795&amp;idx=1&amp;sn=8f835c0699be66f615e7b713f67e26dc&amp;scene=21#wechat_redirect" textvalue="从Gartner2024年北美安全峰会看安全运营的技术趋势" data-itemshowtype="0" linktype="text" data-linktype="2">从Gartner2024年北美安全峰会看安全运营的技术趋势</a></span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484657&amp;idx=1&amp;sn=97ef202f80d16243bc1212bedf759458&amp;scene=21#wechat_redirect" textvalue="从Garnter2023年北美安全与风险管理峰会看SIEM和SOC的发展趋势" data-itemshowtype="0" linktype="text" data-linktype="2">从Garnter2023年北美安全与风险管理峰会看SIEM和SOC的发展趋势</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247485053">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=b31017ff&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyNzMxOTAwMw%3D%3D%26mid%3D2247485053%26idx%3D1%26sn%3De2a7ec77a9a9e7fd7f32ed88e3549b83">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 23 Oct 2025 12:02:00 +0800</pubDate>
    </item>
    <item>
      <title>浅析SecOps中的AI Agent和Agentic AI，以及SOC自主化水平模型</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485048&amp;idx=1&amp;sn=4bceff5bb6514bacc86b69ce83b0fca1</link>
      <description>厘清Agentic AI和AI Agent的关系，建立安全运营平台自主化水平模型，推动自主化安全运营平台（ASOP）的发展</description>
      <content:encoded><![CDATA[<p>
原创 <span>Benny Ye</span> <span>2025-10-21 12:00</span> <span style="display: inline-block;">中国香港</span>
</p>




<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=485de074&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMd2YKsEUSISiajjQ0wjHyjW4dNVpBw7ib4tStJz2JibVpnzcD4icDu3y6UPmgibXDeWOic3UeZjJ9HrXDHQ%2F0%3Fwx_fmt%3Djpeg"/></p>

<p>厘清Agentic AI和AI Agent的关系，建立安全运营平台自主化水平模型，推动自主化安全运营平台（ASOP）的发展</p>

<p><span leaf=""><span textstyle="" style="font-style: italic;">【摘要】</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-style: italic;">本文沿着AI发展的历史脉络系统性的梳理了LLM、GenAI、AI Agent、Agentic AI的概念和之间的关系，并阐述了这些技术在安全运营领域的应用和各自局限，进而提出了自主化安全运营平台/中心的概念，并给出了一个安全运营平台/中心的自主化水平划分模型。</span></span></p><p><span leaf="">从笔者提出<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484848&amp;idx=1&amp;sn=0f7f582e241603ec68bc85be3926998c&amp;scene=21#wechat_redirect" textvalue="用Agentic AI重塑SOC平台" data-itemshowtype="0" linktype="text" data-linktype="2">用Agentic AI重塑SOC平台</a>，并在5月21日正式发布了<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="AI赋能+数据与流程双轮驱动的SOC4.0理念" data-itemshowtype="11" linktype="text" data-linktype="2">AI赋能+数据与流程双轮驱动的SOC4.0理念</a>和<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkzMzkzMjI4OQ==&amp;mid=2247483748&amp;idx=1&amp;sn=403a04f2e7ab7b101d5b34378f1853ba&amp;scene=21#wechat_redirect" textvalue="国内首个Agentic SOP" data-itemshowtype="0" linktype="text" data-linktype="2">国内首个Agentic SOP</a>产品，已经过去了半年。今年以来，全球范围内Agentic SOP / SOC如雨后春笋般不断涌现。国外，在2025年RSAC大会上，对Agentic AI和Agentic SOC的追捧达到了一个高潮；国内，在2025年1月20日的Deepseek时刻刺激下</span><span leaf="">，也掀起了一波GenAI和Agentic AI赋能SOC的小高潮。</span></p><p><span leaf="">伴随着GenAI和Agentic AI在安全领域（尤其是安全运营）的深入应用，AI Agent，Agentic AI，Agentic System，Agentic SOC / SOP等等概念充斥了整个市场，人们的争论从学术界延伸到了产业界，大家对同一个概念的理解不尽相同，英文术语如何翻译为中文的称谓也各不相同。笔者认为此时有必要再探讨一下这些概念。尽管笔者对于这些概念的理解存在主观性，但力求尽可能客观地展示这些个概念背后的内涵和差别。<span textstyle="" style="font-weight: bold;">“叫什么不重要，是什么才关键”</span>。</span></p><p><span leaf="">整体而言，笔者的理解参考了吴恩达关于Agentic AI的理解，Forrester分析师Allie Mellen的观点，Gartner相关报告，S</span><span leaf="">ubstack</span><span leaf="">知名自媒体人<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkzNjE5NjQ4Mw==&amp;mid=2247545134&amp;idx=2&amp;sn=4a4c77cee8f673090596220bafa23dc7&amp;scene=21#wechat_redirect" textvalue="Francis Odum" data-itemshowtype="0" linktype="text" data-linktype="2">Francis Odum</a>的观点，以及对国外多个厂商的分析。同时，笔者的理解也是对《<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484993&amp;idx=1&amp;sn=506b9c0de108b2293d71c15750f0d95c&amp;scene=21#wechat_redirect" textvalue="从RSAC2025看安全运营技术发展趋势" data-itemshowtype="0" linktype="text" data-linktype="2">从RSAC2025看安全运营技术发展趋势</a>》一文中“概念梳理”章节内容的延展。</span></p><p><span leaf="">在正式讨论AI Agent和Agentic AI之前，先铺垫几个基础概念。</span></p><p><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">基础概念</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;" data-pm-slice="0 0 []"><b style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">生成式</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">AI</span></span></span></span></b><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">（</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">Generative AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">，简称</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">GenAI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">）</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;" data-pm-slice="0 0 []"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">根据</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">NIST</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">的定义，生成式</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">是指模拟输入数据的结构和特征以生成衍生的合成内容的人工智能模型，这些内容可以包括图像、视频、音频、文本和其他数字内容。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;" data-pm-slice="0 0 []"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">Gartner</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">将</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">GenAI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">定义为从数据中学习“工件</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">(Artifacts)</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">表示”的人工智能技术，并使用它来大规模生成全新的、完全原始的工件，以保持与原始数据的相似性。</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><br/></span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><b style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">大语言模型</span></span></span></b><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">（</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">Large Language Model</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">，简称</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">LLM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">）</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">根据</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">Gartner</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">的定义，大语言模型是指通过</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">在大量文本上接受训练，使其能够解释和生成类似人类的文本输出的一种模型。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 82, 255);">通常，</span></span><b style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 82, 255);">LLM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 82, 255);">属于一种</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span></b><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 82, 255);">，但</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 82, 255);">不一定都是</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 82, 255);">LLM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 82, 255);">。当前网络空间安全领域应用</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 82, 255);">主要就是指利用</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 82, 255);">LLM，因此二者经常混用</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 82, 255);">。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><b style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">大模型</span></span></span></b><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">（</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">Large Model</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">，简称</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">LM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">）</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">大模型通常指的是具有庞大参数数量和复杂结构的机器学习或深度学习模型，具有参数规模大、架构规模大、训练数据量大和算力需求大等特点。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 82, 255);">注意：大模型不等于大语言模型！</span><span textstyle="" style="color: rgb(0, 0, 0);">大语言模型只是一种大模型的具体表现。</span></span><b style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">LM</span></span></span></b><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">既可以用于生成式</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">，也可以用于判别式</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">。现在很多人经常提“大模型</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">”</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">，同时将其与“大语言模型”等同看待，可能是因为讲“大模型“比较顺口，而讲“大语言模型”有点冗长，或者“</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">LLM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">“的发音很拗口，其实大语言模型（</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">LLM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">）和大模型（</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">LM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">）不是一个意思，需要加以辨别。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><b style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">小模型</span></span></span></b><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">（</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">Small Model</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">）</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">顾名思义，小模型就是相对大模型而言，具有参数规模小、架构规模小，算力需求较小的特点，特别适用于算力资源有限的环境中。这里的小是跟大相较而言的，没有绝对的数值区间，跟</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">1000</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">万参数模型比，</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">80</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">亿参数算大，但跟</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">1000</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">亿参数模型比，</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">80</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">亿就算小了。大模型和小模型有各自适合的应用场景，实际应用中要按需而定，并可以互相配合。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 82, 255);">当前，人们经常提及“大模型</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 82, 255);">+</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 82, 255);">小模型“、”大小模型协同“的概念</span><span textstyle="" style="color: rgb(0, 0, 0);">，通常（但不绝对）是指在生成式</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">领域，使用大规模参数的</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">LLM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">和小规模参数语言模型（</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">SLM</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">）混合搭配的方式实现最优化算力配置、最大化应用效果。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">随着GenAI技术的飞速发展，现在在较低硬件配置的计算机上就能运行特定领域下实际效果相当不错的小模型，而此时的小模型也常常裁剪为领域专用语言模型（DSLM，</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">Domain-specific language models</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">）。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><b style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);">传统</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);">AI</span></span></span></span></b></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">传统AI没有明确定义，只是一种表达方式，泛指除了</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">GenAI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">之外的</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">，譬如传统的符号主义的</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">，非神经网络的机器学习，使用神经网络的判别式</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">，统计分析技术（数据科学），知识图谱等技术。通常这些</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">技术在</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">GenAI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">大行其道之前已经有了较为成熟的应用，包括当前已经大量使用在网络空间安全领域的各种非生成式</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">，譬如基于规则推理的关联分析、基于各种机器学习的异常检测等。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">GenAI和传统AI的区别</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">仅针对安全运营领域而言，GenAI（以及后面讨论的Agentic AI）相较于传统AI，有很大的优势：</span></span></span></p><ul style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px 0px 0px 1.2em;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;list-style-type: circle;" class="list-paddingleft-1"><li style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;font-weight: bold;">GenAI</span></span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;font-weight: bold;">具有较高的</span></span><b style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;font-weight: bold;">普适应</span></span></b><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">。不同于传统</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">的专用性，</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">向通用</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">（</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">AGI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">）迈出了一步，一个模型能够解决多个问题。安全运营的每个领域、运营过程的每个环节都可以利用同一套</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">，简化工作过程、提升工作效率。在</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">的赋能下，安全运营</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">的整体运营效率可以获得巨大提升。</span></span></span></p></li><li style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;font-weight: bold;">GenAI</span></span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;font-weight: bold;">具有较强的</span></span><b style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;font-weight: bold;">普惠性</span><span textstyle="" style="font-size: 17px;font-weight: normal;">（有的叫民主化）</span></span></b><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">。</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">通过自然语言交互的体验方式，降低了对应用型技能（如编码、特定规则的语法、工具调用等）的要求，让广大运营人员可以更快上手，更便捷的进行操作，更聚焦安全运营领域的业务型技能（如特定威胁响应的战法、独特的安全知识等）。</span></span></span></p></li><li style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;font-weight: bold;">GenAI</span></span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;font-size: 12pt;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;font-weight: bold;">让</span></span><b style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;font-weight: bold;">知识价值快速释放</span></span></b><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">。以往安全运营专家的各种知识（譬如各种安全通用知识和安全报告，各类安全情报，基于资产和漏洞的安全姿态，告警研判、事件调查与响应的技战术方法，包括日志解析规则、关联分析规则、剧本在内的各种安全内容）需要事先经过特定的转换（甚至代码开发）才能加载到安全运营平台中，进而发挥作用。同时，这些知识的验证、更新过程也同样繁琐，甚至无法闭环。</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">和智能体则能够以近乎自然语言的形式接收、验证和更新这些知识，并将它们充分的连接起来，催动安全运营平台的运转，让知识价值快速释放。</span></span></span></p></li></ul><p style="-webkit-tap-highlight-color: transparent;margin: 24px 0px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(68, 114, 196);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">复合式</span></span><span style="-webkit-tap-highlight-color: transparent;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(68, 114, 196);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span style="-webkit-tap-highlight-color: transparent;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">AI</span></span></span></span></span><span style="-webkit-tap-highlight-color: transparent;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;color: rgb(68, 114, 196);box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">（</span></span><span style="-webkit-tap-highlight-color: transparent;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">Composite AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 0, 0);font-weight: bold;">）</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">这是</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">Gartner</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">提出来的面向工程化应用的</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">AI应用模式</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">，指组合利用不同</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">技术（包括</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">GenAI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">、数据科学、机器学习、知识图谱等技术）来提高学习效率，以生成层次更丰富的知识表示</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">。可以将复合式</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">理解为</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">GenAI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">和传统</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">的结合。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">注意，GenAI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="font-size: 17px;">不是对传统</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="font-size: 17px;">的替代。尽管</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="font-size: 17px;">具有很多优秀特性，但在针对很多专门的运营问题时，传统</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="font-size: 17px;">依然有效，而且表现得更加高效。当前</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="font-size: 17px;">自身存在的诸多不确定也限制了其发挥，需要利用传统</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="font-size: 17px;">予以约束。在工程实践中，不应追求单一类型的</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="font-size: 17px;">包打天下，而是要从从性价比的角度，按需使用最合适的</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="font-size: 17px;">。复合式AI就是一个将多种不同</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="font-size: 17px;">技术整合到一起的</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 17px;">AI应用模式</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="font-size: 17px;">。</span></span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;line-height: 1.75em;"><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgb(68, 114, 196);"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">当前，国际上主流的安全厂商都是用复合式</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">赋能安全，而非仅仅依靠生成式</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">，譬如</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">Palo Alto Networks</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">的精准</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">（</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">Precision AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">），</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">CrowdStrike</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">的夏洛特</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">（</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">Charlotte AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">），SentinelOne的P</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 0, 0);">urple </span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">AI以及</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">Splunk AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="color: rgb(0, 0, 0);">等。</span></span></span></p><p><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">从GenAI到AI Agent</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">GenAI在安全运营中的应用和局限</span></span></p><p><span leaf="">以LLM为主的GenAI的引入，为安全运营带来了很多丰富的应用场景，譬如：</span></p><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">增强告警分析能力：告警信息解释、告警富化；</span></p></li><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">简化安全内容的生成：基于自然语言生成查询语句、生成关联分析规则、生成检测脚本；</span></p></li><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">加速安全事件响应：事件解释、基本的事件调查与信息增强、生成事件响应建议/计划/剧本；</span></p></li><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">助力暴露管理：资产/漏洞识别、资产/漏洞去重与合并、基本的漏洞处置优先级判断；</span></p></li><li><p><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">加速SOC度量：总结事件响应过程、生成资产/漏洞/事件报告、生成日报周报等报告。</span></p></li></ul><p style="margin-top: 24px;"><span leaf="">但是，简单使用LLM，或者将其封装到聊天机器人中，始终都是让LLM处理一个个单独的操作，一个安全运营任务的整体过程还是由人类分析师全程操控：从设定任务目标到分解任务步骤，只是将其中的某些步骤人为分派给LLM进行处理，然后还需要人类分析师自己判断并决定下一步需要提交给LLM的问题，并最终由人类分析师决定任务是否完成。整个任务操作过程中，LLM都是被动服务的，此时的LLM只是一个更好的“内容生成”工具而已。</span></p><p style="margin-top: 24px;"><span leaf="">如何进一步发挥LLM的价值？</span></p><p style="margin-top: 24px;"><span leaf="">安全运营的最终落脚点是运营，是持续开展各类运营工作（流程、任务）。</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;margin-top: 24px;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">如果</span><span leaf="">LLM能够赋能运营流程和任务，那么将极大提升运营效率。而智能化（包括自主、自动）任务执行的最佳技术就是AI Agent。AI Agent在GenAI之前就已经存在。在安全运营领域，现有最典型的AI Agent就是SOAR（安全编排自动化与响应）。</span></p><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">AI Agent（智能体）</span></span></p><p><span leaf="">根据人工智能促进协会（AAAI）的定义，智能体是指能感知环境、处理信息并自主决策行动的智能实体。</span></p><p><span leaf="">根据Gartner的定义，智能体是利用人工智能技术进行感知、决策、采取行动，并在数字或物理环境中自主或半自主地追求既定目标的软件实体。</span></p><p><span leaf="">注意，<span textstyle="" style="font-weight: bold;">关于AI Agent的中文翻译一直没有统一</span>。<span textstyle="" style="color: rgb(0, 82, 255);">笔者认为，Agent可以翻译为“行为体”，而AI Agent则翻译为“人工智能行为体”，简称“智能体”。业界通常还有一种翻译，将Agent称作智能体，而将AI Agent称作AI智能体，笔者认为欠妥，因为AI就已经具有智能的意思。如果称作AI智能体，把AI展开，不就等于是人工智能智能体吗？不通顺。</span></span></p><p><span leaf="">此外，Agent（行为体）这个概念的历史更为悠久，当AI应用到Agent中之后，就出现了AI Agent。可以认为，AI Agent是Agent发展的必然阶段，从这个意义上来看，AI Agent可以跟Agent互换使用。</span></p><p><span leaf="">同时，AI Agent中的AI并不限于当前热门的LLM/GenAI，而是泛指各种AI，譬如基于编排的专家系统（如SOAR），甚至基于规则的专家系统（如关联分析引擎）都可以看作是某种AI Agent。</span></p><p><span leaf="">LLM的引入将AI Agent带入了一个更高</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">（更自主）的</span><span leaf="">境界。而<span textstyle="" style="font-weight: bold;">LLM与AI Agent的结合则反过来将GenAI应用模式从经典的“内容生成”转变为“任务执行”</span>。有的人将基于LLM的智能体称作LLM Agent。</span></p><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">智能体的基本构成</span></span></p><p><span leaf="">智能体</span><span leaf="">通过 “感知 - 推理 - 行动” 循环，自主完成目标导向的任务，其</span><span leaf="">基本构成包括规划决策模块、记忆模块、工具模块和行动模块4个部分。</span></p><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">规划决策模块</span>是</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">智能体</span><span leaf="">的核心，根据外部输入和记忆模块中的历史信息，分析目标，分解任务，制订行动计划，形成“行动指令”，并交给行动模块执行，并获得执行结果，再判断下一步行动计划，直到做出完成任务的决策，返回最终结果。</span></p></li><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">记忆模块</span></span><span leaf="">存储</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">智能体</span><span leaf="">运行过程中的关键信息，包括 “历史交互数据、任务状态、环境知识”，支撑决策时的上下文关联与经验复用，避免 “一次性决策”。</span></p></li><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">工具模块</span>存放了</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">智能体</span><span leaf="">为达成任务目标所需的各种应用程和跟外部环境交互的应用接口，包括获取相关信息，实施控制等。</span></p></li><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">行动模块</span></span><span leaf="">将规划决策模块生成的 “行动指令” 转化为具体操作，与外部环境进行交互，感知环境（如获取信息），改变环境（如控制设备）。完成 “从决策到落地” 的闭环。</span></p></li></ul><p style="margin-top: 24px;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">智能体的自主化演进</span></span></p><p><span leaf="">自主化程度是衡量</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">智能体</span><span leaf="">的最核心指标，</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">智能体</span><span leaf="">的发展过程就是一个自主化程度不断提升的过程。</span></p><p><span leaf="">自主化的关键在于</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">智能体</span><span leaf="">的规划决策能力。</span></p><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">初级的规则驱动的智能体</span></span></p><p><span leaf="">目前，业界普遍将规则驱动的、无自主学习能力的</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">智能体</span><span leaf="">称作初级（L1）</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">智能体</span><span leaf="">，这类</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">智能体</span><span leaf="">的典型代表就是SOAR。SOAR的剧本相当于</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">智能体</span><span leaf="">规划决策模块中的执行指令，但这个指令是静态的，预先设定和编排的，不是</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">智能体</span><span leaf="">自主推理出来的。</span></p><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">基础的应用LLM的智能体</span></span></p><p><span leaf="">LLM应用于</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">智能体</span><span leaf="">的初期，</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">受限于</span><span leaf="">LLM的能力，基本被当作规则驱动</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">智能体</span><span leaf="">的工具来调用。<span textstyle="" style="font-weight: bold;">此时，整个</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">智能体的任务规划依然是预设的，预先编排好的，但是在执行任务的过程中会根据预设的规划调用LLM，利用LLM的内容生成能力来提升智能体的智能化水平</span>。</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">譬如，一个传统的外网攻击告警调查剧本可以分为三步：（1）比对外网攻击IP的威胁情报；（2）核对内网被攻击IP的资产及漏洞信息；（3）将攻击IP的情报比对结果和被攻击IP的资产及漏洞信息进行整合（通过写脚本或者固化的程序代码），进行输出。</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">在引入LLM后，这个外网攻击告警调查剧本可以改进为：</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">（1）比对外网攻击IP的威胁情报；（2）核对内网被攻击IP的资产及漏洞信息；（3）将攻击IP的情报比对结果和被攻击IP的资产及漏洞信息，连同告警信息一并提交给LLM，LLM基于这些信息生成一段人类可读性极强的告警调查汇报，包括调查结论、调查过程、处置建议等信息。这时，LLM就相当于一个工具，能够在提示词的作用下自主地整合相关信息，编写相关内容。</span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">通过上述例子，可以看到LLM确实提升了智能体的价值。</span></p><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">基于LLM的目标驱动的智能体</span></span></p><p><span leaf="">随着LLM的快速迭代，以及智能体框架的飞速发展，<span textstyle="" style="font-weight: bold;">新一代的智能体以LLM为思考中枢，智能体的规划决策模块在目标驱动下，</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">摆脱之前预设的规划流程，</span></span><span leaf=""><span textstyle="" style="font-weight: bold;">通过LLM进行推理和决策，自主生成任务规划，并自主选择工具，自动执行，达成目标</span>。</span></p><p><span leaf="">这种基于LLM的目标驱动智能体开启了Agentic AI时代，并很快发展到多智能体协作的新高度。</span></p><p><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">迈向Agentic AI时代</span></span></p><p><span leaf="">Agentic AI这个概念最早见于OpenAI在2023年12月发布的一份白皮书，但其真正成形要归功于吴恩达。他在2024年初红杉资本举办的AI峰会上提及，随后又在Snowflake峰会上进行了完善，并给出了Agentic推理的四种设计模式：反思、工具使用、规划和多行为体协作，从而奠定了Agentic AI的框架基础。2024年10月，Gartner发布2025年十大战略技术趋势，Agentic AI居首。</span></p><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">Agentic AI（自主式AI）</span></span></p><p><span leaf="">Gartner将Agentic AI定义为目标驱动的软件实体，这些实体被授予代表组织自主决策和采取行动的权限，使用人工智能技术——结合记忆、规划、感知、工具和护栏等组件——来完成任务并实现目标。</span></p><p><span leaf="">根据AAAI的定义，Agentic AI是指将GenAI和 LLM 集成到自主代理框架中，旨在利用此类模型的生成能力来增强动态环境中的交互性、创造力和实时决策。</span></p><p><span leaf="">Google则将Agentic AI定义为一种使软件系统能够自主行动的AI，它基于目标做出决策并采取行动，最大限度地减少人工干预。</span></p><p><span leaf="">注意，<span textstyle="" style="font-weight: bold;">目前国内尚未形成对Agentic AI这个术语的统一中文翻译</span>。Gartner中国称之为“代理式AI”；IDC将Agentic AI称作“自主智能体集群”，Agentic取义为自主；还有的人翻译为“能动型AI”。<span textstyle="" style="color: rgb(0, 82, 255);">笔者认为，“代理”二字跟安全运营平台的部署在被监测端点上的“代理”（英文也是Agent）软件相冲突，</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 82, 255);">直译为“代理式AI”不妥。考虑到Agentic AI的核心特征之一就是自主化，因此</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">建议称Agentic AI为“自主式AI”</span>，同Autonomous AI。</span></p><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">Agentic AI和AI Agent的关系</span></span></p><p><span leaf="">目前，不少人（如</span><span leaf="">康奈尔大学论文《Agentic AI Systems: A Survey》）</span><span leaf="">从系统架构（复杂性）视角来看待AI Agent和Agentic AI的关系，<span textstyle="" style="font-weight: bold;">将AI Agent定位为单一的智能体，而将Agentic AI看作是多智能体协作集群</span>，以完成更为复杂的任务。Forrester和IDC亦持此观点。</span></p><p><span leaf="">但<span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">笔者更接受吴恩达基于能力程度的视角，认为Agentic AI代表了不同自主程度的智能实体的总称</span>。</span><span leaf="">吴恩达在《Agentic AI: Foundations and Applications》及公开演讲中，尤其是最近发表的Agentic AI公开课中，将 Agentic AI 定义为 “能自主完成感知环境→设定目标→执行行动→反馈优化闭环的 AI 系统”，核心判断标准是 “是否具备自主能力”，而非 “智能体数量”。</span></p><p><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">笔者认为，AI Agent是一种对Agent的类型划分，关键点还是落在Agent上，AI Agent代表了所有利用AI赋能的Agent，但具体如何赋能、赋能到什么程度，尤其是Agent的“自主程度”（Agency / Agenticness，暂译为“自主程度”）无法表达。正如吴恩达所述，“Agent这个名词是一个二元性的术语，无法进一步区分不同自主程度的Agent”。而</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">Agentic AI代表了一种AI技术的类型划分</span><span textstyle="" style="color: rgb(0, 82, 255);">，并可以认为是生成式AI的一个演进方向，关键点落在了AI上。这时，如吴恩达所言，“Agentic作为一个形容词可以（从AI这个视角来）观察和思考不同自主程度的Agent”。</span>下图是吴恩达Agentic AI公开课中的胶片：</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001385" class="rich_pages wxw-img" data-ratio="0.44074074074074077" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=db0f2832&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMeDwvCagM0oBNjpib73D2bNe7iaFDDfWGV2wUWxEUMLAaCTo0uaQ8g23dTibKQDIOMCmhWK5eLe27wqg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="">类似地，Gartner也展示了Agentic AI不同层级的自主性。</span></p><p><span leaf=""><img data-imgfileid="100001399" class="rich_pages wxw-img" data-ratio="0.5518518518518518" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=8b9967a6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcW5IG0ib1OcibgHc97NqwYicgMEvGHQXocFqZIbPYM1LawIWbn7g2oWC0rWOYUgcGSJlgFFGwHxdibHA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span leaf="">综上所述，<span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">Agentic AI与</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">AI Agent与是“抽象框架与</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">具体载体”的包含关系</span>，核心关联围绕 “自主能力” 展开，具体可概括为三点：</span></p><ol style="list-style-type: decimal;" class="list-paddingleft-1"><li style="-webkit-font-smoothing:antialiased;box-sizing:border-box;-webkit-tap-highlight-color:rgba(0, 0, 0, 0);outline:none;border:0px solid;margin:8px 0px;padding:0px 0px 0px 4px;font-size:17px;font-weight:400;line-height:24px;color:rgb(0, 0, 0);list-style-type:decimal;overflow-anchor:auto;"><p><strong style="-webkit-font-smoothing: antialiased;box-sizing: border-box;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: none;border: 0px solid;margin: 0px;padding: 0px;font-weight: 700;color: rgb(0, 0, 0) !important;font-size: 16px;line-height: 28px;overflow-anchor: auto;"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI 是统称，AI Agent 是落地实体</span></span></strong></p><p><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI 是对 “具备自主能力的 AI 系统” 的抽象框架（或能力范畴），强调 “从被动工具到主动执行者” 的属性；而 AI Agent 是这一框架的具体实现载体 ，且被纳入 Agentic AI 的覆盖范围。</span></span></p></li><li style="-webkit-font-smoothing:antialiased;box-sizing:border-box;-webkit-tap-highlight-color:rgba(0, 0, 0, 0);outline:none;border:0px solid;margin:8px 0px;padding:0px 0px 0px 4px;font-size:17px;font-weight:400;line-height:24px;color:rgb(0, 0, 0);list-style-type:decimal;overflow-anchor:auto;"><p><strong style="-webkit-font-smoothing: antialiased;box-sizing: border-box;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: none;border: 0px solid;margin: 0px;padding: 0px;font-weight: 700;color: rgb(0, 0, 0) !important;font-size: 16px;line-height: 28px;overflow-anchor: auto;"><span leaf=""><span textstyle="" style="font-size: 17px;">AI Agent 的自主能力，是 Agentic AI 的核心体现</span></span></strong></p><p><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI 的核心特征是 “自主闭环”，这一特征需通过 AI Agent 落地：无论是初级的单智能体（如规则驱动的 SOAR），还是高级的多智能体（如Agentic SOP/SOC），其自主行动能力都是 Agentic AI 的具象化表现 —— 没有 AI Agent，Agentic AI 就只是抽象的 “自主理念”，无法落地产生价值。</span></span></p></li><li style="-webkit-font-smoothing:antialiased;box-sizing:border-box;-webkit-tap-highlight-color:rgba(0, 0, 0, 0);outline:none;border:0px solid;margin:8px 0px;padding:0px 0px 0px 4px;font-size:17px;font-weight:400;line-height:24px;color:rgb(0, 0, 0);list-style-type:decimal;overflow-anchor:auto;"><p><strong style="-webkit-font-smoothing: antialiased;box-sizing: border-box;-webkit-tap-highlight-color: rgba(0, 0, 0, 0);outline: none;border: 0px solid;margin: 0px;padding: 0px;font-weight: 700;color: rgb(0, 0, 0) !important;font-size: 16px;line-height: 28px;overflow-anchor: auto;"><span leaf=""><span textstyle="" style="font-size: 17px;">AI Agent 的等级梯度，对应 Agentic AI 的自主程度</span></span></strong></p><p><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI 是 一个“自主能力的频谱”（从低自主到高自主），而 AI Agent 的不同等级恰好对应这一频谱的不同位置：初级 AI Agent（如传统 SOAR）对应低自主 Agentic AI，高级 AI Agent（如多智能体协作系统）对应高自主 Agentic AI。</span></span></p></li></ol><p style="margin-top: 24px;"><span leaf="">下图展示了Agentic AI中的不同自主程度的智能体实例。</span></p><p style="text-align: center;"><span leaf=""><img data-imgfileid="100001387" class="rich_pages wxw-img" data-ratio="0.8788177339901477" data-type="png" data-w="1015" src="https://wechat2rss.xlab.app/img-proxy/?k=c1f291e0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMd2YKsEUSISiajjQ0wjHyjW4QaaWibOF7xLFy0x7Gteelwiccb9rsqXUt8ynYUWsqHqNZicQdyFaZAGUg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: justify;"><span leaf="">此外，在业界实践中，我们<span textstyle="" style="color: rgb(0, 82, 255);">可以将</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 82, 255);">以GenAI/LLM为推理（规划和反思）中枢的智能体（即“</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);font-weight: normal;">基于LLM的目标驱动的智能体</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="color: rgb(0, 82, 255);">”）称为</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">狭义的Agentic AI</span>。</span></p><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">Agentic System（自主化系统）</span></span></p><p><span leaf="">Agentic System是指使用了Agentic AI 技术的应用系统，也叫Agentic AI应用。Agentic AI的最大价值在于其在具体系统中的应用，以及在系统中表现出的自主性。<span textstyle="" style="font-weight: bold;">这种自主性的获得不仅要依靠智能体本身，还有赖于与智能体交互的外部环境</span>。</span></p><p><span leaf="">最简单的Agentic系统至少包括一个智能体，但一个Agentic系统通常都会包括多个智能体。这些智能体自主化程度不一，有的是互相独立的，还有的是互相协作的。下图是Gartner提供的一个展示不同自主性智能体之间的协作的示意图。</span></p><p style="text-align: center;"><span leaf=""><img data-imgfileid="100001390" class="rich_pages wxw-img" data-ratio="0.5601851851851852" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=cdfb06cf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMd2YKsEUSISiajjQ0wjHyjW4T4e2icwIs8qoJMJnvosRQUGVnZDNOBQhjAibSSQHibInbbWCCoBUr2Gfg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">需要注意的是，</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">Agentic系统中的</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: left;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">智能体的自主性并非越高越好</span>，根据应用场景和任务目标，合适的才是最好的。譬如，对于确定的、简单重复的任务而言，规则驱动的、预编排的智能体工作流程（如SOAR剧本）更加高效且稳定。又譬如，在威胁调查和威胁猎捕的时候，高自主性智能体可能比较适用，而在容错率很低的威胁处置的时候，预编排的SOAR剧本可能更加合适。总之，高低自主性的智能体要结合使用。</span></p><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">Agentic SOP / Agentic SOC（自主化安全运营平台/自主化安全运营中心）</span></span></p><p><span leaf="">可以将Agentic AI赋能的SOP/SOC系统称为Agentic SOP/ </span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Agentic </span><span leaf="">SOC（简称ASOP/ASOC），即自主化安全运营平台/安全运营中心。<span textstyle="" style="color: rgb(0, 82, 255);">这里的Agentic AI整体上应具备中等（L3）以上的自主性，采用以LLM为思考中枢的自主式多智能体技术来赋能SOP/SOC</span>。</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">显然，ASOP/ASOC是面向安全运营领域的特定Agentic系统。</span></p><p><span leaf="">对ASOP/ASOC而言，Agentic AI将LLM的思考力和智能体的行动力结合起来，借助知识检索和工具调用，一方面可以主动获取安全分析所需的情境（上下文）数据，基于更多的相关性数据进行思考、理解和内容生成，做出更全面的研判和调查；另一方面可以编排各种安全控制指令，调整安全防御体系的工作姿态，做出更恰当的响应。同时，借助多智能体（也叫集群智能体）技术，将整个思考和行动的过程分解到不同的智能体上，让每个细化的目标执行过程更加专业精准，最终更好地实现整体目标。</span></p><p><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">SOP/SOC的自主化水平划分</span></span></p><p><span leaf="">基于前面的分析，我们可以建立一个针对安全运营平台（SOP）/安全运营中心（SOC）的自主化水平梯度的划分模型，如下图所示：</span></p><p style="text-align: center;"><span leaf=""><img data-imgfileid="100001392" class="rich_pages wxw-img" data-ratio="0.5925925925925926" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=31c8e22e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMd2YKsEUSISiajjQ0wjHyjW496yoPQvGjA9VbMrfzpcSVby1ESMzZoudGhoKhSYzUgRk4iazuK3QPIQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span leaf="">L0表示非自主化SOP/SOC。这时，安全运营工作完全依赖人类，各种安全运营工作都采用人工操作来完成，人类分析师手工配置和操作各种安全运营工具。</span></p><p><span leaf="">L1表示具备初步自主性的SOP/SOC。这时，安全运营工作实现了对重复性工作的自动化，采用基于规则的专家系统（如SOAR）自动执行，流程和工作步骤都是预先定义好的，各种安全运营工具的调用也是提前编排好的。</span></p><p><span leaf="">L2表示引入LLM并具备了一定的自主性的SOP/SOC。这时，安全运营工作以人为主，LLM充当人类的辅助工具，安全运营工作的流程和步骤依然是预先定义好的，工具调用也依然是预先编排好的，但运营的部分流程节点调用了LLM，实现了部分工作的自主化。</span></p><p><span leaf="">L3表示以LLM为思考中枢的真正具备自主规划和决策的SOP/SOC（也称作SOC4.0或Agentic SOP/SOC）。这时，LLM成为了人类的伙伴而非简单工具，但人类仍需要参与到运营的各个环节（包括配置、监督、决策、优化等），安全运营工作基于LLM进行规划和决策，自主生成达成任务目标的流程和步骤，并能够自主地调用安全运营工具（包括LLM和基于传统AI的工具），但这些工具需要提前准备好。</span></p><p><span leaf="">L4表示高度自主化的SOC/SOP。这时，AI将自主开展大部分安全运营工作，人类更多行使监督和指导的角色，主要运营工作的流程和步骤都是自主生成、自主决策、自主优化的，并且能够自主创造新的安全运营工具并按需使用。</span></p><p><span leaf="">图中没有绘制L5（完全自主化）级别的SOP/SOC，因为在可以预见的未来，这个级别是无法达成的，并且可能永远也无法达成。</span></p><p><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">总结</span></span></p><p><span leaf="">随着以LLM为代表的GenAI能力的不断提升，以及Agentic AI技术框架的不断演进，以LLM为核心的目标驱动的自主智能体技术将不断深入应用到安全运营领域。未来的安全运营平台/安全运营中心将极大被Agentic AI赋能，并催生出全新的安全运营的人员组织架构、数据架构和流程架构。</span></p><p><span leaf="">【参考资料】</span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484993&amp;idx=1&amp;sn=506b9c0de108b2293d71c15750f0d95c&amp;scene=21#wechat_redirect" textvalue="从RSAC2025看安全运营技术发展趋势" data-itemshowtype="0" linktype="text" data-linktype="2">从RSAC2025看安全运营技术发展趋势</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="迈向AI赋能的SOC4.0时代" data-itemshowtype="11" linktype="text" data-linktype="2">迈向AI赋能的SOC4.0时代</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484848&amp;idx=1&amp;sn=0f7f582e241603ec68bc85be3926998c&amp;scene=21#wechat_redirect" textvalue="是时候重新定义安全运营平台了" data-itemshowtype="0" linktype="text" data-linktype="2">是时候重新定义安全运营平台了</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkzMzkzMjI4OQ==&amp;mid=2247483748&amp;idx=1&amp;sn=403a04f2e7ab7b101d5b34378f1853ba&amp;scene=21#wechat_redirect" textvalue="自主化安全运营平台技术解析与实践" data-itemshowtype="0" linktype="text" data-linktype="2">自主化安全运营平台技术解析与实践</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzkzMzkzMjI4OQ==&amp;mid=2247483723&amp;idx=1&amp;sn=92f7d286203be021a7b7fc0c6a36a24a&amp;scene=21#wechat_redirect" textvalue="20张胶片看清中国安全运营中心发展历程，掌握SOC4.0五大特征！" data-itemshowtype="0" linktype="text" data-linktype="2">20张胶片看清中国安全运营中心发展历程，掌握SOC4.0五大特征！</a></span></p><p><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484842&amp;idx=1&amp;sn=38dba05e2a0024b71d81d1d9b3e74a6c&amp;scene=21#wechat_redirect" textvalue="2024年安全运营技术趋势回顾" data-itemshowtype="0" linktype="text" data-linktype="2">2024年安全运营技术趋势回顾</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><a href="2247485048">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=05747810&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyNzMxOTAwMw%3D%3D%26mid%3D2247485048%26idx%3D1%26sn%3D4bceff5bb6514bacc86b69ce83b0fca1">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 21 Oct 2025 12:00:00 +0800</pubDate>
    </item>
    <item>
      <title>SANS 2025年SOC调查报告解读</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247485019&amp;idx=1&amp;sn=d1e7cfd9d71ef8527d505156299b9b7a</link>
      <description>深入解读SOC的最大挑战，人员配置与选育留，核心职能，涉及的技术和工具满意度，以及关键指标设计</description>
      <content:encoded><![CDATA[<p>
原创 <span>Benny Ye</span> <span>2025-08-28 12:07</span> <span style="display: inline-block;">北京</span>
</p>

<p>深入解读SOC的最大挑战，人员配置与选育留，核心职能，涉及的技术和工具满意度，以及关键指标设计</p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=0c1ca03e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdUhziaX6bGc9q48z6kTpSGibR6QYJQRvbpF1ebFzX2BicFMxYIxiciaUibabmss3bic5SKtWMas7fQajuicA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="line-height: 1.75em;"><em style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: italic;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">【引言】本文不是报告的译文，是作者对报告及调查原始数据的个人理解和解读，以及基于作者自身实践的思考。注意，本文中有很多图表在原始报告中都没有。</span></span></em></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001368" class="rich_pages wxw-img" data-ratio="0.737037037037037" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=e9e0e733&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdUhziaX6bGc9q48z6kTpSGibxTbiaAYRdHnSyUUzhgFOG4bEl4cicUwJxF4pypyAJSRRjHplYKzAgM8A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.75em;"><em style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: italic;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-style: normal;">2025年7月，SANS发布了《2025年SOC调查报告》。这次调研受访者来自57个国家（主要是美国），有效数量为447个，主要来自银行/金融、网络安全、技术和政府四类客户。受访者最大群体是安全管理员及安全分析师。</span></span></em></p><p style="line-height: 1.75em;margin-top: 24px;"><em style="-webkit-tap-highlight-color: transparent;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: italic;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;font-style: normal;">主要发现</span></span></em></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 1.75em;"><span leaf="">79% 的安全运营中心（SOC）实现<span textstyle="" style="font-weight: bold;"> 24 小时不间断运营</span>。</span></p></li><li><p style="line-height: 1.75em;"><span leaf="">85% 的受访者表示，<span textstyle="" style="font-weight: bold;">终端安全告警</span>是其响应工作的主要触发因素。</span></p></li><li><p style="line-height: 1.75em;"><span leaf="">42% 的 SOC 会将<span textstyle="" style="font-weight: bold;">所有接收数据导入安全信息与事件管理</span>（SIEM）系统，但往往缺乏数据检索或管理计划。</span></p></li><li><p style="line-height: 1.75em;"><span leaf="">43% 的受访者表示，招聘时<span textstyle="" style="font-weight: bold;">最看重的技术是 SIEM</span> 相关能力，这一比例是排名第二的两倍多。</span></p></li><li><p style="line-height: 1.75em;"><span leaf="">42% 的 SOC 使用 “开箱即用” 的人工智能 / 机器学习（AI/ML）工具，<span textstyle="" style="font-weight: bold;">未进行任何定制化调整</span>。</span></p></li><li><p style="line-height: 1.75em;"><span leaf="">69% 的 SOC 主要将网络威胁情报（CTI）数据用于事件响应。</span></p></li><li><p style="line-height: 1.75em;"><span leaf="">69% 的 SOC 仍依赖<span textstyle="" style="font-weight: bold;">手动或大部分手动流程来报告指标</span>。</span></p></li><li><p style="line-height: 1.75em;"><span leaf="">人员配置齐全的 SOC 最<span textstyle="" style="font-weight: bold;">常见规模为 2-10 人</span>。</span></p></li><li><p style="line-height: 1.75em;"><span leaf="">SOC 人员最常见的<span textstyle="" style="font-weight: bold;">任职年限为 3-5 年</span>。</span></p></li><li><p style="line-height: 1.75em;"><span leaf="">73% 的组织允许 SOC 团队成员至少在<span textstyle="" style="font-weight: bold;">部分时间远程办公</span>。</span></p></li><li><p style="line-height: 1.75em;"><span leaf="">62% 的 SOC 专业人员认为，其所在组织在留住顶尖人才方面做得不够。</span></p></li><li><p style="line-height: 1.75em;"><span leaf="">42% 的 SOC 人员不了解 SOC 的预算情况，这表明技术团队与业务团队之间存在沟通脱节。</span></p></li></ul><p style="line-height: 1.75em;margin-top: 24px;"><em style="-webkit-tap-highlight-color: transparent;margin-right: 0px;margin-bottom: 0px;margin-left: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: italic;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;font-style: normal;">SOC定义梳理与现状画像</span></span></em></p><p style="line-height: 1.75em;"><em style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: italic;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-style: normal;">SANS根据调研反馈的数据，对SOC进行了定义梳理。</span></span></em></p><p data-pm-slice="0 0 []" style="line-height: 1.75em;"><span leaf="">2025 年的现代 SOC 围绕若干核心要素构建，这些要素决定了其运作方式、优势所在以及应对不断演变威胁的适应能力。其中，<span textstyle="" style="font-weight: bold;">SOC最关键的4个要素：核心能力、运营模式、架构和人员配置策略</span>。</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p data-pm-slice="0 0 []" style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-weight: bold;">核心能力</span>：指SOC 的核心职能及日常处理的任务/活动/流程。</span></p></li></ul><ul class="list-paddingleft-1"><li><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: bold;">运营模式：即自营或外包运营，</span><span textstyle="" style="font-weight: normal;">指</span>由内部团队处理的任务，以及外包给第三方的任务，通常针对每项核心能力都有特定的运营模式。</span></strong></li><li><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: bold;">架构</span>：数据收集、存储与访问的结构设计；</span></strong></li><li><strong><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-weight: bold;">人员配置与运营时长</span>：团队规模、角色分工、人员选育留、所需技能组合，以及 SOC 是 24 小时运营还是限时运营。</span></strong></li></ul><p style="line-height: 1.75em;margin-top: 24px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(0, 82, 255);">【笔者注】通过以上SOC定义梳理，可以清晰地感受到SOC不是一个技术，更不是一个技术平台而已，而是一个组织单元，是人、技术、流程等的合集。</span></span></p><p style="line-height: 1.75em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">本次调研数据显示，SOC的基本画像可以表述为：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 1.75em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">核心能力<span textstyle="" style="font-weight: bold;">以告警分诊、威胁检测和事件响应为重点</span>，威胁情报、漏洞管理和威胁猎捕/狩猎为辅助职能。</span></p></li></ul><ul class="list-paddingleft-1"><li><p style="line-height: 1.75em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">拥有 10 名全职团队成员</span>（或同等全职人力），员工<span textstyle="" style="font-weight: bold;">平均任职年限为 3-5 年</span>。</span></p></li><li><p style="line-height: 1.75em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">大部分监控、检测和事件响应工作由内部团队完成</span>，而渗透测试、数字取证、部分威胁情报及其他需要高水平专业知识或特殊技能的职能则外包。</span></p></li><li><p style="line-height: 1.75em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">多采用<span textstyle="" style="font-weight: bold;">集中式架构</span>，云技术应用虽在增长，但仍落后于云采用规模。</span></p></li><li><p style="line-height: 1.75em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">大多数情况下<span textstyle="" style="font-weight: bold;">实现 24 小时运营覆盖，</span>部分 SOC 仍依赖轮班制或 “按需” 升级机制。</span></p></li><li><p style="line-height: 1.75em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">尽管近半数受访者表示<span textstyle="" style="font-weight: bold;">手动报告指标耗时过长，但目前仍采用手动方式</span>报告；自动化应用程度有限。</span></p></li><li><p style="line-height: 1.75em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">高度依赖终端检测与响应（EDR）工具</span>，将其视为最可靠、最成熟的在用工具；<span textstyle="" style="font-weight: bold;">对 AI/ML 工具的满意度最低</span>。</span></p></li><li><p style="line-height: 1.75em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">存储的数据量比以往任何时候都多</span>，往往将所有数据导入 SIEM 或系统日志（syslog），但缺乏明确的管理或分析计划，导致可见性问题。</span></p></li></ul><p style="line-height: 1.75em;margin-top: 24px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="color: rgb(0, 82, 255);">【笔者注】这个画像与笔者之前列举的SOC面临的挑战基本是吻合的。欢迎对号入座。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001360" class="rich_pages wxw-img" data-ratio="0.42592592592592593" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=db4dcdeb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdUhziaX6bGc9q48z6kTpSGibQStupSJFicYTo9Koxa1WklKJKIia1rBytF3OEYuibTUNB8Fd7fszWp2Mg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.75em;margin-top: 24px;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 24px;font-weight: bold;font-style: normal;">SOC发展格局</span></span></p><ol style="list-style-type: decimal;" class="list-paddingleft-1"><li><p style="line-height: 1.75em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;" data-pm-slice="1 1 [&#34;list&#34;,{&#34;type&#34;:&#34;ol&#34;,&#34;style&#34;:&#34;list-style-type: decimal;&#34;,&#34;class&#34;:&#34;list-paddingleft-1&#34;,&#34;start&#34;:null},&#34;listitem&#34;,{&#34;style&#34;:&#34;&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">55%的受访者表示SOC已经成为他们组织必不可少的部分。还有30%的受访者则表示他们使用外部服务商完成SOC相关工作，但无论选择何种方式，<span textstyle="" style="font-weight: bold;">SOC已经成为安全的基础</span>。</span></p></li><li><p style="line-height: 1.75em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">2024年的调研还显示云部署架构成为主流，但今年结果又显示基于本地部署的单一运营的集中式SOC（38%）比基于云的SOC部署（24%）更为流行。这表明，尽管基于云的SOC备受关注，但集中式的本地架构仍然是主流模式。<span textstyle="" style="font-weight: bold;">云愿景与当前部署之间的差距凸显了一个现实：云迁移，尤其是安全运营的云迁移，仍在过渡之中</span>。</span></p><p style="line-height: 1.75em;"><span leaf=""><img data-imgfileid="100001348" class="rich_pages wxw-img" data-ratio="0.80970625798212" data-s="300,640" data-type="png" data-w="783" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=020d45b8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcLmemuxw9gtNarVPq9MIgGiaPSWLC3hIHkto6cO3CWNS3BTiamVOlJJxCxe9gst0TmibYkyOYM4A4mA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p></li><li><p style="line-height: 1.75em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">随着全球政治不确定性在2025年及2026年加剧，<span textstyle="" style="font-weight: bold;">SOC预计将面临对国际数据流的更多审查</span>。地缘政治冲突促使监管机构和组织<span textstyle="" style="font-weight: bold;">更加关注数据的存储方式、存储位置、访问权限以及监控实体</span>。SOC应做好准备，应对有关跨境可见性、第三方监控和数据驻留的棘手问题。这些不仅仅是技术问题，更是法律和战略问题。随着这些议题在议程上的优先级上升，安全领导者应预计到法律、合规和业务利益相关者将更深入地参与其中。</span></p></li><li><p style="line-height: 1.75em;"><span leaf="">今年，把<span textstyle="" style="font-weight: bold;">日志都吐给SOC的倾向更加显著</span>。这不是一个好的趋势，后续数据管理将成为大问题，“数据不能承受之重”，但也反映了用户的诸多无奈。<span textstyle="" style="color: rgb(0, 82, 255);font-weight: normal;">笔者认为，面对这种现状，SOC平台提供者应该有所考虑，这也成为SOC的数据架构变革的一个驱动因素</span>。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001359" class="rich_pages wxw-img" data-ratio="0.600925925925926" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=a58eec57&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdUhziaX6bGc9q48z6kTpSGibn1dcRKqZ2NspdKaLTBibZdZlkEYywOFjyiadRyFUKO1Z8BLIXcrCbQgw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p></li></ol><p style="margin-top: 24px;line-height: 1.75em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 24px;font-weight: bold;">SOC面临的挑战</span></span></p><p style="line-height: 1.75em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">下图是这次调研中SOC面临的最大挑战排序。</span></p><p style="line-height: 1.75em;"><span leaf=""><img data-imgfileid="100001353" class="rich_pages wxw-img" data-ratio="0.4202401372212693" data-type="png" data-w="1166" src="https://wechat2rss.xlab.app/img-proxy/?k=a52baf0c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdUhziaX6bGc9q48z6kTpSGibs2icxXhCWroP9AgRjeXaPSmf0LAewTwClDkDNQkiasm24DctHia5u2jUw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="line-height: 1.75em;"><span leaf="">对比一下2024年的调查结果：</span></p><p style="line-height: 1.75em;"><span leaf=""><img data-w="785" alt="图片" class="rich_pages wxw-img" data-ratio="0.8038216560509555" src="https://wechat2rss.xlab.app/img-proxy/?k=aa4ff4da&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcM5LG1V2s4mNVaY21icOeWSTX6JNLyLic7de1KFwDouLM4g2XbGhyz2ibPsianl1V0saVHgMpTiaCAibFg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1"/></span></p><p style="line-height: 1.75em;"><span leaf="">可以发现，<span textstyle="" style="font-weight: bold;">人和技能的缺乏又上升到了前两位，但缺少编排与自动化依然排名前三</span>。其他方面，变化不大。</span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">【笔者注】不管现在AI/智能体如何热门，对于SOC而言，安全编排和自动化依然是一个关键的问题，尤其对国内SOC而言，在安全编排和自动化方面还有很多工作值得去做。虽然有人说“SOAR已经过时”，但从实战的角度而言，SOAR的应用程度还远远不够。不论是独立的SOAR，还是集成到SOP的SOAR，都大有可为。</span></span></p><p style="line-height: 1.75em;"><span leaf="">不过，报告并没有直接提供本次调研的挑战结果，因为面临的挑战这个问题为了保持一致性数年来都是11个单选项（如上图所列），并不能全面的反映挑战情况。相反，报告着重分析了当前用户在使用AI/ML和威胁情报时面临的挑战。</span></p><p style="line-height: 1.75em;"><span leaf="">报告指出，</span><span leaf=""><span textstyle="" style="background-color: rgb(255, 251, 0);font-weight: bold;">AI/ML 工具的采纳速度很快，然而若缺乏有针对性的整合与监管，这些工具往往会浪费预算、增加风险，且无法为 SOC 运营提供实质性支持</span><span textstyle="" style="background-color: rgb(255, 251, 0);">。</span><span textstyle="" style="background-color: rgb(255, 251, 0);font-weight: bold;">调查显示，人们对AI/ML的技术满意度极低。</span>与此同时，威胁情报虽数量充足，但由于应用不一致且缺乏客观分析，经常未被充分利用，导致团队陷入被动响应模式。此外，针对SSL/TLS协议（譬如HTTPS）的解密还原已成为获得可见性的争议焦点，引发了关于隐私、性能和信任的担忧。</span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-weight: bold;">AI和ML面临的挑战</span></span></p><p style="line-height: 1.75em;"><span leaf="">调查显示，</span><span leaf="">大多数（40%）SOC 使用这些工具，但它们并未被纳入规范化运营流程，如下图所示。</span></p><p style="text-align: center;line-height: 1.75em;" nodeleaf=""><img data-imgfileid="100001354" class="rich_pages wxw-img" data-ratio="0.46410891089108913" data-s="300,640" data-type="png" data-w="808" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=31daee11&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdUhziaX6bGc9q48z6kTpSGibiat7ics8zCdvj5oVyLHSgvwH6ZzUysoiccc2gVRCowySCxsKldlBdzvtw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.75em;"><span leaf="">报告认为，当下SOC需要从两方面来来推动AI/ML落地的优先事项。</span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-weight: bold;">首先是做好对AI/ML技术的整合，并纳入规范的运营流程</span>：</span><span leaf="">从无协调的个人化 AI/ML 工具使用，转向团队认可的标准化应用 —— 在最大化工具优势的同时，将风险降至最低。<span textstyle="" style="color: rgb(0, 82, 255);">笔者认为，自发的、散乱的使用GenAI和智能体的行为可能导致安全风险且不可控，并且缺乏一致性，使用效果也不稳定。必须逐步将GenAI和智能体等工具纳入标准的安全运营流程和技术平台之中。当然这需要一个过程，要逐步验证，并持续优化。用好AI/ML，不仅是一个技术问题，也涉及到流程，组织和文化。</span></span></p><p style="line-height: 1.75em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">其次是加强对AI/ML的监管</span>：</span><span leaf="">监控从组织流向 AI/ML 平台的数据，以及未经授权的 “影子 IT” 部署。尽管这些数据中的大部分看似风险较低，但必须在标准部署中配备基于主机的数据丢失防护（DLP）工具，以确保可见性和控制力。</span></p><p data-pm-slice="2 2 []" style="line-height: 1.75em;"><span leaf="">报告表示，</span><span leaf="">网络安全团队可能并不承担AI幻觉或不准确输出的风险，但SOC可以在减轻其业务影响方面发挥关键作用。同时，治理、风险和合规（GRC）团队需要技术支持，以监控AI工具的使用方式以及它们与哪些系统或数据进行交互。</span></p><p style="line-height: 1.75em;"><span leaf="">最后，针对AI，报告还引用了SANS专家的评论，“<span textstyle="" style="font-weight: bold;">《2025年SOC调查报告》凸显了一个令人担忧的矛盾现象；SOC在招聘和留住专业分析师方面困难重重，而AI/ML和自动化虽在交付价值方面排名最低，却是最常计划的扩展领域。AI应该辅助分析师，而非取代他们。我担心的是，领导层可能将AI视为填补人员缺口的捷径，而不是投资于人才，并深思熟虑地将AI融入其中，以实质性地改进SOC。</span>”</span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-weight: bold;">威胁情报应用面临的挑战</span></span></p><p data-pm-slice="0 0 []" style="line-height: 1.75em;"><span leaf="">威胁情报活动是SOC运营工作的重要组成部分（占比 73%），其主要用途是事件响应（占比 69%）。</span></p><p data-pm-slice="0 0 []" style="line-height: 1.75em;"><span leaf="">由于威胁情报在很大程度上以分析为核心，调查向受访者询问了他们最常使用的分析方法。最常见的答案（占比 72%）是<span textstyle="" style="font-weight: bold;">分析师依靠自身经验和直觉开展分析</span>。SANS认为，尽管专业经验至关重要，但仍有充分理由采用更具结构性的分析方法（如概念分析法或归纳法），以提高分析的一致性并减少偏差。</span></p><p data-pm-slice="0 0 []" style="line-height: 1.75em;"><span leaf="">SANS同时认为，<span textstyle="" style="font-weight: bold;">从内部数据源生成威胁情报的需求正不断增长</span>，而非仅依赖外部情报流。利用内部数据有助于提升风险评估、威胁狩猎和事件响应能力。构建内部威胁情报最有效的方式是开展协作与信息共享，但基于 SOC 的威胁情报团队可能缺乏开展此类工作所需的组织支持。在这种情况下，非正式的同行协作可作为一种切实可行且可接受的替代方案。</span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">SOC人员分析</span></span></p><p data-pm-slice="2 3 []" style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-weight: bold;">人员配置</span></span></p><p style="line-height: 1.75em;"><span leaf="">SANS表示，</span><span leaf="">SOC 负责人最常被问到的问题之一是：“运营一个 SOC 需要多少人？” <span textstyle="" style="font-weight: bold;">最常见的答案是 10 人</span>（按全职等效人力计算），这一规模可作为规划的起点。10 人的团队足以覆盖监控、事件响应、威胁情报和工程等关键职能的充分人力配置。当然，在大型跨国企业中，SOC 团队规模可扩展至数百人。但对于大多数希望维持扎实内部能力的组织而言，10 人是一个合理的规划基准。</span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-weight: bold;">分析师工作量计算</span></span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-weight: normal;">如下图所示：</span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001365" class="rich_pages wxw-img" data-ratio="0.7166666666666667" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=650afe51&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdUhziaX6bGc9q48z6kTpSGib1LxeE4DS0rciabcIcLz7XyIvmKPvldmAZhnxdy6LjsL6Kic2OUjARnUw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.75em;"><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">对比去年的调查，可以发现情况基本一样，<span textstyle="" style="font-weight: bold;">最主流的工作量计算方式是依据工单处理时长，其次是追加考虑SIEM产生的告警数量，再者还要根据SLA进行更细致的计算</span>。</span></span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-weight: bold;">人员留存</span></span></p><p style="line-height: 1.75em;"><span leaf="">如前所述，SOC 团队长期面临高技能人员短缺的问题，这一困境始终存在。SOC 负责人表示，其所在组织在留住现有优秀人才方面做得还不够。SANS表示，<span textstyle="" style="font-weight: bold;">人才留存并非仅是人力资源部门的问题</span>，更是管理层优先级排序的体现。</span><span leaf="">若人员流动率过高，SOC 将难以维持最高效率和效能的运营状态。</span></p><p style="line-height: 1.75em;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">受访者在 SOC 环境中的任职时长仍多集中在 3-5 年（占比 31%），而任职超过 10 年的人则极少（仅占 4%）。</span></p><p style="line-height: 1.75em;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">SANS专家表示：“</span><span leaf=""><span textstyle="" style="font-weight: bold;">62%的SOC专业人士表示，他们所在的组织在留住顶尖员工方面做得还不够。一个出色的SOC不是靠工具打造出来的，而是靠一种认可并奖励那些表现出色的分析师的文化来塑造的。当分析师们感受到与公司使命的联系，并明白他们的贡献是这一使命的重要组成部分时，他们就会带来取得成功所需的活力、机智和创造力。管理者需要认可那些在各个技术能力层面都树立了成功典范的优秀分析师，并赋予他们权力，让他们成为其他人效仿的领导者。</span>”</span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-weight: bold;">留存策略</span></span></p><p style="line-height: 1.75em;"><span leaf="">如下图，年度对比数据显示，薪酬和有吸引力的工作内容越来越被视为有效的员工留存策略。尽管职业发展机会的重要性在 2024 年有所下降，但在 2025 年明显回升，跃居首位。</span></p><p style="text-align: center;line-height: 1.75em;" nodeleaf=""><img data-imgfileid="100001355" class="rich_pages wxw-img" data-ratio="0.7094017094017094" data-s="300,640" data-type="png" data-w="702" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=48d43ff1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdUhziaX6bGc9q48z6kTpSGibRa0KybvvWVQoP5R2Diaggn6d2fiaYTiaT7yMzQH175MLdb5DSJCAog1QA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-weight: bold;">SOC负责人对员工技能（Skill）的期望</span></span></p><p style="line-height: 1.75em;"><span leaf="">当被问及招聘技术岗位员工时最突出的技术技能缺口（即最缺乏的技能），受访者认为 “信息系统与网络安全”（14%）和 “数字取证”（12%）是最主要的缺口，其他各类技能缺口占比详如下图所示。</span></p><p style="text-align: center;line-height: 1.75em;margin-bottom: 24px;" nodeleaf=""><img data-imgfileid="100001356" class="rich_pages wxw-img" data-ratio="1.21461716937355" data-s="300,640" data-type="png" data-w="862" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=e4b9a17c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdUhziaX6bGc9q48z6kTpSGibj7hvOicsxCFvlPn6tiaBp2GMlOfNa5SayeLicarwicMzibicYk3Yoga88FQA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><div><p style="line-height: 1.75em;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">此外，在非技术技能方面，“风险管理” 以 14% 的占比位居榜首。</span></p></div><div><p style="line-height: 1.75em;margin-top: 24px;margin-bottom: 24px;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">SOC负责人对员工技术（Technology）的期望</span></span></p><p style="line-height: 1.75em;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">如“主要发现”章节所述，<span textstyle="" style="font-weight: bold;">最需要员工掌握的技术/工具是SIEM</span>，其次是ASM、威胁猎捕、EDR/XDR，以及SOAR。并且，对SIEM的要求程度是后面的两倍多。<span textstyle="" style="color: rgb(0, 82, 255);">笔者认为，这充分说明了SIEM在SOC中的重要性和不可取代性，也表明了EDR/XDR在SOC中的位置远不如SIEM。</span></span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001361" class="rich_pages wxw-img" data-ratio="0.4649621212121212" data-s="300,640" data-type="png" data-w="1056" style="width:578px;height:269px;" type="block" data-croporisrc="https://mmbiz.qpic.cn/mmbiz_png/t7v7zyOTkMdUhziaX6bGc9q48z6kTpSGibaedXanxveianlwJmy7V8ttyRr9OiaDJrQNjN5UD8tkUZibfAZoYFwhNug/0?wx_fmt=png&amp;from=appmsg" data-cropx2="1056" data-cropy1="16.442906574394463" data-cropy2="507.9031141868512" src="https://wechat2rss.xlab.app/img-proxy/?k=8bafa444&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdUhziaX6bGc9q48z6kTpSGib60WOKibahRw5LXzthPJeHP4VQrKhDFIG6ibIctH8gY7B0J6ISicYA6ryA%2F640%3Fwx_fmt%3Djpeg"/></p></div><p style="line-height: 1.75em;margin-top: 24px;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">SOC核心能力（职能/流程）分析</span></span></p><p style="line-height: 1.75em;"><span leaf="">调查显示，SOC核心能力包括20项，根据投票多少排序如下：</span></p><p style="text-align: center;line-height: 1.75em;" nodeleaf=""><img data-imgfileid="100001349" class="rich_pages wxw-img" data-ratio="1.0822784810126582" data-s="300,640" data-type="png" data-w="790" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=d62d58ae&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcLmemuxw9gtNarVPq9MIgGoWyB7Jo9B8KNFTYZMtbBeC6P89fGDmkHqd9bEc0mXubX8J0dSq316g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.75em;"><span leaf="">如上图，<span textstyle="" style="font-weight: bold;">最核心的4个能力依次是告警（分诊与升级）、弱点评估、安全监测与检测、事件响应</span>。</span></p><p style="line-height: 1.75em;"><span leaf="">对比一下2024年的调查结果，如下图：</span></p><p style="line-height: 1.75em;"><span leaf=""><img data-w="768" alt="图片" class="rich_pages wxw-img" data-ratio="0.78515625" src="https://wechat2rss.xlab.app/img-proxy/?k=8bb6226d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcM5LG1V2s4mNVaY21icOeWS2Klqy6Jy2fvp8IYlczZ1hibjvCTbekqpYhGfYqE6dkibtkORJKIXsj9A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1"/></span></p><p style="line-height: 1.75em;"><span leaf="">可以发现，<span textstyle="" style="font-weight: bold;">告警分诊与升级始终位居第一</span>，而弱点评估的重要性有较大提升。</span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-weight: bold;">不同能力的运营模式</span></span></p><p style="line-height: 1.75em;"><span leaf="">下图显示了最多被外包的能力排序，其中绿色表示既自己运营也使用外包的情形。<span textstyle="" style="font-weight: bold;">可以发现，对于高度专业化、可重复且资源密集型的任务，外包具有战略意义</span>。像渗透测试和红队演练等服务通常属于这一类别。这些通常是项目制的工作，第三方公司可以比内部团队更高效地提供有针对性的专业知识和可扩展性。此外，<span textstyle="" style="font-weight: bold;">告警分诊与升级越来越多被外包</span>，但如果看自营的情况的话，告警分诊与升级仅自营的情形有260票，还是占绝对多数。</span></p><p style="text-align: center;line-height: 1.75em;" nodeleaf=""><img data-imgfileid="100001350" class="rich_pages wxw-img" data-ratio="0.9451871657754011" data-s="300,640" data-type="png" data-w="748" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=9fb86daf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcLmemuxw9gtNarVPq9MIgGTBftEF4XpvLLUyqNX5gEk6lZrzOaFQMJEqt5XX50f6nqU0rzqadJWg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.75em;"><em style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: italic;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-style: normal;">下图展示了最多自己运营的能力排序。可以发现，安全路径规划、安全管理、架构设计与设施、数据保护、修复、事件响应主要都是自营为主，可以发现，</span><span textstyle="" style="font-weight: bold;font-style: normal;">越是重要，并且跟用户自身系统、业务和组织紧密相关的能力越依赖于自身运营团队</span><span textstyle="" style="font-style: normal;">。</span></span></em></p><p style="text-align: center;line-height: 1.75em;" nodeleaf=""><img data-imgfileid="100001351" class="rich_pages wxw-img" data-ratio="0.9284785435630689" data-s="300,640" data-type="png" data-w="769" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=5a14ab35&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcLmemuxw9gtNarVPq9MIgG1R3dGQO2gY3Iu2AWWWdTeQA8icqw15YOgQkmXHQgMz67Jm5Y6A4eljQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.75em;"><em style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: italic;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-style: normal;">值得一提的是，</span><span textstyle="" style="font-weight: bold;font-style: normal;">事件响应（IR）选择同时自营和外包的情形越来越多</span><span textstyle="" style="font-style: normal;">（135票），一方面说明越来越多MDR类服务成为了客户的选项，响应类服务更多为客户接受，另一方面，SANS表示，可能受到了网络保险更多被采用的影响。当然，话说回来，选择仅自营IR的还是占大多数（275票）。</span></span></em></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-weight: bold;font-style: normal;">事件响应</span></span></p><p style="line-height: 1.75em;"><em style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;font-style: italic;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;visibility: visible;box-sizing: border-box !important;overflow-wrap: break-word !important;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-style: normal;">进一步分析事件响应（IR）能力，大部分受访者表示</span><span textstyle="" style="font-weight: bold;font-style: normal;">IR已经完全集成到SOC中成为其中一个能力，这已经成为主流</span><span textstyle="" style="font-style: normal;">。</span></span></em></p><p style="text-align: center;line-height: 1.75em;" nodeleaf=""><img data-imgfileid="100001352" class="rich_pages wxw-img" data-ratio="0.8327683615819209" data-s="300,640" data-type="png" data-w="885" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=39a5cd11&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcLmemuxw9gtNarVPq9MIgGO3JmlSm8Jz4U0hGhicHGGPztP8oCFzfRQIOXEWic1x6U1xBvN6SYBP3w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="">数据还显示，85% 的事件响应启动主要由内部安全警报触发。具体来看，<span textstyle="" style="font-weight: bold;">EDR告警触发的IR占比最高，其次是SIEM自动触发的告警</span>，以及来自IDS/IPS/FW的告警。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001367" class="rich_pages wxw-img" data-ratio="0.916445623342175" data-s="300,640" data-type="png" data-w="754" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=66d2ffb4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdUhziaX6bGc9q48z6kTpSGibybWYXkC1LYAyIRL4ysOOlpFSeltgCwJuibflzy9ZtRGfHeTmkmh8ONA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span leaf="">SANS甚至表示，EDR告警是SOC告警中最重要的。但即便如此，并不等于说EDR/XDR是SOC中最重要的技术（而是SIEM）。</span></p><p style="margin-bottom: 24px;margin-top: 24px;"><span leaf=""><span textstyle="" style="font-weight: bold;">威胁猎捕</span></span></p><p style="line-height: 1.75em;"><span leaf="">调查显示，大多数团队会使用供应商提供的工具进行部分自动化威胁猎捕（48%）。SANS认为，尽管从技术层面看，这属于</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">威胁猎捕</span><span leaf="">的一种形式，但实际上更多是回溯性分析，而非真正的、基于技术的</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">威胁猎捕</span><span leaf="">。这种区别至关重要，因为<span textstyle="" style="font-weight: bold;">有效的</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">威胁猎捕</span></span><span leaf=""><span textstyle="" style="font-weight: bold;">需要熟练的分析师</span>，而此类人才目前仍供不应求。团队无法开展更复杂</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">威胁猎捕</span><span leaf="">工作的首要原因是缺乏熟练人员（16%）。</span></p><p style="line-height: 1.75em;"><span leaf="">SANS报告进一步阐释到，“运行更新过特征库的 Windows Defender 并扫描文件系统，这并非</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">威胁猎捕</span><span leaf="">，只是基础检测。” 尽管供应商工具的进步提升了<span textstyle="" style="font-weight: bold;">历史搜索能力，但 SOC 不应将此类操作称为 “猎捕/狩猎”</span>。通过更严谨的方式开展</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">威胁猎捕</span><span leaf="">仍具有实际价值：<span textstyle="" style="font-weight: bold;">真正的</span></span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-weight: bold;">威胁猎捕</span></span><span leaf=""><span textstyle="" style="font-weight: bold;">依赖成熟的方法论、基于假设的分析，以及对攻击者行为的深入了解</span>。警报旨在检测已知威胁，但老练的攻击者未必会触发警报 —— 他们会低调行动，避开检测阈值。如果不主动开展</span><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">威胁猎捕</span><span leaf="">，就无法发现这类威胁。</span></p><p><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">【笔者注】在2023年和2024年的调查报告中，SANS反复强调了威胁猎捕/狩猎与告警查询之间的本质区别。也就是“事”前和“事”后的区别。</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">威胁猎捕是一种主动响应/前摄响应</span><span textstyle="" style="color: rgb(0, 82, 255);">，而对告警/事件的处理则属于被动响应，因为告警已经产生。</span></span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">SOC技术/工具满意度分析</span></span></p><p style="line-height: 1.75em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">报告表示，</span><span leaf="">若企业管理层未准备好投入充足资源以确保某一工具发挥效用，那么最好完全不部署该工具。一项看似能完美解决问题的全新技术，实则需要预算支持、人员培训、时间投入，以及与现有工作流程的整合。</span></p><p style="line-height: 1.75em;"><span leaf="">下图是今年的技术满意度评分表（最后一列GPA评分），而第二列表明了该技术在生产环境部署的程度。可以发现，基本上评分越高的，生产环境部署规模越大，也越成熟。</span></p><p style="text-align: center;line-height: 1.75em;" nodeleaf=""><img data-imgfileid="100001357" class="rich_pages wxw-img" data-ratio="1.1428571428571428" data-s="300,640" data-type="png" data-w="840" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=635cb4b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdUhziaX6bGc9q48z6kTpSGibO9B9PzibZb8KjWC8jkia5NJQ3jtqicJnMRmhmIFgSxlmibI5dtdbWtw1ow%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.75em;"><span leaf="">对比一下2024年的技术评分。</span></p><p style="text-align: center;line-height: 1.75em;"><span leaf=""><img data-w="493" alt="图片" class="rich_pages wxw-img" data-ratio="2.255578093306288" src="https://wechat2rss.xlab.app/img-proxy/?k=21411aa7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcM5LG1V2s4mNVaY21icOeWSSiadwoMxX3gvBkVe1vSAUz0u29ZhLia6BQr04fOMtAiayUJwnCwvH49Aw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1"/></span></p><p style="line-height: 1.75em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-weight: bold;">EDR/XDR主机检测技术</span></span></p><p style="line-height: 1.75em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">可以发现，2025年，</span><span leaf=""><span textstyle="" style="font-weight: bold;">满意度最高的依然是EDR/XDR</span>，并且超过了3分，达到了A级。接下来依次是</span><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;float: none;display: inline !important;" data-pm-slice="0 0 []"><span leaf="">VPN、邮件网关、NGFW和<span textstyle="" style="font-weight: bold;">SIEM</span>，跟去年也几乎一样。</span></span></p><p style="line-height: 1.75em;"><span leaf="">SANS认为，</span><span leaf="">EDR/XDR 之所以能获得高满意度，原因在于其部署充分、能有效启动事件响应流程，并且有完善的培训与支持体系作为后盾。</span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-weight: bold;">AI/ML分析技术</span></span></p><p style="line-height: 1.75em;"><span leaf="">如前所述，调查显示，<span textstyle="" style="font-weight: bold;">AI/ML工具的表现仍不尽如人意</span>。在本次统计的三类 AI/ML 技术中，有两类排名垫底，其中生成式语言工具的评分仅为 4 分制中的 2 分。</span></p><p style="line-height: 1.75em;"><span leaf="">SANS认为，<span textstyle="" style="font-weight: bold;">AI/ML 工具表现不佳，一方面是因为这类技术较新，引入时往往缺乏明确的负责人或授权机制；另一方面，部署预算不足、未制定与日常运营整合的计划，也导致其难以发挥作用</span>。</span><span leaf="">这一现象表明，尽管行业对这类技术的关注度颇高，但它们在实际应用中的性能表现及与现有体系的整合程度，仍未跟上需求步伐。</span></p><p style="line-height: 1.75em;"><span leaf="">但是，SANS也表示，对于AI/ML实战满意度不佳也不必过于忧虑，随着时间推移会逐步改善，SANS看好AI/ML。</span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-weight: bold;">SOAR技术</span></span></p><p style="line-height: 1.75em;"><span leaf="">如下图是针对SOAR剧本优化变更的问题反馈。</span></p><p style="line-height: 1.75em;"><span leaf=""><img data-imgfileid="100001366" class="rich_pages wxw-img" data-ratio="0.4616956077630235" data-type="png" data-w="979" src="https://wechat2rss.xlab.app/img-proxy/?k=9e882080&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdUhziaX6bGc9q48z6kTpSGibkw9XvlqeHUR4v9ric0KjiaxThPiaG12PIFqZCvIgNJhzCMGGxxDHv4dzw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="line-height: 1.75em;"><span leaf="">可以发现，在为数不多的回答者中，40%的人很少或不常更新剧本，而更新剧本的回答者则大都需要安排固定的人负责这个工作，说明成本较高。</span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">SOC投资回报和指标管理分析</span></span></p><p style="line-height: 1.75em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">衡量SOC投资回报的最好方式就是建立指标体系并持续维护这个体系。</span></p><p style="line-height: 1.75em;"><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: mp-quote, &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.034em;font-style: normal;font-weight: normal;">如下展示了今年调查结果得到的<span textstyle="" style="font-weight: bold;">最多用到的5个指标</span>，分别是：已处理的时间数量、从检测到遏制再到修复的时长、基于已知弱点发生的事件和基于位置弱点发生的事件比例、一个班次中关闭的事件数量、可避免的事件数量。</span></p><p style="text-align: center;line-height: 1.75em;" nodeleaf=""><img data-imgfileid="100001358" class="rich_pages wxw-img" data-ratio="0.7924016282225237" data-s="300,640" data-type="png" data-w="737" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=b950a1d1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdUhziaX6bGc9q48z6kTpSGibAxJcoibj4YTzgibibbD4jfme6Jk5IXQ4SAukXibibL3FDCicyGFFJ5L6o1HA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.75em;"><span leaf="">对比一下2024年的调查结果：</span></p><p style="text-align: center;line-height: 1.75em;"><span leaf=""><img data-w="906" alt="图片" class="rich_pages wxw-img" data-ratio="0.9514348785871964" src="https://wechat2rss.xlab.app/img-proxy/?k=72e15468&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMeg6iaDvFYgkZBZACQicI6mP4qJUffeKvic74NdkY3dEGib39RFw4KzWEmYH53WFGypxke8msokXzJ6Tg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1"/></span></p><p style="line-height: 1.75em;"><span leaf="">SANS表示，上述涉及事件数量的指标最好进行升级，不仅展示数量，更重要是要展示随时间推移的数量的变化情况（譬如移动平均值）。也就是说，<span textstyle="" style="font-weight: bold;">数量绝对数值不如数量变化趋势更有价值</span>。</span></p><p style="line-height: 1.75em;"><span leaf="">此外，如下图所示，在将指标汇报给谁的问题上，更多还是用于安全部门内部。如果用到安全部门之外的话，则更多会同时汇报给董事会。</span></p><p style="text-align: center;" nodeleaf=""><img data-imgfileid="100001364" class="rich_pages wxw-img" data-ratio="0.940554821664465" data-s="300,640" data-type="png" data-w="757" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=386e58f4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdUhziaX6bGc9q48z6kTpSGibrVlOPiaKibKiczFIhsp7oaauqhexa84o1a5LCYJL6ibydArdbPzTxKbGibg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">结论：趋势向好，但仍需努力</span></span></p><p style="text-align: justify;line-height: 1.75em;"><span leaf="">2025 年 SOC 调查报告证实，SOC 正朝着既定趋势稳步发展，但部分领域的进展十分缓慢。核心能力扎实，但工作重心仍偏向被动响应；AI/ML 工具的表现仍未达预期；威胁狩猎受限于人员配置；工具满意度一如既往地取决于是否全面部署及是否进行深思熟虑的整合。</span></p><p style="text-align: justify;line-height: 1.75em;"><span leaf="">2025 年 SOC 调查呈现出一幅熟悉的图景：能力扎实、趋势向好，但整体进展有限，员工满意度仍有待提升。</span></p><p style="text-align: justify;line-height: 1.75em;"><span leaf="">显而易见，要取得进展，就必须在招聘、培训、架构设计和工具使用方面采取有针对性的行动。收集数据很容易，但明智地利用数据才是难点所在。</span></p><p style="text-align: justify;line-height: 1.75em;"><span leaf="">SOC 团队清楚自己的需求：<span textstyle="" style="font-weight: bold;">能正常工作的工具、稳定留存的员工，以及除响应警报外有更多时间开展其他工作</span>。但预算限制、人员流动和优先级调整等因素始终是阻碍。指标虽在追踪，但仍依赖手动方式；云技术采纳时起时伏；AI/ML 工具仍存在 “过度炒作、效果不足” 的问题。</span></p><p style="text-align: justify;line-height: 1.75em;"><span leaf="">与此同时，越来越多的组织选择 “将所有数据存入 SIEM 系统” 这一做法 —— 如今这样做看似合理，但未来可能会付出高昂代价。这种可视性策略存在 “因不堪重负而崩溃” 的风险。</span></p><p style="text-align: justify;line-height: 1.75em;"><span leaf="">工具本身无法解决这些问题，真正能解决问题的是人。尽管行业正在取得进展，但进展不均衡，且常年受相同结构性问题的制约。归根结底，SOC 并非停滞不前，但发展速度缓慢。要实现实质性突破，就必须明确方向、加强协作，同时停止将回溯性工作流程称为 “猎捕/狩猎”。</span></p><p style="text-align: justify;line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-weight: bold;">SANS对 SOC 未来持乐观态度的五大理由</span></span></p><p style="text-align: justify;line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-weight: bold;">广泛的 24 小时运营覆盖</span>：79% 的 SOC 现已实现 24 小时运营，这体现了 SOC 的成熟度，也表明业务利益相关者认识到全球网络威胁的严重性，并愿意为持续监控与支持提供支持。</span></p><p style="text-align: justify;line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-weight: bold;">云技术应用增加</span>：尽管集中式 SOC 仍是最常见的架构，但已有报告显示，组织计划将 SOC 系统迁移至云资源。</span></p><p style="text-align: justify;line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-weight: bold;">主动检测报告增多</span>：尽管采用主动检测的团队仍占少数，但越来越多的团队报告称，除警报外，还会使用 SIEM 搜索和威胁狩猎等主动检测手段。</span></p><p style="text-align: justify;line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-weight: bold;">AI/ML 应用更清晰</span>：组织正逐步有针对性地将 AI/ML 工具整合到工作流程中 —— 这表明，只要有规划，就能实现有效的工具整合。</span></p><p style="text-align: justify;line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-weight: bold;">职业发展成为首要留存因素</span>：员工愿意留在当前岗位，但前提是能看到发展前景。这对管理层而言是一项行动号召。</span></p><p style="text-align: justify;line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 24px;color: rgb(0, 82, 255);font-weight: bold;">笔者的体会</span></span></p><p style="text-align: justify;line-height: 1.75em;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">如这份报告所揭示的那样，对于SOC而言，一方面面临着持续的人员和技能短缺，另一方面则是数据的日益膨胀和持续过载，有限的自动化程度和范围，以及对AI应用的普遍不满，进一步加剧了安全运营人员的工作倦怠和效率低下，从而陷入一个死循环。</span></span></p><p style="text-align: justify;line-height: 1.75em;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">显然，我们需要在自动化和智能化方面下大力气，并要在实战中产生实效。这不仅是自动化和AI技术的问题，还涉及到整个SOC支撑平台的架构，以及人员组织和流程。</span></span></p><p style="text-align: justify;line-height: 1.75em;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">我们应该把自动化编排技术的应用范围扩展到单纯的事件响应之外，从日志和告警的采集处理、分析到响应都要引入编排与自动化能力。我们应该真正关注流程，只有安全运营实现了流程化，才能借助流程化实现自动化。</span></span></p><p style="text-align: justify;line-height: 1.75em;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">我们还应该加大对以Agentic AI（自主式AI）为核心的复合式AI技术的投入，从场景出发，落到智能体上，一点点（而非一蹴而就）地实现智能自动化。</span></span></p><p style="text-align: justify;line-height: 1.75em;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">更重要地，我们应该重新审视现有的SOC平台数据架构，直面数据过载的问题，用全新的数据编织技术重塑现有的SOC平台架构，让数据不再成为安全运营的瓶颈，发挥出真正的价值。</span></span></p><p style="text-align: justify;line-height: 1.75em;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">综上所述，我们需要一个</span><a class="normal_text_link" target="_blank" style="color: rgb(0, 82, 255);" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="AI赋能的，数据与流程双轮驱动的新一代安全运营平台" data-itemshowtype="11" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 82, 255);">AI赋能的，数据与流程双轮驱动的新一代安全运营平台</span></a><span textstyle="" style="color: rgb(0, 82, 255);">去支撑未来的SOC。</span></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.75em;" data-pm-slice="0 0 []"><span leaf="">【参考】</span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.75em;" data-pm-slice="0 0 []"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484811&amp;idx=1&amp;sn=18c651844e9668dd2ffa2f32db674f8c&amp;scene=21#wechat_redirect" textvalue="SANS 2024年SOC调查报告解读" data-itemshowtype="0" linktype="text" data-linktype="2">SANS 2024年SOC调查报告解读</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.75em;"><span leaf=""><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484680&amp;idx=1&amp;sn=83d86c286a3072137d14a936cf86f098&amp;chksm=fa002fbccd77a6aae4a84f82541ec6d7be90d5965913afe784cd481a41ac708ea9cf95ebf455&amp;scene=21#wechat_redirect" textvalue="SANS 2023年SOC调查报告解读" data-itemshowtype="0" linktype="text" data-linktype="2">SANS 2023年SOC调查报告解读</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.75em;"><span leaf=""><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484450&amp;idx=1&amp;sn=27c3c6e51febebd4ed1a13fa2f85307d&amp;chksm=fa002e96cd77a780251bdec3b12e2fbea2e013d19495d01c33b7aaac9323cbabe4274077e999&amp;scene=21#wechat_redirect" textvalue="SANS 2022年SOC调查报告解读" data-itemshowtype="0" linktype="text" data-linktype="2">SANS 2022年SOC调查报告解读</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.75em;"><span leaf=""><a class="normal_text_link" target="_blank" style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484366&amp;idx=1&amp;sn=ba64aedd9b67d98fa619db281105cf65&amp;chksm=fa00297acd77a06c53139348d4b69c713712c8ee8054871436ab9ff1a386f65983e4144134d8&amp;scene=21#wechat_redirect" textvalue="SANS 2021年SOC调查报告解读" data-itemshowtype="0" linktype="text" data-linktype="2">SANS 2021年SOC调查报告解读</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;box-sizing: border-box !important;overflow-wrap: break-word !important;line-height: 1.75em;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247483963&amp;idx=1&amp;sn=0b532b6edf78076dee6f4b72f86dad9c&amp;scene=21#wechat_redirect" textvalue="SANS 2019年SOC调查报告解读" data-itemshowtype="0" linktype="text" data-linktype="2">SANS 2019年SOC调查报告解读</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247485019">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=55fa5f0f&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyNzMxOTAwMw%3D%3D%26mid%3D2247485019%26idx%3D1%26sn%3Dd1e7cfd9d71ef8527d505156299b9b7a">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 28 Aug 2025 12:07:00 +0800</pubDate>
    </item>
    <item>
      <title>从RSAC2025看安全运营技术发展趋势</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484993&amp;idx=1&amp;sn=506b9c0de108b2293d71c15750f0d95c</link>
      <description>1.2万字长文，详细分享RSAC2025大会上有关安全运营的议题，并以此一窥未来安全运营的技术发展趋势</description>
      <content:encoded><![CDATA[<p>
原创 <span>Benny Ye</span> <span>2025-05-23 17:01</span> <span style="display: inline-block;">北京</span>
</p>

<p>1.2万字长文，详细分享RSAC2025大会上有关安全运营的议题，并以此一窥未来安全运营的技术发展趋势</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=2f91aca8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMcK2n7w23haPmVejBIYFsxJq5J60AiaicsDRVb4hbsJ6qzC2VcxvhnbtRG5peGHXEAUWYvia9Q3yBmFA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="line-height: 1.75em;"><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-style: italic;">【</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;font-style: italic;">引言</span><span textstyle="" style="color: rgb(0, 82, 255);font-style: italic;">】</span></span><span style="color: rgb(68, 114, 196);"><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-style: italic;">1.2</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-style: italic;">万字长文，详细分享</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-style: italic;">RSAC2025</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-style: italic;">大会上有关安全运营的议题，并以此一窥未来安全运营的技术发展趋势。内容涉及</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-style: italic;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-style: italic;">赋能</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-style: italic;">SOC</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-style: italic;">的新理念、新架构、新产品、新交互、新场景和笔者从业</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-style: italic;">20</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-style: italic;">多年来的感悟，以及对未来的研判。透过RSAC2025大会，可以很明显的感受到Agentic SOC时代（笔者称之为</span><a class="normal_text_link" target="_blank" style="color: rgb(0, 82, 255);" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="SOC4.0" data-itemshowtype="11" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 82, 255);font-style: italic;text-decoration: underline;">SOC4.0</span></a><span textstyle="" style="color: rgb(0, 82, 255);font-style: italic;">）已经到来。</span></span></span></span></p><p style="line-height: 1.75em;"><span lang="EN-US"><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-style: normal;">【</span><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;font-style: normal;">摘要</span><span textstyle="" style="color: rgb(0, 82, 255);font-style: normal;">】本文首先梳理了一些关键的AI术语，然后介绍了本次大会最热门的关键词——Agentic AI。本文重点研究了Agentic AI如何深刻变革SOC，以及SOC自身架构如何重塑以更好适应Agentic时代，并透过大会一瞥Agentic时代下的SOC未来趋势。本文还介绍了Agentic AI如何赋能暴露管理。最后，本文介绍了大会上讨论的AI自身安全问题，以及AI的自主程度和与人类的关系问题。</span></span></span></span></p><p style="line-height: 1.75em;text-align: center;"><span lang="EN-US"><span style="color: rgb(68, 114, 196);"><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001265" data-ratio="0.40925925925925927" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=535b22ce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcK2n7w23haPmVejBIYFsxJ1g0LcanWkeacodEmYNYtZUr2MnSkLs3QzpB9YoOlovzWjLxyavK51w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span><span lang="EN-US"><o:p></o:p></span></span></span></p><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 10.5pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">RSAC2025</span></span></span><span style="font-size: 10.5pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">已经落下帷幕。这次大会吸引了全球超过</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">140</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">个国家和地区的超过</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">44000</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">人参加，创造了大会举办</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">34</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">届以来的最多参会人数纪录。毫无疑问，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">依旧是大会上最闪亮的星。不同之处在于，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">成为了</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">明星中的明星。显而易见，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">已经成为了网络空间安全的未来（不论是防御还是攻击）。而随着</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">应用的深入和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的爆火，围绕</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI Agent</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的自身安全问题也成为了焦点。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span leaf="">在研究此次大会更多信息之前，有必要先就一些关键的</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">概念和术语进行梳理。</span><span lang="EN-US"><o:p></o:p></span></p><h1 style="line-height: 1.75em;margin-bottom: 16px;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">概念梳理</span></span><span lang="EN-US"><o:p></o:p></span></h1><p style="line-height: 1.75em;"><b><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">注意，以下概念由笔者本人进行梳理，与本次大会发言无直接关系。</span></span></span></b></p><p style="line-height: 1.75em;"><b><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">生成式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span></span></b><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Generative AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，简称</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">）：根据</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">NIST</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的定义，生成式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">是指模拟输入数据的结构和特征以生成衍生的合成内容的人工智能模型，这些内容可以包括图像、视频、音频、文本和其他数字内容。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Gartner</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">将</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">定义为从数据中学习“工件</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">(Artifacts)</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">表示”的人工智能技术，并使用它来大规模生成全新的、完全原始的工件，以保持与原始数据的相似性。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">是目前</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">领域中最热门的方向，近</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">3</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">年</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">RSAC</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">大会上谈论</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">主要就是指</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">大语言模型</span></span></span></b><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Large Language Model</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，简称</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">LLM</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">）：根据</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Gartner</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的定义，大语言模型是指通过</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">在大量文本上接受训练，使其能够解释和生成类似人类的文本输出的一种模型。通常</span></span><b><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">LLM</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">属于一种</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span></b><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，但</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">不一定都是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">LLM</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">。当前网络空间安全领域应用</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">主要就是指利用</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">LLM</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">大模型</span></span></span></b><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Large Model</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，简称</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">LM</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">）：通常指的是具有庞大参数数量和复杂结构的机器学习或深度学习模型，具有参数规模大、架构规模大、训练数据量大和算力需求大等特点。</span></span><b><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">LLM</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">属于一种</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">LM</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，但</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">LM</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">不等于</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">LLM</span></span></span></b><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">LM</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">既可以用于生成式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，也可以用于判别式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">。现在很多人经常提“大模型</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">”</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，同时将其与“大语言模型”等同看待，可能是因为讲“大模型“比较顺口，而讲“大语言模型”有点冗长，或者“</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">LLM</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">“的发音很拗口，其实大语言模型（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">LLM</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">）和大模型（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">LM</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">）不是一个意思，需要加以辨别。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">小模型</span></span></span></b><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Small Model</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">）：顾名思义，就是相对大模型而言，具有参数规模小、架构规模小，算力需求较小的特点，特别适用于算力资源有限的环境中。这里的小是跟大相较而言的，没有绝对的数值区间，跟</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">1000</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">万参数模型比，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">80</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">亿参数算大，但跟</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">1000</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">亿参数模型比，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">80</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">亿就算小了。大模型和小模型有各自适合的应用场景，实际应用中要按需而定，并可以互相配合。当前，人们经常提及“大模型</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">+</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">小模型“、”大小模型协同“的概念，通常（但不绝对）是指在生成式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">领域，使用大规模参数的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">LLM</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">和小规模参数语言模型（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">SLM</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">）混合搭配的方式实现最优化算力配置、最大化应用效果。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">传统</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span></span></b><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">：没有明确定义，只是一种表达方式，泛指除了</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">之外的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，譬如传统的符号主义的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，非神经网络的机器学习，使用神经网络的判别式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，统计分析技术（数据科学），知识图谱等技术。通常这些</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">技术在</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">大行其道之前已经有了较为成熟的应用，包括当前已经大量使用在网络空间安全领域的各种非生成式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，譬如基于规则推理的关联分析、基于各种机器学习的异常检测等。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">复合式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span></span></b><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Composite AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">）：这是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Gartner</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">提出来的面向工程化应用的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，指组合利用不同</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">技术（包括</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">、数据科学、机器学习、知识图谱等技术）来提高学习效率，以生成层次更丰富的知识表示的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">。可以将复合式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">理解为</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">和传统</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的结合。当前，国际上主流的安全厂商都是用复合式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">赋能安全，而非仅仅依靠生成式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，譬如</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Palo Alto Networks</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的精准</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Precision AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">），</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">CrowdStrike</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的夏洛特</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Charlotte AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">），以及</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Splunk AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">等。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">智能体</span></span></span></b><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">（</span></span><b><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI Agent</span></span></span></b><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">）：根据人工智能促进协会（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AAAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">）的定义，智能体是指能感知环境、处理信息并自主决策行动的智能实体。根据</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Gartner</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的定义，智能体是利用人工智能技术进行感知、决策、采取行动，并在数字或物理环境中自主或半自主地追求既定目标的软件实体。</span></span><b><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">行为体</span></span></b><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">）这个概念已经有几十年的历史了，当</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">应用到行为体中之后，就出现了智能行为体（简称智能体）。可以认为，</span></span><b><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的一个发展方向和发展阶段</span></span></b><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，但</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">中的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">并不限于当前热门的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">LLM / GenAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，而是泛指各种</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="" data-pm-slice="0 0 []"><b><span style="color:#4472C4;mso-themecolor:accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">自主式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span></span></b><span style="color:#4472C4;mso-themecolor:accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">（</span></span><b><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span></b><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，暂译为“自主式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">”）：这个概念最早见于</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">OpenAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">在</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">2023</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">年</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">12</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">月发布的一份白皮书，但其真正成形要归功于吴恩达。他在</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">2024</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">年初红杉资本举办的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">峰会上提及，随后又在</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Snowflake</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">峰会上进行了完善，并给出了</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">推理的四种设计模式：反思、工具使用、规划和多行为体协作，从而奠定了</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的框架基础。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">2024</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">年</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">10</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">月，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Gartner</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">发布</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">2025</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">年十大战略技术趋势，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">居首。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Gartner</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">将</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">定义为目标驱动的软件实体，这些实体被授予代表组织自主决策和采取行动的权限，使用人工智能技术——结合记忆、规划、感知、工具和护栏等组件——来完成任务并实现目标。另外，根据</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AAAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的定义，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">是指将</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);"> LLM </span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">集成到自主代理框架中，旨在利用此类模型的生成能力来增强动态环境中的交互性、创造力和实时决策。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Google</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">则将</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">定义为一种使软件系统能够自主行动的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，它基于目标做出决策并采取行动，最大限度地减少人工干预。简单来说，</span></span><b><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">当前尤指以</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI/LLM</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">为推理（规划和反思）中枢的智能体</span></span></b><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">。当</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">碰上</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">诞生了。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style=""><b><span lang="EN-US" style="color:#4472C4;mso-themecolor:accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span style="color:#4472C4;mso-themecolor:accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">本质区别在于二者看问题的视角不同</span></span></span></b><span style="color:#4472C4;mso-themecolor:accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">：此前的</span></span><b><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">是一种对</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的类型划分</span></span></b><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，关键点还是落在</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">上，</span></span><b><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">代表了所有利用</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">赋能的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，但具体如何赋能、赋能到什么程度，尤其是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的“自主程度”（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agency / Agenticness</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，暂译为“自主程度”）无法表达</span></span></b><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">。正如吴恩达所述，“</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">这个名词是一个二元性的术语，无法进一步区分不同自主程度的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">”。</span></span><b><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">而</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">代表了一种</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">技术的类型划分，并可以认为是生成式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的一个演进方向</span></span></b><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，关键点落在了</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">上。这时，如吴恩达所言，“</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">作为一个形容词可以（从</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">这个视角来）观察和思考不同自主程度的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">”。当视角从</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">转移到</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，再看</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，从当前来说就是寄希望于</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic Workflow</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">来获得一种较高自主程度的智能体，但未来</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">并不一定要依附于</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">代表了一种新型的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，这种</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">超越了当前的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，体现了对</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">三种主义的融合：</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">以连接主义为技术底座，以行为主义为交互范式，融合符号推理的目标导向型智能体。其本质是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">从被动执行任务向主动实现目标的进化，代表了 </span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI </span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">从单一功能工具开始向通用智能体跃迁。有一种观点进一步认为</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">代表了比</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">更高的自主程度，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">具有调度编排多个不同</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，通过</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">间的协作达成既定目标的能力。当前，还有一种</span></span><b><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">广义</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span></b><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的理解，将非基于</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">也划入</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的范畴，看作一种较低自主性（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agency</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">）的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">。譬如</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Gartner</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">认为</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的子集。此外，也存在一种</span></span><b><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">广义</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI Agen</span></span></span></b><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">t</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的理解，认为其代表了基于各种</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的单一或集群</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">。此时，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">两个概念具有等价性。总之，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的概念外延当前尚未稳定。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">代理式系统（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic System</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">）</span></span></span></b><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">：是指应用了</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI </span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">技术的各种应用系统。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><h1 data-pm-slice="0 0 []" style="margin-bottom: 24px;margin-top: 16px;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">迎接</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">时代</span></span><span lang="EN-US"><o:p></o:p></span></h1><p style=""><span style="color:#4472C4;mso-themecolor:accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">可以说，</span></span><b><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">是以</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">LLM</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">为代表的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">发展的一个新阶段</span></span></b><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style=""><span leaf="">在大会召开之前，各路专家便纷纷对今年的热点进行预测。</span><span lang="EN-US"><span leaf="">ESG</span></span><span leaf="">的</span><span lang="EN-US"><span leaf="">Jon Oltsik</span></span><span leaf="">就表示今年的焦点必定在</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">上，并表示很想通过这次大会看看</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">到底是神话还是现实。德勤美国的网络主管</span><span lang="EN-US"><span leaf="">Adnan Amjad</span></span><span leaf="">会前就表示最新一波创新浪潮的重点就包括</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">，并提及将其用于处理</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">的日常任务。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">在大会揭幕演讲环节，大会执行主席</span><span lang="EN-US"><span leaf="">Hugh Thompson</span></span><span leaf="">为大家展示了一幅交互式网络安全地图，以反映从</span><span lang="EN-US"><span leaf="">2021</span></span><span leaf="">年到</span><span lang="EN-US"><span leaf="">2025</span></span><span leaf="">年间大会讨论的主题及其热度。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001293" data-ratio="0.5573170731707318" width="547" data-type="png" data-w="820" height="305" src="https://wechat2rss.xlab.app/img-proxy/?k=78532a46&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWawf1A3JgkP0l5cwaK9vsYRPaWGwuiazmDGxoDvtKw5BSjNxWOfWiaHNA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">上图左侧展示了这幅网络安全地图，图中蓝色圆圈表示</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">相关的主题。显然，</span><b><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">在</span><span lang="EN-US"><span leaf="">2025</span></span><span leaf="">年的所有主题中占比最高</span></b><span leaf="">。上图右侧则展示了“生成式</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">用于安全”这个主题的最近五年走势。可以看出，从</span><span lang="EN-US"><span leaf="">2023</span></span><span leaf="">年开始，这个主题热度出现了大幅增长。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Hugh Thompson</span></span><span leaf="">进一步表示，</span><b><span leaf="">今年有两个</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">主题尤其值得关注。一个是</span><span lang="EN-US"><span leaf="">Agentic AI</span></span></b><span leaf="">，包括它如何应用于安全，以及它自身的安全性，包括身份的问题、治理的问题、可追溯性的问题，等等。</span><b><span leaf="">另一个是</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">应用于</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">AI in the SOC</span></span><span leaf="">，</span><span lang="EN-US"><span leaf="">AI for SOC</span></span><span leaf="">）</span></b><span leaf="">，今年有很多大大小小的此类议题，包括多个顶级赞助商的主题演讲都与此相关。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001289" data-ratio="0.5707257072570726" width="542" data-type="png" data-w="813" height="309" src="https://wechat2rss.xlab.app/img-proxy/?k=53c57809&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWgicXWickDOkBvdlKJ1NG5SXEZwlicFWhKW6P97YDDiajgZ8lTziaJNklLNA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">接着，</span><span lang="EN-US"><span leaf="">Hugh Thompson</span></span><span leaf="">基于现有数据对</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">未来的走势做出了</span><b><span leaf="">两个预测。一个是</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">驱动的应用安全，另一个是对</span><span lang="EN-US"><span leaf="">LLM</span></span><span leaf="">的攻击</span></b><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001291" data-ratio="0.5536791314837153" width="553" data-type="png" data-w="829" height="306" src="https://wechat2rss.xlab.app/img-proxy/?k=1d07b5b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWTB98eZLwxFtWGnS2ZbOcQHhnBABRwUn7ccFjicp3xdbga06g7mYpDKg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span style="color:#4472C4;mso-themecolor:accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">笔者对于</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">赋能的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">SOC</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">成为今年大会的热点丝毫不感到意外。从去年下半年开始，笔者已经从研究</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">转向研究</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI Agent</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，继而研究</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">了。有趣的是，当笔者研究</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI Agent / Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的时候，总是觉得无比亲切。毕竟，对于一个深度参与了</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">SOAR</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的人而言，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">跟</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">SOAR</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">有很多相似</span></span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">之处。笔者在《</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484848&amp;idx=1&amp;sn=0f7f582e241603ec68bc85be3926998c&amp;scene=21#wechat_redirect" textvalue="是时候重新定义安全运营平台了" data-itemshowtype="0" linktype="text" data-linktype="2">是时候重新定义安全运营平台了</a>》一文中，就做过深入的对比分析</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">。</span><span lang="EN-US"><o:p></o:p></span></p><h1 style="margin-bottom: 24px;margin-top: 16px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">正在深刻变革</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">SOC</span></span><o:p></o:p></span></h1><p style=""><span leaf="">在首日主题演讲环节，微软安全业务的副总裁</span><span lang="EN-US"><span leaf="">Vasu Jakkal</span></span><span leaf="">再次登上主会场，以《</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">时代的安全》为题，带领大家畅游了一番</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">时代的网络安全。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Vasu Jakkal</span></span><span leaf="">认定</span><b><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">将</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">带入了一个新时代</span></b><span leaf="">，将改变人类生活的方方面面，</span><b><span leaf="">成为人类的助手、同事和思想的伙伴</span></b><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001290" data-ratio="0.5102533172496985" width="553" data-type="png" data-w="829" height="282" src="https://wechat2rss.xlab.app/img-proxy/?k=eb7fb7df&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWML36Onr31Y9P3NjZxpsIMib784ORs7chGVNCwzyicXZxMM3Dt14Ov3QA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><b><span leaf="">在拥抱</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">之前，其自身的安全性必须首先予以保障</span></b><span leaf="">，因为</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">也面临着前所未有的威胁挑战。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001292" class="rich_pages wxw-img" data-ratio="0.5036231884057971" data-type="png" data-w="828" height="278" width="552" src="https://wechat2rss.xlab.app/img-proxy/?k=ce0f6d51&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWh6YhE6jGtiatKCNADbsTX3kQ2ibPnx221a029PoPicA7o8ticYzf5OpvIA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">越重要，</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">安全就越迫切，她提出了</span><span lang="EN-US"><span leaf="">8</span></span><span leaf="">个方面的关键安全考量，包括身份和权限、数据安全、隐私、内部风险、威胁防护、（智能体之间的）沟通规则、治理、合规。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001298" class="rich_pages wxw-img" data-ratio="0.4643734643734644" data-type="png" data-w="814" height="252" width="543" src="https://wechat2rss.xlab.app/img-proxy/?k=4f259ee1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWU2b0TuicbNaFjCcTHhicyBDzKT5HSicsM0DOS5wnQ0qcoPVUQRpfej2QQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">而当我们保护好</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">的安全后，就要利用</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">赋能安全去保护我们的网络空间。当前，</span><b><span leaf="">聚焦安全的</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">已经集成了我们所有的经验和思想，包括数据、优秀的安全模型，以及对</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">的观测、审计和治理</span></b><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001295" class="rich_pages wxw-img" data-ratio="0.5772558714462299" data-type="png" data-w="809" height="311" width="539" src="https://wechat2rss.xlab.app/img-proxy/?k=ac6d9118&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWFEABgdzunia4R9x01Cx24hF7kbvNiad6WLa0icj2XYdqRITLhVd7tzwcQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">畅想未来，</span><span lang="EN-US"><span leaf="">Vasu Jakkal</span></span><span leaf="">认为</span><b><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">未来可以快速胜任所有安全防御领域的工作</span></b><span leaf="">。她提出了四大畅想：</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001268" data-ratio="0.4685185185185185" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=9e05998c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcK2n7w23haPmVejBIYFsxJznJ6DBScJOUeRRR7zDaFCYouicI4QuhUbjIh5JDaxMNrVCq1qFWbRQA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><ul style="list-style-type: disc;margin-left: 0px;margin-right: 0px;" class="list-paddingleft-1"><li><p style=""><span leaf="">在</span><b><span leaf="">威胁检测方面</span></b><span leaf="">，智能体可以预测新型攻击并在它们发生前就阻止掉</span><span lang="EN-US"><o:p></o:p></span></p></li><li><p style=""><span leaf="">在</span><b><span leaf="">数据安全方面</span></b><span leaf="">，智能体可以协助识别数据风险并采取措施提升安全和生产力</span><span lang="EN-US"><o:p></o:p></span></p></li><li><p style=""><span leaf="">在</span><b><span leaf="">零信任方面</span></b><span leaf="">，智能体可以自动地在正确的时间向正确的人（和</span><span lang="EN-US"><span leaf="">Agent</span></span><span leaf="">）提供正确的访问权限，并根据团队和工作的变化动态调整此权限</span><span lang="EN-US"><o:p></o:p></span></p></li><li><p style=""><span leaf="">在</span><b><span leaf="">应用安全方面</span></b><span leaf="">，智能体可以协同工作实现默认安全和设计安全</span><span lang="EN-US"><o:p></o:p></span></p></li></ul><p style=""><span leaf="">未来，自主</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">的演进将重新定义当今安全的每个方面，为防御者带来全新的安全范式。智能体正在向人类学习，不断适应、行动和规划，自主工作，帮助人类实现目标，当然都在人类的参与下。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">最后，</span><span lang="EN-US"><span leaf="">Vasu Jakkal</span></span><span leaf="">指出，</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">将重塑安全角色。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001301" class="rich_pages wxw-img" data-ratio="0.5433734939759036" data-type="png" data-w="830" height="301" width="553" src="https://wechat2rss.xlab.app/img-proxy/?k=09812e7e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWL0tR0ecYBTvpRgicHNt4zWyFaPMbNfvcgD4suubGkhGSI5czhtfsMbQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span style="color:#4472C4;mso-themecolor:accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">对此，笔者深有感触。</span></span><b><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">改变的不仅是安全技术，更重要的是透过这些技术重塑了我们从事安全的方式，改变了安全组织结构和岗位职责，改变了安全工作的流程</span></span></b><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">。这种改变是建立在</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">优先和自动化优先基础上的，这种改变绝不是简单的减少工作岗位，而是工作岗位的职责变化。从目前来看，可能还需要更多的人，懂</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的人。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style=""><span leaf="">作为对</span><span lang="EN-US"><span leaf="">Vasu Jakkal</span></span><span leaf="">演讲的呼应，在大会第二天上午的分会场，来自微软</span><span lang="EN-US"><span leaf="">Security Copilot</span></span><span leaf="">部门的市场负责人</span><span lang="EN-US"><span leaf="">Dorothy Li</span></span><span leaf="">详细介绍了</span><b><span leaf="">释放</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">潜力的五个关键</span></b><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001302" data-ratio="0.5253012048192771" width="553" data-type="png" data-w="830" height="291" src="https://wechat2rss.xlab.app/img-proxy/?k=76b77c19&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWN1GMHWw06IuGUK4C2cdSZmONOUcQhZuq82CUqvfru1JShHKexOJXVA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Dorothy Li</span></span><span leaf="">表示，</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">正在改变安全产业，我们正处于从自动化向智能体跃升的奇点，</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">将重新定义我们现在的安全，我们需要善用智能体。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">首先，</span><b><span leaf="">智能体最基本的工作方式是赋能你现有的工作过程</span></b><span leaf="">，使之更高效。所谓“</span><span lang="EN-US"><span leaf="">Agents in your flow, not in your way</span></span><span leaf="">”，</span><span lang="EN-US"><span leaf="">Agent</span></span><span leaf="">是让你爽，而不是挡你的道。最典型的例子是通过</span><span lang="EN-US"><span leaf="">Agent</span></span><span leaf="">主动实现对告警和事件的内容富化，缓解运营人员来回切换上下文的工作内耗。这时候，智能体其实也不需要多智能，关键是要能够连接广泛的安全工具。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">其次，</span><b><span leaf="">借助智能体消除安全中的苦力活</span></b><span leaf="">。最典型的用例就是通过自主告警分诊找到真正重要的问题，将运营人员从告警疲劳中解救出来，所谓“</span><span lang="EN-US"><span leaf="">Clear the clutter, prioritize the critical</span></span><span leaf="">”。这时候，不仅需要智能体展现它的智能性，更重要的是要发挥它的规模效应（也就是大规模自动化的能力）。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">第三，</span><b><span leaf="">使用智能体的过程要完全透明，全程可控</span></b><span leaf="">（</span><span lang="EN-US"><span leaf="">Total clarity, full control</span></span><span leaf="">）</span><span lang="EN-US"><span leaf="">,</span></span><span leaf="">通过透明度建立人类对智能体的信任。</span><span lang="EN-US"><span leaf="">Dorothy Li</span></span><span leaf="">引用了一份调研结果表示，</span><span lang="EN-US"><span leaf="">60%</span></span><span leaf="">的安全专家更信任经人类验证后的信息而非</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">生成的结果。她以微软的智能体工作流为例，通过将智能体思考和规划的每个环节都呈现出来，展示了智能体工作过程的透明性。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001303" class="rich_pages wxw-img" data-ratio="0.6144578313253012" data-type="png" data-w="830" height="340" width="553" src="https://wechat2rss.xlab.app/img-proxy/?k=19d32711&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWbJV5E8HxqInjKBRyzt2ohNtPOdu8GJ8O65lbCfjHVgw0ax9fQmA0Jw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">第四，</span><b><span leaf="">借助智能体变被动为主动</span></b><span leaf="">，尤其是针对漏洞扫描、排序、修复过程的自动化。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">第五，</span><b><span leaf="">从实战出发应用智能体</span></b><span leaf="">而不要仅仅是炒作。智能体的设计要以人为本，立足于赋能人类（这才是实战），而非取代人类（而这是炒作）。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">思科的首席产品官</span><span lang="EN-US"><span leaf="">Jeetu Patel</span></span><span leaf="">在主会场演讲时则提到了当前安全领域面临的三大挑战，并认为</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">是当下最好的解药。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001300" class="rich_pages wxw-img" data-ratio="0.44376528117359415" data-type="png" data-w="818" height="242" width="545" src="https://wechat2rss.xlab.app/img-proxy/?k=7d61610e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrW04G5BfQE92CU1r7mHwibEiaNiclYv1WEsk8Oo5ib1EIs7MDC1bmczH9J6g%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">这三大挑战分别是技能短缺、告警疲劳和安全的复杂性。其中安全的复杂性就包括了安全领域众多分散的厂商、产品和技术给用户带来的挑战。</span><span style="color:#4472C4;mso-themecolor:accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">这三大挑战跟笔者经常提及的安全运营三大痛点（人才短缺、技能不足、工作倦怠）基本一致</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">。</span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">思科认为要应对以上三大挑战，不仅需要用到</span><span lang="EN-US"><span leaf="">GenAI</span></span><span leaf="">，还需要一个安全垂域</span><span lang="EN-US"><span leaf="">LLM</span></span><span leaf="">，进而在大会上</span><b><span leaf="">宣布推出开源的基础</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">安全模型</span></b><span leaf="">（</span><span lang="EN-US"><span leaf="">Foundation AI Security Model</span></span><span leaf="">），并且具备推理能力（推理版目前尚未发布），引发了业界的强烈关注。该模型具备</span><span lang="EN-US"><span leaf="">80</span></span><span leaf="">亿参数规模，可以跑在</span><span lang="EN-US"><span leaf="">1</span></span><span leaf="">到</span><span lang="EN-US"><span leaf="">2</span></span><span leaf="">个</span><span lang="EN-US"><span leaf="">A100 GPU</span></span><span leaf="">上。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001304" data-ratio="0.383270911360799" width="534" data-type="png" data-w="801" height="205" src="https://wechat2rss.xlab.app/img-proxy/?k=cd136699&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWQK4DC5UJhqFxwUXnmN9useBmEvRLL1ia6uKlsYgiba4FwuMS74EQneJw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">基于这个</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">安全大模型，</span><span lang="EN-US"><span leaf="">Jeetu Patel</span></span><span leaf="">也给大家分享了几个安全运营的用例，展示了思科</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">安全大模型的能力，都是采用智能体的形式，包括推理链、分析报告、使用外部工具、出具调查结果和推荐处置操作。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001305" class="rich_pages wxw-img" data-ratio="0.3728813559322034" data-type="png" data-w="826" height="205" width="551" src="https://wechat2rss.xlab.app/img-proxy/?k=894e5eed&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrW7A5ek2tKdopLjLhF2ibicAiaicyd798hbqmNS5yibibrZOwXK02PYwbJRgKQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Jeetu Patel</span></span><span leaf="">表示，未来的安全智能将是一个由多种模型、多个智能体互相协作的全面编排的超级智能系统（</span><span lang="EN-US"><span leaf="">Super Intelligent System</span></span><span leaf="">）。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001308" class="rich_pages wxw-img" data-ratio="0.3281061519903498" data-type="png" data-w="829" height="181" width="553" src="https://wechat2rss.xlab.app/img-proxy/?k=03d822b0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWXXiaVM3L5Et6HILiajTdJdXjYSc3jd4HbBEsS7cuGp4kl9Yw2GZhMe0g%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">这不就是一个</span><span lang="EN-US"><span leaf="">Agentic</span></span><span leaf="">安全系统吗？</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">思科基础设施与安全集团的总经理</span><span lang="EN-US"><span leaf="">Tom Gillis</span></span><span leaf="">与旗下</span><span lang="EN-US"><span leaf="">Splunk</span></span><span leaf="">安全产品负责人</span><span lang="EN-US"><span leaf="">Mike Horn</span></span><span leaf="">在题为《威胁检测与响应的未来》的联合演讲中，热烈讨论了</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">给</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">带来的机遇和变革。</span><span lang="EN-US"><span leaf="">Gillis</span></span><span leaf="">认为</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">在安全领域最大和最直接的影响就是正在改变安全运营。</span><span lang="EN-US"><span leaf="">Horn</span></span><span leaf="">表示，</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">从来没有像今天一样令他如此激动。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001306" class="rich_pages wxw-img" data-ratio="0.4387878787878788" data-type="png" data-w="825" height="241" width="550" src="https://wechat2rss.xlab.app/img-proxy/?k=88dc654c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWklV7adLCHVDJgOjibkvaDLNVZPjsOYwcwSPACmvIgPFHyic65H9vmXag%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Horn</span></span><span leaf="">进一步指出，</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">正在深刻变革</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">。首先，是自动化的融合，以及更高级的自主自动化的引入，赋能安全运营人员，提升他们的工作层次。其次，将变革</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">的组织和人员结构。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Horn</span></span><span leaf="">表示，</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">正在带来一场彻底的变革，而安全也需要随之进行彻底变革。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001307" class="rich_pages wxw-img" data-ratio="0.3832923832923833" data-type="jpeg" data-w="814" height="208" width="543" src="https://wechat2rss.xlab.app/img-proxy/?k=5617ab03&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWBickk0vicad0ias7SqNXo4qQBbMNwQLJ5LRuxmu8s6BMNrvbGSqTvBvmA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><h1 style="margin-bottom: 24px;margin-top: 16px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">技术架构正在重构</span></span><span lang="EN-US"><o:p></o:p></span></h1><p style=""><span leaf="">当人们把</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">为核心的各种</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">技术应用于</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">的时候，</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">的技术架构也在不可避免地进行着重构。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">思科基础设施与安全集团的总经理</span><span lang="EN-US"><span leaf="">Tom Gillis</span></span><span leaf="">与旗下</span><span lang="EN-US"><span leaf="">Splunk</span></span><span leaf="">安全产品负责人</span><span lang="EN-US"><span leaf="">Mike Horn</span></span><span leaf="">共同在大会主会场做了一场《威胁检测与响应的未来》的演讲，从战略视角探讨了网络安全的新架构，以及现有安全运营中心</span><span lang="EN-US"><span leaf=""> (SOC)</span></span><span leaf="">技术架构重构的必要性。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Gillis</span></span><span leaf="">首先分析了</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">大模型的引入对当前应用软件架构带来的变革。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001312" data-ratio="0.4933171324422843" width="549" data-type="png" data-w="823" height="271" src="https://wechat2rss.xlab.app/img-proxy/?k=dcf30880&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrW0ofeGQWI0FShLvUfMBNSohBHundsicxDicYiawibBmD3zkcDk7hqTjBnaQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">这种变革就在于</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">大模型在传统的应用三层架构之间插入了模型层。模型以其特有的方式将数据变成洞察并给到上层的应用，同时也不可避免的看到了所有数据，包括机密和隐私数据。大模型输出的不确定性使得人们对于大模型能否保守这些秘密心存疑虑。这种</span><b><span leaf="">融合</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">的应用架构变革是前所未有的，将改变</span><span lang="EN-US"><span leaf="">IT</span></span><span leaf="">架构，进而改变安全防御的架构</span></b><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">接着，</span><span lang="EN-US"><span leaf="">Gillis</span></span><span leaf="">分析了当前以</span><span lang="EN-US"><span leaf="">SIEM</span></span><span leaf="">为核心的集中式安全架构存在的弊端，并表示，在</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">时代，（</span><span lang="EN-US"><span leaf="">SIEM</span></span><span leaf="">和</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">平台）必须转向分布式安全架构。</span><span leaf="">可以认为，这个观点跟<a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484766&amp;idx=1&amp;sn=5b66715c108908d39eb92ecdc964c9f6&amp;scene=21#wechat_redirect" textvalue="去年Splunk在RSAC大会上的发言" data-itemshowtype="0" linktype="text" data-linktype="2">去年Splunk在RSAC大会上的发言</a>一脉相承，但更进一步</span><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001311" class="rich_pages wxw-img" data-ratio="0.42431761786600497" data-type="png" data-w="806" height="228" width="537" src="https://wechat2rss.xlab.app/img-proxy/?k=b9e7715e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWeTbQvdNsdXz2Xu3yZRgk56uUrb4ecdw7FE9ZKXPTWudiaJ7Z6YgRZyw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Splunk</span></span><span leaf="">的</span><span lang="EN-US"><span leaf="">Horn</span></span><span leaf="">将这个分布式架构分为三部分：</span><b><span leaf="">分布式的数据存储、分布式分析、分布式策略执行</span></b><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><b><span leaf="">未来的安全架构必定转向分布式数据存储，这是由安全防御体系的演进规律决定的</span></b><span leaf="">。为了应对威胁，必然会不断增加数据采集点、采集的信息量和采集的频度，海量的数据遍布于用户分散的网络各处，将其集中起来进行分析是低效的、高成本的和拖沓的。未来用户网络中必定存在多个安全数据湖</span><span lang="EN-US"><span leaf="">/</span></span><span leaf="">库，之间的数据移动将变得十分昂贵。在摄取数据这方面我们已经取得了很大的进步，但是在访问数据这块，未来一定要支持分布式数据检索</span><span style="color:#4472C4;mso-themecolor:accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">【注：笔者称之为“数据不动应用动”，本质上就是要实现数据虚拟化】</span></span></span><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Horn</span></span><span leaf="">表示，</span><b><span leaf="">“应用正在迁出数据中心”，分析正在向分散的数据靠拢，而</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">正在推动这一进程</span></b><span leaf="">。将所有数据集中到一个系统中是不现实的，最后得到的只能是一个怪兽数据湖（</span><span lang="EN-US"><span leaf="">Monster Data Lake</span></span><span leaf="">）。</span></p><p style=""><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">对此，笔者深以为然。</span><a class="normal_text_link" target="_blank" style="color: rgb(0, 82, 255);" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484657&amp;idx=1&amp;sn=97ef202f80d16243bc1212bedf759458&amp;scene=21#wechat_redirect" textvalue="从2023年开始" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 82, 255);text-decoration: underline;">从2023年</span><span textstyle="" style="color: rgb(0, 82, 255);">开始</span></a><span textstyle="" style="color: rgb(0, 82, 255);">，笔者就在讲安全架构的联邦化、分布式的趋势，在讲边缘检测（分析）的兴起，在讲安全运营架构的多体化。所有这一切都是相互关联的，都指向了同一个变革——</span></span><span leaf=""><a class="normal_text_link" target="_blank" style="color: rgb(0, 82, 255);" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484854&amp;idx=1&amp;sn=81ac539adfe55fca334828b7e82002e5&amp;scene=21#wechat_redirect" textvalue="安全数据管理与分析架构的重构" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 82, 255);text-decoration: underline;">安全数据管理与分析架构的重构</span></a></span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001309" data-ratio="0.3426829268292683" width="547" data-type="jpeg" data-w="820" height="187" src="https://wechat2rss.xlab.app/img-proxy/?k=eaac403b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWhGBRnjZnB552wJoSPon34lzlkKpvicibLWVAia6QJfiaicABh1YzDstKRzA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">分布式策略执行最显著的例子就是调用分散的安全设备进行响应（如遏制），策略的执行（</span><span lang="EN-US"><span leaf="">PEP</span></span><span leaf="">）是分布式的，但策略的管理（</span><span lang="EN-US"><span leaf="">PDP</span></span><span leaf="">）将维持在一个单一的策略管理平台之上。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001310" class="rich_pages wxw-img" data-ratio="0.36073619631901843" data-type="jpeg" data-w="815" height="196" width="543" src="https://wechat2rss.xlab.app/img-proxy/?k=f639d758&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWhcb75QicsSuVycEysXFjELybJY9d30B6S1cbicP12bleHLGjGLkMrD1w%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">这是一个经典的分布式策略执行架构，但创新点在于思科提出的位于用户内部的、控制东西向流量的、分布式部署的“</span><b><span leaf="">智能交换机</span></b><span lang="EN-US"><span leaf="">”</span></span><span leaf="">的概念。这个概念型设备融合了思科的网络和安全的积累，相当于一个个超级安全策略执行点，接受单一策略管理平台的统一指挥。这个“智能交换机”将具备三种处理单元：</span><span lang="EN-US"><span leaf="">NPU</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">DPU</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">GPU</span></span><span leaf="">。</span><span lang="EN-US"><span leaf="">NPU</span></span><span leaf="">负责处理网络流量的移动和交换；</span><span lang="EN-US"><span leaf="">DPU</span></span><span leaf="">负责对这些网络流量进行数据分析，发现攻击和违规；</span><span lang="EN-US"><span leaf="">GPU</span></span><span leaf="">则作为</span><span lang="EN-US"><span leaf="">GenAI</span></span><span leaf="">的算力平台为“智能交换机”进行</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">赋能。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001313" class="rich_pages wxw-img" data-ratio="0.46987951807228917" data-type="png" data-w="830" height="260" width="553" src="https://wechat2rss.xlab.app/img-proxy/?k=52dcc24f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWCD2jibbG6W4YpLwl6dhYYvmv3z3Pzxnv3tetyHerzBVsXvINaM86l8A%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span style="color:#4472C4;mso-themecolor:accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">笔者认为，这个“智能交换机”事实上并不一定要是一个设备，它本质上是一个理念，一个真正意义上的分布式网络安全架构的策略执行器的理念。它可以是一个新的硬件或者软件，也可以是现有的安全设备和系统。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style=""><span leaf="">最后，</span><span lang="EN-US"><span leaf="">Gillis</span></span><span leaf="">和</span><span lang="EN-US"><span leaf="">Horn</span></span><span leaf="">表示，未来的（</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">）安全架构一定是融合到网络编织中，分布到各处的。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001314" class="rich_pages wxw-img" data-ratio="0.4835965978128797" data-type="png" data-w="823" height="265" width="549" src="https://wechat2rss.xlab.app/img-proxy/?k=4b198c1e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWlibwsBghN7VZCx6t6Xt4q2zMn9MjQ4pTJfr5Bbl1Y6hVwn8QOxicnnIw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">SentinelOne </span></span><span leaf="">美洲地区</span><span lang="EN-US"><span leaf="">CTO Dave Gold</span></span><span leaf="">在演讲中表示，自主</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">的平台架构设计需求发生了变化，更加强调可伸缩性、开放数据集成和联邦数据搜索、低成本海量数据存储、快速、云原生</span><span style="color:#4472C4;mso-themecolor:accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">【笔者注：这一点在国内并不显著】</span></span></span><span leaf="">、长周期数据存储。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001315" class="rich_pages wxw-img" data-ratio="0.5595667870036101" data-type="png" data-w="831" height="310" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=7c78ea2b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrW7blPecGJMvTuzopVRIhXCZPKhuQdTAunaKvUNV3f2gibTGIaBQEEftA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">此外，在大会分论坛上，创新公司</span><span lang="EN-US"><span leaf="">Auguria</span></span><span leaf="">则做了题为《为什么</span><span lang="EN-US"><span leaf=""> AI </span></span><span leaf="">无法在没有正确数据的情况下拯救你的</span><span lang="EN-US"><span leaf=""> SOC</span></span><span leaf="">》的分享，指出数据就绪是</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">应用产生效果的前提和基础，强调了新型数据架构对于释放</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">能量的意义，</span><span style="color:#4472C4;mso-themecolor:accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">而这也正好与笔者提出的“</span><a class="normal_text_link" target="_blank" style="color: rgb(0, 82, 255);" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484854&amp;idx=1&amp;sn=81ac539adfe55fca334828b7e82002e5&amp;scene=21#wechat_redirect" textvalue="数据驱动是SOC原动力" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 82, 255);">数据驱动是SOC原动力</span></a><span textstyle="" style="color: rgb(0, 82, 255);">”的观点相吻合</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">。</span></span><span lang="EN-US"><o:p></o:p></span></p><h1 style="margin-bottom: 24px;margin-top: 16px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">时代下</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">的未来趋势</span></span><span lang="EN-US"><o:p></o:p></span></h1><h2 style="margin-bottom: 24px;margin-top: 16px;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">新产品</span></span><span lang="EN-US"><o:p></o:p></span></h2><p style=""><span lang="EN-US"><span leaf="">SentinelOne</span></span><span leaf="">的</span><span lang="EN-US"><span leaf="">CEO Tomer Weingarten</span></span><span leaf="">在大会主会场宣发了他们的“</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">赋能的自主网络安全平台”。这个平台采用开放架构连接所有安全产品、控制器、网关、平台，汇集所有的安全数据，混合多种</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">技术（包括编排化的</span><span lang="EN-US"><span leaf="">Agentic</span></span><span leaf="">工作流）去实现实时的观察、监测、推理和响应，功能涵盖资产攻击面、弱点、威胁等诸多方面的安全运营。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001316" data-ratio="0.33700980392156865" width="544" data-type="jpeg" data-w="816" height="183" src="https://wechat2rss.xlab.app/img-proxy/?k=c83fbe24&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrW0MwrVnpXibwzfRt1p1m4bYPG9J3AcN5zfjgXDEWDUUSWoU9LynGWNng%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span style="color:#4472C4;mso-themecolor:accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">很显然，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">SentinelOne</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">紧随</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">CrowdStrike</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，实现了从</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">EDR/EPP</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">厂商向</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">SOC</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">和安全平台厂商的转型。打开</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">SentinelOne</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的网站，可以看到他们除了最初的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">EDR</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">EPP</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，更多看到的是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">SIEM</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">SOAR</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">XDR</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">ITDR</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">TIP</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">VM</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，以及</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">CWPP</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">CNAPP</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">CSPM</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">。他们公开把</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">CrowdStrike</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">、微软、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Wiz</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Splunk</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">PAN</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">作为自己的竞争对手。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">SentinelOne</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">向我们诠释了</span></span><span leaf=""><a class="normal_text_link" target="_blank" style="color: rgb(0, 82, 255);" href="https://mp.weixin.qq.com/s?__biz=MzkzNjE5NjQ4Mw==&amp;mid=2247539944&amp;idx=2&amp;sn=3f4ee7e2ea767c469f360f116d187002&amp;scene=21#wechat_redirect" textvalue="一个点产品厂商最后是如何成为一个平台厂商的过程" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 82, 255);text-decoration: underline;">一个点产品厂商最后是如何成为一个平台厂商的过程</span></a><span textstyle="" style="color: rgb(0, 82, 255);text-decoration: none;">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style=""><span leaf="">在次日的分会场，</span><span lang="EN-US"><span leaf="">SentinelOne </span></span><span leaf="">美洲地区</span><span lang="EN-US"><span leaf="">CTO Dave Gold</span></span><span leaf="">做了一个题为《</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">驱动时代下</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">的未来》的报告，进一步阐述了</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">ML</span></span><span leaf="">、自动化如何使</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">转型为一个自适应、自我进化的网络防御力量，如何通过</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">实现实时威胁猎捕、编排工作流程。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Dave Gold</span></span><span leaf="">首先指出了当前</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">不能承受之重（资源不足、工作过载），并分析了为何现有的</span><span lang="EN-US"><span leaf="">SIEM</span></span><span leaf="">和</span><span lang="EN-US"><span leaf="">SOAR</span></span><span leaf="">难以解决</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">存在的顽疾，由此引出</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">、增强和虚拟现实、主动猎捕、零信任、云</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">、联邦数据等新技术可能塑造未来的</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Dave Gold</span></span><span leaf="">列举了</span><span lang="EN-US"><span leaf="">6</span></span><span leaf="">个可以受益于</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">的</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">流程，包括监测、证据收集、调查、分诊、响应与修复、报告，并指出了自主</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">所具备的潜力。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Dave Gold</span></span><span leaf="">给出了</span><span lang="EN-US"><span leaf="">SentinelOne</span></span><span leaf="">的自主</span><b><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">关键能力构成图</span></b><span leaf="">，依然是</span><span lang="EN-US"><span leaf="">PPT</span></span><span leaf="">三个部分，但内涵已经发生变化。</span><span style="color:#4472C4;mso-themecolor:accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">笔者理解，主要表现在：技术融入了</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">（包括传统</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">），流程上以自动化为优先，人员结构上进行了调整，初级岗位（如</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">L1</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">L2</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">分析师）取消或减少，并出现更多高级岗位，譬如增加了</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">专家</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">。</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001317" data-ratio="0.5535499398315282" width="554" data-type="png" data-w="831" height="307" src="https://wechat2rss.xlab.app/img-proxy/?k=8d880745&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWSuavZKs9PELEjicaY57wEY3aOLzvHVLwmuogQFzsGQCbfJnLayoqgcg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">SentinelOne</span></span><span leaf="">的自主</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">强调要用</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">来赋能，但又不仅仅限于使用</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">，而要应用各种</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">技术（即采用复合式</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">）。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001318" data-ratio="0.5523465703971119" width="554" data-type="png" data-w="831" height="306" src="https://wechat2rss.xlab.app/img-proxy/?k=abe80463&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWFRR34h0j0jS0UHjP0jFwMPRy2gYIOy143I3pJ1zL4wserwf1TtnTzQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001321" class="rich_pages wxw-img" data-ratio="0.5691937424789411" data-type="png" data-w="831" height="315" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=b8b3ca02&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWNJevTsXRLG0wOJakKArGN7f0yXxXibXzvTXRwRqL7LBJBNexRpjhOLA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">演讲最后，</span><span lang="EN-US"><span leaf="">Dave Gold</span></span><span leaf="">给用户迈出自主</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">转型之路的第一步提出了几点建议，包括要重构数据平台、要让</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">无所不在、要秉持自动化优先的设计原则，等等。</span><span style="color:#4472C4;mso-themecolor:accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">这些建议，</span></span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(0, 82, 255);">与</span></span><span leaf=""><a class="normal_text_link" target="_blank" style="color: rgb(0, 82, 255);" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="笔者对于未来安全运营平台的理解" data-itemshowtype="11" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 82, 255);text-decoration: underline;">笔者对于未来安全运营平台的理解</span></a></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(0, 82, 255);">都是一致的</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="color: rgb(0, 82, 255);">。</span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">此外，在大会的第一天，</span><span lang="EN-US"><span leaf="">CrowdStrike</span></span><span leaf="">发布了基于</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">的新组件赋能其</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">产品，包括名为</span><span lang="EN-US"><span leaf="">Charlotte AI Agentic Response</span></span><span leaf="">的事件调查智能体和名为</span><span lang="EN-US"><span leaf=""> Charlotte AI Agentic Workflows</span></span><span leaf="">的</span><span lang="EN-US"><span leaf="">AI SOAR</span></span><span leaf="">组件。而</span><span lang="EN-US"><span leaf="">Google</span></span><span leaf="">也撰文介绍自己由</span><span lang="EN-US"><span leaf="">Gemini</span></span><span leaf="">赋能的</span><span lang="EN-US"><span leaf="">Agentic SOC</span></span><span leaf="">，以期通过互联互通的多智能体技术，代表防御者自主或半自主地执行安全运营工作流程。</span><span lang="EN-US"><o:p></o:p></span></p><h2 style="margin-bottom: 24px;margin-top: 16px;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">新交互</span></span><span lang="EN-US"><o:p></o:p></span></h2><p style=""><span leaf="">本次大会上，</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">相关的议题多如牛毛，但有一个不起眼的发言引起了笔者的关注。来自</span><span lang="EN-US"><span leaf="">Google</span></span><span leaf="">云安全的产品和用户体验高级总监</span><span lang="EN-US"><span leaf="">Steph Hay</span></span><span leaf="">做了一个题为《</span><span lang="EN-US"><span leaf="">How Security UX Must Change, with Agentive AI</span></span><span leaf="">》的发言，分享了他对未来</span><span lang="EN-US"><span leaf="">Agentic</span></span><span leaf="">系统的用户体验设计的想法。</span><b><span style="color:#4472C4;mso-themecolor:accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">笔者认为，用户体验（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">UX</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">）对于安全运营平台至关重要，是降低安全运营复杂性、提升平台实战化水平的关键环节</span></span></span></b><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">。</span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Hay</span></span><span leaf="">首先简单回顾了一下从</span><span lang="EN-US"><span leaf="">web1.0</span></span><span leaf="">时代的</span><span lang="EN-US"><span leaf="">C/S</span></span><span leaf="">模式和客户端</span><span lang="EN-US"><span leaf="">/Ajax</span></span><span leaf="">引擎</span><span lang="EN-US"><span leaf="">/</span></span><span leaf="">服务端模式到现在移动互联网时代手指导航模式的应用</span><span lang="EN-US"><span leaf="">UX</span></span><span leaf="">发展历程，然后表示随着</span><span lang="EN-US"><span leaf="">GenAI</span></span><span leaf="">的到来，</span><span lang="EN-US"><span leaf="">UX</span></span><span leaf="">发展再次迎来拐点，而</span><span lang="EN-US"><span leaf="">Agent</span></span><span leaf="">代表了人机交互的新时代。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">当前，将</span><span lang="EN-US"><span leaf="">GenAI</span></span><span leaf="">作为助理的</span><span lang="EN-US"><span leaf="">UX</span></span><span leaf="">设计已经比较成形，不论是侧边栏对话模式，还是嵌入式按钮，同时也充分考虑到如何让</span><span lang="EN-US"><span leaf="">GenAI</span></span><span leaf="">返回的结果更加透明可理解。但是对于</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">时代的多轮交互和内容生成的结果展示还没有形成良好实践。很关键的一点就在于这个交互过程是动态的，生成的内容本身事先是不可控的，不能采用固定的</span><span lang="EN-US"><span leaf="">UI</span></span><span leaf="">设计，而要采用自适应</span><span lang="EN-US"><span leaf="">UI</span></span><span leaf="">设计。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">时代的系统</span><span lang="EN-US"><span leaf="">UX</span></span><span leaf="">设计还有一个很重要的原则就是要顺应</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">的价值取向，</span><span lang="EN-US"><span leaf="">UX</span></span><span leaf="">的设计要能更好地体现自主化、自动化给用户带来的成效。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001319" data-ratio="0.5265060240963856" width="553" data-type="png" data-w="830" height="291" src="https://wechat2rss.xlab.app/img-proxy/?k=29a02ecc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWPbTHsO6AiaAs1NWh9XvBqibwWSO6lHicmSrn8MdWDMKmqY2W9xEMuZqMA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><h2 style="margin-bottom: 24px;margin-top: 16px;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">新场景</span></span><span lang="EN-US"><o:p></o:p></span></h2><p style=""><span leaf="">在大会各个分论坛上，众多安全运营厂商分享了他们基于</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">赋能安全运营的用例和场景。譬如，</span><span lang="EN-US"><span leaf="">Opentext</span></span><span leaf="">介绍了如何利用基于</span><span lang="EN-US"><span leaf="">MITRE ATTCK</span></span><span leaf="">框架的</span><span lang="EN-US"><span leaf="">RAG</span></span><span leaf="">和</span><span lang="EN-US"><span leaf="">LLM</span></span><span leaf="">来增强威胁告警；</span><span lang="EN-US"><span leaf="">Elastic</span></span><span leaf="">详细介绍了它们基于</span><span lang="EN-US"><span leaf="">RAG</span></span><span leaf="">的</span><span lang="EN-US"><span leaf="">LLM</span></span><span leaf="">来赋能安全运营；</span><span lang="EN-US"><span leaf="">Exabeam</span></span><span leaf="">分享了应用</span><span lang="EN-US"><span leaf="">Agentic Workflow</span></span><span leaf="">实现自主安全运营的实例。此外，在简报环节，</span><span lang="EN-US"><span leaf="">DropZone AI</span></span><span leaf="">发表了题为《</span><span lang="EN-US"><span leaf="">SOC </span></span><span leaf="">中的</span><span lang="EN-US"><span leaf=""> AI </span></span><span leaf="">蓝图：如何评估、部署和指导</span><span lang="EN-US"><span leaf=""> AI </span></span><span leaf="">分析师》的报告，讲解如何将智能体集成到</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">分析师的工作流程中。 </span><span lang="EN-US"><o:p></o:p></span></p><h1 style="margin-bottom: 24px;margin-top: 16px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">深刻变革暴露管理</span></span><span lang="EN-US"><o:p></o:p></span></h1><p style=""><span leaf="">暴露管理作为安全运营领域一个重要组成，也受到了极大的关注。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">在主会场，</span><span lang="EN-US"><span leaf="">Tenable </span></span><span leaf="">联合</span><span lang="EN-US"><span leaf="">CEO Mark Thurmond</span></span><span leaf="">分享了</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">时代给暴露管理带来的机遇和变革。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001320" data-ratio="0.5399753997539976" width="542" data-type="png" data-w="813" height="293" src="https://wechat2rss.xlab.app/img-proxy/?k=a42dabb6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWkKll4w7gqgGdV38pASiayPh4cncej0SzWzibntM35neNhiaJVYp57VkPw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Mark Thurmond</span></span><span leaf="">表示，网络风险就是一种业务风险。暴露管理正面临着资产暴增，工具纷乱的时代，像极了最初</span><span lang="EN-US"><span leaf="">SIEM</span></span><span leaf="">所处的时代，而暴露管理技术发展正在重蹈传统</span><span lang="EN-US"><span leaf="">SIEM</span></span><span leaf="">失败的覆辙，那就是手工的规则，机械的关联，随着而来的必定就是告警疲劳。</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">给暴露管理的未来发展带了新的机遇，有机会避开</span><span lang="EN-US"><span leaf="">SIEM</span></span><span leaf="">曾落入的陷阱。而</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">不仅是暴露管理技术升级的机会，也是攻击者的机会，</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">时代的暴露越发充满挑战，这也更要求我们利用好</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">去对抗</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">。安全暴露每年都在数倍的增长，但安全预算不可能每年翻番式增长，必须利用</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">去提升运营效率，</span><b><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">将成为新一代暴露管理的核心</span></b><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Mark Thurmond</span></span><span leaf="">表示，</span><b><span leaf="">暴露管理必须实现三个转变：从分散到统一、从静态到情景化和预测性、从手动到自动和</span><span lang="EN-US"><span leaf="">Agentic</span></span></b><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">首先，攻击面越来越多、越来越分散和动态，但又相互关联，必须将所有攻击面信息统一起来。</span><b><span leaf="">统一的可见性不是一个功能，而是生存的底线</span></b><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">其次，传统的工具呈现的是静态的风险，但未来的暴露管理需要将暴露信息与情境信息相结合，从攻击者的角度来找到优先需要处置的风险点，甚至预测攻击者的攻击路径。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">最后，要实现大规模的暴露风险管理，人类手工操作是远远跟不上的，需要实现自动化闭环，并进一步迈向自主化，变被动的自动化为主动的自动化。自主化的关键就是</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">能够帮助我们回答四个问题：需要修复什么？谁来修复？响应流程是怎样的？人类何时参与其中？</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">不仅是一个分析师，也是一个操作者；不仅仅是一个推荐者，也是一个深思梳理的问题解决者，并且</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">还会持续学习和进步。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Mark Thurmond</span></span><span leaf="">表示，在</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">赋能之下，</span><b><span leaf="">暴露管理正在使我们从一个记录系统转向一个行动系统</span></b><span leaf="">。</span><span style="color:#4472C4;mso-themecolor:accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">笔者感叹，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">SIEM</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">何尝不是如此！如果说</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">SOAR</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">让安全运营实现了自动化的闭环，那么</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">则更进一步，让安全运营实现了自主化（智能自动化）的闭环。</span></span></span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001323" data-ratio="0.5335775335775336" width="546" data-type="png" data-w="819" height="291" src="https://wechat2rss.xlab.app/img-proxy/?k=4554ccf5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWQovaQRgpFeVxB9OTsGoUGx85cTfMRFUmicNRllfDBwjVN121iaNwqkYw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">在分论坛上，调研咨询公司</span><span lang="EN-US"><span leaf="">ESG</span></span><span leaf="">也带来了他们对</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">驱动的暴露管理的见解。</span><span lang="EN-US"><span leaf="">ESG</span></span><span leaf="">认为，随着网络风险管理的难度不断增大，必须变被动为主动。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001322" data-ratio="0.5325301204819277" width="553" data-type="png" data-w="830" height="295" src="https://wechat2rss.xlab.app/img-proxy/?k=d6f5d18d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWYUfcFbTT3omXPaBgfP5ZXH1q8iblIlUIOERorBtaBMrAjW93Ej4SRFA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">如上图所示，</span><span lang="EN-US"><span leaf="">ESG</span></span><span leaf="">认为，要加大对风险管理中主动性战略的投资，包括攻击面收敛和主动安全控制，从而降低被动性战略的依赖程度（譬如检测与响应、事件响应、修复），进而重塑整个风险管理过程的人才结构。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><b><span leaf="">如果说被动管理阶段的核心是对事态（事件）的管理，那么主动管理阶段的核心就是对资产状态（姿态）的管理</span></b><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001326" data-ratio="0.5306859205776173" width="554" data-type="png" data-w="831" height="294" src="https://wechat2rss.xlab.app/img-proxy/?k=4c3cfdb9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWgQssAAKBMaCHTmKUf69SvYc7m0DRJm4kmUd0OchqVPmk3DN43gbJLg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">ESG</span></span><span leaf="">还认为，在构建暴露管理平台的时候，必须充分利用情境数据，要将资产数据与弱点、暴露、威胁数据结合起来，做出更全面的风险分析。基于此，</span><span lang="EN-US"><span leaf="">ESG</span></span><span leaf="">给出了一个</span><b><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">驱动的威胁与暴露管理平台（</span><span lang="EN-US"><span leaf="">TEMP</span></span><span leaf="">）框架</span></b><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001325" data-ratio="0.4139590854392298" width="554" data-type="png" data-w="831" height="229" src="https://wechat2rss.xlab.app/img-proxy/?k=dd0bafe9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWP14nss916YQicXdANudeGwUQWeqEDfwjtDdfGiahaVW7mfWibsYC5L3xg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">这个框架从下至上分为三层：安全数据编织层（实现分布式数据摄取）、分析引擎层（融合了</span><span lang="EN-US"><span leaf="">AI/ML</span></span><span leaf="">分析、符合性分析、行为分析等技术）、威胁与暴露管理平台层（核心是全面的网络安全情境感知）。其中，</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">可以在各个环节提供赋能。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">此外，在分论坛环节，还有很多厂商和客户分享了他们在暴露管理方面的实践和成果。</span><span lang="EN-US"><span leaf="">Splunk</span></span><span leaf="">介绍了他们的</span><span lang="EN-US"><span leaf="">CAASM</span></span><span leaf="">方案和案例，</span><span lang="EN-US"><span leaf="">Axonius</span></span><span leaf="">介绍了资产管理在安全运营中的独特价值。</span><span lang="EN-US"><o:p></o:p></span></p><h1 style="margin-bottom: 24px;margin-top: 16px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">安全（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">Safety &amp; Security</span></span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">）问题</span></span><span lang="EN-US"><o:p></o:p></span></h1><p style=""><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">安全（有的时候称之为“</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">安全与可靠性</span><span lang="EN-US"><span leaf="">”</span></span><span leaf="">，</span><span lang="EN-US"><span leaf="">AI Safety and Security</span></span><span leaf="">）伴随着</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">的出现而出现。在</span><span lang="EN-US"><span leaf="">2023</span></span><span leaf="">年</span><span lang="EN-US"><span leaf="">GenAI</span></span><span leaf="">爆火之时，很多厂商就敏锐的投入到这个领域，但大都没有“破圈”。而随着</span><span lang="EN-US"><span leaf="">GenAI</span></span><span leaf="">飞速进化，</span><span lang="EN-US"><span leaf="">GenAI</span></span><span leaf="">、</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">在各行各业的广泛应用已经起势，随着而来的就是</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">安全议题的真正破圈，受到了各行各业人士的关注。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Gartner</span></span><span leaf="">的</span><span lang="EN-US"><span leaf="">Fellow</span></span><span leaf="">分析师</span><span lang="EN-US"><span leaf="">Leigh C. McMullen</span></span><span leaf="">更是在会上直言，</span><b><span leaf="">网络安全还没有准备好保护基于</span><span lang="EN-US"><span leaf="">Agent</span></span><span leaf="">的系统（即</span><span lang="EN-US"><span leaf="">Agentic</span></span><span leaf="">系统）</span></b><span leaf="">。他表示，</span><span lang="EN-US"><span leaf="">Agentic</span></span><span leaf="">系统的确代表了未来，但这种系统架构与原来的系统有很大不同，传统的防御模式不再适用，</span><b><span leaf="">甚至你不必真的黑掉</span><span lang="EN-US"><span leaf="">Agentic</span></span><span leaf="">系统本身，只需迷惑（</span><span lang="EN-US"><span leaf="">confuse</span></span><span leaf="">）它就能突破系统防护</span></b><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">在本次大会上，有大小数十个关于</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">自身安全的议题，热闹程度不亚于</span><span lang="EN-US"><span leaf="">Agentic SOC</span></span><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">思科的首席产品官</span><span lang="EN-US"><span leaf="">Jeetu Patel</span></span><span leaf="">是</span><span lang="EN-US"><span leaf="">RSCA</span></span><span leaf="">大会执行主席开场发言后的第一个做主题演讲的人，他的题目是《保护</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">基础设施：构建安全、可扩展且有弹性的系统》，可见人们对</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">安全的重视。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Jeetu Patel</span></span><span leaf="">表示，</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">正在改变一切，而网络安全是</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">的核心，</span><b><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">是安全历史上最艰难的挑战</span></b><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001327" data-ratio="0.4261501210653753" width="551" data-type="jpeg" data-w="826" height="235" src="https://wechat2rss.xlab.app/img-proxy/?k=1b80329d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWtneRbC9ibwelIRrlo0JfZqcDuJppRt4vHhwszAheXISb3k5EMC2fxaA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">接着，</span><span lang="EN-US"><span leaf="">Jeetu Patel</span></span><span leaf="">从</span><span lang="EN-US"><span leaf="">Safety</span></span><span leaf="">和</span><span lang="EN-US"><span leaf="">Security</span></span><span leaf="">两方面分析了</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">安全问题。在国际上，</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">安全通常都分为两个方面：</span><span lang="EN-US"><span leaf="">AI Safety</span></span><span leaf="">和</span><span lang="EN-US"><span leaf="">AI Security</span></span><span style="color:#4472C4;mso-themecolor:accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">【笔者注：目前尚未找到贴切的中文翻译来区隔二者，有的人将</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Safe</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">翻译为“安全”，而将</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Security</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">翻译为“可靠”】</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">。</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001324" data-ratio="0.4657039711191336" width="554" data-type="png" data-w="831" height="258" src="https://wechat2rss.xlab.app/img-proxy/?k=6b2974d1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWvphSAr5tsqmnxRiaIiafbrg2fia50UVOoiaI9ib58D1ic7tSpMrmXgQJ4rOA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">顺便提一下，加州大学伯克利分校的</span><span lang="EN-US"><span leaf="">Dawn Song</span></span><span leaf="">教授也在本次大会的分论上做了演讲。她比较清晰的介绍了</span><b><span lang="EN-US"><span leaf="">AI Safety</span></span><span leaf="">和</span><span lang="EN-US"><span leaf="">AI Security</span></span><span leaf="">的区别</span></b><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001328" class="rich_pages wxw-img" data-ratio="0.5354993983152828" data-type="png" data-w="831" height="297" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=13068f02&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrW5IzXBiaiawgZhIXrsBkzhFN6hp4STtOFNwDzqNyCT5ibicbK70C2Z2ibQibQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">简言之，</span><b><span lang="EN-US"><span leaf="">AI Safety</span></span><span leaf="">关注的是不要让</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">系统对外部环境造成危害，而</span><span lang="EN-US"><span leaf="">AI Security</span></span><span leaf="">则关注于保护</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">系统自身免受恶意外部行为体的伤害和利用</span></b><span leaf="">。</span><span style="color:#4472C4;mso-themecolor:accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">【笔者注：前者是向外求安全，后者是向内求安全】</span></span></span><span leaf="">。对于网络安全从业者往往更多关心</span><span lang="EN-US"><span leaf="">AI Security</span></span><span leaf="">，而</span><span lang="EN-US"><span leaf="">AI Safety</span></span><span leaf="">则更多为更广泛的人类社会各群体所关注，譬如</span><span lang="EN-US"><span leaf="">2023</span></span><span leaf="">年英国曾经召开过第一届</span><span lang="EN-US"><span leaf="">AI Safety</span></span><span leaf="">峰会，世界主要国家（包括中国）的政府都参加并发表了</span><span lang="EN-US"><span leaf="">AI Safety</span></span><span leaf="">的宣言。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Jeetu Patel</span></span><span leaf="">表示，要保障</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">安全（</span><span lang="EN-US"><span leaf="">Securing AI</span></span><span leaf="">）必须</span><b><span leaf="">抓住三个关键点：可见性、验证、运行时加固</span></b><span leaf="">（即</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">护栏）。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001331" data-ratio="0.4457978075517661" width="547" data-type="png" data-w="821" height="244" src="https://wechat2rss.xlab.app/img-proxy/?k=52aadc6d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWo97DORo5nK7SXWdelhdQoRszHhuzg3FVX3KcjyWfJafWozNZYaDxlg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">值得一提的是，思科的</span><span lang="EN-US"><span leaf="">Jeetu Patel</span></span><span leaf="">表示，他们的研究表明，</span><b><span leaf="">微调后的</span><span lang="EN-US"><span leaf="">LLM</span></span><span leaf="">被越狱的可能性提升了</span><span lang="EN-US"><span leaf="">3</span></span><span leaf="">倍，产生有害回应的可能性上升了</span><span lang="EN-US"><span leaf="">22</span></span><span leaf="">倍</span></b><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001329" class="rich_pages wxw-img" data-ratio="0.4770755885997522" data-type="jpeg" data-w="807" height="257" width="538" src="https://wechat2rss.xlab.app/img-proxy/?k=0255a269&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWMfupia0nNia0MbynJC2GPT70JGR31kj7r1ZAjqwarpG2ibGToelXetgdg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">在另外一个分论坛中，来自微软的</span><span lang="EN-US"><span leaf="">Tina Ying</span></span><span leaf="">分享了一幅</span><span lang="EN-US"><span leaf="">GenAI</span></span><span leaf="">引入的新威胁</span><span lang="EN-US"><span leaf="">/</span></span><span leaf="">风险的地图，分为</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">平台和模型层、</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">应用层、</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">使用层和延伸风险四个部分。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001332" data-ratio="0.40794223826714804" width="554" data-type="png" data-w="831" height="226" src="https://wechat2rss.xlab.app/img-proxy/?k=f6014c8b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWPhnRQdTL2xuTdBX2G5Xsd5pAgMYuElzLh3Hz3eM1lAOstluWpzo3Tg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">除了</span><span lang="EN-US"><span leaf="">GenAI</span></span><span leaf="">，基于</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">的</span><span lang="EN-US"><span leaf="">Agentic</span></span><span leaf="">系统的安全性受到了与会者的广泛关注。</span><span lang="EN-US"><span leaf="">Agentic</span></span><span leaf="">系统的安全与</span><span lang="EN-US"><span leaf="">GenAI</span></span><span leaf="">的安全存在很大不同，需要专门进行研究。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">微软的</span><span lang="EN-US"><span leaf="">Vasu Jakkal</span></span><span leaf="">在其讲演中表示，随着智能体的自主性越高，自身面临的安全风险也越高，并提到了保障智能体安全的</span><span lang="EN-US"><span leaf="">6</span></span><span leaf="">个方面。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001333" class="rich_pages wxw-img" data-ratio="0.501840490797546" data-type="png" data-w="815" height="273" width="543" src="https://wechat2rss.xlab.app/img-proxy/?k=ba5e7e3e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWBpib7z5QBI5q4NtDf0Q4eCickZYskQDyT0dBjSZw6xtYbwIExz9WFT9A%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Vasu Jakkal</span></span><span leaf="">进一步表示，未来</span><b><span leaf="">需要建立全新的智能体治理方式，从基于实验室环境的静态分析与验证的治理方式演进为实际环境下的动态的概率验证的治理方式</span></b><span leaf="">，要建立全生命周期的身份治理和动态策略，并将安全嵌入到智能体中，设置专门的安全子智能体，等等。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001330" data-ratio="0.5860805860805861" width="546" data-type="png" data-w="819" height="320" src="https://wechat2rss.xlab.app/img-proxy/?k=0c4b12b7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrW30BCBQC2clUTs9GW1Ahnp2If1zkbiaTU0via7iaicRrK8jvY2AOjO5MX1Q%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">加州大学伯克利分校的</span><span lang="EN-US"><span leaf="">Dawn Song</span></span><span leaf="">教授在本次大会上详细报告了</span><span lang="EN-US"><span leaf="">LLM Agent</span></span><span leaf="">及</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">的安全挑战和应对策略。报告很长，值得仔细阅读。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">简言之，</span><span lang="EN-US"><span leaf="">LLM</span></span><span leaf="">的安全和</span><span lang="EN-US"><span leaf="">LLM Agent</span></span><span leaf="">，以及基于</span><span lang="EN-US"><span leaf="">LLM Agent</span></span><span leaf="">的</span><span lang="EN-US"><span leaf="">Agentic</span></span><span leaf="">系统的安全有很大的区别。</span><span lang="EN-US"><span leaf="">Agentic</span></span><span leaf="">系统更加复杂，攻击面更多，更难防护。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001334" class="rich_pages wxw-img" data-ratio="0.5716004813477737" data-type="png" data-w="831" height="317" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=671fd02f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWG6J6jJYkLgqnjuWpVEyYlscKboeeTkW6RppcuZaBiaicicLcpC3XhP7xQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p><span leaf="">一个典型的</span><b><span lang="EN-US"><span leaf="">Agentic</span></span><span leaf="">系统通常存在</span><span lang="EN-US"><span leaf="">7</span></span><span leaf="">方面的安全威胁</span></b><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001336" class="rich_pages wxw-img" data-ratio="0.4969915764139591" data-type="png" data-w="831" height="275" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=e938d7c3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWePSfiaUNd2vN3qt0aPIUwAOaPlJibOWMRJk02icpScscRdyRgGxf19sWw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">很显然，对</span><span lang="EN-US"><span leaf="">Agentic</span></span><span leaf="">系统的评估比单纯针对</span><span lang="EN-US"><span leaf="">LLM</span></span><span leaf="">的评估要更复杂，</span><b><span leaf="">需要对系统端到端的行为进行评估</span></b><span leaf="">。这与前面微软</span><span lang="EN-US"><span leaf="">Vasu Jakkal</span></span><span leaf="">提到的</span><span lang="EN-US"><span leaf="">AI Agent</span></span><span leaf="">的新治理方式在理念上是一致的。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001337" data-ratio="0.5265060240963856" width="553" data-type="png" data-w="830" height="291" src="https://wechat2rss.xlab.app/img-proxy/?k=fe930437&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWpsbx3ebCibvI46QiaI0icuB9ItoNbVjNSj1WzUTHFS0pc4faLC9oYC5Lw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">Dawn Song</span></span><span leaf="">教授给出了</span><b><span lang="EN-US"><span leaf="">Agentic</span></span><span leaf="">系统的三大防御原则和</span><span lang="EN-US"><span leaf="">9</span></span><span leaf="">条防御机制</span></b><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001335" class="rich_pages wxw-img" data-ratio="0.6233453670276775" data-type="png" data-w="831" height="345" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=5f3b5b37&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWOsLgicAX6nveBCZNiaAQ1AIZASibuVd3R86AgAPPEtHE2YObYFwTXCwQA%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001338" data-ratio="0.5216867469879518" width="553" data-type="png" data-w="830" height="289" src="https://wechat2rss.xlab.app/img-proxy/?k=ab06c5a8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWyj6N0zXQH2iapVFCJ1E4QiaQhiaYyQPK69Q6xX2V1pTQQ3mDibo1iamj4Kg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><h1 style="margin-bottom: 24px;margin-top: 16px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">的自主程度和与人类的关系</span></span><span lang="EN-US"><o:p></o:p></span></h1><p style=""><span leaf="">笔者所见，所有演讲者都认为完全自主的安全（运营）不会存在，</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">也不会取代人。</span><b><span lang="EN-US" style="color:#4472C4;mso-themecolor:
accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span style="color:#4472C4;mso-themecolor:accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">时代是一个人机共智的时代</span></span></span></b><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">微软安全业务的副总裁</span><span lang="EN-US"><span leaf="">Vasu Jakkal</span></span><span leaf="">在演讲时向与会者展示了一幅自主</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">赋能安全的演进路线图。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img class="rich_pages wxw-img" data-imgfileid="100001343" data-ratio="0.47868453105968334" width="547" data-type="png" data-w="821" height="262" src="https://wechat2rss.xlab.app/img-proxy/?k=43762674&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWv7SJnAibBcibBxH2LUcbr3rou1Oz9uvsILcsgTAR5iciczcnNQGyXp1ibcw%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">如上图所示，</span><b><span leaf="">微软将自主</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">赋能安全分为四个阶段</span></b><span leaf="">，当前正在迈入第二阶段（</span><span lang="EN-US"><span leaf="">Level1</span></span><span leaf="">），即智能体能够推理并利用工具实现显性化的目标。而到明年，很可能会出现能够自我修改和优化模型以完成显性化声明式目标的半自主智能体。从上图可以看出，最高阶段叫高度自主化阶段，也就是说不会有完全自主化。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">SentinelOne </span></span><span leaf="">美洲地区</span><span lang="EN-US"><span leaf="">CTO Dave Gold</span></span><span leaf="">在演讲中也提出了</span><b><span leaf="">向未来的自主</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">演进的路线图</span></b><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001342" class="rich_pages wxw-img" data-ratio="0.5547533092659447" data-type="png" data-w="831" height="307" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=d7a3fbe6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWQJuH5zJfb2psaddibo7CQFrjqrPqqp2pewPNTJdoaQbvd7g8VlSaBbQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">上述演进路线的阶段划分与此前介绍的微软的自主</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">赋能安全的路线图大体一致，并且都不约而同地回避了“完全自主”这个概念。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">知名</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">专家</span><span lang="EN-US"><span leaf="">Anton Chuvakin</span></span><span leaf="">更是直言，现在的</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">赋能距离真正的自主化、自动化还差得远，并对“人工智能的进步可能会导致包括</span><span lang="EN-US"><span leaf=""> IT </span></span><span leaf="">和安全在内的技术团队在几年内大幅缩减甚至为零”的言论进行了驳斥，表示“所谓的无人自动化完全是胡扯”。</span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">对于</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">和人类在安全防御领域的关系，思科的</span><span lang="EN-US"><span leaf="">Jeetu Patel</span></span><span leaf="">很明确的指出，最好的防御是二者之间紧密协作。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001341" class="rich_pages wxw-img" data-ratio="0.4742647058823529" data-type="png" data-w="816" height="258" width="544" src="https://wechat2rss.xlab.app/img-proxy/?k=6684dfa5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWDyG53PRvfDHSjlics56iaSZYyeWnHBibUxsUhTwJtZkMPgGzmKPGt8BNg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span leaf="">而</span><span lang="EN-US"><span leaf="">SentinelOne</span></span><span leaf="">的</span><span lang="EN-US"><span leaf="">CEO Tomer Weingarten</span></span><span leaf="">在主会场的发言中也表达了相同的观点。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001339" class="rich_pages wxw-img" data-ratio="0.43139678615574784" data-type="png" data-w="809" height="233" width="539" src="https://wechat2rss.xlab.app/img-proxy/?k=16d3ad33&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWibtxlyEzy8bXpicZV5PfAwTZBddnU92qSMEwlKlhwGrDrqTOw3GMSyWg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style=""><span lang="EN-US"><span leaf="">ESG</span></span><span leaf="">指出，必须建立人类与</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">互相协作的闭环，互相促进。</span><span lang="EN-US"><o:p></o:p></span></p><p style="text-align: center;"><span lang="EN-US" style=""><span leaf=""><img data-imgfileid="100001340" class="rich_pages wxw-img" data-ratio="0.5126353790613718" data-type="png" data-w="831" height="284" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=c447f5d5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWNccKCI63wDk9poIEyj25Lq7EjfjqJfl7jgBI4qSMhrGaxrp72XMiaEg%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></span><span lang="EN-US"><o:p></o:p></span></p><p style="line-height: 1.75em;text-align: left;"><span lang="EN-US"><o:p></o:p></span></p><h1 style="margin-bottom: 24px;margin-top: 16px;"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">总结</span></span><span lang="EN-US"><o:p></o:p></span></h1><p style="line-height: 1.75em;"><span lang="EN-US" style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">从</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">2023</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">年开始正式进入安全领域，应用模式迅速发展，从聊天式应用模式到</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">助理应用模式，再到现在最流行的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">应用模式，已经成为安全运营未来发展的决定性力量。尤其是</span></span><b><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">，其迭代思考和行动的工作过程正好符合安全运营工作中绝大部分流程性任务的工作过程，完美适合应用于安全运营</span></span></b><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="" data-pm-slice="0 0 []"><span style="color:#4472C4;mso-themecolor:accent1;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">当前，业内对</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">寄予厚望，大大小小的安全厂商纷纷投入这个领域，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">赋能安全运营的用例和场景不断涌现，有的已经实现了产品化，但距离真正解决安全运营面临的三大难题（人才短缺、技能不足、工作倦怠），以及应对安全工具的复杂性方面还有不小差距。正如知名</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">SOC</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">专家</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Anton Chuvakin</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">在会议期间接受采访时所言，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">可以应对（这些）问题，但还不足以解决（这些）问题（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI Addressable, Not AI Solvable</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">）。他表示，目前</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">给安全运营带来的价值主要还是缓解而非消除（这些）痛苦。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">透过本次</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">RSAC</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">大会，必须清晰的认识到，</span></span><b><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">新一代</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">要真正赋能安全运营，</span></span><span leaf=""><a class="normal_text_link" target="_blank" style="color: rgb(0, 82, 255);" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484854&amp;idx=1&amp;sn=81ac539adfe55fca334828b7e82002e5&amp;scene=21#wechat_redirect" textvalue="仅靠AI自身是不够的" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="color: rgb(0, 82, 255);text-decoration: underline;">仅靠AI自身是不够的</span></a><span textstyle="" style="color: rgb(0, 82, 255);">，需要变革现有安全运营平台的技术架构，尤其是数据架构！此外，要真正让</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">赋能的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">SOC</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">形成持久战斗力，还需要变革</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">SOC</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">的组织和流程，让人类和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">、各种安全工具有效协作起来，实现人机共智</span></span></b><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">最后，在充分利用</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">赋能安全运营的同时，还需要充分认识到</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">自身面临的安全问题，尤其是未来的安全运营系统也是一个</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">Agentic</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">系统，必然存在较大的安全风险，需要有效加以管控。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">最后，笔者要对安全运营领域从业者高呼：</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span style="color: rgb(68, 114, 196);"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">历史机遇，不容错过！</span></span><span lang="EN-US"><o:p></o:p></span></span></b></p><p style="line-height: 1.75em;margin-bottom: 16px;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">【参考资料】</span></span></p><p style="line-height: 1.75em;margin-bottom: 16px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484766&amp;idx=1&amp;sn=5b66715c108908d39eb92ecdc964c9f6&amp;scene=21#wechat_redirect" textvalue="从RSAC2024看SOC发展趋势" data-itemshowtype="0" linktype="text" data-linktype="2">从RSAC2024看SOC发展趋势</a></span></p><p style="line-height: 1.75em;margin-bottom: 16px;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484640&amp;idx=1&amp;sn=6ff1f407b3ad35c01efbf35d5a0ded0d&amp;scene=21#wechat_redirect" textvalue="从RSAC2023看安全运营的技术发展趋势" data-itemshowtype="0" linktype="text" data-linktype="2">从RSAC2023看安全运营的技术发展趋势</a></span></p><p style="line-height: 1.75em;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484848&amp;idx=1&amp;sn=0f7f582e241603ec68bc85be3926998c&amp;scene=21#wechat_redirect" textvalue="是时候重新定义安全运营平台了" data-itemshowtype="0" linktype="text" data-linktype="2">是时候重新定义安全运营平台了</a></span></p><p style="line-height: 1.75em;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484854&amp;idx=1&amp;sn=81ac539adfe55fca334828b7e82002e5&amp;scene=21#wechat_redirect" textvalue="仅靠AI不足以重新定义安全运营平台" data-itemshowtype="0" linktype="text" data-linktype="2">仅靠AI不足以重新定义安全运营平台</a></span></p><p style="line-height: 1.75em;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484862&amp;idx=1&amp;sn=e0006eb7f308c8cb628d462601b8dc0a&amp;scene=21#wechat_redirect" textvalue="以自动化优先和实战化为设计理念的新一代安全运营平台" data-itemshowtype="0" linktype="text" data-linktype="2">以自动化优先和实战化为设计理念的新一代安全运营平台</a></span></p><p style="line-height: 1.75em;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e&amp;scene=21#wechat_redirect" textvalue="迈向AI赋能的SOC4.0时代" data-itemshowtype="11" linktype="text" data-linktype="2">迈向AI赋能的SOC4.0时代</a></span></p><p style="line-height: 1.75em;"><span leaf=""><a class="normal_text_link" target="_blank" style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484842&amp;idx=1&amp;sn=38dba05e2a0024b71d81d1d9b3e74a6c&amp;scene=21#wechat_redirect" textvalue="2024年安全运营技术趋势回顾" data-itemshowtype="0" linktype="text" data-linktype="2">2024年安全运营技术趋势回顾</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1e85736d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcK2n7w23haPmVejBIYFsxJ1g0LcanWkeacodEmYNYtZUr2MnSkLs3QzpB9YoOlovzWjLxyavK51w%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=fdbaff52&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWawf1A3JgkP0l5cwaK9vsYRPaWGwuiazmDGxoDvtKw5BSjNxWOfWiaHNA%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=b6a200d9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWgicXWickDOkBvdlKJ1NG5SXEZwlicFWhKW6P97YDDiajgZ8lTziaJNklLNA%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d419576f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWTB98eZLwxFtWGnS2ZbOcQHhnBABRwUn7ccFjicp3xdbga06g7mYpDKg%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c8fb4306&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWML36Onr31Y9P3NjZxpsIMib784ORs7chGVNCwzyicXZxMM3Dt14Ov3QA%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=410c7346&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWh6YhE6jGtiatKCNADbsTX3kQ2ibPnx221a029PoPicA7o8ticYzf5OpvIA%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=2e293712&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWU2b0TuicbNaFjCcTHhicyBDzKT5HSicsM0DOS5wnQ0qcoPVUQRpfej2QQ%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=675fa9cb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWFEABgdzunia4R9x01Cx24hF7kbvNiad6WLa0icj2XYdqRITLhVd7tzwcQ%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=305522e9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcK2n7w23haPmVejBIYFsxJznJ6DBScJOUeRRR7zDaFCYouicI4QuhUbjIh5JDaxMNrVCq1qFWbRQA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=de742504&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWL0tR0ecYBTvpRgicHNt4zWyFaPMbNfvcgD4suubGkhGSI5czhtfsMbQ%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=3ec50bc7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWN1GMHWw06IuGUK4C2cdSZmONOUcQhZuq82CUqvfru1JShHKexOJXVA%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1dee393c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWbJV5E8HxqInjKBRyzt2ohNtPOdu8GJ8O65lbCfjHVgw0ax9fQmA0Jw%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a03061ec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrW04G5BfQE92CU1r7mHwibEiaNiclYv1WEsk8Oo5ib1EIs7MDC1bmczH9J6g%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=90605e05&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWQK4DC5UJhqFxwUXnmN9useBmEvRLL1ia6uKlsYgiba4FwuMS74EQneJw%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=10f8bed5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrW7A5ek2tKdopLjLhF2ibicAiaicyd798hbqmNS5yibibrZOwXK02PYwbJRgKQ%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=dc38ac5a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWXXiaVM3L5Et6HILiajTdJdXjYSc3jd4HbBEsS7cuGp4kl9Yw2GZhMe0g%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=2afac13a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWklV7adLCHVDJgOjibkvaDLNVZPjsOYwcwSPACmvIgPFHyic65H9vmXag%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=313b8ec5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWBickk0vicad0ias7SqNXo4qQBbMNwQLJ5LRuxmu8s6BMNrvbGSqTvBvmA%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a314594e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrW0ofeGQWI0FShLvUfMBNSohBHundsicxDicYiawibBmD3zkcDk7hqTjBnaQ%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=9dead183&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWeTbQvdNsdXz2Xu3yZRgk56uUrb4ecdw7FE9ZKXPTWudiaJ7Z6YgRZyw%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=959ddcfa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWhGBRnjZnB552wJoSPon34lzlkKpvicibLWVAia6QJfiaicABh1YzDstKRzA%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=e622f29e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWhcb75QicsSuVycEysXFjELybJY9d30B6S1cbicP12bleHLGjGLkMrD1w%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=c9f06d51&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWCD2jibbG6W4YpLwl6dhYYvmv3z3Pzxnv3tetyHerzBVsXvINaM86l8A%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f8276b86&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWlibwsBghN7VZCx6t6Xt4q2zMn9MjQ4pTJfr5Bbl1Y6hVwn8QOxicnnIw%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=254514a7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrW7blPecGJMvTuzopVRIhXCZPKhuQdTAunaKvUNV3f2gibTGIaBQEEftA%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=0abad11a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrW0MwrVnpXibwzfRt1p1m4bYPG9J3AcN5zfjgXDEWDUUSWoU9LynGWNng%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=0542ce25&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWSuavZKs9PELEjicaY57wEY3aOLzvHVLwmuogQFzsGQCbfJnLayoqgcg%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=ad5c420f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWFRR34h0j0jS0UHjP0jFwMPRy2gYIOy143I3pJ1zL4wserwf1TtnTzQ%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1ceb10e3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWNJevTsXRLG0wOJakKArGN7f0yXxXibXzvTXRwRqL7LBJBNexRpjhOLA%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=e6f78299&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWPbTHsO6AiaAs1NWh9XvBqibwWSO6lHicmSrn8MdWDMKmqY2W9xEMuZqMA%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=6ecb4816&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWkKll4w7gqgGdV38pASiayPh4cncej0SzWzibntM35neNhiaJVYp57VkPw%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=21e1d32d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWQovaQRgpFeVxB9OTsGoUGx85cTfMRFUmicNRllfDBwjVN121iaNwqkYw%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d9532018&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWYUfcFbTT3omXPaBgfP5ZXH1q8iblIlUIOERorBtaBMrAjW93Ej4SRFA%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=7a37f2df&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWgQssAAKBMaCHTmKUf69SvYc7m0DRJm4kmUd0OchqVPmk3DN43gbJLg%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=931e7976&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWP14nss916YQicXdANudeGwUQWeqEDfwjtDdfGiahaVW7mfWibsYC5L3xg%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=8aaf8152&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWtneRbC9ibwelIRrlo0JfZqcDuJppRt4vHhwszAheXISb3k5EMC2fxaA%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=ebdcc169&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWvphSAr5tsqmnxRiaIiafbrg2fia50UVOoiaI9ib58D1ic7tSpMrmXgQJ4rOA%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=d34ba37f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrW5IzXBiaiawgZhIXrsBkzhFN6hp4STtOFNwDzqNyCT5ibicbK70C2Z2ibQibQ%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=dd9aa9a1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWo97DORo5nK7SXWdelhdQoRszHhuzg3FVX3KcjyWfJafWozNZYaDxlg%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=03553247&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWMfupia0nNia0MbynJC2GPT70JGR31kj7r1ZAjqwarpG2ibGToelXetgdg%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=ec7df510&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWPhnRQdTL2xuTdBX2G5Xsd5pAgMYuElzLh3Hz3eM1lAOstluWpzo3Tg%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f114efa7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWBpib7z5QBI5q4NtDf0Q4eCickZYskQDyT0dBjSZw6xtYbwIExz9WFT9A%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=28a3bcc8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrW30BCBQC2clUTs9GW1Ahnp2If1zkbiaTU0via7iaicRrK8jvY2AOjO5MX1Q%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1b425dc1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWG6J6jJYkLgqnjuWpVEyYlscKboeeTkW6RppcuZaBiaicicLcpC3XhP7xQ%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a9305d7e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWePSfiaUNd2vN3qt0aPIUwAOaPlJibOWMRJk02icpScscRdyRgGxf19sWw%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a6c434e3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWpsbx3ebCibvI46QiaI0icuB9ItoNbVjNSj1WzUTHFS0pc4faLC9oYC5Lw%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=a28ff8aa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWOsLgicAX6nveBCZNiaAQ1AIZASibuVd3R86AgAPPEtHE2YObYFwTXCwQA%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=640041a4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWyj6N0zXQH2iapVFCJ1E4QiaQhiaYyQPK69Q6xX2V1pTQQ3mDibo1iamj4Kg%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=67947595&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWv7SJnAibBcibBxH2LUcbr3rou1Oz9uvsILcsgTAR5iciczcnNQGyXp1ibcw%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=4e4b0344&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWQJuH5zJfb2psaddibo7CQFrjqrPqqp2pewPNTJdoaQbvd7g8VlSaBbQ%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=26c55435&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWDyG53PRvfDHSjlics56iaSZYyeWnHBibUxsUhTwJtZkMPgGzmKPGt8BNg%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=779e53a3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWibtxlyEzy8bXpicZV5PfAwTZBddnU92qSMEwlKlhwGrDrqTOw3GMSyWg%2F640%3Fwx_fmt%3Djpeg"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f9e44fc1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdveLuNz0saK6lclmlUaicrWNccKCI63wDk9poIEyj25Lq7EjfjqJfl7jgBI4qSMhrGaxrp72XMiaEg%2F640%3Fwx_fmt%3Djpeg"/></p>



<p><a href="2247484993">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=3e0e0c75&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyNzMxOTAwMw%3D%3D%26mid%3D2247484993%26idx%3D1%26sn%3D506b9c0de108b2293d71c15750f0d95c">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 23 May 2025 17:01:00 +0800</pubDate>
    </item>
    <item>
      <title>迈向AI赋能的SOC4.0时代</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484935&amp;idx=1&amp;sn=31de4443db5310b2ac6cdd7b3df19e2e</link>
      <description>SOC4.0是一个AI赋能的、数据与流程双轮驱动的、自动化优先的实战化安全运营平台</description>
      <content:encoded><![CDATA[<p>
<span>叶蓬</span> <span>2025-05-22 12:02</span> <span style="display: inline-block;">北京</span>
</p>

<p>SOC4.0是一个AI赋能的、数据与流程双轮驱动的、自动化优先的实战化安全运营平台</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=99007721&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdqkddfeicVw6Db40okK97ic5lNVZZyCRAqftAzbhXAVkicTRYwPmtD2FRdwZdl7ZNgIFyAcvDJKYb7Q%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><span lang="EN-US" style="font-size: 14pt;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: justify;line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;lang&#34;:&#34;EN-US&#34;,&#34;style&#34;:&#34;font-size: 14pt;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);font-weight: bold;">【前言】</span><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">本文首发于数世咨询，在发布到本人微信号时，进行了微调，主要是增加了摘要，以及文末的参考资料链接。从SOC1.0到SOC4.0，历经25年，也是笔者在SOC领域专注24年的缩影。笔者在2009年提出了SOC2.0，并在2015年提出了SOC3.0，有幸亲历了中国安全运营发展的几乎全过程。对于安全运营的未来，笔者坚定看好，并且还有很多工作</span></span><span lang="EN-US" style="font-size: 14pt;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;lang&#34;:&#34;EN-US&#34;,&#34;style&#34;:&#34;font-size: 14pt;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">值得去做。</span></span></span></span></p><p><span lang="EN-US" style="font-size: 14pt;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: justify;line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;lang&#34;:&#34;EN-US&#34;,&#34;style&#34;:&#34;font-size: 14pt;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">SOC在国内的发展，经历了从合规导向到对抗导向的演进，未来正在向价值导向迈进。如何让SOC平台发挥作用，产生价值，是我们这些从业者需要不断反思、不断突破的。</span></span></span></p><p><span lang="EN-US" style="font-size: 14pt;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: justify;line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;lang&#34;:&#34;EN-US&#34;,&#34;style&#34;:&#34;font-size: 14pt;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">如果您对SOC4.0理念感兴趣，欢迎持续关注我的微信号。如果您对SOC4.0的落地感兴趣，欢迎关注</span><a class="normal_text_link" target="_blank" style="color: rgb(0, 0, 0);" data-unique-id="mayntbck-mu3cxx" href="https://mp.weixin.qq.com/s?__biz=MzkzMzkzMjI4OQ==&amp;mid=2247483680&amp;idx=1&amp;sn=2cd09d78ab450c2fa40360538f5e9367&amp;scene=21#wechat_redirect" textvalue="这支团队" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 17px;color: rgb(0, 0, 0);">这支团队</span></a><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">的微信号。</span></span></span></p><p><span lang="EN-US" style="font-size: 14pt;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: justify;line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;lang&#34;:&#34;EN-US&#34;,&#34;style&#34;:&#34;font-size: 14pt;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 18px;color: rgb(0, 82, 255);font-weight: bold;">【摘要】</span><span textstyle="" style="font-size: 18px;color: rgb(0, 82, 255);">本文在笔者之前</span><a class="normal_text_link" target="_blank" style="" data-unique-id="maymb6hy-62a1dc" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484842&amp;idx=1&amp;sn=38dba05e2a0024b71d81d1d9b3e74a6c&amp;scene=21#wechat_redirect" textvalue="2024年安全运营技术趋势回顾" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 18px;">2024年安全运营技术趋势回顾</span></a><span textstyle="" style="font-size: 18px;">、</span><a class="normal_text_link" target="_blank" style="" data-unique-id="maymbf9q-0tpdic" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484848&amp;idx=1&amp;sn=0f7f582e241603ec68bc85be3926998c&amp;scene=21#wechat_redirect" textvalue="是时候重新定义安全运营平台了" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 18px;">是时候重新定义安全运营平台了</span></a><span textstyle="" style="font-size: 18px;">、</span><a class="normal_text_link" target="_blank" style="" data-unique-id="maymbliq-f6patb" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484854&amp;idx=1&amp;sn=81ac539adfe55fca334828b7e82002e5&amp;scene=21#wechat_redirect" textvalue="仅靠AI不足以重新定义安全运营平台" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 18px;">仅靠AI不足以重新定义安全运营平台</span></a><span textstyle="" style="font-size: 18px;">、</span><a class="normal_text_link" target="_blank" style="" data-unique-id="maymbqsp-fvr82d" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484862&amp;idx=1&amp;sn=e0006eb7f308c8cb628d462601b8dc0a&amp;scene=21#wechat_redirect" textvalue="以自动化优先和实战化为设计理念的新一代安全运营平台" data-itemshowtype="0" linktype="text" data-linktype="2"><span textstyle="" style="font-size: 18px;">以自动化优先和实战化为设计理念的新一代安全运营平台</span></a><span textstyle="" style="font-size: 18px;color: rgb(0, 82, 255);">等一系列文章的基础上，系统性的回顾了中国SOC领域二十五年来三个阶段的演进历程和亲身经历，指出了当下SOC平台面临的不足之处。面对GenAI（尤其是Agentic AI）给SOC发展带来的重大机遇，笔者指出：</span><span textstyle="" style="font-size: 18px;color: rgb(0, 82, 255);font-weight: bold;">AI正在重塑SOC平台，但仅靠AI是不够的，还需要从数据和流程两个方面重塑SOC平台的技术架构</span><span textstyle="" style="font-size: 18px;color: rgb(0, 82, 255);">。为此，笔者提出了SOC4.0的概念，并进一步分析了</span><span textstyle="" style="font-size: 18px;color: rgb(0, 82, 255);font-weight: bold;">SOC4.0的五个关键特征</span><span textstyle="" style="font-size: 18px;color: rgb(0, 82, 255);">：以</span><span textstyle="" style="font-size: 18px;color: rgb(0, 82, 255);font-weight: bold;">Agentic AI</span><span textstyle="" style="font-size: 18px;color: rgb(0, 82, 255);">为核心的AI赋能、基于</span><span textstyle="" style="font-size: 18px;color: rgb(0, 82, 255);font-weight: bold;">安全数据编织</span><span textstyle="" style="font-size: 18px;color: rgb(0, 82, 255);">的数据架构、基于编排的</span><span textstyle="" style="font-size: 18px;color: rgb(0, 82, 255);font-weight: bold;">双流程引擎</span><span textstyle="" style="font-size: 18px;color: rgb(0, 82, 255);">架构，以及</span><span textstyle="" style="font-size: 18px;color: rgb(0, 82, 255);font-weight: bold;">自动化优先</span><span textstyle="" style="font-size: 18px;color: rgb(0, 82, 255);">和</span><span textstyle="" style="font-size: 18px;color: rgb(0, 82, 255);font-weight: bold;">实战化</span><span textstyle="" style="font-size: 18px;color: rgb(0, 82, 255);">的设计原则。</span></span></span></p><p style="text-align: center;"><span lang="EN-US" style="font-size: 14pt;"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;style&#34;:&#34;text-align: justify;line-height: 1.75em;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;lang&#34;:&#34;EN-US&#34;,&#34;style&#34;:&#34;font-size: 14pt;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 24px;">迈向</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 24px;">赋能的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 24px;">时代</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="text-align: center;line-height: 1.75em;"><span lang="EN-US" style="font-size: 14pt;"><span leaf=""><span textstyle="" style="font-size: 24px;">Towards the AI Empowered SOC4.0 Era</span></span></span></p><p style="text-align: center;line-height: 1.75em;"><span lang="EN-US" style="font-size: 14pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">V2025.5.21</span></span></span></p><h1 style="line-height: 1.75em;margin-top: 32px;margin-bottom: 32px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">1</span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">    </span></span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">定义</span></span><span lang="EN-US"><o:p></o:p></span></h1><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">安全运营（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SecOps</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）是一个很泛化的概念。在最广泛意义上，可以</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">把安全运营看作是持续不断地保障目标网络安全平稳运行，达成组织业务战略目标的永续过程，以及在这个过程中开展的各项运营工作</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">从狭义上来看，安全运营的主要工作是威胁事件的运营以及围绕这个威胁事件运营延伸出来的资产、漏洞、情报等等一系列配套运营工作。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Gartner</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">将</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">安全运营定义为一个“通过一套人、流程和技术来识别和管理暴露、监测、检测和响应网络安全威胁与事件，以增加网络弹性”的过程。</span></span></b><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">安全运营中心（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）作为一个组织单元，工作内容更加聚焦，基本围绕狭义的安全运营展开。</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">安全运营中心通常是指一个包含一系列流程、人员、技术等的组织单元，核心目标就是抵御网络安全威胁、保障目标网络安全平稳运行，通常包括威胁事件运营、资产暴露运营、安全漏洞运营、安全情报运营、防御策略运营、态势决策运营</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">6</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">个方面的运营工作</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。围绕这个目标，通常会对目标网络实施持续的检测、监测、分析、调查、响应、报告、修复。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">安全运营平台（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOP</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">），或者称作</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">平台，早期也叫安全管理平台（简称安管平台），是指安全运营中心的核心技术支撑平台</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">，集成安全运营中心所需的各种数据、技术、工具和流程，为各级安全运营人员提供一个便捷易用的工作台，以便开展安全运营工作。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;font-weight: bold;">SOC</span></span></span><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;font-weight: bold;">的演进过程存在多条平行的时间线。</span><span textstyle="" style="font-size: 17px;">可以从</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">平台的技术演进角度去梳理时间线，譬如本文；可以从</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">应用领域的扩张角度去梳理时间线，研究</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">从最初应用于传统</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">IT</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">基础设施，逐步延伸到云、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">OT</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">、物联网，车联网等新领域的过程；可以从</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">部署模式的角度去梳理时间线，研究</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">如何从云下部署发展到后来的云寄生部署、云原生部署，以及由此带来的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">业务模式从产品交付到</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SaaS</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">服务交付的转变过程；还可以从</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">服务的角度去梳理时间线，研究托管安全服务（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">MSS</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）的历史，看其如何衍生出托管检测与响应（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">MDR</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）、协管安全监测服务（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">CMSMS</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）。毫无疑问，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">平台视角是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">演进过程的最重要时间线，无论</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">应用领域如何扩展，无论</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">是在云下还是云上，也无论</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">MSS</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">提供商的服务模式如何变化，它们所依托的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">平台发展进程都是一样的。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">本文所指的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">SOC1.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">SOC2.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">都是针对</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">SOP</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">平台、安全管理平台而言的</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><h1 style="line-height: 1.75em;margin-top: 32px;margin-bottom: 32px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">2</span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">    </span></span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">中国</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">平台代际演进过程回顾</span></span><span lang="EN-US"><o:p></o:p></span></h1><h2 style="line-height: 1.75em;margin-bottom: 32px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">2.1</span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">  </span></span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">概述</span></span><span lang="EN-US"><o:p></o:p></span></h2><p style="line-height: 1.75em;margin-left: 0px;margin-right: 0px;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">从</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">2000</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">年</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">进入中国到</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">2025</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">年的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">25</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">年间，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">平台经历了</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">3</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">个明显的代际叠加演进过程。</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">从最初面向资产的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC1.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">到面向业务的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC2.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">，再到数据驱动的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">，每个时代的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">平台都具有鲜明的时代烙印，体现了</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">建设需求、目标和技术要求的不断演变。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 1.75em;text-indent: 0px;"><span lang="EN-US" style="font-size: 12pt;"><span style=""><span leaf=""><span textstyle="" style="font-size: 17px;">SOC1.0</span></span></span></span><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">身处中国网络安全的萌芽期。这时期的</span></span><b><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">SOC1.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">主要对标</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">ISO17799</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">以及后来的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">ISO27000</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">系列标准，以期落实信息安全管理体系（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">ISMS</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">）的核心要求和实用规则</span><span textstyle="" style="font-size: 17px;">。</span></span></b><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC1.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">侧重于构建以资产为中心的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">ISMS</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">技术支撑平台。</span></span><span lang="EN-US"><o:p></o:p></span></span></p></li><li><p style="line-height: 1.75em;text-indent: 0px;"><span lang="EN-US" style="font-size: 12pt;"><span style=""><span leaf=""><span textstyle="" style="font-size: 17px;">SOC2.0</span></span></span></span><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">时代是中国网络安全的合规时代，等级保护成为当时中国网络安全市场的首要推动力。这时期的</span></span><b><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">SOC2.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">形成了以合规为导向、以业务信息系统保障为核心的设计思路</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC2.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">成为了一个面向等保合规的、功能较为完备的集中化安全管理平台。</span></span><span lang="EN-US"><o:p></o:p></span></span></p></li><li><p style="line-height: 1.75em;text-indent: 0px;"><span lang="EN-US" style="font-size: 12pt;"><span style=""><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span></span><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">时代是中国网络安全回归对抗本质的时代，这时期的</span></span><b><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">经历了从合规到对抗、从管理到运营的叠加演进，确立了数据驱动</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">的技术路线</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">成为了一个基于大数据分析架构的，具备一定智能和主动能力的安全运营平台。</span></span><span lang="EN-US"><o:p></o:p></span></span></p></li></ul><h2 style="line-height: 1.75em;margin-bottom: 32px;margin-top: 24px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">2.2</span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">  </span></span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">SOC1.0</span></span><o:p></o:p></span></h2><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">2000</span></span></span><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">年前后，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">概念开始进入中国。经过约</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">4</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">年左右的摸索，第一代</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">平台（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC1.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）的定义在</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">2004</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">年基本成形，并迎来了一波建设的热潮。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">SOC1.0</span></span></span></b><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">定义</span><span textstyle="" style="font-size: 17px;">：以资产为核心，以安全事态（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Event</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）管理为关键流程，采用安全域划分的思想</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">,</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">建立一套实时的资产风险模型，协助管理员进行事态分析、风险分析、预警管理和应急响应处理的集中安全管理系统</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC1.0</span></span></span><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">在系统设计上向</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">ISO17799</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">以及后来的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">ISO27000</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">系列标准靠拢，参照信息安全管理体系（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">ISMS</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）的要求和实用规则，以实现集中化的安全管理为目标，设计出了第一代</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">平台，当时也叫安全管理平台。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">由于当时国内安全建设尚处于早期，需求不够清晰，加之受限于国内技术水平，多源数据采集和安全分析能力十分薄弱，缺少核心技术，很多</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的理念未能很好落地。这时候，很多国内</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">平台都集成了国外了</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SIEM</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">产品作为内核。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC1.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">渐渐遭遇发展瓶颈。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><h2 style="line-height: 1.75em;margin-bottom: 32px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">2.3</span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">  </span></span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">SOC2.0</span></span><o:p></o:p></span></h2><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">又经过</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">5</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">年的发展，在</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">2009</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">年，第二代</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">平台（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC2.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）出现。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);font-weight: bold;">SOC2.0</span></span></span></b><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);font-weight: bold;">定义</span><span textstyle="" style="font-size: 17px;">：以业务信息系统为核心，通过面向业务的安全建模与业务风险管理流程，采用主动被动相结合的方法采集业务系统的各种安全信息，从业务视角进行数据的标准化、监测、分析、审计、报警、响应、存储和报告的一体化安全管理系统，力求安全与业务战略对齐</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC2.0</span></span></span><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">迅速在国内得到广泛认同，获得了巨大成功，确立了安全管理平台这个细分市场的定位和价值。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">首先，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC2.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">在理念上进行了拔高，实现了安全运营从资产视角到业务视角的提升，指出安全运营的目标就是保障业务信息系统的持续运行，而安全运营的过程就是业务安全风险管理的过程。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">其次，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC2.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">在概念上将</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">和安全管理平台的关系、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">NOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的关系、安全运营与安全合规的关系进行了厘清。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">第三，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC2.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">在平台功能设计上，紧扣《等级保护基本要求》中三级及以上信息系统要求建立安全管理中心的合规要求，建立起了一个面向等保合规（也包含</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">ISMS</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">等其它合规）的、功能较为完备的集中化安全管理平台。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">最后，在技术上，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC2.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">推动作为</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">核心的多源数据融合与关联分析引擎技术走向成熟，大幅提升了安全数据的采集能力和威胁事件的分析能力，并开启了态势感知技术的工程化实践之路。技术的成熟，推动国产化</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">平台逐步成为主流。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">以等保合规为重要契机，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC2.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">凭借理念的提升、概念的厘清、功能的匹配、技术的成熟，推动</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">经历了一波发展高潮。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">也是在这个时期，国内的赛迪顾问（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">CCID</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）开始将支撑</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的安全管理平台作为一个重要安全细分市场纳入《中国信息安全产品市场分析年度报告》的分析之中。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">2012</span></span></span><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">年，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Gartner</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">发布了一份名为《信息安全正在成为大数据分析问题》的报告，揭开了数据驱动安全时代的序幕。同年，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Splunk</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">成为全球第一家大数据上市公司。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">而伴随着国内网络安全建设的铺开，国内的企业和组织也逐渐面临大数据带来的挑战，一方面是每天产生的安全数据不断扩张，另一方面则是以</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">APT</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">为代表的新型威胁的兴起。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC2.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的诸多技术局限性逐步凸显：</span></span><span lang="EN-US"><o:p></o:p></span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span style=""><span leaf=""><span textstyle="" style="font-size: 17px;">数据处理能力有限，缺乏有效的架构支撑：当前分析工具在小数据量时有效，在大数据量时难以为继，海量异构高维数据的融合、存储和管理遇到困难；</span></span></span><span lang="EN-US"><o:p></o:p></span></span></p></li><li><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span style=""><span leaf=""><span textstyle="" style="font-size: 17px;">威胁识别能力有限，缺乏安全智能：安全分析以基于规则的关联分析为主，只能识别已知并且已描述的攻击，难以识别复杂的攻击，无法识别未知的攻击；</span></span></span><span lang="EN-US"><o:p></o:p></span></span></p></li><li><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span style=""><span leaf=""><span textstyle="" style="font-size: 17px;">安全预判能力有限，缺乏对抗能力：安全运营以被动应急响应为主，难以对风险进行提前的评估与研判，总是疲于救火。</span></span></span><span lang="EN-US"><o:p></o:p></span></span></p></li></ul><p style="line-height: 1.75em;margin-top: 16px;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">在这种情况下，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC2.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">必须顺势而变。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><h2 style="line-height: 1.75em;margin-bottom: 32px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">2.4</span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">  </span></span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">SOC3.0</span></span><o:p></o:p></span></h2><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">2015</span></span></span><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">年，基于大数据技术的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">（有的也叫</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">NGSOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）【注：这里的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">NGSOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">是指代一类</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">平台，而非具体品牌型号，后同】出现，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">平台进入第三代。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">SOC3.0</span></span></span></b><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">定义</span><span textstyle="" style="font-size: 17px;">：以大数据分析架构为支撑，以保障业务系统安全为导向，构建起以数据为核心的安全运营平台，强调更加主动、智能地对企业和组织的网络安全进行管理和运营</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span></b><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">标志着安全运营进入了数据驱动的时代</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">首先，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">全面采用大数据分析技术架构，海量、高速、多样的数据采集、存储、分析与展现成为了现实，极大拓展了</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的数据规模和处理性能。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">其次，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">引入了威胁情报数据，通过将网络中遭受的攻击告警和资产信息与威胁情报的比对，实现了更加主动、更加精准的威胁检测与预警。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">第三，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">推动了以</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">UEBA</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">（用户与实体行为分析）和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">NBA</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">（网络行为分析）为代表的基于人工智能（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）和机器学习（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">ML</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）的异常检测技术的落地，与关联分析技术形成</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的双核动力，大幅提升了</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的智能化水平。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">随着</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">2014</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">年网络安全上升为国家战略，以及</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">2016</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">年的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">419</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">讲话，中国网络安全事业进入一个新的历史阶段。面对这个历史机遇，以大数据分析技术为契机，中国市场开启了</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">升级换代和大规模部署的进程，数据驱动的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">取得了巨大成就。而</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">2016</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">年的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">419</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">讲话更是给作为网络安全态势感知基石的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">带来了新的巨大市场增量。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">在</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">时代，</span></span><b><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的使用场景和设计理念也开启了从合规优先到对抗优先、以管理为主到以运营为主的转变过程，并推动</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的持续升级</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">近些年来，以大数据技术架构为基础，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">引入了更多</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">ML</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">算法，以期提升暴露评估、威胁检测、态势评估与预测等关键能力。到</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">2019</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">年，国内又进一步将安全编排自动化与响应（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOAR</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）技术落地，将编排自动化技术带入了</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">，以期提升安全响应的自动化水平和响应速度。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">与大数据同时发展起来的云计算也被引入到了</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">。一方面是用</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">保障云计算的安全，另一方面则是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">自身的云化。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">在这个时期，以端点检测与响应（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">EDR</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）、网络检测与响应（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">NDR</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）、可扩展检测与响应（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">XDR</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）为代表的边缘检测与响应技术的兴起，以及以攻击面管理（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">ASM</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）、暴露评估平台（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">EAP</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）、对抗暴露验证（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AEV</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）为代表的暴露管理技术的重装上阵，改变了</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的部署架构，促使</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的技术架构逐步开始向分布式和多体模式转变。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">与此同时，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的运营者越来越重视</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的组织和流程建设。从</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">时代开始，越来越多使用</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的单位都建立起了专门的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">部门、组织、岗位职责、运营流程、工作场所和运营队伍。而</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">平台也开始提供面向运营的功能。尤其是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOAR</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的引入，让安全事件响应平台（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SIRP</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）成为</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">中重要的运营工具。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">但这些改进，依然将</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">定格在了</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">时代，因为这并未给</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">带来根本的革新，而用户在</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">时代所遇到的困境没有得到根本性的解决。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><h1 style="line-height: 1.75em;margin-top: 32px;margin-bottom: 32px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">3</span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">    </span></span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">面临的困境</span></span><span lang="EN-US"><o:p></o:p></span></h1><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">尽管</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">取得了很大的成功，但此时的安全运营平台也逐渐变得不堪重负，用户的不满日益突出。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="line-height: 1.75em;"><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">缺乏实战</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">：名为安全运营，实际上更多是在做安全分析，偏重面向专家用户的功能设计，缺乏面向真正运营人员的分角色运营流程梳理和运营功能设计，导致安全运营平台的用户体验差、易用性差。有的平台虽然进行了这方面的设计，但却没有跟实际负责运营的团队拉通，在理念和工作方式上严重脱节，设计和使用两张皮，同样导致运营效果不佳。</span></span><span lang="EN-US"><o:p></o:p></span></span></p></li><li><p style="line-height: 1.75em;"><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">数据过载</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">：大数据技术的加持，提升数据处理量，但也带来了数据沼泽，大量的告警和事件积压，真假难辨、误报频频，负责研判和响应处置的运营人员不堪重负</span></span><span leaf=""><span textstyle="" style="font-size: 17px;">，极易产生工作疲劳，</span></span><span leaf=""><span textstyle="" style="font-size: 17px;">运营效果大打折扣。长此以往，导致工作倦怠、人才流失。</span></span><span lang="EN-US"><o:p></o:p></span></span></p></li><li><p style="line-height: 1.75em;"><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">自动化水平偏低</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">：当前以</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOAR</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">为基础的响应自动化对于缓解运营疲劳作用有限，囿于用户运营流程和规程不健全，剧本开发成本高、剧本适应性低，运营自动化难以普及。</span></span><span lang="EN-US"><o:p></o:p></span></span></p></li><li><p style="line-height: 1.75em;"><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">智能化程度有限</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">：</span></span><span style=""><span leaf=""><span textstyle="" style="font-size: 17px;">现有的智能化更多应用于分散的安全运营功能点</span></span></span><span style=""><span leaf=""><span textstyle="" style="font-size: 17px;">，对于整体的安全运营过程还是以人的智力为主</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">，对人的要求依然很高，距离安全运营者的期望还有较大差距。</span></span><span lang="EN-US"><o:p></o:p></span></span></p></li><li><p style="line-height: 1.75em;"><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">定制化能力非常薄弱</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">：安全运营平台的可定制性和可扩展性不够，要么无法定制，要么定制周期过长、成本过高，导致安全运营的实际使用落后于不断增长的安全需求和持续变化的对抗形势。</span></span><span lang="EN-US"><o:p></o:p></span></span></p></li><li><p style="line-height: 1.75em;"><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">运营价值难以体现</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">：</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">建设的价值如何？平台虽有大量数据，但都是安全数据，缺少运营过程数据和验证数据，缺乏对运营价值的度量，安全运营自身的数字化水平不足。</span></span><span lang="EN-US"><o:p></o:p></span></span></p></li></ul><h1 style="line-height: 1.75em;margin-top: 32px;margin-bottom: 32px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">4</span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">    </span></span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">从数据驱动的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">迈向</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">赋能的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">SOC4.0</span></span><o:p></o:p></span></h1><h2 style="line-height: 1.75em;margin-bottom: 32px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">4.1</span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">  </span></span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">生成式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">为</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">的变革带来重大机遇</span></span><span lang="EN-US"><o:p></o:p></span></h2><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">从一开始就应用于</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">平台，基于规则推理的关联分析就是符号主义</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">在</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">中的典型应用。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">2015</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">年，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Gartner</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">发表了一份智能</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的报告，指出要利用高级安全分析来落地智能化</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">，采用机器学习（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">ML</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）算法识别未知威胁的异常检测技术开始盛行。此后，还出现了其它用于提升暴露评估、告警研判、态势评估与预测等关键能力的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">ML</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">算法。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">但是，上述传统</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">通常聚焦</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">中某些专门的问题，采用专门的算法进行复杂的设计与开发，并且不同的问题往往需要使用不同的算法和模型，具有很强的专业性，对开发人员的技术要求很高。安全运营是一个过程，是一系列流程、规程和操作的集合。传统</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">虽然解决了安全运营过程中的一些关键难题，但却不能将整个运营过程串起来，对整体运营帮助有限，还需要安全运营人员的大量工作。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">2022</span></span></span><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">年底以大语言模型（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">LLM</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）为代表的生成式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）技术的爆火让一切开始变得不同。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">作为一种公认的颠覆性技术，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">近两年迅速席卷各行各业，并在安全运营领域取得了令人惊叹的效果，因为它恰好完美地击中了当下安全运营的三大痛点：人才短缺、工作倦怠、技能不足。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">Gartner</span></span></span><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">分析指出，如果说</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">2023</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">年是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">开局之年，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">2024</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">年则应是最小可⾏产品（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">MVP</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">）⼤⾏其道之年，⽽</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">2025</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">年可能会是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">集成到安全⼯作流程中并提供真正价值的元年。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">不到两年，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">在安全运营中的应用模式迅速从早期的智能聊天，发展到后来的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">助理</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">/</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">副驾，再到现在基于</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的智能体，将安全运营带入了自主式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）时代。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">Agentic AI</span></span></span></b><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">是一个以</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">（如</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">LLM</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）为思考中枢的，能够自主或部分自主的进行决策并采取行动，以完成既定目标的系统，具有自主性、适应性和持续学习的特点</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">以及由此衍生出来的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">相较于传统</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">，使</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的效能获得了极大的提升。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">具有较高的</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">普适应</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。不同于传统</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的专用性，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">向通用</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AGI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）迈出了一步，一个模型能够解决多个问题。安全运营的每个领域、运营过程的每个环节都可以利用</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">，简化工作过程、提升工作效率。在</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的赋能下，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的整体运营效率可以获得巨大提升。</span></span><span lang="EN-US"><o:p></o:p></span></span></p></li><li><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">具有较强的</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">普惠性</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">通过自然语言交互的体验方式，降低了对应用型技能（如编码、特定规则的语法、工具调用等）的要求，让广大运营人员可以更快上手，更便捷的进行操作，更聚焦安全运营领域的业务型技能（如特定威胁响应的战法、独特的安全知识等）。此外，随着</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">技术的快速发展，开发各种安全运营智能体所需的应用型技能要求正在变得越来越低。</span></span><span lang="EN-US"><o:p></o:p></span></span></p></li><li><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">基于</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">具有很强的</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">自主性</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">特别适合用于安全运营领域，很多流程性的安全运营任务都可以借助基于</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的智能体实现，提升安全运营的自主性和智能自动化水平，减轻工作压力。</span></span><span lang="EN-US"><o:p></o:p></span></span></p></li><li><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">基于</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">具有很强的</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">协作性</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">，将</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">从工具变成了“伙伴”。传统</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">更多像是一个个工具，由人来调用。而</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">则让</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">成为了工具的使用者，能够主动地使用各种工具，包括传统</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的这个特性特别契合安全运营，因为安全运营的过程主要就是调用各种工具进行协作的过程。</span></span><span lang="EN-US"><o:p></o:p></span></span></p></li><li><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">让</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">知识价值快速释放</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。以往安全运营专家的各种知识（譬如各种安全通用知识和安全报告，各类安全情报，基于资产和漏洞的安全姿态，告警研判、事件调查与响应的技战术方法，包括日志解析规则、关联分析规则、剧本在内的各种安全内容，以往的事件响应报告，甚至用户操作手册）需要事先经过特定的转换（甚至代码开发）才能加载到安全运营平台中，进而发挥作用。同时，这些知识的验证、更新过程也同样繁琐，甚至无法闭环。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">和智能体则能够以近乎自然语言的形式接收、验证和更新这些知识，并将它们充分的连接起来，催动安全运营平台的运转，让知识价值快速释放。而随着</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">和智能体在安全运营中的应用门槛不断降低，安全运营领域的专业知识将显得尤为重要。</span></span><span lang="EN-US"><o:p></o:p></span></span></p></li></ul><p style="line-height: 1.75em;margin-top: 16px;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">基于上述特征，以</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">LLM</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">为核心的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的兴起为</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的变革带来重大机遇，新一代</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">平台呼之欲出。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">必须指出，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">不是对传统</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的替代，尽管</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">具有很多优秀特性，但在针对很多专门的运营问题时，传统</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">依然有效，而且表现得更加高效。当前</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">自身存在的诸多不确定也限制了其发挥，需要利用传统</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">予以约束。在工程实践中，不应追求单一类型的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">包打天下，而是要从从性价比的角度，按需使用最合适的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">。这种将多种不同</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">技术整合到一起的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">技术称作复合式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Composite AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）。根据</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Gartner</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的定义，</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">复合式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">是指组合利用不同</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">技术（包括</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">、数据科学、机器学习、知识图谱等技术）来提高学习效率，以生成层次更丰富的知识表示的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">此外，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">DeepSeek</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">横空出世，使得本地化部署</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">LLM</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的性价比大幅提升，进一步加速了</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">LLM</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">在企业侧的落地过程，进而带动了</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">赋能的新一代</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">平台的落地进程。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><h2 style="line-height: 1.75em;margin-bottom: 32px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">4.2</span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">  </span></span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">赋能的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">SOC4.0</span></span><o:p></o:p></span></h2><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">在以</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">LLM</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">为核心的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的加持下，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">赋能的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">诞生，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">平台进入第四代。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">也可以称作自主化安全运营平台（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic SecOps Platform</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><img data-imgfileid="100001271" class="rich_pages wxw-img" data-ratio="0.4987951807228916" data-type="png" data-w="830" height="276" width="553" src="https://wechat2rss.xlab.app/img-proxy/?k=b9d17632&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdqkddfeicVw6Db40okK97ic5xCmFfGTIRYH5m0Y1h42SJNUUqiclBNhBJyVwjCxDySJZx05sMe2pQ4g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span><span lang="EN-US" style="font-size: 12pt;"><o:p></o:p></span></p><p style="line-height: 1.75em;"><b><span lang="EN-US" style="font-size: 12pt;color: red;"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span></b><b><span style="font-size: 12pt;color: red;"><span leaf=""><span textstyle="" style="font-size: 17px;">定义：</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">是一个</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">赋能的、数据与流程双轮驱动的、自动化优先的实战化安全运营平台</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">。这里，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">是安全运营能效的加速器，数据与流程是驱动安全运营平台的原动力，自动化和实战化是安全运营平台的核心设计理念。同时，无论如何演变，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">始终遵循风险管理思想，以实现网络弹性、保障业务平稳运行为目标。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><img data-imgfileid="100001270" class="rich_pages wxw-img" data-ratio="0.6883273164861613" data-type="png" data-w="831" height="381" width="554" src="https://wechat2rss.xlab.app/img-proxy/?k=23001031&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdqkddfeicVw6Db40okK97ic5hoiaGsehMcBlBA5GqcrYHDMCmHIkkzdOO3E0d04PJJ2xmNcRN8kzsOw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></span><span lang="EN-US" style="font-size: 12pt;"><o:p></o:p></span></p><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">赋能的，但又不仅仅是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">赋能的。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">首先，</span></span><b><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">赋能是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的核心特征，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">则是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的标志</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">将渗透到</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的方方面面和运营过程的各个环节，包括让数据驱动和流程驱动更加高效，让自动化更加智能，让平台更加实战化，全方位提升运营效能。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">其次，</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">数据与流程双轮驱动不仅是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的基本特征，更是所有</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的基本特征，刻画了安全运营的技术本质</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。数据是安全运营的源泉和动力，在数据的驱动下，源源不断地发现问题、分析问题、解决问题、总结问题。流程是安全运营的依据和手段，是安全运营持续运转的纽带，通过平台连接人、运营工具、网络安全防御设施，实现协同防御、联防联控。同时，数据驱动与流程驱动二者在安全运营中各有侧重，且紧密相连，相互转化。以往，我们片面强调数据驱动安全运营，忽略了流程驱动运营的重要性，使得安全运营平台更像一个安全分析平台，而缺乏实战化的日常安全运营支撑能力。因此，在</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">时代，必须将数据驱动和流程驱动放到同等的地位，统一进行设计。一方面，要用基于安全数据编织的新一代安全数据架构来实现数据驱动，另一方面，要用基于安全编排的新一代安全运营流程架构来实现流程驱动。同时，</span></span><b><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">（尤指</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）也是数据与流程驱动的</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。要想真正实现</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">赋能，就必须先建立好数据与流程驱动的安全运营平台技术底座。</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">如果说</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">的倍增器，相当于</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">的“</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">”（十倍）、“</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">00</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">”（百倍）、“</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">000</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">”（千倍），那么数据和流程驱动就是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">的那个“</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">1</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">”。没有好的数据和流程驱动的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">是无法被</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">赋能的</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">第三，</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">自动化优先作为</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的关键特征和设计理念之一，体现了对安全运营过程中人与机器之间协作关系的重新适配</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。在</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">时代，安全运营的组织、流程将进行全面改造，建立其以自动化为优先的组织结构和运营流程，依托自动化安全运营平台，重新调配人员配置、岗位职责、工作流程和规程，让人的价值在合适的地方得到真正发挥。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">第四，</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">实战化作为</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的另一个关键特征和设计理念</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">，</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">体现了以人为本、面向协作、价值交付的平台使用模式</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。在</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">时代，要为安全运营组织的每个角色提供相适应的无摩擦用户体验，提升团队内部和跨团队之间的协作性，提升安全运营平台自身的数字化水平，并建立</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">有效性验证和价值评估体系。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><h1 style="line-height: 1.75em;margin-top: 32px;margin-bottom: 32px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">5</span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">    </span></span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">的五大关键技术特征</span></span><span lang="EN-US"><o:p></o:p></span></h1><h2 style="line-height: 1.75em;margin-bottom: 32px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">5.1</span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">  </span></span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;"> </span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">赋能：以</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">为基础，用复合式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">赋能</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">SOC4.0</span></span><o:p></o:p></span></h2><p style="line-height: 1.75em;"><b><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span></b><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的核心特征</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">。尽管</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">早就应用了</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">，但直到以</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">LLM</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">为代表的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的出现，以及</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">演进而来的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">在</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">领域的应用，才使得</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">真正进入了全面</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">时代。如前所述，这是由</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">超越以往</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">所具备的普适性、普惠性、自主性、协作性，以及知识快速激活等特性所决定的。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">进一步地，</span></span><b><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">赋能</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的标志性特征</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">，基于</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">技术特别适用于安全运营的工作过程。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">将</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">LLM</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的思考力和智能体（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI Agent</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）的行动力结合起来，借助知识检索和工具调用，一方面可以主动获取安全分析所需的情境（上下文）数据，基于更多的相关性数据进行思考、理解和内容生成，做出更全面的研判和调查；另一方面可以编排各种安全控制指令，调整安全防御体系的工作姿态，做出更恰当的响应。而借助多智能体（也叫集群智能体）技术，能够将整个思考和行动的过程分解到不同的智能体上，让每个细化的目标执行过程更加专业精准，最终更好的实现整体目标。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">Gartner</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">预测，到</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">2028</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">年，用于威胁检测和事件响应的多智能体占</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">部署的⽐例将从</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">5%</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">升⾄</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">70%</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">同时，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">不是对传统</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的替代，在针对很多专门的运营问题时，传统</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">依然有效，而且表现得更加高效。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">从实战出发，使用更广泛意义的复合式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">技术去赋能</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">，根据不同的应用场景，采用最合适的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">去解决问题。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">在</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">时代，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">将渗透到安全运营的方方面面和运营过程的各个环节，包括让数据驱动和流程驱动更加高效，让自动化更加智能，让平台更加实战化，全方位提升运营效能</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">必须谨记，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">自身还有很多问题亟待解决，譬如安全性、准确性、可解释性、可信度、数据安全与隐私问题，等等。在利用</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">赋能</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的时候，必须通过多种手段对</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">加以约束，尽可能降低风险。必要的时候，应采购额外的专业</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">安全防护系统。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">最后，</span></span><b><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">赋能不等于</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">万能</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。</span><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">正如</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">Gartner</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">所言，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">取代</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">中的人类职责是虚幻的</span><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><h2 style="line-height: 1.75em;margin-bottom: 32px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">5.2</span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">  </span></span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">数据驱动：用基于安全数据编织的数据架构驱动</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">SOC4.0</span></span><o:p></o:p></span></h2><p style="line-height: 1.75em;"><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">数据驱动是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的技术本质之一，体现了“数据驱动安全”的思想</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">。从技术层面看，安全运营的本质就是将海量的、分散的多元异构安全数据变成安全洞察、形成决策，并付诸行动的过程。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">从</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">开始，安全运营平台的数据技术架构已经完全基于大数据技术，但随着安全建设的不断深入，尤其是数据驱动的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的引入，现有的安全数据技术架构再次遇到瓶颈，</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">数据驱动正在变成垃圾驱动</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。典型的问题譬如：（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">1</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）大数据越来越分散，数据集中的代价越来越高，这不仅体现在边缘检测的兴起导致的数据引力问题，也体现在安全运营所需的大数据集合日益分散（譬如很多企业的日志数据中心、资产数据中心、暴露面数据中心、情报数据中心都是分散建设的），还有的单位存在多套不同的安全管理平台、安全运营平台、态势感知平台的问题。传统的大数据技术，以及所谓的“安全数据中台”设计思路遭遇挑战。（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">2</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）新的数据不断涌现，不同数据间的关系日趋复杂，现有数据架构存在缺陷，导致情境数据难以有效利用，阻碍了安全数据的价值释放。（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">3</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）日益复杂的安全数据自身安全与隐私问题对现有数据架构提出了各种挑战。（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">4</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）更重要的在于，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">赋能是建立在数据基础之上的，如果没有标准化、逻辑统一和高质量的安全数据，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">应用的结果也只能还是“垃圾进，垃圾出”，而现有的数据架构已经很难再有所作为。因此，必须用新的数据架构去驱动</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">！</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">幸运的是，在数据管理与分析领域，已经提出了新的可以应对上述挑战的新型数据架构设计理念和框架，即数据编织（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Data Fabric</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">数据编织</span><span textstyle="" style="font-size: 17px;">作为新型跨不同来源和位置的数据集成与管理的设计范式，旨在建立一套按需编排的数据管道和可扩展的自动化数据服务框架，连接各种数据管理技术和流程，简化数据集成过程，实现无缝的数据治理、访问与分发</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">对于</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">而言，安全数据编织就是对安全运营中的所有安全要素信息采用数据编织的思想，以元数据为基础，统一数据模型和数据治理，编排数据管道，构建逻辑上统一的数据层，并持续监控数据质量。如果传统的安全运营平台数据架构是构建一个传统重量级数据中台的话，那么</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">基于安全数据编织的安全运营平台数据架构则旨在建立一个轻量级的数据中台</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">与此同时，在数据管理与分析领域，数据架构的工程化实践越来越成熟，现代数据栈（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">MDS</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）的兴起，为安全运营平台的数据架构设计提供了一套可供参考的最佳实践。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span></b><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">必须基于安全数据编织的思想，采用现代数据栈的最佳实践，摒弃旧的大数据架构，构建新一代安全数据架构</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">。新一代安全数据架构应包括数据治理、数据编排、数据集成、数据存算、数据分析、数据呈现、数据分发</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">7</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">个构件。基于新一代安全数据架构，实现按需集成数据，简化数据管理，释放数据价值，</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">为安全运营平台的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">化和自动化提供坚实的数据底座</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">，以实现高效的数据驱动的安全运营。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><h2 style="line-height: 1.75em;margin-bottom: 32px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">5.3</span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">  </span></span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">流程驱动：用基于安全编排的流程架构驱动</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">SOC4.0</span></span><o:p></o:p></span></h2><p style="line-height: 1.75em;"><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">流程驱动是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的技术本质之一，真正闭环的安全运营过程是数据驱动和流程驱动叠加的结果</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">。譬如，通过数据驱动的分析识别的安全事件需要触发响应流程，进而通过响应流程实现事件的处置闭环。又譬如，数据驱动的资产和漏洞分析必定要触发资产和漏洞处置流程。还有时候，也存在流程驱动触发数据驱动的过程，譬如通过预警通报接收流程接收到来自外部的预警通报信息后，导入平台进行数据驱动的分析的过程。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">长期以来，人们都忽略了流程驱动的重要性，将流程独立于平台之外</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">，仅存在于安全运营人员的心中，或者仅仅进行简单的设计，导致大部分安全运营平台更倾向于一个分析平台，而不是响应处置平台，安全运营的大量流程没有着落。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">一个完整的安全运营平台必须是数据与流程双轮驱动的</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">。数据是安全运营的源泉和动力，在数据的驱动下，源源不断地发现问题、分析问题、解决问题、总结问题。流程是安全运营的依据和手段，是安全运营持续运转的纽带，通过平台连接人、运营工具、网络安全防御设施，实现协同防御、联防联控。数据和流程分别驱着动安全运营的两种状态：数据驱动的分析态和流程驱动的运行态。只有数据驱动没有流程驱动的安全运营平台只能叫做安全分析平台，而只有流程驱动没有数据驱动的安全运营平台只能叫做安全运营工作办理平台（安全</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">OA</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">强调要将数据驱动和流程驱动放到同等的地位，统一进行设计。从流程驱动的角度而言，</span></span><b><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">必须以工作流引擎为底座，构建基于安全编排的新一代运营流程架构</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">安全编排（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Security Orchestration</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）概念并不新鲜，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">中就存在，它是安全编排响应与自动化（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOAR</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）系统的一项关键技术。安全编排是将企业和组织在安全运营过程中涉及的不同系统或者一个系统内部不同组件的安全功能封装后形成的安全能力和人工检查点按照一定的逻辑关系组合到一起，以完成某个特定的安全运营过程和规程。安全编排是将安全运营相关的工具</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">/</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">技术、流程和人员等各种能力整合到一起的一种协同工作方式。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">在实现安全编排方面，传统的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOAR</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">存在明显的缺陷。一方面，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOAR</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">对于机器到机器的协作流程编排有效，但对人到人的协作流程编排却难以支撑。另一方面，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOAR</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的安全编排都是静态的、固定式编排，一旦流程发生变化，就必须由安全运营人员手工更新，维护成本很高。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">因此，</span></span><b><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的新一代流程架构必须采用</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">赋能的智能化双流程编排引擎架构模式</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。其中一个引擎面向机器到机器的协作流程编排，表现形式为</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">剧本</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。该引擎以剧本高速运行为设计目标，满足需要机器速度进行响应处置的应用场景需求。另一个引擎面向人到人的协作流程编排，表现形式为</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">服务流程</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。该引擎支持复杂的流程流转，满足各类安全运营类办公场景的需求。同时，剧本和服务流程可以互相引用，实现跨人机处理的复杂应用场景。进一步地，在双引擎基础之上，引入</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">技术，用基于</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的智能体进一步提升流程运行的智能化水平，将静态、固定式的流程变成动态、自适应的流程，将与机器（各种设备和系统）的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">API</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">接口</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">MCP</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">化，实现智能自适应协作。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">必须谨记的是，机械式安全编排和智能化安全编排各有优劣势，不应片面追求智能化流程，应该分场合使用，发挥出各自的优势。譬如，剧本具有很强的一致性，且执行速度快，可用于确定的流程场景。而智能体适合没有流程或者现有流程有缺陷的场景，可以智能地进行规划，耗费相对较长的反复思考时间，自适应地完成预定任务。当某个智能体顺利完成任务后，经用户确认，应将工作流程进行恰当的固化，变成某种“剧本”，以便后续可以更加一致高速地运行。此外，当前的工程实践中，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">也不是纯靠</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">思考的，也需要某种“静态工作流”的辅助。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><h2 style="line-height: 1.75em;margin-bottom: 32px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">5.4</span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">  </span></span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">自动化优先的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">SOC4.0</span></span><o:p></o:p></span></h2><p style="line-height: 1.75em;"><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">自动化优先是</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的关键特征之一</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">Gartner</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">预测，到</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">2027</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">年，由于自动化程度的提高和超大规模扩展策略，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">25%</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">的常见</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">任务的成本效率将提高</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">50%</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">如果把自动化看作一项技术，那么自动化优先就</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">代表一种</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的设计理念</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">从技术角度看，</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">自动化必须深度嵌入安全运营平台的数据架构和流程架构之中</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">。数据编织架构是原生自动化的，从数据自动化采集，到基于规则或者基于模型的自动化数据分析，再到各类安全报表报告的自动定期生成和分发。面向流程的编排引擎也是原生自动化的，不论是剧本编排还是服务流程的编排，流程节点都是基于规则自动跳转。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">从设计理念角度看，</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">自动化优先体现了对安全运营过程中人与机器之间协作关系的重新适配</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">，从而使得</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">与其它</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">显著不同。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">在</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">之前，安全运营组织和流程基本都是建立人工处理的基础之上的。譬如很多企业和组织建立了监测、研判、处置团队，或者</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">L1</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">L2</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">L3</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">三线团队，通过有组织的分工协作，实现对安全告警和事件的闭环响应。这些组织基本上采用金字塔机构，负责监测或者</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">L1</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">团队人员最多，往上逐渐减少，表明监测告警的工作量最大。随着安全运营平台的不断升级迭代，自动化水平不断提升，各级团队越来越多依赖自动化来提升自身的工作效率，但整个团队设置和流程设计基本上没有变化。随着自动化运营的成熟和智能化运营的引入，现有的组织和流程阻碍了运营效能的提升。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">在</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">时代，安全运营的组织、流程将进行全面改造，建立起以自动化为优先的组织结构和运营流程</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">，依托自动化安全运营平台，重新调配人员配置、岗位职责、工作流程和规程，让人的价值在合适的地方得到真正发挥。譬如，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">L1</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">团队人员将大幅减少甚至取消，分流到其它团队，告警的分类分级和安全事件的生成工作已经尽可能地交给安全运营平台智能自动的执行。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">L2</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">团队的工作起点不是对事件进行规程化的调查，而是基于安全运营平台自动化事件调查的结果进行研判。处置团队则更多的是与相关安全事件的责任部门、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">IT</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">部门进行沟通协商，确定处置方案，真正的处置指令执行交由安全运营平台自动执行。然后，各个环节节约下来的编制投入到安全运营有效性验证、价值评估、常态化攻防对抗演练、渗透测试等其它更重要且缺乏人手的工作中去。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">自动化优先的流程设计要求尽可能地将机器与机器之间多步交互变成完全自动化的，同时尽可能地减少人与机器、人与人之间的交互步骤，充分发挥自动化的能力，简化流程。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">自动化优先的安全运营组织和流程设计的目标是完善组织结构、简化运营流程、提升运营效率，但并不意味着减少人员。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">体系之下，还有很多安全运营工作尚待开展，亟需大量人员投入，譬如安全内容开发运营、威胁猎捕、有效性验证、对抗演练，等等。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">对于安全运营平台而言，自动化优先意味着需要平台提供有力的支撑，重点是要提供一个可灵活定制的、基于编排的流程架构驱动的安全协作中心。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">最后，</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">自动化优先不等于自动化一切</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">，自动化只是手段不是目标，安全运营最终还是面向人的。</span><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">正如</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">Gartner</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">所言，</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">永远不会有完全自动化的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">SOC</span></span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;color: rgb(0, 82, 255);">，与追求端到端自动化相比，聚焦于关键任务和工作流程的自动化更加有效</span><span textstyle="" style="font-size: 17px;">。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><h2 style="line-height: 1.75em;margin-bottom: 32px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">5.5</span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">  </span></span></span><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">实战化的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">SOC4.0</span></span><o:p></o:p></span></h2><p style="line-height: 1.75em;"><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">实战化作为</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的另一个关键特征，体现了以人为本、面向协作、价值交付的平台使用模式</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">，本质上就是要让安全运营平台简单、好用。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">要从多个方面入手，不断提升平台的实战化水平，增强安全运营人员和各级管理者的获得感。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">要为安全运营组织的每个角色提供相适应的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">UI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">和简洁的用户体验，让他们无摩擦地使用平台。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">要加强流程架构驱动的安全协作中心的功能设计，让安全运营流程能够真正落到平台上，同时要支持多样化的协同工作模式，便于运营人员之间、跨安全和业务团队之间交流分享，便于各类安全工具、设备和系统之间协同工作。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">要加强平台自身数字化的功能设计，实现</span></span><b><span leaf=""><span textstyle="" style="font-size: 17px;">安全运营的数字化</span></span></b><span leaf=""><span textstyle="" style="font-size: 17px;">，对数据处理、流程运行和人员工作等过程进行全程记录，对安全运营平台中的数据、安全内容、流程进行有效性验证和价值评估，对安全运营人员实施绩效考核。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span></b><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">还需要考虑如何让平台的使用者便捷地、与时俱进地扩展</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">平台的业务能力。</span></span><span lang="EN-US"><o:p></o:p></span></span></b></p><h1 style="line-height: 1.75em;margin-top: 32px;margin-bottom: 32px;"><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">6</span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">    </span></span></span><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">总结</span></span><span lang="EN-US"><o:p></o:p></span></h1><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">回首过去，安全运营平台从面向资产的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC1.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">到面向业务的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC2.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">，再到数据驱动的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的叠加演进过程，也是中国网络安全产业从合规导向回归到对抗本质的叠加演进过程。数据驱动</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">已经成为共识，安全运营平台在技术上实现了巨大进步。大数据技术、威胁情报、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">、</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOAR</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">等技术的应用，让安全运营平台处理和分析数据的规模越来越大，安全运营过程也越来越主动、智能和自动。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">审视当下，安全运营平台依然面对诸多挑战，包括：实战化程度不够、大数据导致数据过载和工作疲劳、平台的智能化和自动化水平亟待提升、安全运营价值难以体现、定制扩展能力薄弱，等等。</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC3.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的数据架构、流程架构、智能化程度和自动化水平已经无法驱动安全运营进一步提升。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">近两年，生成式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">为</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的变革带来重大机遇。以</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">LLM</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">为核心的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">GenAI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">和</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">在传统</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的基础之上，凭借普适化、普惠化、协作化、自主化和知识价值快速释放等特性，使安全运营效能获得了极大提升，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">赋能的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">应运而生。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><b><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span></b><b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">是一个</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">赋能的、数据与流程双轮驱动的、自动化优先的实战化安全运营平台</span></span></span></b><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">。同时，无论如何演变，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">始终遵循风险管理思想，以实现网络弹性、保障业务平稳运行为目标。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span lang="EN-US" style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">采用以</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">为核心的复合式</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">赋能安全运营，采用基于安全数据编织的新一代数据架构和基于安全编排的新一代流程架构的双轮模式驱动安全运营，采用自动化优先和面向实战的设计理念。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">展望未来，随着</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的能力越来越强大，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">应用门槛将不断降低，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">应用方式将越来越便捷，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">的智能化水平将不断提升。安全运营将始终以人为本，以数据和流程为底座，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">永远不能取代人，而是增强人、赋能数据和流程。</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span style="font-size: 12pt;"><span leaf=""><span textstyle="" style="font-size: 17px;">未来已来！现在开始，迈入</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">赋能的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">SOC4.0</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">（</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 17px;">Agentic SecOps Platform</span></span></span><span leaf=""><span textstyle="" style="font-size: 17px;">）时代！</span></span><span lang="EN-US"><o:p></o:p></span></span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">【参考资料】</span></span></p><p style="line-height: 1.75em;text-align: left;"><span leaf="">网御神州率先开启SOC2.0时代，2009：</span><span leaf=""><a href="https://www.soft6.com/news/200908/12/14366.html" target="_blank">https://www.soft6.com/news/200908/12/14366.html</a></span></p><p style="text-align: left;"><span leaf="">网神SecFox-UMS跨入SOC2.0 全面保障业务系统安全，2009：</span><span leaf=""><a href="https://www.51cto.com/article/146261.html" target="_blank">https://www.51cto.com/article/146261.html</a></span></p><p style="text-align: left;"><span leaf="">下一代安全管理平台（SOC2.0）技术白皮书，2010：</span><span leaf=""><a href="https://blog.51cto.com/yepeng/571042" target="_blank">https://blog.51cto.com/yepeng/571042</a></span></p><p style="text-align: left;"><span leaf=""><img data-imgfileid="100001280" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="159" src="https://wechat2rss.xlab.app/img-proxy/?k=b1e53158&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdqkddfeicVw6Db40okK97ic5ic4S4oTHqUFZ7LkBEPF9zj9nSuRwZTicmlqicmyiaXcxkGTLEkF7PDZ9zA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: left;"><span leaf="">安全管理平台（SOC平台）的发展趋势分析，2010：</span><span leaf=""><a href="https://blog.51cto.com/yepeng/571157" target="_blank">https://blog.51cto.com/yepeng/571157</a></span></p><p style="text-align: left;"><span leaf="">以数据为核心的SOC3.0时代到来，2015：</span><span leaf=""><a href="https://blog.51cto.com/yepeng/1729338" target="_blank">https://blog.51cto.com/yepeng/1729338</a></span></p><p style="text-align: left;"><span leaf=""><img data-imgfileid="100001279" class="rich_pages wxw-img" data-ratio="1" data-type="png" data-w="148" src="https://wechat2rss.xlab.app/img-proxy/?k=4ab78d12&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdqkddfeicVw6Db40okK97ic5VGcYzYF7hOvGLLw7hXJCqvHn1sSLJp7PLzHrKEHlHas9aUibjXBtZnA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="text-align: left;"><span leaf=""><span textstyle="" style="font-size: 17px;">传统安全管理技术面临新挑战，启明星辰集团重磅推出新一代安管平台，2015：</span></span><span leaf=""><span textstyle="" style="font-size: 16px;"><a href="https://security.zhiding.cn/security_zone/2015/1229/3070512.shtml" target="_blank">https://security.zhiding.cn/security_zone/2015/1229/3070512.shtml</a></span></span></p><p style="text-align: left;"><span leaf="">开启SOC3.0时代，启明星辰集团发布新一代安全管理平台系列产品，2015：</span><span leaf=""><a href="https://www.51cto.com/article/502613.html" target="_blank">https://www.51cto.com/article/502613.html</a></span></p><p style="text-align: left;"><span leaf=""><a class="normal_text_link" target="_blank" style="" data-unique-id="maxrzdur-85ltg1" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484842&amp;idx=1&amp;sn=38dba05e2a0024b71d81d1d9b3e74a6c&amp;scene=21#wechat_redirect" textvalue="2024年安全运营技术趋势回顾" data-itemshowtype="0" linktype="text" data-linktype="2">2024年安全运营技术趋势回顾</a></span></p><p style="text-align: left;"><span leaf=""><a class="normal_text_link" target="_blank" style="" data-unique-id="maxrzjuu-2q0kr8" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484848&amp;idx=1&amp;sn=0f7f582e241603ec68bc85be3926998c&amp;scene=21#wechat_redirect" textvalue="是时候重新定义安全运营平台了" data-itemshowtype="0" linktype="text" data-linktype="2">是时候重新定义安全运营平台了</a></span></p><p style="text-align: left;"><span leaf=""><a class="normal_text_link" target="_blank" style="" data-unique-id="maxrzq71-864mel" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484854&amp;idx=1&amp;sn=81ac539adfe55fca334828b7e82002e5&amp;scene=21#wechat_redirect" textvalue="仅靠AI不足以重新定义安全运营平台" data-itemshowtype="0" linktype="text" data-linktype="2">仅靠AI不足以重新定义安全运营平台</a></span></p><p style="text-align: left;"><span leaf=""><a class="normal_text_link" target="_blank" style="" data-unique-id="maxrzv0r-ayo7pw" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484862&amp;idx=1&amp;sn=e0006eb7f308c8cb628d462601b8dc0a&amp;scene=21#wechat_redirect" textvalue="以自动化优先和实战化为设计理念的新一代安全运营平台" data-itemshowtype="0" linktype="text" data-linktype="2">以自动化优先和实战化为设计理念的新一代安全运营平台</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>


<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=4599ea50&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdqkddfeicVw6Db40okK97ic5xCmFfGTIRYH5m0Y1h42SJNUUqiclBNhBJyVwjCxDySJZx05sMe2pQ4g%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=1d564c80&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdqkddfeicVw6Db40okK97ic5hoiaGsehMcBlBA5GqcrYHDMCmHIkkzdOO3E0d04PJJ2xmNcRN8kzsOw%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=3e653803&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdqkddfeicVw6Db40okK97ic5ic4S4oTHqUFZ7LkBEPF9zj9nSuRwZTicmlqicmyiaXcxkGTLEkF7PDZ9zA%2F640%3Fwx_fmt%3Dpng"/></p>
<p><img src="https://wechat2rss.xlab.app/img-proxy/?k=f38f1b79&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdqkddfeicVw6Db40okK97ic5VGcYzYF7hOvGLLw7hXJCqvHn1sSLJp7PLzHrKEHlHas9aUibjXBtZnA%2F640%3Fwx_fmt%3Dpng"/></p>



<p><a href="2247484935">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=402d28fb&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyNzMxOTAwMw%3D%3D%26mid%3D2247484935%26idx%3D1%26sn%3D31de4443db5310b2ac6cdd7b3df19e2e">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 22 May 2025 12:02:00 +0800</pubDate>
    </item>
    <item>
      <title>以自动化优先和实战化为设计理念的新一代安全运营平台</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484862&amp;idx=1&amp;sn=e0006eb7f308c8cb628d462601b8dc0a</link>
      <description>未来的安全运营平台是一个AI赋能的、数据与流程双轮驱动的、自动化优先的实战化安全运营平台</description>
      <content:encoded><![CDATA[<p>
原创 <span>Benny Ye</span> <span>2025-05-13 12:00</span> <span style="display: inline-block;">北京</span>
</p>

<p>未来的安全运营平台是一个AI赋能的、数据与流程双轮驱动的、自动化优先的实战化安全运营平台</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=c0c833e8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMe2Skn71s1NnSBvH760MUVZvRjRrj3Tm28putwREw1JEUkQGPSTiclBG4f24gsav07qhY5CicFw7mAw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><span leaf="">当前，<a style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484848&amp;idx=1&amp;sn=0f7f582e241603ec68bc85be3926998c&amp;scene=21#wechat_redirect" textvalue="以Agentic AI为核心的复合式AI成为了重塑安全运营平台的关键技术" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">以Agentic AI为核心的复合式AI成为了重塑安全运营平台的关键技术</a>，而AI赋能必须<a style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484854&amp;idx=1&amp;sn=81ac539adfe55fca334828b7e82002e5&amp;scene=21#wechat_redirect" textvalue="依托安全运营平台自身的原动力：数据驱动和流程驱动" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">依托安全运营平台自身的原动力：数据驱动和流程驱动</a>。只有基于新的数据架构和流程架构，才能实现全新的数据加流程双轮驱动的安全运营平台，AI才能有效赋能。</span></p><p><span leaf="">有了AI赋能的、数据与流程双轮驱动的安全运营平台技术架构后，还需要用新的设计理念去指引新一代安全运营平台的功能设计。</span></p><p><span leaf="">面向未来的安全运营，有两个关键的设计理念。</span></p><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">自动化优先</span></span></p><p><span leaf="">从设计理念角度看，<span textstyle="" style="font-weight: bold;">自动化优先体现了对安全运营过程中人与机器之间协作关系的重新适配</span>，也是对未来安全运营（不仅是安全运营平台）的基本要求。</span></p><p><span leaf="">当前的安全运营组织和流程基本都是建立人工处理的基础之上的。譬如，现在很多企业和组织建立了监测、研判、处置团队，或者L1、L2、L3三线团队，通过有组织的分工协作，实现对安全告警和事件的闭环响应。这些组织基本上采用金字塔机构，负责监测或者L1团队人员最多，往上逐渐减少，表明监测告警的工作量最大。随着安全运营平台的不断升级迭代，自动化水平不断提升，各级团队越来越多依赖自动化来提升自身的工作效率，但整个团队设置和流程设计基本上没有变化。随着自动化运营的成熟和智能化运营的引入，现有的组织和流程阻碍了运营效能的提升。</span></p><p><span leaf="">面向未来，<span textstyle="" style="font-weight: bold;">安全运营的组织、流程须进行全面改造，建立以自动化为优先的组织结构和运营流程，依托自动化安全运营平台，重新调配人员配置、岗位职责、工作流程和规程，让人的价值在合适的地方得到真正发挥</span>。譬如，L1团队人员将大幅减少甚至取消，分流到其它团队，告警的分类分级和安全事件的生成工作已经尽可能地交给安全运营平台智能自动的执行。L2团队的工作起点不是对事件进行规程化的调查，而是基于安全运营平台自动化事件调查的结果进行研判。处置团队则更多的是与相关安全事件的责任部门、IT部门进行沟通协商，确定处置方案，真正的处置指令执行交由安全运营平台自动执行。然后，各个环节节约下来的编制投入到安全运营有效性验证、价值评估、常态化攻防对抗演练、渗透测试等其它更重要且缺乏人手的工作中去。</span></p><p><span leaf="">必须指出的是，</span><span leaf=""><span textstyle="" style="font-weight: bold;">自动化优先的安全运营组织和流程设计的目标是完善组织结构、简化运营流程、提升运营效率，但并不意味着减少人员</span>。事实上，安全运营的工作类型有很多，还有很多工作岗位缺乏人手。自动化优先意味着安全运营团队可以重新优化岗位设置，让现有的人员编制发挥出最佳的效益。<span textstyle="" style="font-weight: bold;">现在很多人认为AI和自动化将削减现有的安全团队人员编制，这是对安全运营的误读</span>，需要澄清。</span></p><p><span leaf="">自动化优先作为一个设计理念，体现在新一代安全运营平台功能设计的方方面面，并且要以一个</span><span leaf="">可灵活定制的、基于编排的流程架构驱动的安全协作中心为依托。</span></p><p><span leaf="">最后，<span textstyle="" style="font-weight: bold;">自动化优先不等于自动化一切</span>，自动化只是手段不是目标，安全运营最终还是面向人的。与其指望实现端到端的全过程安全运营自动化（也不可能），不如聚焦于关键任务和工作流程的自动化来得更实在。对自动化优先这个设计理念的拿捏尺度决定了这个平台的最终效果，是对设计者的考验。</span></p><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">实战化</span></span></p><p><span leaf="">从设计理念角度看，实战化</span><span leaf="">体现了以人为本、面向协作、价值交付的平台使用模式，本质上就是要让安全运营平台简单、好用。笔者在《<a style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484634&amp;idx=1&amp;sn=4bf253ef025528fc75493ba8df4444fd&amp;scene=21#wechat_redirect" textvalue="从Gartner2022年魔力象限看SIEM未来发展" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">从Gartner2022年魔力象限看SIEM未来发展</a>》一文的最后就呼吁要重视分析师体验，要尽可能去互联互通，本质上就是要求加强实战化。</span></p><p><span leaf="">具体来说，实战化可以从以下四方面入手。</span></p><p><span leaf="">首先，要为安全运营组织的每个角色提供相适应的UI和简洁的用户体验，让他们无摩擦地使用平台。【现实是大部分平台在设计时都只考虑到有个超级管理员在使用它】</span></p><p><span leaf="">其次，要加强流程架构驱动的安全协作中心的功能设计，让安全运营流程能够真正落到平台上，同时要支持多样化的协同工作模式，便于运营人员之间、跨安全和业务团队之间交流分享，</span><span leaf="">便于各类安全工具、设备和系统之间协同工作。【现实是大部分平台的设计都跟运营流程解耦，“我设计我的，你用你的”，设计者和使用者脱节，设计者更多是取悦采购者而非真正的使用者】</span></p><p><span leaf="">第三，要加强平台自身数字化的功能设计，实现安全运营的数字化，对数据处理、流程运行和人员工作等过程进行全程记录，对安全运营平台中的数据、安全内容、流程进行有效性验证和价值评估，对安全运营人员实施绩效考核。【现实是大家都在喊要建立安全运营指标体系，但实际上都是流于表面，实际上也做不起来，因为根本就没有这方面的数据支撑】</span></p><p><span leaf="">最后，还需要考虑如何让平台的使用者便捷地、与时俱进地扩展SOC平台的业务能力。【现实是平台大都是“即用即抛”型的，说好的“无缝扩展”，在一两年后大都只能是“重新采购”，能利旧就很不错了】</span></p><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">小结</span></span></p><p><span leaf="">结合本文，以及《<a style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484848&amp;idx=1&amp;sn=0f7f582e241603ec68bc85be3926998c&amp;scene=21#wechat_redirect" textvalue="是时候重新定义安全运营平台了" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">是时候重新定义安全运营平台了</a>》和《<a style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484854&amp;idx=1&amp;sn=81ac539adfe55fca334828b7e82002e5&amp;scene=21#wechat_redirect" textvalue="仅靠AI不足以重新定义安全运营平台" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">仅靠AI不足以重新定义安全运营平台</a>》，笔者给出结论：<span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">未来的安全运营平台是</span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">一个AI赋能的、数据与流程双轮驱动的、自动化优先的实战化安全运营平台</span>。</span></p><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">是的，这就是笔者认定的未来SOC！请随我一起，迈向AI赋能的SOC新时代。</span></span></p><p><span leaf="">【参考资料】</span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;">重塑安全运营平台的进程始于2023年，是一个必然的演进过程。因此，要想完整理解这个进程，就应该从2023年的业界发展进程开始去探究。</span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484854&amp;idx=1&amp;sn=81ac539adfe55fca334828b7e82002e5&amp;scene=21#wechat_redirect" textvalue="仅靠AI不足以重新定义安全运营平台" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">仅靠AI不足以重新定义安全运营平台</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484848&amp;idx=1&amp;sn=0f7f582e241603ec68bc85be3926998c&amp;scene=21#wechat_redirect" textvalue="是时候重新定义安全运营平台了" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">是时候重新定义安全运营平台了</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484842&amp;idx=1&amp;sn=38dba05e2a0024b71d81d1d9b3e74a6c&amp;scene=21#wechat_redirect" textvalue="2024年安全运营技术趋势回顾" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">2024年安全运营技术趋势回顾</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484795&amp;idx=1&amp;sn=8f835c0699be66f615e7b713f67e26dc&amp;scene=21#wechat_redirect" textvalue="从Gartner2024年北美安全峰会看安全运营的技术趋势" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">从Gartner2024年北美安全峰会看安全运营的技术趋势</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484766&amp;idx=1&amp;sn=5b66715c108908d39eb92ecdc964c9f6&amp;scene=21#wechat_redirect" textvalue="从RSAC2024看SOC发展趋势" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">从RSAC2024看SOC发展趋势</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484657&amp;idx=1&amp;sn=97ef202f80d16243bc1212bedf759458&amp;scene=21#wechat_redirect" textvalue="从Garnter2023年北美安全与风险管理峰会看SIEM和SOC的发展趋势" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">从Garnter2023年北美安全与风险管理峰会看SIEM和SOC的发展趋势</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a style="-webkit-tap-highlight-color: rgba(0, 0, 0, 0);margin: 0px;padding: 0px;outline: 0px;color: rgb(87, 107, 149);text-decoration: none;-webkit-user-drag: none;cursor: default;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484640&amp;idx=1&amp;sn=6ff1f407b3ad35c01efbf35d5a0ded0d&amp;scene=21#wechat_redirect" textvalue="从RSAC2023看安全运营的技术发展趋势" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">从RSAC2023看安全运营的技术发展趋势</a></span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;white-space: normal;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><a style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484634&amp;idx=1&amp;sn=4bf253ef025528fc75493ba8df4444fd&amp;scene=21#wechat_redirect" textvalue="从Gartner2022年魔力象限看SIEM未来发展" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">从Gartner2022年魔力象限看SIEM未来发展</a></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484862">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=6f47725c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyNzMxOTAwMw%3D%3D%26mid%3D2247484862%26idx%3D1%26sn%3De0006eb7f308c8cb628d462601b8dc0a%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 13 May 2025 12:00:00 +0800</pubDate>
    </item>
    <item>
      <title>仅靠AI不足以重新定义安全运营平台</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484854&amp;idx=1&amp;sn=81ac539adfe55fca334828b7e82002e5</link>
      <description>超越AI，寻找驱动安全运营平台技术架构演进的原动力：数据和流程！</description>
      <content:encoded><![CDATA[<p>
原创 <span>Benny Ye</span> <span>2025-05-06 12:36</span> <span style="display: inline-block;">北京</span>
</p>

<p>超越AI，寻找驱动安全运营平台技术架构演进的原动力：数据和流程！</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=8f460d41&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMe2Skn71s1NnSBvH760MUVZUylic8hkWx9uPoibEufvtic4fyd4hyVlib6nU2xljsTON4ib4PhrWLLf2FA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">Agentic AI引发对SOC的重塑</span></span></section><section><span leaf="">从SOC诞生伊始，AI一直就扮演了重要作用。正如《<a style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484848&amp;idx=1&amp;sn=0f7f582e241603ec68bc85be3926998c&amp;scene=21#wechat_redirect" textvalue="是时候重新定义安全运营平台了" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">是时候重新定义安全运营平台了</a>》所详细分析的，当AI发展到了GenAI和Agentic AI阶段后，因其特有的</span><span style="color: rgb(0, 82, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 700;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;" data-pm-slice="0 0 []"><span leaf="">普适性、普惠性、自主性、协作性，以及让知识价值快速释放的特性</span></span><span leaf="">，给SOC带来了重大机遇。尤其是Agentic AI的工作过程完美契合了安全运营的流程型任务处理过程，并能够更加智能地对分散安全机制进行编排调度，使得其成为了重塑SOC，尤其是支撑SOC的安全运营平台的关键力量。从刚刚结束的RSAC2025大会上，也可见一斑。</span></section><section><span leaf=""><span textstyle="" style="color: rgb(255, 0, 0);">但仅靠AI就能重塑安全运营平台了吗？</span></span></section><section><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><span textstyle="" style="font-size: 24px;font-weight: bold;">当前的安全运营平台面临诸多挑战</span></span></section><section><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">让我们先看看当前安全运营平台面临的一些主要挑战：</span></section><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="margin-left: 22pt;" data-pm-slice="0 0 []"><span lang="EN-US" style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;"></span></span><b><span leaf="">缺乏实战</span></b><span leaf="">：名为安全运营，实际上更多是安全分析，偏重面向专家用户的功能设计，缺乏面向广大运营人员的功能设计，导致安全运营平台的易用性很差，实战化程度不够</span><span lang="EN-US"><o:p></o:p></span></p></li><li><p style="margin-left: 22pt;"><span lang="EN-US" style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;"><span leaf=""><span textstyle="" style="font-weight: bold;">数据过载</span></span></span></span><span leaf="">：大数据技术的加持，带来了数据沼泽，大量的告警和事件积压，真假难辨，误报频频，负责研判和响应处置的运营人员不堪重负，</span><span leaf="">极易产生工作疲劳</span><span leaf="">，运营效果大打折扣。</span><span lang="EN-US"><o:p></o:p></span></p></li><li><p style="margin-left: 22pt;"><span lang="EN-US" style="font-family:Wingdings;mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings;"><span style="mso-list:Ignore;"><span leaf=""><span textstyle="" style="font-weight: bold;">自动化水平偏低</span></span></span></span><span leaf="">：当前以</span><span lang="EN-US"><span leaf="">SOAR</span></span><span leaf="">为基础的响应自动化对于缓解运营疲劳作用有限，囿于用户运营流程不健全，剧本开发成本高、剧本适应性低，运营自动化难以普及</span><span lang="EN-US"><o:p></o:p></span></p></li><li><p style="margin-left: 22pt;"><b><span leaf="">智能化程度有限</span></b><span leaf="">：现有的智能化更多应用于分散的安全运营功能点，对于整体的安全运营过程还是以人的智力为主</span><span leaf="">，对人的要求依然很高，距离安全运营者的期望始终存在较大差距【参见注1】</span></p></li><li><p style="margin-left: 22pt;"><b><span leaf="">运营价值难以体现</span></b><span leaf="">：</span><span lang="EN-US"><span leaf="">SOC</span></span><span leaf="">建设的价值如何？平台虽有大量数据，但都是安全数据，缺少运营过程数据，安全运营自身的数字化水平不足</span><span lang="EN-US"><o:p></o:p></span></p></li><li><p style="margin-left: 22pt;"><b><span leaf="">定制化能力非常薄弱</span></b><span leaf="">：安全运营平台的可定制性和可扩展性不够，要么无法定制，要么定制周期过长、成本过高，导致安全运营的实际使用落后于不断增长的安全需求和持续变化的对抗形势。</span><span lang="EN-US"><o:p></o:p></span></p></li></ul><section><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]"><br/></span></section><section><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">AI有助于缓解上述部分挑战，但并不能从根本上扭转局面。很显然，AI是赋能者，是加速装置，是倍增器，但并非不可或缺，我们还需要找到安全运营平台的原动力（原力），并激活它。</span></section><section><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">寻找并重新激活安全运营平台的原动力</span></span></section><section><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">数据不能承受之重、数据架构需要重构</span></span></section><section><span leaf="">2012年，Gartner发布了一份名为《信息安全正在成为大数据分析问题》的报告，揭开了数据驱动安全时代的序幕。也就是从那时起，确认了<span textstyle="" style="font-weight: bold;">数据是驱动安全运营的一个原动力</span>。</span><span leaf="">从技术层面看，安全运营的本质就是将海量的、分散的多元异构安全数据变成安全洞察、形成决策，并付诸行动的过程。</span></section><section><span leaf="">当前，安全运营平台的数据技术架构已经完全基于大数据技术。但随着安全建设的不断深入，尤其是数据驱动的GenAI的引入，现有的安全数据技术架构再次遇到瓶颈，<span textstyle="" style="font-weight: bold;">数据驱动正在变成垃圾驱动</span>，数据驱动安全面临挑战，譬如：边缘检测的兴起引发的数据引力（Data Gravity）问题，以及由此导致的数据移动与集中的代价越来越大；一个单位内不同作用的安全运营/态势感知平台越来越多导致的数据分散问题；新的数据不断涌现，数据关系越发复杂，囿于现有的数据驱动架构，情境数据难以利用，数据价值难以释放。更重要的是，GenAI本身就是建立在数据之上的，没有好的数据，GenAI也难以奏效。</span></section><section><span leaf="">应该说，<span textstyle="" style="font-weight: bold;">数据驱动这个古老的原力依然有效，但现在的数据驱动遇到了困境，需要革新后重装上阵。只有采用全新的数据架构，才能重新激活数据这个原力</span>，让安全运营平台重新焕发活力。</span></section><section><span leaf="">那么，这个全新的数据架构是什么？在《<a style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484842&amp;idx=1&amp;sn=38dba05e2a0024b71d81d1d9b3e74a6c&amp;scene=21#wechat_redirect" textvalue="2024年安全运营技术趋势回顾" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">2024年安全运营技术趋势回顾</a>》一文中，笔者提及了数据管道（Data Pipeline），并详细阐释了数据管道对于重塑和盘活整个安全运营平台的作用和价值。这里，笔者需要进一步指出，仅仅依靠数据管道还不够，新的数据架构还需要全新的数据治理能力。</span></section><section><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">从安全运营三要素中寻找另一个原力</span></span></section><section><span leaf="">除了数据驱动，安全运营平台还有其它原力吗？显然，数据不是唯一的原力。</span></section><section><span leaf="">让我们把目光转向安全运营/SOC的三要素（技术、流程、人员/组织），并再次思考“运营”（Operations）这个词。什么是运营？如果说运营是数据驱动的过程，那么这个过程就是一个流程牵引的过程！一项项安全运营的工作和任务最终必定转化为一个个安全运营的流程、规程和标准操作步骤。因此，流程驱动是数据驱动之外的安全运营的另一个技术本质，<span textstyle="" style="font-weight: bold;">流程就是那个被人忽略的驱动安全运营的古老原力</span>！</span></section><section><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">长久以来，流程就游离于技术平台之外。传统上，安全运营平台就是安全运营技术的集成平台和人员的操作平台，但流程更多是凝聚于人脑之中，人手之上，所谓“操之在你”。平台如何使用，用的好坏，取决于“你”，导致平台的实战性不够，易用性不够，阻碍了平台的发展。</span></section><section><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;section&#34;,&#34;attributes&#34;:{},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">必须看到，</span><span leaf=""><span textstyle="" style="font-weight: bold;">真正闭环的安全运营过程是数据驱动和流程驱动叠加的结果。安全运营平台除了需要数据驱动，还需要流程驱动</span>。<span textstyle="" style="font-weight: bold;">必须将战术性流程落实到安全运营平台之中</span>，辅助运营人员以流程为牵引，串接起各种平台的能力和安全防御体系中分散的能力，完成既定的安全运营任务。唯有如此，才能进一步发挥Agentic AI的作用。</span></section><section><span leaf="">当前，很多安全运营平台引入了SOAR，初步实现了流程技术在平台中的落地。但这还不够，因为SOAR实现的流程自动化更适合于机机流程，而不适合于人人流程和人机流程。外挂的ITSM模式也不是长久的解决之道。我们需要全面梳理安全运营的组织和流程，然后建立一个全新的、基于编排的安全运营平台流程架构。</span></section><section><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">构建数据与流程双轮驱动的安全运营平台</span></span></section><section><span leaf="">如前所述，数据驱动和流程驱动是安全运营平台的两个原力，即两个技术本质。同时，一个闭环的安全运营平台一定是二者互相依赖，互为驱动的。如下图所示，展示了两大原力之间的转化关系。</span></section><section style="text-align: center;"><span leaf=""><img data-imgfileid="100001203" class="rich_pages wxw-img" data-ratio="0.513681592039801" data-type="png" data-w="804" style="width:450px;height:231px;" src="https://wechat2rss.xlab.app/img-proxy/?k=9726fa8f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMe2Skn71s1NnSBvH760MUVZo88xnVK8hIea4wywhDn6DJC2ZJcjSWwkperDxzyRtFk1tpeOyRnS0Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></section><p><span leaf="">其中，数据是安全运营的力量源泉，在数据的驱动下，源源不断地发现问题、分析问题、解决问题、总结问题。流程是安全运营持续运转的纽带，连接人、运营工具与平台、网络安全防御设施，实现协同防御、联防联控。</span></p><p><span leaf="">现有的数据架构和流程架构不足以继续推动安全运营平台前进，未来的SOC需要新的平台，新的平台需要新一代的数据架构和流程架构。</span></p><section><span leaf="">同时，在AI的赋能和加持之下，新的数据架构和流程架构的价值将进一步释放。</span></section><section><span leaf=""><span textstyle="" style="font-size: 24px;font-weight: bold;">重新设定功能架构设计理念</span></span></section><section><span leaf="">现在，我们找到了安全运营的两大原力，也知道需要用全新的架构让原力重新觉醒，并且AI作为助推器，去赋能原力，让原力加倍释放。</span></section><section><span leaf="">至此，我们有了新的技术架构。</span></section><section><span leaf="">同时，在构建全新安全运营平台时，必定涉及到大量的功能设计，除了要继续让AI赋能，还应该遵循什么样的核心功能设计理念呢？</span></section><section><span leaf="">是的，<span textstyle="" style="font-weight: bold;">我们还需要重新确定安全运营平台的核心设计理念</span>。</span></section><section><span leaf=""><span textstyle="" style="font-size: 20px;color: rgb(0, 82, 255);">保持关注，请继续随</span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;" data-pm-slice="0 0 []"><span textstyle="" style="font-size: 20px;color: rgb(0, 82, 255);">我一起，驶入</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 82, 255);">AI</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="font-size: 20px;color: rgb(0, 82, 255);">赋能的</span></span><span style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span textstyle="" style="font-size: 20px;color: rgb(0, 82, 255);">SOC</span></span></span><span leaf="" style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span textstyle="" style="font-size: 20px;color: rgb(0, 82, 255);">新时代，重新定义安全运营平台！</span></span></section><section><span leaf=""><span textstyle="" style="font-weight: bold;">【注1】</span></span></section><section><span leaf="">智能SOC（或者说智能安全运营平台）很早就被提出来了。</span><span leaf="">早在2015年，Gartner就发表过智能SOC（ISOC）的报告，指出要利用高级安全分析来落地智能化SOC。国内的绿盟科技在2020年也提出了<a style="" href="https://mp.weixin.qq.com/s?__biz=MjM5ODYyMTM4MA==&amp;mid=2650408976&amp;idx=2&amp;sn=03444cecb923ee1084df8bbf3b93098d&amp;scene=21#wechat_redirect" textvalue="AISecOps的概念" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">AISecOps的概念</a>，并发布了一套</span><span leaf="">智能安全运营技术体系。后面几年，也陆续有厂商发布了AISecOps理念的产品。但是，所有这些概念和产品离真正的安全智能还有差距。直到2023年初GenAI在安全运营领域的引入，以及Agentic AI时代的到来，安全运营才真正迎来了AI应用的拐点。因此可以说，<span textstyle="" style="font-weight: bold;">新一代安全运营平台（或AI SOC）的判定标志之一就是是否采用了Agentic AI技术</span>。</span><span leaf=""><br/></span></section><section><span leaf=""><span textstyle="" style="font-weight: bold;">【参考资料】</span></span></section><section><span leaf="">重塑安全运营平台的进程始于2023年，是一个必然的演进过程。因此，要想完整理解这个进程，就应该从2023年的业界发展进程开始去探究。</span></section><section><span leaf=""><a style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484848&amp;idx=1&amp;sn=0f7f582e241603ec68bc85be3926998c&amp;scene=21#wechat_redirect" textvalue="是时候重新定义安全运营平台了" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">是时候重新定义安全运营平台了</a></span></section><section><span leaf=""><a style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484842&amp;idx=1&amp;sn=38dba05e2a0024b71d81d1d9b3e74a6c&amp;scene=21#wechat_redirect" textvalue="2024年安全运营技术趋势回顾" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">2024年安全运营技术趋势回顾</a></span></section><section><span leaf=""><a style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484795&amp;idx=1&amp;sn=8f835c0699be66f615e7b713f67e26dc&amp;scene=21#wechat_redirect" textvalue="从Gartner2024年北美安全峰会看安全运营的技术趋势" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">从Gartner2024年北美安全峰会看安全运营的技术趋势</a></span></section><section><span leaf=""><a style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484766&amp;idx=1&amp;sn=5b66715c108908d39eb92ecdc964c9f6&amp;scene=21#wechat_redirect" textvalue="从RSAC2024看SOC发展趋势" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">从RSAC2024看SOC发展趋势</a></span></section><section><span leaf=""><a style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484657&amp;idx=1&amp;sn=97ef202f80d16243bc1212bedf759458&amp;scene=21#wechat_redirect" textvalue="从Garnter2023年北美安全与风险管理峰会看SIEM和SOC的发展趋势" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">从Garnter2023年北美安全与风险管理峰会看SIEM和SOC的发展趋势</a></span></section><section><span leaf=""><a style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484640&amp;idx=1&amp;sn=6ff1f407b3ad35c01efbf35d5a0ded0d&amp;scene=21#wechat_redirect" textvalue="从RSAC2023看安全运营的技术发展趋势" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">从RSAC2023看安全运营的技术发展趋势</a></span></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484854">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=eee57f47&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyNzMxOTAwMw%3D%3D%26mid%3D2247484854%26idx%3D1%26sn%3D81ac539adfe55fca334828b7e82002e5%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 06 May 2025 12:36:00 +0800</pubDate>
    </item>
    <item>
      <title>是时候重新定义安全运营平台了</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484848&amp;idx=1&amp;sn=0f7f582e241603ec68bc85be3926998c</link>
      <description>为何GenAI和Agentic AI能够重塑SOC？</description>
      <content:encoded><![CDATA[<p>
原创 <span>Benny Ye</span> <span>2025-04-29 12:01</span> <span style="display: inline-block;">日本</span>
</p>

<p>为何GenAI和Agentic AI能够重塑SOC？</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=076d2c4a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMfgAGGDwdwMR9BYFvdjGGscQtxcTmS4QSEtaGjYj8jF9k4r61Tibo20ibQVsQEtL24XX9YtUu3Ghpdw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="line-height: 1.75em;" data-pm-slice="0 0 []"><span leaf="">正如我去年底发布的《</span><span lang="EN-US"><span leaf=""><a style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484842&amp;idx=1&amp;sn=38dba05e2a0024b71d81d1d9b3e74a6c&amp;scene=21#wechat_redirect" textvalue="2024年安全运营技术趋势回顾" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">2024</a></span></span><span leaf=""><a style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484842&amp;idx=1&amp;sn=38dba05e2a0024b71d81d1d9b3e74a6c&amp;scene=21#wechat_redirect" textvalue="2024年安全运营技术趋势回顾" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">年安全运营技术趋势回顾</a>》所言，作为一种公认的颠覆性技术，以大语言模型（</span><span lang="EN-US"><span leaf="">LLM</span></span><span leaf="">）为代表的生成式</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">（</span><span lang="EN-US"><span leaf="">GenAI</span></span><span leaf="">）近两年迅速席卷各行各业，并在安全运营领域取得了令人惊叹的效果。</span></p><p style="line-height: 1.75em;" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">为何GenAI能重塑SOC？</span></span></p><p style="line-height: 1.75em;"><span leaf="">AI很早就应用于SOC。因为传统的AI普适性不够，针对不同的问题需要采用不同的算法和模型，而且技术要求较高，对安全运营整体作用有限。</span></p><p style="line-height: 1.75em;"><span leaf="">GenAI和</span><span lang="EN-US"><span leaf="">Agentic AI在SOC领域</span></span><span leaf="">的应用，恰好覆盖了当前安全运营的三个痛点：</span><span leaf="">人才短缺、工作倦怠、技能不足，使安全运营的效能获得了极大的提升。GenAI和Agentic AI正在重塑SOC，这是由它们</span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">应用于安全运营后所表现出来的高度普适性、普惠性、自主性、协作性，以及让知识价值快速释放的特性</span>所决定的。</span></p><ul style="list-style-type: circle;" class="list-paddingleft-1"><li><p style="line-height: 1.75em;" data-pm-slice="0 0 []"><span lang="EN-US"><span leaf="">GenAI</span></span><span leaf="">具有很高的<span textstyle="" style="font-weight: bold;">普适性</span>：</span><span lang="EN-US"><span leaf="">GenAI</span></span><span leaf="">向通用</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">迈出了一步，一个模型能够解决多个问题。安全运营的每个领域、运营过程的每个环节都可以利用</span><span lang="EN-US"><span leaf="">GenAI</span></span><span leaf="">，简化工作过程、提升工作效率。</span><span lang="EN-US"><o:p></o:p></span></p></li><li><p style="line-height: 1.75em;"><span lang="EN-US"><span leaf="">GenAI</span></span><span leaf="">具有很强的<span textstyle="" style="font-weight: bold;">普惠性</span>：</span><span lang="EN-US"><span leaf="">GenAI</span></span><span leaf="">通过自然语言交互的体验方式，降低了对应用型技能的要求，让广大运营人员可以更快上手安全运营平台，更便捷地进行操作。</span><span lang="EN-US"><o:p></o:p></span></p></li><li><p style="line-height: 1.75em;"><span leaf="">基于</span><span lang="EN-US"><span leaf="">GenAI</span></span><span leaf="">的</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">具有很强的<span textstyle="" style="font-weight: bold;">自主性</span>。很多流程性的安全运营任务都可以借助基于</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">的智能体实现，提升安全运营的自主性和智能自动化水平，减轻工作压力。</span></p></li><li><p style="line-height: 1.75em;"><span leaf="">基于</span><span lang="EN-US"><span leaf="">GenAI</span></span><span leaf="">的</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">具有很强的<span textstyle="" style="font-weight: bold;">协作性</span>：</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">将</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">从工具变成了“伙伴”，成为了工具的使用者，能够主动地使用各种工具，包括传统</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">。</span><span lang="EN-US"><o:p></o:p></span></p></li><li><p style="line-height: 1.75em;"><span lang="EN-US"><span leaf="">GenAI</span></span><span leaf=""><span textstyle="" style="font-weight: bold;">让知识价值快速释放</span>。</span><span lang="EN-US"><span leaf="">GenAI</span></span><span leaf="">和</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">能够以近乎自然语言的形式接收、验证和更新各种安全知识，并将它们充分地连接起来，让知识价值快速释放。</span><span lang="EN-US"><o:p></o:p></span></p></li></ul><p style="line-height: 1.75em;"><span leaf=""><br/></span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">GenAI在SOC中的应用发展历程</span></span></p><p style="" data-pm-slice="0 0 []"><span lang="EN-US"><span leaf="">不到两年，GenAI在SOC</span></span><span leaf="">中的应用模式迅速从早期的智能聊天，发展到后来的</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">助理</span><span lang="EN-US"><span leaf="">/</span></span><span leaf="">副驾，再到现在基于</span><span lang="EN-US"><span leaf="">GenAI</span></span><span leaf="">的智能体。目前，SOC的</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">应用进入了</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">（暂译为“代理式</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">”）时代。</span></p><p style="" data-pm-slice="0 0 []"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">基于Agentic AI的SOC大行其道</span></span></p><p style=""><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">采用以</span><span lang="EN-US"><span leaf="">LLM</span></span><span leaf="">为思考中枢，采用自主或部分自主的方式进行决策并采取行动，以完成既定目标，具有自主性、适应性和持续学习的特点。</span></p><section><span lang="EN-US"><span leaf="" data-pm-slice="1 1 [&#34;para&#34;,{&#34;tagName&#34;:&#34;p&#34;,&#34;attributes&#34;:{&#34;class&#34;:&#34;MsoNormal&#34;,&#34;style&#34;:&#34;&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;},&#34;node&#34;,{&#34;tagName&#34;:&#34;span&#34;,&#34;attributes&#34;:{&#34;lang&#34;:&#34;EN-US&#34;},&#34;namespaceURI&#34;:&#34;http://www.w3.org/1999/xhtml&#34;}]">Agentic AI特别适用于安全运营的工作过程。</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">将</span><span lang="EN-US"><span leaf="">LLM</span></span><span leaf="">的思考力和</span><span lang="EN-US"><span leaf="">Agent</span></span><span leaf="">的行动力结合起来，借助知识检索和工具调用，一方面可以主动获取安全分析所需的情境（上下文）数据，基于更多的相关性数据进行思考、理解和内容生成，做出更全面的研判和调查；另一方面可以编排各种安全控制指令，调整安全防御体系的工作姿态，做出更恰当的响应。</span><span lang="EN-US"><o:p></o:p></span></span></section><p style="line-height: 1.75em;"><span leaf="">我们看到，在</span><span lang="EN-US"><span leaf="">2025</span></span><span leaf="">年</span><span lang="EN-US"><span leaf="">RSAC</span></span><span leaf="">上，</span><span lang="EN-US"><span leaf=""><a style="" href="https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&amp;mid=2247514252&amp;idx=1&amp;sn=793450937069e37a1cf229432949e6f4&amp;scene=21#wechat_redirect" textvalue="Agentic AI已经成为了行业新风向" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">Agentic AI</a></span></span><span leaf=""><a style="" href="https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&amp;mid=2247514252&amp;idx=1&amp;sn=793450937069e37a1cf229432949e6f4&amp;scene=21#wechat_redirect" textvalue="Agentic AI已经成为了行业新风向" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">已经成为了行业新风向</a>，尤其在基于</span><span lang="EN-US"><span leaf="">Agentic AI</span></span><span leaf="">的安全运营领域，大量公司驶入了这个赛道。</span><span lang="EN-US"><o:p></o:p></span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">简单来说，采用</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">技术的智能体相当于一个升级版的智能</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">SOAR</span></span></span><span leaf="">。这个智能体将</span><span lang="EN-US"><span leaf="">SOAR</span></span><span leaf="">中固定式、静态的剧本变成了一个动态的决策和行动流程，使得其更适用于当下复杂多变的流程型任务。</span><span lang="EN-US"><o:p></o:p></span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">从更深层次来看，</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">Agentic AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">技术下的智能体代表了未来流程型安全运营工作的重构</span>。安全运营过程的本质不就是一个个的流程吗？</span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">安全永远都没有银弹！</span></span></p><p style="line-height: 1.75em;"><span leaf="">就像大数据技术刚引入安全运营时一样，人们总是对新的颠覆型技术充满期待，市场里充斥着各种有关Gen</span><span lang="EN-US"><span leaf="">AI</span></span><span leaf="">的美好想象，不乏不切实际的臆想。同时，GenAI自身还有很多问题亟待解决，</span><span leaf="">譬如安全性、准确性、可解释性、可信度、数据安全与隐私问题，等等。</span></p><p style="line-height: 1.75em;"><span leaf="">单纯依靠GenAI和Agentic AI还不足以颠覆SOC，而传统AI依旧有用。只有真正看清</span><span lang="EN-US"><span leaf="">GenAI和Agentic AI</span></span><span leaf="">的优劣势，将它们和传统AI有机结合，找到有效的SOC应用场景，进行有效的约束，并</span><span leaf="">与其它力量结合到一起，才能站在SOC发展的正确道路上。</span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">如何正确打开AI赋能的SOC？</span></span><span lang="EN-US"><o:p></o:p></span></p><p style="line-height: 1.75em;"><span leaf="">简言之，</span><span lang="EN-US"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">AI</span></span></span><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);font-weight: bold;">是能效倍增器，我们还需要安全运营的原力加持</span>。</span><span lang="EN-US"><o:p></o:p></span></p><p style="line-height: 1.75em;"><span leaf=""><span textstyle="" style="font-size: 20px;">准备好，和我一起，驶入</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;">AI</span></span></span><span leaf=""><span textstyle="" style="font-size: 20px;">赋能的</span></span><span lang="EN-US"><span leaf=""><span textstyle="" style="font-size: 20px;">SOC</span></span></span><span leaf=""><span textstyle="" style="font-size: 20px;">新时代！</span><span textstyle="" style="font-size: 20px;font-weight: bold;">就从重新定义安全运营平台开始！</span></span><span lang="EN-US"><o:p></o:p></span></p><section><span leaf=""><br/></span></section><section><span leaf=""><span textstyle="" style="font-weight: bold;">【参考资料】</span></span></section><section><span leaf=""><a style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484842&amp;idx=1&amp;sn=38dba05e2a0024b71d81d1d9b3e74a6c&amp;scene=21#wechat_redirect" textvalue="2024年安全运营技术趋势回顾" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">2024年安全运营技术趋势回顾</a></span></section><section><span leaf=""><a style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484795&amp;idx=1&amp;sn=8f835c0699be66f615e7b713f67e26dc&amp;scene=21#wechat_redirect" textvalue="从Gartner2024年北美安全峰会看安全运营的技术趋势" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">从Gartner2024年北美安全峰会看安全运营的技术趋势</a></span></section><section><span leaf=""><a style="" href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484766&amp;idx=1&amp;sn=5b66715c108908d39eb92ecdc964c9f6&amp;scene=21#wechat_redirect" textvalue="从RSAC2024看SOC发展趋势" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">从RSAC2024看SOC发展趋势</a></span></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484848">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=1b8f6762&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyNzMxOTAwMw%3D%3D%26mid%3D2247484848%26idx%3D1%26sn%3D0f7f582e241603ec68bc85be3926998c%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 29 Apr 2025 12:01:00 +0800</pubDate>
    </item>
    <item>
      <title>2024年安全运营技术趋势回顾</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484842&amp;idx=1&amp;sn=38dba05e2a0024b71d81d1d9b3e74a6c</link>
      <description>万字长文总结SecOps五大技术趋势：AI化、自动化、主动化、整合化、管道化</description>
      <content:encoded><![CDATA[<p>
原创 <span>Benny Ye</span> <span>2024-12-27 12:01</span> <span style="display: inline-block;">北京</span>
</p>

<p>万字长文总结SecOps五大技术趋势：AI化、自动化、主动化、整合化、管道化</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=d13a07ec&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMduAvNFg7K1SeklAKYhA7KdIVDGpRAEbot1Uhggg0MBFOITKrQXllYlda5ic9mVuMu9GWMe2X2fg2Q%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section><span leaf="">回首2024年，在威胁演变和新兴技术的叠加作用下，安全运营（SecOps）技术的迭代正在加速，安全运营的技术平台正在持续重构。如果用几个关键词来勾勒2024年的安全运营技术发展特点的话，笔者选择：AI化、自动化、主动化、整合化、管道化。</span></section><p><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">本文关键要点</span></span></p><p><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">1）GenAI自身的不确定性风险抑制了其在安全运营领域的应用场景拓展；</span></span></p><p><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">2）基于智能体的智能自动化是未来，但现有自动化技术仍然大有可为；</span></span></p><p><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">3）在暴露管理技术的加持下，组织迈向真正资产运营和漏洞运营；</span></span></p><p><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">4）安全运营技术整合是未来，但整合技术路线选择需要仔细平衡；</span></span></p><p><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">5）以数据管道化为核心的新一代安全数据架构是对现有数据驱动安全理念的深化和重塑。</span></span></p><section><span leaf="">首先，需要明确安全运营（SecOps）和安全运营中心（SOC）的概念界定。</span></section><section><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">安全运营和安全运营中心的概念界定</span></span></section><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">安全运营（SecOps）是一个很宽泛的概念。如果我们把整个安全生命周期分为规划、建设、运营三个部分的话，安全运营的历程将伴随企业组织的一生。因此，在最广泛意义上，可以</span><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">把安全运营看作是持续不断地保障目标网络安全平稳运行，达成组织业务战略目标的永续过程，以及在这个过程中开展的各项运营工作</span></strong><span leaf="">。</span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">安全运营涉及的内容很广泛，从能力方面看，可以分解为IPDRR（识别、保护、检测、响应、恢复）或者类似的变体。从运营对象来看，可以分为工作负载、端点、应用、数据、身份等维度，并且针对不同的对象有各自独特的运营工作，譬如在身份运营中涉及账号权限的分配与管理工作，在数据安全运营中涉及对数据的分类分级工作，等等。对于应用的安全运营，可以进一步划分出开发态和运行态等不同的状态。而如果站在国家安全的视角，还能划分出防御性和进攻性等不同的性质。</span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">从狭义上来看，安全运营的核心是威胁事件的运营以及围绕这个威胁事件运营延伸出来的资产、漏洞、情报等等一系列配套运营工作。譬如，Gartner将安全运营定义为一个“</span><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf=""><span textstyle="" style="font-weight: normal;">通过一套人、流程和技术来识别和管理暴露、监测、检测和响应网络安全威胁与事件，以提升网络弹性</span></span></strong><span leaf="">”的过程。同理，SANS则将安全运营的使命定义为“保护业务运营的私密性、完整性和可用性，并最小化非预期事态造成的损失”。</span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf="">安全运营中心（SOC）作为一个组织单元，不可能承担所有安全运营工作，其工作内容更加聚焦，虽然有很多定义，但基本都围绕狭义的安全运营展开，可以看作是安全运营的一个子集，其它安全运营工作则应由不同的运营组织承担并相互协作。<span textstyle="" style="font-weight: bold;">安全运营中心通常是指一个包含一系列流程、人员、技术等的组织单元，</span></span><strong style="-webkit-tap-highlight-color: transparent;margin: 0px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;"><span leaf="">核心目标就是抵御网络安全威胁、保障目标网络安全平稳运行</span></strong><span leaf="">。围绕这个目标，通常会对目标网络实施持续的检测、监测、分析、调查、响应、报告、修复。</span></p><p style="-webkit-tap-highlight-color: transparent;margin: 0px 0px 24px;padding: 0px;outline: 0px;max-width: 100%;box-sizing: border-box !important;overflow-wrap: break-word !important;clear: both;min-height: 1em;color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;white-space: normal;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;"><span leaf=""><span textstyle="" style="font-weight: bold;">安全运营中心可以分为威胁事件运营、资产暴露运营、安全漏洞运营、安全情报运营、防御策略运营、态势决策运营6个方面能力</span></span><span leaf="">。这6个方面既各自独立，又相互关联，形成一个有机的整体。其中，威胁事件运营是所有SOC的基本与核心能力，就是指威胁事件的检测与响应，通常依托于以SIEM或者TDIR为核心的检测与响应技术栈。而资产暴露运营和安全漏洞运营则可以基于CTEM（持续威胁暴露管理），以在事前掌握和完善自身安全防御的姿态，同时又与安全情报运营所依托的TIP一道为SIEM/TDIR提供上下文（情境）信息，提升威胁事件运营的效能。防御策略运营则通过持续的评估、验证和改进来不断提升包括SOC自身在内的防御体系的有效性。最后，态势决策运营持续收集前面5大运营过程中的数据，进行指标计算和态势量化，形成决策，从而动态调整安全保障级别，指挥和调配安全防御力量。</span></p><section><span leaf="">基于上述概念定义，回顾2024年国内外安全运营领域的发展动向，可以从以下几个方面来总结当前安全运营技术的发展特点。</span></section><section><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">AI化</span></span></section><section><span leaf="">早在2015年，Gartner就发表过智能SOC的报告，指出要利用高级安全分析来落地智能化SOC。从那以来，AI和ML的应用主要聚焦到了UEBA、NDR、EDR等细分产品上，并且已经趋于成熟。但这时候AI和ML对包括安全运营在内的安全领域并未掀起太大波澜，属于一种改进型技术，直到2022年底以LLM为代表的GenAI技术的爆火。</span></section><section><span leaf=""><span textstyle="" style="font-weight: bold;">市场格局</span></span></section><section><span leaf="">作为一种颠覆性技术，<span textstyle="" style="font-weight: bold;">GenAI很快应用到了安全领域，并首先在安全运营上得到了应用</span>，</span><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">因为它恰好完美地击中了当下安全运营的三大痛点：人才短缺、工作倦怠（告警疲劳）、技能不足。如果说2023年是各个安全运营厂商对GenAI跑马圈地的一年，那么2024年可以算是GenAI在安全运营领域真正落地的元年，并且几乎都集中在安全运营智能助理（SecOps AI Assistants）这个细分产品上。2024年，基于GenAI的安全运营议题充斥了各大顶级安全会议，从<a href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484766&amp;idx=1&amp;sn=5b66715c108908d39eb92ecdc964c9f6&amp;scene=21#wechat_redirect" textvalue="RSAC" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">RSAC</a>到<a href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484795&amp;idx=1&amp;sn=8f835c0699be66f615e7b713f67e26dc&amp;scene=21#wechat_redirect" textvalue="Gartner安全峰会" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">Gartner安全峰会</a>，再到SANS的各类峰会。</span></span></section><section><span leaf="">在这一年，各大SOC平台/SIEM厂商纷纷发布基于GenAI的产品或功能。</span></section><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><section><span leaf="">5月，Palo Alto Networks正式发布了</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Precision AI，并且嵌入到其SOC产品Cortex XSIAM之中。</span></section></li><li><section><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Sumo Logic发布了基于GenAI的Mo Copilot产品</span></section></li><li><section><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Elastic推出了</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">基于</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Search AI</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">平台构建的</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">AI</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">驱动的安全分析解决方案。</span></section></li><li><section><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">4月3日，</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">Fortinet</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">发布了最新版本的操作系统</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">FortiOS</span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">7.6，并在其SOC产品中添加了基于GenAI的FortiAI功能，重点赋能FortiSIEM和FortiSOAR产品。</span></section></li><li><section><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">4月8日，SentinelOne宣布试运行一年的智能助理产品Purple AI正式上线。</span></section></li><li><section><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">在RSAC2024上，</span><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">Securonix带来了基于其AI增强的CyberOps理念的SOC产品Securonix EON。</span></span></section></li><li><section><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">在RSAC2024上，Exabeam也推出了基于GenAI的SOC产品模块Exabeam Copilot。</span></span></section></li><li><section><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">Rapid7推出了基于AWS GenAI解决方案的SOC智能助理。</span></span></section></li><li><section><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">Devo推出了Intelligent SIEM，利用GenAI全面升级现有SIEM。</span></span></section></li></ul><section><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">此外，在2024年，CrowdStrike Charlotte AI、微软的Security Copilot，以及Google的Security AI Workbench都进行了大规模的升级。</span></span></section><section><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">以上厂商除了PAN和CrowdStrike，都入选了<a href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484777&amp;idx=1&amp;sn=dd216426fc6cf09be507e2d8d83b3695&amp;scene=21#wechat_redirect" textvalue="Gartner的2024年SIEM魔力象限" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">Gartner的2024年SIEM魔力象限</a>。</span></span></section><section><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">还必须指出的是，以上厂商发布的都是Copilot/智能助理类GenAI应用。而除了这类较为成形的GenAI应用模式，一些初创公司也推出了基于智能体（AI Agent）的AI SOC类产品，譬如DropZone AI、Culminate，等等。随着智能体的爆火，相信未来会有更多基于智能体技术的虚拟安全分析师产品推出。</span></span></section><section><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">视线回到国内，GenAI同样横扫安全领域，尤其是安全运营。数说安全发表的《<a href="https://mp.weixin.qq.com/s?__biz=MzkzMDE5MDI5Mg==&amp;mid=2247507242&amp;idx=1&amp;sn=db3f81def2f10099e18983de18b1e6a6&amp;scene=21#wechat_redirect" textvalue="2024网络安全十大创新方向" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">2024网络安全十大创新方向</a>》报告中，GenAI+安全运营位列其中。IDC中国发布了<a href="https://mp.weixin.qq.com/s?__biz=MzA5MTc1NzQzOQ==&amp;mid=2651789545&amp;idx=3&amp;sn=52bd9126f11a229eafa91d4dcb11b6a0&amp;scene=21#wechat_redirect" textvalue="大模型赋能安全运营的洞察报告" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">大模型赋能安全运营的洞察报告</a>，并对国内主流厂商<a href="https://mp.weixin.qq.com/s?__biz=MzA5MTc1NzQzOQ==&amp;mid=2651791331&amp;idx=1&amp;sn=7b1ddd22f24dd39790110a919ee4f739&amp;scene=21#wechat_redirect" textvalue="基于GenAI的安全运营应用水平进行了一次实测" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">基于GenAI的安全运营应用水平进行了一次实测</a>。2024年，国内主流的SOC平台厂商基本上都推出了GenAI应用，尽管总体应用水平距离国外大厂还有一定差距。</span></span></section><section><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf=""><span textstyle="" style="font-weight: bold;">现状思考</span></span></span></section><section><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">根据笔者的调研，当前，单纯利用GenAI赋能安全运营的整体效果还十分有限，现在谈论替代人类分析师还为时尚早，即便是增强分析师的能力这块也效果一般，目前主要功效还是降低用户使用安全运营系统时的摩擦，改善用户体验。以国外主流的安全运营智能助理为例，对大模型的应用主要还是聚焦于自然语言理解和特定内容生成上，真正的信息查询、威胁检测、响应联动还是依靠现有的安全运营功能。在推荐和预测方面，其实也是基于已有的知识。不仅安全领域，GenAI在其它领域的应用也遭遇瓶颈。正如<a href="https://mp.weixin.qq.com/s?__biz=MzA5NjQyNjMxNA==&amp;mid=2651418893&amp;idx=1&amp;sn=d360a4181aea1bbbcbecfca0ec6efd4c&amp;scene=21#wechat_redirect" textvalue="Garnter的2024年AI技术成熟度曲线" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">Garnter的2024年AI技术成熟度曲线</a>所示，GenAI正开始从炒作的顶峰滑向失落区间，相信2025年会更加明显。</span></span></section><section><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">如何改进？一种思路是不断提升GenAI的技术水平、能力和应用技巧。但更切实际的方法是<span textstyle="" style="font-weight: bold;">用更广泛意义的AI和智能体技术去扩展现有的GenAI应用，这就是所谓“</span><a href="https://mp.weixin.qq.com/s?__biz=MzA5NjQyNjMxNA==&amp;mid=2651418811&amp;idx=1&amp;sn=0683825a8139cecb1975e2de589c0452&amp;scene=21#wechat_redirect" textvalue="复合式AI" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2"><span textstyle="" style="font-weight: bold;">复合式AI</span></a><span textstyle="" style="font-weight: bold;">”</span>（Composite AI）。</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">根据Gartner的定义，复合式AI是指组合利用（或融合）不同AI技术来提高学习效率，以生成层次更丰富的知识表示。复合式AI提供了更丰富的AI抽象机制，并最终提供了⼀个能够以更有效方式解决更广泛业务问题的平台。简而言之，单纯利用GenAI不足以变革安全运营，要将GenAI和传统（符号主义）AI结合使用。也正因如此，笔者将这个章节标题定为AI化，而不是GenAI化。</span></section><section><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">事实上，仔细研究诸如PAN的Precision AI、CrowdStrike的Charlotte AI，或者是Splunk AI，都是一个AI应用功能包的统称，里面有基于GenAI的智能助理，还有各种威胁检测、安全分析、告警分诊、调查响应的AI和ML算法。同时，这些AI之间不是孤立的，不是一个简单的工具箱，而是相关的，借助智能编排和智能体，可以将不同的AI协同起来。</span></section><section><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">在想方设法利用GenAI和其它AI共同促进安全运营的同时，还必须认识到GenAI自身存在的诸多不确定性，譬如安全性、</span><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">准确性、可解释性、可信度、数据安全与隐私问题，等等。尤其是大模型的生成内容准确性的问题，也就是大模型幻觉/胡言乱语问题，容易让使用者陷入困境，信还是不信？尤其对于初级水平的分析师，可能无法判断大模型给出的方案是否正确，从而可能导致不良后果。而高级分析师也不可能事事都去复核一遍。这就需要建立一套可行的、常态化的验证反馈机制。当前，很多人都在谈论GenAI如何赋能安全运营，但如果不提前把上述风险缓解措施设计好，是无法真正落地任何赋能方案的。</span></span></section><section><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">而在国内，受到体制机制以及认知的影响，除了要借鉴以上国外同行的发展经验之外，还需要特别面对大模型本地化部署的问题。也正是在这个背景之下，一些国内头部安全厂商为了占得先机而投入到安全垂域大模型的开发上。从2023年到2024年间，国内举办了多次此类发布会。但是，这种本地部署的安全垂域大模型将不可避免地陷入两难。</span></span></section><section><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">一方面，为了追求本地大模型的质量和速度，必定需要很高的算力，而这个算力的成本会极大推高整个安全投资，并且可能算力投资比安全运营本身的投资还要高。而高企的总投资必定使得大部分客户望而却步，何况GenAI到底能够给安全运营增色多少还尚难量化。另一方面，为了控制成本使得本地大模型能够满足主力客户的投资承受能力，必定需要控制大模型的质量和速度，相当于用户可能被迫要接受使用业界普通（甚至较低）水平的大模型去赋能自身的安全运营，最终赋能效果必定要打折扣，反过来可能影响管理层继续投资大模型的信心。笔者认为，稍有不慎，本地化部署的安全大模型可能就会陷入这种“高不成、低不就”的困局，需要安全大模型厂商们从应用场景的角度出发，精心平衡。</span></span></section><section><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">此外，安全行业的攻防对抗本质决定了其是一个快速变化的行业，安全数据和知识的急速更新必将导致安全大模型的更新速度必须跟上，使得本地安全大模型的更新维护面临更高挑战。同时，大模型所代表的GenAI领域属于数据驱动的AI，对数据质量和知识管理的水平要求极高，当前国内客户现有数据条件差距明显，所谓的向本地大模型投喂客户自有安全数据和运营知识获得有效成果的概率势必也要大打折扣。</span></span></section><section><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf=""><span textstyle="" style="font-weight: bold;">小结</span></span></span></section><section><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">综上所述，在2024年，GenAI赋能安全运营的用例更加清晰，智能体等新型应用崭露头角。短期内，需要对GenAI的应用价值建立更为合理的预期，同时关注GenAI自身的安全风险。长期来看，需要建立更为长远的技术路线，不要仅考虑GenAI，而应该将GenAI和其它AI综合使用，采用复合式AI技术。此外，还应做好本地安全垂域大模型的定位。</span></span></span></section><section><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">自动化</span></span></span></section><section><span leaf="">自动化是安全运营的基本需求，更是大规模安全运营的必备能力。2024年11月SANS发布的《<a href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484836&amp;idx=1&amp;sn=05ff688d9865a0d5bc38815a37d63725&amp;scene=21#wechat_redirect" textvalue="检测与响应调研报告" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">检测与响应调研报告</a>》显示，</span><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">87%的受访者使用了自动化辅助工具去检测威胁，还有64%的组织正在将自动响应机制集成到其安全运营中。</span></span></section><section><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: justify;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">经过多年的发展，安全运营中的自动化已经从最早的安全技术或能力的自动化（譬如资产发现自动化、数据采集处理自动化、安全分析自动化，等等）发展到了安全运营流程/过程的自动化（最典型的是SOAR）。安全流程的自动化可以将一系列自动化安全技术衔接起来，形成更大规模的自动化，因而成为安全运营自动化的核心。</span></span></section><section><span leaf="">安全编排技术是安全运营流程自动化的基础，通过编排将流程变成可以机器自动执行的剧本，再通过剧本的运行实现安全运营流程的自动化。一直以来，剧本的编排都是人工编写的，预先设定好的，是一种静态剧本。基于静态剧本，安全运营实现的自动化是一种机械自动化，其特点就是重复不走样，可以帮助分析师处理安全运营过程中的很多固定、重复、无聊、耗时的工作，提升运营效率。但是，网络安全的动态攻防特性决定了很多安全运营的流程需要应时而变，人们不得不持续不断地手工更新剧本，机械自动化的缺陷逐步显露。</span></section><section><span leaf="">智能体技术的兴起带来了转机。</span></section><section><span leaf=""><span textstyle="" style="font-weight: bold;">市场格局</span></span></section><section><span leaf="">在2024年5月份的<a href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484766&amp;idx=1&amp;sn=5b66715c108908d39eb92ecdc964c9f6&amp;scene=21#wechat_redirect" textvalue="RSAC" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">RSAC</a>上，DropZone.AI向大家展示了基于智能体技术的智能机器人SOC分析师。通过智能体的推理、规划和工具调用，系统生成了（隐含的）动态剧本，并自动执行，实现了告警研判和事件响应，展示了安全运营流程的智能自动化的价值，将人们从预先编写剧本并持续更新剧本的繁重负担中解脱出来。</span></section><section><span leaf=""><span textstyle="" style="font-weight: bold;">从静态剧本到动态剧本，从机械自动化到智能自动化，这是安全运营流程自动化的一次迭代演进</span>。在GenAI的激励下，国际上迅速涌现了多家基于智能体的AI SOAR/SOC公司，如DropZone AI、Culminate等。而放眼国内，可以看到奇安信、雾帜智能等公司的SOAR产品也正在利用GenAI/AI，向智能编排、动态剧本生成和智能自动化方向演进。</span></section><section><span leaf="">除了智能编排与自动化，传统的静态编排自动化也还有提升的空间。有的公司从低代码/无代码开发的角度去降低剧本的开发门槛，或者内置更多开箱即用的剧本，等等。还有的公司也在思考对剧本进行分层，让剧本更易于组装、复用、快速更新。</span></section><section><span leaf="">SANS 2024年的《<a href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484811&amp;idx=1&amp;sn=18c651844e9668dd2ffa2f32db674f8c&amp;scene=21#wechat_redirect" textvalue="SOC调查报告" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">SOC调查报告</a>》显示，缺乏编排与自动化是</span><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">SOC面临的最大挑战。多年来，SIEM/SOC厂商们一直在布局SOAR。</span></span></section><section><span leaf=""><img class="rich_pages wxw-img" data-ratio="0.35" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=83d92342&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcclMcHAuIVBMek9aULhLiceySRJXsVpFOkD9O1RBQl5HaY3m9XiciccfsicoeOKYvuEiauYqicXibaAWd6Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;">如上图所示，入围Gartner2024年SIEM魔力象限的所有SIEM厂商都有SOAR，要么自研，要么收购（主要方式），要么是SIEM产品中的一个模块，要么是SIEM产品套件中的一个子产品。而国内，主要SOC平台厂商都集成了SOAR模块，有的还提供独立SOAR。</span></section><section><span style="color: rgba(0, 0, 0, 0.9);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 17px;font-style: normal;font-variant-ligatures: normal;font-variant-caps: normal;font-weight: 400;letter-spacing: 0.544px;orphans: 2;text-align: left;text-indent: 0px;text-transform: none;widows: 2;word-spacing: 0px;-webkit-text-stroke-width: 0px;background-color: rgb(255, 255, 255);text-decoration-thickness: initial;text-decoration-style: initial;text-decoration-color: initial;display: inline !important;float: none;"><span leaf="">除了成为SIEM/SOC的一部分，还有一些传统的SOAR公司开始向更广泛的安全运营领域转型，譬如Torq、Swimlane转型成为AI SOC厂商，还有的甚至跳出安全，成为通用型智能流程自动化工具，譬如Tines。</span></span></section><section><span leaf=""><span textstyle="" style="font-weight: bold;">现状思考</span></span></section><section><span leaf="">自动化如此重要，SOAR已经成为安全运营必不可少的一部分，SIEM厂商和其它DR厂商纷纷在自己产品中集成SOAR。终于，Gartner在2024年的安全运营技术成熟度曲线中，<a href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484818&amp;idx=1&amp;sn=1966e121ac2e4f4dacda712854534d0c&amp;scene=21#wechat_redirect" textvalue="将SOAR标定为“过时”" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">将SOAR标定为“过时”</a>，认为SOAR已经融入到SIEM或者其它DR类产品中成为其中一项功能或能力，独立SOAR市场将成为非主流。</span></section><section><span leaf="">不过，笔者认为在国内现阶段其实更加需要独立SOAR产品。因为当前国内大部分客户的SOC/SIEM平台都不具备SOAR能力。<span textstyle="" style="font-weight: bold;">在用户彻底更换为下一代具有SOAR功能的SOC平台之前，还需要购买独立SOAR来弥补现有平台的这部分不足</span>。而鉴于当前的中国经济发展状况，用户花费大量资金投资于下一代SOC替换以前大额投资的意愿不高，会倾向于采用“向存量投资要效益&#34;和&#34;查漏补缺&#34;的方式来完善其SOC平台。</span></section><section><span leaf="">此外，GenAI赋能的安全运营向动态编排、智能自动化演进才刚刚开始，尽管前景可观，但受限于目前GenAI以及智能体技术还不够成熟，现阶段不要对此有过高的期待。AI SOAR将取代传统SOAR，但不是现在。如果说SOAR已死，并不是SOAR技术已死，即便是机械式自动化也还大有可为。</span></section><section><span leaf=""><span textstyle="" style="font-weight: bold;">小结</span></span></section><section><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">综上所述，在2024年，编排自动化已经成为SOC平台的基础能力，SOAR正在与SIEM/SOC平台融合。与此同时，在GenAI和智能体技术的加持下，编排正在经历一场从静态剧本到动态剧本的升级，传统的机械式自动化正在向智能自动化演进，并成为AI SOC的关键能力。但是，请谨记，在可见的未来，安全运营还不可能实现完全的自动化（即所谓“自主化”）。</span></span></section><section><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">主动化</span></span></section><section><span leaf="">从安全运营中心的6大运营来看，核心的威胁事件运营聚焦于安全事件发生之时以及之后，强调快速检测、快速响应，属于事中和事后的被动环节。显然，要做好安全运营，还必须强化事前性工作，包括资产运营和漏洞运营，实现主动化安全运营，减轻威胁事件运营的压力，并为威胁事件分析提供上下文。</span></section><section><span leaf="">随着组织攻击面的不断扩展，传统的资产和漏洞管理技术手段已经难以帮助组织盘清资产及其暴露，造成了运营的盲点。因此，结合攻击者视角的攻击面评估应运而生，后来又进一步扩展为暴露评估，并与对抗性暴露验证一道，组合形成了持续威胁暴露管理（CTEM）的理念。攻击面评估以及暴露管理的理念在最近三年一直位于Gartner年度网络安全顶级趋势之列。</span></section><section><span leaf=""><span textstyle="" style="font-weight: bold;">市场格局</span></span></section><section><span leaf="">进入2024年，在暴露管理领域，一个比较显著的市场变化就是暴露管理平台的逐步形成，现有的漏洞管理（VM）厂商、攻击面管理（ASM）厂商，甚至是BAS厂商，都开始扩展自己的产品边界，向暴露管理平台方向发力。与此同时，SOC厂商开始集成暴露管理平台，将其作为SOC平台的一个组成部件，譬如Palo Alto Networks的XSIAM中就集成了之前收购来的Xpanse暴露管理组件，CrowdStrike在其所谓原生AI SOC平台中也集成了暴露管理。而就在11月，微软正式发布了安全暴露管理产品，并能够与其Sentinel SIEM产品整合。</span></section><section><span leaf="">视线放回国内，头部的SOC平台厂商也纷纷布局暴露管理领域，但主要聚焦在攻击面管理产品或功能组件上。同时，一些国内初创的攻击面管理厂商、BAS厂商、漏洞管理厂商，甚至XDR厂商，也开始跨界发展，布局综合性暴露管理平台产品。</span></section><section><span leaf=""><span textstyle="" style="font-weight: bold;">现状思考</span></span></section><section><span leaf="">必须指出，在CTEM之前，资产运营和漏洞运营就已经是安全运营的组成部分，以前的SOC平台一直就具备资产和漏洞管理功能。</span></section><section><span leaf="">通过对比，可以发现，CTEM语境下的资产运营和漏洞运营相较于以往在技术上有重大突破。以ASM为基础的资产运营极大地丰富了资产发现的手段，通过攻击者视角的攻击面发现与评估，能够极大地弥补传统资产清点方式的不足。同时，以BAS为代表的对抗性暴露验证技术能够帮助组织识别真实的风险，并且给出置信度极高的风险排序。</span></section><section><span leaf="">而进一步来看，<span textstyle="" style="font-weight: bold;">在暴露管理技术的加持下，组织真正实现了资产运营和漏洞运营</span>。相比之下，以往只能叫资产管理和漏洞管理，也就是对资产安全信息和漏洞信息进行导入、整理维护，为威胁事件运营提供上下文。这个管理维护工作是十分滞后的、低效的，资产和漏洞信息的质量很低，无法真正为威胁事件分析研判提供依据。而有了暴露管理之后，通过多源资产和漏洞数据融合和分析、能够对数据进行持续运营，持续维持相关数据的一致性和有效性，数据质量大大提升。而这个对多源资产和漏洞数据进行采集、融合、分析研判的过程恰恰体现了资产运营和漏洞运营的精髓。</span></section><section><span leaf=""><span textstyle="" style="font-weight: bold;">小结</span></span></section><section><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">综上所述，在2024年，暴露管理正在成为SOC平台的必备主动化运营能力支撑。同时，攻击面管理产品、漏洞管理产品、BAS产品正在相互渗透融合，共同形成暴露管理平台。</span></span></section><section><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">整合化</span></span></section><section><span leaf="">从多个角度来看，网络安全的碎片化问题都十分严重，这不仅体现在多如牛毛的安全厂商，也表现在碎片化的安全解决方案和产品，即便经济不景气的时候，也没有多少好转。国内的碎片化现象则更加显著。业内人士常说：“安全厂商永远在整合，但永远也整合不完”。国外有研究表明，平均每个组织的使用超过43种网络安全产品，还有5%的组织使用超过100种产品。</span></section><section><span leaf="">进一步探究，碎片化的安全解决方案及产品的出现源于层出不穷、永不止境的安全新威胁，这是网络安全的本质决定的，无法改变。但碎片化造成的安全运营的复杂度和难度急剧上升则是可以想办法予以缓解的，于是就出现了供应商整合（Vendor Consolidation）这个概念。这里的整合不仅包括狭义的供应商产品的合并和数量的减少，更包括基于平台的跨供应商产品集成与组合。总之，整合的目标就是要让用户在安全运营的时候感到简单，并降低整个运营周期的维护成本。举个例子，一个厂商预先将SIEM、SOAR、EDR、NDR、ASM、甚至TIP等等安全运营的相关系统整合到一个安全运营平台/SOC平台之中，就是一种典型的整合。</span></section><section><span leaf="">根据Gartner的最新预测，到2028年，随着整合的深化，45%的组织将在其产品组合中使用少于15 种网络安全工具。不过笔者认为这个预测过于乐观了。</span></section><section><span leaf=""><span textstyle="" style="font-weight: bold;">市场格局</span></span></section><section><span leaf="">聚焦安全运营，整合化已然成为2024年的主旋律。但业界的整合者们正在朝着两个不同的方向前进。</span></section><section><span leaf="">一类是所谓的融合安全平台厂商。它是一套融合了多种安全产品功能的模块化单一型产品，将原来满足特定领域需求的分散于多种安全产品中的功能融合到一起，形成一个单一的产品，以实现覆盖这个特定领域的全生命周期的各种功能。这个融合安全平台不是简单的解决方案，也不是产品集成，而是更为深度的产品融合，笔者称之为全家桶2.0。平台通常具有统一的管理控制台，统一的数据存储，高度一致的用户体验，等等。融合安全平台存在于多个安全领域，譬如融合端点安全、邮件安全的工作空间安全平台，或者融合服务器安全、CNAPP、应用安全的工作负载安全平台，以及面向安全运营的融合性安全运营平台，甚至XDR也可以属于此列。</span></section><section><span leaf="">在安全运营领域，业界典型的融合性安全运营平台包括：Palo Alto Networks的XSIAM，CrowdStrike的AI SOC，微软的统一安全运营平台，等等。此外，XDR、暴露管理平台本质上也是秉持这个理念，只是功能范围没有融合安全运营平台那么大。</span></section><section><span leaf="">另一类是以Gartner的CSMA（网络安全网格架构）为代表的开放性集成平台厂商，笔者称之为集成安全平台【尽管在美国，安全平台已经要成为融合安全平台的代名词了，但笔者认为安全平台这个中性术语不应被绑架】。在安全运营领域，集成安全运营平台遵循的理念与现有SOC平台是一脉相承的，它强调基于开放（数据和接口等）标准和规范实现异构供应商和产品的整合与协同。目前，大部分SOC厂商属于这个阵营。</span></section><section><span leaf="">视线放到国内，笔者还未看到真正的融合性安全运营平台厂商，深信服的XDR平台可以算是初步具备了这个气质。而集成性安全运营平台虽然覆盖了大部分SOC厂商，但由于缺乏规范、缺少生态，导致集成度表现得参差不齐。</span></section><section><span leaf=""><span textstyle="" style="font-weight: bold;">现状思考</span></span></section><section><span leaf=""><span textstyle="" style="font-weight: bold;">都是整合，都是为了降低用户使用安全运营平台的难度和成本，提升安全运营的效率，但却发展出了两条相反的产品策略。</span></span></section><section><span leaf="">对融合安全运营平台而言，显然具有高度一致的用户使用体验，更统一的架构设计和更清晰的功能模块，以及更简洁的采购过程和更低的维护成本。但风险在于容易形成单一供应商锁定，而且是大范围的锁定，同时更容易成为单一故障点，并且可能由于竞争原因而难以与必须采购的额外安全运营工具有效对接。</span></section><section><span leaf="">对集成安全运营平台而言，情况恰恰相反。平台的开放性决定了其能够更好地与众多异构安全系统和工具对接，具有更好的扩展性，集成带来的冗余也为实现安全弹性创造了有利条件。问题则在于相对更复杂的用户使用体验，并且使用界面的一致性和连续性难免会有所欠缺。然而，开放性价值的实现受限于跨厂商和产品的互操作规范以及接口的成熟度。</span></section><section><span leaf="">尽管业内很多大咖（譬如ESG的Jon Oltsik），一众初创的细分领域特色公司，甚至Gartner都在极力鼓吹开放的、网格化的集成安全运营平台，但奉行单一融合安全运营平台路线的急先锋Palo Alto Networks却用屡创新高的业绩给予有力回应。更令人吃惊的是，PAN为了快速扩张自己的融合安全运营平台XSIAM的市场，直接<a href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484774&amp;idx=1&amp;sn=987126678b5166e4149e90aca01e2d78&amp;scene=21#wechat_redirect" textvalue="打包买下了IBM的QRadar" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">打包买下了IBM的QRadar</a>，但购买的目的不是为了继续维护QRadar这个品牌，而只是为了获得IBM的SOC客户，将XSIAM替换掉QRadar！PAN对自己产品和业务模式的自信心可见一斑。笔者分析，至少有一点对融合安全运营平台是有利的，即“天下苦SIEM久矣”，而简单才是王道。</span></section><section><span leaf="">笔者的观点，用户需要简单高效的安全运营，需要一致的用户体验。与此同时，世界上没有包打天下的安全运营平台，未来需要将融合和集成两种技术路线搭配使用，形成更为平衡的整合安全运营平台。而这，首先需要在技术架构上进行重构。</span></section><section><span leaf=""><span textstyle="" style="font-weight: bold;">小结</span></span></section><section><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">综上所述，在2024年，采用融合路线的整合安全运营平台异军突起，准确抓住了当前安全运营的痛点，但需要警惕过度的供应商整合，未来宜采用更为平衡的整合路线。</span></span></section><section><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">管道化</span></span></section><p><span leaf="">2012年，Gartner发布了一份名为《信息安全正在成为大数据分析问题》的报告，揭开了数据驱动安全时代的序幕。在2015年，“数据驱动安全”成为了中国网络安全业界的顶流，笔者也在那年提出了以数据为核心的“SOC3.0”理念。</span></p><p><span leaf="">在数据驱动安全口号的带动下，大数据架构以及融合大数据的安全分析技术在SOC平台种得到了充分的应用。但经过这些年的发展，现有基于大数据的SOC平台架构再次遭遇瓶颈，面临诸多挑战，譬如：边缘检测的兴起引发了数据引力问题，并带来了数据移动的困难；天量安全数据的长周期存储需求与高成本之间的矛盾日益突出；SOC没有也无法成为唯一的企业安全数据湖导致的数据孤岛使得跨数据存储的安全运营面临挑战；日益复杂的安全数据自身的安全与隐私问题对现有数据架构提出了各种挑战；等等。更重要的是，为了实现安全运营的AI化、自动化、整合化，现有的SOC平台技术架构明显有心无力，难以支撑。</span></p><p><span leaf="">为了应对上述挑战，就需要对现有的SOC技术架构，尤其是安全数据架构进行革新。在新一代安全数据架构创新方面，有的聚焦于云原生，有的聚焦于数据湖仓，还有的聚焦分布式查询引擎。如果要用一个词来描述新一代安全数据架构的话，笔者当前选择 “数据管道”【注1】这个词。数据管道以一种统一、全面和简洁的机制来管理源到目的地的安全数据的收集、提取、丰富、转换和路由，并贯穿安全运营的检测与响应全过程。</span></p><p><span leaf=""><span textstyle="" style="font-size: 16px;font-style: italic;">【注1】用一个词来指代用于SOC平台的新一代安全数据架构并不容易，可以选择的词除了“管道化”，还有“编排化”等。由于编排已经在SOAR领域广为人知，为了避免引起混淆，笔者暂定使用“管道化“这个词。</span></span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">市场格局</span></span></p><p><span leaf="">国际上，2024年涌现出了很多基于新一代安全数据架构的安全运营平台，主要集中在各种初创公司，如AbstracSecurity、AnviLogic、Auguria（背后是SentinelOne）、Cribl（背后是CrowdStrike）、Panther、Substation，等等。此外，擅长云数据管理的Snowflake凭借其先进的安全数据技术栈，也开始跨界进入这个领域。</span></p><p><span leaf="">反观国内，就笔者所见，只有很少的几个创业公司在这个领域耕耘。人们更多将目光聚焦到了新的应用技术（如GenAI应用）和功能扩充（如主动化）上，缺少对现在安全运营技术架构的创新和突破。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">现状思考</span></span></p><p><span leaf="">相较于前面4种特点（AI化、自动化、主动化、整合化），面向新一代安全数据架构的管道化尚未得到广泛的认知。Gartner也仅仅是在2024年的安全运营技术成熟度报告中有所提及，但也仅仅是笔者所指管道化概念的子集。而Forrester也是才开始关注到这个变革（Allie Mellen在2024年11月12日发布的博客中表示打算发表这方面的研究报告）。</span></p><p><span leaf="">笔者认为，<span textstyle="" style="font-weight: bold;">新一代安全数据架构是对现有数据驱动安全理念的深化和重塑</span>！唯有采用新的数据架构，才能支撑数据驱动安全的未来发展。</span></p><p><span leaf="">如果说AI（尤其是GenAI）将重塑安全，那么AI应用成功的基石是什么？是数据！如果没有标准化、逻辑统一和高质量的安全数据、安全情报、安全知识，AI应用的结果也只能还是“垃圾进，垃圾出”。现有的数据架构对此已经无能为力，需要重构，而数据管道化恰恰给了安全运营一个机会，能够基于数据工程，建立起持续改进的数据治理与管理能力。</span></p><p><span leaf="">如果说安全运营（尤其是规模化安全运营）必须依赖自动化，那么自动化成功的基石是什么？是编排！没错，安全运营流程（譬如响应流程）需要编排，数据的处理流转过程也需要编排。编排代表了解决某个问题的思路和过程。无论是人工预先编排，还是GenAI智能编排，只有在形成了一个个解决具体问题的剧本后，自动化才能发挥作用，将这个解决问题的过程形成规模化。而要实现数据可编排，就必须先实现数据管道化，但现有的数据架构对此已经无能为力，需要重构。只有数据架构在技术上实现了管道化，才能让安全运营在应用层面实施各种编排，就如同进行各种管道的组合（如分支、合并、转换）。</span></p><p><span leaf="">数据管道化不仅针对日志、事态和安全事件，也针对资产、漏洞、情报等等主动安全运营所需的各种数据，以及其它各种上下文（情境）数据。所有数据流转都必须建立的统一的数据管道之上，让各类数据在统一的管道中汇聚、关联，如此，才能实现真正有效的主动化安全运营。现有的数据架构将上述数据分割对待，需要重构。</span></p><p><span leaf="">而一旦实现了基于数据管道的新一代数据架构，在此之上的安全运营架构就能更好地支撑各种能力整合（包括融合和集成）。这时，数据管道就相当于一条数据总线，可以将不同的安全能力中的数据整合到一起。</span></p><p><span leaf="">其实，美国政府已经意识到了这个问题，并已经开始从数据架构入手，<a href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484730&amp;idx=1&amp;sn=a4dfcb4c250f3128b59cab19c6a393f2&amp;scene=21#wechat_redirect" textvalue="重塑他们的安全运营技术架构" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">重塑他们的安全运营技术架构</a>。这也是他们将国家级态势感知项目从NCPS（National Cybersecurity Protection System，国家网空安全保护系统，俗称爱因斯坦计划）升级到CADS（Cyber Analytics and Data System，网络分析与数据系统）的一个重要原因。根据他们的定义，CADS提供了一个强大且可伸缩的分析环境，能够集成数据集并提供工具和功能。CADS工具和能力将促进数据的摄取和集成，并通过对数据分析（过程）的编排和自动化，以支持快速识别、检测、缓解和阻断恶意网络活动。</span></p><p><span leaf=""><span textstyle="" style="font-weight: bold;">小结</span></span></p><p><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">当前的SOC平台技术架构遇到了发展瓶颈，底层的数据架构无法支撑其实现数据驱动安全的目标价值，需要进行重塑。以数据管道化为代表的新一代安全数据架构正在脱颖而出。</span></span></p><section><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">总结</span></span></section><section><span leaf="">安全运营中心不承担安全运营的所有工作。正确界定安全运营中心与安全运营的关系才能更好地推动安全运营的发展。</span></section><section><span leaf="">回顾2024年，安全运营技术取得了长足的进步：<span textstyle="" style="font-weight: bold;">AI（尤其是GenAI）让安全运营更加智能高效；AI让编排更智能并进而带动实现大规模自动化；主动化让安全运营更加完整；整合化让安全运营更加简单；管道化重塑安全数据架构为真正实现数据驱动安全运营提供支撑</span>。</span></section><section><span leaf="">最后，安全运营当前呈现出来的这些特点之间是相互关联、相互作用、相互转化的，不能孤立的去看。</span></section><section><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">【参考资料】</span></span></section><section><span leaf=""><a href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484500&amp;idx=1&amp;sn=91a3a818e697213a9b46ac7b5559944e&amp;scene=21#wechat_redirect" textvalue="SIEM的未来" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">SIEM的未来</a></span></section><section><span leaf=""><a href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484818&amp;idx=1&amp;sn=1966e121ac2e4f4dacda712854534d0c&amp;scene=21#wechat_redirect" textvalue="SOAR的未来" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">SOAR的未来</a></span></section><section><span leaf=""><a href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484795&amp;idx=1&amp;sn=8f835c0699be66f615e7b713f67e26dc&amp;scene=21#wechat_redirect" textvalue="从Gartner2024年北美安全峰会看安全运营的技术趋势" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">从Gartner2024年北美安全峰会看安全运营的技术趋势</a></span></section><section><span leaf=""><a href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484766&amp;idx=1&amp;sn=5b66715c108908d39eb92ecdc964c9f6&amp;scene=21#wechat_redirect" textvalue="从RSAC2024看SOC发展趋势" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">从RSAC2024看SOC发展趋势</a></span></section><section><span leaf=""><a href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484777&amp;idx=1&amp;sn=dd216426fc6cf09be507e2d8d83b3695&amp;scene=21#wechat_redirect" textvalue="Gartner：2024年SIEM（安全信息与事件管理）市场分析" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">Gartner：2024年SIEM（安全信息与事件管理）市场分析</a></span></section><section><span leaf=""><a href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484730&amp;idx=1&amp;sn=a4dfcb4c250f3128b59cab19c6a393f2&amp;scene=21#wechat_redirect" textvalue="再见！爱因斯坦计划，网安态势感知迎来转型" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">再见！爱因斯坦计划，网安态势感知迎来转型</a></span></section><section><span leaf=""><a href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484774&amp;idx=1&amp;sn=987126678b5166e4149e90aca01e2d78&amp;scene=21#wechat_redirect" textvalue="IBM放弃自己的QRadar，转而使用派拓网络的XSIAM" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">IBM放弃自己的QRadar，转而使用派拓网络的XSIAM</a></span></section><section><span leaf=""><a href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484836&amp;idx=1&amp;sn=05ff688d9865a0d5bc38815a37d63725&amp;scene=21#wechat_redirect" textvalue="SANS：2024年检测与响应（DR）报告解读" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">SANS：2024年检测与响应（DR）报告解读</a></span></section><section><span leaf=""><a href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484811&amp;idx=1&amp;sn=18c651844e9668dd2ffa2f32db674f8c&amp;scene=21#wechat_redirect" textvalue="SANS 2024年SOC调查报告解读" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">SANS 2024年SOC调查报告解读</a></span></section><section style="text-align: left;"><span leaf="">以数据为核心的SOC3.0时代到来：<a href="https://blog.51cto.com/yepeng/1729338" target="_blank">https://blog.51cto.com/yepeng/1729338</a></span></section><section style="text-align: left;"><span leaf="">大数据分析——信息安全下一站：<a href="https://blog.51cto.com/yepeng/1630748" target="_blank">https://blog.51cto.com/yepeng/1630748</a></span></section><section style="text-align: left;"><span leaf="">Gartner：智能SOC/情报驱动的SOC的五大特征：<a href="https://blog.51cto.com/yepeng/1718678" target="_blank">https://blog.51cto.com/yepeng/1718678</a></span></section><section><span leaf=""><br/></span></section><section><span leaf=""><br/></span></section><section><span leaf=""><br/></span></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484842">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=ae8b70a1&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyNzMxOTAwMw%3D%3D%26mid%3D2247484842%26idx%3D1%26sn%3D38dba05e2a0024b71d81d1d9b3e74a6c%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 27 Dec 2024 12:01:00 +0800</pubDate>
    </item>
    <item>
      <title>SANS：2024年检测与响应（DR）报告解读</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484836&amp;idx=1&amp;sn=05ff688d9865a0d5bc38815a37d63725</link>
      <description>检测与响应的未来在于智能化、自动化和集成化</description>
      <content:encoded><![CDATA[<p>
原创 <span>Benny Ye</span> <span>2024-12-19 12:00</span> <span style="display: inline-block;">北京</span>
</p>

<p>检测与响应的未来在于智能化、自动化和集成化</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=9908bf88&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMfu5UFByDSCYOoOFKgGqyp9kibibTPWIVuCwLgJ3TicEicSTmpQPePnfqa5gMe2Pet4WRIMC7tXb8BMIQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section><span leaf="">2024年11月，SANS发表了针对检测与响应（DR）的首份调研报告。正如这份报告的副标题——安全运营转型中：检测与响应的智能化、自动化和集成化——所言，SANS认为检测与响应（DR）的未来发展方向的核心就聚焦在智能化（AI）、自动化和集成化三个方面。注意，这里的AI不仅包括以大模型（LLM）为代表的GenAI，而是指完整的人工智能（AI）和机器学习（ML）技术。</span></section><section><span leaf="">报告的主要发现包括：</span></section><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">大部分组织 （64%） 正在将自动响应机制集成到其安全运营中。</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">只有 16% 的受访者表示他们的响应流程已完全自动化。</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">59% 的受访者认为，对熟练人员的需求是实施的最大障碍。</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-weight: bold;"> 47% 的受访者表示，预算限制是首要问题。</span></span></p></li><li><p><span leaf=""><span textstyle="" style="font-weight: bold;">约三分之二的受访者 （67%） 表示，他们计划扩大人工智能 （AI） 和机器学习（ML）在威胁检测和响应方面的使用。</span></span></p></li></ul><section><span leaf=""><br/></span></section><section><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">威胁检测</span></span></section><section><span leaf="">1）<span textstyle="" style="font-weight: bold;">自动化检测工具大量使用，手动监测工作依然大量存在</span>。87%的受访者使用了自动化辅助工具去检测威胁，但同时有66%的受访者表示他们还在开展人工的监测工作。此外，38.9%的受访者表示他们使用了AI和ML技术去检测威胁。</span></section><section style="text-align: center;" nodeleaf=""><img data-imgfileid="100001172" class="rich_pages wxw-img" data-ratio="0.6591230551626591" data-s="300,640" data-type="png" data-w="707" style="width:448px;height:295px;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=bf20df03&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMfBRLUUIFWwdBZMZve7EibYgxhy0gqmQhlnHrcEUicereSZAJGbkicnrHSDglpLXRicNoPicAYGToqZjQQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section><section><span leaf="">2）<span textstyle="" style="font-weight: bold;">EDR/XDR被认为是最有效的检测工具，威胁猎捕次之，认为AI/ML无效的比率最高。</span>42%的受访者认为EDR/XDR十分有效，这与界内的EDR发展趋势相符，即威胁检测最关键的环节是端点【<span textstyle="" style="color: rgb(0, 82, 255);">笔者注：譬如美国联邦政府在吃了几次亏以后强制要求部署EDR</span>】。而XDR作为EDR的扩展，进一步增强了检测的效果。有意思的是，威胁猎捕团队以29.8%的十分有效率位居EDR/XDR之后，超过了SIEM。<span textstyle="" style="color: rgb(0, 82, 255);">笔者认为，这至少表明，以人为主的威胁猎捕工作证明了人在威胁检测中的独特价值，也间接表明在自动化和AI大行其道的未来，人的工作依然占有一席之地</span>。此外，AI/ML工具还需要进一步深化和演进。</span></section><section style="text-align: center;" nodeleaf=""><img data-imgfileid="100001173" class="rich_pages wxw-img" data-ratio="0.8707865168539326" data-s="300,640" data-type="png" data-w="712" style="width:448px;height:390px;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=25a0fd69&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMfBRLUUIFWwdBZMZve7EibYg0mgmfCtvVXbHxvS7dgTEsk3LX3oHxOiarQic1rSrTpIdfT6cspMLxECg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section><section><span leaf="">3）<span textstyle="" style="font-weight: bold;">针对AI和ML应用于检测的进一步调研中，超过一半（51.2%）的人表示用到了AI和ML，但应用程度还不够深入</span>。调查显示，只有25.3%的人表示在检测过程中深入使用了AI和ML能力。近22%的人表示仅仅使用了AI和ML的最小（基本）能力。</span></section><section style="text-align: center;" nodeleaf=""><img data-imgfileid="100001174" class="rich_pages wxw-img" data-ratio="0.387037037037037" data-s="300,640" data-type="png" data-w="1080" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=358d8e86&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMfBRLUUIFWwdBZMZve7EibYgxTjZCkCtDjthgz27kibHj8gU45tJZh7K0fMDU4F2Uj8v27Zvm5swvjw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section><section><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">【笔者注】在2024年9月，SANS单独发布了一份《AI调研报告》，专门对AI在网络安全中扮演的角色进行了分析。在那个报告中，SANS表示，AI在网络安全的应用领域基本都聚焦在了安全运营上。进一步分析，主要就应用在检测与响应（譬如排在前四位的异常检测、恶意代码检测、自动化事件响应、告警富化）。</span></span></section><section style="text-align: center;" nodeleaf=""><img data-imgfileid="100001181" class="rich_pages wxw-img" data-ratio="0.6540880503144654" data-s="300,640" data-type="png" data-w="795" style="width:471px;height:308px;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=52ca1bf2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMfu5UFByDSCYOoOFKgGqyp9FZGHcUpia1JfGLoWWFcTqjE4aQaHCLIryibbkS0v9kVIzFRibYglt9JYg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section><section><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">报告同时显示，AI在安全运营领域最大的价值在于改进了威胁检测，其次是事件响应。</span></span></section><section style="text-align: center;" nodeleaf=""><img data-imgfileid="100001183" class="rich_pages wxw-img" data-ratio="0.5308310991957105" data-s="300,640" data-type="png" data-w="746" style="width:462px;height:245px;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=1502a63f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMfu5UFByDSCYOoOFKgGqyp9CQgJKzaSQsdicl9icuRw186Vbt05wrBeXBOlg4N8KSNOhHexXnT8iatGA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section><section><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">另一方面，这份《AI调研报告》也提及了AI在检测与响应领域应用时存在缺陷。主要的缺陷包括：AI检测也会产生误报、严重依赖受训练数据、检测新型威胁效果不佳（主要还是受训数据的问题）。</span></span></section><section style="text-align: center;" nodeleaf=""><img data-imgfileid="100001182" class="rich_pages wxw-img" data-ratio="0.9171717171717172" data-s="300,640" data-type="png" data-w="495" style="width:287px;height:263px;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=f6ba2bf4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMfu5UFByDSCYOoOFKgGqyp9Ey6rN9RGqOL4fC8xfibYShMUCYTYbCtLmyomfMZYYymfPEL7T9rJCiaQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section><section><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">最后，这份报告还给出了AI应用于网络安全领域的6大误区，其中第一大误区就是以为AI将完全取代人类。</span></span></section><section style="text-align: center;" nodeleaf=""><img data-imgfileid="100001184" class="rich_pages wxw-img" data-ratio="0.4765258215962441" data-s="300,640" data-type="png" data-w="852" style="width:465px;height:222px;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=19b66955&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMfu5UFByDSCYOoOFKgGqyp9YjfwzK6a1cgxNwAia7fKAURaSK0kurxgGEjZI9XovhIJD50ZGpSt3jA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section><section><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">正如笔者在《</span><a href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484766&amp;idx=1&amp;sn=5b66715c108908d39eb92ecdc964c9f6&amp;scene=21#wechat_redirect" textvalue="从RSAC2024看SOC发展趋势" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">从RSAC2024看SOC发展趋势</a><span textstyle="" style="color: rgb(0, 82, 255);">》和《</span><a href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484795&amp;idx=1&amp;sn=8f835c0699be66f615e7b713f67e26dc&amp;scene=21#wechat_redirect" textvalue="从Gartner2024年北美安全峰会看安全运营的技术趋势" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">从Gartner2024年北美安全峰会看安全运营的技术趋势</a><span textstyle="" style="color: rgb(0, 82, 255);">》中写到的那样，AI（包括GenAI）的价值（至少从中期来看）在于赋能人类、增强人类，而非取代人类。</span></span></section><section><span leaf="">4）调研显示，<span textstyle="" style="font-weight: bold;">展望未来，人们普遍对AI和ML增强威胁检测寄予厚望</span>。67%的受访者表示要增强这方面的应用，人们越发认识到AI和ML在增强安全自动化和提升威胁检测准确性方面的潜力，25%受访者表示不确定，处于观望状态，而只有8%的受访者表示不计划对AI和ML的采用。</span></section><section><span leaf="">5）展望未来，除了AI和ML，<span textstyle="" style="font-weight: bold;">其它拟应用的先进技术还包括：行为分析（83%）、（部分）自动化威胁猎捕（64%）、预测分析（60%）、高级关联引擎（56%）</span>。</span></section><section><span leaf="">6）<span textstyle="" style="font-weight: bold;">针对云中的威胁（主要是针对IaaS、SaaS和FaaS的）检测，认为最有效的还是云原生工具</span>，第三方工具次之，自研工具排第三。</span></section><section><span leaf="">7）<span textstyle="" style="font-weight: bold;">检测内容（规则）的主要来源</span>依次是：威胁情报平台（65%）、内部团队自行开发（62%）、安全供应商（59%）、政府主管机构（57%），以及开源社区（46%）。而在<span textstyle="" style="font-weight: bold;">获取这些检测内容时面临的挑战方面</span>，首要的是内容（规则）的质量和可靠性（73%），其次是兼容性（55%）、信息过载（54%）、缺乏检测相关的上下文（50%）。相反，<span textstyle="" style="font-weight: bold;">在对外分享自己的检测内容（规则）时</span>，只有39%的受访者表示做到了。同时，他们分享的动机主要（68%）是为了更好地获得对方的检测内容。</span></section><section><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">事件响应</span></span></section><section><span leaf="">1）<span textstyle="" style="font-weight: bold;">大部分（67.8%）组织的事件响应过程都是半（部分）自动化的</span>，但也有不小（22.7%）的组织依然采用手工过程。</span></section><section style="text-align: center;" nodeleaf=""><img data-imgfileid="100001176" class="rich_pages wxw-img" data-ratio="0.6699576868829337" data-s="300,640" data-type="png" data-w="709" style="width:451px;height:302px;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=33f3eed9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMfBRLUUIFWwdBZMZve7EibYgZPEfiapp9t0gTMjdqQKHicF70QUSoePj8DwBsAJf2L8sMTakEmWVSZJw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section><section><span leaf="">2）<span textstyle="" style="font-weight: bold;">最基本的响应工具是EDR（81.8%），其次是SOAR（60.5%）</span>。此外，依然还有50.4%的组织还在采用手工方式连接系统、手动运行各种指令。此外，对于NDR的响应能力，具有其独特的功效，可以与EDR互补使用。</span></section><section style="text-align: center;" nodeleaf=""><img data-imgfileid="100001177" class="rich_pages wxw-img" data-ratio="0.47503045066991473" data-s="300,640" data-type="png" data-w="821" style="width:456px;height:217px;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=d7da6474&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMfBRLUUIFWwdBZMZve7EibYgtqdTTvCZSuvEUEH2iamhAyWs1UN9saQSenP8FmricmZxSYEPS7DTl5RQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section><section><span leaf="">3）<span textstyle="" style="font-weight: bold;">对已确认威胁的响应时长主要（41.4%）集中在分钟级，其次（32.6%）在小时级</span>。总体上，83%的受访组织事件响应时长在秒级到小时级之间。SANS对这个结果表示满意。<span textstyle="" style="color: rgb(0, 82, 255);">笔者认为，可以看出，要想进一步缩短响应的时长，自动化是必然的路径，而智能化则是对自动化的再加速</span>。</span></section><section style="text-align: center;" nodeleaf=""><img data-imgfileid="100001178" class="rich_pages wxw-img" data-ratio="0.5669481302774427" data-s="300,640" data-type="png" data-w="829" style="width:452px;height:256px;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=8a8a78db&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMfBRLUUIFWwdBZMZve7EibYgIETqhRViciazx2icPdqcyR7DpHXYXGc8yPhVHibahlptzZRxTBaYYCqiclQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section><section><span leaf="">4）<span textstyle="" style="font-weight: bold;">64%的受访者表示他们的安全运营部分集成了自动化响应工具/系统</span>，16%的受访者则表示他们完全实现了这类集成，但还有15%的受访者表示没有任何这方面的集成。</span></section><section><span leaf="">5）<span textstyle="" style="font-weight: bold;">自动化的检测到响应工作流程的最常用策略是预定义的剧本</span><span textstyle="" style="color: rgb(0, 82, 255);">【笔者注：非特指机读剧本）】</span>— 74% 的受访者使用它们来标准化和简化响应操作。64%的受访者采用自定义的集成和自动化脚本，62%的受访者采用SOAR工具，还有35%的受访者表示采用了AI技术。</span></section><section><span leaf="">6）<span textstyle="" style="font-weight: bold;">在自动化的检测到响应工作流程领域，对于未来的首要事项，68%的受访者表示将加强剧本，65%计划提升SOAR工具的集成，52%计划定制自动化脚本</span>。此外，还有38%的受访者表示计划采购新的开箱即用的集成化解决方案<span textstyle="" style="color: rgb(0, 82, 255);">（譬如XDR）</span>。</span></section><section><span leaf="">7）<span textstyle="" style="font-weight: bold;">在威胁响应优先级方面，首要（41%）考虑的因素是威胁的严重性级别</span>，其次（29%）是对业务的影响程度，第三是受影响的资产类型。</span></section><section><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">检测与响应团队架构</span></span></section><section><span leaf="">调查显示，<span textstyle="" style="font-weight: bold;">将检测与响应职能放到一个团队的比例和将检测与响应职能拆分到两个不同团队的比例相当</span>（都是48%），并且有48%的受访者对当前组织结构设置表示十分满意或满意。这表明，对于检测与响应团队的设置方式没有绝对的好与坏，各有利弊，主要还是要结合组织自己的实际。</span></section><section><span leaf=""><span textstyle="" style="font-weight: bold;">对于未来，近50%的受访者倾向于采用混合式的团队结构，即综合整合式单一型团队团队和专业化分工型团队两种形态</span>。而希望建立分工型团队的受访者比例略高于希望建立整合型团队的受访者。</span></section><section><span leaf=""><span textstyle="" style="color: rgb(0, 82, 255);">笔者发现，放眼国内，当前主流的威胁检测与响应团队大都采用分工型组织，在工作职责上大都分为监测组、研判组、处置组，或者类似地划分出一线运营人员和二线运营人员，通过专业化、层次化的分工和操作规程串联起完整的威胁检测与响应过程。这种方式是否就是最佳？尤其是在人员不足的情况下，会显得捉襟见肘。同时这种分工在某种程度上也给初级的运营人员设置了一个无形的天花板，容易造成职业倦怠。那么，还有其它选择吗？什么时候可以，以及如何采用整合型团队或者混合型团队呢？对此，国外同行们进行了不少实践。譬如，Google的Anton Chuvakin基于SRE（站点可靠性工程）提出了整合型威胁检测与响应团队的思路，而Forrester的Allie Mellen基于检测工程（DE）的生命周期理论也提出了整合型团队的设计思路。另一方面，随着包括威胁检测与响应在内的安全运营工具的智能化、自动化和体验水平的不断提升，也为更高效的团队架构设计提供了支撑。</span></span></section><section><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">威胁检测与响应预算</span></span></section><section><span leaf=""><span textstyle="" style="font-weight: bold;">42%的受访者认为其威胁检测与响应的预算紧张</span>，21.5%表示不足。对于未来，42%的受访者预计预算会适度增长。<span textstyle="" style="color: rgb(0, 82, 255);">这个结果，对国内适用吗？不得而知。</span></span></section><section style="text-align: center;" nodeleaf=""><img data-imgfileid="100001179" class="rich_pages wxw-img" data-ratio="0.661849710982659" data-s="300,640" data-type="png" data-w="692" style="width:460px;height:304px;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=ad7c20e3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMfu5UFByDSCYOoOFKgGqyp9icBakaOLVtJFbgy9x9eIlaI2hFIToIiaSa4ibxpHHSELjiaR1BSaozsG9A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section><section><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">检测与响应团队绩效度量</span></span></section><section><span leaf="">1）<span textstyle="" style="font-weight: bold;">度量检测与响应团队的绩效对于向领导层阐释网络安全工作的价值和有效性至关重要，组织基本上都建立了自己的KPI指标体系</span>。其中，67%的受访者采用了MTTR（平均响应时长），52%采用了MTTD（平均检测时长），其它关键指标还包括检测的事件数量（64%）、解决的事件数量（58%）。</span></section><section><span leaf="">2）<span textstyle="" style="font-weight: bold;">针对这些指标，大家对其有效性的评价普遍不高</span>。只有26%的受访者认为他们的指标很有效，还有39%的受访者认为他们的指标有效性一般般，依然存在较大改善空间。此外，51%的人认为他们在获取指标所需数据方面面临挑战。</span></section><section><span leaf="">3）<span textstyle="" style="font-weight: bold;">与行业标杆进行对标分析（benchmarking）为度量指标（KPI）提供了更丰富的价值，因为对标分析可以让组织了解自身在同行中的水平</span>。调研显示，仅有23%的组织实现了这项工作的常态化。<span textstyle="" style="color: rgb(0, 82, 255);">笔者认为，随着指标度量的深化，对标分析意义越发凸显。否则，组织只能跟自己的过去比，无法进行同行间的比较，不知道行业的发展水平，不知道某个指标值多少才是好，多少才是差，可能还在为自己取得的“成绩”沾沾自喜，或者花费了过多的精力试图在低效的方向上进行改进</span>。</span></section><section><span leaf="">4）<span textstyle="" style="font-weight: bold;">掌握并度量检测覆盖情况对于旨在保持稳健安全姿态的组织至关重要。调查显示，大部分（64%）的组织会主动评估自己的检测覆盖和能力</span>，但还有23%的组织没有做这个工作。如果不做常态化的检测覆盖评估，组织防御的盲点风险就高。<span textstyle="" style="font-weight: bold;">74%的受访者采用ATT&amp;CK框架来进行检测覆盖评估</span>，采用威胁情报报告的比例是72%，采用攻击测试方式的比例是62%。</span></section><section><span leaf="">5）调查显示，<span textstyle="" style="font-weight: bold;">不同组织的度量周期差异较大</span>。29%的受访者表示他们每月评估一次（SANS认为这个频次有点低），每天评估的有9%，<span textstyle="" style="font-weight: bold;">每周评估的有22%</span>（SANS认为这个频次的性价比比较高），还有14%表示每个季度评估一次。</span></section><section><span leaf="">6）<span textstyle="" style="font-weight: bold;">在度量指标改进提升方面</span>，54%的受访者选择了实时监测能力，52%选择了高级分析与报告工具，50%选择了更好与其它安全工具集成，49%选择了常态化技能培训与评估，48%选择了采用更好的度量指标。</span></section><section><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">面临的挑战</span></span></section><section><span leaf="">1）调查显示，<span textstyle="" style="font-weight: bold;">误报（FP）是检测网络威胁过程中面临的最大挑战</span>，近64%的受访者做出了这个选择，排在挑战第二位的是数据量问题。<span textstyle="" style="color: rgb(0, 82, 255);">笔者看来，误报直接导致告警疲劳，降低安全事件响应效率，浪费了响应人员的宝贵时间，引发职业倦怠</span>。</span></section><section style="text-align: center;" nodeleaf=""><img data-imgfileid="100001180" class="rich_pages wxw-img" data-ratio="0.53125" data-s="300,640" data-type="png" data-w="736" style="width:460px;height:244px;" type="block" src="https://wechat2rss.xlab.app/img-proxy/?k=3cc6234c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMfu5UFByDSCYOoOFKgGqyp91lUJ0jMLic2OAS74cAiasQ2O8S1xrsbib6hZzGdRNphW3Pr9B2MCIxVibg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></section><section><span leaf="">2）<span textstyle="" style="font-weight: bold;">在威胁有效的检测与响应能力方面，组织面临的最大挑战是预算制约</span>（47%），其次是人才选育留、技术限制、合规要求。</span></section><section><span leaf=""><span textstyle="" style="font-size: 20px;font-weight: bold;">总结</span></span></section><section><span leaf="">1）<span textstyle="" style="font-weight: bold;">威胁检测与响应过程的自动化至关重要</span>，82%的受访者使用了EDR，以及67%的组织使用了半自动化的响应系统证明了这一点。与此同时，<span textstyle="" style="font-weight: bold;">人在检测与响应过程中的作用必将越来越重要</span>，不要期待100%的自动化，而<span textstyle="" style="font-weight: bold;">要不断平衡人与自动化之间的任务分工</span>。</span></section><section><span leaf=""><span textstyle="" style="font-weight: normal;">2）</span><span textstyle="" style="font-weight: bold;">人们对AI有较大的期待，但当前AI的效果还有待提升</span>。</span></section><section><span leaf="">3）近一半的受访者表示<span textstyle="" style="font-weight: bold;">预算不足是他们保持有效检测和响应能力的最大障碍</span>。<span textstyle="" style="color: rgb(0, 82, 255);">笔者认为，放眼国内，在经济增速放缓的大背景下，安全投资增速必定也受到影响，如何盘活存量安全投资将越发重要，而盘活的关键就在于提升安全运营的效益。另一方面，网络安全与数据安全的法律法规和监管要求仍然在持续提升。这就要求包括检测与响应在内的安全运营更加高效，更加能够证明其价值。</span></span></section><section><span leaf="">4）<span textstyle="" style="font-weight: bold;">误报（FP）是检测网络威胁过程中面临的最大挑战。</span><span textstyle="" style="font-weight: normal;">短期内，应优化检测内容（规则），并要求供应商改进以减少误报。</span></span></section><section><span leaf=""><span textstyle="" style="font-weight: normal;">5）</span><span textstyle="" style="font-weight: bold;">对更全面的DR度量指标和更好地集成安全工具的需求</span>凸显了该领域不断发展的格局，组织必须不断调整其策略以应对内部和外部压力。</span></section><section><span leaf="">6）当组织展望未来时，人们清楚地认识到投资于高级检测和响应功能的重要性，<span textstyle="" style="font-weight: bold;">重点关注增加 AI 和 ML 的使用，改进与 SOAR 工具的集成，并加强培训计划以建立内部专业知识</span>。</span></section><section><span leaf=""><span textstyle="" style="font-weight: bold;">【参考资料】</span></span></section><section><span leaf=""><a href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484725&amp;idx=1&amp;sn=8d318b47e9dced09f5862dda65427ad6&amp;scene=21#wechat_redirect" textvalue="SANS：2023年事件响应调查报告" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">SANS：2023年事件响应调查报告</a></span></section><section><span leaf=""><a href="https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484811&amp;idx=1&amp;sn=18c651844e9668dd2ffa2f32db674f8c&amp;scene=21#wechat_redirect" textvalue="SANS 2024年SOC调查报告解读" data-itemshowtype="0" target="_blank" linktype="text" data-linktype="2">SANS 2024年SOC调查报告解读</a></span></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484836">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=069ef26d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyNzMxOTAwMw%3D%3D%26mid%3D2247484836%26idx%3D1%26sn%3D05ff688d9865a0d5bc38815a37d63725%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 19 Dec 2024 12:00:00 +0800</pubDate>
    </item>
    <item>
      <title>SOAR的未来</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484818&amp;idx=1&amp;sn=1966e121ac2e4f4dacda712854534d0c</link>
      <description>SOAR已死？中国SOAR市场未来如何？</description>
      <content:encoded><![CDATA[<p>
原创 <span>Benny Ye</span> <span>2024-09-18 12:00</span> <span style="display: inline-block;">北京</span>
</p>

<p>SOAR已死？中国SOAR市场未来如何？</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=cfcd1abd&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMdGGBNqwIOIXXkLzRcrxicgT5iaCib3RhbA18mAqLCGubGW64ZrsuRXEnx0VoSibS4kJpiagUcRysJSbhA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><strong><span style="font-size: 20px;">Gartner一句“SOAR已过时”引发热议<br/></span></strong></p><p>2024年7月底，Gartner发布了2024年度的安全运行（SecOps）技术与服务成熟度曲线（Hype Cycle）。报告中，Gartner正式表示SOAR“已经过时（obsolete）”，进而在业内引发热议。</p><p><em>之前主打SOAR现在改打“安全自动化”的厂商Swimlane的CEO James Brear在X上表示：“任何有关SOAR已死的提法都是我听过的最愚蠢（dumbest）的事情——绝对愚蠢（absolutely asinine）”</em></p><p><em>IBM产品管理副总裁及SOAR产品Resilient（被IBM收购）的联合创始人Ted Julian在Linkedin上愤怒的表示：“鉴于Gartner正在取消SOAR，我要……取消Gartner”。Ted更是直言Gartner的分析和业务模式已经过时。</em></p><p><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">而针对Ted在Linkedin上的发言，有人赞同有人反对。有人表示，这对于正在进行下一代SOAR（AI SOAR）创业的公司来说是一个打击【笔者：换个名字不就好了】。<br/></span></p><p><em><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">D3 Security的一位产品市场经理表示，尽管Gartner将SOAR归为过时产品，并且出现了一些不再使用SOAR缩写的新SOAR公司，但SOAR市场仍在增长，并估计每年有超过10亿美元的交易，这说明SOAR有市场。</span></em><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;"><br/></span></p><p><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">这类声音的核心意思是认为SOAR技术依然存在，虽然遇到很多问题，但依然有其市场空间，并且还在不断改善和演进。</span></p><p><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">还有不少公司也在官网博客上发表观点，赞同Gartner的观点，并为自己的产品打Call。<br/></span></p><p><em><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">号称下一代SOAR（超级自动化）的厂商Torq表示，“SecOps专业人员对过时的、传统的SOAR产品深感不安”，“基于GenAI的安全自动化是现代企业的发展方向”，然后表示自己的产品代表SOAR的未来。<br/></span></em></p><p><em><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">标榜“安全自动副驾”Blink表示，“SOAR已经过时”，“网络安全的重点显然正在转向更先进的自动化工具，尤其是那些由GenAI驱动的工具”。<br/></span></em></p><p><em><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">StrikeReady的首席客户官表示，“SOAR就不是一个产品类别”，“作为一个功能集合，它早就失败了”，然后就给自己的产品打Call。</span></em><em style="font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></em></p><p><span style="font-size: var(--articleFontsize);letter-spacing: 0.578px;">网络上，还有很多“XX已死，XX永生”的言论。</span></p><p><em>Google云安全首席营销官及前Siemplify首席营销官Nimmy Reichenberg则表示赞同Gartner关于SOAR已经过时的提法，认为SOAR已经是大多数安全运营平台的一部分，不再值得作为独立产品类别了，就像以前的UEBA那样，并不是说不需要SOAR了，而是演变成了大平台的功能。</em></p><p><em>Exabeam首席战略官及前Gartner分析师Gorka Sadowski发表了一篇题为《SOAR已死，SOAR永生》的文章，提及了SOAR的起源、繁荣和当前遇到的困境，表示SOAR就跟UEBA一样，作为独立市场基本消失，更多融入到了其它市场（譬如SIEM）中。他写道：“是否还需要独立SOAR工具？有时需要，但更多组织可以利用他们技术栈中已有工具的SOAR功能，尤其是SIEM和CloudSec工具。”</em><br/></p><p><em><em style="letter-spacing: 0.578px;white-space: normal;">Sumo Logic的Field CTO Chase Clawson表示，SOAR功能已经迁移到各种安全产品之中。</em></em></p><p>在Linkedin上也有不少类似的声音。其核心思想就是说，SOAR技术本身并未过时，SOAR还是很有价值的，否则为什么Gartner的这份Hype Cycle依然详细分析了SOAR技术，并明确给出了他的价值，以及用户应该如何选购SOAR的建议？Gartner想要表达的主要是独立SOAR市场已经过时了。<br/></p><p><span style="color: rgb(255, 0, 0);"><strong>对于SOAR已过时的论断，各位读者怎么看？欢迎参与小调研，或者留言交流。</strong></span><br/></p><section class="mp_vote_iframe_wrp"><mp-common-vote class="js_editor_vote_card js_uneditable custom_select_card mp_vote_iframe" data-pluginname="mpvote" data-supervoteid="467493610" data-logincheckfailed="0" data-expiretime="0" data-votesubject="[{&#34;type&#34;:1,&#34;title&#34;:&#34;您认为SOAR已经过时了吗？&#34;,&#34;options&#34;:[{&#34;name&#34;:&#34;SOAR已经过时（现在SOAR存在很多问题，应该被新的技术所取代）&#34;,&#34;url&#34;:&#34;&#34;,&#34;cnt&#34;:0},{&#34;name&#34;:&#34;SOAR没有过时（现在SOAR虽然存在不少问题，但依然有独立存在的价值，并且其技术正在演进，譬如利用GenAI等技术）&#34;,&#34;url&#34;:&#34;&#34;,&#34;cnt&#34;:0},{&#34;name&#34;:&#34;SOAR将被整合（现在独立SOAR机会不大，但作为一个有价值的自动化能力，应该整合到SIEM/SOC平台等技术中去）&#34;,&#34;url&#34;:&#34;&#34;,&#34;cnt&#34;:0},{&#34;name&#34;:&#34;都是概念炒作，无所谓过时不过时，关键是安全自动化技术如何有效的提升安全运营效率&#34;,&#34;url&#34;:&#34;&#34;,&#34;cnt&#34;:0},{&#34;name&#34;:&#34;其它&#34;,&#34;url&#34;:&#34;&#34;,&#34;cnt&#34;:0}],&#34;total_cnt&#34;:0}]" data-delflag="0" data-fail="0"></mp-common-vote></section><p><span style="color: rgb(255, 0, 0);"></span></p><p><strong><span style="letter-spacing: 0.578px;">在深入讨论</span><span style="letter-spacing: 0.578px;">SOAR是否已死之前，</span><span style="letter-spacing: 0.578px;">让我们先</span><span style="letter-spacing: 0.578px;">回顾一下SOAR的发展历程，当前面临的困境和市场格局，以及发展趋势。</span></strong></p><p><span style="font-size: 20px;"><strong>SOAR的发展历程</strong></span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></p><p>Gartner在<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484584&amp;idx=1&amp;sn=ec647bae8b71e4f2a4d68603b8aade00&amp;chksm=fa002e1ccd77a70ae712591a9b745f5dd4f82aee5fe7959fd63e6ef641e5d5d7952576cf5309&amp;scene=21#wechat_redirect" textvalue="2015年发明了SOAR这个术语，并在2017年正式确立了现代SOAR的定义" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">2015年发明了SOAR这个术语，并在2017年正式确立了现代SOAR的定义</a>。<br/></p><p>目前，SOAR的最新定义是：</p><p><span style="font-family: 宋体;font-size: 16px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">SOAR是一个将事件响应、编排和自动化以及威胁情报管理功能组合成的单一解决方案。SOAR 工具可用于许多安全运营任务，例如记录并实施流程，支持安全事件管理，向人类安全分析师和操作员提供基于机器的协助，以及更好地实现威胁情报实战化。</span></p><p>根据Gartner的定义，SOAR是包含<span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;text-indent: 28px;background-color: rgb(255, 255, 255);">安全编排与自动化（SOA， Security Orchestration and Automation）、安全事件响应平台（SIRP, Security Incident Response Platform）和威胁情报平台（TIP, Threat Intelligence Platform）的三合一解决方案，主要旨在解决安全运营（SecOps）的事件响应环节的自动化和闭环，捎带进行自动化的威胁情报管理与利用，后来又发展到可以自动化处理安全运营各个环节的任务。</span><br/></p><p><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;text-indent: 28px;background-color: rgb(255, 255, 255);">在SOAR之前，安全运营人员先是借助自定义的脚本实现原始的自动化，后来又借助<span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 28px;background-color: rgb(255, 255, 255);">IT运营自动化工具，</span>以及<span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 28px;background-color: rgb(255, 255, 255);">RPA等面向跨系统工作流程的通用自动化平台</span>。而SOAR正是基于之前这些实践基础上专门面向安全运营的自动化技术。</span></p><p><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;text-indent: 28px;background-color: rgb(255, 255, 255);">在SOAR技术处于Gartner技术成熟曲线炒作高峰的那段时间，人们对SOAR的期待很高，给人感觉SOAR自动化能力“没有上限”。</span></p><p><span style="font-size: 20px;"><strong>SOAR面临</strong></span><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;text-indent: 28px;background-color: rgb(255, 255, 255);"><strong style="font-size: 20px;letter-spacing: 0.578px;white-space: normal;">的困境</strong></span></p><p><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;text-indent: 28px;background-color: rgb(255, 255, 255);">随着SOAR实践的深入，SOAR暴露的问题也越来越多。</span></p><p><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;text-indent: 28px;background-color: rgb(255, 255, 255);">首先，人们再次认识到安全运营作为一种人、技术和流程相结合的产物，不存在技术上的银弹。SOAR技术也一样，它严重依赖组织的安全运营流程和规程，需要投入资源进行剧本的设计与开发，并要持续投入。人们发现，对于中小型组织或者安全运营成熟度不高的组织而言，上SOAR的投入产出比可能不高。</span></p><p><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;text-indent: 28px;background-color: rgb(255, 255, 255);">其次，基于预置剧本的编排更适合那些机械式重复的、相对简单和固化的工作任务的自动化。对于一些复杂的、时常变化的工作过程，采用剧本编排则很容易陷入无止尽的开发、修改过程之中。而不幸的是，网络安全领域的攻防变化太快，响应过程分支情况太多。</span></p><p><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;text-indent: 28px;background-color: rgb(255, 255, 255);">再次，与各类第三方系统和工具的对接和集成也成为了制约SOAR发展的瓶颈。</span></p><p><span style="font-size: 20px;"><strong><span style="font-size: 20px;font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 28px;background-color: rgb(255, 255, 255);">SOAR的演进</span></strong></span></p><p><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;text-indent: 28px;background-color: rgb(255, 255, 255);">为了应对上述挑战，SOAR厂商们也在尽力改善。当前，所谓的“下一代SOAR”的主要功能都反映在如何改善上述问题上。现在的“下一代SOAR”主要有两个发展方向。一个是向所谓“超自动化SOAR”方向发展（譬如Torq），旨在将安全编排自动化技术的应用领域向安全运营之外扩展，成为通用安全自动化工具。同时，充分采用低代码-无代码开发技术，降低剧本开发难度和成本。此外，预先开发好大量第三方应用接口，并内置大量剧本模板，再以应用市场和社区的形式进行发布，降低用户的使用门槛。另一个发展方向则是“AI SOAR”或“AI SOC助理”（譬如DropZone.AI），使用GenAI技术实现一个“网络AI助理”，用智能化改造基于剧本的编排自动化。</span></p><p><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;text-indent: 28px;background-color: rgb(255, 255, 255);">此外，SOAR厂商们也逐步总结了一套剧本设计开发的方法论，并不断将SOAR的价值聚焦到基于剧本的编排技术能够驾驭的应用场景上去。</span></p><p><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;text-indent: 28px;background-color: rgb(255, 255, 255);"><strong><strong style="font-size: 20px;letter-spacing: 0.578px;white-space: normal;"><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 28px;background-color: rgb(255, 255, 255);">SOAR市场格局</span></strong></strong><br/></span></p><p><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;text-indent: 28px;background-color: rgb(255, 255, 255);">在SOAR技术不断演进的同时，SOAR市场格局也经历了巨变。</span></p><p><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;text-indent: 28px;background-color: rgb(255, 255, 255);">从安全运营的角度来看，正是由于自动化和响应如此重要，<span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 28px;background-color: rgb(255, 255, 255);">响应技术（包括自动化响应）已经不再是SOAR的专属。</span>检测类产品纷纷布局响应，出现了各种DR（检测与响应）类产品，从NDR、EDR到后来的XDR，纷纷<span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-indent: 28px;background-color: rgb(255, 255, 255);">内置（简化的）SOAR能力</span>。而作为SOC核心的SIEM产品也在朝TDIR方向前进，大力发展响应自动化技术，并成为SOAR厂商的最大买家群体。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-imgfileid="100001169" data-ratio="0.35" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=97787d37&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcclMcHAuIVBMek9aULhLiceySRJXsVpFOkD9O1RBQl5HaY3m9XiciccfsicoeOKYvuEiauYqicXibaAWd6Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 16px;letter-spacing: 0.544px;text-indent: 28px;background-color: rgb(255, 255, 255);">如上图所示，入围Gartner2024年SIEM魔力象限的所有SIEM厂商都有SOAR，要么自研，要么收购（主要方式），要么是SIEM产品中的一个模块，要么是SIEM产品套件中的一个子产品。<br/></span></p><p>Gartner在<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484685&amp;idx=1&amp;sn=2fe383d8335d300614f748ee7f91ceb7&amp;chksm=fa002fb9cd77a6af55094c6484ef13c2e8faa85e5e5536d9c371eed9fd1933c8bee6526b9252&amp;scene=21#wechat_redirect" textvalue="2023年的SOAR市场指南报告" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">2023年的SOAR市场指南报告</a>中就指出，SOAR整合到各种TDIR类产品中的趋势已经十分明显。</p><p><img class="rich_pages wxw-img" data-imgfileid="100001166" data-ratio="0.6565934065934066" data-w="728" src="https://wechat2rss.xlab.app/img-proxy/?k=5d40f2fa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMfzYw8Jc8c9ibKGCKQjBgQ5m0vRAQDpUXF0Pox3k0a1P7CPRyozv33hmewqowkcBx0LR92dxvVQq8Q%2F640%3Fwx_fmt%3Dother%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></p><p><span style="font-size: 20px;"><strong>Gartner的观点解读</strong></span></p><p>对SOAR进行了全面审视之后，我们再回过头来研究Gartner的观点。</p><p>在2024年2月份的时候，笔者跟Gartner分析师Pete Shoard进行了一次Inquiry，当时就询问他对SOAR未来的看法，SOAR市场是否会消失。<span style="letter-spacing: 0.578px;">Shoard</span>当时就委婉的表示，SOAR将更多的融入SIEM中，但独立SOAR还存在于某些缝隙（niche）市场。同时，<span style="letter-spacing: 0.578px;">Shoard</span>表示Gartner对GenAI应用于安全（包括SOAR）持审慎态度。笔者理解，GenAI作为革新SOAR或者安全自动化的技术还有较长的路要走。</p><p>今年8月份，Dark Reading对Gartner的SOAR过时论点进行了专门的文章报道。文章引述了<span style="letter-spacing: 0.578px;">Gartne</span><span style="letter-spacing: 0.578px;">r SecOps </span>Hype Cycle报告中SOAR词条的主笔分析师Eric Ahlm的话。他表示，将SOAR标记为过时是因为该类产品的组件已经被其它产品和服务所取代。当前，自动化越来越成为一种众人期待的功能，SOC需要编排作为一项单独的功能，将分散的产品集成到单一的运营中心。同时，由于企业客户越来越倾向于简化运营，因而供应商纷纷将SOAR与他们的产品和服务进一步整合到一起。Ahlm进一步表示，<span style="letter-spacing: 0.578px;">Gartner真正要传递的信息，<span style="letter-spacing: 0.578px;"></span><span style="letter-spacing: 0.578px;">不是</span><span style="letter-spacing: 0.578px;">说SOAR</span><span style="letter-spacing: 0.578px;">这个概念</span><span style="letter-spacing: 0.578px;">过时</span><span style="letter-spacing: 0.578px;">或者</span><span style="letter-spacing: 0.578px;">自动化已经</span><span style="letter-spacing: 0.578px;">终结</span><span style="letter-spacing: 0.578px;">，而是</span></span>有很多不同的方法可以增加自动化（以提升效率、扩大规模），而无需去购买独立的SOAR平台。</p><p><strong>总结一下，笔者认为Gartner的观点是：</strong></p><p><span style="color: rgb(0, 82, 255);">基于三方面原因——1）随着自动化技术越来越渗透到各类安全产品（尤其是SIEM）中，独立SOAR厂商和产品越来越少；2）SOAR自身面临各种落地障碍，需要将SOAR与其它产品能力相结合来化解其中的一些障碍；3）用户对于供应商和产品能力整合的呼声越来越高——Gartner呼吁用户更多考虑在SIEM等其它SOC核心产品平台中考虑使用SOAR功能，而不要使用独立SOAR。因此，Gartner将SOAR标记为过时，独立SOAR产品将不再是主流产品，独立SOAR市场将逐步萎缩，仅存在于某些缝隙市场，但SOAR技术将在其它产品和市场中继续发展演进。</span><br/></p><p>顺便提一下，笔者在8月份的时候，针对SOAR的未来发展趋势也咨询了Forrester的分析师Allie Mellen。她表示，独立SOAR依然会存在，但它也会变成更广泛产品的一个能力，因为越来越多的客户在购买其它产品时都会需要这个自动化的能力。对于SOAR未来技术趋势，她认为除了GenAI之外，还要关注低代码-无代码能力，以及诸如案例管理、协作管理等安全运营功能。<br/></p><p><span style="font-size: 20px;"><strong>SOAR在中国的未来</strong></span></p><p>那么，中国SOAR市场未来走势如何？<span style="color: rgb(255, 0, 0);"><strong>笔者认为，其实在国内尤其更加需要独立SOAR产品。</strong></span>因为当前国内大部分客户的SOC/SIEM平台都不具备SOAR能力。在用户彻底更换为下一代具有SOAR功能的SOC平台之前，还需要购买独立SOAR来弥补现有平台的这部分不足。而鉴于当前的中国经济不利局面，用户花费大量资金投资于下一代SOC替换以前大额投资的意愿不高，会倾向于采用“向存量投资要效益&#34;和&#34;查漏补缺&#34;的方式来完善其SOC。因此，<strong>在中国，独立SOAR的机会仍然很多</strong>。</p><p>不论SOAR是否独立存在，还是被整合到SIEM或其它产品中，SOAR技术都必须继续演进。<br/></p><p>在技术发展趋势方面，需要让SOAR更加易于实施和维护，要降低用户使用成本，譬如积极引入低代码-无代码开发技术降低用户设计开发剧本的难度，积极探索利用GenAI增强现有的SOAR能力。功能上，<span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">应该</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">继续深化</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">作战室功能</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">，</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">把SIRP</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">平台做好</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">。对于Gartner提及的TIP部分，<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484584&amp;idx=1&amp;sn=ec647bae8b71e4f2a4d68603b8aade00&amp;chksm=fa002e1ccd77a70ae712591a9b745f5dd4f82aee5fe7959fd63e6ef641e5d5d7952576cf5309&amp;scene=21#wechat_redirect" textvalue="鉴于国内的实际情况" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">鉴于国内的实际情况</a>，建议由专门的TIP承接，在SOAR产品中更多考虑如何利用好威胁情报即可。</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">此外，应内置尽可能多的剧本和APP，提升产品开箱即用的程度。最后，要优化剧本开发方法论，教育用户树立正确认知，聚焦投入产出比高的应用场景，避免造成“SOAR万能自动化”的假象。</span></p><p><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">最后，作为中国SOAR厂商，应该在继续发展独立SOAR的同时，将SOAR与SOC平台进行整合。<br/></span></p><p><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">【参考】</span></p><p><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484685&amp;idx=1&amp;sn=2fe383d8335d300614f748ee7f91ceb7&amp;chksm=fa002fb9cd77a6af55094c6484ef13c2e8faa85e5e5536d9c371eed9fd1933c8bee6526b9252&amp;scene=21#wechat_redirect" textvalue="Gartner2023年SOAR市场指南报告评述" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">Gartner2023年SOAR市场指南报告评述</a><br/></span></p><p><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484584&amp;idx=1&amp;sn=ec647bae8b71e4f2a4d68603b8aade00&amp;chksm=fa002e1ccd77a70ae712591a9b745f5dd4f82aee5fe7959fd63e6ef641e5d5d7952576cf5309&amp;scene=21#wechat_redirect" textvalue="重新定义SOAR（2023年重编完整版）" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">重新定义SOAR（2023年重编完整版）</a><br/></p><p><a href="https://www.darkreading.com/cybersecurity-operations/soar-is-dead-long-live-soar" target="_blank">https://www.darkreading.com/cybersecurity-operations/soar-is-dead-long-live-soar</a></p><p><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484818">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=fff3b4ea&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyNzMxOTAwMw%3D%3D%26mid%3D2247484818%26idx%3D1%26sn%3D1966e121ac2e4f4dacda712854534d0c%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 18 Sep 2024 12:00:00 +0800</pubDate>
    </item>
    <item>
      <title>SANS 2024年SOC调查报告解读</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484811&amp;idx=1&amp;sn=18c651844e9668dd2ffa2f32db674f8c</link>
      <description>看看国际上甲方SOC运营的最新动态</description>
      <content:encoded><![CDATA[<p>
原创 <span>Benny Ye</span> <span>2024-09-05 12:01</span> <span style="display: inline-block;">北京</span>
</p>

<p>看看国际上甲方SOC运营的最新动态</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=d9ff8581&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMeg6iaDvFYgkZBZACQicI6mP4shbKN4rqA6seZSpNjxbhlhHLs1mTEAia93RQ5ed9Q9QpuAwicjiaZiaMJA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><em>【引言】本文不是报告的译文，是作者对报告的个人理解和解读，以及基于作者自身实践的思考。</em></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100001159" data-ratio="0.8240740740740741" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=b832def2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMeg6iaDvFYgkZBZACQicI6mP4hj6nNYmM3V1iaObImhgbibJAKVwEb82sKzrjIN5gkQ4pjBIicgr2qxdnA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>2024年7月，SANS发布了2024年的《SOC调查报告》，副标题是“安全运营中面临的主要挑战”，凸显了这份报告关注的重点。报告保持了国际化的视野，访谈了全球范围内的各种类型各种行业的组织。注意，这份报告中，位于美国的受访者占大多数（403位受访者中占301位），也表明我们在阅读这份报告的时候，要结合国内的实际情况来看待，切勿简单地将观点照搬过来。同时，为了便于与笔者之前写的《2023年SOC调查报告解读》形成对比，本文采用与之相同的提纲顺序。</p><p><strong><span style="font-size: 20px;">SANS的关键发现</span></strong><br/></p><p>1）在151份有效回答中，表示“不知道自己的SOC预算”的人占比最高（38%+），远高于2023年的回答比例（22%），说明组织的预算过程跟SOC团队之间出现了脱节，SOC运作机制可能存在问题。<br/></p><p>2）67%的受访者表示他们向上面管理层汇报工作时采用了度量指标，与去年基本持平。根据笔者自己的分析，在国内这方面还比较落后，也是未来国内SOC可以发力的方向。<br/></p><p>3）SOC团队规模（含驻场外包）主要分布在2-10人区间。国内的情况与之也基本一致。<br/></p><p>4）SOC当前面临最大障碍是编排与自动化，其次是人手不足和人员技能不足，都跟人有关。<br/></p><p>5）触发SOC团队启动响应的首要告警是EDR/XDR类，其次是SIEM告警。</p><p><span style="font-size: 20px;"><strong>SOC格局<br/></strong></span></p><p>1）<span style="color: rgb(2, 30, 170);">基于云的SOC架构占据主流</span>，这与Gartner多年前的判断一致。但在国内，主流架构还是还是传统的，有些号称上云的SOC不过是云上虚拟化部署，距离云原生架构还很远。当然，云原生SOC的需求也不足。<br/></p><p>2）<span style="color: rgb(2, 30, 170);">单一的集中式SOC部署模式</span>继续保持多数比例。<br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100001149" data-ratio="0.5691158156911582" data-s="300,640" style="" data-type="png" data-w="803" src="https://wechat2rss.xlab.app/img-proxy/?k=7645e7a0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcM5LG1V2s4mNVaY21icOeWSlAibHPpdsHr5eVWoKxX1YN4Lpe0xjV7kSU370rticxRN8ibXwPfB4tibMQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: left;">3）<span style="color: rgb(2, 30, 170);">把所有数据都给SIEM</span>成为一种习惯。SANS分析师表示，尽管这个发现有悖SOC实践常理，但相较于花费时间去甄别到底需要什么数据，一股脑儿先扔给SIEM更省事儿。不过，笔者看来，这种习惯显然不可取，不仅是给后续的分析处理增大了难度，传统SIEM的数据存储和维护成本也将不堪重负。这显然是一种“先甜后苦”的做法。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100001150" data-ratio="0.6062893081761006" data-s="300,640" style="" data-type="png" data-w="795" src="https://wechat2rss.xlab.app/img-proxy/?k=05703246&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcM5LG1V2s4mNVaY21icOeWSsOhA9t1zW16EPxrAbypSPL24TpX3Q17nhVHBhicKSRbQg1tXkZ7qvbg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>不过，反过来思考，这也印证了客户渴望“简单的安全运营”的诉求。<br/></p><p><span style="font-size: 20px;"><strong>SOC面临的最大挑战</strong></span></p><p style="text-align: left;">下图展示了这次调研中SOC面临的最大挑战排序，首先是<strong><span style="color: rgb(2, 30, 170);">缺乏自动化与编排</span></strong>，接下来第二和第三位都是<span style="color: rgb(2, 30, 170);">人的缺乏</span>，第四是缺少企业级的可见性，“<span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">缺少与我们所观测对象相关的上下文（情境）信息</span>”位次大幅下降，该挑战在2023年的调研中位居第一。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100001151" data-ratio="0.8038216560509555" data-s="300,640" style="width: 526px;height: 423px;" data-type="png" data-w="785" src="https://wechat2rss.xlab.app/img-proxy/?k=9682d570&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcM5LG1V2s4mNVaY21icOeWSTX6JNLyLic7de1KFwDouLM4g2XbGhyz2ibPsianl1V0saVHgMpTiaCAibFg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>下图是2023年调研的结果：<br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-imgfileid="100001152" data-ratio="0.851145038167939" data-w="524" src="https://wechat2rss.xlab.app/img-proxy/?k=f501b00a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMd5zUUZGKTAHppIBjJYOTVVibOWbXb5HQR3e8IXHqBIy9fIicLeLYicA94xgEWQ9LypUQDiaZc7QNJLwA%2F640%3Fwx_fmt%3Dother%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></p><p><span style="font-size: 20px;"><strong>SOC人员调研<br/></strong></span></p><p>1）<span style="letter-spacing: 0.578px;">SOC团队规模（含驻场外包）主要分布在2-10人区间。</span><br/></p><p><span style="letter-spacing: 0.578px;">2）人员在职年限较上年调研结果有所增加，表现在1-3年比例下降，3-5年比例上升。</span></p><p><span style="letter-spacing: 0.578px;">3）SOC技能要求方面，最重要的三个分别是：<span style="letter-spacing: 0.578px;color: rgb(2, 30, 170);">使用SIEM做分析、使用EDR/XDR、漏洞修复</span>。</span></p><p><span style="letter-spacing: 0.578px;">4）保留员工最有效的方法主要包括“有意义的工作”、“钱”和“职业前途”三个，相较于去年排序有所变化。</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100001153" data-ratio="0.5626598465473146" data-s="300,640" style="" data-type="png" data-w="782" src="https://wechat2rss.xlab.app/img-proxy/?k=87e3fd54&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcM5LG1V2s4mNVaY21icOeWSnfhu8AyCiatVIyjHAEKfknJg0YFTONutmEG7nQibMyl8lgIDcgtdKtdg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>5）今年新增了一个调研问题，是关于如何计算每个分析师的工作量的，如下图所示：<span style="letter-spacing: 0.578px;"></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100001154" data-ratio="0.47320261437908495" data-s="300,640" style="" data-type="png" data-w="765" src="https://wechat2rss.xlab.app/img-proxy/?k=24a8339b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcM5LG1V2s4mNVaY21icOeWSIh0UnQ2dxR6lP7gib1J9c2fZAVav6Xic8Dib0g7dwWbsFFhqYeb1kxPQA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: left;">可以发现，最主流的一种工作量计算方式是依据工单处理时长，其次是追加考虑SIEM产生的告警数量，再者还要根据SLA进行更细致的计算。<br/></p><p style="text-align: left;"><span style="font-size: 20px;"><strong>SOC能力（流程）分析</strong></span><br/></p><p style="text-align: left;">如下图所示，本次调研发现最重要的SOC能力【笔者注：这种能力外化表现为流程】排序为：<span style="color: rgb(2, 30, 170);">告警（分诊和升级）、安全监测与检测、事件响应、系统安全管理、安全架构与工程</span>，等等，与2023年的结果差异较大，但唯一没有改变的就是告警处置能力排名第一。<br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100001155" data-ratio="0.78515625" data-s="300,640" style="" data-type="png" data-w="768" src="https://wechat2rss.xlab.app/img-proxy/?k=3a612994&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcM5LG1V2s4mNVaY21icOeWS2Klqy6Jy2fvp8IYlczZ1hibjvCTbekqpYhGfYqE6dkibtkORJKIXsj9A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><strong>威胁猎捕<br/></strong></p><p>SANS认为威胁猎捕的基本目标是寻找告警系统未能检测到的失陷。威胁猎捕是一个<span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">在假定其它基于告警机制失效情况下的对现有数据进行调查的过程。威胁猎捕最简单最基本的形式是将新发现的指标（譬如来自安全情报的）用于历史数据的回溯查询分析。</span></p><p><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">如下图所示，SANS调查显示，威胁猎捕活动的自动化程度正在不断提升，厂商提供的自动化威胁猎捕工具越来越强大。同时，纯手工方式的</span><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;">威胁<span style="background-color: rgb(255, 255, 255);">猎捕活动依然占比较高。</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100001156" data-ratio="0.45" data-s="300,640" style="" data-type="png" data-w="800" src="https://wechat2rss.xlab.app/img-proxy/?k=0ac33e1f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcM5LG1V2s4mNVaY21icOeWS4GZ6I5aUISibTvqTaicrYhvXlicVCichIRAq0RtSSQeb8mA3VPgEibyRcww%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;font-size: var(--articleFontsize);">笔</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;font-size: var(--articleFontsize);">者这里需要指出的是，上述猎捕过程中的</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;font-size: var(--articleFontsize);">查询分析不是一次</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;font-size: var(--articleFontsize);">性的，而是要迭代</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;font-size: var(--articleFontsize);">进行的，</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;font-size: var(--articleFontsize);">是一系列查询和调查</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;font-size: var(--articleFontsize);">，</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;font-size: var(--articleFontsize);">期间需要人的直觉和智慧的参与，最终</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;font-size: var(--articleFontsize);">抽丝剥茧，识别出</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;font-size: var(--articleFontsize);">威胁事件，并</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;font-size: var(--articleFontsize);">触发</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;font-size: var(--articleFontsize);">事件响应处置流程。</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;font-size: var(--articleFontsize);">如果无需人的参与就能识别出的威胁</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;font-size: var(--articleFontsize);">，</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;font-size: var(--articleFontsize);">属于检测</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;font-size: var(--articleFontsize);">，而非猎捕。</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;font-size: var(--articleFontsize);">因此，完全自动化的威胁猎捕是不存在的，</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;font-size: var(--articleFontsize);">我们只能将威胁猎捕的部分过程自动化。所以，笔者认为SANS报告中所指的完全自动化是指某个活动片段，而非全过程。</span></p><p><strong><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">威胁情报</span><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"></span></strong></p><p>SANS本次调研了用户如何使用威胁情报。结果显示，最多人选择（将威胁情报用于）“事件响应”，紧跟其后的是（将威胁情报用于）“威胁猎捕”。</p><p><span style="font-size: 20px;"><strong><span style="font-size: 20px;background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;">SOC技术</span></strong></span></p><p><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">今年SANS分析了47种SOC技术的客户满意度，比去年多一种技术——GPT。如下图所示：</span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100001157" data-ratio="2.255578093306288" data-s="300,640" style="" data-type="png" data-w="493" src="https://wechat2rss.xlab.app/img-proxy/?k=38fcab4b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcM5LG1V2s4mNVaY21icOeWSSiadwoMxX3gvBkVe1vSAUz0u29ZhLia6BQr04fOMtAiayUJwnCwvH49Aw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">结果表明，<span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;color: rgb(2, 30, 170);">满意度最高的是EDR/XDR</span>，并且超过了3分，达到了A级。接下来依次是VPN、邮件网关、SIEM、NGFW、MPS（恶意代码保护系统）、定制化或裁剪的SIEM监测用例分析，等等。相较于去年，对日志分析的满意度有所下降。</span></p><p><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">反过来，看看<span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;color: rgb(2, 30, 170);">最不满意的有哪些，包括：GPT、AI和ML、欺骗技术</span>，等等。对比一下可以发现，从2023年到2024年，计划实施AI和ML的SOC项目比例呈现下降趋势。报告作者认为，GPT可以极大地促进沟通和分析师对信息的理解，但还无法取代分析师。</span></p><p><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">此外，TIP和SOAR技术的满意度评分比去年有所下降，其中，SOAR满意度倒数第九。<br/></span></p><p><strong><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">SOAR</span></strong><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;"><br/></span></p><p><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">针对SOAR，笔者这里稍微展开一下。<br/></span></p><p><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">首先，SANS报告显示SOC最大挑战是缺乏自动化与编排；其次，SOC团队对SOAR的满意度偏低。说明什么？说明SOAR对于SOC十分重要，当前需求旺盛，但现有的产品和能力无法完全满足客户需求，期望与现实之间存在较大的鸿沟。这也正如SANS召开的针对这份报告的线上研讨会上，来自DropZone.AI的创始人Edward Wu所说，现在的SOAR技术存在问题。</span></p><p><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">同时，也正如Gartner和Forrester</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">分析师</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">在报告中指出的</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">，当前主流的</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">SOAR的实施和维护成本过高，</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">对于用户的</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">技能水平要求较高，</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">需要有较高的</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">流程</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">成熟度和代码开发水平，最终导致</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">SOAR的投入产出比低于预期。</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">当前SOAR正处于Gartner定义的</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">技术谷底，同时</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">Gartner还</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">表示SOAR已经</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">融入了</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">SIEM等其它</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">产品中成为一个</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">功能，而不再</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">作为独立</span><span style="background-color: rgb(255, 255, 255);font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.544px;">产品和市场。</span></p><p><span style="font-family:PingFang SC, system-ui, -apple-system, BlinkMacSystemFont, Helvetica Neue, Hiragino Sans GB, Microsoft YaHei UI, Microsoft YaHei, Arial, sans-serif;"><span style="letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">以上种种叠加到一起，说明SOAR革新的时候到了。自动化和编排本身没有问题，有旺盛需求，但是SOAR技术需要变革，需要更加简单易用，更加智能，易于实施和扩展。</span></span></p><p><span style="font-family:PingFang SC, system-ui, -apple-system, BlinkMacSystemFont, Helvetica Neue, Hiragino Sans GB, Microsoft YaHei UI, Microsoft YaHei, Arial, sans-serif;"><span style="letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">为此，DropZone.AI等公司提出了用GenAI去改造SOAR，但又面临另一个问题，即SOC团队对GPT等AI技术的满意度水平更低。如何在SOAR中应用好GPT和AI还需要仔细斟酌。同时，有的公司从低代码/无代码开发的角度去降低剧本的开发门槛，或者内置更多开箱即用的剧本，等等。还有的公司也在思考对剧本进行分层，让剧本更易于组装。如此种种，都是为了降低SOAR的使用门槛。对于SOAR技术的未来，笔者充满信心，而不论其是继续作为独立产品，抑或成为一个能力（功能），如UEBA那般。</span></span></p><p><strong><span style="font-family:PingFang SC, system-ui, -apple-system, BlinkMacSystemFont, Helvetica Neue, Hiragino Sans GB, Microsoft YaHei UI, Microsoft YaHei, Arial, sans-serif;"><span style="letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">事件响应<br/></span></span></strong></p><p><span style="font-family:PingFang SC, system-ui, -apple-system, BlinkMacSystemFont, Helvetica Neue, Hiragino Sans GB, Microsoft YaHei UI, Microsoft YaHei, Arial, sans-serif;"><span style="letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">调查显示，最满意的技术是基于端点的响应能力，而最大挑战（最不满意）来自于对抗性欺骗技术。</span></span></p><p><span style="font-size: 20px;"><strong><span style="font-family: &#34;PingFang SC&#34;, system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: 20px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">SOC度量指标</span></strong></span></p><p><span style="font-family:PingFang SC, system-ui, -apple-system, BlinkMacSystemFont, Helvetica Neue, Hiragino Sans GB, Microsoft YaHei UI, Microsoft YaHei, Arial, sans-serif;"><span style="letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">定义度量指标已经成为大部分SOC的共识，不仅可用于衡量外包工作成效，更是为了SOC团队向上汇报工作成效之用。下图展示了一些常用的内部度量指标：</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100001158" data-ratio="0.9514348785871964" data-s="300,640" style="" data-type="png" data-w="906" src="https://wechat2rss.xlab.app/img-proxy/?k=f569a1f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMeg6iaDvFYgkZBZACQicI6mP4qJUffeKvic74NdkY3dEGib39RFw4KzWEmYH53WFGypxke8msokXzJ6Tg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>可以看到，“处理的事件量”是最常用的指标，其次是MTTD/MTTC/MTTE、彻底根除率、发现所有受影响的资产和用户的时长、应知事件与未知漏洞的比率、可避免事件数量、依据IOC全面检查信息系统的彻底性和准确性、威胁行为体溯源数量、安全事件导致的业务停机时长或怠工时长、一个班次关闭的事件量、数据丢失发生数量与阻止数量的比率、事件造成的经济损金额。</p><p><span style="font-size: 20px;"><strong>小结</strong></span></p><p>透过这份报告，可以发现：<br/></p><p>从技术发展路线上看，国际（尤指美国）趋势是云化SOC，同时，SIEM依然是SOC的核心部件，但EDR/XDR的地位凸显，成为重要的告警来源，并且满意度最高。而SOC迫切需要发展的技术和能力在于SOAR所代表的自动化和编排，但SOAR当前技术水平未能达到预期。威胁猎捕在SOC中越来越普遍，也越来越成熟。<span style="letter-spacing: 0.578px;">SOC对AI和ML（包括GPT）也产生了兴趣，但真正上马智能SOC的还是少数，大部分都在观望。</span></p><p>从运营成熟度上看，国际上的现状是：自营+外包已经成为SOC运营的主流选择，主流SOC团队的大小也稳定在2-10的区间，解决人手短缺的问题主要还要靠自动化技术。此外，大部分SOC组织都制定了度量指标，在面向管理层和董事会的汇报中都会用数字说话，以证明SOC取得的实效，从而获得管理层对SOC的进一步投资。值得注意的是，出于对数据复杂性的畏惧，大部分客户选择先将所有数据一股脑儿扔给SIEM处理，笔者认为这是一个隐患。解决之道恐怕不能从用户侧去考虑，而更多要从技术架构上加以考量。</p><p>反观国内，根据笔者的观察，受限于客户实际环境，云化SOC也就刚刚起步，而SOAR（尤其是独立SOAR）在国内的发展空间显然更大，GenAI应用于安全运营更多还是概念验证阶段，MSS服务（尤其是MDR）还任重道远。<br/></p><p>【参考】<br/></p><p><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484680&amp;idx=1&amp;sn=83d86c286a3072137d14a936cf86f098&amp;chksm=fa002fbccd77a6aae4a84f82541ec6d7be90d5965913afe784cd481a41ac708ea9cf95ebf455&amp;scene=21#wechat_redirect" textvalue="SANS 2023年SOC调查报告解读" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">SANS 2023年SOC调查报告解读</a><br/></p><p><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484450&amp;idx=1&amp;sn=27c3c6e51febebd4ed1a13fa2f85307d&amp;chksm=fa002e96cd77a780251bdec3b12e2fbea2e013d19495d01c33b7aaac9323cbabe4274077e999&amp;scene=21#wechat_redirect" textvalue="SANS 2022年SOC调查报告解读" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">SANS 2022年SOC调查报告解读</a><br/></p><p><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484366&amp;idx=1&amp;sn=ba64aedd9b67d98fa619db281105cf65&amp;chksm=fa00297acd77a06c53139348d4b69c713712c8ee8054871436ab9ff1a386f65983e4144134d8&amp;scene=21#wechat_redirect" textvalue="SANS 2021年SOC调查报告解读" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">SANS 2021年SOC调查报告解读</a><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484811">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=106af850&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyNzMxOTAwMw%3D%3D%26mid%3D2247484811%26idx%3D1%26sn%3D18c651844e9668dd2ffa2f32db674f8c%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 05 Sep 2024 12:01:00 +0800</pubDate>
    </item>
    <item>
      <title>从Gartner2024年北美安全峰会看安全运营的技术趋势</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484795&amp;idx=1&amp;sn=8f835c0699be66f615e7b713f67e26dc</link>
      <description>暴露管理、生成式AI、自动化，将共同塑造未来的SOC</description>
      <content:encoded><![CDATA[<p>
原创 <span>Benny Ye</span> <span>2024-07-19 12:01</span> <span style="display: inline-block;">北京</span>
</p>

<p>暴露管理、生成式AI、自动化，将共同塑造未来的SOC</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=23801fa2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMeEziadp1sBictffc7G4iborx5GMn2v0a9tibmjlJfzau9ZlkYT219WdgXicGyWMarKovoqSLanoaCgfCg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: left;"><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;">2024年度的Gartner北美安全与风险管理峰会在6月3日至5日在美国召开。</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;">这次峰会并没有在媒体（尤其是中国媒体和自媒体）上受到关注，可能是现在Gartner的安全峰会一年多次在全球举办分散了注意力，也可能是现在对于网络安全的创新点过于聚焦在GenAI之上而显得各种安全大会缺乏差异而造成了思考疲劳，抑或国内外的网络安全技术越来越多的分叉导致国内网络安全技术从业者越来越关注自身，而国内当前低迷的网络安全产业市场多少也对人们谈论网络安全的前瞻技术形成了阻碍。</span></p><p><span style="font-size: 24px;"><strong>重点的新兴技术领域</strong><br/></span></p><p>在《2024年安全与风险管理新兴技术》议题中，Neil McDonald筛选出了5类关键技术：<br/></p><p>1）<strong>AI和GenAI</strong>：包括保护AI和利用AI两个方面。在保护AI方面，是Garnter重点关注的方向，涉及的新兴技术包括AI TRISM（AI信任、风险与安全管理）技术、LLM防火墙、在SASE/SSE中增加对AI应用的保护技术，以及AISPM（AI安全姿态管理）。在利用AI方面，Gartner显得十分谨慎，目前的建议就是在现有的安全控制台中增加GenAI接口。</p><p>2）<strong>安全平台整合</strong>：这个已经谈了好几年了，主要集中在各个领域内的横向整合，包括面向云的CNAPP，面向边缘接入的SSE和SASE，以及面向安全运营领域的SIEM/SOC与XDR、CTEM的整合，此外还有身份安全平台的出现。Gartner还指出，现在已经出现了跨多个领域的整合平台。<br/></p><p>3）<strong>身份即关键基础设施</strong>：也即要保护身份这个关键基础设施。涉及的新兴技术包括ITDR、ISPM（身份安全姿态管理）、机器身份管理，以及无口令认证。<br/></p><p>4）<strong>xSPM的崛起</strong>：xSPM（或者简称为SPM，即安全姿态管理）代表了Neil自己提出的自适应安全架构的I（识别）和P（保护）【笔者注：最新的Gartner自适应安全架构的四象限分别是IPDR，其中第一个是I（识别），而原来是P（预测），仅修改了名称，内容未变，估计是为了与CSF的IPDRR中的I保持一致性】的I和P象限，而包括XDR等在内的ITDR则重点聚焦在D和R象限。在各种SPM中，新兴的SPM包括ASPM（应用SPM）、DSPM（数据SPM）、AISPM（人工智能SPM）、SSPM（SaaS SPM）。<br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100001133" data-ratio="0.45" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=091418bb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdfqwTT5cJNZB4Gv4cc0TOqWB530Izouib1FG2GSQjsQbwNrGXcu3Bkbuib3ibHL9iaDz5SJXTBbarLpA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>5）<strong>CTEM</strong>：这个也谈了好几年了，新的变化主要是将CTEM从IT环境扩展到OT和CPS环境中。而新兴技术趋势包括CTEM下不同类型产品的相互融合，以及SPM厂商和SIEM厂商的纷纷介入（增加EM方面的功能）。而正是由于SPM厂商和EM（暴露管理）厂商的互相渗透，使得Posture（姿态）和Exposure（暴露）两个概念之间的关系越发微妙。<br/></p><p>从安全<span style="letter-spacing: 0.578px;">运营</span>的角度来看，以上5个方面中，有四个方面都跟安全<span style="letter-spacing: 0.578px;">运营</span>有关，包括：安全<span style="letter-spacing: 0.578px;">运营</span>领域是利用GenAI的最佳场合之一；安全<span style="letter-spacing: 0.578px;">运营</span>的平台整合正在塑造新一代的SOC平台；而SPM和EM也都正在融合到全新的SOC框架中。<br/></p><p><span style="font-size: 24px;"><strong>安全运营领域的前景展望</strong></span></p><p>在峰会上，Gartner提出了<strong>三大方面的展望：CTEM和TI（威胁情报）助力安全运营、GenAI赋能SOC、超大规模安全<span style="letter-spacing: 0.578px;">运营</span></strong>。<br/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-imgfileid="100001134" data-ratio="0.5601851851851852" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=1c6ebff2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdfqwTT5cJNZB4Gv4cc0TOqRrnmTNr6hHe0uNMHFPsFBpX4lpLicGI8h0nPYGiazGyqUlNNMv4FR9gA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>其中，CTEM和TI有助于帮助收敛攻击面，为安全<span style="letter-spacing: 0.578px;">运营</span>做好事前准备，同时它们获取的信息可以作为后续检测和响应的情境（上下文）数据使用，以加速检测和响应。GenAI能够从多方面赋能SOC，但还很不成熟 ，存在安全隐患，一定要慎重使用【笔者注：Gartner对GenAI一直持谨慎态度】。而如何在现有（小）资源的条件下进行超大规模的安全<span style="letter-spacing: 0.578px;">运营</span>工作正成为越来越迫切的问题，必须有机结合AI与自动化技术。<br/></p><p>以下笔者分别从CTEM助力安全<span style="letter-spacing: 0.578px;">运营</span>【注：TI助力安全<span style="letter-spacing: 0.578px;">运营</span>已深入人心，故略过】、GenAI赋能安全<span style="letter-spacing: 0.578px;">运营</span>和超大规模安全<span style="letter-spacing: 0.578px;">运营</span>三个方面进行深入分析。</p><p><span style="font-size: 20px;"><strong>CTEM助力安全运营</strong></span></p><p><span style="font-size: 18px;"><strong>CTEM解析</strong></span></p><p><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">结合Gartner观点，笔者认为持续威胁暴露</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">管理(Continuous Threat Exposure </span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">Management</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">)是一套包含技术、流程和人员在内的系统性、集成化、迭代性的方法和体系，让企业和组织有意识地持续并</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">一</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">致地评估其数字资产和物理资产的可见性、脆弱性和可访问性，以持续优化提升安全姿态。Gartner将CTEM看作是一个过程和方法，而将EM（Exposure Management，暴露管理）看作是支撑CTEM的技术集合。</span></p><p>EM的核心能力是进行暴露评估和暴露验证，其中暴露评估包括攻击面评估（ASA）【注1】【注2】和漏洞评估与优先级研判（VA&amp;VPT）【注3】，暴露验证主要是使用破坏和攻击模拟（BAS）和自动化渗透测试等网络安全验证技术【注4】。简单地说，EM = ASM + VM + CyVal。</p><p>【注1：最新的Gartner ASM市场指南报告中指出ASM中的M（管理）不是一个准确的定义，其实ASM的工作更多是ASA（攻击面评估），由于历史原因也不会改名了，但有的场合会使用ASA。】</p><p>【注2：ASA或者说ASM又包括三个技术，分别是EASM、DPRS和CAASM。这里不再展开叙述。】<br/></p><p>【注3：这里的漏洞还包括安全配置缺陷和安全防御策略的缺陷。安全配置的缺陷通常使用配置核查工具来识别，而xSPM类产品也都提供相关能力。安全防御策略缺陷则包括了安全及网络设备的安全策略缺陷（譬如防火墙规则缺陷），甚至于安全<span style="letter-spacing: 0.578px;">运营</span>体系（如SOC）的检测、监测和响应策略的缺陷，等等。】</p><p>【注4：安全验证技术和工具不仅可以用于暴露验证，即验证暴露的有效性，还能用于安全漏洞以及配置和防御策略缺陷的评估。】<br/></p><p>必须指出，CTEM的闭环并不是我们一般所理解的闭环，并不是以暴露面的收敛（包括漏洞缓解），暴露事项（issue）或者工单（ticket)的关闭为结束，而是以“动员”为结束。也就是说，Gartner认为暴露面收敛的具体工作主要是IT和业务部门的事情，安全部门当然也要参与，但不属于安全部门自个儿的事情，因此不在CTEM闭环中。CTEM的闭环最后就是能够将有效的暴露面事项或工单提供给专门的团队和人员，并协助和督促其整改。因此，不要想当然地认为CTEM会真正“管理”和收敛暴露面。</p><p>上述CTEM的工作内容也恰恰印证了安全<span style="letter-spacing: 0.578px;">运营</span>工作中资产运行和漏洞运行的工作范围。其中最重要的是安全<span style="letter-spacing: 0.578px;">运营</span>中的漏洞运行工作也是不包括漏洞缓解本身的（尽管有的漏洞缓解工作也能在安全<span style="letter-spacing: 0.578px;">运营</span>团队内部实施），漏洞缓解系统应该另行由安全部门、IT部门和业务部门共同建设与运行。</p><p><span style="font-size: 18px;"><strong>EM为SOC提供上下文</strong></span></p><p>但是，暴露评估和验证的结果对于SOC的检测和响应工作却十分有价值。EM可以为TDIR提供上下文（情境）信息，譬如：精准的资产和漏洞信息可以让分析师编写更加精准（包含资产和漏洞关联信息）的检测规则，并且这些规则可以真正用起来；可以生成更加丰富易懂的告警信息；有助于支撑威胁猎捕；而暴露验证获得的安全控制策略方面的缺陷有助进行威胁建模。总之，有了EM提供的上下文信息，TDIR可以更加高效，也即安全<span style="letter-spacing: 0.578px;">运营</span>更加高效。<br/></p><p><strong><span style="font-size: 18px;">EM可以提升SOC自身弹性/韧性<br/></span></strong></p><p>EM中的安全验证工具通过对<span style="letter-spacing: 0.578px;">安全</span><span style="letter-spacing: 0.578px;">漏洞、</span><span style="letter-spacing: 0.578px;">配置和防</span><span style="letter-spacing: 0.578px;">御策略缺陷的评估，以及暴露的验证，可以实现对包括TDIR在内的SOC有效性的评估，从而提升SOC自身的弹性。SOC自身策略和安全内容的缺陷也是一种暴露，也需要被识别和验证，譬如发现针对某项不可修复的漏洞的补偿措施（虚拟补丁或者增强监控策略等）的缺陷，识别出低效（导致高误报）的关联分析规则，发现针对某种关键威胁的响应对策的缺失，等等。通过对这类缺陷的识别和验证，有助于提升SOC自身的强度。</span><br/></p><p style="text-align: center;"><span style="letter-spacing: 0.578px;"><img class="rich_pages wxw-img" data-imgfileid="100001135" data-ratio="0.5527777777777778" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=7b7a05d7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMcmozicIBJQXaFoVpy4lH55UWpYp9gibq1xmFHicHF2LBPszGPoOrUib7rDhy4084buxuNcYowL6BohJQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><strong><span style="font-size: 18px;">从SOC的角度看TDIR和EM<br/></span></strong></p><p>首先，安全运营（SecOps）是一个很宽泛的概念。如果我们把整个安全生命周期分为规划、建设、运营三个部分的话，安全运营的历程将伴随企业组织的一生。因此，可以<strong>把安全运营看作是持续不断地保障目标网络安全平稳运行，达成组织业务战略目标的永续过程</strong>。安全运营涉及的内容很广泛，从能力方面看，可以分解为IPDRR（识别、保护、检测、响应、恢复）或者类似的变体。从运营对象来看，可以分为工作负载、端点、应用、数据、身份等维度。Gartner将安全运营定义为一个“<strong>通过一套人、流程和技术来识别和管理暴露、监测、检测和响应网络安全威胁与事件，以提升网络弹性</strong>”的过程。SANS则将安全运营的使命定义为“保护业务运营的私密性、完整性和可用性，并最小化非预期事态造成的损失”。<br/></p><p>安全运营中心（SOC）则比安全运营更加聚焦，虽然有很多定义，但通常都是指一个包含一系列流程、人员、技术等的组织单元，<strong>核心目标就是抵御网络安全威胁、保障目标网络安全平稳运行</strong>。围绕这个目标，通常会对目标网络实施持续的检测、监测、分析、调查、响应、报告、修复。笔者基于自己的多年实践，认为<span style="background-color: rgb(255, 251, 0);"><strong>安全运营中心可以分为威胁事件运营、资产暴露运营、安全漏洞运营、安全情报运营、防御策略运营、态势决策运营6个方面能力</strong></span>。其中，威胁事件运营是所有SOC的核心能力，就是指威胁事件的检测与响应，通常依托于SIEM或者Gartner新提出的TDIR。而资产暴露运营和安全漏洞运营则跟Gartner的EM相匹配，以在事前掌握和完善自身安全防御的姿态，同时又与安全情报运营所依托的TIP一道为TDIR提供上下文（情境）信息，提升威胁事件运营的效能。防御策略运营则通过持续的评估、验证和改进来不断提升包括SOC自身在内的防御体系的有效性。最后，态势决策运营持续收集前面5大运营过程中的数据，进行指标计算和态势量化，形成决策，从而动态调整安全保障级别，调配安全防御力量。</p><p>在笔者看来，当前国内大部分SOC基本还处于基于SIEM所承载的威胁事件运营阶段。安全情报虽已普遍应用，但客户自身TIP建设及其上的安全情报运营还处于早期。资产暴露运营和安全漏洞运营则还处于初始、分散的阶段，相关信息还处于不全、不准、滞后的状态，尚无法实战，难以赋能威胁事件运营，而这在全球范围内都是一个痛点，也<strong>因此Gartner近几年一直在力推EM/CTEM</strong>。至于防御策略运营、态势决策运营（尤指宏观态势）则更多还停留在纸面上。以2023年发布的网络安全态势感知通用技术要求国标为例，更多还是描述了态势展示的内容，而态势信息的获取与分析则基本与SIEM重合。<span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></p><p><strong><span style="letter-spacing: 0.578px;font-size: 20px;">GenAI赋能SOC</span></strong></p><p>这已经是不争的事实了！从笔者分析的<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484640&amp;idx=1&amp;sn=6ff1f407b3ad35c01efbf35d5a0ded0d&amp;chksm=fa002e54cd77a7425235ca39c42acb32187bd913d3b3ab9ec75c9d2c504fab0f49d75efada57&amp;scene=21#wechat_redirect" textvalue="RSAC2023大会" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">RSAC2023大会</a>和<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484766&amp;idx=1&amp;sn=5b66715c108908d39eb92ecdc964c9f6&amp;chksm=fa002feacd77a6fcdc78bff2275afb83ea403c19d547584bd02669f68550e26c5d27b7303c8b&amp;scene=21#wechat_redirect" textvalue="RSAC2024大会" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">RSAC2024大会</a>的情况看，所有人都知道GenAI用在安全领域的首要场景就是安全运营和SOC。因为GenAI恰好完美地击中了当下安全运营的三大痛点：人才短缺、工作倦怠（告警疲劳）、技能不足。不论是副驾、助理还是智能体，都试图让GenAI驱动的机器人充实到客户的安全运营团队中去。</p><p><span style="letter-spacing: 0.578px;">Gartner预计，到2028年，基于多智能体的威胁检测与事件响应工作将从现在的5%暴涨到70%。</span><span style="letter-spacing: 0.578px;">同时，Gartner认定届时AI主要还是增强而非替代员工。</span></p><p><strong><span style="letter-spacing: 0.578px;font-size: 18px;">GenAI应用部署模式</span></strong></p><p><span style="letter-spacing: 0.578px;">Gartner将GenAI应用分为了4层：基础模型层、微调层、数据检索与提示工程层、应用层。对于使用/开发GenAI应用的人而言，可以采用5种部署模式：直接用第三方的GenAI App、将GenAI嵌入到自己的App中、自己实现数据检索与提示工程、自己实现微调、自己从底层模型开始搭建。显然，从不同的层次开始构建GenAI APP，成本和技术考量都是不同的。如下图所示，展示了GenAI的分层和五种部署模式，其中蓝色块表示采购自第三方的组件。</span></p><p style="text-align: center;"><span style="letter-spacing: 0.578px;"><img class="rich_pages wxw-img" data-imgfileid="100001137" data-ratio="0.425" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=3556cd49&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMeEziadp1sBictffc7G4iborx5PTicawZVDIA0AQRj8qn2SRrc2AyDBNWNrgUot34VyQDuX5d9rSIlmuQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="font-size: 18px;"><strong>GenAI应用类型</strong></span></p><p>目前，仅就用于SecOps的GenAI应用而言，大体上可以分为三种类型：聊天机器人、AI助理/副驾、智能体。三种类型的难度依次上升。目前，主流的SecOps厂商聚焦于AI助理/副驾（譬如<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484640&amp;idx=1&amp;sn=6ff1f407b3ad35c01efbf35d5a0ded0d&amp;chksm=fa002e54cd77a7425235ca39c42acb32187bd913d3b3ab9ec75c9d2c504fab0f49d75efada57&amp;scene=21#wechat_redirect" textvalue="微软的Copilot、SentinelOne的Purple AI" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">微软的Copilot、SentinelOne的Purple AI</a>），而初创企业（如<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484766&amp;idx=1&amp;sn=5b66715c108908d39eb92ecdc964c9f6&amp;chksm=fa002feacd77a6fcdc78bff2275afb83ea403c19d547584bd02669f68550e26c5d27b7303c8b&amp;scene=21#wechat_redirect" textvalue="Dropzone AI" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">Dropzone AI</a>）则更多聚焦于智能体。下图展示了不同类型下的厂商示例。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-imgfileid="100001138" data-ratio="0.48055555555555557" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=bc4a617e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMeEziadp1sBictffc7G4iborx5syqcbERqrxMPNERaD3oz3lViaB2wTNOAyAkZy4gWbdbJoHuvLrZZezw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>下图展示了当下主流的AI助理/副驾的工作原理，核心就是提示工程和RAG。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-imgfileid="100001139" data-ratio="0.5037037037037037" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=e98312f6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMeEziadp1sBictffc7G4iborx5PsvwP1wMMbWiaMP1sym67qLicPkORQABczXYicU7K6lITzduGgjMKQ7cA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: left;">Gartner表示，以当前最重要的大语言模型（LLM）为例，它其实并不真的“智能”。在笔者看来，往深了讲，它的“智能”都基于你喂给它的语料和对它使用各种安全运营工作套路的训练，抑或各种静态知识库。此外，LLM尚未真正取代现有的威胁检测引擎，大部分情况下都是LLM基于你自然语言的输入生成检测规则或代码，然后还是由原来那个检测分析引擎去跑。此时，<span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;">大模型不会让你的检测引擎变好，而只是加速这个引擎的使用速度，降低引擎使用难度。而即便未来可以通过自然语言来生成检测/调查/猎捕的规则或代码了，对于分析师的业务领域技能的要求依然不会降低，因为如果分析师不能问出正确的问题，也不会得到预期的结果。</span></p><p style="text-align: center;"><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"><img class="rich_pages wxw-img" data-imgfileid="100001140" data-ratio="0.362962962962963" style="width: 417px;height: 151px;" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=a52cc4d8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMeEziadp1sBictffc7G4iborx5ZVB1NtIcntQJqKU5GsMFbgAnMiczvZymwibSib4ian7fD67spYRDVVxGzA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="font-size: 18px;"><strong><span style="font-size: 18px;letter-spacing: 0.034em;">GenAI赋能SOC的用例</span></strong></span></p><p><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">在本次峰会上，多位分析师都列举了自己心中的主要GenAI赋能SOC的用例，以下是笔者综合多位分析师观点的一份用例清单。注意，以下用例主要都工作在AI助理/副驾模式下。</span></p><ol class="list-paddingleft-1" style="list-style-type: decimal;"><li><p>增强威胁检测能力：查询/规则生成、告警分析、告警信息解释、告警富化</p></li><li><p>简化检测工程：生成检测代码/规则</p></li><li><p>加速安全事件响应：事件解释、事件调查与信息增强、生成事件响应建议/计划/剧本</p></li><li><p>提升工作流程效率：GenAI功能有机整合到现有UI中、工作流程提示</p></li><li><p>加速SOC度量：总结事件响应过程、生成资产/漏洞/事件报告、生成日报周报等报告</p></li><li><p>提供培训：培训新手使用本系统、安全运营实战教学、安全知识教学</p></li><li><p>助力攻击面管理：资产/漏洞识别、资产/漏洞去重与合并<br/></p></li><li><p>简化情报分析：交互式威胁情报分析</p></li><li><p>辅助攻击演练：生成攻击场景、攻击模拟、桌面推演</p></li></ol><p style="text-align: left;margin-top: 24px;"><strong><span style="font-size: 18px;">SOC使用GenAI的禁忌</span></strong><br/></p><p style="text-align: left;">Gartner对GenAI一向特别谨慎，因为GenAI本身存在很多不确定性（譬如准确性、可解释性、可信度、隐私问题等）。Gartner不断敬告大家，使用GenAI要以我为主，按需使用，不要彻底依赖GenAI。把GenAI看作是增强人的一个工具，而不是替代人，要建立起合理的GenAI应用效果预期。如前所述，人的安全运营技能依然十分重要，不要降低这方面的投入和培训。此外，对于GenAI生成的结果，不要完全相信，要建立常态化的验证反馈机制。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100001141" data-ratio="0.48518518518518516" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=00d1f7ab&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMeEziadp1sBictffc7G4iborx5E73AthjLfH2Y3dUZ1M2NwhD8XTyOFxAHcgNHXDTe73eiaUN5uCPbBibw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: left;">现在，主流的SOC AI助理厂商也都在尽力提升通过GenAI的回答结果的透明度和可解释性，包括给出结果的原始信息来源，给出分析的步骤，等等。<br/></p><p><strong><span style="letter-spacing: 0.578px;font-size: 20px;">超大规模安全运营</span></strong></p><p><span style="letter-spacing: 0.578px;">随着日志量的不断攀升，数据存储量，告警量都与日俱增。在现有本就短缺的安全运营资源投入条件下，如何处理海量日志告警并响应安全事件成为一个难题。目前为止的大部分方法都是采用上下文丰富、排序、分组等方式，让分析师聚焦到少部分重要的告警和事件上【注5】，对于相对不重要的，就只能看着办，有时间就处理，没时间就忽略。现在，随着AI的火爆，业界产生了一种期待，能否对所有（或者大部分）的告警和事件都进行处理？这就是笔者理解的所谓超大规模安全运营（hyperscale SecOps）。</span></p><p><span style="letter-spacing: 0.578px;">超大规模安全运营是指综合采用自动化和AI等多种技术【注6】，实现对超大规模日志量、告警量和事件量的安全运营。超大规模安全运营至少要使用自动化，但还必须使用AI等其它技术，即所谓的超自动化（hyperautomation）。</span></p><p><span style="letter-spacing: 0.578px;">【注5：有的厂商说能够让用户一天就处理10条安全事件，并不是说只有10条，而是还有很多条疑似事件由于没有触发阈值（或者评分较低）而被忽略了。从安全的角度来说，可能恰恰问题就隐藏在其中。因此，如何把需要优先处理的安全事件降到最低，同时在概率上不遗漏重大的危害，就成为了各家的本事。】<br/></span></p><p><span style="letter-spacing: 0.578px;">【注6：正如笔者以前就指出的，AI不等于自动化！AI也取代不了自动化，包括SOAR，但AI可以赋予自动化以智能，让自动化更强大。】</span></p><p><span style="letter-spacing: 0.578px;">要实现超大规模安全运营必须使用自动化。自动化尤其擅长将“低端”的重复性安全任务规模化。但是，SOAR的发展路径提醒我们，不要试图去做全流程的、端到端的自动化！这样会适得其反！因此，真正实战化的SOAR都在不断提醒用户，先将剧本做小，然后再通过拼接的方式形成大的流程，同时要合理设计流程中人机交互的断点。<br/></span></p><p><span style="letter-spacing: 0.578px;">Gartner显然也意识到了这个问题，表示对一个完整的流程实现规模化并不可取（也不现实）。同时，将某个岗位角色的工作过程简单的规模化也不可取，因为每个角色的不同活动性质各不相同，需要采取不同的规模化方式。综合比较，从构成流程的活动入手，实现规模化最为可行，同时有针对性地使用不同的规模化方法(自动化和AI）。</span></p><p><span style="letter-spacing: 0.578px;"><img class="rich_pages wxw-img" data-imgfileid="100001142" data-ratio="0.5537037037037037" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=a3614df8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMeEziadp1sBictffc7G4iborx51iaYMwMoZXbn4pPZbI9ibRvS4LYwIManrBS8skn8iasEgtSxe8v64gA6A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="letter-spacing: 0.578px;">自动化和AI各有所长。自动化擅长工作流执行、命令处理、知识编纂，而AI更擅长提出建议、提供指导，以及知识发现（尤其是总结）。因此，针对不同的安全运营目标，其分解出来的不同活动适用于不同的规模化方法。如下图示例：</span></p><p><span style="letter-spacing: 0.578px;"><img class="rich_pages wxw-img" data-imgfileid="100001143" data-ratio="0.5148148148148148" data-w="1080" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=d5927e40&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMeEziadp1sBictffc7G4iborx5XxyibjNyYTpH2RSap5xxZFfmMGXNOOgvIicPrZ0qksQ2Z6AQdj1LW6xw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="letter-spacing: 0.578px;">以新威胁检测为例，威胁优先级排序使用AI技术，检测工程使用使用GenAI基于自然语言生成检测规则/代码，而威胁验证则使用采用自动化剧本。</span></p><p><strong><span style="letter-spacing: 0.578px;font-size: 20px;">安全运营技术展望总结<br/></span></strong></p><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><p><span style="letter-spacing: 0.578px;">将CTEM与TIDR技术结合，实现更完整的SOC<br/></span></p></li><li><p><span style="letter-spacing: 0.578px;">实验试点GenAI赋能的SOC应用，同时保持合理预期，清醒的把GenAI作为一个能力的增强，而非取代现有的技术专家</span></p></li><li><p><span style="letter-spacing: 0.578px;">综合使用自动化和AI技术迈向超大规模的安全运营</span></p></li></ul><section style="margin-top: 24px;"><strong><span style="font-size: 24px;">总结</span></strong></section><p>暴露管理正在借助实战化、真正面向运营的资产管理、漏洞管理和验证管理将SOC的实战性提升到新的高度。现有SOC中的资产管理、漏洞管理模块需要从设计理念、目标和架构上进行重构。同时，GenAI正在深刻塑造未来SOC的运营方式，包括GenAI在内的AI技术，连同自动化技术，将大幅提升SOC的运营效能。<br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484795">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=8e8c07fd&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyNzMxOTAwMw%3D%3D%26mid%3D2247484795%26idx%3D1%26sn%3D8f835c0699be66f615e7b713f67e26dc%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 19 Jul 2024 12:01:00 +0800</pubDate>
    </item>
    <item>
      <title>Gartner：2024年SIEM（安全信息与事件管理）市场分析</title>
      <link>https://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484777&amp;idx=1&amp;sn=dd216426fc6cf09be507e2d8d83b3695</link>
      <description>SIEM市场将迎来一段动荡期，同时也是活跃期、机会期</description>
      <content:encoded><![CDATA[<p>
原创 <span>Benny Ye</span> <span>2024-05-20 12:00</span> <span style="display: inline-block;">北京</span>
</p>

<p>SIEM市场将迎来一段动荡期，同时也是活跃期、机会期</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=4e6c3ac4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2Ft7v7zyOTkMeSmcmyiaEXnofWbXT1b6ro3AdDbKbicLicBDFtBtEXmsDJHqWBjkiaGiaKp8jsNl0UfzKIVBx4ibhYv6nQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><em style="outline: 0px;color: rgb(2, 30, 170);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);visibility: visible;">【注：本文不是译文，结合了大量笔者自己的体会和判断，请勿将此文观点等同于Gartner观点】</em></p><p>2024年5月8日，Gartner发布了原计划应于2023年底发布的SIEM市场魔力象限（MQ）报告。该报告基于2023年3月31日及其之前12个月的数据做出，因此，并不能反映当前最新的SIEM市场状况，但仍然具有较高的参考价值。本次报告的主笔分析师由上一年度SIEM报告的第二分析师Andrew Davies担纲，而上年度的主笔Pete Shoard作为Gartner的SecOps研究方向的部门负责人，事实上也参与了报告，因而报告具有较强的延续性。</p><p><strong style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);visibility: visible;"><span style="outline: 0px;font-size: 20px;visibility: visible;">SIEM市场定义</span></strong></p><p>今年的定义跟以往的定义内涵保持一致，仅表述方式有所不同。<br/></p><blockquote class="js_blockquote_wrap" data-type="2" data-url="" data-author-name="" data-content-utf8-length="240" data-source-title=""><section class="js_blockquote_digest"><section>SIEM is a configurable security system of record that aggregates and analyzes security <span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">event data from on-premi</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">ses and cloud environments. SIEM assists with response actions </span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">to mitigate issues that cause harm to the organization and satisfy compliance and </span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">reporting requirements.</span></section></section></blockquote><blockquote class="js_blockquote_wrap" data-type="2" data-url="" data-author-name="" data-content-utf8-length="155" data-source-title=""><section class="js_blockquote_digest"><section>SIEM 是一个可配置的安全记录系统，用于聚合和分析来自本地和云环境的安全事态数据。SIEM 协助采取响应措施，以缓解对组织造成损害的事项，并满足合规性和报告要求。SIEM必须能够对各种IT和OT环境中的数据进行采集和范化，能识别感兴趣之事态并进行调查，支持手工和自动的响应，维护当前和历史的安全事态并出具报告。</section></section></blockquote><p>现在，Gartner所有报告中对市场的定义都统一的描述模板，需要从必备能力、标准能力和可选能力三个维度对市场进行详细描述。<br/></p><p>必备能力：</p><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><p>能从位于本地或云端的各种资产中采集基础设施的详细数据和安全相关的数据</p></li><li><p>最终用户可以通过关联的、分析的和签名的方法自助开发、修改和维护威胁检测用例</p></li><li><p>SIEM供应商能够向客户提供安全内容及相关设施以帮助客户创建安全内容。这些安全内容包括：分析、数据范化、数据收集、数据富化等</p></li><li><p>提供案例管理以支撑事件响应活动<br/></p></li><li><p>能按照业务、合规和审计需求生成报告</p></li></ul><section style="margin-top: 24px;">标准能力</section><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><p>能长期存储基本的安全事态数据，并能够方便查询<br/></p></li><li><p>能够根据威胁检测用例、报告和事件调查等不同意图，通过多种方式（日志流、API、文件）从不同的事态源收集事态数据</p></li><li><p>具备多种部署选项，包括本地部署、云宿主中部署（云寄生）、云原生部署和SaaS</p></li><li><p>能对来自第三方系统的数据进行范化、富化和风险评分<br/></p></li><li><p>对任务和工作流进行编排和自动化以强化调查从而遏制事件的不利影响</p></li><li><p>具备完整的SOAR功能<br/></p></li><li><p>具备UEBA和基于数据科学（譬如有监督/无监督机器学习、深度学习、递归神经网络）的高级分析能力<br/></p></li><li><p>具备TIP能力，能管理情报，并为威胁信息提供上下文<br/></p></li></ul><section style="margin-top: 24px;">可选能力：<br/></section><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><p><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">客户可以从平台订阅威胁内容和与第三方技术集成的设施，包括各种应用市场</span></p></li><li><p><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">对分散环境进行联邦搜索<br/></span></p></li><li><p><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">能对SIEM存储库之外的事态进行去中心化查询，以在必要时提取附加的富化信息</span></p></li><li><p>具备EDR、NDR等附加技术组件</p></li><li><p>存储能够与数据湖平台集成</p></li></ul><section style="margin-top: 24px;"><strong style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);visibility: visible;"><span style="outline: 0px;font-size: 20px;visibility: visible;">厂商分析（今年太热闹了）</span></strong><br/></section><p><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">本次入围了22家厂商，比上一次的16家大幅增长，其中出现了3个中国厂商。<br/></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100001120" data-ratio="1.0256410256410255" data-s="300,640" style="" data-type="png" data-w="975" src="https://wechat2rss.xlab.app/img-proxy/?k=52fcd93b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMftfrmibPvKKCsicFwusHkZ46ZfuY7HErJqtMVxhhvWBc3gh3Fua1bgUoO3ibhOcJ1s0y7rAcC97ts5A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p>对比上一次的魔力象限图，如下：<span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></p><p><img class="rich_pages wxw-img" data-imgfileid="100001121" data-ratio="1.0361328125" data-w="1024" src="https://wechat2rss.xlab.app/img-proxy/?k=ce89fecf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2Ft7v7zyOTkMdUic8uKibBic4pAvmINbmicF9SThib4Ht0Q0rGuEicH8bLnPseBYvjTeFEml8ZPvL19g43sVHYibQ83WBNQ%2F640%3Fwx_fmt%3Dother%26tp%3Dwebp%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></p><p>可以发现，厂商分布趋势重回正常（沿一四象限45度斜线两侧分布），入围厂商显著增加集中在利基（niche）象限，头部厂商分化，两强显现。<br/></p><p><strong>领导阵营分化，微软和Splunk两强凸显</strong><br/></p><p>本次报告的领导阵营还是上一次的那五家厂商，但微软稳扎稳打坐实强中强位置，而Splunk不甘示弱，强劲回暖，夺回霸主位置，与微软不相上下。</p><p>微软从2021年上榜以来，一年一大变，三年大变样。2022年大幅提升了执行力，而2023年则大幅增强了愿景的完整性（横轴排第二）。毫无疑问，微软的Security Copilot为其在创新指标上加分不少。Gartner认为微软SIEM具有高度集成的生态系统，便捷丰富的定制化能力，以及对攻击的ATT&amp;CK标注的高度覆盖。必须看到，微软借助其在云和ITOps软件中的领导者地位帮助其SIEM大肆攻城略地，势头很猛。当然，其缺点也比较鲜明，体现在对Azure的依赖，复杂的价格体系，以及开箱即用合规报表模板数量有限。<br/></p><p>Splunk在2018、2019年的时候都是强中强，但在2021年出现了明显的滑坡。从2022年开始回暖（主要是因为补齐了CloudSIEM的能力），到这次终于重回巅峰，尽管这次依然因为价高和过于复杂而遭受诟病。笔者认为，思科收购Splunk后，将补齐Splunk SIEM在端上的能力（借助思科的EDR/XDR），将有助于夯实其领导者地位，并应对来自微软的进攻。但笔者担心的是，不知道Splunk AI跟微软PK胜算几何。</p><p><strong>Securonix继续稳坐钓鱼台</strong></p><p>最近三次报告，Securonix的位置几乎没有改变。Securonix的产品理念总是保持跟Gartner高度一致，譬如受到Gartner表扬的对第三方数据湖数据的访问支持（数据联邦化），以及引入了SIEM的有效性评估指标体系。此外，就笔者所知，在与其合作的SOAR厂商被Fortinet收购后，快速推出了自研的SOAR模块，也展现了该公司的韧性。</p><p><strong>IBM和Exabeam巅峰不再</strong><br/></p><p>IBM在以前常年处于领导者的头牌位置，看着跟他PK的对手换了一茬又一茬。从2021年开始慢慢显现出了颓势，到现在依然起色不大，虽然销量依然排第二，但增速疲软。应该说，这几年IBM在SIEM领域还是比较积极的，通过收购陆续补齐了SOAR、EDR、ASM等组件，也在CloudSIEM方面有所提升。<strong style="font-size: var(--articleFontsize);letter-spacing: 0.034em;"></strong></p><p>就在北京时间2024年5月16日，<span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);background-color: rgb(255, 255, 255);letter-spacing: 0.034em;visibility: visible;">IBM和</span><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);background-color: rgb(255, 255, 255);letter-spacing: 0.578px;visibility: visible;">派拓网络（Palo Alto Networks，简称PANW</span><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);background-color: rgb(255, 255, 255);letter-spacing: 0.578px;visibility: visible;">）</span><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);background-color: rgb(255, 255, 255);letter-spacing: 0.578px;visibility: visible;">签署了一揽子合作协议，并</span><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzkzMDE5MDI5Mg==&amp;mid=2247506022&amp;idx=1&amp;sn=05fc4ad89114e91876d6c04090633479&amp;chksm=c27c9eddf50b17cb2615bf038085fb28a03e0678c3b2d44ac6f3921587372b1d3511edc4541b&amp;scene=21#wechat_redirect" textvalue="宣布将QRadar SaaS资产出售给PANW" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" style="outline: 0px;color: var(--weui-LINK);cursor: pointer;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);white-space: normal;background-color: rgb(255, 255, 255);letter-spacing: 0.034em;visibility: visible;"><strong style="outline: 0px;visibility: visible;">宣布将QRadar SaaS资产出售给PANW</strong></a><strong style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);white-space: normal;background-color: rgb(255, 255, 255);letter-spacing: 0.034em;visibility: visible;">，同时，IBM未来将主推PANW的SOC产品XSIAM，并且IBM咨询部门将依托XSIAM开展MSS业务，而PANW则凭借收购来的QRadar SaaS资产一次性获得大量客户，强势进入SIEM/SOC市场</strong><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);background-color: rgb(255, 255, 255);letter-spacing: 0.034em;visibility: visible;">。可以参见《<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484774&amp;idx=1&amp;sn=987126678b5166e4149e90aca01e2d78&amp;chksm=fa002fd2cd77a6c41bcb0af88e4e01c1dfd3b595b4f6e7c0b5566d782fd0130813141aa7cebe&amp;scene=21#wechat_redirect" textvalue="IBM放弃自己的QRadar，转而使用派拓网络的XSIAM" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">IBM放弃自己的QRadar，转而使用派拓网络的XSIAM</a>》了解更多信息。<span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"></span></span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);"><span style="letter-spacing: 0.578px;font-size: var(--articleFontsize);">Exabeam作为当年的新兴SIEM厂商，凭借UEBA强势入局，2021年曾经位于Gartner SIEM MQ领导象限榜首，达到巅峰，如今也已经锋芒不在，但仍然是领导者阵营的一员。Gartner表示，Exabeam产品主要聚焦大型客户，具备较先进的联邦数据搜索能力，以及承袭自UEBA的实体评分功能，但其售价较高，部署初始化难度较大。</span></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);"><strong><span style="outline: 0px;font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="outline: 0px;letter-spacing: 0.578px;"><span style="outline: 0px;letter-spacing: 0.578px;">OpenText平稳转移</span></span></span></strong></p><p>对于笔者比较有感情的ArcSight团队在2023年初又更换了一次东家，随着Micro Focus被收购到了OpenText。不过好在无论哪里都站住了SIEM这个阵地，品牌也得以继续保留，因此本次Gartner SIEM MQ位置基本没有什么变化。如今，ArcSight的架构已经重构完成，并已经集齐了Gartner推崇的SIEM、UEBA、SOAR、TIP，还有OpenText早前收购的EDR加持。<span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></p><p><strong>LogRhythm继续退步</strong><br/></p><p>作为中生代典范的LogRhythm继续退步，进入了利基象限，眼看着就要奔ArcSight后尘而去。Gartner认为<span style="letter-spacing: 0.578px;">LogRhythm虽然补齐了云原生架构的SIEM产品，但却存在多条产线并存的复杂局面，导致其产品和市场战略不清晰。同样是在5月16日，<span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;background-color: rgb(255, 255, 255);">LogRhythm和Exabeam宣布了合并计划，不知道双方将如何整合，让我们拭目以待。</span></span><br/></p><p><strong><span style="letter-spacing: 0.578px;"><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;background-color: rgb(255, 255, 255);">上榜厂商大幅增加，Google终于入选</span></span></strong><span style="letter-spacing: 0.578px;"><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;background-color: rgb(255, 255, 255);"><br/></span></span></p><p><span style="letter-spacing: 0.578px;"><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;background-color: rgb(255, 255, 255);">这次报告增加了6个厂商，其中中国厂商2家，欧洲厂商1家，<span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;background-color: rgb(255, 255, 255);">总上榜厂家达到22家。值得一提的是</span>Google终于上榜，虽然比微软晚了3年。笔者分析，Google这次上榜跟其在近几年通过收购Siemplify获得SOAR能力，以及收购Mandiant并集成其威胁情报能力不无关系。这些使得其Chronicle SaaS产品更符合Gartner的入围标准。不过，Gartner依然认为Google <span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;background-color: rgb(255, 255, 255);">Chronic</span><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;background-color: rgb(255, 255, 255);">le</span><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;background-color: rgb(255, 255, 255);"> </span>的UEBA功能偏弱。<br/></span></span></p><p><strong><span style="letter-spacing: 0.578px;"><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;background-color: rgb(255, 255, 255);">未能上榜的CrowdStrike和Palo Alto Networks</span></span></strong><span style="letter-spacing: 0.578px;"><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;background-color: rgb(255, 255, 255);"></span></span></p><p><span style="letter-spacing: 0.578px;"><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;background-color: rgb(255, 255, 255);">在刚刚结束的<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484766&amp;idx=1&amp;sn=5b66715c108908d39eb92ecdc964c9f6&amp;chksm=fa002feacd77a6fcdc78bff2275afb83ea403c19d547584bd02669f68550e26c5d27b7303c8b&amp;scene=21#wechat_redirect" textvalue="RSAC2024大会" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">RSAC2024大会</a>上，CrowdStrike的联合创始人兼CEO大谈特谈以人、工作流程自动化、数据和AI为核心的下一代SIEM，为其在5月7日发布的AI原生的Falcon Next-Gen SIEM造势。此举说明，CrowdStrike开始大举进入SIEM市场。而早在<span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">2021</span><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">年，CrowdStrike通过</span><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">Humio收购获得了日志分析管理技术，并基于此发布了初代的SIEM产品<span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">Falcon LogScale。</span></span></span></span></p><p><span style="letter-spacing: 0.578px;"><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;background-color: rgb(255, 255, 255);"><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">在</span><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">Gartner本次</span><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">发布的</span><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">2024</span><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">年</span><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">SIEM</span><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">魔力象限中，</span><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">CrowdStrike</span><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">未能上榜，理由是</span><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">Gartner</span><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">认为</span><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">Falcon LogScale</span><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">还是不够开放，更适合作为</span><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">CrowdStrike</span><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">家族产品和技术的扩展。考虑到这个报告分析的主要是LogScale，而非最新的<span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;background-color: rgb(255, 255, 255);">Falcon Next-Gen </span><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;background-color: rgb(255, 255, 255);">S</span><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;background-color: rgb(255, 255, 255);">IEM，想必下一次报告中会强势上榜。作为现在的当红炸子鸡，CrowdStrike的实力不容小觑，下一代SIEM是其安全平台战略（跟PANW一个调性）的重要组成部分。</span></span></span></span><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"></span></span></span></p><p><span style="letter-spacing: 0.578px;"><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;background-color: rgb(255, 255, 255);"><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;background-color: rgb(255, 255, 255);">同样，尽管PANW在2022年初就发布了它的SIEM类产品XSIAM，但<span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">Gartner</span><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">认为</span><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">XSIAM并不符合此次评估标准，而</span><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">更适合那些希望购买</span><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">PANW</span><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">全家桶的客户。言外之意，就是认为</span><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">XSIAM</span><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">的开放性和生态并不好。考虑到这份报告分析时间截至2023年9月1日而并未纳入最新情况，以及这次</span><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484774&amp;idx=1&amp;sn=987126678b5166e4149e90aca01e2d78&amp;chksm=fa002fd2cd77a6c41bcb0af88e4e01c1dfd3b595b4f6e7c0b5566d782fd0130813141aa7cebe&amp;scene=21#wechat_redirect" textvalue="PANW强势购买IBM QRadar SIEM客户" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2"><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">PANW</span><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">强势购买</span><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">IBM QRadar SIEM</span><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">客户</span></a><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">的行为和IBM的力推，估计下一次入选不在话下</span><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">。</span><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);background-color: rgb(255, 255, 255);letter-spacing: 0.034em;"></span></span></span></span></span></span></span></p><p><span style="color: rgb(255, 0, 0);"><strong><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">厂商格局小结</span></strong></span><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><br/></span></p><p><span style="letter-spacing: 0.578px;"><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;background-color: rgb(255, 255, 255);"><span style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);"><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.578px;background-color: rgb(255, 255, 255);"><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);">通过以上令人眼花缭乱的分析，笔者发现，现在顶级的云厂商（微软，Google），以及大型的安全厂商（不管你是什么出身）都将SIEM/SOC所代表的SecOps业务视为自己未来的重要战略（有的是所谓安全平台战略），纷纷入局，<strong>SIEM市场格局将迎来一段动荡期，也可以说是活跃期、机会期</strong>。还有一个动向，就是大量XDR厂商（包括CrowdStrike、Cisco、PANW、Cybereason），已经等不及说服用户用XDR替代SIEM了，干脆就直接发布一个SIEM/SOC产品，强切SIEM/SOC市场。</span></span></span></span></span></span></span></p><p style="margin-top: 24px;"><strong style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);visibility: visible;"><span style="outline: 0px;font-size: 20px;visibility: visible;">产品和市场分析</span></strong></p><p style="margin-top: 24px;"><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">总体描述跟上一年一样：</span><span style="font-size: var(--articleFontsize);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">SIEM产品继续不断吸纳新的功能，并正在转变架构策略以适应客户需求。</span><span style="background-color: rgb(255, 255, 255);font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;font-size: var(--articleFontsize);"></span></p><p style="margin-top: 24px;"><span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">Gartner估计，SIEM市场规模从2022年的20亿美元增长到2023年的57亿美元，增长率为13%，增速有所回落。SIEM的购买驱动因素也没有变化，还是<span style="font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-align: left;background-color: rgb(255, 255, 255);">检测、响应、暴露管理，以及合规。</span></span></p><p style="margin-top: 24px;">Gartner认为，尽管SIEM已经位于Hype Cycle的生产力平原，属于成熟阶段，但有多股外部力量正式试图颠覆SIEM，反思SIEM的角色定位，以及实现SIEM的最佳技术。这些外力包括：<br/></p><ul class="list-paddingleft-1" style="list-style-type: circle;"><li><p style="margin-top: 24px;">客户越来越青睐选择云服务供应商【对于中国客户，可能恰恰相反？】</p></li><li><p style="margin-top: 24px;"><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">需要处理更多的数据（成本膨胀）</span></p></li><li><p style="margin-top: 24px;">对检测栈整体简化的呼声越来越高</p></li></ul><p style="margin-top: 24px;">因此，此时SIEM厂商在与客户沟通时经常会涉及到云原生、数据湖、XDR等议题。数据主权和隐私等合规要求也对SIEM的自身数据安全问题提出了挑战。</p><p style="margin-top: 24px;">正是由于有了各种颠覆性力量和动机，以及客户需求，给有进取心的SIEM厂商带来了机会。<br/></p><p style="margin-top: 24px;">不过，Gartner对于GenAI在SIEM中的价值持审慎态度。</p><p style="margin-top: 24px;">纵览整个报告，对于SIEM未来发展趋势和一些热点话题，并未展开。可以参考笔者《<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484530&amp;idx=1&amp;sn=af1537ab8fe4503a0b10fb133d507096&amp;chksm=fa002ec6cd77a7d01239618b95446d54a2fd0b83c1e6b16c22a1bbb2718df271fc94a6fb3abe&amp;scene=21#wechat_redirect" textvalue="Gartner：2022年SIEM（安全信息与事件管理）市场分析" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">Gartner：2022年SIEM（安全信息与事件管理）市场分析</a>》中的产品和市场分析章节的内容，了解Cloud SIEM的问题，XDR和SIEM的关系，SOAR和SIEM的关系，以及暴露管理和SIEM的关系。相关内容至今依然有效。<br/></p><p style="margin-top: 24px;">【参考】<br/></p><p style="line-height: 1.6em;margin-bottom: 8px;margin-top: 0px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484530&amp;idx=1&amp;sn=af1537ab8fe4503a0b10fb133d507096&amp;chksm=fa002ec6cd77a7d01239618b95446d54a2fd0b83c1e6b16c22a1bbb2718df271fc94a6fb3abe&amp;scene=21#wechat_redirect" textvalue="Gartner：2022年SIEM（安全信息与事件管理）市场分析" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">Gartner：2022年SIEM（安全信息与事件管理）市场分析</a><br/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);text-align: left;line-height: 1.6em;margin-bottom: 8px;margin-top: 0px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484351&amp;idx=1&amp;sn=ff83fa4e2b4286a301a541ccc971c3cf&amp;chksm=fa00290bcd77a01d7b917fd6c9041ef12b5f2300916212d0dd74fe836c78bcffc1887ed11520&amp;scene=21#wechat_redirect" textvalue="Gartner：2021年SIEM（安全信息与事件管理）市场分析" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" style="outline: 0px;color: var(--weui-LINK);cursor: pointer;">Gartner：2021年SIEM（安全信息与事件管理）市场分析</a></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);line-height: 1.6em;margin-bottom: 8px;margin-top: 0px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484022&amp;idx=1&amp;sn=e39ec5ac122c698f201e94df81d6d7f3&amp;chksm=fa0028c2cd77a1d442b08e857f98863b9be1894f56ef98615d4d588cbdb90e5ae3270fc4eb78&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" style="outline: 0px;color: var(--weui-LINK);cursor: pointer;">Gartner：2019年SIEM（安全信息与事件管理）市场分析</a></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);line-height: 1.6em;margin-bottom: 8px;margin-top: 0px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247483705&amp;idx=1&amp;sn=575fd73452bccf2dbfd4612f93aabf1c&amp;chksm=fa002b8dcd77a29bdabd04ba1e2819b3cf710bd98412c45e6b036433b24b3605bfbc1060843e&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" style="outline: 0px;color: var(--weui-LINK);cursor: pointer;">Gartner：2018年SIEM（安全信息与事件管理）市场分析</a><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);line-height: 1.6em;margin-bottom: 8px;margin-top: 0px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247483705&amp;idx=2&amp;sn=893002cafd46ae55c1f932435ac81fbb&amp;chksm=fa002b8dcd77a29bdef3b56239692999329f32a80eb6ad6ab98ad901e7e1b54460297293c211&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" style="outline: 0px;color: var(--weui-LINK);cursor: pointer;">Gartner：2017年SIEM（安全信息与事件管理）市场分析</a><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);line-height: 1.6em;margin-bottom: 8px;margin-top: 0px;"><br/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);line-height: 1.6em;margin-bottom: 8px;margin-top: 0px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484553&amp;idx=1&amp;sn=4822cc424ee1859f410a5be56b6c243a&amp;chksm=fa002e3dcd77a72b7f5baa57441369cab95a3d84e20470e5e5ad002a4ec1181e20fd1d8e788e&amp;scene=21#wechat_redirect" textvalue="Forrester：2022年安全分析平台厂商评估" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">Forrester：2022年安全分析平台厂商评估</a><br/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);line-height: 1.6em;margin-bottom: 8px;margin-top: 0px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484513&amp;idx=1&amp;sn=36739ae447e070bbe70ba52a3f73f274&amp;chksm=fa002ed5cd77a7c3609048c1c346c21d1808b5da9e7da06ace4ae5031faf778ad3ded9cf8484&amp;scene=21#wechat_redirect" textvalue="Forrester：2021年安全分析平台厂商评估" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" style="outline: 0px;color: var(--weui-LINK);cursor: pointer;">Forrester：2021年安全分析平台厂商评估</a><br style="outline: 0px;"/></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);line-height: 1.6em;margin-bottom: 8px;margin-top: 0px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484260&amp;idx=1&amp;sn=64b4bcc40cbd2a49b9463aa47b4d67cc&amp;chksm=fa0029d0cd77a0c6dcfb950ddb31a07eeee8893748fef729561080a19eea1a9612a658425835&amp;scene=21#wechat_redirect" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" style="outline: 0px;color: var(--weui-LINK);cursor: pointer;">Forrester：2020年安全分析平台厂商评估</a></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);line-height: 1.6em;margin-bottom: 8px;margin-top: 0px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484524&amp;idx=1&amp;sn=cac5a8d1fe5cec250e4ce7bbdeb70b92&amp;chksm=fa002ed8cd77a7cedb552b234cf884475bb70409e21e8060b05e72cc6f648400ddc6f29e9241&amp;scene=21#wechat_redirect" textvalue="浅析IDC全球SIEM市场预测(2022-2026)" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" style="outline: 0px;color: var(--weui-LINK);cursor: pointer;">浅析IDC全球SIEM市场预测(2022-2026)</a></p><p style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;color: rgb(34, 34, 34);background-color: rgb(255, 255, 255);line-height: 1.6em;margin-bottom: 8px;margin-top: 0px;"><br/></p><section style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);margin-top: 0px;margin-bottom: 8px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484766&amp;idx=1&amp;sn=5b66715c108908d39eb92ecdc964c9f6&amp;chksm=fa002feacd77a6fcdc78bff2275afb83ea403c19d547584bd02669f68550e26c5d27b7303c8b&amp;scene=21#wechat_redirect" textvalue="从RSAC2024看SOC发展趋势" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" style="outline: 0px;color: var(--weui-LINK);cursor: pointer;">从RSAC2024看SOC发展趋势</a><br style="outline: 0px;"/></section><section style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);margin-top: 0px;margin-bottom: 8px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484730&amp;idx=1&amp;sn=a4dfcb4c250f3128b59cab19c6a393f2&amp;chksm=fa002f8ecd77a698a4d47c17f463eaa132656a7fdfecef6f280c698759af43704b1210b1ae1e&amp;scene=21#wechat_redirect" textvalue="再见！爱因斯坦计划，网安态势感知迎来转型" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" style="outline: 0px;color: var(--weui-LINK);cursor: pointer;">再见！爱因斯坦计划，网安态势感知迎来转型</a><br style="outline: 0px;"/></section><section style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);margin-top: 0px;margin-bottom: 8px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484657&amp;idx=1&amp;sn=97ef202f80d16243bc1212bedf759458&amp;chksm=fa002e45cd77a75364e60ca7227c60618c930f3f54eb514f850630b26bd60fa359e9ee03894d&amp;scene=21#wechat_redirect" textvalue="从Garnter2023年北美安全与风险管理峰会看SIEM和SOC的发展趋势" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" style="outline: 0px;color: var(--weui-LINK);cursor: pointer;">从Gartner2023年北美安全与风险管理峰会看SIEM和SOC的发展趋势</a><br style="outline: 0px;"/></section><section style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);margin-top: 0px;margin-bottom: 8px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484640&amp;idx=1&amp;sn=6ff1f407b3ad35c01efbf35d5a0ded0d&amp;chksm=fa002e54cd77a7425235ca39c42acb32187bd913d3b3ab9ec75c9d2c504fab0f49d75efada57&amp;scene=21#wechat_redirect" textvalue="从RSAC2023看安全运营的技术发展趋势" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" style="outline: 0px;color: var(--weui-LINK);cursor: pointer;">从RSAC2023看安全运营的技术发展趋势</a><br style="outline: 0px;"/></section><section style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);margin-top: 0px;margin-bottom: 8px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484634&amp;idx=1&amp;sn=4bf253ef025528fc75493ba8df4444fd&amp;chksm=fa002e6ecd77a77823156257953359d03278eb1ac2543c0fbd244181f918a81206869ff90b83&amp;scene=21#wechat_redirect" textvalue="从Gartner2022年魔力象限看SIEM未来发展" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" style="outline: 0px;color: var(--weui-LINK);cursor: pointer;">从Gartner2022年魔力象限看SIEM未来发展</a></section><section style="outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);margin-top: 0px;margin-bottom: 8px;"><a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzUyNzMxOTAwMw==&amp;mid=2247484500&amp;idx=1&amp;sn=91a3a818e697213a9b46ac7b5559944e&amp;chksm=fa002ee0cd77a7f6503c923d308c43d53b0cdd2e6725326b24fd49915c33e9f3b1ba9a42af05&amp;scene=21#wechat_redirect" textvalue="SIEM的未来" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2" hasload="1" style="outline: 0px;color: var(--weui-LINK);cursor: pointer;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;white-space: normal;background-color: rgb(255, 255, 255);">SIEM的未来</a></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484777">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=fee50177&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzUyNzMxOTAwMw%3D%3D%26mid%3D2247484777%26idx%3D1%26sn%3Ddd216426fc6cf09be507e2d8d83b3695%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 20 May 2024 12:00:00 +0800</pubDate>
    </item>
  </channel>
</rss>